commit 45d4ad51a828705846f87350e94c22b3b6746f8a
parent 7913a330d1b57eac972cced2c8f3b4c2740236a2
Author: triesap <tyson@radroots.org>
Date: Sun, 6 Sep 2026 23:03:56 +0000
fix: accept canonical Nix evaluation transport
- Account for the Nix JSON transport newline.
- Preserve the exact supported-system byte payload.
- Rebind the gate contract to corrected verifier bytes.
- Keep all Step 298 source and mutation checks unchanged.
Diffstat:
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/contracts/rshr-202-step-298-gates.v1.json b/contracts/rshr-202-step-298-gates.v1.json
@@ -1 +1 @@
-{"gate_command_contract":[{"argv_template":["cargo","extbuild","run","--","uv","run","--offline","--no-project","python3","-B","tools/rshr_202_step_298_gate.py","--step={step}","--check-id={check_id}","--source-revision={source_revision}","--source-tree={source_tree}","--candidate-digest={candidate_digest}","--platform=macos_aarch64","--execution-request-sha256={execution_request_sha256}"],"assertion_id":["step_298_gate_01_14c62391f40dcf5a2e166bac481c9eb8f50052ee65403ddbd63df5cc82ec6843"],"check_id":"gate-01-14c62391f40dcf5a2e166bac481c9eb8f50052ee65403ddbd63df5cc82ec6843","environment_authority":{"cache_policy_id":"rshr-200-step-287-cache-policy.v1","cache_policy_sha256":"3e81d178bce97b6c349dfbb00c68fd6f620ac00b1a1c8d37b12e9998f3c9eaaa","cadence_policy_id":"rshr-200-step-287-cadence-policy.v1","cadence_policy_sha256":"d24903df8659ee3772297c84994911efe7d21cb8b988320ddc6ddce0431892a1","isolation":"extbuild_host_constrained","network":"disabled","network_policy_id":"none","network_policy_sha256":"none","resource_policy_id":"rshr-200-step-287-resource-policy.v1","resource_policy_sha256":"05d3c7a89185d3c55678d97955193fce2ed92b1eee5af99083d77ea64c98d14e"},"environment_names":["EXT_BUILD_CONFIG","EXT_BUILD_MACHINE_CONFIG","EXT_BUILD_ROOT","HOME","PATH","RUSTUP_TOOLCHAIN","TMPDIR"],"gate_definition_sha256":"14c62391f40dcf5a2e166bac481c9eb8f50052ee65403ddbd63df5cc82ec6843","required_platforms":["macos_aarch64"],"required_tools":["uv","python3","git","perl"],"result_schema":"radroots.services-hardening.rshr-200-step-check-result.v1","schema":"radroots.services-hardening.rshr-200-step-check-command.v1","step":298,"verifier_path":"tools/rshr_202_step_298_gate.py","verifier_sha256":"eb4131b2c9c6b3888547ce32a765eb6ab6c273ccb89ea47040a532c39a3f8725"}],"schema":"radroots.lib.rshr-202-step-298-gates.v1","step":[298]}
+{"gate_command_contract":[{"argv_template":["cargo","extbuild","run","--","uv","run","--offline","--no-project","python3","-B","tools/rshr_202_step_298_gate.py","--step={step}","--check-id={check_id}","--source-revision={source_revision}","--source-tree={source_tree}","--candidate-digest={candidate_digest}","--platform=macos_aarch64","--execution-request-sha256={execution_request_sha256}"],"assertion_id":["step_298_gate_01_14c62391f40dcf5a2e166bac481c9eb8f50052ee65403ddbd63df5cc82ec6843"],"check_id":"gate-01-14c62391f40dcf5a2e166bac481c9eb8f50052ee65403ddbd63df5cc82ec6843","environment_authority":{"cache_policy_id":"rshr-200-step-287-cache-policy.v1","cache_policy_sha256":"3e81d178bce97b6c349dfbb00c68fd6f620ac00b1a1c8d37b12e9998f3c9eaaa","cadence_policy_id":"rshr-200-step-287-cadence-policy.v1","cadence_policy_sha256":"d24903df8659ee3772297c84994911efe7d21cb8b988320ddc6ddce0431892a1","isolation":"extbuild_host_constrained","network":"disabled","network_policy_id":"none","network_policy_sha256":"none","resource_policy_id":"rshr-200-step-287-resource-policy.v1","resource_policy_sha256":"05d3c7a89185d3c55678d97955193fce2ed92b1eee5af99083d77ea64c98d14e"},"environment_names":["EXT_BUILD_CONFIG","EXT_BUILD_MACHINE_CONFIG","EXT_BUILD_ROOT","HOME","PATH","RUSTUP_TOOLCHAIN","TMPDIR"],"gate_definition_sha256":"14c62391f40dcf5a2e166bac481c9eb8f50052ee65403ddbd63df5cc82ec6843","required_platforms":["macos_aarch64"],"required_tools":["uv","python3","git","perl"],"result_schema":"radroots.services-hardening.rshr-200-step-check-result.v1","schema":"radroots.services-hardening.rshr-200-step-check-command.v1","step":298,"verifier_path":"tools/rshr_202_step_298_gate.py","verifier_sha256":"1e4719de5d317bd2caf1403940af7ae8a763efd6b0d952e80f84a97a75cead57"}],"schema":"radroots.lib.rshr-202-step-298-gates.v1","step":[298]}
diff --git a/tools/rshr_202_step_298_gate.py b/tools/rshr_202_step_298_gate.py
@@ -185,7 +185,7 @@ def run_nix_lane() -> None:
environment,
label="Step 298 Nix system evaluation",
)
- if systems != b'["aarch64-darwin","x86_64-linux"]':
+ if systems != b'["aarch64-darwin","x86_64-linux"]\n':
raise shared.GateError("Step 298 Nix systems differ")
shared.run(
[