commit db5564c02a74f8b7a74dd4e5de26ece3f24eb6a5
parent 8eedb0a69161d8869ea986fec9905cff65b0dcd4
Author: triesap <tyson@radroots.org>
Date: Sun, 6 Sep 2026 23:20:48 +0000
fix: remove Step 298 probe digest circularity
- Read the producing request digest from an isolated control file.
- Keep the recorded platform command independent of its own digest.
- Reject missing or malformed request identities before probing.
- Preserve canonical byte-exact platform result output.
Diffstat:
2 files changed, 18 insertions(+), 8 deletions(-)
diff --git a/tools/xtask/src/main.rs b/tools/xtask/src/main.rs
@@ -148,10 +148,7 @@ enum XtaskCommand {
execution_request_sha256: String,
},
#[command(name = "rshr-step-298-platform-probe", hide = true)]
- RshrStep298PlatformProbe {
- #[arg(long)]
- execution_request_sha256: String,
- },
+ RshrStep298PlatformProbe,
SourceLock {
#[arg(long)]
consumer_root: PathBuf,
@@ -612,9 +609,7 @@ fn run(args: &[String]) -> Result<(), String> {
platform,
execution_request_sha256,
}),
- XtaskCommand::RshrStep298PlatformProbe {
- execution_request_sha256,
- } => rshr_202_step_298_platform::run(&execution_request_sha256),
+ XtaskCommand::RshrStep298PlatformProbe => rshr_202_step_298_platform::run(),
XtaskCommand::SourceLock { consumer_root } => {
build_control::validate_consumer(&consumer_root).map(|_| ())
}
diff --git a/tools/xtask/src/rshr_202_step_298_platform.rs b/tools/xtask/src/rshr_202_step_298_platform.rs
@@ -1,3 +1,5 @@
+use std::fs;
+use std::path::Path;
use std::process::Command;
use serde_json::{Value, json};
@@ -9,6 +11,14 @@ const PROBE_SOURCE_PATH: &str =
"tools/radroots_scripts/src/radroots_scripts/verify/rshr_200_series.py";
const PROBE_SOURCE_SHA256: &str =
"add949c6c20a037123808230625dfd09dd6fa6c5afe5a856400227191f5de5b5";
+const REQUEST_PATH: &str = ".git/rshr-step-298-platform-request-sha256";
+
+fn root() -> &'static Path {
+ Path::new(env!("CARGO_MANIFEST_DIR"))
+ .parent()
+ .and_then(Path::parent)
+ .expect("xtask must remain under tools/xtask")
+}
fn canonical(value: &Value) -> Result<Vec<u8>, String> {
serde_json::to_vec(value).map_err(|_| "Step 298 platform JSON encoding failed".to_owned())
@@ -36,7 +46,12 @@ fn uname(flag: &str) -> Result<String, String> {
Ok(value.to_owned())
}
-pub(crate) fn run(execution_request_sha256: &str) -> Result<(), String> {
+pub(crate) fn run() -> Result<(), String> {
+ let request_bytes = fs::read(root().join(REQUEST_PATH))
+ .map_err(|_| "Step 298 platform execution request is unavailable".to_owned())?;
+ let raw_request = std::str::from_utf8(&request_bytes)
+ .map_err(|_| "Step 298 platform execution request is not UTF-8".to_owned())?;
+ let execution_request_sha256 = raw_request.strip_suffix('\n').unwrap_or(raw_request);
if execution_request_sha256.len() != 64
|| !execution_request_sha256
.bytes()