lib

Core libraries for Radroots
git clone https://radroots.dev/git/lib.git
Log | Files | Refs | README

commit db5564c02a74f8b7a74dd4e5de26ece3f24eb6a5
parent 8eedb0a69161d8869ea986fec9905cff65b0dcd4
Author: triesap <tyson@radroots.org>
Date:   Sun,  6 Sep 2026 23:20:48 +0000

fix: remove Step 298 probe digest circularity

- Read the producing request digest from an isolated control file.
- Keep the recorded platform command independent of its own digest.
- Reject missing or malformed request identities before probing.
- Preserve canonical byte-exact platform result output.

Diffstat:
Mtools/xtask/src/main.rs | 9++-------
Mtools/xtask/src/rshr_202_step_298_platform.rs | 17++++++++++++++++-
2 files changed, 18 insertions(+), 8 deletions(-)

diff --git a/tools/xtask/src/main.rs b/tools/xtask/src/main.rs @@ -148,10 +148,7 @@ enum XtaskCommand { execution_request_sha256: String, }, #[command(name = "rshr-step-298-platform-probe", hide = true)] - RshrStep298PlatformProbe { - #[arg(long)] - execution_request_sha256: String, - }, + RshrStep298PlatformProbe, SourceLock { #[arg(long)] consumer_root: PathBuf, @@ -612,9 +609,7 @@ fn run(args: &[String]) -> Result<(), String> { platform, execution_request_sha256, }), - XtaskCommand::RshrStep298PlatformProbe { - execution_request_sha256, - } => rshr_202_step_298_platform::run(&execution_request_sha256), + XtaskCommand::RshrStep298PlatformProbe => rshr_202_step_298_platform::run(), XtaskCommand::SourceLock { consumer_root } => { build_control::validate_consumer(&consumer_root).map(|_| ()) } diff --git a/tools/xtask/src/rshr_202_step_298_platform.rs b/tools/xtask/src/rshr_202_step_298_platform.rs @@ -1,3 +1,5 @@ +use std::fs; +use std::path::Path; use std::process::Command; use serde_json::{Value, json}; @@ -9,6 +11,14 @@ const PROBE_SOURCE_PATH: &str = "tools/radroots_scripts/src/radroots_scripts/verify/rshr_200_series.py"; const PROBE_SOURCE_SHA256: &str = "add949c6c20a037123808230625dfd09dd6fa6c5afe5a856400227191f5de5b5"; +const REQUEST_PATH: &str = ".git/rshr-step-298-platform-request-sha256"; + +fn root() -> &'static Path { + Path::new(env!("CARGO_MANIFEST_DIR")) + .parent() + .and_then(Path::parent) + .expect("xtask must remain under tools/xtask") +} fn canonical(value: &Value) -> Result<Vec<u8>, String> { serde_json::to_vec(value).map_err(|_| "Step 298 platform JSON encoding failed".to_owned()) @@ -36,7 +46,12 @@ fn uname(flag: &str) -> Result<String, String> { Ok(value.to_owned()) } -pub(crate) fn run(execution_request_sha256: &str) -> Result<(), String> { +pub(crate) fn run() -> Result<(), String> { + let request_bytes = fs::read(root().join(REQUEST_PATH)) + .map_err(|_| "Step 298 platform execution request is unavailable".to_owned())?; + let raw_request = std::str::from_utf8(&request_bytes) + .map_err(|_| "Step 298 platform execution request is not UTF-8".to_owned())?; + let execution_request_sha256 = raw_request.strip_suffix('\n').unwrap_or(raw_request); if execution_request_sha256.len() != 64 || !execution_request_sha256 .bytes()