commit ecfa5ec333069200b28f9809d5e3416e44e2e75c
parent 035717adf65596f2ec93b59462f5db241232ba5b
Author: triesap <tyson@radroots.org>
Date: Mon, 3 Aug 2026 16:13:57 +0000
app-rt: finalize packaged sdk integration
- Isolate UniFFI bindgen tooling from production FFI dependencies
- Make package metadata and embedded provenance reproducible
- Verify path-free core and FFI archives against the local registry
- Rebuild native artifacts and generated bindings byte-for-byte
Diffstat:
6 files changed, 62 insertions(+), 37 deletions(-)
diff --git a/crates/mobile_bindgen/Cargo.toml b/crates/mobile_bindgen/Cargo.toml
@@ -0,0 +1,23 @@
+[package]
+name = "radroots_app_bindgen"
+description = "Private UniFFI binding generator for Radroots mobile artifacts"
+version.workspace = true
+edition.workspace = true
+authors = ["Radroots Authors"]
+rust-version.workspace = true
+license.workspace = true
+repository.workspace = true
+homepage.workspace = true
+readme.workspace = true
+publish = false
+include = ["src/**", "Cargo.toml"]
+
+[[bin]]
+name = "radroots-app-bindgen"
+path = "src/main.rs"
+
+[lints.rust]
+unexpected_cfgs = { level = "warn", check-cfg = ['cfg(coverage_nightly)'] }
+
+[dependencies]
+uniffi = { workspace = true, features = ["cli"] }
diff --git a/crates/mobile_ffi/bin/uniffi-bindgen.rs b/crates/mobile_bindgen/src/main.rs
diff --git a/crates/mobile_core/Cargo.toml b/crates/mobile_core/Cargo.toml
@@ -9,6 +9,8 @@ description = "Application core runtime for Radroots apps"
repository.workspace = true
homepage.workspace = true
readme.workspace = true
+publish = false
+include = ["src/**", "tests/**", "build.rs", "Cargo.toml"]
[lib]
crate-type = ["rlib"]
diff --git a/crates/mobile_core/build.rs b/crates/mobile_core/build.rs
@@ -1,45 +1,46 @@
-use std::{
- env,
- process::Command,
- time::{SystemTime, UNIX_EPOCH},
-};
+use std::{env, process::Command};
fn main() {
println!("cargo:rerun-if-changed=build.rs");
println!("cargo:rerun-if-env-changed=RUSTC");
println!("cargo:rerun-if-env-changed=PROFILE");
+ println!("cargo:rerun-if-env-changed=RADROOTS_SOURCE_SHA");
+ println!("cargo:rerun-if-env-changed=SOURCE_DATE_EPOCH");
let rustc = env::var("RUSTC").expect("missing required env var RUSTC");
- if let Ok(out) = Command::new(rustc).arg("--version").output()
- && out.status.success()
- && let Ok(ver) = String::from_utf8(out.stdout)
+ if let Ok(output) = Command::new(rustc).arg("--version").output()
+ && output.status.success()
+ && let Ok(version) = String::from_utf8(output.stdout)
{
- println!("cargo:rustc-env=RUSTC_VERSION={}", ver.trim());
+ println!("cargo:rustc-env=RUSTC_VERSION={}", version.trim());
}
- if let Ok(out) = Command::new("git")
- .args(["rev-parse", "--short=12", "HEAD"])
- .output()
- && out.status.success()
- {
- let mut sha = String::from_utf8_lossy(&out.stdout).trim().to_string();
- let dirty = Command::new("git")
- .args(["status", "--porcelain"])
- .output()
- .ok()
- .is_some_and(|output| output.status.success() && !output.stdout.is_empty());
- if dirty {
- sha.push_str("-dirty");
- }
- println!("cargo:rustc-env=GIT_HASH={sha}");
+ if let Some(source_sha) = optional_source_sha() {
+ println!("cargo:rustc-env=GIT_HASH={source_sha}");
}
let profile = env::var("PROFILE").expect("missing required env var PROFILE");
println!("cargo:rustc-env=PROFILE={profile}");
- let epoch = SystemTime::now()
- .duration_since(UNIX_EPOCH)
- .map(|d| d.as_secs())
- .expect("system time before unix epoch");
- println!("cargo:rustc-env=BUILD_TIME_UNIX={epoch}");
+ if let Some(epoch) = optional_source_date_epoch() {
+ println!("cargo:rustc-env=BUILD_TIME_UNIX={epoch}");
+ }
+}
+
+fn optional_source_sha() -> Option<String> {
+ let value = env::var("RADROOTS_SOURCE_SHA").ok()?;
+ assert!(
+ (7..=64).contains(&value.len()) && value.bytes().all(|byte| byte.is_ascii_hexdigit()),
+ "RADROOTS_SOURCE_SHA must contain 7 to 64 hexadecimal characters"
+ );
+ Some(value.to_ascii_lowercase())
+}
+
+fn optional_source_date_epoch() -> Option<u64> {
+ let value = env::var("SOURCE_DATE_EPOCH").ok()?;
+ Some(
+ value
+ .parse()
+ .expect("SOURCE_DATE_EPOCH must be an unsigned Unix timestamp"),
+ )
}
diff --git a/crates/mobile_ffi/Cargo.toml b/crates/mobile_ffi/Cargo.toml
@@ -6,7 +6,11 @@ edition.workspace = true
authors = ["Radroots Authors"]
rust-version.workspace = true
license.workspace = true
+repository.workspace = true
+homepage.workspace = true
+readme.workspace = true
publish = false
+include = ["src/**", "uniffi.toml", "Cargo.toml"]
[lib]
crate-type = ["staticlib", "cdylib"]
@@ -14,13 +18,6 @@ crate-type = ["staticlib", "cdylib"]
[lints.rust]
unexpected_cfgs = { level = "warn", check-cfg = ['cfg(coverage_nightly)'] }
-[[bin]]
-name = "uniffi-bindgen"
-path = "bin/uniffi-bindgen.rs"
-
-[build-dependencies]
-uniffi_build = { workspace = true }
-
[dependencies]
radroots_app_core = { workspace = true }
-uniffi = { workspace = true, features = ["cli"] }
+uniffi = { workspace = true }
diff --git a/crates/mobile_wasm/Cargo.toml b/crates/mobile_wasm/Cargo.toml
@@ -9,6 +9,8 @@ description = "WebAssembly bindings for Radroots web apps"
repository.workspace = true
homepage.workspace = true
readme.workspace = true
+publish = false
+include = ["src/**", "Cargo.toml"]
[lib]
crate-type = ["cdylib", "rlib"]