lib

Core libraries for Radroots
git clone https://radroots.dev/git/lib.git
Log | Files | Refs | README

services_hardening_source_lock.v3.json (6075B)


      1 {
      2   "$schema": "https://json-schema.org/draft/2020-12/schema",
      3   "$id": "radroots.services-hardening.rshr-200-service-source-lock.v3",
      4   "type": "object",
      5   "additionalProperties": false,
      6   "required": [
      7     "schema",
      8     "contract_version",
      9     "service",
     10     "repository",
     11     "revision",
     12     "architecture",
     13     "workspace_catalog_sha256",
     14     "version",
     15     "source_archive_sha256",
     16     "source_archive_contract",
     17     "cargo_lock_sha256",
     18     "rust_version",
     19     "host_feature_profile",
     20     "nix",
     21     "artifact_contract",
     22     "sqlite",
     23     "contract_versions"
     24   ],
     25   "properties": {
     26     "schema": {
     27       "const": "radroots.service.source-lock.v3"
     28     },
     29     "contract_version": {
     30       "const": 3
     31     },
     32     "service": {
     33       "enum": [
     34         "myc",
     35         "rhi"
     36       ]
     37     },
     38     "repository": {
     39       "const": "https://github.com/radrootslabs/lib"
     40     },
     41     "revision": {
     42       "$ref": "#/$defs/oid"
     43     },
     44     "architecture": {
     45       "const": "radroots.crates.release.v2"
     46     },
     47     "workspace_catalog_sha256": {
     48       "$ref": "#/$defs/sha256"
     49     },
     50     "version": {
     51       "const": "0.1.0-alpha"
     52     },
     53     "source_archive_sha256": {
     54       "$ref": "#/$defs/sha256"
     55     },
     56     "source_archive_contract": {
     57       "const": {
     58         "binding": "sha256_of_canonical_exact_lib_revision_tree_archive",
     59         "format": "ustar",
     60         "compression": "none",
     61         "compression_timestamp": "not_applicable",
     62         "entry_order": "bytewise_git_path",
     63         "path_prefix": "none",
     64         "file_mode": "git_index_100644_or_100755",
     65         "uid": 0,
     66         "gid": 0,
     67         "uname": "",
     68         "gname": "",
     69         "mtime": "lib_revision_commit_timestamp",
     70         "pax_headers": "forbidden",
     71         "directory_entries": "omitted",
     72         "symlinks": "forbidden",
     73         "hardlinks": "forbidden",
     74         "submodules": "forbidden",
     75         "trailer": "two_zero_blocks"
     76       }
     77     },
     78     "cargo_lock_sha256": {
     79       "$ref": "#/$defs/sha256"
     80     },
     81     "rust_version": {
     82       "const": "1.97.1"
     83     },
     84     "host_feature_profile": {
     85       "const": "service-host"
     86     },
     87     "nix": {
     88       "type": "object",
     89       "additionalProperties": false,
     90       "required": [
     91         "material",
     92         "lib_revision",
     93         "public_input_lock",
     94         "parent_result",
     95         "supported_systems"
     96       ],
     97       "properties": {
     98         "material": {
     99           "const": "qualified"
    100         },
    101         "lib_revision": {
    102           "$ref": "#/$defs/oid"
    103         },
    104         "public_input_lock": {
    105           "type": "object",
    106           "additionalProperties": false,
    107           "required": [
    108             "path",
    109             "sha256",
    110             "binding",
    111             "mutable_reference",
    112             "lib_input"
    113           ],
    114           "properties": {
    115             "path": {
    116               "const": "flake.lock"
    117             },
    118             "sha256": {
    119               "$ref": "#/$defs/sha256"
    120             },
    121             "binding": {
    122               "const": "exact_regular_file_bytes"
    123             },
    124             "mutable_reference": {
    125               "const": "forbidden"
    126             },
    127             "lib_input": {
    128               "const": "lib"
    129             }
    130           }
    131         },
    132         "parent_result": {
    133           "const": {
    134             "embedded_in_public_input_lock": false,
    135             "embedded_in_source_lock": false,
    136             "storage": "separate_generation_scoped_evidence"
    137           }
    138         },
    139         "supported_systems": {
    140           "const": [
    141             "aarch64-darwin",
    142             "x86_64-linux"
    143           ]
    144         }
    145       }
    146     },
    147     "artifact_contract": {
    148       "type": "object",
    149       "additionalProperties": false,
    150       "required": [
    151         "path",
    152         "sha256",
    153         "binding"
    154       ],
    155       "properties": {
    156         "path": {
    157           "enum": [
    158             "contracts/release/myc-artifact-contract.v3.json",
    159             "contracts/release/rhi-artifact-contract.v3.json"
    160           ]
    161         },
    162         "sha256": {
    163           "$ref": "#/$defs/sha256"
    164         },
    165         "binding": {
    166           "const": "exact_regular_file_bytes_in_same_source_revision"
    167         }
    168       }
    169     },
    170     "sqlite": {
    171       "const": {
    172         "high_level_authority": "sqlx_only",
    173         "second_pool_connection_query_transaction_migration_authority": "forbidden",
    174         "incremental_backup_adapter": "sealed_native_sqlx_owned_locked_handle_only",
    175         "native_linkage_count": 1
    176       }
    177     },
    178     "contract_versions": {
    179       "type": "object",
    180       "additionalProperties": false,
    181       "required": [
    182         "config",
    183         "state",
    184         "admin",
    185         "status",
    186         "provider"
    187       ],
    188       "properties": {
    189         "config": {
    190           "$ref": "#/$defs/nonzero_u32"
    191         },
    192         "state": {
    193           "$ref": "#/$defs/nonzero_u32"
    194         },
    195         "admin": {
    196           "$ref": "#/$defs/nonzero_u32"
    197         },
    198         "status": {
    199           "$ref": "#/$defs/nonzero_u32"
    200         },
    201         "provider": {
    202           "$ref": "#/$defs/nonzero_u32"
    203         }
    204       }
    205     }
    206   },
    207   "allOf": [
    208     {
    209       "if": {
    210         "properties": { "service": { "const": "myc" } },
    211         "required": ["service"]
    212       },
    213       "then": {
    214         "properties": {
    215           "artifact_contract": {
    216             "properties": {
    217               "path": {
    218                 "const": "contracts/release/myc-artifact-contract.v3.json"
    219               }
    220             }
    221           }
    222         }
    223       }
    224     },
    225     {
    226       "if": {
    227         "properties": { "service": { "const": "rhi" } },
    228         "required": ["service"]
    229       },
    230       "then": {
    231         "properties": {
    232           "artifact_contract": {
    233             "properties": {
    234               "path": {
    235                 "const": "contracts/release/rhi-artifact-contract.v3.json"
    236               }
    237             }
    238           }
    239         }
    240       }
    241     }
    242   ],
    243   "$defs": {
    244     "oid": {
    245       "type": "string",
    246       "pattern": "^[0-9a-f]{40}$"
    247     },
    248     "sha256": {
    249       "type": "string",
    250       "pattern": "^[0-9a-f]{64}$"
    251     },
    252     "nonzero_u32": {
    253       "type": "integer",
    254       "minimum": 1,
    255       "maximum": 4294967295
    256     }
    257   }
    258 }