prototype-contracts.v1.toml (5382B)
1 schema = "radroots.prototype-contract-source-guard.v1" 2 mode = "report_only" 3 4 [scan] 5 roots = [ 6 ".cargo", 7 ".envrc", 8 ".gitignore", 9 "AGENTS.md", 10 "AGENT_INSTRUCTIONS.md", 11 "BUILD.md", 12 "CHANGELOG.md", 13 "CONTRIBUTING.md", 14 "Cargo.lock", 15 "Cargo.toml", 16 "README.md", 17 "build", 18 "crates", 19 "deny.toml", 20 "dto_bindgen.toml", 21 "flake.lock", 22 "flake.nix", 23 "fuzz", 24 "rust-toolchain-coverage.toml", 25 "rust-toolchain.toml", 26 "tools", 27 "treefmt.nix", 28 ] 29 path_roots = ["."] 30 path_excludes = [".direnv", ".git", ".treefmt-cache", "result", "target"] 31 extensions = [ 32 "capnp", 33 "csv", 34 "dot", 35 "json", 36 "lock", 37 "md", 38 "nix", 39 "rs", 40 "sha256", 41 "sh", 42 "sql", 43 "toml", 44 "ts", 45 "txt", 46 ] 47 extensionless_names = [ 48 ".envrc", 49 ".gitignore", 50 "LICENSE-APACHE", 51 "LICENSE-MIT", 52 "README", 53 ] 54 55 [limits] 56 max_scan_entries = 20000 57 max_inventory_bytes = 33554432 58 max_file_bytes = 8388608 59 max_matches = 4096 60 max_reported_findings = 200 61 max_reported_allowlisted = 200 62 63 [[pattern]] 64 id = "config-env" 65 needle = "config.env" 66 match_kind = "substring" 67 description = "prototype environment-file configuration selector" 68 69 [[pattern]] 70 id = "env-example" 71 needle = ".env.example" 72 match_kind = "substring" 73 description = "prototype service environment example" 74 match_path = true 75 76 [[pattern]] 77 id = "env-file-flag" 78 needle = "--env-file" 79 match_kind = "substring" 80 description = "prototype environment-file CLI flag" 81 82 [[pattern]] 83 id = "myc-paths-environment" 84 needle = "MYC_PATHS_" 85 match_kind = "substring" 86 description = "prototype Myc path environment contract" 87 88 [[pattern]] 89 id = "rhi-paths-environment" 90 needle = "RHI_PATHS_" 91 match_kind = "substring" 92 description = "prototype RHI path environment contract" 93 94 [[pattern]] 95 id = "trade-validation-receipt" 96 needle = "trade_validation_receipt" 97 match_kind = "substring" 98 description = "prototype trade validation receipt surface" 99 100 [[pattern]] 101 id = "json-file-state" 102 needle = "JsonFile" 103 match_kind = "substring" 104 description = "prototype JSON mutable-state backend" 105 106 [[pattern]] 107 id = "jsonl-file-state" 108 needle = "JsonlFile" 109 match_kind = "substring" 110 description = "prototype JSONL mutable-state backend" 111 112 [[pattern]] 113 id = "identity-auto-generation" 114 needle = "allow_generate_identity" 115 match_kind = "substring" 116 description = "prototype ordinary-run identity generation" 117 118 [[pattern]] 119 id = "identity-json-example" 120 needle = "identity.example.json" 121 match_kind = "substring" 122 description = "prototype plaintext identity example" 123 match_path = true 124 125 [[pattern]] 126 id = "rhi-worker-path" 127 needle = "workers/rhi" 128 match_kind = "substring" 129 description = "prototype RHI worker path" 130 match_path = true 131 132 [[pattern]] 133 id = "external-command-provider" 134 needle = "external_command" 135 match_kind = "substring" 136 description = "prototype executable signer-provider selector" 137 138 [[pattern]] 139 id = "logging-output-directory" 140 needle = "logging.output_dir" 141 match_kind = "substring" 142 description = "prototype daemon-owned log-directory selector" 143 144 [[pattern]] 145 id = "never-rolling-appender" 146 needle = "rolling::never" 147 match_kind = "substring" 148 description = "prototype service-owned non-rolling file logger" 149 150 [[pattern]] 151 id = "daily-rolling-appender" 152 needle = "rolling::daily" 153 match_kind = "substring" 154 description = "prototype service-owned daily file logger" 155 156 [[pattern]] 157 id = "import-json-flag" 158 needle = "import-json" 159 match_kind = "substring" 160 description = "prototype mutable-state import CLI surface" 161 162 [[pattern]] 163 id = "import-json-identifier" 164 needle = "import_json" 165 match_kind = "substring" 166 description = "prototype mutable-state import implementation surface" 167 168 [[pattern]] 169 id = "legacy-concept" 170 needle = "legacy" 171 match_kind = "word_prefix" 172 description = "legacy product or compatibility concept requiring review" 173 path_prefixes = [ 174 "crates/runtime_paths", 175 "crates/secrets", 176 "crates/service_host", 177 "crates/service_sqlite", 178 ] 179 180 [[pattern]] 181 id = "compatibility-concept" 182 needle = "compat" 183 match_kind = "word_prefix" 184 description = "compatibility product concept requiring review" 185 path_prefixes = [ 186 "crates/runtime_paths", 187 "crates/secrets", 188 "crates/service_host", 189 "crates/service_sqlite", 190 ] 191 192 [[pattern]] 193 id = "deprecated-concept" 194 needle = "deprecated" 195 match_kind = "word_prefix" 196 description = "deprecated product concept requiring review" 197 path_prefixes = [ 198 "crates/runtime_paths", 199 "crates/secrets", 200 "crates/service_host", 201 "crates/service_sqlite", 202 ] 203 204 [[allow]] 205 pattern_id = "import-json-identifier" 206 path = "crates/replica_store_wasm/src/wasm_impl.rs" 207 line_contains = "#[wasm_bindgen(js_name = replica_store_import_json)]" 208 reason = "The replica-store interchange API is not a Myc or RHI mutable service-state importer." 209 210 [[allow]] 211 pattern_id = "import-json-identifier" 212 path = "crates/replica_store_wasm/src/wasm_impl.rs" 213 line_contains = "pub fn replica_store_import_json" 214 reason = "The replica-store interchange API is not a Myc or RHI mutable service-state importer." 215 216 [[allow]] 217 pattern_id = "import-json-identifier" 218 path = "tools/xtask/src/sdk_generation/wasm_declarations.rs" 219 line_contains = "replica_store_import_json" 220 reason = "The generated replica-store interchange declaration is not a Myc or RHI mutable service-state importer." 221 222 [[allow]] 223 pattern_id = "compatibility-concept" 224 path = "crates/secrets/src/wrapping.rs" 225 line_contains = "dyn-compatible data-key wrapping" 226 reason = "This describes Rust trait object safety rather than a Radroots-owned compatibility path."