lib

Core libraries for Radroots
git clone https://radroots.dev/git/lib.git
Log | Files | Refs | README

prototype-contracts.v1.toml (5382B)


      1 schema = "radroots.prototype-contract-source-guard.v1"
      2 mode = "report_only"
      3 
      4 [scan]
      5 roots = [
      6   ".cargo",
      7   ".envrc",
      8   ".gitignore",
      9   "AGENTS.md",
     10   "AGENT_INSTRUCTIONS.md",
     11   "BUILD.md",
     12   "CHANGELOG.md",
     13   "CONTRIBUTING.md",
     14   "Cargo.lock",
     15   "Cargo.toml",
     16   "README.md",
     17   "build",
     18   "crates",
     19   "deny.toml",
     20   "dto_bindgen.toml",
     21   "flake.lock",
     22   "flake.nix",
     23   "fuzz",
     24   "rust-toolchain-coverage.toml",
     25   "rust-toolchain.toml",
     26   "tools",
     27   "treefmt.nix",
     28 ]
     29 path_roots = ["."]
     30 path_excludes = [".direnv", ".git", ".treefmt-cache", "result", "target"]
     31 extensions = [
     32   "capnp",
     33   "csv",
     34   "dot",
     35   "json",
     36   "lock",
     37   "md",
     38   "nix",
     39   "rs",
     40   "sha256",
     41   "sh",
     42   "sql",
     43   "toml",
     44   "ts",
     45   "txt",
     46 ]
     47 extensionless_names = [
     48   ".envrc",
     49   ".gitignore",
     50   "LICENSE-APACHE",
     51   "LICENSE-MIT",
     52   "README",
     53 ]
     54 
     55 [limits]
     56 max_scan_entries = 20000
     57 max_inventory_bytes = 33554432
     58 max_file_bytes = 8388608
     59 max_matches = 4096
     60 max_reported_findings = 200
     61 max_reported_allowlisted = 200
     62 
     63 [[pattern]]
     64 id = "config-env"
     65 needle = "config.env"
     66 match_kind = "substring"
     67 description = "prototype environment-file configuration selector"
     68 
     69 [[pattern]]
     70 id = "env-example"
     71 needle = ".env.example"
     72 match_kind = "substring"
     73 description = "prototype service environment example"
     74 match_path = true
     75 
     76 [[pattern]]
     77 id = "env-file-flag"
     78 needle = "--env-file"
     79 match_kind = "substring"
     80 description = "prototype environment-file CLI flag"
     81 
     82 [[pattern]]
     83 id = "myc-paths-environment"
     84 needle = "MYC_PATHS_"
     85 match_kind = "substring"
     86 description = "prototype Myc path environment contract"
     87 
     88 [[pattern]]
     89 id = "rhi-paths-environment"
     90 needle = "RHI_PATHS_"
     91 match_kind = "substring"
     92 description = "prototype RHI path environment contract"
     93 
     94 [[pattern]]
     95 id = "trade-validation-receipt"
     96 needle = "trade_validation_receipt"
     97 match_kind = "substring"
     98 description = "prototype trade validation receipt surface"
     99 
    100 [[pattern]]
    101 id = "json-file-state"
    102 needle = "JsonFile"
    103 match_kind = "substring"
    104 description = "prototype JSON mutable-state backend"
    105 
    106 [[pattern]]
    107 id = "jsonl-file-state"
    108 needle = "JsonlFile"
    109 match_kind = "substring"
    110 description = "prototype JSONL mutable-state backend"
    111 
    112 [[pattern]]
    113 id = "identity-auto-generation"
    114 needle = "allow_generate_identity"
    115 match_kind = "substring"
    116 description = "prototype ordinary-run identity generation"
    117 
    118 [[pattern]]
    119 id = "identity-json-example"
    120 needle = "identity.example.json"
    121 match_kind = "substring"
    122 description = "prototype plaintext identity example"
    123 match_path = true
    124 
    125 [[pattern]]
    126 id = "rhi-worker-path"
    127 needle = "workers/rhi"
    128 match_kind = "substring"
    129 description = "prototype RHI worker path"
    130 match_path = true
    131 
    132 [[pattern]]
    133 id = "external-command-provider"
    134 needle = "external_command"
    135 match_kind = "substring"
    136 description = "prototype executable signer-provider selector"
    137 
    138 [[pattern]]
    139 id = "logging-output-directory"
    140 needle = "logging.output_dir"
    141 match_kind = "substring"
    142 description = "prototype daemon-owned log-directory selector"
    143 
    144 [[pattern]]
    145 id = "never-rolling-appender"
    146 needle = "rolling::never"
    147 match_kind = "substring"
    148 description = "prototype service-owned non-rolling file logger"
    149 
    150 [[pattern]]
    151 id = "daily-rolling-appender"
    152 needle = "rolling::daily"
    153 match_kind = "substring"
    154 description = "prototype service-owned daily file logger"
    155 
    156 [[pattern]]
    157 id = "import-json-flag"
    158 needle = "import-json"
    159 match_kind = "substring"
    160 description = "prototype mutable-state import CLI surface"
    161 
    162 [[pattern]]
    163 id = "import-json-identifier"
    164 needle = "import_json"
    165 match_kind = "substring"
    166 description = "prototype mutable-state import implementation surface"
    167 
    168 [[pattern]]
    169 id = "legacy-concept"
    170 needle = "legacy"
    171 match_kind = "word_prefix"
    172 description = "legacy product or compatibility concept requiring review"
    173 path_prefixes = [
    174   "crates/runtime_paths",
    175   "crates/secrets",
    176   "crates/service_host",
    177   "crates/service_sqlite",
    178 ]
    179 
    180 [[pattern]]
    181 id = "compatibility-concept"
    182 needle = "compat"
    183 match_kind = "word_prefix"
    184 description = "compatibility product concept requiring review"
    185 path_prefixes = [
    186   "crates/runtime_paths",
    187   "crates/secrets",
    188   "crates/service_host",
    189   "crates/service_sqlite",
    190 ]
    191 
    192 [[pattern]]
    193 id = "deprecated-concept"
    194 needle = "deprecated"
    195 match_kind = "word_prefix"
    196 description = "deprecated product concept requiring review"
    197 path_prefixes = [
    198   "crates/runtime_paths",
    199   "crates/secrets",
    200   "crates/service_host",
    201   "crates/service_sqlite",
    202 ]
    203 
    204 [[allow]]
    205 pattern_id = "import-json-identifier"
    206 path = "crates/replica_store_wasm/src/wasm_impl.rs"
    207 line_contains = "#[wasm_bindgen(js_name = replica_store_import_json)]"
    208 reason = "The replica-store interchange API is not a Myc or RHI mutable service-state importer."
    209 
    210 [[allow]]
    211 pattern_id = "import-json-identifier"
    212 path = "crates/replica_store_wasm/src/wasm_impl.rs"
    213 line_contains = "pub fn replica_store_import_json"
    214 reason = "The replica-store interchange API is not a Myc or RHI mutable service-state importer."
    215 
    216 [[allow]]
    217 pattern_id = "import-json-identifier"
    218 path = "tools/xtask/src/sdk_generation/wasm_declarations.rs"
    219 line_contains = "replica_store_import_json"
    220 reason = "The generated replica-store interchange declaration is not a Myc or RHI mutable service-state importer."
    221 
    222 [[allow]]
    223 pattern_id = "compatibility-concept"
    224 path = "crates/secrets/src/wrapping.rs"
    225 line_contains = "dyn-compatible data-key wrapping"
    226 reason = "This describes Rust trait object safety rather than a Radroots-owned compatibility path."