commit 6496dd631e732f61b3d35fc925b93e601022008b
parent 5dbaeb68f220158b7f74c8114378640e3d6b88de
Author: triesap <tyson@radroots.org>
Date: Tue, 25 Aug 2026 08:15:47 +0000
security: enforce standalone boundary gates
- compare the root-only public API with the reviewed baseline
- reject forbidden roots and tracked credential material
- include the boundary gate in release acceptance
- document the standalone extbuild verification command
Diffstat:
4 files changed, 30 insertions(+), 0 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md
@@ -366,6 +366,7 @@ cargo extbuild run -- cargo fmt --all --check
cargo extbuild run -- cargo check --workspace --locked
cargo extbuild run -- cargo test --workspace --all-targets --locked
cargo extbuild run -- cargo clippy --workspace --all-targets --locked -- -D warnings
+cargo extbuild run -- ./scripts/verify-boundaries.sh
cargo extbuild run -- ./scripts/verify-supply-chain.sh
cargo extbuild run -- ./scripts/release-acceptance.sh
```
diff --git a/README b/README
@@ -549,6 +549,7 @@ crate through extbuild:
```text
cargo extbuild doctor
+cargo extbuild run -- ./scripts/verify-boundaries.sh
cargo extbuild run -- ./scripts/verify-supply-chain.sh
cargo extbuild run -- ./scripts/release-acceptance.sh
```
diff --git a/scripts/release-acceptance.sh b/scripts/release-acceptance.sh
@@ -13,4 +13,5 @@ cargo clippy --locked --all-targets -- -D warnings
cargo test --locked
cargo test --locked -p myc_xtask
scripts/verify-supply-chain.sh
+scripts/verify-boundaries.sh
git diff --check
diff --git a/scripts/verify-boundaries.sh b/scripts/verify-boundaries.sh
@@ -0,0 +1,27 @@
+#!/usr/bin/env bash
+set -euo pipefail
+
+repo_root="$(git rev-parse --show-toplevel)"
+cd "$repo_root"
+
+test "$(cargo public-api --version)" = "cargo-public-api 0.52.0"
+temporary_api="$(mktemp)"
+trap 'rm -f "$temporary_api"' EXIT
+cargo +nightly-2026-07-16 public-api --all-features -sss -p myc >"$temporary_api"
+cmp "$temporary_api" contracts/api_baselines/myc.txt
+
+for forbidden_root in docs .github .act; do
+ test ! -e "$forbidden_root"
+ test ! -L "$forbidden_root"
+done
+
+if git ls-files | grep -E -i '(^|/)(\.env|id_rsa|id_ed25519|credentials|[^/]+\.(pem|key|p12|pfx|jks|keystore))$' >/dev/null; then
+ echo "boundary_invalid: sensitive credential path is tracked" >&2
+ exit 1
+fi
+if git grep -I -n -E -e '-----BEGIN ([A-Z0-9 ]+ )?PRIVATE KEY-----|AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{36,}|nsec1[023456789acdefghjklmnpqrstuvwxyz]{40,}' -- src >/dev/null; then
+ echo "boundary_invalid: production source contains credential material" >&2
+ exit 1
+fi
+
+echo "boundary ok: root-only API, fresh baseline, no forbidden or credential surface"