myc

Self-custodial remote signer for Radroots apps
git clone https://radroots.dev/git/myc.git
Log | Files | Refs | README | LICENSE

commit 6496dd631e732f61b3d35fc925b93e601022008b
parent 5dbaeb68f220158b7f74c8114378640e3d6b88de
Author: triesap <tyson@radroots.org>
Date:   Tue, 25 Aug 2026 08:15:47 +0000

security: enforce standalone boundary gates

- compare the root-only public API with the reviewed baseline
- reject forbidden roots and tracked credential material
- include the boundary gate in release acceptance
- document the standalone extbuild verification command

Diffstat:
MAGENTS.md | 1+
MREADME | 1+
Mscripts/release-acceptance.sh | 1+
Ascripts/verify-boundaries.sh | 27+++++++++++++++++++++++++++
4 files changed, 30 insertions(+), 0 deletions(-)

diff --git a/AGENTS.md b/AGENTS.md @@ -366,6 +366,7 @@ cargo extbuild run -- cargo fmt --all --check cargo extbuild run -- cargo check --workspace --locked cargo extbuild run -- cargo test --workspace --all-targets --locked cargo extbuild run -- cargo clippy --workspace --all-targets --locked -- -D warnings +cargo extbuild run -- ./scripts/verify-boundaries.sh cargo extbuild run -- ./scripts/verify-supply-chain.sh cargo extbuild run -- ./scripts/release-acceptance.sh ``` diff --git a/README b/README @@ -549,6 +549,7 @@ crate through extbuild: ```text cargo extbuild doctor +cargo extbuild run -- ./scripts/verify-boundaries.sh cargo extbuild run -- ./scripts/verify-supply-chain.sh cargo extbuild run -- ./scripts/release-acceptance.sh ``` diff --git a/scripts/release-acceptance.sh b/scripts/release-acceptance.sh @@ -13,4 +13,5 @@ cargo clippy --locked --all-targets -- -D warnings cargo test --locked cargo test --locked -p myc_xtask scripts/verify-supply-chain.sh +scripts/verify-boundaries.sh git diff --check diff --git a/scripts/verify-boundaries.sh b/scripts/verify-boundaries.sh @@ -0,0 +1,27 @@ +#!/usr/bin/env bash +set -euo pipefail + +repo_root="$(git rev-parse --show-toplevel)" +cd "$repo_root" + +test "$(cargo public-api --version)" = "cargo-public-api 0.52.0" +temporary_api="$(mktemp)" +trap 'rm -f "$temporary_api"' EXIT +cargo +nightly-2026-07-16 public-api --all-features -sss -p myc >"$temporary_api" +cmp "$temporary_api" contracts/api_baselines/myc.txt + +for forbidden_root in docs .github .act; do + test ! -e "$forbidden_root" + test ! -L "$forbidden_root" +done + +if git ls-files | grep -E -i '(^|/)(\.env|id_rsa|id_ed25519|credentials|[^/]+\.(pem|key|p12|pfx|jks|keystore))$' >/dev/null; then + echo "boundary_invalid: sensitive credential path is tracked" >&2 + exit 1 +fi +if git grep -I -n -E -e '-----BEGIN ([A-Z0-9 ]+ )?PRIVATE KEY-----|AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{36,}|nsec1[023456789acdefghjklmnpqrstuvwxyz]{40,}' -- src >/dev/null; then + echo "boundary_invalid: production source contains credential material" >&2 + exit 1 +fi + +echo "boundary ok: root-only API, fresh baseline, no forbidden or credential surface"