commit 89999473c8954da577704a9838b0047db5e29bd4
parent cbd72bcc435094cc38401dd6cb99161bb600aaa3
Author: triesap <tyson@radroots.org>
Date: Fri, 21 Aug 2026 22:57:17 +0000
build: adopt final Myc service source lock
Replace the temporary consumer lock with the canonical service-source-lock schema generated from the exact promoted Lib archive and verified Cargo/flake source data.
Diffstat:
5 files changed, 34 insertions(+), 12 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md
@@ -28,7 +28,7 @@
## 2. Authority and preflight
- Before editing, read this file, `README`, `Cargo.toml`,
- `radroots.lib.source-lock.v1.toml`, the relevant implementation and tests,
+ `radroots.service.source-lock.v1.toml`, the relevant implementation and tests,
and `flake.nix` or migrations when they are in scope.
- `.radroots-consumer-root` is the standalone source-lock identity and must
remain exactly `myc`. The reserved pre-implementation control-plane
diff --git a/radroots.lib.source-lock.v1.toml b/radroots.lib.source-lock.v1.toml
@@ -1,9 +0,0 @@
-schema = "radroots.lib.source-lock.v1"
-repository = "https://github.com/radrootslabs/lib"
-revision = "b44119fbac5985be8127ad1bf56d2950e6399427"
-architecture = "radroots.crates.release.v2"
-workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4"
-version = "0.1.0-alpha"
-source_archive_sha256 = "975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379"
-lockfile = "Cargo.lock"
-lockfile_sha256 = "04f566ee4c444c81002f090ac77e61b77000e8aeb1a337ae38447e2f0913a3b9"
diff --git a/radroots.service.source-lock.v1.toml b/radroots.service.source-lock.v1.toml
@@ -0,0 +1,20 @@
+schema = "radroots.service.source-lock.v1"
+contract_version = 1
+service = "myc"
+repository = "https://github.com/radrootslabs/lib"
+revision = "b44119fbac5985be8127ad1bf56d2950e6399427"
+architecture = "radroots.crates.release.v2"
+workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4"
+version = "0.1.0-alpha"
+source_archive_sha256 = "975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379"
+cargo_lock_sha256 = "04f566ee4c444c81002f090ac77e61b77000e8aeb1a337ae38447e2f0913a3b9"
+flake_lock_sha256 = "90a03f6f0794f3f6556b1f2bf6700812d48ce8dc1cee7c4f8bc62cea69b42bd1"
+rust_version = "1.97.1"
+host_feature_profile = "service-host"
+
+[contract_versions]
+config = 1
+state = 7
+admin = 1
+status = 1
+provider = 1
diff --git a/tests/build_policy.rs b/tests/build_policy.rs
@@ -4,7 +4,8 @@ use sha2::{Digest, Sha256};
const MANIFEST: &str = include_str!("../Cargo.toml");
const RELEASE_ACCEPTANCE: &str = include_str!("../scripts/release-acceptance.sh");
-const SOURCE_LOCK: &str = include_str!("../radroots.lib.source-lock.v1.toml");
+const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v1.toml");
+const FLAKE_LOCK: &[u8] = include_bytes!("../flake.lock");
#[test]
fn manifest_freezes_the_final_rust_policy() {
@@ -68,7 +69,12 @@ fn release_acceptance_checks_both_feature_profiles() {
#[test]
fn source_lock_binds_the_current_cargo_lock() {
let digest = hex::encode(Sha256::digest(include_bytes!("../Cargo.lock")));
- assert!(SOURCE_LOCK.contains(&format!("lockfile_sha256 = \"{digest}\"")));
+ let flake_digest = hex::encode(Sha256::digest(FLAKE_LOCK));
+ assert!(SOURCE_LOCK.starts_with(
+ "schema = \"radroots.service.source-lock.v1\"\ncontract_version = 1\nservice = \"myc\"\n"
+ ));
+ assert!(SOURCE_LOCK.contains(&format!("cargo_lock_sha256 = \"{digest}\"")));
+ assert!(SOURCE_LOCK.contains(&format!("flake_lock_sha256 = \"{flake_digest}\"")));
assert!(SOURCE_LOCK.contains("revision = \"b44119fbac5985be8127ad1bf56d2950e6399427\""));
assert!(SOURCE_LOCK.contains(
"workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\""
@@ -76,4 +82,7 @@ fn source_lock_binds_the_current_cargo_lock() {
assert!(SOURCE_LOCK.contains(
"source_archive_sha256 = \"975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379\""
));
+ assert!(SOURCE_LOCK.ends_with(
+ "[contract_versions]\nconfig = 1\nstate = 7\nadmin = 1\nstatus = 1\nprovider = 1\n"
+ ));
}
diff --git a/tests/services_hardening_native_release.rs b/tests/services_hardening_native_release.rs
@@ -223,6 +223,8 @@ fn every_radroots_dependency_is_exactly_source_locked() {
#[test]
fn removed_and_deferred_release_surfaces_cannot_be_smuggled_into_step_139() {
let root = std::path::Path::new(env!("CARGO_MANIFEST_DIR"));
+ assert!(!root.join("radroots.lib.source-lock.v1.toml").exists());
+ assert!(root.join("radroots.service.source-lock.v1.toml").is_file());
for forbidden in [
".github",
"target",