myc

Self-custodial remote signer for Radroots apps
git clone https://radroots.dev/git/myc.git
Log | Files | Refs | README | LICENSE

commit 89999473c8954da577704a9838b0047db5e29bd4
parent cbd72bcc435094cc38401dd6cb99161bb600aaa3
Author: triesap <tyson@radroots.org>
Date:   Fri, 21 Aug 2026 22:57:17 +0000

build: adopt final Myc service source lock

Replace the temporary consumer lock with the canonical service-source-lock schema generated from the exact promoted Lib archive and verified Cargo/flake source data.

Diffstat:
MAGENTS.md | 2+-
Dradroots.lib.source-lock.v1.toml | 9---------
Aradroots.service.source-lock.v1.toml | 20++++++++++++++++++++
Mtests/build_policy.rs | 13+++++++++++--
Mtests/services_hardening_native_release.rs | 2++
5 files changed, 34 insertions(+), 12 deletions(-)

diff --git a/AGENTS.md b/AGENTS.md @@ -28,7 +28,7 @@ ## 2. Authority and preflight - Before editing, read this file, `README`, `Cargo.toml`, - `radroots.lib.source-lock.v1.toml`, the relevant implementation and tests, + `radroots.service.source-lock.v1.toml`, the relevant implementation and tests, and `flake.nix` or migrations when they are in scope. - `.radroots-consumer-root` is the standalone source-lock identity and must remain exactly `myc`. The reserved pre-implementation control-plane diff --git a/radroots.lib.source-lock.v1.toml b/radroots.lib.source-lock.v1.toml @@ -1,9 +0,0 @@ -schema = "radroots.lib.source-lock.v1" -repository = "https://github.com/radrootslabs/lib" -revision = "b44119fbac5985be8127ad1bf56d2950e6399427" -architecture = "radroots.crates.release.v2" -workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4" -version = "0.1.0-alpha" -source_archive_sha256 = "975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379" -lockfile = "Cargo.lock" -lockfile_sha256 = "04f566ee4c444c81002f090ac77e61b77000e8aeb1a337ae38447e2f0913a3b9" diff --git a/radroots.service.source-lock.v1.toml b/radroots.service.source-lock.v1.toml @@ -0,0 +1,20 @@ +schema = "radroots.service.source-lock.v1" +contract_version = 1 +service = "myc" +repository = "https://github.com/radrootslabs/lib" +revision = "b44119fbac5985be8127ad1bf56d2950e6399427" +architecture = "radroots.crates.release.v2" +workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4" +version = "0.1.0-alpha" +source_archive_sha256 = "975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379" +cargo_lock_sha256 = "04f566ee4c444c81002f090ac77e61b77000e8aeb1a337ae38447e2f0913a3b9" +flake_lock_sha256 = "90a03f6f0794f3f6556b1f2bf6700812d48ce8dc1cee7c4f8bc62cea69b42bd1" +rust_version = "1.97.1" +host_feature_profile = "service-host" + +[contract_versions] +config = 1 +state = 7 +admin = 1 +status = 1 +provider = 1 diff --git a/tests/build_policy.rs b/tests/build_policy.rs @@ -4,7 +4,8 @@ use sha2::{Digest, Sha256}; const MANIFEST: &str = include_str!("../Cargo.toml"); const RELEASE_ACCEPTANCE: &str = include_str!("../scripts/release-acceptance.sh"); -const SOURCE_LOCK: &str = include_str!("../radroots.lib.source-lock.v1.toml"); +const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v1.toml"); +const FLAKE_LOCK: &[u8] = include_bytes!("../flake.lock"); #[test] fn manifest_freezes_the_final_rust_policy() { @@ -68,7 +69,12 @@ fn release_acceptance_checks_both_feature_profiles() { #[test] fn source_lock_binds_the_current_cargo_lock() { let digest = hex::encode(Sha256::digest(include_bytes!("../Cargo.lock"))); - assert!(SOURCE_LOCK.contains(&format!("lockfile_sha256 = \"{digest}\""))); + let flake_digest = hex::encode(Sha256::digest(FLAKE_LOCK)); + assert!(SOURCE_LOCK.starts_with( + "schema = \"radroots.service.source-lock.v1\"\ncontract_version = 1\nservice = \"myc\"\n" + )); + assert!(SOURCE_LOCK.contains(&format!("cargo_lock_sha256 = \"{digest}\""))); + assert!(SOURCE_LOCK.contains(&format!("flake_lock_sha256 = \"{flake_digest}\""))); assert!(SOURCE_LOCK.contains("revision = \"b44119fbac5985be8127ad1bf56d2950e6399427\"")); assert!(SOURCE_LOCK.contains( "workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\"" @@ -76,4 +82,7 @@ fn source_lock_binds_the_current_cargo_lock() { assert!(SOURCE_LOCK.contains( "source_archive_sha256 = \"975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379\"" )); + assert!(SOURCE_LOCK.ends_with( + "[contract_versions]\nconfig = 1\nstate = 7\nadmin = 1\nstatus = 1\nprovider = 1\n" + )); } diff --git a/tests/services_hardening_native_release.rs b/tests/services_hardening_native_release.rs @@ -223,6 +223,8 @@ fn every_radroots_dependency_is_exactly_source_locked() { #[test] fn removed_and_deferred_release_surfaces_cannot_be_smuggled_into_step_139() { let root = std::path::Path::new(env!("CARGO_MANIFEST_DIR")); + assert!(!root.join("radroots.lib.source-lock.v1.toml").exists()); + assert!(root.join("radroots.service.source-lock.v1.toml").is_file()); for forbidden in [ ".github", "target",