commit c0771042391d582f8318fcc44078376ef609d3e9 parent 294ee8941f3eab74488f1c7c8144f4e5bfa28a50 Author: triesap <tyson@radroots.org> Date: Sun, 23 Aug 2026 08:19:37 +0000 build: adopt source-lock v2 Lib pin - advance every active native Lib dependency to the promoted revision - replace source-lock v1 with the canonical deferred-Nix v2 document - preserve the independently bound older flake selection without qualification - update release policy, fixtures, and build identity evidence coherently Diffstat:
21 files changed, 98 insertions(+), 79 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md @@ -28,7 +28,7 @@ ## 2. Authority and preflight - Before editing, read this file, `README`, `Cargo.toml`, - `radroots.service.source-lock.v1.toml`, the relevant implementation and tests, + `radroots.service.source-lock.v2.toml`, the relevant implementation and tests, and `flake.nix` or migrations when they are in scope. - `.radroots-consumer-root` is the standalone source-lock identity and must remain exactly `myc`. The implemented control-plane contract is @@ -89,11 +89,13 @@ every intentional public-surface change. Shared runtime-path, SQLite, and storage identity types are deliberate governed contract dependencies; provider, SQLx, Serde, transport, and task implementation types are not. -- Step 139 owns the final service source-lock schema and the pre-promotion +- Step 139 established the predecessor service source lock and pre-promotion native package metadata. Keep the exact Lib revision consistent across every - direct Radroots dependency, Cargo.lock, flake.lock source data, the verified - source archive, and the generated service lock. Native target metadata does - not qualify an artifact; Nix, OCI, signing, tags, publication, and deployment + direct Radroots dependency, Cargo.lock, the verified source archive, and the + generated v2 service lock. Deferred `flake.nix` and `flake.lock` material is + independently digest-bound and may select an older reachable Lib revision; + it is not active native revision authority. Native target metadata does not + qualify an artifact; Nix, OCI, signing, tags, publication, and deployment remain deferred. - Step 148 closes the production NIP-46 response authority in `contracts/services_hardening/nip46_response_commit.v1.json`. Production diff --git a/Cargo.lock b/Cargo.lock @@ -1572,7 +1572,7 @@ checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" [[package]] name = "radroots_blossom" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "mediatype", "serde", @@ -1584,7 +1584,7 @@ dependencies = [ [[package]] name = "radroots_core" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "rust_decimal", "serde", @@ -1593,7 +1593,7 @@ dependencies = [ [[package]] name = "radroots_event" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "hex", "jiff-tzdb", @@ -1611,7 +1611,7 @@ dependencies = [ [[package]] name = "radroots_event_codec" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "hex", "radroots_blossom", @@ -1628,7 +1628,7 @@ dependencies = [ [[package]] name = "radroots_identity" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "k256", "serde", @@ -1638,7 +1638,7 @@ dependencies = [ [[package]] name = "radroots_nostr" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "nostr", "radroots_event", @@ -1652,7 +1652,7 @@ dependencies = [ [[package]] name = "radroots_nostr_connect" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "nostr", "radroots_event", @@ -1668,7 +1668,7 @@ dependencies = [ [[package]] name = "radroots_protocol" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "serde", ] @@ -1676,7 +1676,7 @@ dependencies = [ [[package]] name = "radroots_runtime_paths" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "serde", "thiserror 1.0.69", @@ -1685,7 +1685,7 @@ dependencies = [ [[package]] name = "radroots_secrets" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "chacha20poly1305", "serde", @@ -1697,7 +1697,7 @@ dependencies = [ [[package]] name = "radroots_service_host" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "bytes", "fs2", @@ -1718,7 +1718,7 @@ dependencies = [ [[package]] name = "radroots_service_sqlite" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "fs2", "futures", @@ -1736,7 +1736,7 @@ dependencies = [ [[package]] name = "radroots_storage" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "radroots_event", "radroots_event_codec", @@ -1749,7 +1749,7 @@ dependencies = [ [[package]] name = "radroots_trade" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "radroots_core", "radroots_event", @@ -1759,7 +1759,7 @@ dependencies = [ [[package]] name = "radroots_transport" version = "0.1.0-alpha" -source = "git+https://github.com/radrootslabs/lib?rev=b44119fbac5985be8127ad1bf56d2950e6399427#b44119fbac5985be8127ad1bf56d2950e6399427" +source = "git+https://github.com/radrootslabs/lib?rev=7d7b454b4c9ed86569671993bd03ca868b676665#7d7b454b4c9ed86569671993bd03ca868b676665" dependencies = [ "radroots_event", "radroots_identity", diff --git a/Cargo.toml b/Cargo.toml @@ -16,6 +16,7 @@ resolver = "3" [workspace.metadata.radroots.service_source_lock] service = "myc" host_feature_profile = "service-host" +nix_material = "deferred" config_contract_version = 1 state_contract_version = 9 admin_contract_version = 1 @@ -55,13 +56,13 @@ futures-executor = "0.3" hex = "0.4" jsonschema = { version = "0.48.1", default-features = false } nostr = { version = "0.44.2", features = ["nip04", "nip44", "nip46", "nip49"] } -radroots_nostr = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha", features = ["events"] } -radroots_nostr_connect = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha" } -radroots_runtime_paths = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha" } -radroots_service_host = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha" } -radroots_service_sqlite = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha" } -radroots_secrets = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha", features = ["std"] } -radroots_storage = { git = "https://github.com/radrootslabs/lib", rev = "b44119fbac5985be8127ad1bf56d2950e6399427", version = "=0.1.0-alpha", default-features = false } +radroots_nostr = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha", features = ["events"] } +radroots_nostr_connect = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha" } +radroots_runtime_paths = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha" } +radroots_service_host = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha" } +radroots_service_sqlite = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha" } +radroots_secrets = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha", features = ["std"] } +radroots_storage = { git = "https://github.com/radrootslabs/lib", rev = "7d7b454b4c9ed86569671993bd03ca868b676665", version = "=0.1.0-alpha", default-features = false } serde = { version = "1.0", features = ["derive"] } serde_json = { version = "1.0", features = ["raw_value"] } sha2 = "0.10" diff --git a/README b/README @@ -37,9 +37,12 @@ let _snapshot = MycStatusSnapshot {}; The native package and dependency-trust metadata is frozen by `contracts/services_hardening/native_release.v1.json`. Linux x86_64 and aarch64 are declared release targets, not qualified artifacts. The canonical -service source lock binds the exact public Lib cohort, Cargo and flake lock -source data, toolchain, feature profile, and service contract versions. Nix, -OCI, signing, tags, publication, and deployment remain deferred and unclaimed. +service source lock binds the exact active public Lib cohort, Cargo lock, +verified source archive, toolchain, feature profile, and service contract +versions. Deferred flake source data is independently digest-bound and may +select an older reachable Lib revision; it does not control native builds or +claim Nix qualification. Nix, OCI, signing, tags, publication, and deployment +remain deferred and unclaimed. ## Hardened v1 configuration contract diff --git a/contracts/services_hardening/native_release.v1.json b/contracts/services_hardening/native_release.v1.json @@ -24,8 +24,8 @@ "panic": "unwind" }, "source_lock": { - "filename": "radroots.service.source-lock.v1.toml", - "schema": "radroots.service.source-lock.v1", + "filename": "radroots.service.source-lock.v2.toml", + "schema": "radroots.service.source-lock.v2", "generator": "cargo xtask service-source-lock", "lib_repository": "https://github.com/radrootslabs/lib", "architecture": "radroots.crates.release.v2" diff --git a/radroots.service.source-lock.v1.toml b/radroots.service.source-lock.v1.toml @@ -1,20 +0,0 @@ -schema = "radroots.service.source-lock.v1" -contract_version = 1 -service = "myc" -repository = "https://github.com/radrootslabs/lib" -revision = "b44119fbac5985be8127ad1bf56d2950e6399427" -architecture = "radroots.crates.release.v2" -workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4" -version = "0.1.0-alpha" -source_archive_sha256 = "975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379" -cargo_lock_sha256 = "04f566ee4c444c81002f090ac77e61b77000e8aeb1a337ae38447e2f0913a3b9" -flake_lock_sha256 = "90a03f6f0794f3f6556b1f2bf6700812d48ce8dc1cee7c4f8bc62cea69b42bd1" -rust_version = "1.97.1" -host_feature_profile = "service-host" - -[contract_versions] -config = 1 -state = 9 -admin = 1 -status = 1 -provider = 1 diff --git a/radroots.service.source-lock.v2.toml b/radroots.service.source-lock.v2.toml @@ -0,0 +1,24 @@ +schema = "radroots.service.source-lock.v2" +contract_version = 2 +service = "myc" +repository = "https://github.com/radrootslabs/lib" +revision = "7d7b454b4c9ed86569671993bd03ca868b676665" +architecture = "radroots.crates.release.v2" +workspace_catalog_sha256 = "deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4" +version = "0.1.0-alpha" +source_archive_sha256 = "b425371c134be96cce46b37f7035d6212f1efe8cff50bef366631ba5632991b0" +cargo_lock_sha256 = "57be61e2ce5f5cf37c960e8aaf223a8716c7cd49922a752b437f0be45fd71a08" +rust_version = "1.97.1" +host_feature_profile = "service-host" + +[nix] +material = "deferred" +lib_revision = "b44119fbac5985be8127ad1bf56d2950e6399427" +flake_lock_sha256 = "90a03f6f0794f3f6556b1f2bf6700812d48ce8dc1cee7c4f8bc62cea69b42bd1" + +[contract_versions] +config = 1 +state = 9 +admin = 1 +status = 1 +provider = 1 diff --git a/src/nip46_wave_080_a.rs b/src/nip46_wave_080_a.rs @@ -110,7 +110,7 @@ pub(crate) fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationB let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/build_policy.rs b/tests/build_policy.rs @@ -4,7 +4,7 @@ use sha2::{Digest, Sha256}; const MANIFEST: &str = include_str!("../Cargo.toml"); const RELEASE_ACCEPTANCE: &str = include_str!("../scripts/release-acceptance.sh"); -const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v1.toml"); +const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v2.toml"); const FLAKE_LOCK: &[u8] = include_bytes!("../flake.lock"); #[test] @@ -30,28 +30,28 @@ fn service_host_is_the_exact_default_feature_profile() { #[test] fn shared_runtime_paths_is_exactly_pinned_to_the_source_locked_lib() { assert!(MANIFEST.contains( - "radroots_runtime_paths = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\", version = \"=0.1.0-alpha\" }" + "radroots_runtime_paths = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\", version = \"=0.1.0-alpha\" }" )); } #[test] fn shared_service_host_is_exactly_pinned_to_the_source_locked_lib() { assert!(MANIFEST.contains( - "radroots_service_host = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\", version = \"=0.1.0-alpha\" }" + "radroots_service_host = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\", version = \"=0.1.0-alpha\" }" )); } #[test] fn shared_service_sqlite_is_exactly_pinned_to_the_source_locked_lib() { assert!(MANIFEST.contains( - "radroots_service_sqlite = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\", version = \"=0.1.0-alpha\" }" + "radroots_service_sqlite = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\", version = \"=0.1.0-alpha\" }" )); } #[test] fn shared_storage_evidence_is_exactly_pinned_to_the_source_locked_lib() { assert!(MANIFEST.contains( - "radroots_storage = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\", version = \"=0.1.0-alpha\", default-features = false }" + "radroots_storage = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\", version = \"=0.1.0-alpha\", default-features = false }" )); } @@ -71,16 +71,22 @@ fn source_lock_binds_the_current_cargo_lock() { let digest = hex::encode(Sha256::digest(include_bytes!("../Cargo.lock"))); let flake_digest = hex::encode(Sha256::digest(FLAKE_LOCK)); assert!(SOURCE_LOCK.starts_with( - "schema = \"radroots.service.source-lock.v1\"\ncontract_version = 1\nservice = \"myc\"\n" + "schema = \"radroots.service.source-lock.v2\"\ncontract_version = 2\nservice = \"myc\"\n" )); assert!(SOURCE_LOCK.contains(&format!("cargo_lock_sha256 = \"{digest}\""))); assert!(SOURCE_LOCK.contains(&format!("flake_lock_sha256 = \"{flake_digest}\""))); - assert!(SOURCE_LOCK.contains("revision = \"b44119fbac5985be8127ad1bf56d2950e6399427\"")); + assert!(SOURCE_LOCK.contains("revision = \"7d7b454b4c9ed86569671993bd03ca868b676665\"")); + assert!(SOURCE_LOCK.contains( + "[nix]\nmaterial = \"deferred\"\nlib_revision = \"b44119fbac5985be8127ad1bf56d2950e6399427\"\n" + )); + assert!(!SOURCE_LOCK.contains( + "[nix]\nmaterial = \"deferred\"\nlib_revision = \"7d7b454b4c9ed86569671993bd03ca868b676665\"\n" + )); assert!(SOURCE_LOCK.contains( "workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\"" )); assert!(SOURCE_LOCK.contains( - "source_archive_sha256 = \"975474804e6358b9228981add0a23181dbdd1afddf5ae12579c82220876bc379\"" + "source_archive_sha256 = \"b425371c134be96cce46b37f7035d6212f1efe8cff50bef366631ba5632991b0\"" )); assert!(SOURCE_LOCK.ends_with( "[contract_versions]\nconfig = 1\nstate = 9\nadmin = 1\nstatus = 1\nprovider = 1\n" diff --git a/tests/services_hardening_connection_state.rs b/tests/services_hardening_connection_state.rs @@ -85,7 +85,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_delivery_state.rs b/tests/services_hardening_delivery_state.rs @@ -126,7 +126,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_discovery_state.rs b/tests/services_hardening_discovery_state.rs @@ -109,7 +109,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_local_signer_transport.rs b/tests/services_hardening_local_signer_transport.rs @@ -84,7 +84,7 @@ fn machine_contract_freezes_the_complete_local_signer_transport() { #[test] fn implementation_uses_only_the_hardened_fixed_unix_admin_boundary() { for required in [ - "radroots_service_host = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\"", + "radroots_service_host = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\"", "const MYC_LOCAL_SIGNER_ENDPOINT: &str = \"/v1/provider/operation\"", "radroots_service_host::AdminClient", ".mutate::<_, LocalSignerResponse>(", diff --git a/tests/services_hardening_native_release.rs b/tests/services_hardening_native_release.rs @@ -10,7 +10,8 @@ const LOCK: &str = include_str!("../Cargo.lock"); const FLAKE: &str = include_str!("../flake.nix"); const FLAKE_LOCK: &str = include_str!("../flake.lock"); -const LIB_REVISION: &str = "b44119fbac5985be8127ad1bf56d2950e6399427"; +const LIB_REVISION: &str = "7d7b454b4c9ed86569671993bd03ca868b676665"; +const DEFERRED_NIX_LIB_REVISION: &str = "b44119fbac5985be8127ad1bf56d2950e6399427"; const LIB_REPOSITORY: &str = "https://github.com/radrootslabs/lib"; #[test] @@ -44,8 +45,8 @@ fn native_release_contract_and_manifest_metadata_are_exact() { "panic": "unwind" }, "source_lock": { - "filename": "radroots.service.source-lock.v1.toml", - "schema": "radroots.service.source-lock.v1", + "filename": "radroots.service.source-lock.v2.toml", + "schema": "radroots.service.source-lock.v2", "generator": "cargo xtask service-source-lock", "lib_repository": LIB_REPOSITORY, "architecture": "radroots.crates.release.v2" @@ -111,6 +112,7 @@ fn native_release_contract_and_manifest_metadata_are_exact() { toml::Value::Table(toml::toml! { service = "myc" host_feature_profile = "service-host" + nix_material = "deferred" config_contract_version = 1 state_contract_version = 9 admin_contract_version = 1 @@ -207,13 +209,13 @@ fn every_radroots_dependency_is_exactly_source_locked() { "narHash": "sha256-WOcgJuKhM9aP55yTuTM63uBf+/IroeBu26zy+lMkvpE=", "owner": "radrootslabs", "repo": "lib", - "rev": LIB_REVISION, + "rev": DEFERRED_NIX_LIB_REVISION, "type": "github" }, "original": { "owner": "radrootslabs", "repo": "lib", - "rev": LIB_REVISION, + "rev": DEFERRED_NIX_LIB_REVISION, "type": "github" } }) @@ -224,7 +226,8 @@ fn every_radroots_dependency_is_exactly_source_locked() { fn removed_and_deferred_release_surfaces_cannot_be_smuggled_into_step_139() { let root = std::path::Path::new(env!("CARGO_MANIFEST_DIR")); assert!(!root.join("radroots.lib.source-lock.v1.toml").exists()); - assert!(root.join("radroots.service.source-lock.v1.toml").is_file()); + assert!(!root.join("radroots.service.source-lock.v1.toml").exists()); + assert!(root.join("radroots.service.source-lock.v2.toml").is_file()); for forbidden in [ ".github", "target", diff --git a/tests/services_hardening_runtime_context.rs b/tests/services_hardening_runtime_context.rs @@ -288,7 +288,7 @@ fn unsupported_profile_platform_and_diagnostics_fail_safely() { #[test] fn shared_runtime_paths_are_the_only_path_policy_and_identity_authority() { assert!(MANIFEST.contains( - "radroots_runtime_paths = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\", version = \"=0.1.0-alpha\" }" + "radroots_runtime_paths = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\", version = \"=0.1.0-alpha\" }" )); assert!(LIB_SOURCE.contains("mod runtime_context;")); assert!(!LIB_SOURCE.contains("pub mod runtime_context;")); diff --git a/tests/services_hardening_runtime_foundation.rs b/tests/services_hardening_runtime_foundation.rs @@ -129,7 +129,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_signer_request_state.rs b/tests/services_hardening_signer_request_state.rs @@ -66,7 +66,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_state_catalog.rs b/tests/services_hardening_state_catalog.rs @@ -368,7 +368,7 @@ fn catalog_errors_are_stable_source_free_and_redacted() { #[test] fn catalog_source_is_pure_pinned_and_uses_only_the_shared_authority() { assert!(MANIFEST.contains( - "radroots_service_sqlite = { git = \"https://github.com/radrootslabs/lib\", rev = \"b44119fbac5985be8127ad1bf56d2950e6399427\", version = \"=0.1.0-alpha\" }" + "radroots_service_sqlite = { git = \"https://github.com/radrootslabs/lib\", rev = \"7d7b454b4c9ed86569671993bd03ca868b676665\", version = \"=0.1.0-alpha\" }" )); assert!(LIB_SOURCE.contains("mod state_catalog;")); assert!(!LIB_SOURCE.contains("pub mod state_catalog;")); diff --git a/tests/services_hardening_state_host.rs b/tests/services_hardening_state_host.rs @@ -60,7 +60,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", @@ -78,7 +78,7 @@ fn mismatched_migration_build() -> MigrationBuildIdentity { MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_state_repository.rs b/tests/services_hardening_state_repository.rs @@ -62,7 +62,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host", diff --git a/tests/services_hardening_state_resilience.rs b/tests/services_hardening_state_resilience.rs @@ -72,7 +72,7 @@ fn migration_evidence() -> (MigrationAppliedAtUnixSeconds, MigrationBuildIdentit let build = MigrationBuildIdentity::new( env!("CARGO_PKG_VERSION"), "1111111111111111111111111111111111111111", - "b44119fbac5985be8127ad1bf56d2950e6399427", + "7d7b454b4c9ed86569671993bd03ca868b676665", "rustc-test", "test-target", "service-host",