myc

Self-custodial remote signer for Radroots apps
git clone https://radroots.dev/git/myc.git
Log | Files | Refs | README | LICENSE

build_policy.rs (4904B)


      1 #![forbid(unsafe_code)]
      2 
      3 use sha2::{Digest, Sha256};
      4 
      5 const MANIFEST: &str = include_str!("../Cargo.toml");
      6 const RELEASE_ACCEPTANCE: &str = include_str!("../scripts/release-acceptance.sh");
      7 const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v3.toml");
      8 const FLAKE_LOCK: &[u8] = include_bytes!("../flake.lock");
      9 
     10 #[test]
     11 fn manifest_freezes_the_final_rust_policy() {
     12     assert!(MANIFEST.contains("[workspace]\nresolver = \"3\""));
     13     assert!(MANIFEST.contains("[workspace.lints.rust]\nunsafe_code = \"deny\""));
     14     assert!(MANIFEST.contains("[workspace.lints.rustdoc]\nbroken_intra_doc_links = \"deny\""));
     15     assert!(MANIFEST.contains(
     16         "[workspace.lints.clippy]\ndbg_macro = \"deny\"\ntodo = \"deny\"\nunimplemented = \"deny\""
     17     ));
     18     assert!(MANIFEST.contains("[lints]\nworkspace = true"));
     19 }
     20 
     21 #[test]
     22 fn service_host_is_the_exact_default_feature_profile() {
     23     assert!(MANIFEST.contains("[features]\ndefault = [\"service-host\"]\nservice-host = []"));
     24     assert!(!MANIFEST.contains("getrandom = \"0.2\""));
     25     assert!(MANIFEST.contains(
     26         "tokio = { version = \"1.48\", default-features = false, features = [\"io-util\", \"macros\", \"net\", \"rt-multi-thread\", \"signal\", \"sync\", \"time\"] }"
     27     ));
     28 }
     29 
     30 #[test]
     31 fn shared_runtime_paths_is_exactly_pinned_to_the_source_locked_lib() {
     32     assert!(MANIFEST.contains(
     33         "radroots_runtime_paths = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }"
     34     ));
     35 }
     36 
     37 #[test]
     38 fn shared_identity_is_exactly_pinned_to_the_source_locked_lib() {
     39     assert!(MANIFEST.contains(
     40         "radroots_identity = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }"
     41     ));
     42 }
     43 
     44 #[test]
     45 fn shared_service_host_is_exactly_pinned_to_the_source_locked_lib() {
     46     assert!(MANIFEST.contains(
     47         "radroots_service_host = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }"
     48     ));
     49 }
     50 
     51 #[test]
     52 fn shared_service_sqlite_is_exactly_pinned_to_the_source_locked_lib() {
     53     assert!(MANIFEST.contains(
     54         "radroots_service_sqlite = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }"
     55     ));
     56 }
     57 
     58 #[test]
     59 fn shared_storage_evidence_is_exactly_pinned_to_the_source_locked_lib() {
     60     assert!(MANIFEST.contains(
     61         "radroots_storage = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\", default-features = false }"
     62     ));
     63 }
     64 
     65 #[test]
     66 fn delivery_dependencies_are_exactly_source_locked() {
     67     for dependency in [
     68         "radroots_event_codec",
     69         "radroots_transport",
     70         "radroots_transport_nostr",
     71     ] {
     72         assert!(
     73             MANIFEST.contains(&format!(
     74                 "{dependency} = {{ git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\""
     75             )),
     76             "{dependency} is not pinned to the exact source lock"
     77         );
     78     }
     79 }
     80 
     81 #[test]
     82 fn release_acceptance_checks_both_feature_profiles() {
     83     assert!(
     84         RELEASE_ACCEPTANCE.contains("cargo check --locked --all-targets --no-default-features\n")
     85     );
     86     assert!(RELEASE_ACCEPTANCE.contains(
     87         "cargo check --locked --all-targets --no-default-features --features service-host\n"
     88     ));
     89     assert!(RELEASE_ACCEPTANCE.contains("cargo test --locked -p myc_xtask\n"));
     90     assert!(!RELEASE_ACCEPTANCE.contains("nix "));
     91 }
     92 
     93 #[test]
     94 fn source_lock_binds_the_current_cargo_lock() {
     95     let digest = hex::encode(Sha256::digest(include_bytes!("../Cargo.lock")));
     96     let flake_digest = hex::encode(Sha256::digest(FLAKE_LOCK));
     97     assert!(SOURCE_LOCK.starts_with(
     98         "schema = \"radroots.service.source-lock.v3\"\ncontract_version = 3\nservice = \"myc\"\n"
     99     ));
    100     assert!(SOURCE_LOCK.contains(&format!("cargo_lock_sha256 = \"{digest}\"")));
    101     assert!(SOURCE_LOCK.contains(&format!("sha256 = \"{flake_digest}\"")));
    102     assert!(SOURCE_LOCK.contains("revision = \"055096853fca95e15d0f813d33a14aca13be3881\""));
    103     assert!(SOURCE_LOCK.contains(
    104         "[nix]\nmaterial = \"qualified\"\nlib_revision = \"055096853fca95e15d0f813d33a14aca13be3881\"\nsupported_systems = [\"aarch64-darwin\", \"x86_64-linux\"]\n"
    105     ));
    106     assert!(SOURCE_LOCK.contains(
    107         "workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\""
    108     ));
    109     assert!(SOURCE_LOCK.contains(
    110         "source_archive_sha256 = \"89b8ace3f61167df43aca89917405d58b2aaf2ddea8fadfb21d351d76f184e68\""
    111     ));
    112     assert!(SOURCE_LOCK.ends_with(
    113         "[contract_versions]\nconfig = 1\nstate = 12\nadmin = 1\nstatus = 1\nprovider = 1\n"
    114     ));
    115 }