myc

Self-custodial remote signer for Radroots apps
git clone https://radroots.dev/git/myc.git
Log | Files | Refs | README | LICENSE

package_boundary.rs (59011B)


      1 #![forbid(unsafe_code)]
      2 
      3 use std::collections::BTreeSet;
      4 
      5 const ROOT: &str = include_str!("../src/lib.rs");
      6 const README: &str = include_str!("../README");
      7 const PUBLIC_API: &str = include_str!("../contracts/api_baselines/myc.txt");
      8 const ADMIN_V1: &str = include_str!("../src/admin_v1.rs");
      9 const CONTROL_SURFACES_CONTRACT: &str =
     10     include_str!("../contracts/services_hardening/control_surfaces.v1.json");
     11 const NIP46_VERIFICATION: &str = include_str!("../src/nip46_verification.rs");
     12 const NIP46_AUTHORIZATION: &str = include_str!("../src/nip46_authorization.rs");
     13 const NIP46_REPLAY: &str = include_str!("../src/nip46_replay.rs");
     14 const NIP46_WORK: &str = include_str!("../src/nip46_work.rs");
     15 const NIP46_WAVE_080_A: &str = include_str!("../src/nip46_wave_080_a.rs");
     16 const NIP46_COMPLETION: &str = include_str!("../src/state_completion.rs");
     17 const NIP46_RESPONSE: &str = include_str!("../src/state_response.rs");
     18 const STATE_CATALOG: &str = include_str!("../src/state_catalog.rs");
     19 const STATE_HOST: &str = include_str!("../src/state_host.rs");
     20 const DELIVERY_RECOVERY: &str = include_str!("../src/state_recovery.rs");
     21 const DELIVERY_WORKER: &str = include_str!("../src/delivery_worker.rs");
     22 const PROVIDER_EXECUTOR: &str = include_str!("../src/provider_executor.rs");
     23 const TRANSPORT_NOSTR_ADAPTER: &str = include_str!("../src/transport_nostr_adapter.rs");
     24 const PROVIDER_DELIVERY_CONTRACT: &str =
     25     include_str!("../contracts/services_hardening/provider_delivery.v1.json");
     26 const DOCTOR_V1: &str = include_str!("../src/doctor_v1.rs");
     27 const CONTROL_PLANE_WAVE_090_A: &str = include_str!("../src/control_plane_wave_090_a.rs");
     28 const CONTROL_PLANE_WAVE_090_A_CONTRACT: &str =
     29     include_str!("../contracts/services_hardening/control_plane_wave_090_a.v1.json");
     30 const DIAGNOSTICS_V1: &str = include_str!("../src/diagnostics_v1.rs");
     31 const DIAGNOSTICS_CONTRACT: &str =
     32     include_str!("../contracts/services_hardening/diagnostics.v1.json");
     33 const MAIN: &str = include_str!("../src/main.rs");
     34 const PROCESS_V1: &str = include_str!("../src/process_v1.rs");
     35 const PROCESS_V1_UNSUPPORTED: &str = include_str!("../src/process_v1_unsupported.rs");
     36 const CONFIG_LOADER: &str = include_str!("../src/config_loader.rs");
     37 const SYSTEM_DOCTOR: &str = include_str!("../src/system_doctor.rs");
     38 const STATUS_V1: &str = include_str!("../src/status_v1.rs");
     39 const RUNTIME_GRAPH: &str = include_str!("../src/runtime_graph.rs");
     40 const RUNTIME_NIP46: &str = include_str!("../src/runtime_nip46.rs");
     41 const RUNTIME_SIGNAL: &str = include_str!("../src/runtime_signal.rs");
     42 const RUNTIME_SUPERVISION: &str = include_str!("../src/runtime_supervision.rs");
     43 const RUNTIME_SUPERVISION_CONTRACT: &str =
     44     include_str!("../contracts/services_hardening/runtime_supervision.v1.json");
     45 const STATUS_CONTRACT: &str = include_str!("../contracts/services_hardening/status_cache.v1.json");
     46 const OPERATIONS_V1: &str = include_str!("../src/operations_v1.rs");
     47 const OPERATIONS_CONTRACT: &str =
     48     include_str!("../contracts/services_hardening/tcp_operations.v1.json");
     49 const DISCOVERY_STATE: &str = include_str!("../src/state_discovery.rs");
     50 const NIP46_VERIFICATION_CONTRACT: &str =
     51     include_str!("../contracts/services_hardening/nip46_verification.v1.json");
     52 const NIP46_REPLAY_CONTRACT: &str =
     53     include_str!("../contracts/services_hardening/nip46_replay.v1.json");
     54 const NIP46_AUTHORIZATION_CONTRACT: &str =
     55     include_str!("../contracts/services_hardening/nip46_authorization.v1.json");
     56 const NIP46_WORK_CONTRACT: &str =
     57     include_str!("../contracts/services_hardening/nip46_work.v1.json");
     58 const NIP46_WAVE_080_A_CONTRACT: &str =
     59     include_str!("../contracts/services_hardening/nip46_wave_080_a.v1.json");
     60 const NIP46_COMPLETION_CONTRACT: &str =
     61     include_str!("../contracts/services_hardening/nip46_completion.v1.json");
     62 const NIP46_RESPONSE_CONTRACT: &str =
     63     include_str!("../contracts/services_hardening/nip46_response_commit.v1.json");
     64 const NIP46_PENDING_RESPONSE_CONTRACT: &str =
     65     include_str!("../contracts/services_hardening/nip46_pending_response.v1.json");
     66 const DELIVERY_RECOVERY_EXPORT_CONTRACT: &str =
     67     include_str!("../contracts/services_hardening/delivery_recovery_export.v1.json");
     68 const PROCESS_QUALIFICATION_CONTRACT: &str =
     69     include_str!("../contracts/services_hardening/process_qualification.v1.json");
     70 const SOURCES: &[&str] = &[
     71     include_str!("../src/admin_v1.rs"),
     72     include_str!("../src/cli_bootstrap.rs"),
     73     include_str!("../src/cli_v1.rs"),
     74     include_str!("../src/config_loader.rs"),
     75     include_str!("../src/config_v1.rs"),
     76     include_str!("../src/control_plane_wave_090_a.rs"),
     77     include_str!("../src/delivery_worker.rs"),
     78     include_str!("../src/doctor_v1.rs"),
     79     include_str!("../src/diagnostics_v1.rs"),
     80     include_str!("../src/nip46_admission.rs"),
     81     include_str!("../src/nip46_authorization.rs"),
     82     include_str!("../src/nip46_replay.rs"),
     83     include_str!("../src/nip46_verification.rs"),
     84     include_str!("../src/nip46_work.rs"),
     85     include_str!("../src/nip46_wave_080_b.rs"),
     86     include_str!("../src/operations_v1.rs"),
     87     include_str!("../src/process_v1.rs"),
     88     include_str!("../src/process_v1_unsupported.rs"),
     89     include_str!("../src/provider_contract.rs"),
     90     include_str!("../src/provider_credential.rs"),
     91     include_str!("../src/provider_envelope.rs"),
     92     include_str!("../src/provider_executor.rs"),
     93     include_str!("../src/provider_local_signer.rs"),
     94     include_str!("../src/provider_verification.rs"),
     95     include_str!("../src/runtime_context.rs"),
     96     include_str!("../src/runtime_foundation.rs"),
     97     include_str!("../src/runtime_graph.rs"),
     98     include_str!("../src/runtime_nip46.rs"),
     99     include_str!("../src/runtime_signal.rs"),
    100     include_str!("../src/runtime_supervision.rs"),
    101     include_str!("../src/status_v1.rs"),
    102     include_str!("../src/system_doctor.rs"),
    103     include_str!("../src/transport_nostr_adapter.rs"),
    104     include_str!("../src/state_catalog.rs"),
    105     include_str!("../src/state_admin.rs"),
    106     include_str!("../src/state_completion.rs"),
    107     include_str!("../src/state_config.rs"),
    108     include_str!("../src/state_connection.rs"),
    109     include_str!("../src/state_delivery.rs"),
    110     include_str!("../src/state_discovery.rs"),
    111     include_str!("../src/state_governance.rs"),
    112     include_str!("../src/state_host.rs"),
    113     include_str!("../src/state_maintenance.rs"),
    114     include_str!("../src/state_metadata.rs"),
    115     include_str!("../src/state_repository.rs"),
    116     include_str!("../src/state_recovery.rs"),
    117     include_str!("../src/state_request.rs"),
    118     include_str!("../src/state_response.rs"),
    119 ];
    120 
    121 #[test]
    122 fn state_initialization_uses_only_governed_directory_and_sqlite_authority() {
    123     for required in [
    124         "ServiceSqliteInitializer",
    125         "ServiceSqliteInitializerFuture",
    126         ".state_directory_plan()",
    127         ".and_then(|plan| plan.provision())",
    128         "initialize_database(",
    129     ] {
    130         assert!(
    131             STATE_HOST.contains(required),
    132             "state initialization is missing `{required}`"
    133         );
    134     }
    135     for forbidden in [
    136         "PathBuf",
    137         "use sqlx::",
    138         "SqliteConnectOptions",
    139         "ConnectOptions",
    140         "create_dir_all",
    141         "try_exists",
    142     ] {
    143         assert!(
    144             !STATE_HOST.contains(forbidden),
    145             "state initialization regained `{forbidden}`"
    146         );
    147     }
    148 }
    149 
    150 #[test]
    151 fn implementation_modules_are_private_and_rustdoc_uses_the_reviewed_readme() {
    152     assert_eq!(
    153         ROOT.lines()
    154             .filter_map(|line| line.strip_prefix("mod "))
    155             .filter_map(|line| line.strip_suffix(';'))
    156             .collect::<BTreeSet<_>>(),
    157         BTreeSet::from([
    158             "admin_v1",
    159             "cli_bootstrap",
    160             "cli_v1",
    161             "config_loader",
    162             "config_v1",
    163             "control_plane_wave_090_a",
    164             "delivery_worker",
    165             "doctor_v1",
    166             "diagnostics_v1",
    167             "nip46_admission",
    168             "nip46_authorization",
    169             "nip46_replay",
    170             "nip46_verification",
    171             "nip46_work",
    172             "nip46_wave_080_a",
    173             "nip46_wave_080_b",
    174             "operations_v1",
    175             "process_v1",
    176             "provider_contract",
    177             "provider_credential",
    178             "provider_envelope",
    179             "provider_executor",
    180             "provider_local_signer",
    181             "provider_verification",
    182             "runtime_context",
    183             "runtime_foundation",
    184             "runtime_graph",
    185             "runtime_nip46",
    186             "runtime_signal",
    187             "runtime_supervision",
    188             "status_v1",
    189             "system_doctor",
    190             "transport_nostr_adapter",
    191             "state_catalog",
    192             "state_admin",
    193             "state_completion",
    194             "state_config",
    195             "state_connection",
    196             "state_delivery",
    197             "state_discovery",
    198             "state_governance",
    199             "state_host",
    200             "state_maintenance",
    201             "state_metadata",
    202             "state_repository",
    203             "state_recovery",
    204             "state_request",
    205             "state_response",
    206         ])
    207     );
    208     assert!(!ROOT.contains("pub mod "));
    209     assert!(ROOT.contains("#![doc = include_str!(\"../README\")]"));
    210 
    211     for required in [
    212         "## Public API boundary",
    213         "one curated crate-root API",
    214         "public errors use Myc-owned stable classifications",
    215         "```compile_fail",
    216         "[Myc API baseline](contracts/api_baselines/myc.txt)",
    217         "Status publication and cached snapshots can be obtained only",
    218         "Schema v10 adds an append-only configuration-binding history capped at exactly\n1,024 generations",
    219         "Exact replay returns the retained generation without another\nappend or revocation",
    220         "Future startup\nmust present the latest normalized config and public-identity binding",
    221         "Schema v11 adds the bounded admin-operation journal",
    222         "at most 128 unresolved Prepared records and 4,096 completed responses",
    223         "caps a\nreplayed response model at 8,192 bytes",
    224         "admits at least 8,382 UTF-8 bytes",
    225         "The journal stores no request body, path,\ncorrelation ID, credential, bundle path, or secret",
    226         "Schema v12 adds immutable response authority for a connect request awaiting\nexplicit approval",
    227         "without recording a false terminal operation completion",
    228         "Exact\nreplay and delivery use only the retained signed bytes",
    229         "The Step 159 provider and delivery boundary is sealed inside the crate",
    230         "persists Submitted immediately before execution",
    231         "The selected absolute config path is opened no-follow through its retained\nparent descriptor",
    232         "One binary-owned Tokio runtime is created from the validated fixed thread\nlimits",
    233         "Restore derives expected backup identity\nfrom the trusted manifest digest",
    234         "The production adapter composes secure path and disk inspection",
    235         "It never publishes a relay event",
    236         "The production `run` path owns the exact five-role bounded graph",
    237         "Required relay subscriptions and provider handshakes complete before\nReady",
    238         "one configured absolute graceful-shutdown deadline",
    239         "## Executable qualification",
    240         "eight\nconcurrent inspection processes, 32 deterministic reopen iterations, and one\n64 MiB crash fixture",
    241         "without adding a production\nfailpoint, hidden command, environment selector, feature, or detached test\nworker",
    242     ] {
    243         assert!(README.contains(required), "README is missing `{required}`");
    244     }
    245 }
    246 
    247 #[test]
    248 fn step161_qualification_is_machine_bound_without_a_production_test_surface() {
    249     let contract: serde_json::Value =
    250         serde_json::from_str(PROCESS_QUALIFICATION_CONTRACT).expect("qualification contract");
    251     assert_eq!(contract["schema"], "radroots.myc.process-qualification.v1");
    252     assert_eq!(contract["step"], 161);
    253     assert_eq!(contract["invariants"]["actual_executable_required"], true);
    254     assert_eq!(
    255         contract["invariants"]["production_failpoint_surface"],
    256         false
    257     );
    258     assert_eq!(contract["invariants"]["test_environment_selector"], false);
    259     for source in SOURCES.iter().copied().chain([ROOT, MAIN]) {
    260         for forbidden in [
    261             "MYC_TEST_",
    262             "MYC_FAILPOINT",
    263             "process_qualification_failpoint",
    264             "qualification-only-command",
    265         ] {
    266             assert!(
    267                 !source.contains(forbidden),
    268                 "production source contains `{forbidden}`"
    269             );
    270         }
    271     }
    272 }
    273 
    274 #[test]
    275 fn step159_runtime_graph_is_fixed_joined_and_binary_signal_owned() {
    276     for required in [
    277         "const TASK_ADMIN_SERVER: &str = \"admin_server\"",
    278         "const TASK_OPERATIONS_SERVER: &str = \"operations_server\"",
    279         "const TASK_RELAY_INGRESS: &str = \"relay_ingress\"",
    280         "const TASK_PROVIDER_DISPATCH: &str = \"provider_dispatch\"",
    281         "const TASK_DELIVERY_OUTBOX: &str = \"delivery_outbox\"",
    282         "open_initial_subscriptions(&ingress_adapter, &configuration).await",
    283         "required_relays_ready(slots)",
    284         "MycRuntimeNip46Coordinator::new",
    285         "let admission_evidence = runtime_nip46_admission_evidence()",
    286         "let mut retry = initial",
    287         "GracefulShutdown::new(grace)",
    288         "ProcessSignalAdapter::new(HostSignalSource::new(signals))",
    289         "publish(MycServicePhase::Ready)",
    290     ] {
    291         assert!(RUNTIME_GRAPH.contains(required), "missing `{required}`");
    292     }
    293     assert_eq!(RUNTIME_GRAPH.matches(".spawn(").count(), 5);
    294     assert!(RUNTIME_NIP46.contains("commit_nip46_response(&commit)"));
    295     assert!(RUNTIME_NIP46.contains("ExactResponseReplay"));
    296     assert!(RUNTIME_NIP46.contains("admission_evidence: MycRuntimeNip46AdmissionEvidence"));
    297     assert!(RUNTIME_SIGNAL.contains("pub trait MycProcessSignalSource: Send"));
    298     for forbidden in [
    299         "tokio::spawn",
    300         "spawn_blocking",
    301         "std::thread::spawn",
    302         "std::process::exit",
    303     ] {
    304         assert!(!RUNTIME_GRAPH.contains(forbidden), "found `{forbidden}`");
    305     }
    306 }
    307 
    308 #[test]
    309 fn reviewed_api_is_root_only_and_exposes_no_implementation_authority() {
    310     for required in [
    311         "pub struct myc::MycCliExecutionPlanV1",
    312         "pub enum myc::MycCliPrimaryAuthorityV1",
    313         "pub enum myc::MycCliOfflineOperationV1",
    314         "pub enum myc::MycCliAdminOperationV1",
    315         "pub const fn myc::plan_myc_cli_v1",
    316         "pub enum myc::MycCliOutputModeV1",
    317         "pub struct myc::MycConfigApplyArgsV1",
    318         "pub struct myc::MycStateBackupArgsV1",
    319         "pub struct myc::MycStateRestoreArgsV1",
    320         "pub struct myc::MycIdentityCommandArgsV1",
    321         "pub struct myc::MycRuntimeThreadLimitsV1",
    322         "pub struct myc::MycConfigLoadError",
    323         "pub enum myc::MycConfigLoadErrorKind",
    324         "pub fn myc::execute_myc_cli_v1",
    325         "pub fn myc::initialize_myc_config_document",
    326         "pub fn myc::load_myc_config_candidate",
    327         "pub fn myc::load_myc_config_document",
    328         "pub struct myc::MycDoctorReport",
    329         "pub struct myc::MycLogRecord",
    330         "pub enum myc::MycLogEvent",
    331         "pub enum myc::MycLogLevel",
    332         "pub enum myc::MycProcessResult",
    333         "pub struct myc::MycDoctorCheckDefinition",
    334         "pub struct myc::MycDoctorCheckResult",
    335         "pub enum myc::MycDoctorCheckId",
    336         "pub enum myc::MycDoctorCheckStatus",
    337         "pub enum myc::MycDoctorAggregateStatus",
    338         "pub enum myc::MycDoctorObservation",
    339         "pub enum myc::MycDoctorRemediationCode",
    340         "pub trait myc::MycDoctorProbe",
    341         "pub async fn myc::run_myc_doctor",
    342         "pub struct myc::MycStatusPublisher",
    343         "pub struct myc::MycStatusReader",
    344         "pub struct myc::MycStatusSnapshot",
    345         "pub struct myc::MycStatusCommonV1",
    346         "pub struct myc::MycStatusObservationV1",
    347         "pub fn myc::myc_status_cache",
    348         "pub struct myc::MycOperationsServer",
    349         "pub struct myc::MycBoundOperationsServer",
    350         "pub struct myc::MycOperationsCancellationToken",
    351         "pub struct myc::MycOperationsError",
    352         "pub enum myc::MycOperationsErrorKind",
    353         "pub struct myc::MycAdminRequestDocument",
    354         "pub struct myc::MycAdminResponseDocument",
    355         "pub enum myc::MycAdminMethod",
    356         "pub enum myc::MycAdminRoute",
    357         "pub trait myc::MycAdminHandler",
    358         "pub struct myc::MycAdminRouter",
    359         "pub fn myc::build_myc_admin_router",
    360         "pub struct myc::MycAdminServer",
    361         "pub struct myc::MycBoundAdminServer",
    362         "pub struct myc::MycAdminCancellationToken",
    363         "pub struct myc::MycAdminServerError",
    364         "pub enum myc::MycAdminServerErrorKind",
    365         "pub struct myc::MycRuntimeContext",
    366         "pub struct myc::MycRuntimeFoundation",
    367         "pub struct myc::MycRuntimeReadiness",
    368         "pub enum myc::MycRuntimeReadinessReason",
    369         "pub struct myc::MycBoundedNip46Event",
    370         "pub struct myc::MycBoundedNip46Request",
    371         "pub struct myc::MycNip46AdmissionLimits",
    372         "pub enum myc::MycNip46AdmissionErrorKind",
    373         "pub struct myc::MycVerifiedNip46Event",
    374         "pub struct myc::MycVerifiedNip46Request",
    375         "pub struct myc::MycNip46AuthoredTimePolicy",
    376         "pub struct myc::MycNip46ConnectionIdentity",
    377         "pub struct myc::MycNip46LogicalRequestIdentity",
    378         "pub struct myc::MycNip46ReplayKey",
    379         "pub struct myc::MycReplayBoundNip46Request",
    380         "pub enum myc::MycNip46ReplayDisposition",
    381         "pub enum myc::MycNip46VerificationErrorKind",
    382         "pub struct myc::MycNip46DecryptWork",
    383         "pub struct myc::MycDecryptedNip46Request",
    384         "pub struct myc::MycPreparedNip46Request",
    385         "pub struct myc::MycNip46Work",
    386         "pub enum myc::MycNip46WorkKind",
    387         "pub enum myc::MycNip46WorkErrorKind",
    388         "pub struct myc::MycNip46WorkError",
    389         "pub struct myc::MycStateHost",
    390         "pub struct myc::MycStateRepository",
    391         "pub struct myc::MycPreparedAdminOperation",
    392         "pub enum myc::MycAdminOperationAdmission",
    393         "pub enum myc::MycAdminOperationCompletion",
    394         "pub struct myc::MycAdminOperationJournalPolicy",
    395         "pub struct myc::MycAdminOperationTimeUnixMs",
    396         "pub struct myc::MycAdminOperationError",
    397         "pub enum myc::MycAdminOperationErrorKind",
    398         "pub const myc::MYC_ADMIN_OPERATION_RESPONSE_ENVELOPE_MAX_UTF8_BYTES: u32",
    399         "pub async fn myc::MycStateRepository<'_>::prepare_admin_operation",
    400         "pub async fn myc::MycStateRepository<'_>::complete_admin_operation",
    401         "pub const myc::MYC_CONFIG_BINDING_MAX_GENERATIONS: u16",
    402         "pub struct myc::MycConfigApplyOutcome",
    403         "pub struct myc::MycConfigApplyError",
    404         "pub enum myc::MycConfigApplyErrorKind",
    405         "pub async fn myc::MycStateRepository<'_>::apply_configuration",
    406         "pub struct myc::MycNip46CommitRequest",
    407         "pub struct myc::MycNip46CommitRecord",
    408         "pub enum myc::MycNip46CommitAdmission",
    409         "pub enum myc::MycNip46SessionEffect",
    410         "pub enum myc::MycNip46CommitErrorKind",
    411         "pub struct myc::MycNip46ResponseCommitRequest",
    412         "pub struct myc::MycNip46ResponseRecord",
    413         "pub struct myc::MycNip46ResponseCommitRecord",
    414         "pub enum myc::MycNip46ResponseCommitAdmission",
    415         "pub enum myc::MycNip46ResponseCommitErrorKind",
    416         "pub async fn myc::MycStateRepository<'_>::commit_nip46_response",
    417         "pub async fn myc::MycStateRepository<'_>::read_nip46_response",
    418         "pub const myc::MYC_STATE_SCHEMA_VERSION_12_MIGRATION_SHA256: [u8; 32]",
    419         "pub const myc::MYC_STATE_SCHEMA_VERSION_12_OBJECT_COUNT: u32",
    420         "pub const myc::MYC_STATE_SCHEMA_VERSION_12_SHA256: [u8; 32]",
    421         "pub async fn myc::MycStateRepository<'_>::recover_delivery_state",
    422         "pub async fn myc::MycStateRepository<'_>::render_offline_nip05",
    423         "pub struct myc::MycDeliveryRecoveryEntropy",
    424         "pub struct myc::MycDeliveryRecoveryReport",
    425         "pub struct myc::MycNip05Document",
    426         "pub enum myc::MycNip05ExportSelection",
    427         "pub async fn myc::MycStateRepository<'_>::read_connection_decision",
    428         "pub fn myc::admit_myc_nip46_event",
    429         "pub fn myc::admit_myc_nip46_request",
    430         "pub fn myc::bind_myc_nip46_replay",
    431         "pub fn myc::prepare_myc_nip46_decrypt_work",
    432         "pub fn myc::prepare_myc_nip46_request",
    433         "pub fn myc::prepare_myc_nip46_work",
    434         "pub fn myc::verify_myc_nip46_event",
    435         "pub fn myc::verify_myc_nip46_request",
    436         "pub async fn myc::open_myc_runtime_foundation",
    437         "pub struct myc::MycCriticalTask",
    438         "pub struct myc::MycCriticalTaskError",
    439         "pub struct myc::MycRuntimeSupervisionError",
    440         "pub enum myc::MycRuntimeSupervisionErrorKind",
    441         "pub struct myc::MycSupervisedRuntime",
    442         "pub struct myc::MycTaskCancellation",
    443     ] {
    444         assert!(
    445             PUBLIC_API.contains(required),
    446             "reviewed API baseline is missing `{required}`"
    447         );
    448     }
    449 
    450     for module in [
    451         "admin_v1",
    452         "cli_bootstrap",
    453         "cli_v1",
    454         "config_loader",
    455         "config_v1",
    456         "control_plane_wave_090_a",
    457         "delivery_worker",
    458         "doctor_v1",
    459         "diagnostics_v1",
    460         "nip46_admission",
    461         "nip46_authorization",
    462         "nip46_replay",
    463         "nip46_verification",
    464         "nip46_work",
    465         "nip46_wave_080_a",
    466         "nip46_wave_080_b",
    467         "operations_v1",
    468         "process_v1",
    469         "provider_contract",
    470         "provider_credential",
    471         "provider_envelope",
    472         "provider_executor",
    473         "provider_local_signer",
    474         "provider_verification",
    475         "runtime_context",
    476         "runtime_foundation",
    477         "runtime_supervision",
    478         "status_v1",
    479         "system_doctor",
    480         "transport_nostr_adapter",
    481         "state_catalog",
    482         "state_admin",
    483         "state_completion",
    484         "state_config",
    485         "state_connection",
    486         "state_delivery",
    487         "state_discovery",
    488         "state_governance",
    489         "state_host",
    490         "state_maintenance",
    491         "state_metadata",
    492         "state_repository",
    493         "state_recovery",
    494         "state_request",
    495         "state_response",
    496     ] {
    497         assert!(
    498             !PUBLIC_API.contains(&format!("pub mod myc::{module}")),
    499             "implementation module `{module}` became public"
    500         );
    501         assert!(
    502             !PUBLIC_API.contains(&format!("myc::{module}::")),
    503             "implementation module `{module}` leaked into the public API"
    504         );
    505     }
    506 
    507     for forbidden in [
    508         "sqlx::",
    509         "serde::",
    510         "serde_json::",
    511         "futures_util::",
    512         "toml::",
    513         "url::",
    514         "nostr::",
    515         "radroots_secrets::",
    516         "radroots_service_host::",
    517         "TaskSupervisor",
    518         "SqlitePool",
    519         "SqliteConnection",
    520         "std::io::Error",
    521     ] {
    522         assert!(
    523             !PUBLIC_API.contains(forbidden),
    524             "implementation-owned public type `{forbidden}` escaped"
    525         );
    526     }
    527 }
    528 
    529 #[test]
    530 fn status_cache_is_passive_latest_value_and_dependency_neutral() {
    531     for required in [
    532         "CachedServiceStatePublisher<MycCachedStatus>",
    533         "pub struct MycStatusPublisher",
    534         "pub struct MycStatusReader",
    535         "pub struct MycStatusSnapshot",
    536         "pub fn myc_status_cache(",
    537         "status.to_bounded_json()",
    538         ".publish(next.operations)",
    539         ".publish(next.detail)",
    540         "self.inner.snapshot()",
    541         "connection_counts: MycConnectionCountsV1",
    542         "oldest_pending_at_utc: Option<MycStatusUnixSeconds>",
    543         "MYC_STATUS_REASON_CODE_COUNT: usize = 12",
    544     ] {
    545         assert!(STATUS_V1.contains(required), "missing `{required}`");
    546     }
    547     for forbidden in [
    548         "sqlx::",
    549         "std::fs::",
    550         "tokio::spawn",
    551         "spawn_blocking",
    552         "std::time::SystemTime",
    553         "std::env::",
    554         "reqwest::",
    555         "url::Url",
    556         "provider.execute",
    557         "relay.connect",
    558         "dns",
    559     ] {
    560         assert!(!STATUS_V1.contains(forbidden), "found `{forbidden}`");
    561     }
    562     assert!(PUBLIC_API.contains("impl core::clone::Clone for myc::MycStatusReader"));
    563     assert!(!PUBLIC_API.contains("impl core::clone::Clone for myc::MycStatusPublisher"));
    564     assert!(!PUBLIC_API.contains("impl core::clone::Clone for myc::MycStatusSnapshot"));
    565     for required in [
    566         "identity_unavailable",
    567         "database_schema_mismatch",
    568         "database_read_only",
    569         "database_low_disk",
    570         "required_relay_unavailable",
    571         "subscriber_not_active",
    572         "signer_provider_unavailable",
    573         "outbox_invariant_failed",
    574         "publication_backlog_exceeded",
    575         "admin_listener_failed",
    576         "operations_listener_failed",
    577         "shutdown_in_progress",
    578     ] {
    579         assert!(
    580             STATUS_CONTRACT.contains(required),
    581             "status contract is missing `{required}`"
    582         );
    583     }
    584 }
    585 
    586 #[test]
    587 fn step155_tcp_operations_are_exact_passive_and_dependency_neutral() {
    588     let contract: serde_json::Value =
    589         serde_json::from_str(OPERATIONS_CONTRACT).expect("Step 155 operations contract");
    590     assert_eq!(contract["schema"], "radroots.myc.tcp-operations.v1");
    591     assert_eq!(contract["contract_version"], 1);
    592     assert_eq!(contract["step"], 155);
    593     assert_eq!(contract["route_registration_extension"], false);
    594     for required in [
    595         "HostOperationsServer::new(listener, status.operations_cache())",
    596         "MycOperationsCancellationToken",
    597         "radroots_myc_service_phase",
    598         "radroots_myc_service_ready",
    599         "HostOperationsTransportLimits::new(values)",
    600         "HeaderLimitBelowParserFloor",
    601     ] {
    602         assert!(
    603             OPERATIONS_V1.contains(required) || STATUS_V1.contains(required),
    604             "Step 155 implementation is missing `{required}`"
    605         );
    606     }
    607     for forbidden in [
    608         "sqlx::",
    609         "std::fs::",
    610         "tokio::spawn",
    611         "spawn_blocking",
    612         "SystemTime",
    613         "provider.execute",
    614         "relay.connect",
    615         "credential",
    616         "dns",
    617         "route(",
    618         "Router",
    619     ] {
    620         assert!(
    621             !OPERATIONS_V1.contains(forbidden),
    622             "Step 155 adapter gained forbidden authority `{forbidden}`"
    623         );
    624     }
    625     assert!(README.contains("exactly HTTP/1.1 `GET /livez`"));
    626     assert!(README.contains("Requests perform no SQLite"));
    627     assert!(!PUBLIC_API.contains("radroots_service_host::"));
    628 }
    629 
    630 #[test]
    631 fn doctor_boundary_is_closed_bounded_and_dependency_neutral() {
    632     for required in [
    633         "MYC_DOCTOR_CHECK_COUNT: usize = 13",
    634         "MYC_DOCTOR_SUMMARY_MAX_UTF8_BYTES: usize = 256",
    635         "MYC_DOCTOR_REPORT_MAX_UTF8_BYTES: usize = 8_192",
    636         "for definition in CHECK_DEFINITIONS",
    637         "tokio::time::timeout(",
    638         "MycDoctorObservation::Skipped) if !definition.required",
    639         "MycDoctorObservation::Skipped) => MycDoctorCheckStatus::Fail",
    640     ] {
    641         assert!(DOCTOR_V1.contains(required), "missing `{required}`");
    642     }
    643     for forbidden in [
    644         "std::fs::",
    645         "sqlx::",
    646         "reqwest::",
    647         "url::Url",
    648         "std::env::",
    649         "raw_error",
    650         "PathBuf",
    651     ] {
    652         assert!(!DOCTOR_V1.contains(forbidden), "found `{forbidden}`");
    653     }
    654 }
    655 
    656 #[test]
    657 fn step156_diagnostics_are_closed_stderr_only_and_whole_chain_redacted() {
    658     let contract: serde_json::Value =
    659         serde_json::from_str(DIAGNOSTICS_CONTRACT).expect("Step 156 diagnostics contract");
    660     assert_eq!(contract["schema"], "radroots.myc.diagnostics.v1");
    661     assert_eq!(contract["contract_version"], 1);
    662     assert_eq!(contract["step"], 156);
    663     assert_eq!(contract["stream_policy"]["result_data"], "stdout");
    664     assert_eq!(contract["stream_policy"]["logs_and_diagnostics"], "stderr");
    665     assert_eq!(contract["public_error_policy"]["error_source"], "none");
    666     for required in [
    667         "MYC_LOG_RECORD_MAX_UTF8_BYTES: usize = 512",
    668         "Self::Success => 0",
    669         "Self::DoctorRequiredCheckFailed => 6",
    670         "formatter.write_str(\"}\")",
    671         "MycLogRecord::process_result(result)",
    672     ] {
    673         assert!(
    674             DIAGNOSTICS_V1.contains(required) || MAIN.contains(required),
    675             "Step 156 implementation is missing `{required}`"
    676         );
    677     }
    678     assert!(MAIN.contains("eprintln!(\"{}\", MycLogRecord::process_result(result))"));
    679     for forbidden in [
    680         "process::exit",
    681         "{error}",
    682         "source()",
    683         "raw_error",
    684         "std::fs::",
    685         "sqlx::",
    686         "SystemTime",
    687     ] {
    688         assert!(
    689             !DIAGNOSTICS_V1.contains(forbidden) && !MAIN.contains(forbidden),
    690             "Step 156 diagnostic boundary gained `{forbidden}`"
    691         );
    692     }
    693     assert!(
    694         !MAIN
    695             .lines()
    696             .any(|line| line.trim_start().starts_with("println!("))
    697     );
    698     assert!(!SOURCES.join("\n").contains("fn source("));
    699     assert!(!PUBLIC_API.contains("std::io::Error"));
    700 }
    701 
    702 #[test]
    703 fn step157_control_plane_wave_is_machine_bound_native_and_test_only() {
    704     let contract: serde_json::Value = serde_json::from_str(CONTROL_PLANE_WAVE_090_A_CONTRACT)
    705         .expect("Step 157 control-plane wave contract");
    706     assert_eq!(
    707         contract["schema"],
    708         "radroots.myc.control-plane-wave-090-a.v1"
    709     );
    710     assert_eq!(
    711         contract["steps"],
    712         serde_json::json!([152, 153, 154, 155, 156, 157])
    713     );
    714     assert_eq!(contract["gate"]["wave"], "090-a");
    715     assert_eq!(contract["gate"]["complete_after_step"], 157);
    716     assert_eq!(contract["gate"]["rcld_promotion_owner"], 162);
    717     assert!(ROOT.contains(
    718         "#[cfg(all(test, any(target_os = \"linux\", target_os = \"macos\")))]\nmod control_plane_wave_090_a;"
    719     ));
    720     for required in [
    721         "one_parse_offline_doctor",
    722         "required_doctor_failure_exits_6",
    723         "latest_cached_status_publication",
    724         "exact_passive_tcp_routes",
    725         "detailed_status_is_not_tcp_routable",
    726         "prevalidated_cached_value",
    727         "runtime_task_supervision",
    728     ] {
    729         assert!(
    730             CONTROL_PLANE_WAVE_090_A_CONTRACT.contains(required),
    731             "Step 157 corpus is missing `{required}`"
    732         );
    733     }
    734     for forbidden in [
    735         "sqlx::",
    736         "std::fs::",
    737         "std::env::",
    738         "SystemTime",
    739         "reqwest::",
    740         "RelayPool",
    741         "provider_local_signer",
    742         "process::exit",
    743     ] {
    744         assert!(
    745             !CONTROL_PLANE_WAVE_090_A.contains(forbidden),
    746             "Step 157 gate gained forbidden authority `{forbidden}`"
    747         );
    748     }
    749 }
    750 
    751 #[test]
    752 fn step158_runtime_supervision_is_one_owned_bounded_redacted_graph() {
    753     let contract: serde_json::Value = serde_json::from_str(RUNTIME_SUPERVISION_CONTRACT)
    754         .expect("Step 158 runtime-supervision contract");
    755     assert_eq!(contract["schema"], "radroots.myc.runtime-supervision.v1");
    756     assert_eq!(contract["contract_version"], 1);
    757     assert_eq!(contract["step"], 158);
    758     assert_eq!(contract["task_set"]["minimum_count"], 1);
    759     assert_eq!(contract["task_set"]["maximum_count"], 32);
    760     assert_eq!(contract["task_set"]["classification"], "critical");
    761     assert_eq!(
    762         contract["task_set"]["shutdown_phase_assignment"],
    763         "deferred_to_step_159"
    764     );
    765     assert_eq!(contract["task_set"]["detached_tasks"], false);
    766     assert_eq!(
    767         contract["fatal_outcomes"],
    768         serde_json::json!([
    769             "task_returned_error",
    770             "task_panicked",
    771             "unexpected_completion",
    772             "unexpected_cancellation",
    773             "join_failed"
    774         ])
    775     );
    776     assert_eq!(
    777         contract["fatal_effect"]["all_task_joins_observed_before_return"],
    778         true
    779     );
    780     assert_eq!(
    781         contract["deferred"],
    782         serde_json::json!([
    783             "process_panic_hook",
    784             "signal_installation",
    785             "first_signal_graceful_shutdown",
    786             "second_signal_forced_shutdown",
    787             "shutdown_grace_deadline",
    788             "ordered_durability_drain"
    789         ])
    790     );
    791     for required in [
    792         "MYC_CRITICAL_TASK_MAX_COUNT: usize = 32",
    793         ".take(MYC_CRITICAL_TASK_MAX_COUNT + 1)",
    794         "TaskClassification::Critical",
    795         "supervisor.request_cancellation()",
    796         "supervisor.supervise().await",
    797         "MycProcessResult::UnexpectedInternal",
    798         "MycLogRecord::critical_task_failed()",
    799         "MycTaskCancellation([sealed])",
    800         "MycCriticalTask([sealed])",
    801     ] {
    802         assert!(
    803             RUNTIME_SUPERVISION.contains(required),
    804             "Step 158 implementation is missing `{required}`"
    805         );
    806     }
    807     for forbidden in [
    808         "pub use radroots_service_host",
    809         "pub fn cancellation_token",
    810         "pub fn request_cancellation",
    811         "JoinHandle",
    812         "tokio::spawn",
    813         "spawn_blocking",
    814         "signal::",
    815         "process::exit",
    816         "std::time::SystemTime",
    817         "rand::",
    818         "getrandom",
    819         "fn source(",
    820     ] {
    821         assert!(
    822             !RUNTIME_SUPERVISION.contains(forbidden),
    823             "Step 158 boundary gained forbidden authority `{forbidden}`"
    824         );
    825     }
    826     for required in [
    827         "one sealed, bounded critical-task graph",
    828         "task names and handles remain internal",
    829         "The binary owns signal\ninstallation",
    830     ] {
    831         assert!(README.contains(required), "README is missing `{required}`");
    832     }
    833 }
    834 
    835 #[test]
    836 fn step148_response_commit_is_one_atomic_exact_byte_authority() {
    837     let contract: serde_json::Value =
    838         serde_json::from_str(NIP46_RESPONSE_CONTRACT).expect("Step 148 contract");
    839     assert_eq!(contract["schema"], "radroots.myc.nip46-response-commit.v1");
    840     assert_eq!(contract["contract_version"], 1);
    841     assert_eq!(contract["step"], 148);
    842     assert_eq!(contract["schema_version"], 9);
    843     for required in [
    844         "sealed_step147_completion_component",
    845         "independently_signature_verified_canonical_kind_24133_event",
    846         "exact_bound_transport_provider_operation",
    847         "exact_signed_response_bytes_sha256_and_event_id",
    848         "zero_attempt_target_state",
    849         "committed_response_bytes_only",
    850         "completion_without_response_or_job",
    851         "fail_closed_without_repair",
    852         "relay_io_inside_transaction",
    853         "response_reconstruction_on_retry",
    854     ] {
    855         assert!(
    856             NIP46_RESPONSE_CONTRACT.contains(required),
    857             "Step 148 contract is missing `{required}`"
    858         );
    859     }
    860     for required in [
    861         "ServiceSqliteTransaction",
    862         "commit_operation(transaction",
    863         "nip46_signed_responses",
    864         "create_job(",
    865         "read_response_by_operation",
    866         "signed_response_bytes",
    867         "fail_after_completion_for_test",
    868         "fail_after_response_for_test",
    869     ] {
    870         assert!(
    871             NIP46_RESPONSE.contains(required),
    872             "Step 148 implementation is missing `{required}`"
    873         );
    874     }
    875     assert!(!PUBLIC_API.contains("commit_nip46_operation"));
    876     for forbidden in [
    877         "RelayPool",
    878         ".publish(",
    879         "tokio::spawn",
    880         "std::time::SystemTime",
    881         "Timestamp::now",
    882         "rand::",
    883         "getrandom",
    884         "SqlitePool",
    885         "rusqlite",
    886     ] {
    887         assert!(
    888             !NIP46_RESPONSE.contains(forbidden),
    889             "Step 148 gained forbidden authority `{forbidden}`"
    890         );
    891     }
    892 }
    893 
    894 #[test]
    895 fn step221_pending_response_is_atomic_exact_and_nonterminal() {
    896     let contract: serde_json::Value = serde_json::from_str(NIP46_PENDING_RESPONSE_CONTRACT)
    897         .expect("Step 221 pending-response contract");
    898     assert_eq!(contract["schema"], "radroots.myc.nip46-pending-response.v1");
    899     assert_eq!(contract["contract_version"], 1);
    900     assert_eq!(contract["step"], 221);
    901     assert_eq!(contract["state_schema_version"], 12);
    902     assert_eq!(contract["terminal_effects"]["operation_completion"], false);
    903     assert_eq!(contract["terminal_effects"]["session_activation"], false);
    904     for required in [
    905         "immutable_explicit_approval_pending_decision",
    906         "exact_bound_transport_provider_operation",
    907         "exact_committed_pending_response_bytes",
    908         "response_edge_failure_rolls_back_response_and_delivery",
    909         "no_terminal_operation_commit_is_created",
    910         "live_nip46_client_observes_pending_then_continues_after_admin_approval",
    911         "false_terminal_operation_completion",
    912     ] {
    913         assert!(
    914             NIP46_PENDING_RESPONSE_CONTRACT.contains(required),
    915             "Step 221 contract is missing `{required}`"
    916         );
    917     }
    918     for required in [
    919         "commit_nip46_pending_response(&commit)",
    920         "Response::PendingConnection",
    921         "MycNip46DispatchDisposition::PendingApproval",
    922     ] {
    923         assert!(RUNTIME_NIP46.contains(required), "missing `{required}`");
    924     }
    925     for required in [
    926         "CREATE TABLE nip46_pending_responses",
    927         "nip46_signed_responses_guard_pending_insert",
    928         "fail_after_response_for_test",
    929     ] {
    930         assert!(NIP46_RESPONSE.contains(required) || STATE_CATALOG.contains(required));
    931     }
    932 }
    933 
    934 #[test]
    935 fn step147_completion_is_atomic_redacted_and_defers_delivery_authority() {
    936     let contract: serde_json::Value =
    937         serde_json::from_str(NIP46_COMPLETION_CONTRACT).expect("Step 147 contract");
    938     assert_eq!(contract["schema"], "radroots.myc.nip46-completion.v1");
    939     assert_eq!(contract["contract_version"], 1);
    940     assert_eq!(contract["step"], 147);
    941     assert_eq!(contract["schema_version"], 8);
    942     for required in [
    943         "radroots.myc.nip46-completion.v1",
    944         "existing_durable_nip46_request",
    945         "existing_service_sqlite_transaction_runner",
    946         "connection_admission_or_logout_session_revocation",
    947         "exact_verified_inner_signed_event_bytes_and_sha256_when_present",
    948         "protected_provider_output\": \"not_persisted",
    949         "failed_transaction\": \"no_session_or_completion_effect",
    950         "step147_checkpoint\": \"integration_only_not_promotable",
    951         "step147_component\": \"composed_by_step148_atomic_response_commit",
    952         "composition_status\": \"satisfied_on_rcld_080_integration_branch",
    953         "commit_owner\": 148",
    954         "promotion_owner\": 151",
    955         "outer_signed_nip46_response\": 148",
    956         "outbox_and_initial_attempt_state\": 148",
    957         "outbox_creation",
    958     ] {
    959         assert!(
    960             NIP46_COMPLETION_CONTRACT.contains(required),
    961             "Step 147 contract is missing `{required}`"
    962         );
    963     }
    964     for required in [
    965         "ServiceSqliteTransaction",
    966         "nip46_operation_commits",
    967         "REVOKE_CONNECTION_SQL",
    968         "provider_artifact_sha256",
    969         "ExactReplay",
    970         "fail_after_session_effect_for_test",
    971     ] {
    972         assert!(
    973             NIP46_COMPLETION.contains(required),
    974             "Step 147 implementation is missing `{required}`"
    975         );
    976     }
    977     for forbidden in [
    978         "RelayPool",
    979         ".publish(",
    980         "tokio::spawn",
    981         "std::time::SystemTime",
    982         "Timestamp::now",
    983         "rand::",
    984         "getrandom",
    985         "SqlitePool",
    986         "rusqlite",
    987     ] {
    988         assert!(
    989             !NIP46_COMPLETION.contains(forbidden),
    990             "Step 147 gained forbidden authority `{forbidden}`"
    991         );
    992     }
    993 }
    994 
    995 #[test]
    996 fn step145_work_is_exactly_bound_and_transaction_free() {
    997     for forbidden in [
    998         "sqlx::",
    999         "ServiceSqlite",
   1000         "StateRepository",
   1001         "StateHost",
   1002         "ServiceSqliteTransaction",
   1003         "tokio::spawn",
   1004         "std::time::SystemTime",
   1005         "rand::",
   1006         "getrandom",
   1007         "RelayPool",
   1008     ] {
   1009         assert!(
   1010             !NIP46_WORK.contains(forbidden),
   1011             "Step 145 gained forbidden authority `{forbidden}`"
   1012         );
   1013     }
   1014     for required in [
   1015         "radroots.myc.nip46.decrypt.operation.v1\\\\0",
   1016         "radroots.myc.nip46.decrypt.correlation.v1\\\\0",
   1017         "radroots.myc.provider.operation_binding.v1\\\\0",
   1018         "radroots_nostr_connect::server::required_permission",
   1019         "after_durable_request_admission_returns",
   1020         "alternate_plaintext_to_work_path",
   1021         "custom_methods",
   1022         "provider_execution",
   1023         "response_commit",
   1024         "relay_publication",
   1025     ] {
   1026         assert!(
   1027             NIP46_WORK_CONTRACT.contains(required),
   1028             "Step 145 contract is missing `{required}`"
   1029         );
   1030     }
   1031 }
   1032 
   1033 #[test]
   1034 fn step146_first_wave_gate_is_machine_bound_and_test_only() {
   1035     for required in [
   1036         "radroots.myc.nip46-wave-080-a.v1",
   1037         "nip04_ping_full_pipeline",
   1038         "nip44_ping_full_pipeline",
   1039         "nip44_connect_durable_approval",
   1040         "nip44_sign_event_provider_work",
   1041         "wrong_event_provider_response",
   1042         "wrong_outer_provider_correlation",
   1043         "late_provider_response",
   1044         "wrong_provider_result_shape",
   1045         "conflicting_request_id_reuse",
   1046         "configured_connection_admission_rate_window",
   1047         "existing_myc_state_repository",
   1048         "existing_service_sqlite_transaction_runner",
   1049         "\"complete_after_step\": 146",
   1050         "\"rcld_promotion_owner\": 151",
   1051     ] {
   1052         assert!(
   1053             NIP46_WAVE_080_A_CONTRACT.contains(required),
   1054             "Step 146 corpus is missing `{required}`"
   1055         );
   1056     }
   1057     assert!(ROOT.contains(
   1058         "#[cfg(all(test, any(target_os = \"linux\", target_os = \"macos\")))]\nmod nip46_wave_080_a;"
   1059     ));
   1060     for forbidden in [
   1061         "RelayPool",
   1062         ".publish(",
   1063         "tokio::spawn",
   1064         "std::time::SystemTime",
   1065         "Timestamp::now",
   1066         "rand::",
   1067         "getrandom",
   1068         "SqlitePool",
   1069         "SqliteConnection",
   1070     ] {
   1071         assert!(
   1072             !NIP46_WAVE_080_A.contains(forbidden),
   1073             "Step 146 gate gained forbidden authority `{forbidden}`"
   1074         );
   1075     }
   1076 }
   1077 
   1078 #[test]
   1079 fn step150_admin_adapter_is_closed_typed_and_transport_bounded() {
   1080     assert!(
   1081         ROOT.contains("#[cfg(any(target_os = \"linux\", target_os = \"macos\"))]\nmod admin_v1;")
   1082     );
   1083     assert!(ROOT.contains(
   1084         "#[cfg(any(target_os = \"linux\", target_os = \"macos\"))]\npub use admin_v1::{"
   1085     ));
   1086     for required in [
   1087         "pub const ALL: [Self; 19]",
   1088         "models.len() == 32",
   1089         "operator_route_inventory_is_exact",
   1090         "AdminMutationRequest<Value>",
   1091         "strict_json(bytes)",
   1092         "MycAdminDocumentErrorKind::DuplicateField",
   1093         "MycAdminDocumentErrorKind::NullForbidden",
   1094         "MycAdminHandlerErrorKind::InvalidCursor",
   1095         "MycAdminHandlerErrorKind::OperationIdConflict",
   1096         "original committed response",
   1097         "same route, filters, and snapshot",
   1098         "relay submission or delivery is not implied",
   1099         "all_nineteen_routes_round_trip_over_the_hardened_unix_boundary",
   1100     ] {
   1101         assert!(
   1102             ADMIN_V1.contains(required),
   1103             "Step 150 adapter is missing `{required}`"
   1104         );
   1105     }
   1106     for forbidden in [
   1107         "TcpListener",
   1108         "axum::",
   1109         "warp::",
   1110         "actix",
   1111         "SqlitePool",
   1112         "SqliteConnection",
   1113         "tokio::spawn(async move { handler",
   1114         "SystemTime",
   1115         "rand::",
   1116         "getrandom",
   1117         "process::exit",
   1118     ] {
   1119         assert!(
   1120             !ADMIN_V1.contains(forbidden),
   1121             "Step 150 adapter gained forbidden authority `{forbidden}`"
   1122         );
   1123     }
   1124     for required in [
   1125         "exact 19-route",
   1126         "all 32 model",
   1127         "Raw shared-host routers and JSON values never cross the public",
   1128         "operation_id_conflict",
   1129         "Unit 13\nseals that handler boundary inside the production `MycAdminServer`",
   1130         "Unit 15 alone owns task\nspawning, provider/relay wiring, readiness, reconnect, and phase-aware\nshutdown",
   1131     ] {
   1132         assert!(README.contains(required), "README is missing `{required}`");
   1133     }
   1134 }
   1135 
   1136 #[test]
   1137 fn step159_unit13_control_surfaces_are_sealed_and_machine_bound() {
   1138     let contract: serde_json::Value =
   1139         serde_json::from_str(CONTROL_SURFACES_CONTRACT).expect("control-surface contract");
   1140     assert_eq!(contract["schema"], "radroots.myc.control-surfaces.v1");
   1141     assert_eq!(contract["step"], 159);
   1142     assert_eq!(contract["unit"], 13);
   1143     assert_eq!(contract["admin"]["route_count"], 19);
   1144     assert_eq!(contract["admin"]["model_count"], 32);
   1145     assert_eq!(contract["status"]["publisher_count"], 1);
   1146     assert_eq!(contract["operations"]["active_probe"], false);
   1147     assert_eq!(contract["doctor"]["check_count"], 13);
   1148     assert_eq!(
   1149         contract["deferred"]["authoritative_daemon_task_graph"],
   1150         "unit_15"
   1151     );
   1152     for required in [
   1153         "AdminServer::with_system_entropy(router.into_inner(), limits)",
   1154         ".pointer(\"/resource_limits/admin\")",
   1155         "UnixAdminSocketWriterAuthority::acquire(runtime.context().paths().run())",
   1156         "UnixAdminSocketBinding::bind(authority, runtime.artifacts().admin_socket())",
   1157         "pub struct MycAdminServer",
   1158         "pub struct MycBoundAdminServer",
   1159         "pub struct MycAdminCancellationToken",
   1160     ] {
   1161         assert!(
   1162             ADMIN_V1.contains(required),
   1163             "Unit 13 is missing `{required}`"
   1164         );
   1165     }
   1166     for forbidden in [
   1167         "pub fn into_inner",
   1168         "pub const fn into_inner",
   1169         "pub fn listener",
   1170         "TcpListener",
   1171         "std::process::exit",
   1172     ] {
   1173         assert!(
   1174             !ADMIN_V1.contains(forbidden),
   1175             "Unit 13 exposes forbidden `{forbidden}`"
   1176         );
   1177     }
   1178 }
   1179 
   1180 #[test]
   1181 fn step159_unit14_process_bootstrap_is_secure_bounded_and_daemon_deferred() {
   1182     let process = PROCESS_V1
   1183         .split("#[cfg(test)]")
   1184         .next()
   1185         .expect("production process source");
   1186     let system_doctor = SYSTEM_DOCTOR
   1187         .split("#[cfg(test)]")
   1188         .next()
   1189         .expect("production doctor source");
   1190     assert_eq!(MAIN.matches("parse_myc_cli_v1_from").count(), 1);
   1191     assert_eq!(MAIN.matches("execute_myc_cli_v1").count(), 1);
   1192     for required in [
   1193         "plan_myc_cli_v1(&invocation)",
   1194         "Builder::new_multi_thread()",
   1195         "worker_threads(limits.worker_threads())",
   1196         "max_blocking_threads(limits.blocking_threads())",
   1197         "ServiceBackupManifest::from_canonical_bytes",
   1198         "parsed.digest() != arguments.manifest_sha256()",
   1199         "read_secure_bounded_file(path, maximum)",
   1200         "emit_exact_bytes(manifest.canonical_bytes())",
   1201     ] {
   1202         assert!(
   1203             process.contains(required),
   1204             "Unit 14 process boundary is missing `{required}`"
   1205         );
   1206     }
   1207     assert_eq!(process.matches("Builder::new_multi_thread()").count(), 1);
   1208     for forbidden in [
   1209         "available_parallelism",
   1210         "std::process::exit",
   1211         "path(\"MYC_",
   1212         "tokio::spawn",
   1213         "tokio::task::spawn",
   1214     ] {
   1215         assert!(
   1216             !process.contains(forbidden),
   1217             "Unit 14 process boundary gained `{forbidden}`"
   1218         );
   1219     }
   1220 
   1221     for required in [
   1222         "OFlags::RDONLY | OFlags::NOFOLLOW | OFlags::CLOEXEC | OFlags::NONBLOCK",
   1223         "OFlags::WRONLY",
   1224         "OFlags::CREATE",
   1225         "OFlags::EXCL",
   1226         "Mode::RUSR | Mode::WUSR",
   1227         "normalize_link_count(status.st_nlink) != 1",
   1228         "status.st_uid != geteuid().as_raw()",
   1229         "mode & 0o022 != 0",
   1230         "file.sync_all()",
   1231         "parent.sync_all()",
   1232         "open_parent(&selected.parent)",
   1233     ] {
   1234         assert!(
   1235             CONFIG_LOADER.contains(required),
   1236             "Unit 14 config loader is missing `{required}`"
   1237         );
   1238     }
   1239     for forbidden in ["canonicalize(", "create_dir_all", "from_current_process"] {
   1240         assert!(
   1241             !CONFIG_LOADER.contains(forbidden),
   1242             "Unit 14 config loader gained `{forbidden}`"
   1243         );
   1244     }
   1245 
   1246     for required in [
   1247         "MycDoctorCheckId::PathsPermissions",
   1248         "MycDoctorCheckId::WriterLock",
   1249         "MycDoctorCheckId::SqliteSchema",
   1250         "MycDoctorCheckId::SqliteFreeSpace",
   1251         "MycDoctorCheckId::SqliteIntegrity",
   1252         "MycDoctorCheckId::OutboxInvariants",
   1253         "MycDoctorCheckId::IdentityBinding",
   1254         "MycDoctorCheckId::SignerProvider",
   1255         "MycDoctorCheckId::AdminBindPolicy",
   1256         "MycDoctorCheckId::OperationsBindPolicy",
   1257         "MycDoctorCheckId::NetworkPolicy",
   1258         "MycDoctorCheckId::RequiredRelays",
   1259         "MycDoctorCheckId::ClockSkew",
   1260         "MycDoctorObservation::Skipped",
   1261         "probe_required_relays",
   1262     ] {
   1263         assert!(
   1264             system_doctor.contains(required),
   1265             "Unit 14 doctor adapter is missing `{required}`"
   1266         );
   1267     }
   1268     for forbidden in ["publish(", "format!(\"{error", "to_string()", "source()"] {
   1269         assert!(
   1270             !system_doctor.contains(forbidden),
   1271             "Unit 14 doctor adapter gained `{forbidden}`"
   1272         );
   1273     }
   1274 
   1275     for required in [
   1276         "MycProcessResult::ServiceOrDependencyUnavailable",
   1277         "MycProcessResult::InputOrConfiguration",
   1278     ] {
   1279         assert!(PROCESS_V1_UNSUPPORTED.contains(required));
   1280     }
   1281     for forbidden in [
   1282         "std::fs",
   1283         "sqlx::",
   1284         "AdminClient",
   1285         "tokio::",
   1286         "MycStateHost",
   1287         "MycProviderExecutor",
   1288     ] {
   1289         assert!(
   1290             !PROCESS_V1_UNSUPPORTED.contains(forbidden),
   1291             "unsupported process executor gained `{forbidden}`"
   1292         );
   1293     }
   1294 }
   1295 
   1296 #[test]
   1297 fn step144_authorization_is_configuration_bound_and_reuses_durable_state() {
   1298     for forbidden in [
   1299         "sqlx::",
   1300         "ServiceSqlite",
   1301         "tokio::spawn",
   1302         "std::time::SystemTime",
   1303         "rand::",
   1304         "getrandom",
   1305         "RelayPool",
   1306     ] {
   1307         assert!(
   1308             !NIP46_AUTHORIZATION.contains(forbidden),
   1309             "Step 144 policy projection gained forbidden authority `{forbidden}`"
   1310         );
   1311     }
   1312     for required in [
   1313         "normalized_configuration_bound_in_myc_state_metadata",
   1314         "configured_denied_client_is_direct_denial_without_connection_or_rate_window",
   1315         "configured_trusted_and_unknown_client_admissions_consume_global_and_relay_rate_windows",
   1316         "all_unknown_clients_require_explicit_operator_approval",
   1317         "exact_operator_configured_url_only",
   1318         "separate_configuration_bound_connection_scope",
   1319         "existing_myc_state_repository_and_service_sqlite_transaction",
   1320         "\"new_store_or_limiter\": \"forbidden\"",
   1321     ] {
   1322         assert!(
   1323             NIP46_AUTHORIZATION_CONTRACT.contains(required),
   1324             "Step 144 contract is missing `{required}`"
   1325         );
   1326     }
   1327 }
   1328 
   1329 #[test]
   1330 fn step143_replay_binding_remains_pure_and_reuses_the_durable_authority() {
   1331     for forbidden in [
   1332         "ServiceSqlite",
   1333         "sqlx::",
   1334         "tokio::spawn",
   1335         "std::time::SystemTime",
   1336         "rand::",
   1337         "getrandom",
   1338         "RelayPool",
   1339         "nip04::decrypt",
   1340         "nip44::decrypt",
   1341     ] {
   1342         assert!(
   1343             !NIP46_REPLAY.contains(forbidden),
   1344             "Step 143 gained forbidden authority `{forbidden}`"
   1345         );
   1346     }
   1347     for required in [
   1348         "existing_myc_state_repository_dual_request_and_event_dedup",
   1349         "\"new_replay_store\": \"forbidden\"",
   1350         "\"plaintext_event_cryptographic_binding\"",
   1351         "\"supported_method_admission\"",
   1352         "\"database_mutation\"",
   1353     ] {
   1354         assert!(
   1355             NIP46_REPLAY_CONTRACT.contains(required),
   1356             "Step 143 contract is missing `{required}`"
   1357         );
   1358     }
   1359 }
   1360 
   1361 #[test]
   1362 fn public_errors_remain_crate_owned_redacted_and_source_free() {
   1363     let production = SOURCES.join("\n");
   1364 
   1365     assert!(!production.contains("fn source("));
   1366     for forbidden in [
   1367         "source: std::io::Error",
   1368         "source: sqlx::Error",
   1369         "source: serde_json::Error",
   1370         "source: toml::de::Error",
   1371         "source: url::ParseError",
   1372     ] {
   1373         assert!(
   1374             !production.contains(forbidden),
   1375             "raw error source `{forbidden}` escaped"
   1376         );
   1377     }
   1378 
   1379     let public_error_count = PUBLIC_API
   1380         .lines()
   1381         .filter(|line| line.starts_with("pub struct myc::") && line.ends_with("Error"))
   1382         .count();
   1383     assert_eq!(public_error_count, 36);
   1384     assert!(PUBLIC_API.contains("pub struct myc::MycDoctorError"));
   1385     assert!(PUBLIC_API.contains("pub struct myc::MycConfigApplyError"));
   1386     assert!(PUBLIC_API.contains("pub struct myc::MycAdminOperationError"));
   1387     assert!(PUBLIC_API.contains("pub struct myc::MycAdminServerError"));
   1388     assert!(PUBLIC_API.contains("pub struct myc::MycConfigLoadError"));
   1389     assert!(!PUBLIC_API.contains("pub struct myc::MycRuntimeFoundation {"));
   1390     assert!(!PUBLIC_API.contains("pub struct myc::MycStateHost {"));
   1391 }
   1392 
   1393 #[test]
   1394 fn step142_verification_remains_pure_and_defers_later_authority() {
   1395     for forbidden in [
   1396         "nip04::decrypt",
   1397         "nip44::decrypt",
   1398         "ServiceSqlite",
   1399         "sqlx::",
   1400         "tokio::spawn",
   1401         "std::time::SystemTime",
   1402         "Timestamp::now",
   1403         "RelayPool",
   1404     ] {
   1405         assert!(
   1406             !NIP46_VERIFICATION.contains(forbidden),
   1407             "Step 142 gained forbidden authority `{forbidden}`"
   1408         );
   1409     }
   1410     for required in [
   1411         "\"decryption\": \"deferred_to_step_145\"",
   1412         "\"plaintext_event_binding\": \"deferred_to_step_145\"",
   1413         "\"replay_and_conflicting_reuse\": \"deferred_to_step_143\"",
   1414         "\"authorization\"",
   1415         "\"database_mutation\"",
   1416         "\"relay_publication\"",
   1417     ] {
   1418         assert!(
   1419             NIP46_VERIFICATION_CONTRACT.contains(required),
   1420             "Step 142 contract is missing `{required}`"
   1421         );
   1422     }
   1423 }
   1424 
   1425 #[test]
   1426 fn step149_recovery_and_offline_export_are_bounded_and_non_networked() {
   1427     let contract: serde_json::Value =
   1428         serde_json::from_str(DELIVERY_RECOVERY_EXPORT_CONTRACT).expect("Step 149 contract");
   1429     assert_eq!(
   1430         contract["schema"],
   1431         "radroots.myc.delivery-recovery-export.v1"
   1432     );
   1433     assert_eq!(contract["contract_version"], 1);
   1434     assert_eq!(contract["step"], 149);
   1435     assert_eq!(contract["schema_version"], 9);
   1436     for required in [
   1437         "atomic_response_or_discovery_commit_only",
   1438         "caller_injected_full_jitter_milliseconds",
   1439         "internal_opaque_job_identity_cursor",
   1440         "one_bounded_service_sqlite_transaction_per_batch",
   1441         "signature_verified_canonical_active_response_bytes",
   1442         "signature_verified_canonical_active_discovery_bytes",
   1443         "delivered_desired_restart_promotion",
   1444         "verified_committed_projection",
   1445         "compact_canonical_utf8_json",
   1446         "standalone_signer_delivery_job_creation",
   1447         "final_supervised_startup_loop",
   1448     ] {
   1449         assert!(
   1450             DELIVERY_RECOVERY_EXPORT_CONTRACT.contains(required),
   1451             "Step 149 contract is missing `{required}`"
   1452         );
   1453     }
   1454     for required in [
   1455         "MYC_DELIVERY_RECOVERY_BATCH_MAX_COUNT: usize = 128",
   1456         "READ_INVARIANTS_SQL",
   1457         "recover_delivery_state",
   1458         "verify_response_for_delivery_job",
   1459         "verify_document_for_delivery_job",
   1460         "recover_expired",
   1461         "promote_current_if_desired",
   1462     ] {
   1463         assert!(
   1464             DELIVERY_RECOVERY.contains(required),
   1465             "Step 149 recovery is missing `{required}`"
   1466         );
   1467     }
   1468     for required in [
   1469         "render_offline_nip05",
   1470         "MycNip05ExportSelection::Desired",
   1471         "MycNip05ExportSelection::Current",
   1472         "struct Nip05Output",
   1473         "names: Nip05Names",
   1474         "nip46: Nip46Discovery",
   1475     ] {
   1476         assert!(
   1477             DISCOVERY_STATE.contains(required),
   1478             "Step 149 offline export is missing `{required}`"
   1479         );
   1480     }
   1481     for removed in ["MycDeliveryJobRequest", "create_delivery_job"] {
   1482         assert!(
   1483             !PUBLIC_API.contains(removed),
   1484             "partial delivery authority remains public: `{removed}`"
   1485         );
   1486     }
   1487     for forbidden in [
   1488         "reqwest",
   1489         "RelayPool",
   1490         ".publish(",
   1491         "tokio::spawn",
   1492         "std::time::SystemTime",
   1493         "Timestamp::now",
   1494         "rand::",
   1495         "getrandom",
   1496         "rusqlite",
   1497     ] {
   1498         assert!(
   1499             !DELIVERY_RECOVERY.contains(forbidden),
   1500             "Step 149 recovery gained forbidden authority `{forbidden}`"
   1501         );
   1502     }
   1503 }
   1504 
   1505 #[test]
   1506 fn step159_provider_delivery_is_sealed_exact_and_durability_ordered() {
   1507     let contract: serde_json::Value = serde_json::from_str(PROVIDER_DELIVERY_CONTRACT)
   1508         .expect("Step 159 provider-delivery contract");
   1509     assert_eq!(contract["schema"], "radroots.myc.provider-delivery.v1");
   1510     assert_eq!(contract["contract_version"], 1);
   1511     assert_eq!(contract["step"], 159);
   1512     assert_eq!(contract["unit"], "myc-provider-delivery");
   1513     assert_eq!(
   1514         contract["relay_adapter"]["implementation"],
   1515         "radroots_transport_nostr"
   1516     );
   1517     assert_eq!(
   1518         contract["durable_delivery"]["submitted_transition"],
   1519         "immediately_after_prepare_before_execute"
   1520     );
   1521     for required in [
   1522         "spawn_blocking",
   1523         "OwnedBlockingTask",
   1524         "worker.join(MycProviderExecutionErrorKind::Open).await",
   1525         "handle.abort()",
   1526         "handle.is_finished()",
   1527         "verify_encrypted_provider_response",
   1528         "MycLocalSignerClient",
   1529     ] {
   1530         assert!(
   1531             PROVIDER_EXECUTOR.contains(required),
   1532             "provider executor is missing `{required}`"
   1533         );
   1534     }
   1535     for required in [
   1536         "radroots_transport_nostr",
   1537         "prepare_delivery(request)",
   1538         "execute_prepared_delivery(prepared).await",
   1539         "DeliveryOutcomeKind::Accepted",
   1540         "DeliveryOutcomeKind::Rejected",
   1541         "DeliveryOutcomeKind::Unavailable",
   1542     ] {
   1543         assert!(
   1544             TRANSPORT_NOSTR_ADAPTER.contains(required),
   1545             "transport adapter is missing `{required}`"
   1546         );
   1547     }
   1548     for required in [
   1549         "claim_delivery_target",
   1550         "read_nip46_response",
   1551         "read_discovery_document_for_job",
   1552         "mark_delivery_attempt_submitted",
   1553         "adapter.execute(prepared)",
   1554         "MycDeliveryAttemptOutcome::UnknownAcknowledgement",
   1555         "record_delivery_attempt_outcome",
   1556     ] {
   1557         assert!(
   1558             DELIVERY_WORKER.contains(required),
   1559             "delivery worker is missing `{required}`"
   1560         );
   1561     }
   1562     for forbidden in [
   1563         "pub struct myc::MycProviderExecutor",
   1564         "pub struct myc::MycDeliveryWorker",
   1565         "pub struct myc::MycNostrDeliveryAdapter",
   1566         "radroots_transport_nostr::",
   1567         "radroots_transport::",
   1568     ] {
   1569         assert!(
   1570             !PUBLIC_API.contains(forbidden),
   1571             "sealed delivery authority escaped: `{forbidden}`"
   1572         );
   1573     }
   1574     for source in [PROVIDER_EXECUTOR, TRANSPORT_NOSTR_ADAPTER, DELIVERY_WORKER] {
   1575         for forbidden in [
   1576             "std::time::SystemTime",
   1577             "Timestamp::now",
   1578             "getrandom",
   1579             "rand::",
   1580             "tokio::runtime::Runtime",
   1581             "tokio::spawn(",
   1582         ] {
   1583             assert!(
   1584                 !source.contains(forbidden),
   1585                 "Step 159 provider-delivery gained `{forbidden}`"
   1586             );
   1587         }
   1588     }
   1589 }