commit 07aa6ea988da5372654bb3d1ee183ac099a77cae
parent 9060f39e16bf9332565bdbdd5640752b48eab286
Author: triesap <tyson@radroots.org>
Date: Mon, 24 Aug 2026 22:34:49 +0000
release: align RHI native evidence inputs
Align the private generator with the final twelve-package Radroots dependency graph and bind the release contract to state schema 11. Add source-lock and workspace-metadata drift checks and remove stale placeholder guidance.
Diffstat:
4 files changed, 21 insertions(+), 6 deletions(-)
diff --git a/README b/README
@@ -826,9 +826,9 @@ name/version/source/checksum identity, so they neither disclose a checkout path
nor vary when the same exact source is built from another directory.
The checked-in systemd instance unit is package material only. Its presence
-does not claim that the current placeholder binary graph is production-ready,
-installed, enabled, or started. Complete service runtime behavior remains with
-the later RHI checkpoints, and promotion remains Step 182 ownership.
+does not claim that the governed daemon is installed, enabled, started, or
+production-activated. Native artifact qualification remains Step 216
+ownership, and promotion remains Step 217 ownership.
Validate the standalone crate through extbuild:
diff --git a/contracts/services_hardening/native_release.v1.json b/contracts/services_hardening/native_release.v1.json
@@ -51,7 +51,7 @@
},
"contract_versions": {
"config": 1,
- "state": 2,
+ "state": 11,
"admin": 1,
"status": 1,
"provider": 1
diff --git a/tests/services_hardening_native_release.rs b/tests/services_hardening_native_release.rs
@@ -70,7 +70,7 @@ fn native_release_contract_and_manifest_metadata_are_exact() {
},
"contract_versions": {
"config": 1,
- "state": 2,
+ "state": 11,
"admin": 1,
"status": 1,
"provider": 1
@@ -164,6 +164,20 @@ fn native_release_contract_and_manifest_metadata_are_exact() {
version = "0.1.0"
})
);
+ let source_lock: toml::Value = toml::from_str(SOURCE_LOCK).expect("source lock");
+ assert_eq!(
+ contract["contract_versions"]["state"].as_u64(),
+ source_lock["contract_versions"]["state"]
+ .as_integer()
+ .and_then(|value| u64::try_from(value).ok())
+ );
+ assert_eq!(
+ contract["contract_versions"]["state"].as_u64(),
+ manifest["workspace"]["metadata"]["radroots"]["service_source_lock"]
+ ["state_contract_version"]
+ .as_integer()
+ .and_then(|value| u64::try_from(value).ok())
+ );
assert_eq!(
manifest["profile"]["release"],
toml::Value::Table(toml::toml! {
diff --git a/tools/xtask/src/main.rs b/tools/xtask/src/main.rs
@@ -19,6 +19,7 @@ const VERSION: &str = "0.1.0";
const REPOSITORY: &str = "https://github.com/radrootslabs/rhi";
const RUST_VERSION: &str = "1.97.1";
const HOST_FEATURE_PROFILE: &str = "service-host";
+const RADROOTS_DEPENDENCY_COUNT: usize = 12;
const SOURCE_LOCK: &str = "radroots.service.source-lock.v2.toml";
const CONFIG_EXAMPLE: &str = "contracts/services_hardening/config.v1.example.toml";
const CONFIG_SCHEMA: &str = "contracts/services_hardening/config.v1.schema.json";
@@ -695,7 +696,7 @@ fn cargo_dependency_revisions(root: &Path) -> Result<BTreeSet<String>, ReleaseEr
.to_owned(),
);
}
- if count != 11 {
+ if count != RADROOTS_DEPENDENCY_COUNT {
return Err(ReleaseError::InvalidSourceLock);
}
Ok(revisions)