commit 52cd39192a9ae55c8aee09c50359e5fb5db34105
parent b5b0602cb7321f7bcbc1308972191bb238261afb
Author: triesap <tyson@radroots.org>
Date: Tue, 25 Aug 2026 08:15:48 +0000
security: enforce standalone boundary gates
- compare the root-only public API with the reviewed baseline
- reject forbidden roots and tracked credential material
- include the boundary gate in release acceptance
- document the standalone extbuild verification command
Diffstat:
4 files changed, 30 insertions(+), 0 deletions(-)
diff --git a/AGENTS.md b/AGENTS.md
@@ -527,6 +527,7 @@ cargo extbuild run -- cargo check --workspace --all-targets --locked
cargo extbuild run -- cargo test --workspace --all-targets --locked
cargo extbuild run -- cargo clippy --workspace --all-targets --locked -- -D warnings
cargo extbuild run -- env RUSTDOCFLAGS=-Dwarnings cargo doc --workspace --no-deps --locked
+cargo extbuild run -- ./scripts/verify-boundaries.sh
cargo extbuild run -- ./scripts/verify-supply-chain.sh
cargo extbuild run -- ./scripts/release-acceptance.sh
```
diff --git a/README b/README
@@ -834,6 +834,7 @@ Validate the standalone crate through extbuild:
```text
cargo extbuild doctor
+cargo extbuild run -- ./scripts/verify-boundaries.sh
cargo extbuild run -- ./scripts/verify-supply-chain.sh
cargo extbuild run -- ./scripts/release-acceptance.sh
cargo extbuild run -- cargo fmt --all --check
diff --git a/scripts/release-acceptance.sh b/scripts/release-acceptance.sh
@@ -13,4 +13,5 @@ cargo clippy --locked --all-targets -- -D warnings
cargo test --locked
cargo test --locked -p rhi_xtask
scripts/verify-supply-chain.sh
+scripts/verify-boundaries.sh
git diff --check
diff --git a/scripts/verify-boundaries.sh b/scripts/verify-boundaries.sh
@@ -0,0 +1,27 @@
+#!/usr/bin/env bash
+set -euo pipefail
+
+repo_root="$(git rev-parse --show-toplevel)"
+cd "$repo_root"
+
+test "$(cargo public-api --version)" = "cargo-public-api 0.52.0"
+temporary_api="$(mktemp)"
+trap 'rm -f "$temporary_api"' EXIT
+cargo +nightly-2026-07-16 public-api --all-features -sss -p rhi >"$temporary_api"
+cmp "$temporary_api" contracts/api_baselines/rhi.txt
+
+for forbidden_root in docs .github .act; do
+ test ! -e "$forbidden_root"
+ test ! -L "$forbidden_root"
+done
+
+if git ls-files | grep -E -i '(^|/)(\.env|id_rsa|id_ed25519|credentials|[^/]+\.(pem|key|p12|pfx|jks|keystore))$' >/dev/null; then
+ echo "boundary_invalid: sensitive credential path is tracked" >&2
+ exit 1
+fi
+if git grep -I -n -E -e '-----BEGIN ([A-Z0-9 ]+ )?PRIVATE KEY-----|AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{36,}|nsec1[023456789acdefghjklmnpqrstuvwxyz]{40,}' -- src >/dev/null; then
+ echo "boundary_invalid: production source contains credential material" >&2
+ exit 1
+fi
+
+echo "boundary ok: root-only API, fresh baseline, no forbidden or credential surface"