source_guards.rs (8199B)
1 use std::fs; 2 use std::path::Path; 3 4 #[test] 5 fn rhi_manifest_has_no_sdk_or_legacy_proof_dependency() { 6 let manifest = read_repo_file("Cargo.toml"); 7 8 for forbidden in [ 9 "radroots_sdk", 10 "radroots_trade_sp1_guest", 11 "radroots_trade_sp1_host", 12 "sp1_verify", 13 "sp1_proving", 14 "sp1_cuda_proving", 15 "reqwest", 16 "libsqlite3-sys", 17 ] { 18 assert!( 19 !manifest.contains(forbidden), 20 "RHI manifest must not retain retired dependency `{forbidden}`" 21 ); 22 } 23 } 24 25 #[test] 26 fn rhi_manifest_exact_pins_radroots_contract() { 27 let manifest: toml::Value = toml::from_str(&read_repo_file("Cargo.toml")).expect("manifest"); 28 let dependencies = manifest["dependencies"] 29 .as_table() 30 .expect("package dependencies"); 31 32 for (name, dependency) in dependencies { 33 if !name.starts_with("radroots_") { 34 continue; 35 } 36 let dependency = dependency 37 .as_table() 38 .unwrap_or_else(|| panic!("{name} must use an explicit dependency table")); 39 assert_eq!( 40 dependency.get("git").and_then(toml::Value::as_str), 41 Some("https://github.com/radrootslabs/lib"), 42 "RHI must source {name} from the governed public Lib repository" 43 ); 44 assert_eq!( 45 dependency.get("rev").and_then(toml::Value::as_str), 46 Some("055096853fca95e15d0f813d33a14aca13be3881"), 47 "RHI must source-lock {name} to the exact promoted Lib revision" 48 ); 49 assert_eq!( 50 dependency.get("version").and_then(toml::Value::as_str), 51 Some("=0.1.0-alpha"), 52 "RHI must exact-pin {name} to the governed event contract release" 53 ); 54 } 55 } 56 57 #[test] 58 fn rhi_release_product_surface_has_no_order_or_receipt_modules() { 59 for forbidden_path in [ 60 "src/features/trade_listing/mod.rs", 61 "src/features/trade_validation_receipt.rs", 62 "src/proof_smoke.rs", 63 "src/remote_prove.rs", 64 ] { 65 assert!( 66 !Path::new(env!("CARGO_MANIFEST_DIR")) 67 .join(forbidden_path) 68 .exists(), 69 "RHI must not retain retired source path `{forbidden_path}`" 70 ); 71 } 72 73 for (path, source) in rust_sources_under("src") { 74 for forbidden in [ 75 "trade_listing", 76 "trade_validation_receipt", 77 "proof_smoke", 78 "remote_prove", 79 "KIND_ORDER", 80 "RadrootsOrder", 81 "radroots_trade::order", 82 "radroots_event_codec::order", 83 "AgreedPendingValidation", 84 "ValidationExpired", 85 "order_acceptance", 86 "KIND_TRADE_VALIDATION_RECEIPT", 87 "validation_receipt_event_build", 88 "verify_validation_receipt_event", 89 "radroots_trade_sp1", 90 "proof_mode", 91 "LocalExecute", 92 "local_execute", 93 ] { 94 assert!( 95 !source.contains(forbidden), 96 "{path} retains retired order or proof surface `{forbidden}`" 97 ); 98 } 99 } 100 } 101 102 #[test] 103 fn rhi_agreement_attestation_retains_only_the_pure_foundation() { 104 let attestation = read_repo_file("src/features/trade_agreement_attestation.rs"); 105 let cli = read_repo_file("src/cli_v1.rs"); 106 107 for required in [ 108 "RHI_AGREEMENT_ATTESTATION_PROTOCOL_ID", 109 "TradeAgreementAttestationPolicy", 110 "LocalStatementHash", 111 "attest_projection_claim", 112 "projection_digest", 113 "RadrootsTradeAttestationResultV1::Valid", 114 "RadrootsTradeAttestationResultV1::Invalid", 115 "TRADE_MUTATION_EVENT_KINDS", 116 "expected_statement_contract_hash", 117 ] { 118 assert!( 119 attestation.contains(required), 120 "agreement attestation foundation must retain release-product requirement `{required}`" 121 ); 122 } 123 124 assert!( 125 !cli.contains("AttestationSmoke") 126 && !cli.contains("ProofSmoke") 127 && !cli.contains("remote-prove"), 128 "RHI CLI must not retain prototype smoke commands" 129 ); 130 } 131 132 #[test] 133 fn rhi_runtime_context_retains_only_governed_artifacts() { 134 let context = read_repo_file("src/runtime_context.rs"); 135 136 assert!(!context.contains("trade-listing")); 137 assert!( 138 context.contains("default_service_instance_artifacts") 139 && context.contains("service.identity.ncrypt"), 140 "RHI path authority must derive exact common and credential artifacts" 141 ); 142 } 143 144 #[test] 145 fn rhi_wave_one_removes_prototype_runtime_and_selection_authority() { 146 for forbidden_path in [ 147 "config.toml", 148 "radroots.lib.source-lock.v1.toml", 149 "src/config.rs", 150 "src/host_nostr.rs", 151 "src/host_runtime.rs", 152 "src/rhi.rs", 153 ] { 154 assert!( 155 !Path::new(env!("CARGO_MANIFEST_DIR")) 156 .join(forbidden_path) 157 .exists(), 158 "RHI must not retain removed wave-one path `{forbidden_path}`" 159 ); 160 } 161 162 for (path, source) in rust_sources_under("src") { 163 for forbidden in [ 164 "load_settings_from_path", 165 "TradeAgreementAttestationRuntime", 166 "TradeAgreementAttestationStatePersistence", 167 "TradeAgreementAttestationSmoke", 168 "handle_smoke_request_bytes", 169 "worker_name", 170 "state.json", 171 "std::env::var(\"RHI_", 172 "std::env::var_os(\"RHI_", 173 "worker_root", 174 "nostr_sdk::Client", 175 "tracing_appender", 176 "tracing_subscriber", 177 ] { 178 assert!( 179 !source.contains(forbidden), 180 "{path} retains removed wave-one authority `{forbidden}`" 181 ); 182 } 183 if source.contains("tokio::signal") { 184 assert_eq!( 185 path, "src/main.rs", 186 "only the Step213 binary-owned process adapter may observe OS signals" 187 ); 188 } 189 } 190 } 191 192 #[test] 193 fn step_198_publication_boundary_has_no_runtime_or_storage_authority() { 194 let source = read_repo_file("src/publication.rs"); 195 let root = read_repo_file("src/lib.rs"); 196 197 assert!(root.contains("mod publication;")); 198 assert!(!root.contains("pub mod publication;")); 199 for forbidden in [ 200 "sqlx::", 201 "radroots_transport", 202 "std::fs", 203 "std::net", 204 "tokio::", 205 "SystemTime", 206 "thread_rng", 207 "OsRng", 208 "PublicationSink", 209 ] { 210 assert!( 211 !source.contains(forbidden), 212 "Step 198 publication authority gained deferred behavior `{forbidden}`" 213 ); 214 } 215 } 216 217 fn read_repo_file(relative_path: &str) -> String { 218 let path = Path::new(env!("CARGO_MANIFEST_DIR")).join(relative_path); 219 fs::read_to_string(path.as_path()) 220 .unwrap_or_else(|error| panic!("failed to read {}: {error}", path.display())) 221 } 222 223 fn rust_sources_under(relative_root: &str) -> Vec<(String, String)> { 224 let root = Path::new(env!("CARGO_MANIFEST_DIR")); 225 let mut paths = Vec::new(); 226 collect_rust_sources(root.join(relative_root).as_path(), &mut paths); 227 paths.sort(); 228 paths 229 .into_iter() 230 .map(|path| { 231 let relative_path = path 232 .strip_prefix(root) 233 .expect("source under manifest root") 234 .to_string_lossy() 235 .replace('\\', "/"); 236 let source = fs::read_to_string(path.as_path()) 237 .unwrap_or_else(|error| panic!("failed to read {}: {error}", path.display())); 238 (relative_path, source) 239 }) 240 .collect() 241 } 242 243 fn collect_rust_sources(path: &Path, paths: &mut Vec<std::path::PathBuf>) { 244 if path.is_file() { 245 if path.extension().and_then(|extension| extension.to_str()) == Some("rs") { 246 paths.push(path.to_path_buf()); 247 } 248 return; 249 } 250 251 for entry in fs::read_dir(path) 252 .unwrap_or_else(|error| panic!("failed to read {}: {error}", path.display())) 253 { 254 let entry = entry.expect("source entry"); 255 collect_rust_sources(entry.path().as_path(), paths); 256 } 257 }