sdk

Radroots SDK and bindings
git clone https://radroots.dev/git/sdk.git
Log | Files | Refs | README

commit ef39fc6d21e1e9d082132083f2ef853aa6ae0cae
parent c21b66f4402b934f52d73d8720675d264672ed07
Author: triesap <tyson@radroots.org>
Date:   Tue, 28 Jul 2026 18:14:10 +0000

deps: consume frozen library version

- select the exact 0.1.0-alpha library cohort across SDK dependencies
- make repository-owned versions explicit in the shared architecture contract
- refresh generated architecture projections and the resolved lock graph
- verify architecture policy and the runtime-contract consumer with locked Cargo

Diffstat:
MCargo.lock | 56++++++++++++++++++++++++++++----------------------------
MCargo.toml | 52++++++++++++++++++++++++++--------------------------
Mcrates/runtime_contract_v1/Cargo.toml | 2+-
Mdocs/specs/radroots_crates_release_v1.md | 20+++++++++++++++++---
Mdocs/specs/radroots_crates_release_v1.sha256 | 6+++---
Mdocs/specs/radroots_crates_release_v1.toml | 3++-
Mdocs/specs/radroots_crates_release_v1_inventory.csv | 34+++++++++++++++++-----------------
Mtools/xtask/src/architecture.rs | 38+++++++++++++++++++++++++++-----------
Mtools/xtask/src/check.rs | 2+-
9 files changed, 122 insertions(+), 91 deletions(-)

diff --git a/Cargo.lock b/Cargo.lock @@ -1958,7 +1958,7 @@ version = "0.1.0" [[package]] name = "radroots_authority" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "radroots_event", "radroots_identity", @@ -1967,7 +1967,7 @@ dependencies = [ [[package]] name = "radroots_blossom" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "mediatype", "serde", @@ -1978,7 +1978,7 @@ dependencies = [ [[package]] name = "radroots_core" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "rust_decimal", "serde", @@ -1995,7 +1995,7 @@ dependencies = [ [[package]] name = "radroots_event" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "dto_bindgen", "hex", @@ -2021,7 +2021,7 @@ dependencies = [ [[package]] name = "radroots_event_codec" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "hex", "nostr", @@ -2050,7 +2050,7 @@ dependencies = [ [[package]] name = "radroots_event_index" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "dto_bindgen", "dto_bindgen_core", @@ -2066,7 +2066,7 @@ dependencies = [ [[package]] name = "radroots_event_store" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "getrandom 0.2.17", "hex", @@ -2084,7 +2084,7 @@ dependencies = [ [[package]] name = "radroots_geocoder" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "futures-executor", "hex", @@ -2101,7 +2101,7 @@ dependencies = [ [[package]] name = "radroots_identity" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "k256", "serde", @@ -2118,7 +2118,7 @@ dependencies = [ [[package]] name = "radroots_log" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "chrono", "serde_json", @@ -2130,7 +2130,7 @@ dependencies = [ [[package]] name = "radroots_nostr" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "nostr", "nostr-sdk", @@ -2144,7 +2144,7 @@ dependencies = [ [[package]] name = "radroots_nostr_connect" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "nostr", "serde", @@ -2155,7 +2155,7 @@ dependencies = [ [[package]] name = "radroots_nostr_signer" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "hex", "nostr", @@ -2173,7 +2173,7 @@ dependencies = [ [[package]] name = "radroots_outbox" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "hex", "radroots_event", @@ -2188,7 +2188,7 @@ dependencies = [ [[package]] name = "radroots_protected_store" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "chacha20poly1305", "getrandom 0.2.17", @@ -2200,14 +2200,14 @@ dependencies = [ [[package]] name = "radroots_protocol_contract_v1" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "serde", ] [[package]] name = "radroots_replica_schema" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "dto_bindgen_core", "serde", @@ -2224,7 +2224,7 @@ dependencies = [ [[package]] name = "radroots_replica_store" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "hex", "radroots_replica_schema", @@ -2253,7 +2253,7 @@ dependencies = [ [[package]] name = "radroots_replica_sync" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "base64 0.22.1", "hex", @@ -2286,7 +2286,7 @@ dependencies = [ [[package]] name = "radroots_runtime" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "anyhow", "chacha20poly1305", @@ -2316,7 +2316,7 @@ dependencies = [ [[package]] name = "radroots_runtime_paths" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "serde", "thiserror 1.0.69", @@ -2401,11 +2401,11 @@ dependencies = [ [[package]] name = "radroots_secret_vault" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" [[package]] name = "radroots_sql_core" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "chrono", "futures-executor", @@ -2417,7 +2417,7 @@ dependencies = [ [[package]] name = "radroots_trade" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "base64 0.22.1", "dto_bindgen", @@ -2447,7 +2447,7 @@ dependencies = [ [[package]] name = "radroots_transport" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "serde", "sha2", @@ -2455,7 +2455,7 @@ dependencies = [ [[package]] name = "radroots_transport_nostr" -version = "0.1.0" +version = "0.1.0-alpha" dependencies = [ "futures", "nostr", @@ -2473,7 +2473,7 @@ dependencies = [ [[package]] name = "radroots_transport_publish_protocol" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "radroots_transport", "serde", @@ -2481,7 +2481,7 @@ dependencies = [ [[package]] name = "radroots_transport_reticulum" -version = "1.0.0-alpha.1" +version = "0.1.0-alpha" dependencies = [ "radroots_transport", ] diff --git a/Cargo.toml b/Cargo.toml @@ -48,36 +48,36 @@ unimplemented = "deny" dto_bindgen = { version = "0.1.0" } dto_bindgen_backend_ts = { version = "0.1.0" } dto_bindgen_core = { version = "0.1.0" } -radroots_authority = { version = "=1.0.0-alpha.1", default-features = false } -radroots_blossom = { package = "radroots_blossom", version = "=0.1.0", default-features = false } -radroots_core = { package = "radroots_core", version = "=0.1.0", default-features = false } -radroots_event_store = { version = "=1.0.0-alpha.1", default-features = false } -radroots_event = { package = "radroots_event", version = "=0.1.0", default-features = false } -radroots_event_codec = { package = "radroots_event_codec", version = "=0.1.0", default-features = false } -radroots_event_index = { version = "=1.0.0-alpha.1", default-features = false } -radroots_geocoder = { version = "=1.0.0-alpha.1" } -radroots_identity = { package = "radroots_identity", version = "=0.1.0", default-features = false, features = [ +radroots_authority = { version = "=0.1.0-alpha", default-features = false } +radroots_blossom = { package = "radroots_blossom", version = "=0.1.0-alpha", default-features = false } +radroots_core = { package = "radroots_core", version = "=0.1.0-alpha", default-features = false } +radroots_event_store = { version = "=0.1.0-alpha", default-features = false } +radroots_event = { package = "radroots_event", version = "=0.1.0-alpha", default-features = false } +radroots_event_codec = { package = "radroots_event_codec", version = "=0.1.0-alpha", default-features = false } +radroots_event_index = { version = "=0.1.0-alpha", default-features = false } +radroots_geocoder = { version = "=0.1.0-alpha" } +radroots_identity = { package = "radroots_identity", version = "=0.1.0-alpha", default-features = false, features = [ "std", ] } -radroots_nostr = { package = "radroots_nostr", version = "=0.1.0", default-features = false } -radroots_nostr_connect = { package = "radroots_nostr_connect", version = "=0.1.0", default-features = false } -radroots_nostr_signer = { version = "=1.0.0-alpha.1", default-features = false } -radroots_outbox = { version = "=1.0.0-alpha.1", default-features = false } -radroots_protocol_contract_v1 = { version = "=1.0.0-alpha.1", default-features = false } -radroots_protected_store = { version = "=1.0.0-alpha.1", default-features = false } +radroots_nostr = { package = "radroots_nostr", version = "=0.1.0-alpha", default-features = false } +radroots_nostr_connect = { package = "radroots_nostr_connect", version = "=0.1.0-alpha", default-features = false } +radroots_nostr_signer = { version = "=0.1.0-alpha", default-features = false } +radroots_outbox = { version = "=0.1.0-alpha", default-features = false } +radroots_protocol_contract_v1 = { version = "=0.1.0-alpha", default-features = false } +radroots_protected_store = { version = "=0.1.0-alpha", default-features = false } radroots_runtime_contract_v1 = { path = "crates/runtime_contract_v1", version = "0.1.0", default-features = false } -radroots_secret_vault = { version = "=1.0.0-alpha.1", default-features = false } -radroots_transport = { package = "radroots_transport", version = "=0.1.0", default-features = false } -radroots_transport_publish_protocol = { version = "=1.0.0-alpha.1", default-features = false } -radroots_transport_nostr = { package = "radroots_transport_nostr", version = "=0.1.0", default-features = false } -radroots_transport_reticulum = { version = "=1.0.0-alpha.1", default-features = false } -radroots_replica_store = { version = "=1.0.0-alpha.1", default-features = false } -radroots_replica_schema = { version = "=1.0.0-alpha.1", default-features = false } -radroots_replica_sync = { version = "=1.0.0-alpha.1", default-features = false } -radroots_runtime_paths = { version = "=1.0.0-alpha.1", default-features = false } +radroots_secret_vault = { version = "=0.1.0-alpha", default-features = false } +radroots_transport = { package = "radroots_transport", version = "=0.1.0-alpha", default-features = false } +radroots_transport_publish_protocol = { version = "=0.1.0-alpha", default-features = false } +radroots_transport_nostr = { package = "radroots_transport_nostr", version = "=0.1.0-alpha", default-features = false } +radroots_transport_reticulum = { version = "=0.1.0-alpha", default-features = false } +radroots_replica_store = { version = "=0.1.0-alpha", default-features = false } +radroots_replica_schema = { version = "=0.1.0-alpha", default-features = false } +radroots_replica_sync = { version = "=0.1.0-alpha", default-features = false } +radroots_runtime_paths = { version = "=0.1.0-alpha", default-features = false } radroots_sdk_sql_wasm_runtime = { path = "crates/sql_wasm_runtime", version = "0.1.0-alpha.2" } -radroots_sql_core = { version = "=1.0.0-alpha.1", default-features = false } -radroots_trade = { package = "radroots_trade", version = "=0.1.0", default-features = false, features = [ +radroots_sql_core = { version = "=0.1.0-alpha", default-features = false } +radroots_trade = { package = "radroots_trade", version = "=0.1.0-alpha", default-features = false, features = [ "serde_json", "std", ] } diff --git a/crates/runtime_contract_v1/Cargo.toml b/crates/runtime_contract_v1/Cargo.toml @@ -16,7 +16,7 @@ serde = ["dep:serde", "radroots_protocol_contract_v1/serde"] std = ["radroots_protocol_contract_v1/std"] [dependencies] -radroots_protocol_contract_v1 = { version = "=1.0.0-alpha.1", default-features = false } +radroots_protocol_contract_v1 = { version = "=0.1.0-alpha", default-features = false } serde = { workspace = true, default-features = false, features = [ "alloc", "derive", diff --git a/docs/specs/radroots_crates_release_v1.md b/docs/specs/radroots_crates_release_v1.md @@ -84,7 +84,11 @@ The final review makes the following deliberate changes: 6. **Public codegen features are removed.** `dto-bindgen`, binding generation, WASM wrappers, and fixture switches remain private build/test concerns. 7. **The workspace moves to Cargo resolver 3.** A virtual Rust 2024 workspace MUST explicitly set `resolver = "3"`. 8. **Release V1 uses MSRV 1.97.1.** The patch release is selected rather than 1.97.0 because it contains a compiler miscompilation fix. -9. **Lower crates do not remain permanently lockstep.** All begin at `0.1.0`, but only `radroots` and `radroots_sdk` are an exact lockstep pair; lower packages follow independent SemVer after the first release. +9. **Lower crates do not remain permanently lockstep.** The current + `radrootslabs/lib` development cohort is frozen at `0.1.0-alpha`, while + `radroots` and `radroots_sdk` remain an exact `0.1.0` lockstep pair. Lower + packages may follow independent SemVer only after explicit future authority + ends the temporary library version freeze. ## 4. Non-negotiable architecture invariants @@ -1282,7 +1286,7 @@ Every public package MUST define: ```toml [package] name = "radroots_..." -version = "0.1.0" +version = "<repository-governed exact version>" publish = ["crates-io"] edition.workspace = true rust-version.workspace = true @@ -1312,7 +1316,17 @@ Additional rules: ### 22.1 Initial versions -All 19 packages start at `0.1.0`. This document's “V1” is the architecture specification version, not a claim that Rust APIs are already 1.0-stable. +Every Rust crate in `radrootslabs/lib`, including private build, test, preview, +and support crates, is pinned to exactly `0.1.0-alpha`. Every same-repository +dependency requirement is pinned to exactly `=0.1.0-alpha`. This temporary +cohort is frozen until an explicit future authority changes it; neither normal +development nor release preparation may bump it implicitly. + +The two `radrootslabs/sdk` public packages remain at `0.1.0` under their +independent repository authority. Cross-repository dependencies therefore use +the exact version assigned to the package's owning repository rather than a +single monorepo-wide version. This document's “V1” is the architecture +specification version, not a claim that Rust APIs are already 1.0-stable. ### 22.2 SemVer groups diff --git a/docs/specs/radroots_crates_release_v1.sha256 b/docs/specs/radroots_crates_release_v1.sha256 @@ -1,4 +1,4 @@ -80c81c75b1eeba5a6f835ea49d53a0445f6852ff5b941d309577ffcf574826f5 radroots_crates_release_v1.md -3a6aead840fb14886e95f25f07b9b2fd9136b3daf70b93f199882cf99a54a209 radroots_crates_release_v1.toml -479f4a09dcad343161c9c644cbde18919eb4365cc295c296ed8ea1458e213882 radroots_crates_release_v1_inventory.csv +592082517ef37a9cebec69849b57928e3efda147d2cdb4a48d5551ce77cf2369 radroots_crates_release_v1.md +93843b41c11d2854244eb5518b591e1d8efb8e5f560ccf895dc50e5779b3766f radroots_crates_release_v1.toml +c04ecb0de9143510862da8a2a9039d6aff28136d76cb819eb1bb1a2d8a370355 radroots_crates_release_v1_inventory.csv d47de10be596a4d33fee102a4f0617f66700b49515a75a1f42d62c9710043059 radroots_crates_release_v1.dot diff --git a/docs/specs/radroots_crates_release_v1.toml b/docs/specs/radroots_crates_release_v1.toml @@ -2,7 +2,6 @@ spec_id = "radroots.crates.release.v1" status = "final_architecture" date = "2026-07-26" package_count = 19 -initial_version = "0.1.0" edition = "2024" resolver = "3" rust_version = "1.97.1" @@ -14,6 +13,7 @@ canonical_repositories = [ [repositories.lib] url = "https://github.com/radrootslabs/lib" +version = "0.1.0-alpha" packages = [ "radroots_core", "radroots_identity", @@ -36,6 +36,7 @@ packages = [ [repositories.sdk] url = "https://github.com/radrootslabs/sdk" +version = "0.1.0" packages = ["radroots_sdk", "radroots"] [repository_policy] diff --git a/docs/specs/radroots_crates_release_v1_inventory.csv b/docs/specs/radroots_crates_release_v1_inventory.csv @@ -1,20 +1,20 @@ publish_order_hint,package,crate,repository,tier,platform,initial_version,default_features,features,required_radroots_dependencies,optional_radroots_dependencies,direct_consumers,responsibility,forbidden -1,radroots_core,radroots_core,lib,foundation,no_std + alloc; std feature,0.1.0,std;serde,std;serde,,,radroots_event;radroots_trade;radroots_sdk;radroots,"Foundational value objects and deterministic invariants: decimal, currency, money, percentage, quantity, units, and pricing.","Identifiers, identities, event kinds, networking, persistence, clocks, filesystem paths, process behavior, or application configuration." -2,radroots_identity,radroots_identity,lib,foundation,no_std + alloc; std feature,0.1.0,std;serde,std;serde,,,radroots_event;radroots_signing;radroots_transport;radroots_nostr;radroots_nostr_connect;radroots_sdk;services,"Public identity and account value types: canonical public keys, identity IDs, account IDs, public profiles, and usernames.","Secret keys, key generation, NIP-49 encryption, keyrings, files, SQLite, runtime paths, upstream nostr::Event values, signer sessions, or host account selection." -3,radroots_blossom,radroots_blossom,lib,protocol primitive,no_std + alloc; std feature,0.1.0,std;serde,std;serde,,,radroots_event;radroots_event_codec;radroots_nostr;media clients,"Portable Blossom protocol primitives: canonical blob URLs, hashes, media descriptors, byte-verification typestates, and authorization claims.","HTTP clients, upload scheduling, cache management, filesystem traversal, application media policy, or global authentication state." -4,radroots_protocol,radroots_protocol,lib,versioned wire contract,no_std + alloc; std feature,0.1.0,std;serde,std;serde,,,radroots_event;radroots_signing;radroots_transport;radroots_storage;radroots_sync;radroots_sdk;radrootsd;bindings,"Versioned cross-process and cross-language schemas, capability catalogs, operation descriptors, stable error reports, schema IDs, and structural validation.","Native clients, storage, network I/O, executor/runtime ownership, domain reducers, upstream dependency types, unversioned serialized DTOs, or package names containing protocol generations." -5,radroots_event,radroots_event,lib,domain protocol model,no_std + alloc; std feature,0.1.0,std;serde,std;serde;knowledge,radroots_core;radroots_identity;radroots_blossom;radroots_protocol,,radroots_event_codec;radroots_trade;radroots_signing;radroots_transport;radroots_storage;radroots_sync;radroots_nostr;radroots_sdk;indexers,"Canonical Radroots event-domain models, validated event identifiers, tags, event contracts, authoring drafts, signed/verified typestates, and NIP-01 wire-neutral representations.","Live Nostr clients, relay pools, signing backends, SQLite, outbox claims, retry scheduling, application state, or duplicate trade/order identifier concepts." -6,radroots_event_codec,radroots_event_codec,lib,deterministic algorithm,no_std + alloc where selected features permit; std feature,0.1.0,std;json,std;serde;json;knowledge;manifests,radroots_event;radroots_blossom;radroots_protocol,,radroots_nostr;radroots_storage_sqlite;radroots_transport_nostr;radroots_sync;radroots_sdk;bindings,"Deterministic canonical encoding, decoding, ID/signature verification, contract validation, admission, and manifest generation for Radroots events.","nostr-sdk clients, relay networking, persistence, background work, upstream client errors, or host configuration." -7,radroots_trade,radroots_trade,lib,domain algorithm,no_std + alloc for model/reducer; std feature,0.1.0,std;serde;json,std;serde;json,radroots_core;radroots_identity;radroots_event,,radroots_storage;radroots_sync;radroots_sdk;RHI;applications,"Trade validation, evidence models, deterministic reduction, conflict analysis, and side-effect-free workflow plans over the canonical event trade model.","A second TradeId definition, actor authorization, signers, event-store access, SQLx, filesystem state, transport delivery, outbox mutation, or process scheduling." -8,radroots_signing,radroots_signing,lib,host SPI,no_std + alloc core; std feature,0.1.0,std;serde,std;serde,radroots_identity;radroots_event;radroots_protocol,,radroots_nostr;radroots_sync;radroots_sdk;CLI;Studio;FFI hosts,"Object-safe author/signing SPI, actor provenance, authorization checks, requests, receipts, progress, capabilities, and normalized signing errors.","Raw secret-key ownership, keyrings, relay networking, NIP-46 session persistence, SQL, UI prompts, or executor creation." -9,radroots_transport,radroots_transport,lib,network SPI,no_std + alloc data model; std feature,0.1.0,std;serde,std;serde,radroots_identity;radroots_event;radroots_protocol,,radroots_storage;radroots_transport_nostr;radroots_sync;radroots_sdk;services;future adapters,"Transport-neutral target identities, capability/status models, source and sink SPIs, delivery/fetch policies, bounded requests, provenance, and normalized outcomes.","Closed enums that prevent new transports, Reticulum-specific constants, Nostr URLs at the generic root, storage/outbox access, retries, scheduler ownership, or silent fallback." -10,radroots_nostr,radroots_nostr,lib,protocol adapter,no_std + alloc for conversion surface; std feature,0.1.0,std;events,std;events;signing;nip17;blossom,radroots_identity;radroots_event;radroots_event_codec,radroots_signing;radroots_blossom,radroots_nostr_connect;radroots_transport_nostr;radroots_sdk;Myc;radrootsd,"Portable conversion between Radroots native event/identity types and Nostr protocol types, typed NIP helpers, and concrete local signing adapters; no live relay client.","nostr-sdk relay pools, reqwest clients, runtime ownership, broad aliases of upstream nostr types at the root, account persistence, or outbox orchestration." -11,radroots_nostr_connect,radroots_nostr_connect,lib,security protocol,std for v1; protocol data kept portable,0.1.0,serde,serde,radroots_identity;radroots_event;radroots_nostr;radroots_protocol,,radroots_sdk;Myc;remote signer tooling,"Nostr Connect/NIP-46 URIs, methods, permissions, requests, responses, client/server state machines, timeout-independent protocol validation, and normalized errors.","Relay-pool implementation, secret persistence, approval UI, global sessions, Tokio runtime ownership, or Myc-specific service storage." -12,radroots_secrets,radroots_secrets,lib,security SPI,no_std + alloc core; std adapters,0.1.0,std;serde,std;serde;memory;file;keyring,,,radroots_storage_sqlite;radroots_sdk;signing hosts;services,"Secret references, provider and key-wrapping SPIs, versioned encrypted envelopes, zeroization-safe secret handling, and explicit memory/file/keyring adapters.","Public secret bytes, Clone/Debug/Serialize for secret-bearing values, identity profiles, domain tables, arbitrary key/value storage, hidden key generation, or process-global vaults." -13,radroots_storage,radroots_storage,lib,storage SPI,std for v1,0.1.0,memory;serde,memory;serde,radroots_event;radroots_trade;radroots_transport;radroots_protocol,,radroots_storage_sqlite;radroots_sync;radroots_sdk;indexers;tests;future backends,"Backend-neutral canonical event, operation journal, outbox, transport evidence, projection, private-artifact metadata, backup, status, and atomic commit interfaces, plus an in-memory reference backend.","SQL text, SQLx pools or transactions, filesystem paths, application UI state, concrete retry loops, Nostr clients, or unconstrained raw key/value escape hatches." -14,radroots_storage_sqlite,radroots_storage_sqlite,lib,native storage backend,std-only native backend,0.1.0,,,radroots_storage;radroots_event_codec;radroots_secrets,,radroots_sdk;CLI;Studio;mobile/FFI,"SQLite implementation of the storage SPIs with schema migration, WAL, locking, integrity, backup/restore, crash recovery, and encrypted private storage.","Public SqlitePool/Connection/Transaction handles, caller-supplied arbitrary SQL, Studio state, global connection pools, runtime installation, or silent schema downgrade." -15,radroots_transport_nostr,radroots_transport_nostr,lib,native network adapter,std-only; Tokio implementation detail in v1,0.1.0,,,radroots_transport;radroots_nostr;radroots_event_codec;radroots_protocol,,radroots_sdk;CLI;radrootsd;advanced hosts,"Concrete Nostr EventSource/EventSink implementation: relay URL policy, connection, NIP-42 authentication, bounded fetch pages, delivery, status, and relay-outcome normalization.","Event-store ingestion, outbox claiming, retry scheduling, projection refresh, global relay clients, direct SQL, or transport fallback." -16,radroots_sync,radroots_sync,lib,local-first orchestration,std-only in v1; executor-neutral public API,0.1.0,serde,serde,radroots_event;radroots_event_codec;radroots_signing;radroots_transport;radroots_storage;radroots_trade;radroots_protocol,,radroots_sdk;CLI;Studio;mobile/FFI;advanced hosts,"Shared pull, verification, canonical admission, duplicate handling, projection refresh, outbox signing/delivery, status, and retry-decision orchestration without owning scheduling.","Creating an executor, spawning hidden workers, installing timers globally, owning process lifecycle, storing UI state, or transport-specific branches outside adapters." -17,radroots_geonames,radroots_geonames,lib,concrete data provider,std-only,0.1.0,,,,,radroots_sdk;CLI;geocoding applications,"GeoNames asset specification, authenticated/integrity-checked acquisition, database lifecycle, and forward/reverse locality lookup using provider-owned types.","Generic multi-provider abstraction before a second provider exists, runtime-path policy, hidden downloads, SDK configuration types, SQLx/reqwest types in the public API, or test-fixture features." +1,radroots_core,radroots_core,lib,foundation,no_std + alloc; std feature,0.1.0-alpha,std;serde,std;serde,,,radroots_event;radroots_trade;radroots_sdk;radroots,"Foundational value objects and deterministic invariants: decimal, currency, money, percentage, quantity, units, and pricing.","Identifiers, identities, event kinds, networking, persistence, clocks, filesystem paths, process behavior, or application configuration." +2,radroots_identity,radroots_identity,lib,foundation,no_std + alloc; std feature,0.1.0-alpha,std;serde,std;serde,,,radroots_event;radroots_signing;radroots_transport;radroots_nostr;radroots_nostr_connect;radroots_sdk;services,"Public identity and account value types: canonical public keys, identity IDs, account IDs, public profiles, and usernames.","Secret keys, key generation, NIP-49 encryption, keyrings, files, SQLite, runtime paths, upstream nostr::Event values, signer sessions, or host account selection." +3,radroots_blossom,radroots_blossom,lib,protocol primitive,no_std + alloc; std feature,0.1.0-alpha,std;serde,std;serde,,,radroots_event;radroots_event_codec;radroots_nostr;media clients,"Portable Blossom protocol primitives: canonical blob URLs, hashes, media descriptors, byte-verification typestates, and authorization claims.","HTTP clients, upload scheduling, cache management, filesystem traversal, application media policy, or global authentication state." +4,radroots_protocol,radroots_protocol,lib,versioned wire contract,no_std + alloc; std feature,0.1.0-alpha,std;serde,std;serde,,,radroots_event;radroots_signing;radroots_transport;radroots_storage;radroots_sync;radroots_sdk;radrootsd;bindings,"Versioned cross-process and cross-language schemas, capability catalogs, operation descriptors, stable error reports, schema IDs, and structural validation.","Native clients, storage, network I/O, executor/runtime ownership, domain reducers, upstream dependency types, unversioned serialized DTOs, or package names containing protocol generations." +5,radroots_event,radroots_event,lib,domain protocol model,no_std + alloc; std feature,0.1.0-alpha,std;serde,std;serde;knowledge,radroots_core;radroots_identity;radroots_blossom;radroots_protocol,,radroots_event_codec;radroots_trade;radroots_signing;radroots_transport;radroots_storage;radroots_sync;radroots_nostr;radroots_sdk;indexers,"Canonical Radroots event-domain models, validated event identifiers, tags, event contracts, authoring drafts, signed/verified typestates, and NIP-01 wire-neutral representations.","Live Nostr clients, relay pools, signing backends, SQLite, outbox claims, retry scheduling, application state, or duplicate trade/order identifier concepts." +6,radroots_event_codec,radroots_event_codec,lib,deterministic algorithm,no_std + alloc where selected features permit; std feature,0.1.0-alpha,std;json,std;serde;json;knowledge;manifests,radroots_event;radroots_blossom;radroots_protocol,,radroots_nostr;radroots_storage_sqlite;radroots_transport_nostr;radroots_sync;radroots_sdk;bindings,"Deterministic canonical encoding, decoding, ID/signature verification, contract validation, admission, and manifest generation for Radroots events.","nostr-sdk clients, relay networking, persistence, background work, upstream client errors, or host configuration." +7,radroots_trade,radroots_trade,lib,domain algorithm,no_std + alloc for model/reducer; std feature,0.1.0-alpha,std;serde;json,std;serde;json,radroots_core;radroots_identity;radroots_event,,radroots_storage;radroots_sync;radroots_sdk;RHI;applications,"Trade validation, evidence models, deterministic reduction, conflict analysis, and side-effect-free workflow plans over the canonical event trade model.","A second TradeId definition, actor authorization, signers, event-store access, SQLx, filesystem state, transport delivery, outbox mutation, or process scheduling." +8,radroots_signing,radroots_signing,lib,host SPI,no_std + alloc core; std feature,0.1.0-alpha,std;serde,std;serde,radroots_identity;radroots_event;radroots_protocol,,radroots_nostr;radroots_sync;radroots_sdk;CLI;Studio;FFI hosts,"Object-safe author/signing SPI, actor provenance, authorization checks, requests, receipts, progress, capabilities, and normalized signing errors.","Raw secret-key ownership, keyrings, relay networking, NIP-46 session persistence, SQL, UI prompts, or executor creation." +9,radroots_transport,radroots_transport,lib,network SPI,no_std + alloc data model; std feature,0.1.0-alpha,std;serde,std;serde,radroots_identity;radroots_event;radroots_protocol,,radroots_storage;radroots_transport_nostr;radroots_sync;radroots_sdk;services;future adapters,"Transport-neutral target identities, capability/status models, source and sink SPIs, delivery/fetch policies, bounded requests, provenance, and normalized outcomes.","Closed enums that prevent new transports, Reticulum-specific constants, Nostr URLs at the generic root, storage/outbox access, retries, scheduler ownership, or silent fallback." +10,radroots_nostr,radroots_nostr,lib,protocol adapter,no_std + alloc for conversion surface; std feature,0.1.0-alpha,std;events,std;events;signing;nip17;blossom,radroots_identity;radroots_event;radroots_event_codec,radroots_signing;radroots_blossom,radroots_nostr_connect;radroots_transport_nostr;radroots_sdk;Myc;radrootsd,"Portable conversion between Radroots native event/identity types and Nostr protocol types, typed NIP helpers, and concrete local signing adapters; no live relay client.","nostr-sdk relay pools, reqwest clients, runtime ownership, broad aliases of upstream nostr types at the root, account persistence, or outbox orchestration." +11,radroots_nostr_connect,radroots_nostr_connect,lib,security protocol,std for v1; protocol data kept portable,0.1.0-alpha,serde,serde,radroots_identity;radroots_event;radroots_nostr;radroots_protocol,,radroots_sdk;Myc;remote signer tooling,"Nostr Connect/NIP-46 URIs, methods, permissions, requests, responses, client/server state machines, timeout-independent protocol validation, and normalized errors.","Relay-pool implementation, secret persistence, approval UI, global sessions, Tokio runtime ownership, or Myc-specific service storage." +12,radroots_secrets,radroots_secrets,lib,security SPI,no_std + alloc core; std adapters,0.1.0-alpha,std;serde,std;serde;memory;file;keyring,,,radroots_storage_sqlite;radroots_sdk;signing hosts;services,"Secret references, provider and key-wrapping SPIs, versioned encrypted envelopes, zeroization-safe secret handling, and explicit memory/file/keyring adapters.","Public secret bytes, Clone/Debug/Serialize for secret-bearing values, identity profiles, domain tables, arbitrary key/value storage, hidden key generation, or process-global vaults." +13,radroots_storage,radroots_storage,lib,storage SPI,std for v1,0.1.0-alpha,memory;serde,memory;serde,radroots_event;radroots_trade;radroots_transport;radroots_protocol,,radroots_storage_sqlite;radroots_sync;radroots_sdk;indexers;tests;future backends,"Backend-neutral canonical event, operation journal, outbox, transport evidence, projection, private-artifact metadata, backup, status, and atomic commit interfaces, plus an in-memory reference backend.","SQL text, SQLx pools or transactions, filesystem paths, application UI state, concrete retry loops, Nostr clients, or unconstrained raw key/value escape hatches." +14,radroots_storage_sqlite,radroots_storage_sqlite,lib,native storage backend,std-only native backend,0.1.0-alpha,,,radroots_storage;radroots_event_codec;radroots_secrets,,radroots_sdk;CLI;Studio;mobile/FFI,"SQLite implementation of the storage SPIs with schema migration, WAL, locking, integrity, backup/restore, crash recovery, and encrypted private storage.","Public SqlitePool/Connection/Transaction handles, caller-supplied arbitrary SQL, Studio state, global connection pools, runtime installation, or silent schema downgrade." +15,radroots_transport_nostr,radroots_transport_nostr,lib,native network adapter,std-only; Tokio implementation detail in v1,0.1.0-alpha,,,radroots_transport;radroots_nostr;radroots_event_codec;radroots_protocol,,radroots_sdk;CLI;radrootsd;advanced hosts,"Concrete Nostr EventSource/EventSink implementation: relay URL policy, connection, NIP-42 authentication, bounded fetch pages, delivery, status, and relay-outcome normalization.","Event-store ingestion, outbox claiming, retry scheduling, projection refresh, global relay clients, direct SQL, or transport fallback." +16,radroots_sync,radroots_sync,lib,local-first orchestration,std-only in v1; executor-neutral public API,0.1.0-alpha,serde,serde,radroots_event;radroots_event_codec;radroots_signing;radroots_transport;radroots_storage;radroots_trade;radroots_protocol,,radroots_sdk;CLI;Studio;mobile/FFI;advanced hosts,"Shared pull, verification, canonical admission, duplicate handling, projection refresh, outbox signing/delivery, status, and retry-decision orchestration without owning scheduling.","Creating an executor, spawning hidden workers, installing timers globally, owning process lifecycle, storing UI state, or transport-specific branches outside adapters." +17,radroots_geonames,radroots_geonames,lib,concrete data provider,std-only,0.1.0-alpha,,,,,radroots_sdk;CLI;geocoding applications,"GeoNames asset specification, authenticated/integrity-checked acquisition, database lifecycle, and forward/reverse locality lookup using provider-owned types.","Generic multi-provider abstraction before a second provider exists, runtime-path policy, hidden downloads, SDK configuration types, SQLx/reqwest types in the public API, or test-fixture features." 18,radroots_sdk,radroots_sdk,sdk,advanced front door,std-only native engine,0.1.0,memory,memory;sqlite;sync;nostr;nip46;local-signing;radrootsd;geonames;knowledge;native;full,radroots_core;radroots_identity;radroots_protocol;radroots_event;radroots_event_codec;radroots_trade;radroots_signing;radroots_transport;radroots_storage,radroots_secrets;radroots_storage_sqlite;radroots_nostr;radroots_nostr_connect;radroots_transport_nostr;radroots_sync;radroots_geonames,CLI;Studio;FFI/mobile;advanced native applications,"Host-neutral asynchronous client engine, product operations, capability reporting, explicit storage/signing/transport composition, diagnostics, backup/restore, and safe commit semantics.","Global runtimes or subscribers, hidden workers, process signals, CLI parsing, UI state, Studio databases, raw SQLx/upstream client types, broad wildcard reexports, or a nominal no_std claim." 19,radroots,radroots,sdk,ordinary-user front door,std-only,0.1.0,client,client;native;nostr;nip46;radrootsd;geonames;knowledge;full,radroots_sdk;radroots_core;radroots_identity;radroots_event;radroots_trade;radroots_transport,,ordinary Rust applications;examples;documentation,"Canonical Rust onboarding package with curated modules, safe defaults, stable convenience builders, domain aggregation, examples, and primary documentation.","A public radroots::sdk namespace, wildcard reexport of radroots_sdk, duplicate engine implementation, CLI binary, hidden network/filesystem/keychain side effects, or exposure of every lower-crate symbol." diff --git a/tools/xtask/src/architecture.rs b/tools/xtask/src/architecture.rs @@ -46,7 +46,6 @@ struct DeviationRecord { #[derive(Debug, Deserialize)] struct ArchitectureIdentity { spec_id: String, - initial_version: String, edition: String, resolver: String, rust_version: String, @@ -59,6 +58,7 @@ struct ArchitectureIdentity { #[derive(Debug, Deserialize)] struct ArchitectureRepository { url: String, + version: String, packages: Vec<String>, } @@ -213,12 +213,15 @@ fn validate_workspace_toolchain( } let workspace_package = &manifest.workspace.package; let public_metadata = &manifest.workspace.metadata.radroots.public_package; - if public_metadata.version != architecture.initial_version - || architecture.initial_version != "0.1.0" - { + let repository = architecture + .repositories + .values() + .find(|repository| repository.url == workspace_package.repository) + .ok_or_else(|| "workspace repository has no architecture allocation".to_owned())?; + if public_metadata.version != repository.version { return Err(format!( - "public package version source {} must match architecture initial_version {}", - public_metadata.version, architecture.initial_version + "public package version source {} must match repository version {}", + public_metadata.version, repository.version )); } if public_metadata.authors != PUBLIC_AUTHORS { @@ -350,7 +353,7 @@ fn validate_public_package_metadata( package, "version", &workspace.workspace.package.version, - &architecture.initial_version, + &repository.version, name, )?; validate_public_manifest_field( @@ -471,6 +474,16 @@ fn validate_public_dependency_versions( .iter() .map(|package| package.name.as_str()) .collect::<BTreeSet<_>>(); + let package_versions = architecture + .repositories + .values() + .flat_map(|repository| { + repository + .packages + .iter() + .map(|package| (package.as_str(), repository.version.as_str())) + }) + .collect::<BTreeMap<_, _>>(); for member in &workspace.workspace.members { let manifest_path = workspace_root.join(member).join("Cargo.toml"); @@ -493,7 +506,7 @@ fn validate_public_dependency_versions( workspace_dependencies, public_packages: &public_packages, local_packages: &local_packages, - initial_version: &architecture.initial_version, + package_versions: &package_versions, }; validate_public_dependency_sections(member, package_name, &manifest, &policy)?; } @@ -505,7 +518,7 @@ struct PublicDependencyPolicy<'a> { workspace_dependencies: Option<&'a toml::value::Table>, public_packages: &'a BTreeSet<&'a str>, local_packages: &'a BTreeSet<&'a str>, - initial_version: &'a str, + package_versions: &'a BTreeMap<&'a str, &'a str>, } fn validate_public_dependency_sections( @@ -600,7 +613,10 @@ fn validate_public_dependency_table( toml::Value::Table(table) => table.get("version").and_then(toml::Value::as_str), _ => None, }; - let exact_version = format!("={}", policy.initial_version); + let governed_version = policy.package_versions.get(dependency_name).ok_or_else(|| { + format!("public dependency {dependency_name} has no repository version authority") + })?; + let exact_version = format!("={governed_version}"); if policy.local_packages.contains(dependency_name) && (dependency_path.is_none() || version != Some(exact_version.as_str())) { @@ -1162,7 +1178,6 @@ adr_required = false fn architecture() -> ArchitectureIdentity { ArchitectureIdentity { spec_id: "radroots.crates.release.v1".to_string(), - initial_version: "0.1.0".to_string(), edition: "2024".to_string(), resolver: "3".to_string(), rust_version: "1.97.1".to_string(), @@ -1172,6 +1187,7 @@ adr_required = false "sdk".to_string(), ArchitectureRepository { url: "https://github.com/radrootslabs/sdk".to_string(), + version: "0.1.0".to_string(), packages: vec!["radroots".to_string()], }, )]), diff --git a/tools/xtask/src/check.rs b/tools/xtask/src/check.rs @@ -2175,7 +2175,7 @@ mod tests { fn write_publication_architecture(root: &Path) { fs::create_dir_all(root.join("docs/specs")).expect("create spec directory"); let mut architecture = format!( - "spec_id = \"radroots.crates.release.v1\"\npackage_count = 19\n\n[repositories.lib]\npackages = [{}]\n\n[repositories.sdk]\npackages = [{}]\n", + "spec_id = \"radroots.crates.release.v1\"\npackage_count = 19\n\n[repositories.lib]\nversion = \"0.1.0-alpha\"\npackages = [{}]\n\n[repositories.sdk]\nversion = \"0.1.0\"\npackages = [{}]\n", toml_strings(&APPROVED_CRATES[..17]), toml_strings(&APPROVED_CRATES[17..]), );