sdk

Radroots SDK and bindings
git clone https://radroots.dev/git/sdk.git
Log | Files | Refs | README

radroots_sdk_contract.test.mjs (2776B)


      1 import assert from "node:assert/strict";
      2 import { createHash } from "node:crypto";
      3 import {
      4   copyFileSync,
      5   mkdirSync,
      6   mkdtempSync,
      7   readFileSync,
      8   writeFileSync,
      9 } from "node:fs";
     10 import { tmpdir } from "node:os";
     11 import { dirname, join, resolve } from "node:path";
     12 import { fileURLToPath } from "node:url";
     13 import test from "node:test";
     14 
     15 import {
     16   HISTORICAL_ARTIFACTS,
     17   HISTORICAL_AUTHORITY_PATH,
     18   validateHistoricalAuthority,
     19 } from "./radroots_sdk_contract_lib.mjs";
     20 
     21 const root = resolve(dirname(fileURLToPath(import.meta.url)), "..");
     22 
     23 function fixture() {
     24   const target = mkdtempSync(join(tmpdir(), "radroots-sdk-contract-"));
     25   for (const relative of [
     26     HISTORICAL_AUTHORITY_PATH,
     27     ...HISTORICAL_ARTIFACTS.map((artifact) => artifact.path),
     28   ]) {
     29     const destination = join(target, relative);
     30     mkdirSync(dirname(destination), { recursive: true });
     31     copyFileSync(join(root, relative), destination);
     32   }
     33   return target;
     34 }
     35 
     36 test("checked-in historical authority is exact", () => {
     37   assert.doesNotThrow(() => validateHistoricalAuthority(root));
     38 });
     39 
     40 test("historical authority rejects artifact drift", () => {
     41   const target = fixture();
     42   const artifact = HISTORICAL_ARTIFACTS[0].path;
     43   writeFileSync(join(target, artifact), "tampered\n");
     44   assert.throws(
     45     () => validateHistoricalAuthority(target),
     46     /artifact digest mismatch/,
     47   );
     48 });
     49 
     50 test("historical authority rejects coordinated artifact and manifest drift", () => {
     51   const target = fixture();
     52   const artifact = HISTORICAL_ARTIFACTS[0].path;
     53   const replacement = "coordinated tamper\n";
     54   writeFileSync(join(target, artifact), replacement);
     55   const path = join(target, HISTORICAL_AUTHORITY_PATH);
     56   const manifest = JSON.parse(readFileSync(path, "utf8"));
     57   manifest.artifacts[0].sha256 = createHash("sha256")
     58     .update(replacement)
     59     .digest("hex");
     60   writeFileSync(path, `${JSON.stringify(manifest, null, 2)}\n`);
     61   assert.throws(
     62     () => validateHistoricalAuthority(target),
     63     /artifact 0 identity is invalid/,
     64   );
     65 });
     66 
     67 test("historical authority rejects unknown manifest fields", () => {
     68   const target = fixture();
     69   const path = join(target, HISTORICAL_AUTHORITY_PATH);
     70   const manifest = JSON.parse(readFileSync(path, "utf8"));
     71   manifest.unreviewed = true;
     72   writeFileSync(path, `${JSON.stringify(manifest, null, 2)}\n`);
     73   assert.throws(() => validateHistoricalAuthority(target), /invalid keys/);
     74 });
     75 
     76 test("historical authority rejects public documentation and workflows", () => {
     77   for (const forbidden of ["docs", ".github", ".act"]) {
     78     const target = fixture();
     79     mkdirSync(join(target, forbidden));
     80     assert.throws(
     81       () => validateHistoricalAuthority(target),
     82       { message: `forbidden capsule root exists: ${forbidden}` },
     83     );
     84   }
     85 });