Add audit maintenance, verified recovery and reproducible verification
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
parent
820f0ff7b5
commit
3166da1d2e
13 changed files with 413 additions and 5 deletions
26
scripts/verify.sh
Normal file
26
scripts/verify.sh
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
#!/usr/bin/env bash
|
||||
# Full Python and native owner-contract suite; fail if native dependencies are absent.
|
||||
set -euo pipefail
|
||||
cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.."
|
||||
repo_root="$PWD"
|
||||
audit_source="${RTEL_AUDIT_CORE_SOURCE:-$repo_root/../audit-core}"
|
||||
policy_source="${RTEL_FLEX_AUTH_SOURCE:-$repo_root/../flex-auth}"
|
||||
if [[ ! -f "$audit_source/audit_core/ingestion.py" || ! -f "$policy_source/go.mod" ]]; then
|
||||
echo 'Required: sibling audit-core and flex-auth checkouts, or RTEL_AUDIT_CORE_SOURCE / RTEL_FLEX_AUTH_SOURCE.' >&2
|
||||
exit 1
|
||||
fi
|
||||
mkdir -p .cache/verify
|
||||
export UV_CACHE_DIR="$repo_root/.cache/verify/uv"
|
||||
export GOCACHE="$repo_root/.cache/verify/go-build"
|
||||
if [[ ! -x .venv-verify/bin/python ]]; then
|
||||
uv venv --python python3 .venv-verify
|
||||
fi
|
||||
uv pip sync --python .venv-verify/bin/python --require-hashes requirements-runtime.lock
|
||||
go -C "$policy_source" build -mod=readonly -o "$repo_root/.cache/verify/flex-auth" ./cmd/flex-auth
|
||||
export RTEL_AUDIT_CORE_SOURCE="$audit_source"
|
||||
export RTEL_FLEX_AUTH_BINARY="$repo_root/.cache/verify/flex-auth"
|
||||
echo 'Native owner source revisions:'
|
||||
git -C "$audit_source" rev-parse HEAD
|
||||
git -C "$policy_source" rev-parse HEAD
|
||||
.venv-verify/bin/python -m unittest discover -s tests -v
|
||||
.venv-verify/bin/python -m unittest discover -s tests_runtime -v
|
||||
Loading…
Add table
Add a link
Reference in a new issue