railiance-telemetry/scripts/verify.sh
tegwick 3166da1d2e Add audit maintenance, verified recovery and reproducible verification
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
2026-09-28 11:48:01 +02:00

26 lines
1.3 KiB
Bash

#!/usr/bin/env bash
# Full Python and native owner-contract suite; fail if native dependencies are absent.
set -euo pipefail
cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.."
repo_root="$PWD"
audit_source="${RTEL_AUDIT_CORE_SOURCE:-$repo_root/../audit-core}"
policy_source="${RTEL_FLEX_AUTH_SOURCE:-$repo_root/../flex-auth}"
if [[ ! -f "$audit_source/audit_core/ingestion.py" || ! -f "$policy_source/go.mod" ]]; then
echo 'Required: sibling audit-core and flex-auth checkouts, or RTEL_AUDIT_CORE_SOURCE / RTEL_FLEX_AUTH_SOURCE.' >&2
exit 1
fi
mkdir -p .cache/verify
export UV_CACHE_DIR="$repo_root/.cache/verify/uv"
export GOCACHE="$repo_root/.cache/verify/go-build"
if [[ ! -x .venv-verify/bin/python ]]; then
uv venv --python python3 .venv-verify
fi
uv pip sync --python .venv-verify/bin/python --require-hashes requirements-runtime.lock
go -C "$policy_source" build -mod=readonly -o "$repo_root/.cache/verify/flex-auth" ./cmd/flex-auth
export RTEL_AUDIT_CORE_SOURCE="$audit_source"
export RTEL_FLEX_AUTH_BINARY="$repo_root/.cache/verify/flex-auth"
echo 'Native owner source revisions:'
git -C "$audit_source" rev-parse HEAD
git -C "$policy_source" rev-parse HEAD
.venv-verify/bin/python -m unittest discover -s tests -v
.venv-verify/bin/python -m unittest discover -s tests_runtime -v