feat: add signed numbered module lifecycle
This commit is contained in:
parent
d30d84631d
commit
7673c337fc
18 changed files with 1622 additions and 12 deletions
|
|
@ -0,0 +1,37 @@
|
|||
import assert from 'node:assert/strict'
|
||||
import { readFileSync } from 'node:fs'
|
||||
import test from 'node:test'
|
||||
|
||||
const contract = JSON.parse(readFileSync(new URL('../contracts/module-package-runtime.json', import.meta.url), 'utf8'))
|
||||
const registry = JSON.parse(readFileSync(new URL('../contracts/numbered-ipc-registry.json', import.meta.url), 'utf8'))
|
||||
const rust = readFileSync(new URL('../src-tauri/src/module_package_runtime.rs', import.meta.url), 'utf8')
|
||||
|
||||
test('module packages are signed declarative artifacts rather than executable repositories', () => {
|
||||
assert.equal(contract.schema, 'hololake.module-package-runtime/v1')
|
||||
assert.equal(contract.signature.source_repository_is_executable, false)
|
||||
assert.equal(contract.signature.package_bytes_are_signed_exactly, true)
|
||||
assert.equal(contract.host.arbitrary_native_code, false)
|
||||
assert.equal(contract.host.arbitrary_webview_javascript, false)
|
||||
assert.equal(contract.host.declarative_payload_only, true)
|
||||
assert.equal(contract.rules.self_test_before_active, true)
|
||||
assert.equal(contract.rules.failed_self_test_rolls_back, true)
|
||||
assert.equal(contract.rules.unmount_preserves_user_data, true)
|
||||
})
|
||||
|
||||
test('module lifecycle is reachable only through numbered verified-human routes', () => {
|
||||
const routes = registry.operations.filter((route) => route.module_number === 'HLP-NIPC-MOD-0020')
|
||||
assert.equal(routes.length, 7)
|
||||
assert.deepEqual(routes.map((route) => route.operation_number), [
|
||||
'HLP-NIPC-OP-0063',
|
||||
'HLP-NIPC-OP-0064',
|
||||
'HLP-NIPC-OP-0065',
|
||||
'HLP-NIPC-OP-0066',
|
||||
'HLP-NIPC-OP-0067',
|
||||
'HLP-NIPC-OP-0068',
|
||||
'HLP-NIPC-OP-0069',
|
||||
])
|
||||
assert.ok(routes.every((route) => route.admission === 'VERIFIED_HUMAN_ROUTE'))
|
||||
assert.match(rust, /MINISIGN_ED25519|PublicKey::decode/)
|
||||
assert.match(rust, /module_receipts/)
|
||||
assert.match(rust, /ROLLBACK_PENDING_SELF_TEST/)
|
||||
})
|
||||
Loading…
Reference in a new issue