Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .githooks/pre-commit
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,13 @@ info "Checking canonical bilateral gates..."
bash ci/canonical_bilateral_gates.sh
pass "Canonical bilateral gates"

# ---------------------------------------------------------------------------
# 7. Real-code guard: no placeholders, fabricated results or boolean literals
# ---------------------------------------------------------------------------
info "Checking the real-code guard..."
python3 scripts/real_code_guard.py || fail "real-code guard refused the tree (see above)"
pass "Real-code guard"

echo ""
echo -e "${GREEN}All pre-commit checks passed.${NC}"
echo ""
15 changes: 15 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -108,6 +108,21 @@ jobs:
# per crate so the PR critical path is the slowest crate rather than the
# whole workspace in series.
# --------------------------------------------------------------------------
# Every layer's build runs scripts/real_code_guard.py over its own sources. This job runs on
# every change, whatever layers it touches, against main: the guard must equal main's guard
# (only the owner changes it) and the baseline may only lose entries.
real-code-guard:
name: Real-code guard
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Fetch main, the guard's reference
run: git fetch --no-tags --depth=1 origin main
- name: Refuse placeholders, fabricated results and boolean literals
run: |
python3 scripts/real_code_guard.py --self-test
python3 scripts/real_code_guard.py --reference origin/main

rust-gates:
name: Rust gates
needs: [select]
Expand Down
6 changes: 6 additions & 0 deletions crates/dsm-anchor-bench/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,13 @@ fn git(args: &[&str]) -> Option<String> {
}
}

include!("../../scripts/real_code_guard_build.rs");

fn main() {
if let Err(refusal) = real_code_guard() {
eprintln!("{refusal}");
std::process::exit(1);
}
let commit = git(&["rev-parse", "--short=12", "HEAD"]).unwrap_or_else(|| "unknown".into());
let dirty = git(&["status", "--porcelain"])
.map(|s| !s.is_empty())
Expand Down
3 changes: 3 additions & 0 deletions crates/dsm-anchor-core/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,10 @@
use std::env;
use std::path::PathBuf;

include!("../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), Box<dyn std::error::Error>> {
real_code_guard()?;
let out_dir = PathBuf::from(env::var("OUT_DIR")?);

// Use the vendored protoc so no system protoc is required.
Expand Down
7 changes: 7 additions & 0 deletions crates/dsm-anchor-hw-verifier/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
// SPDX-License-Identifier: MIT OR Apache-2.0
// The build refuses what scripts/real_code_guard.py forbids in this crate.
include!("../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), String> {
real_code_guard()
}
7 changes: 7 additions & 0 deletions crates/dsm-anchor-nonsecure-app/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
// SPDX-License-Identifier: MIT OR Apache-2.0
// The build refuses what scripts/real_code_guard.py forbids in this crate.
include!("../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), String> {
real_code_guard()
}
6 changes: 6 additions & 0 deletions crates/dsm-anchor-pico/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,13 @@ use std::fs::File;
use std::io::Write;
use std::path::PathBuf;

include!("../../scripts/real_code_guard_build.rs");

fn main() {
if let Err(refusal) = real_code_guard() {
eprintln!("{refusal}");
std::process::exit(1);
}
let out = PathBuf::from(env::var("OUT_DIR").unwrap());
File::create(out.join("memory.x"))
.unwrap()
Expand Down
6 changes: 6 additions & 0 deletions crates/dsm-anchor-secure-monitor/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,13 @@ use std::env;
use std::path::PathBuf;
use std::process::Command;

include!("../../scripts/real_code_guard_build.rs");

fn main() {
if let Err(refusal) = real_code_guard() {
eprintln!("{refusal}");
std::process::exit(1);
}
println!("cargo:rerun-if-changed=veneer/dsm_sg_veneer.S");
println!("cargo:rerun-if-changed=veneer/dsm_ns_payload.S");
println!("cargo:rerun-if-changed=veneer/dsm_sg_abi.h");
Expand Down
7 changes: 7 additions & 0 deletions crates/dsm-anchor-verifier/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
// SPDX-License-Identifier: MIT OR Apache-2.0
// The build refuses what scripts/real_code_guard.py forbids in this crate.
include!("../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), String> {
real_code_guard()
}
7 changes: 7 additions & 0 deletions crates/dsm-android-anchor/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
// SPDX-License-Identifier: MIT OR Apache-2.0
// The build refuses what scripts/real_code_guard.py forbids in this crate.
include!("../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), String> {
real_code_guard()
}
7 changes: 7 additions & 0 deletions crates/dsm-sphincs/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
// SPDX-License-Identifier: MIT OR Apache-2.0
// The build refuses what scripts/real_code_guard.py forbids in this crate.
include!("../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), String> {
real_code_guard()
}
18 changes: 18 additions & 0 deletions dsm_client/android/app/build.gradle.kts
Original file line number Diff line number Diff line change
Expand Up @@ -296,6 +296,24 @@ tasks.named("preBuild").configure {
dependsOn("failOnJsonOrB64")
}

// The build refuses what scripts/real_code_guard.py forbids anywhere under dsm_client/android:
// a source line holding one of its tokens that the baseline does not already record fails it.
val realCodeGuard = tasks.register<Exec>("realCodeGuard") {
val repoRoot = rootProject.projectDir.parentFile.parentFile
workingDir = repoRoot
commandLine(
"python3",
"scripts/real_code_guard.py",
"--root",
repoRoot.absolutePath,
"--scope",
"dsm_client/android",
)
}
tasks.named("preBuild").configure {
dependsOn(realCodeGuard)
}


// Disable Kotlin incremental compilation for release tasks to avoid flaky cache/daemon issues.
val isCi = (System.getenv("CI") ?: "").equals("true", ignoreCase = true)
Expand Down
3 changes: 3 additions & 0 deletions dsm_client/deterministic_state_machine/dsm/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,10 @@
use std::env;
use std::path::PathBuf;

include!("../../../scripts/real_code_guard_build.rs");

fn main() -> Result<(), Box<dyn std::error::Error>> {
real_code_guard()?;
let out_dir = PathBuf::from(env::var("OUT_DIR")?);
let vendored_include = protoc_bin_vendored::include_path()?;
// Canonical schema location is the repository root at `proto/`.
Expand Down
6 changes: 6 additions & 0 deletions dsm_client/deterministic_state_machine/dsm_sdk/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,13 @@ fn sanitize_generated_prost(out_dir: &std::path::Path) {
// LZ78 / manufacturing-gate math now lives entirely in `security::cdbrw_ffi`
// as pure Rust. No build-time C step is needed.

include!("../../../scripts/real_code_guard_build.rs");

fn main() {
if let Err(refusal) = real_code_guard() {
eprintln!("{refusal}");
std::process::exit(1);
}
// Safety check: prevent release builds with test-only flags
if std::env::var("PROFILE").as_deref() == Ok("release") {
// Check if FORCE_NO_BACKEND is accessible in release builds
Expand Down
4 changes: 4 additions & 0 deletions dsm_client/frontend/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,9 @@
"description": "Production-Ready DSM Wallet React Frontend",
"main": "src/index.tsx",
"scripts": {
"prestart": "python3 ../../scripts/real_code_guard.py --scope dsm_client/frontend",
"start": "cross-env NODE_ENV=development webpack serve --mode development",
"prebuild": "python3 ../../scripts/real_code_guard.py --scope dsm_client/frontend",
"build": "npm run build:full-deploy",
"build:ts": "tsc --project tsconfig.build.json",
"build:webpack": "cross-env NODE_ENV=production NODE_OPTIONS='--max-old-space-size=2048' webpack --mode production",
Expand All @@ -30,12 +32,14 @@
"clean": "rimraf dist",
"lint:security": "eslint src -c .eslintrc.security.json --ext .ts,.tsx",
"security-check": "npm audit --audit-level high && npm run lint:security",
"pretype-check": "python3 ../../scripts/real_code_guard.py --scope dsm_client/frontend",
"type-check": "tsc -p tsconfig.typecheck.json --noEmit",
"lint": "eslint src -c .eslintrc.production.json --ext .ts,.tsx",
"lint:fix": "eslint src -c .eslintrc.production.json --ext .ts,.tsx --fix",
"lint:dev": "eslint 'src/**/*.{ts,tsx}' -c .eslintrc.json",
"format": "prettier --write 'src/**/*.{ts,tsx}'",
"format:check": "prettier --check 'src/**/*.{ts,tsx}'",
"pretest": "python3 ../../scripts/real_code_guard.py --scope dsm_client/frontend",
"test": "cross-env NODE_OPTIONS='--max-old-space-size=4096' jest",
"test:ci": "cross-env CI=1 NODE_OPTIONS='--max-old-space-size=4096' jest --ci",
"test:coverage": "cross-env CI=1 NODE_OPTIONS='--max-old-space-size=4096' jest --coverage --runInBand",
Expand Down
7 changes: 7 additions & 0 deletions dsm_storage_node/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
// SPDX-License-Identifier: MIT OR Apache-2.0
// The build refuses what scripts/real_code_guard.py forbids in this crate.
include!("../scripts/real_code_guard_build.rs");

fn main() -> Result<(), String> {
real_code_guard()
}
Loading
Loading