Some checks failed
email / gates (push) Has been cancelled
nigig-site / Owned paths and honest test contracts (push) Has been cancelled
nigig-site / Cargo check-all-targets (push) Has been cancelled
nigig-site / Cargo clippy-site-owned (push) Has been cancelled
nigig-site / Cargo contained-media-export-fixtures (push) Has been cancelled
nigig-site / Cargo containment-storage-crypto (push) Has been cancelled
nigig-site / Cargo core-clippy (push) Has been cancelled
nigig-site / Cargo core-contracts (push) Has been cancelled
nigig-site / Cargo integration-non-live (push) Has been cancelled
nigig-site / Cargo production-dependency-containment (push) Has been cancelled
nigig-site / Cargo site02-crypto (push) Has been cancelled
nigig-site / Cargo site02-repository (push) Has been cancelled
nigig-site / Cargo site02-store (push) Has been cancelled
nigig-site / Cargo unit (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (macos-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (ubuntu-latest) (push) Has been cancelled
nigig-site / SITE-02 native provider/filesystem (windows-latest) (push) Has been cancelled
nigig-site / SITE-02 desktop runtime and normal shutdown (push) Has been cancelled
nigig-site / SITE-02 migration, recovery, and fault corpus (push) Has been cancelled
nigig-site / Media limits (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Real server interoperability (explicitly skipped until enabled) (push) Has been cancelled
nigig-site / Security and supply-chain baseline (push) Has been cancelled
nigig-site / Release capability gate (push) Has been cancelled
repo hygiene / hygiene (push) Has been cancelled
cad / cad-truth-gates (push) Has been cancelled
cad / cad-core-checks (push) Has been cancelled
cad / cad-consumers (push) Has been cancelled
doc-engine / engine (push) Has been cancelled
doc-engine / coverage (push) Has been cancelled
doc-engine / consumer (push) Has been cancelled
email / email-domain (push) Has been cancelled
email / nigig-email (push) Has been cancelled
email / supply-chain (push) Has been cancelled
nigig-build (CAD) / supply-chain (push) Has been cancelled
nigig-build (CAD) / cad-module (push) Has been cancelled
nigig-build (CAD) / full-crate-check (push) Has been cancelled
nigig-build (CAD) / cad-engine-coverage (push) Has been cancelled
nigig-build (CAD) / doc-workspace-coverage (push) Has been cancelled
nigig-build (CAD) / cad-widget-coverage (push) Has been cancelled
nigig-map / test (push) Has been cancelled
sms / gates (push) Has been cancelled
sms / robius-sms (push) Has been cancelled
sms / android (push) Has been cancelled
sms / nigig-sms (push) Has been cancelled
sms / supply-chain (push) Has been cancelled
spreadsheet / engine-coverage (push) Has been cancelled
spreadsheet / ui-controller-coverage (push) Has been cancelled
traffic / gates (push) Has been cancelled
traffic / nigig-traffic (push) Has been cancelled
traffic / supply-chain (push) Has been cancelled
Thirteen hardening modules (3,079 lines) sat in nigig-site/src/ declared in no
mod statement. They had never been compiled or tested: cargo check never saw
them, and the plan's "implemented in the worktree and pending verification"
status was unverifiable by construction.
Extract the UI-free core into crates/apps/nigig-site-core (scope 5's "Rust core
crate ... testable; safe"; plan 6's target architecture). nigig-site depends on
it and re-exports it, so there is one copy of each module source: the app and
the core's unit tests compile the same files. The core has no Makepad
dependency, so its contracts run on a memory-limited runner.
Compiling that code for the first time found four real defects, all fixed:
- Role/Capability lacked Ord, so every BTreeSet of them failed to compile
(auth.rs)
- CaptureResult::empty never initialised site_id from its site parameter
(ocr_policy.rs)
- negotiate_version(2, 5) agreed on a protocol the peer never offered, which is
the silent downgrade the function exists to prevent (sync_protocol.rs)
- an absurd frame size returned Overflow instead of the actionable budget
breach (media_bounds.rs)
New feature-tranche domain modules, each with unit tests:
- organisation.rs SITE-20 invites, per-site roles, the 4.2 matrix as testable
data, site registry with geofence, settings
- report_pack.rs SITE-21 report numbering, entry status, signatures binding
actor/device/timestamp/document hash, lock and versioning,
multi-site compilation, monthly packs
- site_diary.rs SITE-22 weather with provenance, plant, deliveries, delay
log where a weather delay needs supporting rainfall,
visitors, manpower by trade
- workforce.rs SITE-23 consent-gated registration, tag-only blocklist,
attendance with overtime, QR badges, payroll CSV that never
emits identity, offboarding tombstones
- programme.rs SITE-25 dependencies with cycle detection and rollback,
topological order, critical path, frozen baselines with
slippage, checklists gating approval, snags, RFIs,
variations needing two distinct approvers
- hse.rs SITE-28 append-only incidents, closure requires corrective
action, toolbox talks, inspections, monthly statistics
workflows.rs gains the FR-1.14 Locked state; commands.rs gains a bounded
non-empty text validator shared by the new modules.
CI: the SITE-02 crypto/repository/store lanes pointed at -p nigig-site, where
those suites no longer live; left alone they would have compiled nothing and
reported a vacuous green. Repointed at the core, and added core-contracts and
core-clippy lanes with a ">=100 tests collected" check so a lane cannot pass
vacuously. All six existing Python contract gates still pass.
Auto-purge of worker ID data refuses to run until the scope 18 retention
question is answered rather than inventing a window.
Verified 2026-09-26: cargo test -p nigig-site-core --locked = 175 passed,
0 failed, 1 ignored (needs a live Secret Service session); cargo clippy -p
nigig-site-core --all-targets --no-deps -- -D warnings clean; cargo check -p
nigig-site clean. cargo test -p nigig-site is still killed by SIGKILL compiling
makepad-widgets on a 2 GB host, as recorded in plan 2.1.
EXECUTION_PLAN.md gains a per-tranche status ledger (1a) that states plainly
which tranches are done, domain-only, externally blocked, or not started, and
records that this branch and main diverged at b3a9005 with SITE-03 published
only on main.
49 lines
2.3 KiB
TOML
49 lines
2.3 KiB
TOML
[package]
|
|
name = "nigig-site-core"
|
|
version = "0.1.0"
|
|
edition = "2021"
|
|
description = "Nigig Site core — UI-free domain, storage, and hardening contracts (SITE-02..SITE-19)."
|
|
|
|
# This crate is the scope's "Rust core crate ... shared across platforms;
|
|
# testable; safe" (`construction-site-app-scope.md` §5) and the plan's target
|
|
# architecture boundary (`EXECUTION_PLAN.md` §6). It deliberately depends on no
|
|
# UI framework so the domain, repository, crypto, and hardening contracts can be
|
|
# compiled and unit-tested on a memory-limited runner without building Makepad.
|
|
#
|
|
# There is exactly one copy of each module source: the files live here and
|
|
# `nigig-site` re-exports them, so a production build and a core test build
|
|
# compile the same bytes.
|
|
|
|
[dependencies]
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
chrono = { version = "0.4", features = ["serde"] }
|
|
uuid = { version = "1", features = ["v4", "serde"] }
|
|
robius-directories = { git = "https://github.com/project-robius/robius", rev = "b766e62b0600f5d2ee21cc6995648346fc277bd8" }
|
|
# Fail-closed authenticated storage (see src/crypto.rs and src/repository.rs).
|
|
# `aes-gcm` 0.10 does not propagate its optional zeroization into the AES and
|
|
# GHASH backends, so the feature-only direct pins below deliberately unify those
|
|
# already-transitive crates with their drop-time zeroization support enabled.
|
|
aes-gcm = { version = "0.10", default-features = false, features = ["aes", "alloc", "zeroize"] }
|
|
aes = { version = "0.8.4", features = ["zeroize"] }
|
|
ghash = { version = "0.5.1", features = ["zeroize"] }
|
|
polyval = { version = "0.6.2", features = ["zeroize"] }
|
|
aead = "0.5"
|
|
getrandom = "0.2"
|
|
zeroize = "1"
|
|
keyring-core = "1"
|
|
|
|
# Use one explicit native credential-store provider per desktop platform. The
|
|
# all-in-one `keyring` facade is intentionally not linked by production code.
|
|
[target.'cfg(target_os = "linux")'.dependencies]
|
|
zbus-secret-service-keyring-store = { version = "1", features = ["crypto-rust"] }
|
|
|
|
[target.'cfg(target_os = "macos")'.dependencies]
|
|
apple-native-keyring-store = { version = "1", features = ["keychain"] }
|
|
|
|
[target.'cfg(target_os = "windows")'.dependencies]
|
|
windows-native-keyring-store = { version = "1", default-features = false }
|
|
windows-sys = { version = "0.61.2", features = ["Win32_Foundation", "Win32_Storage_FileSystem"] }
|
|
|
|
[target.'cfg(unix)'.dependencies]
|
|
libc = "0.2"
|