dita_v2: port M5 native-artifact provenance UP to canonical upstream
M5 (native_artifact.py + rust_backend build_verified_artifact/verify_artifact hooks) existed ONLY in the uv/exec-refactor worktree. Canonical never received it, so vendor_sync.sh downgraded the vendored copy back to a raw 'cargo build' — the same mechanism by which M1's relock clobbered the bingx_venue telemetry fix and orphaned 6 live positions. Canonical is the source of truth; M5 belongs here. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -16,7 +16,6 @@ import ctypes
|
||||
import json
|
||||
import math
|
||||
import os
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
from .account import AccountProjection
|
||||
@@ -39,6 +38,7 @@ from .contracts import (
|
||||
)
|
||||
from .journal import KernelJournal, MemoryKernelJournal
|
||||
from .mock_venue import MockVenueAdapter
|
||||
from .native_artifact import ArtifactProvenanceError, build_verified_artifact, verify_artifact
|
||||
from .projection import HazelcastProjection
|
||||
from .projection import build_projection
|
||||
from .utils import json_safe
|
||||
@@ -46,10 +46,6 @@ from .venue import VenueAdapter
|
||||
from .zinc_plane import InMemoryZincPlane, ZincPlane
|
||||
|
||||
|
||||
def _repo_root() -> Path:
|
||||
return Path(__file__).resolve().parents[3]
|
||||
|
||||
|
||||
# ── Rust FFI JSON encoding ────────────────────────────────────────────────────
|
||||
#
|
||||
# All JSON that crosses the Python→Rust boundary via ctypes.c_char_p MUST be
|
||||
@@ -127,20 +123,21 @@ def _build_library() -> None:
|
||||
crate_dir = _crate_dir()
|
||||
if not crate_dir.exists():
|
||||
raise FileNotFoundError(f"Missing Rust kernel crate: {crate_dir}")
|
||||
_LOCAL_TARGET_DIR.mkdir(parents=True, exist_ok=True)
|
||||
env = {**os.environ, "CARGO_TARGET_DIR": str(_LOCAL_TARGET_DIR)}
|
||||
subprocess.run(
|
||||
["cargo", "build", "--release", "--manifest-path", str(crate_dir / "Cargo.toml")],
|
||||
cwd=_repo_root(),
|
||||
check=True,
|
||||
env=env,
|
||||
)
|
||||
build_verified_artifact(crate_dir, _LOCAL_TARGET_DIR)
|
||||
|
||||
|
||||
def _ensure_library() -> Path:
|
||||
path = _library_path()
|
||||
if not path.exists():
|
||||
_build_library()
|
||||
path = _library_path()
|
||||
try:
|
||||
verify_artifact(path, _crate_dir())
|
||||
except ArtifactProvenanceError:
|
||||
# A present but stale artifact is a hard startup failure. Rebuilding
|
||||
# in-place here would make the loaded binary depend on mutable runtime
|
||||
# source and would erase the evidence needed for operator rollback.
|
||||
raise
|
||||
return path
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user