feat(v4): consolidate audited data recovery economic replay and optional archival

This commit is contained in:
ENELIX Agent
2026-10-03 10:40:18 +00:00
parent 6c91d6bcc6
commit 8eb9688942
26 changed files with 1747 additions and 38 deletions
@@ -0,0 +1,28 @@
"""Reproduce the frozen candidate context from the versioned application sources.
No Docker/runtime/secret reads. Existing output is verified, never silently replaced.
"""
from pathlib import Path
import hashlib,json,shutil
PACKAGE=Path(__file__).resolve().parent
ROOT=PACKAGE.parents[1]
def build():
manifest=json.loads((PACKAGE/'RELEASE.json').read_text())
context=PACKAGE/'context'
for name,v in manifest['files'].items():
if Path(name).is_absolute() or '..' in Path(name).parts:raise ValueError('Unsafe source path')
source=ROOT/name;target=context/name
if source.is_symlink() or not source.is_file() or hashlib.sha256(source.read_bytes()).hexdigest()!=v['after']:
raise ValueError('Checked-out source does not match release: '+name)
if target.is_symlink():raise ValueError('Target symlink refused')
if target.exists() and hashlib.sha256(target.read_bytes()).hexdigest()!=v['after']:
raise ValueError('Existing context differs: '+name)
for name in manifest['files']:
target=context/name
if target.exists():continue
target.parent.mkdir(parents=True,exist_ok=True);shutil.copyfile(ROOT/name,target);target.chmod(0o644)
print('Frozen build context verified:',len(manifest['files']),'source files; no installation.')
if __name__=='__main__':build()