feat(v4): consolidate audited data recovery economic replay and optional archival
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
"""Reproduce the frozen candidate context from the versioned application sources.
|
||||
|
||||
No Docker/runtime/secret reads. Existing output is verified, never silently replaced.
|
||||
"""
|
||||
from pathlib import Path
|
||||
import hashlib,json,shutil
|
||||
|
||||
PACKAGE=Path(__file__).resolve().parent
|
||||
ROOT=PACKAGE.parents[1]
|
||||
|
||||
def build():
|
||||
manifest=json.loads((PACKAGE/'RELEASE.json').read_text())
|
||||
context=PACKAGE/'context'
|
||||
for name,v in manifest['files'].items():
|
||||
if Path(name).is_absolute() or '..' in Path(name).parts:raise ValueError('Unsafe source path')
|
||||
source=ROOT/name;target=context/name
|
||||
if source.is_symlink() or not source.is_file() or hashlib.sha256(source.read_bytes()).hexdigest()!=v['after']:
|
||||
raise ValueError('Checked-out source does not match release: '+name)
|
||||
if target.is_symlink():raise ValueError('Target symlink refused')
|
||||
if target.exists() and hashlib.sha256(target.read_bytes()).hexdigest()!=v['after']:
|
||||
raise ValueError('Existing context differs: '+name)
|
||||
for name in manifest['files']:
|
||||
target=context/name
|
||||
if target.exists():continue
|
||||
target.parent.mkdir(parents=True,exist_ok=True);shutil.copyfile(ROOT/name,target);target.chmod(0o644)
|
||||
print('Frozen build context verified:',len(manifest['files']),'source files; no installation.')
|
||||
|
||||
if __name__=='__main__':build()
|
||||
Reference in New Issue
Block a user