23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
221 lines
9.2 KiB
JavaScript
221 lines
9.2 KiB
JavaScript
#!/usr/bin/env node
|
|
/**
|
|
* Verify a signed witness manifest against the live tree (ADR-103).
|
|
*
|
|
* Project-agnostic — works without ruflo CLI being installed.
|
|
*
|
|
* Usage:
|
|
* node verify.mjs --manifest <path> [--root <path>] [--json]
|
|
*
|
|
* Exit codes:
|
|
* 0 — signature valid + all fixes pass or drift (marker present)
|
|
* 1 — signature invalid OR any fix regressed/missing (real failure)
|
|
* 2 — bad arguments / file not found OR precondition not met
|
|
* (e.g. @noble/ed25519 not installed, or dist files not built —
|
|
* source-only checkout without `npm ci && npm run build`).
|
|
* Issue #1880: scheduled runners use this to distinguish a
|
|
* "needs install+build" environment from a real verification
|
|
* failure, so we stop filing recurring issues on every cron run.
|
|
*/
|
|
|
|
import { readFileSync, existsSync } from 'node:fs';
|
|
import { resolve, join, sep } from 'node:path';
|
|
import { createHash } from 'node:crypto';
|
|
import { createRequire } from 'node:module';
|
|
import { fileSha256, fileContains } from './lib.mjs';
|
|
|
|
const args = parseArgs(process.argv.slice(2));
|
|
if (!args.manifest) { console.error('--manifest <path> required'); process.exit(2); }
|
|
|
|
const manifestPath = resolve(args.manifest);
|
|
if (!existsSync(manifestPath)) { console.error(`not found: ${manifestPath}`); process.exit(2); }
|
|
|
|
const repoRoot = resolve(args.root ?? process.cwd());
|
|
const asJson = !!args.json;
|
|
|
|
const witness = JSON.parse(readFileSync(manifestPath, 'utf8'));
|
|
|
|
// ─── signature ────────────────────────────────────────────────────
|
|
const sig = await verifySignature(witness, repoRoot);
|
|
|
|
// Issue #1880 — if @noble/ed25519 isn't installed, this is a
|
|
// precondition failure, not a verification failure. Exit 2 so the
|
|
// scheduled runner can distinguish "install needed" from a real
|
|
// regression and stop filing duplicate issues every 12 hours.
|
|
if (sig.reason === 'noble-ed25519-not-installed') {
|
|
if (asJson) {
|
|
console.log(JSON.stringify(
|
|
{ ok: false, precondition: 'noble-ed25519-not-installed', signature: sig },
|
|
null, 2
|
|
));
|
|
}
|
|
process.exit(2);
|
|
}
|
|
|
|
// ─── per-fix marker check ─────────────────────────────────────────
|
|
const fileResults = witness.manifest.fixes.map((fix) => {
|
|
const installed = join(repoRoot, fix.file);
|
|
if (!existsSync(installed)) {
|
|
return { ...fix, status: 'missing', sha256Match: false, markerPresent: false };
|
|
}
|
|
const localSha256 = fileSha256(installed);
|
|
const markerPresent = fileContains(installed, fix.marker);
|
|
const sha256Match = localSha256 === fix.sha256;
|
|
const status = sha256Match && markerPresent ? 'pass'
|
|
: (markerPresent ? 'drift' : 'regressed');
|
|
return { ...fix, status, sha256Match, markerPresent, localSha256 };
|
|
});
|
|
|
|
const summary = {
|
|
pass: fileResults.filter(r => r.status === 'pass').length,
|
|
drift: fileResults.filter(r => r.status === 'drift').length,
|
|
regressed: fileResults.filter(r => r.status === 'regressed').length,
|
|
missing: fileResults.filter(r => r.status === 'missing').length,
|
|
};
|
|
|
|
// Issue #1880 / #2528 — heuristic: if the only missing entries are
|
|
// generated `/dist/` artifacts and no marker regressed, the checkout was
|
|
// source-only (dependencies may be installed, but no build ran). That's a
|
|
// precondition failure, not a regression. Source-file drift is still
|
|
// reported in the JSON summary, but the operator action is the same:
|
|
// install + build before verifying the dist-layer witness entries.
|
|
const allMissing = fileResults.length > 0
|
|
&& summary.missing === fileResults.length;
|
|
const missingResults = fileResults.filter(r => r.status === 'missing');
|
|
const missingOnlyDist = missingResults.length > 0
|
|
&& missingResults.every(r => r.file && (
|
|
r.file.includes(`${sep}dist${sep}`) || r.file.includes('/dist/')
|
|
));
|
|
const referencesDist = fileResults.some(r => r.file && (
|
|
r.file.includes(`${sep}dist${sep}`) || r.file.includes('/dist/')
|
|
));
|
|
if ((allMissing && referencesDist) || (missingOnlyDist && summary.regressed === 0)) {
|
|
if (asJson) {
|
|
console.log(JSON.stringify(
|
|
{ ok: false, precondition: 'dist-not-built', signature: sig, summary },
|
|
null, 2
|
|
));
|
|
} else {
|
|
console.error(
|
|
`verify.mjs: every manifest entry is missing and the manifest references\n` +
|
|
`dist/ artifacts. The checkout appears to be source-only (no build run).\n` +
|
|
`\n` +
|
|
`Fix: from the repo root, run \`npm ci && npm run build\` (or the\n` +
|
|
`equivalent for the workspaces witness markers reference) before\n` +
|
|
`invoking this script. See #1880 for the full diagnosis.`
|
|
);
|
|
}
|
|
process.exit(2);
|
|
}
|
|
|
|
const ok = sig.signatureValid && sig.manifestHashOk && sig.publicKeyReproducible
|
|
&& summary.regressed === 0 && summary.missing === 0;
|
|
|
|
if (asJson) {
|
|
console.log(JSON.stringify({ ok, signature: sig, summary, results: fileResults }, null, 2));
|
|
} else {
|
|
console.log('Manifest signature:');
|
|
console.log(` hash matches: ${sig.manifestHashOk ? 'yes' : 'NO'}`);
|
|
console.log(` public key reproducible: ${sig.publicKeyReproducible ? 'yes' : 'NO'}`);
|
|
console.log(` Ed25519 signature valid: ${sig.signatureValid ? 'yes' : 'NO'}`);
|
|
console.log('');
|
|
console.log(`Summary: pass=${summary.pass} drift=${summary.drift} regressed=${summary.regressed} missing=${summary.missing}`);
|
|
if (summary.regressed > 0) {
|
|
console.log('\nRegressed:');
|
|
for (const r of fileResults.filter(r => r.status === 'regressed')) {
|
|
console.log(` ${r.id} marker missing in ${r.file}`);
|
|
}
|
|
}
|
|
if (summary.missing > 0) {
|
|
console.log('\nMissing files:');
|
|
for (const r of fileResults.filter(r => r.status === 'missing')) {
|
|
console.log(` ${r.id} ${r.file}`);
|
|
}
|
|
}
|
|
}
|
|
|
|
process.exit(ok ? 0 : 1);
|
|
|
|
// ─── ed25519 helpers ─────────────────────────────────────────────
|
|
async function verifySignature(witness, repoRoot) {
|
|
// Probe multiple plausible install roots — pnpm's isolated linker
|
|
// doesn't hoist transitive deps to v3/node_modules, so we also check
|
|
// workspace packages that declare @noble/ed25519 directly. A user's
|
|
// flat npm install satisfies the first probe; pnpm satisfies the latter.
|
|
let ed;
|
|
let probeErr;
|
|
const probes = [
|
|
repoRoot,
|
|
join(repoRoot, 'v3'),
|
|
join(repoRoot, 'v3/@claude-flow/cli'),
|
|
join(repoRoot, 'v3/@claude-flow/plugin-agent-federation'),
|
|
];
|
|
for (const root of probes) {
|
|
try { ed = createRequire(join(root, 'noop.js'))('@noble/ed25519'); break; }
|
|
catch (e) { probeErr = e; }
|
|
}
|
|
if (!ed) {
|
|
// ruflo#1880 — the scheduled 12h verification has bounced off this
|
|
// 6+ times. Spell out the fix in the error message instead of
|
|
// leaving the operator to chase it.
|
|
console.error(
|
|
`verify.mjs: could not load @noble/ed25519 from any of:\n` +
|
|
` ${probes.join('\n ')}\n` +
|
|
` last error: ${probeErr?.message ?? '?'}\n` +
|
|
`\n` +
|
|
`Fix: from the repo root, run \`npm install\` (the dep is declared\n` +
|
|
`in the root package.json under @noble/ed25519). If your runner\n` +
|
|
`is a source-only checkout, your verification pipeline must run\n` +
|
|
`\`npm ci && npm run build\` before invoking this script. See #1880\n` +
|
|
`for the full diagnosis.`
|
|
);
|
|
return {
|
|
manifestHashOk: false,
|
|
publicKeyReproducible: false,
|
|
signatureValid: false,
|
|
// Machine-parseable hint for the scheduled runner so it can
|
|
// distinguish "missing dep" from a real signature failure.
|
|
reason: 'noble-ed25519-not-installed',
|
|
};
|
|
}
|
|
|
|
// noble/ed25519 v2 freezes `etc` and ships sync verify by default — the
|
|
// sha512Sync shim is only needed for v1. Guard the assignment so it works
|
|
// on both major versions (#2274).
|
|
if (!ed.etc.sha512Sync) {
|
|
try {
|
|
ed.etc.sha512Sync = (...m) => { const h = createHash('sha512'); for (const x of m) h.update(x); return h.digest(); };
|
|
} catch {
|
|
// v2 freezes `etc`; assignment is unnecessary because sha512Sync
|
|
// is already wired internally. Swallow the TypeError and continue.
|
|
}
|
|
}
|
|
|
|
const recomputed = createHash('sha256').update(JSON.stringify(witness.manifest)).digest('hex');
|
|
const manifestHashOk = recomputed === witness.integrity.manifestHash;
|
|
const seed = createHash('sha256').update(witness.manifest.gitCommit + ':ruflo-witness/v1').digest();
|
|
const reKey = ed.getPublicKey(seed);
|
|
const publicKeyReproducible = Buffer.from(reKey).toString('hex') === witness.integrity.publicKey;
|
|
const signatureValid = ed.verify(
|
|
Buffer.from(witness.integrity.signature, 'hex'),
|
|
Buffer.from(witness.integrity.manifestHash, 'hex'),
|
|
Buffer.from(witness.integrity.publicKey, 'hex'),
|
|
);
|
|
return { manifestHashOk, publicKeyReproducible, signatureValid };
|
|
}
|
|
|
|
function parseArgs(argv) {
|
|
const out = {};
|
|
for (let i = 0; i < argv.length; i++) {
|
|
const a = argv[i];
|
|
if (a === '--json' || a === '--help') { out[a.slice(2)] = true; continue; }
|
|
if (a.startsWith('--')) {
|
|
const key = a.slice(2);
|
|
const next = argv[i + 1];
|
|
if (next && !next.startsWith('--')) { out[key] = next; i++; }
|
|
else { out[key] = true; }
|
|
}
|
|
}
|
|
return out;
|
|
}
|