File size: 2,218 Bytes
a6a5d8e
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
#!/usr/bin/env python3
"""tools/freeze_manifest.py — compute the frozen-baseline manifest for THIS Space.

Author: Yachay <yachay@szlholdings.dev>  ·  ADDITIVE  ·  Doctrine v11 LOCKED (749/14/163)
Signed-off-by: Yachay <yachay@szlholdings.dev>  ·  cosign keyid: szlholdings-cosign

Run this ONCE on the freeze commit (locally or in the Space repo) to fill the
`critical_file_hashes` in demo_freeze_baseline.manifest.json with real sha256
digests of the critical files that currently exist. The advisory startup check in
szl_demo_freeze.py then compares against these at runtime.

Usage:
    python tools/freeze_manifest.py            # update in place
    python tools/freeze_manifest.py --check    # exit 1 if current files drift
"""
from __future__ import annotations
import hashlib, json, sys
from pathlib import Path

MANIFEST = "demo_freeze_baseline.manifest.json"


def sha256_file(p: Path) -> str:
    h = hashlib.sha256()
    with open(p, "rb") as f:
        for c in iter(lambda: f.read(65536), b""):
            h.update(c)
    return h.hexdigest()


def main() -> int:
    check = "--check" in sys.argv
    mpath = Path(MANIFEST)
    if not mpath.is_file():
        print(f"❌ {MANIFEST} not found in cwd", file=sys.stderr)
        return 2
    m = json.loads(mpath.read_text())
    files = list(m.get("critical_file_hashes", {}).keys())
    current = {f: (sha256_file(Path(f)) if Path(f).is_file() else "MISSING") for f in files}

    if check:
        drift = {f: (m["critical_file_hashes"][f], current[f]) for f in files
                 if m["critical_file_hashes"][f] != current[f]}
        if drift:
            print("⚠️ DRIFT vs frozen baseline:")
            for f, (exp, act) in drift.items():
                print(f"  {f}: expected {exp} got {act}")
            return 1
        print(f"✅ all {len(files)} critical files match {m.get('freeze_tag')}")
        return 0

    m["critical_file_hashes"] = current
    mpath.write_text(json.dumps(m, indent=2))
    print(f"✅ wrote {len(files)} hashes into {MANIFEST} (freeze_tag={m.get('freeze_tag')})")
    for f, h in current.items():
        print(f"  {f}: {h}")
    return 0


if __name__ == "__main__":
    raise SystemExit(main())