mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-15 07:36:50 +03:00
The engine no longer lives in a separate repo. `crates/` is a snapshot of the
open crates (foundation, core, common, context, live, hook, skills, comp,
comp-verbs, html, browser, detect, cli) plus `Cargo.lock`, taken as a git
archive of the engine repo at the commit that finished the boundary split.
None of that repo's history comes with it, and none of it should: the closed
half stays private.
The closed half is the rule engine. It ships as a prebuilt native archive per
target, `libimpeccable_detector.a`, published as a `detector-v<X>` GitHub
Release on this repo. `crates/core/build.rs` resolves and links it three ways:
`IMPECCABLE_DETECTOR_LIB=<dir>` for a local detector build, else the
`~/.impeccable/detector/<version>/<target>/` cache, else a download verified
against its `.sha256` sidecar. `crates/core` is a thin shim over a three-symbol
C ABI; nothing above it knows the boundary exists.
What changed versus the engine repo copy:
- Every crate manifest moves from `license-file.workspace` to
`license.workspace` (this workspace declares Apache-2.0), and the workspace
gains the `postcard` dependency the boundary encoding needs.
- The launcher contract test reads `skill/scripts/impeccable{,.cmd}` instead of
a sibling `launcher/` dir, and `engine_binary` downloads from
`github.com/pbakaus/impeccable/releases/download/engine-v<version>/` instead
of the retired dist repo. No oracle golden carried the old URL, so no
re-recording was owed.
- The tests that hunted for a public repo through `IMPECCABLE_PUBLIC_REPO`,
`../impeccable-second` or a hardcoded home directory now resolve the root as
`CARGO_MANIFEST_DIR/../..`, because they are in it. The env var stays as an
override for an out-of-tree checkout.
- The in-page bundle (`detect-antipatterns-browser.js`, 2 MB of generated wasm
glue) is no longer tracked. `crates/core/build.rs` resolves it beside the
archive, hands the path to `impeccable_core::browser::IN_PAGE_BUNDLE_JS`, and
live mode serves that. `scripts/check-detector-release.mjs` now requires it
and its `.sha256` in a detector release.
- The live crate embeds `skill/scripts/live-browser*.js` and
`modern-screenshot.umd.js` directly rather than through vendored copies, so
the binary and the installed skill cannot drift.
- `crates/browser/assets/` (an unused second copy of the bundle) is gone.
- `tests/lib/engine-bin.mjs` also accepts `target/release/impeccable`, so a
plain `cargo build --release -p impeccable` is enough to run `bun run test`.
Verified with the archive from a local detector build: `cargo test --workspace`
267 pass, oracle 795 pass / 0 fail / 0 missing, `bun run build` clean, the
default suite green, and the launcher's `engine-probe` handshake answering
through `skill/scripts/impeccable`.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vau2X53xGTjjTCXWMVBoNY
50 lines
1.4 KiB
Rust
50 lines
1.4 KiB
Rust
//! `crypto.randomUUID()` for the server token and the manual-apply event ids.
|
|
|
|
/// A version-4 UUID from the OS CSPRNG (falls back to a time/pid hash only if
|
|
/// the OS source is unavailable, which is not expected).
|
|
pub fn random_uuid() -> String {
|
|
let mut b = [0u8; 16];
|
|
if getrandom::getrandom(&mut b).is_err() {
|
|
let t = std::time::SystemTime::now()
|
|
.duration_since(std::time::UNIX_EPOCH)
|
|
.map(|d| d.as_nanos())
|
|
.unwrap_or(0);
|
|
let mut x = (t as u64) ^ ((std::process::id() as u64) << 32) ^ 0x9E3779B97F4A7C15;
|
|
for chunk in b.chunks_mut(8) {
|
|
x ^= x >> 33;
|
|
x = x.wrapping_mul(0xff51afd7ed558ccd);
|
|
x ^= x >> 33;
|
|
for (i, byte) in chunk.iter_mut().enumerate() {
|
|
*byte = (x >> (i * 8)) as u8;
|
|
}
|
|
}
|
|
}
|
|
b[6] = (b[6] & 0x0f) | 0x40;
|
|
b[8] = (b[8] & 0x3f) | 0x80;
|
|
let hex: Vec<String> = b.iter().map(|x| format!("{:02x}", x)).collect();
|
|
format!(
|
|
"{}{}{}{}-{}{}-{}{}-{}{}-{}{}{}{}{}{}",
|
|
hex[0],
|
|
hex[1],
|
|
hex[2],
|
|
hex[3],
|
|
hex[4],
|
|
hex[5],
|
|
hex[6],
|
|
hex[7],
|
|
hex[8],
|
|
hex[9],
|
|
hex[10],
|
|
hex[11],
|
|
hex[12],
|
|
hex[13],
|
|
hex[14],
|
|
hex[15]
|
|
)
|
|
}
|
|
|
|
/// JS: `randomUUID().replace(/-/g, '').slice(0, 8)`
|
|
pub fn random_id8() -> String {
|
|
random_uuid().replace('-', "").chars().take(8).collect()
|
|
}
|