From 10d78fbbfba7ea5152368e4e3b5e8dccae5da8df Mon Sep 17 00:00:00 2001 From: Ivan Date: Mon, 13 Jul 2026 14:10:38 -0500 Subject: [PATCH] feat: update Makefile and docs --- .githooks/pre-commit | 4 ++-- Makefile | 19 ++++++++++++++++++- README.md | 3 +++ SECURITY.md | 6 +++--- meshchatx.rsm | Bin 144018 -> 144018 bytes 5 files changed, 26 insertions(+), 6 deletions(-) diff --git a/.githooks/pre-commit b/.githooks/pre-commit index cc60a639..eb33fea4 100755 --- a/.githooks/pre-commit +++ b/.githooks/pre-commit @@ -2,7 +2,7 @@ # pre-commit: keep meshchatx.rsm in sync with the staged tree inventory. # # Enable once per clone: -# task hooks:install +# make hooks-install # # or: sh scripts/ci/install-git-hooks.sh # # Skip for one commit: @@ -53,7 +53,7 @@ fi if [ -z "$ID_PATH" ] || [ ! -f "$ID_PATH" ]; then echo "pre-commit: staged inventory paths changed but no signing identity found." >&2 - echo "pre-commit: set RNS_ID_PATH or run: task tree-rsm-sign" >&2 + echo "pre-commit: set RNS_ID_PATH or run: make tree-rsm-sign" >&2 echo "pre-commit: or skip with SKIP_TREE_RSM_HOOK=1" >&2 exit 0 fi diff --git a/Makefile b/Makefile index a62e119f..6ce41e95 100644 --- a/Makefile +++ b/Makefile @@ -1,9 +1,11 @@ # Compatibility shim — Taskfile.yml owns install, lint, test, and build targets. +# Tree RSM targets call shell scripts directly so Make works without Task. TASK ?= task .DEFAULT_GOAL := help .PHONY: install install-offline run dev dev-fe build format lint test test-be-perf clean help dist-linux dist-linux-x64 +.PHONY: tree-manifest tree-rsm-sign tree-rsm-verify hooks-install install: @$(TASK) install @@ -44,6 +46,21 @@ dist-linux: dist-linux-x64: @$(TASK) dist:linux-x64 +tree-manifest: + sh scripts/ci/tree-manifest.sh generate + +tree-rsm-verify: + sh scripts/ci/verify-tree-rsm.sh + +tree-rsm-sign: + sh scripts/ci/sign-tree-rsm.sh + +hooks-install: + sh scripts/ci/install-git-hooks.sh + help: - @echo "Makefile targets delegate to Task (see: task --list)." + @echo "Makefile targets (most delegate to Task, see: task --list)." + @echo " make tree-rsm-verify Verify meshchatx.rsm (no Task required)" + @echo " make tree-rsm-sign Sign tree inventory (requires RNS_ID_PATH)" + @echo " make hooks-install Enable .githooks pre-commit" @$(TASK) --list diff --git a/README.md b/README.md index cce2b9be..4be3e200 100644 --- a/README.md +++ b/README.md @@ -430,6 +430,9 @@ task build | `make lint` | `task lint` | ESLint, vue-tsc, knip, Ruff, and basedpyright | | `make test` | `task test` | Run frontend and backend tests | | `make clean` | `task clean` | Remove build artifacts and node_modules | +| `make tree-rsm-verify` | (shell) | Verify `meshchatx.rsm` signature and hashes | +| `make tree-rsm-sign` | (shell) | Sign tree inventory (requires `RNS_ID_PATH`) | +| `make hooks-install` | (shell) | Enable tracked pre-commit RSM resign hook | ## Versioning diff --git a/SECURITY.md b/SECURITY.md index 3a292332..85192386 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -39,20 +39,20 @@ The repository root includes a signed rnid message file, `meshchatx.rsm`. It emb Verify locally: ```bash -task tree-rsm-verify +make tree-rsm-verify ``` Maintainers regenerate the signature after intentional tree changes (requires a private identity file that hashes to the signer above, never commit `*.rid`): ```bash export RNS_ID_PATH="$HOME/.local/share/reticulum-go/reticulum-go-release.rid" -task tree-rsm-sign +make tree-rsm-sign ``` Enable the tracked pre-commit hook so commits that change inventory paths resign `meshchatx.rsm` automatically when that identity is available: ```bash -task hooks:install +make hooks-install ``` Skip one commit with `SKIP_TREE_RSM_HOOK=1`. diff --git a/meshchatx.rsm b/meshchatx.rsm index 820f80fd880c3f155d288aac79ac86df893ffd37..87c5e86a53202c7c52c803a3014624361fe17349 100644 GIT binary patch delta 410 zcmWNLze|;26vw?6A-xh@q6-cUFAfe4^`7&b=e*|$i5pyp5SPGcXnB5}ijo=&3pIx* zYEYy>8bTd}LWcs83T_aje?c?_f!NScOEmWK<-2_O^5L_3G_-m&)SZJXi_gzo8vHPQ zqyOfx|8b+(864l={qyYU#HqDM$NKBe^8MIc{M1;QKYgwL^2zJFCw?F9Ug&+_{yDaA z@M2`8J6iOPCud(#n*H}}XW*-M1Lrqe=f12zxc+|l^SkEA!QYj8Ke|F$vXCc4wUV6$ zbQzVRG3Py$&#Z=otXN|L@aOD8(SwAqN#!{#iM!*Y5)*y5>!bnkkv)t z5U_I5JI18-mITCPvC&mYu_$Kzt*ke1=N20e!78yg6|+I4tft0t$|k81Ut08rAeNap zMomoSYVC%KKvf7(6qlzi_GYHe&ZSm#bxQB+Ce>V_5yK^*wVcRVrkKS9isFfCaw1LM XIIy;sWb0tL(|+7(H}*R1=EJf7V+Mta delta 410 zcmWNLJxkS57{Ix{gh;{_ybulYFLMg?yr1Xk^$Lj+h+QXfiF3~LoJ*L4!v%+;$RTLc z!6C9ibaQKv#K}Qx5V0>1Bo_q1DNv!I{|ETJthRer+dcKm&YSXV!>qsm-56f_d-!8u z@ZRlTYhSNkQnPDkYp{Rp`}6&aN43R?x%tNWofnh*SS$~HIbS>GPp#IQ?yi;kt)ewM z`egdwN#}=$+k4kXqYn-ip6bQj)BAgs8|}&F&&JBqpL(WbH5=j}MIeRB12AS_4S<-P zQ|x1O)-pgwKxd-x!2yNrl*;kj=gMZ^JB5i7IAu!!l8nqINbh_W$Yg>CEfeIx(RxLQ zmQzHeY@J2z!OEhT3iF&_z2;u+gj88LFH1o{ikU15?PEEJ*&s%?B@E0gtalcq^0QJ# z9g`vBv@MF6@v&!9<0A{y>&q;Xbf^PlMNt@%Nm(b*utp=4w5V8{1eyg4GMs>vkKUD! TI;G`W^<%AC*{M}K-roHW9N>a%