#!/usr/bin/env python3 """Verify every RUN_AS_IS root script against the actual 40250 root.epk bytes.""" from __future__ import annotations import argparse import hashlib import json import sys from pathlib import Path REPO = Path(__file__).resolve().parents[1] sys.path.insert(0, str(REPO / "tools" / "epk_scan")) import epk_scan # noqa: E402 def digest(data: bytes) -> str: return hashlib.sha256(data).hexdigest() def main() -> int: parser = argparse.ArgumentParser(description=__doc__) parser.add_argument("--client", type=Path, default=REPO / "../40250/Server Client TMP4/Client") args = parser.parse_args() client = args.client.resolve() reference = epk_scan.refroot.reference_root(REPO) _, keys, _, packs, _ = epk_scan.load(client, reference) root_pack = packs["root"] if root_pack["missing"]: print("FAIL: root.eix/root.epk missing", file=sys.stderr) return 1 entries = {entry["name"].lower(): entry for entry in root_pack["entries"]} source_dir = client / "Eternexus" / "root" ledger_dir = REPO / "audit" / "port-map" / "Client" / "root" failures: list[str] = [] scripts = sorted(source_dir.glob("*.py")) if {p.stem for p in scripts} != {p.name.removesuffix(".py.json") for p in ledger_dir.glob("*.py.json")}: failures.append("ledger files do not match the reference root script list") with root_pack["epk"].open("rb") as archive: for source in scripts: name = source.name entry = entries.get(name.lower()) ledger_path = ledger_dir / f"{name}.json" if entry is None or not ledger_path.is_file(): failures.append(f"{name}: missing pack entry or ledger") continue archive.seek(entry["pos"]) data = archive.read(entry["size"]) if entry["type"] in (1, 2): archive.seek(entry["pos"]) data = archive.read(epk_scan.lz_object_len(data[:16])) data = epk_scan.lz_object( data, keys["s_adwEterPackSecurityKey"] if entry["type"] == 2 else None ) elif entry["type"] != 0: failures.append(f"{name}: unsupported pack compression type {entry['type']}") continue ledger = json.loads(ledger_path.read_text(encoding="utf-8")) expected = digest(source.read_bytes()) if digest(data) != expected or ledger["reference_sha256"] != expected: failures.append(f"{name}: root.epk, reference source and ledger hashes differ") for function, info in ledger["functions"].items(): if info.get("status") != "RUN_AS_IS" or info.get("impl") != [f"pack://{name}:{function}"]: failures.append(f"{name}:{function}: incorrect RUN_AS_IS mapping") if not isinstance(info.get("evidence"), list) or not info["evidence"]: failures.append(f"{name}:{function}: missing evidence list") for failure in failures: print(f"FAIL: {failure}", file=sys.stderr) if failures: return 1 print(f"PASS: {len(scripts)} root scripts match 40250 source, root.epk and port-map") return 0 if __name__ == "__main__": raise SystemExit(main())