File size: 6,200 Bytes
9425aed | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 | #!/usr/bin/env bash
# BOB-AUDIT: Generate cryptographically sealed audit records
# Purpose: Create tamper-evident audit trail for components
# Inputs: component name, output format
# Outputs: Cryptographically sealed audit record
# Dependencies: sha256sum, openssl (optional for ML-DSA-65)
# Verification: Generates SHA-256 seals for all audit events
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)"
AUDIT_DIR="${REPO_ROOT}/.audit"
FORMAT="json"
COMPONENT=""
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
NC='\033[0m'
usage() {
cat << EOF
Usage: bob-audit [component] [options]
Generate cryptographically sealed audit records according to BOB Trust Deed v1.0
Arguments:
component Component to audit (required)
Options:
--format=FORMAT Output format: json, text (default: json)
--help Show this help message
Examples:
bob-audit compiler
bob-audit runtime --format=text
EOF
exit 1
}
while [[ $# -gt 0 ]]; do
case $1 in
--format=*)
FORMAT="${1#*=}"
shift
;;
--help)
usage
;;
-*)
echo -e "${RED}Error: Unknown option $1${NC}"
usage
;;
*)
COMPONENT="$1"
shift
;;
esac
done
if [[ -z "$COMPONENT" ]]; then
echo -e "${RED}Error: Component name required${NC}"
usage
fi
case $FORMAT in
json|text)
;;
*)
echo -e "${RED}Error: Invalid format '$FORMAT'. Must be json or text${NC}"
exit 1
;;
esac
echo -e "${GREEN}BOB-AUDIT: Auditing component '$COMPONENT'${NC}"
# Create audit directory
mkdir -p "$AUDIT_DIR"
# Collect audit data
TIMESTAMP=$(date -u +"%Y-%m-%dT%H:%M:%SZ")
AUDIT_ID="audit-${COMPONENT}-$(date +%Y%m%d-%H%M%S)"
# Component metadata
if [[ -d "${REPO_ROOT}/${COMPONENT}" ]]; then
COMPONENT_PATH="${REPO_ROOT}/${COMPONENT}"
else
echo -e "${RED}Error: Component '$COMPONENT' not found${NC}"
exit 1
fi
# Calculate file hashes
echo -e "${YELLOW}Calculating file hashes...${NC}"
declare -a FILE_HASHES=()
while IFS= read -r -d '' file; do
if [[ -f "$file" ]]; then
rel_path="${file#$COMPONENT_PATH/}"
hash=$(sha256sum "$file" | cut -d' ' -f1)
FILE_HASHES+=("$rel_path:$hash")
fi
done < <(find "$COMPONENT_PATH" -type f -print0)
# Check for Trust Deed compliance
PYTHON_IN_PROD=false
STUBS_FOUND=false
MISSING_DOCS=false
# Scan for Python in production paths
if grep -r "#!/usr/bin/env python" "$COMPONENT_PATH" 2>/dev/null | grep -v "tools/" | grep -v "scripts/" > /dev/null; then
PYTHON_IN_PROD=true
fi
# Scan for stub implementations
if grep -r "TODO\|FIXME\|PLACEHOLDER\|NotImplementedError" "$COMPONENT_PATH" 2>/dev/null > /dev/null; then
STUBS_FOUND=true
fi
# Check for documentation headers
if [[ -d "${COMPONENT_PATH}/src" ]]; then
for src_file in "${COMPONENT_PATH}/src"/*.rs "${COMPONENT_PATH}/src"/*.ada "${COMPONENT_PATH}/src"/*.c; do
if [[ -f "$src_file" ]]; then
if ! grep -q "Purpose:\|Inputs:\|Outputs:\|Dependencies:\|Verification:" "$src_file" 2>/dev/null; then
MISSING_DOCS=true
break
fi
fi
done
fi
# Calculate component seal
COMPONENT_SEAL=$(echo -n "${COMPONENT}:${TIMESTAMP}:${FILE_HASHES[*]}" | sha256sum | cut -d' ' -f1)
# Generate audit record
if [[ "$FORMAT" == "json" ]]; then
AUDIT_FILE="${AUDIT_DIR}/${AUDIT_ID}.json"
cat > "$AUDIT_FILE" << EOF
{
"audit_id": "${AUDIT_ID}",
"component": "${COMPONENT}",
"timestamp": "${TIMESTAMP}",
"component_seal": "${COMPONENT_SEAL}",
"trust_deed_compliance": {
"python_in_production": ${PYTHON_IN_PROD},
"stubs_found": ${STUBS_FOUND},
"missing_documentation": ${MISSING_DOCS},
"overall_status": "$(if [[ "$PYTHON_IN_PROD" == false && "$STUBS_FOUND" == false && "$MISSING_DOCS" == false ]]; then echo "COMPLIANT"; else echo "NON_COMPLIANT"; fi)"
},
"file_count": ${#FILE_HASHES[@]},
"file_hashes": [
$(for hash_entry in "${FILE_HASHES[@]}"; do
file="${hash_entry%%:*}"
hash="${hash_entry##*:}"
echo " {\"file\": \"$file\", \"sha256\": \"$hash\"},"
done | sed '$ s/,$//')
],
"audit_seal": "$(echo -n "${AUDIT_ID}:${COMPONENT_SEAL}:${TIMESTAMP}" | sha256sum | cut -d' ' -f1)"
}
EOF
else
AUDIT_FILE="${AUDIT_DIR}/${AUDIT_ID}.txt"
cat > "$AUDIT_FILE" << EOF
BOB AUDIT RECORD
================
Audit ID: ${AUDIT_ID}
Component: ${COMPONENT}
Timestamp: ${TIMESTAMP}
Component Seal: ${COMPONENT_SEAL}
TRUST DEED COMPLIANCE
---------------------
Python in Production: ${PYTHON_IN_PROD}
Stubs Found: ${STUBS_FOUND}
Missing Documentation: ${MISSING_DOCS}
Overall Status: $(if [[ "$PYTHON_IN_PROD" == false && "$STUBS_FOUND" == false && "$MISSING_DOCS" == false ]]; then echo "COMPLIANT"; else echo "NON_COMPLIANT"; fi)
FILE INVENTORY
--------------
Total Files: ${#FILE_HASHES[@]}
$(for hash_entry in "${FILE_HASHES[@]}"; do
file="${hash_entry%%:*}"
hash="${hash_entry##*:}"
echo "$file"
echo " SHA-256: $hash"
done)
AUDIT SEAL
----------
$(echo -n "${AUDIT_ID}:${COMPONENT_SEAL}:${TIMESTAMP}" | sha256sum | cut -d' ' -f1)
EOF
fi
echo -e "${GREEN}✓ Audit record generated: $AUDIT_FILE${NC}"
# Check compliance status
if [[ "$PYTHON_IN_PROD" == true ]]; then
echo -e "${RED}✗ VIOLATION: Python found in production paths${NC}"
fi
if [[ "$STUBS_FOUND" == true ]]; then
echo -e "${RED}✗ VIOLATION: Stub implementations found${NC}"
fi
if [[ "$MISSING_DOCS" == true ]]; then
echo -e "${YELLOW}⚠ WARNING: Missing documentation headers${NC}"
fi
if [[ "$PYTHON_IN_PROD" == false && "$STUBS_FOUND" == false && "$MISSING_DOCS" == false ]]; then
echo -e "${GREEN}✓ Component is Trust Deed compliant${NC}"
exit 0
else
echo -e "${YELLOW}⚠ Component has compliance issues${NC}"
exit 1
fi
# Made with Bob
|