Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@
#
# / root workspace (vcl-ut, fmt, lint, core)
# /src/interface/parse parser + decider + vclt-gate <- the real spine
# /src/interface/attest depends on ../parse (in-repo)
# /src/interface/recompute-wasm depends on ../parse (in-repo)
# /ffi/rust/attest depends on src/interface/parse (in-repo)
# /ffi/rust/recompute-wasm depends on src/interface/parse (in-repo)
#
# DELIBERATELY EXCLUDED: /src/interface/echidna-client. It depends on
# ../../interface, which in turn carries an out-of-tree path dependency
Expand Down Expand Up @@ -66,13 +66,13 @@ updates:
open-pull-requests-limit: 0

- package-ecosystem: "cargo"
directory: "/src/interface/attest"
directory: "/ffi/rust/attest"
schedule:
interval: "weekly"
open-pull-requests-limit: 0

- package-ecosystem: "cargo"
directory: "/src/interface/recompute-wasm"
directory: "/ffi/rust/recompute-wasm"
schedule:
interval: "weekly"
open-pull-requests-limit: 0
2 changes: 1 addition & 1 deletion .github/workflows/rhodibot.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# rhodibot.yml — RSR compliance CANARY (report-only)
#
# Rhodibot does NOT mutate this repository. It never deletes, renames,
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/satellite-crates-gate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@
# / e2e.yml
# /src/interface/parse parse-gate.yml
# /src/interface/echidna-client backend-matrix.yml (needs echidna sibling)
# /src/interface/attest NOTHING <- gated here
# /src/interface/recompute-wasm NOTHING <- gated here
# /ffi/rust/attest NOTHING <- gated here
# /ffi/rust/recompute-wasm NOTHING <- gated here
#
# The cost of that gap was measured on 2026-07-21: both ungated crates had
# stopped compiling. `ast::Statement` gained the S1 consonance field `verb`
Expand Down Expand Up @@ -76,10 +76,10 @@ jobs:
- name: Clippy — warnings are errors
run: |
set -euo pipefail
cargo clippy --manifest-path src/interface/${{ matrix.crate }}/Cargo.toml \
cargo clippy --manifest-path ffi/rust/${{ matrix.crate }}/Cargo.toml \
--all-targets -- -D warnings

- name: Tests
run: |
set -euo pipefail
cargo test --manifest-path src/interface/${{ matrix.crate }}/Cargo.toml
cargo test --manifest-path ffi/rust/${{ matrix.crate }}/Cargo.toml
16 changes: 13 additions & 3 deletions CHANGELOG.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,16 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning].

==== Changed

* *SPARK-grade safe-source boundary* (vcl-ut#49): moved the Rust C-ABI
attestation crate and the `wasm32` host/guest recompute crate from
`src/interface/{attest,recompute-wasm}` to `ffi/rust/`, so every Rust
`unsafe` block in the repository lives under `ffi/`. The aspect gate
(`tests/aspect_tests.sh`) now requires: no unsafe Rust constructs anywhere
under `src/` (tests included); `#![forbid(unsafe_code)]` on every `src/`
crate root; and the SPDX identifier on the first line of every `src/` Rust
file. It keeps the fail-open check from vcl-ut#117 (`unwrap`/`expect`/
`panic!` family). Moved crates keep their own lockfiles; the Zig shim,
satellite gate, Dependabot, and audit classifications follow the new paths.
* *Modality profiles distinguished from the fixed Octad schema* (vcl-ut#118):
adopted `modality profile` for versioned, implementation-specific modality
selections and `modality set` for membership alone. Clarified that VCL-UT's
Expand Down Expand Up @@ -123,7 +133,7 @@ the corpus decision core (`+Schema+`/`+Decide+`/`+Checker+`
public deciders via `+WireConformance+` on shared golden bytes
(find-dependent verdicts pinned Rust-side + input-value conformance,
disclosed); P5c-5 (#32) the recompute *`+wasm32+`* artefact
`+src/interface/recompute-wasm+` (`+vcl_recompute+`, fail-closed, one
`+ffi/rust/recompute-wasm+` (`+vcl_recompute+`, fail-closed, one
audited host/guest `+unsafe+` block; all logic in the forbid-unsafe
crate); P5c-6 (this change) the `+OWED→RESOLVED+` stance flip + ADR
`+docs/decisions/0002-ffi-attestation-trust-boundary.adoc+`. The
Expand All @@ -133,7 +143,7 @@ system not load-bearing under recompute); `+affinescriptiser+` N/A
(resource-required + wasm-backend-pending; disclosed in
`+AFFINESCRIPTISER-NA.adoc+`, not faked).
* Phase 5 / vcl-ut#25 — *Tier-2 (P5d) RESOLVED*:
`+src/interface/attest+` (`+vcltotal-attest+`) mints/verifies an Ed25519
`+ffi/rust/attest+` (`+vcltotal-attest+`) mints/verifies an Ed25519
attestation over
`+DOMAIN ‖ sha256(stmt_wire) ‖ sha256(schema_wire) ‖ level+` (level =
the conformance-pinned `+certified_level+`, signed iff `+0..=10+`,
Expand All @@ -143,7 +153,7 @@ crate, linked into `+ffi/zig/src/lib.zig+` (`+vclut_verify_wire+`) by
(roundtrip + 5 tamper variants + fail-closed + C-ABI tests).
`+ed25519-dalek+`/`+sha2+` contained to the Tier-2 crate; zero-dep
forbid-unsafe core untouched; one audited host/guest `+unsafe+` block.
Spec `+src/interface/attest/ATTESTATION-FORMAT.adoc+`; ADR-0002 → both
Spec `+ffi/rust/attest/ATTESTATION-FORMAT.adoc+`; ADR-0002 → both
tiers RESOLVED. *The vcl-ut#25 boundary-reinforcement workstream is
complete* (only the precisely-scoped disclosed limits remain — not
gaps). A re-checkable proof is impossible _only_ over the C-ABI fallback
Expand Down
4 changes: 2 additions & 2 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions REUSE.toml
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,7 @@ path = [
"contractiles/**",
"examples/**",
"features/**",
"ffi/**",
"src/**",
"verification/**",
]
Expand Down
4 changes: 2 additions & 2 deletions audits/assail-classifications.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -22,12 +22,12 @@
;; Mirrors the reference pattern in hyperpolymath/007
;; audits/assail-classifications.a2ml (zig_bridge.rs UnsafeCode).
(classification
(file "src/interface/recompute-wasm/src/lib.rs")
(file "ffi/rust/recompute-wasm/src/lib.rs")
(category "UnsafeCode")
(audit "in-file UNSAFE POLICY (lib.rs:40-46) + deny(clippy::undocumented_unsafe_blocks)")
(rationale "only unsafe is the documented host/guest memory-ABI block (alloc/dealloc pair); all decision logic lives in the forbid(unsafe_code) vcltotal-parse crate"))
(classification
(file "src/interface/attest/src/lib.rs")
(file "ffi/rust/attest/src/lib.rs")
(category "UnsafeCode")
(audit "in-file UNSAFE POLICY (lib.rs:38-42) + deny(clippy::undocumented_unsafe_blocks)")
(rationale "single documented C-ABI block in vclut_rs_verify with null/len checks and fail-closed -1 returns; decode logic in forbid(unsafe_code) crate"))
Expand Down
2 changes: 1 addition & 1 deletion docs/2026-07-21-workup-consonance-and-verisim.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -398,7 +398,7 @@ that preserves VeriSimDB's genuinely good UX work:

=== 3. Attestation

`src/interface/attest` mints a signed attestation over `(statement, schema)`
`ffi/rust/attest` mints a signed attestation over `(statement, schema)`
carrying the certified level, verifiable independently. For a database whose
selling point is maintained identity consonance, being able to prove *after
the fact* that a transition was admitted at a stated level — and have a third
Expand Down
10 changes: 5 additions & 5 deletions docs/decisions/0002-ffi-attestation-trust-boundary.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ Date: 2026-05-19
## Status

Accepted (**both tiers RESOLVED** — Tier-1 recompute-PCC over `wasm32`;
Tier-2 / P5d C-ABI Ed25519 attestation fallback, `src/interface/attest`
Tier-2 / P5d C-ABI Ed25519 attestation fallback, `ffi/rust/attest`
linked into the Zig shim). Tracked: hyperpolymath/vcl-ut#25.
Authoritative companion:
`verification/proofs/VERIFICATION-STANCE.adoc` (canonical two-tier
Expand Down Expand Up @@ -41,15 +41,15 @@ Constraints established during Phase 5:
verdict entry is a pure resource-free function (fabricating a
resource to satisfy the tool would violate the verification-honesty
doctrine), and its wasm backend is Phase-2-pending. (Disclosed:
`src/interface/recompute-wasm/AFFINESCRIPTISER-NA.adoc`.)
`ffi/rust/recompute-wasm/AFFINESCRIPTISER-NA.adoc`.)

## Decision

Adopt a **two-tier boundary**:

**Tier-1 — recompute-PCC over plain `wasm32` (the achieved tier).**
The consumer is shipped the `wasm32` module
`src/interface/recompute-wasm` (`vcl_recompute`) + the wire bytes of a
`ffi/rust/recompute-wasm` (`vcl_recompute`) + the wire bytes of a
`(Statement, OctadSchema)` + the producer's claimed level, and
**re-runs the certified decision itself**, comparing its verdict to
the claim. This is proof-carrying code by *recomputation*, not by
Expand Down Expand Up @@ -79,7 +79,7 @@ decode/decision logic in the `#![forbid(unsafe_code)]` crate.

**Tier-2 — C-ABI trusted-certifier attestation (fallback, P5d,
RESOLVED).** For consumers that cannot run the Tier-1 wasm:
`src/interface/attest` (`vcltotal-attest`) mints an Ed25519 signature
`ffi/rust/attest` (`vcltotal-attest`) mints an Ed25519 signature
over `DOMAIN ‖ sha256(stmt_wire) ‖ sha256(schema_wire) ‖ level`, where
`level` is the conformance-pinned `vcltotal_parse::certified_level`
(signed iff `0..=10`, fail-closed); the consumer Ed25519-verifies
Expand All @@ -90,7 +90,7 @@ shim (`vclut_verify_wire`) by `build.zig`; `zig build test` exercises
the boundary end-to-end. Strictly weaker than Tier-1 (pure trust in
the minting certifier + that it ran the pinned decider), and labelled
as such everywhere. Spec:
`src/interface/attest/ATTESTATION-FORMAT.adoc`; crypto
`ffi/rust/attest/ATTESTATION-FORMAT.adoc`; crypto
(`ed25519-dalek`/`sha2`) contained to this Tier-2 crate, the
zero-dep forbid-unsafe core untouched.

Expand Down
9 changes: 6 additions & 3 deletions docs/developer/ABI-FFI-README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -68,13 +68,16 @@ vcl_total/
│ │ ├── legacy/ # Pre-Phase-5 plumbing (DEPRECATED)
│ │ │ └── Foreign.idr # Legacy libvqlut bindings (Zig
│ │ │ # asserts level; no Idris certificate)
│ │ ├── attest/ # Tier-2 Rust: signed attestation
│ │ ├── recompute-wasm/ # Tier-1 Rust: consumer-side recompute
│ │ ├── parse/ # Safe Rust parser + decider (forbid-unsafe)
│ │ └── ffi/ # Legacy Zig multi-stage pipeline
│ └── core/ # Idris2 corpus (the certifier itself)
│ # No unsafe Rust anywhere under src/ (#49)
│
├── ffi/
│ └── zig/ # FFI implementation (Zig)
│ ├── rust/ # Rust unsafe-boundary crates (only here)
│ │ ├── attest/ # Tier-2 Rust: signed C-ABI attestation
│ │ └── recompute-wasm/ # Tier-1 Rust: consumer-side wasm recompute
│ └── zig/ # Zig shim, links ffi/rust/attest
│ ├── build.zig # Build configuration
│ ├── build.zig.zon # Dependencies
│ ├── src/
Expand Down
4 changes: 2 additions & 2 deletions docs/status/PROOF-NEEDS.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -115,15 +115,15 @@ conformant with the Rust encoder by `+Refl+` in
`+VclTotal.Interface.WireConformance+`. The marshalling seam’s _decode_
side is machine-verified. *P5c — RESOLVED (Tier-1 recompute-PCC):* the
consumer re-runs the certified decision itself from the fail-closed
`+wasm32+` module `+src/interface/recompute-wasm+` (`+vcl_recompute+`);
`+wasm32+` module `+ffi/rust/recompute-wasm+` (`+vcl_recompute+`);
the decision core is a faithful Rust port of the corpus
(`+Schema+`/`+Decide+`/`+Checker+`) machine-pinned via
`+WireConformance+`. TCB = conformance-pinned decider image + wasm
runtime + the once-proved corpus (offline-re-checkable) — _not_ a
trusted tag, _not_ a transported proof object. Plain `+wasm32+` suffices
(type system not load-bearing under recompute); `+affinescriptiser+` N/A
(disclosed). *P5d — RESOLVED (Tier-2 fallback):*
`+src/interface/attest+` mints/verifies an Ed25519 attestation bound to
`+ffi/rust/attest+` mints/verifies an Ed25519 attestation bound to
`+(sha256(stmt_wire), sha256(schema_wire), level)+` (fail-closed); the
`+vclut_rs_verify+` backend is linked into `+ffi/zig+`
(`+vclut_verify_wire+`, `+zig build test+` green end-to-end).
Expand Down
40 changes: 40 additions & 0 deletions ffi/rust/README.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
// SPDX-License-Identifier: CC-BY-SA-4.0
= Rust FFI Boundary Crates
:toc:

This directory is the Rust host/guest and C-ABI boundary layer, and the
*only* place in the repository where Rust `unsafe` is allowed (vcl-ut#49).
Rust code under `src/` is safe Rust: every crate root there carries
`#![forbid(unsafe_code)]`, and `tests/aspect_tests.sh` rejects any unsafe
construct under `src/`, test code included.

Each crate here keeps its unsafe surface to one audited block with a
`// SAFETY:` justification (`#![deny(clippy::undocumented_unsafe_blocks)]`)
and delegates all decoding and decision logic to the safe
`src/interface/parse` (`vcltotal-parse`) crate.

== Crates

* `attest/` (`vcltotal-attest`): Tier-2 C-ABI Ed25519 trusted-certifier
attestation backend (`vclut_rs_verify`), linked into the Zig shim
`ffi/zig` by `ffi/zig/build.zig`. Spec: `attest/ATTESTATION-FORMAT.adoc`.
* `recompute-wasm/` (`vcltotal-recompute-wasm`): Tier-1 `wasm32`
recompute-PCC entry point (`vcl_recompute`).

Each crate is an independent Cargo workspace root with its own committed
lockfile, so it builds without the repository's other workspace roots
(one of which carries an external path dependency).

== Validation

[source,sh]
----
cargo clippy --manifest-path ffi/rust/attest/Cargo.toml --all-targets -- -D warnings
cargo test --manifest-path ffi/rust/attest/Cargo.toml --locked
cargo clippy --manifest-path ffi/rust/recompute-wasm/Cargo.toml --all-targets -- -D warnings
cargo test --manifest-path ffi/rust/recompute-wasm/Cargo.toml --locked
(cd ffi/zig && zig build test) # links attest/ end to end
----

CI: `.github/workflows/satellite-crates-gate.yml`.
File renamed without changes.
Original file line number Diff line number Diff line change
Expand Up @@ -62,13 +62,13 @@ registry/trust). "query" in the issue-#25 phrasing

A tampered `stmt_wire`, `schema_wire`, `level`, or `sig`, or a wrong
public key, all fail verification (machine-tested:
`src/interface/attest` — roundtrip + 5 tamper variants + fail-closed +
`ffi/rust/attest` — roundtrip + 5 tamper variants + fail-closed +
C-ABI).

== C-ABI

`vclut_rs_verify(stmt_ptr, stmt_len, schema_ptr, schema_len, sk_ptr,
out_ptr, out_cap) -> i64` (Rust, `src/interface/attest`), linked into
out_ptr, out_cap) -> i64` (Rust, `ffi/rust/attest`), linked into
the Zig shim `ffi/zig/src/lib.zig` and exposed as
`vclut_verify_wire(...)`. Returns the level `0..10` (and writes the
65-byte token) or `-1` Rejected (writes nothing; `vclut_last_error`
Expand Down
File renamed without changes.
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
# SPDX-License-Identifier: MPL-2.0

# Standalone workspace root (same rationale as ../parse, ../recompute-wasm):
# decoupled from the broken parent virtual workspace. This is the Tier-2
# Standalone workspace root (same rationale as src/interface/parse and
# ffi/rust/recompute-wasm): an FFI boundary crate that builds and gates in
# isolation from the other workspace roots. This is the Tier-2
# (C-ABI trusted-certifier attestation) FALLBACK crate — explicitly the
# weaker boundary tier (see VERIFICATION-STANCE.adoc's two-tier model).
# The crypto dependency is CONTAINED here and never touches the
Expand All @@ -23,7 +24,7 @@ crate-type = ["staticlib", "rlib"]
path = "src/lib.rs"

[dependencies]
vcltotal-parse = { path = "../parse" }
vcltotal-parse = { path = "../../../src/interface/parse" }
# de-facto standard, widely audited (user decision 2026-05-19).
# default-features off keeps the tree minimal; `std` for the host
# staticlib; no rng feature (deterministic keys via from_bytes).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ attestation (the FALLBACK tier).** Authoritative model:
== Role

For consumers that **cannot run the Tier-1 recompute `wasm32` module**
(`src/interface/recompute-wasm`). A C ABI cannot carry a re-checkable
(`ffi/rust/recompute-wasm`). A C ABI cannot carry a re-checkable
proof, so this mints an Ed25519 attestation binding
`(sha256(stmt_wire), sha256(schema_wire), level)` — unforgeable and
bound, but *trusted* (the consumer trusts the certifier that signed
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
//!
//! See `verification/proofs/VERIFICATION-STANCE.adoc`'s canonical
//! two-tier boundary model. Tier-1 (recompute-PCC over `wasm32`,
//! `src/interface/recompute-wasm`) is the achieved tier: the consumer
//! `ffi/rust/recompute-wasm`) is the achieved tier: the consumer
//! re-validates. Tier-2 — *this crate* — is the explicit **weaker
//! fallback** for consumers that cannot run the Tier-1 wasm. A C ABI
//! erases types to machine words, so it cannot carry a re-checkable
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ wasm's type system:

[source,sh]
----
cd src/interface/recompute-wasm
cd ffi/rust/recompute-wasm
cargo build --release --target wasm32-unknown-unknown
# → target/wasm32-unknown-unknown/release/vcltotal_recompute_wasm.wasm
----
Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
# SPDX-License-Identifier: MPL-2.0

# Standalone workspace root (same rationale as ../parse/Cargo.toml): the
# parent virtual workspace has a pre-existing unresolvable external
# path-dep, so this boundary crate builds/gates in isolation. Its ONLY
# dependency is the in-repo, forbid-unsafe `vcltotal-parse` (internal
# path-dep — resolves in a standalone checkout, unlike the broken
# `../../../echidna/...` member).
# Standalone workspace root (same rationale as
# src/interface/parse/Cargo.toml): this FFI boundary crate builds and gates
# in isolation from the other workspace roots. Its ONLY dependency is the
# in-repo, forbid-unsafe `vcltotal-parse` (`src/interface/parse`, an
# internal path-dep that resolves in a standalone checkout, unlike the
# external `../../../echidna/...` dependency of `src/interface`).
[workspace]

[package]
Expand All @@ -23,7 +23,7 @@ crate-type = ["cdylib", "rlib"]
path = "src/lib.rs"

[dependencies]
vcltotal-parse = { path = "../parse" }
vcltotal-parse = { path = "../../../src/interface/parse" }

# Total/panic-free is inherited from `vcltotal-parse`'s static SPARK
# lint set (the decoder/decider carry no panics). `panic = "abort"`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@
//! Phase-2-pending.) The recompute security argument does not need it:
//! soundness is the corpus proof, faithfulness is the conformance pin,
//! and the wasm is a deterministic `cargo build` of the pinned source.
//! See `src/interface/recompute-wasm/AFFINESCRIPTISER-NA.adoc`.
//! See `ffi/rust/recompute-wasm/AFFINESCRIPTISER-NA.adoc`.
//!
//! UNSAFE POLICY. All decision/decoding logic lives in the
//! `#![forbid(unsafe_code)]` `vcltotal-parse` crate. The ONLY `unsafe`
Expand Down Expand Up @@ -65,7 +65,7 @@
pub extern "C" fn vcl_alloc(len: usize) -> *mut u8 {
let mut buf = Vec::<u8>::with_capacity(len);
let ptr = buf.as_mut_ptr();
core::mem::forget(buf);

Check failure on line 68 in ffi/rust/recompute-wasm/src/lib.rs

View workflow job for this annotation

GitHub Actions / Hypatia neurosymbolic scan

[hypatia] mem::forget leaks memory by skipping Drop (1 occurrences, CWE-401, line 68)
ptr
}

Expand All @@ -81,7 +81,7 @@
// are exactly a prior `vcl_alloc` pair (capacity == len, never
// freed). Reconstituting and dropping the `Vec` frees it.
unsafe {
drop(Vec::from_raw_parts(ptr, 0, len));

Check failure on line 84 in ffi/rust/recompute-wasm/src/lib.rs

View workflow job for this annotation

GitHub Actions / Hypatia neurosymbolic scan

[hypatia] from_raw constructs types from raw pointers without safety checks (3 occurrences, CWE-676, line 84, 119, 120)
}
}
}
Expand Down
9 changes: 6 additions & 3 deletions ffi/zig/build.zig
Original file line number Diff line number Diff line change
Expand Up @@ -10,13 +10,16 @@
//
// P5d (vcl-ut#25): the Tier-2 attestation backend `vclut_rs_verify`
// (previously declared-but-unlinked, NAMED OWED) is now the Rust
// `vcltotal-attest` crate (`src/interface/attest`). build.zig compiles
// `vcltotal-attest` crate (`ffi/rust/attest`). build.zig compiles
// that staticlib via cargo and links it into every artefact (incl. the
// test runner), so the shim's `vclut_verify_wire` calls a real,
// conformance-pinned, fail-closed backend — not a stub.

const std = @import("std");

/// Configure installation of the shared and static FFI libraries and the `test`
/// step. Each artefact links the Rust attestation backend, built by Cargo in
/// release mode; the standard target and optimisation options apply to Zig.
pub fn build(b: *std.Build) void {
const target = b.standardTargetOptions(.{});
const optimize = b.standardOptimizeOption(.{});
Expand All @@ -25,10 +28,10 @@ pub fn build(b: *std.Build) void {
const cargo = b.addSystemCommand(&.{
"cargo", "build",
"--release", "--manifest-path",
"../../src/interface/attest/Cargo.toml",
"../../ffi/rust/attest/Cargo.toml",
});

const attest_a = b.path("../../src/interface/attest/target/release/libvcltotal_attest.a");
const attest_a = b.path("../../ffi/rust/attest/target/release/libvcltotal_attest.a");

const lib_mod = b.createModule(.{
.root_source_file = b.path("src/lib.zig"),
Expand Down
Loading
Loading