commit 97122770639eeac4269a860cd023e56e45515028
parent 5b0ad5e9d96770fcda89d21d86a50453076b7e3c
Author: triesap <tyson@radroots.org>
Date: Wed, 1 Jul 2026 21:18:05 +0000
cli: guard production dead code suppressions
Extend the CLI production-source scanner so runtime code rejects allow(dead_code) suppressions while preserving test-only fixture patterns through the existing cfg(test) stripper.
Validation: cargo extbuild run -- cargo fmt --all; cargo extbuild run -- cargo test --workspace cli_production_sources_reject_dead_code_suppressions
Diffstat:
1 file changed, 29 insertions(+), 0 deletions(-)
diff --git a/src/runtime/sdk.rs b/src/runtime/sdk.rs
@@ -1297,6 +1297,35 @@ mod tests {
}
#[test]
+ fn cli_production_sources_reject_dead_code_suppressions() {
+ let manifest_dir = Path::new(env!("CARGO_MANIFEST_DIR"));
+ let mut files = Vec::new();
+ collect_rs_files(manifest_dir.join("src").as_path(), &mut files);
+ files.sort();
+
+ let findings = files
+ .iter()
+ .flat_map(|file| {
+ let source = fs::read_to_string(file).expect("read cli source");
+ let relative_path = relative_source_path(manifest_dir, file.as_path());
+ match production_source_without_tests(&relative_path, &source) {
+ Ok(production_source) => production_source
+ .contains("allow(dead_code)")
+ .then(|| vec![format!("{relative_path}: production dead-code suppression")])
+ .unwrap_or_default(),
+ Err(error) => vec![error],
+ }
+ })
+ .collect::<Vec<_>>();
+
+ assert!(
+ findings.is_empty(),
+ "CLI production sources contain dead-code suppressions:\n{}",
+ findings.join("\n")
+ );
+ }
+
+ #[test]
fn migrated_cli_paths_are_guarded_against_workflow_bypasses() {
for guard in MIGRATED_CLI_PATH_GUARDS {
let source = crate_source(guard.path);