service_target_boundary.rs (4784B)
1 const MANAGEMENT_FIXTURE: &str = include_str!("fixtures/hardened_service_management.v1.toml"); 2 const MANAGER_ROOT_SOURCE: &str = include_str!("../src/lib.rs"); 3 const MANAGER_SOURCE: &str = include_str!("../src/managed.rs"); 4 const CLI_SOURCE: &str = include_str!("../src/cli.rs"); 5 const MODEL_SOURCE: &str = include_str!("../src/model.rs"); 6 #[cfg(any(target_os = "linux", target_os = "macos"))] 7 const STATUS_SOURCE: &str = include_str!("../src/status.rs"); 8 const MANIFEST: &str = include_str!("../Cargo.toml"); 9 const README: &str = include_str!("../README"); 10 11 fn production_source(source: &str) -> &str { 12 source 13 .split("\n#[cfg(test)]") 14 .next() 15 .expect("production source") 16 } 17 18 #[test] 19 fn hardened_services_use_only_the_common_context_bound_interfaces() { 20 for forbidden in [ 21 "install_strategy", 22 "binary_name", 23 "artifact_adapter", 24 "qualified", 25 "default_instance_id", 26 "preferred_cli_binding", 27 "typed_instance_registry", 28 "instances.toml", 29 "explicit_runtime_endpoint_overrides", 30 "[paths.", 31 "[bootstrap]", 32 ] { 33 assert!( 34 !MANAGEMENT_FIXTURE.contains(forbidden), 35 "management fixture contains deferred authority `{forbidden}`" 36 ); 37 } 38 39 assert!(MANAGEMENT_FIXTURE.contains("active = [\"myc\", \"rhi\"]")); 40 assert!(MANAGEMENT_FIXTURE.contains("active = [\"cli_v1\", \"unix_admin_v1\"]")); 41 assert!(MANAGEMENT_FIXTURE.contains( 42 "actions = [\"config_init\", \"config_validate\", \"state_init\", \"run\", \"status\", \"doctor\"]" 43 )); 44 assert!(MANAGEMENT_FIXTURE.contains("destructive_actions = []")); 45 assert!(MANAGEMENT_FIXTURE.contains("runtime_binding = \"typed_runtime_context\"")); 46 assert!(MANAGEMENT_FIXTURE.contains("admin_endpoint = \"runtime_context_admin_socket\"")); 47 } 48 49 #[test] 50 fn management_contract_is_bounded_before_toml_admission() { 51 assert!( 52 MANAGER_ROOT_SOURCE.contains("if raw.len() > RUNTIME_MANAGEMENT_CONTRACT_MAX_UTF8_BYTES") 53 ); 54 let bound = MANAGER_ROOT_SOURCE 55 .find("if raw.len() > RUNTIME_MANAGEMENT_CONTRACT_MAX_UTF8_BYTES") 56 .expect("pre-parser bound"); 57 let parser = MANAGER_ROOT_SOURCE 58 .find("toml::from_str::<RadrootsRuntimeManagementContract>(raw)") 59 .expect("TOML parser"); 60 assert!( 61 bound < parser, 62 "contract size must be checked before parsing" 63 ); 64 } 65 66 #[test] 67 fn public_package_contains_only_typed_cli_and_bounded_admin_authority() { 68 let sources = [ 69 production_source(MANAGER_ROOT_SOURCE), 70 production_source(MANAGER_SOURCE), 71 production_source(CLI_SOURCE), 72 production_source(MODEL_SOURCE), 73 #[cfg(any(target_os = "linux", target_os = "macos"))] 74 production_source(STATUS_SOURCE), 75 ]; 76 let production = sources.join("\n"); 77 for forbidden in [ 78 "std::fs", 79 "std::process", 80 "ManagedRuntimeArtifactName", 81 "ManagedRuntimeInstancePaths", 82 "ManagedRuntimeSharedPaths", 83 "ManagedRuntimeInstanceRegistry", 84 "ManagedRuntimeInstanceRecord", 85 "load_registry", 86 "save_registry", 87 "register_instance", 88 "remove_instance", 89 "start_process", 90 "stop_process", 91 "process_running", 92 "install_binary", 93 "extract_binary_archive", 94 "remove_instance_artifacts", 95 "write_instance_config", 96 "inspect_runtime_", 97 "read_secret", 98 "credential_path", 99 "binary_name", 100 "archive_name", 101 "install_path", 102 ] { 103 assert!( 104 !production.contains(forbidden), 105 "production surface retained `{forbidden}`" 106 ); 107 } 108 109 for forbidden_dependency in ["flate2", "tar ="] { 110 assert!( 111 !MANIFEST.contains(forbidden_dependency), 112 "manifest retained `{forbidden_dependency}`" 113 ); 114 } 115 116 for required in [ 117 "sole service, instance,\nprofile, and canonical-path authority", 118 "exact CLI-v1 argument\nplans", 119 "fixed `/v1/status`", 120 "never discovers or executes a program", 121 "Artifact and\ndistribution resolution remains separately governed by Step220", 122 ] { 123 assert!(README.contains(required), "README omitted `{required}`"); 124 } 125 126 for required in ["RuntimeContext", "ManagedCliInvocation"] { 127 assert!( 128 production.contains(required), 129 "production omitted `{required}`" 130 ); 131 } 132 #[cfg(any(target_os = "linux", target_os = "macos"))] 133 for required in ["AdminClient", "AdminClientTarget", "STATUS_V1_TARGET"] { 134 assert!( 135 production.contains(required), 136 "native production omitted `{required}`" 137 ); 138 } 139 }