build_policy.rs (4904B)
1 #![forbid(unsafe_code)] 2 3 use sha2::{Digest, Sha256}; 4 5 const MANIFEST: &str = include_str!("../Cargo.toml"); 6 const RELEASE_ACCEPTANCE: &str = include_str!("../scripts/release-acceptance.sh"); 7 const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v3.toml"); 8 const FLAKE_LOCK: &[u8] = include_bytes!("../flake.lock"); 9 10 #[test] 11 fn manifest_freezes_the_final_rust_policy() { 12 assert!(MANIFEST.contains("[workspace]\nresolver = \"3\"")); 13 assert!(MANIFEST.contains("[workspace.lints.rust]\nunsafe_code = \"deny\"")); 14 assert!(MANIFEST.contains("[workspace.lints.rustdoc]\nbroken_intra_doc_links = \"deny\"")); 15 assert!(MANIFEST.contains( 16 "[workspace.lints.clippy]\ndbg_macro = \"deny\"\ntodo = \"deny\"\nunimplemented = \"deny\"" 17 )); 18 assert!(MANIFEST.contains("[lints]\nworkspace = true")); 19 } 20 21 #[test] 22 fn service_host_is_the_exact_default_feature_profile() { 23 assert!(MANIFEST.contains("[features]\ndefault = [\"service-host\"]\nservice-host = []")); 24 assert!(!MANIFEST.contains("getrandom = \"0.2\"")); 25 assert!(MANIFEST.contains( 26 "tokio = { version = \"1.48\", default-features = false, features = [\"io-util\", \"macros\", \"net\", \"rt-multi-thread\", \"signal\", \"sync\", \"time\"] }" 27 )); 28 } 29 30 #[test] 31 fn shared_runtime_paths_is_exactly_pinned_to_the_source_locked_lib() { 32 assert!(MANIFEST.contains( 33 "radroots_runtime_paths = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }" 34 )); 35 } 36 37 #[test] 38 fn shared_identity_is_exactly_pinned_to_the_source_locked_lib() { 39 assert!(MANIFEST.contains( 40 "radroots_identity = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }" 41 )); 42 } 43 44 #[test] 45 fn shared_service_host_is_exactly_pinned_to_the_source_locked_lib() { 46 assert!(MANIFEST.contains( 47 "radroots_service_host = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }" 48 )); 49 } 50 51 #[test] 52 fn shared_service_sqlite_is_exactly_pinned_to_the_source_locked_lib() { 53 assert!(MANIFEST.contains( 54 "radroots_service_sqlite = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\" }" 55 )); 56 } 57 58 #[test] 59 fn shared_storage_evidence_is_exactly_pinned_to_the_source_locked_lib() { 60 assert!(MANIFEST.contains( 61 "radroots_storage = { git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\", default-features = false }" 62 )); 63 } 64 65 #[test] 66 fn delivery_dependencies_are_exactly_source_locked() { 67 for dependency in [ 68 "radroots_event_codec", 69 "radroots_transport", 70 "radroots_transport_nostr", 71 ] { 72 assert!( 73 MANIFEST.contains(&format!( 74 "{dependency} = {{ git = \"https://github.com/radrootslabs/lib\", rev = \"055096853fca95e15d0f813d33a14aca13be3881\", version = \"=0.1.0-alpha\"" 75 )), 76 "{dependency} is not pinned to the exact source lock" 77 ); 78 } 79 } 80 81 #[test] 82 fn release_acceptance_checks_both_feature_profiles() { 83 assert!( 84 RELEASE_ACCEPTANCE.contains("cargo check --locked --all-targets --no-default-features\n") 85 ); 86 assert!(RELEASE_ACCEPTANCE.contains( 87 "cargo check --locked --all-targets --no-default-features --features service-host\n" 88 )); 89 assert!(RELEASE_ACCEPTANCE.contains("cargo test --locked -p myc_xtask\n")); 90 assert!(!RELEASE_ACCEPTANCE.contains("nix ")); 91 } 92 93 #[test] 94 fn source_lock_binds_the_current_cargo_lock() { 95 let digest = hex::encode(Sha256::digest(include_bytes!("../Cargo.lock"))); 96 let flake_digest = hex::encode(Sha256::digest(FLAKE_LOCK)); 97 assert!(SOURCE_LOCK.starts_with( 98 "schema = \"radroots.service.source-lock.v3\"\ncontract_version = 3\nservice = \"myc\"\n" 99 )); 100 assert!(SOURCE_LOCK.contains(&format!("cargo_lock_sha256 = \"{digest}\""))); 101 assert!(SOURCE_LOCK.contains(&format!("sha256 = \"{flake_digest}\""))); 102 assert!(SOURCE_LOCK.contains("revision = \"055096853fca95e15d0f813d33a14aca13be3881\"")); 103 assert!(SOURCE_LOCK.contains( 104 "[nix]\nmaterial = \"qualified\"\nlib_revision = \"055096853fca95e15d0f813d33a14aca13be3881\"\nsupported_systems = [\"aarch64-darwin\", \"x86_64-linux\"]\n" 105 )); 106 assert!(SOURCE_LOCK.contains( 107 "workspace_catalog_sha256 = \"deca0c080deae187ff8186c0708903e42f41ea57f77c5f91581e23aa561164a4\"" 108 )); 109 assert!(SOURCE_LOCK.contains( 110 "source_archive_sha256 = \"89b8ace3f61167df43aca89917405d58b2aaf2ddea8fadfb21d351d76f184e68\"" 111 )); 112 assert!(SOURCE_LOCK.ends_with( 113 "[contract_versions]\nconfig = 1\nstate = 12\nadmin = 1\nstatus = 1\nprovider = 1\n" 114 )); 115 }