services_hardening_control_surfaces.rs (2981B)
1 #![forbid(unsafe_code)] 2 #![cfg(any(target_os = "linux", target_os = "macos"))] 3 4 use myc::{ 5 MYC_DOCTOR_CHECK_COUNT, MYC_LIVEZ_PATH, MYC_METRICS_PATH, MYC_READYZ_PATH, 6 MycAdminCancellationToken, MycAdminRoute, 7 }; 8 9 const CONTRACT: &str = include_str!("../contracts/services_hardening/control_surfaces.v1.json"); 10 const ADMIN_SOURCE: &str = include_str!("../src/admin_v1.rs"); 11 12 #[test] 13 fn unit_13_contract_binds_the_complete_production_control_surface_inventory() { 14 let contract: serde_json::Value = serde_json::from_str(CONTRACT).expect("control contract"); 15 assert_eq!(contract["schema"], "radroots.myc.control-surfaces.v1"); 16 assert_eq!(contract["contract_version"], 1); 17 assert_eq!(contract["step"], 159); 18 assert_eq!(contract["unit"], 13); 19 assert_eq!(contract["unit_id"], "myc-control-surfaces"); 20 assert_eq!(contract["admin"]["route_count"], 19); 21 assert_eq!(contract["admin"]["model_count"], 32); 22 assert_eq!(MycAdminRoute::ALL.len(), 19); 23 assert_eq!(contract["admin"]["live_identity_mutation_routes"], false); 24 assert_eq!(contract["status"]["publisher_count"], 1); 25 assert_eq!(contract["doctor"]["check_count"], MYC_DOCTOR_CHECK_COUNT); 26 assert_eq!( 27 contract["operations"]["routes"], 28 serde_json::json!([MYC_LIVEZ_PATH, MYC_READYZ_PATH, MYC_METRICS_PATH]) 29 ); 30 assert_eq!( 31 contract["deferred"]["authoritative_daemon_task_graph"], 32 "unit_15" 33 ); 34 } 35 36 #[test] 37 fn admin_server_is_sealed_around_canonical_paths_limits_and_system_entropy() { 38 let production = ADMIN_SOURCE 39 .split("\n#[cfg(test)]\nmod tests") 40 .next() 41 .expect("production source"); 42 for required in [ 43 "AdminServer::with_system_entropy(router.into_inner(), limits)", 44 ".pointer(\"/resource_limits/admin\")", 45 "UnixAdminSocketWriterAuthority::acquire(runtime.context().paths().run())", 46 "UnixAdminSocketBinding::bind(authority, runtime.artifacts().admin_socket())", 47 "pub struct MycAdminServer", 48 "pub struct MycBoundAdminServer", 49 "pub struct MycAdminCancellationToken", 50 ] { 51 assert!( 52 production.contains(required), 53 "admin source is missing `{required}`" 54 ); 55 } 56 for forbidden in [ 57 "pub fn into_inner", 58 "pub const fn into_inner", 59 "pub fn listener", 60 "pub fn router", 61 "TcpListener", 62 "std::process::exit", 63 "tokio::spawn", 64 ] { 65 assert!( 66 !production.contains(forbidden), 67 "admin source exposes forbidden `{forbidden}`" 68 ); 69 } 70 } 71 72 #[test] 73 fn control_surface_cancellation_is_idempotent_and_redacted() { 74 let token = MycAdminCancellationToken::new(); 75 assert!(!token.is_cancelled()); 76 token.cancel(); 77 token.cancel(); 78 assert!(token.is_cancelled()); 79 let rendered = format!("{token:?}"); 80 assert!(!rendered.contains("/private/control.sock")); 81 assert!(!rendered.contains("credential")); 82 }