services_hardening_wave_100_a.rs (3149B)
1 #![forbid(unsafe_code)] 2 3 use std::path::Path; 4 5 use rhi::{RHI_CONFIG_SCHEMA, RhiConfigProfile, parse_rhi_config_v1}; 6 use serde_json::Value; 7 8 const CONFIG_EXAMPLE: &str = include_str!("../contracts/services_hardening/config.v1.example.toml"); 9 const CONFIG_SCHEMA: &str = include_str!("../contracts/services_hardening/config.v1.schema.json"); 10 const SOURCE_LOCK: &str = include_str!("../radroots.service.source-lock.v3.toml"); 11 12 #[test] 13 fn canonical_example_agrees_with_the_exact_schema_and_parser() { 14 let schema: Value = serde_json::from_str(CONFIG_SCHEMA).expect("configuration schema"); 15 let example: toml::Value = toml::from_str(CONFIG_EXAMPLE).expect("canonical example TOML"); 16 let example = serde_json::to_value(example).expect("canonical example JSON projection"); 17 let errors = jsonschema::validator_for(&schema) 18 .expect("configuration schema compiles") 19 .iter_errors(&example) 20 .map(|error| error.to_string()) 21 .collect::<Vec<_>>(); 22 assert!(errors.is_empty(), "schema/parser example drift: {errors:?}"); 23 24 let document = parse_rhi_config_v1(CONFIG_EXAMPLE.as_bytes(), RhiConfigProfile::Production) 25 .expect("the canonical example must pass the production parser"); 26 assert_eq!(document.schema(), RHI_CONFIG_SCHEMA); 27 assert_eq!(document.profile(), RhiConfigProfile::Production); 28 assert!(document.effective().field_count() > 0); 29 } 30 31 #[test] 32 fn wave_one_removed_files_remain_absent_after_nix_qualification() { 33 let root = Path::new(env!("CARGO_MANIFEST_DIR")); 34 for removed in [ 35 "config.toml", 36 "radroots.lib.source-lock.v1.toml", 37 "src/config.rs", 38 "src/host_nostr.rs", 39 "src/host_runtime.rs", 40 "src/rhi.rs", 41 ] { 42 assert!( 43 !root.join(removed).exists(), 44 "removed path remains: {removed}" 45 ); 46 } 47 assert!(!root.join("radroots.service.source-lock.v2.toml").exists()); 48 assert!(root.join("radroots.service.source-lock.v3.toml").is_file()); 49 assert!(root.join("flake.nix").is_file()); 50 assert!(root.join("flake.lock").is_file()); 51 assert!(SOURCE_LOCK.starts_with( 52 "schema = \"radroots.service.source-lock.v3\"\ncontract_version = 3\nservice = \"rhi\"\n" 53 )); 54 assert!(SOURCE_LOCK.contains("material = \"qualified\"")); 55 assert!(SOURCE_LOCK.contains("lib_revision = \"055096853fca95e15d0f813d33a14aca13be3881\"")); 56 } 57 58 #[test] 59 fn executable_has_no_prototype_runtime_fallback() { 60 let main = include_str!("../src/main.rs"); 61 for forbidden in [ 62 "load_settings_from_path", 63 "run_rhi", 64 "init_rhi_logging", 65 "tokio::runtime", 66 "tracing_subscriber", 67 "RHI_", 68 ] { 69 assert!( 70 !main.contains(forbidden), 71 "executable retains prototype fallback: {forbidden}" 72 ); 73 } 74 assert!(main.contains("parse_rhi_cli_v1_from")); 75 assert!(main.contains("execute_rhi_cli_v1_with_signal_source")); 76 assert!(main.contains("RhiProcessResult::InputOrConfiguration")); 77 let process = include_str!("../src/process_v1.rs"); 78 assert!(process.contains("resolve_rhi_runtime_context")); 79 }