ci(gateway): slim Test (Gateway) batch 1 — split architecture guards, pin build fingerprint

第一批减负(对应 docs/operations/gateway-ci-timeout-reduction-plan.md):

A1 架构守卫迁出
- 将 src/tests/architecture/**(208 项 / 约 1.5 万行字符串断言)迁至
  tests/architecture/,入口 tests/architecture_guard.rs
- 从 lib cfg(test) 巨型编译单元移除,压低 rustc 峰值与 OOM 风险
- 断言逻辑不变;helper 可见性改为 pub(crate)

A2 构建指纹统一
- test_gateway 的 mold RUSTFLAGS / RUST_MIN_STACK / sccache 上移至 job 级 env
- rust-ci.yml 全部 toolchain 钉住 1.95.0(与 rust-toolchain.toml、fmt/clippy 一致)
- Gateway 独立 cache key,避免 mold 指纹与无 mold job 互相污染

A4 补安全集成测试
- 新增 Test integration targets:cargo nextest run -p aether-gateway --tests
- 覆盖 architecture_guard + 此前未执行的 admin_unsigned_identity_headers

验证:architecture_guard + admin_unsigned 209 passed;
cargo check -p aether-gateway --lib --tests 通过;cargo fmt --check 通过。

不创建 PR,仅本地分支提交。
This commit is contained in:
AAEE86
2026-09-23 17:51:45 +08:00
parent 57f53903f5
commit 3394a51278
17 changed files with 311 additions and 27 deletions
-1
View File
@@ -10,7 +10,6 @@ pub(super) use http::StatusCode;
pub(super) use serde_json::json;
mod ai_execute;
mod architecture;
mod async_task;
mod audit;
mod concurrency;
@@ -1194,7 +1194,7 @@ fn ai_serving_planner_separates_local_candidate_resolution_from_ranking() {
let candidate_resolution =
read_workspace_file("apps/aether-gateway/src/ai_serving/planner/candidate_resolution.rs");
let ranking_call = candidate_resolution
candidate_resolution
.find("rank_eligible_local_execution_candidates(")
.expect("candidate_resolution.rs should call core-backed local candidate ranking");
assert!(
@@ -5045,7 +5045,9 @@ fn retired_api_format_occurrences_are_whitelisted() {
.expect("file should be under workspace root")
.to_string_lossy()
.replace('\\', "/");
if relative == "apps/aether-gateway/src/tests/architecture/ai_serving.rs" {
if relative == "apps/aether-gateway/tests/architecture/ai_serving.rs"
|| relative == "apps/aether-gateway/src/tests/architecture/ai_serving.rs"
{
continue;
}
@@ -1,7 +1,9 @@
use std::fs;
use std::path::{Path, PathBuf};
pub(super) fn collect_rust_files(root: &Path, files: &mut Vec<PathBuf>) {
// 架构守卫在独立 integration test 中是顶层模块;helper 统一 pub(crate),
// 子模块经 `use super::*` / `use super::{...}` 访问(与原 lib 内布局一致)。
pub(crate) fn collect_rust_files(root: &Path, files: &mut Vec<PathBuf>) {
for entry in fs::read_dir(root).expect("directory should be readable") {
let entry = entry.expect("directory entry should be readable");
let path = entry.path();
@@ -15,7 +17,7 @@ pub(super) fn collect_rust_files(root: &Path, files: &mut Vec<PathBuf>) {
}
}
pub(super) fn assert_no_sqlx_queries(root_relative_path: &str) {
pub(crate) fn assert_no_sqlx_queries(root_relative_path: &str) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
@@ -80,7 +82,7 @@ fn sql_pool_scan_distinguishes_pool_types_from_repository_names() {
));
}
pub(super) fn assert_no_sensitive_log_patterns(root_relative_path: &str, patterns: &[&str]) {
pub(crate) fn assert_no_sensitive_log_patterns(root_relative_path: &str, patterns: &[&str]) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
@@ -109,7 +111,7 @@ pub(super) fn assert_no_sensitive_log_patterns(root_relative_path: &str, pattern
);
}
pub(super) fn assert_no_module_dependency_patterns(root_relative_path: &str, patterns: &[&str]) {
pub(crate) fn assert_no_module_dependency_patterns(root_relative_path: &str, patterns: &[&str]) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
@@ -138,14 +140,14 @@ pub(super) fn assert_no_module_dependency_patterns(root_relative_path: &str, pat
);
}
pub(super) fn workspace_file_exists(root_relative_path: &str) -> bool {
pub(crate) fn workspace_file_exists(root_relative_path: &str) -> bool {
Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path)
.exists()
}
pub(super) fn workspace_files_with_extension(
pub(crate) fn workspace_files_with_extension(
root_relative_path: &str,
extension: &str,
) -> Vec<PathBuf> {
@@ -162,7 +164,7 @@ pub(super) fn workspace_files_with_extension(
files
}
pub(super) fn collect_workspace_rust_files(root_relative_path: &str) -> Vec<PathBuf> {
pub(crate) fn collect_workspace_rust_files(root_relative_path: &str) -> Vec<PathBuf> {
let root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path);
@@ -172,7 +174,7 @@ pub(super) fn collect_workspace_rust_files(root_relative_path: &str) -> Vec<Path
files
}
pub(super) fn read_workspace_file(path: &str) -> String {
pub(crate) fn read_workspace_file(path: &str) -> String {
let workspace_root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.canonicalize()
@@ -180,7 +182,7 @@ pub(super) fn read_workspace_file(path: &str) -> String {
fs::read_to_string(workspace_root.join(path)).expect("source file should be readable")
}
pub(super) fn read_workspace_module_tree(path: &str) -> String {
pub(crate) fn read_workspace_module_tree(path: &str) -> String {
let workspace_root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.canonicalize()
@@ -1,4 +1,4 @@
use std::path::{Path, PathBuf};
use std::path::Path;
use super::*;
@@ -0,0 +1,5 @@
//! 架构守卫独立测试目标。
//!
//! 从 lib 的 `cfg(test)` 巨型编译单元迁出:只做源码/manifest 字符串断言,
//! 不启动 AppState、不依赖 gateway 私有类型,用于压低 lib test 编译面与 rustc 峰值。
mod architecture;