ci(gateway): slim Test (Gateway) batch 1 — split architecture guards, pin build fingerprint

第一批减负(对应 docs/operations/gateway-ci-timeout-reduction-plan.md):

A1 架构守卫迁出
- 将 src/tests/architecture/**(208 项 / 约 1.5 万行字符串断言)迁至
  tests/architecture/,入口 tests/architecture_guard.rs
- 从 lib cfg(test) 巨型编译单元移除,压低 rustc 峰值与 OOM 风险
- 断言逻辑不变;helper 可见性改为 pub(crate)

A2 构建指纹统一
- test_gateway 的 mold RUSTFLAGS / RUST_MIN_STACK / sccache 上移至 job 级 env
- rust-ci.yml 全部 toolchain 钉住 1.95.0(与 rust-toolchain.toml、fmt/clippy 一致)
- Gateway 独立 cache key,避免 mold 指纹与无 mold job 互相污染

A4 补安全集成测试
- 新增 Test integration targets:cargo nextest run -p aether-gateway --tests
- 覆盖 architecture_guard + 此前未执行的 admin_unsigned_identity_headers

验证:architecture_guard + admin_unsigned 209 passed;
cargo check -p aether-gateway --lib --tests 通过;cargo fmt --check 通过。

不创建 PR,仅本地分支提交。
This commit is contained in:
AAEE86
2026-09-23 17:51:45 +08:00
parent 57f53903f5
commit 3394a51278
17 changed files with 311 additions and 27 deletions
@@ -0,0 +1,227 @@
use std::fs;
use std::path::{Path, PathBuf};
// 架构守卫在独立 integration test 中是顶层模块;helper 统一 pub(crate),
// 子模块经 `use super::*` / `use super::{...}` 访问(与原 lib 内布局一致)。
pub(crate) fn collect_rust_files(root: &Path, files: &mut Vec<PathBuf>) {
for entry in fs::read_dir(root).expect("directory should be readable") {
let entry = entry.expect("directory entry should be readable");
let path = entry.path();
if path.is_dir() {
collect_rust_files(&path, files);
continue;
}
if path.extension().and_then(|value| value.to_str()) == Some("rs") {
files.push(path);
}
}
}
pub(crate) fn assert_no_sqlx_queries(root_relative_path: &str) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
let patterns = [
"sqlx::query(",
"sqlx::query_scalar",
"sqlx::postgres::PgRow",
"sqlx::Row",
"PostgresPoolFactory",
"PostgresPool",
"query_scalar::<",
"QueryBuilder<",
];
let violations = files
.into_iter()
.filter_map(|path| {
let source = fs::read_to_string(&path).expect("source file should be readable");
let hits = patterns
.iter()
.filter(|pattern| source_contains_sql_pattern(&source, pattern))
.copied()
.collect::<Vec<_>>();
if hits.is_empty() {
None
} else {
Some(format!("{} -> {}", path.display(), hits.join(", ")))
}
})
.collect::<Vec<_>>();
assert!(
violations.is_empty(),
"disallowed SQL ownership violations:\n{}",
violations.join("\n")
);
}
fn source_contains_sql_pattern(source: &str, pattern: &str) -> bool {
if pattern == "PostgresPool" {
source
.split(|character: char| !character.is_ascii_alphanumeric() && character != '_')
.any(|identifier| identifier == pattern)
} else {
source.contains(pattern)
}
}
#[test]
fn sql_pool_scan_distinguishes_pool_types_from_repository_names() {
assert!(source_contains_sql_pattern(
"pool: PostgresPool",
"PostgresPool"
));
assert!(source_contains_sql_pattern(
"PostgresPool::connect(url)",
"PostgresPool"
));
assert!(!source_contains_sql_pattern(
"PostgresPoolMemberScoreRepository::new(pool)",
"PostgresPool"
));
}
pub(crate) fn assert_no_sensitive_log_patterns(root_relative_path: &str, patterns: &[&str]) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
let violations = files
.into_iter()
.filter_map(|path| {
let source = fs::read_to_string(&path).expect("source file should be readable");
let hits = patterns
.iter()
.filter(|pattern| source.contains(**pattern))
.copied()
.collect::<Vec<_>>();
if hits.is_empty() {
None
} else {
Some(format!("{} -> {}", path.display(), hits.join(", ")))
}
})
.collect::<Vec<_>>();
assert!(
violations.is_empty(),
"disallowed sensitive logging patterns:\n{}",
violations.join("\n")
);
}
pub(crate) fn assert_no_module_dependency_patterns(root_relative_path: &str, patterns: &[&str]) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
let violations = files
.into_iter()
.filter_map(|path| {
let source = fs::read_to_string(&path).expect("source file should be readable");
let hits = patterns
.iter()
.filter(|pattern| source.contains(**pattern))
.copied()
.collect::<Vec<_>>();
if hits.is_empty() {
None
} else {
Some(format!("{} -> {}", path.display(), hits.join(", ")))
}
})
.collect::<Vec<_>>();
assert!(
violations.is_empty(),
"disallowed module dependency patterns:\n{}",
violations.join("\n")
);
}
pub(crate) fn workspace_file_exists(root_relative_path: &str) -> bool {
Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path)
.exists()
}
pub(crate) fn workspace_files_with_extension(
root_relative_path: &str,
extension: &str,
) -> Vec<PathBuf> {
let root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path);
let mut files = fs::read_dir(root)
.expect("workspace directory should be readable")
.filter_map(Result::ok)
.map(|entry| entry.path())
.filter(|path| path.extension().and_then(|value| value.to_str()) == Some(extension))
.collect::<Vec<_>>();
files.sort();
files
}
pub(crate) fn collect_workspace_rust_files(root_relative_path: &str) -> Vec<PathBuf> {
let root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
files.sort();
files
}
pub(crate) fn read_workspace_file(path: &str) -> String {
let workspace_root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.canonicalize()
.expect("workspace root should resolve");
fs::read_to_string(workspace_root.join(path)).expect("source file should be readable")
}
pub(crate) fn read_workspace_module_tree(path: &str) -> String {
let workspace_root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.canonicalize()
.expect("workspace root should resolve");
let root_path = workspace_root.join(path);
let mut contents =
vec![fs::read_to_string(&root_path).expect("source file should be readable")];
let module_dir = if root_path.file_name().and_then(|value| value.to_str()) == Some("mod.rs") {
root_path
.parent()
.expect("mod.rs should have parent module directory")
.to_path_buf()
} else if root_path.extension().and_then(|value| value.to_str()) == Some("rs") {
root_path.with_extension("")
} else {
root_path.clone()
};
if module_dir.is_dir() {
let mut files = Vec::new();
collect_rust_files(&module_dir, &mut files);
files.sort();
for file in files {
contents.push(fs::read_to_string(file).expect("source file should be readable"));
}
}
contents.join("\n")
}
mod admin_billing;
mod admin_model;
mod admin_observability;
mod admin_provider;
mod admin_shared;
mod admin_system;
mod admin_users;
mod ai_serving;
mod runtime_and_security;
mod sql_and_data;
mod usage;
mod workspace_tiers;