Merge pull request #854 from AAEE86/ci/gateway-test-slim-batch1

ci: fix Nightly scope detection in reusable Rust CI
This commit is contained in:
ZheFox
2026-09-29 10:19:06 +08:00
committed by GitHub
4 changed files with 134 additions and 10 deletions
+4 -6
View File
@@ -1,8 +1,6 @@
# GitHub-hosted ubuntu runner 当前按 4 vCPU 配置;固定线程数可避免 runner
# 规格变化时测试并发和内存峰值随之漂移。
# 不固定 test-threads:nextest 默认按 num-cpus 并发,固定值会在更大规格的
# runner 或本地开发机上主动压低并发、反而变慢,且无法表达 min(4, num-cpus)。
# 这里只保留卡死保护,避免单个挂起用例拖满整个 job。
[profile.default]
test-threads = 4
# 60 秒后标记慢测试,连续两轮仍未结束则终止,避免单个卡死用例拖满整个 job。
# 真实连接/数据库测试仍有足够时间完成;超时结果保持失败,不隐藏回归。
# 60 秒后标记慢测试,连续两轮仍未结束则终止;超时结果保持失败,不隐藏回归。
slow-timeout = { period = "60s", terminate-after = 2, grace-period = "10s" }
+2
View File
@@ -63,6 +63,8 @@ jobs:
name: Rust CI
needs: source
uses: ./.github/workflows/rust-ci.yml
with:
full_scope: true
rust_extended:
name: Rust extended checks
+92 -4
View File
@@ -2,11 +2,71 @@ name: Rust CI
on:
workflow_call:
inputs:
full_scope:
description: "Run all Rust and shell scopes, used by Nightly"
required: false
type: boolean
default: false
push:
branches:
- master
- main
paths:
- "Cargo.toml"
- "Cargo.lock"
- "rust-toolchain.toml"
- ".cargo/**"
- "crates/**"
- "apps/**"
- "*.sql"
- "install.sh"
- "deploy.sh"
- "update.sh"
- "generate_keys.sh"
- ".env.example"
- "README.md"
- "Dockerfile.app"
- "docker-compose.yml"
- "docker-compose.single-node.yml"
- "docker-compose.local.yml"
- "docker-compose.release-local.yml"
- "tests/compose_database_config_test.py"
- "tests/install_*_test.sh"
- "tests/deploy_*_test.sh"
- "tests/update_*_test.sh"
- "tests/release_supply_chain_test.sh"
- "tests/tunnel_installer_config_security_test.sh"
- ".github/workflows/*.yml"
- ".github/workflows/*.yaml"
pull_request:
paths:
- "Cargo.toml"
- "Cargo.lock"
- "rust-toolchain.toml"
- ".cargo/**"
- "crates/**"
- "apps/**"
- "*.sql"
- "install.sh"
- "deploy.sh"
- "update.sh"
- "generate_keys.sh"
- ".env.example"
- "README.md"
- "Dockerfile.app"
- "docker-compose.yml"
- "docker-compose.single-node.yml"
- "docker-compose.local.yml"
- "docker-compose.release-local.yml"
- "tests/compose_database_config_test.py"
- "tests/install_*_test.sh"
- "tests/deploy_*_test.sh"
- "tests/update_*_test.sh"
- "tests/release_supply_chain_test.sh"
- "tests/tunnel_installer_config_security_test.sh"
- ".github/workflows/*.yml"
- ".github/workflows/*.yaml"
concurrency:
group: rust-ci-${{ github.event_name }}-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
@@ -36,24 +96,43 @@ jobs:
- name: Classify changed paths
id: scope
shell: bash
env:
RUST_CI_FULL_SCOPE: ${{ inputs.full_scope || false }}
run: |
# workflow_call(Nightly)仍须完整执行;普通 push/PR 只按源码和构建
# 任何命令失败都必须让本 job 失败,否则 git fetch/diff 出错后仍会写出
# rust=false/shell=false,下游会误判为“无需测试”而假绿放行。
set -euo pipefail
# Nightly 通过 workflow_call 显式传入 full_scope;普通 push/PR 只按源码和构建
# 指纹触发 Rust jobs,安装脚本、Compose、README 等由 shell scope 覆盖。
if [ "$GITHUB_EVENT_NAME" = "workflow_call" ]; then
if [ "$RUST_CI_FULL_SCOPE" = "true" ]; then
echo "rust=true" >> "$GITHUB_OUTPUT"
echo "shell=true" >> "$GITHUB_OUTPUT"
exit 0
fi
if [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then
if [ "$GITHUB_EVENT_NAME" = "pull_request" ] \
&& [ -n "${GITHUB_BASE_REF:-}" ] \
&& [ -n "${GITHUB_SHA:-}" ]; then
git fetch --no-tags origin "$GITHUB_BASE_REF" --depth=1
changed_paths=$(git diff --name-only "origin/$GITHUB_BASE_REF...$GITHUB_SHA")
elif [ "$GITHUB_EVENT_NAME" = "push" ] && [ "$GITHUB_EVENT_BEFORE" != "0000000000000000000000000000000000000000" ]; then
elif [ "$GITHUB_EVENT_NAME" = "push" ] \
&& [ -n "${GITHUB_EVENT_BEFORE:-}" ] \
&& [ "$GITHUB_EVENT_BEFORE" != "0000000000000000000000000000000000000000" ] \
&& [ -n "${GITHUB_SHA:-}" ]; then
changed_paths=$(git diff --name-only "$GITHUB_EVENT_BEFORE" "$GITHUB_SHA")
else
changed_paths=$(git ls-files)
fi
# 防御性兜底:diff 结果为空(异常事件或比较失败)时按全量运行,
# 宁可多跑也不能漏测。
if [ -z "$changed_paths" ]; then
echo "rust=true" >> "$GITHUB_OUTPUT"
echo "shell=true" >> "$GITHUB_OUTPUT"
exit 0
fi
rust=false
shell=false
while IFS= read -r path; do
@@ -646,6 +725,10 @@ jobs:
steps:
- name: Verify database smoke jobs
run: |
if [ "${{ needs.changes.result }}" != "success" ]; then
echo "Scope detection failed"
exit 1
fi
if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then
echo "Rust scope unchanged; database smoke jobs skipped"
exit 0
@@ -669,6 +752,11 @@ jobs:
steps:
- name: Verify required jobs
run: |
# changes 失败或未产出 scope 时不允许直接放行,避免假绿。
if [ "${{ needs.changes.result }}" != "success" ]; then
echo "Scope detection failed"
exit 1
fi
rust="${{ needs.changes.outputs.rust }}"
shell="${{ needs.changes.outputs.shell }}"
@@ -387,6 +387,42 @@ async fn gateway_handles_admin_security_blacklist_add_locally_with_trusted_admin
assert_eq!(upstream_count, 0);
}
/// 真实 TCP 冒烟测试:其余安全用例已改为进程内 Router 调用以提速,这里保留一条
/// 覆盖网络层装配(真实监听端口、HTTP 请求头传递、JSON 收发)的端到端路径。
///
/// `/api/admin/security/*` 在路由分类中是本地管理端点
/// (`execution_runtime_candidate: false`),架构上不经过任何可注入 base_url 的上游,
/// 因此这里不构造无意义的“上游计数器”,只验证真实链路下本地处理结果正确。
#[tokio::test]
async fn gateway_serves_admin_security_blacklist_over_real_tcp() {
let gateway = build_router_with_state(AppState::new().expect("gateway should build"));
let (gateway_url, gateway_handle) = start_server(gateway).await;
let response = reqwest::Client::new()
.post(format!("{gateway_url}/api/admin/security/ip/blacklist"))
.header(GATEWAY_HEADER, "rust-phase3b")
.header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123")
.header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin")
.header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123")
.json(&json!({ "ip_address": "1.2.3.4", "reason": "manual", "ttl": 60 }))
.send()
.await
.expect("request should reach the gateway over TCP");
let status = response.status();
let payload: serde_json::Value = response
.json()
.await
.expect("gateway response should be json");
assert_eq!(status, StatusCode::OK);
assert_eq!(payload["success"], true);
assert_eq!(payload["message"], "IP 1.2.3.4 已加入黑名单");
assert_eq!(payload["reason"], "manual");
assert_eq!(payload["ttl"], 60);
gateway_handle.abort();
}
#[tokio::test]
async fn gateway_rejects_invalid_admin_security_blacklist_ip() {
let gateway = build_router_with_state(AppState::new().expect("gateway should build"));