Files
Aether/apps/aether-gateway/tests/architecture/mod.rs
T
AAEE86 3394a51278 ci(gateway): slim Test (Gateway) batch 1 — split architecture guards, pin build fingerprint
第一批减负(对应 docs/operations/gateway-ci-timeout-reduction-plan.md):

A1 架构守卫迁出
- 将 src/tests/architecture/**(208 项 / 约 1.5 万行字符串断言)迁至
  tests/architecture/,入口 tests/architecture_guard.rs
- 从 lib cfg(test) 巨型编译单元移除,压低 rustc 峰值与 OOM 风险
- 断言逻辑不变;helper 可见性改为 pub(crate)

A2 构建指纹统一
- test_gateway 的 mold RUSTFLAGS / RUST_MIN_STACK / sccache 上移至 job 级 env
- rust-ci.yml 全部 toolchain 钉住 1.95.0(与 rust-toolchain.toml、fmt/clippy 一致)
- Gateway 独立 cache key,避免 mold 指纹与无 mold job 互相污染

A4 补安全集成测试
- 新增 Test integration targets:cargo nextest run -p aether-gateway --tests
- 覆盖 architecture_guard + 此前未执行的 admin_unsigned_identity_headers

验证:architecture_guard + admin_unsigned 209 passed;
cargo check -p aether-gateway --lib --tests 通过;cargo fmt --check 通过。

不创建 PR,仅本地分支提交。
2026-09-23 17:51:45 +08:00

228 lines
7.0 KiB
Rust
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
use std::fs;
use std::path::{Path, PathBuf};
// 架构守卫在独立 integration test 中是顶层模块;helper 统一 pub(crate),
// 子模块经 `use super::*` / `use super::{...}` 访问(与原 lib 内布局一致)。
pub(crate) fn collect_rust_files(root: &Path, files: &mut Vec<PathBuf>) {
for entry in fs::read_dir(root).expect("directory should be readable") {
let entry = entry.expect("directory entry should be readable");
let path = entry.path();
if path.is_dir() {
collect_rust_files(&path, files);
continue;
}
if path.extension().and_then(|value| value.to_str()) == Some("rs") {
files.push(path);
}
}
}
pub(crate) fn assert_no_sqlx_queries(root_relative_path: &str) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
let patterns = [
"sqlx::query(",
"sqlx::query_scalar",
"sqlx::postgres::PgRow",
"sqlx::Row",
"PostgresPoolFactory",
"PostgresPool",
"query_scalar::<",
"QueryBuilder<",
];
let violations = files
.into_iter()
.filter_map(|path| {
let source = fs::read_to_string(&path).expect("source file should be readable");
let hits = patterns
.iter()
.filter(|pattern| source_contains_sql_pattern(&source, pattern))
.copied()
.collect::<Vec<_>>();
if hits.is_empty() {
None
} else {
Some(format!("{} -> {}", path.display(), hits.join(", ")))
}
})
.collect::<Vec<_>>();
assert!(
violations.is_empty(),
"disallowed SQL ownership violations:\n{}",
violations.join("\n")
);
}
fn source_contains_sql_pattern(source: &str, pattern: &str) -> bool {
if pattern == "PostgresPool" {
source
.split(|character: char| !character.is_ascii_alphanumeric() && character != '_')
.any(|identifier| identifier == pattern)
} else {
source.contains(pattern)
}
}
#[test]
fn sql_pool_scan_distinguishes_pool_types_from_repository_names() {
assert!(source_contains_sql_pattern(
"pool: PostgresPool",
"PostgresPool"
));
assert!(source_contains_sql_pattern(
"PostgresPool::connect(url)",
"PostgresPool"
));
assert!(!source_contains_sql_pattern(
"PostgresPoolMemberScoreRepository::new(pool)",
"PostgresPool"
));
}
pub(crate) fn assert_no_sensitive_log_patterns(root_relative_path: &str, patterns: &[&str]) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
let violations = files
.into_iter()
.filter_map(|path| {
let source = fs::read_to_string(&path).expect("source file should be readable");
let hits = patterns
.iter()
.filter(|pattern| source.contains(**pattern))
.copied()
.collect::<Vec<_>>();
if hits.is_empty() {
None
} else {
Some(format!("{} -> {}", path.display(), hits.join(", ")))
}
})
.collect::<Vec<_>>();
assert!(
violations.is_empty(),
"disallowed sensitive logging patterns:\n{}",
violations.join("\n")
);
}
pub(crate) fn assert_no_module_dependency_patterns(root_relative_path: &str, patterns: &[&str]) {
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
let violations = files
.into_iter()
.filter_map(|path| {
let source = fs::read_to_string(&path).expect("source file should be readable");
let hits = patterns
.iter()
.filter(|pattern| source.contains(**pattern))
.copied()
.collect::<Vec<_>>();
if hits.is_empty() {
None
} else {
Some(format!("{} -> {}", path.display(), hits.join(", ")))
}
})
.collect::<Vec<_>>();
assert!(
violations.is_empty(),
"disallowed module dependency patterns:\n{}",
violations.join("\n")
);
}
pub(crate) fn workspace_file_exists(root_relative_path: &str) -> bool {
Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path)
.exists()
}
pub(crate) fn workspace_files_with_extension(
root_relative_path: &str,
extension: &str,
) -> Vec<PathBuf> {
let root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path);
let mut files = fs::read_dir(root)
.expect("workspace directory should be readable")
.filter_map(Result::ok)
.map(|entry| entry.path())
.filter(|path| path.extension().and_then(|value| value.to_str()) == Some(extension))
.collect::<Vec<_>>();
files.sort();
files
}
pub(crate) fn collect_workspace_rust_files(root_relative_path: &str) -> Vec<PathBuf> {
let root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.join(root_relative_path);
let mut files = Vec::new();
collect_rust_files(&root, &mut files);
files.sort();
files
}
pub(crate) fn read_workspace_file(path: &str) -> String {
let workspace_root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.canonicalize()
.expect("workspace root should resolve");
fs::read_to_string(workspace_root.join(path)).expect("source file should be readable")
}
pub(crate) fn read_workspace_module_tree(path: &str) -> String {
let workspace_root = Path::new(env!("CARGO_MANIFEST_DIR"))
.join("../..")
.canonicalize()
.expect("workspace root should resolve");
let root_path = workspace_root.join(path);
let mut contents =
vec![fs::read_to_string(&root_path).expect("source file should be readable")];
let module_dir = if root_path.file_name().and_then(|value| value.to_str()) == Some("mod.rs") {
root_path
.parent()
.expect("mod.rs should have parent module directory")
.to_path_buf()
} else if root_path.extension().and_then(|value| value.to_str()) == Some("rs") {
root_path.with_extension("")
} else {
root_path.clone()
};
if module_dir.is_dir() {
let mut files = Vec::new();
collect_rust_files(&module_dir, &mut files);
files.sort();
for file in files {
contents.push(fs::read_to_string(file).expect("source file should be readable"));
}
}
contents.join("\n")
}
mod admin_billing;
mod admin_model;
mod admin_observability;
mod admin_provider;
mod admin_shared;
mod admin_system;
mod admin_users;
mod ai_serving;
mod runtime_and_security;
mod sql_and_data;
mod usage;
mod workspace_tiers;