Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 57 additions & 3 deletions .github/scripts/test_ci_changes.py
Original file line number Diff line number Diff line change
Expand Up @@ -949,12 +949,66 @@ def test_breg_tutorial_runs_native_example_recovery(self) -> None:
breg_job = workflow.split("\n breg-tutorial:\n", 1)[1].split(
"\n breg-evidence-composition:\n", 1
)[0]
self.assertIn(
test = (
"dev::examples::tests::"
"native_create_and_apply_recover_after_process_exit_without_duplicate_revisions",
breg_job,
"native_create_recovers_after_process_exit_without_duplicate_records"
)
self.assertIn(test, breg_job)
self.assertIn("-- --ignored --exact", breg_job)
# A renamed test would otherwise leave the step running zero tests.
self.assertIn(
"grep -q 'test result: ok\\. 1 passed' "
'"${RUNNER_TEMP}/breg-example-recovery.log" || '
'{ echo "::error::expected exactly one passing test for '
f'{test.rsplit("::", 1)[1]}"; exit 1; }}',
breg_job,
)
source = (
Path("crates/registry-bregctl/src/dev/examples.rs").read_text()
)
self.assertIn(f"fn {test.rsplit('::', 1)[1]}()", source)

def test_casework_postgres_runs_task_approval_and_local_session_exactly(
self,
) -> None:
workflow = Path(".github/workflows/ci.yml").read_text()
casework_job = workflow.split("\n casework-postgres:\n", 1)[1].split(
"\n scheduling-contracts:\n", 1
)[0]
cases = (
(
"task_grants::native_exchange_tests::"
"approved_casework_tasks_reach_evidence_breg_and_scheduling_through_stock_thunderid",
"casework-task-approval.log",
),
(
"task_grants::local_session_tests::"
"source_backed_dev_approves_exchanges_and_revokes_on_stock_issuer",
"casework-local-session.log",
),
)
source_dir = Path("crates/registry-casework/src/task_grants")
for test, log in cases:
with self.subTest(test=test):
self.assertIn(test, casework_job)
# A renamed test would otherwise leave the step running zero
# tests, and an inexact filter could silently match more than
# one, so the step names each test exactly and fails unless
# it reports one pass.
self.assertRegex(
casework_job,
rf"-- --ignored --exact \\\s*\n\s*{re.escape(test)} \\",
)
self.assertIn(
"grep -q 'test result: ok\\. 1 passed' "
f'"${{RUNNER_TEMP}}/{log}" || '
'{ echo "::error::expected exactly one passing test for '
f'{test.rsplit("::", 1)[1]}"; exit 1; }}',
casework_job,
)
module, name = test.rsplit("::", 2)[1:]
module_source = (source_dir / f"{module}.rs").read_text()
self.assertIn(f"fn {name}()", module_source)

def test_breg_tutorial_inputs_cover_every_replayed_tutorial(self) -> None:
# Each page's tutorial_test frontmatter is the source of truth for
Expand Down
38 changes: 32 additions & 6 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -408,6 +408,22 @@ jobs:
- name: Cargo deny
run: cargo deny check

- name: Standalone Cargo lockfiles
# Fuzz, SDK and editor workspaces keep their own Cargo.lock, and most
# build root crates by path, so a root change can leave one stale.
# Resolving with --locked fails on a stale lock and reads only the
# registry index, not crate sources.
shell: bash
run: |
set -euo pipefail
mapfile -t locks < <(git ls-files '*/Cargo.lock')
(( ${#locks[@]} > 0 ))
for lock in "${locks[@]}"; do
echo "Checking ${lock}"
cargo update --workspace --locked \
--manifest-path "$(dirname "${lock}")/Cargo.toml"
done

rust-quality:
name: Rust format and clippy
needs:
Expand Down Expand Up @@ -752,6 +768,8 @@ jobs:
POSTGRES_CONTAINER_ID: ${{ job.services.postgres.id }}
run: docker exec "$POSTGRES_CONTAINER_ID" createdb -U casework casework_task_approval
- name: Casework task approval through stock issuer to Evidence, BReg, and Scheduling
# An inexact name filter that selects nothing still exits 0, so the
# step names each test exactly and fails unless it reports one pass.
shell: bash
env:
CASEWORK_ASSIGNMENT_TEST_DATABASE_URL: postgresql://casework:casework_test@localhost:${{ job.services.postgres.ports['5432'] }}/casework_task_approval
Expand All @@ -763,13 +781,17 @@ jobs:
SCHEDULING_AUTH_PROBE_BIN="${GITHUB_WORKSPACE}/target/debug/examples/scheduling-auth-probe" \
cargo test --locked -p registry-casework \
--features postgres-test --lib \
approved_casework_tasks_reach_evidence_breg_and_scheduling_through_stock_thunderid \
-- --ignored
-- --ignored --exact \
task_grants::native_exchange_tests::approved_casework_tasks_reach_evidence_breg_and_scheduling_through_stock_thunderid \
| tee "${RUNNER_TEMP}/casework-task-approval.log"
grep -q 'test result: ok\. 1 passed' "${RUNNER_TEMP}/casework-task-approval.log" || { echo "::error::expected exactly one passing test for approved_casework_tasks_reach_evidence_breg_and_scheduling_through_stock_thunderid"; exit 1; }
cargo build --locked -p registry-casework -p registry-caseworkctl
cargo test --locked -p registry-casework \
--features postgres-test --lib \
source_backed_dev_approves_exchanges_and_revokes_on_stock_issuer \
-- --ignored
-- --ignored --exact \
task_grants::local_session_tests::source_backed_dev_approves_exchanges_and_revokes_on_stock_issuer \
| tee "${RUNNER_TEMP}/casework-local-session.log"
grep -q 'test result: ok\. 1 passed' "${RUNNER_TEMP}/casework-local-session.log" || { echo "::error::expected exactly one passing test for source_backed_dev_approves_exchanges_and_revokes_on_stock_issuer"; exit 1; }

scheduling-contracts:
name: Scheduling product contracts
Expand Down Expand Up @@ -1496,12 +1518,16 @@ jobs:
--bin-dir target/debug --verification

- name: Verify retained example recovery after process exit
# An inexact name filter that selects nothing still exits 0, so the
# step names the test exactly and fails unless it reports one pass.
shell: bash
run: |
set -euo pipefail
cargo test --locked -p registry-bregctl --lib \
dev::examples::tests::native_create_and_apply_recover_after_process_exit_without_duplicate_revisions \
-- --ignored --exact
dev::examples::tests::native_create_recovers_after_process_exit_without_duplicate_records \
-- --ignored --exact \
| tee "${RUNNER_TEMP}/breg-example-recovery.log"
grep -q 'test result: ok\. 1 passed' "${RUNNER_TEMP}/breg-example-recovery.log" || { echo "::error::expected exactly one passing test for native_create_recovers_after_process_exit_without_duplicate_records"; exit 1; }

- name: Execute the Base Registry Engine tutorials from a reader directory
shell: bash
Expand Down
16 changes: 15 additions & 1 deletion crates/registry-bregctl/src/dev/examples.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1807,7 +1807,7 @@ mod tests {
/// An optional structured field exercises untyped nested reference refusal.
fn prepare_native_fixture(project: &Path) {
let path = project.join("registry.yaml");
let mut source: Value = serde_json::from_slice(&fs::read(&path).unwrap()).unwrap();
let mut source: Value = serde_norway::from_slice(&fs::read(&path).unwrap()).unwrap();
let entity = source["entities"]
.as_array_mut()
.unwrap()
Expand Down Expand Up @@ -1861,6 +1861,20 @@ mod tests {
grant[fields].as_array_mut().unwrap().push(json!("notes"));
}
fs::write(path, serde_json::to_vec_pretty(&source).unwrap()).unwrap();
// The starter's change requests name the `casework` review authority,
// which a start activates. No scenario here submits a request, so the
// binding needs only a declared client and an unused loopback endpoint.
let path = project.join("dev-clients.yaml");
let mut clients: Value = serde_norway::from_slice(&fs::read(&path).unwrap()).unwrap();
clients["clients"].as_array_mut().unwrap().push(json!({
"id":"casework-producer", "accessProfiles":[],
"scopes":["casework:reviews:request"], "claims":{}
}));
clients["reviewAuthorities"] = json!({"casework":{
"endpoint":"http://127.0.0.1:9/", "profile":"integration-requester",
"producerId":"registry-breg", "recoveryDays":7, "client":"casework-producer"
}});
fs::write(path, serde_norway::to_string(&clients).unwrap()).unwrap();
}

fn preflight_refuses_before_writes(project: &Path, first: &Value) {
Expand Down
Loading
Loading