diff --git a/.config/make/tests.mak b/.config/make/tests.mak index d1297e9ad..d32e12103 100644 --- a/.config/make/tests.mak +++ b/.config/make/tests.mak @@ -38,6 +38,7 @@ script-tests: ## Run shell script tests ./scripts/test_python_bin.sh ./scripts/check_embedded_secrets.sh --self-test $(RUSTFS_PYTHON_BIN) ./scripts/check_test_wiring.py --self-test + $(RUSTFS_PYTHON_BIN) ./scripts/test_e2e_binary.py $(RUSTFS_PYTHON_BIN) ./scripts/check_security_coverage.py --self-test $(RUSTFS_PYTHON_BIN) ./scripts/check_scheduled_validation_freshness.py --self-test $(RUSTFS_PYTHON_BIN) ./scripts/test_security_workflow.py diff --git a/.github/workflows/ci-docs-only.yml b/.github/workflows/ci-docs-only.yml index 7c6ad22ec..15bddcc8a 100644 --- a/.github/workflows/ci-docs-only.yml +++ b/.github/workflows/ci-docs-only.yml @@ -128,6 +128,7 @@ jobs: - name: Check test wiring run: | python3 ./scripts/check_test_wiring.py --self-test + python3 ./scripts/test_e2e_binary.py python3 ./scripts/check_scheduled_validation_freshness.py --self-test python3 ./scripts/test_security_workflow.py python3 ./scripts/check_test_wiring.py diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 171f52380..974f1ec09 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -166,6 +166,7 @@ jobs: - name: Check test wiring run: | python3 ./scripts/check_test_wiring.py --self-test + python3 ./scripts/test_e2e_binary.py python3 ./scripts/check_scheduled_validation_freshness.py --self-test python3 ./scripts/test_security_workflow.py python3 ./scripts/check_test_wiring.py @@ -646,13 +647,15 @@ jobs: install-build-packaging-tools: 'false' - name: Build debug binary - run: cargo build -p rustfs --bins --features e2e-test-hooks + run: python3 scripts/e2e_binary.py build --bins --features e2e-test-hooks - name: Upload debug binary uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 with: name: rustfs-debug-binary - path: target/debug/rustfs + path: | + target/debug/rustfs + target/debug/rustfs.e2e.json if-no-files-found: error retention-days: 1 @@ -684,13 +687,15 @@ jobs: install-build-packaging-tools: 'false' - name: Build debug binary with rio-v2 - run: cargo build -p rustfs --bins --features rio-v2,e2e-test-hooks + run: python3 scripts/e2e_binary.py build --bins --features rio-v2,e2e-test-hooks - name: Upload debug binary uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 with: name: rustfs-debug-binary-rio-v2 - path: target/debug/rustfs + path: | + target/debug/rustfs + target/debug/rustfs.e2e.json if-no-files-found: error retention-days: 1 @@ -839,7 +844,7 @@ jobs: NEXTEST_ARCHIVE: ${{ runner.temp }}/rustfs-e2e-smoke.tar.zst RUSTFS_E2E_LOG_DIR: ${{ runner.temp }}/rustfs-e2e-smoke-logs run: | - cargo nextest run --profile e2e-smoke --archive-file "${NEXTEST_ARCHIVE}" \ + python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-smoke --archive-file "${NEXTEST_ARCHIVE}" \ --status-level all --final-status-level all --failure-output final - name: Upload e2e smoke diagnostics @@ -875,7 +880,7 @@ jobs: RUSTFS_TEST_PORT="$(python3 -c 'import socket; s=socket.socket(); s.bind(("127.0.0.1", 0)); print(s.getsockname()[1]); s.close()')" RUSTFS_TEST_PORT="${RUSTFS_TEST_PORT}" \ RUSTFS_TEST_LOG="${RUN_ROOT}/rustfs.log" \ - ./scripts/e2e-run.sh ./target/debug/rustfs "${RUN_ROOT}/data" + python3 scripts/e2e_binary.py run --features e2e-test-hooks -- ./scripts/e2e-run.sh ./target/debug/rustfs "${RUN_ROOT}/data" - name: Upload test logs if: failure() @@ -977,7 +982,7 @@ jobs: # extend that filter, never add ad-hoc e2e jobs here. Reuses the downloaded # debug binary; each test spawns its own rustfs server on a random port. - name: Run e2e full suite - run: cargo nextest run --profile e2e-full -p e2e_test + run: python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-full -p e2e_test - name: Upload junit if: always() @@ -1038,7 +1043,7 @@ jobs: - name: Run end-to-end tests run: | s3s-e2e --version - ./scripts/e2e-run.sh ./target/debug/rustfs /tmp/rustfs + python3 scripts/e2e_binary.py run --features rio-v2,e2e-test-hooks -- ./scripts/e2e-run.sh ./target/debug/rustfs /tmp/rustfs - name: Upload test logs if: failure() @@ -1081,7 +1086,7 @@ jobs: S3_PORT="${S3_PORT}" \ DATA_ROOT="${RUN_ROOT}" \ S3TESTS_CONF=artifacts/s3tests-single/s3tests.conf \ - ./scripts/s3-tests/run.sh + python3 scripts/e2e_binary.py run --features e2e-test-hooks -- ./scripts/s3-tests/run.sh - name: Upload s3 test artifacts if: always() @@ -1163,7 +1168,7 @@ jobs: S3_PORT="${S3_PORT}" \ DATA_ROOT="${RUN_ROOT}" \ S3TESTS_CONF=artifacts/s3tests-single/s3tests.conf \ - ./scripts/s3-tests/run.sh + python3 scripts/e2e_binary.py run --features e2e-test-hooks -- ./scripts/s3-tests/run.sh - name: Upload s3 test artifacts if: always() diff --git a/.github/workflows/e2e-replication-nightly.yml b/.github/workflows/e2e-replication-nightly.yml index e59d1155a..f8f9c8824 100644 --- a/.github/workflows/e2e-replication-nightly.yml +++ b/.github/workflows/e2e-replication-nightly.yml @@ -89,14 +89,10 @@ jobs: - name: Verify awscurl run: test -x "$AWSCURL_PATH" - # Build the rustfs binary once up front. The e2e tests spawn it as a - # child process (crates/e2e_test/src/common.rs) and will build it on - # demand otherwise, but a single explicit build avoids several parallel - # nextest test processes racing to build it at once. + # Build once and carry its source/binary identity into the test invocation. - name: Build rustfs binary run: | - cargo build -p rustfs --bins - : > target/debug/rustfs.features + python3 scripts/e2e_binary.py build --bins - name: Verify replication e2e membership env: @@ -108,7 +104,7 @@ jobs: - name: Run replication e2e nightly suite env: RUSTFS_E2E_LOG_DIR: ${{ runner.temp }}/rustfs-e2e-repl-nightly-logs - run: cargo nextest run --profile e2e-repl-nightly -p e2e_test + run: python3 scripts/e2e_binary.py run -- cargo nextest run --profile e2e-repl-nightly -p e2e_test - name: Upload nextest junit report if: always() @@ -144,8 +140,7 @@ jobs: - name: Build rustfs binary run: | - cargo build -p rustfs --bins --features e2e-test-hooks - : > target/debug/rustfs.features + python3 scripts/e2e_binary.py build --bins --features e2e-test-hooks - name: Verify cluster fault e2e membership env: @@ -157,7 +152,7 @@ jobs: - name: Run cluster fault e2e nightly suite env: RUSTFS_E2E_LOG_DIR: ${{ runner.temp }}/rustfs-e2e-nightly-logs - run: cargo nextest run --profile e2e-nightly -p e2e_test + run: python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-nightly -p e2e_test - name: Upload cluster fault diagnostics if: always() @@ -198,6 +193,9 @@ jobs: sudo apt-get install -y -qq iproute2 ss -tn state CLOSE-WAIT >/dev/null + - name: Build protocol server + run: python3 scripts/e2e_binary.py build --features "$RUSTFS_BUILD_FEATURES" + # The suite owns fixed protocol ports and serializes its internal cases. - name: Verify protocol e2e membership env: @@ -210,7 +208,7 @@ jobs: env: RUSTFS_E2E_LOG_DIR: ${{ runner.temp }}/rustfs-protocol-e2e-logs run: >- - cargo nextest run -j 1 --profile e2e-protocols -p e2e_test --no-capture + python3 scripts/e2e_binary.py run --features "$RUSTFS_BUILD_FEATURES" -- cargo nextest run -j 1 --profile e2e-protocols -p e2e_test --no-capture - name: Upload protocol diagnostics if: always() diff --git a/.github/workflows/e2e-upgrade.yml b/.github/workflows/e2e-upgrade.yml index ed420cd06..eedbb7367 100644 --- a/.github/workflows/e2e-upgrade.yml +++ b/.github/workflows/e2e-upgrade.yml @@ -98,12 +98,11 @@ jobs: - name: Build current RustFS binary run: | - cargo build --locked -p rustfs --bin rustfs - : > target/debug/rustfs.features + python3 scripts/e2e_binary.py build - name: Run upgrade compatibility test run: | - cargo test --locked -p e2e_test \ + python3 scripts/e2e_binary.py run -- cargo test --locked -p e2e_test \ "upgrade_compatibility_test::${{ matrix.test }}" \ -- --ignored --exact --nocapture diff --git a/.github/workflows/on-demand-migration-interop.yml b/.github/workflows/on-demand-migration-interop.yml index 7b285fd25..60dbe1cad 100644 --- a/.github/workflows/on-demand-migration-interop.yml +++ b/.github/workflows/on-demand-migration-interop.yml @@ -132,7 +132,7 @@ jobs: s3api create-bucket --bucket "${RUSTFS_ODM_INTEROP_BUCKET}" - name: Build the RustFS binary under test - run: cargo build --locked -p rustfs --bins + run: python3 scripts/e2e_binary.py build --bins # The lane selects tests by module, so a rename would quietly shrink it. # The committed digest in .config/e2e-odm-interop-selection.txt fails @@ -143,7 +143,7 @@ jobs: python3 ./scripts/check_test_wiring.py --check-profile e2e-odm-interop "${NEXTEST_LISTING}" - name: Run the interop cases against MinIO - run: cargo nextest run --profile e2e-odm-interop -p e2e_test --no-tests=fail + run: python3 scripts/e2e_binary.py run -- cargo nextest run --profile e2e-odm-interop -p e2e_test --no-tests=fail - name: Build the MinIO interop report if: always() @@ -251,7 +251,7 @@ jobs: - name: Build the RustFS binary under test if: steps.credentials.outputs.present == 'true' - run: cargo build --locked -p rustfs --bins + run: python3 scripts/e2e_binary.py build --bins # A filterset that matches nothing is valid, so the count is asserted # rather than inferred from a green run. @@ -272,7 +272,7 @@ jobs: - name: Run the three-case minimum if: steps.credentials.outputs.present == 'true' run: | - cargo nextest run --profile e2e-odm-interop -p e2e_test \ + python3 scripts/e2e_binary.py run -- cargo nextest run --profile e2e-odm-interop -p e2e_test \ -E "${CLOUD_CASE_FILTER}" --no-tests=fail - name: Build the ${{ matrix.provider }} interop report diff --git a/crates/e2e_test/README.md b/crates/e2e_test/README.md index ed5a65d97..de4fd1d53 100644 --- a/crates/e2e_test/README.md +++ b/crates/e2e_test/README.md @@ -1,7 +1,7 @@ # e2e_test End-to-end test suite for RustFS. Each test spawns a **real `rustfs` binary** -(built on demand from the workspace) and drives it over the network with the +(built and identified before the test invocation) and drives it over the network with the AWS SDK (`aws-sdk-s3`), raw HTTP (`reqwest` / `awscurl`), or a protocol client (FTPS / WebDAV / SFTP). This is the black-box integration layer: exhaustive end-to-end behavior lives here, unit behavior stays in the source crates @@ -31,32 +31,28 @@ Registered in [`src/lib.rs`](src/lib.rs). Grouped by concern: ## How to run -All commands assume repo root. `cargo test` triggers an on-demand build of the -`rustfs` binary from [`src/common.rs`](src/common.rs) (`rustfs_binary_path`) on -first use — the first invocation is slow, later ones reuse the binary. +All commands assume repo root and Python 3.9 or newer on Linux or macOS. Build the server once through the provenance entry point, then run the test command through the same script: ```bash -# Whole crate (default = ignored tests skipped) -cargo nextest run -p e2e_test +python3 scripts/e2e_binary.py build --features e2e-test-hooks + +# Whole crate (ignored tests remain skipped) +python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run -p e2e_test # One module -cargo nextest run -p e2e_test -E 'test(list_objects_v2_pagination_test)' - -# PR smoke subset (see "CI smoke subset" below) -cargo nextest run --profile e2e-smoke -p e2e_test - -# ILM serial lane — ignored lifecycle tests, single-threaded (mirrors CI) -cargo nextest run -j1 --run-ignored ignored-only -p rustfs-scanner -p rustfs \ - -E 'binary(lifecycle_integration_test) or (package(rustfs) and test(lifecycle_transition_api_test))' +python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run -p e2e_test -E 'test(list_objects_v2_pagination_test)' +# PR smoke subset +python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-smoke -p e2e_test ``` -The protocols suite has its own contract (fixed bind ports 9022–9301, -single-worker execution, feature-gated scheduling) documented in -[`src/protocols/README.md`](src/protocols/README.md). `RUSTFS_BUILD_FEATURES` -selects which features the spawned binary is built with; leave it unset to run -every protocol entry. Use the exact profile command under -[Troubleshooting](#troubleshooting) for CI-equivalent execution. +`build` records the source contents, HEAD, resolved Cargo features, profile, toolchain, and binary SHA-256 beside the executable in `rustfs.e2e.json`. `run` validates that identity before and after the command, preserves command failures, and removes its temporary run receipt on completion. The Rust harness checks that receipt before starting each server; it never compiles a server inside a test process. Source or binary changes during a run invalidate the result, even when the test command succeeds. Use an isolated worktree and keep it unchanged until the command finishes. + +The additional `--features` arguments must match between `build` and `run`; Cargo defaults remain enabled. The wrapper supplies `RUSTFS_BUILD_FEATURES` from Cargo's resolved feature list, including features enabled by `full`. Protocol helpers require a subset of that list. `CARGO_TARGET_DIR` and `--profile release` are supported. An in-workspace target directory must be Git-ignored; tracked files are always included in the source identity. `build --bins` preserves CI lanes that compile all RustFS binary targets. For a downloaded artifact, copy both the executable and its sidecar, then use `run`; do not generate a new identity for an arbitrary prebuilt binary. `CARGO_BIN_EXE_rustfs` cannot override the verified executable. + +Each build/run holds an exclusive `rustfs.e2e.lock` marker beside the binary; concurrent wrappers fail immediately. Use a private target directory and do not run ordinary Cargo builds against it while tests are active: Cargo does not honor this marker. Interrupted runs fail and terminate their command group. After an uncatchable kill, inspect the PID recorded in a leftover marker and remove it only after confirming its owner has stopped. Embedded file symlinks are hashed through their target; embedded directory symlinks are rejected because their contents cannot be enumerated safely by this entry point. + +The protocols suite has its own fixed-port and single-worker contract in [`src/protocols/README.md`](src/protocols/README.md). Use its command under [Troubleshooting](#troubleshooting). ### `#[ignore]` semantics @@ -122,7 +118,7 @@ via `create_s3_client(idx)` / `create_all_clients()`. See | `wait_for_server_ready` | Poll readiness before issuing requests | | `create_s3_client` / `create_test_bucket` / `delete_test_bucket` | aws-sdk-s3 client + bucket lifecycle | | `find_available_port` | Random free port (isolation primitive) | -| `rustfs_binary_path` / `_with_features` | Locate/build the binary; honors `RUSTFS_BUILD_FEATURES` | +| `rustfs_binary_path` / `_with_features` | Verify this run's binary receipt and required feature subset | | `requested_rustfs_build_features` / `rustfs_build_feature_enabled` | Feature-gate a test to what the binary was built with | | `execute_awscurl` / `awscurl_post` / `_get` / `_put` / `_delete` / `awscurl_post_sts_form_urlencoded` | Admin/STS API calls via `awscurl`; missing binaries are test failures | | `replication_fast_env` | Env vars that shrink replication timers (from repl-4); pass to `start_rustfs_server_with_env` | @@ -185,32 +181,26 @@ the wiring source of truth. Committed test-ID digests under **Reproduce a CI failure locally** — run the exact profile/lane: ```bash -# Smoke (e2e-tests job) — includes the 20 fast replication tests -cargo nextest run --profile e2e-smoke -p e2e_test -# Full single-node merge/main lane -cargo nextest run --profile e2e-full -p e2e_test -# Cluster fault nightly lane -cargo nextest run --profile e2e-nightly -p e2e_test -# Replication nightly lane; awscurl is required for STS paths -cargo nextest run --profile e2e-repl-nightly -p e2e_test -# Fixed-port protocol nightly lane -RUSTFS_BUILD_FEATURES=ftps,webdav,sftp \ - cargo nextest run -j 1 --profile e2e-protocols -p e2e_test --no-capture -# ILM serial lane +# Smoke, full, and cluster lanes share a server with fault-test hooks. +python3 scripts/e2e_binary.py build --features e2e-test-hooks +python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-smoke -p e2e_test +python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-full -p e2e_test +python3 scripts/e2e_binary.py run --features e2e-test-hooks -- cargo nextest run --profile e2e-nightly -p e2e_test + +# Replication nightly uses the default server; awscurl is required for STS. +python3 scripts/e2e_binary.py build +python3 scripts/e2e_binary.py run -- cargo nextest run --profile e2e-repl-nightly -p e2e_test + +# Protocol nightly owns fixed ports. +python3 scripts/e2e_binary.py build --features ftps,webdav,sftp +python3 scripts/e2e_binary.py run --features ftps,webdav,sftp -- cargo nextest run -j 1 --profile e2e-protocols -p e2e_test --no-capture + +# The ILM serial lane does not use this server harness. cargo nextest run -j1 --run-ignored ignored-only -p rustfs-scanner -p rustfs \ -E 'binary(lifecycle_integration_test) or (package(rustfs) and test(lifecycle_transition_api_test))' -# s3s-e2e black box -./scripts/e2e-run.sh ./target/debug/rustfs /tmp/rustfs-e2e-data ``` -**Stale binary.** Tests build the `rustfs` binary once and reuse it. To avoid -rebuilding while iterating on tests, `common.rs` reuses an existing binary when -running *inside* the e2e test process even if sources changed -(`can_reuse_inside_e2e`, [`src/common.rs`](src/common.rs) line 98). Downside: if -you changed **server** code, force a rebuild with -`cargo build -p rustfs` (or `touch` a source file outside the reuse window) -before re-running, or CI's freshly built artifact will diverge from your local -one. +**Stale or unverified binary.** Re-run the matching `build` command after changing source or features, then invoke tests through `run`. A missing receipt, copied old executable, or mismatched build identity is a prerequisite failure. Bare Cargo invocations that start a server deliberately fail; unit tests that do not start a server can still run directly. **Port already in use / orphan processes.** A hard-killed run can leak a `rustfs` child holding its port. Find and kill it: diff --git a/crates/e2e_test/src/common.rs b/crates/e2e_test/src/common.rs index b108cd074..0699a55b0 100644 --- a/crates/e2e_test/src/common.rs +++ b/crates/e2e_test/src/common.rs @@ -31,7 +31,6 @@ use rustfs_signer::constants::UNSIGNED_PAYLOAD; use rustfs_signer::sign_v4; use s3s::Body; use serde_json; -use std::ffi::OsStr; use std::fs as stdfs; use std::io::ErrorKind; use std::net::SocketAddr; @@ -44,7 +43,6 @@ use tokio::net::TcpStream; use tokio::time::sleep; use tracing::{error, info, warn}; use uuid::Uuid; -use walkdir::WalkDir; // Common constants for all E2E tests pub const DEFAULT_ACCESS_KEY: &str = "rustfsadmin"; @@ -365,59 +363,75 @@ fn resolve_rustfs_binary_path(workspace: &Path, configured_target_dir: Option<&P path } -/// Resolve the RustFS binary relative to the workspace, optionally requesting build features. +/// Resolve the server verified by `scripts/e2e_binary.py run` for this test invocation. +/// Requested features are a required subset of the server's resolved Cargo features. pub fn rustfs_binary_path_with_features(requested_features: Option<&str>) -> PathBuf { - if let Some(path) = std::env::var_os("CARGO_BIN_EXE_rustfs") { - return PathBuf::from(path); - } - let requested_features = requested_features.and_then(normalize_rustfs_build_features); - let workspace = workspace_root(); let configured_target_dir = std::env::var_os("CARGO_TARGET_DIR").map(PathBuf::from); - let binary_path = resolve_rustfs_binary_path(&workspace, configured_target_dir.as_deref()); + let binary_path = std::env::var_os("CARGO_BIN_EXE_rustfs") + .map(PathBuf::from) + .unwrap_or_else(|| resolve_rustfs_binary_path(&workspace, configured_target_dir.as_deref())); + let receipt_path = std::env::var_os("RUSTFS_E2E_BINARY_RECEIPT").map(PathBuf::from); + receipt_path + .ok_or_else(|| std::io::Error::new(ErrorKind::NotFound, "missing E2E run receipt")) + .and_then(|receipt| verify_e2e_binary_receipt(&receipt, &workspace, &binary_path, requested_features)) + .unwrap_or_else(|error| { + panic!( + "E2E server prerequisite failed: {error}. Build with `python3 scripts/e2e_binary.py build --features ` and run tests with `python3 scripts/e2e_binary.py run --features -- cargo nextest run ...`" + ) + }) +} - let features_match = binary_features_match(&binary_path, requested_features.as_deref()); - let source_is_newer = workspace_sources_newer_than_binary(&binary_path); - let can_reuse_inside_e2e = running_inside_e2e_test_binary() && requested_features.is_none() && features_match; - if binary_path.is_file() && features_match && (!source_is_newer || can_reuse_inside_e2e) { - if source_is_newer { - warn!( - "RustFS binary at {:?} appears older than workspace sources; reusing it inside cargo test to avoid nested builds", - binary_path - ); - } - info!("Using existing RustFS binary at {:?}", binary_path); - return binary_path; +#[derive(serde::Deserialize)] +#[serde(deny_unknown_fields)] +struct E2eBinaryReceipt { + schema: u32, + workspace: PathBuf, + binary: PathBuf, + size: u64, + modified_ns: u128, + features: Vec, +} + +fn verify_e2e_binary_receipt( + receipt_path: &Path, + workspace: &Path, + binary_path: &Path, + requested_features: Option<&str>, +) -> std::io::Result { + let receipt: E2eBinaryReceipt = serde_json::from_slice(&stdfs::read(receipt_path)?)?; + let binary = binary_path.canonicalize()?; + let metadata = binary.metadata()?; + let modified_ns = metadata + .modified()? + .duration_since(std::time::UNIX_EPOCH) + .map_err(std::io::Error::other)? + .as_nanos(); + // The runner hashes source and binary before/after the entire suite. Each + // nextest process checks only this invocation's path, features, and file stat. + if receipt.schema != 1 + || receipt.workspace != workspace.canonicalize()? + || receipt.binary != binary + || !metadata.is_file() + || receipt.size != metadata.len() + || receipt.modified_ns != modified_ns + { + return Err(std::io::Error::new( + ErrorKind::InvalidData, + "E2E server differs from this run's verified binary", + )); } - - info!("Building RustFS binary to ensure it's up to date..."); - build_rustfs_binary(requested_features.as_deref(), &binary_path); - - info!("Using RustFS binary at {:?}", binary_path); - binary_path -} - -fn workspace_sources_newer_than_binary(binary_path: &PathBuf) -> bool { - let Ok(binary_meta) = std::fs::metadata(binary_path) else { - return true; - }; - let Ok(binary_modified) = binary_meta.modified() else { - return true; - }; - - let workspace = workspace_root(); - let watch_roots = [ - workspace.join("Cargo.toml"), - workspace.join("Cargo.lock"), - workspace.join("rustfs"), - workspace.join("crates"), - ]; - - watch_roots.iter().any(|path| path_is_newer_than(binary_modified, path)) -} - -fn running_inside_e2e_test_binary() -> bool { - std::env::var("CARGO_PKG_NAME").is_ok_and(|value| value == "e2e_test") + if let Some(requested) = requested_features.and_then(normalize_rustfs_build_features) + && requested + .split(',') + .any(|feature| !receipt.features.iter().any(|actual| actual == feature)) + { + return Err(std::io::Error::new( + ErrorKind::InvalidInput, + "E2E server is missing a requested build feature", + )); + } + Ok(binary) } pub fn requested_rustfs_build_features() -> Option { @@ -447,96 +461,6 @@ pub fn rustfs_build_feature_enabled(requested_features: Option<&str>, required_f .any(|feature| feature.eq_ignore_ascii_case(RUSTFS_FULL_FEATURE) || feature.eq_ignore_ascii_case(required_feature)) } -fn rustfs_binary_features_stamp_path(binary_path: &Path) -> PathBuf { - binary_path.with_extension("features") -} - -fn binary_features_match(binary_path: &Path, requested_features: Option<&str>) -> bool { - let stamp_path = rustfs_binary_features_stamp_path(binary_path); - let recorded = stdfs::read_to_string(stamp_path) - .ok() - .and_then(|value| normalize_rustfs_build_features(&value)); - let requested = requested_features.and_then(normalize_rustfs_build_features); - - match requested.as_deref() { - Some(features) => recorded.as_deref() == Some(features), - None => recorded.is_none(), - } -} - -fn path_is_newer_than(binary_modified: std::time::SystemTime, path: &Path) -> bool { - if path.is_file() { - return std::fs::metadata(path) - .and_then(|meta| meta.modified()) - .map(|modified| modified > binary_modified) - .unwrap_or(false); - } - - if !path.is_dir() { - return false; - } - - WalkDir::new(path) - .into_iter() - .filter_entry(|entry| { - let name = entry.file_name(); - name != OsStr::new("target") && name != OsStr::new(".git") - }) - .filter_map(Result::ok) - .filter(|entry| entry.file_type().is_file()) - .any(|entry| { - std::fs::metadata(entry.path()) - .and_then(|meta| meta.modified()) - .map(|modified| modified > binary_modified) - .unwrap_or(false) - }) -} - -/// Build the RustFS binary using cargo -fn build_rustfs_binary(requested_features: Option<&str>, binary_path: &Path) { - let workspace = workspace_root(); - info!("Building RustFS binary from workspace: {:?}", workspace); - - let _profile = if cfg!(debug_assertions) { - info!("Building in debug mode"); - "dev" - } else { - info!("Building in release mode"); - "release" - }; - - let mut cmd = Command::new("cargo"); - cmd.current_dir(&workspace).args(["build", "--bin", "rustfs"]); - - if let Some(features) = requested_features { - cmd.arg("--features").arg(features); - info!("Building with features: {}", features); - } - - if !cfg!(debug_assertions) { - cmd.arg("--release"); - } - - info!( - "Executing: cargo build --bin rustfs {}", - if cfg!(debug_assertions) { "" } else { "--release" } - ); - - let output = cmd.output().expect("Failed to execute cargo build command"); - - if !output.status.success() { - let stderr = String::from_utf8_lossy(&output.stderr); - panic!("Failed to build RustFS binary. Error: {stderr}"); - } - - let stamp_path = rustfs_binary_features_stamp_path(binary_path); - if let Err(err) = stdfs::write(&stamp_path, requested_features.unwrap_or_default()) { - warn!("Failed to write RustFS feature stamp {:?}: {}", stamp_path, err); - } - - info!("✅ RustFS binary built successfully"); -} - fn awscurl_binary_path() -> PathBuf { std::env::var_os("AWSCURL_PATH") .map(PathBuf::from) @@ -2073,16 +1997,66 @@ mod tests { } #[test] - fn binary_feature_stamp_matching_uses_normalized_features() { - let binary_path = std::env::temp_dir().join(format!("rustfs-feature-stamp-test-{}", Uuid::new_v4())); - let stamp_path = rustfs_binary_features_stamp_path(&binary_path); + fn explicit_binary_without_run_receipt_is_rejected() { + const CHILD_ENV: &str = "RUSTFS_E2E_RECEIPT_TEST_CHILD"; + if std::env::var_os(CHILD_ENV).is_some() { + rustfs_binary_path_with_features(None); + return; + } + let executable = std::env::current_exe().expect("locate isolated test process"); + let output = Command::new(&executable) + .args([ + "--exact", + "common::tests::explicit_binary_without_run_receipt_is_rejected", + "--nocapture", + ]) + .env(CHILD_ENV, "1") + .env("CARGO_BIN_EXE_rustfs", &executable) + .env_remove("RUSTFS_E2E_BINARY_RECEIPT") + .output() + .expect("run the missing-receipt scenario with isolated environment variables"); + assert!(!output.status.success(), "an explicit binary must not bypass run verification"); + assert!(String::from_utf8_lossy(&output.stderr).contains("missing E2E run receipt")); + } - stdfs::write(&stamp_path, " SFTP, ftps ").expect("write feature stamp"); - assert!(binary_features_match(&binary_path, Some("sftp,ftps"))); - assert!(binary_features_match(&binary_path, Some(" SFTP, FTPS "))); - assert!(!binary_features_match(&binary_path, Some("sftp"))); - - stdfs::remove_file(stamp_path).ok(); + #[test] + fn e2e_run_receipt_rejects_replaced_binary_and_missing_features() { + let directory = std::env::temp_dir().join(format!("rustfs-e2e-receipt-test-{}", Uuid::new_v4())); + stdfs::create_dir(&directory).expect("create receipt fixture"); + let binary = directory.join("rustfs"); + let receipt = directory.join("receipt.json"); + stdfs::write(&binary, "server").expect("write fixture binary"); + let metadata = binary.metadata().expect("stat fixture binary"); + let record = serde_json::json!({ + "schema": 1, + "workspace": directory.canonicalize().expect("canonical workspace"), + "binary": binary.canonicalize().expect("canonical binary"), + "size": metadata.len(), + "modified_ns": metadata.modified().expect("modified time").duration_since(std::time::UNIX_EPOCH).expect("positive timestamp").as_nanos(), + "features": ["default", "full", "ftps", "webdav", "sftp"] + }); + stdfs::write(&receipt, serde_json::to_vec(&record).expect("serialize receipt")).expect("write receipt"); + verify_e2e_binary_receipt(&receipt, &directory, &binary, Some("sftp,webdav")).expect("resolved feature subset"); + verify_e2e_binary_receipt(&receipt, &directory, &binary, Some("full")).expect("full was actually requested"); + assert_eq!( + verify_e2e_binary_receipt(&receipt, &directory, &binary, Some("rio-v2")) + .expect_err("full does not enable rio-v2") + .kind(), + ErrorKind::InvalidInput + ); + let other = directory.join("old-server"); + stdfs::write(&other, "server").expect("write alternate binary"); + assert!(verify_e2e_binary_receipt(&receipt, &directory, &other, None).is_err()); + stdfs::write(&binary, "different server").expect("replace fixture binary"); + assert!(verify_e2e_binary_receipt(&receipt, &directory, &binary, None).is_err()); + stdfs::remove_file(&receipt).expect("remove expired receipt"); + assert_eq!( + verify_e2e_binary_receipt(&receipt, &directory, &binary, None) + .expect_err("expired receipt") + .kind(), + ErrorKind::NotFound + ); + stdfs::remove_dir_all(directory).expect("remove receipt fixture"); } /// Build a cluster environment struct in-memory (no ports, no processes) so diff --git a/crates/e2e_test/src/protocols/README.md b/crates/e2e_test/src/protocols/README.md index 0cbb222b1..6359ed634 100644 --- a/crates/e2e_test/src/protocols/README.md +++ b/crates/e2e_test/src/protocols/README.md @@ -17,15 +17,13 @@ Use the canonical CI-equivalent protocol command in the parent For targeted debugging of the core suite only: ```bash -RUSTFS_BUILD_FEATURES=ftps,webdav,sftp cargo test --package e2e_test test_protocol_core_suite -- --test-threads=1 --nocapture +python3 scripts/e2e_binary.py build --features ftps,webdav,sftp +python3 scripts/e2e_binary.py run --features ftps,webdav,sftp -- cargo test --package e2e_test test_protocol_core_suite -- --test-threads=1 --nocapture ``` This targeted command does not cover the full `e2e-protocols` profile. -`RUSTFS_BUILD_FEATURES` controls which features the test rustfs binary is -built with. When this variable is set, the protocol test runner schedules -only entries whose protocol is present in the requested feature list. Leave -it unset to run every protocol entry. +`e2e_binary.py` supplies `RUSTFS_BUILD_FEATURES` from the verified server's resolved Cargo features. The protocol runner schedules only entries present in that feature list; helpers check that their required features are available without rebuilding the server. `--test-threads=1` is required because every entry spawns a rustfs server on fixed bind ports. diff --git a/scripts/e2e_binary.py b/scripts/e2e_binary.py new file mode 100644 index 000000000..feae58873 --- /dev/null +++ b/scripts/e2e_binary.py @@ -0,0 +1,253 @@ +#!/usr/bin/env python3 +"""Build an identified E2E server and verify it around one test invocation.""" + +import argparse +from contextlib import contextmanager +import hashlib +import json +import os +from pathlib import Path +import stat +import signal +import subprocess +import sys +import tempfile + +ROOT = Path(__file__).resolve().parent.parent +RECEIPT_ENV = "RUSTFS_E2E_BINARY_RECEIPT" + + +def feature_set(value): + return sorted(set(part.strip() for part in value.split(",") if part.strip())) + + +def file_hash(path): + digest = hashlib.sha256() + with path.open("rb") as source: + for chunk in iter(lambda: source.read(1024 * 1024), b""): + digest.update(chunk) + return digest.hexdigest() + + +def source_identity(): + head = subprocess.check_output(["git", "rev-parse", "HEAD"], cwd=ROOT, text=True).strip() + tracked = subprocess.check_output(["git", "ls-files", "--cached", "--others", "--exclude-standard", "-z"], cwd=ROOT) + paths = set(tracked.decode("utf-8").rstrip("\0").split("\0")) - {""} + # RustEmbed consumes ignored console assets as well as tracked Rust sources. + static_dir = ROOT / "rustfs/static" + if static_dir.is_symlink(): + raise ValueError("The embedded static directory must not be a symlink") + if static_dir.is_dir(): + for path in static_dir.rglob("*"): + if path.is_symlink() and path.is_dir(): + raise ValueError(f"Unsupported embedded directory symlink: {path}") + if not path.is_dir(): + paths.add(str(path.relative_to(ROOT))) + elif static_dir.exists(): + paths.add("rustfs/static") + digest = hashlib.sha256() + digest.update(b"static-present\0" if static_dir.is_dir() else b"static-absent\0") + for name in sorted(paths): + path = ROOT / name + digest.update(name.encode("utf-8") + b"\0") + try: + metadata = path.lstat() + except FileNotFoundError: + digest.update(b"deleted\0") + continue + if stat.S_ISLNK(metadata.st_mode): + digest.update(b"symlink\0" + os.fsencode(os.readlink(path)) + b"\0") + if path.is_dir(): + target = path.resolve() + if ROOT not in target.parents: + raise ValueError(f"Directory link escapes the source inventory: {name}") + # Directory aliases such as .claude/skills share already-hashed inputs. + for child in target.rglob("*"): + if child.is_dir() and not child.is_symlink(): + continue + if child.is_dir() or str(child.relative_to(ROOT)) not in paths: + raise ValueError(f"Directory link contains an unrecorded input: {child}") + digest.update(b"directory\0" + str(target.relative_to(ROOT)).encode("utf-8") + b"\0") + continue + elif not stat.S_ISREG(metadata.st_mode): + raise ValueError(f"Unsupported build input: {name}") + digest.update(str(metadata.st_mode & 0o111).encode() + b"\0") + digest.update(file_hash(path).encode() + b"\0") + return {"head": head, "sha256": digest.hexdigest()} + + +def sidecar_path(binary): + return binary.with_name(binary.name + ".e2e.json") + + +def validate_target_directory(target_dir): + if target_dir == ROOT or target_dir in ROOT.parents: + raise ValueError("CARGO_TARGET_DIR must not contain the source workspace") + if ROOT in target_dir.parents: + ignored = subprocess.run(["git", "check-ignore", "--quiet", "--no-index", str(target_dir.relative_to(ROOT))], cwd=ROOT) + if ignored.returncode != 0: + raise ValueError("An in-workspace CARGO_TARGET_DIR must be Git-ignored; use target/ or an external directory") + + +@contextmanager +def exclusive_binary(binary): + marker = binary.with_name(binary.name + ".e2e.lock") + try: + descriptor = os.open(marker, os.O_CREAT | os.O_EXCL | os.O_WRONLY, 0o600) + except FileExistsError as error: + raise ValueError(f"Another E2E build/run owns {marker}; do not share a target directory between concurrent runs") from error + try: + identity = os.fstat(descriptor) + with os.fdopen(descriptor, "w") as lock: + lock.write(f"pid={os.getpid()}\n") + yield + finally: + current = marker.stat() + if (current.st_dev, current.st_ino) != (identity.st_dev, identity.st_ino): + raise ValueError("The E2E ownership marker changed during the command") + marker.unlink() + + +def terminate_command(process): + if process.poll() is not None: + return + try: + os.killpg(process.pid, signal.SIGTERM) + except ProcessLookupError: + return + try: + process.wait(timeout=5) + except subprocess.TimeoutExpired: + os.killpg(process.pid, signal.SIGKILL) + process.wait() + + +def build(binary, target_dir, profile, requested, all_bins): + sidecar = sidecar_path(binary) + sidecar.unlink(missing_ok=True) + before = source_identity() + command = ["cargo", "build", "--locked", "-p", "rustfs", "--target-dir", str(target_dir), "--message-format=json-render-diagnostics"] + command.extend(["--bins"] if all_bins else ["--bin", "rustfs"]) + if requested: + command.extend(["--features", ",".join(requested)]) + if profile == "release": + command.append("--release") + artifact = None + with subprocess.Popen(command, cwd=ROOT, stdout=subprocess.PIPE, text=True, start_new_session=True) as process: + try: + for line in process.stdout: + message = json.loads(line) + if message.get("reason") == "compiler-message": + print(message["message"].get("rendered", ""), end="", file=sys.stderr) + if message.get("reason") == "compiler-artifact" and message.get("target", {}).get("name") == "rustfs" and "bin" in message.get("target", {}).get("kind", []): + artifact = message + if process.wait() != 0: + raise ValueError("RustFS build failed; no E2E identity was recorded") + except BaseException: + terminate_command(process) + raise + if not artifact or Path(artifact.get("executable", "")).resolve() != binary: + raise ValueError("Cargo did not produce the requested RustFS executable") + if source_identity() != before: + raise ValueError("Build inputs changed during compilation; finish preparing embedded assets and rebuild in an isolated worktree") + record = { + "schema": 1, + "source": before, + "requested_features": requested, + "features": sorted(artifact["features"]), + "profile": profile, + "rustc": subprocess.check_output(["rustc", "-Vv"], text=True), + "binary_sha256": file_hash(binary), + } + sidecar.write_text(json.dumps(record, sort_keys=True) + "\n") + print(f"Built E2E server: {binary}\nIdentity: {sidecar}", file=sys.stderr) + + +def verify(binary, profile, requested): + record = json.loads(sidecar_path(binary).read_text()) + if not isinstance(record, dict) or set(record) != {"schema", "source", "requested_features", "features", "profile", "rustc", "binary_sha256"} or type(record["schema"]) is not int or record["schema"] != 1: + raise ValueError("Missing or unsupported E2E binary identity; run the build command") + if not isinstance(record["rustc"], str) or not record["rustc"].strip(): + raise ValueError("Missing E2E build toolchain identity") + if record["requested_features"] != requested or record["profile"] != profile: + raise ValueError("E2E binary build features/profile differ from this test invocation") + if not isinstance(record["features"], list) or not all(isinstance(item, str) for item in record["features"]) or not set(requested) <= set(record["features"]): + raise ValueError("Invalid resolved E2E binary features") + if record["source"] != source_identity(): + raise ValueError("E2E binary was built from different inputs; rebuild before testing") + if record["binary_sha256"] != file_hash(binary): + raise ValueError("E2E binary content differs from its build identity") + return record + + +def run(binary, profile, requested, command): + if not command: + raise ValueError("run requires a test command after --") + override = os.environ.get("CARGO_BIN_EXE_rustfs") + if override and Path(override).resolve() != binary: + raise ValueError("CARGO_BIN_EXE_rustfs selects a different server; use --binary explicitly") + record = verify(binary, profile, requested) + metadata = binary.stat() + with tempfile.TemporaryDirectory(prefix="rustfs-e2e-receipt-") as directory: + receipt = Path(directory) / "receipt.json" + receipt.write_text(json.dumps({ + "schema": 1, + "workspace": str(ROOT), + "binary": str(binary), + "size": metadata.st_size, + "modified_ns": metadata.st_mtime_ns, + "features": record["features"], + })) + env = dict(os.environ, CARGO_BIN_EXE_rustfs=str(binary), RUSTFS_BUILD_FEATURES=",".join(record["features"])) + env[RECEIPT_ENV] = str(receipt) + with subprocess.Popen(command, cwd=ROOT, env=env, start_new_session=True) as process: + try: + status = process.wait() + except (KeyboardInterrupt, SystemExit): + terminate_command(process) + raise + try: + if verify(binary, profile, requested) != record: + raise ValueError("E2E build identity changed during testing") + except (OSError, ValueError, subprocess.SubprocessError) as error: + print(f"E2E validation invalidated: {error}", file=sys.stderr) + return status if status else 1 + return status + + +def main(): + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument("mode", choices=("build", "run")) + parser.add_argument("--features", default="", help="additional Cargo features; defaults remain enabled") + parser.add_argument("--profile", choices=("debug", "release"), default="debug") + parser.add_argument("--binary", type=Path, help="prebuilt server path for run") + parser.add_argument("--bins", action="store_true", help="build all RustFS binary targets, preserving the CI build matrix") + # Parse the child command separately so its options are never interpreted here. + args = sys.argv[1:] + separator = args.index("--") if "--" in args else len(args) + command = args[separator + 1:] if separator < len(args) else [] + options = parser.parse_args(args[:separator]) + target_dir = Path(os.environ.get("CARGO_TARGET_DIR", ROOT / "target")).resolve() + binary = (options.binary or target_dir / options.profile / ("rustfs.exe" if os.name == "nt" else "rustfs")).resolve() + try: + validate_target_directory(target_dir) + requested = feature_set(options.features) + if options.mode == "build": + binary.parent.mkdir(parents=True, exist_ok=True) + with exclusive_binary(binary): + if options.mode == "build": + if options.binary or command: + raise ValueError("build does not accept --binary or a child command") + build(binary, target_dir, options.profile, requested, options.bins) + return 0 + if options.bins: + raise ValueError("--bins is a build option") + return run(binary, options.profile, requested, command) + except (OSError, ValueError, subprocess.SubprocessError) as error: + print(f"E2E prerequisite failed: {error}", file=sys.stderr) + return 1 + + +if __name__ == "__main__": + signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit(128 + signum)) + raise SystemExit(main()) diff --git a/scripts/run_e2e_tests.sh b/scripts/run_e2e_tests.sh index 7a1a470eb..a23cb0028 100755 --- a/scripts/run_e2e_tests.sh +++ b/scripts/run_e2e_tests.sh @@ -14,7 +14,12 @@ NC='\033[0m' # No Color # Default values PROJECT_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" -TARGET_DIR="$PROJECT_ROOT/target/debug" +CARGO_TARGET_DIR="${CARGO_TARGET_DIR:-$PROJECT_ROOT/target}" +if [[ "$CARGO_TARGET_DIR" != /* ]]; then + CARGO_TARGET_DIR="$PROJECT_ROOT/$CARGO_TARGET_DIR" +fi +export CARGO_TARGET_DIR +TARGET_DIR="$CARGO_TARGET_DIR/debug" RUSTFS_BINARY="$TARGET_DIR/rustfs" DATA_DIR="$TARGET_DIR/rustfs_test_data" RUSTFS_PID="" @@ -94,7 +99,7 @@ build_rustfs() { print_info "Building RustFS..." cd "$PROJECT_ROOT" - if ! cargo build --bin rustfs --features "$RUSTFS_BUILD_FEATURES"; then + if ! python3 scripts/e2e_binary.py build --features "$RUSTFS_BUILD_FEATURES"; then print_error "Failed to build RustFS" exit 1 fi @@ -115,6 +120,10 @@ check_dependencies() { missing_tools+=("curl") fi + if ! command -v python3 >/dev/null 2>&1; then + missing_tools+=("python3") + fi + if ! command -v cargo >/dev/null 2>&1; then missing_tools+=("cargo") fi @@ -203,7 +212,7 @@ run_tests() { print_info "Test command: ${test_cmd[*]}" - if "${test_cmd[@]}"; then + if python3 scripts/e2e_binary.py run --features "$RUSTFS_BUILD_FEATURES" -- "${test_cmd[@]}"; then print_success "All tests passed!" return 0 else diff --git a/scripts/run_ecstore_validation_suite.sh b/scripts/run_ecstore_validation_suite.sh index 12fc9dd74..f621cc1fb 100755 --- a/scripts/run_ecstore_validation_suite.sh +++ b/scripts/run_ecstore_validation_suite.sh @@ -243,9 +243,10 @@ run_quick_e2e_steps() { return fi - run_step "e2e-reliability-disk-fault" cargo test --package e2e_test reliability_disk_fault_test -- --nocapture - run_step "e2e-heal-erasure-disk-rebuild" cargo test --package e2e_test heal_erasure_disk_rebuild_test -- --nocapture - run_step "e2e-namespace-lock-quorum" cargo test --package e2e_test namespace_lock_quorum_test -- --nocapture + run_step "build-e2e-server" python3 scripts/e2e_binary.py build + run_step "e2e-reliability-disk-fault" python3 scripts/e2e_binary.py run -- cargo test --package e2e_test reliability_disk_fault_test -- --nocapture + run_step "e2e-heal-erasure-disk-rebuild" python3 scripts/e2e_binary.py run -- cargo test --package e2e_test heal_erasure_disk_rebuild_test -- --nocapture + run_step "e2e-namespace-lock-quorum" python3 scripts/e2e_binary.py run -- cargo test --package e2e_test namespace_lock_quorum_test -- --nocapture } run_quick_profile() { @@ -313,15 +314,15 @@ write_blackbox_matrix() { { printf 'profile\tscenario\tgate\tcommand\tfixture_env\tstatus\n' - printf 'quick\tsingle-node disk fault read/write\tblack-box\tcargo test --package e2e_test reliability_disk_fault_test -- --nocapture\tnone\t%s\n' "$e2e_status" - printf 'quick\theal degraded erasure disk rebuild\tblack-box\tcargo test --package e2e_test heal_erasure_disk_rebuild_test -- --nocapture\tnone\t%s\n' "$e2e_status" - printf 'quick\tnamespace lock quorum under EC ops\tblack-box\tcargo test --package e2e_test namespace_lock_quorum_test -- --nocapture\tnone\t%s\n' "$e2e_status" + printf 'quick\tsingle-node disk fault read/write\tblack-box\tpython3 scripts/e2e_binary.py run -- cargo test --package e2e_test reliability_disk_fault_test -- --nocapture\tnone\t%s\n' "$e2e_status" + printf 'quick\theal degraded erasure disk rebuild\tblack-box\tpython3 scripts/e2e_binary.py run -- cargo test --package e2e_test heal_erasure_disk_rebuild_test -- --nocapture\tnone\t%s\n' "$e2e_status" + printf 'quick\tnamespace lock quorum under EC ops\tblack-box\tpython3 scripts/e2e_binary.py run -- cargo test --package e2e_test namespace_lock_quorum_test -- --nocapture\tnone\t%s\n' "$e2e_status" printf 'full\tlegacy bitrot read fixture restore\tfixture\tcargo test -p rustfs-ecstore --test legacy_bitrot_read_test -- --nocapture\tRUSTFS_LEGACY_TEST_ROOT,RUSTFS_LEGACY_TEST_DISK\t%s\n' "$legacy_status" printf 'full\tMinIO generated encrypted read and negative restore fixture\tfixture\tcargo test -p rustfs --features rio-v2 storage::minio_generated_read_test --lib -- --ignored --nocapture\tRUSTFS_MINIO_FIXTURE_ROOT,RUSTFS_MINIO_STATIC_KMS_KEY_B64\t%s\n' "$minio_status" printf 'full\tS3 multipart range versioning delete subset\tblack-box\tenv TESTEXPR=\"multipart or range or versioning or delete\" DEPLOY_MODE=build MAXFAIL=0 ./scripts/s3-tests/run.sh\tnone\t%s\n' "$s3_status" - printf 'destructive\tdistributed cluster concurrency\tblack-box\tcargo test --package e2e_test cluster_concurrency_test -- --nocapture\tnone\t%s\n' "$destructive_status" - printf 'destructive\tstale multipart cleanup cluster\tblack-box\tcargo test --package e2e_test stale_multipart_cleanup_cluster_test -- --nocapture\tnone\t%s\n' "$destructive_status" - printf 'destructive\tdelete marker migration semantics\tblack-box\tcargo test --package e2e_test delete_marker_migration_semantics_test -- --nocapture\tnone\t%s\n' "$destructive_status" + printf 'destructive\tdistributed cluster concurrency\tblack-box\tpython3 scripts/e2e_binary.py run -- cargo test --package e2e_test cluster_concurrency_test -- --nocapture\tnone\t%s\n' "$destructive_status" + printf 'destructive\tstale multipart cleanup cluster\tblack-box\tpython3 scripts/e2e_binary.py run -- cargo test --package e2e_test stale_multipart_cleanup_cluster_test -- --nocapture\tnone\t%s\n' "$destructive_status" + printf 'destructive\tdelete marker migration semantics\tblack-box\tpython3 scripts/e2e_binary.py run -- cargo test --package e2e_test delete_marker_migration_semantics_test -- --nocapture\tnone\t%s\n' "$destructive_status" } >"$BLACKBOX_MATRIX" } @@ -566,9 +567,9 @@ run_destructive_profile() { return fi - run_step "e2e-cluster-concurrency" cargo test --package e2e_test cluster_concurrency_test -- --nocapture - run_step "e2e-stale-multipart-cleanup-cluster" cargo test --package e2e_test stale_multipart_cleanup_cluster_test -- --nocapture - run_step "e2e-delete-marker-migration-semantics" cargo test --package e2e_test delete_marker_migration_semantics_test -- --nocapture + run_step "e2e-cluster-concurrency" python3 scripts/e2e_binary.py run -- cargo test --package e2e_test cluster_concurrency_test -- --nocapture + run_step "e2e-stale-multipart-cleanup-cluster" python3 scripts/e2e_binary.py run -- cargo test --package e2e_test stale_multipart_cleanup_cluster_test -- --nocapture + run_step "e2e-delete-marker-migration-semantics" python3 scripts/e2e_binary.py run -- cargo test --package e2e_test delete_marker_migration_semantics_test -- --nocapture } run_fuzz_profile() { diff --git a/scripts/test_e2e_binary.py b/scripts/test_e2e_binary.py new file mode 100644 index 000000000..cc11399f2 --- /dev/null +++ b/scripts/test_e2e_binary.py @@ -0,0 +1,263 @@ +#!/usr/bin/env python3 +"""Exercise the E2E build/run boundary without compiling RustFS.""" + +import json +import os +from pathlib import Path +import shutil +import signal +import subprocess +import sys +import tempfile +import unittest + + +class BinaryProvenanceTests(unittest.TestCase): + def setUp(self): + self.temp = tempfile.TemporaryDirectory() + self.addCleanup(self.temp.cleanup) + self.root = Path(self.temp.name) + (self.root / "scripts").mkdir() + shutil.copy(Path(__file__).with_name("e2e_binary.py"), self.root / "scripts/e2e_binary.py") + (self.root / "Cargo.toml").write_text("[workspace]\n") + (self.root / "source.rs").write_text("original source\n") + (self.root / ".gitignore").write_text("/target/\n/rustfs/static/\n") + (self.root / ".agents/skills").mkdir(parents=True) + (self.root / ".agents/skills/SKILL.md").write_text("tracked instructions\n") + (self.root / ".claude").mkdir() + (self.root / ".claude/skills").symlink_to("../.agents/skills", target_is_directory=True) + subprocess.run(["git", "init", "-q", str(self.root)], check=True) + for args in (["add", "."], ["-c", "user.name=Test", "-c", "user.email=test@example.com", "commit", "-qm", "fixture"]): + subprocess.run(["git", "-C", str(self.root), *args], check=True) + self.commands = self.root / "target/commands" + self.commands.mkdir(parents=True) + cargo = self.commands / "cargo" + cargo.write_text(f"#!{sys.executable}\n" + '''import json, os, pathlib, sys +if os.environ.get("FAKE_BUILD_FAIL"): + raise SystemExit(23) +args = sys.argv[1:] +target = pathlib.Path(args[args.index("--target-dir") + 1]) +binary = target / ("release" if "--release" in args else "debug") / "rustfs" +binary.parent.mkdir(parents=True, exist_ok=True) +binary.write_text("#!/bin/sh\\nexit 0\\n") +binary.chmod(0o755) +features = ["default", "ftps", "webdav"] +if "--features" in args: + features.extend(args[args.index("--features") + 1].split(",")) +if "full" in features: + features.extend(["sftp", "swift", "metrics-gpu", "pyroscope"]) +print(json.dumps({"reason": "compiler-artifact", "target": {"name": "rustfs", "kind": ["bin"]}, "executable": str(binary), "features": sorted(set(features))})) +if os.environ.get("FAKE_BUILD_MUTATE"): + pathlib.Path("source.rs").write_text("changed during build") +''') + cargo.chmod(0o755) + rustc = self.commands / "rustc" + rustc.write_text("#!/bin/sh\nprintf 'rustc fixture\\nhost: fixture\\n'\n") + rustc.chmod(0o755) + self.env = dict(os.environ, PATH=f"{self.commands}{os.pathsep}{os.environ['PATH']}") + for name in ("CARGO_TARGET_DIR", "CARGO_BIN_EXE_rustfs", "RUSTFS_BUILD_FEATURES", "RUSTFS_E2E_BINARY_RECEIPT"): + self.env.pop(name, None) + self.binary = self.root / "target/debug/rustfs" + self.sidecar = self.binary.with_name("rustfs.e2e.json") + + def invoke(self, *args, env=None): + return subprocess.run([sys.executable, str(self.root / "scripts/e2e_binary.py"), *args], cwd=self.root, env=env or self.env, text=True, capture_output=True) + + def build(self, features=""): + result = self.invoke("build", "--features", features) + self.assertEqual(result.returncode, 0, result.stderr) + + def run_code(self, code="pass", features="", env=None): + return self.invoke("run", "--features", features, "--", sys.executable, "-c", code, env=env) + + def test_build_run_and_receipt_cleanup(self): + self.build("full,e2e-test-hooks") + result = self.run_code("import os,pathlib; print(os.environ['RUSTFS_E2E_BINARY_RECEIPT']); assert pathlib.Path(os.environ['CARGO_BIN_EXE_rustfs']).is_file(); assert 'sftp' in os.environ['RUSTFS_BUILD_FEATURES']", "e2e-test-hooks,full") + self.assertEqual(result.returncode, 0, result.stderr) + self.assertFalse(Path(result.stdout.strip()).exists(), "run receipts must not survive their command") + self.assertIn("sftp", json.loads(self.sidecar.read_text())["features"]) + + def test_source_changes_are_not_hidden_by_timestamps_or_head(self): + self.build() + path = self.root / "source.rs" + old = path.stat() + path.write_text("different bytes\n") + os.utime(path, ns=(old.st_atime_ns, old.st_mtime_ns)) + self.assertNotEqual(self.run_code().returncode, 0) + + def test_deleted_untracked_and_ignored_embedded_inputs(self): + for mutation in ("delete", "untracked", "static"): + with self.subTest(mutation=mutation): + self.build() + path = self.root / "source.rs" + if mutation == "delete": + path.unlink() + elif mutation == "untracked": + (self.root / "new.rs").write_text("new source") + else: + static = self.root / "rustfs/static" + static.mkdir(parents=True) + (static / "index.html").write_text("embedded content") + self.assertNotEqual(self.run_code().returncode, 0) + path.write_text("original source\n") + + def test_wrong_binary_features_and_manifest_fail_closed(self): + self.build("sftp") + self.assertNotEqual(self.run_code(features="webdav").returncode, 0) + self.binary.write_text("old server") + self.assertNotEqual(self.run_code(features="sftp").returncode, 0) + self.sidecar.write_text("{}") + self.assertNotEqual(self.run_code(features="sftp").returncode, 0) + self.sidecar.unlink() + self.assertNotEqual(self.run_code(features="sftp").returncode, 0) + + def test_build_failure_or_source_race_does_not_leave_a_receipt(self): + for failure in ("FAKE_BUILD_FAIL", "FAKE_BUILD_MUTATE"): + self.build() + result = self.invoke("build", env=dict(self.env, **{failure: "1"})) + self.assertNotEqual(result.returncode, 0) + self.assertFalse(self.sidecar.exists()) + + def test_child_failure_and_changes_during_run_fail(self): + self.build() + failed = self.run_code("raise SystemExit(37)") + self.assertEqual(failed.returncode, 37, failed.stderr) + for code in ("import pathlib; pathlib.Path('source.rs').write_text('changed while testing')", "import pathlib; pathlib.Path('target/debug/rustfs').write_text('different server')"): + self.build() + self.assertNotEqual(self.run_code(code).returncode, 0) + + def test_override_cannot_select_an_unverified_server(self): + self.build() + result = self.run_code(env=dict(self.env, CARGO_BIN_EXE_rustfs="/some/old/server")) + self.assertNotEqual(result.returncode, 0) + + def test_artifact_moves_between_clean_checkouts(self): + self.build() + with tempfile.TemporaryDirectory() as destination: + clone = Path(destination) / "clone" + subprocess.run(["git", "clone", "-q", str(self.root), str(clone)], check=True) + (clone / "target/debug").mkdir(parents=True) + shutil.copy2(self.binary, clone / "target/debug/rustfs") + shutil.copy2(self.sidecar, clone / "target/debug/rustfs.e2e.json") + result = subprocess.run([sys.executable, str(clone / "scripts/e2e_binary.py"), "run", "--", sys.executable, "-c", "pass"], cwd=clone, env=self.env, text=True, capture_output=True) + self.assertEqual(result.returncode, 0, result.stderr) + + def test_target_directory_and_profile_are_explicit(self): + env = dict(self.env, CARGO_TARGET_DIR="target/custom") + built = self.invoke("build", "--profile", "release", env=env) + self.assertEqual(built.returncode, 0, built.stderr) + run = self.invoke("run", "--profile", "release", "--", sys.executable, "-c", "pass", env=env) + self.assertEqual(run.returncode, 0, run.stderr) + self.assertNotEqual(self.invoke("run", "--", sys.executable, "-c", "pass", env=env).returncode, 0) + + def test_target_directory_cannot_hide_source_inputs(self): + for target in (str(self.root), str(self.root / "crates"), str(self.root.parent)): + with self.subTest(target=target): + result = self.invoke("build", env=dict(self.env, CARGO_TARGET_DIR=target)) + self.assertNotEqual(result.returncode, 0) + self.assertIn("CARGO_TARGET_DIR", result.stderr) + tracked = self.root / "target/tracked.rs" + tracked.write_text("tracked build input") + subprocess.run(["git", "add", "-f", "target/tracked.rs"], cwd=self.root, check=True) + self.build() + tracked.write_text("changed tracked build input") + self.assertNotEqual(self.run_code().returncode, 0) + + def test_unsupported_embedded_directory_links_fail_closed(self): + self.build() + destination = self.root / "target/embedded-assets" + destination.mkdir() + (destination / "index.html").write_text("untracked embedded input") + static = self.root / "rustfs/static" + static.mkdir(parents=True) + (static / "linked-assets").symlink_to(destination, target_is_directory=True) + self.assertNotEqual(self.run_code().returncode, 0) + + def test_directory_aliases_cannot_hide_unrecorded_inputs(self): + self.build() + target = self.root / ".agents/skills/SKILL.md" + target.write_text("changed instructions\n") + self.assertNotEqual(self.run_code().returncode, 0) + self.build() + (target.parent / ".gitignore").write_text("hidden.rs\n") + (target.parent / "hidden.rs").write_text("ignored build input\n") + result = self.invoke("build") + self.assertNotEqual(result.returncode, 0) + self.assertIn("unrecorded input", result.stderr) + alias = self.root / ".claude/skills" + alias.unlink() + with tempfile.TemporaryDirectory() as external: + alias.symlink_to(external, target_is_directory=True) + result = self.invoke("build") + self.assertNotEqual(result.returncode, 0) + self.assertIn("escapes the source inventory", result.stderr) + + def test_directory_alias_indirection_is_part_of_the_identity(self): + for name in ("first", "second"): + directory = self.root / name + directory.mkdir() + (directory / "input.rs").write_text(name) + selection = self.root / "target/selection" + selection.symlink_to(self.root / "first", target_is_directory=True) + (self.root / "source-alias").symlink_to("target/selection", target_is_directory=True) + self.build() + selection.unlink() + selection.symlink_to(self.root / "second", target_is_directory=True) + self.assertNotEqual(self.run_code().returncode, 0) + + def test_existing_embedded_files_and_symlink_targets_are_hashed(self): + static = self.root / "rustfs/static" + static.mkdir(parents=True) + index = static / "index.html" + index.write_text("embedded version one") + external = self.root / "target/embedded-file" + external.write_text("linked version one") + (static / "linked.html").symlink_to(external) + self.build() + index.write_text("embedded version two") + self.assertNotEqual(self.run_code().returncode, 0) + self.build() + external.write_text("linked version two") + self.assertNotEqual(self.run_code().returncode, 0) + + def test_each_run_hashes_binary_twice_and_never_calls_cargo(self): + script = self.root / "scripts/e2e_binary.py" + script.write_text(script.read_text().replace("def file_hash(path):\n", "def file_hash(path):\n if path.name == 'rustfs':\n with (ROOT / 'target/hash-count').open('a') as count:\n count.write('hash\\n')\n")) + self.build() + count = self.root / "target/hash-count" + count.write_text("") + result = self.run_code(env=dict(self.env, FAKE_BUILD_FAIL="1")) + self.assertEqual(result.returncode, 0, result.stderr) + self.assertEqual(count.read_text().splitlines(), ["hash", "hash"]) + + def test_concurrent_build_or_run_is_rejected(self): + self.build() + command = [sys.executable, str(self.root / "scripts/e2e_binary.py"), "run", "--", sys.executable, "-c", "print('ready', flush=True); input()"] + with subprocess.Popen(command, cwd=self.root, env=self.env, stdin=subprocess.PIPE, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True) as process: + self.assertEqual(process.stdout.readline().strip(), "ready") + try: + for args in (("build", "--features", "sftp"), ("run", "--", sys.executable, "-c", "pass")): + rejected = self.invoke(*args) + self.assertNotEqual(rejected.returncode, 0) + self.assertIn("Another E2E build/run", rejected.stderr) + finally: + output, error = process.communicate("\n", timeout=10) + self.assertEqual(process.returncode, 0, error + output) + self.assertFalse(self.binary.with_name("rustfs.e2e.lock").exists()) + + def test_interruption_cleans_receipt_and_releases_ownership(self): + self.build() + for signum in (signal.SIGINT, signal.SIGTERM): + command = [sys.executable, str(self.root / "scripts/e2e_binary.py"), "run", "--", sys.executable, "-c", "import os; print(os.environ['RUSTFS_E2E_BINARY_RECEIPT'], flush=True); input()"] + with subprocess.Popen(command, cwd=self.root, env=self.env, stdin=subprocess.PIPE, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True) as process: + receipt = Path(process.stdout.readline().strip()) + self.assertTrue(receipt.is_file()) + process.send_signal(signum) + process.communicate(timeout=10) + self.assertNotEqual(process.returncode, 0) + self.assertFalse(receipt.exists()) + self.assertFalse(self.binary.with_name("rustfs.e2e.lock").exists()) + + +if __name__ == "__main__": + unittest.main()