mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-18 18:46:17 +00:00
test(kms): move the Vault KV2 Transit-wrapping doc guard into check_fips_wording.sh
`test_vault_kv2_sources_do_not_claim_transit_wrapping` asserted that four `include_str!`-pinned files never describe the Vault KV2 backend as wrapping key material through Vault's Transit engine. The invariant is a documentation-claim invariant with no behavioral twin by construction, and the test form was weak in both directions: it saw only four files (the same prose in a fifth file passed silently) and it stopped compiling — rather than reporting a violation — as soon as one of them was renamed. Move the four literals verbatim into `scripts/check_fips_wording.sh`, which already guards the adjacent cryptographic over-claim class (unsupported FIPS validation wording) and is anchored to the same policy document. The guard now greps every file under `crates/kms` for the same four case-sensitive literals and separately reports a moved pinned source instead of failing to build. `check_fips_wording.sh` previously ran only in `make pre-commit` / `pre-pr`, so wire it into the Quick Checks job of both CI workflows to keep the invariant's failure visibility at least as strong as the deleted test's.
This commit is contained in:
@@ -1729,30 +1729,10 @@ mod tests {
|
||||
assert!(config.validate().is_ok(), "deprecated mount_path must not be required");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_vault_kv2_sources_do_not_claim_transit_wrapping() {
|
||||
let sources = [
|
||||
("config.rs", include_str!("config.rs")),
|
||||
("api_types.rs", include_str!("api_types.rs")),
|
||||
("backends/vault.rs", include_str!("backends/vault.rs")),
|
||||
("lib.rs", include_str!("lib.rs")),
|
||||
];
|
||||
// Assemble the needles at runtime so this guard does not match its own source.
|
||||
let needles = [
|
||||
format!("wrapping via {}", "Transit"),
|
||||
format!("KV v2 + {}", "Transit"),
|
||||
format!("KV2+{}", "Transit"),
|
||||
format!("you would use Vault's {} engine", "transit"),
|
||||
];
|
||||
for (name, source) in sources {
|
||||
for needle in &needles {
|
||||
assert!(
|
||||
!source.contains(needle.as_str()),
|
||||
"{name} still describes the Vault KV2 backend with `{needle}`"
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
// The "VaultKv2 must not claim Transit wrapping" documentation-claim
|
||||
// invariant is enforced by scripts/check_fips_wording.sh, which scans every
|
||||
// file in crates/kms rather than a fixed include_str! list
|
||||
// (rustfs/backlog#1884).
|
||||
|
||||
#[test]
|
||||
fn test_legacy_persisted_vault_transit_config_uses_metadata_defaults() {
|
||||
|
||||
Reference in New Issue
Block a user