mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-19 11:06:17 +00:00
8315c23d49
test(kms): move the Vault KV2 Transit-wrapping doc guard into check_fips_wording.sh `test_vault_kv2_sources_do_not_claim_transit_wrapping` asserted that four `include_str!`-pinned files never describe the Vault KV2 backend as wrapping key material through Vault's Transit engine. The invariant is a documentation-claim invariant with no behavioral twin by construction, and the test form was weak in both directions: it saw only four files (the same prose in a fifth file passed silently) and it stopped compiling — rather than reporting a violation — as soon as one of them was renamed. Move the four literals verbatim into `scripts/check_fips_wording.sh`, which already guards the adjacent cryptographic over-claim class (unsupported FIPS validation wording) and is anchored to the same policy document. The guard now greps every file under `crates/kms` for the same four case-sensitive literals and separately reports a moved pinned source instead of failing to build. `check_fips_wording.sh` previously ran only in `make pre-commit` / `pre-pr`, so wire it into the Quick Checks job of both CI workflows to keep the invariant's failure visibility at least as strong as the deleted test's.
82 lines
2.9 KiB
Makefile
82 lines
2.9 KiB
Makefile
## —— Code quality and Formatting ------------------------------------------------------------------
|
|
|
|
.NOTPARALLEL: fix
|
|
|
|
.PHONY: fmt
|
|
fmt: core-deps fmt-deps ## Format code
|
|
@echo "🔧 Formatting code..."
|
|
cargo fmt --all
|
|
|
|
.PHONY: fmt-check
|
|
fmt-check: core-deps fmt-deps ## Check code formatting
|
|
@echo "📝 Checking code formatting..."
|
|
cargo fmt --all --check
|
|
|
|
.PHONY: clippy-check
|
|
clippy-check: core-deps ## Run clippy checks
|
|
@echo "🔍 Running clippy checks..."
|
|
cargo clippy --all-targets -- -D warnings
|
|
|
|
.PHONY: clippy-fix
|
|
clippy-fix: core-deps ## Apply clippy fixes
|
|
@echo "🔧 Applying clippy fixes..."
|
|
cargo clippy --fix --allow-dirty
|
|
|
|
.PHONY: fix
|
|
fix: fmt clippy-fix ## Format code and apply clippy fixes
|
|
|
|
.PHONY: quick-check
|
|
quick-check: core-deps ## Run fast workspace compilation check
|
|
@echo "🔨 Running fast compilation check..."
|
|
cargo check --workspace --exclude e2e_test
|
|
|
|
.PHONY: unsafe-code-check
|
|
unsafe-code-check: ## Check unsafe_code allowances have SAFETY comments
|
|
@echo "🔒 Checking unsafe_code allowances..."
|
|
./scripts/check_unsafe_code_allowances.sh
|
|
|
|
.PHONY: architecture-migration-check
|
|
architecture-migration-check: ## Check architecture migration guardrails
|
|
@echo "🏗️ Checking architecture migration guardrails..."
|
|
./scripts/check_architecture_migration_rules.sh
|
|
|
|
.PHONY: logging-guardrails-check
|
|
logging-guardrails-check: ## Check logging guardrails for redaction and noise regressions
|
|
@echo "🪵 Checking logging guardrails..."
|
|
./scripts/check_logging_guardrails.sh
|
|
|
|
.PHONY: tokio-io-uring-check
|
|
tokio-io-uring-check: ## Check tokio io-uring runtime feature stays removed
|
|
@echo "🚫 Checking tokio io-uring feature guard..."
|
|
./scripts/check_no_tokio_io_uring.sh
|
|
|
|
.PHONY: extension-schema-check
|
|
extension-schema-check: ## Check extension-schema stays a lightweight contract crate
|
|
@echo "🧩 Checking extension schema boundaries..."
|
|
./scripts/check_extension_schema_boundaries.sh
|
|
|
|
.PHONY: body-cache-whitelist-check
|
|
body-cache-whitelist-check: ## Check the body-cache eligibility gate stays a fail-closed allow-list
|
|
@echo "🧱 Checking body-cache whitelist guard..."
|
|
./scripts/check_body_cache_whitelist.sh
|
|
|
|
.PHONY: s3s-footprint-check
|
|
s3s-footprint-check: ## Check the s3s dependency footprint ratchet stays frozen
|
|
@echo "📦 Checking s3s footprint ratchet..."
|
|
./scripts/check_s3s_footprint.sh
|
|
|
|
.PHONY: fips-wording-check
|
|
fips-wording-check: ## Check docs and crates/kms do not over-claim crypto capabilities
|
|
@echo "📣 Checking cryptographic capability wording guard..."
|
|
./scripts/check_fips_wording.sh
|
|
|
|
.PHONY: log-analyzer-rules-check
|
|
log-analyzer-rules-check: core-deps ## Check log-analyzer rule anchors still exist verbatim in source
|
|
@echo "🩺 Checking log-analyzer rule anchors..."
|
|
./scripts/check_log_analyzer_rules.sh
|
|
|
|
.PHONY: compilation-check
|
|
compilation-check: core-deps ## Run compilation check
|
|
@echo "🔨 Running compilation check..."
|
|
cargo check --all-targets
|