mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-18 10:43:15 +00:00
abca7ddfd7
`test_vault_kv2_sources_do_not_claim_transit_wrapping` asserted that four `include_str!`-pinned files never describe the Vault KV2 backend as wrapping key material through Vault's Transit engine. The invariant is a documentation-claim invariant with no behavioral twin by construction, and the test form was weak in both directions: it saw only four files (the same prose in a fifth file passed silently) and it stopped compiling — rather than reporting a violation — as soon as one of them was renamed. Move the four literals verbatim into `scripts/check_fips_wording.sh`, which already guards the adjacent cryptographic over-claim class (unsupported FIPS validation wording) and is anchored to the same policy document. The guard now greps every file under `crates/kms` for the same four case-sensitive literals and separately reports a moved pinned source instead of failing to build. `check_fips_wording.sh` previously ran only in `make pre-commit` / `pre-pr`, so wire it into the Quick Checks job of both CI workflows to keep the invariant's failure visibility at least as strong as the deleted test's.
151 lines
5.7 KiB
YAML
151 lines
5.7 KiB
YAML
# Copyright 2026 RustFS Team
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
# Companion to ci.yml for required status checks.
|
|
#
|
|
# ci.yml skips docs-only pull requests via paths-ignore, but the branch ruleset
|
|
# requires a check named "Test and Lint" — without this workflow a docs-only PR
|
|
# would wait on it forever. This workflow triggers on exactly the paths ci.yml
|
|
# ignores and reports success under the same job name. Mixed PRs trigger both
|
|
# workflows and the real check still gates: a required check with any failing
|
|
# run blocks the merge.
|
|
# https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/troubleshooting-required-status-checks#handling-skipped-but-required-checks
|
|
#
|
|
# "Quick Checks" is mirrored here ahead of the ruleset change that will make it
|
|
# required too (rustfs/backlog#1599). Until that change lands this job is
|
|
# inert; mirroring it first is what lets the ruleset change happen without
|
|
# stranding docs-only PRs on a check nobody reports.
|
|
#
|
|
# Keep the paths list below in sync with the pull_request paths-ignore list
|
|
# in ci.yml, and keep the quick-checks steps below byte-identical to the
|
|
# quick-checks job in ci.yml.
|
|
|
|
name: Continuous Integration (docs only)
|
|
|
|
on:
|
|
pull_request:
|
|
types: [ opened, synchronize, reopened ]
|
|
branches: [ main ]
|
|
paths:
|
|
- "**.md"
|
|
- "docs/**"
|
|
- "deploy/**"
|
|
- "scripts/dev_*.sh"
|
|
- "scripts/probe.sh"
|
|
- "LICENSE*"
|
|
- ".gitignore"
|
|
- ".dockerignore"
|
|
- "README*"
|
|
- "**/*.png"
|
|
- "**/*.jpg"
|
|
- "**/*.svg"
|
|
- ".github/workflows/build.yml"
|
|
- ".github/workflows/docker.yml"
|
|
- ".github/workflows/audit.yml"
|
|
- "flake.lock"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
# Deliberately NOT a bare `echo`. Once "Quick Checks" becomes a required
|
|
# check, ci.yml gates every expensive job behind it, so a mixed PR reports
|
|
# two check runs with this name: the real one (45-51s) and this companion.
|
|
# GitHub has no written contract for how it picks between same-named
|
|
# required check runs ("latest wins" vs "any failure blocks"), so instead of
|
|
# relying on ordering we make both runs execute the same commands against
|
|
# the same merge ref — their conclusions are then necessarily identical and
|
|
# the choice does not matter. Keep these steps byte-identical to the
|
|
# quick-checks job in ci.yml (a guard script that asserts this, and the paths
|
|
# sync below, is tracked in rustfs/backlog#1603).
|
|
#
|
|
# For a genuinely docs-only PR this adds no strictness (no code changed, so
|
|
# fmt and the guards always pass) and costs ~50s of ubuntu-latest.
|
|
quick-checks:
|
|
name: Quick Checks
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install ripgrep
|
|
run: sudo apt-get update && sudo apt-get install -y ripgrep
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
|
|
with:
|
|
components: rustfmt
|
|
|
|
- name: Check code formatting
|
|
run: cargo fmt --all --check
|
|
|
|
- name: Check unsafe code allowances
|
|
run: ./scripts/check_unsafe_code_allowances.sh
|
|
|
|
- name: Check layered dependencies
|
|
run: ./scripts/check_layer_dependencies.sh
|
|
|
|
- name: Check architecture migration rules
|
|
run: ./scripts/check_architecture_migration_rules.sh
|
|
|
|
- name: Check logging guardrails
|
|
run: ./scripts/check_logging_guardrails.sh
|
|
|
|
- name: Check tokio io-uring feature guard
|
|
run: ./scripts/check_no_tokio_io_uring.sh
|
|
|
|
- name: Check extension schema boundaries
|
|
run: ./scripts/check_extension_schema_boundaries.sh
|
|
|
|
- name: Check body-cache whitelist guard
|
|
run: ./scripts/check_body_cache_whitelist.sh
|
|
|
|
- name: Check s3s footprint ratchet
|
|
run: ./scripts/check_s3s_footprint.sh
|
|
|
|
- name: Check cryptographic capability wording
|
|
run: ./scripts/check_fips_wording.sh
|
|
|
|
- name: Check no planning docs committed
|
|
run: ./scripts/check_no_planning_docs.sh
|
|
|
|
- name: Check CI paths stay in sync
|
|
run: ./scripts/check_ci_paths_sync.sh
|
|
|
|
- name: Check io_uring lane --lib precondition
|
|
run: ./scripts/check_uring_lane_lib_only.sh
|
|
|
|
test-and-lint:
|
|
name: Test and Lint
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# Docs-only PRs skip the full code CI, but they are exactly where a
|
|
# planning-type document could be slipped in (git add -f bypasses
|
|
# .gitignore). Run the guard here so the required "Test and Lint" check
|
|
# stays meaningful for docs-only changes.
|
|
- name: Check no planning docs committed
|
|
run: ./scripts/check_no_planning_docs.sh
|
|
|
|
- name: Satisfy required check for docs-only changes
|
|
run: echo "Docs-only change — code CI is skipped by paths-ignore; planning-docs guard passed, reporting success for the required 'Test and Lint' check."
|