mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 00:23:53 +08:00
* fix(ci): restore Windows test portability Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> * fix(tasks): skip Unix lockfile check on Windows Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> * fix(tasks): use buf shim on Windows Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> --------- Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
91 lines
4.4 KiB
TOML
91 lines
4.4 KiB
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# Rust check, lint, and format tasks
|
|
|
|
["rust:check"]
|
|
description = "Check all Rust crates for errors"
|
|
depends = ["rust:lockfiles:check"]
|
|
run = "cargo check --workspace"
|
|
run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/windows-msvc.ps1 check native"
|
|
hide = true
|
|
|
|
["rust:lockfiles:check"]
|
|
description = "Verify all tracked Cargo lockfiles are current"
|
|
run = "tasks/scripts/check-cargo-lockfiles.sh"
|
|
run_windows = "echo Skipping rust:lockfiles:check: Cargo lockfile validation uses a Unix shell helper."
|
|
hide = true
|
|
|
|
["rust:lint"]
|
|
description = "Lint Rust code with Clippy (deny warnings)"
|
|
depends = ["rust:lockfiles:check"]
|
|
run = [
|
|
"cargo clippy --workspace --all-targets -- -D warnings",
|
|
"cargo clippy --manifest-path e2e/rust/Cargo.toml --all-targets -- -D warnings",
|
|
"cargo clippy --manifest-path examples/governance-interceptor/Cargo.toml --all-targets -- -D warnings",
|
|
"cargo clippy --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all-targets -- -D warnings",
|
|
]
|
|
run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/windows-msvc.ps1 lint native"
|
|
hide = true
|
|
|
|
["rust:format"]
|
|
description = "Format Rust code"
|
|
run = [
|
|
"cargo fmt --all",
|
|
"cargo fmt --manifest-path e2e/rust/Cargo.toml --all",
|
|
"cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all",
|
|
"cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all",
|
|
]
|
|
hide = true
|
|
|
|
["rust:format:check"]
|
|
description = "Check Rust formatting"
|
|
run = [
|
|
"cargo fmt --all -- --check",
|
|
"cargo fmt --manifest-path e2e/rust/Cargo.toml --all -- --check",
|
|
"cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all -- --check",
|
|
"cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all -- --check",
|
|
]
|
|
hide = true
|
|
|
|
["rust:deny"]
|
|
description = "Check dependencies for all cargo-deny rules"
|
|
run = "cargo deny check"
|
|
|
|
["rust:deny:policy"]
|
|
description = "Check dependencies for license violations, bans, and source restrictions"
|
|
run = "cargo deny check licenses bans sources"
|
|
|
|
|
|
["rust:verify:telemetry-off"]
|
|
description = "Verify telemetry emission code is compiled out with --no-default-features"
|
|
run = [
|
|
# Positive control: the default (telemetry-on) gateway must contain the
|
|
# markers, so the absent checks below can never become silently vacuous.
|
|
"cargo build -p openshell-gateway --bin openshell-gateway",
|
|
"tasks/scripts/verify-telemetry-compiled-out.sh present target/debug/openshell-gateway",
|
|
# Guard: telemetry-free builds must contain no telemetry markers. Built
|
|
# through the `defaults-without-telemetry` alias, which is how the docs tell
|
|
# operators to produce these artifacts.
|
|
"cargo build -p openshell-gateway --bin openshell-gateway --no-default-features --features defaults-without-telemetry",
|
|
"tasks/scripts/verify-telemetry-compiled-out.sh absent target/debug/openshell-gateway",
|
|
"cargo build -p openshell-sandbox --bin openshell-sandbox --no-default-features --features defaults-without-telemetry",
|
|
"tasks/scripts/verify-telemetry-compiled-out.sh absent target/debug/openshell-sandbox",
|
|
]
|
|
|
|
["rust:verify:defaults-without-telemetry"]
|
|
description = "Verify the defaults-without-telemetry feature alias matches default minus telemetry and cannot be used additively"
|
|
run = "tasks/scripts/verify-defaults-without-telemetry.sh"
|
|
|
|
["rust:verify:system-ca-roots"]
|
|
description = "Verify system CA roots build mode compiles and excludes bundled Mozilla root crates"
|
|
run = [
|
|
# Check that the sandbox compiles cleanly in system CA roots mode (all
|
|
# defaults except bundled-ca-roots).
|
|
"cargo check -p openshell-sandbox --all-targets --no-default-features --features system-ca-roots",
|
|
# Guard: webpki-roots must not appear in the dependency graph.
|
|
"bash -c 'if cargo tree -p openshell-sandbox -i webpki-roots --no-default-features --features system-ca-roots 2>/dev/null | grep -q webpki-roots; then echo \"ERROR: webpki-roots found in system CA roots build\" >&2; exit 1; fi'",
|
|
# Guard: webpki-root-certs must not appear either (webpki-roots re-exports it).
|
|
"bash -c 'if cargo tree -p openshell-sandbox -i webpki-root-certs --no-default-features --features system-ca-roots 2>/dev/null | grep -q webpki-root-certs; then echo \"ERROR: webpki-root-certs found in system CA roots build\" >&2; exit 1; fi'",
|
|
]
|