Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/branch-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,7 @@ jobs:
shell: nix develop -c bash -euo pipefail {0}
run: |
cargo fmt --all -- --check
cargo fmt --manifest-path tests/suites/conformance/Cargo.toml --all -- --check
cargo fmt --manifest-path e2e/rust/Cargo.toml --all -- --check
cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all -- --check
cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all -- --check
Expand Down Expand Up @@ -196,6 +197,7 @@ jobs:
shell: nix develop -c bash -euo pipefail {0}
run: |
cargo clippy --locked --workspace --all-targets -- -D warnings
cargo clippy --locked --manifest-path tests/suites/conformance/Cargo.toml --workspace --all-targets -- -D warnings
cargo clippy --locked --manifest-path e2e/rust/Cargo.toml --all-targets -- -D warnings
cargo clippy --locked --manifest-path examples/governance-interceptor/Cargo.toml --all-targets -- -D warnings
cargo clippy --locked --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all-targets -- -D warnings
Expand Down Expand Up @@ -235,6 +237,7 @@ jobs:
OPENSHELL_TELEMETRY_ENABLED: "false"
run: |
cargo nextest run --locked --profile ci --workspace --features openshell-server/test-support
cargo nextest run --locked --config-file .config/nextest.toml --profile ci --manifest-path tests/suites/conformance/Cargo.toml --package openshell-conformance
cargo nextest run --locked --config-file .config/nextest.toml --profile ci --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml

rust-build-modes:
Expand Down
1 change: 0 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,6 @@ Do not rely on this file for a full inventory. The detailed public and contribut
| Path | Components | Purpose |
|------|-----------|---------|
| `crates/openshell-cli/` | CLI binary | User-facing command-line interface |
| `crates/openshell-conformance/` | CLI conformance library | Reusable driver-agnostic scenarios and command runner |
| `crates/openshell-server/` | Gateway server | Control-plane API, sandbox lifecycle, auth boundary |
| `crates/openshell-sandbox/` | Sandbox runtime | Capability-free workload launcher, process identity, and seccomp-mediated I/O |
| `crates/openshell-supervisor/` | Supervisor runtime | Gateway session, policy evaluation, credentials, and upstream networking |
Expand Down
8 changes: 8 additions & 0 deletions CI.md
Original file line number Diff line number Diff line change
Expand Up @@ -512,6 +512,14 @@ merge.
Do not add the informational Actionlint, Zizmor, Dependency Review, or CodeQL
jobs to the required status list while they remain in observation mode.

## Conformance source checks

Branch Rust checks format and lint the separate
`tests/suites/conformance` workspace. The Rust test jobs run the
`openshell-conformance` support package with the CI nextest profile, without
a gateway. Gateway-backed CLI tests retain their driver E2E and installed-artifact
integration lanes; source unit-test jobs do not execute those entry points.

## Nix download recovery

Jobs that enter the development shell enable `prepare-shell: "true"` on
Expand Down
11 changes: 0 additions & 11 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

5 changes: 5 additions & 0 deletions TESTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -210,6 +210,11 @@ When more than one test needs this behavior, put the transport in the shared
Rust e2e harness and require callers to use it instead of duplicating DNS,
HTTP `Host`, TLS SNI, and mTLS handling.

The [conformance suite guide](tests/suites/conformance/README.md) describes its
layout, authoring, and execution. Shared runner code lives under
`tests/suites/conformance/support`, alongside the CLI entry points. Run
`mise run test:conformance-support` to validate the harness without a gateway.

Suites:

- Common suite (`--features e2e`) - driver-neutral CLI behavior, sandbox lifecycle, sync, port forwarding, policy, and provider tests.
Expand Down
4 changes: 4 additions & 0 deletions tasks/rust.toml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ description = "Check all Rust crates for errors"
depends = ["rust:lockfiles:check"]
run = [
"cargo check --workspace",
"cargo check --locked --manifest-path tests/suites/conformance/Cargo.toml --workspace --all-targets",
"cargo check -p openshell-sandbox --all-targets --features perf-harness",
]
run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/windows-msvc.ps1 check native"
Expand All @@ -28,6 +29,7 @@ description = "Lint Rust code with Clippy (deny warnings)"
depends = ["rust:lockfiles:check"]
run = [
"cargo clippy --workspace --all-targets -- -D warnings",
"cargo clippy --locked --manifest-path tests/suites/conformance/Cargo.toml --workspace --all-targets -- -D warnings",
"cargo clippy -p openshell-sandbox --all-targets --features perf-harness -- -D warnings",
"cargo clippy --manifest-path e2e/rust/Cargo.toml --all-targets -- -D warnings",
"cargo clippy --manifest-path examples/governance-interceptor/Cargo.toml --all-targets -- -D warnings",
Expand All @@ -40,6 +42,7 @@ hide = true
description = "Format Rust code"
run = [
"cargo fmt --all",
"cargo fmt --manifest-path tests/suites/conformance/Cargo.toml --all",
"cargo fmt --manifest-path e2e/rust/Cargo.toml --all",
"cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all",
"cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all",
Expand All @@ -50,6 +53,7 @@ hide = true
description = "Check Rust formatting"
run = [
"cargo fmt --all -- --check",
"cargo fmt --manifest-path tests/suites/conformance/Cargo.toml --all -- --check",
"cargo fmt --manifest-path e2e/rust/Cargo.toml --all -- --check",
"cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all -- --check",
"cargo fmt --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml --all -- --check",
Expand Down
5 changes: 5 additions & 0 deletions tasks/test.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
description = "Run all tests (Rust + Python + TypeScript SDK)"
depends = [
"test:rust",
"test:conformance-support",
"test:python",
"sdk:ts:test",
"test:sbom",
Expand Down Expand Up @@ -274,3 +275,7 @@ description = "Test generated local gateway TOML without starting a runtime"
run = "bash tasks/scripts/test-gateway-config.sh"
run_windows = "echo Skipping test:gateway-config: Unix gateway scripts do not apply on Windows."
hide = true

["test:conformance-support"]
description = "Run conformance harness unit tests without a gateway"
run = "cargo test --locked --manifest-path tests/suites/conformance/Cargo.toml --package openshell-conformance"
65 changes: 0 additions & 65 deletions tests/suites/conformance/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

31 changes: 30 additions & 1 deletion tests/suites/conformance/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,33 @@

[workspace]
resolver = "2"
members = ["cli"]
members = ["cli", "support"]

[workspace.lints.rust]
unsafe_code = "warn"
rust_2018_idioms = { level = "warn", priority = -1 }
trivial_casts = "warn"
trivial_numeric_casts = "warn"
unused_lifetimes = "warn"
unused_qualifications = "warn"

[workspace.lints.clippy]
all = { level = "warn", priority = -1 }
pedantic = { level = "warn", priority = -1 }
nursery = { level = "warn", priority = -1 }

# Allow certain pedantic lints that are too noisy
module_name_repetitions = "allow"
must_use_candidate = "allow"
missing_errors_doc = "allow"
missing_panics_doc = "allow"

# Allow noisy nursery lints
significant_drop_tightening = "allow" # Often gives incorrect suggestions
missing_const_for_fn = "allow" # Too noisy for async code patterns

# Allow noisy pedantic lints
too_many_lines = "allow" # Function length limits are subjective
needless_pass_by_value = "allow" # Common pattern in async handlers
ref_option = "allow" # Common pattern for optional references
missing_fields_in_debug = "allow" # Manual Debug impls often intentionally omit fields
86 changes: 86 additions & 0 deletions tests/suites/conformance/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# OpenShell conformance suite

This workspace contains public-behavior scenarios and Cargo test entry points
that run against an already configured gateway. The CLI is the current client
interface; lifecycle, file transfer, and policy behavior define the test groups.

## Layout

- `cli/tests/`: gateway-backed Cargo tests grouped by behavior.
- `support/src/scenarios/`: scenario implementations and their assertions.
- `support/src/lib.rs`: CLI runner, bounded polling, diagnostics, resource cleanup,
and harness unit tests.
- `support/src/executor.rs`: process execution and the injected executor interface.

The `openshell-conformance` support crate belongs to this test workspace. Driver
and feature suites may reuse its runner without becoming general conformance.
Product crates must not depend on it.

## Run without a gateway

Run harness unit tests:

```shell
mise run test:conformance-support
```

Compile the gateway-backed entry points without executing them:

```shell
cargo test --locked --manifest-path tests/suites/conformance/Cargo.toml \
--package openshell-test-conformance-cli --no-run
```

Repository formatting, Clippy, and unit-test checks include this workspace.
Select the support package for unit tests; running every workspace test also
executes the gateway-backed cases.

## Run against a prepared gateway

Install, register, and select the gateway before starting the suite. Supply the
matching candidate CLI explicitly:

```shell
OPENSHELL_BIN=/absolute/path/to/openshell \
cargo test --locked --manifest-path tests/suites/conformance/Cargo.toml \
--package openshell-test-conformance-cli --no-fail-fast -- \
--test-threads=1 --nocapture
```

Use the same OpenShell revision for the suite, CLI, and gateway. The suite does
not install OpenShell, start a gateway, or select a compute driver. The target
must supply the workload image and tools used by the selected scenarios. Missing
CLI or gateway prerequisites fail the run rather than silently passing.

Run one group with `--test file_transfer`, `--test lifecycle`,
`--test policy_advisor`, or `--test smoke`, before the `--` separator. A group or
individual-test filter exercises only part of the suite.

The tmachine conformance testsuite runs these same entry points from the
nextest archive built by `build-openshell-conformance-test-archive`. See
[CI.md](../../../CI.md) for the implemented integration lanes and
[the test-guest guide](../../../nix/test-guest/README.md) for preparation
and artifact execution. Archive construction selects the CLI test package;
harness unit tests run separately in source checks.

## Add or change a test

Keep the expected public behavior, preconditions, resource mutations, and
assertions beside the scenario implementation. Add its Cargo entry point in the
behavior group it exercises. Preserve existing test names when moving code so
Cargo and nextest filters keep working.

Use structured CLI output and sandbox operations for behavioral assertions.
Keep gateway provisioning, runtime inspection, and host-specific setup in their
own harness or driver suite. Use unique resource names, register resources before
creation, and call `OpenShellRunner::finish` even when the scenario fails so it
attempts cleanup. Cleanup failures must remain visible. Current policy-advisor
cases set the proposal setting on their own sandbox; the suite runs serially.

[RFC 0016](https://github.com/NVIDIA/OpenShell/pull/3460) proposes the wider
strategy. This consolidation does not establish conformance qualification:
effective capability discovery, distinct unsupported/skipped/infrastructure
outcomes, and attributed completeness reporting remain follow-ups in
[#3954](https://github.com/NVIDIA/OpenShell/issues/3954). Cargo currently reports
ordinary test success or failure. Existing scenario coverage is preserved here;
this move does not provide new cross-driver admission evidence.
2 changes: 1 addition & 1 deletion tests/suites/conformance/cli/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,5 +10,5 @@ license = "Apache-2.0"
repository = "https://github.com/NVIDIA/OpenShell"

[dependencies]
openshell-conformance = { path = "../../../../crates/openshell-conformance" }
openshell-conformance = { path = "../support" }
tokio = { version = "1.43", features = ["macros", "rt"] }
4 changes: 2 additions & 2 deletions tests/suites/conformance/cli/tests/file_transfer.rs
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ async fn path_safety() {
}

async fn run(scenario: Scenario) {
let mut runner = OpenShellRunner::from_env(scenario.name)
.expect("candidate openshell CLI is available");
let mut runner =
OpenShellRunner::from_env(scenario.name).expect("candidate openshell CLI is available");
let result = async {
runner.check_gateway_status().await?;
scenario.run(&mut runner).await
Expand Down
Loading
Loading