test: derive the no-user-specific-data needles from the running machine - #155
Merged
Merged
Conversation
The guard stored one developer's account names and mount path as string fragments, which is itself the user-specific data invariant 5 forbids, and it read src/ only. Derive the needles at test time from $USER, $HOME and the checkout path, skipping ones too short to identify anyone and none on CI, and scan every git-tracked file except Cargo.toml's authors line. Closes #131
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
src/testing.rs: the invariant-5 guard no longer stores anyone's identity. Its needles were one developer's account names and mount path held as string fragments, which is itself user-specific data in the repository, and it scannedsrc/only.user_specific_needles(on_ci, account, home, checkout)derives the needles from the running machine's$USER(whole word),$HOMEand the checkout path (CARGO_MANIFEST_DIR) (anywhere), lowercased, a trailing/dropped. An account name under 4 characters and a path with fewer than 2 named components (/,/root) are skipped as too short to identify anyone. On CI (CIset and non-empty) there are none: a hosted runner's account identifies nobody, and its name (runner) occurs as a whole word inci.yml,release-plz.yml,CHANGELOG.mdand several sources, so the scan would fail on ordinary prose.user_specific_offencestakes the needles as an argument, so theRule::AnywhereandRule::WholeWordtests are driven by a synthetic machine (quillon,/home/quillon,/srv/build/quillon/bx) rather than real values.no_user_specific_literal_survives_under_srcbecomesno_user_specific_literal_survives_in_a_tracked_file: it reads every filegit ls-files -zlists (this one included, since it no longer holds the needles), skipping only theauthorsline ofCargo.toml.contains_tokennow requires a word boundary on both sides of an account name, not only before it.Cargo.tomlauthorsexemption (and that the exemption is that line only).src/env_guard.rs: a doc comment's reference to the renamed test is updated.Validation
mise run format— no change after the fixermise run lint(cargo clippy --all-targets -- -D warnings) — passcargo test— pass (2040 lib tests, 14 ignored; all integration suites pass)CI=1 cargo test --lib testing::— 22 passedUSER=justin cargo test --lib tracked_file— pass (theCargo.tomlauthorsline is exempt)USER=runner cargo test --lib tracked_file(not CI) — fails as intended, naming.github/workflows/ci.yml,release-plz.yml,CHANGELOG.mdand more; this is the evidence for the CI decisionmise run line-check— no file newly over 3743 lineshkpre-push gate, includingmise run coverage, run bygit push— passCoverage gaps
hk's pre-push gate). The matching rules themselves run on CI through the synthetic tests.mark) will match prose as a whole word. Nothing in the repository can tell that apart from the name, and no test covers it.tracked_filesneedsgitand a work tree. Run outside one, the test fails rather than scanning nothing.Risks and rollout
Decisions taken
Taken: the environment of the machine running the test (accepted unrebutted)
Rejected: a fixed list in the repository - that list is the violation
Reverses: restore the fixed list
Taken: none when
CIis set and non-emptyRejected: deriving them from the runner -
USER=runnermakes the scan fail onci.yml,release-plz.yml,CHANGELOG.mdand sources that use "runner" as an ordinary word, and the runner's identity is nobody'sReverses: drop the
on_ciearly return inuser_specific_needlesTaken: no alphanumeric on either side
Rejected: leading boundary only - the name now comes from whatever machine runs the test, and a short name is the start of many words (
mark/markdown,will/willing)Reverses: drop the trailing-character check in
contains_tokenTaken: an account name under 4 characters, and a path with fewer than 2 named components
Rejected: no threshold - a 3-letter name, or
/root, matches all over ordinary text and identifies no personReverses: change
SHORTEST_ACCOUNT_NAME/FEWEST_PATH_COMPONENTSTaken: every file
git ls-fileslists, whatever is in the working tree outside them is notRejected: walking the directory - untracked files like coverage output and local tool state would be scanned
Reverses: replace
tracked_fileswith a directory walkCloses #131