-
Notifications
You must be signed in to change notification settings - Fork 8
build: import the stack-* crates, node bindings and Go module #1001
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
8d870b1
3d7a5b3
07db41f
57a1f18
e286459
473bd7a
882ecec
c02729a
62d8dfc
6afac7e
085b7f7
37d8e47
3cab1ea
ee92fad
8a38d53
29b6d12
a0f23d8
c278732
d0c438b
33419fa
8950a74
f4fec2a
975d9fa
6a981c2
586d177
27ad2cf
d9f4c9f
67105b0
d6503e5
76a0605
946bbd8
166b113
4461bb3
aa211b9
23cfcb6
435c5a0
e3765a5
8970413
7362511
b79f268
93990f4
1c71647
7ea876e
428d83f
f90d677
f0883b3
5f68d3b
b6b46e2
c6a3c54
6c0f8a1
a7e960b
e68a08a
93c43b6
95708af
e2e3bff
427fe41
f8c84d4
3e4f64e
e8a42ce
c9e7d21
ceca2f0
3c30a60
bbcc1b2
e743eb5
9ee94d8
0f4bbfd
ac4f958
ef117d3
b0e2668
23c2e53
53accce
d293be8
f8da8e2
a118060
3438596
fd0b1bc
07fb2a2
8675635
bec2922
6edfb13
61d9f44
968a663
aabc8e0
1b64c77
fe17d68
76a4e70
0692efa
52565ab
38d8b05
961ee65
ea3da1e
25af1b9
e6f0f14
360a1d7
f5a772e
e748c5f
1cb4643
7db88f6
72d347d
e9f3d7e
0505537
ebd4912
71db1b2
d44bdbb
df73957
9518118
b04e794
3e1b402
28b420d
3d34c1f
bc7c7b3
7190306
3ff867c
4845078
d388761
70c64a8
85254e1
0e84f10
08d432e
3b21c74
fd62062
f268ed5
4eca152
ec7a253
1925824
1f61ce2
6089fb5
534f41e
7af383f
cb0afd8
ab2868a
c3e35bd
7834a78
381fb4f
d59ad8c
dbd4bb9
7d7ad6c
6eed5e9
7e8ff98
e732b04
225519f
d5eea6d
53d5801
c578f81
856f34b
ced50d1
1dafe3c
a3f131a
505eb4e
ce9f342
f44f027
07fae27
4e198ec
d1d594f
ba16144
64345b4
b31db96
5218276
dd640d2
32d7594
9629eaa
21ab9c6
1b5f76e
6894ab5
3d0d46f
db40c9c
329abf4
54eb214
09e4a29
cc9a7bd
1e6ff91
921af24
5f1b0ef
587af1d
358c739
7f9fd38
e6b40eb
a850bc0
1b71f9e
66fd8d9
ea56421
91ce93f
a9e7d7b
501928f
d9e2492
d2098a3
82a254c
6ad8407
fb14197
7845690
6d7234d
9fdd770
a9a5e48
00e1d6f
85dc6ff
b5a39b3
dcea252
2584100
73c94f1
b13be20
23a3993
bb149b3
db88f12
7193e61
5cecdcb
de6ad64
b836591
66654af
250cb28
e8ed7f4
e753829
16c6121
ad774a0
7e6ee60
a695c72
6dce6e2
2501d4e
08df071
ff95b40
ffba33a
36964cb
2f7728f
4fcd788
99b9e4a
4cb1e1b
e67d13f
f4ca03b
1afeb31
f799a1e
c0efd52
9aff82f
118e1d1
96c0079
82a85b4
d0cea7c
359a6f1
6bb5775
fa05f24
d94d6a7
2371f73
8c86f4b
542fa51
1c52c8f
f7b0031
8e8dd7a
0dc76af
5147dd0
a981590
d3524b8
1ad1055
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,23 @@ | ||
| # Configuration for `cargo crap` — the CRAP (Change Risk Anti-Patterns) metric. | ||
| # | ||
| # CRAP rewards complex code that is well tested and penalises complex code that | ||
| # is not: | ||
| # | ||
| # CRAP = CC^2 * (1 - coverage)^3 + CC (CC = cyclomatic complexity) | ||
| # | ||
| # A simple or fully covered function scores roughly its complexity; a complex, | ||
| # untested one scores into the hundreds. It surfaces exactly the kind of risky, | ||
| # under-tested logic where a subtle mistake can hide (see CIP-3233 / #2036). | ||
| # | ||
| # Run it via `mise run crap:stack-auth` (generates coverage first, then scores). | ||
| # Config discovery walks up from the working directory, so this single root file | ||
| # applies anywhere in the workspace. | ||
|
|
||
| # CRAP score above which a function is flagged for refactoring or more tests. | ||
| # 30 is the long-standing Crap4J default: a CC-10 function needs ~42% coverage, | ||
| # a CC-15 function ~59%, to fall below it. | ||
| threshold = 30 | ||
|
|
||
| # Functions with complexity but no coverage data are scored as 0% covered | ||
| # (worst case) rather than silently skipped — uninstrumented code is risk too. | ||
| missing = "pessimistic" |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| # Wasm target needs the `wasm_js` getrandom backend (used by deps that pull | ||
| # `getrandom >= 0.3`, e.g. `rand 0.9+` via `vitaminc-random`). Without this | ||
| # rustflag, those crates fail to compile on wasm32-unknown-unknown — the | ||
| # stack-auth-wasm build (`languages/typescript/packages/stack-auth-wasm`). | ||
| # See: https://docs.rs/getrandom/latest/getrandom/#opt-in-backends | ||
| [target.wasm32-unknown-unknown] | ||
| rustflags = ['--cfg', 'getrandom_backend="wasm_js"'] |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,81 @@ | ||
| # Configuration for cargo-mutants — mutation testing for the stack crates. | ||
| # | ||
| # Mutation testing rewrites small pieces of logic (flip a `<` to `<=`, replace | ||
| # a body with `Default::default()`, drop an `&&` arm) and reruns the tests: a | ||
| # mutant that survives is a line the suite does not actually pin down. CRAP | ||
| # (`crap:*`) says which complex code is uncovered; this says which covered | ||
| # code is not asserted on — in a crypto crate, the comparisons, length checks | ||
| # and context bindings a test can execute without ever checking. | ||
| # | ||
| # CI runs this `--in-diff` as a per-PR gate (.github/workflows/mutants.yml): | ||
| # only the lines a PR changes are mutated, so the gate trips when a PR adds | ||
| # logic its tests do not exercise. A full per-crate sweep is | ||
| # `mise run mutants:<crate>` (stack-auth ~15 min, stack-encrypt ~60 min on a | ||
| # laptop with four jobs); `mise run mutants` runs every crate that has one. | ||
| # Both read the settings below, so they stay in sync. | ||
|
|
||
| # Build and test with every feature on, so feature-gated code (stack-encrypt's | ||
| # `dynamic` module, the `http` transports) is compiled and exercised. Without | ||
| # this a mutant there would "survive" only because the feature was off. | ||
| additional_cargo_args = ["--all-features"] | ||
|
|
||
| # nextest, as everywhere else in the suite. The filterset drops two things | ||
| # from the per-mutant test command that are slow and pin no mutant: | ||
| # stack-encrypt's trybuild UI suite (`binary(ui)`: it compiles the derive's | ||
| # compile-fail cases in a scratch project, ~60s, and exercises no mutable | ||
| # line) and stack-auth's wall-clock stress tests (real servers, real sleeps, | ||
| # flaky under a slowed build). A filter naming something a package does not | ||
| # have matches nothing, so one filter serves every package. | ||
| test_tool = "nextest" | ||
| additional_cargo_test_args = ["-E", "not binary(ui) & not test(stress_tests)"] | ||
|
|
||
| # Skip the derive crate: its logic runs inside `#[proc_macro_derive]` entry | ||
| # points at compile time, not in the instrumented test binary, so every | ||
| # mutant there survives spuriously. Its behaviour is pinned by stack-encrypt's | ||
| # `tests/derive.rs` and the trybuild UI suite instead. | ||
| exclude_globs = ["packages/stack-encrypt-derive/**"] | ||
|
|
||
| # Mutants no test binary can kill, by name. Every other survivor is a test to | ||
| # write, not a line to add here. Two kinds qualify: | ||
| # | ||
| # - Unreachable: code compiled out of the native `--all-features` test build | ||
| # (wasm32-only impls, the no-`http` fallback, the non-test reqwest client). | ||
| # A mutant there builds and "survives" because nothing it touches is run. | ||
| # - Equivalent: the replacement is the value the code already returns | ||
| # (`Some(())` for a `()` credential, `Map::new()` for `Default::default()`, | ||
| # a builder's `new()` for its `Default`), so no test can tell them apart. | ||
| # | ||
| # The regexes match the name `--list` prints, `path:line:col: replace …`. | ||
| # Anchor on the replacement text, so an entry cannot swallow a reachable | ||
| # sibling with the same function name. The wasm32 `TokenStoreFn`, | ||
| # `AutoStrategy::detect_inner` and `Pending::into_future` entries also anchor | ||
| # on the line because their names are identical to the native impl's. | ||
| # If those lines move, a full sweep reports them again and the line numbers | ||
| # here need moving with them. | ||
| exclude_re = [ | ||
| # stack-auth — unreachable under the native test build. | ||
| 'stack-auth/src/transport\.rs:\d+:\d+: replace <impl std::fmt::Display for NoTransport>::fmt ', | ||
| 'stack-auth/src/transport\.rs:\d+:\d+: replace <impl DynTransport for T>::send_dyn -> std::pin::Pin<Box<dyn Future<Output = Result<HttpResponse, RequestError>>\+\x27a>> ', | ||
| # Production http_client variants are cfg-disabled here; the test variant | ||
| # builds an unconfigured Client, equivalent to Client::default(). | ||
| 'stack-auth/src/transport\.rs:\d+:\d+: replace http_client -> reqwest::Client with Default::default\(\)$', | ||
| 'stack-auth/src/auto_strategy\.rs:150:9: replace AutoStrategy::detect_inner -> Result<Self, AuthError> with Ok\(Default::default\(\)\)$', | ||
| 'stack-auth/src/token_store\.rs:(258|266):9: replace <impl TokenStore for TokenStoreFn<L, S>>::(load|save)', | ||
| # stack-auth — equivalent. | ||
| 'stack-auth/src/(access_key|oidc)_refresher\.rs:\d+:\d+: replace <impl Refresher for \w+(<P>)?>::try_credential -> Option<Self::Credential> with Some\(Default::default\(\)\)$', | ||
| 'stack-auth/src/error\.rs:\d+:\d+: replace AuthErrorKind::payload -> serde_json::Map<String, serde_json::Value> with Default::default\(\)$', | ||
| # stack-encrypt — unreachable under the native test build (the wasm32 | ||
| # variant; the native one returns a `FallbackKeyProvider`). | ||
| 'stack-encrypt/src/cipher\.rs:\d+:\d+: replace client_key_provider -> EnvKeyProvider with Default::default\(\)$', | ||
| 'stack-encrypt/src/target/pending\.rs:443:9: replace <impl IntoFuture for Pending<.*>>::into_future -> Self::IntoFuture with Default::default\(\)$', | ||
| # stack-encrypt — equivalent. | ||
| 'stack-encrypt/src/cipher\.rs:\d+:\d+: replace StackCipher<FromEnv>::builder -> StackCipherBuilder with Default::default\(\)$', | ||
| 'stack-encrypt/src/sem/mod\.rs:\d+:\d+: replace <impl MatchConfig for DefaultMatch>::options -> MatchOptions with Default::default\(\)$', | ||
| # Both unit-context conversions explicitly return Self::default(). | ||
| 'stack-encrypt/src/target/context\.rs:\d+:\d+: replace <impl From<\(\)> for (DeclaredContext|ExpectedContext<T>)>::from -> Self with Default::default\(\)$', | ||
| ] | ||
|
|
||
| # Headroom over the measured baseline before a slow-but-correct mutant is | ||
| # misreported as a timeout. | ||
| timeout_multiplier = 5.0 | ||
| minimum_test_timeout = 90 |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,4 @@ | ||
| # Workflows set NEXTEST_PROFILE=ci. | ||
| [profile.ci] | ||
| # Do not cancel the test run on the first failure. | ||
| fail-fast = false |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -136,6 +136,15 @@ jobs: | |
| - name: Build the protect-ffi binding | ||
| uses: ./.github/actions/build-ffi-binding | ||
|
|
||
| # `pnpm run test` below also runs the @cipherstash/auth and | ||
| # @cipherstash/profile vitest suites, which load the napi module. Their | ||
| # `test` scripts do not build it, so cargo stays off the default `test` | ||
| # path; this step builds it, as the protect-ffi step above does for | ||
| # `index.node`. Each `build:debug` writes its typings to the committed | ||
| # `native.d.ts`, so the build leaves the tree clean. | ||
| - name: Build the auth and profile node bindings | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Non-blocking: this step compiles the root workspace with whatever Rust the runner ships, not the 1.94.1 pinned in the root Generated by Claude Code |
||
| run: pnpm --filter @cipherstash/auth --filter @cipherstash/profile run build:debug | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Not a blocker. In each |
||
|
|
||
| - name: Type tests (stack) | ||
| run: pnpm exec turbo run test:types --filter @cipherstash/stack | ||
|
|
||
|
|
@@ -285,6 +294,13 @@ jobs: | |
| - name: Lint — no references to deleted package directories | ||
| run: pnpm run lint:package-paths | ||
|
|
||
| # TEMPORARY — delete with the script in the arming PR (PR E) of the | ||
| # stack-* crates import. The seven @cipherstash/auth packages live here | ||
| # but still publish from cipherstash/cipherstash-suite, so a changeset | ||
| # naming one would bump a frozen package and block every release. | ||
| - name: Lint — no @cipherstash/auth changeset before the publishing cutover | ||
| run: pnpm run lint:auth-changeset | ||
|
|
||
| # `eql-bindings` emits EQL payloads; `@cipherstash/eql` carries the SQL | ||
| # that stores them. Both live here now and release at one lockstep | ||
| # version. A registry pin on either lets them drift apart — it compiles, | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nit: this comment predates
5147dd00.cts-commonandzerokms-protocolnow take caret requirements in the rootCargo.toml; onlyrecipherandcllw-ore(and the two Go guests) still pin with=. The ignore list itself is still right, since all four move in lockstep with the suite by hand. Same stale wording as theAGENTS.mdline already flagged above.Generated by Claude Code