release_manifest.rs

crates/veilvoice-verify/tests/release_manifest.rs

veilvoice-verify · 208 lines · read the source here · or on GitHub

Roadmap item 97. The release job's contents list, read back by the parser that will read it for real.

Why this test exists

CONTENTS.sha256 is the newest link in the chain a verifier follows:

SHA256SUMS.asc -> SHA256SUMS -> CONTENTS.sha256 -> each file on disk

Every other link has tests on both sides of it. This one had a writer that ran once a release, in a job nobody can run on a laptop, and a reader with unit tests over hand-written samples. Two halves that were never introduced to each other, and the failure mode is the worst shape a verifier has: a manifest the reader parses happily and whose paths do not line up with what is actually on disk, so every file reads as MISSING and a genuine release is refused. Or worse, paths that line up by accident on one platform.

So this builds a release the way the release job does, runs the real generator over it, and checks the real reader against the real extracted files. Nothing here is a stand-in.

Why it is allowed to skip

It needs Python, and the test job does not install one. Every runner this project uses has one anyway, so the test runs on all three in practice; on a machine without one it returns rather than failing, because "Python is not installed here" is a fact about the machine and not a defect in the release job. The generator is also run by the release workflow itself, which is where its absence would actually matter and where it cannot be absent.

WHAT THIS FILE CONTAINS

208 lines defining 6 functions (0 public), 0 types and 0 constants. Everything below is read out of the source, so it cannot disagree with the code.

WHAT CALLS WHAT

repository line 40 python line 49 room line 56 stage line 71 have line 88 what_the_release_job_writes_is_what_ the_verifier_reads line 102 helper: private to this file dashed: a call that goes back up, or across a wrapped rank The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The functions this file defines, and the calls between them. An edge means the callee's name appears, called, inside the caller's body. This is a syntactic reading, not a type-resolved one.

The same graph as Mermaid source
%%{init: {"theme":"base","themeVariables":{"background":"#1a1b26","primaryColor":"#1f2335","primaryTextColor":"#c0caf5","primaryBorderColor":"#7aa2f7","secondaryColor":"#16161e","tertiaryColor":"#16161e","lineColor":"#737aa2","textColor":"#c0caf5","mainBkg":"#1f2335","nodeBorder":"#7aa2f7","clusterBkg":"#16161e","clusterBorder":"#2f3549","fontFamily":"ui-monospace, SFMono-Regular, Consolas, monospace","fontSize":"14px"}}}%%
flowchart TD
    n_repository["repository<br/>line 40"]
    n_python["python<br/>line 49"]
    n_room["room<br/>line 56"]
    n_stage["stage<br/>line 71"]
    n_have["have<br/>line 88"]
    n_what_the_release_job_writes_is_what_the_verifier_reads["what_the_release_job_writes_is_what_<br/>the_verifier_reads<br/>line 102"]
    n_what_the_release_job_writes_is_what_the_verifier_reads --> n_have
    n_what_the_release_job_writes_is_what_the_verifier_reads --> n_python
    n_what_the_release_job_writes_is_what_the_verifier_reads --> n_repository
    n_what_the_release_job_writes_is_what_the_verifier_reads --> n_room
    n_what_the_release_job_writes_is_what_the_verifier_reads --> n_stage
    click n_repository href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/tests/release_manifest.rs#L40" "open the source"
    click n_python href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/tests/release_manifest.rs#L49" "open the source"
    click n_room href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/tests/release_manifest.rs#L56" "open the source"
    click n_stage href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/tests/release_manifest.rs#L71" "open the source"
    click n_have href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/tests/release_manifest.rs#L88" "open the source"
    click n_what_the_release_job_writes_is_what_the_verifier_reads href "https://github.com/tilas01/veilvoice/blob/main/crates/veilvoice-verify/tests/release_manifest.rs#L102" "open the source"
    classDef helper fill:#1f2335,stroke:#bb9af7,color:#c0caf5
    class n_repository,n_python,n_room,n_stage,n_have,n_what_the_release_job_writes_is_what_the_verifier_reads helper

This site loads no third-party script, so it cannot run Mermaid; the diagram above is the same nodes and edges drawn by the generator instead. GitHub renders the source below directly.

ITEMS

ItemLineDocumentation
repository fn40The repository root, from this test's own location.
python fn49A Python to run, if this machine has one.
room fn56Somewhere to build a release, removed by the caller.
stage fn71Build one release directory, the shape the release job stages.
have fn88Whether a program is on this machine at all.
what_the_release_job_writes_is_what_the_verifier_reads fn102The whole seam: stage, archive, generate, parse, extract, check.