1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
//! Test facilities for embedders, and for this crate's own assurance layers.
//!
//! Shipped rather than confined to `tests/` because an embedder's own store
//! implementation and own skills need the same treatment this crate's do, and
//! rebuilding a fault injector per project is how each one ends up testing a
//! slightly different, slightly weaker thing.
//!
//! Behind the `testkit` feature, off by default, and **no feature a release
//! enables pulls it in** — `no_shipped_feature_enables_testkit` in
//! `tests/guards/docs.rs` is what makes that a fact rather than an intention.
//!
//! The deterministic *model* is deliberately not here but in
//! [`model::fake`](crate::model::fake), behind `fake-model`, which ships: a
//! stand-in model is a driver, while everything in this module stands in for a
//! control.
// Ungated: `BlobStore` is in `core`'s own layer, every implementation of it
// ships in the default build, and the contract this checks is the one an
// erasure request lands on.
// Ungated for the reason the blob battery is: `Calendar` is a `core` seam, and
// it is the one this crate is most likely to be *replaced* at — the built-in
// calendar understands hours, days and minutes, and a real regulatory deadline
// does not.
// The case-layer battery is backend-agnostic — it names no `redb` type — so the
// gate has to be "a backend exists", not "the embedded one does". Read as `redb`
// it made the *shared-store* backend's own contract untestable without linking
// the embedded one, which is the configuration a Postgres deployment ships.
// Gated on `http`, which is where `Authenticator` lives: the seam only exists
// for a deployment serving the operator surface.
// Ungated: `PolicyEngine` is a `core` seam with no feature of its own, and the
// deployment most likely to replace it is the one that wrote its rules in Rust
// rather than taking the shipped evaluator.
pub use SharedJournal;
pub use MemoryKeyRing;
pub use ;
pub use StubSigner;
/// The deterministic provider, which lives beside the real drivers.
///
/// Named here too, because a test author looking for a double looks in
/// `testkit`. It is *not* gated on `testkit` at its definition — see
/// [`model::fake`](crate::model::fake).
pub use crate;
pub use assert_replay_was_not_backstopped;
pub use ;
pub use ;