1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
//! Scaffolding the suite shares, and nothing production reads. Compiled only
//! under `cfg(test)`.
//!
//! Two things live here that live nowhere else in the crate, and both are
//! deliberate:
//!
//! - **The certificate mint** ([`mint`]). The seat mints nothing (yog's
//! `docs/REMOTE.md` §1.4) — the operator issues a pair on the box that holds
//! the CA and carries it here by hand — so the suite has to perform that act
//! on the operator's behalf before it can open a channel at all. It is
//! `cfg(test)`, it shells to the tool an operator would use, and **no
//! certificate is ever committed**: a fixture key in a tree is a private key
//! in a repository, which is the exact class `make leak-scan` refuses.
//! - **The stand-in engine** ([`engine`]), which LISTENS — the one thing a seat
//! must never do. That is precisely why it is here and not in the crate
//! proper.
use ;
use ;
use OnceLock;
use ;
/// The suite's clock: an offset the test advances by hand.
pub
/// The one walk over the wire conformance corpus, shared by both replays.
pub
/// The far end of the wire, so a channel can be tested against something that
/// speaks the protocol.
pub
/// The operator's out-of-channel act, performed by the suite.
pub
/// The far end of a PUNCHED wire: an engine that serves a held line, or
/// that calls back what the seat wrote to its inbox.
pub
/// The window's fixtures, and the two ways a test looks at one.
pub
/// A data root with an engine behind one of its channels.
pub
/// How many scratch directories this process has minted, so two tests running
/// at once never name one directory.
static NEXT: AtomicUsize = new;
/// A throwaway directory, removed when it drops.
///
/// Hand-rolled rather than a crate, because the dependency set is closed
/// (`Cargo.toml`'s approval comment): a scratch directory is a `create_dir_all`
/// and a `remove_dir_all`, and a test-only crate is still a crate in the
/// lockfile, the licence audit and the supply chain.
pub
/// A loopback TCP address nothing answers, for as long as the process runs: a
/// socket bound and never listening, so a SYN to it is reset, and held so the
/// kernel never hands its port to anyone else.
///
/// Binding a port and dropping it is not this. The number goes back to the
/// kernel's pool, and the next `bind(0)` — another test's listener or punch
/// port, in this process or a concurrent one — may be handed it, so the "dead"
/// address answers as somebody else: a punch aimed at it once handshook with a
/// stranger's punch (bl-73f2). No reuse flag is set, so no other socket can
/// share it.
pub