use super::*;
#[test]
fn canonical_consts_match_the_convention() {
for svc in SERVICES {
if svc.sub_unit.is_some() {
continue;
}
assert_eq!(
svc.label,
canonical_label(svc.member),
"{}'s label restates something the `com.trusty.<stem>` convention \
does not produce — either the convention changed (update \
`canonical_label`) or the literal drifted (#4919)",
svc.member
);
}
}
#[test]
fn sub_unit_labels_extend_their_base() {
for svc in SERVICES {
let Some(sub) = svc.sub_unit else { continue };
let base = canonical_label(svc.member);
assert_eq!(
svc.label,
sub_label(&base, sub),
"{}'s `{sub}` sub-unit must be named off its member's base label",
svc.member
);
}
}
#[test]
fn legacy_labels_are_never_canonical() {
for svc in SERVICES {
for legacy in svc.legacy {
assert!(
service_for_label(legacy).is_none(),
"{legacy} is listed as a legacy alias of {} but is also some \
service's canonical label — evicting it would take down a \
live unit",
svc.label
);
}
}
}
#[test]
fn every_legacy_label_resolves_to_one_service() {
let mut seen: Vec<&str> = Vec::new();
for svc in SERVICES {
for label in std::iter::once(&svc.label).chain(svc.legacy.iter()) {
assert!(
!seen.contains(label),
"{label} is claimed by more than one service"
);
seen.push(label);
}
}
}
#[test]
fn pre_fix_labels_are_recorded_as_legacy() {
assert!(
legacy_labels_for(SEARCH).contains(&"com.trusty.trusty-search"),
"the label `trusty-search service install` wrote before #4919 must be \
evicted on upgrade"
);
assert!(
legacy_labels_for(SEARCH).contains(&"com.bobmatnyc.trusty-search"),
"the trusty-search Makefile's `com.bobmatnyc.*` family must be evicted \
on upgrade"
);
assert!(legacy_labels_for(CONSOLE).contains(&"com.trusty.trusty-console"));
assert!(legacy_labels_for(REVIEW).contains(&"com.trusty.trusty-review"));
assert!(legacy_labels_for(SEARCH_LOGROTATE).contains(&"com.trusty.trusty-search.logrotate"));
}
const SCAN_EXEMPT_PATHS: &[&str] = &["trusty-installer/src/commands/macos_signing"];
#[test]
fn no_stray_launchd_label_literals_in_workspace_sources() {
let root = workspace_root();
let mut files = Vec::new();
collect_scannable_files(&root, &mut files);
let rs = files.iter().filter(|p| kind_of(p) == Kind::Rust).count();
let other = files.len() - rs;
assert!(
rs > 2000 && other > 20,
"the scan found {rs} Rust and {other} build/deploy file(s) under {} — a \
broken walk would pass this test vacuously",
root.display()
);
let mut strays: Vec<String> = Vec::new();
for path in &files {
let rel = path
.strip_prefix(&root)
.unwrap_or(path)
.display()
.to_string();
if SCAN_EXEMPT_PATHS.iter().any(|ex| rel.contains(ex)) {
continue;
}
if rel.contains("trusty-common/src/launchd_labels") {
continue;
}
let kind = kind_of(path);
let Ok(body) = std::fs::read_to_string(path) else {
continue;
};
for line in production_lines(&body, kind) {
let evicting =
kind != Kind::Rust && (line.contains("bootout") || line.contains("unload"));
for label in extract_labels(&codesign_stripped(&line)) {
if evicting && legacy_labels_for_any().contains(&label.as_str()) {
continue;
}
if kind != Kind::Rust && is_canonical_label(&label) {
continue;
}
strays.push(format!("{rel}: {label}"));
}
}
}
assert!(
strays.is_empty(),
"launchd label literals not owned by `trusty_common::launchd_labels` \
(#4919 — derive them from the registry instead of restating them):\n {}",
strays.join("\n ")
);
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
enum Kind {
Rust,
Hash,
Xml,
}
fn production_lines(body: &str, kind: Kind) -> Vec<String> {
let mut out = Vec::new();
let mut lines = body.lines().peekable();
let mut in_block_comment = false;
while let Some(line) = lines.next() {
if kind == Kind::Rust && !in_block_comment && is_test_cfg_attribute(line) {
skip_test_item(line, &mut lines);
continue;
}
let code = strip_comment(line, kind, &mut in_block_comment);
if !code.trim().is_empty() {
out.push(code);
}
}
out
}
fn is_test_cfg_attribute(line: &str) -> bool {
let t = line.trim_start();
if !t.starts_with("#[cfg(") {
return false;
}
let is_ident = |c: char| c.is_ascii_alphanumeric() || c == '_' || c == '-';
let mut rest = t;
while let Some(idx) = rest.find("test") {
let before = &rest[..idx];
let before_ok = before.chars().next_back().is_none_or(|c| !is_ident(c));
let after_ok = rest[idx + 4..].chars().next().is_none_or(|c| !is_ident(c));
if before_ok && after_ok && !under_negation_or_disjunction(before) {
return true;
}
rest = &rest[idx + 4..];
}
false
}
fn under_negation_or_disjunction(prefix: &str) -> bool {
let bytes = prefix.as_bytes();
let mut depth: i32 = 0;
let mut open_combinators: Vec<i32> = Vec::new();
let mut i = 0;
while i < bytes.len() {
if bytes[i] == b'(' {
let head = prefix[..i].trim_end();
if head.ends_with("not") || head.ends_with("any") {
open_combinators.push(depth);
}
depth += 1;
} else if bytes[i] == b')' {
depth -= 1;
open_combinators.retain(|d| *d < depth);
}
i += 1;
}
!open_combinators.is_empty()
}
fn skip_test_item<'a>(
attr_line: &str,
lines: &mut std::iter::Peekable<impl Iterator<Item = &'a str>>,
) {
let tail = attr_line
.rsplit_once("])")
.map_or_else(|| attr_line.rsplit_once(']').map(|(_, t)| t), |_| None)
.unwrap_or("")
.trim();
if !tail.is_empty() {
let opens = tail.matches('{').count();
let closes = tail.matches('}').count();
if tail.ends_with(';') || (opens > 0 && opens == closes) {
return;
}
if opens > closes {
consume_until_balanced(lines, i32::try_from(opens - closes).unwrap_or(1));
return;
}
}
let mut depth: i32 = 0;
let mut opened = false;
for line in lines.by_ref() {
depth += i32::try_from(line.matches('{').count()).unwrap_or(0);
depth -= i32::try_from(line.matches('}').count()).unwrap_or(0);
if line.contains('{') {
opened = true;
}
if opened {
if depth <= 0 {
return;
}
} else if line.trim_end().ends_with(';') {
return;
}
}
}
fn consume_until_balanced<'a>(
lines: &mut std::iter::Peekable<impl Iterator<Item = &'a str>>,
mut depth: i32,
) {
for line in lines.by_ref() {
depth += i32::try_from(line.matches('{').count()).unwrap_or(0);
depth -= i32::try_from(line.matches('}').count()).unwrap_or(0);
if depth <= 0 {
return;
}
}
}
fn strip_comment(line: &str, kind: Kind, in_block_comment: &mut bool) -> String {
let t = line.trim_start();
match kind {
Kind::Rust => {
if *in_block_comment {
if let Some((_, after)) = line.split_once("*/") {
*in_block_comment = false;
return after.to_string();
}
return String::new();
}
if t.starts_with("//") {
return String::new();
}
if let Some((before, rest)) = line.split_once("/*") {
if let Some((_, after)) = rest.split_once("*/") {
return format!("{before}{after}");
}
*in_block_comment = true;
return before.to_string();
}
line.to_string()
}
Kind::Hash => line.split('#').next().unwrap_or("").to_string(),
Kind::Xml => {
if t.starts_with("<!--") {
String::new()
} else {
line.to_string()
}
}
}
}
fn kind_of(path: &std::path::Path) -> Kind {
let name = path.file_name().unwrap_or_default().to_string_lossy();
if name.ends_with(".rs") {
Kind::Rust
} else if name.ends_with(".plist") {
Kind::Xml
} else {
Kind::Hash
}
}
fn workspace_root() -> std::path::PathBuf {
std::path::Path::new(env!("CARGO_MANIFEST_DIR"))
.ancestors()
.nth(2)
.expect("crates/trusty-common has a workspace root two levels up")
.to_path_buf()
}
fn collect_scannable_files(dir: &std::path::Path, out: &mut Vec<std::path::PathBuf>) {
let Ok(entries) = std::fs::read_dir(dir) else {
return;
};
for entry in entries.flatten() {
let path = entry.path();
let name = entry.file_name();
let name = name.to_string_lossy();
if path.is_dir() {
if matches!(
name.as_ref(),
"target"
| "tests"
| "benches"
| "node_modules"
| "docs"
| ".git"
| ".claude"
| "test-data"
| "testdata"
| "vmtest-harness"
) {
continue;
}
collect_scannable_files(&path, out);
continue;
}
let is_rust = name.ends_with(".rs")
&& !name.ends_with("_tests.rs")
&& !name.ends_with("_test.rs")
&& name != "tests.rs";
let is_build_or_deploy = name == "Makefile"
|| name.ends_with(".sh")
|| name.ends_with(".plist")
|| name.ends_with(".yml");
if is_rust || is_build_or_deploy {
out.push(path);
}
}
}
#[test]
fn production_lines_skips_past_a_test_module_declaration() {
let body = "pub mod a;\n#[cfg(test)]\nmod tests;\npub mod b;\nlet x = \"deep\";\n";
let kept = production_lines(body, Kind::Rust);
assert!(
kept.iter().any(|l| l.contains("deep")),
"code below a `mod tests;` declaration must still be scanned, kept: {kept:?}"
);
assert!(!kept.iter().any(|l| l.contains("mod tests;")));
}
#[test]
fn production_lines_strips_an_inline_test_block() {
let body = "fn real() {}\n#[cfg(all(test, target_os = \"macos\"))]\nmod tests {\n let f = \"com.trusty.trusty-fixture\";\n}\nfn after() {}\n";
let kept = production_lines(body, Kind::Rust);
assert!(!kept.iter().any(|l| l.contains("trusty-fixture")));
assert!(
kept.iter().any(|l| l.contains("fn after")),
"code after the test block must survive, kept: {kept:?}"
);
}
#[test]
fn production_lines_keeps_a_feature_cfg_that_merely_contains_test() {
assert!(!is_test_cfg_attribute(
"#[cfg(feature = \"embedder-test-support\")]"
));
assert!(is_test_cfg_attribute("#[cfg(test)]"));
assert!(is_test_cfg_attribute(
"#[cfg(all(test, target_os = \"macos\"))]"
));
let body = "#[cfg(feature = \"embedder-test-support\")]\npub fn kept() {}\n";
let kept = production_lines(body, Kind::Rust);
assert!(
kept.iter().any(|l| l.contains("pub fn kept")),
"a feature cfg must not swallow the item it guards, kept: {kept:?}"
);
}
#[test]
fn production_lines_strips_hash_comments() {
let body = "# was com.trusty.trusty-search\nPLIST := com.trusty.search.plist\n";
let kept = production_lines(body, Kind::Hash);
assert_eq!(kept.len(), 1);
assert!(kept[0].contains("com.trusty.search"));
}
#[test]
fn is_test_cfg_attribute_respects_polarity() {
assert!(is_test_cfg_attribute("#[cfg(test)]"));
assert!(is_test_cfg_attribute(
"#[cfg(all(test, target_os = \"macos\"))]"
));
assert!(
!is_test_cfg_attribute("#[cfg(not(test))]"),
"`not(test)` gates code present in every non-test build"
);
assert!(
!is_test_cfg_attribute(
"#[cfg(any(all(target_os = \"macos\", target_arch = \"aarch64\"), test))]"
),
"`any(…, test)` gates code present outside test builds too"
);
assert!(!is_test_cfg_attribute("#[cfg(all(not(test), unix))]"));
}
#[test]
fn production_lines_reads_bodies_gated_on_not_test() {
let body =
"#[cfg(not(test))]\nfn cache_base_dir() {\n let x = \"com.trusty.trusty-search\";\n}\n";
let kept = production_lines(body, Kind::Rust);
assert!(
kept.iter().any(|l| l.contains("com.trusty.trusty-search")),
"a `not(test)` body is production and must be scanned, kept: {kept:?}"
);
}
#[test]
fn strip_comment_keeps_a_deref_assignment() {
let body = "*target = \"com.trusty.trusty-search\".to_string();\n";
let kept = production_lines(body, Kind::Rust);
assert!(
kept.iter().any(|l| l.contains("com.trusty.trusty-search")),
"a deref assignment is code, not a comment continuation, kept: {kept:?}"
);
}
#[test]
fn strip_comment_tracks_block_comment_state() {
let body = "/*\n * com.trusty.trusty-search was the old label\n */\nlet a = 1;\n";
let kept = production_lines(body, Kind::Rust);
assert!(
!kept.iter().any(|l| l.contains("com.trusty.trusty-search")),
"a block-comment body must stay unscanned, kept: {kept:?}"
);
assert!(kept.iter().any(|l| l.contains("let a = 1")));
}
#[test]
fn skip_test_item_consumes_nothing_when_the_item_is_on_the_attribute_line() {
let body = "#[cfg(test)] use std::fmt;\nlet x = \"com.trusty.trusty-search\";\n";
let kept = production_lines(body, Kind::Rust);
assert!(
kept.iter().any(|l| l.contains("com.trusty.trusty-search")),
"the line after a self-contained test item is production, kept: {kept:?}"
);
}
#[test]
fn codesign_stripped_spares_only_the_identifier_token() {
let line = "local X_IDENTIFIER=\"com.trusty.trusty-mpm\"; local f2=\"/x/com.bobmatnyc.trusty-search.plist\"";
let out = codesign_stripped(line);
assert!(
!out.contains("com.trusty.trusty-mpm"),
"the codesign identifier must be exempt, got: {out}"
);
assert!(
out.contains("com.bobmatnyc.trusty-search"),
"a launchd label on the same line must still be scanned, got: {out}"
);
let flag = codesign_stripped("codesign --identifier com.trusty.trusty-search /bin/x");
assert!(!flag.contains("com.trusty.trusty-search"), "got: {flag}");
}
fn legacy_labels_for_any() -> Vec<&'static str> {
SERVICES
.iter()
.flat_map(|s| s.legacy.iter().copied())
.collect()
}
#[test]
fn eviction_lines_may_name_a_legacy_label() {
let evict = "\t-launchctl bootout gui/$$(id -u)/com.trusty.trusty-search 2>/dev/null\n";
let install = "PLIST := $(HOME)/Library/LaunchAgents/com.trusty.trusty-search.plist\n";
let kept = production_lines(evict, Kind::Hash);
assert!(
!kept.is_empty(),
"the bootout line must survive comment stripping"
);
assert!(
legacy_labels_for_any().contains(&"com.trusty.trusty-search"),
"the alias must be registered for the eviction allowance to apply"
);
let install_kept = production_lines(install, Kind::Hash);
assert!(!install_kept[0].contains("bootout"));
}
fn codesign_stripped(line: &str) -> String {
const MARKERS: &[&str] = &["--identifier", "IDENTIFIER="];
let mut out = line.to_string();
for marker in MARKERS {
while let Some(idx) = out.find(marker) {
let after = idx + marker.len();
let rest = &out[after..];
let val_start = rest
.find(|c: char| !matches!(c, ' ' | '=' | '"' | '\'' | '\t'))
.unwrap_or(rest.len());
let tail = &rest[val_start..];
let val_end = tail
.find(|c: char| !(c.is_ascii_alphanumeric() || c == '.' || c == '-' || c == '_'))
.unwrap_or(tail.len());
let abs_start = after + val_start;
let abs_end = abs_start + val_end;
out.replace_range(abs_start..abs_end, "");
out.replace_range(idx..after, &"_".repeat(marker.len()));
}
}
out
}
fn extract_labels(line: &str) -> Vec<String> {
const PREFIXES: &[&str] = &["com.trusty.", "com.bobmatnyc."];
let mut found = Vec::new();
for prefix in PREFIXES {
let mut rest = line;
while let Some(idx) = rest.find(prefix) {
let tail = &rest[idx..];
let end = tail
.find(|c: char| !(c.is_ascii_alphanumeric() || c == '.' || c == '-' || c == '_'))
.unwrap_or(tail.len());
let token = tail[..end]
.trim_end_matches('.')
.trim_end_matches(".plist")
.trim_end_matches('.');
if token.len() > prefix.len() {
found.push(token.to_string());
}
rest = &rest[idx + prefix.len()..];
}
}
found
}