Public source sync 06ad9c949dc7
Source commit: 06ad9c949dc7aece0883315a3b3c3133df98f794 Public tree identity: sha256:deb98e60f26cb4942e2bc1972601259d4015fd3a945eac94d60e115b5823bbdb
This commit is contained in:
parent
fd41e0ee3b
commit
a6ab33d161
8 changed files with 115 additions and 20 deletions
1
.gitignore
vendored
1
.gitignore
vendored
|
|
@ -1,4 +1,5 @@
|
||||||
/target/
|
/target/
|
||||||
|
/web/target/
|
||||||
/.clusterflux/
|
/.clusterflux/
|
||||||
**/.clusterflux/
|
**/.clusterflux/
|
||||||
/vscode-extension/node_modules/
|
/vscode-extension/node_modules/
|
||||||
|
|
|
||||||
10
Cargo.lock
generated
10
Cargo.lock
generated
|
|
@ -1726,6 +1726,16 @@ dependencies = [
|
||||||
"windows-sys 0.52.0",
|
"windows-sys 0.52.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "runtime-conformance"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"clusterflux-sdk",
|
||||||
|
"futures-executor",
|
||||||
|
"serde",
|
||||||
|
"serde_json",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "rustc-hash"
|
name = "rustc-hash"
|
||||||
version = "2.1.3"
|
version = "2.1.3"
|
||||||
|
|
|
||||||
|
|
@ -1,5 +1,6 @@
|
||||||
[workspace]
|
[workspace]
|
||||||
resolver = "2"
|
resolver = "2"
|
||||||
|
exclude = ["web"]
|
||||||
members = [
|
members = [
|
||||||
"crates/clusterflux-cli",
|
"crates/clusterflux-cli",
|
||||||
"crates/clusterflux-client",
|
"crates/clusterflux-client",
|
||||||
|
|
|
||||||
|
|
@ -97,6 +97,9 @@ cargo install --path crates/clusterflux-coordinator --bin clusterflux-coordinato
|
||||||
cargo install --path crates/clusterflux-dap --bin clusterflux-debug-dap
|
cargo install --path crates/clusterflux-dap --bin clusterflux-debug-dap
|
||||||
~~~
|
~~~
|
||||||
|
|
||||||
|
On NixOS or another system with Nix, the equivalent package is available with
|
||||||
|
`nix profile install .#clusterflux-tools`.
|
||||||
|
|
||||||
Rootless Podman is required on Linux nodes that build or run a declared
|
Rootless Podman is required on Linux nodes that build or run a declared
|
||||||
Containerfile environment. Install VS Code when you want the graphical debug
|
Containerfile environment. Install VS Code when you want the graphical debug
|
||||||
workflow.
|
workflow.
|
||||||
|
|
|
||||||
|
|
@ -70,26 +70,6 @@ pub(super) struct CoordinatorControlledProcessRunner {
|
||||||
pub(super) configured_secrets: Vec<String>,
|
pub(super) configured_secrets: Vec<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod tests {
|
|
||||||
use super::redact_safe_live_log_prefix;
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn live_log_redaction_holds_boundaries_until_split_secrets_are_complete() {
|
|
||||||
let secrets = vec!["correct-horse".to_owned()];
|
|
||||||
let mut pending = b"prefix correct-".to_vec();
|
|
||||||
let (consumed, first) = redact_safe_live_log_prefix(&pending, &secrets, false).unwrap();
|
|
||||||
pending.drain(..consumed);
|
|
||||||
pending.extend_from_slice(b"horse suffix");
|
|
||||||
let (_, second) = redact_safe_live_log_prefix(&pending, &secrets, true).unwrap();
|
|
||||||
|
|
||||||
let combined = format!("{first}{second}");
|
|
||||||
assert_eq!(combined, "prefix [REDACTED] suffix");
|
|
||||||
assert!(!combined.contains("correct-"));
|
|
||||||
assert!(!combined.contains("horse"));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl CoordinatorControlledProcessRunner {
|
impl CoordinatorControlledProcessRunner {
|
||||||
const MAX_CAPTURE_BYTES: usize = 256 * 1024 + 1;
|
const MAX_CAPTURE_BYTES: usize = 256 * 1024 + 1;
|
||||||
|
|
||||||
|
|
@ -601,3 +581,23 @@ impl ProcessRunner for CoordinatorControlledProcessRunner {
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::redact_safe_live_log_prefix;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn live_log_redaction_holds_boundaries_until_split_secrets_are_complete() {
|
||||||
|
let secrets = vec!["correct-horse".to_owned()];
|
||||||
|
let mut pending = b"prefix correct-".to_vec();
|
||||||
|
let (consumed, first) = redact_safe_live_log_prefix(&pending, &secrets, false).unwrap();
|
||||||
|
pending.drain(..consumed);
|
||||||
|
pending.extend_from_slice(b"horse suffix");
|
||||||
|
let (_, second) = redact_safe_live_log_prefix(&pending, &secrets, true).unwrap();
|
||||||
|
|
||||||
|
let combined = format!("{first}{second}");
|
||||||
|
assert_eq!(combined, "prefix [REDACTED] suffix");
|
||||||
|
assert!(!combined.contains("correct-"));
|
||||||
|
assert!(!combined.contains("horse"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
|
|
@ -11,6 +11,9 @@ cargo install --path crates/clusterflux-node --bin clusterflux-node
|
||||||
cargo install --path crates/clusterflux-dap --bin clusterflux-debug-dap
|
cargo install --path crates/clusterflux-dap --bin clusterflux-debug-dap
|
||||||
~~~
|
~~~
|
||||||
|
|
||||||
|
On NixOS or another system with Nix, the equivalent package is available with
|
||||||
|
`nix profile install .#clusterflux-tools`.
|
||||||
|
|
||||||
Install rootless Podman on each Linux node that will execute container-backed
|
Install rootless Podman on each Linux node that will execute container-backed
|
||||||
environments.
|
environments.
|
||||||
|
|
||||||
|
|
|
||||||
12
flake.nix
12
flake.nix
|
|
@ -9,6 +9,18 @@
|
||||||
forAllSystems = nixpkgs.lib.genAttrs systems;
|
forAllSystems = nixpkgs.lib.genAttrs systems;
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
|
packages = forAllSystems (system:
|
||||||
|
let
|
||||||
|
pkgs = import nixpkgs { inherit system; };
|
||||||
|
publicPackages = import ./packages.nix { inherit pkgs self; };
|
||||||
|
privatePackages =
|
||||||
|
if builtins.pathExists ./web/packages.nix then
|
||||||
|
import ./web/packages.nix { inherit pkgs self; }
|
||||||
|
else
|
||||||
|
{ };
|
||||||
|
in
|
||||||
|
publicPackages // privatePackages);
|
||||||
|
|
||||||
devShells = forAllSystems (system:
|
devShells = forAllSystems (system:
|
||||||
let
|
let
|
||||||
pkgs = import nixpkgs { inherit system; };
|
pkgs = import nixpkgs { inherit system; };
|
||||||
|
|
|
||||||
65
packages.nix
Normal file
65
packages.nix
Normal file
|
|
@ -0,0 +1,65 @@
|
||||||
|
{ pkgs, self }:
|
||||||
|
let
|
||||||
|
clusterflux-tools = pkgs.rustPlatform.buildRustPackage {
|
||||||
|
pname = "clusterflux-tools";
|
||||||
|
version = "0.1.0";
|
||||||
|
src = self;
|
||||||
|
cargoLock.lockFile = ./Cargo.lock;
|
||||||
|
nativeBuildInputs = [
|
||||||
|
pkgs.git
|
||||||
|
pkgs.lld
|
||||||
|
pkgs.makeWrapper
|
||||||
|
];
|
||||||
|
cargoBuildFlags = [
|
||||||
|
"--package"
|
||||||
|
"clusterflux-cli"
|
||||||
|
"--package"
|
||||||
|
"clusterflux-node"
|
||||||
|
"--package"
|
||||||
|
"clusterflux-coordinator"
|
||||||
|
"--package"
|
||||||
|
"clusterflux-dap"
|
||||||
|
];
|
||||||
|
cargoTestFlags = [
|
||||||
|
"--package"
|
||||||
|
"clusterflux-cli"
|
||||||
|
"--package"
|
||||||
|
"clusterflux-node"
|
||||||
|
"--package"
|
||||||
|
"clusterflux-coordinator"
|
||||||
|
"--package"
|
||||||
|
"clusterflux-dap"
|
||||||
|
];
|
||||||
|
NIX_BUILD_CORES = "2";
|
||||||
|
RUST_MIN_STACK = "1073741824";
|
||||||
|
postInstall = ''
|
||||||
|
test -x "$out/bin/clusterflux"
|
||||||
|
test -x "$out/bin/clusterflux-node"
|
||||||
|
test -x "$out/bin/clusterflux-coordinator"
|
||||||
|
test -x "$out/bin/clusterflux-debug-dap"
|
||||||
|
'';
|
||||||
|
postFixup =
|
||||||
|
let
|
||||||
|
runtimePath = pkgs.lib.makeBinPath [
|
||||||
|
pkgs.cargo
|
||||||
|
pkgs.git
|
||||||
|
pkgs.lld
|
||||||
|
pkgs.rustc
|
||||||
|
];
|
||||||
|
in
|
||||||
|
''
|
||||||
|
wrapProgram "$out/bin/clusterflux" --prefix PATH : ${runtimePath}
|
||||||
|
wrapProgram "$out/bin/clusterflux-node" --prefix PATH : ${runtimePath}
|
||||||
|
wrapProgram "$out/bin/clusterflux-debug-dap" --prefix PATH : ${runtimePath}
|
||||||
|
'';
|
||||||
|
meta = {
|
||||||
|
description = "Clusterflux CLI, node, coordinator, and debugger adapter";
|
||||||
|
mainProgram = "clusterflux";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
inherit clusterflux-tools;
|
||||||
|
clusterflux = clusterflux-tools;
|
||||||
|
default = clusterflux-tools;
|
||||||
|
}
|
||||||
Loading…
Add table
Add a link
Reference in a new issue