v0.3.2-pre.004-fix.001

This commit is contained in:
2026-08-29 19:04:47 +02:00
parent 6d2b1401aa
commit 0a4cddafc4
17 changed files with 509 additions and 99 deletions

View File

@@ -0,0 +1,78 @@
{
"format_version": 1,
"default_profile": "devnet",
"profiles": [
{
"profile_id": "devnet",
"network": "devnet",
"backend": "postgres",
"postgres": {
"connection_uri": "${KSP_SECRET_STORE_DEVNET_POSTGRES_URI:-postgresql://localhost/ksp_devnet}",
"pool": {
"max_connections": 8,
"connect_timeout_ms": 10000,
"wait_timeout_ms": 5000,
"create_timeout_ms": 10000,
"recycle_timeout_ms": 5000
},
"tls": {
"mode": "verify_full"
},
"bootstrap": {
"auto_migrate": true,
"migration_timeout_ms": 30000,
"migration_lock_timeout_ms": 10000
},
"shutdown_timeout_ms": 5000
}
},
{
"profile_id": "mainnet",
"network": "mainnet-beta",
"backend": "postgres",
"postgres": {
"connection_uri": "${KSP_SECRET_STORE_MAINNET_POSTGRES_URI:-postgresql://localhost/ksp_mainnet}",
"pool": {
"max_connections": 8,
"connect_timeout_ms": 10000,
"wait_timeout_ms": 5000,
"create_timeout_ms": 10000,
"recycle_timeout_ms": 5000
},
"tls": {
"mode": "verify_full"
},
"bootstrap": {
"auto_migrate": true,
"migration_timeout_ms": 30000,
"migration_lock_timeout_ms": 10000
},
"shutdown_timeout_ms": 5000
}
},
{
"profile_id": "testnet",
"network": "testnet",
"backend": "postgres",
"postgres": {
"connection_uri": "${KSP_SECRET_STORE_TESTNET_POSTGRES_URI:-postgresql://localhost/ksp_testnet}",
"pool": {
"max_connections": 8,
"connect_timeout_ms": 10000,
"wait_timeout_ms": 5000,
"create_timeout_ms": 10000,
"recycle_timeout_ms": 5000
},
"tls": {
"mode": "verify_full"
},
"bootstrap": {
"auto_migrate": true,
"migration_timeout_ms": 30000,
"migration_lock_timeout_ms": 10000
},
"shutdown_timeout_ms": 5000
}
}
]
}

View File

@@ -1,5 +1,5 @@
// file: crates/ksp-config-lib/unit_tests/store.rs
// version: 1
// version: 2
#[test]
fn committed_store_profile_maps_exact_runtime_settings_and_secret_fallback() {
@@ -13,9 +13,11 @@ fn committed_store_profile_maps_exact_runtime_settings_and_secret_fallback() {
assert!(resolved.is_ok(), "committed Store profile should map without opening PostgreSQL: {resolved:?}");
if let std::result::Result::Ok(resolved) = resolved {
assert_eq!(resolved.file_id().as_str(), crate::FILE_ID_STD_STORE);
assert_eq!(resolved.profile_id(), "postgres_default");
assert_eq!(resolved.profile_id(), "devnet");
assert_eq!(resolved.target_id(), "devnet");
assert_eq!(resolved.selection_source(), crate::ConfigProfileSelectionSource::DefaultProfile);
assert_eq!(resolved.settings().backend_kind(), ksp_store_lib::StoreBackendKind::Postgres);
assert_eq!(resolved.settings().network().as_str(), "devnet");
assert_eq!(resolved.settings().shutdown_timeout(), std::time::Duration::from_millis(5_000));
let postgres = match resolved.settings().backend() {
ksp_store_lib::StoreBackendSettings::Postgres(postgres) => std::option::Option::Some(postgres),
@@ -35,10 +37,10 @@ fn committed_store_profile_maps_exact_runtime_settings_and_secret_fallback() {
}
assert!(resolved.effective().sensitivity().is_secret());
let safe = resolved.effective().safe_value().to_string();
assert!(!safe.contains("postgresql://localhost/ksp"));
assert!(!safe.contains("postgresql://localhost/ksp_devnet"));
assert!(safe.contains(crate::REDACTED_CONFIG_VALUE));
let debug = format!("{resolved:?}");
assert!(!debug.contains("postgresql://localhost/ksp"));
assert!(!debug.contains("postgresql://localhost/ksp_devnet"));
}
}
@@ -49,9 +51,9 @@ fn process_store_uri_wins_and_remains_redacted_in_safe_views() {
std::result::Result::Ok(value) => value,
std::result::Result::Err(_) => return,
};
let canary = "postgresql://secret-user:secret-pass@db.example/ksp";
let canary = "postgresql://secret-user:secret-pass@db.example/ksp_devnet";
let mut process = std::collections::BTreeMap::<String, String>::new();
process.insert("KSP_SECRET_STORE_POSTGRES_URI".to_owned(), canary.to_owned());
process.insert("KSP_SECRET_STORE_DEVNET_POSTGRES_URI".to_owned(), canary.to_owned());
let environment = crate::ConfigEnvironment::from_maps(process, std::collections::BTreeMap::new());
let resolved = engine.load_resolved_store_config(std::option::Option::None, &environment);
assert!(resolved.is_ok(), "secret process Store URI should map: {resolved:?}");
@@ -82,10 +84,10 @@ fn literal_or_nonsecret_store_uri_is_rejected_by_effective_adapter() {
std::result::Result::Err(_) => return,
};
let profiles = source.get_mut("profiles").and_then(serde_json::Value::as_array_mut);
if let std::option::Option::Some(profiles) = profiles {
if let std::option::Option::Some(profile) = profiles.first_mut() {
profile["postgres"]["connection_uri"] = serde_json::Value::String(value.to_owned());
}
if let std::option::Option::Some(profiles) = profiles
&& let std::option::Option::Some(profile) = profiles.first_mut()
{
profile["postgres"]["connection_uri"] = serde_json::Value::String(value.to_owned());
}
let engine = fixture_engine_with_document(fixture.path(), &source);
assert!(engine.is_ok());
@@ -104,6 +106,40 @@ fn literal_or_nonsecret_store_uri_is_rejected_by_effective_adapter() {
}
}
#[test]
fn named_store_targets_select_one_network_and_database_without_runtime_multiplexing() {
let engine = committed_engine();
let engine = match engine {
std::result::Result::Ok(value) => value,
std::result::Result::Err(_) => return,
};
let mut process = std::collections::BTreeMap::<String, String>::new();
process.insert("KSP_SECRET_STORE_DEVNET_POSTGRES_URI".to_owned(), "postgresql://devnet.invalid/ksp_devnet".to_owned());
process.insert("KSP_SECRET_STORE_MAINNET_POSTGRES_URI".to_owned(), "postgresql://mainnet.invalid/ksp_mainnet".to_owned());
process.insert("KSP_SECRET_STORE_TESTNET_POSTGRES_URI".to_owned(), "postgresql://testnet.invalid/ksp_testnet".to_owned());
let environment = crate::ConfigEnvironment::from_maps(process, std::collections::BTreeMap::new());
for (target_id, network, expected_uri) in [
("devnet", "devnet", "postgresql://devnet.invalid/ksp_devnet"),
("mainnet", "mainnet-beta", "postgresql://mainnet.invalid/ksp_mainnet"),
("testnet", "testnet", "postgresql://testnet.invalid/ksp_testnet"),
] {
let resolved = engine.load_resolved_store_config(std::option::Option::Some(target_id), &environment);
assert!(resolved.is_ok(), "named Store target should resolve independently: {target_id}: {resolved:?}");
if let std::result::Result::Ok(resolved) = resolved {
assert_eq!(resolved.target_id(), target_id);
assert_eq!(resolved.profile_id(), target_id);
assert_eq!(resolved.selection_source(), crate::ConfigProfileSelectionSource::Explicit);
assert_eq!(resolved.settings().network().as_str(), network);
assert_eq!(
resolved.effective().value().pointer("/postgres/connection_uri").and_then(serde_json::Value::as_str),
std::option::Option::Some(expected_uri),
);
assert!(!resolved.effective().safe_value().to_string().contains(expected_uri));
}
}
return;
}
fn committed_engine() -> ksp_core_lib::Result<crate::ConfigDocumentEngine> {
let workspace = workspace_root();
let bootstrap = crate::ConfigBootstrapOptions::from_paths(workspace.join("config"), workspace.join("config/schemas"));
@@ -122,24 +158,16 @@ fn committed_engine() -> ksp_core_lib::Result<crate::ConfigDocumentEngine> {
fn fixture_engine_with_document(root: &std::path::Path, document: &serde_json::Value) -> ksp_core_lib::Result<crate::ConfigDocumentEngine> {
let config_root = root.join("config");
if let std::result::Result::Err(error) = std::fs::create_dir_all(config_root.as_path()) {
return std::result::Result::Err(
ksp_core_lib::Error::new(crate::ERROR_CODE_JSON_FILE_READ_FAILED, "test Config root cannot be created").with_source(error),
);
return std::result::Result::Err(ksp_core_lib::Error::new(crate::ERROR_CODE_JSON_FILE_READ_FAILED, "test Config root cannot be created").with_source(error));
}
let bytes = serde_json::to_vec_pretty(document);
let bytes = match bytes {
std::result::Result::Ok(value) => value,
std::result::Result::Err(error) => {
return std::result::Result::Err(
ksp_core_lib::Error::new(crate::ERROR_CODE_JSON_SYNTAX_INVALID, "test Store Config cannot be encoded").with_source(error),
);
},
std::result::Result::Err(error) => return std::result::Result::Err(ksp_core_lib::Error::new(crate::ERROR_CODE_JSON_SYNTAX_INVALID, "test Store Config cannot be encoded").with_source(error)),
};
let path = config_root.join(crate::DEFAULT_STD_STORE_FILENAME);
if let std::result::Result::Err(error) = std::fs::write(path.as_path(), bytes) {
return std::result::Result::Err(
ksp_core_lib::Error::new(crate::ERROR_CODE_JSON_FILE_READ_FAILED, "test Store Config cannot be written").with_source(error),
);
return std::result::Result::Err(ksp_core_lib::Error::new(crate::ERROR_CODE_JSON_FILE_READ_FAILED, "test Store Config cannot be written").with_source(error));
}
let bootstrap = crate::ConfigBootstrapOptions::from_paths(config_root, workspace_root().join("config/schemas"));
let bootstrap = match bootstrap {