# Quality Assurance & Testing Strategy `nx9-wg` enforces a comprehensive, multi-tiered verification strategy designed to guarantee code correctness, memory safety, failure semantics, and secret protection. --- ## 1. Test Suite Summary & Quality Gates | Tier | Test Suite / Check | Scope & Execution Target | Current Status | | :--- | :--- | :--- | :---: | | **Tier 1** | Code Formatting | `cargo fmt --all -- --check` | **PASS** (Zero diffs) | | **Tier 2** | Type & Borrow Check | `cargo check --workspace` | **PASS** (Zero errors) | | **Tier 3** | Workspace Unit Tests | `cargo test --workspace` | **PASS** (**91 / 91 passed**) | | **Tier 4** | Clippy Linter Check | `cargo clippy --workspace --all-targets --all-features -- -D warnings` | **PASS** (Zero warnings) | | **Tier 5** | Release Compilation | `cargo build --release` | **PASS** (Clean build) | | **Tier 6** | Comprehensive CLI Suite | `LIVE=0 bash scripts/test-cli-comprehensive.sh` | **PASS** (**203 passed** / 7 skipped) | | **Tier 7** | Native Integration Suite | `LIVE=0 bash scripts/test-native-integration.sh` | **PASS** (**19 passed** / 1 skipped) | | **Tier 8** | Dedicated Live Kernel Suite | `LIVE=0 bash scripts/test-live-kernel.sh` | **PASS** (**23 passed** / 1 skipped) | | **Tier 9** | Subprocess Safety Audit | Automated source scan for `Command::new` | **PASS** (Zero subprocesses) | | **Tier 10** | Secret Leakage Audit | Automated scan for plaintext credentials | **PASS** (Zero secrets leaked) | | **Tier 11** | Release Package Check | Standalone archive extraction & verification | **PASS** (Independent execution) | --- ## 2. SAFE Mode (`LIVE=0`) vs Real-Kernel Mode (`LIVE=1`) To guarantee safety when developing on unprivileged developer workstations: ### SAFE Mode (`LIVE=0` — Default) - Uses real in-memory SQLite stores and dry-run Netlink message builders. - Validates CLI parsers, JSON/YAML/CSV output formatters, route equality rules, and read-only reconciliation planning. - Automatically skips live kernel mutation steps that require root or `CAP_NET_ADMIN`. ### Real-Kernel Mode (`LIVE=1` — Dedicated Host Only) - Requires `root` or `CAP_NET_ADMIN` in a dedicated, disposable Linux VM. - Creates real kernel WireGuard interfaces (e.g. `nx9t...`), attaches IPv4/IPv6 addresses, installs routes in the kernel routing table, configures `table inet nx9_wg` in Netfilter, and validates live handshake telemetry. --- ## 3. Automated Subprocess & Secret Audits Every verification run executes strict source-level security audits: 1. **Subprocess Audit**: Confirms zero instances of `std::process::Command`, `tokio::process::Command`, `Command::new`, or shell scripts in production Rust crates. 2. **Secret Redaction Audit**: Confirms that password hashes, private keys, preshared keys, and token hashes are never printed in human-readable status outputs or logs. 3. **Environment Audit**: Confirms that all recognized environment variables strictly observe the `NX9_WG_*` namespace.