Files
nx9-wg/docs/testing.md
T

2.9 KiB

Quality Assurance & Testing Strategy

nx9-wg enforces a comprehensive, multi-tiered verification strategy designed to guarantee code correctness, memory safety, failure semantics, and secret protection.


1. Test Suite Summary & Quality Gates

Tier Test Suite / Check Scope & Execution Target Current Status
Tier 1 Code Formatting cargo fmt --all -- --check PASS (Zero diffs)
Tier 2 Type & Borrow Check cargo check --workspace PASS (Zero errors)
Tier 3 Workspace Unit Tests cargo test --workspace PASS (91 / 91 passed)
Tier 4 Clippy Linter Check cargo clippy --workspace --all-targets --all-features -- -D warnings PASS (Zero warnings)
Tier 5 Release Compilation cargo build --release PASS (Clean build)
Tier 6 Comprehensive CLI Suite LIVE=0 bash scripts/test-cli-comprehensive.sh PASS (203 passed / 7 skipped)
Tier 7 Native Integration Suite LIVE=0 bash scripts/test-native-integration.sh PASS (19 passed / 1 skipped)
Tier 8 Dedicated Live Kernel Suite LIVE=0 bash scripts/test-live-kernel.sh PASS (23 passed / 1 skipped)
Tier 9 Subprocess Safety Audit Automated source scan for Command::new PASS (Zero subprocesses)
Tier 10 Secret Leakage Audit Automated scan for plaintext credentials PASS (Zero secrets leaked)
Tier 11 Release Package Check Standalone archive extraction & verification PASS (Independent execution)

2. SAFE Mode (LIVE=0) vs Real-Kernel Mode (LIVE=1)

To guarantee safety when developing on unprivileged developer workstations:

SAFE Mode (LIVE=0 — Default)

  • Uses real in-memory SQLite stores and dry-run Netlink message builders.
  • Validates CLI parsers, JSON/YAML/CSV output formatters, route equality rules, and read-only reconciliation planning.
  • Automatically skips live kernel mutation steps that require root or CAP_NET_ADMIN.

Real-Kernel Mode (LIVE=1 — Dedicated Host Only)

  • Requires root or CAP_NET_ADMIN in a dedicated, disposable Linux VM.
  • Creates real kernel WireGuard interfaces (e.g. nx9t...), attaches IPv4/IPv6 addresses, installs routes in the kernel routing table, configures table inet nx9_wg in Netfilter, and validates live handshake telemetry.

3. Automated Subprocess & Secret Audits

Every verification run executes strict source-level security audits:

  1. Subprocess Audit: Confirms zero instances of std::process::Command, tokio::process::Command, Command::new, or shell scripts in production Rust crates.
  2. Secret Redaction Audit: Confirms that password hashes, private keys, preshared keys, and token hashes are never printed in human-readable status outputs or logs.
  3. Environment Audit: Confirms that all recognized environment variables strictly observe the NX9_WG_* namespace.