2.9 KiB
2.9 KiB
Quality Assurance & Testing Strategy
nx9-wg enforces a comprehensive, multi-tiered verification strategy designed to guarantee code correctness, memory safety, failure semantics, and secret protection.
1. Test Suite Summary & Quality Gates
| Tier | Test Suite / Check | Scope & Execution Target | Current Status |
|---|---|---|---|
| Tier 1 | Code Formatting | cargo fmt --all -- --check |
PASS (Zero diffs) |
| Tier 2 | Type & Borrow Check | cargo check --workspace |
PASS (Zero errors) |
| Tier 3 | Workspace Unit Tests | cargo test --workspace |
PASS (91 / 91 passed) |
| Tier 4 | Clippy Linter Check | cargo clippy --workspace --all-targets --all-features -- -D warnings |
PASS (Zero warnings) |
| Tier 5 | Release Compilation | cargo build --release |
PASS (Clean build) |
| Tier 6 | Comprehensive CLI Suite | LIVE=0 bash scripts/test-cli-comprehensive.sh |
PASS (203 passed / 7 skipped) |
| Tier 7 | Native Integration Suite | LIVE=0 bash scripts/test-native-integration.sh |
PASS (19 passed / 1 skipped) |
| Tier 8 | Dedicated Live Kernel Suite | LIVE=0 bash scripts/test-live-kernel.sh |
PASS (23 passed / 1 skipped) |
| Tier 9 | Subprocess Safety Audit | Automated source scan for Command::new |
PASS (Zero subprocesses) |
| Tier 10 | Secret Leakage Audit | Automated scan for plaintext credentials | PASS (Zero secrets leaked) |
| Tier 11 | Release Package Check | Standalone archive extraction & verification | PASS (Independent execution) |
2. SAFE Mode (LIVE=0) vs Real-Kernel Mode (LIVE=1)
To guarantee safety when developing on unprivileged developer workstations:
SAFE Mode (LIVE=0 — Default)
- Uses real in-memory SQLite stores and dry-run Netlink message builders.
- Validates CLI parsers, JSON/YAML/CSV output formatters, route equality rules, and read-only reconciliation planning.
- Automatically skips live kernel mutation steps that require root or
CAP_NET_ADMIN.
Real-Kernel Mode (LIVE=1 — Dedicated Host Only)
- Requires
rootorCAP_NET_ADMINin a dedicated, disposable Linux VM. - Creates real kernel WireGuard interfaces (e.g.
nx9t...), attaches IPv4/IPv6 addresses, installs routes in the kernel routing table, configurestable inet nx9_wgin Netfilter, and validates live handshake telemetry.
3. Automated Subprocess & Secret Audits
Every verification run executes strict source-level security audits:
- Subprocess Audit: Confirms zero instances of
std::process::Command,tokio::process::Command,Command::new, or shell scripts in production Rust crates. - Secret Redaction Audit: Confirms that password hashes, private keys, preshared keys, and token hashes are never printed in human-readable status outputs or logs.
- Environment Audit: Confirms that all recognized environment variables strictly observe the
NX9_WG_*namespace.