Repository navigation
Expand file tree
/
Copy pathprogress.toml
More file actions
41 lines (35 loc) · 6.68 KB
/
Copy pathprogress.toml
File metadata and controls
41 lines (35 loc) · 6.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
[[items]]
id = "password-kdf-design"
description = "Design and implement password/passphrase-derived key support with approved KDF parameters, salt storage, migration behavior, and secret-handling rules."
validation = "cargo test -- --list > /tmp/git-zcrypt-unit-tests.txt && (rg -q '^key_store::tests::key_id_for_key_uses_sha256_prefix: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: key_store::tests::key_id_for_key_uses_sha256_prefix' >&2; exit 1)) && cargo test key_store::tests::key_id_for_key_uses_sha256_prefix -- --exact && cargo test --test filter_roundtrip -- --list > /tmp/git-zcrypt-filter-tests.txt && (rg -q '^password_derived_key_round_trips_from_stdin_setup: test$' /tmp/git-zcrypt-filter-tests.txt || (echo 'missing test: password_derived_key_round_trips_from_stdin_setup' >&2; exit 1)) && cargo test --test filter_roundtrip password_derived_key_round_trips_from_stdin_setup -- --exact && rg -q 'derive-key|sha256:' README.md && rg -q 'Argon2id|derive-key|sha256:|constrained JSON' codex-notes/password-kdf-design/plan.md"
passes = true
[[items]]
id = "option-name-inconsistency"
description = "keys should be given via --key option, regardless of the command"
validation = "cargo test -- --list > /tmp/git-zcrypt-unit-tests.txt && (rg -q '^tests::parses_key_option_for_key_commands: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: tests::parses_key_option_for_key_commands' >&2; exit 1)) && cargo test tests::parses_key_option_for_key_commands -- --exact && rg -q 'generate-key --key|derive-key --key|install-filter --key|import-key --key|export-key --key' README.md"
passes = true
[[items]]
id = "data-structure-doc"
description = "for data structures this software handles (keys, encrypted files), formats should be documented"
validation = "rg -q 'docs/data-formats\\.md' README.md && rg -q '^# Data Formats' docs/data-formats.md && rg -q '^## Encrypted Blob Format' docs/data-formats.md && rg -q 'magic: \"GZC1\\\\0\\\\0\\\\0\\\\0\"' docs/data-formats.md && rg -q 'version: 1' docs/data-formats.md && rg -q 'key_id_len' docs/data-formats.md && rg -q 'nonce_len: 12' docs/data-formats.md && rg -q 'reserved: 0' docs/data-formats.md && rg -q 'ChaCha20-Poly1305 ciphertext and tag' docs/data-formats.md && rg -q '^## Local Key File Format' docs/data-formats.md && rg -q 'magic: \"GZCKEY\\\\0\\\\0\"' docs/data-formats.md && rg -q 'raw_key_len: 32' docs/data-formats.md && rg -q 'sha256:<64 lowercase hex chars>' docs/data-formats.md && rg -q 'constrained JSON object' docs/data-formats.md"
passes = true
[[items]]
id = "versioning"
description = "for data structures this software handles (keys, encrypted files), version should be present"
validation = "cargo test -- --list > /tmp/git-zcrypt-unit-tests.txt && (rg -q '^blob::tests::rejects_malformed_headers: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: blob::tests::rejects_malformed_headers' >&2; exit 1)) && cargo test blob::tests::rejects_malformed_headers -- --exact && (rg -q '^key_store::tests::versioned_key_files_reject_malformed_headers: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: key_store::tests::versioned_key_files_reject_malformed_headers' >&2; exit 1)) && cargo test key_store::tests::versioned_key_files_reject_malformed_headers -- --exact && rg -q 'magic: \"GZC1\\\\0\\\\0\\\\0\\\\0\"' docs/data-formats.md && rg -q 'magic: \"GZCKEY\\\\0\\\\0\"' docs/data-formats.md && rg -q 'version: 1' docs/data-formats.md && rg -q 'raw_key_len: 32' docs/data-formats.md"
passes = true
[[items]]
id = "delete-key"
description = "keys can be deleted from local git-zcrypt state when they are no longer needed in a clone"
validation = "cargo test -- --list > /tmp/git-zcrypt-unit-tests.txt && (rg -q '^tests::parses_key_option_for_key_commands: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: tests::parses_key_option_for_key_commands' >&2; exit 1)) && cargo test tests::parses_key_option_for_key_commands -- --exact && (rg -q '^key_store::tests::delete_key_removes_key_file_and_index_entry: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: key_store::tests::delete_key_removes_key_file_and_index_entry' >&2; exit 1)) && cargo test key_store::tests::delete_key_removes_key_file_and_index_entry -- --exact && cargo test --test filter_roundtrip -- --list > /tmp/git-zcrypt-filter-tests.txt && (rg -q '^delete_key_removes_local_key_material: test$' /tmp/git-zcrypt-filter-tests.txt || (echo 'missing test: delete_key_removes_local_key_material' >&2; exit 1)) && cargo test --test filter_roundtrip delete_key_removes_local_key_material -- --exact && rg -q 'delete-key --key' README.md"
passes = true
[[items]]
id = "avoid-clap"
description = "clap is too heavy a crate (in size). use lighter one"
validation = "cargo test -- --list > /tmp/git-zcrypt-unit-tests.txt && (rg -q '^cli::tests::parses_planned_subcommands: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: cli::tests::parses_planned_subcommands' >&2; exit 1)) && cargo test cli::tests::parses_planned_subcommands -- --exact && (rg -q '^cli::tests::parses_key_option_for_key_commands: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: cli::tests::parses_key_option_for_key_commands' >&2; exit 1)) && cargo test cli::tests::parses_key_option_for_key_commands -- --exact && (rg -q '^cli::tests::parser_rejects_missing_and_unexpected_options: test$' /tmp/git-zcrypt-unit-tests.txt || (echo 'missing test: cli::tests::parser_rejects_missing_and_unexpected_options' >&2; exit 1)) && cargo test cli::tests::parser_rejects_missing_and_unexpected_options -- --exact && ! rg -q 'clap =' Cargo.toml && ! rg -q '^name = \"clap' Cargo.lock && ! rg -q 'use clap|Parser|Subcommand' src/main.rs src/cli.rs"
passes = true
[[items]]
id = "auto-check-executable-sizes"
description = "executable sizes matter. Use GitHub Actions to auto-check. You must decide the threshold for each platform"
validation = "rg -q '^name: ci$' .github/workflows/ci.yml && rg -q 'workflow_dispatch:' .github/workflows/ci.yml && rg -q 'schedule:' .github/workflows/ci.yml && rg -q 'cron: \"0 0 \\* \\* 1\"' .github/workflows/ci.yml && rg -q 'pull_request:' .github/workflows/ci.yml && rg -q 'actions/checkout@v7' .github/workflows/ci.yml && rg -q 'cargo fmt --check' .github/workflows/ci.yml && rg -q 'cargo clippy --locked --all-targets -- -D warnings' .github/workflows/ci.yml && rg -q 'cargo test --locked' .github/workflows/ci.yml && rg -q 'cargo build --release --locked' .github/workflows/ci.yml && rg -q 'File.size' .github/workflows/ci.yml && rg -q 'max_size: 850000' .github/workflows/ci.yml && rg -q 'max_size: 750000' .github/workflows/ci.yml && rg -q 'max_size: 550000' .github/workflows/ci.yml && rg -q 'codex-notes/auto-check-executable-sizes/plan.md' codex-notes/auto-check-executable-sizes/plan.md"
passes = true