chore: restore clippy quality gate

This commit is contained in:
Eric Wendland 2026-07-05 17:24:03 +02:00
commit cad4bc0e74
4 changed files with 71 additions and 72 deletions

View file

@ -258,46 +258,46 @@ fn explain_from_ops_and_view(
let evaluated_ops = ops.len(); let evaluated_ops = ops.len();
if let Some(secret) = subject.as_str().strip_prefix("bearer:") { if let Some(secret) = subject.as_str().strip_prefix("bearer:") {
let secret = SecretId::new(secret.to_owned()); let secret = SecretId::new(secret.to_owned());
if let Some(access) = view.bearer_access.get(&secret) { if let Some(access) = view.bearer_access.get(&secret)
if access.resource == resource { && access.resource == resource
if let Some(granted_capability) = access {
.capabilities if let Some(granted_capability) = access
.iter() .capabilities
.find(|granted| capability_allows(granted, &capability)) .iter()
{ .find(|granted| capability_allows(granted, &capability))
return AuthExplanation { {
subject: subject.to_string(),
resource: resource.to_string(),
capability: capability.to_string(),
allowed: true,
reason: format!(
"active bearer access {} allows resource-scoped capability via {} without granting node identity",
access.secret, granted_capability
),
evaluated_ops,
diagnostics: vec![
"subject:bearer-secret".to_owned(),
format!("bearer:active:{}", access.secret),
format!("capability:matched:{granted_capability}"),
],
};
}
return AuthExplanation { return AuthExplanation {
subject: subject.to_string(), subject: subject.to_string(),
resource: resource.to_string(), resource: resource.to_string(),
capability: capability.to_string(), capability: capability.to_string(),
allowed: false, allowed: true,
reason: reason: format!(
"active bearer access exists for this resource but lacks the requested capability" "active bearer access {} allows resource-scoped capability via {} without granting node identity",
.to_owned(), access.secret, granted_capability
),
evaluated_ops, evaluated_ops,
diagnostics: vec![ diagnostics: vec![
"subject:bearer-secret".to_owned(), "subject:bearer-secret".to_owned(),
format!("bearer:active:{secret}"), format!("bearer:active:{}", access.secret),
"capability:missing".to_owned(), format!("capability:matched:{granted_capability}"),
], ],
}; };
} }
return AuthExplanation {
subject: subject.to_string(),
resource: resource.to_string(),
capability: capability.to_string(),
allowed: false,
reason:
"active bearer access exists for this resource but lacks the requested capability"
.to_owned(),
evaluated_ops,
diagnostics: vec![
"subject:bearer-secret".to_owned(),
format!("bearer:active:{secret}"),
"capability:missing".to_owned(),
],
};
} }
if ops.iter().any(|op| { if ops.iter().any(|op| {

View file

@ -491,11 +491,11 @@ pub fn reduce_keychain_ops(ops: &[KeychainOp]) -> KeychainView {
revoked_devices.insert(device.clone()); revoked_devices.insert(device.clone());
} }
KeychainOpKind::DeviceKeyAdd { device, key } => { KeychainOpKind::DeviceKeyAdd { device, key } => {
if let Some(record) = devices.get_mut(device) { if let Some(record) = devices.get_mut(device)
if !record.keys.contains(key) { && !record.keys.contains(key)
record.keys.push(key.clone()); {
record.keys.sort(); record.keys.push(key.clone());
} record.keys.sort();
} }
} }
KeychainOpKind::DeviceKeyRevoke { device, key } => { KeychainOpKind::DeviceKeyRevoke { device, key } => {
@ -521,11 +521,11 @@ pub fn reduce_keychain_ops(ops: &[KeychainOp]) -> KeychainView {
revoked_nodes.insert(node.clone()); revoked_nodes.insert(node.clone());
} }
KeychainOpKind::NodeEndpointAdd { node, endpoint } => { KeychainOpKind::NodeEndpointAdd { node, endpoint } => {
if let Some(record) = nodes.get_mut(node) { if let Some(record) = nodes.get_mut(node)
if !record.endpoints.contains(endpoint) { && !record.endpoints.contains(endpoint)
record.endpoints.push(endpoint.clone()); {
record.endpoints.sort(); record.endpoints.push(endpoint.clone());
} record.endpoints.sort();
} }
} }
KeychainOpKind::NodeEndpointRevoke { node, endpoint } => { KeychainOpKind::NodeEndpointRevoke { node, endpoint } => {

View file

@ -1657,13 +1657,13 @@ async fn cas_root_sync_from_peer(
let stored_name = remote_file_root_name(&node_id, &remote_root.name); let stored_name = remote_file_root_name(&node_id, &remote_root.name);
let stored_path = format!("remote:{node_id}:{}", remote_root.name); let stored_path = format!("remote:{node_id}:{}", remote_root.name);
let existing_remote_root = store.get_file_root_by_name(&stored_name)?; let existing_remote_root = store.get_file_root_by_name(&stored_name)?;
if let Some(existing) = &existing_remote_root { if let Some(existing) = &existing_remote_root
if existing.path != stored_path { && existing.path != stored_path
return Err(NodeError::IrohPeer(format!( {
"refusing to overwrite existing file root {} at {}", return Err(NodeError::IrohPeer(format!(
existing.name, existing.path "refusing to overwrite existing file root {} at {}",
))); existing.name, existing.path
} )));
} }
let base_tree = existing_remote_root let base_tree = existing_remote_root
.as_ref() .as_ref()
@ -1695,20 +1695,19 @@ async fn cas_root_sync_from_peer(
remote_tree_json = Some(serde_json::to_string(&remote_tree)?); remote_tree_json = Some(serde_json::to_string(&remote_tree)?);
if let (Some(base_tree), Some(local_root)) = if let (Some(base_tree), Some(local_root)) =
(&base_tree, store.get_file_root_by_name(&remote_root.name)?) (&base_tree, store.get_file_root_by_name(&remote_root.name)?)
&& local_root.latest_tree_json.is_some()
{ {
if local_root.latest_tree_json.is_some() { sync_conflicts.extend(record_sync_tree_conflicts(
sync_conflicts.extend(record_sync_tree_conflicts( &store,
&store, &local_root,
&local_root, existing_remote_root
existing_remote_root .as_ref()
.as_ref() .and_then(|existing| existing.latest_tree_hash.as_deref()),
.and_then(|existing| existing.latest_tree_hash.as_deref()), base_tree,
base_tree, local_root.latest_tree_hash.as_deref(),
local_root.latest_tree_hash.as_deref(), remote_root.latest_tree.as_ref(),
remote_root.latest_tree.as_ref(), &remote_tree,
&remote_tree, )?);
)?);
}
} }
} }
let stored = StoredFileRoot { let stored = StoredFileRoot {
@ -3735,10 +3734,10 @@ async fn db_sync_from_peer(
} else { } else {
0 0
}; };
if schema_match { if schema_match
if let Some(next_cursor) = high_water_db_version.or(max_db_version) { && let Some(next_cursor) = high_water_db_version.or(max_db_version)
store_live_sync_cursor(&store, peer_node, &stream, next_cursor)?; {
} store_live_sync_cursor(&store, peer_node, &stream, next_cursor)?;
} }
( (
changes_received, changes_received,
@ -4056,13 +4055,13 @@ fn sync_watermarks_for_peer(
} }
} }
for db in store.list_db_resources()? { for db in store.list_db_resources()? {
if can_sync_resource(store, &peer, &db.resource_id, "db.sync")? { if can_sync_resource(store, &peer, &db.resource_id, "db.sync")?
if let Ok(metadata) = geth_db::crsqlite_change_metadata(Path::new(&db.path)) { && let Ok(metadata) = geth_db::crsqlite_change_metadata(Path::new(&db.path))
watermarks.push(SyncWatermark { {
stream: format!("db:{}", db.name), watermarks.push(SyncWatermark {
high_water: metadata.max_db_version.unwrap_or(0), stream: format!("db:{}", db.name),
}); high_water: metadata.max_db_version.unwrap_or(0),
} });
} }
} }
for root in store.list_file_roots()? { for root in store.list_file_roots()? {

View file

@ -27,7 +27,7 @@ Goal: make the documented local quality gate pass before deeper refactors.
- `[x]` `cargo fmt --all -- --check` passes. - `[x]` `cargo fmt --all -- --check` passes.
- `[x]` `cargo check --workspace --all-targets` passes. - `[x]` `cargo check --workspace --all-targets` passes.
- `[x]` `cargo test --workspace` passes. - `[x]` `cargo test --workspace` passes.
- `[ ]` `cargo clippy --workspace --all-targets -- -D warnings` passes. - `[x]` `cargo clippy --workspace --all-targets -- -D warnings` passes.
- `[ ]` CI enforces the same required checks. - `[ ]` CI enforces the same required checks.
## Phase 1: Daemon Subsystem Refactor ## Phase 1: Daemon Subsystem Refactor