Skip to content

Commit 37d9403

Browse files
committed
Inject SecurityBackedRuntime in stdlib_security integration tests.
Strict permission and secure-topic publish checks require the real security runtime, not the lean-core builtin no-op implementation.
1 parent 6ccd764 commit 37d9403

1 file changed

Lines changed: 16 additions & 3 deletions

File tree

‎crates/spanda-core/tests/stdlib_security.rs‎

Lines changed: 16 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,23 @@
11
//! Security foundation integration tests.
22
33
use spanda_core::{check, compile, run, RunOptions};
4+
use spanda_runtime::security_runtime::SecurityRuntime;
45
use spanda_security::{
5-
CapabilitySet, PackagePermissions, RobotIdentity, SecurePolicy, SecurityContext, TrustLevel,
6+
CapabilitySet, PackagePermissions, RobotIdentity, SecurePolicy, SecurityBackedRuntime,
7+
SecurityContext, TrustLevel,
68
};
79

10+
fn security_backed_runtime() -> Box<dyn SecurityRuntime> {
11+
Box::new(SecurityBackedRuntime::new())
12+
}
13+
14+
fn secured_run_options() -> RunOptions {
15+
RunOptions {
16+
security_runtime_factory: Some(security_backed_runtime),
17+
..Default::default()
18+
}
19+
}
20+
821
#[test]
922
fn security_example_type_checks() {
1023
// Description:
@@ -93,7 +106,7 @@ robot R {
93106
}
94107
}
95108
"#;
96-
let err = run(source, RunOptions::default()).expect_err("unsigned secure topic should fail");
109+
let err = run(source, secured_run_options()).expect_err("unsigned secure topic should fail");
97110
assert!(
98111
err.to_string().contains("Identity required") || err.to_string().contains("identity"),
99112
"expected identity requirement, got: {err}"
@@ -287,7 +300,7 @@ robot R {
287300
behavior run() { audit.record("e", "p"); }
288301
}
289302
"#;
290-
let err = run(source, RunOptions::default())
303+
let err = run(source, secured_run_options())
291304
.expect_err("strict permissions should block audit.write");
292305
assert!(
293306
err.to_string().contains("capability denied"),

0 commit comments

Comments
 (0)