Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions src/notification.rs
Original file line number Diff line number Diff line change
Expand Up @@ -212,10 +212,27 @@ fn body(
let mut text = format!("Result: {}\n", account.outcome);
if let Some(findings) = account.security_findings {
let audit = match &account.ended {
Err(_) if account.failed_reproduction.is_some() => "audit complete",
Ok(line) => line.as_str(),
Err(_) => account.outcome,
};
text += &format!("Audit: {audit}\n");
if let Some(number) = account.failed_reproduction {
let status = if account.interrupted {
"interrupted"
} else if account
.ended
.as_ref()
.err()
.and_then(|cause| cause.safeguard_refusal())
.is_some()
{
"refused"
} else {
"failed"
};
text += &format!("Reproduction: {number} {status}\n");
}
if !findings.is_empty() {
text += "\nSecurity findings:\n";
for finding in findings {
Expand Down Expand Up @@ -331,6 +348,7 @@ mod tests {
ticket_lines: &[],
review: None,
security_findings: None,
failed_reproduction: None,
urls: vec![PR],
}
}
Expand All @@ -349,6 +367,7 @@ mod tests {
ticket_lines: &[],
review: None,
security_findings: None,
failed_reproduction: None,
urls: Vec::new(),
}
}
Expand Down
19 changes: 18 additions & 1 deletion src/run_ending.rs
Original file line number Diff line number Diff line change
Expand Up @@ -53,11 +53,20 @@ pub fn read(ending: &Ending) -> Result<Account<'_>, &Skip> {
ticket_lines: &[],
review: None,
security_findings: None,
failed_reproduction: None,
urls: Vec::new(),
},
Err(failed) => Account::of_failure(failed, "audit failed"),
Err(failed) => Account::of_failure(
failed,
if audited.failed_reproduction.is_some() {
"reproduction failed"
} else {
"audit failed"
},
),
};
Ok(Account {
failed_reproduction: audited.failed_reproduction,
security_findings: Some(&audited.findings),
advice: &audited.advice,
..account
Expand Down Expand Up @@ -102,6 +111,8 @@ pub struct Account<'a> {
pub ticket_lines: &'a [String],
/// In an Architect run, how its Architecture review ended.
pub review: Option<Review<'a>>,
/// The failed reproduction, after a completed Security audit and private recording.
pub failed_reproduction: Option<usize>,
/// Safe metadata from a Security run's private records, even if the audit failed.
pub security_findings: Option<&'a [crate::security::RecordedFinding]>,
/// The URLs on stdout, a line each: the pull request's, or that of the
Expand Down Expand Up @@ -172,6 +183,7 @@ impl<'a> Account<'a> {
ticket_lines: &reached.ticket_lines,
review: None,
security_findings: None,
failed_reproduction: None,
urls: vec![&reached.pr_url],
},
Err(failed) => Account {
Expand All @@ -196,6 +208,7 @@ impl<'a> Account<'a> {
ticket_lines: &failed.ticket_lines,
review: None,
security_findings: None,
failed_reproduction: None,
urls: failed.pr_url.as_deref().into_iter().collect(),
}
}
Expand Down Expand Up @@ -224,6 +237,7 @@ impl<'a> Account<'a> {
ticket_lines: &[],
review: None,
security_findings: None,
failed_reproduction: None,
urls: vec![reviewed.url()],
},
(Err(failed), None) => Account::of_failure(failed, "review failed"),
Expand Down Expand Up @@ -476,6 +490,7 @@ mod tests {
ticket_lines: &[],
review: None,
security_findings: None,
failed_reproduction: None,
urls: vec![PR],
}
}
Expand All @@ -494,6 +509,7 @@ mod tests {
ticket_lines: &[],
review: None,
security_findings: None,
failed_reproduction: None,
urls: Vec::new(),
}
}
Expand Down Expand Up @@ -670,6 +686,7 @@ mod tests {
dispatched: None,
}),
security_findings: None,
failed_reproduction: None,
urls: vec![PLAN],
}
);
Expand Down
13 changes: 12 additions & 1 deletion src/security.rs
Original file line number Diff line number Diff line change
Expand Up @@ -44,9 +44,11 @@ pub enum Outcome {
},
}

/// The audit's outcome and the private records it reached, including before a failure.
/// The Security run's outcome and the private records it reached, including before a failure.
pub struct Ended {
pub outcome: Result<Recorded, FailedRun>,
/// A failed reproduction's number; its audit and private recording completed.
pub failed_reproduction: Option<usize>,
pub findings: Vec<RecordedFinding>,
pub advice: Vec<Advice>,
}
Expand All @@ -55,6 +57,7 @@ impl From<anyhow::Error> for Ended {
fn from(error: anyhow::Error) -> Self {
Self {
outcome: Err(error.into()),
failed_reproduction: None,
findings: Vec::new(),
advice: Vec::new(),
}
Expand Down Expand Up @@ -329,6 +332,7 @@ fn audit_and_record(
let mut advice = Vec::new();
let mut findings = Vec::new();
let mut log = None;
let mut reproduction = None;
let recorded = (|| -> Result<Recorded> {
outside.check_harness()?;
outside.check_node()?;
Expand Down Expand Up @@ -376,6 +380,7 @@ fn audit_and_record(
"starting Security reproduction {number} of {}",
record.name()
));
reproduction = Some(number);
let (reproduced, session_log) = outside.reproduce(record, number);
if session_log.is_some() {
log = session_log;
Expand Down Expand Up @@ -409,11 +414,17 @@ fn audit_and_record(
}
Ok(recorded)
})();
let failed_reproduction = if recorded.is_err() {
reproduction
} else {
None
};
Ended {
outcome: recorded.map_err(|error| FailedRun {
log,
..error.into()
}),
failed_reproduction,
findings,
advice,
}
Expand Down
Loading
Loading