Skip to content

test(host): script specs start from a sanitized environment (gh-#776) - #782

Merged
genwave-radio merged 6 commits into
mainfrom
test/script-env-isolation-776
Sep 15, 2026
Merged

genwave-radio merged 6 commits into
mainfrom
test/script-env-isolation-776

Conversation

@genwave-radio

Copy link
Copy Markdown
Collaborator

Closes #776

Stacked on #780 (gh-#770) and #781 (gh-#775); the first three commits are theirs. Only the three test(host) commits are new here.

What

  • New tests/GenWave.Host.Tests/Support/ScriptProcess.cs: the one way a Host spec starts launch.sh, build.sh, setup.sh, migrate.sh or tools/preflight.sh. Run strips every GW_*, SKIP_*, COMPOSE_*, BUILD, CONFIG, ADMIN_PASSWORD, MEDIA_DIR and the five Postgres/Icecast password variables before the child starts, sets PATH to the scratch bin dir alone, then applies GW_ENV_FILE and the scenario's own extraEnv. Start returns the live process (optional stdin redirect) for the two wizard facts that answer prompts. Sanitize covers the one setsid fact that must build its own start info.
  • 18 spec files migrated onto the helper; their file-local RunScript/MakeBinDir/AddStub/RepoRoot copies are gone. No behaviour change: same env vars, same fixtures, same assertions.

Specs

  • New Story438_ScriptEnvIsolation: red on main (helper missing), green here. Its grep fact holds: grep -rn 'new ProcessStartInfo("bash")' tests/GenWave.Host.Tests/Specs/ is empty.
  • Full solution green with a clean parent shell (Host 2901 passed / 0 failed / 57 skipped), and identical with SKIP_PREFLIGHT=1 COMPOSE_FILE=/nope/compose.yaml GW_SPEC_CANARY_438=leak POSTGRES_PASSWORD=leak exported in the parent.

Wire check on the dev box (T475)

SKIP_PREFLIGHT=1 dotnet test tests/GenWave.Host.Tests --filter "FullyQualifiedName~FeatureScriptPreflight|FullyQualifiedName~FeaturePreflightExpansion|FullyQualifiedName~FeatureScriptSpecsDoNotInheritTheDevelopersShell":

Passed!  - Failed:     0, Passed:    66, Skipped:     0, Total:    66, Duration: 351 ms - GenWave.Host.Tests.dll (net10.0)

SKIP_PREFLIGHT=1 SKIP_TESTS=0 ./build.sh:

==> GenWave build (config: Release, version: v5.8.2-9-g133d75b)
==> dotnet build GenWave.sln
==> dotnet test
Passed!  - Failed:     0, Passed:    78, Skipped:     0, Total:    78 - GenWave.Context.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:   182, Skipped:     0, Total:   182 - GenWave.Core.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:   220, Skipped:     3, Total:   223 - GenWave.Ads.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:   437, Skipped:     3, Total:   440 - GenWave.Orchestration.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:    53, Skipped:     0, Total:    53 - GenWave.Plugins.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:   881, Skipped:    13, Total:   894 - GenWave.Tts.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:   146, Skipped:     0, Total:   146 - GenWave.Architecture.Tests.dll (net10.0)
Failed!  - Failed:   226, Passed:  2903, Skipped:   369, Total:  3498 - GenWave.Host.Tests.dll (net10.0)
Passed!  - Failed:     0, Passed:  1347, Skipped:    47, Total:  1394 - GenWave.MediaLibrary.Tests.dll (net10.0)
exit=1

The bypass itself is harmless: every preflight and script spec passed inside that child, which is the point of the env -u SKIP_PREFLIGHT line. The 226 Host failures are all Category=Integration Postgres classes and share one error, all predefined address pools have been fully subnetted. build.sh runs the suite unfiltered and with default xUnit parallelism, so on the dev box the per-class compose projects exhaust Docker's default address pools. CI runs --filter "Category!=Integration" and does not hit this. Pre-existing and unrelated to this branch; noted as a follow-up below.

Follow-ups (not this PR)

  • build.sh test step: mirror CI's Category!=Integration filter or cap xUnit.MaxParallelThreads, so a dev-box build with tests enabled can go green.
  • Story344/Story345 RunSetup still spool answers through a wrapper script; ScriptProcess.Start(redirectStdin: true) can replace that in a later pass.
  • Two stale test containers from an earlier session (genwave-t386-…, genwave-t414-…) are still up on the dev box.

…env-isolation-776

# Conflicts:
#	DEPLOYMENT.md
… environment (gh-#776)

One helper for every spec that drives launch.sh, setup.sh, build.sh or
tools/preflight.sh. It strips GW_*, SKIP_*, COMPOSE_*, BUILD, CONFIG,
ADMIN_PASSWORD, MEDIA_DIR and the five passwords from the child environment,
sets PATH to the scratch bin dir, applies GW_ENV_FILE and then the per-test
overrides, and reads stdout and stderr concurrently. The strip rule is public
(IsStripped) so Story438 pins names without touching the test process's own
environment. MakeBinDir and AddStub are lifted from Gh019; the nine file-local
copies move onto the helper in T474.
…ss (gh-#776)

Migrate the 18 Host specs that ran ./launch.sh, ./build.sh, ./setup.sh or
tools/preflight.sh through a file-local ProcessStartInfo("bash") onto the
ScriptProcess helper, so each child starts from the sanitized environment
(GW_*/SKIP_*/COMPOSE_* and the .env secrets stripped, PATH = scratch bin)
instead of whatever the developer's shell happened to export. Deletes the
per-file RunScript/MakeBinDir/AddStub/RepoRoot copies; scenario env now
goes through extraEnv, bespoke fixtures through small bin-dir builders.

ScriptProcess gains Start (returns the live Process, optional stdin
redirect) for the two wizard facts that answer prompts interactively, and
Sanitize for the one setsid-based SIGINT fact that must build its own
ProcessStartInfo. Run's signature is unchanged (Story438 reflects on it).

Behaviour-preserving: Host suite 2901/0/57 in a clean shell and with
SKIP_PREFLIGHT/COMPOSE_FILE/a canary exported in the parent.
@genwave-radio
genwave-radio merged commit e2b8859 into main Sep 15, 2026
11 checks passed
@genwave-radio
genwave-radio deleted the test/script-env-isolation-776 branch September 15, 2026 20:02
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 15, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test: script-driving helpers inherit SKIP_PREFLIGHT and other control seams from the parent environment

1 participant