test(host): script specs start from a sanitized environment (gh-#776) - #782
Merged
Merged
Conversation
…env-isolation-776 # Conflicts: # DEPLOYMENT.md
… environment (gh-#776)
… environment (gh-#776) One helper for every spec that drives launch.sh, setup.sh, build.sh or tools/preflight.sh. It strips GW_*, SKIP_*, COMPOSE_*, BUILD, CONFIG, ADMIN_PASSWORD, MEDIA_DIR and the five passwords from the child environment, sets PATH to the scratch bin dir, applies GW_ENV_FILE and then the per-test overrides, and reads stdout and stderr concurrently. The strip rule is public (IsStripped) so Story438 pins names without touching the test process's own environment. MakeBinDir and AddStub are lifted from Gh019; the nine file-local copies move onto the helper in T474.
…ss (gh-#776) Migrate the 18 Host specs that ran ./launch.sh, ./build.sh, ./setup.sh or tools/preflight.sh through a file-local ProcessStartInfo("bash") onto the ScriptProcess helper, so each child starts from the sanitized environment (GW_*/SKIP_*/COMPOSE_* and the .env secrets stripped, PATH = scratch bin) instead of whatever the developer's shell happened to export. Deletes the per-file RunScript/MakeBinDir/AddStub/RepoRoot copies; scenario env now goes through extraEnv, bespoke fixtures through small bin-dir builders. ScriptProcess gains Start (returns the live Process, optional stdin redirect) for the two wizard facts that answer prompts interactively, and Sanitize for the one setsid-based SIGINT fact that must build its own ProcessStartInfo. Run's signature is unchanged (Story438 reflects on it). Behaviour-preserving: Host suite 2901/0/57 in a clean shell and with SKIP_PREFLIGHT/COMPOSE_FILE/a canary exported in the parent.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #776
Stacked on #780 (gh-#770) and #781 (gh-#775); the first three commits are theirs. Only the three
test(host)commits are new here.What
tests/GenWave.Host.Tests/Support/ScriptProcess.cs: the one way a Host spec startslaunch.sh,build.sh,setup.sh,migrate.shortools/preflight.sh.Runstrips everyGW_*,SKIP_*,COMPOSE_*,BUILD,CONFIG,ADMIN_PASSWORD,MEDIA_DIRand the five Postgres/Icecast password variables before the child starts, setsPATHto the scratch bin dir alone, then appliesGW_ENV_FILEand the scenario's ownextraEnv.Startreturns the live process (optional stdin redirect) for the two wizard facts that answer prompts.Sanitizecovers the onesetsidfact that must build its own start info.RunScript/MakeBinDir/AddStub/RepoRootcopies are gone. No behaviour change: same env vars, same fixtures, same assertions.Specs
Story438_ScriptEnvIsolation: red on main (helper missing), green here. Its grep fact holds:grep -rn 'new ProcessStartInfo("bash")' tests/GenWave.Host.Tests/Specs/is empty.SKIP_PREFLIGHT=1 COMPOSE_FILE=/nope/compose.yaml GW_SPEC_CANARY_438=leak POSTGRES_PASSWORD=leakexported in the parent.Wire check on the dev box (T475)
SKIP_PREFLIGHT=1 dotnet test tests/GenWave.Host.Tests --filter "FullyQualifiedName~FeatureScriptPreflight|FullyQualifiedName~FeaturePreflightExpansion|FullyQualifiedName~FeatureScriptSpecsDoNotInheritTheDevelopersShell":SKIP_PREFLIGHT=1 SKIP_TESTS=0 ./build.sh:The bypass itself is harmless: every preflight and script spec passed inside that child, which is the point of the
env -u SKIP_PREFLIGHTline. The 226 Host failures are allCategory=IntegrationPostgres classes and share one error,all predefined address pools have been fully subnetted.build.shruns the suite unfiltered and with default xUnit parallelism, so on the dev box the per-class compose projects exhaust Docker's default address pools. CI runs--filter "Category!=Integration"and does not hit this. Pre-existing and unrelated to this branch; noted as a follow-up below.Follow-ups (not this PR)
build.shtest step: mirror CI'sCategory!=Integrationfilter or capxUnit.MaxParallelThreads, so a dev-box build with tests enabled can go green.RunSetupstill spool answers through a wrapper script;ScriptProcess.Start(redirectStdin: true)can replace that in a later pass.genwave-t386-…,genwave-t414-…) are still up on the dev box.