fix: run vulture and coverage on scripts/ now hyperi-ci finds it - #57
Merged
Merged
Conversation
hyperi-ci 2.12.5 detects a flat layout and points its source gates at scripts/. The vulture disable and `coverage: false` that worked around the old hardcoded src/ come out. vulture found eleven items. Five were dead and go with their tests: validate_bool and validate_url in lib/config.py, run_quiet in lib/process.py, BaseHandler.send_text in lib/health.py and validate_external_pki_files in lib/pki.py. Nothing outside the tests called them. The other six have callers vulture cannot see and carry a noqa naming the caller: do_GET and log_message (BaseHTTPRequestHandler), get_metrics and get_content_type (scalo's observability server) and the frame argument of both signal handlers. ruff lists V as an external code so it leaves those marks alone. A system vulture 2.14 also flags ctx.minimum_version in lib/download.py, which the ssl module reads. It carries the same mark, so the gate passes whichever vulture runs. Unit-tier coverage of scripts/ was 58% against hyperi-ci's default 80% floor. New tests take it past the floor, which is unchanged: generate-client end to end against a real CA, the deploy generator compared byte for byte with the committed chart and compose fragment, every listener rendered from the shipped templates, the OIDC certificate check against real certificates, OAuth2 and server setting validation, revoke-client's CLI, ProcessManager shutdown and signals, update-crl, the CRL refresh loop and the metrics parsers. pytest-cov joins the dev extra because hyperi-ci passes its --cov flags. The tests turned up three defects, fixed here: - configure_server_tcp and configure_server_https never applied CULVERT_LOG_MODE. 424a7a2 said all three listeners did, but only UDP was wired, so under the chart's stdout default a failing TCP or HTTPS listener still logged to a file inside the container. - validate_oauth2_tls_cert kept the newline that ends openssl's subject line, so a certificate naming the server only in its CN, or with a wildcard CN, was refused. Certificates with a matching SAN hid it. - sync_running_interface raised FileNotFoundError where wg is not installed. It now reports no interface to sync, as revoke-client already does. start_crl_refresh takes a float interval, which lets the refresh-loop test run one cycle in about a second. The README no longer says CI runs without coverage or vulture.
openssl prints the subject as "CN = name" on the CI runner and "CN=name" on newer releases. The pattern only matched the second, so the CN tests failed in CI. It now accepts both.
Contributor
|
Released in v2.1.17 -- https://github.com/hyperi-io/culvert/releases/tag/v2.1.17 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
hyperi-ci 2.12.5 finds scripts/ on its own, so culvert's vulture and coverage gates come back on and have to pass for real.
vulture: disabledandcoverage: falseworkarounds from.hyperi-ci.yaml.# noqa: V1xxnaming the caller vulture cannot see, and ruff treats V as external.wgis not installed.hyperi-ci check --strictwith 2.12.5 is green locally: 586 unit tests, 81.53% coverage.