Skip to content

fix: run vulture and coverage on scripts/ now hyperi-ci finds it - #57

Merged
catinspace-au merged 2 commits into
mainfrom
fix/flat-layout-gates
Oct 1, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/flat-layout-gates

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

hyperi-ci 2.12.5 finds scripts/ on its own, so culvert's vulture and coverage gates come back on and have to pass for real.

  • Removes the vulture: disabled and coverage: false workarounds from .hyperi-ci.yaml.
  • vulture: five dead helpers removed with their tests (validate_bool, validate_url, run_quiet, send_text, validate_external_pki_files). Six false positives carry a # noqa: V1xx naming the caller vulture cannot see, and ruff treats V as external.
  • Coverage of scripts/ went from 58% to 81.5% against hyperi-ci's default 80% floor. The floor is untouched; the gap is closed with tests, and pytest-cov joins the dev extra.
  • Three bugs the new tests found, fixed: TCP and HTTPS listeners ignored CULVERT_LOG_MODE, the OIDC cert check refused CN-only and wildcard-CN certificates, and generate-client crashed where wg is not installed.
  • New guard: the committed chart and compose fragment must match the generator byte for byte.
  • hyperi-ci check --strict with 2.12.5 is green locally: 586 unit tests, 81.53% coverage.

hyperi-ci 2.12.5 detects a flat layout and points its source gates at scripts/. The vulture disable and `coverage: false` that worked around the old hardcoded src/ come out.

vulture found eleven items. Five were dead and go with their tests: validate_bool and validate_url in lib/config.py, run_quiet in lib/process.py, BaseHandler.send_text in lib/health.py and validate_external_pki_files in lib/pki.py. Nothing outside the tests called them. The other six have callers vulture cannot see and carry a noqa naming the caller: do_GET and log_message (BaseHTTPRequestHandler), get_metrics and get_content_type (scalo's observability server) and the frame argument of both signal handlers. ruff lists V as an external code so it leaves those marks alone.

A system vulture 2.14 also flags ctx.minimum_version in lib/download.py, which the ssl module reads. It carries the same mark, so the gate passes whichever vulture runs.

Unit-tier coverage of scripts/ was 58% against hyperi-ci's default 80% floor. New tests take it past the floor, which is unchanged: generate-client end to end against a real CA, the deploy generator compared byte for byte with the committed chart and compose fragment, every listener rendered from the shipped templates, the OIDC certificate check against real certificates, OAuth2 and server setting validation, revoke-client's CLI, ProcessManager shutdown and signals, update-crl, the CRL refresh loop and the metrics parsers. pytest-cov joins the dev extra because hyperi-ci passes its --cov flags.

The tests turned up three defects, fixed here:
- configure_server_tcp and configure_server_https never applied CULVERT_LOG_MODE. 424a7a2 said all three listeners did, but only UDP was wired, so under the chart's stdout default a failing TCP or HTTPS listener still logged to a file inside the container.
- validate_oauth2_tls_cert kept the newline that ends openssl's subject line, so a certificate naming the server only in its CN, or with a wildcard CN, was refused. Certificates with a matching SAN hid it.
- sync_running_interface raised FileNotFoundError where wg is not installed. It now reports no interface to sync, as revoke-client already does.

start_crl_refresh takes a float interval, which lets the refresh-loop test run one cycle in about a second. The README no longer says CI runs without coverage or vulture.
@catinspace-au
catinspace-au requested a review from a team as a code owner October 1, 2026 09:43
openssl prints the subject as "CN = name" on the CI runner and "CN=name" on newer releases. The pattern only matched the second, so the CN tests failed in CI. It now accepts both.
@catinspace-au
catinspace-au merged commit 18198b3 into main Oct 1, 2026
13 checks passed
@catinspace-au
catinspace-au deleted the fix/flat-layout-gates branch October 1, 2026 09:52
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Released in v2.1.17 -- https://github.com/hyperi-io/culvert/releases/tag/v2.1.17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant