fix: resolve final addon review
CI / validate (pull_request) Failing after 1m33s

This commit is contained in:
Dennis Juhler Aagaard
2026-09-24 19:02:05 +02:00
parent 6d218f02a3
commit f3c1abf2cf
7 changed files with 198 additions and 33 deletions
+82 -8
View File
@@ -51,26 +51,40 @@ def test_repository_hostname_derivation() -> None:
assert f"{repository_id}-stelloauth" == "0031621f-stelloauth"
def test_documentation_contract() -> None:
documentation = "\n".join(
(ROOT / path).read_text(encoding="utf-8")
for path in ("README.md", "stelloauth/README.md", "stelloauth/DOCS.md")
)
def test_user_guide_documentation_contract() -> None:
documentation = (ROOT / "stelloauth/DOCS.md").read_text(encoding="utf-8")
for required_text in (
REPOSITORY_URL,
"Installér **Stelloauth**",
"aktivér **Start ved opstart** og **Watchdog**",
"http://0031621f-stelloauth:8080/worker",
"http://192.168.1.20:8080/worker",
"Brand: Opel",
"Country: DK",
"v0.6.0",
"0.5.10",
"CloakBrowser Binary License",
"Image: 2,571,693,650 bytes (2.571 GB decimal / 2452.56 MiB).",
"Dokumenteret Task 4-måling: 121,5 MiB.",
"Stop: cirka 9.3 sekunder.",
"approximately 4 GB free",
"Der er ikke gennemført et live MyOpel-login.",
"Login-flow RAM: not measured without real MyOpel credentials.",
):
assert required_text in documentation
assert "deaktivér porttilknytningen igen" in documentation
assert "Seneste idle RAM" not in documentation
def test_root_readme_repository_source_and_license_facts() -> None:
readme = (ROOT / "README.md").read_text(encoding="utf-8")
for required_text in (
REPOSITORY_URL,
"v0.6.0",
"367d4f8c02a3b072c59142c49dffc129edc8548b",
"0.5.10",
"f04c23da285b3b3d3cf10c8f9d282e7adc1d52ce",
"CloakBrowser Binary License",
"MIT-licenseret",
):
assert required_text in readme
def test_translations_cover_every_option() -> None:
keys = set(load_yaml("stelloauth/config.yaml")["options"])
@@ -107,6 +121,8 @@ def test_dockerfile_declares_home_assistant_runtime_contract() -> None:
"io.hass.version",
):
assert label in dockerfile
assert 'io.hass.type="app"' in dockerfile
assert 'io.hass.type="addon"' not in dockerfile
assert re.search(r"^EXPOSE 8080$", dockerfile, re.MULTILINE)
assert not re.search(r"^EXPOSE .*\b9222\b", dockerfile, re.MULTILINE)
assert "ENTRYPOINT []" in dockerfile
@@ -127,6 +143,64 @@ def test_runtime_accepts_docker_port_unpublished_status() -> None:
assert 'docker port "$container" 9222/tcp 2>/dev/null || true' in runtime_test
def test_ci_builds_and_loads_only_the_amd64_test_image() -> None:
workflow = (ROOT / ".gitea/workflows/ci.yml").read_text(encoding="utf-8")
parsed = yaml.safe_load(workflow)
steps = parsed["jobs"]["validate"]["steps"]
build_command = next(
step["run"] for step in steps if step.get("name") == "Build amd64 image"
)
assert build_command.split() == [
"docker",
"buildx",
"build",
"--platform",
"linux/amd64",
"--build-arg",
"BUILD_ARCH=amd64",
"--load",
"--tag",
"homeassistant-stelloauth-addon:test",
"stelloauth",
]
for publication_primitive in (
"--push",
"docker push",
"docker/login-action",
"docker/build-push-action",
"packages: write",
):
assert publication_primitive not in workflow
def test_patch_payloads_disable_git_whitespace_errors() -> None:
result = subprocess.run(
[
"git",
"check-attr",
"whitespace",
"--",
"stelloauth/patches/stelloauth-security.patch",
"stelloauth/patches/cloakserve-loopback.patch",
],
cwd=ROOT,
text=True,
capture_output=True,
check=True,
)
assert result.stdout.splitlines() == [
"stelloauth/patches/stelloauth-security.patch: whitespace: unset",
"stelloauth/patches/cloakserve-loopback.patch: whitespace: unset",
]
def test_runtime_rejects_every_ipv6_cdp_listener() -> None:
runtime_test = (ROOT / "tests/test_runtime.sh").read_text(encoding="utf-8")
assert 'cat /proc/net/tcp6 > "$tcp6_artifact"' in runtime_test
assert 'for table in ("/proc/net/tcp", "/proc/net/tcp6"):' in runtime_test
assert 'if table == "/proc/net/tcp6":' in runtime_test
def test_runtime_requires_process_baseline_after_cdp_close_and_zero_stopped_pid() -> None:
runtime_test = (ROOT / "tests/test_runtime.sh").read_text(encoding="utf-8")
assert 'docker top "$container" -eo pid,args' in runtime_test
+30 -16
View File
@@ -209,26 +209,34 @@ assert_processes_return_to_baseline() {
assert_loopback_cdp_listener() {
local container="$1"
local artifact="$2"
docker exec "$container" cat /proc/net/tcp > "$artifact"
local tcp_artifact="$2"
local tcp6_artifact="$3"
docker exec "$container" cat /proc/net/tcp > "$tcp_artifact"
docker exec "$container" cat /proc/net/tcp6 > "$tcp6_artifact"
docker exec -i "$container" python3 - <<'PY'
expected = f"0100007F:{9222:04X}"
wildcard = f"00000000:{9222:04X}"
if expected != "0100007F:2406":
raise SystemExit(f"unexpected 9222 hexadecimal encoding: {expected}")
listeners = set()
with open("/proc/net/tcp", encoding="ascii") as handle:
next(handle)
for line in handle:
fields = line.split()
if len(fields) >= 4 and fields[3] == "0A":
listeners.add(fields[1].upper())
listeners = {"/proc/net/tcp": set(), "/proc/net/tcp6": set()}
for table in ("/proc/net/tcp", "/proc/net/tcp6"):
with open(table, encoding="ascii") as handle:
next(handle)
for line in handle:
fields = line.split()
if len(fields) < 4 or fields[3] != "0A":
continue
local_address = fields[1].upper()
if local_address.rsplit(":", 1)[-1] != "2406":
continue
listeners[table].add(local_address)
if table == "/proc/net/tcp6":
raise SystemExit(f"IPv6 CDP listener present: {local_address}")
if expected not in listeners:
raise SystemExit(f"missing loopback CDP listener {expected}: {sorted(listeners)}")
if wildcard in listeners:
raise SystemExit(f"wildcard CDP listener present: {wildcard}")
if listeners["/proc/net/tcp"] != {expected}:
raise SystemExit(
f"IPv4 CDP listeners = {sorted(listeners['/proc/net/tcp'])}, want [{expected}]"
)
PY
}
@@ -370,7 +378,10 @@ first_port="$(host_port "$first_container")"
wait_ready "$first_container" "$first_port"
first_baseline="$(capture_process_baseline "$first_container")"
assert_no_9222_mapping "$first_container"
assert_loopback_cdp_listener "$first_container" "${artifacts_dir}/runtime-proc-net-tcp.txt"
assert_loopback_cdp_listener \
"$first_container" \
"${artifacts_dir}/runtime-proc-net-tcp.txt" \
"${artifacts_dir}/runtime-proc-net-tcp6.txt"
probe_and_close_cdp "$first_container"
assert_processes_return_to_baseline "$first_container" "$first_baseline"
post_invalid_worker "$first_port" "${artifacts_dir}/runtime-invalid-worker-response.json"
@@ -383,7 +394,10 @@ second_port="$(host_port "$second_container")"
wait_ready "$second_container" "$second_port"
second_baseline="$(capture_process_baseline "$second_container")"
assert_no_9222_mapping "$second_container"
assert_loopback_cdp_listener "$second_container" "${artifacts_dir}/runtime-restart-proc-net-tcp.txt"
assert_loopback_cdp_listener \
"$second_container" \
"${artifacts_dir}/runtime-restart-proc-net-tcp.txt" \
"${artifacts_dir}/runtime-restart-proc-net-tcp6.txt"
probe_and_close_cdp "$second_container"
assert_processes_return_to_baseline "$second_container" "$second_baseline"