fix(e2e): require secret probe success

This commit is contained in:
Vincent Koc
2026-06-07 11:22:43 +02:00
parent 3dc6ac3802
commit f36e54cd68
2 changed files with 34 additions and 0 deletions
@@ -1265,6 +1265,15 @@ async function p3ThroughP6StaticReloadAndCommandSnapshot() {
return "static capture, reload success, reload LKG, and command snapshot resolution proved";
}
function assertAllowedFailureCommandSucceeded(result, label, combinedOutput) {
if (result.signal) {
throw new Error(`${label} terminated by signal ${result.signal}: ${combinedOutput}`);
}
if (result.code !== 0) {
throw new Error(`${label} failed (${String(result.code)}): ${combinedOutput}`);
}
}
async function p7AuthProfileSecretRefPersistsAndResolves() {
await withProofEnv("p7", async (envCtx, _plugin, storePath) => {
const port = await allocatePort();
@@ -1316,6 +1325,11 @@ async function p7AuthProfileSecretRefPersistsAndResolves() {
`auth-profile SecretRef did not resolve through plugin integration: ${combined}`,
);
}
assertAllowedFailureCommandSucceeded(
result,
"auth-profile SecretRef model status probe",
combined,
);
const callsAfter = readJson(storePath).calls;
if (callsAfter <= callsBefore) {
throw new Error("auth-profile proof did not invoke the plugin-managed resolver");
@@ -1897,6 +1911,7 @@ async function main() {
}
export {
assertAllowedFailureCommandSucceeded,
collectBlockingProofResults,
cleanupEnv,
expectGatewayStartupFails,
@@ -294,6 +294,25 @@ describe("secret provider integration proof harness", () => {
}
});
it("fails allowed-failure probes when the command exits nonzero", async () => {
const proof = await import(
`${pathToFileURL(proofScriptPath).href}?case=allowed-failure-${Date.now()}`
);
expect(() =>
proof.assertAllowedFailureCommandSucceeded(
{
code: 1,
signal: null,
stderr: "resolver invoked openai-profile",
stdout: "openai-profile",
},
"auth-profile SecretRef model status probe",
"openai-profile\nresolver invoked",
),
).toThrow("auth-profile SecretRef model status probe failed (1)");
});
it.runIf(process.platform !== "win32")("bounds captured PTY configure output", async () => {
const root = makeTempDir();
const fakeOpenClaw = writeNoisySecretsConfigureOpenClaw(root);