Skip to content

test(node-setup): #20 向导 fresh-board E2E (mock KMS + 真实 setup-server) + CI - #182

Merged
jhfnetboy merged 1 commit into
mainfrom
test/20-wizard-e2e
Jul 17, 2026
Merged

jhfnetboy merged 1 commit into
mainfrom
test/20-wizard-e2e

Conversation

@jhfnetboy

Copy link
Copy Markdown
Member

承接 #20(向导 fresh-board E2E 自动化测试)。补上 kms/node-setup 一直零 test 的空白。

改动

  • test_setup_server.py(新):纯 stdlib(unittest + http.server),零外部依赖、不碰真板/TEE/网络。起一个 mock KMS(答 /health、/gen-key、/pop),把真实 setup-server.py 起成子进程指向它,端到端跑 8 例:
    1. GET / + /health → 200
    2. 缺 setup_token → 403
    3. 错 token → 403
    4. 非法 operator 地址 → 400
    5. rpId=aastar.io → 400
    6. KMS 不可达 → 503
    7. happy → 200,校验 kms.env/dvt.env 落盘 0600 + 内容(rpId/key_id/pubkey/RUST_SIGNER_REQUIRED)
    8. 幂等 → 409
  • node-setup-test.yml(新):只在 kms/node-setup/ 改动触发,CI 自动 gate。

测试

本地 8/8 通过,0.6s。CI 用 ubuntu + python 3.11 跑同一脚本。

覆盖边界(诚实)

覆盖 web 向导的认证/校验/可达性/provision/写 config/幂等全路径。未覆盖:真链注册(attempt_onchain_register 在无 operator key 时回落,测的是回落分支)、popSigner→/pop 真机、aastar-kms-selfinit.sh(bash 自运行,需 systemctl,留作板上验证)。

https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5

…setup-server) + CI

社区节点 web 向导零 test 的空白补上(#20):
- test_setup_server.py: 纯 stdlib(unittest+http.server),起 mock KMS(/health,/gen-key,/pop)
  + 把真实 setup-server.py 起成子进程,端到端跑 8 例:index/health、缺token 403、错token 403、
  非法 operator 400、rpId=aastar.io 400、KMS 不可达 503、happy 200(校验 kms.env/dvt.env 0600+内容)、
  幂等 409。不碰真板/TEE/网络,0.6s 跑完。
- node-setup-test.yml: 只在 kms/node-setup/ 改动触发,CI 自动 gate。

本地 8/8 通过。

Claude-Session: https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5
@github-actions

Copy link
Copy Markdown

Security Audit Report

Date: Fri Jul 17 12:14:39 UTC 2026
Commit: 1b7ec97

Cargo Audit Results

�[1m�[33mwarning�[0m: profiles for the non root package will be ignored, specify profiles at the workspace root:
package:   /home/runner/work/AirAccount/AirAccount/kms/host/Cargo.toml
workspace: /home/runner/work/AirAccount/AirAccount/Cargo.toml
�[1m�[92m    Updating�[0m crates.io index
�[1m�[92m     Locking�[0m 1 package to latest compatible version
�[1m�[92m    Updating�[0m kms v0.28.1 (/home/runner/work/AirAccount/AirAccount/kms/host) -> v0.29.0
�[1m�[92mnote�[0m: pass `--verbose` to see 52 unchanged dependencies behind latest
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1166 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[31merror:�[0m not found: Couldn't load Cargo.lock
Caused by:
  -

... [查看完整报告](artifacts)

@clestons clestons left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE — 补上 node-setup 一直零 test 的空白,8 例 E2E 断言有料、CI 门正确。

核过(正确)

  • 真 E2E 不是 stub:起 mock KMS(答 /health、/gen-key、/pop)+ 把真实 setup-server.py 起成子进程指向它,驱动 HTTP。8 例覆盖:GET / +/health→200 · 缺 token→403 · 错 token→403 · 非法 operator→400 · rpId=aastar.io→400 · KMS 不可达→503 · happy→200 · 幂等→409。
  • 断言有价值:happy 路径不只看 200,还校验 bls_pubkey、registered=False(无 operator key→回落分支)、kms.env/dvt.env 落盘 0600、内容(KMS_RP_ID/KMS_BLS_KEY_ID/KMS_BLS_PUBKEY/RUST_SIGNER_REQUIRED=true)。0600 这类安全属性进 CI 很好。
  • 顺带固化了 token 认证:test_01/02 把 check_setup_token→403 变成回归门 —— 将来有人删掉 token 检查会被 CI 挡住(正是我 #179 误判、#180 澄清的那处,现在有测试兜底)。
  • CI 门正确:node-setup-test.yml 路径过滤到 kms/node-setup/** + workflow 自身,只在相关改动跑,stdlib 秒级。
  • 覆盖边界诚实标注(未覆盖真链注册//pop 真机/selfinit.sh,留板上验证)。

备注(非问题)

test_06→test_07 靠数字前缀顺序共享状态(test_07 的 409 依赖 test_06 已写 config)。unittest 按名字典序稳定,是有意设计、确定性 OK;仅提醒单独跑某例会因缺前置状态而行为不同。非阻塞。

纯测试 + CI,无逻辑可 PK。可合。

@jhfnetboy
jhfnetboy merged commit 4b523b2 into main Jul 17, 2026
7 checks passed
@jhfnetboy
jhfnetboy deleted the test/20-wizard-e2e branch July 17, 2026 13:41
@github-actions github-actions Bot locked and limited conversation to collaborators Jul 17, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants