test(node-setup): #20 向导 fresh-board E2E (mock KMS + 真实 setup-server) + CI - #182
Merged
Merged
Conversation
…setup-server) + CI 社区节点 web 向导零 test 的空白补上(#20): - test_setup_server.py: 纯 stdlib(unittest+http.server),起 mock KMS(/health,/gen-key,/pop) + 把真实 setup-server.py 起成子进程,端到端跑 8 例:index/health、缺token 403、错token 403、 非法 operator 400、rpId=aastar.io 400、KMS 不可达 503、happy 200(校验 kms.env/dvt.env 0600+内容)、 幂等 409。不碰真板/TEE/网络,0.6s 跑完。 - node-setup-test.yml: 只在 kms/node-setup/ 改动触发,CI 自动 gate。 本地 8/8 通过。 Claude-Session: https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5
Security Audit ReportDate: Fri Jul 17 12:14:39 UTC 2026 Cargo Audit Results |
clestons
approved these changes
Jul 17, 2026
clestons
left a comment
Contributor
There was a problem hiding this comment.
APPROVE — 补上 node-setup 一直零 test 的空白,8 例 E2E 断言有料、CI 门正确。
核过(正确)
- 真 E2E 不是 stub:起 mock KMS(答 /health、/gen-key、/pop)+ 把真实
setup-server.py起成子进程指向它,驱动 HTTP。8 例覆盖:GET / +/health→200· 缺 token→403 · 错 token→403 · 非法 operator→400 ·rpId=aastar.io→400 · KMS 不可达→503 · happy→200 · 幂等→409。 - 断言有价值:happy 路径不只看 200,还校验
bls_pubkey、registered=False(无 operator key→回落分支)、kms.env/dvt.env落盘 0600、内容(KMS_RP_ID/KMS_BLS_KEY_ID/KMS_BLS_PUBKEY/RUST_SIGNER_REQUIRED=true)。0600 这类安全属性进 CI 很好。 - 顺带固化了 token 认证:test_01/02 把
check_setup_token→403变成回归门 —— 将来有人删掉 token 检查会被 CI 挡住(正是我 #179 误判、#180 澄清的那处,现在有测试兜底)。 - CI 门正确:
node-setup-test.yml路径过滤到kms/node-setup/**+ workflow 自身,只在相关改动跑,stdlib 秒级。 - 覆盖边界诚实标注(未覆盖真链注册/
/pop真机/selfinit.sh,留板上验证)。
备注(非问题)
test_06→test_07 靠数字前缀顺序共享状态(test_07 的 409 依赖 test_06 已写 config)。unittest 按名字典序稳定,是有意设计、确定性 OK;仅提醒单独跑某例会因缺前置状态而行为不同。非阻塞。
纯测试 + CI,无逻辑可 PK。可合。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
承接 #20(向导 fresh-board E2E 自动化测试)。补上
kms/node-setup一直零 test 的空白。改动
test_setup_server.py(新):纯 stdlib(unittest+http.server),零外部依赖、不碰真板/TEE/网络。起一个 mock KMS(答/health、/gen-key、/pop),把真实setup-server.py起成子进程指向它,端到端跑 8 例:GET /+/health→ 200rpId=aastar.io→ 400kms.env/dvt.env落盘 0600 + 内容(rpId/key_id/pubkey/RUST_SIGNER_REQUIRED)node-setup-test.yml(新):只在kms/node-setup/改动触发,CI 自动 gate。测试
本地 8/8 通过,0.6s。CI 用 ubuntu + python 3.11 跑同一脚本。
覆盖边界(诚实)
覆盖 web 向导的认证/校验/可达性/provision/写 config/幂等全路径。未覆盖:真链注册(
attempt_onchain_register在无 operator key 时回落,测的是回落分支)、popSigner→/pop真机、aastar-kms-selfinit.sh(bash 自运行,需 systemctl,留作板上验证)。https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5