Repository navigation
test: keep the suite off GitHub and away from real gh and zizmor (#548) - #561
Merged
mlieberman85 merged 1 commit intoOct 6, 2026
Merged
Conversation
…nitdevorg#548) Tests that ran a full audit called the live GitHub API through gh and ran the installed zizmor, so their results depended on the network, the developer's gh login, rate limits, and the zizmor version. Parity tests that compare several drivers failed whenever those answers differed. An autouse fixture in tests/conftest.py now installs RecordedGhApi({}) for every test (an unrecorded endpoint answers status 0, ERROR unavailable) and puts stand-ins first on PATH: gh exits 4 as if not authenticated, zizmor prints an empty findings list. A test's own responder or stand_in_tool still takes precedence. Tests that must reach the network are marked live and skipped unless the -m expression names the marker; the upstream spec-sync tests, which fetch from raw.githubusercontent.com, now work the same way (and --update-hash still selects them). The tests of gh_api_with_status and gh_api that mock subprocess.run drop the responder so they keep exercising the real gh path. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Before this change, 111 tests in 37 files made 576 real
ghcalls and 76 realzizmorruns per suite run. Calls includedgh api /repos/fake-owner/fake-repo,/userand/orgs/example. Results depended on network access, localghauth and rate limits, so runs failed intermittently.The change is test-only:
tests/conftest.pystand-ins: a session fixture writes stand-ingh(exits 4, "not authenticated in tests") andzizmor(prints[]).PATHand installsRecordedGhApi({}), so unrecorded endpoints answer deterministically as ERRORunavailable. Tests that install their own responder, or override a tool withstand_in_tool, still win.livemarker: tests markedliveorupstreamare skipped unless the-mexpression names that marker.pytest tests/, CI's-m unit/-m integration, and release.yml's-m "not upstream"never run them.-m upstreamworkflow and--update-hashkeep working.test_gh_api_status.pyandtest_utils.py::TestGithubCliErrorstest the realghcode path by mockingsubprocess.run, so they opt out of the default responder.docs/getting-started/testing.mdgains a "Network and external tools" section.Closes #548
Type of Change
Testing
uv run pytest tests/ -v): 5108 passed, 29 skippeduv run ruff check .)Determinism checks:
ghorzizmorcall and every network connection. They recorded zero of each.AI assistance
Claude (Claude Code, claude-opus-5-5) traced the network calls and made the change. This description was also drafted with Claude. The commit carries an
Assisted-by: Claude:claude-opus-5-5trailer.Additional Notes
upstreamtests are now opt-in too. They fetch from raw.githubusercontent.com and used to run on every default run.tests/packaging/test_wheel_install_config.pystill reaches PyPI (pip install, markedslow). It is left alone so release.yml keeps running it._classify_exec_failurelabels any unexpected exit code aserror_class=network. That coversgrepexiting 2 on a missing directory andgitexiting 128, so the class is misleading.🤖 Generated with Claude Code