Repository navigation
test(cloud-lab): Docker-based integration test environment - #362
Conversation
Rebase of OpenTollGate#362 onto rewritten main — carries only the tests/cloud-lab/ Docker environment (2-router + mint topology: smoke payment, two-router autopay, mint-failure scenarios, fake-ndsctl shim). Dropped: deploy-backup-20260730/ (leaked secrets, incident #364), DEPENDS packaging change, go.mod churn, token-recovery binary. Original-PR: OpenTollGate#362
98fc2ff to
2081c4e
Compare
|
Same incident cleanup as #360/#361: the branch carried New head Dropped: secrets directory, DEPENDS packaging change, go.mod churn, token-recovery binary, pre-commit config. |
Dockerfile.tollgate pinned golang:1.24-bookworm while src/go.mod declares go 1.25.0 — the in-container build fails (exit 1). Align the base image.
|
Thanks for this — a Docker-based integration lab with a FakeWallet mint is a big step up from hardware-only testing, and the README does a good job delineating logic-level coverage vs QEMU/hardware-only. Review findings below, in priority order:
Nice work overall — the fake-ndsctl logging design and documenting the keyset-ID expansion workaround (modulo the padding bug above) are good touches. No approval/merge from me; just review. |
f178b45 to
80897bb
Compare
|
Thanks — re-reviewed the new head Delta review — no new findings. Both changes are correct:
Status of prior findings: the seven findings from my earlier comment (2 BLOCK / 3 RISK / 2 NIT) are still unaddressed at this head — in particular both BLOCKs ( E2E / verification note (test-infra PR — hardware video run not applicable, per project gate rules): no UI files touched, so no physical-router video evidence is required for this change. Mechanical verification performed at
Cold-review verdict: infra wiring is syntactically sound and the compose topology is well-formed, but from a review standpoint this is not merge-ready while the two BLOCK findings stand — as wired, the mint-failure suite cannot actually exercise its scenarios (it will |
|
E2E results (follow-up to review): deployed head
This PR's own environment exercised in full (
Two content fixes were applied to the branch during review:
With those, the environment builds cleanly from scratch and all three suites run green — the payment e2e inside this environment is actually the strongest payment evidence of the whole batch, since the shared lab's payment path had environment issues today (see final note). Ready for approval/merge from our side; noting for reviewers that the fake-ndsctl shim means gate operations are simulated — all payment/session/merchant logic is real. |
Two lab repairs found by running the suite for the gonuts-bump e2e:
- Dockerfile.mint pinned cdk-mintd to 0.17.6. The unpinned cargo install
now fetches 0.18.0 (released 2026-09-02), which replaced env-var
startup with a mandatory 'config init --file <toml>' flow — the mint
container exited immediately ('mintd configuration is not initialized')
and the whole lab was unrunnable. 0.17.6 (2026-08-26) is the version
the lab was green on when it landed in #362 (2026-08-27).
- README quick-start used 'compose run --rm client pytest -sv …', but the
client service's entrypoint IS pytest, so 'pytest' arrived as a test
filename: 'ERROR: file or directory not found: pytest'. Drop the
prefix.
With these, the full suite passes at this branch's head: smoke 6/6,
mint-failure 3 passed + 1 skipped, two-router 3/3.
…TokenAlreadySpent reachable (#392) * fix(wallet): bump gonuts to the #23/#24/#25 integration ref; make ErrTokenAlreadySpent reachable Pins gonuts-tollgate to 717c886 (main + #23 + #25 + #24, branch tmp/release-integration on the gonuts repo; re-pin to the tagged release when it exists) across every consuming module (root, merchant, cli, tollwallet). With the bump, three wallet-layer fixes ride into tollgate: the empty-proofs panic becomes a normal error, mint swap rejections surface verbatim, and the below-fee swap fails fast. The surfaced rejections are what finally make the ErrTokenAlreadySpent sentinel reachable: tollwallet matched only the exact string 'Token already spent', while the mint's rejection (previously swallowed entirely by gonuts) says 'inputs have already been spent'. The match is broadened (case-insensitive 'already spent' / 'already been spent') and pinned two ways: a phrasing table, and a two-layer test driving a mock mint's rejection through gonuts into the sentinel via errors.Is — which fails if either layer regresses to swallowing. Verified: gofmt/vet/build clean; root module -race testenv green (15.3s); merchant (185s), cli, tollwallet modules green. * test(cloud-lab): pin cdk-mintd 0.17.6; fix quick-start pytest invocation Two lab repairs found by running the suite for the gonuts-bump e2e: - Dockerfile.mint pinned cdk-mintd to 0.17.6. The unpinned cargo install now fetches 0.18.0 (released 2026-09-02), which replaced env-var startup with a mandatory 'config init --file <toml>' flow — the mint container exited immediately ('mintd configuration is not initialized') and the whole lab was unrunnable. 0.17.6 (2026-08-26) is the version the lab was green on when it landed in #362 (2026-08-27). - README quick-start used 'compose run --rm client pytest -sv …', but the client service's entrypoint IS pytest, so 'pytest' arrived as a test filename: 'ERROR: file or directory not found: pytest'. Drop the prefix. With these, the full suite passes at this branch's head: smoke 6/6, mint-failure 3 passed + 1 skipped, two-router 3/3. --------- Co-authored-by: Amperstrand <amperstrand@localhost> Co-authored-by: c03rad0r <1100745+c03rad0r@users.noreply.github.com>
…ate#362) * test(cloud-lab): Docker-based integration test environment Rebase of OpenTollGate#362 onto rewritten main — carries only the tests/cloud-lab/ Docker environment (2-router + mint topology: smoke payment, two-router autopay, mint-failure scenarios, fake-ndsctl shim). Dropped: deploy-backup-20260730/ (leaked secrets, incident #364), DEPENDS packaging change, go.mod churn, token-recovery binary. Original-PR: OpenTollGate#362 * fix(cloud-lab): golang:1.25 base — go.mod requires go 1.25.0 Dockerfile.tollgate pinned golang:1.24-bookworm while src/go.mod declares go 1.25.0 — the in-container build fails (exit 1). Align the base image. * docs: changelog entry for docker cloud-lab test environment --------- Co-authored-by: Amperstrand <amperstrand@users.noreply.github.com> Co-authored-by: c03rad0r <1100745+c03rad0r@users.noreply.github.com>
SEC-AUDIT T4 Review EvidenceCold cross-family review (Gate 2.5) — dispatched to Kimi family reviewer (kimi-k3, moonshot family ≠ author's deepseek/glm lane). Verdict: APPROVED (0 blocking). {
"verdict": "APPROVED",
"reviewer_model": "kimi-k3",
"blocking_findings": "0",
"summary": "Docker cloud-lab integration test suite is well-structured and safe to merge. All 18 files add a self-contained test-only environment; no production code is touched. The two hardcoded nsec keys are identical across upstream and reseller identity files, but they are (a) bech32-encoded test patterns, (b) not actually used at runtime because docker-compose.yml does NOT mount *-identities.json into the containers — the code generates a fresh random hex key via nostr.GeneratePrivateKey(). The checked-in nsec files are effectively dead fixtures. Test logic is mostly meaningful... Compose file passes docker compose config validation with and without profiles."
}Non-blocking findings (low): dead nsec fixtures not mounted; weak Docker compose validation (Gate 5 verification) — Full build (executed) — Runtime note (honest) — at the as-merged commit, Merge status — PR already merged via squash |
From net4sats/main; Dockerized 2-router + mint test environment (smoke payment, autopay, mint-failure scenarios). Part of the net4sats->OpenTollGate consolidation.