Repository navigation
Add acceptance foundations: private origins, cross-platform CI and the Acme fixture - #15
Merged
Merged
Conversation
added 30 commits
October 7, 2026 23:38
…ld in the changelog
added 10 commits
October 8, 2026 04:31
…t IDs pytest exports each running test's ID as PYTEST_CURRENT_TEST, and Windows refuses an environment variable longer than 32,767 characters. The oversized case put a 64 KiB document into its generated ID, so the cross-platform tier errored on Windows at setup and teardown.
Collection now fails when a test's PYTEST_CURRENT_TEST assignment would exceed the Windows limit, so a long generated ID fails on macOS and Linux too instead of only on the Windows runner. The four tests whose oversized cases tripped it get short explicit IDs.
…atform test Create needs the connector version that the dialog's readiness check finds; clicking while the check is still running only reports that Studio is still checking and sends nothing. On the Linux CI runner the click landed inside that window, so no POST /connections ever came and the test timed out.
…on preview A test that failed before removing its platform left its credentials in the system store, so the suite's audit failed a second time for the same cause. Delete the bindings a failed test stored after it; the audit still fails when a passing test leaves one behind. The quick-integration test opened the YAML preview 5 seconds after filling the builder, but the preview appears only once the test's freshly started Studio host has analyzed the request, which the host allows 30 seconds. Wait for the preview to name the action first.
journeys.toml keyed step enablement by internal planning IDs. The table is now [capabilities], and each entry names the product capability a step waits for (acceptance-foundations, compose-operations, step-tests, and so on), one for one with the old keys and with the same values. Requirements, alternatives, skipped-step evidence, error messages and the acceptance guide use the new names; unknown capability keys are refused, and the harness comments no longer cite private planning documents.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
S6-M0 foundations for end-to-end acceptance:
firefly_weave.private_originsis the one loader every process uses for private egress and the per-purpose plain-text rules:WEAVE_PRIVATE_ORIGINS_FILE, entries{origin, purpose, networks, credentials}, one decision before every connection's first write, always-refused addresses after decoding IPv4-mapped, NAT64, 6to4 and Teredo forms, audit lines, "Development only" and "Legacy setting" labels, and the legacy-setting mapping.http-connector,event-delivery) decide private reach through C8. HTTP profile connections (weave-http@2.0.0) accepthttp://base URLs exactly likeweave-http@1.0.0: public addresses as they are, private, loopback and CGNAT ones only through C8; machine-token endpoints stay HTTPS-only.encrypted: falsefor anhttp://connection;weave connections create,readandtest, andweave connector import-openapi --target builtin, printNot encrypted: requests to http://… travel in plain text.on standard error; Studio's connection form shows a "Not encrypted" notice next to the API address.weave platform up --allow-private-origin ORIGIN(development only): records consent inplatform.jsonbefore anything is written, createsweave-local-<id>-egress, writes one entry per purpose withcredentials: bridgeandnetworksset to exactly the egress subnet, and mounts a read-only copy into the API. A changed, loosened, linked or missing file stops everyweave platformcommand; the docs give the recovery.macos-15andwindows-2022: Studio vitest, the@xplatPlaywright subset (47 tests) and a portable Python subset. Linux jobs are pinned toubuntu-24.04; the desktop Linux build keepsubuntu-22.04.studio/tests/python-path.tsresolves the interpreter per operating system (CI fails instead of skipping), and the credential-store audit works on macOS, Linux and Windows and fails when the store is unavailable.scripts/acceptance.py(prepare, up, run, collect, scan, down),evidence.schema.jsonand the canary scan (fails closed on unreadable directories),journeys.tomlstep enablement,versions.toml, the Acme API fixture, journey J0 with redacted failure output, and the quick-integration test moved from jsonplaceholder to the Acme fixture. A run fails when an enabled step has no passing test. The newAcceptanceworkflow runs theprprofile onubuntu-24.04with container egress blocked.tests/unit/test_release_versions.py, andupgrades.mdrows for alpha13 and alpha14.C8 loader API (
firefly_weave.private_origins)Purpose(the ten C8 purposes),Credentials(none | loopback | bridge),PurposeRule(schemes, plaintext, connector, public_plaintext),PURPOSES,LEGACY_SETTINGS,ENV_FILE = "WEAVE_PRIVATE_ORIGINS_FILE",FORMAT = "weave/private-origins-v1",PLATFORM = "local-development",DEVELOPMENT_ONLY,LEGACY_SETTING,MAX_FILE_BYTES.PrivateOriginsInvalid(ValueError)(the process must not start),PrivateOriginDenied(ValueError)with.reason.PrivateOrigin(origin, purpose, networks, credentials, source="file" | "legacy", setting=None, plaintext_networks=None)with.label;PrivateOrigins(entries, platform, file_sha256)with.empty(),.for_purpose(),.match(),.permits_plaintext(),.check(purpose, url, addresses, *, plaintext=None, sends_credentials=False, local=is_local_address),.with_entries(),.with_legacy(purposes, networks, *, setting, plaintext_networks=None).canonical_origin,address,embedded_ipv4,always_denied,is_private,is_local_address,parse,read_file,render,load,install,active,installed.firefly_weave.sdk.platform_origins(FILE,COMPOSE,CONTAINER_PATH,requested,prepare,verified,summary, …) is how other lanes add their own entries: readverified(state), callPrivateOrigins.with_entries, writerender(...)and updatefile_sha256.Behavior changes for the next release notes
weave-http@1.0.0) and signed webhooks keep plain HTTP to public addresses, with or without credentials, and every existing check (allowlist, DNS pinning, peer check, redirect rules, caps).WEAVE_HTTP_PRIVATE_NETWORKSbecomes a legacy setting mapped to the private-origin policy with a startup warning and the same reach; CGNAT addresses still need an explicit network entry, and100.100.100.200stays refused.http://base URLs and warn that traffic is not encrypted.encryptedfield. CLIs and SDKs from 0.1.0a14 cannot readweave connections testanswers for HTTP connections from an upgraded server: upgrade them together with the server (recorded inCHANGELOG.md).CHANGELOG.mdanddocs/operations/configuration.md).Testing
Verified locally (macOS, Python 3.13 locally; CI runs 3.12):
scripts/check.py(offline gate: source coverage, docs and docs site, ruff, mypy, unit and contract tests, both workers' gates, artifact checks):All requested checks passed.on the head commit.WEAVE_E2E_*).tests/integration/test_http_connector.py,tests/integration/connectors/test_plain_http_acme.py): 22 passed.scripts/acceptance.py --profile pragainst a real Docker platform on Colima, on the head commit: all six stages passed; J0's enabled steps passed or are partial only for checks owned by unmerged milestones; the quick-integration test passed against the Acme fixture; secret scan 0 hits; no resources left.Proven only by CI on this PR:
macos-15andwindows-2022(Studio vitest, the@xplatsubset, the portable Python subset), including the Windows interpreter path, the Windowscmdkeyaudit and Studio tests that used to skip silently on Windows.Acceptanceworkflow onubuntu-24.04with container egress blocked by iptables, the Secret Service audit throughgnome-keyring, and a cold image cache (local runs were warm and did not block egress).Documentationand the fourDesktop installerstargets.