From f576d94c8c3eb8689cbcf6c01aba6ee39de25f54 Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Tue, 19 May 2026 22:23:54 -0700 Subject: [PATCH] =?UTF-8?q?ci(proxy-mgmt-behavior):=20diag=20=E2=80=94=20r?= =?UTF-8?q?un=20world-seed=20test=20first=20+=20bump=20max-failures?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Third CI run failed identically: seeded PROXY_ADMIN actor's auth resolves to ``user_id=None`` even though the DB row has the right ``user_id``. The suite was aborting at maxfail=10 inside test_key_delete, so test_world_seed (which would tell us whether the seed itself is reachable) never ran in CI. Two diagnostic moves on this push, no behavior change: * Rename ``test_world_seed.py`` → ``test_aaa_world_seed.py`` so it's the first collected file. If it passes in CI we know the seed is fine and the bug lives downstream; if it fails the same way the bug is in the auth resolution path. * Bump ``max-failures`` to 200 for this workflow so we see the full failure surface instead of stopping at the first cascading setup error. Will tighten back down once the suite is green. Adds one new test ``test_proxy_admin_actor_can_create_keys_for_others`` that explicitly exercises the PROXY_ADMIN bypass via /key/generate with an explicit user_id — the same shape the matrix setup helper uses but without the matrix machinery muddying the diagnostic. --- .../test-unit-proxy-mgmt-behavior.yml | 4 ++++ ...t_world_seed.py => test_aaa_world_seed.py} | 21 +++++++++++++++++++ 2 files changed, 25 insertions(+) rename tests/proxy_behavior/management/{test_world_seed.py => test_aaa_world_seed.py} (60%) diff --git a/.github/workflows/test-unit-proxy-mgmt-behavior.yml b/.github/workflows/test-unit-proxy-mgmt-behavior.yml index e73997323a4..38b606901ae 100644 --- a/.github/workflows/test-unit-proxy-mgmt-behavior.yml +++ b/.github/workflows/test-unit-proxy-mgmt-behavior.yml @@ -29,6 +29,10 @@ jobs: # so the cost of disabling parallelism here is negligible. workers: 0 reruns: 0 + # Don't abort early — first CI runs need the full failure surface so we + # can correlate setup-helper failures (one bad fixture cascades to N + # tests) vs. real per-scenario failures. Will tighten back down later. + max-failures: 200 enable-postgres: true artifact-name: proxy-mgmt-behavior timeout-minutes: 15 diff --git a/tests/proxy_behavior/management/test_world_seed.py b/tests/proxy_behavior/management/test_aaa_world_seed.py similarity index 60% rename from tests/proxy_behavior/management/test_world_seed.py rename to tests/proxy_behavior/management/test_aaa_world_seed.py index 5b6abb12d1c..5c8afb03a43 100644 --- a/tests/proxy_behavior/management/test_world_seed.py +++ b/tests/proxy_behavior/management/test_aaa_world_seed.py @@ -35,3 +35,24 @@ async def test_each_actor_can_self_info(actor, proxy_client, world): f"{actor.value}: /key/info returned the wrong user_id " f"(got {info.get('user_id')!r}, expected {seeded.user_id!r})" ) + + +async def test_proxy_admin_actor_can_create_keys_for_others(proxy_client, world): + """Diagnostic: the seeded PROXY_ADMIN actor must be able to /key/generate + a key for another user. If this fails, the user_role is not propagating + through user_api_key_auth → the actor's auth context disagrees with the + DB row, and the cause is elsewhere in the auth stack (not the seed).""" + seeder = world.keys[Actor.PROXY_ADMIN] + target_user_id = world.keys[Actor.OWNER].user_id + + resp = await proxy_client.post( + "/key/generate", + headers={"Authorization": f"Bearer {seeder.cleartext}"}, + json={"key_alias": "diag-proxy-admin-seeder", "user_id": target_user_id}, + ) + assert resp.status_code == 200, ( + f"PROXY_ADMIN-seeded actor can't create keys for others: " + f"{resp.status_code} {resp.text}\n" + f" seeder user_id: {seeder.user_id}\n" + f" target user_id: {target_user_id}" + )