mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-26 01:12:21 +00:00
* ci: run the unit_selection.sh shard files on every event instead of only fork pull requests Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * ci: rename fork-flag to unit-flag now that it applies on every event * test: move tests/test_litellm root and small trees into tests/unit Pure renames, no content changes. Follow-up commits in this PR fix references, merge the three files that already existed in tests/unit, keep live-provider tests in tests/test_litellm and wire CI. * test: carry tests/test_litellm conftest isolation into tests/unit Callback lists, routing fallbacks, cached HTTP clients, logger state, AWS, proxy-URL and keychain env, and session-end client cleanup now reset for unit tests too. The environment isolation owns its MonkeyPatch so a test's own monkeypatch is undone before the model-cost teardown runs. * test: merge, split and prune the moved root and small-tree tests Merge batches/test_batch_utils.py and the chat_completions and messages dispatch tests into the files that already existed in tests/unit. Keep the live Gemini interactions tests, the async image-fetch format test and the OpenAI embedding scorer test in tests/test_litellm since they need real network or keys. Put test_router.py under tests/unit/test_router so the existing package no longer shadows it. Delete eight tests the audit found superseded by stronger ones kept in this move. * ci: run the moved root and small-tree tests under their legacy flags Add the misc and responses-caching-types flags to unit_selection.sh and CircleCI, extend enterprise-routing and mcp-integration, and point the legacy GHA shards, Makefile, redis-compat workflow, merge smoke manifest and change classifier at the new paths. * test: make the new tests/unit directories packages tests/unit/test_package_layout.py requires every directory to carry an __init__.py, and without one the moved and retained test_litellm_responses_bridge.py modules collide on import. * test: scope the unit socket block to tests/unit in shared sessions The GHA shards collect the legacy test-path and the unit selection in one pytest session. The unit conftest's loopback-only block leaked into legacy modules that reach the network at import. The legacy conftest now lifts the restriction at collect and setup time, and the unit conftest re-applies it when collecting its own modules. * test: give the shard-script tests their own GITHUB_OUTPUT They only passed where the runner set it. The CircleCI unit job's env allowlist drops it, so the script's redirect failed there. * test: point the router and module-deletion checks at tests/unit router_code_coverage and code_qa_check_tests only searched tests/test_litellm, so the moved router tests no longer counted. The two silent-experiment tests the audit deleted were the only direct callers of those methods; they are replaced with tests that assert the forwarded shadow request and the recursion guard. --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
54 lines
1.7 KiB
Python
54 lines
1.7 KiB
Python
"""
|
|
Static checks on docker/Dockerfile.non_root.
|
|
|
|
The non_root image is intended for deployment into hardened Kubernetes
|
|
clusters where `securityContext.runAsNonRoot: true` is enforced. The
|
|
kubelet validates non-root status by parsing the image's USER field as
|
|
an integer — a string name like "nobody" is rejected with
|
|
CreateContainerConfigError because the kubelet cannot resolve
|
|
/etc/passwd inside the image at admission time.
|
|
"""
|
|
|
|
import os
|
|
import re
|
|
|
|
import pytest
|
|
|
|
DOCKERFILE_PATH = os.path.join(
|
|
os.path.dirname(__file__),
|
|
"..",
|
|
"..",
|
|
"docker",
|
|
"Dockerfile.non_root",
|
|
)
|
|
|
|
|
|
def _final_user_directive(dockerfile_text: str) -> str:
|
|
"""Return the value of the last `USER` directive in the file."""
|
|
matches = re.findall(r"^USER\s+(\S+)\s*$", dockerfile_text, re.MULTILINE)
|
|
assert matches, "Dockerfile.non_root has no USER directive"
|
|
return matches[-1]
|
|
|
|
|
|
@pytest.mark.skipif(
|
|
not os.path.exists(DOCKERFILE_PATH),
|
|
reason="Dockerfile.non_root not present in this checkout",
|
|
)
|
|
def test_final_user_directive_is_numeric():
|
|
"""The runtime USER must be a numeric UID so kubelet's runAsNonRoot
|
|
admission check (strconv.Atoi) succeeds."""
|
|
with open(DOCKERFILE_PATH, "r", encoding="utf-8") as f:
|
|
contents = f.read()
|
|
|
|
final_user = _final_user_directive(contents)
|
|
|
|
assert final_user.isdigit(), (
|
|
f"Dockerfile.non_root final USER is {final_user!r}; must be a numeric UID "
|
|
"so Kubernetes' runAsNonRoot admission check can verify non-root status. "
|
|
"See https://kubernetes.io/docs/tasks/configure-pod-container/security-context/"
|
|
)
|
|
|
|
assert int(final_user) != 0, (
|
|
f"Dockerfile.non_root final USER is {final_user} (root); the non_root image "
|
|
"must run as a non-zero UID."
|
|
)
|