Skip to content

fix(tests): re-baseline raw-ClientSession ceiling to 13, document new SSRF-pinned carve-out, wire guard into CI (#13041) - #13046

Merged
mrveiss merged 3 commits into
Dev_new_guifrom
issue-13041
Jul 30, 2026
Merged

mrveiss merged 3 commits into
Dev_new_guifrom
issue-13041

Conversation

@mrveiss

@mrveiss mrveiss commented Jul 30, 2026

Copy link
Copy Markdown
Owner

Thinking Path

test_raw_client_session_ceiling_12992.py was failing on origin/Dev_new_gui (13 raw aiohttp.ClientSession(...) sites vs. a recorded ceiling of 12). Re-measured with the test's own AST walker (never grep -c — it over/under-counts on string literals) against a tree freshly synced to origin/Dev_new_gui at a2f788889: confirmed 13, same offender list #13041 reported.

Investigated each of #13041's three claimed "new, undocumented" offenders individually before touching anything:

So the fix is: raise the ceiling to the measured, correct value (13) and document the one genuinely new carve-out — not convert config_declared_provider.py to the pooled client, which would be a security regression.

Root cause of why this regressed unnoticed: the guard has never been collected by any CI workflow. autobot-backend/tests/** only appears in migration-gate.yml (migrations subdir only) and startup-import-smoke.yml (only test_startup_imports.py); the required "Unit & Integration Tests" check (frontend-test.yml) is entirely frontend. That gap is tracked separately as #10691 (evidence already posted there) — out of scope for a "smallest sound fix" PR to broaden. Within this PR's blast radius, the guard has zero non-stdlib dependencies (ast/pathlib only, no backend-module imports) and startup-import-smoke.yml's job already installs the full backend dependency set and is a required check — the natural, low-risk place to add exactly this one test.

What Changed

Verification

  • Re-measured with the AST walker against origin/Dev_new_gui @ a2f788889: 13 constructions, offender list matches fix(http): raw aiohttp.ClientSession ceiling regressed 12→13 (undocumented offenders, #12992) #13041 exactly.
  • pytest autobot-backend/tests/test_raw_client_session_ceiling_12992.py -v: 2 passed (walker-sanity + ceiling).
  • Negative case: temporarily set MAX_RAW_CLIENT_SESSIONS back to 12 in the working tree and re-ran — reproduced fix(http): raw aiohttp.ClientSession ceiling regressed 12→13 (undocumented offenders, #12992) #13041's exact AssertionError: 13 raw ... exceeding ... 12 failure with the same offender list, then reverted to 13. Confirms the ratchet trips at ceiling+1.
  • py_compile / flake8 --max-line-length=120 / black --check --line-length=120 on the changed test file: all clean.
  • CI-wiring evidence: built a Python 3.14 venv (matches the workflow's actions/setup-python version), installed requirements-ci.txt + pytest + editable autobot_shared (the exact steps the job runs), then ran pytest autobot-backend/tests/test_startup_imports.py autobot-backend/tests/test_raw_client_session_ceiling_12992.py together and standalone — the ceiling guard collects and passes cleanly in both cases (2 passed), confirming the new workflow step actually executes the test rather than repeating the "silently never collected" failure mode fix(http): raw aiohttp.ClientSession ceiling regressed 12→13 (undocumented offenders, #12992) #13041 is about.
  • Startup-import smoke ratio: unchanged — the new step is a separate, independent pytest invocation appended after the existing test_startup_imports.py step; test_startup_imports.py itself was not modified (350/350 passing locally against available deps, same as before this change).

Model Used

Sonnet

…fig_declared_provider.py carve-out and enforce guard in CI (#13041)
@github-actions

Copy link
Copy Markdown
Contributor

✅ SSOT Configuration Compliance: Passing

🎉 No hardcoded values detected that have SSOT config equivalents!

@mrveiss
mrveiss merged commit dbd1cce into Dev_new_gui Jul 30, 2026
41 of 42 checks passed
@mrveiss
mrveiss deleted the issue-13041 branch July 30, 2026 14:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant