Repository navigation
fix(ci): boot protocol E2E on the peer-stamped custom server with preserved open bootstrap (#11535) - #11549
Merged
diegosouzapw merged 1 commit intoAug 25, 2026
Conversation
…served open bootstrap (diegosouzapw#11535) - run-protocol-clients-tests.mjs spawns scripts/dev/run-next.mjs dev (real custom server, trusted PEER_IP_HEADER stamp) instead of the bare next CLI via run-next-playwright.mjs, fixing the deterministic 403 LOCAL_ONLY on GET /api/mcp/audit from loopback; pins HOST=127.0.0.1 because under the programmatic next() entry middleware nextUrl.hostname mirrors the bind address and apiAuth.isLoopbackRequest reads it first - run-next.mjs honors OMNIROUTE_E2E_BOOTSTRAP_MODE=open by clearing INITIAL_PASSWORD/OMNIROUTE_E2E_PASSWORD/OMNIROUTE_API_KEY to empty strings AFTER the bootstrap env merge — empty string, not delete, so Next's dotenv re-read of repo .env during prepare() cannot restore a leaked credential that instrumentation would bcrypt-persist (401 green-shallow) - regression guard: tests/unit/protocol-e2e-server-stamping-11535.test.ts (4 source-contract tests, red before / green after) - changelog fragment: changelog.d/fixes/11535-protocol-e2e-peer-stamped-server.md Live validation on release/v3.8.50 @ 7790b0d: before: health 200, audit 403 LOCAL_ONLY | after: audit 200 with entries JSON, settings PATCH 200, agent card 200. Playwright webServer runner untouched.
diegosouzapw
merged commit Aug 25, 2026
700819a
into
diegosouzapw:release/v3.8.51
10 of 16 checks passed
diegosouzapw
pushed a commit
to jonlwheat2-gif/OmniRoute
that referenced
this pull request
Aug 25, 2026
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…served open bootstrap (diegosouzapw#11535) (diegosouzapw#11549) Validated in a combined 3-PR batch worktree off release/v3.8.51 tip. - Focused test: protocol-e2e-server-stamping-11535.test.ts — part of batch's 165/165 node:test run - typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity, check:docs-counts-sync — all OK - Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff Thanks for the meticulous root-causing here — three distinct issues (server flavor, HOST pin, open-bootstrap env leak) traced to exact line numbers with live-boot before/after evidence.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Freeze-aware retarget of #11535's fix to the active development branch:
release/v3.8.50is frozen, so per the parallel-cycle model this lands onrelease/v3.8.51. Cherry-picked from the validated fork branch (fix/11535-protocol-e2e-peer-stamped-server, commit3abf113) onto.51tip (ae7a843) as73fb0f6— applied cleanly, no drift in any touched file.Fixes the deterministic
Protocol Clients E2Efailure (#10049 / #11535):GET /api/mcp/auditanswered 403 LOCAL_ONLY from loopback because the harness booted a server flavour that never writes the trusted peer stamp. Two further green-shallow 401 traps surfaced while swapping boot targets; all three root causes are fixed here without relaxing any assertion and without touching the shared Playwright webServer runner.Full investigation (root causes, failed attempts, line-level before/after, red/green evidence): #11535 (comment)
Changes
1.
scripts/dev/run-protocol-clients-tests.mjs"scripts/dev/run-next-playwright.mjs"→"scripts/dev/run-next.mjs"— the real custom Node server stamps the TCP peer IP (peer-stamp.mjs:48–68, wired atrun-next.mjs:163), soLOCAL_ONLYlocality resolves instead of failing closed (management.ts:228).HOST: process.env.HOST || "127.0.0.1". Under the programmaticnext()entry, middlewarenextUrl.hostnamemirrors the bind address (run-next.mjs:83, default0.0.0.0), andapiAuth.isLoopbackRequest()readsnextUrl.hostnamefirst (apiAuth.ts:89–137) — an unpinned boot makes every request look remote and the anonymous open-bootstrap allow never fires.2.
scripts/dev/run-next.mjsOMNIROUTE_E2E_BOOTSTRAP_MODE === "open": clearsINITIAL_PASSWORD/OMNIROUTE_E2E_PASSWORD/OMNIROUTE_API_KEYto empty strings, not deletes.bootstrap-env.mjs:180–182filters empty strings — an injected""cannot survive it..envduringprepare()after this point; a deleted var gets restored andinstrumentation-node.ts:392bcrypt-persists it as a real login at startup (observed live). An existing empty var is falsy to every consumer and wins over dotenv's no-override load.3. New regression guard:
tests/unit/protocol-e2e-server-stamping-11535.test.tsFour source-contract tests (repo pattern per
dev-script-heap-limit.test.ts): stamped-server spawn target, env-contract incl. HOST pin, peer stamp wired into the custom listener, open-mode clear present + empty-string-not-delete + positioned after the merge.4.
changelog.d/fixes/11535-protocol-e2e-peer-stamped-server.md— fragment per convention.Validation on this branch (.51 tip,
73fb0f6)INITIAL_PASSWORD=CHANGEMEforced into env to simulate the CI.envleak):/api/monitoring/health→ 200GET /api/mcp/audit?limit=50&tool=omniroute_get_health→ 200{"entries":[],"total":0,"limit":50,"offset":0}— the audit block inprotocol-clients.test.ts:138–143is genuinely exercised.50harness flavour): audit 403 LOCAL_ONLY, byte-identical to the CI failure.Issue requirements (#11535)
test-e2e)bootstrap-env.mjs:176filteringprotocol-clients.test.ts:137untouchedFollow-up (intentionally not in this surgical change): once merged, drop
continue-on-errorontest-protocols-e2e(ci.yml:1327, annotated :1319–1326).