Skip to content

fix: wire five dark Go tests into CI and fix the two fixtures that blocked them (#708) - #709

Merged
sakibsadmanshajib merged 2 commits into
mainfrom
fix/708-wire-dark-go-tests
Aug 4, 2026
Merged

sakibsadmanshajib merged 2 commits into
mainfrom
fix/708-wire-dark-go-tests

Conversation

@sakibsadmanshajib

@sakibsadmanshajib sakibsadmanshajib commented Aug 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Issue #708 audited every Go test that can skip or is build-tag-gated and found six items never executing in CI. This PR addresses the Go side of that audit: five tests wired for real, one deliberately deferred.

Never ran, now wired

  1. TestDispatchHappyPathWritesLLMTraceAndAuditsChatRequest (apps/edge-api/internal/chat) — HIVE_TEST_DB_URL was already exported at the CI job level, but the RLS step's edge-api package list never included ./internal/chat/....
  2. Four TestTenantFallback_* tests (apps/edge-api/internal/auth) — same gap, ./internal/auth/... was also missing from that package list.
  3. TestChatCompletions_ToolCapable_AllowsTools plus four sibling tests (apps/edge-api/internal/inference) — needs no database at all (mocks LiteLLM and control-plane with httptest); never ran purely because the edge-api leg never passed -tags integration.
  4. TestTenantVisibilityIntegration (apps/control-plane/internal/catalog) — gated behind CATALOG_TEST_DB_URL, which appeared nowhere under .github/.
  5. TestProviderCRUDIntegration and TestProviderCRUDIntegration_MissingToken (apps/control-plane/internal/providers) — gated behind PROVIDERS_TEST_DB_URL, same gap.

Items 4 and 5 had never once passed

Both fixtures had a real bug that made them impossible to pass against any real schema, which is exactly why nobody had noticed:

  • TestTenantVisibilityIntegration inserted tenant_model_visibility rows for two hardcoded tenant UUIDs (a0000000-...-0001, b0000000-...-0001) that were never inserted into public.tenants. tenant_model_visibility.tenant_id has a foreign key to tenants(id), so every insert failed with insert or update on table "tenant_model_visibility" violates foreign key constraint "tenant_model_visibility_tenant_id_fkey".
  • TestProviderCRUDIntegration's raw provider_routes INSERT omitted route_id, a text primary key with no default, so every insert failed with null value in column "route_id" of relation "provider_routes" violates not-null constraint.

Both are fixture bugs, not assertion bugs. The fix is fixture setup only: seedTenant now inserts the two tenant rows (with cleanup) before any visibility row references them, and the provider_routes insert now supplies an explicit route_id (route-<slug>, derived from the test's own unique slug). No assertion was weakened, deleted, or loosened.

CI wiring

Deliberately out of scope

apps/edge-api/internal/audio/live_voice_integration_test.go is untouched. Its round trip needs a real GROQ_API_KEY and belongs in the paid live-integration lane, not this free job. Its gating is otherwise correct.

Verification

Ran against an ephemeral pgvector/pgvector:pg17 container with the full 86-migration chain applied (bootstrap SQL + every file under supabase/migrations/), via the same toolchain image CI uses.

All five newly wired test surfaces pass with explicit --- PASS lines:

--- PASS: TestTenantVisibilityIntegration (0.20s)
--- PASS: TestProviderCRUDIntegration (0.15s)
--- PASS: TestProviderCRUDIntegration_MissingToken (0.02s)
--- PASS: TestDispatchHappyPathWritesLLMTraceAndAuditsChatRequest (0.15s)
--- PASS: TestTenantFallback_NilPool_ReportsNotFound (0.00s)
--- PASS: TestTenantFallback_NilReceiver_ReportsNotFound (0.00s)
--- PASS: TestTenantFallback_NoActiveMembership_ReportsNotFound (0.03s)
--- PASS: TestTenantFallback_QueryError_ReturnsError (0.00s)
--- PASS: TestChatCompletions_ToolCapable_AllowsTools (0.07s)
--- PASS: TestChatCompletions_IncapableRoute_Rejects (0.00s)
--- PASS: TestChatCompletions_NoTools_NotBlocked (0.00s)
--- PASS: TestChatCompletions_RoutingTransient_Returns502 (0.00s)
--- PASS: TestChatCompletions_ToolCapable_UpstreamContainsTools (0.00s)

Also ran the exact package lists ci.yml now invokes for both matrix legs, against a freshly migrated database (single pass, matching real CI's fresh-container-per-job semantics):

ok  	.../apps/control-plane/internal/accounts	0.380s
ok  	.../apps/control-plane/internal/agenttask	1.708s
ok  	.../apps/control-plane/internal/egress	0.377s
ok  	.../apps/control-plane/internal/payments	0.315s
ok  	.../apps/control-plane/internal/payments/bkash	0.089s
ok  	.../apps/control-plane/internal/payments/invoices	0.025s
ok  	.../apps/control-plane/internal/payments/sslcommerz	0.091s
ok  	.../apps/control-plane/internal/payments/stripe	0.108s
ok  	.../apps/control-plane/internal/payments/stub	0.014s
ok  	.../apps/control-plane/internal/profiles	0.203s
ok  	.../apps/control-plane/internal/rag	0.562s
ok  	.../apps/control-plane/internal/tenants	0.262s
ok  	.../apps/control-plane/internal/signup	3.079s
ok  	.../apps/control-plane/internal/routing	0.121s
ok  	.../apps/control-plane/internal/litellmconfig	0.160s
ok  	.../apps/control-plane/internal/catalog	0.150s
ok  	.../apps/control-plane/internal/providers	0.129s
ok  	.../apps/edge-api/internal/artifacts	...
ok  	.../apps/edge-api/internal/rag	...
ok  	.../apps/edge-api/internal/chat	0.189s
ok  	.../apps/edge-api/internal/auth	5.991s
ok  	.../apps/edge-api/internal/inference	3.204s

No shared Supabase pooler was touched at any point.

Test plan

  • RED confirmed for items 4 and 5 before the fixture fix: FK violation on tenant_model_visibility, not-null violation on provider_routes.route_id
  • GREEN after the fixture fix, no assertions changed
  • All five items 1 to 6 (excluding the deferred audio test) show explicit --- PASS lines against a real, freshly migrated database
  • Full curated package lists ci.yml now runs for both matrix legs pass cleanly on a fresh database
  • CI=true loud-fail path added to every touched connect/skip helper, matching PR fix: point LiteLLM config sync at provider_routes.provider_model #705's precedent
  • No shared Supabase pooler used anywhere in verification
  • apps/edge-api/internal/audio/live_voice_integration_test.go left untouched and explicitly called out as deferred to the paid live-integration lane

Refs #708. Related: #701, #705.

Summary by CodeRabbit

  • Tests

    • Catalog, provider, and auth integration tests now properly initialize databases and explicitly report failures in CI when required configuration is missing, preventing silent test skips.
  • Chores

    • Enhanced CI pipeline to export database URLs for integration test execution across all services.

@cursor

cursor Bot commented Aug 4, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Aug 4, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@sakibsadmanshajib, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 26 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: eaee6b95-de91-480d-86e6-8203a8807666

📥 Commits

Reviewing files that changed from the base of the PR and between 640de78 and d83d72a.

📒 Files selected for processing (6)
  • .github/workflows/ci.yml
  • .wolf/buglog.jsonl
  • apps/control-plane/internal/catalog/catalog_integration_test.go
  • apps/control-plane/internal/providers/integration_test.go
  • apps/edge-api/internal/auth/tenant_fallback_test.go
  • apps/edge-api/internal/chat/dispatch_test.go
📝 Walkthrough

Walkthrough

CI now runs catalog, provider, chat, auth, and inference integration suites. Test helpers fail in CI when database configuration is missing. Catalog and provider fixtures now seed required database values.

Changes

Database integration coverage

Layer / File(s) Summary
Integration fixture setup
apps/control-plane/internal/catalog/catalog_integration_test.go, apps/control-plane/internal/providers/integration_test.go
Catalog tests seed tenant rows and clean them up. Provider fixtures assign unique route_id values.
CI database configuration checks
apps/control-plane/internal/catalog/catalog_integration_test.go, apps/control-plane/internal/providers/integration_test.go, apps/edge-api/internal/auth/tenant_fallback_test.go, apps/edge-api/internal/chat/dispatch_test.go
Database-backed helpers fail in CI when required URLs are missing and continue to skip locally without configuration.
CI integration test execution
.github/workflows/ci.yml, .wolf/buglog.jsonl
CI exports catalog and provider database URLs, applies the integration tag, and runs the expanded control-plane and edge-api package sets. The bug log records the corrected coverage gaps and fixtures.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related issues

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the CI wiring and fixture fixes that are the main changes in this pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/708-wire-dark-go-tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
apps/control-plane/internal/catalog/catalog_integration_test.go (1)

141-161: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

Register cleanup before setup can fail.

The tenant cleanup is registered at Line [155], after both tenant inserts and both alias inserts. If a later seed fails, t.Fatal runs before this cleanup is registered, so earlier tenant rows remain in the database. Register cleanup immediately after assigning the tenant IDs, before any seed call.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/control-plane/internal/catalog/catalog_integration_test.go` around lines
141 - 161, Move the t.Cleanup registration in the catalog integration test to
immediately after tenantA and tenantB are assigned, before seedTenant or
seedAlias runs. Keep the existing visibility-row and tenant deletion operations
unchanged so partial setup failures still clean up all seeded rows.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@apps/control-plane/internal/catalog/catalog_integration_test.go`:
- Around line 141-161: Move the t.Cleanup registration in the catalog
integration test to immediately after tenantA and tenantB are assigned, before
seedTenant or seedAlias runs. Keep the existing visibility-row and tenant
deletion operations unchanged so partial setup failures still clean up all
seeded rows.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c4b83a6d-9d79-4a0a-be8d-6e5522559241

📥 Commits

Reviewing files that changed from the base of the PR and between 7ed2079 and 640de78.

📒 Files selected for processing (6)
  • .github/workflows/ci.yml
  • .wolf/buglog.jsonl
  • apps/control-plane/internal/catalog/catalog_integration_test.go
  • apps/control-plane/internal/providers/integration_test.go
  • apps/edge-api/internal/auth/tenant_fallback_test.go
  • apps/edge-api/internal/chat/dispatch_test.go

@sakibsadmanshajib

Copy link
Copy Markdown
Owner Author

REQUEST CHANGES

Two blockers. Both are in the wiring, not in the fixture fixes. The fixture fixes themselves are correct and no assertion was weakened.

The second one matters more than it looks, because this PR's own control-plane leg went green with it present.


Blocker 1: the CI=true guard fires in the wrong step and turns a required check permanently red

apps/edge-api/internal/chat/dispatch_test.go:351 and apps/edge-api/internal/auth/tenant_fallback_test.go:31 are the only two files in this PR that carry no //go:build integration tag. They therefore compile into the plain unit step at .github/workflows/ci.yml:339:

go test -count=1 -short -race -timeout 5m ./...

That step runs before the bootstrap step at ci.yml:352 that exports HIVE_TEST_DB_URL. GitHub Actions always sets CI=true, so at that point the new guard sees an empty DSN inside CI and calls t.Fatal.

This is not hypothetical. Run 30925072277 on head 640de789, job Go tests (edge-api):

--- FAIL: TestTenantFallback_NoActiveMembership_ReportsNotFound (0.00s)
    tenant_fallback_test.go:73: HIVE_TEST_DB_URL not set in CI; this suite must not silently skip (issue #708)
--- FAIL: TestTenantFallback_QueryError_ReturnsError (0.00s)
    tenant_fallback_test.go:91: HIVE_TEST_DB_URL not set in CI; this suite must not silently skip (issue #708)
--- FAIL: TestDispatchHappyPathWritesLLMTraceAndAuditsChatRequest (0.00s)
    dispatch_test.go:54: HIVE_TEST_DB_URL not set in CI; this suite must not silently skip (issue #708)

The failure is in step 6, the plain go test. Steps 7 (bootstrap) and 8 (RLS suites) both report skipped.

Two consequences:

  1. Go tests (edge-api) is a required check, and this break is not specific to this branch. The plain step always precedes the DSN export, so after merge every PR that runs the Go suite goes red the same way.
  2. Items 1, 2 and 3 of this PR still have zero CI evidence. The step that would have run ./internal/chat/..., ./internal/auth/... and ./internal/inference/... never executed. internal/inference shows ok in the plain step, but that step passes no -tags integration, so the five TestChatCompletions_* tests did not compile in there. The PR description's --- PASS block is a local run, not this CI run.

The #705 precedent did not expose this trap because litellmconfig/sync_integration_test.go is build tagged, so it never enters the -short step at all. Copying the guard into two untagged files changed its meaning.

Smallest fix, and it maps exactly onto the existing step layout, since ci.yml:339 passes -short and the RLS step at ci.yml:423 does not:

if os.Getenv("CI") != "" && !testing.Short() {
    t.Fatal("HIVE_TEST_DB_URL not set in CI; this suite must not silently skip (issue #708)")
}

That keeps the loud failure exactly where you want it, in the RLS step, and restores the skip in the unit step. Moving the bootstrap step ahead of the unit step would also unblock it, but that pulls DB backed tests under -race and widens the change, so I would not do that here.


Blocker 2: ./internal/catalog/... collides with routing's global assertion whenever the two packages overlap

ci.yml:412 runs twelve package patterns in one invocation with no -p constraint. Go defaults -p to GOMAXPROCS, and the hosted ubuntu-24.04 runner has 4 vCPU, so up to four test binaries run concurrently against the single shared DSN exported at ci.yml:365 through ci.yml:393.

apps/control-plane/internal/routing/catalog_pricing_integration_test.go:87 scans the entire table, unfiltered:

SELECT a.alias_id, count(r.route_id)
FROM public.model_aliases a
LEFT JOIN public.provider_routes r
  ON r.alias_id = a.alias_id AND r.health_state <> 'disabled'
GROUP BY a.alias_id

and :114 asserts enabled == 1 for every alias that is not in pendingMultiRouteAliases.

The newly added catalog test inserts two model_aliases rows with no provider_routes at all (catalog_integration_test.go:148 and :149) and holds them for its whole run. The control-plane log for this head shows TestTenantVisibilityIntegration at 0.03s, so that window is tens of milliseconds wide, not microseconds. If internal/routing is scheduled against internal/catalog, routing fails with:

alias public-integ-<nano> has 0 enabled routes, want exactly 1

internal/providers has the same shape in a narrower window: the alias goes in at integration_test.go:220 and its route only at :241, and the LIFO cleanup deletes the route before the alias, opening the window a second time.

Scheduling decides whether this fires, which is the bad part. Your control-plane leg passed on this head, so a reviewer who trusts one green run merges a required check that fails intermittently, and intermittent failure on a required check teaches people to hit re-run instead of reading the log. That is the same class of blindness #708 exists to remove.

Smallest fix, one flag on ci.yml:412:

go test -tags integration -count=1 -p 1 -v ./internal/accounts/... ...

Every package in that list shares one database, so serialising them is the honest description of what they are. The cost is negligible: the whole DB suite set totals roughly eight seconds. It also covers the next package someone appends, which scoping routing's query with a test-% filter would not. Please apply the same flag to the edge-api leg at ci.yml:423, which shares one database across artifacts, rag, chat and auth.


Answers to the freshness questions, verified

  1. The database is fresh per run and per matrix leg. services: at ci.yml:288 is job scoped, and each matrix leg is a separate job on its own hosted VM, so control-plane and edge-api never share an instance and nothing survives between runs. No volume is declared. The author's earlier reused container failures are therefore not reachable from CI as configured.
  2. Within one leg, every suite shares a single database. All five env vars at ci.yml:365 to :393 point at the same $dsn. That is where blocker 2 lives.
  3. Cleanup is real and both new suites are re-runnable against a dirty database. Catalog cleans visibility rows then both tenant rows at catalog_integration_test.go:151, and seedAlias registers its own cleanup. Providers registers three cleanups, and LIFO ordering gives the correct FK order: route, then alias, then provider. ON CONFLICT (id) DO NOTHING plus nanosecond suffixed alias ids make a second run safe.

Verified with no finding

  • No assertion was weakened. The catalog diff adds two seedTenant calls and two tenant deletes, nothing else. The providers diff changes only the INSERT column list and supplies route_id. Every original check survives byte for byte.
  • ON CONFLICT (id) DO NOTHING at catalog_integration_test.go:63 is not masking a uniqueness problem. tenants.slug is UNIQUE NOT NULL per supabase/migrations/20260516_01_phase19_tenants.sql:10, but the slug is derived from the id, so a slug collision implies the same id, which the conflict target already covers.
  • Adding -tags integration to the edge-api leg pulls in exactly one previously dark file, inference/chat_completions_integration_test.go. audio/live_voice_integration_test.go sits in internal/audio, which is outside that package list, so it stays deferred as intended.
  • Items 4 and 5 are genuinely proven on this head. Job Go tests (control-plane) emits --- PASS: TestTenantVisibilityIntegration, --- PASS: TestProviderCRUDIntegration and --- PASS: TestProviderCRUDIntegration_MissingToken, with no --- SKIP and no --- FAIL anywhere in that leg.
  • Local developer runs are not broken by the guards. The toolchain service in deploy/docker/docker-compose.yml sets no CI, so the documented local command still skips rather than failing.

Nits, not blocking

  • providers/integration_test.go:239 names the value wantRouteID but never asserts routeID == wantRouteID. Either add the comparison or rename it, since the current name promises a check that is not there.
  • catalog_integration_test.go:158 deletes both tenant rows even on the path where ON CONFLICT DO NOTHING means the test did not create them, with the error discarded. Harmless against a per-job fresh database, but against a developer's shared database it removes a row the test does not own.

sakibsadmanshajib added a commit that referenced this pull request Aug 4, 2026
…st step (#709 review)

Two defects from independent review of #709.

The CI=true loud t.Fatal added for issue #708 fired in the wrong step for the two build-tag-free files (chat/dispatch_test.go, auth/tenant_fallback_test.go). They compile into the plain `go test ./... -short` step, which runs before the DSN export step and never has a DSN by design, so the guard now also checks !testing.Short() to tell that expected case apart from a real missing-DSN bug in the RLS step. litellmconfig's precedent test is build-tagged and never enters the -short step at all, which is why it did not surface this.

ci.yml's RLS step ran up to 12 package patterns under Go's default GOMAXPROCS parallelism against one shared live database. routing's catalog_pricing test scans all of model_aliases unfiltered and asserts exactly one enabled route per alias; the new catalog test briefly holds two zero-route aliases. Concurrent runs can collide. Added -p 1 to both matrix legs' RLS step invocations to force sequential execution; the DB suites cost about 8 seconds total, which is negligible next to the flakiness risk.

Also: providers/integration_test.go now asserts the route_id insert returned the value the fixture requested instead of computing and discarding it. catalog_integration_test.go's cleanup now tracks which of the two seeded tenant rows this test call actually created (ON CONFLICT DO NOTHING can no-op) and only deletes those, surfacing any cleanup error via t.Errorf instead of discarding it.

Refs #708, #709.
@sakibsadmanshajib

Copy link
Copy Markdown
Owner Author

Both defects fixed in 26b0903, pushed to this branch.

Blocker 1: loud guard firing in the wrong step

chat/dispatch_test.go and auth/tenant_fallback_test.go carry no build tag, so they compile into the plain -short step, which runs before the DSN export. The guard now reads:

if os.Getenv("CI") != "" && !testing.Short() {
    t.Fatal(...)
}

-short distinguishes "the -short step, which never has a DSN by design" from "the RLS step forgot the DSN" (a real bug). Confirmed locally: the plain go test -count=1 -short ./... step for edge-api now passes (both packages report ok, meaning t.Skip fired, not t.Fatal).

Blocker 2: parallel packages sharing one DB

Added -p 1 to both matrix legs' RLS-step go test invocations, forcing sequential execution across all 12 (control-plane) / 5 (edge-api) package patterns that share one live database.

Nits

  • providers/integration_test.go: now asserts routeID == wantRouteID instead of computing and discarding it.
  • catalog_integration_test.go: seedTenant now reports whether it actually created the row (RETURNING id against ON CONFLICT DO NOTHING); cleanup deletes only rows this test call owns, and surfaces a delete failure via t.Errorf instead of discarding it.

Verification

Local, exact command requested (docker compose --profile tools run toolchain "cd /workspace && go test ./apps/control-plane/... ./apps/edge-api/... -count=1 -tags integration -p 1", plus the plain -short step separately): all target packages pass — catalog, providers, chat, auth, inference, tenants, signup, routing, litellmconfig all ok. One unrelated failure surfaced in internal/marketplace (permission denied for table marketplace_entries) on both the pre-fix and post-fix runs; that package is untouched by this PR and is not wired into any ci.yml invocation (confirmed via grep, no marketplace string anywhere in the workflow), so it is a separate, pre-existing gap, not a regression from this change or from -p 1. Flagging it rather than fixing it since it is out of this PR's scope.

Real CI, this head (run 30926685151), Go tests (edge-api) job log:

--- PASS: TestDispatchHappyPathWritesLLMTraceAndAuditsChatRequest (0.02s)
--- PASS: TestTenantFallback_NilPool_ReportsNotFound (0.00s)
--- PASS: TestTenantFallback_NilReceiver_ReportsNotFound (0.00s)
--- PASS: TestTenantFallback_NoActiveMembership_ReportsNotFound (0.01s)
--- PASS: TestTenantFallback_QueryError_ReturnsError (0.00s)
--- PASS: TestChatCompletions_ToolCapable_AllowsTools (0.00s)
--- PASS: TestChatCompletions_IncapableRoute_Rejects (0.00s)
--- PASS: TestChatCompletions_NoTools_NotBlocked (0.00s)
--- PASS: TestChatCompletions_RoutingTransient_Returns502 (0.00s)
--- PASS: TestChatCompletions_ToolCapable_UpstreamContainsTools (0.00s)

Go tests (control-plane) job log, same head:

--- PASS: TestTenantVisibilityIntegration (0.02s)
--- PASS: TestProviderCRUDIntegration (0.02s)
--- PASS: TestProviderCRUDIntegration_MissingToken (0.00s)

Both jobs report the "go test — RLS suites" step completed (not skipped), and gh pr checks 709 shows all required checks passing on this head.

…ocked them (#708)

Issue #708 found the same failure shape #701/#705 already fixed, repeated five more times: HIVE_TEST_DB_URL-gated tests in edge-api/internal/chat and edge-api/internal/auth were never included in the RLS step's package list; edge-api/internal/inference's integration tests (no DB needed) never got -tags integration; and control-plane/internal/catalog and control-plane/internal/providers were gated behind CATALOG_TEST_DB_URL/PROVIDERS_TEST_DB_URL, neither of which was ever wired into any workflow.

The catalog and providers integration tests had never once passed against a real schema. TestTenantVisibilityIntegration inserted tenant_model_visibility rows for two hardcoded tenant UUIDs that were never inserted into public.tenants, so the FK on tenant_id could never be satisfied. TestProviderCRUDIntegration's raw provider_routes INSERT omitted route_id, a text primary key with no default, so the not-null constraint could never be satisfied. Both are fixture bugs, not assertion bugs: fixed by seeding the missing tenant rows and supplying an explicit route_id, with no assertions weakened.

CI wiring: added CATALOG_TEST_DB_URL and PROVIDERS_TEST_DB_URL to the existing ephemeral-Postgres bootstrap step (same DSN as HIVE_TEST_DB_URL/ROUTING_TEST_DB_URL/LITELLM_TEST_DB_URL); added catalog and providers to control-plane's -tags integration invocation; added -tags integration plus chat, auth, and inference to edge-api's RLS step. Added a CI=true loud t.Fatal, matching #705's precedent, to every connect/skip helper touched so a future missing env var fails the build instead of silently skipping again.

apps/edge-api/internal/audio/live_voice_integration_test.go is deliberately left untouched: its round trip needs a real GROQ_API_KEY and belongs in the paid live-integration lane, not this free job.

Verified against an ephemeral pgvector/pgvector:pg17 container with the full 86-migration chain applied: all five newly wired test surfaces pass with explicit PASS lines, and the full curated control-plane and edge-api package lists that ci.yml now runs pass cleanly on a fresh database (control-plane 12/12 ok, edge-api 5/5 ok).
…st step (#709 review)

Two defects from independent review of #709.

The CI=true loud t.Fatal added for issue #708 fired in the wrong step for the two build-tag-free files (chat/dispatch_test.go, auth/tenant_fallback_test.go). They compile into the plain `go test ./... -short` step, which runs before the DSN export step and never has a DSN by design, so the guard now also checks !testing.Short() to tell that expected case apart from a real missing-DSN bug in the RLS step. litellmconfig's precedent test is build-tagged and never enters the -short step at all, which is why it did not surface this.

ci.yml's RLS step ran up to 12 package patterns under Go's default GOMAXPROCS parallelism against one shared live database. routing's catalog_pricing test scans all of model_aliases unfiltered and asserts exactly one enabled route per alias; the new catalog test briefly holds two zero-route aliases. Concurrent runs can collide. Added -p 1 to both matrix legs' RLS step invocations to force sequential execution; the DB suites cost about 8 seconds total, which is negligible next to the flakiness risk.

Also: providers/integration_test.go now asserts the route_id insert returned the value the fixture requested instead of computing and discarding it. catalog_integration_test.go's cleanup now tracks which of the two seeded tenant rows this test call actually created (ON CONFLICT DO NOTHING can no-op) and only deletes those, surfacing any cleanup error via t.Errorf instead of discarding it.

Refs #708, #709.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant