Repository navigation
test(e2e): drop firewall CA overrides along with proxy vars - #1575
Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 1 commit intoOct 5, 2026
Merged
Conversation
getTestEnv unset the proxy variables for the spawned CLI but kept the CA variables a firewall proxy sets alongside them. uv then connected to pypi.org directly while trusting only the proxy CA, so every pypi install failed with UnknownIssuer. The pypi reach test masked this with --reach-continue-on-install-errors until a Coana change made the same failure fatal during analysis. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Oskar Haarklou Veileborg (BarrensZeppelin)
approved these changes
Oct 5, 2026
Jeppe Fredsgaard Blaabjerg (jfblaa)
deleted the
jfblaa/e2e-drop-sfw-ca-env
branch
October 5, 2026 07:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes the e2e failure blocking #1574 (Coana 15.11.6).
In CI, sfw-free sets both proxy variables and CA variables (
SSL_CERT_FILE,SSL_CERT_DIR,PIP_CERT,GIT_SSL_CAINFO) pointing at its own CA. The e2egetTestEnvhelpers unset only the proxy variables, souvreached pypi.org directly while trusting only the sfw CA, and every pypi install failed withinvalid peer certificate: UnknownIssuer. The helpers now unset the CA variables too.The pypi reach test had worked around this with
--reach-continue-on-install-errors, attributing it to a runner firewall blocking pypi.org. Coana 15.11.6 no longer reuses the pre-install venv during analysis, so the same failure became a fatal analysis error. The flag is removed so the test covers a real install again.Reproduced in an Ubuntu 24.04 container with sfw-free 1.15.0 and uv 0.12.15: same error with the proxy unset and CA vars kept; install succeeds with both unset.
🤖 Generated with Claude Code
Note
Low Risk
Test-only environment and flag changes; no production CLI behavior.
Overview
E2E subprocess env helpers in fix and scan reach tests now clear CI firewall CA variables (
GIT_SSL_CAINFO,PIP_CERT,SSL_CERT_DIR,SSL_CERT_FILE) in addition to proxy vars, so direct PyPI/API traffic uses normal system trust roots instead of only the sfw CA.The mixed-ecosystem pypi reach test drops
--reach-continue-on-install-errorsso it again requires a successful PyPI install, now that the CA fix addresses the priorUnknownIssuerfailures (and Coana 15.11.6 treats install errors as fatal during analysis).Reviewed by Cursor Bugbot for commit e441315. Configure here.