Skip to content

test(e2e): drop firewall CA overrides along with proxy vars - #1575

Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 1 commit into
v1.xfrom
jfblaa/e2e-drop-sfw-ca-env
Oct 5, 2026
Merged

Jeppe Fredsgaard Blaabjerg (jfblaa) merged 1 commit into
v1.xfrom
jfblaa/e2e-drop-sfw-ca-env

Conversation

@jfblaa

@jfblaa Jeppe Fredsgaard Blaabjerg (jfblaa) commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

LLM Description written by Claude Code:claude-opus-5-5

Fixes the e2e failure blocking #1574 (Coana 15.11.6).

In CI, sfw-free sets both proxy variables and CA variables (SSL_CERT_FILE, SSL_CERT_DIR, PIP_CERT, GIT_SSL_CAINFO) pointing at its own CA. The e2e getTestEnv helpers unset only the proxy variables, so uv reached pypi.org directly while trusting only the sfw CA, and every pypi install failed with invalid peer certificate: UnknownIssuer. The helpers now unset the CA variables too.

The pypi reach test had worked around this with --reach-continue-on-install-errors, attributing it to a runner firewall blocking pypi.org. Coana 15.11.6 no longer reuses the pre-install venv during analysis, so the same failure became a fatal analysis error. The flag is removed so the test covers a real install again.

Reproduced in an Ubuntu 24.04 container with sfw-free 1.15.0 and uv 0.12.15: same error with the proxy unset and CA vars kept; install succeeds with both unset.

🤖 Generated with Claude Code


Note

Low Risk
Test-only environment and flag changes; no production CLI behavior.

Overview
E2E subprocess env helpers in fix and scan reach tests now clear CI firewall CA variables (GIT_SSL_CAINFO, PIP_CERT, SSL_CERT_DIR, SSL_CERT_FILE) in addition to proxy vars, so direct PyPI/API traffic uses normal system trust roots instead of only the sfw CA.

The mixed-ecosystem pypi reach test drops --reach-continue-on-install-errors so it again requires a successful PyPI install, now that the CA fix addresses the prior UnknownIssuer failures (and Coana 15.11.6 treats install errors as fatal during analysis).

Reviewed by Cursor Bugbot for commit e441315. Configure here.

getTestEnv unset the proxy variables for the spawned CLI but kept the
CA variables a firewall proxy sets alongside them. uv then connected
to pypi.org directly while trusting only the proxy CA, so every pypi
install failed with UnknownIssuer. The pypi reach test masked this
with --reach-continue-on-install-errors until a Coana change made the
same failure fatal during analysis.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) merged commit f3b43e4 into v1.x Oct 5, 2026
16 checks passed
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) deleted the jfblaa/e2e-drop-sfw-ca-env branch October 5, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants