From e441315cad3e1b8e5f7ac317eef6e74e7de821d0 Mon Sep 17 00:00:00 2001 From: Jeppe Fredsgaard Blaabjerg Date: Mon, 5 Oct 2026 09:46:42 +0200 Subject: [PATCH] test(e2e): drop firewall CA overrides along with proxy vars getTestEnv unset the proxy variables for the spawned CLI but kept the CA variables a firewall proxy sets alongside them. uv then connected to pypi.org directly while trusting only the proxy CA, so every pypi install failed with UnknownIssuer. The pypi reach test masked this with --reach-continue-on-install-errors until a Coana change made the same failure fatal during analysis. Co-Authored-By: Claude Opus 5.5 --- src/commands/fix/cmd-fix.e2e.test.mts | 6 ++++++ src/commands/scan/cmd-scan-reach.e2e.test.mts | 11 ++++++----- 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/src/commands/fix/cmd-fix.e2e.test.mts b/src/commands/fix/cmd-fix.e2e.test.mts index ac4b7f5a89..d0acab8b6f 100644 --- a/src/commands/fix/cmd-fix.e2e.test.mts +++ b/src/commands/fix/cmd-fix.e2e.test.mts @@ -27,6 +27,12 @@ function getTestEnv(apiToken: string): Record { http_proxy: undefined, https_proxy: undefined, SOCKET_CLI_API_PROXY: undefined, + // A firewall proxy (e.g. sfw in CI) also points these at its own CA, which + // then becomes the only trusted root for direct connections. + GIT_SSL_CAINFO: undefined, + PIP_CERT: undefined, + SSL_CERT_DIR: undefined, + SSL_CERT_FILE: undefined, } } diff --git a/src/commands/scan/cmd-scan-reach.e2e.test.mts b/src/commands/scan/cmd-scan-reach.e2e.test.mts index 3ca0ced0a5..d5787dac95 100644 --- a/src/commands/scan/cmd-scan-reach.e2e.test.mts +++ b/src/commands/scan/cmd-scan-reach.e2e.test.mts @@ -90,6 +90,12 @@ function getTestEnv(apiToken: string): Record { http_proxy: undefined, https_proxy: undefined, SOCKET_CLI_API_PROXY: undefined, + // A firewall proxy (e.g. sfw in CI) also points these at its own CA, which + // then becomes the only trusted root for direct connections. + GIT_SSL_CAINFO: undefined, + PIP_CERT: undefined, + SSL_CERT_DIR: undefined, + SSL_CERT_FILE: undefined, } } @@ -980,11 +986,6 @@ describe('socket scan reach (E2E tests)', async () => { // Coana v15 halts on by default. The test asserts on the ecosystem // filter, not source-file presence. '--reach-continue-on-no-source-files', - // The CI runner's network firewall blocks pypi.org, so the pypi - // pre-install step fails. Coana v15 halts on install errors by - // default; this test asserts on ecosystem-filter discovery, not - // successful installation. - '--reach-continue-on-install-errors', ], 'should only analyze pypi ecosystem when --reach-ecosystems pypi is specified', async cmd => {