Skip to content

test(cache): cover rejected remote cache uploads - #810

Draft
wan9chi wants to merge 1 commit into
remote-cache-e2e-oidcfrom
remote-cache-e2e-rejected-uploads
Draft

wan9chi wants to merge 1 commit into
remote-cache-e2e-oidcfrom
remote-cache-e2e-rejected-uploads

Conversation

@wan9chi

@wan9chi wan9chi commented Oct 5, 2026

Copy link
Copy Markdown
Member

Motivation

With the write policy in place from #809, the e2e cases can cover the uploads the public cache service rejects. A developer running --remote-cache=read-write outside GitHub Actions, or a job for a pull request, should still see their task succeed and be told why nothing was uploaded.

Changes

  • pull_request_upload: a pull request's token doesn't satisfy the write policy. The upload gets 403, and the details show Write not permitted.
  • upload_without_token: an upload from outside GitHub Actions has no token. It gets 401, and the details show Invalid credentials.

Both tasks succeed. The snapshots come from the file backend here. The backend switch later in this stack must leave them unchanged, which shows that the emulated policy matches the service.

Stacked on #809.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

fspy benchmark

linux

dynamic/launch             change  -1.63%  [-17.11% .. +16.10%]  overhead  +288.89%
dynamic/access             change  +0.40%  [ -9.30% ..  +9.19%]  overhead   +14.35%
dynamic/access-relative    change  +0.76%  [ -3.74% ..  +5.92%]  overhead   +67.07%
dynamic/access-contended   change  -0.39%  [-16.55% .. +21.97%]  overhead   +24.79%
static/launch              change  +0.31%  [-10.74% .. +11.94%]  overhead  +654.20%
static/access              change  +1.01%  [ -6.78% .. +15.30%]  overhead +1380.91%
static/access-relative     change  -1.18%  [-16.85% ..  +2.72%]  overhead +1897.96%
static/access-contended    change  +1.04%  [ -2.15% ..  +5.35%]  overhead +1548.95%

macos

dynamic/launch             change  -0.28%  [ -4.09% ..  +3.50%]  overhead  +244.07%
dynamic/access             change  -0.35%  [ -7.19% ..  +4.23%]  overhead    +3.37%
dynamic/access-relative    change  -0.50%  [ -4.40% ..  +2.01%]  overhead  +275.21%
dynamic/access-contended   change  -8.01%  [-25.35% ..  +7.95%]  overhead    +2.98%

windows

dynamic/launch             change  -0.38%  [ -2.82% ..  +3.74%]  overhead   +27.05%
dynamic/access             change  +0.00%  [ -0.93% ..  +1.52%]  overhead    +1.18%
dynamic/access-relative    change  -0.18%  [ -0.95% ..  +0.57%]  overhead    +1.13%
dynamic/access-contended   change  -0.53%  [ -3.10% ..  +1.60%]  overhead    +1.81%

@wan9chi
wan9chi added this pull request to stack #812 October 5, 2026 05:59
@wan9chi
wan9chi removed this pull request from stack #812 October 6, 2026 02:42
@wan9chi
wan9chi added this pull request to stack #813 October 6, 2026 02:42
Add e2e cases for uploads that the backend rejects, like the public
cache service would: a token from a pull request's job, which the write
policy doesn't allow, and an upload without a token from outside GitHub
Actions. Both tasks succeed, and the run reports the upload as failed
with the backend's message.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wan9chi
wan9chi force-pushed the remote-cache-e2e-rejected-uploads branch from f5802bf to 0514599 Compare October 6, 2026 02:48

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant