From 02a4b031bcc20e975812de8e46a223c42a2aabe5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 27 Sep 2026 21:50:53 +0900 Subject: [PATCH] fix(ci): restore Pingora raw evidence failure coverage --- scripts/ci/pingora_edge_policy.py | 2 -- tests/test_pingora_edge_policy.py | 14 ++++++++++++++ 2 files changed, 14 insertions(+), 2 deletions(-) diff --git a/scripts/ci/pingora_edge_policy.py b/scripts/ci/pingora_edge_policy.py index 518ef84d3c..4c17cd809e 100644 --- a/scripts/ci/pingora_edge_policy.py +++ b/scripts/ci/pingora_edge_policy.py @@ -610,8 +610,6 @@ def _load_raw_file_bytes( return raw if encoding == "none": raise PolicyError(f"GitHub content evidence for {path} has no inline content and no verifiable oversized size") - if encoding != "base64": - raise PolicyError(f"GitHub content evidence for {path} is not a regular base64 file") encoded = payload.get("content") if not isinstance(encoded, str): raise PolicyError(f"GitHub content evidence for {path} has a malformed size or content field") diff --git a/tests/test_pingora_edge_policy.py b/tests/test_pingora_edge_policy.py index f9bc5888ea..88c68930d3 100644 --- a/tests/test_pingora_edge_policy.py +++ b/tests/test_pingora_edge_policy.py @@ -1005,6 +1005,7 @@ def test_changed_file_pagination_bound_is_provably_unreachable() -> None: ({"type": "file", "encoding": "none", "size": 1}, "no inline content"), ({"type": "file", "encoding": "none", "size": "not-an-int"}, "malformed size"), ({"type": "file", "encoding": "utf-8", "size": 1, "content": "x"}, "invalid encoding"), + ({"type": "file", "encoding": "base64", "size": 1, "content": None}, "malformed size or content"), ({"type": "file", "encoding": "base64", "size": 1, "content": "!"}, "invalid base64"), ({"type": "file", "encoding": "base64", "size": 2, "content": base64.b64encode(b"x").decode()}, "size mismatch"), ({"type": "file", "encoding": "base64", "size": 1, "content": base64.b64encode(b"\xff").decode()}, "not valid UTF-8"), @@ -1190,6 +1191,19 @@ def open_response(request: object, timeout: int) -> FakeResponse: policy._github_open_raw_bytes(url, "token", 3) +@pytest.mark.parametrize("error", [URLError("unreachable"), TimeoutError("timeout"), HTTPError("https://api.github.com", 403, "denied", {}, None)]) +def test_raw_blob_transport_failure_remains_fail_closed(monkeypatch: pytest.MonkeyPatch, error: Exception) -> None: + """Failed raw evidence requests preserve their cause without returning bytes.""" + + def fail_request(_request: object, timeout: int) -> None: + raise error + + monkeypatch.setattr(policy.github_opener, "open", fail_request) + with pytest.raises(policy.PolicyError, match="GitHub raw blob request failed") as caught: + policy._github_open_raw_bytes("https://api.github.com/repos/a/b/git/blobs/" + "a" * 40, "token", 4) + assert caught.value.__cause__ is error + + @pytest.mark.parametrize( "url", [