test(opencode): verify request URL and sent HTTP status independently of UI rendering - #2539
Conversation
Preserve real CLI URL assertions and require the stub to have written 200 or 404. The inherited stderr wording assertion raced fixture cleanup on busy hosts; this does not change any production timeout, retry or security gate. Co-Authored-By: Claude Code <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head COMMENT review for b6d9cdaf0a4afc8f7429afbe7a713dc5888ad0c5 against main@37b10243cec3d160ecc9c1be75c71428b160a703. The two-file test-only delta keeps the real installed CLI and tracked provider configuration, records the response only after the stub writes it, and separates route/sent-status evidence from timing-sensitive terminal rendering. /v1/chat/completions must receive sent 200 and the bare origin must request /chat/completions with sent 404. I found no source-backed blocker in the claimed boundary. This does not prove client receipt, rejection, error propagation, or an end-to-end model verdict, as the PR states. Four hosted workflows are queued and no qualifying independent approval exists; COMMENT only.
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head integration review for 50fe7a76b25e3b550177b45ee9b5fc8762731196 (tree fb23daab06284442385e46e255f6d6c7c2ed21a4). The prior retarget plus empty commit did not carry the security/quality base tree: Trivy still found the two PyO3 fixture advisories, and a warning-fatal #2531-only integration exposed 25 HTTPError/preflight/metadata/sandbox/Strix failures. The ordinary two-parent repair preserves prior #2539 head 62f37979… and integrates current #2530 ef014b9c…, whose latest provenance commits have zero tree delta. Effective diff remains the original two files. Focused former-failure set: 462 passed, 2 skipped. Full Python 3.14 warning-fatal suite: 5,292 passed, 5 skipped, 40 subtests. git diff --check is clean. COMMENT only; the PR correctly remains Draft until #2530 protected merge, base reconciliation, fresh exact-head hosted checks, and independent approval.
|
RCA and repair published at exact head |
Inherited verification failure
The route test introduced by 9c6d053 observed the real CLI request URL but also required not found to be rendered before fixture cleanup. On a busy host a whole-suite run failed that display assertion despite observing the expected unserved /chat/completions URL. The two cases passed independently, showing the UI timing dependency rather than a proved route defect.
Narrow repair and scope
Record the stub status only after its HTTP response is written. Keep real installed-CLI URL assertions: shipped config requests /v1/chat/completions with sent200; bare origin requests /chat/completions with sent404. The pinned error body remains unchanged. No production timeout, retry, sanitizer, provider selection or security gate changes.
This proves requested URL and server-sent status only. It does NOT prove that the CLI consumed/rejected404, propagated an error, or completed an end-to-end model verdict. Return-code/error-consumption evidence is not claimed. Noema metadata repair remains a separate diff.
Evidence
Exact head b6d9cda on base37b10243cec3d160ecc9c1be75c71428b160a703.
RCA: docs/doctoring/gateway-route-proof-not-cli-rendering-20260930.md.
Developer experience: a route binding regression is measured at the actual HTTP boundary rather than racing terminal rendering.
User experience: no product change, approval or live provider recovery is claimed.
🤖 Generated with Claude Code
Stack repair (2026-09-30)
Retargeted from
main@37b10243cec3d160ecc9c1be75c71428b160a703to canonical security prerequisite #2531 (codex/security-baseline-final-20260930@d1aa3659fca527a6c7330151f3ab4df3d7578391). The semantic source tree remains unchanged fromb6d9cdaf0a4afc8f7429afbe7a713dc5888ad0c5. A single empty fast-forward commit62f3797982e4d137d9914c04d190a355d0e9b50arefreshed Checks on the new base; no force update, approval, or merge was performed. Prior Python Security/Trivy failures were inherited from the vulnerable PyJWT/PyO3 base and are not current-head GREEN evidence. Fresh mergeability and hosted Checks are required on the new stack.Current quality-successor integration — 2026-09-30
The prior base retarget plus empty check-refresh commit did not integrate the base tree. Exact-head Security run 36710179694 therefore still scanned vulnerable PyO3 fixture evidence, while the first warning-fatal local integration against #2531 exposed 25 failures in the separately owned HTTPError lifecycle, preflight, metadata, sandbox, and Strix evidence contracts.
The branch now carries the current #2530 successor by an ordinary two-parent commit and targets that same prerequisite branch.
50fe7a76b25e3b550177b45ee9b5fc8762731196fb23daab06284442385e46e255f6d6c7c2ed21a462f3797982e4d137d9914c04d190a355d0e9b50aand current fix(ci): integrate parser, security, response, and coverage gates #2530 headef014b9c877bd8b64733c630210ad155cde8a552063eeefa…; the exact integrated tree was therefore verified without reusing stale run conclusionsgit diff --check: cleanThis dependent PR is Draft / Proposed until #2530 merges through ordinary protected flow, the base is reconciled to protected
main, fresh exact-head hosted Checks are terminal, and a qualifying independent approval exists. Local GREEN is not merge authorization.