mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
Adds the two stdlib-only helpers that back the maintainer approval gate, ahead of the workflows that call them. check_maintainer_approval.py parses the linked handles out of MAINTAINERS.md, folds a review list to each reviewer's latest decisive position, and exits non-zero unless a maintainer's latest position is an approval. It fails closed when the list yields no handles. alert_maintainer_change.py renders the approver-set delta between two versions of MAINTAINERS.md, and prints nothing when the set is unchanged. Landing these first lets the gate workflow, which reads both the list and the decision logic from main rather than from the pull request ref, actually execute on the pull request that introduces it. Signed-off-by: Jim Meyer <jimeyer@nvidia.com>
317 lines
16 KiB
TOML
317 lines
16 KiB
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# Test tasks (Rust + Python + TypeScript SDK)
|
|
|
|
[test]
|
|
description = "Run all tests (Rust + Python + TypeScript SDK)"
|
|
depends = [
|
|
"test:rust",
|
|
"test:python",
|
|
"sdk:ts:test",
|
|
"test:sbom",
|
|
"test:install-sh",
|
|
"test:build-env",
|
|
"test:gateway-pull-policy",
|
|
"test:e2e-image-overrides",
|
|
"test:gateway-config",
|
|
"test:e2e-parity",
|
|
"test:packaging-assets",
|
|
"test:qualification-summary",
|
|
"test:codex-security-release-range",
|
|
"test:docs-website",
|
|
"test:docs-nav",
|
|
"test:maintainer-approval",
|
|
]
|
|
|
|
["test:docs-website"]
|
|
description = "Test the docs-website sync script"
|
|
# --no-project skips installing the OpenShell package; --with supplies the test
|
|
# dependencies and the script's runtime dependency, which live outside the project env.
|
|
run = "uv run --no-project --with pytest --with pytest-asyncio --with pyyaml pytest tasks/scripts/sync_docs_website_test.py"
|
|
|
|
["test:docs-nav"]
|
|
description = "Test the docs navigation check"
|
|
run = "uv run --no-project --with pytest --with pytest-asyncio --with pyyaml pytest tasks/scripts/check_docs_nav_test.py"
|
|
|
|
["test:sbom"]
|
|
description = "Run SBOM tooling tests"
|
|
run = "uv run --no-project --with pytest pytest -o \"python_files=*_test.py\" deploy/sbom/"
|
|
hide = true
|
|
|
|
["test:install-sh"]
|
|
description = "Run focused install.sh shell tests"
|
|
run = "tasks/scripts/test-install-sh.sh"
|
|
run_windows = "echo Skipping test:install-sh: Linux glibc installer tests do not apply on Windows."
|
|
hide = true
|
|
|
|
["test:build-env"]
|
|
description = "Run build-env.sh helper shell tests"
|
|
run = "tasks/scripts/test-build-env.sh"
|
|
run_windows = "echo Skipping test:build-env: the Unix build-env.sh helper does not apply on Windows."
|
|
hide = true
|
|
|
|
["test:gateway-pull-policy"]
|
|
description = "Test development gateway image pull-policy normalization"
|
|
run = "tasks/scripts/test-gateway-pull-policy.sh"
|
|
run_windows = "echo Skipping test:gateway-pull-policy: Unix gateway scripts do not apply on Windows."
|
|
hide = true
|
|
|
|
["test:e2e-image-overrides"]
|
|
description = "Test E2E gateway and supervisor image override resolution"
|
|
run = "tasks/scripts/test-e2e-image-overrides.sh"
|
|
run_windows = "echo Skipping test:e2e-image-overrides: Unix E2E wrappers do not apply on Windows."
|
|
hide = true
|
|
|
|
["test:packaging-assets"]
|
|
description = "Run static packaging asset tests"
|
|
run = "tasks/scripts/test-packaging-assets.sh"
|
|
run_windows = "echo Skipping test:packaging-assets: Linux service and RPM assets do not apply on Windows."
|
|
hide = true
|
|
|
|
["test:qualification-summary"]
|
|
description = "Test release qualification summary generation"
|
|
run = "tasks/scripts/test-qualification-summary.sh"
|
|
run_windows = "echo Skipping test:qualification-summary: the release workflow runs on Unix hosts."
|
|
hide = true
|
|
|
|
["test:codex-security-release-range"]
|
|
description = "Test Codex Security release-range resolution"
|
|
run = "uv run --no-project --with pytest pytest -o \"python_files=*_test.py\" tasks/scripts/codex_security_range_test.py"
|
|
hide = true
|
|
|
|
["test:maintainer-approval"]
|
|
description = "Test the maintainer approval gate and change-alert tools"
|
|
run = "uv run --no-project --with pytest pytest -o \"python_files=*_test.py\" tasks/scripts/check_maintainer_approval_test.py tasks/scripts/alert_maintainer_change_test.py"
|
|
hide = true
|
|
|
|
[e2e]
|
|
description = "Run all end-to-end tests (Rust + Python + MCP)"
|
|
depends = ["e2e:rust", "e2e:python", "e2e:mcp"]
|
|
|
|
["e2e:test"]
|
|
description = "Build the current checkout and run a named host or Nix test-guest E2E suite"
|
|
run = "e2e/run.sh"
|
|
|
|
["e2e:gpu"]
|
|
description = "Run Docker GPU end-to-end tests"
|
|
depends = ["e2e:docker:gpu"]
|
|
|
|
["e2e:workloads:build"]
|
|
description = "Build local GPU workload test images and manifest"
|
|
run = "bash tasks/scripts/e2e-gpu-build-images.sh"
|
|
|
|
["test:rust"]
|
|
description = "Run Rust tests"
|
|
depends = ["rust:lockfiles:check"]
|
|
env = { OPENSHELL_TELEMETRY_ENABLED = "false" }
|
|
run = [
|
|
# Run the workspace once without openshell-server so we can run that crate
|
|
# with test-only helpers enabled.
|
|
"cargo test --workspace --exclude openshell-server",
|
|
"cargo test -p openshell-server --features test-support",
|
|
"cargo nextest run --config-file .config/nextest.toml --manifest-path examples/supervisor-middleware-content-guard/Cargo.toml",
|
|
]
|
|
run_windows = "powershell -NoProfile -ExecutionPolicy Bypass -File tasks/scripts/windows-msvc.ps1 test-precommit native"
|
|
hide = true
|
|
|
|
["test:python"]
|
|
description = "Run Python tests"
|
|
depends = ["python:proto"]
|
|
env = { UV_NO_SYNC = "1" }
|
|
run = "uv run pytest python/"
|
|
hide = true
|
|
|
|
["e2e:rust"]
|
|
description = "Run Rust CLI e2e tests against a Docker-backed gateway"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-docker.sh"
|
|
|
|
["e2e:workload:build"]
|
|
description = "Build the Docker E2E workload fixture"
|
|
run = "CONTAINER_ENGINE=docker bash tasks/scripts/e2e-build-workload.sh"
|
|
|
|
["e2e:conformance:build"]
|
|
description = "Build the standalone CLI conformance binary"
|
|
run = "if [ -z \"${OPENSHELL_CONFORMANCE_BIN:-}\" ]; then cargo build -p openshell-conformance-cli; fi"
|
|
hide = true
|
|
|
|
["e2e:cli-conformance"]
|
|
description = "Build and run the standalone CLI conformance suite against the configured gateway"
|
|
depends = ["e2e:conformance:build"]
|
|
run = [
|
|
"if [ -z \"${OPENSHELL_BIN:-}\" ]; then cargo build -p openshell-cli; fi",
|
|
"\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" run --openshell-bin \"${OPENSHELL_BIN:-$PWD/target/debug/openshell}\"",
|
|
]
|
|
|
|
["e2e:websocket-conformance"]
|
|
description = "Run focused WebSocket conformance e2e tests against a Docker-backed gateway"
|
|
run = [
|
|
"CONTAINER_ENGINE=docker bash tasks/scripts/e2e-build-workload.sh",
|
|
"e2e/with-docker-gateway.sh cargo test --manifest-path e2e/rust/Cargo.toml --features e2e-docker --test websocket_conformance",
|
|
]
|
|
|
|
["e2e:mcp"]
|
|
description = "Run MCP conformance e2e scenarios against one Docker-backed gateway (static defaults for spec 2025-11-25; set OPENSHELL_MCP_CONFORMANCE_SCENARIOS for a focused subset)"
|
|
run = "bash e2e/mcp-conformance.sh"
|
|
|
|
["e2e:nodejs"]
|
|
description = "Alias for e2e:mcp"
|
|
depends = ["e2e:mcp"]
|
|
|
|
["e2e:python"]
|
|
description = "Run Python e2e tests against a Docker-backed gateway (E2E_PARALLEL=N or 'auto'; default 5)"
|
|
depends = ["python:proto"]
|
|
env = { UV_NO_SYNC = "1", PYTHONPATH = "python" }
|
|
run = [
|
|
"CONTAINER_ENGINE=docker bash tasks/scripts/e2e-build-workload.sh",
|
|
"OPENSHELL_E2E_DOCKER_SANDBOX_IMAGE=openshell/e2e-python:dev OPENSHELL_E2E_DOCKER_SANDBOX_IMAGE_PULL_POLICY=never e2e/with-docker-gateway.sh uv run pytest -o python_files='test_*.py *_test.py' -m 'not gpu' -n ${E2E_PARALLEL:-5} e2e/python",
|
|
]
|
|
|
|
["e2e:podman"]
|
|
description = "Run Rust CLI e2e tests against a Podman-backed gateway"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-podman.sh"
|
|
|
|
["e2e:podman:ci"]
|
|
description = "Run the Podman Rust e2e targets enabled in required branch CI"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_E2E_PODMAN_TEST_SET=ci OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-podman.sh"
|
|
|
|
["e2e:oidc-pkce"]
|
|
description = "Run Linux browser PKCE and RBAC e2e tests against Keycloak and a Podman gateway"
|
|
run = [
|
|
"CONTAINER_RUNTIME=podman e2e/with-keycloak.sh env OPENSHELL_E2E_OIDC_GATEWAY=1 e2e/with-podman-gateway.sh cargo test --manifest-path e2e/rust/Cargo.toml --features e2e-oidc-pkce --test oidc_pkce",
|
|
]
|
|
|
|
["e2e:oidc-pkce:docker"]
|
|
description = "Run Linux browser PKCE and RBAC e2e tests against Keycloak and a Docker gateway"
|
|
run = [
|
|
"CONTAINER_RUNTIME=docker e2e/with-keycloak.sh env OPENSHELL_E2E_OIDC_GATEWAY=1 e2e/with-docker-gateway.sh cargo test --manifest-path e2e/rust/Cargo.toml --features e2e-oidc-pkce --test oidc_pkce",
|
|
]
|
|
|
|
["e2e:oidc-python:docker"]
|
|
description = "Run Python OIDC and workspace authorization e2e tests against Keycloak and a Docker gateway"
|
|
depends = ["python:proto"]
|
|
env = { UV_NO_SYNC = "1", PYTHONPATH = "python" }
|
|
run = [
|
|
"CONTAINER_RUNTIME=docker e2e/with-keycloak.sh env OPENSHELL_E2E_OIDC_GATEWAY=1 e2e/with-docker-gateway.sh uv run pytest -m 'not gpu' e2e/python/oidc",
|
|
]
|
|
|
|
["e2e:podman:gpu"]
|
|
description = "Run GPU e2e against a standalone gateway with the Podman compute driver"
|
|
env = { OPENSHELL_E2E_PODMAN_GPU = "1", OPENSHELL_E2E_PODMAN_TEST = "gpu", OPENSHELL_E2E_PODMAN_FEATURES = "e2e-podman-gpu" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-podman.sh"
|
|
|
|
["e2e:kubernetes"]
|
|
description = "Run Rust CLI e2e tests against an OpenShell gateway deployed on Kubernetes via Helm (set OPENSHELL_E2E_KUBE_CONTEXT to reuse a cluster; otherwise creates a local k3d cluster when k3d is installed; set OPENSHELL_E2E_KUBE_TEST=<name> to scope to one test)"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:v1alpha1"]
|
|
description = "Run Kubernetes e2e against Agent Sandbox v1alpha1"
|
|
env = { AGENT_SANDBOX_VERSION = "v0.4.6" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:agent-sandbox-versions"]
|
|
description = "Run Kubernetes e2e against Agent Sandbox v1beta1 and v1alpha1"
|
|
depends = ["e2e:conformance:build"]
|
|
run = [
|
|
"OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh",
|
|
"OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" AGENT_SANDBOX_VERSION=v0.4.6 e2e/rust/e2e-kubernetes.sh",
|
|
]
|
|
|
|
["e2e:kubernetes:isolation"]
|
|
description = "Run Kubernetes e2e with the workload network fence and separate supervisor"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:db"]
|
|
description = "Run Kubernetes e2e with all database backend scenarios (SQLite and external PostgreSQL with existingSecret)"
|
|
env = { OPENSHELL_E2E_KUBE_DB_SCENARIOS = "1" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:ha-rebalancing"]
|
|
description = "Run the Kubernetes HA rebalancing suite through Envoy against two gateway replicas and external PostgreSQL"
|
|
env = { OPENSHELL_E2E_KUBE_EXTERNAL_POSTGRES_SECRET = "openshell-ha-pg", OPENSHELL_E2E_KUBE_EXTRA_VALUES = "deploy/helm/openshell/ci/values-high-availability.yaml", OPENSHELL_E2E_KUBE_TEST = "kubernetes_ha_rebalancing", OPENSHELL_E2E_KUBERNETES_FEATURES = "e2e,e2e-host-gateway,e2e-kubernetes,e2e-kubernetes-ha", OPENSHELL_E2E_KUBE_USE_ENVOY = "1" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:credential-drivers"]
|
|
description = "Run Kubernetes e2e for provider credential storage backed by Kubernetes Secrets and Vault"
|
|
env = { OPENSHELL_E2E_CREDENTIAL_DRIVERS = "1", OPENSHELL_E2E_KUBE_TEST = "credential_drivers", OPENSHELL_E2E_KUBERNETES_FEATURES = "e2e,e2e-kubernetes,e2e-kubernetes-credential-drivers" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:workspace-managed"]
|
|
description = "Run Kubernetes e2e with managed workspace mode (auto-created per-workspace namespaces)"
|
|
env = { OPENSHELL_E2E_CREDENTIAL_DRIVERS = "1", OPENSHELL_E2E_CREDENTIAL_DRIVER = "kubernetes-secrets", OPENSHELL_E2E_KUBE_EXTRA_VALUES = "deploy/helm/openshell/ci/values-workspace-managed.yaml", OPENSHELL_E2E_KUBE_IMAGE_PULL_SECRET = "e2e-regcred", OPENSHELL_E2E_KUBE_TEST = "workspace_namespace_managed", OPENSHELL_E2E_KUBERNETES_FEATURES = "e2e,e2e-kubernetes,e2e-kubernetes-workspace-managed" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:kubernetes:workspace-operator"]
|
|
description = "Run Kubernetes e2e with operator workspace mode (pre-provisioned per-workspace namespaces)"
|
|
env = { OPENSHELL_E2E_KUBE_EXTRA_VALUES = "deploy/helm/openshell/ci/values-workspace-operator.yaml", OPENSHELL_E2E_KUBE_TEST = "workspace_namespace_operator", OPENSHELL_E2E_KUBERNETES_FEATURES = "e2e,e2e-kubernetes,e2e-kubernetes-workspace-operator" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:vm"]
|
|
description = "Start openshell-gateway with the VM compute driver and run VM e2e tests"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-vm.sh"
|
|
|
|
["e2e:gateway:no-compute-drivers"]
|
|
description = "Build and launch-check openshell-gateway without compiled compute drivers"
|
|
run = "bash e2e/no-compute-driver-gateway.sh"
|
|
|
|
["e2e:docker:external-driver"]
|
|
description = "Run Docker conformance with a driver-free gateway and external Docker driver binary"
|
|
env = { OPENSHELL_E2E_EXTERNAL_COMPUTE_DRIVER = "1", OPENSHELL_E2E_DOCKER_FEATURES = "" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-docker.sh"
|
|
|
|
["e2e:podman:external-driver"]
|
|
description = "Run Podman conformance with a driver-free gateway and external Podman driver binary"
|
|
env = { OPENSHELL_E2E_EXTERNAL_COMPUTE_DRIVER = "1", OPENSHELL_E2E_PODMAN_FEATURES = "" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-podman.sh"
|
|
|
|
["e2e:vm:external-driver"]
|
|
description = "Run VM E2E with a driver-free gateway and external VM driver binary"
|
|
env = { OPENSHELL_E2E_EXTERNAL_COMPUTE_DRIVER = "1" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-vm.sh"
|
|
|
|
["e2e:kubernetes:external-driver"]
|
|
description = "Run Kubernetes conformance with a driver-free gateway and external Kubernetes driver"
|
|
env = { OPENSHELL_E2E_EXTERNAL_COMPUTE_DRIVER = "1", OPENSHELL_E2E_KUBE_BUILD_IMAGES = "1", OPENSHELL_E2E_KUBERNETES_FEATURES = "" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-kubernetes.sh"
|
|
|
|
["e2e:docker"]
|
|
description = "Run Docker conformance and Rust e2e tests against a standalone gateway"
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-docker.sh"
|
|
|
|
["e2e:mechanistic-existing-endpoint"]
|
|
description = "Run #2821 existing inspected-endpoint auto-approval regression"
|
|
run = [
|
|
"cargo build -p openshell-cli",
|
|
"e2e/with-docker-gateway.sh bash -lc 'target/debug/openshell settings set --global --key agent_policy_proposals_enabled --value true --yes && OPENSHELL_BIN=$PWD/target/debug/openshell bash e2e/policy-advisor/existing-endpoint-auto-approve.sh'",
|
|
]
|
|
|
|
["e2e:docker:gpu"]
|
|
description = "Run GPU e2e against a standalone gateway with the Docker compute driver"
|
|
env = { OPENSHELL_E2E_DOCKER_GPU = "1", OPENSHELL_E2E_DOCKER_TEST = "gpu", OPENSHELL_E2E_DOCKER_FEATURES = "e2e-docker-gpu" }
|
|
depends = ["e2e:conformance:build"]
|
|
run = "OPENSHELL_CONFORMANCE_BIN=\"${OPENSHELL_CONFORMANCE_BIN:-$PWD/target/debug/openshell-conformance}\" e2e/rust/e2e-docker.sh"
|
|
|
|
["test:gateway-config"]
|
|
description = "Test generated local gateway TOML without starting a runtime"
|
|
run = "bash tasks/scripts/test-gateway-config.sh"
|
|
run_windows = "echo Skipping test:gateway-config: Unix gateway scripts do not apply on Windows."
|
|
hide = true
|