mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-08-08 04:08:06 +00:00
* ci: run the whole test tree and make the plugin-safety job assert something real The unit-tests CI job ran an explicit 24-file allowlist that had rotted: 63 of 90 test files (display, vegas, store manager, web API, web_interface) never ran on a PR. The job now runs all of test/ (minus test/plugins, which the plugin-safety job owns) so new test files are enrolled by default and any exclusion needs a visible, commented --ignore. The plugin-safety job was a green no-op: plugins/ is empty in CI, so every test skipped with 'Manifest not found'. It now renders a bundled deterministic fixture plugin (test/fixtures/plugins/ci-fixture-plugin, golden images included for all 8 default sizes) via LEDMATRIX_PLUGINS_DIR, and sets LEDMATRIX_REQUIRE_PLUGINS=1 so discovering zero plugins fails loudly instead of skipping green. The per-plugin suites document that they target dev machines with real plugins installed. Coverage is now measured and enforced in exactly one place — the CI unit-tests step (--cov=src --cov=web_interface --cov-fail-under=45, from a measured 47% baseline). pytest.ini previously declared --cov-fail-under=30 but CI always passed --no-cov, so the gate had never run anywhere; local pytest is now coverage-free and fast. Enabling the 63 unenrolled files surfaced three cases of test rot, fixed here: test_display_controller_vegas_tick.py could not collect without the hardware rgbmatrix module (now uses the emulator convention), the state-reconciliation unrecoverable-cache tests broke when production added the is_plugin_uninstalled tombstone check (bare Mock returned truthy), and test_get_system_status assumed the optional psutil dependency (now installed via requirements-test.txt and guarded by importorskip). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * test: replace can't-fail tests with real assertions test_font_manager.py was 5 of 6 tests shaped as 'try: call(); assert True / except: assert True' — running in CI while unable to fail on any regression. Rewritten against the real FontManager API and the bundled assets/fonts: returned font types, cache-hit identity, distinct entries per size, default-font fallback for unknown families and corrupt files (recorded in failed_loads), BDF native-size reading, text measurement, and cache lifecycle. test_display_manager.py's test_draw_text ended in 'assert True'; it now renders onto a known-black canvas and asserts pixels were actually lit — which required un-breaking the fixture's freetype MagicMock so draw_text's isinstance check doesn't silently swallow the draw. test_display_controller.py carried a permanently-skipped test whose skip reason already declared it redundant; deleted. Both display test files now set EMULATOR=true before importing display_manager (the same convention as test_display_dirty_tracking.py) so they collect standalone instead of depending on which test module imports display_manager first. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * test: cover the untested fragile logic (compatibility gate, secrets, config merges, durations, skin cards) New unit tests for pure or filesystem-only logic that previously had zero direct coverage: - test_compatibility.py: the semver install gate (parse_semver suffix handling, every range operator, TRUSTWORTHY_FLOOR behavior for cores reporting untrustworthy versions, 'more restrictive wins', and the malformed-manifest shapes that used to raise). - test/web_interface/test_secret_helpers.py: the canonical x-secret helpers — find/separate/mask/remove, array-item secrets, no input mutation, and a separate->recombine round-trip. - test/web_interface/test_api_v3_helpers.py: the module-level helpers behind the plugin config save endpoint (_is_plugin_update_available, _coerce_to_bool including the int==1 quirk, deep_merge including its shared-subtree shallowness, _parse_form_value, dotted-key-aware _get_schema_property/_set_nested_value). - test_base_plugin_duration.py: get_display_duration's full coercion ladder (instance attr -> config -> 15.0), including the bool-is-int quirk where display_duration=True means one second. - test_config_manager_secrets.py: the secrets round-trip — deep-merge on load, strip on save, group pruning, the load fast path — and two characterized sharp edges marked SUSPECTED BUG: an unreadable secrets file at save time writes secrets into config.json in plaintext, and a same-mtime-same-size content swap is served stale. - test_schema_manager_merge.py: merge_with_defaults branch behavior (None replacement vs falsey preservation, dict-vs-scalar mismatches, arrays replaced wholesale, defaults never mutated). - test_skin_system.py (extended): render_skin_card shares _render_game's 3-strike counter but never resets it on success — the asymmetry is pinned in both directions, along with card fallthrough and the disable interaction between the two paths. Suspected bugs are characterized, not fixed — each carries a comment so a future behavior change is deliberate rather than accidental. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * test: add drift guards for cross-file contracts Three guard suites that pin contracts spanning multiple files, where one side changing unilaterally breaks the other silently: - test_version_comparison_consistency.py: the repo's four version comparators (compatibility.parse_semver, api_v3's packaging-based _is_plugin_update_available, store_manager update_plugin's raw string equality, skin_runtime._major) answer differently on the same inputs. A table pins each one's verdict; update_plugin is driven through its real code path to show the SUSPECTED BUGs: 'v1.2.0' vs '1.2.0' triggers a full reinstall the UI calls unnecessary, and a locally-ahead plugin gets downgraded. A pairwise-ordering check keeps parse_semver agreeing with packaging on plain X.Y.Z. - test/web_interface/test_secret_separation_parity.py: api_v3.py carries three inline copies of find_secret_fields/separate_secrets that lack the canonical module's array-item support. The copy count is asserted exact (it may only go down; new copies must import src/web_interface/secret_helpers), the missing-array-support gap is asserted so it can't grow silently, and the canonical behavior that migration will adopt is documented executably. - test_discovery_path_contract.py: the three 'where is plugin X' resolvers (PluginManager discovery, StoreManager._find_plugin_path, SchemaManager.get_schema_path) agree on the configured directory, and their divergent fallback chains are characterized. Also pins the .standalone-backup- naming contract shared by store rollback and discovery, and _resolve_skin_target's path-traversal rejection. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * test: address review feedback — fixture lifecycle, test names, ClassVar - ci-fixture-plugin: call display_manager.clear() before rendering (per plugin guidelines — the fixture should model a well-behaved plugin), add a class docstring, and document why Pillow is deliberately not pinned in its requirements.txt (core dependency; harness installs nothing). - Rename two tests whose names contradicted their assertions: test_unparseable_core_version_is_compatible -> test_unparseable_core_with_high_floor_is_blocked, and test_unreadable_secrets_file... -> test_corrupt_secrets_file... - Annotate TestGetSchemaProperty.SCHEMA as ClassVar (RUF012). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * ci: allow manual test.yml runs via workflow_dispatch Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * fix: unify version comparison, refuse secret-leaking saves, reset skin strikes on card success Fixes the three suspected bugs this PR's characterization tests pinned, flipping those tests to assert the corrected behavior: - plugins/store: ONE shared update comparator. New compatibility.is_update_available() (PEP 440 via packaging) is now used by both the web UI's update badge (api_v3._is_plugin_update_available is a thin alias) and store_manager.update_plugin's reinstall decision. Previously update_plugin used raw string equality: 'v1.2.0' vs '1.2.0' triggered a full reinstall the UI called unnecessary, and a locally- ahead plugin (2.0.0 installed, registry 1.9.0) was silently DOWNGRADED. Now equivalent spellings skip the reinstall and locally-ahead versions are never downgraded; unparseable versions still reconcile by reinstalling from the registry. - config: save_config and save_config_atomic now refuse (ConfigError) when config_secrets.json exists but cannot be loaded. Both previously proceeded without stripping, writing the merged secrets into config.json in plaintext. The shared _load_secrets_for_save() helper raises with an actionable message instead; a missing secrets file is still fine (nothing to strip), and _migrate_config's catch-all keeps boot resilient. - skins: render_skin_card resets _skin_failures on both success paths (vegas card returned, or mode renderer handled), mirroring _render_game. Transient card failures no longer accumulate across a session until they permanently disable a working skin. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh * fix: harden shared comparator edges from review - is_update_available: reject truthy non-string versions (a malformed manifest can carry a number; packaging raises TypeError on those) by surfacing the mismatch instead of raising. - store_manager.update_plugin: drop the truthiness gate around the comparator so a missing version on either side follows the shared 'no update' verdict, keeping the store consistent with the UI badge; a missing manifest still uses the reinstall recovery path. - config_manager._load_secrets_for_save: catch only expected read/parse failures (OSError/ValueError/RecursionError) so implementation bugs propagate as themselves, and log with traceback. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh --------- Co-authored-by: Claude <noreply@anthropic.com>
272 lines
11 KiB
Python
272 lines
11 KiB
Python
"""
|
|
Tests for src/plugin_system/compatibility.py — the "can this plugin run on
|
|
this core?" gate used by both the plugin loader (advisory) and the store
|
|
manager (blocking at install/update time).
|
|
|
|
This module had zero direct test coverage despite guarding every install.
|
|
These tests pin the documented contract: refuse only on evidence, resolve
|
|
every uncertain case (unparseable versions, missing fields, untrustworthy
|
|
core) to compatible.
|
|
"""
|
|
|
|
import pytest
|
|
|
|
from src.plugin_system.compatibility import (
|
|
TRUSTWORTHY_FLOOR,
|
|
parse_semver,
|
|
_parse_strict,
|
|
_satisfies_range,
|
|
satisfies_compatible_versions,
|
|
declared_min_version,
|
|
check,
|
|
)
|
|
|
|
|
|
class TestParseSemver:
|
|
def test_plain_triplet(self):
|
|
assert parse_semver("1.2.3") == (1, 2, 3)
|
|
|
|
def test_leading_v_tolerated(self):
|
|
assert parse_semver("v3.2.1") == (3, 2, 1)
|
|
|
|
def test_prerelease_suffix_stripped(self):
|
|
# "3.2.0-rc1" must NOT parse as (3, 2, 1) — a release candidate must
|
|
# not rank above its own release.
|
|
assert parse_semver("3.2.0-rc1") == (3, 2, 0)
|
|
|
|
def test_build_suffix_stripped(self):
|
|
# "3.2.0+build42" must NOT parse as (3, 2, 42).
|
|
assert parse_semver("3.2.0+build42") == (3, 2, 0)
|
|
|
|
def test_two_part_version_pads_zero(self):
|
|
assert parse_semver("1.2") == (1, 2, 0)
|
|
|
|
def test_one_part_version_pads_zeros(self):
|
|
assert parse_semver("2") == (2, 0, 0)
|
|
|
|
def test_extra_parts_ignored(self):
|
|
assert parse_semver("1.2.3.4") == (1, 2, 3)
|
|
|
|
def test_non_string_returns_none(self):
|
|
assert parse_semver(None) is None
|
|
assert parse_semver(123) is None
|
|
assert parse_semver((1, 2, 3)) is None
|
|
|
|
def test_garbage_with_no_digits_is_lenient_zero(self):
|
|
# Documented leniency: digit-scraping yields (0, 0, 0) for pure
|
|
# garbage. Fine for a floor (0.0.0 never blocks), wrong for ranges —
|
|
# which is why ranges go through _parse_strict instead.
|
|
assert parse_semver("garbage") == (0, 0, 0)
|
|
|
|
def test_whitespace_stripped(self):
|
|
assert parse_semver(" 1.2.3 ") == (1, 2, 3)
|
|
|
|
|
|
class TestParseStrict:
|
|
def test_accepts_real_versions(self):
|
|
assert _parse_strict("1.2.3") == (1, 2, 3)
|
|
assert _parse_strict("v1.2.3-rc1") == (1, 2, 3)
|
|
assert _parse_strict("2.0") == (2, 0, 0)
|
|
|
|
def test_rejects_garbage(self):
|
|
assert _parse_strict("not-a-version") is None
|
|
assert _parse_strict("") is None
|
|
|
|
def test_rejects_non_string(self):
|
|
assert _parse_strict(None) is None
|
|
|
|
|
|
class TestSatisfiesRange:
|
|
CORE = (3, 1, 0)
|
|
|
|
@pytest.mark.parametrize("spec,expected", [
|
|
(">=3.0.0", True),
|
|
(">=3.1.0", True),
|
|
(">=3.2.0", False),
|
|
("<=3.1.0", True),
|
|
("<=3.0.9", False),
|
|
(">3.0.9", True),
|
|
(">3.1.0", False),
|
|
("<3.2.0", True),
|
|
("<3.1.0", False),
|
|
])
|
|
def test_comparison_operators(self, spec, expected):
|
|
assert _satisfies_range(self.CORE, spec) is expected
|
|
|
|
def test_tilde_allows_patch_only(self):
|
|
# ~3.1.0 means >=3.1.0, <3.2.0
|
|
assert _satisfies_range((3, 1, 5), "~3.1.0") is True
|
|
assert _satisfies_range((3, 2, 0), "~3.1.0") is False
|
|
assert _satisfies_range((3, 0, 9), "~3.1.0") is False
|
|
|
|
def test_caret_allows_minor_and_patch(self):
|
|
# ^3.1.0 means >=3.1.0, <4.0.0
|
|
assert _satisfies_range((3, 9, 9), "^3.1.0") is True
|
|
assert _satisfies_range((4, 0, 0), "^3.1.0") is False
|
|
assert _satisfies_range((3, 0, 0), "^3.1.0") is False
|
|
|
|
def test_bare_exact_version(self):
|
|
assert _satisfies_range((3, 1, 0), "3.1.0") is True
|
|
assert _satisfies_range((3, 1, 1), "3.1.0") is False
|
|
|
|
def test_inclusive_dash_range(self):
|
|
assert _satisfies_range((2, 5, 0), "2.0.0 - 3.1.0") is True
|
|
assert _satisfies_range((2, 0, 0), "2.0.0 - 3.1.0") is True
|
|
assert _satisfies_range((3, 1, 0), "2.0.0 - 3.1.0") is True
|
|
assert _satisfies_range((3, 1, 1), "2.0.0 - 3.1.0") is False
|
|
|
|
def test_unparseable_spec_returns_none_not_false(self):
|
|
# Garbage must read as "no evidence", never as a refusal — an
|
|
# unrecognised spelling must not cost a user a working install.
|
|
assert _satisfies_range(self.CORE, "banana") is None
|
|
assert _satisfies_range(self.CORE, ">=banana") is None
|
|
assert _satisfies_range(self.CORE, "") is None
|
|
assert _satisfies_range(self.CORE, "banana - 3.0.0") is None
|
|
|
|
|
|
class TestSatisfiesCompatibleVersions:
|
|
def test_any_entry_satisfying_wins(self):
|
|
manifest = {"compatible_versions": ["<1.0.0", ">=3.0.0"]}
|
|
assert satisfies_compatible_versions(manifest, (3, 1, 0)) is True
|
|
|
|
def test_all_entries_failing_is_false(self):
|
|
manifest = {"compatible_versions": ["<1.0.0", "2.0.0 - 2.9.9"]}
|
|
assert satisfies_compatible_versions(manifest, (3, 1, 0)) is False
|
|
|
|
def test_absent_field_returns_none(self):
|
|
assert satisfies_compatible_versions({}, (3, 1, 0)) is None
|
|
|
|
def test_empty_list_returns_none(self):
|
|
assert satisfies_compatible_versions(
|
|
{"compatible_versions": []}, (3, 1, 0)) is None
|
|
|
|
def test_non_list_returns_none(self):
|
|
assert satisfies_compatible_versions(
|
|
{"compatible_versions": ">=2.0.0"}, (3, 1, 0)) is None
|
|
|
|
def test_all_unparseable_entries_returns_none(self):
|
|
manifest = {"compatible_versions": ["banana", 42, None]}
|
|
assert satisfies_compatible_versions(manifest, (3, 1, 0)) is None
|
|
|
|
def test_mixed_parseable_and_garbage_uses_parseable(self):
|
|
manifest = {"compatible_versions": ["banana", ">=3.0.0"]}
|
|
assert satisfies_compatible_versions(manifest, (3, 1, 0)) is True
|
|
|
|
|
|
class TestDeclaredMinVersion:
|
|
def test_top_level_field(self):
|
|
assert declared_min_version({"min_ledmatrix_version": "2.1.0"}) == "2.1.0"
|
|
|
|
def test_requires_dict_fallback(self):
|
|
manifest = {"requires": {"min_ledmatrix_version": "2.2.0"}}
|
|
assert declared_min_version(manifest) == "2.2.0"
|
|
|
|
def test_versions_array_fallback(self):
|
|
manifest = {"versions": [{"ledmatrix_min_version": "2.3.0"}]}
|
|
assert declared_min_version(manifest) == "2.3.0"
|
|
|
|
def test_versions_array_deprecated_spelling(self):
|
|
manifest = {"versions": [{"ledmatrix_min": "2.4.0"}]}
|
|
assert declared_min_version(manifest) == "2.4.0"
|
|
|
|
def test_top_level_wins_over_versions_array(self):
|
|
manifest = {
|
|
"min_ledmatrix_version": "2.1.0",
|
|
"versions": [{"ledmatrix_min_version": "9.9.9"}],
|
|
}
|
|
assert declared_min_version(manifest) == "2.1.0"
|
|
|
|
def test_requires_as_list_does_not_raise(self):
|
|
# A hand-edited manifest can carry `requires` as a list; this used to
|
|
# raise AttributeError and one malformed manifest would take down the
|
|
# whole install path.
|
|
assert declared_min_version({"requires": ["something"]}) is None
|
|
|
|
def test_versions_as_dict_does_not_raise(self):
|
|
# Same for `versions` as a mapping (used to raise KeyError).
|
|
assert declared_min_version({"versions": {"0": {}}}) is None
|
|
|
|
def test_nothing_declared_returns_none(self):
|
|
assert declared_min_version({}) is None
|
|
|
|
|
|
class TestCheck:
|
|
def test_compatible_when_nothing_declared(self):
|
|
assert check({}, "3.1.0") == (True, None)
|
|
|
|
def test_min_version_blocks_older_core(self):
|
|
manifest = {"name": "Test Plugin", "min_ledmatrix_version": "3.2.0"}
|
|
ok, reason = check(manifest, "3.1.0")
|
|
assert ok is False
|
|
assert "3.2.0" in reason and "3.1.0" in reason
|
|
|
|
def test_min_version_allows_equal_core(self):
|
|
manifest = {"min_ledmatrix_version": "3.1.0"}
|
|
assert check(manifest, "3.1.0") == (True, None)
|
|
|
|
def test_compatible_versions_upper_bound_blocks(self):
|
|
# A range is the only field that can express "not compatible with
|
|
# newer cores" — it must win even when the floor passes.
|
|
manifest = {
|
|
"name": "Old Plugin",
|
|
"min_ledmatrix_version": "2.0.0",
|
|
"compatible_versions": ["2.0.0 - 2.9.9"],
|
|
}
|
|
ok, reason = check(manifest, "3.1.0")
|
|
assert ok is False
|
|
assert "2.0.0 - 2.9.9" in reason
|
|
|
|
def test_unparseable_core_with_high_floor_is_blocked(self):
|
|
manifest = {"min_ledmatrix_version": "3.2.0",
|
|
"compatible_versions": [">=3.2.0"]}
|
|
# An unparseable core version is "unknown", not "old"... but note
|
|
# parse_semver("garbage") == (0,0,0) which is below TRUSTWORTHY_FLOOR,
|
|
# so this rides the untrustworthy-core branch: floor > 2.0.0 blocks.
|
|
ok, reason = check(manifest, "garbage")
|
|
assert ok is False
|
|
assert "too old to identify reliably" in reason
|
|
|
|
def test_untrustworthy_core_allows_ecosystem_baseline_floor(self):
|
|
# A core reporting 1.0.0 may really be v3.1.0 (which shipped with a
|
|
# wrong __version__). Floors at or below TRUSTWORTHY_FLOOR must not
|
|
# block, or that population could install nothing.
|
|
manifest = {"min_ledmatrix_version": "2.0.0",
|
|
"compatible_versions": [">=2.0.0"]}
|
|
assert check(manifest, "1.0.0") == (True, None)
|
|
|
|
def test_untrustworthy_core_blocks_floor_above_baseline(self):
|
|
# But a floor above 2.0.0 needs modules that no core reporting below
|
|
# the floor can have — the one refusal on that branch.
|
|
manifest = {"name": "New Plugin", "min_ledmatrix_version": "3.2.0"}
|
|
ok, reason = check(manifest, "1.0.0")
|
|
assert ok is False
|
|
assert "too old to identify reliably" in reason
|
|
|
|
def test_untrustworthy_core_ignores_compatible_versions(self):
|
|
# On the untrustworthy branch only the declared floor is consulted;
|
|
# ranges cannot be evaluated against a version that isn't evidence.
|
|
manifest = {"compatible_versions": ["2.0.0 - 2.9.9"]}
|
|
assert check(manifest, "1.0.0") == (True, None)
|
|
|
|
def test_floor_exactly_at_trustworthy_floor_is_allowed(self):
|
|
floor = ".".join(str(n) for n in TRUSTWORTHY_FLOOR)
|
|
manifest = {"min_ledmatrix_version": floor}
|
|
assert check(manifest, "1.0.0") == (True, None)
|
|
|
|
def test_reason_uses_manifest_name(self):
|
|
manifest = {"name": "Fancy Clock", "min_ledmatrix_version": "9.0.0"}
|
|
ok, reason = check(manifest, "3.1.0")
|
|
assert ok is False
|
|
assert reason.startswith("Fancy Clock")
|
|
|
|
def test_reason_falls_back_to_id(self):
|
|
manifest = {"id": "fancy-clock", "min_ledmatrix_version": "9.0.0"}
|
|
ok, reason = check(manifest, "3.1.0")
|
|
assert ok is False
|
|
assert reason.startswith("fancy-clock")
|
|
|
|
def test_prerelease_core_compares_equal_to_release(self):
|
|
# Documented: prereleases compare equal to their release.
|
|
manifest = {"min_ledmatrix_version": "3.2.0"}
|
|
assert check(manifest, "3.2.0-rc1") == (True, None)
|