From 783c1f1ddb7a21dace3eb4c137445ddcbc167899 Mon Sep 17 00:00:00 2001 From: SoFlo1 Date: Thu, 14 May 2026 13:43:41 -0400 Subject: [PATCH 1/2] fix(firecracker): skip fallback egress test on linux MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit TestApplyEgressRules_FallbackBehavior is documented as testing the non-Linux fallback path of applyEgressRules, but it has no build tag gating it. On Linux CI it picks up the real nftables applier, which calls nft.New() — that opens a netlink socket and fails without CAP_NET_ADMIN, killing make test. Skip with runtime.GOOS check rather than splitting into a !linux- tagged file so the test stays adjacent to its sibling translate + teardown tests. Linux-side coverage of applyEgressRules already lives in egress_linux_test.go behind a root-only gate. Co-Authored-By: Claude Opus 4.7 (1M context) --- internal/adapter/firecracker/egress_test.go | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/internal/adapter/firecracker/egress_test.go b/internal/adapter/firecracker/egress_test.go index 690cd200..ec9ad570 100644 --- a/internal/adapter/firecracker/egress_test.go +++ b/internal/adapter/firecracker/egress_test.go @@ -5,6 +5,7 @@ import ( "context" "errors" "log/slog" + "runtime" "strings" "testing" @@ -110,6 +111,12 @@ func TestTranslate_SanitizesTableName(t *testing.T) { // touching the kernel. Linux integration tests live in // egress_linux_integration_test.go and are gated on root + GOOS=linux. func TestApplyEgressRules_FallbackBehavior(t *testing.T) { + if runtime.GOOS == "linux" { + // On Linux applyEgressRules hits the real nftables path, which needs + // CAP_NET_ADMIN. CI runners don't have it; Linux-specific coverage + // lives in egress_linux_test.go behind a root-only gate. + t.Skip("Linux path exercises real nftables; see egress_linux_test.go") + } var buf bytes.Buffer log := slog.New(slog.NewTextHandler(&buf, &slog.HandlerOptions{Level: slog.LevelDebug})) From f7ee9a4ee3c81b584c7e3a84f0055249902b1bdd Mon Sep 17 00:00:00 2001 From: SoFlo1 Date: Thu, 14 May 2026 13:47:49 -0400 Subject: [PATCH 2/2] fix(cli): deflake TestPollForGitHubToken_Cancel MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Cancel ctx up-front instead of racing a sleep-then-cancel goroutine against the poll loop — the previous version was flaky on loaded CI runners (macos-14 in particular). Also switch the error assertion from string match on "cancelled" to errors.Is(err, context.Canceled) so a future refactor of the wrap message doesn't silently break the test. Co-Authored-By: Claude Opus 4.7 (1M context) --- internal/cli/login_github_test.go | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/internal/cli/login_github_test.go b/internal/cli/login_github_test.go index 19249a8e..bf79742d 100644 --- a/internal/cli/login_github_test.go +++ b/internal/cli/login_github_test.go @@ -4,6 +4,7 @@ import ( "bytes" "context" "encoding/json" + "errors" "net/http" "net/http/httptest" "path/filepath" @@ -196,18 +197,17 @@ func TestPollForGitHubToken_Cancel(t *testing.T) { }) defer gh.server.Close() ctx, cancel := context.WithCancel(context.Background()) - // Cancel almost immediately. - go func() { - time.Sleep(5 * time.Millisecond) - cancel() - }() + // Cancel up-front so the first poll observes ctx.Err() deterministically. + // The previous version raced a sleep-then-cancel goroutine against the + // poll loop and was flaky under loaded CI runners. + cancel() _, err := pollForGitHubToken(ctx, gh.server.Client(), gh.server.URL, "id", "DEV", 1*time.Millisecond) if err == nil { t.Fatalf("expected error on cancel, got nil") } - if !strings.Contains(err.Error(), "cancelled") { - t.Fatalf("error should mention cancel; got %v", err) + if !errors.Is(err, context.Canceled) { + t.Fatalf("error should wrap context.Canceled; got %v", err) } }