build: run the browser e2e suites in CI (closes #259)
Nothing automatic ran either e2e suite, so every browser-level guarantee in this wallet -- WebAssembly under the shipped CSP, the recovery-phrase and private-key DOM wipes, the ConfirmTx spend gate, the dApp approval round trips -- held only when a human or an agent remembered to run it by hand. .gitea/workflows/e2e.yml adds two jobs, e2e-chrome and e2e-firefox, one per browser so a Chrome failure cannot hide the Firefox result. They are separate from the check workflow: REPO_POLICIES.md caps make test at 20 seconds and script/cibuild is a docker build whose Dockerfile runs make check, so neither the cap nor the local fast path is touched. make check is byte-for-byte unchanged. Neither suite could run on the runner as it stood, and the reason is not docker-in-docker. The runner executes a job inside a container against the HOST's docker daemon, and the job's checkout lives on a docker volume rather than a host path, so `docker run -v "$PWD:/work"` is resolved by the host, silently succeeds and mounts an empty directory -- measured on this runner. The runner image's node is also too old to install this repo's dependencies. Both suites therefore ship the repo to the daemon as a build context and build the extension inside the pinned image, which leaves docker as the only prerequisite on a runner or a laptop. The suites themselves are unchanged; only how the repo reaches the container is. Both scripts now build with --iidfile and run the image by ID rather than by tag, so two clones running a suite at once on the same host cannot swap it under each other. The jobs report, they do not gate. Whether a check blocks a merge is Gitea branch protection, which this repo does not configure, so a failure is a red mark a reviewer must account for. Nothing can pass vacuously: no continue-on-error, no `|| true`, and both scripts exit non-zero when docker is missing, when the image build fails and when the browser fails to start.
This commit is contained in:
@@ -7,17 +7,29 @@
|
||||
# caps make test at 20 seconds and a browser suite does not fit. Run it
|
||||
# yourself before touching popup views; it is the only check that can see
|
||||
# a used-but-not-imported identifier blow up at runtime.
|
||||
# .gitea/workflows/e2e.yml also runs it on every push, in a job separate
|
||||
# from check so that cap and the local fast path both stay intact.
|
||||
#
|
||||
# Docker is the only prerequisite. The repo reaches the container as a
|
||||
# build context and the extension is built inside it (see
|
||||
# tests/e2e/Dockerfile), so nothing here depends on the node, yarn or make
|
||||
# on the machine that starts the run. That is not a convenience: a bind
|
||||
# mount cannot work under Gitea Actions, and the runner image's node is too
|
||||
# old to install this repo's dependencies.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
# mcr.microsoft.com/playwright:v1.56.0-noble, 2026-08-09
|
||||
#
|
||||
# The playwright-core devDependency is pinned to the matching Playwright
|
||||
# version (1.56.0) and the two must be bumped together: the browsers ship
|
||||
# inside this image, and playwright-core looks for the exact browser
|
||||
# revision its own version expects. A mismatch fails at launch.
|
||||
IMAGE="mcr.microsoft.com/playwright@sha256:35246d87a7c88ea9b771c65d33171b2611b02a8253b4b12ce6f94376c55f99f2"
|
||||
IMAGE="$("$SCRIPT_DIR/projectname")-e2e-chrome"
|
||||
|
||||
IIDFILE=""
|
||||
|
||||
cleanup() {
|
||||
if [ -n "$IIDFILE" ]; then
|
||||
rm -f "$IIDFILE"
|
||||
fi
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
@@ -27,14 +39,23 @@ main() {
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Building extension for e2e..."
|
||||
yarn run build 2>&1
|
||||
IIDFILE="$(mktemp)"
|
||||
trap cleanup EXIT
|
||||
trap 'cleanup; exit 130' INT TERM
|
||||
|
||||
echo "Building the Chrome e2e image (extension included)..."
|
||||
docker build --iidfile "$IIDFILE" -t "$IMAGE" -f tests/e2e/Dockerfile .
|
||||
|
||||
echo "Running e2e suite in the pinned Playwright container..."
|
||||
# The image is run by ID, not by tag: where two clones of this repo run
|
||||
# the suite at once, the other build can move the tag between this
|
||||
# build and this run, and the suite would then silently test the other
|
||||
# checkout.
|
||||
#
|
||||
# --ipc=host: Chromium's shared-memory needs more than the default
|
||||
# 64MB /dev/shm or renderers crash.
|
||||
# --user: keep files the suite touches owned by the caller, not root.
|
||||
# HOME=/tmp: the mapped uid has no home directory in the image.
|
||||
# HOME=/tmp: the image's root home is not a reliable place for the
|
||||
# browser profile.
|
||||
# PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1: without it,
|
||||
# ctx.route() intercepts page requests only, and every fetch made by
|
||||
# the MV3 background service worker — including the phishing
|
||||
@@ -51,13 +72,10 @@ main() {
|
||||
# on a deliberate bump.
|
||||
docker run --rm \
|
||||
--ipc=host \
|
||||
--user "$(id -u):$(id -g)" \
|
||||
-e HOME=/tmp \
|
||||
-e PW_EXPERIMENTAL_SERVICE_WORKER_NETWORK_EVENTS=1 \
|
||||
-e "E2E_TRACE_NETWORK=${E2E_TRACE_NETWORK:-0}" \
|
||||
-v "$ROOT:/work" \
|
||||
-w /work \
|
||||
"$IMAGE" \
|
||||
"$(cat "$IIDFILE")" \
|
||||
node tests/e2e/run.js
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user