Nothing automatic ran either e2e suite, so every browser-level guarantee in this wallet -- WebAssembly under the shipped CSP, the recovery-phrase and private-key DOM wipes, the ConfirmTx spend gate, the dApp approval round trips -- held only when a human or an agent remembered to run it by hand. .gitea/workflows/e2e.yml adds two jobs, e2e-chrome and e2e-firefox, one per browser so a Chrome failure cannot hide the Firefox result. They are separate from the check workflow: REPO_POLICIES.md caps make test at 20 seconds and script/cibuild is a docker build whose Dockerfile runs make check, so neither the cap nor the local fast path is touched. make check is byte-for-byte unchanged. Neither suite could run on the runner as it stood, and the reason is not docker-in-docker. The runner executes a job inside a container against the HOST's docker daemon, and the job's checkout lives on a docker volume rather than a host path, so `docker run -v "$PWD:/work"` is resolved by the host, silently succeeds and mounts an empty directory -- measured on this runner. The runner image's node is also too old to install this repo's dependencies. Both suites therefore ship the repo to the daemon as a build context and build the extension inside the pinned image, which leaves docker as the only prerequisite on a runner or a laptop. The suites themselves are unchanged; only how the repo reaches the container is. Both scripts now build with --iidfile and run the image by ID rather than by tag, so two clones running a suite at once on the same host cannot swap it under each other. The jobs report, they do not gate. Whether a check blocks a merge is Gitea branch protection, which this repo does not configure, so a failure is a red mark a reviewer must account for. Nothing can pass vacuously: no continue-on-error, no `|| true`, and both scripts exit non-zero when docker is missing, when the image build fails and when the browser fails to start.
78 lines
2.8 KiB
Bash
Executable File
78 lines
2.8 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/test-e2e-firefox: build the extension and drive the real popup in
|
|
# a real Firefox inside a pinned container. The Firefox counterpart to
|
|
# script/test-e2e. Our own extension to scripts-to-rule-them-all.
|
|
#
|
|
# Deliberately NOT called by script/check or script/test, for the same
|
|
# reason as the Chrome suite: REPO_POLICIES.md caps make test at 20 seconds
|
|
# and a browser suite does not fit. .gitea/workflows/e2e.yml also runs it
|
|
# on every push, in a job separate from check.
|
|
#
|
|
# Unlike script/test-e2e this builds its base image locally, because no
|
|
# published image carries both a pinned Firefox and a matching geckodriver.
|
|
# All three external artifacts are pinned by digest inside the Dockerfile;
|
|
# see tests/e2e/firefox/Dockerfile, which also explains why the repo and
|
|
# the extension build are baked into the image rather than mounted.
|
|
#
|
|
# Docker is the only prerequisite: nothing here depends on the node, yarn
|
|
# or make on the machine that starts the run.
|
|
set -eu
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
|
|
IMAGE="$("$SCRIPT_DIR/projectname")-e2e-firefox"
|
|
|
|
IIDFILE=""
|
|
|
|
cleanup() {
|
|
if [ -n "$IIDFILE" ]; then
|
|
rm -f "$IIDFILE"
|
|
fi
|
|
}
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
if ! command -v docker >/dev/null 2>&1; then
|
|
echo "test-e2e-firefox: docker is required to run the e2e suite" >&2
|
|
exit 1
|
|
fi
|
|
|
|
IIDFILE="$(mktemp)"
|
|
trap cleanup EXIT
|
|
trap 'cleanup; exit 130' INT TERM
|
|
|
|
echo "Building the pinned Firefox e2e image (extension included)..."
|
|
docker build --iidfile "$IIDFILE" -t "$IMAGE" \
|
|
-f tests/e2e/firefox/Dockerfile .
|
|
|
|
echo "Running the Firefox e2e suite..."
|
|
# The image is run by ID, not by tag: where two clones of this repo run
|
|
# the suite at once, the other build can move the tag between this
|
|
# build and this run, and the suite would then silently test the other
|
|
# checkout.
|
|
#
|
|
# --shm-size=1g: Firefox needs more than the default 64MB /dev/shm.
|
|
# --network none: the suite stubs nothing, so this is what keeps the
|
|
# run offline and deterministic. The extension swallows its own
|
|
# fetch failures, so the popup flows work unchanged; see the
|
|
# network note in README.md. Weaker than the Chrome suite's
|
|
# fixture interception, and honestly so — it proves no request
|
|
# escaped, but it cannot report which ones were attempted.
|
|
# HOME=/tmp: the image's root home is not a reliable place for the
|
|
# browser profile.
|
|
#
|
|
# No --privileged. Firefox's sandbox logs
|
|
# "CanCreateUserNamespace() clone() failure: EPERM" on startup here;
|
|
# it is cosmetic and headless Firefox runs fine without it.
|
|
docker run --rm \
|
|
--shm-size=1g \
|
|
--network none \
|
|
-e HOME=/tmp \
|
|
"$(cat "$IIDFILE")" \
|
|
node tests/e2e/firefox/run.js dist/firefox
|
|
}
|
|
|
|
main "$@"
|