Skip to content

fix: make the SQL integration suite runnable, and honest when it is not - #11

Merged
lintdeveloper merged 2 commits into
mainfrom
fix/integration-test-message
Aug 27, 2026
Merged

lintdeveloper merged 2 commits into
mainfrom
fix/integration-test-message

Conversation

@lintdeveloper

Copy link
Copy Markdown
Owner

#9 fixed the path so the file is found. Running it revealed the rest.

  • The gate checks whether RESILIX_TEST_DATABASE_URL is set, but the script always sets it with a localhost default — so without a database you got a bare AggregateError and two node:net frames. Now it names the URL, gives the docker run line, and points at pnpm test.
  • Ran it for real against PostgreSQL 14.15: 13 of 13 pass. First successful run since the reorg, and a second data point — classifySql's mappings were captured on 16 and hold on 14.
  • CONTRIBUTING documents the trap that cost me a false failure: initdb --auth=trust makes "bad password" unfalsifiable, so that test reports NO THROW until pg_hba.conf uses scram-sha-256.

Fixing the path in #9 only got the file found. Actually running it surfaced
two things.

The describe-level gate is `URL_ ? describe : describe.skip`, which tests
whether RESILIX_TEST_DATABASE_URL is SET — but `pnpm test:integration` always
sets it, defaulting to localhost:5459. So the script can never distinguish
"asked for integration tests" from "has a database", and without one the
failure was a bare AggregateError with two node:net frames and no indication of
what to do. It now names the URL it tried, carries the docker run line, and
points at `pnpm test` to skip.

Then it was run for real, against PostgreSQL 14.15, which had not happened
since the reorg: 13 of 13 pass. That is a second data point for classifySql —
the mappings were captured on PostgreSQL 16 and hold on 14 too.

One trap found while setting that up, now in CONTRIBUTING: initdb --auth=trust
makes the "bad password -> transient" case unfalsifiable, because a bad
password does not fail. It reports `NO THROW` until pg_hba.conf uses
scram-sha-256 for 127.0.0.1. Twelve of thirteen passing with the thirteenth
failing for a harness reason is exactly the shape that gets mistaken for a
library bug.
@gitguardian

gitguardian Bot commented Aug 27, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
36194417 Triggered Generic Password 6cfe381 src/scenarios/sql-integration.test.ts View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Adding test:compat to CI in #9 turned an environment-sensitive check into a
required one, and it failed on the first PR after: 170 of 362, with test.js
reporting STALLED in CI while passing locally in 6 seconds.

Two problems behind that, both worth fixing regardless of which one it was.

The suite tracked opossum's main branch. .opossum-compat/ is not cached in CI,
so every run fetched afresh and the README's "362 of 362" was being measured
against whatever opossum had merged that morning. The expected value of a
required check must not be something upstream can change without us. It is now
pinned to decbedf6, and bumping it is a deliberate act.

And a stall reported only the word STALLED, discarding the child's stdout,
stderr and exit status. That is why the CI failure could not be diagnosed and
had to be guessed at — first as a 60s timeout, which the 16-second total run
already ruled out. It now prints the exit code, the signal, and the last twelve
lines the child produced, or says explicitly that there was none.

362 of 362 locally at the pin. Whether CI agrees is now something the output
will explain rather than something to infer.
@lintdeveloper
lintdeveloper merged commit f09f4d9 into main Aug 27, 2026
11 checks passed
@lintdeveloper
lintdeveloper deleted the fix/integration-test-message branch August 27, 2026 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant