MrMasterbay f97eb5575c ci: run tests in an isolated venv (fix ubuntu-24.04 zope namespace shadowing)
First CI run failed at pytest with ModuleNotFoundError: No module named 'zope.event'
— ubuntu-24.04's system Python carries a partial `zope` namespace that shadows the
pip-installed zope.event (a gevent runtime dep), so the app import in conftest broke.
Build + run inside a clean `python3 -m venv` (no system site-packages) so the deps
resolve in isolation. (Exactly the kind of fresh-environment issue local dev masks —
which is why running tests in CI matters.)
2026-07-13 10:24:28 +02:00

39 lines
1.4 KiB
YAML

name: Tests
# NS Jul 2026 — run the pytest suite (including the route-authz contract test) on
# every PR and on pushes to the integration branches. The static reviewers
# (CodeAnt / Aikido / Qodo) READ the code; this actually EXECUTES the invariants
# — the layer that caught this project's real authz/behaviour bugs.
#
# persist-credentials is left at its default on purpose (Nico: "wir brauchen die
# Zugangsdaten"); the GITHUB_TOKEN is scoped read-only since this job only reads.
on:
pull_request:
push:
branches: [main, Testing]
permissions:
contents: read
concurrency:
group: tests-${{ github.ref }}
cancel-in-progress: true
jobs:
pytest:
runs-on: ubuntu-24.04 # ships Python 3.12, matching the Dockerfile base image
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Install dependencies
# NS: build in an ISOLATED venv — ubuntu-24.04's system Python carries a
# partial `zope` namespace that shadows pip-installed zope.event (a gevent
# dep), breaking the app import. A clean venv (no system site-packages) fixes it.
run: |
python3 --version
python3 -m venv .venv
.venv/bin/pip install --upgrade pip
.venv/bin/pip install -r requirements.txt -r requirements-dev.txt
- name: Run test suite
run: .venv/bin/python -m pytest tests/ -q