Split compose generator tests by runtime and topology - #9079
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change cleanly reorganizes existing tests while preserving their fixtures, mocks, assertions, and lifecycle handling.
Review effort: Balanced
Findings: None
What changed in this PR
Splits the monolithic compose-generator test suite into focused runtime, topology, and filesystem-policy suites without changing production code.
Changes:
- Retains baseline compose tests in the original suite.
- Separates network isolation, runtime, ARC-DinD, and filesystem-gating coverage.
- Preserves per-file mocks and temporary-directory cleanup.
| File | Description |
|---|---|
src/compose-generator.test.ts |
Retains baseline compose-generation tests. |
src/compose-generator-runtimes.test.ts |
Covers gVisor and microVM behavior. |
src/compose-generator-network-isolation.test.ts |
Covers isolated-network topology. |
src/compose-generator-filesystem-gating.test.ts |
Covers runtime-specific write-policy gating. |
src/compose-generator-arc-dind.test.ts |
Covers host-gateway and ARC-DinD staging. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
✅ Copilot review passed with no inline comments. @copilot Add the |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (1 files)
Coverage comparison generated by |
|
🔌 Smoke Services — All services reachable! ✅
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "clients2.google.com"See Network Configuration for more information.
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Claude passed
|
|
✅ Build Test Suite completed successfully!
|
|
🚀 Security Guard has started processing this pull request |
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
🛡️ Smoke Copilot Network Isolation is verifying network-isolation egress on this pull request... |
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
Smoke Test: Copilot Engine —
Overall: PASS
|
Smoke Test: Cloud Hypervisor + Copilot
Overall: 2/4 PASS. Checks 2 & 4 could not run because the sandbox's bash tool blocked outbound curl invocations entirely (independent of AWF firewall behavior).
|
Smoke Test: Copilot BYOK ✅
Mode: Direct BYOK via Result: PASS
|
|
Smoke Test: GHA Services Connectivity
Overall: PASS
|
Chroot Version Comparison
Result: Not all tests passed — Node.js version mismatch between host and chroot environments. The
|
📡 OTel Tracing Smoke Test Results
Overall: all scenarios passed, no regressions detected.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes (environment, not firewall-related):
All 18 test projects across all 8 ecosystems built/installed and passed their test suites successfully with no network egress issues observed.
|
|
Split model-resolver.test.js into three focused test files ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "clients2.google.com"See Network Configuration for more information.
|
The monolithic
generateDockerComposesuite mixed baseline behavior with security-sensitive runtime and topology variants, making fixtures and ownership difficult to isolate.compose-generator.test.ts.filesystem.allowWritegating coverage.