diff --git a/CHANGELOG.md b/CHANGELOG.md index 59d1fa68..dd4e2c04 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -27,6 +27,12 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format — pinned via `--pythonpath sys.executable`. The audit is now deterministic local == CI (proven all-13-branches-100% in an unactivated shell). Also: `drone` bypasses the test-only broker `start_background` (intentional API, not dead code). +- **windows-setup CI: guard Linux-only sandbox tests.** The kernel-sandbox build + is Linux-only (bwrap, `AF_UNIX` sockets, `openat2`); the code already guards on + `sys.platform`, but `drone/tests/test_broker.py` and `hooks/tests/test_sandbox.py` + ran unconditionally and failed on `windows-latest`. Added module-level + `pytestmark = pytest.mark.skipif(sys.platform != "linux", …)` so they skip on + Windows and run unchanged on Linux. ### Added diff --git a/src/aipass/drone/tests/test_broker.py b/src/aipass/drone/tests/test_broker.py index 4e81d51b..b9ea145d 100644 --- a/src/aipass/drone/tests/test_broker.py +++ b/src/aipass/drone/tests/test_broker.py @@ -16,6 +16,7 @@ client broker_delete / create_identified_connection, and rm broker routing. from __future__ import annotations +import sys import hashlib import hmac as hmac_mod import json @@ -38,6 +39,10 @@ from aipass.drone.apps.handlers.broker.client import ( ) from aipass.drone.apps.handlers.json import json_handler +pytestmark = pytest.mark.skipif( + sys.platform != "linux", + reason="broker is Linux-only: AF_UNIX sockets + openat2 RESOLVE_BENEATH", +) json_handler.log_operation("test_broker_load", {}) diff --git a/src/aipass/hooks/tests/test_sandbox.py b/src/aipass/hooks/tests/test_sandbox.py index 147b2d4a..83c94009 100644 --- a/src/aipass/hooks/tests/test_sandbox.py +++ b/src/aipass/hooks/tests/test_sandbox.py @@ -9,11 +9,14 @@ """Tests for apps/modules/sandbox.py.""" +import sys from pathlib import Path from unittest.mock import MagicMock, patch import pytest +pytestmark = pytest.mark.skipif(sys.platform != "linux", reason="sandbox is Linux-only: bwrap mount namespaces") + class TestBuildSrtConfig: """Config generation from policy dict."""