From 05145998578b437538edb19ec84c9280ce2c3cd7 Mon Sep 17 00:00:00 2001 From: wan9chi Date: Mon, 5 Oct 2026 12:44:33 +0800 Subject: [PATCH] test(cache): cover rejected remote cache uploads Add e2e cases for uploads that the backend rejects, like the public cache service would: a token from a pull request's job, which the write policy doesn't allow, and an upload without a token from outside GitHub Actions. Both tasks succeed, and the run reports the upload as failed with the backend's message. Co-Authored-By: Claude Opus 5.5 --- .../fixtures/remote_cache/snapshots.toml | 77 +++++++++++++++++++ .../snapshots/pull_request_upload.md | 46 +++++++++++ .../snapshots/upload_without_token.md | 46 +++++++++++ 3 files changed, 169 insertions(+) create mode 100644 crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/pull_request_upload.md create mode 100644 crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/upload_without_token.md diff --git a/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots.toml b/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots.toml index f05c9f7bb..f6af6f949 100644 --- a/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots.toml +++ b/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots.toml @@ -574,6 +574,83 @@ steps = [ ], comment = "The details include why the token request failed." }, ] +[[e2e]] +name = "pull_request_upload" +cfg = "not(windows)" +ignore = true +steps = [ + [ + "remote-cache-server", + "start", + ], + { argv = [ + "remote-cache-server", + "run", + "--github-actions", + "vt", + "run", + "build", + ], envs = [ + [ + "VP_REMOTE_CACHE", + "read-write", + ], + [ + "ACTIONS_ID_TOKEN_REQUEST_TOKEN", + "pull-request", + ], + [ + "VP_RUN_INTERNAL_HIDE_PENDING_UPLOADS", + "1", + ], + ], comment = "The job runs for a pull request, so its token doesn't satisfy the write policy and the backend rejects the upload. The task succeeds." }, + { argv = [ + "vt", + "run", + "--last-details", + ], comment = "The details include the backend's message." }, + [ + "remote-cache-server", + "stop", + ], +] + +[[e2e]] +name = "upload_without_token" +cfg = "not(windows)" +ignore = true +steps = [ + [ + "remote-cache-server", + "start", + ], + { argv = [ + "remote-cache-server", + "run", + "vt", + "run", + "build", + ], envs = [ + [ + "VP_REMOTE_CACHE", + "read-write", + ], + [ + "VP_RUN_INTERNAL_HIDE_PENDING_UPLOADS", + "1", + ], + ], comment = "Outside GitHub Actions, the upload has no token, so the backend rejects it. The task succeeds." }, + { argv = [ + "vt", + "run", + "--last-details", + ], comment = "The details include the backend's message." }, + [ + "remote-cache-server", + "stop", + ], +] + [[e2e]] name = "read_invalid_endpoint" steps = [ diff --git a/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/pull_request_upload.md b/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/pull_request_upload.md new file mode 100644 index 000000000..ba59dadd1 --- /dev/null +++ b/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/pull_request_upload.md @@ -0,0 +1,46 @@ +# pull_request_upload + +## `remote-cache-server start` + +``` +``` + +## `VP_REMOTE_CACHE=read-write ACTIONS_ID_TOKEN_REQUEST_TOKEN=pull-request VP_RUN_INTERNAL_HIDE_PENDING_UPLOADS=1 remote-cache-server run --github-actions vt run build` + +The job runs for a pull request, so its token doesn't satisfy the write policy and the backend rejects the upload. The task succeeds. + +``` +$ vtt write-file dist/output.txt built + +--- +vt run: remote-cache#build not uploaded to the remote cache: HTTP status 403. (Run `vt run --last-details` for full details) +[remote-cache] POST /fetch 404 +[remote-cache] POST /store 403 +``` + +## `vt run --last-details` + +The details include the backend's message. + +``` + +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ + Vite+ Task Runner • Execution Summary +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ + +Statistics: 1 task • 0 cache hits • 1 cache miss +Performance: 0% cache hit rate + +Task Details: +──────────────────────────────────────────────── + [1] remote-cache#build: $ vtt write-file dist/output.txt built ✓ + → Cache miss: no previous cache entry found + ⚠ Not uploaded to the remote cache: HTTP status 403 + ↳ Write not permitted +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ +``` + +## `remote-cache-server stop` + +``` +``` diff --git a/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/upload_without_token.md b/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/upload_without_token.md new file mode 100644 index 000000000..f133a749d --- /dev/null +++ b/crates/vt_bin/tests/e2e_snapshots/fixtures/remote_cache/snapshots/upload_without_token.md @@ -0,0 +1,46 @@ +# upload_without_token + +## `remote-cache-server start` + +``` +``` + +## `VP_REMOTE_CACHE=read-write VP_RUN_INTERNAL_HIDE_PENDING_UPLOADS=1 remote-cache-server run vt run build` + +Outside GitHub Actions, the upload has no token, so the backend rejects it. The task succeeds. + +``` +$ vtt write-file dist/output.txt built + +--- +vt run: remote-cache#build not uploaded to the remote cache: HTTP status 401. (Run `vt run --last-details` for full details) +[remote-cache] POST /fetch 404 +[remote-cache] POST /store 401 +``` + +## `vt run --last-details` + +The details include the backend's message. + +``` + +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ + Vite+ Task Runner • Execution Summary +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ + +Statistics: 1 task • 0 cache hits • 1 cache miss +Performance: 0% cache hit rate + +Task Details: +──────────────────────────────────────────────── + [1] remote-cache#build: $ vtt write-file dist/output.txt built ✓ + → Cache miss: no previous cache entry found + ⚠ Not uploaded to the remote cache: HTTP status 401 + ↳ Invalid credentials +━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ +``` + +## `remote-cache-server stop` + +``` +```