SIGN IN SIGN UP

fix(tests): run the #213 permit-leak regression in CI (#434)

test_stream_permit_release.py carried a whole-suite `pytestmark =
pytest.mark.model`, so the per-PR job's `-m "not model"` filter excluded it --
and the job's explicit file list did not name it either. The guard against the
#213 remote unauthenticated permit-exhaustion DoS therefore ran nowhere except
a full local release.

None of the three tests needs the model. Every request they send fails
validation and returns 400 before a LanguageModelSession is constructed; the
assertions are on status codes and on /health's active_requests counter.

Marked `serial` rather than simply unmarked, which is where the three candidate
PRs (#446, #448, #454) stop short in two ways:

  - They remove the model marker but do not touch ci.yml, which names only
    security_test.py, openapi_spec_test.py and server_validation_test.py. The
    tests still would not have run in CI, which is the entire point of the
    issue.
  - Dropping the marker outright would have put the suite in the parallel
    phase. Its assertions read /health's *global* active_requests counter on
    the shared 11434 server, so any other worker with a request in flight makes
    it non-zero -- a guaranteed flake. `serial` keeps it out of the parallel
    phase locally, and in CI it runs as its own step after the parallel one.

test_marker_discipline.py moved from MODEL_SUITES to SERIAL_SUITES to match, so
the classification stays enforced rather than merely corrected once.

Verified: 3 passed under `-m "not model"` against a plain server, and the
marker-discipline suite is green.

Closes #434

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ccLBbEaVVd4sJyUd5wyhA
A
Arthur Ficial committed
8e5cfec2cc913572ada3c76679fd4dab27bcb005
Parent: d7a4db6