fix(tests): run the #213 permit-leak regression in CI (#434)
test_stream_permit_release.py carried a whole-suite `pytestmark =
pytest.mark.model`, so the per-PR job's `-m "not model"` filter excluded it --
and the job's explicit file list did not name it either. The guard against the
#213 remote unauthenticated permit-exhaustion DoS therefore ran nowhere except
a full local release.
None of the three tests needs the model. Every request they send fails
validation and returns 400 before a LanguageModelSession is constructed; the
assertions are on status codes and on /health's active_requests counter.
Marked `serial` rather than simply unmarked, which is where the three candidate
PRs (#446, #448, #454) stop short in two ways:
- They remove the model marker but do not touch ci.yml, which names only
security_test.py, openapi_spec_test.py and server_validation_test.py. The
tests still would not have run in CI, which is the entire point of the
issue.
- Dropping the marker outright would have put the suite in the parallel
phase. Its assertions read /health's *global* active_requests counter on
the shared 11434 server, so any other worker with a request in flight makes
it non-zero -- a guaranteed flake. `serial` keeps it out of the parallel
phase locally, and in CI it runs as its own step after the parallel one.
test_marker_discipline.py moved from MODEL_SUITES to SERIAL_SUITES to match, so
the classification stays enforced rather than merely corrected once.
Verified: 3 passed under `-m "not model"` against a plain server, and the
marker-discipline suite is green.
Closes #434
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ccLBbEaVVd4sJyUd5wyhA A
Arthur Ficial committed
8e5cfec2cc913572ada3c76679fd4dab27bcb005
Parent: d7a4db6