Repository navigation
Conversation
tests/run.sh builds a small Debian image and runs, in a throwaway
container (identical locally - including Git Bash on Windows - and in CI):
- ShellCheck on every script and test double
- systemd-analyze security: exposure must stay <= 5.0 (currently 4.2),
so a sandboxing change can no longer silently break or weaken the unit
- bats suites that run the *real* fiero-hotspot.sh, fiero-prompt.sh,
install.sh and uninstall.sh against test doubles of create_ap, iw,
notify-send, systemctl, sudo and a fake charger (27 tests):
lifecycle, passphrase handling, other tools' hotspots, --no-virt,
channel drift, hung create_ap, lost upstream, prompt timeouts and
stale prompts, sudoers validation, re-install, uninstall
The create_ap double reproduces create_ap's on-disk contract (confdir,
pid, wifi_iface, hostapd command line, USR1 clean exit) and the iw
double uses iw 6.9's exact output formats. The suites refuse to run
outside the container because they replace system commands.
CI (.github/workflows/ci.yml): pinned actions/checkout SHA, permissions
{} with contents: read, no persisted credentials. Dependabot keeps the
pin current with a 7-day cooldown.
test_harness.sh stays as the on-hardware check.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- CONTRIBUTING.md: how to report, branch/PR/commit conventions, how to run the automated suite and the on-hardware harness (exit code 2) - issue forms for bug reports (asks for card, iw combinations, journal) and hardware reports (feeds a compatibility list); security reports are pointed to private vulnerability reporting - README: automated tests section and CI badge Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
On Linux hosts (GitHub Actions) Docker's default AppArmor profile denies every write under /sys inside the container - even to the tmpfs mounted at /sys/class/power_supply - so the prompt and install suites failed in setup with "mkdir: cannot create directory '/sys/class/power_supply/AC': Permission denied". Docker Desktop on Windows has no AppArmor, which is why it passed locally. tests/run.sh now mounts one scratch volume twice: at /sys/class/power_supply, where the scripts read the charger state, and at /fake-power, where the tests write it. The volume is removed after the run. Reproduced locally by mounting the /sys path read-only: the previous tests fail exactly like CI, these pass (27/27). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Fiero1186
approved these changes
Sep 27, 2026
Fiero1186
left a comment
Owner
There was a problem hiding this comment.
Approved Phase 2 CI workflows and community templates.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1 (phase 2: tests you can trust). Stacked on #2: this PR's base is
fix/phase-1-critical. Once #2 is merged, GitHub retargets it tomainautomatically.What this adds
Automated tests that run the real scripts (no Wi-Fi hardware needed)
This builds a small Debian image and runs, in a throwaway Docker container:
systemd-analyze security: fails if the unit's exposure goes above 5.0 (currently 4.2). This is the check that would have caught the v1.5.0PrivateTmpproblem.fiero-hotspot.sh,fiero-prompt.sh,install.shanduninstall.shagainst test doubles intests/mocks/:create_ap: reproduces its on-disk contract (config dir,pid,wifi_iface,hostapdcommand line,USR1clean exit,--config,--no-virt)iw: uses the exact output formats of iw 6.9notify-send,systemctl,sudo, and a fake charger in/sys/class/power_supplydaemon.bats(13)ps, other tools' hotspots left alone,--no-virt, channel drift, hung create_ap, lost upstream, unsupported channel, help/version without rootprompt.bats(7)AUTO_START_ON_TIMEOUT, unplug cancels an open prompt, debounce, stop on unplug,AUTO_PROMPT=falseinstall.bats(7)--keep-configThe suites replace system commands, so they refuse to run outside the container. They can't damage a developer's machine.
The same command works on Linux, macOS and Git Bash on Windows (it handles the Windows path conversion).
CI (
.github/workflows/ci.yml)Runs
tests/run.shon every PR and on pushes tomain. It's set up the way security-conscious projects do it:actions/checkoutpinned to a full commit SHA (v7.0.1)permissions: {}at the top,contents: readfor the jobpersist-credentials: falsedependabot.ymlkeeps the pinned action up to date, with a 7-day cooldown.Contributor docs
CONTRIBUTING.md: how to report, branch/PR/commit conventions, how to run both test levelsiw listcombinations and the journal) and Hardware report, which feeds a future compatibility list. Security reports are pointed to private vulnerability reporting.test_harness.shstays as the on-hardware check. The two complement each other: the container suite catches logic regressions on every PR, and the harness proves it works with a real card.Suggestion for the repo settings (owner only)
Once this is merged, consider protecting
main(Settings → Branches → add rule): require a pull request and require theCIstatus check to pass. Then a broken release like v1.5.0 can't reachmainagain.🤖 Generated with Claude Code