From 88e45a48b603d3b1e7bb1d418679bba42acde6a9 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Wed, 23 Sep 2026 08:35:24 -0700 Subject: [PATCH] fix: run_tests.sh forwards HERMES_RUN_E2E so the documented iron-proxy E2E runs The egress developer guide says `HERMES_RUN_E2E=1 scripts/run_tests.sh tests/agent/test_iron_proxy_e2e.py`, but the runner's `env -i` dropped the variable, so all three cases skipped silently. Forward it next to the other opt-in knobs (HERMES_RUN_SLOW_PET_TESTS, HERMES_E2E_BROWSER); before: 3 skipped, after: 3 passed. The test docstring no longer names a --run-e2e option that never existed. --- scripts/run_tests.sh | 4 +++- tests/agent/test_iron_proxy_e2e.py | 7 ++++--- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/scripts/run_tests.sh b/scripts/run_tests.sh index bc0b4e6b98..7db21c42d6 100755 --- a/scripts/run_tests.sh +++ b/scripts/run_tests.sh @@ -138,7 +138,8 @@ done # HERMES_GIT_SHA build-arg the workflow bakes in). # # These are test-infrastructure knobs, not credentials — same class as the -# HERMES_RUN_SLOW_PET_TESTS / HERMES_E2E_BROWSER opt-ins already forwarded. +# HERMES_RUN_SLOW_PET_TESTS / HERMES_E2E_BROWSER / HERMES_RUN_E2E opt-ins +# forwarded below. # Keep this an explicit allowlist (no HERMES_TEST_* glob) so the "no # credential can leak" property stays auditable at a glance. TEST_ENV=() @@ -179,6 +180,7 @@ exec env -i \ PYTHONUTF8=1 \ ${HERMES_RUN_SLOW_PET_TESTS:+HERMES_RUN_SLOW_PET_TESTS="$HERMES_RUN_SLOW_PET_TESTS"} \ ${HERMES_E2E_BROWSER:+HERMES_E2E_BROWSER="$HERMES_E2E_BROWSER"} \ + ${HERMES_RUN_E2E:+HERMES_RUN_E2E="$HERMES_RUN_E2E"} \ ${EXTRA_PYTHONPATH:+PYTHONPATH="$EXTRA_PYTHONPATH"} \ ${EXTRA_PYTEST_PLUGINS:+PYTEST_PLUGINS="$EXTRA_PYTEST_PLUGINS"} \ "$PYTHON" "$SCRIPT_DIR/run_tests_parallel.py" "$@" diff --git a/tests/agent/test_iron_proxy_e2e.py b/tests/agent/test_iron_proxy_e2e.py index 37c3936c0d..8204384977 100644 --- a/tests/agent/test_iron_proxy_e2e.py +++ b/tests/agent/test_iron_proxy_e2e.py @@ -4,9 +4,10 @@ Spins up the REAL iron-proxy binary (auto-installed if not present), routes a curl request through it against a local fake upstream, and verifies that the Authorization header was swapped from a proxy token to a real secret. -Gated on the network. Skipped by default in CI unless the user explicitly -opts in with --run-e2e or HERMES_RUN_E2E=1. This is intentional — the test -downloads ~16MB and requires both `openssl` and `curl` to be present. +Gated on the network: skipped unless HERMES_RUN_E2E=1 (no CI lane sets it; +it is a manual smoke, see website/docs/developer-guide/egress-internals.md). +This is intentional — the test downloads ~16MB and requires both `openssl` +and `curl` to be present. """ from __future__ import annotations