You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit c8d0633
Browse filesBrowse the repository at this point in the historyBrowse files
ci,scripts: pin the conformance catalog tooling, stop ignoring uv lockfiles, record the changelog
The conformance suite stops xfailing the inbound DPoP-Nonce case now that the
catalog carries it, and the catalog-fetch tooling is aligned with the pinned ref
so a local run matches CI rather than the moving default branch.
`backport-fixes.sh` accepts a tag as `--from`: `release.yml` deletes
`release/vX.Y.Z` once the tag is pushed, so afterwards the tag is the only ref
naming those commits — which is exactly what the release summary tells the
operator to pass. `--from` and `--to` are validated as ref names before reaching
a fetch refspec, since `git ls-remote` matches its arguments as globs.
`uv.lock` is ignored: nothing tracks or consumes these files — no workflow
installs with uv — so they are local resolution artifacts. Three of them were
swept into a merge commit as untracked files once and accounted for 94% of that
diff. Tracking them for reproducible installs is a real decision and belongs in
its own PR, alongside the CI change that would make them load-bearing.
note="Python rejects the proof but does not expose a stable diagnostic.",
29
+
note="<which part of the case the test does not reach>",
30
30
)
31
31
async def test_...(...):
32
32
...
33
33
```
34
34
35
+
The case id is a placeholder on purpose: naming a real one here would claim
36
+
coverage metadata that the marker on the actual test may not carry.
37
+
35
38
| Parameter | Default | Description |
36
39
|-----------|---------|-------------|
37
-
|`level`|`"full"`|`"full"` or `"partial"` — how closely the test matches the catalog spec |
38
-
|`gaps`|`[]`| List of expected catalog fields not covered by this test |
39
-
|`note`|`""`| Free-text explanation (appears in both JSON and Markdown reports) |
40
+
|`level`|`"full"`|`"full"` or `"partial"` — how closely the test matches the catalog spec. Always reaches `conformance-report.md`. |
41
+
|`gaps`|`[]`| Catalog *field paths* the test does not reach (`use_case`, `expected.error_hint`, …). Reaches `conformance-report.md` only alongside a `note`; always reaches `conformance-report.json`. |
42
+
|`note`|`""`| Free-text prose. Gates the Coverage Notes section — see below. |
43
+
44
+
Keep them in that order — `gaps` names the fields, `note` carries the prose —
45
+
and **always write a `note` alongside `gaps`, because `note` is the gate**. In
46
+
`conftest.py`'s `_build_markdown_report`, a single filter (`:216`) selects the
47
+
cases with a truthy `note`, and it decides both whether the Coverage Notes
48
+
section is emitted at all (`:217`) and which cases it lists (`:219`) — and the
49
+
`Gaps:` line (`:224-225`) is emitted *inside* that section. So a `gaps`-only
50
+
marker states no reason anywhere in `conformance-report.md` and its `gaps`
51
+
survive in `conformance-report.json` alone; set a `note` and both render.
52
+
53
+
`level` is not gated on `note`: it reaches the markdown either way, via the
54
+
Cases table's Coverage column (`:193-197`).
55
+
56
+
Also keep `|` out of the `note` — it is interpolated into a markdown table cell
57
+
unescaped and will break the row.
58
+
59
+
### Partial coverage vs. not implemented
40
60
41
-
### Not-yet-implemented tests
61
+
A test that exercises part of a case but not all of it is a `partial`: it still
62
+
runs and still asserts. Prefer that over an `xfail` wherever one is honest — an
63
+
`xfail` asserts nothing, so it cannot notice the day the gap closes, and it
64
+
reports as a skip while the report carries the case as not-run.
42
65
43
-
Tests for features that don't exist yet should still be present with the marker and a `pytest.xfail(...)` body that documents what is missing:
66
+
A case with nothing behind it at all should carry the marker with a
67
+
`pytest.xfail(...)` body documenting what is missing:
These tests show up as `skipped` (with their `note` carried through) in both `conformance-report.json` and `conformance-report.md` — pytest classifies `xfail` outcomes as skips. Keeping the suite green for known gaps means CI never has to be ignored to merge; the gap is still visible in the report's per-case status and coverage notes.
78
+
The id is a placeholder deliberately: **the suite currently has no `xfail`s**,
79
+
so there is no live case to point at, and `test_catalog_alignment.py` requires
80
+
every catalog id to carry a marker — so any real id named here would be one
81
+
that does have a test behind it. (This section previously used
82
+
`rfc9449-dpop-inbound-nonce-must-be-validated-when-required` as its worked
83
+
example; that case now runs as a `partial`.)
84
+
85
+
`xfail` tests show up as `skipped` — with their `note` carried through — in both
86
+
`conformance-report.json` and `conformance-report.md`, because pytest
87
+
classifies `xfail` outcomes as skips. Keeping the suite green for known gaps
88
+
means CI never has to be ignored to merge; the gap stays visible in the
0 commit comments