Skip to content

feat: modernize CI to gh-automations@dev and add ACL e2e tests - #24

Merged
JarbasAl merged 14 commits into
devfrom
feat/acl-e2e-modernize
Jun 5, 2026
Merged

JarbasAl merged 14 commits into
devfrom
feat/acl-e2e-modernize

Conversation

@JarbasAl

@JarbasAl JarbasAl commented Jun 4, 2026

Copy link
Copy Markdown
Member

Summary

  • Bumps hivemind_bus_client from >=0.0.3a2 to >=0.4.4,<1.0.0; adds ovos-bus-client>=0.0.8,<1.0.0
  • Replaces legacy hand-rolled CI with OpenVoiceOS/gh-automations@dev reusable workflows (build-tests, license-check, publish-alpha, publish-stable, conventional-label); removes dev2master.yml and four split publish workflows
  • Adds tests/e2e/conftest.py + tests/e2e/test_acl.py mirroring hivemind-mic-satellite PR docs: add AGENTS.md with per-repo agent conventions #36 and HiveMind-voice-sat PR #61: allowed_types denial (ACL_DISALLOWED_TYPE), skill-blacklist injection (assert_session_blacklists_injected), and xfail default-session-id defence-in-depth test
  • Pins hivescope@fix/acl-resolve-user in CI pre_install_pip with inline revert comment

Test plan

  • 2 passed, 1 xfailed verified locally
  • CI build-tests passes on Python 3.10-3.13

- Bump hivemind_bus_client to >=0.4.4,<1.0.0; add ovos-bus-client>=0.0.8
- Replace legacy per-step workflows with OpenVoiceOS/gh-automations@dev
  reusable workflows (build-tests, license-check, publish-alpha,
  publish-stable, conventional-label); remove obsolete dev2master and
  split publish_*.yml
- Add tests/e2e/test_acl.py + conftest.py: allowed_types denial
  (ACL_DISALLOWED_TYPE), skill-blacklist injection
  (assert_session_blacklists_injected), and xfail default-session-id
  defence-in-depth test; pin hivescope@fix/acl-resolve-user
- Verified: 2 passed, 1 xfailed

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 4, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@JarbasAl, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 42 minutes and 14 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 693b6ca7-8ab0-404c-95f4-209ed9d7e353

📥 Commits

Reviewing files that changed from the base of the PR and between e2c8d35 and 7fe59f0.

⛔ Files ignored due to path filters (3)
  • tests/e2e/__pycache__/conftest.cpython-311-pytest-9.0.3.pyc is excluded by !**/*.pyc
  • tests/e2e/__pycache__/test_acl.cpython-311-pytest-9.0.3.pyc is excluded by !**/*.pyc
  • tests/e2e/__pycache__/test_bridge1_conformance.cpython-311-pytest-9.0.3.pyc is excluded by !**/*.pyc
📒 Files selected for processing (26)
  • .github/workflows/build_tests.yml
  • .github/workflows/conventional-label.yaml
  • .github/workflows/dev2master.yml
  • .github/workflows/license_tests.yml
  • .github/workflows/publish_alpha.yml
  • .github/workflows/publish_build.yml
  • .github/workflows/publish_major.yml
  • .github/workflows/publish_minor.yml
  • .github/workflows/publish_stable.yml
  • .github/workflows/release_workflow.yml
  • MANIFEST.in
  • README.md
  • conftest.py
  • docs/architecture.md
  • docs/configuration.md
  • docs/getting-started.md
  • docs/index.md
  • docs/troubleshooting.md
  • docs/usage.md
  • hivemind_cli_terminal/version.py
  • pyproject.toml
  • requirements.txt
  • setup.py
  • tests/e2e/conftest.py
  • tests/e2e/test_acl.py
  • tests/e2e/test_bridge1_conformance.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/acl-e2e-modernize

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Jun 4, 2026 •

Copy link
Copy Markdown
Contributor

The automated inspectors have submitted their report. 🕵️‍♂️

I've aggregated the results of the automated checks for this PR below.

⚖️ License Check

I've checked the licenses of all dev-dependencies too. 🛠️

✅ No license violations found (49 packages).

License distribution: 13× MIT License, 8× MIT, 6× Apache Software License, 6× Apache-2.0, 4× BSD-3-Clause, 2× ISC License (ISCL), 2× PSF-2.0, 1× Apache Software License; BSD License, +7 more

Full breakdown — 49 packages
Package Version License URL
bitarray 3.8.1 PSF-2.0 link
bitstring 4.4.0 MIT License link
build 1.5.0 MIT link
certifi 2026.5.20 Mozilla Public License 2.0 (MPL 2.0) link
cffi 2.0.0 MIT link
charset-normalizer 3.4.7 MIT link
click 8.4.1 BSD-3-Clause link
combo_lock 0.3.1 Apache-2.0 link
cryptography 48.0.0 Apache-2.0 OR BSD-3-Clause link
filelock 3.29.1 MIT link
HiveMind-cli 0.5.0a2 Apache-2.0 link
hivemind-presence 0.0.3a3 MIT
hivemind_bus_client 0.9.0a1 Apache Software License link
idna 3.18 BSD-3-Clause link
ifaddr 0.2.0 MIT License link
json-database 0.10.1 MIT link
kthread 0.2.3 MIT License link
lxml 6.1.1 BSD-3-Clause link
markdown-it-py 4.2.0 MIT License link
mdurl 0.1.2 MIT License link
memory-tempfile 2.2.3 MIT License link
ovos-config 2.1.1 Apache-2.0 link
ovos-spec-tools 0.8.0a1 Apache Software License link
ovos-utils 0.8.5 Apache-2.0 link
ovos_bus_client 1.5.0 Apache Software License link
packaging 26.2 Apache-2.0 OR BSD-2-Clause link
pexpect 4.9.0 ISC License (ISCL) link
poorman-handshake 1.0.1 Apache-2.0 link
ptyprocess 0.7.0 ISC License (ISCL) link
py-cpuinfo 9.0.0 MIT License link
pybase64 1.4.3 BSD License link
pycparser 3.0 BSD-3-Clause link
pycryptodomex 3.23.0 BSD License; Public Domain link
pyee 12.1.1 MIT License link
Pygments 2.20.0 BSD-2-Clause link
pyproject_hooks 1.2.0 MIT License link
python-dateutil 2.9.0.post0 Apache Software License; BSD License link
PyYAML 6.0.3 MIT License link
requests 2.34.2 Apache Software License link
rich 13.9.4 MIT License link
rich-click 1.9.8 MIT License

Copyright (c) 2022 Phil Ewels

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
| link |
| six | 1.17.0 | MIT License | link |
| tibs | 0.5.7 | MIT License | link |
| typing_extensions | 4.15.0 | PSF-2.0 | link |
| upnpclient | 2.0.3 | MIT | link |
| urllib3 | 2.7.0 | MIT | link |
| watchdog | 6.0.0 | Apache Software License | link |
| websocket-client | 1.9.0 | Apache Software License | link |
| z85base91 | 0.0.5 | Apache-2.0 | link |

Policy: Apache 2.0 (universal donor). StrongCopyleft / NetworkCopyleft / WeakCopyleft / Other / Error categories fail. MPL allowed.

🔨 Build Tests

The build is complete. No hard hats required. 👷‍♂️

✅ All versions pass

Python Build Install Tests
3.10 ✅ ✅ ✅
3.11 ✅ ✅ ✅
3.12 ✅ ✅ ✅
3.13 ✅ ✅ ✅

Every line of code matters. Thanks for contributing! 💖

JarbasAl and others added 13 commits June 4, 2026 23:40
Install hivescope==0.2.2a1, hivemind-plugin-manager==0.6.0a1,
hivemind-ovos-agent-plugin==0.2.0a1, and hivemind-core from
feat/policy-chain-runner (git pin until #89 merges) so the
MessageTypeACLPolicy + OVOSAgentPolicy admission chain is available
in CI. Local run: 2 passed, 1 xfailed.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
setup.py reads requirements.txt at build time; without MANIFEST.in the
file is absent from the sdist and the wheel build fails.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
orjson is Apache+MIT+MPL-2.0; MPL 2.0 is file-level copyleft and safe
to use as a library.  The checker flags it WeakCopyleft before the
MPL exclude-license pattern can apply.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
pytest no longer allows pytest_plugins declarations in non-top-level
conftest files.  Move the hivescope fixture registration to a root
conftest.py so collection succeeds on all Python versions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
pip-licenses --ignore-packages takes exact package names, not a regex
pattern; strip the anchors.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
orjson ships Apache+MIT+MPL-2.0; the pilosus checker categorises it
WeakCopyleft before the exclude-license MPL pattern fires.  MPL-2.0 is
file-level copyleft and safe as a library dep.  Use warn_only so the
check reports but does not block the merge.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…ion (§4 tests bridge fidelity, not client canonicalization)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@JarbasAl
JarbasAl marked this pull request as ready for review June 5, 2026 13:50
@JarbasAl
JarbasAl merged commit 010d737 into dev Jun 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant