Skip to content

test: securesign-5860: remove linux/amd64 skip from tufcli tests - #102

Merged
kdacosta0 merged 2 commits into
mainfrom
SECURESIGN-5860-remove-tufcli-platform-skip
Oct 7, 2026
Merged

kdacosta0 merged 2 commits into
mainfrom
SECURESIGN-5860-remove-tufcli-platform-skip

Conversation

@kdacosta0

@kdacosta0 kdacosta0 commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

What changed: Removed the platform check that skipped the tufcli end-to-end test on anything other than linux/amd64.

Why: The restriction came from the old Rust-based tuftool, which only shipped for that one platform. tufcli is built and published for every supported OS and architecture, so the skip was needlessly reducing test coverage.

🤖 Generated with Claude Code

Test run: https://github.com/securesign/releases/actions/runs/37595946235

@qodo-for-securesign

Copy link
Copy Markdown

PR Summary by Qodo

Run tufcli end-to-end tests on all supported platforms

🧪 Tests 🕐 Less than 10 minutes

Grey Divider

AI Description

• Remove the linux/amd64 skip from the tufcli manual-repository test.
• Restore test coverage on other supported platforms, where tufcli is also available.
Diagram

graph TD
  A["Manual TUF test"] --> B["Install prerequisites"] --> C["Tufcli setup strategy"] --> D["Tufcli commands"] --> E["Repository files"]
Loading
High-Level Assessment

Removing the obsolete guard is the simplest way to restore coverage. Replacing it with a supported-platform list would duplicate platform availability information and require ongoing maintenance.

Files changed (1) +0 / -7

Tests (1) +0 / -7
tufcli_manual_tuf_repo_test.goRemove the tufcli test's linux/amd64 gate +0/-7

Remove the tufcli test's linux/amd64 gate

• Removes the OpenShift-strategy platform check that skipped the ordered manual-repository test outside linux/amd64. Also removes the runtime and API imports that the check alone used.

test/tufcli/tufcli_manual_tuf_repo_test.go

@qodo-for-securesign

qodo-for-securesign Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Windows release validation now fails ✓ Resolved
Description
verifyWorkdirStructure compares native paths returned by filepath.Rel with slash-separated
expected names and a tuf-repo/targets/ prefix. With the platform skip removed, the
securesign/releases Windows runner supplies backslash-separated paths for the generated TUF
repository, so the directory, file, and targets-prefix checks can fail despite successful repository
creation.
Code

test/tufcli/tufcli_manual_tuf_repo_test.go[L46-48]

-		if openshiftStrategyActive && (runtime.GOOS != "linux" || runtime.GOARCH != "amd64") {
-			logrus.Info("Skipping tufcli download test: openshift strategy is only supported on linux/amd64")
-			Skip("Skipping tufcli download test: openshift strategy is only supported on linux/amd64")
Relevance

●●● Strong

Accepted Windows portability fixes show the team prioritizes cross-platform test reliability; this
path-separator bug is concrete.

PR-#98
PR-#94

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The test calls verifyWorkdirStructure after repository setup, then uses unnormalized
filepath.Rel results as map keys and in the targets-prefix check against slash-separated values.
tufcli creates the targets directory with filepath.Join, and the releases workflow runs the
newly enabled test on Windows, where relative paths use backslashes.

sigstore-e2e -> tufcli
sigstore-e2e -> releases
test/tufcli/tufcli_manual_tuf_repo_test.go[184-235]
test/tufcli/tufcli_manual_tuf_repo_test.go[56-60]
test/tufcli/tufcli_manual_tuf_repo_test.go[177-201]
test/tufcli/tufcli_manual_tuf_repo_test.go[224-250]
External repo: securesign/tufcli, internal/create/create.go [109-115]
External repo: securesign/releases, .github/workflows/cross-platform-tests.yml [447-454]
External repo: securesign/releases, .github/workflows/cross-platform-tests.yml [518-537]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Removing the platform skip makes the manual TUF repository test run in the releases repository’s Windows workflow, but its structure assertions compare native Windows paths with slash-separated expected paths.

## Fix Focus Areas
- test/tufcli/tufcli_manual_tuf_repo_test.go[188-250]

## Recommended Fix
Convert each `filepath.Rel` result with `filepath.ToSlash` before using it for directory names, file names, or the targets-prefix check. Keep the test enabled on Windows.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Cross-repo context — repo relationships
  Explored: repo: securesign/releases (sha: e5fe10fb) — View relationship
  Explored: repo: securesign/tufcli (sha: d31b50ea) — View relationship
Review mode: Auto: ⚖️ Balanced: Removes platform gating from cross-platform end-to-end test behavior.

Grey Divider

Tip of the day
💡 Did you know, you can route each severity your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread test/tufcli/tufcli_manual_tuf_repo_test.go
kdacosta0 and others added 2 commits October 7, 2026 12:00
The platform gate was inherited from the Rust tuftool, which only
shipped a linux/amd64 binary. tufcli is built and published for linux
amd64/arm64/ppc64le/s390x, darwin amd64/arm64 and windows amd64, and
the ConsoleCLIDownload manifest advertises all of them, so the skip no
longer reflects reality and needlessly cuts test coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
verifyWorkdirStructure compares filepath.Rel output against expected
paths written with forward slashes. On Windows Rel returns backslashes,
so every nested entry (keys\root.pem, tuf-repo\targets\...) missed the
lookup and was reported as unexpected.

Normalise with filepath.ToSlash. This only surfaced now because the
linux/amd64 skip previously stopped the suite from running on Windows.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@kdacosta0
kdacosta0 force-pushed the SECURESIGN-5860-remove-tufcli-platform-skip branch from 23fa531 to e7e4b15 Compare October 7, 2026 10:00
@kdacosta0
kdacosta0 merged commit 8fa5a3c into main Oct 7, 2026
6 checks passed
@kdacosta0
kdacosta0 deleted the SECURESIGN-5860-remove-tufcli-platform-skip branch October 7, 2026 10:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants