Skip to content

test: reject arbitrary-port routing failures - #1144

Open
Flandern (Flandern1211) wants to merge 1 commit into
agent-substrate:mainfrom
Flandern1211:arbitrary-port-rejection-test
Open

test: reject arbitrary-port routing failures#1144
Flandern (Flandern1211) wants to merge 1 commit into
agent-substrate:mainfrom
Flandern1211:arbitrary-port-rejection-test

Conversation

@Flandern1211

@Flandern1211 Flandern (Flandern1211) commented Aug 22, 2026

Copy link
Copy Markdown

Fixes #1102

Summary

The arbitrary-port E2E test previously treated every non-200 response as a successful rejection. That allowed upstream routing failures such as HTTP 503 or 504 to pass the test.

Require the expected 502 Bad Gateway response emitted by atunnel instead, so the test only passes when the unlisted actor port is actually rejected by the actor ingress path.

Validation

  • go test ./internal/e2e/suites/networking -run '^$' -count=1 — passed (package compilation)

  • go vet ./internal/e2e/suites/networking — passed

  • go test ./internal/atunnel -run '^TestServeHTTP' -count=1 — passed

  • Full Linux test suite, root-gated tests, and gVisor/microVM E2E — delegated to GitHub Actions because this workstation is Windows without Docker/KinD

  • Tests pass

  • Appropriate changes to documentation are included in the PR (no documentation changes are needed for this test-only fix)

Require the unlisted-port E2E case to receive atunnel's 502 Bad Gateway response so upstream 503/504 failures cannot be reported as a successful port rejection.
@google-cla

google-cla Bot commented Aug 22, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@Flandern1211

Copy link
Copy Markdown
Author

I signed the Google CLA and triggered the New Contributors rescan. The cla/google check is currently pending; please let me know if maintainer-side approval or a further rescan is required.

@orangeCatDeveloper

Copy link
Copy Markdown
Contributor

We already have https://github.com/agent-substrate/substrate/pull/1103/changes. This PR is duplicate please close it

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TestActorArbitraryPortAccess passes when the worker is unreachable, masking #1050

2 participants