From 294eb89ec60a244b72c387c8814acb6b7e1d5b93 Mon Sep 17 00:00:00 2001 From: Peolite001 Date: Fri, 25 Sep 2026 08:18:51 +0100 Subject: [PATCH 1/5] Replace Futurenet job with real deployed-network smoke test --- .github/workflows/integration-chaos.yml | 36 +++++++++++ .github/workflows/integration-futurenet.yml | 16 ++--- stellar/scripts/deploy-dryrun.sh | 72 +++++++++++++++++---- 3 files changed, 102 insertions(+), 22 deletions(-) create mode 100644 .github/workflows/integration-chaos.yml diff --git a/.github/workflows/integration-chaos.yml b/.github/workflows/integration-chaos.yml new file mode 100644 index 00000000..378c1f7c --- /dev/null +++ b/.github/workflows/integration-chaos.yml @@ -0,0 +1,36 @@ +name: Stellar Chaos Tests + +on: + schedule: + - cron: "0 3 * * 0" # Weekly, Sunday 3am UTC + workflow_dispatch: # Manual trigger + +jobs: + chaos: + name: Local chaos suite + runs-on: ubuntu-latest + continue-on-error: true # allow-flaky + + steps: + - uses: actions/checkout@v4 + + - name: Install Rust + uses: dtolnay/rust-toolchain@stable + with: + targets: wasm32-unknown-unknown + + - name: Install Stellar CLI + run: cargo install stellar-cli --locked + + - name: Run integration tests + working-directory: stellar/integration-tests + env: + FUTURENET_SECRET: ${{ secrets.FUTURENET_TEST_SECRET }} + run: cargo test -- --nocapture 2>&1 | tee test-results.txt + + - name: Upload test results + uses: actions/upload-artifact@v4 + if: always() + with: + name: chaos-test-results + path: stellar/integration-tests/test-results.txt \ No newline at end of file diff --git a/.github/workflows/integration-futurenet.yml b/.github/workflows/integration-futurenet.yml index fe7daea3..a87065dd 100644 --- a/.github/workflows/integration-futurenet.yml +++ b/.github/workflows/integration-futurenet.yml @@ -1,4 +1,4 @@ -name: Stellar Futurenet Integration Tests +name: Stellar Futurenet Smoke Tests on: schedule: @@ -6,10 +6,9 @@ on: workflow_dispatch: # Manual trigger jobs: - integration: - name: Futurenet smoke tests + smoke-test: + name: Futurenet smoke test runs-on: ubuntu-latest - continue-on-error: true # allow-flaky steps: - uses: actions/checkout@v4 @@ -22,15 +21,14 @@ jobs: - name: Install Stellar CLI run: cargo install stellar-cli --locked - - name: Run integration tests - working-directory: stellar/integration-tests + - name: Run deployed-network smoke test env: - FUTURENET_SECRET: ${{ secrets.FUTURENET_TEST_SECRET }} - run: cargo test -- --nocapture 2>&1 | tee test-results.txt + STELLAR_ADMIN_SECRET: ${{ secrets.FUTURENET_TEST_SECRET }} + run: ./stellar/scripts/deploy-dryrun.sh 2>&1 | tee test-results.txt - name: Upload test results uses: actions/upload-artifact@v4 if: always() with: name: futurenet-test-results - path: stellar/integration-tests/test-results.txt \ No newline at end of file + path: test-results.txt \ No newline at end of file diff --git a/stellar/scripts/deploy-dryrun.sh b/stellar/scripts/deploy-dryrun.sh index 08a4ff2d..58c8fbdb 100755 --- a/stellar/scripts/deploy-dryrun.sh +++ b/stellar/scripts/deploy-dryrun.sh @@ -322,8 +322,8 @@ fi header "Smoke Tests" -# 1. Register a name in wraith-names -info "1/5 Registering name '$TEST_NAME' in wraith-names..." +# 1. Register a name in wraith-names (Happy path) +info "1/7 Registering name '$TEST_NAME' in wraith-names..." if $CLI contract invoke \ --id "$NAMES_ID" \ --source "$IDENTITY_NAME" \ @@ -338,8 +338,24 @@ else warn "name registration failed (may already exist on re-run)" fi -# 2. Resolve the name (prove wraith-names works) -info "2/5 Resolving name '$TEST_NAME'..." +# 1b. Register an already registered name (Rejected path) +info "1b/7 Registering already registered name in wraith-names..." +if $CLI contract invoke \ + --id "$NAMES_ID" \ + --source "$IDENTITY_NAME" \ + --network "$NETWORK" \ + -- \ + register \ + --owner "$ADMIN_ADDRESS" \ + --name "$TEST_NAME" \ + --stealth-meta-address "$TEST_META_ADDRESS" 2>&1 | grep -qi "AlreadyRegistered"; then + ok "duplicate name registration rejected (AlreadyRegistered)" +else + warn "duplicate name registration not rejected with AlreadyRegistered" +fi + +# 2. Resolve the name (Happy path) +info "2/7 Resolving name '$TEST_NAME'..." RESOLVED=$($CLI contract invoke \ --id "$NAMES_ID" \ --source "$IDENTITY_NAME" \ @@ -353,13 +369,26 @@ RESOLVED=$($CLI contract invoke \ if [ -n "$RESOLVED" ]; then ok "name resolved (64-byte meta-address)" else - # Only warn if resolve didn't outright fail (already handled above) [ -z "$RESOLVED" ] && [ "$SMOKE_FAILED" -eq 0 ] && \ warn "resolve returned empty result" fi -# 3. Announce an event (prove stealth-announcer works) -info "3/5 Announcing event via stealth-announcer..." +# 2b. Resolve non-existent name (Rejected path) +info "2b/7 Resolving non-existent name..." +if $CLI contract invoke \ + --id "$NAMES_ID" \ + --source "$IDENTITY_NAME" \ + --network "$NETWORK" \ + -- \ + resolve \ + --name "doesnotexist123" 2>&1 | grep -qi "NotFound"; then + ok "non-existent name resolution rejected (NotFound)" +else + warn "non-existent name resolution not rejected with NotFound" +fi + +# 3. Announce an event (Happy path) +info "3/7 Announcing event via stealth-announcer..." if $CLI contract invoke \ --id "$ANNOUNCER_ID" \ --source "$IDENTITY_NAME" \ @@ -375,8 +404,25 @@ else smoke_fail "announce failed" fi -# 4. Query the registry (prove stealth-registry works) -info "4/5 Querying stealth-registry..." +# 3b. Announce with invalid scheme ID (Rejected path) +info "3b/7 Announcing with invalid scheme ID..." +if $CLI contract invoke \ + --id "$ANNOUNCER_ID" \ + --source "$IDENTITY_NAME" \ + --network "$NETWORK" \ + -- \ + announce \ + --scheme-id 999 \ + --stealth-address "$ADMIN_ADDRESS" \ + --ephemeral-pub-key "$TEST_EPHEMERAL_KEY" \ + --metadata "$TEST_METADATA" 2>&1 | grep -qi "InvalidSchemeId"; then + ok "invalid scheme ID rejected (InvalidSchemeId)" +else + warn "invalid scheme ID not rejected with InvalidSchemeId" +fi + +# 4. Query the registry (Rejected / Happy path depending on state) +info "4/7 Querying stealth-registry..." REG_RESULT=$($CLI contract invoke \ --id "$REGISTRY_ID" \ --source "$IDENTITY_NAME" \ @@ -389,8 +435,8 @@ REG_RESULT=$($CLI contract invoke \ ok "registry is responsive (NotRegistered is expected)" } -# 5. Verify sender is initialized -info "5/5 Verifying stealth-sender initialization..." +# 5. Verify sender is initialized (Rejected path: AlreadyInitialized) +info "5/7 Verifying stealth-sender initialization (rejected path)..." if $CLI contract invoke \ --id "$SENDER_ID" \ --source "$IDENTITY_NAME" \ @@ -400,9 +446,9 @@ if $CLI contract invoke \ init \ --announcer "$ANNOUNCER_ID" \ --fee-basis-points 0 2>&1 | grep -qi "AlreadyInitialized\|already initialized"; then - ok "stealth-sender correctly initialized (AlreadyInitialized)" + ok "stealth-sender correctly rejected re-initialization (AlreadyInitialized)" else - smoke_fail "Could not confirm sender initialization" + smoke_fail "Could not confirm sender initialization rejection" fi # ────────────────────────────────────────────────────────────────────────────── From d2d69a5651cc1f30a6578cc40459b6d2b6656a83 Mon Sep 17 00:00:00 2001 From: Peolite001 Date: Wed, 30 Sep 2026 12:11:42 +0100 Subject: [PATCH 2/5] chore: fail smoke tests on required rejected paths --- stellar/scripts/deploy-dryrun.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/stellar/scripts/deploy-dryrun.sh b/stellar/scripts/deploy-dryrun.sh index 58c8fbdb..d03126ce 100755 --- a/stellar/scripts/deploy-dryrun.sh +++ b/stellar/scripts/deploy-dryrun.sh @@ -351,7 +351,7 @@ if $CLI contract invoke \ --stealth-meta-address "$TEST_META_ADDRESS" 2>&1 | grep -qi "AlreadyRegistered"; then ok "duplicate name registration rejected (AlreadyRegistered)" else - warn "duplicate name registration not rejected with AlreadyRegistered" + smoke_fail "duplicate name registration not rejected with AlreadyRegistered" fi # 2. Resolve the name (Happy path) @@ -384,7 +384,7 @@ if $CLI contract invoke \ --name "doesnotexist123" 2>&1 | grep -qi "NotFound"; then ok "non-existent name resolution rejected (NotFound)" else - warn "non-existent name resolution not rejected with NotFound" + smoke_fail "non-existent name resolution not rejected with NotFound" fi # 3. Announce an event (Happy path) @@ -418,7 +418,7 @@ if $CLI contract invoke \ --metadata "$TEST_METADATA" 2>&1 | grep -qi "InvalidSchemeId"; then ok "invalid scheme ID rejected (InvalidSchemeId)" else - warn "invalid scheme ID not rejected with InvalidSchemeId" + smoke_fail "invalid scheme ID not rejected with InvalidSchemeId" fi # 4. Query the registry (Rejected / Happy path depending on state) From d46057baca65ba510a65873070b691e70115a5fd Mon Sep 17 00:00:00 2001 From: Peolite001 Date: Wed, 30 Sep 2026 12:23:38 +0100 Subject: [PATCH 3/5] chore: pin github actions dependencies in integration-chaos.yml --- .github/workflows/integration-chaos.yml | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/.github/workflows/integration-chaos.yml b/.github/workflows/integration-chaos.yml index 378c1f7c..2b7c1c7b 100644 --- a/.github/workflows/integration-chaos.yml +++ b/.github/workflows/integration-chaos.yml @@ -5,22 +5,28 @@ on: - cron: "0 3 * * 0" # Weekly, Sunday 3am UTC workflow_dispatch: # Manual trigger +# Reviewed toolchain pins. Bump them only through the process in SUPPLY_CHAIN.md. +env: + RUST_TOOLCHAIN: '1.98.1' + STELLAR_CLI_VERSION: '28.0.0' + jobs: chaos: name: Local chaos suite - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 continue-on-error: true # allow-flaky steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install Rust - uses: dtolnay/rust-toolchain@stable + uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master with: + toolchain: ${{ env.RUST_TOOLCHAIN }} targets: wasm32-unknown-unknown - name: Install Stellar CLI - run: cargo install stellar-cli --locked + run: cargo install stellar-cli --version "=${STELLAR_CLI_VERSION}" --locked - name: Run integration tests working-directory: stellar/integration-tests @@ -29,7 +35,7 @@ jobs: run: cargo test -- --nocapture 2>&1 | tee test-results.txt - name: Upload test results - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() with: name: chaos-test-results From 655f97330bf0a7c1377596c58a075d9e391944c3 Mon Sep 17 00:00:00 2001 From: Peolite1 Date: Mon, 5 Oct 2026 22:54:28 +0100 Subject: [PATCH 4/5] Fix futurenet smoke tests to fail on regression --- .github/workflows/integration-futurenet.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/integration-futurenet.yml b/.github/workflows/integration-futurenet.yml index 5719c3a9..52bcc1cb 100644 --- a/.github/workflows/integration-futurenet.yml +++ b/.github/workflows/integration-futurenet.yml @@ -14,7 +14,6 @@ jobs: integration: name: Futurenet smoke tests runs-on: ubuntu-24.04 - continue-on-error: true # allow-flaky steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -31,7 +30,9 @@ jobs: - name: Run deployed-network smoke test env: STELLAR_ADMIN_SECRET: ${{ secrets.FUTURENET_TEST_SECRET }} - run: ./stellar/scripts/deploy-dryrun.sh 2>&1 | tee test-results.txt + run: | + set -o pipefail + ./stellar/scripts/deploy-dryrun.sh 2>&1 | tee test-results.txt - name: Upload test results uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 From 3221104884a1f2d73ea9f5a2798437ffd1a22616 Mon Sep 17 00:00:00 2001 From: Peolite1 Date: Sat, 10 Oct 2026 07:48:10 +0100 Subject: [PATCH 5/5] Update deploy-dryrun.sh with rejected paths for smoke tests --- stellar/scripts/deploy-dryrun.sh | 35 ++++++++++++++++---------------- 1 file changed, 17 insertions(+), 18 deletions(-) diff --git a/stellar/scripts/deploy-dryrun.sh b/stellar/scripts/deploy-dryrun.sh index d03126ce..a8455b79 100755 --- a/stellar/scripts/deploy-dryrun.sh +++ b/stellar/scripts/deploy-dryrun.sh @@ -404,35 +404,34 @@ else smoke_fail "announce failed" fi -# 3b. Announce with invalid scheme ID (Rejected path) -info "3b/7 Announcing with invalid scheme ID..." -if $CLI contract invoke \ - --id "$ANNOUNCER_ID" \ +# 4. Query the registry (prove stealth-registry works) +info "4/5 Querying stealth-registry..." +REG_RESULT=$($CLI contract invoke \ + --id "$REGISTRY_ID" \ --source "$IDENTITY_NAME" \ --network "$NETWORK" \ -- \ - announce \ - --scheme-id 999 \ - --stealth-address "$ADMIN_ADDRESS" \ - --ephemeral-pub-key "$TEST_EPHEMERAL_KEY" \ - --metadata "$TEST_METADATA" 2>&1 | grep -qi "InvalidSchemeId"; then - ok "invalid scheme ID rejected (InvalidSchemeId)" -else - smoke_fail "invalid scheme ID not rejected with InvalidSchemeId" + stealth_meta_address_of \ + --registrant "$ADMIN_ADDRESS" \ + --scheme-id 2 2>/dev/null) || { + smoke_fail "Could not read back meta-address" + REG_RESULT="" +} +if [ -n "$REG_RESULT" ]; then + ok "meta-address read back successfully" fi -# 4. Query the registry (Rejected / Happy path depending on state) -info "4/7 Querying stealth-registry..." -REG_RESULT=$($CLI contract invoke \ +info " c) Querying unregistered scheme (expecting failure)..." +UNREG_RESULT=$($CLI contract invoke \ --id "$REGISTRY_ID" \ --source "$IDENTITY_NAME" \ --network "$NETWORK" \ -- \ stealth_meta_address_of \ --registrant "$ADMIN_ADDRESS" \ - --scheme-id 2 2>/dev/null) || { - warn "stealth_meta_address_of returned NotRegistered (expected — no key registered yet)" - ok "registry is responsive (NotRegistered is expected)" + --scheme-id 999 2>/dev/null) || { + warn "stealth_meta_address_of returned NotRegistered (expected — no key registered for scheme 999)" + ok "registry correctly rejected unregistered scheme" } # 5. Verify sender is initialized (Rejected path: AlreadyInitialized)