Skip to content

fix(e2ee): stabilize production storage CI - #416

Merged
VishnuM049 merged 1 commit into
RCfrom
fix/e2ee-production-ci
Sep 20, 2026
Merged

VishnuM049 merged 1 commit into
RCfrom
fix/e2ee-production-ci

Conversation

@VishnuM049

Copy link
Copy Markdown
Contributor

Purpose

Restore the E2EE browser and macOS Keychain checks that block aggregate draft PR #394.

Chrome, Firefox, and WebKit stopped before browser execution because WASM clippy treated two native-only resync methods as dead code. Both Keychain jobs reached their 20-minute timeout because the concurrency test waited at a two-party insert barrier while holding the shared store mutex.

Fixes

Fixes: N/A. CI stabilization for #394.

Approach

  • Compile the two resync helpers only for non-WASM targets, matching their native persistence callers.
  • Run the conflicting Keychain prepare test through independent store instances backed by one fake Keychain. This exercises the cross-constructor insertion race without deadlocking on one instance's serialization mutex.

The change does not alter endpoint behavior, dependencies, support metadata, or production readiness. Production constructors remain fail-closed and productionStorageReady remains false.

How was this tested?

Passed:

cd packages/e2ee && cargo test --locked
cd packages/e2ee && cargo fmt --check
cd packages/e2ee && cargo clippy --locked --all-targets -- -D warnings
cd packages/e2ee && cargo clippy --locked -p axl-e2ee --all-targets --features browser-test-fixtures -- -D warnings
cd packages/e2ee && cargo clippy --locked -p axl-e2ee-node --all-targets --features test-fixtures -- -D warnings
cd packages/e2ee && cargo clippy --locked --target wasm32-unknown-unknown -p axl-e2ee --features browser-test-fixtures -- -D warnings
cd packages/e2ee && cargo clippy --locked --target wasm32-unknown-unknown -p axl-e2ee-browser --all-targets --features test-fixtures --no-deps -- -D warnings
AXL_RUN_MACOS_KEYCHAIN_TESTS=1 cargo test --locked -p axl-e2ee macos_keychain -- --nocapture
pnpm --filter @axl/e2ee-browser build
pnpm --filter @axl/e2ee-browser build:test
pnpm --filter @axl/e2ee-browser check:abi
pnpm --filter @axl/e2ee-browser check:types
pnpm --filter @axl/e2ee-browser pack:local
pnpm --filter @axl/e2ee-browser exec playwright test --project=chrome
pnpm --filter @axl/e2ee-browser exec playwright test --project=firefox
pnpm --filter @axl/e2ee-browser exec playwright test --project=webkit
pnpm --filter @axl/e2ee-browser test:safari
pnpm --filter @axl/e2ee-node test
pnpm --filter @axl/e2ee-node check:abi
pnpm --filter @axl/e2ee-node pack:local
pnpm format:check
pnpm lint
pnpm typecheck
pnpm check:boundaries
pnpm check:generated
reuse lint
git diff --check

Results and limitations:

  • Chrome, Firefox, and WebKit each passed all 7 focused tests.
  • Actual Safari WebDriver evidence passed. Passwordless sudo safaridriver --enable was unavailable, but Safari WebDriver was already enabled.
  • The local host provided macOS arm64 Keychain coverage. The unsigned data-protection Keychain probe returned access denied as expected and remained fail-closed. Native Intel execution remains CI-only.
  • Node tests passed 12 tests and skipped the opt-in real relay integration because AXL_RUN_REAL_E2EE_RELAY_INTEGRATION and Mix were not configured.
  • The root pnpm test run reached an unrelated daemon cleanup failure in queue restore leaves queue and active work untouched when its event append fails, then hit the one-hour command timeout. A focused diagnostic run reproduced an ENOENT during that test's cleanup. PR feat: integrate E2EE remote-control foundation #394's existing Build and test job passes, and this PR does not change daemon code.
  • Browser production builds retain existing dead-code warnings. All required clippy invocations pass with warnings denied.
  • Cargo and npm dependency audits were not rerun because no dependency declaration or lockfile changed.

Learning

A synchronization barrier placed below a serialized store boundary cannot model competing constructors. Cross-constructor races need separate store owners sharing only the external atomic backend.

Checklist

  • I reviewed the complete diff.
  • I added or updated the smallest relevant test for behavior changes.
  • I ran the relevant formatting, lint, type-check, test, boundary, and license checks.
  • Every new file has SPDX metadata, directly or through REUSE.toml.
  • Every commit has a matching DCO Signed-off-by trailer.
  • UI changes include screenshots attached to the pull request, not committed to the repository. No UI files changed.

AI assistance

  • Generative AI materially assisted this change. Tool and model/version: pi coding agent with OpenAI ChatGPT; the harness did not expose a model identifier.
  • I manually reviewed, understood, and tested the generated work. The responsible human reviewer must complete this before merge.

Signed-off-by: VishnuM049 <vishnu.muthiah04@gmail.com>
@coderabbitai

coderabbitai Bot commented Sep 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1683f67d-fdd7-4ded-b1b9-ad6e1921a715

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@VishnuM049
VishnuM049 merged commit 6a53764 into RC Sep 20, 2026
34 checks passed
@VishnuM049
VishnuM049 deleted the fix/e2ee-production-ci branch September 20, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant