Files
OmniRoute/tests/integration/live-default-combo-wire-capture.test.ts
Diego Rodrigues de Sa e Souza a448b146bf cherry-pick(pr-9744): test(integration): add general live-test tool for the real "default" combo + rootless wire capture (#9862)
* test(integration): add general live-test tool for the real "default" combo

Temporary WIP commit on this deferred branch — lands in its own separate
PR once the bug-fix extraction batch is done (never bundled into a
bug-fix PR). Unlike liveGeminiShared.ts (provisions its own narrow
2-model Gemini-only combo), this reads the REAL "default" combo
currently configured on the target instance directly from the DB and
exercises every provider/model step in it directly, bypassing combo
routing, so live-test coverage always matches whatever is actually
configured instead of a hardcoded snapshot.

Live-verified against omniroute-beta (seeded with the real 18-model,
5-provider default combo): 14/18 models pass consistently across
non-streaming + streaming Chat Completions and streaming Responses API.
The 4 consistent failures are real external state (cerebras
credits_exhausted, one deprecated openrouter free-tier model), not code
regressions.

(cherry picked from commit c40b13a48fd897259c56f5122e9e57a3dc7654ba)

* test(integration): add rootless wire-capture correlation to the live-test tool

Temporary WIP commit on this deferred branch — lands in the same final
live-test-tool PR as the general default-combo suite, never bundled into
a bug-fix PR.

liveContainerHarness.ts spins up a dedicated, throwaway podman container
(same runner-base image target as the operator's local dev/beta
containers) so wire-capture tests are fully self-contained: builds the
image if missing, starts the container with a persistent data dir, waits
for health, seeds the real "default" combo + provider connections from
the operator's local omniroute-dev instance (idempotent — only runs once
per data dir), and provisions API keys via the running instance's own
auth flow.

wireCapture.ts captures the container's actual network traffic via
`podman unshare nsenter --net=<container netns> -- tcpdump` — no root
needed, verified working live (this generalizes the root-requiring
`sudo nsenter -t $PID` command scripts/sre/tcp-close-analyzer.py already
documented for the same rootless-Podman netns problem; that script's
docstring now documents both). Capture and analysis needed two real fixes
found only by running the pipeline live: `-U` (unbuffered tcpdump writes)
plus a `pkill -f <pcap path>` fallback, since `podman unshare -> nsenter
-> tcpdump` is a 3-level subprocess chain and SIGTERM to the top-level
process doesn't reach the tcpdump grandchild, leaving an orphaned process
and a truncated/unreadable pcap; and filtering on the container's
internal listening port (20128) rather than the dynamically-assigned host
port, since capture happens inside the container's own network namespace
where only the internal port is meaningful.

live-default-combo-wire-capture.test.ts (gated on RUN_LIVE_WIRE_CAPTURE=1)
ties it together: sends a small representative sample of requests through
the real default combo, then cross-checks each one's app-level JSON
status against the actual HTTP status line observed on the wire via
scripts/sre/tcp-close-analyzer.py's stream reassembly — catching bugs
where the app layer claims success but the wire shows a
truncated/reset stream, not just what liveDefaultComboShared.ts's
existing breadth suite already covers.

Live-verified end-to-end: 4/4 sampled requests correlated correctly
across 8 captured TCP streams, container + capture process fully torn
down afterward (verified no orphaned podman container or tcpdump
process left running).

sendModelRequest/filterActiveModelTargets (liveDefaultComboShared.ts) gain
optional baseUrl/apiKey overrides, defaulting to the existing module-level
omniroute-beta target, so the wire-capture suite can point the same
request-sending logic at its own dedicated container instead.

(cherry picked from commit 914a7e42cbe914f257db9f72eedc902ee1532083)

---------

Co-authored-by: Markus Hartung <mail@hartmark.se>
2026-08-09 09:53:07 -03:00

144 lines
5.2 KiB
TypeScript

/**
* tests/integration/live-default-combo-wire-capture.test.ts
*
* Wire-level correlation test. Spins up a dedicated, throwaway podman
* container (liveContainerHarness.ts), captures its network traffic
* (wireCapture.ts — rootless tcpdump via `podman unshare nsenter`, no root),
* sends a representative sample of requests against the real "default"
* combo, then cross-checks each request's app-level result (JSON status)
* against what actually went out on the wire (HTTP response status line,
* verdict on who closed the connection first). Catches bugs where the app
* layer claims success but the wire shows a truncated/reset stream.
*
* Fully self-contained — does not touch omniroute-beta or omniroute-dev
* (only reads from omniroute-dev's DB once, to seed its own dedicated
* container's data dir). Gated on RUN_LIVE_WIRE_CAPTURE=1: needs podman,
* tcpdump, python3, and a real .env with provider credentials, so it must
* never run in CI.
*/
import test from "node:test";
import assert from "node:assert/strict";
import {
LIVE_CONTAINER_ENABLED,
startLiveContainer,
type LiveContainerHandle,
} from "./liveContainerHarness.ts";
import {
startWireCapture,
analyzeCapture,
indexByCorrelationId,
responseStatusLine,
type CaptureHandle,
} from "./wireCapture.ts";
import {
getDefaultComboModelTargets,
filterActiveModelTargets,
sendModelRequest,
} from "./liveDefaultComboShared.ts";
const skip = !LIVE_CONTAINER_ENABLED
? "RUN_LIVE_WIRE_CAPTURE not set — skipping wire-capture live test"
: undefined;
// Wire-level correlation is the point of this suite, not breadth across
// every provider (already covered by live-default-combo-workload.test.ts) —
// keep the sample small so capture/analysis stays fast.
const SAMPLE_SIZE = 4;
let container: LiveContainerHandle;
let capture: CaptureHandle;
test.before(async () => {
if (skip) return;
container = await startLiveContainer();
process.env.DATA_DIR = container.dataDir;
// PID-scoped so a concurrent session running this same test never
// collides on the capture file or the pkill-by-path cleanup in
// wireCapture.ts's stop().
const pcapPath = `/tmp/omniroute-live-wire-capture-${process.pid}.pcap`;
// Capture happens INSIDE the container's own netns (podman unshare
// nsenter --net=<SandboxKey>), so packets there are addressed to the
// container's internal listening port (20128), not the dynamically
// assigned host port used to reach it from outside — filtering on
// hostPort here would silently match nothing.
capture = await startWireCapture(container.netnsPath, pcapPath, "tcp port 20128");
});
test.after(async () => {
if (skip) return;
await capture?.stop();
await container?.stop();
});
test(
"wire capture: app-level status matches the HTTP status line actually observed on the wire",
{ skip },
async () => {
const allTargets = await getDefaultComboModelTargets();
assert.ok(allTargets.length > 0, `"default" combo has no model steps — nothing to test`);
const { active } = await filterActiveModelTargets(allTargets, {
baseUrl: container.baseUrl,
apiKey: container.managementApiKey,
});
assert.ok(active.length > 0, "no active provider connections in the seeded container");
const sample = active.slice(0, SAMPLE_SIZE);
console.log(
`\n [wire-capture] sampling ${sample.length} model(s): ${sample.map((t) => t.model).join(", ")}`
);
const results = await Promise.all(
sample.map((t) =>
sendModelRequest(t.model, false, "chat", {
baseUrl: container.baseUrl,
apiKey: container.apiKey,
})
)
);
// Give the capture a moment to flush the last packets before analyzing.
await new Promise((r) => setTimeout(r, 1000));
await capture.stop();
const streams = await analyzeCapture(capture.pcapPath);
const byCorrelationId = indexByCorrelationId(streams);
console.log(` [wire-capture] captured ${streams.length} TCP stream(s)`);
const mismatches: string[] = [];
for (const r of results) {
if (r.correlationId === "?") {
mismatches.push(`${r.model}: no correlationId returned in response headers`);
continue;
}
const matched = byCorrelationId.get(r.correlationId);
if (!matched || matched.length === 0) {
mismatches.push(
`${r.model}: correlationId ${r.correlationId} not found in any captured wire stream`
);
continue;
}
const wireStatusLines = matched.map(responseStatusLine).filter(Boolean);
const wireStatusCodes = wireStatusLines.map((line) => line!.split(" ")[1]);
if (!wireStatusCodes.includes(String(r.status))) {
mismatches.push(
`${r.model}: app-level status ${r.status} but wire shows ${wireStatusCodes.join(",") || "no status line"} (cid ${r.correlationId})`
);
}
}
if (mismatches.length > 0) {
console.log(`\n Wire/app-level mismatches (${mismatches.length}):`);
for (const m of mismatches) console.log(` ${m}`);
}
assert.equal(
mismatches.length,
0,
`${mismatches.length}/${results.length} requests had app-level results that don't match what was observed on the wire`
);
}
);