Skip to content

fix(invite-gate): drop --allow-scripts from moonlight-pay deno install - #83

Merged
AquiGorka merged 1 commit into
mainfrom
fix/invite-gate-mp-allow-scripts
May 5, 2026
Merged

fix(invite-gate): drop --allow-scripts from moonlight-pay deno install#83
AquiGorka merged 1 commit into
mainfrom
fix/invite-gate-mp-allow-scripts

Conversation

@AquiGorka

Copy link
Copy Markdown
Contributor

Summary

The invite-gate CI suite started failing on amd64 Linux runners with spawn node-gyp ENOENT cascading through bufferutil, utf-8-validate, usb, secp256k1, blake-hash, esbuild, etc. Locally on arm64 macOS Docker the same compose passed because the prebuilds exist for that arch.

--allow-scripts opted into running every npm postinstall in the moonlight-pay container. Those native modules are optional ws/wallet-hardware deps that the frontend bundle does not actually use at runtime, so dropping the flag avoids the node-gyp path entirely.

Verified: BASE_DIR=… ./test.sh invite-gate → 6/6 pass on macOS arm64. The same change is applied to docker-compose.playwright.yml so the full-flow suite picks it up too.

Test plan

  • ./test.sh invite-gate — 6/6 pass locally
  • CI re-runs invite-gate green on this PR (and downstream consumers)

bufferutil@4.1.0 (and a chain of optional native deps) lack amd64 Linux
prebuilds and try to spawn node-gyp at install time, which is not in the
denoland/deno container. The frontend bundle does not use these modules
at runtime, so installing without postinstall scripts is safe.
@AquiGorka
AquiGorka merged commit 69d7176 into main May 5, 2026
6 checks passed
@AquiGorka
AquiGorka deleted the fix/invite-gate-mp-allow-scripts branch May 5, 2026 17:58
AquiGorka added a commit that referenced this pull request May 6, 2026
…ate local-dev PRs on invite-gate spec (#85)

## Summary

Two related changes:

1. **Fix the regression** — restore CI-safe defaults in the shared
`playwright/fixtures/contexts.ts`; push recording-only overrides to the
recording specs.
2. **Prevent recurrence** — gate local-dev PRs on the invite-gate spec
so this failure class is caught at the source.

## 1. The regression

PR #82 ([`feat(recording): rig improvements for Tranche 2
demo`](#82)) added
macOS-specific browser launch args + `viewport: null` + 80% page zoom
directly into the **shared** `playwright/fixtures/contexts.ts`. That
file is also imported by the invite-gate playwright spec, which runs in
CI Docker xvfb at `1280x960`.

The `--window-size=1728,1080` override (larger than the xvfb display)
causes Chromium's GPU process to fail initialization in CI:

```
TimeoutError: browserType.launch: Timeout 180000ms exceeded.
[err] [...:ERROR:components/viz/service/main/viz_main_impl.cc:189]
       Exiting GPU process due to errors during initialization
```

This has broken every council-console / moonlight-pay / provider-console
PR opened since 2026-05-05 (PR #82's merge). Recording itself was
unaffected because it runs on macOS host with a real display.

### Fix (commit 1)

- **`playwright/fixtures/contexts.ts`**: restore CI-safe defaults (no
`--start-maximized`, no `--window-size`, viewport `1280x800`, no zoom).
Add a third `options` parameter (`CreateUserContextOptions`) for
per-call overrides.
- **`recording/playwright/fixtures/recording-context.ts`** (new):
exports `RECORDING_CONTEXT_OPTIONS` with the recording-host args +
`viewport: null` + `applyZoom: true`.
- **`recording/playwright/specs/01-council-onboard.spec.ts`** +
**`02-provider-create-join-approve.spec.ts`**: pass
`RECORDING_CONTEXT_OPTIONS` to `createUserContext`.

`invite-gate.spec.ts` and `full-flow.spec.ts` are unchanged — they call
`createUserContext` without overrides and now get the CI-safe shape.

## 2. Why local-dev's own CI didn't catch it

The invite-gate spec only runs from consumer-repo PRs via the reusable
workflow (`invite-gate-reusable.yml`), and that workflow's local-dev
checkout was hardcoded to `main`. local-dev's own E2E pipeline runs the
`e2e/` Docker stack, not playwright. PR #82 went green on local-dev CI
while silently breaking every downstream PR.

### Fix (commit 2)

- **`invite-gate-reusable.yml`**: new `local_dev_ref` input (defaults to
`main`, so existing consumer-repo callers are unchanged).
- **`.github/workflows/invite-gate.yml`** (new): triggers on local-dev
PRs and calls the reusable with `local_dev_ref: ${{ github.head_ref }}`.
PR #82-class regressions now fail CI here on the source PR.

Trade-off: adds ~8 min to every local-dev PR run, plus playwright flake
risk. Worth it given recent infra churn (PRs #82, #83, #84 all touched
test infra in 10 days).

## Test plan

- [ ] After merge, re-run the four open hardening PRs on the consumer
repos (council-console #34, moonlight-pay #26, provider-console #25,
network-dashboard #11) and confirm `invite-gate / invite-gate` goes
green.
- [ ] This PR's own `Invite Gate` CI run (newly added) should pass.
- [ ] Run a recording spec locally (`bash
recording/setup-recording-keys.sh` + `npx playwright test
--config=recording/playwright/playwright.config.ts`) and confirm
Chromium still launches maximized with 80% zoom and click-highlight
intact.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant