fix(invite-gate): drop --allow-scripts from moonlight-pay deno install - #83
Merged
Conversation
bufferutil@4.1.0 (and a chain of optional native deps) lack amd64 Linux prebuilds and try to spawn node-gyp at install time, which is not in the denoland/deno container. The frontend bundle does not use these modules at runtime, so installing without postinstall scripts is safe.
3 tasks
AquiGorka
added a commit
that referenced
this pull request
May 6, 2026
…ate local-dev PRs on invite-gate spec (#85) ## Summary Two related changes: 1. **Fix the regression** — restore CI-safe defaults in the shared `playwright/fixtures/contexts.ts`; push recording-only overrides to the recording specs. 2. **Prevent recurrence** — gate local-dev PRs on the invite-gate spec so this failure class is caught at the source. ## 1. The regression PR #82 ([`feat(recording): rig improvements for Tranche 2 demo`](#82)) added macOS-specific browser launch args + `viewport: null` + 80% page zoom directly into the **shared** `playwright/fixtures/contexts.ts`. That file is also imported by the invite-gate playwright spec, which runs in CI Docker xvfb at `1280x960`. The `--window-size=1728,1080` override (larger than the xvfb display) causes Chromium's GPU process to fail initialization in CI: ``` TimeoutError: browserType.launch: Timeout 180000ms exceeded. [err] [...:ERROR:components/viz/service/main/viz_main_impl.cc:189] Exiting GPU process due to errors during initialization ``` This has broken every council-console / moonlight-pay / provider-console PR opened since 2026-05-05 (PR #82's merge). Recording itself was unaffected because it runs on macOS host with a real display. ### Fix (commit 1) - **`playwright/fixtures/contexts.ts`**: restore CI-safe defaults (no `--start-maximized`, no `--window-size`, viewport `1280x800`, no zoom). Add a third `options` parameter (`CreateUserContextOptions`) for per-call overrides. - **`recording/playwright/fixtures/recording-context.ts`** (new): exports `RECORDING_CONTEXT_OPTIONS` with the recording-host args + `viewport: null` + `applyZoom: true`. - **`recording/playwright/specs/01-council-onboard.spec.ts`** + **`02-provider-create-join-approve.spec.ts`**: pass `RECORDING_CONTEXT_OPTIONS` to `createUserContext`. `invite-gate.spec.ts` and `full-flow.spec.ts` are unchanged — they call `createUserContext` without overrides and now get the CI-safe shape. ## 2. Why local-dev's own CI didn't catch it The invite-gate spec only runs from consumer-repo PRs via the reusable workflow (`invite-gate-reusable.yml`), and that workflow's local-dev checkout was hardcoded to `main`. local-dev's own E2E pipeline runs the `e2e/` Docker stack, not playwright. PR #82 went green on local-dev CI while silently breaking every downstream PR. ### Fix (commit 2) - **`invite-gate-reusable.yml`**: new `local_dev_ref` input (defaults to `main`, so existing consumer-repo callers are unchanged). - **`.github/workflows/invite-gate.yml`** (new): triggers on local-dev PRs and calls the reusable with `local_dev_ref: ${{ github.head_ref }}`. PR #82-class regressions now fail CI here on the source PR. Trade-off: adds ~8 min to every local-dev PR run, plus playwright flake risk. Worth it given recent infra churn (PRs #82, #83, #84 all touched test infra in 10 days). ## Test plan - [ ] After merge, re-run the four open hardening PRs on the consumer repos (council-console #34, moonlight-pay #26, provider-console #25, network-dashboard #11) and confirm `invite-gate / invite-gate` goes green. - [ ] This PR's own `Invite Gate` CI run (newly added) should pass. - [ ] Run a recording spec locally (`bash recording/setup-recording-keys.sh` + `npx playwright test --config=recording/playwright/playwright.config.ts`) and confirm Chromium still launches maximized with 80% zoom and click-highlight intact.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The invite-gate CI suite started failing on amd64 Linux runners with
spawn node-gyp ENOENTcascading through bufferutil, utf-8-validate, usb, secp256k1, blake-hash, esbuild, etc. Locally on arm64 macOS Docker the same compose passed because the prebuilds exist for that arch.--allow-scriptsopted into running every npm postinstall in the moonlight-pay container. Those native modules are optional ws/wallet-hardware deps that the frontend bundle does not actually use at runtime, so dropping the flag avoids the node-gyp path entirely.Verified:
BASE_DIR=… ./test.sh invite-gate→ 6/6 pass on macOS arm64. The same change is applied todocker-compose.playwright.ymlso the full-flow suite picks it up too.Test plan
./test.sh invite-gate— 6/6 pass locally