test: migrate credential-test gating to requires_credential marker - #9308
Merged
Merged
Conversation
…es_credential marker Replace the legacy per-test credential gate -- SKIP_* = RUNNING_ON_CI and RUNNING_TEST_FOR_MASTER_ON_CI and not RUN_BY_CANARY -- with the @pytest.mark.requires_credential marker, now that CI runs exclusively on GitHub Actions and AppVeyor is retired. Changes: - Register requires_credential + tiering markers in pytest.ini. - Collapse 25 copies of the branch-name idiom; the branch term was a proven no-op (BY_CANARY is workflow-wide in the only master-triggered workflow). Drop the dead AppVeyor env reads; RUNNING_ON_CI now reads CI directly. - Mark all 43 credential-gated classes with @pytest.mark.requires_credential, then delete every credential @skipIf gate, the SKIP_CREDENTIAL_TESTS flag, the alias imports, and the dead setUpClass runtime guard. Compound gates keep their non-credential condition (IS_WINDOWS, IS_TARGETTED_PYTHON_VERSION). - Filter the two no-credential PR lanes in build.yml (integ-all-other and the buildcmd catch-all) with 'not requires_credential' so credential tests are deselected where no AWS credentials exist. integration-tests.yml already filters correctly (cloud-based-tests selects requires_credential; the credential-free suites exclude it). - Retire the 5 appveyor-*.yml files and the installer appveyor cleanup steps. Verified: full tree collects (2433) under --strict-markers; the no-credential lanes deselect exactly the set the canary lane selects; no credential test runs without credentials in any lane.
Contributor
Author
|
Integration test run: |
licjun
approved these changes
Oct 2, 2026
roger-zhangg
approved these changes
Oct 2, 2026
2 of 9 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue(s) does this change fix?
N/A
Why is this change necessary?
Credential-dependent integration tests were skipped by a stale proxy:
SKIP_* = RUNNING_ON_CI and RUNNING_TEST_FOR_MASTER_ON_CI and not RUN_BY_CANARY. That gate dates from the AppVeyor era and reads a branch name to guess whether AWS credentials exist. CI now runs exclusively on GitHub Actions, so the branch-name proxy no longer describes anything real, and AppVeyor is retired. The right signal is simply "this test needs credentials" — a pytest marker — not an inference from the branch.How does it address the issue?
It replaces the proxy gate with the
@pytest.mark.requires_credentialmarker and lets each CI lane filter on it directly.requires_credential,tier1,tier1_extra,flaky,xdist_group) intopytest.ini'smarkers =block, and mark all 43 credential-gated test classes withrequires_credential. These markers were all already in use and already registered elsewhere —requires_credential/tier1/tier1_extraviatests/conftest.py'spytest_configure, andflaky/xdist_groupby thepytest-rerunfailuresandpytest-xdistplugins — so this is a documentation/consolidation step that puts the whole marker vocabulary in the canonical config, not a first-time registration.tests/conftest.pyis unchanged.@skipIfgate, theSKIP_CREDENTIAL_TESTSflag, its 25 alias imports, and a deadsetUpClassguard. Compound gates keep their non-credential condition (IS_WINDOWS,IS_TARGETTED_PYTHON_VERSION).RUNNING_ON_CInow readsCIdirectly.build.yml(integ-all-otherand thebuildcmdcatch-all) gain-m 'not requires_credential', so credential tests are deselected where no AWS credentials exist.integration-tests.ymlalready filtered correctly and is unchanged.appveyor-linux-binary.yml,appveyor-ubuntu.yml,appveyor-windows-al2023.yml,appveyor-windows-binary.yml,appveyor-windows.yml) and the installer AppVeyor cleanup steps.The behaviour is identical to before: the no-credential lanes deselect exactly the set the credentialed canary lane selects — the marker just makes the decision at collection instead of guessing from the branch name.
What side effects does this change have?
One visible change in the no-credential PR lanes' pytest summary: credential tests are now deselected at collection rather than collected-then-skipped at runtime, so those lanes report fewer collected and fewer skipped tests. No test's run/skip outcome changes in any lane. The full tree still collects cleanly (2433 tests):
pytest.inisetsfilterwarnings = error, so any unregistered marker would raisePytestUnknownMarkWarningas a hard error — registering the five markers keeps that gate satisfied. (Note:--strict-markersis not enabled in this repo;filterwarnings = erroris what enforces registration.)How was this validated?
A two-part no-drop audit compared the base (
develop, old@skipIfgates) against this branch, collecting under the real CI-lane environments. Both parts pass — the migration drops zero tests and runs the identical set in every lane.1. Identical test universe. Full-tree
pytest --collect-onlyyields the same total on both revisions; once a pre-existing parametrize-ordinal non-determinism (two unrelated, untouched parametrized tests whose_NN_<name>suffix shuffles between interpreter runs) is normalized, the two ID sets are byte-identical: 0 added, 0 dropped.2. Per-lane run-set equivalence. For each lane, the base run set (collected minus what the old credential
@skipIfwould skip under that lane's env) equals the branch run set (collected after the-mmarker filter):build.ymlbuildcmd catch-allbuild.ymlinteg-all-otherintegration-tests.ymlcloud-based-testsThe table counts the run set (what executes), which is identical before and after — that is the invariant this PR preserves. What does change is how pytest reports that set: for the buildcmd catch-all, both base and branch collect 272 and run 241, but base reaches 241 by collecting all 272 and skipping 31 credential tests at runtime, whereas the branch reaches 241 by deselecting those 31 at collection (
272 collected, 31 deselected → 241 run). Same 241 executed; the 31 move from runtime-skip to collection-deselect.3. No credential leak in no-credential lanes. Every PR (credential-free) lane selects zero
requires_credentialtests: the two lanes touching credential paths (integ-buildcmd-other: 31 present;integ-all-other: 114 present) deselect all of them vianot requires_credential; the rest have no credential tests on their paths. The credential-heavy command groups (delete/deploy/package/publish/sync/traces/validate/logs) remain path-excluded from the PR matrix exactly as before. Non-credential grouped skips (SKIP_DOCKER_TESTS,SKIP_LMI_TESTS) were not migrated and still collect-then-skip, unchanged.Mandatory Checklist
PRs will only be reviewed after checklist is complete
make prpasses — validated via the full canary integration-tests run (24/24 green)make update-reproducible-reqsif dependencies were changed — N/A, no dependency changes