AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 18 Monero

ci: port tests branch CI fixes to vacay

Public commit record

What the developer wrote

Authored by sneurlax

90/100 · Strong
ci: port tests branch CI fixes to vacay

- Replace PowerShell workflow with bash-based test.yaml from tests branch
(rustup install, valac/libtss2-dev deps, git_versions stubs, bash secrets,
ensure_test_app_config.sh, prebuild.sh, build_runner, coverage checks)
- Add scripts/ensure_test_app_config.sh (stub app_config.g.dart for CI)
- Add test infrastructure: hive_ce_test_utils, mock_electrum_server,
platform_test_overrides
- Update test files from tests branch (change_now, node_service, lockscreen,
create_pin, firo_wallet, price, electrumx, cached_electrumx, node_card,
node_options_sheet, utilities)
- Delete stale mock files; regenerate all mocks via build_runner
- Add testNodeConnectionProvider + typedef to test_node_connection.dart;
switch node_card, node_options_sheet, add_edit_node_view, node_details_view
to call via provider so platform_test_overrides can intercept in tests
- Fix logger infinite recursion: swallow dispatch errors instead of
recursively calling t() which causes StackOverflow in tests
- Upgrade bitcoindart to b02aaf6c (adds isParticl param used by particl_wallet)
with dependency_overrides entry to beat bip47's pin
- Pin dart_style 3.1.3 and analyzer <8.4.0 in pubspec.lock for build_runner
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
The short version

What changed, and why it matters

This commit is almost entirely about making the automated test suite run reliably in CI. It swaps a PowerShell CI workflow for a bash one, adds test helpers and stubs, updates many generated mock files, and makes a small code change so the logger does not call itself forever when it fails. There is no obvious security vulnerability being introduced; the main risk is that a real bug in the logger could now be silently swallowed instead of reported.

Recommended action

No immediate security action required. Review the logger swallow change to ensure production log failures are still observable through other channels (e.g., stderr, crash reporting). Verify the CI secret handling and stub generation do not leak real keys or write unexpected files in release builds.

Security signals we found

01

Logger error path changed from recursive logging to silent swallowing

02

CI workflow now decodes only CHANGE_NOW secret; other per-coin test parameter secrets removed from workflow

03

New test stub script writes a generated app_config.g.dart if missing

04

test_node_connection refactored to use a Reader instead of WidgetRef for test overrides

Risk score

Why this scored 18/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 2/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.