test: lock in the field-specific startup error with static, mutation and deterministic probes (E00-S04-T02)

- tests/config-startup-error.test.mjs: static assertions on the committed
  startup-error module, the package boundary, the server wiring (validation
  before bind), the compose secret and the Dockerfile shipping, each backed
  by mutation probes; the deterministic probes execute the issue's test plan
  ("start with a missing required field and confirm the error names it") —
  the compiled boundary throws MissingRequiredSettingError naming
  sessionSecret, and booting the committed server without EPPP_SESSION_SECRET
  exits non-zero naming the field while a valid secret boots to /health 200
- health-endpoint/app-readiness boot probes: provide a valid
  EPPP_SESSION_SECRET (the required setting is validated at startup)
- ci.yml: new config-startup-error job (builds config + database-postgres,
  runs the suite); app-readiness job now builds the config package too
- .gitignore: transient .config-startup-probe-*.mjs files
This commit is contained in:
implementer
2026-08-30 03:00:45 +00:00
parent 0ce790fca3
commit 1a9fd592d9
5 changed files with 695 additions and 10 deletions
+11 -2
View File
@@ -246,7 +246,11 @@ function reservePort() {
/**
* Boots the committed server source on `port` with the given env overrides
* (merged over `process.env`; `DATABASE_URL` is stripped unless explicitly
* provided). Returns `{ child, stderr, stdout }`; the child writes its
* provided, and a valid `EPPP_SESSION_SECRET` is provided unless explicitly
* overridden — since E00-S04-T02 the required admin-session secret is
* validated at startup, and a missing secret is the field-specific
* startup-error path locked in by tests/config-startup-error.test.mjs).
* Returns `{ child, stderr, stdout }`; the child writes its
* stdout/stderr into closures for diagnostics.
*/
function bootServer(port, envOverrides = {}) {
@@ -254,7 +258,12 @@ function bootServer(port, envOverrides = {}) {
tsExecMode() === 'strip-types-flag'
? ['--experimental-strip-types', SERVER_SRC]
: [SERVER_SRC];
const env = { ...process.env, PORT: String(port), ...envOverrides };
// Strip an inherited DATABASE_URL unless the caller explicitly provides one
// (the no-database path must be deterministic), and provide the required
// admin-session secret (E00-S04-T02) unless the caller overrides it.
const env = { ...process.env, PORT: String(port) };
delete env.DATABASE_URL;
Object.assign(env, { EPPP_SESSION_SECRET: 's'.repeat(32) }, envOverrides);
const child = spawn(process.execPath, args, {
cwd: REPO_ROOT,
env,