RC-7
release-tag / release-image (push) Failing after 2m44s

This commit is contained in:
2026-08-11 16:58:07 +02:00
parent 185ccf1101
commit bcfbef390f
44 changed files with 4778 additions and 172 deletions
+114
View File
@@ -357,3 +357,117 @@ WS: normal browser websocket connects; a foreign browser Origin is rejected
```
The OpenAI circuit breaker uses rolling windows and successful usage rows. Set very small limits in Admin Runtime to verify that a winning artifact stays `pending` with an `OpenAI cost circuit breaker active` diagnostic instead of making another provider call. Restore the desired limits afterward.
## V3.9 portable identity + owned artifact recovery
1. Start the CLI with a persistent identity path and note the printed Client-ID and file path:
```bash
NEURALHUNT_IDENTITY=/tmp/nh-client/identity.json go run ./cmd/client -url http://127.0.0.1:8080
```
2. Run `identity` and verify the same Client-ID/path is shown. Restart with the same file and verify the Client-ID is unchanged.
3. Set a passphrase of at least 12 characters and create an encrypted browser-compatible backup:
```bash
export NEURALHUNT_IDENTITY_PASSPHRASE='correct horse battery staple'
go run ./cmd/client -identity /tmp/nh-client/identity.json -export /tmp/neuralhunt-browser-import.json
```
4. In the browser choose **IDENTITÄT → IMPORT**, select that JSON, enter the same passphrase and confirm the switch. The browser Client-ID must exactly equal the CLI Client-ID. The import validates that public/private P-256 keys can sign/verify and that the optional export Client-ID matches.
5. After a win is fully rendered, **MEINE NFTS** must list the artifact and **ORIGINAL** must download the unwatermarked artifact. A different identity requesting `/api/me/artifacts/<task-id>/download` must receive 404.
6. In the CLI, `my-nfts` lists only the authenticated identity's ready winner artifacts and `nft original <task-id> <datei>` downloads the original. `nfts` / `nft get` remain public watermarked previews.
7. Verify legacy encrypted exports without `format/clientId/iterations` metadata still import using 250,000 PBKDF2 iterations.
Focused identity tests can run without the optional network/database dependencies:
```bash
go test ./cmd/client/identity.go ./cmd/client/identity_test.go
node --check internal/webui/dist/app.js
```
## V4.0 Beacon Hunt + Hosted Service smoke test
### Beacon Hunt
1. Start the game and enable `Guess Lottery Max Accepted > 0` plus `Beacon Hunt` in Admin Runtime.
2. Open two browser/CLI identities and choose different paths (`PULSE`, `FLUX`, `ORBIT`).
3. Confirm requests wait until the window closes and that `/api/public/beacon/<task-id>/latest` returns the recorded drand round, signature, derived randomness and boosted path.
4. Disable Beacon Hunt again and confirm the legacy `crypto/rand` lottery still works.
### Hosted reward pairing
1. Build with `make images-compose`, then start with `docker compose --profile hosted up -d` and route 8090 publicly over HTTPS; keep 8081/8091/8092 private.
2. Create/log in to a Customer Service account.
3. Log into the normal Neural Hunt browser with the desired reward identity and click **HOSTED CODE** (or run `hosted-code` in the CLI).
4. Paste the one-shot code into the Customer Service portal. Confirm the portal shows the proven Client-ID. Reusing the same code must fail.
### Protected manual credits
1. Set `CS_ALLOW_MANUAL_CREDITS=1` only in a test/private environment.
2. Log into the Customer Service admin on private port 8091 and grant a small amount of credits.
3. Verify the customer ledger contains a positive `manual_test_grant` entry.
4. Set `CS_ALLOW_MANUAL_CREDITS=0` again and verify grants are rejected.
### Managed workers / prepaid stop
1. Create a worker and assign an active task and Beacon path.
2. Start it. The worker should create/register its own P-256 identity and the game should install `worker -> reward owner` delegation.
3. Let the worker win a test task (use a deliberately tiny range only in a private test environment). Confirm `winner_client_id` is the main reward owner while `winner_worker_client_id` is the worker identity.
4. Reduce the prepaid balance to less than one billable minute and verify Customer Service stops the worker before another paid minute is allowed.
5. Stop/start the worker and confirm its Docker identity volume preserves the same Client-ID.
6. Download the worker identity, replace it with another valid raw identity, start again and confirm a new worker Client-ID registers while reward ownership remains delegated to the same main identity.
### PayPal Sandbox
1. Keep `PAYPAL_ENVIRONMENT=sandbox` and configure sandbox client ID/secret/webhook ID.
2. Buy the smallest test package from the Customer Service portal.
3. Confirm credits are added only after a server-confirmed `COMPLETED` capture whose amount and currency match the stored package.
4. Repeat the return/capture callback or webhook and verify the `paypal:<order-id>` ledger reference prevents duplicate credits.
5. Leave live mode disabled until the provider/legal review for the actual product is complete.
## V4.1 split Docker images
1. Build the three roles locally:
```bash
docker buildx bake --load
```
2. Verify the image contents/entrypoints:
```bash
docker image inspect neuralhunt-server:local --format '{{json .Config.Entrypoint}}'
docker image inspect neuralhunt-customer-service:local --format '{{json .Config.Entrypoint}}'
docker image inspect neuralhunt-worker:local --format '{{json .Config.Entrypoint}}'
```
Expected entrypoints are `/app/neuralhunt`, `/app/neuralhunt-customer-service`
and `/app/neuralhunt-client` respectively. The server image should not contain
the client or Customer Service binaries.
3. For local Hosted Service testing, build/tag the worker image before starting
the hosted profile:
```bash
make images-compose
docker compose --profile hosted up -d
```
4. Set `CS_WORKER_IMAGE` to a deliberately missing public image with
`CS_WORKER_AUTO_PULL=true`; starting a worker should cause Docker Engine to pull
the configured image. Repeat with `CS_WORKER_AUTO_PULL=false`; the request must
fail before prepaid credits are charged.
5. For a private registry, configure a read-only token with
`CS_WORKER_REGISTRY_SERVER/USERNAME/PASSWORD`, remove the local worker image and
confirm an on-demand pull succeeds. Verify the credentials do not appear in the
managed worker container environment (`docker inspect`).
Focused stdlib-only tests for the Docker image orchestration can be run even
without the application's external Go dependencies:
```bash
go test ./internal/customer/docker.go ./internal/customer/docker_test.go
```