oscerd opened a new pull request, #26987:
URL: https://github.com/apache/camel/pull/26987

   ## What
   
   Fixes the camel-opa test failures reported in #26969 by finishing 
CAMEL-24742 instead of reverting it.
   
   ## Why it broke
   
   Three camel-opa PRs merged within two minutes on 2026-09-25, each green 
against its own base:
   
   | Merged (UTC) | PR | Effect |
   |---|---|---|
   | 09:04:48 | #26670 (CAMEL-24830) | added `OpaSecurityPolicyWasmTest`, which 
loads `classpath:authz.wasm` |
   | 09:05:45 | #26677 (CAMEL-24742) | deleted `authz.wasm` and moved the 
bundle-dependent producer tests to ITs |
   | 09:06:45 | #26679 (CAMEL-24740) | added another `classpath:authz.wasm` 
reference |
   
   `OpaSecurityPolicyWasmTest` wires its `direct:wasm` route in 
`createRouteBuilder()`, so the missing fixture fails context startup and all 8 
of its tests error with the `FileNotFoundException` quoted in #26969. Those 8 
are the only camel-opa failures in Jenkins `main` build #2223. 
`OpaBatchEvaluationTest` kept passing only because `batch` is rejected before 
the bundle is opened.
   
   ## How
   
   The same split #26677 applied to the producer tests:
   
   - **`OpaSecurityPolicyWasmIT`** (new) takes the three tests that need a 
bundle that evaluates: allow, deny, and "only the rest policy registers a 
readiness check". They moved unchanged. `@BeforeAll` compiles `authz.rego` with 
`OpaWasmBundleBuilder`, as `OpaWasmIT` does.
   - **`OpaSecurityPolicyWasmTest`** keeps the five startup-failure tests, 
which never need a working bundle. `failsRouteStartOnAPoolSizeBelowOne` now 
uses `file:unused.wasm`, since `poolSize` is rejected before the location is 
opened.
   - **`OpaBatchEvaluationTest.rejectsBatchInWasmModeAtStartup`** gets the same 
`file:unused.wasm` treatment for its dead reference.
   - Two comments (`OpaIT`, `wasm-data/roles.rego`) still named 
`OpaWasmEvaluatorTest`, which #26677 renamed to `OpaWasmIT`.
   
   ## Testing
   
   - Reproduced on `main`: `OpaSecurityPolicyWasmTest` 8 of 8 errors, `Cannot 
find resource: classpath:authz.wasm`.
   - `mvn clean verify` in `components/camel-opa` (Docker): 92 unit tests and 
26 ITs, 0 failures. `OpaSecurityPolicyWasmIT` 3/3.
   - Broke the `allow` rule in `authz.rego`: 
`OpaSecurityPolicyWasmIT.allowsWhenTheWasmPolicyMatches` fails with 
`CamelAuthorizationException: Denied by policy authz/allow`, so the IT 
evaluates a bundle compiled from the Rego under test. Restored.
   - Full reactor `mvn clean install -DskipTests -DskipITs`: green, no 
generated-file drift.
   
   ## Scope
   
   `main` only, test code only, no production changes. As with `OpaWasmIT`, the 
moved tests run where the OPA image does; `camel-opa` already skips ITs on 
ppc64le and s390x.
   
   _Claude Code on behalf of @oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to