From 64180fd376b7581f4dad2a8eb0bee8b7037ad985 Mon Sep 17 00:00:00 2001 From: Wolfgang Schoenberger <221313372+wolfiesch@users.noreply.github.com> Date: Fri, 31 Jul 2026 01:43:01 -0700 Subject: [PATCH] test(ai): stop bedrock payload suites from needing ambient AWS auth Three Bedrock suites capture a request payload from a fire-and-forget stream. Without credentials the credential lookup rejects after the test has finished, so Bun reports it as an unhandled error against whichever test runs next and fails an unrelated file. Skip Bedrock auth for those suites, matching the existing repro tests: the payload is assembled before signing and no request leaves the process. --- .../ai/test/bedrock-inference-profile.test.ts | 17 ++++++++++++++++- packages/ai/test/bedrock-prompt-cache.test.ts | 17 ++++++++++++++++- packages/ai/test/bedrock-system-prompt.test.ts | 17 ++++++++++++++++- 3 files changed, 48 insertions(+), 3 deletions(-) diff --git a/packages/ai/test/bedrock-inference-profile.test.ts b/packages/ai/test/bedrock-inference-profile.test.ts index 495ad7a44..49755fe71 100644 --- a/packages/ai/test/bedrock-inference-profile.test.ts +++ b/packages/ai/test/bedrock-inference-profile.test.ts @@ -1,10 +1,25 @@ -import { describe, expect, test } from "bun:test"; +import { afterAll, beforeAll, describe, expect, test } from "bun:test"; import { streamBedrock } from "@oh-my-pi/pi-ai/providers/amazon-bedrock"; import type { Context, FetchImpl, Model } from "@oh-my-pi/pi-ai/types"; import { buildModel } from "@oh-my-pi/pi-catalog/build"; import { Effort } from "@oh-my-pi/pi-catalog/effort"; import { withEnv } from "./helpers"; +// These suites capture the request payload from a fire-and-forget stream, so a +// credential lookup that rejects after the test ends surfaces as an unhandled +// error against whatever runs next. Skip Bedrock auth: the payload is built +// before signing and no request leaves the process. +const originalSkipAuth = process.env.AWS_BEDROCK_SKIP_AUTH; + +beforeAll(() => { + process.env.AWS_BEDROCK_SKIP_AUTH = "1"; +}); + +afterAll(() => { + if (originalSkipAuth === undefined) delete process.env.AWS_BEDROCK_SKIP_AUTH; + else process.env.AWS_BEDROCK_SKIP_AUTH = originalSkipAuth; +}); + const profileArn = "arn:aws:bedrock:us-east-2:1234567890:application-inference-profile/company-opus-48"; const profileModel: Model<"bedrock-converse-stream"> = buildModel({ id: profileArn, diff --git a/packages/ai/test/bedrock-prompt-cache.test.ts b/packages/ai/test/bedrock-prompt-cache.test.ts index 83461ac38..8b85e3798 100644 --- a/packages/ai/test/bedrock-prompt-cache.test.ts +++ b/packages/ai/test/bedrock-prompt-cache.test.ts @@ -1,10 +1,25 @@ -import { describe, expect, test } from "bun:test"; +import { afterAll, beforeAll, describe, expect, test } from "bun:test"; import { streamBedrock } from "@oh-my-pi/pi-ai/providers/amazon-bedrock"; import type { Context, Model } from "@oh-my-pi/pi-ai/types"; import { buildModel } from "@oh-my-pi/pi-catalog/build"; import { getBundledModel } from "@oh-my-pi/pi-catalog/models"; import { withEnv } from "./helpers"; +// These suites capture the request payload from a fire-and-forget stream, so a +// credential lookup that rejects after the test ends surfaces as an unhandled +// error against whatever runs next. Skip Bedrock auth: the payload is built +// before signing and no request leaves the process. +const originalSkipAuth = process.env.AWS_BEDROCK_SKIP_AUTH; + +beforeAll(() => { + process.env.AWS_BEDROCK_SKIP_AUTH = "1"; +}); + +afterAll(() => { + if (originalSkipAuth === undefined) delete process.env.AWS_BEDROCK_SKIP_AUTH; + else process.env.AWS_BEDROCK_SKIP_AUTH = originalSkipAuth; +}); + interface CachePoint { cachePoint: { type: "default"; ttl?: "1h" }; } diff --git a/packages/ai/test/bedrock-system-prompt.test.ts b/packages/ai/test/bedrock-system-prompt.test.ts index 3b14d57a7..0fd6b9c64 100644 --- a/packages/ai/test/bedrock-system-prompt.test.ts +++ b/packages/ai/test/bedrock-system-prompt.test.ts @@ -1,8 +1,23 @@ -import { describe, expect, test } from "bun:test"; +import { afterAll, beforeAll, describe, expect, test } from "bun:test"; import { streamBedrock } from "@oh-my-pi/pi-ai/providers/amazon-bedrock"; import type { Context, Model } from "@oh-my-pi/pi-ai/types"; import { buildModel } from "@oh-my-pi/pi-catalog/build"; +// These suites capture the request payload from a fire-and-forget stream, so a +// credential lookup that rejects after the test ends surfaces as an unhandled +// error against whatever runs next. Skip Bedrock auth: the payload is built +// before signing and no request leaves the process. +const originalSkipAuth = process.env.AWS_BEDROCK_SKIP_AUTH; + +beforeAll(() => { + process.env.AWS_BEDROCK_SKIP_AUTH = "1"; +}); + +afterAll(() => { + if (originalSkipAuth === undefined) delete process.env.AWS_BEDROCK_SKIP_AUTH; + else process.env.AWS_BEDROCK_SKIP_AUTH = originalSkipAuth; +}); + interface Payload { system?: Array<{ text: string } | { cachePoint: unknown }>; }