headroom/tests/_dotenv.py

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

107 lines
3.9 KiB
Python
Raw Normal View History

fix(tests): stop module-level dotenv loaders from polluting os.environ during pytest collection # The bug Several test modules and two production modules loaded the project `.env` at *import time*. During pytest collection (where every test module is imported once), this populated `os.environ` with API keys from `.env`. The skipif guards in `test_proxy_passthrough_integration.py` (and others) evaluate at collection time: @pytest.mark.skipif(not os.environ.get("OPENAI_API_KEY"), reason="...") If the polluter module was collected *before* the guard, the guard saw the leaked key, decided not to skip, and the integration tests ran live against a fake key and failed. In a fresh local-dev venv with `.env` + full `[dev]` extras, this manifested as ~16 spurious test failures plus a misleading test runtime of 6+ minutes (live HTTP). # Why now CI does not see this (no `.env`). It only manifests when: 1. `litellm` (and friends) are installed — they run `dotenv.load_dotenv()` on import, populating `os.environ` from `.env`. 2. A `.env` file with real API keys exists locally. Until the venv was provisioned with the full `[dev]` extras during recent test work, `pytest.importorskip("litellm")` and `from headroom.pricing import litellm_pricing` both silently no-op'd (via try/except ImportError → `LITELLM_AVAILABLE=False`), so the leak never triggered. With litellm now installed, the latent bug surfaced. # The fix — three patterns 1. **Production modules** (`headroom/pricing/litellm_pricing.py`, `headroom/backends/litellm.py`): wrap the eager `import litellm` with a snapshot/restore of `os.environ`. Any keys litellm's bundled `python-dotenv` adds during import are deleted immediately. The module is fully imported and cached in `sys.modules` so subsequent imports hit the cache without re-running the side effect. 2. **Test modules using `pytest.importorskip("litellm")`** (`test_backend_bugs.py`, `test_bedrock_region.py`, `test_cost_tracker_counterfactual.py`): replace with `tests._dotenv.importorskip_no_env_leak("litellm")`, which does the same snapshot/restore around `importlib.import_module`. 3. **Test modules that intentionally need `.env` values for skipif guards** (`test_compression_summary_*.py`, `test_query_echo.py`, `test_cost_tracker_counterfactual.py`, `test_memory_usage_integration.py`, `test_bundled_tools_savings.py`): replace module-level `os.environ.setdefault(...)` / `dotenv.load_dotenv()` with `tests._dotenv.load_env_overrides()` (returns a local dict — does NOT mutate `os.environ`) plus `autouse_apply_env(...)` (function- scoped fixture that applies via `monkeypatch.setenv`, auto-cleaned at teardown). The skipif still works because `ANTHROPIC_KEY = os.environ.get(...) or _env_overrides.get(...)` reads from the local dict as fallback. # Helper module New `tests/_dotenv.py` exposes: - `load_env_overrides() -> dict[str, str]` — read `.env` into a dict. - `autouse_apply_env(overrides) -> fixture` — function-scoped autouse fixture that applies via `monkeypatch.setenv`. - `importorskip_no_env_leak(module) -> module` — drop-in `pytest.importorskip` substitute that quarantines env mutations. # Results Local full-suite (excluding live-LLM and live-feed tests): - Before: 46 failed, 4830 passed, 387s - After: 2 failed, 4672 passed, 134s The remaining 2 failures are unrelated environment-dependent tests (missing `PIL` / Docker daemon).
2026-04-26 09:12:21 -07:00
"""Local-only `.env` loader for tests that need provider API keys.
Why this exists: several test modules (compression-summary evals,
query-echo, cost-tracker counterfactual) need real API keys and used to
load the project `.env` at module level via `os.environ.setdefault(...)`.
That ran during pytest collection and *globally* mutated `os.environ`,
which caused unrelated tests (e.g. `test_proxy_passthrough_integration`)
to flip from cleanly skipped to running-live-and-failing their
`@pytest.mark.skipif(not os.environ.get(...))` guards saw the leaked
key and decided not to skip.
Usage from a test module that needs `.env`:
from tests._dotenv import load_env_overrides, autouse_apply_env
_env = load_env_overrides()
ANTHROPIC_KEY = os.environ.get("ANTHROPIC_API_KEY") or _env.get(
"ANTHROPIC_API_KEY", ""
)
pytestmark = pytest.mark.skipif(
not ANTHROPIC_KEY,
reason="ANTHROPIC_API_KEY not set",
)
apply_dotenv = autouse_apply_env(_env)
The `apply_dotenv` autouse fixture sets the values via `monkeypatch.setenv`,
which auto-restores at function-scope teardown no cross-module leak.
"""
from __future__ import annotations
import os
from pathlib import Path
import pytest
def load_env_overrides() -> dict[str, str]:
"""Read the project `.env` file (if present) into a plain dict.
Returns an empty dict when `.env` is missing CI runs with real
secrets in the environment and no `.env`, so the per-test fixture
becomes a no-op there.
"""
env_path = Path(__file__).parent.parent / ".env"
out: dict[str, str] = {}
if not env_path.exists():
return out
for raw in env_path.read_text().splitlines():
line = raw.strip()
if not line or line.startswith("#") or "=" not in line:
continue
key, _, value = line.partition("=")
out[key.strip()] = value.strip()
return out
def autouse_apply_env(overrides: dict[str, str]) -> pytest.FixtureFunction:
"""Build an autouse fixture that applies `overrides` for the test
function and restores at teardown. Skips keys already set in the real
environment so CI/secret-store values take precedence over `.env`.
"""
@pytest.fixture(autouse=True)
def _apply(monkeypatch: pytest.MonkeyPatch) -> None:
for key, value in overrides.items():
if not os.environ.get(key):
monkeypatch.setenv(key, value)
return _apply
def importorskip_no_env_leak(module_name: str):
"""`pytest.importorskip` substitute that quarantines `os.environ` mutations.
Why: `litellm` (and other libraries that bundle `python-dotenv`) call
`dotenv.load_dotenv()` at module import time, which loads the project
`.env` into the global `os.environ`. When a test module does
`pytest.importorskip("litellm")` at module-level, that pollution
happens during pytest's collection phase — and any *later-collected*
test module whose `@pytest.mark.skipif(not os.environ.get("FOO_API_KEY"))`
decorator runs after the leak will see the polluted value and stop
skipping. The proxy-passthrough integration tests stop being safely
skipped, run live against fake keys, and fail.
This wrapper snapshots `os.environ`, imports the module, then deletes
any keys that the import added. The module is fully imported and
cached in `sys.modules` its functionality (price tables, model
metadata) is unaffected. Subsequent `import litellm` calls hit the
cache and don't re-run the `dotenv.load_dotenv` side-effect.
Use as a drop-in replacement for `pytest.importorskip` at the top of
test modules that need litellm or any other dotenv-loading library.
"""
import importlib
snapshot = set(os.environ)
try:
mod = importlib.import_module(module_name)
except ImportError:
pytest.skip(f"{module_name} not installed", allow_module_level=True)
for key in set(os.environ) - snapshot:
del os.environ[key]
return mod