headroom/headroom
chopratejas d5ca50cd03 fix(tests): stop module-level dotenv loaders from polluting os.environ during pytest collection
# The bug

Several test modules and two production modules loaded the project `.env`
at *import time*. During pytest collection (where every test module is
imported once), this populated `os.environ` with API keys from `.env`.

The skipif guards in `test_proxy_passthrough_integration.py` (and
others) evaluate at collection time:

    @pytest.mark.skipif(not os.environ.get("OPENAI_API_KEY"), reason="...")

If the polluter module was collected *before* the guard, the guard saw
the leaked key, decided not to skip, and the integration tests ran
live against a fake key and failed. In a fresh local-dev venv with
`.env` + full `[dev]` extras, this manifested as ~16 spurious test
failures plus a misleading test runtime of 6+ minutes (live HTTP).

# Why now

CI does not see this (no `.env`). It only manifests when:
1. `litellm` (and friends) are installed — they run `dotenv.load_dotenv()`
   on import, populating `os.environ` from `.env`.
2. A `.env` file with real API keys exists locally.

Until the venv was provisioned with the full `[dev]` extras during
recent test work, `pytest.importorskip("litellm")` and
`from headroom.pricing import litellm_pricing` both silently no-op'd
(via try/except ImportError → `LITELLM_AVAILABLE=False`), so the leak
never triggered. With litellm now installed, the latent bug surfaced.

# The fix — three patterns

1. **Production modules** (`headroom/pricing/litellm_pricing.py`,
   `headroom/backends/litellm.py`): wrap the eager `import litellm` with
   a snapshot/restore of `os.environ`. Any keys litellm's bundled
   `python-dotenv` adds during import are deleted immediately. The
   module is fully imported and cached in `sys.modules` so subsequent
   imports hit the cache without re-running the side effect.

2. **Test modules using `pytest.importorskip("litellm")`**
   (`test_backend_bugs.py`, `test_bedrock_region.py`,
   `test_cost_tracker_counterfactual.py`): replace with
   `tests._dotenv.importorskip_no_env_leak("litellm")`, which does the
   same snapshot/restore around `importlib.import_module`.

3. **Test modules that intentionally need `.env` values for skipif
   guards** (`test_compression_summary_*.py`, `test_query_echo.py`,
   `test_cost_tracker_counterfactual.py`, `test_memory_usage_integration.py`,
   `test_bundled_tools_savings.py`): replace module-level
   `os.environ.setdefault(...)` / `dotenv.load_dotenv()` with
   `tests._dotenv.load_env_overrides()` (returns a local dict — does
   NOT mutate `os.environ`) plus `autouse_apply_env(...)` (function-
   scoped fixture that applies via `monkeypatch.setenv`, auto-cleaned
   at teardown). The skipif still works because
   `ANTHROPIC_KEY = os.environ.get(...) or _env_overrides.get(...)`
   reads from the local dict as fallback.

# Helper module

New `tests/_dotenv.py` exposes:
- `load_env_overrides() -> dict[str, str]` — read `.env` into a dict.
- `autouse_apply_env(overrides) -> fixture` — function-scoped autouse
  fixture that applies via `monkeypatch.setenv`.
- `importorskip_no_env_leak(module) -> module` — drop-in
  `pytest.importorskip` substitute that quarantines env mutations.

# Results

Local full-suite (excluding live-LLM and live-feed tests):
- Before: 46 failed, 4830 passed, 387s
- After:   2 failed, 4672 passed, 134s

The remaining 2 failures are unrelated environment-dependent tests
(missing `PIL` / Docker daemon).
2026-04-26 09:15:37 -07:00
..
backends fix(tests): stop module-level dotenv loaders from polluting os.environ during pytest collection 2026-04-26 09:15:37 -07:00
cache docs: preserve package entrypoint comments 2026-04-10 22:10:43 -05:00
ccr refactor: migrate Python callsites to canonical paths module 2026-04-16 19:12:21 -05:00
cli Merge pull request #266 from ipapapa/fix/31-qdrant-env-vars 2026-04-25 13:33:48 -07:00
compression Route diffs to DiffCompressor via Magika label mapping 2026-04-06 22:52:27 -07:00
dashboard Merge remote-tracking branch 'upstream/main' into fix/dashboard-stats-snapshot-cache 2026-04-22 10:46:37 +00:00
evals chore: fix ruff lint issues (import sorting, trailing whitespace) 2026-04-07 21:33:16 -07:00
graph Auto-download codebase-memory-mcp binary, add watchdog to proxy deps 2026-04-11 19:30:38 -07:00
image fix(onnx): reduce retained cpu memory 2026-04-20 22:31:48 +00:00
install chore: renormalize line endings to LF 2026-04-24 15:33:30 +02:00
integrations fix: restore Windows mypy compatibility 2026-04-11 18:40:53 -05:00
learn fix(learn): show prior patterns block to LLM to prevent dangling refs 2026-04-23 12:59:02 +02:00
memory feat(memory): resolve Qdrant connection from HEADROOM_QDRANT_* env vars (#31) 2026-04-24 22:16:16 -07:00
models docs: restore models init comments 2026-04-10 22:33:53 -05:00
observability feat: add Anthropic Claude Code subscription window tracking 2026-04-11 21:53:44 -05:00
perf refactor: migrate Python callsites to canonical paths module 2026-04-16 19:12:21 -05:00
prediction chore: add nosec B324 annotations to non-cryptographic MD5 usages and update temporary database path to use system temp directory 2026-04-07 13:07:26 +06:00
pricing fix(tests): stop module-level dotenv loaders from polluting os.environ during pytest collection 2026-04-26 09:15:37 -07:00
providers chore: renormalize line endings to LF 2026-04-24 15:33:30 +02:00
proxy Merge pull request #266 from ipapapa/fix/31-qdrant-env-vars 2026-04-25 13:33:48 -07:00
relevance fix: harden edge cases, expand tool exclusions, and fix mypy errors 2026-03-06 22:30:30 -08:00
reporting fix: harden edge cases, expand tool exclusions, and fix mypy errors 2026-03-06 22:30:30 -08:00
rtk refactor: migrate Python callsites to canonical paths module 2026-04-16 19:12:21 -05:00
storage Fix 19 test failures: missing security attr, nosec inside f-strings, stale test mock 2026-04-07 18:30:29 -07:00
subscription chore: renormalize line endings to LF 2026-04-24 15:33:30 +02:00
telemetry refactor(telemetry): centralize stack slug validation + cardinality cap 2026-04-17 18:42:41 +02:00
tokenizers Count Strands reasoningContent, image, document, video tokens (#111 follow-up) 2026-04-08 17:31:00 -07:00
transforms feat(rust): retire python diff_compressor, ship rust-only via pyo3 2026-04-26 09:15:37 -07:00
__init__.py feat: introduce canonical pipeline lifecycle contract 2026-04-21 23:54:28 -05:00
_version.py Bump version to 0.5.25 for PyPI release 2026-04-13 16:32:13 -07:00
binaries.py fix: docker install fails with PermissionError in readonly cache dir 2026-04-20 17:36:44 -07:00
cli.py Add Click-based CLI with memory management commands 2026-01-29 21:30:21 -08:00
client.py chore: normalize provider slice line endings 2026-04-21 23:54:28 -05:00
compress.py chore: renormalize line endings to LF 2026-04-24 15:33:30 +02:00
config.py feat: introduce canonical pipeline lifecycle contract 2026-04-21 23:54:28 -05:00
copilot_auth.py chore: renormalize line endings to LF 2026-04-24 15:33:30 +02:00
exceptions.py Fix all ruff lint and format errors for CI 2026-01-10 15:33:44 -08:00
hooks.py feat: introduce canonical pipeline lifecycle contract 2026-04-21 23:54:28 -05:00
onnx_runtime.py fix(onnx): reduce retained cpu memory 2026-04-20 22:31:48 +00:00
parser.py Fix Strands SDK tool pairing, CCR marker format, and startup timeout (#114 #116 #117) 2026-04-08 11:28:23 -07:00
paths.py feat(paths): add canonical HEADROOM_CONFIG_DIR / HEADROOM_WORKSPACE_DIR module 2026-04-16 18:50:50 -05:00
pipeline.py feat: introduce canonical pipeline lifecycle contract 2026-04-21 23:54:28 -05:00
py.typed Prepare for OSS release v0.2.0 2026-01-07 11:36:44 -08:00
release_version.py chore: renormalize line endings to LF 2026-04-24 15:33:30 +02:00
shared_context.py Add SharedContext for multi-agent, rewrite README, fix proxy cleanup 2026-03-17 16:31:04 -07:00
tokenizer.py Initial commit: Headroom SDK - LLM context optimization toolkit 2026-01-06 23:16:58 -08:00
tools.json fix(review): address PR #210 feedback — race, query-params, SHA logging, frozen prefix, etc 2026-04-20 17:36:44 -07:00
utils.py chore: add nosec B324 annotations to non-cryptographic MD5 usages and update temporary database path to use system temp directory 2026-04-07 13:07:26 +06:00