diff --git a/src/apphosting/secrets/index.spec.ts b/src/apphosting/secrets/index.spec.ts index e05a13a5c76..17fda76c42b 100644 --- a/src/apphosting/secrets/index.spec.ts +++ b/src/apphosting/secrets/index.spec.ts @@ -28,6 +28,12 @@ describe("secrets", () => { gcsm.labels.restore(); gcsm.getIamPolicy.throws("Unexpected getIamPolicy call"); gcsm.setIamPolicy.throws("Unexpected setIamPolicy call"); + // Unstubbed, this reaches the Compute API over the network and races mocha's 2s + // timeout. The fake derives the address from its argument so the tests still pin + // that the project number is passed through. + sinon + .stub(gce, "getDefaultServiceAccount") + .callsFake((pn: string) => Promise.resolve(`${pn}-compute@developer.gserviceaccount.com`)); }); afterEach(() => { @@ -49,7 +55,7 @@ describe("secrets", () => { const backend = {} as any as apphosting.Backend; expect(await secrets.serviceAccountsForBackend("number", backend)).to.deep.equal({ buildServiceAccount: gcb.getDefaultServiceAccount("number"), - runServiceAccount: await gce.getDefaultServiceAccount("number"), + runServiceAccount: "number-compute@developer.gserviceaccount.com", }); }); }); diff --git a/src/deploy/functions/checkIam.spec.ts b/src/deploy/functions/checkIam.spec.ts index b1dadcef3c6..e6034b9e594 100644 --- a/src/deploy/functions/checkIam.spec.ts +++ b/src/deploy/functions/checkIam.spec.ts @@ -3,6 +3,7 @@ import * as sinon from "sinon"; import * as checkIam from "./checkIam"; import * as storage from "../../gcp/storage"; import * as rm from "../../gcp/resourceManager"; +import * as gce from "../../gcp/computeEngine"; import * as backend from "./backend"; const projectId = "my-project"; @@ -30,6 +31,13 @@ describe("checkIam", () => { let setIamStub: sinon.SinonStub; beforeEach(() => { + // Unstubbed, this reaches the Compute API over the network and each test that + // needs the default service account races mocha's 2s timeout. The fake derives + // the address from its argument so the tests still pin that checkIam passes the + // project number through. + sinon + .stub(gce, "getDefaultServiceAccount") + .callsFake((pn: string) => Promise.resolve(`${pn}-compute@developer.gserviceaccount.com`)); storageStub = sinon .stub(storage, "getServiceAccount") .throws("unexpected call to storage.getServiceAccount"); diff --git a/src/deploy/functions/release/fabricator.spec.ts b/src/deploy/functions/release/fabricator.spec.ts index 64127af797d..1940b7e2a31 100644 --- a/src/deploy/functions/release/fabricator.spec.ts +++ b/src/deploy/functions/release/fabricator.spec.ts @@ -27,6 +27,8 @@ import * as gce from "../../../gcp/computeEngine"; import * as iam from "../../../gcp/iam"; import * as resourcemanager from "../../../gcp/resourceManager"; +const DEFAULT_COMPUTE_SERVICE_ACCOUNT = "1234567-compute@developer.gserviceaccount.com"; + describe("Fabricator", () => { // Stub all GCP APIs to make sure this test is hermetic let gcf: sinon.SinonStubbedInstance; @@ -40,6 +42,7 @@ describe("Fabricator", () => { let tasks: sinon.SinonStubbedInstance; let services: sinon.SinonStubbedInstance; let identityPlatform: sinon.SinonStubbedInstance; + let computeEngine: sinon.SinonStubbedInstance; beforeEach(() => { gcf = sinon.stub(gcfNS); @@ -53,6 +56,7 @@ describe("Fabricator", () => { tasks = sinon.stub(cloudtasksNS); services = sinon.stub(servicesNS); identityPlatform = sinon.stub(identityPlatformNS); + computeEngine = sinon.stub(gce); gcf.functionFromEndpoint.restore(); gcfv2.functionFromEndpoint.restore(); @@ -104,6 +108,13 @@ describe("Fabricator", () => { identityPlatform.setBlockingFunctionsConfig.rejects( new Error("unexpected identityPlatform.setBlockingFunctionsConfig"), ); + // Unstubbed, this reaches the Compute API over the network and every test that + // needs the default service account races mocha's 2s timeout. The fake derives + // the address from its argument so the tests still pin that the fabricator passes + // the project number through. + computeEngine.getDefaultServiceAccount.callsFake((pn: string) => + Promise.resolve(`${pn}-compute@developer.gserviceaccount.com`), + ); }); afterEach(() => { @@ -892,7 +903,7 @@ describe("Fabricator", () => { await fab.createV2Function(ep, new scraper.SourceTokenScraper()); expect(run.setInvokerCreate).to.have.been.calledWith(ep.project, "service", [ - await gce.getDefaultServiceAccount(fab.projectNumber), + DEFAULT_COMPUTE_SERVICE_ACCOUNT, ]); }); diff --git a/src/gcp/cloudscheduler.spec.ts b/src/gcp/cloudscheduler.spec.ts index 85e2900d29c..004e13aa2bf 100644 --- a/src/gcp/cloudscheduler.spec.ts +++ b/src/gcp/cloudscheduler.spec.ts @@ -1,10 +1,12 @@ import { expect } from "chai"; +import * as sinon from "sinon"; import nock from "../test/helpers/nock"; import { FirebaseError } from "../error"; import * as api from "../api"; import * as backend from "../deploy/functions/backend"; import * as cloudscheduler from "./cloudscheduler"; +import * as gce from "./computeEngine"; import { cloneDeep } from "../utils"; const VERSION = "v1"; @@ -157,6 +159,19 @@ describe("cloudscheduler", () => { }); describe("jobFromEndpoint", () => { + beforeEach(() => { + // Unstubbed, this reaches the Compute API over the network and each v2 endpoint + // test races mocha's 2s timeout. The fake derives the address from its argument + // so the tests still pin that jobFromEndpoint passes the project number through. + sinon + .stub(gce, "getDefaultServiceAccount") + .callsFake((pn: string) => Promise.resolve(`${pn}-compute@developer.gserviceaccount.com`)); + }); + + afterEach(() => { + sinon.verifyAndRestore(); + }); + const V1_ENDPOINT: backend.Endpoint = { platform: "gcfv1", id: "id",