oscerd opened a new pull request, #26987: URL: https://github.com/apache/camel/pull/26987
## What Fixes the camel-opa test failures reported in #26969 by finishing CAMEL-24742 instead of reverting it. ## Why it broke Three camel-opa PRs merged within two minutes on 2026-09-25, each green against its own base: | Merged (UTC) | PR | Effect | |---|---|---| | 09:04:48 | #26670 (CAMEL-24830) | added `OpaSecurityPolicyWasmTest`, which loads `classpath:authz.wasm` | | 09:05:45 | #26677 (CAMEL-24742) | deleted `authz.wasm` and moved the bundle-dependent producer tests to ITs | | 09:06:45 | #26679 (CAMEL-24740) | added another `classpath:authz.wasm` reference | `OpaSecurityPolicyWasmTest` wires its `direct:wasm` route in `createRouteBuilder()`, so the missing fixture fails context startup and all 8 of its tests error with the `FileNotFoundException` quoted in #26969. Those 8 are the only camel-opa failures in Jenkins `main` build #2223. `OpaBatchEvaluationTest` kept passing only because `batch` is rejected before the bundle is opened. ## How The same split #26677 applied to the producer tests: - **`OpaSecurityPolicyWasmIT`** (new) takes the three tests that need a bundle that evaluates: allow, deny, and "only the rest policy registers a readiness check". They moved unchanged. `@BeforeAll` compiles `authz.rego` with `OpaWasmBundleBuilder`, as `OpaWasmIT` does. - **`OpaSecurityPolicyWasmTest`** keeps the five startup-failure tests, which never need a working bundle. `failsRouteStartOnAPoolSizeBelowOne` now uses `file:unused.wasm`, since `poolSize` is rejected before the location is opened. - **`OpaBatchEvaluationTest.rejectsBatchInWasmModeAtStartup`** gets the same `file:unused.wasm` treatment for its dead reference. - Two comments (`OpaIT`, `wasm-data/roles.rego`) still named `OpaWasmEvaluatorTest`, which #26677 renamed to `OpaWasmIT`. ## Testing - Reproduced on `main`: `OpaSecurityPolicyWasmTest` 8 of 8 errors, `Cannot find resource: classpath:authz.wasm`. - `mvn clean verify` in `components/camel-opa` (Docker): 92 unit tests and 26 ITs, 0 failures. `OpaSecurityPolicyWasmIT` 3/3. - Broke the `allow` rule in `authz.rego`: `OpaSecurityPolicyWasmIT.allowsWhenTheWasmPolicyMatches` fails with `CamelAuthorizationException: Denied by policy authz/allow`, so the IT evaluates a bundle compiled from the Rego under test. Restored. - Full reactor `mvn clean install -DskipTests -DskipITs`: green, no generated-file drift. ## Scope `main` only, test code only, no production changes. As with `OpaWasmIT`, the moved tests run where the OPA image does; `camel-opa` already skips ITs on ppc64le and s390x. _Claude Code on behalf of @oscerd_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
