# Contributor testing Run the smallest affected package first, then the complete gate from `AGENTS.md`. `make e2e` runs the Linux black-box bootstrap test against the real `dogama` binary and a temporary SQLite database; it verifies first-run closure, CSRF denial, secure cookies, security headers, authentication and protected catalog access. The following V1 critical paths are intentionally split between deterministic integration tests and disposable-Docker release verification: | Boundary or workflow | Automated coverage | |---|---| | Bootstrap, login, logout, CSRF, session rotation and throttling | `internal/web` and `tests/e2e` | | Admin/user/manager membership and explicit-deny behavior | `internal/web` and `internal/authorization` | | Agent authentication, replay, request bounds and unrelated-container denial | `internal/agent` | | Path, symlink, plan, image, port and label restrictions | `internal/agent` | | Archive traversal, links, extraction limits, backup integrity and restore safety | `internal/importexport` and `internal/backup` | | WASM capability, network, fuel, memory, response and concurrency bounds | `internal/module` | | Digest update success, failed readiness and rollback | `internal/instance` and `internal/web` | | Empty-database current-schema initialization | `internal/persistence/sqlite` | Before publishing a release, additionally use an isolated Docker daemon with disposable host roots. Render the canonical two-service Compose with default and custom paths/network names, build both image targets, then start from absent application state and absent `agent_state` and `agent_auth` volumes using only `docker compose up -d`. Confirm that both services become healthy enough for an authenticated agent call, both secrets appear without entering logs, the main container has no socket and cannot mount the agent registry, and the agent has no published port. Record the secret digests, run `docker compose down` without `-v`, start again and confirm identical digests and registry state. Then exercise Palworld draft/install/start/stop, configured game-network attachment, backup/restore, an intentionally failing digest update, and container-only deletion. Confirm that unrelated containers cannot be inspected or mutated and that player and backup roots remain after deletion and interruption. Never point this test at a host containing valuable containers or player data. Tests must use generated secrets and fixtures. Do not place real credentials, host paths, saves, database copies or registry tokens in logs or commits. A failure report should name the operation and stable error code without copying secret-bearing request bodies.