Split the rootless Tor e2e skip so the deterministic offline checks (the real offline onion keygen and the production-flag guard) run whenever the tor binary is present, while only the live onion round-trip stays gated on LIM_E2E_TOR=1. The pytest job now installs tor so the keygen — which validates the exact production keygen path — runs on every push. A separate continue-on-error tor-network-e2e job exercises the full round-trip without making the public Tor network a blocking merge gate. The full QEMU build/boot/unlock e2e still needs root + KVM + Arch tooling and stays local/opt-in. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
4.0 KiB
4.0 KiB