| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189 |
- import { readFileSync } from 'node:fs'
- import { resolve } from 'node:path'
- import * as yaml from 'js-yaml'
- import { describe, expect, it } from 'vitest'
- const root = resolve(import.meta.dirname, '..')
- const runnerPrivatePnpmDestination = '${{ runner.temp }}/setup-pnpm'
- describe('CI workflow', () => {
- it('isolates every pnpm action setup destination per runner', () => {
- const workflow: unknown = yaml.load(readFileSync(resolve(root, '.github/workflows/ci.yml'), 'utf8'))
- if (!isRecord(workflow) || !isRecord(workflow.jobs)) throw new TypeError('CI workflow must define jobs')
- const setups = Object.entries(workflow.jobs).flatMap(([jobName, job]) => {
- if (!isRecord(job) || !Array.isArray(job.steps)) return []
- return job.steps.flatMap((step) => {
- if (!isRecord(step) || typeof step.uses !== 'string' || !step.uses.startsWith('pnpm/action-setup@')) return []
- return [{ jobName, step }]
- })
- })
- expect(setups.length).toBeGreaterThan(0)
- for (const { jobName, step } of setups) {
- expect(step, `${jobName} must not share pnpm/action-setup's default destination`).toMatchObject({
- with: { dest: runnerPrivatePnpmDestination },
- })
- }
- })
- it('keeps a required Wine Windows job, a non-blocking native Windows job with failover, and a master-only standby', () => {
- const workflow = loadWorkflow('.github/workflows/ci.yml')
- if (!isRecord(workflow.jobs)
- || !isRecord(workflow.jobs.windows)
- || !isRecord(workflow.jobs['windows-native'])
- || !isRecord(workflow.jobs['wine-apt-cache'])
- || !isRecord(workflow.jobs['serial-windows'])
- || !isRecord(workflow.jobs['all-checks-passed'])) {
- throw new TypeError('CI workflow must define windows, windows-native, wine-apt-cache, serial-windows, and all-checks-passed jobs')
- }
- const windows = workflow.jobs.windows
- const windowsNative = workflow.jobs['windows-native']
- const wineAptCache = workflow.jobs['wine-apt-cache']
- const serialWindows = workflow.jobs['serial-windows']
- const aggregate = workflow.jobs['all-checks-passed']
- if (!Array.isArray(windows.steps) || !Array.isArray(aggregate.needs)) {
- throw new TypeError('Windows job must define steps and the aggregate must define needs')
- }
- const commandSteps = windows.steps.filter((step): step is Record<string, unknown> & { run: string } => (
- isRecord(step) && typeof step.run === 'string'
- ))
- // Required PR job: Wine on ubuntu-latest, runs wine-windows-gates.sh.
- expect(windows['runs-on']).toBe('ubuntu-latest')
- expect(windows.name).toBe('windows node 24 / wine blocking')
- expect(windows.if).toBe("github.event_name == 'pull_request'")
- expect(commandSteps.some(step => step.run.includes('wine-windows-gates.sh'))).toBe(true)
- // windows-native: non-blocking native job with failover, runs windows-complete.
- expect(typeof windowsNative['runs-on']).toBe('string')
- expect(windowsNative['runs-on']).toContain('DSH_CI_FAILOVER')
- expect(windowsNative['runs-on']).toContain('self-hosted')
- expect(windowsNative['runs-on']).toContain('dsh-win-ci')
- expect(windowsNative['runs-on']).toContain('dsh-windows-2025-16core')
- expect(windowsNative.name).toBe('windows node 24 / native complete')
- expect(windowsNative.if).toBe("github.event_name == 'pull_request'")
- const nativeCommandSteps = (windowsNative.steps as unknown[]).filter((step): step is Record<string, unknown> & { run: string } => (
- isRecord(step) && typeof step.run === 'string'
- ))
- expect(nativeCommandSteps.map(step => step.run)).toContain('pnpm run check:ci:windows-complete')
- // wine-apt-cache: master-only, seeds the Wine apt cache.
- expect(wineAptCache.if).toBe("github.event_name == 'push' && github.ref == 'refs/heads/master'")
- expect(wineAptCache['runs-on']).toBe('ubuntu-latest')
- // serial-windows: master-only standby, self-hosted, non-blocking.
- expect(serialWindows.if).toBe("github.event_name == 'push' && github.ref == 'refs/heads/master'")
- expect(serialWindows['runs-on']).toEqual(['self-hosted', 'dsh-win-ci', 'windows'])
- expect(serialWindows.name).toBe('serial / windows (self-hosted standby)')
- // Aggregate: Wine `windows` required, native `windows-native` excluded.
- expect(aggregate.needs).toContain('windows')
- expect(aggregate.needs).not.toContain('windows-native')
- expect(aggregate.needs).not.toContain('serial-windows')
- })
- it('keeps supported LSP source under native Windows coverage', () => {
- const config = readFileSync(resolve(root, 'vitest.config.ts'), 'utf8')
- expect(config).not.toContain('packages/lsp/lsp-local/src/connection.ts')
- expect(config).not.toContain('packages/lsp/lsp-local/src/index.ts')
- expect(config).not.toContain('packages/lsp/lsp-local/src/instance.ts')
- })
- it('keeps every Vitest project process-isolated on native Windows', () => {
- const config = readFileSync(resolve(root, 'vitest.config.ts'), 'utf8')
- expect(config).not.toContain("pool: process.platform === 'win32' ? 'threads' : 'forks'")
- expect(config.match(/pool: 'forks'/g)).toHaveLength(2)
- })
- })
- describe('E2B e2e workflow', () => {
- it('is manual-only and fails loud before running the focused live suite', () => {
- const workflow = loadWorkflow('.github/workflows/e2b-e2e.yml')
- expect(workflow.on).toEqual({ workflow_dispatch: null })
- if (!isRecord(workflow.jobs) || !isRecord(workflow.jobs.e2b) || !Array.isArray(workflow.jobs.e2b.steps)) {
- throw new TypeError('E2B e2e workflow must define the e2b job steps')
- }
- const steps = workflow.jobs.e2b.steps.filter(isRecord)
- const preflight = steps.find(step => step.name === 'Preflight (require E2B API key)')
- const e2b = steps.find(step => step.name === 'E2B tests (live sandbox)')
- expect(preflight).toMatchObject({
- env: { E2B_API_KEY: '${{ secrets.E2B_API_KEY_EXTERNAL }}' },
- })
- expect(preflight?.run).toContain('E2B_API_KEY_EXTERNAL repository secret')
- expect(e2b).toMatchObject({
- env: {
- E2B_API_KEY: '${{ secrets.E2B_API_KEY_EXTERNAL }}',
- DSH_E2E_MAX_WORKERS: '1',
- DSH_EXAMPLE_MODE: 'lib',
- },
- })
- expect(e2b?.run).toContain('packages/e2b/e2b/tests/composition.e2e.ts')
- })
- })
- describe('Issue lifecycle workflow', () => {
- it('uses explicit review handoff events without rerunning when a draft becomes ready', () => {
- const lifecycle = loadWorkflow('.github/workflows/issue-lifecycle.yml')
- const lifecyclePullRequest = workflowEvent(lifecycle, 'pull_request')
- const lifecycleReview = workflowEvent(lifecycle, 'pull_request_review')
- const lifecycleJob = workflowJob(lifecycle, 'lifecycle')
- const policy = loadWorkflow('.github/workflows/issue-policy.yml')
- const policyPullRequest = workflowEvent(policy, 'pull_request')
- expect(lifecyclePullRequest.types).not.toContain('ready_for_review')
- expect(lifecyclePullRequest.types).toContain('review_requested')
- expect(lifecycleReview.types).toEqual(['submitted'])
- expect(lifecycleJob.if).toBe(
- "${{ github.event_name != 'pull_request_review' || (github.event.action == 'submitted' && github.event.review.state == 'changes_requested') }}",
- )
- expect(policyPullRequest.types).toContain('ready_for_review')
- })
- })
- describe('Git hooks', () => {
- it('leaves frozen Agent Note sidecars to the archive verifier', () => {
- const lefthook = loadWorkflow('lefthook.yml')
- for (const hookName of ['pre-commit', 'pre-merge-commit']) {
- const hook = lefthook[hookName]
- if (!isRecord(hook) || !Array.isArray(hook.jobs)) {
- throw new TypeError(`lefthook must define ${hookName} jobs`)
- }
- const pairing: unknown = hook.jobs.find(
- (job: unknown) => isRecord(job) && job.name === 'translation pairing (staged records)',
- )
- expect(pairing).toMatchObject({ exclude: ['.agents/notes/archived/**'] })
- }
- })
- })
- function loadWorkflow(path: string): Record<string, unknown> {
- const workflow: unknown = yaml.load(readFileSync(resolve(root, path), 'utf8'))
- if (!isRecord(workflow)) throw new TypeError(`${path} must define a workflow`)
- return workflow
- }
- function workflowEvent(workflow: Record<string, unknown>, event: string): Record<string, unknown> {
- if (!isRecord(workflow.on) || !isRecord(workflow.on[event])) {
- throw new TypeError(`workflow must define the ${event} event`)
- }
- return workflow.on[event]
- }
- function workflowJob(workflow: Record<string, unknown>, job: string): Record<string, unknown> {
- if (!isRecord(workflow.jobs) || !isRecord(workflow.jobs[job])) {
- throw new TypeError(`workflow must define the ${job} job`)
- }
- return workflow.jobs[job]
- }
- function isRecord(value: unknown): value is Record<string, unknown> {
- return typeof value === 'object' && value !== null && !Array.isArray(value)
- }
|