Skip to content

fix(ci): make main's CI green and keep real-CLI evidence - #18

Merged
GQAdonis merged 5 commits into
mainfrom
fix/ci-green
Sep 30, 2026
Merged

GQAdonis merged 5 commits into
mainfrom
fix/ci-green

Conversation

@GQAdonis

@GQAdonis GQAdonis commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

main's CI has failed on every OS/Node leg (see the merges of #9, #10, #16). I reproduced the exact failing set locally with a runner-like PATH (node, npm, git only) and fixed each cause.

Failures Cause Fix
4 review tests 532e4cd moved crossModelCheck to resolved identities (connection, provider, model) and added roleIdentities to parseModelsToml; tests still used the old alias-string contract Tests pin the identity contract (incl. same model via another connection = distinct; bare aliases = unverified)
1 bootstrap test ed01fd2 reworded the testing policy; test matched the old phrase Match the current wording
16 kbd-new-phase integration Default OpenSpec bin dir pointed two levels above the repo (worked only with a global openspec); runtime-mode tests need the real prometheus CLI, absent on runners Use the pinned node_modules/.bin; matrix skips runtime tests with a visible reason; new kbd-runtime job builds the real CLI from the public full pack at a pinned commit and runs them with PROMETHEUS_CLI_REQUIRED=1 (missing binary = failure)
workflow shape "every job" test flattened all jobs Per-job checks; kbd-runtime must build the pinned CLI and require it

Windows fixes (pre-existing on main)

  • OpenSpec could never run on Windows: spec-backend spawned a bare openspec, which on Windows is only an npm .cmd shim Node cannot start without a shell. The default spawner now runs a locally resolved @fission-ai/openspec through its JavaScript entry (no PATH), falling back to a real executable on PATH. New test runs OpenSpec with an emptied PATH, reproducing Windows on any platform.
  • .mcp.json machine-path guard missed Windows paths (JSON escapes backslashes); containsMachinePath now checks raw, JSON-escaped and forward-slashed forms.
  • buildWorkspaceMembers printed crates\\one on Windows; Cargo member paths are /-separated everywhere.
  • kbd-runtime: sparse-checkout also substrate/kbd-runtime, install libdbus-1-dev, and withhold CI markers from the private runtime fixture (the runtime makes CI replicas read-only by design).

Needs an operator edit (agents do not edit versions.toml)

versions.toml agrees with the tree still fails: tools/surreal-memory-server is pinned at 6acb605 but the gitlink is 4ed6b2c ("support scoped The Boss service credentials"), which the integration-administration freeze (58796bf, evidence task-1.2-baselines.json: before 6acb605 → after 4ed6b2c) deliberately approved. Change line 17 to:

"tools/surreal-memory-server"   = "4ed6b2c79b9a28b56e53f208fcb85306ec443ae2"    # Scoped authentication for the approved The Boss release

Test plan

  • Runner-like PATH: 1044 tests, only versions.toml agrees with the tree fails (15 runtime tests skipped with reason)
  • Real prometheus CLI + PROMETHEUS_CLI_REQUIRED=1: kbd-new-phase integration 26/26 pass
  • PROMETHEUS_CLI_REQUIRED=1 without the CLI fails loudly
  • rules build check, spec-validate (39/39), hooks test pass
  • Operator applies the versions.toml pin, then all CI legs + kbd-runtime green

🤖 Generated with Claude Code

main's CI failed on every leg since at least #9/#10/#16. Reproduced
exactly with a runner-like PATH (node, npm, git only), then fixed:

- Review tests (4): 532e4cd changed crossModelCheck to compare resolved
  identities (connection, provider, model) and added roleIdentities to
  parseModelsToml, but left the tests on the old alias-string contract.
  Tests now pin the identity contract.
- Bootstrap test (1): ed01fd2 reworded the testing policy; the test still
  matched the old 'smallest integration flow' phrase.
- kbd-new-phase integration (16): the default OpenSpec bin dir pointed two
  levels above the repo, so it only worked with a global openspec. It now
  uses the pinned node_modules/.bin. Runtime-mode tests need the real
  prometheus executable; the matrix skips them with a visible reason, and
  a new kbd-runtime job builds the real CLI from the public full pack at a
  pinned commit and runs them with PROMETHEUS_CLI_REQUIRED=1 (a missing
  binary fails there, never skips).
- ci-workflow test: split per job; the matrix job keeps the four ordered
  commands, and kbd-runtime must build the pinned CLI and require it.

Remaining (operator action, agents do not edit versions.toml): the
tools/surreal-memory-server pin must move 6acb605 -> 4ed6b2c, the
baseline the integration-administration freeze (58796bf) approved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T12:27:15.924696Z fc577c9 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fc577c9522

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
# never a skip. Bump PROMETHEUS_CLI_REF deliberately, alongside the full pack.
kbd-runtime:
name: kbd runtime integration (real prometheus CLI)
runs-on: ubuntu-latest

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run the real-CLI integration on every supported OS

Because the regular verify matrix now skips every runtime-mode case when the CLI is absent, and this replacement job runs only on Ubuntu, no Windows or macOS job exercises kbd-new-phase against the real runtime. A Windows-specific regression in executable spawning, path handling, or runtime projections can therefore leave every CI job green despite the repository requiring three-OS integration evidence; make this job a supported-OS matrix or provide the real CLI to the existing matrix.

AGENTS.md reference: scripts/AGENTS.md:L10-L19

Useful? React with 👍 / 👎.

Comment on lines +22 to +23
const prometheusAvailable = !prometheusProbe.error && prometheusProbe.status === 0;
const prometheusRequired = process.env.PROMETHEUS_CLI_REQUIRED === '1';

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Verify that the discovered executable is the KBD CLI

When an unrelated executable named prometheus is on PATH and exits successfully for --version, this probe marks it available and enables all runtime tests, which then fail while parsing or invoking unsupported kbd commands instead of taking the documented skip path. This is reproducible by setting PROMETHEUS_CLI_TEST_BINARY=/usr/bin/true; probe a KBD-specific command or validate the version output before treating the process as the real CLI.

AGENTS.md reference: scripts/AGENTS.md:L60-L65

Useful? React with 👍 / 👎.

GQAdonis and others added 4 commits September 30, 2026 07:58
The kbd-runtime job failed: prometheus-cli depends on the path crate
substrate/kbd-runtime, outside tools/prometheus-cli. Verified locally
with the same sparse checkout at the pinned ref: cargo check passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
libdbus-sys (OS keyring) needs the system D-Bus library on Linux.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
kbd-runtime classifies any replica as observation-only when CI,
GITHUB_ACTIONS, BUILDKITE or GITLAB_CI is set, so on the runner every
runtime-mode fixture failed with "registry classification forbids
authoritative writes". The fixture is a private, disposable runtime (own
data dir and signer) standing in for a developer checkout, so its child
processes no longer inherit those markers. Reproduced locally with
CI=true (13 failures) and verified 26/26 after the fix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pre-existing windows-latest failures (also on main):
- spec-backend spawned a bare 'openspec', which on Windows is only an npm
  .cmd shim that Node cannot start without a shell, so the OpenSpec
  backend could never work there. The default spawner now runs a locally
  resolved @fission-ai/openspec through its JavaScript entry (no PATH),
  falling back to a real executable on PATH. The integration test uses
  the same entry and gives helpers PROMETHEUS_PACK_ROOT. New test runs
  OpenSpec with an emptied PATH, reproducing Windows on any platform.
- The .mcp.json machine-path guard searched serialized JSON for the raw
  path; JSON escapes Windows backslashes, so a literal source root passed.
  containsMachinePath checks raw, JSON-escaped and forward-slashed forms.
- buildWorkspaceMembers printed crates\one on Windows (path.join);
  Cargo member paths are '/'-separated on every platform.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@GQAdonis
GQAdonis merged commit aaf7377 into main Sep 30, 2026
2 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant