mirror of
https://github.com/deepseek-ai/deepseek-harness
synced 2026-08-15 21:04:50 +00:00
BLOCKER — the published lib/bin.js (stdio + acp) was exercised only via tsx
(demo:* / the src/bin.ts smokes); the built artifact under plain `node` was
unguarded. Root-cause on the BUILT bin:
1. Settle race: boot() returned once loader.create() registered the include
ENTRY, but the include loads its child plugins asynchronously — so boot()
(and main()) resolved while the app plugins (stdin reader, agent loop, ACP
bridge) were still mounting. A CLI with no attached handles yet exits 0
silently, and a load error surfaces as an unhandled rejection AFTER boot.
Fix: `await ctx.loader.await()` after create() — settle the whole tree.
2. Config-path robustness: hand the include the config's ABSOLUTE file:// URL
so resolution never depends on ctx.baseUrl / can never fall back to cwd.
Both bins fixed identically. NOTE: the cordis Loader resolves a config's bare
plugin specifiers via its internal module loader, active only under
`node --expose-internals`; the bin cannot add a node flag itself, so this is
documented in the bin JSDoc + both package READMEs (the demos already comply).
The repo `examples/*/cordis.yml` are tsx-only artifacts (workspace plugins
resolve through the tsconfig paths map, not node_modules), so they are not a
valid plain-node bin target — the smokes use a real-install-shaped temp dir.
Fail loud on a load failure: boot() previously exited 0 SILENTLY when a config
path's directory does not exist — the include plugin fails to IMPORT, the cordis
Loader catches+LOGS it and leaves the entry with no fiber (no rejection), and
`loader.await()` does not rethrow (EntryTree.await uses Promise.allSettled). Fix:
boot() now calls assertEntriesLoaded(ctx) after the tree settles and throws on
any entry with no fiber, so a typo'd config dir exits non-zero with a clear
message. main() also installs an unhandledRejection guard (installFailLoud) that
replaces Node's stack dump with a single labelled stderr line for the
companion case (a missing config FILE in a real dir, whose include-init throw
surfaces as a rejection Node already exits non-zero on). Regression tests added
to both built-bin smokes (missing dir + missing file → non-zero exit + stderr);
verified the missing-dir test fails on the pre-fix bin.
Built-bin smokes (the reviewer's ask): packages/ui/{stdio,acp}-agent/tests/
built-bin.e2e.ts run the REAL lib/bin.js under `node` (NOT tsx) in a temp
consumer dir, asserting the stdio echo round-trip / the acp initialize response
+ stdout purity, plus the fail-loud cases above. They build-gate (skip if lib/
absent) and run in a new ci.yml step after the build.
Issue 2 — packages/README.md + docs/architecture.md said "plugins depend on
interfaces, never on the concrete loop", but dsh-agent-core imports the concrete
dsh-agent-loop. Scope the rule to EXTENSION plugins and carve out the sanctioned
COMPOSITION/bundle exception (dsh-agent-core composes the concrete spine); note
it in the implemented RFC too.
Issue 3 — examples/acp-agent/tests/acp.snapshot.ts fixture-guard claimed
no-model scenarios need no session.jsonl, but runScenario() always boots
llm-replay with the session.jsonl path and loadReplayScript() throws when it is
absent. Require session.jsonl for ALL scenarios (no-model ones ship a
header-only fixture) and rewrite the comment to match reality.
101 lines
4.1 KiB
YAML
101 lines
4.1 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main, master]
|
|
pull_request:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
checks:
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
node: [24, 26]
|
|
name: node ${{ matrix.node }}
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- uses: actions/setup-node@v6
|
|
with:
|
|
node-version: ${{ matrix.node }}
|
|
|
|
- name: Enable corepack (pnpm)
|
|
run: corepack enable
|
|
|
|
- name: Install (immutable)
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Constraints
|
|
run: pnpm run constraints
|
|
|
|
# Before lint: the type-aware ESLint config resolves vendor packages via
|
|
# their built declarations (tsconfig.typecheck.json -> vendor/*/lib),
|
|
# which `pnpm run typecheck` emits. Lint on a fresh checkout would otherwise
|
|
# see unresolved types and erupt with no-unsafe-* errors.
|
|
- name: Typecheck (src + tests + examples)
|
|
run: pnpm run typecheck
|
|
|
|
- name: Lint
|
|
run: pnpm run lint
|
|
|
|
# Doc-sync gates (doc-sync-enforcement RFC). doc-typecheck compiles the fenced ts blocks in
|
|
# the docs and resolves vendor packages via their built declarations, which
|
|
# the typecheck step above emits — so it runs after typecheck. The cordis
|
|
# catalog freshness check, type-equiv check, and markdown wrap/link checks
|
|
# only read source. Same `doc-sync` script the pre-push hook runs
|
|
# (quality-gates RFC: one source of truth).
|
|
- name: Doc-sync gates (doc code blocks + cordis catalog + type-equiv + markdown wrap/links)
|
|
run: pnpm run doc-sync
|
|
|
|
# Module-graph freshness: regenerate docs/module-graph.md from the
|
|
# packages' peerDependencies and fail if it differs from the committed
|
|
# file. Only reads source package.json — no build needed.
|
|
- name: Module-graph freshness
|
|
run: pnpm run verify-module-graph
|
|
|
|
- name: Tests with coverage gate (per-file 100%)
|
|
run: pnpm run test:coverage
|
|
|
|
# ACP snapshot tests (acp-snapshot-tests RFC): boot the real acp-agent
|
|
# subprocess and replay recorded session-log fixtures, diffing the
|
|
# normalized stdout transcript + re-persisted log against committed
|
|
# goldens. KEYLESS by design — the same `test:snapshot` script the pre-push
|
|
# hook runs (one source of truth), so the full-transcript regression net
|
|
# is part of every PR gate, not just local pre-push.
|
|
- name: Snapshot tests (ACP transcript replay)
|
|
run: pnpm run test:snapshot
|
|
|
|
# Before hygiene: publint validates the packed artifacts (lib/index.js),
|
|
# which only the tsdown bundling step emits.
|
|
- name: Build (tsc -b + tsdown bundles)
|
|
run: pnpm run build
|
|
|
|
- name: Hygiene (knip + publint)
|
|
run: pnpm run knip && pnpm run publint
|
|
|
|
- name: Demo smoke test
|
|
run: |
|
|
set -euo pipefail
|
|
out=$(printf 'echo ci smoke\n' | timeout 60 pnpm run demo:echo 2>&1)
|
|
echo "$out"
|
|
echo "$out" | grep -q '\[tool call\] echo({"text":"ci smoke"})'
|
|
echo "$out" | grep -q '\[tool result\] ECHO: CI SMOKE'
|
|
# The JSONL backend (root ./.sessions, no cwd → _no-cwd bucket) writes a
|
|
# per-run session log named main-session-<uuid>.jsonl. Assert one exists.
|
|
ls .sessions/_no-cwd/main-session-*.jsonl >/dev/null
|
|
rm -rf .sessions
|
|
|
|
# The published `bin` is `lib/bin.js`, run under plain `node` by a real
|
|
# consumer — NOT the tsx dev path the demo smoke and demo:* scripts use.
|
|
# These keyless smokes boot the BUILT bins (this step runs AFTER the build)
|
|
# in a temp dir that mirrors a real install, catching a regression in the
|
|
# published artifact that tsx would mask. They self-skip if lib/ is absent,
|
|
# so the e2e job (which does not build) does not run them.
|
|
- name: Built-bin smoke test (published lib/bin.js under node)
|
|
run: pnpm exec vitest run --config vitest.e2e.config.ts packages/ui/stdio-agent/tests/built-bin.e2e.ts packages/ui/acp-agent/tests/built-bin.e2e.ts
|