mirror of
https://github.com/stablyai/orca.git
synced 2026-09-22 16:02:32 +00:00
* test(codex): pin Codex read-repair with a real-binary contract check
Orca's session index-heal depends on a Codex behavior: a `thread/read` of an
unindexed rollout performs a read-repair that inserts the `threads` row. All 55
existing heal tests drive a stub app-server and assert "healed" as "the call did
not error", so if Codex ever dropped the repair they would all stay green while
the subsystem went silently inert.
Adds a real-binary contract check built to the same shape as the Git binary
compatibility contract (src/shared/git-binary-compatibility.test.ts): env-gated
test file, version asserted against the binary, dedicated path-filtered PR job.
Pins only the four arms ablation established Orca relies on:
- a read of an unindexed rollout inserts the state row
- a session with no read inserts nothing (the negative control that makes the
insert causal rather than incidental)
- re-reading an indexed thread inserts nothing
- an archived thread stays archived rather than being resurrected
Written against codex-cli 0.150.1. The job sets ORCA_CODEX_CONTRACT_REQUIRED=1
so a missing or failed CLI install fails red instead of silently skipping.
Existing heal tests are unchanged.
* test(codex): register the contract job in the verify aggregate contract
`pr-workflow-parallelism.test.mjs` pins `verify.needs` exactly, so adding the
job to pr.yml without updating that list failed the shard. Adds the entry, and
adds a workflow contract test mirroring `git-binary-compatibility-workflow.test.mjs`:
- the pinned CODEX_CLI_VERSION is the single source for both the npm install
and the runtime version assertion, so the two cannot drift apart
- the install prefix and the binary path the test is pointed at are the same tree
- ORCA_CODEX_CONTRACT_REQUIRED=1 is set, so a failed install fails red rather
than turning the job into a green no-op
Removing the REQUIRED env from pr.yml reddens the new test, confirming it is live.
* test(codex): make binary version guard exact and bounded
* ci(codex): cover index-heal transport dependencies
* test(ci): pin Codex contract dependency coverage
* test(codex): align contract watchdog with child deadlines
* test(codex): cover three-session contract watchdog
* fix(codex): add sqlite sync-database to index-heal scope
---------
Co-authored-by: Merge Sim <sim@local>
38 lines
1.8 KiB
JavaScript
38 lines
1.8 KiB
JavaScript
import { readFileSync } from 'node:fs'
|
|
import { parse } from 'yaml'
|
|
import { describe, expect, it } from 'vitest'
|
|
|
|
describe('Codex index-heal contract PR gate', () => {
|
|
const workflow = parse(readFileSync('.github/workflows/pr.yml', 'utf8'))
|
|
const job = workflow.jobs.codex_index_heal_contract
|
|
|
|
it('installs and verifies against one pinned Codex version', () => {
|
|
const install = job.steps.find((step) => step.name === 'Install pinned Codex CLI')
|
|
const verify = job.steps.find((step) => step.name === 'Verify Codex index-heal contract')
|
|
|
|
// Why one source: the install and the runtime version assertion drifting apart is
|
|
// the failure that would leave this job verifying a Codex nobody declared.
|
|
expect(job.env.CODEX_CLI_VERSION).toMatch(/^\d+\.\d+\.\d+$/)
|
|
expect(install.run).toContain('"@openai/codex@$CODEX_CLI_VERSION"')
|
|
expect(verify.env.ORCA_CODEX_CONTRACT_VERSION).toBe('${{ env.CODEX_CLI_VERSION }}')
|
|
|
|
// The install prefix and the binary the test is pointed at must be the same tree.
|
|
expect(install.run).toContain('--prefix "$RUNNER_TEMP/codex-cli"')
|
|
expect(verify.run).toContain(
|
|
'ORCA_CODEX_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli/node_modules/.bin/codex"'
|
|
)
|
|
expect(verify.run).toContain('src/main/codex/codex-index-heal-binary-contract.test.ts')
|
|
})
|
|
|
|
it('fails rather than skipping when the Codex binary is missing', () => {
|
|
const verify = job.steps.find((step) => step.name === 'Verify Codex index-heal contract')
|
|
|
|
// Why asserted: the contract skips itself without a binary, so a failed install
|
|
// would otherwise turn this job into a green no-op that verifies nothing.
|
|
expect(verify.env.ORCA_CODEX_CONTRACT_REQUIRED).toBe('1')
|
|
expect(job.steps.find((step) => step.name === 'Install pinned Codex CLI').run).toContain(
|
|
'set -euo pipefail'
|
|
)
|
|
})
|
|
})
|