Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
90 commits
Select commit Hold shift + click to select a range
7da98ea
test: require Unix-testable Brew snapshot boundary
seonghobae Aug 13, 2026
f855a63
test: expose verified brew opener to unix unit tests
seonghobae Aug 13, 2026
48f44b2
test: prove same-inode brew content mutation is unsafe
seonghobae Aug 13, 2026
dc5e369
security: snapshot approved brew script bytes
seonghobae Aug 13, 2026
ddf7fc3
test: avoid audit authority contract false positive
seonghobae Aug 13, 2026
fe13b27
merge: advance content-bound Homebrew execution onto Intel compatibility
seonghobae Aug 20, 2026
eec9d48
merge: advance content-bound Homebrew execution onto current Intel co…
seonghobae Aug 20, 2026
9366790
fix(stack): preserve current audit root in content-bound execution owner
seonghobae Aug 20, 2026
2e7b845
merge: advance content-bound execution onto current Intel compatibili…
seonghobae Aug 20, 2026
3de1191
Merge remote-tracking branch 'origin/fix/intel-homebrew-executable-v1…
seonghobae Aug 29, 2026
5e2e54b
test: reject invalid negative paths-ignore filters
seonghobae Sep 3, 2026
47d16e0
fix(ci): use valid ordered path filters for contract docs
seonghobae Sep 3, 2026
439431a
test: reproduce paths-ignore parser blind spots
seonghobae Sep 3, 2026
80c8971
fix(test): inspect every paths-ignore list item
seonghobae Sep 3, 2026
bf8be64
merge: restack path-filter repair on release verifier
seonghobae Sep 3, 2026
5b005dd
merge: restack path-filter repair on release contract inheritance
seonghobae Sep 3, 2026
8633229
restack(ci): adopt current release foundation
seonghobae Sep 4, 2026
e0bf338
chore(stack): adopt bounded Vitest worker foundation
seonghobae Sep 4, 2026
7440ceb
chore(stack): restack path-filter repair on release owner
seonghobae Sep 4, 2026
9e236eb
chore(stack): adopt exact release test repair
seonghobae Sep 4, 2026
7523243
chore: restack path-filter owner on current release foundation
seonghobae Sep 4, 2026
eb255b9
chore(stack): restack path-filter owner on current release foundation
seonghobae Sep 5, 2026
fe20596
test(ci): require canonical Windows agent-state regression
seonghobae Sep 6, 2026
29aaf64
fix(ci): own Windows agent-state regression in Test workflow
seonghobae Sep 6, 2026
f339ee4
fix(ci): run source-present macOS cache owner regressions
seonghobae Sep 6, 2026
dad7832
test: quote workflow command fixture correctly
seonghobae Sep 6, 2026
ce005cb
merge: refresh content-bound execution stack
seonghobae Sep 7, 2026
a0668aa
test(ci): require exact-head test checkout
seonghobae Sep 7, 2026
50ad308
fix(ci): pin test checkouts to exact head
seonghobae Sep 7, 2026
90ca448
test(ci): bound exact-head checkout parser to one step
seonghobae Sep 7, 2026
5b4e656
merge(ci): adopt current release/Test foundation
seonghobae Sep 9, 2026
13aa167
test(ci): require provider OAuth Windows process contract
seonghobae Sep 9, 2026
8b0e2b5
fix(ci): run provider OAuth process contract on Windows
seonghobae Sep 9, 2026
0e53be7
test(ci): require explicit agent-state skip evidence
seonghobae Sep 9, 2026
e17c2ad
fix(ci): make agent-state source absence explicit
seonghobae Sep 9, 2026
235780c
chore(deps-dev): bump vitest from 4.1.11 to 5.0.0 (#349)
dependabot[bot] Sep 9, 2026
e6de6fd
feat: runtime-agnostic container orphan reclamation (docker/podman/co…
seonghobae Sep 9, 2026
8a10edc
test(ci): make exact-head checkout contract lane-extensible
seonghobae Sep 9, 2026
02a95a6
chore: adopt current release foundation into Test owner
seonghobae Sep 9, 2026
f6c1d9a
fix(ci): isolate Ubuntu dependency refresh
seonghobae Sep 9, 2026
f5a7402
test(ci): lock Ubuntu apt isolation contract
seonghobae Sep 9, 2026
90e3d8b
test(ci): require bounded npm failure phase diagnostics
seonghobae Sep 10, 2026
e855260
fix(ci): expose failed npm test phase without weakening gate
seonghobae Sep 10, 2026
11a089f
test(ci): use expression-safe npm test step id
seonghobae Sep 10, 2026
ecd74a9
fix(ci): use expression-safe diagnostic step id
seonghobae Sep 10, 2026
da57069
test(ci): require original npm failure evidence
seonghobae Sep 10, 2026
442ea0d
fix(ci): retain authoritative npm failure transcript
seonghobae Sep 10, 2026
f0876de
feat(runtime): add no-reap Unix process-group primitive
seonghobae Sep 11, 2026
af70c8f
feat(runtime): register Unix process-group lifecycle boundary
seonghobae Sep 11, 2026
c6fcda4
style(runtime): keep Unix lifecycle primitive rustfmt-clean
seonghobae Sep 11, 2026
5791356
feat(runtime): bound no-reap child completion polling
seonghobae Sep 11, 2026
4ba48ab
test(ci): exercise Unix process-group lifecycle on macOS
seonghobae Sep 11, 2026
ac11d24
test(ci): isolate macOS workflow admission steps
seonghobae Sep 11, 2026
65d0002
Merge remote-tracking branch 'origin/fix/test-path-filter-contract-v1…
seonghobae Sep 11, 2026
3c83608
test(runtime): require waitid child-pid observation
seonghobae Sep 11, 2026
8ca5b91
fix(runtime): classify waitid WNOHANG by returned child pid
seonghobae Sep 11, 2026
a43f424
test(ci): require macOS provider process-group admission
seonghobae Sep 11, 2026
ca1324d
fix(ci): compile provider process-group contract on macOS
seonghobae Sep 11, 2026
a1d1cce
chore(ci): adopt current shared Test owner
seonghobae Sep 11, 2026
ad61c38
fix(runtime): retry interrupted no-reap observations
seonghobae Sep 11, 2026
9558c85
test(ci): expose shared Test owner gaps on protected main
seonghobae Sep 12, 2026
8377227
fix(ci): restack shared Test owner on protected main
seonghobae Sep 12, 2026
cef7ffe
test(ci): harden shared Test workflow contracts
seonghobae Sep 12, 2026
a2edb18
test(ci): expose cross-event path-filter bleed
seonghobae Sep 12, 2026
3f5c516
fix(ci): scope path parsing to its workflow event
seonghobae Sep 12, 2026
3e05a9f
test(release): align retry contract with PR-only cancellation
seonghobae Sep 12, 2026
078e57c
test(release): require docs to match PR-scoped retry semantics
seonghobae Sep 12, 2026
7d97076
docs(release): align concurrency evidence with PR-only cancellation
seonghobae Sep 12, 2026
634870b
docs(release): align rerun concurrency evidence wording
seonghobae Sep 12, 2026
e21da71
chore(ci): restack shared Test owner on release repair
seonghobae Sep 12, 2026
7f0f834
test(ci): require lockfile-bound Cargo commands
seonghobae Sep 12, 2026
b05919f
fix(ci): lock canonical Cargo dependency graph
seonghobae Sep 12, 2026
a535f07
test(ci): align Cargo lock contract with canonical lanes
seonghobae Sep 12, 2026
f2d87f6
test(ci): align macOS admission expectation with lockfile-bound Cargo
seonghobae Sep 12, 2026
fc3ee0c
test(ci): require Rust failure transcript
seonghobae Sep 12, 2026
e4e36de
fix(ci): preserve Rust failure transcript
seonghobae Sep 12, 2026
7c3a7b3
fix(ci): reconcile shared Test owner with canonical release foundation
seonghobae Sep 13, 2026
eebc9a7
test(ci): require successful Rust diagnostic evidence
seonghobae Sep 13, 2026
1bfcc7c
fix(ci): retain successful Rust diagnostics
seonghobae Sep 13, 2026
50724c1
feat(runtime): add cancellable bounded Unix pipe readers
seonghobae Sep 15, 2026
437d81f
test(runtime): keep escaped writer open during cancellable-reader ass…
seonghobae Sep 15, 2026
9257991
test(brew): require cancellable Unix process lifecycle
seonghobae Sep 15, 2026
74539f7
chore(runtime): inherit canonical Unix lifecycle owner
seonghobae Sep 15, 2026
7354008
fix(brew): contain descendants during cleanup output settlement
coderabbitai[bot] Sep 15, 2026
17d89c2
ci(brew): adopt canonical cross-platform Test owner
seonghobae Sep 15, 2026
c34f652
fix(runtime): bound cancelled continuous pipe writers
seonghobae Sep 15, 2026
e75501e
fix(runtime): stop pipe readers after cancellation
coderabbitai[bot] Sep 15, 2026
c2b91a0
merge(runtime): adopt canonical Unix lifecycle owner
seonghobae Sep 15, 2026
cf78273
test(runtime): tolerate disconnected cancellable pipe writers
coderabbitai[bot] Sep 15, 2026
5185457
merge(runtime): adopt current Unix lifecycle owner
seonghobae Sep 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
210 changes: 174 additions & 36 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,29 +3,31 @@ name: Test
on:
push:
branches: [main]
paths-ignore:
- "docs/**"
- "*.md"
# Content-checked by contract tests (vitest + cargo test) — must still run CI.
- "!docs/doctoring/release-artifact-provenance.md"
- "!docs/doctoring/tauri-content-security-policy.md"
- "!docs/doctoring/model-artifact-integrity.md"
- "!docs/doctoring/model-load-handle-binding.md"
- "!docs/development/icloud-local-eviction-batch.md"
- "!docs/architecture/goals/cloud-offload-goal.json"
- "!CHANGELOG.md"
paths:
- "**"
- "!docs/**"
- "!*.md"
# GitHub supports re-inclusion only with ordered positive patterns under `paths`.
- "docs/doctoring/release-artifact-provenance.md"
- "docs/doctoring/tauri-content-security-policy.md"
- "docs/doctoring/model-artifact-integrity.md"
- "docs/doctoring/model-load-handle-binding.md"
- "docs/development/icloud-local-eviction-batch.md"
- "docs/architecture/goals/cloud-offload-goal.json"
- "CHANGELOG.md"
pull_request:
paths-ignore:
- "docs/**"
- "*.md"
# Content-checked by contract tests (vitest + cargo test) — must still run CI.
- "!docs/doctoring/release-artifact-provenance.md"
- "!docs/doctoring/tauri-content-security-policy.md"
- "!docs/doctoring/model-artifact-integrity.md"
- "!docs/doctoring/model-load-handle-binding.md"
- "!docs/development/icloud-local-eviction-batch.md"
- "!docs/architecture/goals/cloud-offload-goal.json"
- "!CHANGELOG.md"
paths:
- "**"
- "!docs/**"
- "!*.md"
# GitHub supports re-inclusion only with ordered positive patterns under `paths`.
- "docs/doctoring/release-artifact-provenance.md"
- "docs/doctoring/tauri-content-security-policy.md"
- "docs/doctoring/model-artifact-integrity.md"
- "docs/doctoring/model-load-handle-binding.md"
- "docs/development/icloud-local-eviction-batch.md"
- "docs/architecture/goals/cloud-offload-goal.json"
- "CHANGELOG.md"

permissions:
contents: read
Expand All @@ -38,45 +40,155 @@ jobs:
test:
runs-on: ubuntu-latest
timeout-minutes: 30
env:
CARGO_BUILD_JOBS: 2
CARGO_INCREMENTAL: 0
CARGO_PROFILE_TEST_DEBUG: 0
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Install Tauri system deps
run: |
sudo apt-get update
sudo apt-get install -y libwebkit2gtk-4.1-dev libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev
for source_file in /etc/apt/sources.list.d/*; do
if [[ -f "$source_file" ]] && grep -q 'dl.google.com/linux/chrome' "$source_file"; then
sudo rm -f "$source_file"
fi
done
sudo apt-get -o Acquire::Retries=3 update
sudo apt-get install -y libwebkit2gtk-4.1-dev libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev lsof
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
workspaces: src-tauri
cache-targets: false
- name: Configure private test temp
run: |
mkdir -p "$RUNNER_TEMP/disksage"
echo "TMPDIR=$RUNNER_TEMP/disksage" >> "$GITHUB_ENV"
- name: Rust tests (includes unix symlink test)
run: cargo test --manifest-path src-tauri/Cargo.toml
id: rust_test
continue-on-error: true
run: |
set -o pipefail
cargo test --locked --manifest-path src-tauri/Cargo.toml 2>&1 | tee "$RUNNER_TEMP/disksage-rust-test.log"
- name: Upload authoritative Rust diagnostic transcript
if: steps.rust_test.outcome == 'success'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: rust-test-diagnostics-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/disksage-rust-test.log
if-no-files-found: error
- name: Upload authoritative Rust test failure transcript
if: steps.rust_test.outcome == 'failure'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: rust-test-failure-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/disksage-rust-test.log
if-no-files-found: error
- name: Preserve Rust test failure
if: steps.rust_test.outcome == 'failure'
run: exit 1
- name: Headless cloud planner tests
run: cargo test --manifest-path src-tauri/Cargo.toml --features cloud-cli --bin disksage-cloud-plan
run: cargo test --locked --manifest-path src-tauri/Cargo.toml --features cloud-cli --bin disksage-cloud-plan
- name: Exact duplicate audit tests
run: |
cargo test --manifest-path src-tauri/Cargo.toml --features cloud-cli duplicate_audit
cargo test --manifest-path src-tauri/Cargo.toml --features cloud-cli --bin disksage-duplicate-audit
cargo test --locked --manifest-path src-tauri/Cargo.toml --features cloud-cli duplicate_audit
cargo test --locked --manifest-path src-tauri/Cargo.toml --features cloud-cli --bin disksage-duplicate-audit
- name: Extraction-free archive tree proof tests
run: |
cargo test --manifest-path src-tauri/Cargo.toml --features archive-cli archive_git_tree
cargo test --manifest-path src-tauri/Cargo.toml --features archive-cli --bin disksage-archive-tree
cargo test --manifest-path src-tauri/Cargo.toml --features archive-cli --test archive_tree_help_exit
cargo test --locked --manifest-path src-tauri/Cargo.toml --features archive-cli archive_git_tree
cargo test --locked --manifest-path src-tauri/Cargo.toml --features archive-cli --bin disksage-archive-tree
cargo test --locked --manifest-path src-tauri/Cargo.toml --features archive-cli --test archive_tree_help_exit
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 20.19.0
node-version: 22.12.0
- run: npm ci
- run: npm test
- name: Run npm test
id: npm_test
continue-on-error: true
run: |
set -o pipefail
npm test 2>&1 | tee "$RUNNER_TEMP/disksage-npm-test.log"
- name: Upload authoritative npm test failure transcript
if: steps.npm_test.outcome == 'failure'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: npm-test-failure-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/disksage-npm-test.log
if-no-files-found: error
- name: Diagnose SvelteKit sync after npm test failure
if: steps.npm_test.outcome == 'failure'
continue-on-error: true
run: npm exec -- svelte-kit sync
- name: Diagnose Vitest after npm test failure
if: steps.npm_test.outcome == 'failure'
continue-on-error: true
run: npm exec -- vitest run
- name: Diagnose workflow contract after npm test failure
if: steps.npm_test.outcome == 'failure'
continue-on-error: true
run: node --test scripts/ci/workflow-concurrency-contract.test.mjs
- name: Diagnose browser test after npm test failure
if: steps.npm_test.outcome == 'failure'
continue-on-error: true
run: npm run test:browser --if-present
- name: Preserve npm test failure
if: steps.npm_test.outcome == 'failure'
run: exit 1
- run: npm run build

macos-cache-cleanup:
runs-on: macos-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
workspaces: src-tauri
cache-targets: false
- name: macOS cache cleanup regressions when owner source is present
env:
TMPDIR: ${{ runner.temp }}
run: |
for test_name in cache_cleanup_corepack_scope cache_cleanup_cli_permanent_gradle generated_cache_staged_activity; do
if [[ -f "src-tauri/tests/${test_name}.rs" ]]; then
cargo test --locked --manifest-path src-tauri/Cargo.toml --test "$test_name"
else
printf 'SKIP %s: owner source absent; no runtime regression executed\n' "$test_name"
fi
done
- name: macOS Unix process-group regression when owner source is present
env:
TMPDIR: ${{ runner.temp }}
run: |
if [[ -f "src-tauri/src/unix_process_group.rs" ]]; then
cargo test --locked --manifest-path src-tauri/Cargo.toml --lib unix_process_group::tests
else
printf 'SKIP unix_process_group: owner source absent; no runtime regression executed\n'
fi
- name: macOS provider global-sync process-group regression when owner source is present
env:
TMPDIR: ${{ runner.temp }}
run: |
if [[ -f "src-tauri/tests/provider_global_sync_success_pipe_contract.rs" ]]; then
cargo test --locked --manifest-path src-tauri/Cargo.toml --test provider_global_sync_success_pipe_contract
else
printf 'SKIP provider_global_sync_success_pipe_contract: owner source absent; no runtime regression executed\n'
fi

windows-home-resolution:
runs-on: windows-latest
timeout-minutes: 10
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
- name: Windows absolute-home regression
Expand All @@ -85,22 +197,48 @@ jobs:
New-Item -ItemType Directory -Force target | Out-Null
rustc --edition=2021 --test src-tauri/tests/home_resolution_contract.rs -o target/home-resolution-contract.exe
& .\target\home-resolution-contract.exe
- name: Windows agent-state regression when owner source is present
shell: pwsh
run: |
if (Test-Path 'src-tauri/src/agent_state_guard.rs') {
rustc --edition=2021 --test src-tauri/src/agent_state_guard.rs -o target/agent-state-guard.exe
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
& .\target\agent-state-guard.exe --nocapture
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
} else {
Write-Output 'SKIP agent_state_guard: owner source absent; no runtime regression executed'
}
- name: Windows provider OAuth process contract when owner source is present
shell: pwsh
run: |
if (Test-Path 'src-tauri/tests/provider_oauth_cli_process.rs') {
cargo test --manifest-path src-tauri/Cargo.toml --locked --features cloud-cli --test provider_oauth_cli_process
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
} else {
Write-Output 'SKIP provider_oauth_cli_process: owner source absent; no runtime regression executed'
}

llm-engine-build:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Install build deps (llama.cpp native + tauri)
run: |
sudo apt-get update
for source_file in /etc/apt/sources.list.d/*; do
if [[ -f "$source_file" ]] && grep -q 'dl.google.com/linux/chrome' "$source_file"; then
sudo rm -f "$source_file"
fi
done
sudo apt-get -o Acquire::Retries=3 update
sudo apt-get install -y cmake clang libclang-dev libwebkit2gtk-4.1-dev libgtk-3-dev libayatana-appindicator3-dev librsvg2-dev
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
workspaces: src-tauri
cache-targets: false
- name: Build with llm-engine (compiles real llama.cpp CPU + engine.rs FFI)
run: cargo test --manifest-path src-tauri/Cargo.toml --features llm-engine --lib --no-run
run: cargo test --locked --manifest-path src-tauri/Cargo.toml --features llm-engine --lib --no-run
Loading