Finding
PR #1064 adds tests/test_apps_just.bats (21 cases covering the apps.just
recipes install-opentabletdriver and cncf) and wires it into the Justfile
test recipe. It is not wired into .github/workflows/unit-tests.yml.
unit-tests.yml enumerates each BATS suite as its own explicit step
(bats tests/test_libsetup.bats, bats tests/test_update_just.bats, …) rather
than globbing tests/*.bats. A suite that is not listed simply never runs in
CI, silently, with a green check.
The workflow step could not be added in #1064 because the hive GitHub App token
has no workflows permission — the push is rejected outright:
! [remote rejected] quality/test-apps-just-otd-cncf -> quality/test-apps-just-otd-cncf
(refusing to allow a GitHub App to create or update workflow
`.github/workflows/unit-tests.yml` without `workflows` permission)
Recommendation
Add the step to unit-tests.yml, next to the other BATS steps:
- name: Run bats (apps.just — install-opentabletdriver, cncf)
run: bats tests/test_apps_just.bats
Structural follow-up
The explicit per-suite enumeration is itself the underlying gap — it makes
"suite exists but never runs in CI" the default failure mode for every new test
file, and it has to be kept in sync with the Justfile test recipe by hand.
Two lists, no gate that they agree.
Two options worth considering:
- Replace the enumerated steps with a single
bats tests/ (or bats tests/*.bats) invocation, excluding the suites that genuinely cannot run in
CI (e.g. test_libvirt_helper.bats, which the Justfile already documents
as needing a live libvirtd session) via an explicit skip list.
- Keep the enumeration but add a check that every
tests/*.bats file appears
in both unit-tests.yml and the Justfile test recipe, failing CI when a
new suite is added to neither.
Option 1 is less machinery and removes the drift class entirely.
Priority
- Impact: medium — a passing local
just test does not imply CI coverage
- Effort: low for the single step; medium for the structural fix
Filed by quality agent (hold-gated mode).
🐝 Hive Agent: quality | Instance: hosted-projectbluefin-knuckle-gjvq | SHA: unknown
— hive: agent=quality backend=copilot model=claude-opus-5
Finding
PR #1064 adds
tests/test_apps_just.bats(21 cases covering theapps.justrecipes
install-opentabletdriverandcncf) and wires it into theJustfiletestrecipe. It is not wired into.github/workflows/unit-tests.yml.unit-tests.ymlenumerates each BATS suite as its own explicit step(
bats tests/test_libsetup.bats,bats tests/test_update_just.bats, …) ratherthan globbing
tests/*.bats. A suite that is not listed simply never runs inCI, silently, with a green check.
The workflow step could not be added in #1064 because the hive GitHub App token
has no
workflowspermission — the push is rejected outright:Recommendation
Add the step to
unit-tests.yml, next to the other BATS steps:Structural follow-up
The explicit per-suite enumeration is itself the underlying gap — it makes
"suite exists but never runs in CI" the default failure mode for every new test
file, and it has to be kept in sync with the
Justfiletestrecipe by hand.Two lists, no gate that they agree.
Two options worth considering:
bats tests/(orbats tests/*.bats) invocation, excluding the suites that genuinely cannot run inCI (e.g.
test_libvirt_helper.bats, which theJustfilealready documentsas needing a live libvirtd session) via an explicit skip list.
tests/*.batsfile appearsin both
unit-tests.ymland theJustfiletestrecipe, failing CI when anew suite is added to neither.
Option 1 is less machinery and removes the drift class entirely.
Priority
just testdoes not imply CI coverageFiled by quality agent (hold-gated mode).
🐝 Hive Agent:
quality| Instance:hosted-projectbluefin-knuckle-gjvq| SHA:unknown— hive: agent=quality backend=copilot model=claude-opus-5