Skip to content

test(cli): unbreak the Full Suite lanes on push-to-main - #36

Merged
timoteo7 merged 1 commit into
mainfrom
fix/ci-screenshot-reference-drift
Sep 29, 2026
Merged

timoteo7 merged 1 commit into
mainfrom
fix/ci-screenshot-reference-drift

Conversation

@timoteo7

Copy link
Copy Markdown
Owner

test(cli): unbreak the Full Suite lanes on push-to-main

Full Suite (non-blocking) run 36404155928 on d3573cc fails every shard plus the
pipeline smoke tier, all from packages/cli. Each failure is test drift, not product
defect — none of these assertions are protecting behaviour that regressed.

  1. docs-screenshot-links: "expected [ ...(18) ] to deeply equal [ ...(16) ]".
    FN-9295 dropped artifacts-doc-edit.png and artifacts-gallery.png from the expected
    list because no markdown referenced them yet. docs/dashboard-guide.md has since
    referenced both again, so the references are real and the list must carry them.

  2. cli-quiet-prompt-surfaces: died with ENOENT on src/commands/research.ts. That
    command was deleted in FN-9331 (74ffa19, "remove the fn research CLI") while this
    test kept auditing it. Drop the removed path from the audited list.

  3. extension-experiment-finalize: all 5 cases failed at module setup with
    'No "MAX_TASK_MESSAGE_LENGTH" export is defined on the @fusion/core mock'.
    extension.ts reads that constant while registering the refine tool's zod schema, and
    this file uses a FULL-REPLACEMENT mock, so the missing export aborts the file before a
    single assertion runs. The mock now carries the real constant (100_000).

A fourth red test, task-retry.test.ts, is not touched here: it fails only when the
workspace has not been built, because @fusion-plugin-examples/antigravity-runtime
resolves through exports.import -> ./dist/index.js. pnpm build produces that dist and
the test passes, which is what Full Suite already does before the shards. Fixing it
would mean changing the build cache contract, not a test.

Verified on this branch: the whole packages/cli suite is green — 150 files passed,
1859 tests passed, 0 failures. eslint 0 errors, check-mock-completeness green.

Impacto no gate de post-merge

O gate post-merge-verification (FN-9369) exige um Full Suite verde apos o merge. Com
estes 4 arquivos vermelhos o gate reprovaria mesmo que conseguisse executar. Esta PR remove a
causa de reprovamento; a limitacao de execucao do gate em in-review esta sendo tratada a parte
(PR #34).

Nao mexi no quarto teste vermelho

task-retry.test.ts falha apenas sem build do workspace. Nao ha correcao de teste a fazer — mexer
seria mudar o contrato de cache de build.

Escopo

Apenas arquivos de teste. Zero mudanca em codigo de produto. Nenhuma alteracao na main.

Full Suite (non-blocking) run 36404155928 on d3573cc fails every shard plus the
pipeline smoke tier, all from packages/cli. Each failure is test drift, not product
defect — none of these assertions are protecting behaviour that regressed.

1. docs-screenshot-links: "expected [ ...(18) ] to deeply equal [ ...(16) ]".
   FN-9295 dropped artifacts-doc-edit.png and artifacts-gallery.png from the expected
   list because no markdown referenced them yet. docs/dashboard-guide.md has since
   referenced both again, so the references are real and the list must carry them.

2. cli-quiet-prompt-surfaces: died with ENOENT on src/commands/research.ts. That
   command was deleted in FN-9331 (74ffa19, "remove the fn research CLI") while this
   test kept auditing it. Drop the removed path from the audited list.

3. extension-experiment-finalize: all 5 cases failed at module setup with
   'No "MAX_TASK_MESSAGE_LENGTH" export is defined on the @fusion/core mock'.
   extension.ts reads that constant while registering the refine tool's zod schema, and
   this file uses a FULL-REPLACEMENT mock, so the missing export aborts the file before a
   single assertion runs. The mock now carries the real constant (100_000).

A fourth red test, task-retry.test.ts, is not touched here: it fails only when the
workspace has not been built, because @fusion-plugin-examples/antigravity-runtime
resolves through exports.import -> ./dist/index.js. `pnpm build` produces that dist and
the test passes, which is what Full Suite already does before the shards. Fixing it
would mean changing the build cache contract, not a test.

Verified on this branch: the whole packages/cli suite is green — 150 files passed,
1859 tests passed, 0 failures. eslint 0 errors, check-mock-completeness green.
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

4589 finding(s)

HIGH/CRITICAL: 43 | MEDIUM: 4035 | LOW: 511

Severity Rule Location
HIGH secret-database-url .github/workflows/full-suite.yml:55
HIGH secret-generic-credential .github/workflows/full-suite.yml:56
HIGH secret-database-url .github/workflows/full-suite.yml:284
HIGH secret-generic-credential .github/workflows/full-suite.yml:285
HIGH secret-database-url .github/workflows/full-suite.yml:324
HIGH secret-generic-credential .github/workflows/full-suite.yml:325
HIGH secret-database-url .github/workflows/pr-checks.yml:221
HIGH secret-generic-credential .github/workflows/pr-checks.yml:222
HIGH secret-generic-credential .github/workflows/release.yml:522
HIGH secret-generic-credential .github/workflows/release.yml:524
HIGH secret-generic-credential .github/workflows/test-release.yml:445
HIGH secret-generic-credential .github/workflows/test-release.yml:447
HIGH secret-generic-credential docs/cli-reference.md:80
HIGH secret-generic-credential docs/signals-connectors.md:34
HIGH secret-generic-credential docs/signals-connectors.md:77
HIGH secret-generic-credential docs/signals-connectors.md:94
HIGH secret-generic-credential docs/signals-connectors.md:117
HIGH secret-generic-credential docs/signals-connectors.md:159
HIGH secret-generic-credential packages/cli/STANDALONE.md:71
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:12
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:30
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:31
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:102
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:103
HIGH secret-generic-credential packages/core/src/postgres/embedded-lifecycle.ts:843
HIGH secret-database-url packages/core/src/postgres/embedded-lifecycle.ts:1574
HIGH secret-database-url packages/core/src/postgres/pg-backup.ts:756
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:651
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:727
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:81
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:115
HIGH js-ssrf-outbound-request packages/dashboard/src/routes.ts:1858
HIGH js-host-header-trust packages/dashboard/src/server.ts:2689
HIGH js-host-header-trust packages/dashboard/src/server.ts:2714
HIGH js-host-header-trust packages/dashboard/src/server.ts:3025
HIGH js-host-header-trust packages/dashboard/src/server.ts:3193
HIGH secret-slack-webhook plugins/examples/fusion-plugin-notification/README.md:46
HIGH secret-database-url scripts/pg-test-server.mjs:200
HIGH secret-database-url scripts/pg-test-server.mjs:231
HIGH secret-database-url scripts/pg-test-server.mjs:241
HIGH secret-generic-credential scripts/sync-fusion-skill-tools.mjs:550
HIGH secret-generic-credential scripts/verify-windows-elevated-restricted.mjs:81
HIGH secret-generic-credential scripts/verify-windows-encoding-recovery.mjs:41
MEDIUM redos-nested-quantifier docs/agents.md:1710
MEDIUM insecure-temp-file docs/solutions/test-failures/main-full-suite-census-2026-09-25.md:376
MEDIUM insecure-temp-file docs/solutions/test-failures/main-full-suite-census-2026-09-25.md:377
MEDIUM insecure-temp-file docs/solutions/test-failures/main-full-suite-census-2026-09-25.md:541
MEDIUM insecure-temp-file packages/cli/src/__tests__/bin.test.ts:136
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:33
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:34

…and 4539 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@timoteo7
timoteo7 merged commit b4cddcb into main Sep 29, 2026
7 checks passed
timoteo7 pushed a commit that referenced this pull request Sep 29, 2026
…rence-drift

Two packages/cli tests failed in the Full Suite shard on b4cddcb. Both were
pre-existing drift that PR #36 (test files only) neither caused nor fixed.

1. task-retry.test.ts "clears the deadlock auto-pause" — expected 'todo', got
   'in-review'. The fixture is a MERGE failure (all steps done, mergeRetries 4),
   and FN-9317 ("recover stalled in-review merges", 706c155) made that shape
   retry IN PLACE: clear status/error/auto-pause, reset mergeRetries, keep the
   card in review so approved work is not re-run. The `todo` assertion is
   pre-FN-9317 drift from FN-6173 (1c69ea7), which briefly sent CLI merge
   retries back to todo and was later reverted. Every sibling surface already
   asserts the in-place behavior for this exact shape: commands/__tests__/task.test.ts
   asserts moveTask is NOT called and logs "in-review merge retry, mergeRetries
   reset"; __tests__/extension.test.ts asserts details.newColumn === "in-review";
   the dashboard route classifies it the same way. The product is correct, so the
   stale expectation is fixed and the test is renamed to state the contract it
   pins. Added the complementary execution-failure case (unfinished steps -> re-queue
   to the hold column with progress preserved), mirroring extension.test.ts, so the
   re-queue half of the deadlock auto-pause stays covered. 3 passed / 1 failed -> 4 passed.

2. skills-get.test.ts "prints a guide and version from the same built CLI entry
   point" — 'Test timed out in 5000ms'. The test did three SERIAL cold boots of
   the ~19 MB dist/bin.js ESM bundle inside one `it` (~1.0 s each locally, 2-3 s on
   a shared GitHub runner): the guide, --version, and the unknown-skill error path.
   Three serial boots need ~3.1 s locally against Vitest's 5000 ms default and
   exceed it on the runner. Nothing hung; the seam is what was wrong. Fix: run the
   two independent guide/version invocations concurrently via Promise.all so their
   boots overlap, and move the error-path boot into its own test. Wall clock drops
   from ~3.1 s to ~1.2 s (measured) with identical assertions and no timeout bump
   (check-no-test-timeout-appeasement.mjs stays green). Coverage unchanged: the
   guide must still come from the built entry point and its embedded version must
   still match that same built binary's --version.

Gates: task-retry 4/4 pass, skills-get 6/6 pass, runTaskRetry suite 12/12 pass,
cli tsc --noEmit clean, check-no-test-timeout-appeasement.mjs clean,
check-changeset-format.mjs clean, eslint 0 errors (test files are eslint-ignored).
No changeset: test-only change, no published behavior delta (AGENTS.md).

Pipeline smoke tier is a SEPARATE pre-existing timing failure, not touched here.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant