Skip to content

ci: select affected checks and separate full integration verification - #256

Merged
Qiyuanqiii merged 2 commits into
mainfrom
codex/ci-affected-checks
Oct 5, 2026
Merged

Qiyuanqiii merged 2 commits into
mainfrom
codex/ci-affected-checks

Conversation

@Qiyuanqiii

@Qiyuanqiii Qiyuanqiii commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

Small frontend and Go PRs currently start the entire backend, Store, LSP, Rust and native desktop matrix. Select PR and main-push checks from changed inputs instead. Frontend changes retain API drift, tests, build, dependency audit and actual production bundle loading without starting the backend integration suites or release packaging.

Go selection uses the real import graph. Directly changed packages run complete tests; indirect consumers run tests, with the four large integration packages compiling and running selected existing provider/MCP regressions. Production dependencies propagate; test imports add only their test consumer. Store shards and real native/LSP/browser/analyzer checks run when their inputs are affected.

Keep cross-package contracts in partial runs:

  • The Linux frontend lane runs the existing production bundle test through the same LoadEmbeddedFS loader used by Desktop startup. Native and packaging scripts also run this test after its move to web.
  • Indirect HTTP consumers retain the Go DTO-to-OpenAPI golden check. A snapshot-only change runs this targeted Go check and the frontend JSON-to-TypeScript check.
  • Shared launch-handoff and upstream skill fixtures explicitly select their MCP, snapshot, import, CLI or Store consumers. Local testdata stays with its package; shared inputs do not propagate through production dependency edges.
  • The Rust lane also runs the Go consumers of its two shared golden fixtures.

Full verification runs nightly at 03:23 Asia/Hong_Kong and through Actions CI → Run workflow. CI machinery, Go dependency changes and unclassified inputs also select full checks. Authority race checks and the Go audit run independently of ordinary Go tests. Native-only changes keep desktop boundary tests but omit archive/reproducibility builds.

The release workflow now limits PR packaging to release tooling and distribution inputs. Tags/manual releases require a successful Full CI verification job for the exact commit and run attempt; a successful partial CI run is insufficient. Existing font/branding assertions remain in the central release-contract tests, with obsolete requirements to trigger packaging removed.

Direct edits to large packages such as application still run their complete suites. This change does not claim that every PR finishes within a fixed number of minutes.

CI redesign idea credited to Claude; implementation credited to Codex in the commit coauthor trailers.

Validation

  • CI helper suite: 54 tests, 53 passed and one existing Windows filename limitation skip.
  • Actual production bundle test passed; adding a temporary .js.map caused the selected test to fail with the loader's unsupported-extension error. It passed again after removing the probe.
  • Using the real repository package graph, an optional DTO field added through a Go overlay and a snapshot-only mutation both failed the selected OpenAPI golden check.
  • Changing the shared launch-handoff fixture's command failed the actual selected runner in the MCP consumer. Restoring it passed vet and the complete agentpackages/MCP suites.
  • The existing OpenAPI golden and both Go analyzer shared-golden tests passed. Classifier regressions cover indirect DTO changes, snapshot-only changes, shared fixtures, ordinary fixtures and Store selection.
  • actionlint v1.7.12 passed for the updated CI workflow; the Windows build script parsed successfully.
  • Current revision 78ac92b7: CI and Desktop release validation are running. These full runs are separate from the partial-selection regression evidence above.

Surface governance

  • No Surface is added, promoted, downgraded, deprecated, or removed.
  • Registry item(s): N/A — no Surface change.
  • Target tier / transition: N/A.
  • Entry criteria / decision: N/A.
  • Owner: N/A.
  • Shared Go Application contract: Unchanged.
  • Authority impact: Runtime authority unchanged; release verification distinguishes full from partial CI.
  • Supported platforms: Existing platforms retained.
  • Release / test evidence: Validation above; full platform matrix retained.
  • Compatibility strategy: Keep the Go control plane result and add an explicit full-only release result.
  • Deprecation window: N/A.
  • Removal / rollback plan: Revert this CI-only policy change.

Audit

  • No credentials or local runtime data are included.
  • Runtime policy, workspace, sandbox and persistence code is unchanged.
  • docs/ci.md documents selection, full runs and release prerequisites.

Run PR and main checks from changed inputs and the Go dependency graph.
Keep complete verification on nightly/manual runs and global CI/dependency
changes, and require that explicit result before releasing.

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Claude <81847+claude@users.noreply.github.com>

@NanaseInori NanaseInori left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed against 669dc78817f3ab2463d15a70519b1dc38348d43e. Full CI is green, but I found three reproducible gaps in the partial-selection paths:

  1. [P2] Validate the actual production bundle in the frontend lane — .github/workflows/ci.yml:317–318

    internal/webui tests use synthetic bundles, while web has no test files, so go test -tags desktop ./web only checks that embedding compiles. Frontend-only changes now skip the native jobs and therefore skip TestEmbeddedProductionUIBundleLoadsApprovedFontsAndNotices. Using the unchanged loader, tests and embedding adapter, I reproduced both new Go commands passing with an embedded .js.map asset, while the actual Desktop startup loader fails with unsupported extension ".map". Please run LoadEmbeddedFS against the actual built production assets in this lane; this can be a Linux-runnable test without restoring packaging.

  2. [P2] Preserve the Go-to-OpenAPI golden check for indirect HTTP changes — scripts/ci/run_go_checks.py:166–173

    The real package graph selects only compilation for httpapi when internal/application/github_review_service.go changes, with no selected HTTP integration test and no web job. This file contains DTOs directly reflected by the OpenAPI generator. Adding an optional JSON field to GitHubReviewCredentialView in an isolated overlay makes TestOpenAPIGoldenDocumentMatchesGoDTOs fail because docs/openapi.json is stale, but the selected plan omits that check. npm run check:api only validates the committed JSON-to-TypeScript step. Please retain the golden test when HTTP is affected but not fully tested, and when the OpenAPI snapshot changes.

  3. [P2] Include shared testdata consumers in the affected set — scripts/ci/run_go_checks.py:141–144

    internal/agentpackages/testdata/launch-handoff/mcp.json is also read directly by MCP integration tests, but a change to this fixture selects only internal/agentpackages. I changed only default-cwd.command from ./bin/helper.exe to ./work/bin/helper.exe: the actual selected runner, including vet and the complete agentpackages suite, passes, while the omitted TestAgentPluginsSharedLaunchHandoff fails at client_agentplugins_integration_test.go:103. Please model these existing shared fixture consumers explicitly, or use a conservative fallback for shared fixture paths.

These can be addressed while preserving the affected-check design. The current PR selects full CI because it changes CI machinery, so its successful full run does not exercise these partial-selection cases.

Run the existing production bundle loader test from the Linux frontend lane
and preserve its native and packaging coverage. Keep the OpenAPI golden check
for indirect HTTP consumers and snapshot-only changes. Declare shared fixture
consumers without propagating test-only input changes through production edges.

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Claude <81847+claude@users.noreply.github.com>

@NanaseInori NanaseInori left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at 78ac92b7d53ce597351c0846d0ab045ee0077993. All three issues from my previous review are resolved.

  • The frontend lane now executes the relocated production-bundle test, including the actual LoadEmbeddedFS call and the existing font/license assertions. The previous .js.map fault is now rejected by that test, and removing the fault restores a passing result. Native and packaging callers also retain the relocated test.
  • Indirect HTTP changes now retain the Go DTO-to-OpenAPI golden check. Snapshot-only changes also select the targeted Go check alongside the frontend checks. Both the DTO-overlay and snapshot-mutation cases are detected.
  • Shared launch-handoff fixtures now select both the agentpackages and MCP suites. Repeating the previous command-path mutation causes the actual selected runner to fail in the MCP consumer; restoring the fixture makes the same selection pass.

The 54 CI helper tests pass locally, and both full CI and Desktop release validation have succeeded for this exact head.

I found no remaining blocking issues in this re-review. Approve.

@Qiyuanqiii
Qiyuanqiii merged commit dab1e2b into main Oct 5, 2026
28 checks passed
@Qiyuanqiii
Qiyuanqiii deleted the codex/ci-affected-checks branch October 5, 2026 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants