Repository navigation
ci: run the tools against a released ix and generate no-backend fixtures - #30
Merged
Merged
Conversation
Add a `real-ix` CI job that installs the checksummed ix v0.12.0 release tarball (no fake) and, with no backend (IX_ENDPOINT on port 1, empty IX_HOME): - runs every tool through tests/real-ix.test.ts (skipped unless IX_REAL_TESTS=1), behind a transparent shim that logs argv and stderr. It fails if ix rejects any argv a tool builds (unknown option/command), if a graph read does not surface ix's real workspace_not_mapped record, if ix-decide ALLOWs, if ix-health misreads the version, or if ix-locate loses the real `ix text` hit; - regenerates the fixtures that need no backend with tests/fixtures/regen-no-backend.ts (unmapped/ and a new no-backend/: --version, status with the backend down, ix text) and fails on any git diff. Fixtures that need a populated graph (success/, empty-repo/, empty-graph/, synthetic/) stay hand-captured. The unmapped/ records change only in the embedded temp directory, now a fixed path. `CI Passed` now also needs `real-ix`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EqMeW5huGYgRUWS2TtuvF8
The release's .sha256 sidecar only proves the download matches whatever the release holds now. The job also checks a sha256 pinned in the workflow, so a replaced asset fails it. ix-trace with a target adds --to to the argv the real CLI must accept. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
KageBinary
commented
Oct 4, 2026
KageBinary
left a comment
Collaborator
Author
There was a problem hiding this comment.
Reviewed. The release is pinned, actions are pinned by SHA, the job needs no secrets, and zizmor is clean. A bogus flag turns the job red.
Fixed in 4a18489 (after merging main, d294a2f):
- The only checksum came from the same release, so a swapped asset plus checksum would pass. The workflow now also pins the tarball's sha256.
- Tools stop at their first error, so optional flags were never sent. Added an
ix-tracecall withto; a bogus--tonow fails the job.
Still unchecked: map --silent and the Pro commands. Merging after #29.
KageBinary
marked this pull request as ready for review
October 4, 2026 20:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Task PL-03 of the Ix audit remediation plan.
What this adds
A
real-ixjob inci.yml(andCI Passednow needs it). It installs the released ix v0.12.0 tarball (sha256sum -cagainst the release's.sha256, Node 22, ripgrep from apt) and runs with no backend:IX_ENDPOINT=http://127.0.0.1:1, an emptyIX_HOME,IX_NO_UPDATE_CHECK=1. Actions are pinned by SHA,contents: read,persist-credentials: false. zizmor reports nothing.1.
tests/real-ix.test.ts(skipped unlessIX_REAL_TESTS=1)Every tool (17, plus extra ix-neighbors directions) runs in a child Bun with a transparent
ixshim first on PATH that logs argv and stderr, then hands off to the real CLI. Assertions:unknown option/unknown command/arity error on stderr, and the argv log shows each command was actually reached. I checked this by hand: adding--bogus-flagto ix-locate's argv turns it red. So pinning a CLI that lacks a flag a tool uses fails the job;workspace_not_mappedrecord, never "ix unavailable", "No matches found" or "No smells detected";ix --version, DEGRADED, and the error code;ix texthit from a temp file.The argv check covers code argv only. Agent and command prompts are not checked. A one-off local scan of
agents/*.jsonagainstix <cmd> --helpfound one problem, the known one:agents/ix-safe-refactor-planner.jsonusesix locate "$INPUT" --limit 5, and v0.12.0 has no--limitonlocate. #29 fixes it, so this PR does not.2.
tests/fixtures/regen-no-backend.ts: generated fixturesThis script regenerates every fixture that needs no backend from the real v0.12.0. The job reruns it and
git diff --exit-codestests/fixtures. It also fails on untracked files.unmapped/*(20 files, every graph read'sworkspace_not_mappedrecord in both formats) and the newno-backend/*:--version,statuswith the backend unreachable, andix text(hits,--path/--languagescoped, none). Their manifest entries carry"generatedBy".unmapped/diff only changes the embedded temp dir (/tmp/tmp.aWIz1DclPg→ fixed/tmp/ix-fixtures-v0.12.0/unmapped). Records embed the absolute cwd, so the script runs from fixed paths.success/,empty-repo/andempty-graph/(each needs a backend holding a graph, or answering for a registered workspace).synthetic/is still hand-written. The script header and the fixtures README say so.Notes found on the way (Ix, not plugin bugs)
ix status --format jsonwith the backend unreachable prints nothing on stdout (the error goes to stderr in red), while--format llmprintserror code=cli_error.no-backend/status.jsonis empty on purpose. ix-health handles the empty case.ix --version --format jsonprints plain0.12.0. ix-health already handles this.ix textgives every ripgrep hit the same score and keeps ripgrep's unstable cross-file order. A multi-file result, or a truncated one ("showing the 1 highest-ranked"), is not reproducible run to run. The fixture repo keeps all hits in one file for that reason.No version fields changed.
🤖 Generated with Claude Code
https://claude.ai/code/session_01EqMeW5huGYgRUWS2TtuvF8