Skip to content

ci: run the tools against a released ix and generate no-backend fixtures - #30

Merged
KageBinary merged 3 commits into
mainfrom
ci/real-ix-job
Oct 4, 2026
Merged

KageBinary merged 3 commits into
mainfrom
ci/real-ix-job

Conversation

@KageBinary

Copy link
Copy Markdown
Collaborator

Task PL-03 of the Ix audit remediation plan.

What this adds

A real-ix job in ci.yml (and CI Passed now needs it). It installs the released ix v0.12.0 tarball (sha256sum -c against the release's .sha256, Node 22, ripgrep from apt) and runs with no backend: IX_ENDPOINT=http://127.0.0.1:1, an empty IX_HOME, IX_NO_UPDATE_CHECK=1. Actions are pinned by SHA, contents: read, persist-credentials: false. zizmor reports nothing.

1. tests/real-ix.test.ts (skipped unless IX_REAL_TESTS=1)

Every tool (17, plus extra ix-neighbors directions) runs in a child Bun with a transparent ix shim first on PATH that logs argv and stderr, then hands off to the real CLI. Assertions:

  • every tool returns a non-empty markdown string and does not throw;
  • ix accepts every argv the tools build: no unknown option/unknown command/arity error on stderr, and the argv log shows each command was actually reached. I checked this by hand: adding --bogus-flag to ix-locate's argv turns it red. So pinning a CLI that lacks a flag a tool uses fails the job;
  • graph reads (query, neighbors, impact, map, ingest, docs, explain, rank, stats, subsystems, inventory, trace, smells) report ix's real workspace_not_mapped record, never "ix unavailable", "No matches found" or "No smells detected";
  • ix-decide does not ALLOW on a project Ix cannot read;
  • ix-health shows the real ix --version, DEGRADED, and the error code;
  • ix-locate returns the real ix text hit from a temp file.

The argv check covers code argv only. Agent and command prompts are not checked. A one-off local scan of agents/*.json against ix <cmd> --help found one problem, the known one: agents/ix-safe-refactor-planner.json uses ix locate "$INPUT" --limit 5, and v0.12.0 has no --limit on locate. #29 fixes it, so this PR does not.

2. tests/fixtures/regen-no-backend.ts: generated fixtures

This script regenerates every fixture that needs no backend from the real v0.12.0. The job reruns it and git diff --exit-codes tests/fixtures. It also fails on untracked files.

  • Now generated: unmapped/* (20 files, every graph read's workspace_not_mapped record in both formats) and the new no-backend/*: --version, status with the backend unreachable, and ix text (hits, --path/--language scoped, none). Their manifest entries carry "generatedBy".
  • The unmapped/ diff only changes the embedded temp dir (/tmp/tmp.aWIz1DclPg → fixed /tmp/ix-fixtures-v0.12.0/unmapped). Records embed the absolute cwd, so the script runs from fixed paths.
  • Still hand-captured: success/, empty-repo/ and empty-graph/ (each needs a backend holding a graph, or answering for a registered workspace). synthetic/ is still hand-written. The script header and the fixtures README say so.

Notes found on the way (Ix, not plugin bugs)

  • ix status --format json with the backend unreachable prints nothing on stdout (the error goes to stderr in red), while --format llm prints error code=cli_error. no-backend/status.json is empty on purpose. ix-health handles the empty case.
  • ix --version --format json prints plain 0.12.0. ix-health already handles this.
  • ix text gives every ripgrep hit the same score and keeps ripgrep's unstable cross-file order. A multi-file result, or a truncated one ("showing the 1 highest-ranked"), is not reproducible run to run. The fixture repo keeps all hits in one file for that reason.

No version fields changed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EqMeW5huGYgRUWS2TtuvF8

KageBinary and others added 3 commits October 4, 2026 12:11
Add a `real-ix` CI job that installs the checksummed ix v0.12.0 release
tarball (no fake) and, with no backend (IX_ENDPOINT on port 1, empty
IX_HOME):

- runs every tool through tests/real-ix.test.ts (skipped unless
  IX_REAL_TESTS=1), behind a transparent shim that logs argv and stderr.
  It fails if ix rejects any argv a tool builds (unknown option/command),
  if a graph read does not surface ix's real workspace_not_mapped record,
  if ix-decide ALLOWs, if ix-health misreads the version, or if ix-locate
  loses the real `ix text` hit;
- regenerates the fixtures that need no backend with
  tests/fixtures/regen-no-backend.ts (unmapped/ and a new no-backend/:
  --version, status with the backend down, ix text) and fails on any
  git diff.

Fixtures that need a populated graph (success/, empty-repo/,
empty-graph/, synthetic/) stay hand-captured. The unmapped/ records
change only in the embedded temp directory, now a fixed path.

`CI Passed` now also needs `real-ix`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EqMeW5huGYgRUWS2TtuvF8
The release's .sha256 sidecar only proves the download matches whatever
the release holds now. The job also checks a sha256 pinned in the workflow,
so a replaced asset fails it. ix-trace with a target adds --to to the argv
the real CLI must accept.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@KageBinary KageBinary left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed. The release is pinned, actions are pinned by SHA, the job needs no secrets, and zizmor is clean. A bogus flag turns the job red.

Fixed in 4a18489 (after merging main, d294a2f):

  • The only checksum came from the same release, so a swapped asset plus checksum would pass. The workflow now also pins the tarball's sha256.
  • Tools stop at their first error, so optional flags were never sent. Added an ix-trace call with to; a bogus --to now fails the job.

Still unchecked: map --silent and the Pro commands. Merging after #29.

@KageBinary
KageBinary marked this pull request as ready for review October 4, 2026 20:23
@KageBinary
KageBinary merged commit 0e41a8f into main Oct 4, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant