name: CI on: push: branches: [master, main] pull_request: jobs: ci: name: Typecheck & Lint runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - name: Setup Node.js uses: actions/setup-node@v6 with: node-version: 22 cache: 'npm' - name: Install dependencies run: npm ci - name: Check package-lock.json version sync run: npm run check:lockfile - name: Type check run: npm run typecheck - name: Lint run: npm run lint - name: Frontend JS syntax check run: npm run check:frontend-syntax - name: Format check run: npm run format:check # install.sh reaches users through `curl | bash` with nothing between it and # them, and until now nothing in this repo checked it at all: no shellcheck, # no bats, and the vitest gate is Node-only. - name: install.sh syntax run: bash -n install.sh # macOS ships bash 3.2 and this runner has bash 5, so the constructs that # actually break a Mac install are invisible here without a container. This # step is what catches them — in particular expanding an EMPTY array under # `set -u`, which bash 3.2 treats as an unbound variable and `bash -n` # cannot see because it is a runtime error, not a syntax one. - name: install.sh runs on bash 3.2 (macOS's version) run: | set -euo pipefail docker run --rm -v "$PWD":/w -w /w bash:3.2 bash -n /w/install.sh docker run --rm -v "$PWD":/w -w /w -e CODEMAN_INSTALL_SH_LIB=1 bash:3.2 bash -c ' set -euo pipefail . /w/install.sh detect_all_clis # `shell` declares no binaries, so its offset/length window is length 0. # Iterating it is the empty-array case; reaching here means it did not abort. echo "bash $BASH_VERSION: ${#CLI_IDS[@]} CLIs, $CLI_FOUND_COUNT found" cli_catalog_names >/dev/null cli_catalog_print_install_hints >/dev/null # The install menu with nothing installed and the user answering "s": # skipping must warn and continue, never trip the "failed to install" # gate (it did once, aborting the install before the clone). has_tty() { return 0; } headless_guard() { return 0; } read_reply() { eval "$1=s"; } NONINTERACTIVE=0 k=0; while [[ $k -lt ${#CLI_ALL_BINS[@]} ]]; do CLI_ALL_BINS[$k]="no-such-cli-$k"; k=$((k + 1)); done k=0; while [[ $k -lt ${#CLI_ALL_PATHS[@]} ]]; do CLI_ALL_PATHS[$k]="/nonexistent/$k"; k=$((k + 1)); done CLI_DETECT_DONE=""; detect_all_clis offer_ai_cli_install >/dev/null 2>&1 echo "bash $BASH_VERSION: skipping the AI CLI install menu continues" ' # Issue #382: the dsh identity probe builds an OPTIONAL `timeout` prefix as an # array, and on stock macOS there is no `timeout`, so the array is empty and the # expansion aborts the whole installer under `set -u`. The step above cannot # reach that branch: this image HAS `timeout`, and with no `dsh` on PATH the # probe is never called at all. So hide `timeout` and call it directly. docker run --rm -v "$PWD":/w -w /w -e CODEMAN_INSTALL_SH_LIB=1 bash:3.2 bash -c ' set -euo pipefail . /w/install.sh printf "#!/bin/sh\necho \"DeepSeek Harness 0.1\"\n" > /tmp/dsh printf "#!/bin/sh\necho \"dancer shell (Debian dsh)\"\n" > /tmp/not-dsh chmod 755 /tmp/dsh /tmp/not-dsh # A PATH the probe can still work on, minus the binary under test. mkdir -p /tmp/nobin for b in grep sh; do ln -sf "$(command -v $b)" "/tmp/nobin/$b"; done export PATH=/tmp/nobin if command -v timeout >/dev/null 2>&1; then echo "timeout is still on PATH, so this is NOT exercising the empty-array branch" >&2 exit 1 fi dsh_banner_probe /tmp/dsh if dsh_banner_probe /tmp/not-dsh; then echo "identity probe accepted a foreign dsh" >&2 exit 1 fi echo "bash $BASH_VERSION: dsh identity probe survives a missing timeout" ' # Installer v2: the question phase runs before the build, and every decision it # takes is bash logic over stubbed tailscale state. Drive the flags, the launch # default, the occupied-:443 menu and the rename question with canned answers, # so a bash-4 construct or a flipped default in any of them fails here, not on a # Mac. The JSON parsers need node (absent in this image) and are stubbed; their # own coverage is test/install-sh-invariants.test.ts plus the vitest gate. docker run --rm -v "$PWD":/w -w /w -e CODEMAN_INSTALL_SH_LIB=1 -e HOME=/tmp/h bash:3.2 bash -c ' set -euo pipefail mkdir -p /tmp/h . /w/install.sh parse_flags --tailscale --service --name Build-Box --port 4000 [[ "$CODEMAN_TAILSCALE" == "1" && "$LAUNCH_PRESET" == "2" && "$TS_NAME" == "Build-Box" && "$CODEMAN_PORT" == "4000" ]] [[ "$(ts_sanitize_name "$TS_NAME")" == "build-box" ]] has_tty() { return 0; } ANSWER=""; read_reply() { eval "$1=\"\$ANSWER\""; } systemctl() { return 0; } LAUNCH_PRESET=""; NONINTERACTIVE=0 choose_launch_mode linux >/dev/null 2>&1 [[ "$LAUNCH_CHOICE" == "2" ]] check_tailscale() { return 0; } ts_status_field() { case "$1" in "s.BackendState") printf Running ;; "s.Self && s.Self.DNSName") printf "box.tail.ts.net." ;; esac; } ts_backend_state() { printf Running; } ts_dns_name() { printf box.tail.ts.net; } ts_serve_443_target_port() { printf 8080; } ts_serve_find_port_mapping() { :; } ts_serve_port_used() { return 1; } detect_tailscale_serve_url() { :; } tailscale_choose_mapping >/dev/null 2>&1 [[ "$TS_SERVE_MODE" == "path" && "$BIND_BASE_URL" == "/codeman" ]] RENAMED=""; tailscale_rename_node() { RENAMED="$1"; } TS_NAME=""; tailscale_choose_name >/dev/null 2>&1 [[ -z "$RENAMED" ]] # A flag re-run keeps the password the unit already carries (and so # never writes the unauthenticated ack), and the hand-start line the # done screen prints carries every non-default value. read_existing_binding() { EXISTING_FOUND=1; EXISTING_HOST=0.0.0.0; EXISTING_PASSWORD=s3cret; EXISTING_ACK=0; EXISTING_BASE_URL=""; } CODEMAN_HOST=0.0.0.0; CODEMAN_TAILSCALE=0; unset CODEMAN_PASSWORD; BIND_ACK=0 choose_network_binding >/dev/null 2>&1 [[ "$BIND_PASSWORD" == "s3cret" && "$BIND_ACK" == "0" ]] BIND_HOST=0.0.0.0; BIND_PASSWORD=x; BIND_ACK=0; BIND_BASE_URL=/codeman; CODEMAN_PORT=4000 [[ "$(start_command_hint)" == "CODEMAN_HOST=0.0.0.0 CODEMAN_PASSWORD="*" CODEMAN_BASE_URL=/codeman CODEMAN_PORT=4000 codeman web" ]] RECONFIGURE=0; parse_flags --port 4001; [[ "$RECONFIGURE" == "1" ]] echo "bash $BASH_VERSION: question phase (flags, launch default, occupied :443, rename opt-in, kept password, start line) ok" ' - name: CLI catalogue artifacts are in sync with stock.ts run: npm run generate:cli-catalog -- --check - name: Server boot smoke test run: | set -u if ! command -v tmux >/dev/null; then sudo apt-get update -qq sudo apt-get install -y tmux fi npx tsx src/index.ts web --port 3151 > /tmp/boot.log 2>&1 & SERVER_PID=$! trap "kill $SERVER_PID 2>/dev/null || true" EXIT for i in $(seq 1 30); do if curl -fsS http://localhost:3151/api/status -o /dev/null; then echo "Server booted in ${i}s" exit 0 fi if ! kill -0 $SERVER_PID 2>/dev/null; then echo "Server exited before becoming ready. Logs:" cat /tmp/boot.log exit 1 fi sleep 1 done echo "Server did not respond on /api/status within 30s. Logs:" cat /tmp/boot.log exit 1 test: name: Unit & integration tests runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - name: Setup Node.js uses: actions/setup-node@v6 with: node-version: 22 cache: 'npm' - name: Install dependencies run: npm ci - name: Install tmux run: | if ! command -v tmux >/dev/null; then sudo apt-get update -qq sudo apt-get install -y tmux fi - name: Run unit & integration tests # Excludes the suites that need chromium, per-machine PNG baselines or a # quiet machine — see config/test-suites.ts for the list and the reason # behind each entry. Identical to what `npm test` runs locally. # Safe in CI: TmuxManager no-ops all shell commands under VITEST (test/setup.ts). run: npm run test:ci - name: Run xterm-zerolag-input package tests # Layers 1-3 of the predictive-echo suites (unit laws, fixture replay, # seeded fuzz): deterministic, no browser, no live server. Depends on # the ROOT `npm ci` above — workspaces hoist the package's vitest into # the root node_modules; do not add a separate install here. run: npx vitest run working-directory: packages/xterm-zerolag-input # Note: three suites are excluded from CI, each with its own local runner: # npm run test:browser Playwright + chromium (+ a live server, and a real # codex binary for codex-predictive-echo) # npm run test:mobile the above plus environment-specific PNG baselines # npm run test:perf wall-clock benchmarks; need an otherwise idle machine # config/test-suites.ts holds the globs; the configs derive from it so the # exclusions here and those runners cannot drift apart. Everything else runs in # the `test` job above, which is the same thing `npm test` runs.