mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
The installer used to ask about ten things, half of them after a multi-minute build, and the question that matters most (how do I reach the dashboard) came last. It now looks at what is on the machine, asks at most three questions (access, an optional tailnet name, service), and does the rest unattended. - Every step that needs a human runs before the build: one consent for all missing packages, one sudo prompt kept warm for the run, the AI CLI menu, and the Tailscale install/login/operator/HTTPS-toggle preflight (the toggle is polled and the admin page opened in a browser, instead of "re-check now?"). - The build, the service and `tailscale serve` run behind spinners with their output in ~/.codeman/install.log; the tail is shown on failure and a failed dependency install names its step. - The done screen leads with the URL (tailnet, network, this machine) and a terminal QR code from the qrcode package Codeman already ships. `install.sh status` prints it again. - Tailscale is two halves: tailscale_prepare (question phase) decides the serve SHAPE, tailscale_apply (after the build) issues the one serve command. When :443 already belongs to another app, Codeman goes under a sub-path (serve --set-path /codeman + CODEMAN_BASE_URL in the unit; serve strips the prefix, Codeman's ingress tolerates that, --base-url covers the URLs it emits) or a second port, instead of replace-or-nothing. - Renaming the node to codeman-<hostname> is opt-in and defaults to no everywhere (the tailnet name is the machine's ssh identity); --name and `install.sh name` do it, uninstall offers the old name back. Serve config is keyed by the DNS name, so a rename takes our mapping down first and re-adds it under the new name. - Flags pipe through `bash -s --`: --tailscale|--lan|--local, --name|--no-rename, --service|--run|--no-start, --yes, --password, --port. --port is now also written into the service file. - npm install runs with CODEMAN_NO_AUTOSTART=1: postinstall otherwise builds and starts a detached `codeman web` on 127.0.0.1:3000, which made the service crash-loop on EADDRINUSE while the done screen reported "running" off the orphan (fresh Ubuntu 24 sandbox). - The LAN address comes from the default route, not the first interface. - A foreign /Library/LaunchDaemons/com.codeman.web.plist is left alone instead of being replaced by a LaunchAgent. - The cloudflared question leaves the main flow (`install.sh cloudflared`). - "Continue WITHOUT a password?" defaults to yes (owner decision). Tests: the invariants test pins no `serve reset`, no funnel, no Tailscale Service, every serve mutation through ts_cmd_serve, rename before shape, flag/header parity, the rename default and the NO_AUTOSTART opt-out; the CI bash 3.2 step drives the question phase with stubbed tailscale state. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
211 lines
9.2 KiB
YAML
211 lines
9.2 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [master, main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
ci:
|
|
name: Typecheck & Lint
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version: 22
|
|
cache: 'npm'
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
|
|
- name: Check package-lock.json version sync
|
|
run: npm run check:lockfile
|
|
|
|
- name: Type check
|
|
run: npm run typecheck
|
|
|
|
- name: Lint
|
|
run: npm run lint
|
|
|
|
- name: Frontend JS syntax check
|
|
run: npm run check:frontend-syntax
|
|
|
|
- name: Format check
|
|
run: npm run format:check
|
|
|
|
# install.sh reaches users through `curl | bash` with nothing between it and
|
|
# them, and until now nothing in this repo checked it at all: no shellcheck,
|
|
# no bats, and the vitest gate is Node-only.
|
|
- name: install.sh syntax
|
|
run: bash -n install.sh
|
|
|
|
# macOS ships bash 3.2 and this runner has bash 5, so the constructs that
|
|
# actually break a Mac install are invisible here without a container. This
|
|
# step is what catches them — in particular expanding an EMPTY array under
|
|
# `set -u`, which bash 3.2 treats as an unbound variable and `bash -n`
|
|
# cannot see because it is a runtime error, not a syntax one.
|
|
- name: install.sh runs on bash 3.2 (macOS's version)
|
|
run: |
|
|
set -euo pipefail
|
|
docker run --rm -v "$PWD":/w -w /w bash:3.2 bash -n /w/install.sh
|
|
docker run --rm -v "$PWD":/w -w /w -e CODEMAN_INSTALL_SH_LIB=1 bash:3.2 bash -c '
|
|
set -euo pipefail
|
|
. /w/install.sh
|
|
detect_all_clis
|
|
# `shell` declares no binaries, so its offset/length window is length 0.
|
|
# Iterating it is the empty-array case; reaching here means it did not abort.
|
|
echo "bash $BASH_VERSION: ${#CLI_IDS[@]} CLIs, $CLI_FOUND_COUNT found"
|
|
cli_catalog_names >/dev/null
|
|
cli_catalog_print_install_hints >/dev/null
|
|
# The install menu with nothing installed and the user answering "s":
|
|
# skipping must warn and continue, never trip the "failed to install"
|
|
# gate (it did once, aborting the install before the clone).
|
|
has_tty() { return 0; }
|
|
headless_guard() { return 0; }
|
|
read_reply() { eval "$1=s"; }
|
|
NONINTERACTIVE=0
|
|
k=0; while [[ $k -lt ${#CLI_ALL_BINS[@]} ]]; do CLI_ALL_BINS[$k]="no-such-cli-$k"; k=$((k + 1)); done
|
|
k=0; while [[ $k -lt ${#CLI_ALL_PATHS[@]} ]]; do CLI_ALL_PATHS[$k]="/nonexistent/$k"; k=$((k + 1)); done
|
|
CLI_DETECT_DONE=""; detect_all_clis
|
|
offer_ai_cli_install >/dev/null 2>&1
|
|
echo "bash $BASH_VERSION: skipping the AI CLI install menu continues"
|
|
'
|
|
# Issue #382: the dsh identity probe builds an OPTIONAL `timeout` prefix as an
|
|
# array, and on stock macOS there is no `timeout`, so the array is empty and the
|
|
# expansion aborts the whole installer under `set -u`. The step above cannot
|
|
# reach that branch: this image HAS `timeout`, and with no `dsh` on PATH the
|
|
# probe is never called at all. So hide `timeout` and call it directly.
|
|
docker run --rm -v "$PWD":/w -w /w -e CODEMAN_INSTALL_SH_LIB=1 bash:3.2 bash -c '
|
|
set -euo pipefail
|
|
. /w/install.sh
|
|
printf "#!/bin/sh\necho \"DeepSeek Harness 0.1\"\n" > /tmp/dsh
|
|
printf "#!/bin/sh\necho \"dancer shell (Debian dsh)\"\n" > /tmp/not-dsh
|
|
chmod 755 /tmp/dsh /tmp/not-dsh
|
|
# A PATH the probe can still work on, minus the binary under test.
|
|
mkdir -p /tmp/nobin
|
|
for b in grep sh; do ln -sf "$(command -v $b)" "/tmp/nobin/$b"; done
|
|
export PATH=/tmp/nobin
|
|
if command -v timeout >/dev/null 2>&1; then
|
|
echo "timeout is still on PATH, so this is NOT exercising the empty-array branch" >&2
|
|
exit 1
|
|
fi
|
|
dsh_banner_probe /tmp/dsh
|
|
if dsh_banner_probe /tmp/not-dsh; then
|
|
echo "identity probe accepted a foreign dsh" >&2
|
|
exit 1
|
|
fi
|
|
echo "bash $BASH_VERSION: dsh identity probe survives a missing timeout"
|
|
'
|
|
# Installer v2: the question phase runs before the build, and every decision it
|
|
# takes is bash logic over stubbed tailscale state. Drive the flags, the launch
|
|
# default, the occupied-:443 menu and the rename question with canned answers,
|
|
# so a bash-4 construct or a flipped default in any of them fails here, not on a
|
|
# Mac. The JSON parsers need node (absent in this image) and are stubbed; their
|
|
# own coverage is test/install-sh-invariants.test.ts plus the vitest gate.
|
|
docker run --rm -v "$PWD":/w -w /w -e CODEMAN_INSTALL_SH_LIB=1 -e HOME=/tmp/h bash:3.2 bash -c '
|
|
set -euo pipefail
|
|
mkdir -p /tmp/h
|
|
. /w/install.sh
|
|
parse_flags --tailscale --service --name Build-Box --port 4000
|
|
[[ "$CODEMAN_TAILSCALE" == "1" && "$LAUNCH_PRESET" == "2" && "$TS_NAME" == "Build-Box" && "$CODEMAN_PORT" == "4000" ]]
|
|
[[ "$(ts_sanitize_name "$TS_NAME")" == "build-box" ]]
|
|
has_tty() { return 0; }
|
|
ANSWER=""; read_reply() { eval "$1=\"\$ANSWER\""; }
|
|
systemctl() { return 0; }
|
|
LAUNCH_PRESET=""; NONINTERACTIVE=0
|
|
choose_launch_mode linux >/dev/null 2>&1
|
|
[[ "$LAUNCH_CHOICE" == "2" ]]
|
|
check_tailscale() { return 0; }
|
|
ts_status_field() { case "$1" in "s.BackendState") printf Running ;; "s.Self && s.Self.DNSName") printf "box.tail.ts.net." ;; esac; }
|
|
ts_serve_443_target_port() { printf 8080; }
|
|
ts_serve_find_port_mapping() { :; }
|
|
ts_serve_port_used() { return 1; }
|
|
detect_tailscale_serve_url() { :; }
|
|
tailscale_choose_mapping >/dev/null 2>&1
|
|
[[ "$TS_SERVE_MODE" == "path" && "$BIND_BASE_URL" == "/codeman" ]]
|
|
RENAMED=""; tailscale_rename_node() { RENAMED="$1"; }
|
|
TS_NAME=""; tailscale_choose_name >/dev/null 2>&1
|
|
[[ -z "$RENAMED" ]]
|
|
echo "bash $BASH_VERSION: question phase (flags, launch default, occupied :443, rename opt-in) ok"
|
|
'
|
|
|
|
- name: CLI catalogue artifacts are in sync with stock.ts
|
|
run: npm run generate:cli-catalog -- --check
|
|
|
|
- name: Server boot smoke test
|
|
run: |
|
|
set -u
|
|
if ! command -v tmux >/dev/null; then
|
|
sudo apt-get update -qq
|
|
sudo apt-get install -y tmux
|
|
fi
|
|
npx tsx src/index.ts web --port 3151 > /tmp/boot.log 2>&1 &
|
|
SERVER_PID=$!
|
|
trap "kill $SERVER_PID 2>/dev/null || true" EXIT
|
|
for i in $(seq 1 30); do
|
|
if curl -fsS http://localhost:3151/api/status -o /dev/null; then
|
|
echo "Server booted in ${i}s"
|
|
exit 0
|
|
fi
|
|
if ! kill -0 $SERVER_PID 2>/dev/null; then
|
|
echo "Server exited before becoming ready. Logs:"
|
|
cat /tmp/boot.log
|
|
exit 1
|
|
fi
|
|
sleep 1
|
|
done
|
|
echo "Server did not respond on /api/status within 30s. Logs:"
|
|
cat /tmp/boot.log
|
|
exit 1
|
|
|
|
test:
|
|
name: Unit & integration tests
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version: 22
|
|
cache: 'npm'
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
|
|
- name: Install tmux
|
|
run: |
|
|
if ! command -v tmux >/dev/null; then
|
|
sudo apt-get update -qq
|
|
sudo apt-get install -y tmux
|
|
fi
|
|
|
|
- name: Run unit & integration tests
|
|
# Excludes the suites that need chromium, per-machine PNG baselines or a
|
|
# quiet machine — see config/test-suites.ts for the list and the reason
|
|
# behind each entry. Identical to what `npm test` runs locally.
|
|
# Safe in CI: TmuxManager no-ops all shell commands under VITEST (test/setup.ts).
|
|
run: npm run test:ci
|
|
|
|
- name: Run xterm-zerolag-input package tests
|
|
# Layers 1-3 of the predictive-echo suites (unit laws, fixture replay,
|
|
# seeded fuzz): deterministic, no browser, no live server. Depends on
|
|
# the ROOT `npm ci` above — workspaces hoist the package's vitest into
|
|
# the root node_modules; do not add a separate install here.
|
|
run: npx vitest run
|
|
working-directory: packages/xterm-zerolag-input
|
|
|
|
# Note: three suites are excluded from CI, each with its own local runner:
|
|
# npm run test:browser Playwright + chromium (+ a live server, and a real
|
|
# codex binary for codex-predictive-echo)
|
|
# npm run test:mobile the above plus environment-specific PNG baselines
|
|
# npm run test:perf wall-clock benchmarks; need an otherwise idle machine
|
|
# config/test-suites.ts holds the globs; the configs derive from it so the
|
|
# exclusions here and those runners cannot drift apart. Everything else runs in
|
|
# the `test` job above, which is the same thing `npm test` runs.
|