Skip to content

fix(ci): pin Bun to the workspace version and untrack a local node_modules symlink - #520

Merged
gHashTag merged 8 commits into
fix/queen-worker-provider-and-prompt-sizefrom
claude/ci-bun-pin-symlink
Oct 2, 2026
Merged

gHashTag merged 8 commits into
fix/queen-worker-provider-and-prompt-sizefrom
claude/ci-bun-pin-symlink

Conversation

@dmitrii-f-t27

@dmitrii-f-t27 dmitrii-f-t27 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

What and why

Every Tests / * job on #517 and #518 is cancelled at the 20-minute timeout-minutes while it is still running Install dependencies (bun ci). No test ever runs (#518 server-api log).

Two problems combine to cause this:

  1. A local symlink was committed. trios/agent-server/apps/server/node_modules points to /Users/playom/queen-patches/work/browseros-deploy/.... It was last touched in ce13b7e (feat(queen): a lane can be signed with a GitHub login #511). The .gitignore rule node_modules/ matches directories only, so a symlink, which is a file, was not ignored.
  2. CI gets the latest Bun instead of the pinned one. oven-sh/setup-bun@v2 runs without a version. The packageManager: bun@1.3.6 pin is in trios/agent-server/package.json, not at the repo root, so CI installs the latest release, 1.4.2, which hangs on that dangling symlink.

Once installs worked, the suites ran for the first time since 2026-09-23 and surfaced latent test problems. Commits 2–6 fix each one, so the whole matrix is green.

Change

  1. b3f92ee — CI install
    • Untrack the symlink (git rm --cached). Nobody's checkout loses anything.
    • Change .gitignore from node_modules/ to node_modules, so a symlink can't be committed again.
    • In test.yml, set setup-bun to bun-version-file: trios/agent-server/package.json, which resolves to 1.3.6.
  2. 583d8ea — get_page_content
    • The test read the live https://example.com 57 ms after opening it and found no text.
    • It now writes the text into about:blank, the same way the neighbouring get_page_links test does.
  3. 26938a6 — killProcessOnPort
    • It used lsof -ti :<port>, which also lists clients connected to the port. One of those clients was the bun test process itself, so it sent SIGTERM to its own run (exit 143, no junit report).
    • It now kills only listeners (-sTCP:LISTEN) and never process.pid.
  4. 3d57649 — wait_for finds text on page
    • The test waited 10 s for "Example Domain" on the live example.com and never saw it.
    • It now opens a data: page that adds the text 500 ms after load, so it still exercises the waiting.
  5. 8321349 — search_dom class-selector test
    • It searched once, straight after new_page. That is the load race dom.test.ts already documents.
    • It now uses the file's own searchUntil helper, like its two sibling tests.
  6. 350d559 — salvage rename test
    • This test runs real git over 205 files. It hit bun's 5 s default once on a loaded runner, while passing on the runs before and after.
    • It now has an explicit 30 s budget.

Verification

bun ci was run on a git archive export of trios/agent-server:

Tree Bun Result
base 6bf7efe (symlink tracked) 1.4.2 hangs, killed by timeout 120
base 6bf7efe 1.3.14 installs
b3f92ee 1.3.6 (the pin) 4654 packages, 12.63 s
b3f92ee 1.4.2 2325 packages, 2.23 s

CI: #518 carries all six commits. On its head bf15d74 all 14 suites pass, 2436/2496 with the rest skipped:

  • server-tools 244/244
  • server-api 1315
  • server-pglive 3/3
  • server-integration 10/11

Local runs used the BrowserOS AppImage, headless, with --no-sandbox --disable-dev-shm-usage as in CI:

  • get_page_content fails before commit 2 and passes 3/3 after it.
  • input + navigation-newtab-guard exit 143 before commit 3 and pass 18/18 after it.
  • wait_for passes 2/2, repeated.
  • search_dom passes 13/13, three runs in a row.
  • queen-salvage-guards passes 13/13.

biome check is clean on every changed file.

The workflows audit, code-quality, trios-logic and release-agent-extension also call setup-bun without a version, and this PR leaves them unchanged. Removing the symlink is what unblocks them; pinning them is a separate decision.

Unblocks #518 and any other PR into feat/queen-supervisor. All six commits are also carried in #518, so they no-op there once this merges.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2

…dules symlink

Every `Tests / *` job on #517 and #518 was cancelled at the 20-minute
budget while still inside `bun ci`, before any test ran.

Two things combined:
- trios/agent-server/apps/server/node_modules was committed as a symlink
  to a local macOS path. `.gitignore` said `node_modules/`, which only
  matches directories, so the symlink slipped through.
- setup-bun ran without a version. The `packageManager: bun@1.3.6` pin
  lives in trios/agent-server/package.json, not at the repo root, so CI
  got the latest release (1.4.2), which hangs on that dangling symlink.
  1.3.x installs past it.

Untrack the symlink, make the ignore rule match files too, and read the
Bun version from the workspace package.json in test.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
@github-actions github-actions Bot added the fix label Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

cla is red for a reason unrelated to this PR. The CLA action stops before it checks any signature: Please add a personal access token … for writing signatures in a remote repository, because PERSONAL_ACCESS_TOKEN is empty in this repository (log). It failed the same way on #517, which was merged, and on #518.

Nothing in this PR can fix it: the token secret has to be set, or the CLA workflow disabled for this fork. A re-run would fail the same way.

The change this PR targets is working: on this head the Tests / * suites install and run instead of hanging in bun ci. shared, server-agent, server-lib, server-skills, server-pglive and eval finished green within about a minute.


Generated by Claude Code

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Tests passed — 2435/2495

Suite Passed Failed Skipped
✅ agent 87/87 0 0
✅ build 9/9 0 0
✅ cdp-protocol 5/5 0 0
✅ eval 93/93 0 0
✅ server-agent 272/272 0 0
✅ server-api 1305/1364 0 59
✅ server-browser 6/6 0 0
✅ server-integration 10/11 0 1
✅ server-lib 279/279 0 0
✅ server-pglive 12/12 0 0
✅ server-root 68/68 0 0
✅ server-skills 31/31 0 0
✅ server-tools 244/244 0 0
✅ shared 14/14 0 0

View workflow run

claude added 7 commits October 1, 2026 17:04
…example.com

With installs no longer hanging, server-tools ran for the first time
since 2026-09-23 and failed one test: get_page_content read
https://example.com 57 ms after opening it and found no "Example
Domain". The test is about extracting text, so it now writes that text
into about:blank with evaluate_script, as get_page_links already does.

Locally (BrowserOS AppImage, headless, --no-sandbox): the old test
fails the same way; the new one passes 3/3.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
… process

server-tools still exited 1 after every test in observation.test.ts
passed: before navigation-newtab-guard.test.ts the helper ran
`lsof -ti :<cdp port>`, which also lists clients still connected to the
port. One of them was the bun test process itself (its CDP socket to the
previous file's browser), so the SIGTERM ended the whole run and no
junit report was written ("workflow > server-tools setup").

Use `lsof -ti tcp:<port> -sTCP:LISTEN` and drop process.pid.

Locally, input.test.ts + navigation-newtab-guard.test.ts in one process:
before, exit 143 right after "Terminating process(es) <own pid>, ...";
after, 18 pass / 0 fail. The whole test:tools group now runs to the end
(242 pass; the 2 local failures load https://example.com, which this
sandbox's browser cannot reach and CI can).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
…example.com

With the run no longer killing itself, server-tools finished in CI with
243 pass / 1 fail: `wait_for finds text on page` waited its full 10 s
for "Example Domain" on https://example.com and never saw it - the same
page get_page_content could not read either.

The page now adds that text itself 500 ms after load, so the test still
proves wait_for waits, with nothing outside the runner involved.

Locally: 2/2 wait_for tests pass on repeat; the whole test:tools group
is 243 pass, the one local failure being take_screenshot (a 60 s hang
in this sandbox only - it passes in CI).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
… too

server-tools on 3d57649 ran clean except one test that had passed on
both earlier runs: `search_dom > finds multiple elements with CSS class
selector` (123 ms, fewer than 3 matches). It searches once, straight
after new_page - the race this file already names and fixes with
searchUntil for two sibling tests. Use the same helper here.

Locally: search_dom 13/13, three runs in a row.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
…udget

`the salvage commit > never splits a rename across the path cap` runs
real git over 205 files and salvageWorktree. It takes ~2 s for the whole
file locally and passed on the two CI runs before, then hit bun's 5 s
default once on a loaded runner (job 110500921083) with nothing in the
change touching salvage. A git-heavy fixture test should not share the
budget of a pure unit test.

Locally: queen-salvage-guards.test.ts 13 pass / 0 fail.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
#522 mounted /queen/contributor-keys and left the route-guard audit
unchanged, so feat/queen-supervisor fails four route-guard tests: 46
mounts against a pin of 45, 23 /queen mounts against 22, and an
unguarded mount nobody allowlisted.

The route is a server-to-server door for the app render proxy and has
its own guard: a bearer equal to QUEEN_CONTRIBUTOR_PROXY_TOKEN (32+
bytes, timingSafeEqual) plus a verified contributor header, and it is
off while that token is unset. The trusted-origin check would refuse
its only caller, so it is allowlisted with that reason and the pins are
re-measured. No other number moved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
dmitrii-f-t27 pushed a commit that referenced this pull request Oct 2, 2026
Conflicts, both additive:
- server.ts: keep the runner mounts and add /queen/contributor-keys.
- queen-leaderboard.ts: rank() takes the operator map merged with
  contributorOwnerNames(), and the runner owners beside it.

Also ports the route-guard fix from #520: #522 left
/queen/contributor-keys out of the audit, which turns four route-guard
tests red on the base. It is allowlisted with its own capability guard
and the pins are re-measured (48 mounts; 25 /queen: 8/8/9).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2

Copy link
Copy Markdown
Collaborator Author

One more base breakage fixed here (aa74689). #522 mounted /queen/contributor-keys but didn't add it to trios/tools/route-guard-audit.mjs. As a result, feat/queen-supervisor now fails four route-guard.test.ts cases: 46 mounts against a pin of 45, 23 /queen mounts against 22, and an unguarded mount with no allowlist entry. I reproduced the failures on the base head (e36fab3).

The route has its own guard. Its bearer must equal QUEEN_CONTRIBUTOR_PROXY_TOKEN (at least 32 bytes, compared with timingSafeEqual), the request needs a verified x-queen-contributor-id, and the route is off while the token is unset. Its only caller is the render proxy, which sends no browser Origin, so the trusted-origin check would refuse it. I allowlisted it with that reason and re-measured the pins. No other count changed.

After merging the base, test:api passes locally: 1305 tests, 0 failed. The same fix is ported into #518 and #521.


Generated by Claude Code

@gHashTag
gHashTag changed the base branch from feat/queen-supervisor to fix/queen-worker-provider-and-prompt-size October 2, 2026 07:45
gHashTag added a commit that referenced this pull request Oct 2, 2026
…into feat/queen-tri-earnings

Route-guard pins now add both new mounts: 47 total, 24 under /queen
(9 public-read, 8 wrapper-guarded, 7 allowlisted).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag
gHashTag merged commit 29ed593 into fix/queen-worker-provider-and-prompt-size Oct 2, 2026
16 of 17 checks passed
@gHashTag
gHashTag deleted the claude/ci-bun-pin-symlink branch October 2, 2026 08:04
gHashTag added a commit that referenced this pull request Oct 2, 2026
Route-guard pins keep this branch's sums: 47 mounts, 24 under /queen.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants