Repository navigation
fix(ci): pin Bun to the workspace version and untrack a local node_modules symlink - #520
Conversation
…dules symlink Every `Tests / *` job on #517 and #518 was cancelled at the 20-minute budget while still inside `bun ci`, before any test ran. Two things combined: - trios/agent-server/apps/server/node_modules was committed as a symlink to a local macOS path. `.gitignore` said `node_modules/`, which only matches directories, so the symlink slipped through. - setup-bun ran without a version. The `packageManager: bun@1.3.6` pin lives in trios/agent-server/package.json, not at the repo root, so CI got the latest release (1.4.2), which hangs on that dangling symlink. 1.3.x installs past it. Untrack the symlink, make the ignore rule match files too, and read the Bun version from the workspace package.json in test.yml. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
|
Nothing in this PR can fix it: the token secret has to be set, or the CLA workflow disabled for this fork. A re-run would fail the same way. The change this PR targets is working: on this head the Generated by Claude Code |
✅ Tests passed — 2435/2495
|
…example.com With installs no longer hanging, server-tools ran for the first time since 2026-09-23 and failed one test: get_page_content read https://example.com 57 ms after opening it and found no "Example Domain". The test is about extracting text, so it now writes that text into about:blank with evaluate_script, as get_page_links already does. Locally (BrowserOS AppImage, headless, --no-sandbox): the old test fails the same way; the new one passes 3/3. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
… process
server-tools still exited 1 after every test in observation.test.ts
passed: before navigation-newtab-guard.test.ts the helper ran
`lsof -ti :<cdp port>`, which also lists clients still connected to the
port. One of them was the bun test process itself (its CDP socket to the
previous file's browser), so the SIGTERM ended the whole run and no
junit report was written ("workflow > server-tools setup").
Use `lsof -ti tcp:<port> -sTCP:LISTEN` and drop process.pid.
Locally, input.test.ts + navigation-newtab-guard.test.ts in one process:
before, exit 143 right after "Terminating process(es) <own pid>, ...";
after, 18 pass / 0 fail. The whole test:tools group now runs to the end
(242 pass; the 2 local failures load https://example.com, which this
sandbox's browser cannot reach and CI can).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
…example.com With the run no longer killing itself, server-tools finished in CI with 243 pass / 1 fail: `wait_for finds text on page` waited its full 10 s for "Example Domain" on https://example.com and never saw it - the same page get_page_content could not read either. The page now adds that text itself 500 ms after load, so the test still proves wait_for waits, with nothing outside the runner involved. Locally: 2/2 wait_for tests pass on repeat; the whole test:tools group is 243 pass, the one local failure being take_screenshot (a 60 s hang in this sandbox only - it passes in CI). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
… too server-tools on 3d57649 ran clean except one test that had passed on both earlier runs: `search_dom > finds multiple elements with CSS class selector` (123 ms, fewer than 3 matches). It searches once, straight after new_page - the race this file already names and fixes with searchUntil for two sibling tests. Use the same helper here. Locally: search_dom 13/13, three runs in a row. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
…udget `the salvage commit > never splits a rename across the path cap` runs real git over 205 files and salvageWorktree. It takes ~2 s for the whole file locally and passed on the two CI runs before, then hit bun's 5 s default once on a loaded runner (job 110500921083) with nothing in the change touching salvage. A git-heavy fixture test should not share the budget of a pure unit test. Locally: queen-salvage-guards.test.ts 13 pass / 0 fail. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
…de/ci-bun-pin-symlink
#522 mounted /queen/contributor-keys and left the route-guard audit unchanged, so feat/queen-supervisor fails four route-guard tests: 46 mounts against a pin of 45, 23 /queen mounts against 22, and an unguarded mount nobody allowlisted. The route is a server-to-server door for the app render proxy and has its own guard: a bearer equal to QUEEN_CONTRIBUTOR_PROXY_TOKEN (32+ bytes, timingSafeEqual) plus a verified contributor header, and it is off while that token is unset. The trusted-origin check would refuse its only caller, so it is allowlisted with that reason and the pins are re-measured. No other number moved. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
Conflicts, both additive: - server.ts: keep the runner mounts and add /queen/contributor-keys. - queen-leaderboard.ts: rank() takes the operator map merged with contributorOwnerNames(), and the runner owners beside it. Also ports the route-guard fix from #520: #522 left /queen/contributor-keys out of the audit, which turns four route-guard tests red on the base. It is allowlisted with its own capability guard and the pins are re-measured (48 mounts; 25 /queen: 8/8/9). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2
|
One more base breakage fixed here (aa74689). #522 mounted The route has its own guard. Its bearer must equal After merging the base, Generated by Claude Code |
…into feat/queen-tri-earnings Route-guard pins now add both new mounts: 47 total, 24 under /queen (9 public-read, 8 wrapper-guarded, 7 allowlisted). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
29ed593
into
fix/queen-worker-provider-and-prompt-size
Route-guard pins keep this branch's sums: 47 mounts, 24 under /queen. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
What and why
Every
Tests / *job on #517 and #518 is cancelled at the 20-minutetimeout-minuteswhile it is still runningInstall dependencies(bun ci). No test ever runs (#518 server-api log).Two problems combine to cause this:
trios/agent-server/apps/server/node_modulespoints to/Users/playom/queen-patches/work/browseros-deploy/.... It was last touched in ce13b7e (feat(queen): a lane can be signed with a GitHub login #511). The.gitignorerulenode_modules/matches directories only, so a symlink, which is a file, was not ignored.oven-sh/setup-bun@v2runs without a version. ThepackageManager: bun@1.3.6pin is intrios/agent-server/package.json, not at the repo root, so CI installs the latest release, 1.4.2, which hangs on that dangling symlink.Once installs worked, the suites ran for the first time since 2026-09-23 and surfaced latent test problems. Commits 2–6 fix each one, so the whole matrix is green.
Change
git rm --cached). Nobody's checkout loses anything..gitignorefromnode_modules/tonode_modules, so a symlink can't be committed again.test.yml, setsetup-buntobun-version-file: trios/agent-server/package.json, which resolves to 1.3.6.get_page_contenthttps://example.com57 ms after opening it and found no text.about:blank, the same way the neighbouringget_page_linkstest does.killProcessOnPortlsof -ti :<port>, which also lists clients connected to the port. One of those clients was the bun test process itself, so it sent SIGTERM to its own run (exit 143, no junit report).-sTCP:LISTEN) and neverprocess.pid.wait_for finds text on pageexample.comand never saw it.data:page that adds the text 500 ms after load, so it still exercises the waiting.search_domclass-selector testnew_page. That is the load racedom.test.tsalready documents.searchUntilhelper, like its two sibling tests.Verification
bun ciwas run on agit archiveexport oftrios/agent-server:6bf7efe(symlink tracked)timeout 1206bf7efeCI: #518 carries all six commits. On its head
bf15d74all 14 suites pass, 2436/2496 with the rest skipped:server-tools244/244server-api1315server-pglive3/3server-integration10/11Local runs used the BrowserOS AppImage, headless, with
--no-sandbox --disable-dev-shm-usageas in CI:get_page_contentfails before commit 2 and passes 3/3 after it.input+navigation-newtab-guardexit 143 before commit 3 and pass 18/18 after it.wait_forpasses 2/2, repeated.search_dompasses 13/13, three runs in a row.queen-salvage-guardspasses 13/13.biome checkis clean on every changed file.The workflows
audit,code-quality,trios-logicandrelease-agent-extensionalso callsetup-bunwithout a version, and this PR leaves them unchanged. Removing the symlink is what unblocks them; pinning them is a separate decision.Unblocks #518 and any other PR into
feat/queen-supervisor. All six commits are also carried in #518, so they no-op there once this merges.🤖 Generated with Claude Code
https://claude.ai/code/session_01SJ8KjRoGNBoHBoDR92fAo2