Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,24 @@ jobs:
go-version-file: go.mod
target: test-static-smoke

pi-runtime: # installed Pi RPC runtime gate — not a required check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22.22.3 # Pi 1.0 requires Node >= 22.19.0
# The Makefile owns the Pi version; test-pi-runtime fails if it differs.
# Read it first so a failed lookup stops the step instead of installing
# an unpinned (latest) Pi.
- run: |
pi_version="$(make -s pi-runtime-version)"
npm install -g --ignore-scripts "@earendil-works/pi-coding-agent@${pi_version}"
- uses: open-cli-collective/.github/actions/go-test@b6382514b809d960c6fbdc85745a60c14cde04f1 # shared .github
with:
go-version-file: go.mod
target: test-pi-runtime

lint:
runs-on: ubuntu-latest
steps:
Expand Down
21 changes: 20 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
.PHONY: all build test test-cover test-static-smoke lint fmt tidy deps check install snapshot package-render-check release clean
.PHONY: all build test test-cover test-static-smoke test-pi-runtime pi-runtime-version check-pi-runtime-version lint fmt tidy deps check install snapshot package-render-check release clean

# Standard keyring tags: enable 1Password support, keep passage disabled.
GOFLAGS ?= -tags=keyring_nopassage
Expand All @@ -18,6 +18,25 @@ test-cover:
test-static-smoke:
go test -v ./internal/... ./cmd/... -count=1

# Exact Pi version the installed-runtime gate requires. CI installs this
# version; test-pi-runtime fails, rather than skips, when `pi --version` on PATH
# reports anything else or Pi is missing.
PI_RUNTIME_VERSION ?= 1.0.0

# A blank pin would make the runtime tests skip and let npm install the latest
# Pi, so both targets below require exactly one version.
check-pi-runtime-version:
@if [ "$(words $(PI_RUNTIME_VERSION))" != 1 ]; then \
echo "PI_RUNTIME_VERSION must be exactly one Pi version" >&2; \
exit 1; \
fi

test-pi-runtime: check-pi-runtime-version
CR_PI_RUNTIME_VERSION=$(strip $(PI_RUNTIME_VERSION)) go test -v -race -count=1 -run 'TestPiRPCRuntime|TestPiRPCReviewerExtensionLoadsInInstalledPi' ./internal/llmadapters

pi-runtime-version: check-pi-runtime-version
@echo $(strip $(PI_RUNTIME_VERSION))

lint:
golangci-lint run

Expand Down
40 changes: 40 additions & 0 deletions docs/development.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,10 +95,50 @@ make tidy # go mod tidy and verify go.mod is unchanged
make deps # download and verify Go modules
make check # tidy + fmt + lint + test + build
make clean # remove build artifacts
make test-pi-runtime # installed Pi runtime gate (see Pi Runtime Gate)
```

`make snapshot` runs a local GoReleaser snapshot build without publishing.

## Pi Runtime Gate

`make test-pi-runtime` runs the `pi_rpc` adapter against the installed Pi on
`PATH` instead of the fake Pi the ordinary adapter tests use. It sets
`CR_PI_RUNTIME_VERSION` to the Makefile's `PI_RUNTIME_VERSION` (currently
`1.0.0`, printed by `make -s pi-runtime-version`). Both targets fail when
`PI_RUNTIME_VERSION` is blank or holds more than one version. When
`CR_PI_RUNTIME_VERSION` is set, the runtime tests fail if it is blank, if Pi is
missing, or if `pi --version` reports any other version. When it is unset, as in
`make test`, they skip. To install the pinned runtime:

```bash
pi_version="$(make -s pi-runtime-version)"
npm install -g --ignore-scripts "@earendil-works/pi-coding-agent@${pi_version}"
make test-pi-runtime
```

The tests make no paid or external calls:

- Each test gives Pi a fresh `PI_CODING_AGENT_DIR` and `HOME` with
`PI_OFFLINE=1`.
- The only model is a scripted OpenAI-compatible endpoint on loopback, with a
dummy key.
- Reviewer tool calls run the real `__pi-review-tool` helper, dispatched to the
test binary by `TestMain`.
- Hostile instructions, extensions, MCP servers, and skills are planted under
the fixture `HOME`'s default `.pi/agent` location and in the reviewer
checkout, while Pi reads the fresh agent directory. The tests fail if any of
them reaches a provider request or runs.

This shows that the fixture is isolated, not that production runs are. CR does
not replace the developer's own Pi agent directory, so its global instructions
can still reach prompts
([#642](https://github.com/open-cli-collective/codereview-cli/issues/642)).

The CI `pi-runtime` job installs the Makefile version on the Node release it
pins and runs the same target. It is not a required check. To move to a new Pi
release, change `PI_RUNTIME_VERSION` and run the target locally first.

## Repo-Local Shape

- Module: `github.com/open-cli-collective/codereview-cli`
Expand Down
Loading
Loading