mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 13:53:15 +00:00
Part of the domain-reorg adoption (build plan step C3): fork content,
upstream layout. Adds agent/graphs/{agent,analyzer,chat,reviewer,
scheduler}.py as thin re-export shims delegating to the existing fork
graph factories (agent.server/analyzer/chat/reviewer/scheduler), plus
agent/providers/__init__.py re-exporting agent.utils.model's
make_model/provider_model_kwargs/fallback_model_id_for surface —
verbatim upstream content, verified each import resolves against fork
modules with no name changes needed.
agent/runtime/{constants,execution}.py deviate from upstream's
verbatim shim bodies: rather than duplicating DEFAULT_LLM_MODEL_ID/
DEFAULT_LLM_MAX_TOKENS/DEFAULT_RECURSION_LIMIT/MODEL_CALL_RECURSION_LIMIT
and graph_loaded_for_execution's logic (upstream's shims assume
agent/server.py already had these extracted into runtime/ modules,
which is out of this commit's scope — server.py is untouched), they
import the fork's existing agent.server attributes directly. This
keeps the values/logic single-sourced instead of forking a second
copy that could drift.
agent/runtime/sandbox.py's delegation targets also differ from
upstream: fork's sandbox lifecycle helpers are private
(_get_cached_sandbox_backend, _configure_git_identity,
_recreate_sandbox in agent/server.py) since the fork's sync
4-case `__creating__` sentinel design (AGENTS.md) never made them
public. get_cached_sandbox_backend() also drops upstream's
caller-supplied `reconnect` callback parameter — fork's
_get_cached_sandbox_backend is a plain cache lookup; reconnection is
handled internally by ensure_sandbox_for_thread/
check_or_recreate_sandbox, not via a passed-in callback. No other
signature changes.
Added fork-only agent/graphs/ci_monitor.py (delegates to
agent.ci_monitor:get_ci_monitor) for symmetry, since upstream deleted
its ci-autofix cluster and has no equivalent shim. langgraph.json's
five stock graph entrypoints plus the fork-only ci_monitor now all
point at agent.graphs.<name>; http.app stays agent.webapp:app
(unchanged, per plan).
Deliberately NOT included (owned by build plan step C4, the FastAPI
split, gated on /sh-security-review): agent/api/{__init__,app,
health}.py, agent/webhooks/common.py, and the three
agent/webhooks/{github,linear,slack}_routes.py files. Those aren't
thin structural shims like the 21-file list implies in isolation —
they carry the fork's actual webhook dispatch/verify logic split out
of the still-monolithic webapp.py, which hasn't happened yet.
Building them now against upstream's placeholder content would ship
incomplete auth surface that C4 would just discard and redo.
Pinned oven-sh/setup-bun's bun-version to 1.3.14 (the version
installed locally; ui/ has no .bun-version file or package.json
engines/packageManager field pinning one) across all three CI jobs
that install bun, removing the latest-resolution flake.
Gates: ruff check + ruff format --check (clean), pytest --co -q
(1637 collected, no import errors), a direct import smoke-test of
every new module's public symbols, and a make dev boot check —
langgraph dev registered all six graphs (agent, reviewer, analyzer,
chat, scheduler, ci_monitor) each importing from agent.graphs.*, and
loaded the custom app from agent.webapp:app, before the process was
killed. (The subsequent lifespan failure, "DEFAULT_SANDBOX_SNAPSHOT_ID
must be set when SANDBOX_TYPE=langsmith", is expected with no .env
secrets configured in this environment and unrelated to this commit.)
143 lines
4.6 KiB
YAML
143 lines
4.6 KiB
YAML
name: CI
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
# dev as well as main so every dev HEAD carries the full CI signal that
|
|
# the dev->main promotion gate (check-dev-green.sh) reads. PR checks alone are
|
|
# not enough: an admin-merge can land a red PR onto dev.
|
|
branches: ["main", "dev"]
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
lint:
|
|
name: Lint
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run lint
|
|
run: make lint
|
|
|
|
format:
|
|
name: Format check
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run format check
|
|
run: make format-check
|
|
|
|
typecheck:
|
|
name: Typecheck
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
|
|
with:
|
|
bun-version: "1.3.14"
|
|
- name: Install UI dependencies
|
|
working-directory: ui
|
|
run: bun install --frozen-lockfile
|
|
- name: Run Typecheck
|
|
working-directory: ui
|
|
run: bun run typecheck
|
|
|
|
unit-tests:
|
|
name: Unit tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run unit tests
|
|
run: make test
|
|
|
|
e2e:
|
|
name: Playwright E2E
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version: "24"
|
|
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
|
|
with:
|
|
bun-version: "1.3.14"
|
|
- name: Install Python deps (langgraph dev runtime)
|
|
run: uv sync --locked
|
|
- name: Install Playwright + Chromium
|
|
working-directory: tests/e2e
|
|
run: |
|
|
npm ci
|
|
sudo rm -f /etc/apt/sources.list.d/azure-cli.list /etc/apt/sources.list.d/microsoft-prod.list
|
|
npx playwright install --with-deps chromium
|
|
# Playwright's webServer boots `langgraph dev`; globalSetup builds the real
|
|
# ui/ SPA. The fake LLM/GitHub/Slack boundaries need no secrets.
|
|
- name: Run E2E
|
|
working-directory: tests/e2e
|
|
# Playwright's globalSetup runs the real `bun run build`, whose vite bundle
|
|
# exceeds Node's default ~2 GB heap.
|
|
# The runner has ~16 GB, so lift the heap cap.
|
|
env:
|
|
NODE_OPTIONS: "--max-old-space-size=8192"
|
|
run: npx playwright test
|
|
- name: Upload Playwright report
|
|
if: ${{ !cancelled() }}
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: playwright-report
|
|
path: |
|
|
tests/e2e/playwright-report
|
|
tests/e2e/test-results
|
|
retention-days: 7
|
|
|
|
docker-build:
|
|
name: Docker build smoke
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
# Smoke-build the sandbox image so a bad Dockerfile pin (e.g. an
|
|
# apt "nodejs=${NODEJS_VERSION}" that no longer resolves) fails a check
|
|
# instead of only surfacing at sandbox-provision time. No push, no
|
|
# registry credentials: this only proves the image builds.
|
|
- name: Build sandbox image (no push)
|
|
run: docker build --pull -t open-swe-sandbox:ci .
|
|
|
|
triage-ledger:
|
|
name: Triage ledger up to date
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
# docs/upstream-sync/triage.md is GENERATED from triage.jsonl. Fail if a
|
|
# ledger edit forgot to regenerate it (`make triage-render`). Stdlib-only
|
|
# Python, so no uv sync / deps needed.
|
|
- name: triage.md is up to date with triage.jsonl
|
|
run: make triage-check
|
|
|
|
ui-lockfile:
|
|
name: ui bun.lock in sync
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
|
|
with:
|
|
bun-version: "1.3.14"
|
|
- name: ui/package.json and ui/bun.lock agree
|
|
working-directory: ui
|
|
run: bun install --frozen-lockfile
|