fix(agent-team): apply/verify build-test runs the hermetic agent-team suite for the orchestrator target (#35)

The build-test step ran the generic root `pytest -q`, but this repo's root
suite needs live ANTHROPIC/COMPOSIO keys (collect-only in CI) — so on the
orchestrator target it would fail in the credential-less build sandbox and block
every apply. Retarget the authoritative test to the self-contained agent-team/
subproject (exactly what the repo's green `ci / subproject-tests` runs). ruff
stays repo-wide. Command is AUTHOR-FIXED (not a dispatch input) so no injection
surface is added; multi-target parameterization remains a provisioning item.
This unblocks the first live smoke test.
This commit is contained in:
Adam Moussa 2026-06-22 19:02:40 -04:00 • committed by GitHub
parent 03b9a94881
commit e875d97cbf
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -696,19 +696,22 @@ jobs:
# The tool installs are best-effort (|| true), but ruff + pytest run
# AUTHORITATIVELY under `set -e` so a real failure fails the job.
#
# DEPLOY: the build/test invocation is parameterized per target repo at
# provisioning (a repo with no pytest suite needs its own command). Until
# then this generic ruff+pytest is the gate; a target whose tests need a
# different runner MUST be wired before it is dispatched.
# PER-TARGET (Sea-Haven-Industries/orchestrator): the AUTHORITATIVE test
# suite for this target is the self-contained, hermetic `agent-team/`
# subproject — the repo's own `ci / subproject-tests` runs exactly this,
# and the ROOT suite is deliberately NOT used (it needs live
# ANTHROPIC/COMPOSIO keys, so it is collect-only in CI). Multi-target
# support = wire each target's command at provisioning (this command is
# author-fixed here, NOT taken from any dispatch input, so it adds no
# injection surface).
if [ -f requirements.txt ]; then
python3 -m pip install --quiet -r requirements.txt || true
fi
python3 -m pip install --quiet ruff pytest || true
python3 -m pip install --quiet ruff pytest pyyaml slack_sdk slack_bolt || true
# ruff over the whole repo (lint must hold for the applied diff).
ruff check .
# pytest exit 5 == "no tests collected"; treat ONLY that as non-fatal
# (a fix with no test suite), every other non-zero is an authoritative
# failure. Never blanket-swallow.
pytest -q || { rc=$?; [ "$rc" -eq 5 ] || exit "$rc"; echo "no tests collected (exit 5)"; }
# The hermetic agent-team suite is authoritative (exit code IS the gate).
( cd agent-team && python3 -m pytest -q )
- name: Post-build denied-path check (build hook may not write the trust surface)
if: always()