From e875d97cbfbd3bbb80579977ad056863a9d5fec1 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 22 Jun 2026 19:02:40 -0400 Subject: [PATCH] fix(agent-team): apply/verify build-test runs the hermetic agent-team suite for the orchestrator target (#35) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The build-test step ran the generic root `pytest -q`, but this repo's root suite needs live ANTHROPIC/COMPOSIO keys (collect-only in CI) — so on the orchestrator target it would fail in the credential-less build sandbox and block every apply. Retarget the authoritative test to the self-contained agent-team/ subproject (exactly what the repo's green `ci / subproject-tests` runs). ruff stays repo-wide. Command is AUTHOR-FIXED (not a dispatch input) so no injection surface is added; multi-target parameterization remains a provisioning item. This unblocks the first live smoke test. --- agent-team/ci/agent-team-apply-verify.yml | 21 ++++++++++++--------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/agent-team/ci/agent-team-apply-verify.yml b/agent-team/ci/agent-team-apply-verify.yml index 96f3ad3..d1392ed 100644 --- a/agent-team/ci/agent-team-apply-verify.yml +++ b/agent-team/ci/agent-team-apply-verify.yml @@ -696,19 +696,22 @@ jobs: # The tool installs are best-effort (|| true), but ruff + pytest run # AUTHORITATIVELY under `set -e` so a real failure fails the job. # - # DEPLOY: the build/test invocation is parameterized per target repo at - # provisioning (a repo with no pytest suite needs its own command). Until - # then this generic ruff+pytest is the gate; a target whose tests need a - # different runner MUST be wired before it is dispatched. + # PER-TARGET (Sea-Haven-Industries/orchestrator): the AUTHORITATIVE test + # suite for this target is the self-contained, hermetic `agent-team/` + # subproject — the repo's own `ci / subproject-tests` runs exactly this, + # and the ROOT suite is deliberately NOT used (it needs live + # ANTHROPIC/COMPOSIO keys, so it is collect-only in CI). Multi-target + # support = wire each target's command at provisioning (this command is + # author-fixed here, NOT taken from any dispatch input, so it adds no + # injection surface). if [ -f requirements.txt ]; then python3 -m pip install --quiet -r requirements.txt || true fi - python3 -m pip install --quiet ruff pytest || true + python3 -m pip install --quiet ruff pytest pyyaml slack_sdk slack_bolt || true + # ruff over the whole repo (lint must hold for the applied diff). ruff check . - # pytest exit 5 == "no tests collected"; treat ONLY that as non-fatal - # (a fix with no test suite), every other non-zero is an authoritative - # failure. Never blanket-swallow. - pytest -q || { rc=$?; [ "$rc" -eq 5 ] || exit "$rc"; echo "no tests collected (exit 5)"; } + # The hermetic agent-team suite is authoritative (exit code IS the gate). + ( cd agent-team && python3 -m pytest -q ) - name: Post-build denied-path check (build hook may not write the trust surface) if: always()