Skip to content

ci: run every central module's own gate in hosted CI - #54

Closed
hseshadr wants to merge 1 commit into
fix/python-package-zip64-eocdfrom
ci/run-module-gates
Closed

hseshadr wants to merge 1 commit into
fix/python-package-zip64-eocdfrom
ci/run-module-gates

Conversation

@hseshadr

Copy link
Copy Markdown
Owner

TL;DR

Hosted CI now runs every central module's own poe gate. Before this, dagger call ci ran only the root .dagger gate, so a module could go red on main and no hosted check would notice.

Claim touched: "module regressions cannot reach main unchecked."

Stacked on #53 (python-package ZIP64 fix), which this gate found on its first run. Merge #53 first.

What changed (CI config + tests only)

  • Ci.ci runs _module_gates() after root quality and before security. Each module (cloudflare-pages, portfolio-foundation, python-package) runs uv run poe gate in its own container: digest-pinned python:3.13.14-bookworm, with uv, uvx, and the v0.21.8 Dagger CLI from the pinned engine image. The engine-generated SDK is overlaid on the explicit source. Privileged nesting gives dagger -m .. functions (the schema task) its engine.
  • MODULE_GATES must equal modules/*/dagger.json, so a new module cannot skip the gate.
  • All gates run concurrently. The error names every module that failed.
  • The workflow is unchanged. dagger.yml stays a thin ingress, as test_central_workflows.py requires.

What hosted CI still does not run

These tests are deselected by exact node id, and a test pins the list and checks that each id still names a real test:

Module Deselected Why
portfolio-foundation test_guard_integration.py (7 tests) gitleaks via host docker run; no Docker daemon inside Dagger. Hosted CI still runs gitleaks for real through foundation.guard.
portfolio-foundation 4 tests in test_artifact.py, test_bootstrap.py, test_source_integration.py run the Dagger CLI in a pytest temp dir. A nested CLI resolves paths against the container workdir, not the process cwd, so they load the wrong module.
cloudflare-pages test_deploy_contract.py::test_should_run_real_dagger_mock_provider_contract same nested-CLI dagger init issue

These still run locally with each module's poe gate.

Evidence (local engine v0.21.8, dagger call ci)

Check Result
Contract tests before the change red: ImportError: cannot import name 'ENGINE_IMAGE', and the ci-order test fails
New step on main's module trees red: module gates failed: modules/python-package. test_should_observe_bounded_forced_zip64_wheel fails with ProbeError: wheel physical EOF differs on CPython 3.13.14. Fixed in #53.
New step on this branch (stacked on #53) all four gates green: root 96.45%; foundation 93.97% (236 passed, 11 deselected); cloudflare-pages 93.91% (174 passed, 1 deselected); python-package 96.95% (134 passed)
Mutation: git rm foundation tests/test_github.py red: FAIL Required test coverage of 90% not reached. Total coverage: 68.79% → module gates failed: modules/portfolio-foundation
Root poe gate green, 227 passed
git merge-tree vs #47, #48, #50, #51 clean (all four)

The requested "foundation stops at 86% on main" did not reproduce on a clean main: foundation's gate is 93.97% there. The 86.50% log came from a tree with #50's lineage.py but no test_lineage.py (lineage.py at 0%). This gate would catch that tree. No floor was lowered, and no foundation tests were needed.

🤖 Generated with Claude Code

https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a

`dagger call ci` ran only the root .dagger gate, so a module could go red on
main without any hosted check noticing. It now runs each module's `poe gate`
(lint, typecheck, complexity, tests with coverage floors, branch rates, schema,
audit) inside Dagger, after root quality and before security:

- one container per module from digest-pinned python:3.13.14-bookworm, with uv,
  uvx and the v0.21.8 Dagger CLI; the engine-generated SDK is overlaid on the
  explicit source, and nesting gives `dagger -m ..` in the gate its engine;
- MODULE_GATES must equal modules/*/dagger.json, so a new module cannot skip it;
- all gates run concurrently and the error names every failed module;
- tests that need host Docker or a host Dagger CLI working in a temp directory
  are deselected by exact node id, pinned by a test that also checks each id
  still names a real test.

Red: on main's module trees the new step fails on python-package
(test_should_observe_bounded_forced_zip64_wheel, CPython 3.13.14); fixed in the
base branch. Mutation: deleting foundation tests/test_github.py drops its
coverage to 68.79% and fails the step with "module gates failed:
modules/portfolio-foundation".

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
@hseshadr
hseshadr deleted the branch fix/python-package-zip64-eocd September 25, 2026 20:09
@hseshadr hseshadr closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant