Files
yellowjacket/backend/testctl/register_dev.go
T
logan 5ca6cad45a
Build & publish Arch package / arch-package (push) Successful in 2m8s
CI / check (push) Failing after 1m56s
CI / e2e (push) Skipped
Search index maintenance / maintain-index (push) Successful in 13s
feat(harness): agent-drivable dev harness and CI that gates
A coding agent could develop this repo's Go packages and could not
develop the application: every path to running YellowJacket ended in a
blocking GTK window, so 265 bound methods, 46 events, 33 component
directories and 13 stores had exactly one form of verification
available — `tsc --noEmit`.

The unlock is that `wails dev`'s dev server on :34115 serves the real
frontend with the real generated bindings against the same Go backend a
desktop window attaches to, so a plain Chromium under Xvfb gets a fully
functional app. Four test tiers now exist, cheapest first:

- `make ui-test` — 313 Vitest tests in a real browser in ~2 s, no app,
  no backend, no display. Works because `frontend/wailsjs/` is a pure
  passthrough to `window.go`/`window.runtime`, so faking just those two
  globals runs the real bindings and the real store code.
- `make test` — services in-process, asserting on the payload the
  frontend would receive, via a new `events.Emit` wrapper.
- `make dev-headless` + `playwright-cli` — the real app, driven
  interactively, with an event bridge on `window.__yjEvents` and a
  dev-only control surface at `/__test/`.
- `make e2e` — 19 of those flows frozen as Playwright specs.

`events.Emit(ctx, …)` replaces all 35 direct `runtime.EventsEmit` call
sites: wails' `getEvents` `log.Fatalf`s on any context without its
runtime, so those paths could not run under test and a background
worker could take the app down. Four packages had each hand-rolled the
same guard; nine more guarded on `ctx != nil`, which does not help.
`TestNoDirectRuntimeEmits` fails the build on a new one.

Fixtures are generated, not committed (`make testdata`), and seeds are
built by *running the app* — never by hand-writing config and DB rows,
which would be a second description of a valid YJ_HOME.

`.gitea/workflows/ci.yml` is the first workflow here that tests
anything; the other three only package, so `gitea_ci` reported only
packaging jobs and misled anyone asking whether a push was healthy.
Both jobs were prototyped to green in a bare ubuntu:24.04 container
before the YAML was written, which immediately caught `make lint`
linting three configurations that nothing builds: all three passes
omitted `webkit2_41`, so wails resolved webkit2gtk-4.0 — which Arch
still ships and Ubuntu 24.04 dropped.

Operational instructions live in `.pi/skills/yellowjacket-dev/`,
measured discoveries in `.planning/NOTES.md`, and architecture in
`CLAUDE.md` — split by tense, not by topic, because a topical split
gives every new fact two plausible homes. `make skill-check` fails a
commit if the skill cites a make target that does not exist.
2026-08-10 23:20:42 -04:00

99 lines
2.8 KiB
Go

//go:build dev
package testctl
import (
"encoding/json"
"errors"
"io"
"net/http"
"os"
"regexp"
)
// Static errors — err113 forbids fmt.Errorf with a dynamic message at
// the point of failure, and these are all conditions a caller may want
// to match on anyway.
var (
errBadName = errors.New("name must match [A-Za-z0-9_-]{1,64}")
errNoSnapshot = errors.New("no such snapshot")
errNoEventName = errors.New("emit needs a non-empty name")
errNoSQL = errors.New("sql must be non-empty")
errBadBody = errors.New("request body is not valid JSON")
errInconsistent = errors.New(
"restore left foreign key violations")
)
// safeName keeps snapshot names to something that cannot escape the
// snapshot directory or surprise a shell.
var safeName = regexp.MustCompile(`^[A-Za-z0-9_-]{1,64}$`)
// Register mounts the control surface, if and only if this is a dev
// build *and* YJ_TESTCTL=1. A human running `make dev` gets neither
// the routes nor the risk.
func Register(r Registrar, d Deps) {
if os.Getenv(EnvEnable) != "1" {
return
}
mux := http.NewServeMux()
mux.HandleFunc("GET /__test/health", jsonHandler(d, handleHealth))
mux.HandleFunc("POST /__test/db/snapshot", jsonHandler(d, handleSnapshot))
mux.HandleFunc("POST /__test/db/restore", jsonHandler(d, handleRestore))
mux.HandleFunc("POST /__test/emit", jsonHandler(d, handleEmit))
mux.HandleFunc("POST /__test/sql", jsonHandler(d, handleSQL))
r.RegisterHandler(Prefix, mux)
d.Logger.Warn(
"test control surface enabled — dev build with YJ_TESTCTL=1",
"prefix", Prefix,
)
}
// handlerFunc is the shape every endpoint has: take the request,
// return something JSON-encodable or an error.
type handlerFunc func(Deps, *http.Request) (any, error)
// jsonHandler centralises encoding, status codes and logging so each
// endpoint is only its own logic. A failure is a 400 with the reason
// in the body — an agent reading a spec failure needs the reason, not
// a bare status code.
func jsonHandler(d Deps, fn handlerFunc) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
result, err := fn(d, r)
w.Header().Set("Content-Type", "application/json")
if err != nil {
d.Logger.Error("testctl request failed",
"path", r.URL.Path, "err", err.Error())
w.WriteHeader(http.StatusBadRequest)
_ = json.NewEncoder(w).Encode(map[string]string{
"error": err.Error(),
})
return
}
_ = json.NewEncoder(w).Encode(result)
}
}
// decode reads a JSON request body into v. An empty body is not an
// error: several endpoints take everything in the query string.
func decode(r *http.Request, v any) error {
if r.Body == nil {
return nil
}
dec := json.NewDecoder(r.Body)
if err := dec.Decode(v); err != nil && !errors.Is(err, io.EOF) {
return errBadBody
}
return nil
}