Skip to content

ci: run npm test and the hooks against a released ix - #36

Merged
KageBinary merged 2 commits into
mainfrom
ci/real-ix-job
Oct 4, 2026
Merged

KageBinary merged 2 commits into
mainfrom
ci/real-ix-job

Conversation

@KageBinary

Copy link
Copy Markdown
Collaborator

Audit remediation PL-03.

What changes

  • mcp build job: adds npm test (the mock-ix suite; the mock is bash, so it stays on Linux). The existing "Committed dist matches the build" step already rebuilds and fails on any mcp/dist drift (including untracked emit), so no second dist check was added.
  • New real ix job: installs ix v0.12.0 from the release tarball (sha256sum -c against the .sha256 sidecar), Node 22, ripgrep; IX_ENDPOINT=http://127.0.0.1:1, IX_NO_UPDATE_CHECK=1; runs npm run test:real-ix. CI Passed now needs it.
  • mcp/tests/real-ix/hooks.real-ix.ts (+ its committed dist emit, since tsc compiles tests into mcp/dist). Named *.real-ix.ts so npm test does not pick it up.

What the real-ix test asserts

Hooks are run exactly as Cursor runs them: the node "${CURSOR_PLUGIN_ROOT}/mcp/dist/hooks/*.js" commands from hooks/hooks.json, with IX_BIN unset so the real ix on PATH is used, temp HOME/IX_HOME/XDG_STATE_HOME.

  1. ix --version is the pinned release.
  2. parseIxJson reads ix's real workspace_not_mapped error record (exit 1, JSON on stdout).
  3. postToolUse Grep, unmapped dir: locate's error record is not read as a symbol; ripgrep hits from ix text still reach additional_context; output keys are ones Cursor reads.
  4. postToolUse Write, unmapped: ix impact's exit-1 error body is parsed and the hook stays silent.
  5. Backend unreachable (workspace registered): all six hook entry points exit 0, inside their hooks.json timeouts, with only Cursor-documented output fields; no auto-map stamp written.
  6. Every ix argv the hooks actually ran (from the plugin's own IX_DEBUG_LOG), plus the two auto-map argv and pre-search's optional --path/--language, is accepted by this CLI: no unknown option. Checked locally that a CLI rejecting --silent turns this test red.

No version fields changed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EqMeW5huGYgRUWS2TtuvF8

KageBinary and others added 2 commits October 4, 2026 12:08
The mcp job now runs `npm test` (mock-ix suite) after the committed-dist
check. A new `real ix` job installs ix v0.12.0 from its release tarball
(sha256-verified), points IX_ENDPOINT at a dead port, and runs
tests/real-ix: the hooks.json commands against the real CLI, asserting
they parse ix's real error records, exit 0 with Cursor-protocol output
when the backend is unreachable, and that the CLI accepts every flag
the plugin passes it. CI Passed now needs both.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EqMeW5huGYgRUWS2TtuvF8
…uage

The only checksum came from the same release, so a tarball replaced
together with its .sha256 passed. Pin the sha256 in the workflow too.

The Grep payload's path was the project root, so pre-search passed no
--path, and no payload had a type. The optional filters were only
checked from a hand-written argv list, which a renamed flag in
pre-search would not change. Run a Grep scoped to a subdirectory with a
type, and require both flags among the argv the hooks actually ran.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@KageBinary KageBinary left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed against the released ix v0.12.0. Fixed in a0066a3:

  • Pinned the tarball's sha256 in the workflow.
  • The Grep path was the project root, so pre-search sent no --path, and no payload had a type. --path and --language were only checked against a hand-written argv list. A scoped Grep (lib/, ts) now makes the hook send both, and the test requires them among the argv it actually ran; renaming --language now fails 2 tests.

Note: the status and map argv lists are still hand-written. Real-ix 7/7 and npm test 27/27 on Node 22; CI is green. Merging.

@KageBinary
KageBinary marked this pull request as ready for review October 4, 2026 23:04
@KageBinary
KageBinary merged commit 5d072f6 into main Oct 4, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant