# library-desk — the repo's command surface (D-27). # # Note the port split, which is the trap this repo's CLAUDE.md leads with: # `make run` serves on 8778 with reload, while 8089 is the *container*. Testing # localhost:8089 on this box hits the deployed service, not your dev server. # # Paths resolve here (D-10): `python3` is 3.8 on this host and a bare `pytest` # resolves only in a login shell, so both go through the venv explicitly. VENV := $(CURDIR)/.venv PYTHON ?= python3.12 .DEFAULT_GOAL := help .PHONY: help help: ## Show this help @grep -hE '^[a-z][a-z0-9_-]*:.*?## ' $(MAKEFILE_LIST) \ | awk 'BEGIN{FS=":.*?## "}{printf " \033[36m%-14s\033[0m %s\n", $$1, $$2}' .PHONY: setup setup: ## Create the venv, install dependencies, and prove the result works $(PYTHON) -m venv .venv # requirements-dev.txt pulls in requirements.txt via -r, so this is still # the full runtime set plus pytest/ruff. Installing only requirements.txt # here (as this line originally did) left `make test` and `make lint` # unreachable from a clean `make setup` since the Makefile's introduction # in b9f55cb — pytest was never installed by setup at all. Found by the # check below failing on its first clean-tree run; fixed in the same # commit rather than filed separately, since the new check cannot pass # honestly against the old line. $(VENV)/bin/pip install -r requirements-dev.txt # Exit 0 from pip install is not evidence (D-24) — it is the same exit code # whether requirements.txt matches what's on disk or a dependency silently # failed to install. Two cheap checks, for two different drift modes: # pip check - installed packages satisfy each other's declared # version constraints (a stale/partial install). # pytest --collect-only - every test module actually imports, which # walks the full src/ import graph and is exactly # what catches a *missing* declared dependency # (core-api's sqlalchemy case in T-47). It builds # no client and opens no socket - dependencies.py # wraps client construction in lru_cache getters, # never called at collection time - so this needs # none of the five backing services running. $(VENV)/bin/pip check $(VENV)/bin/python -m pytest tests/ --collect-only -q .PHONY: run run: ## Dev server on :8778 with reload (8089 is the container, not this) ./wakeup.sh .PHONY: test test: ## Run the test suite (no network needed — live tests are marked and self-skip) @test -x $(VENV)/bin/python || { echo "FAIL — no venv; run: make setup"; exit 69; } $(VENV)/bin/python -m pytest tests/ # The `integration` marker and its RUN_INTEGRATION_TESTS/TEST_TENANT gate already # lived in tests/conftest.py before T-55 (see test_integration.py, # test_tenant_isolation_live.py, test_quality_report_live.py, and the # TestWikiChangeListenerIntegration class) — `make test` never ran them because # `pytest_collection_modifyitems` skips anything carrying the marker unless # RUN_INTEGRATION_TESTS=1. That gate made them silent under `make test`, but # nothing ran them WITH the flag set either, so "runnable" had never been # reasserted. This target is that home (D-26): it sets the flag, selects the # marker, and — the part that matters — fails loudly if selection ever drops to # zero, since a target that passes by collecting nothing is worse than one that # needs a network (T-55). .PHONY: test-integration test-integration: ## Live tests against neo4j/qdrant/wikijs/searxng/ollama (needs network + services) @test -x $(VENV)/bin/python || { echo "FAIL — no venv; run: make setup"; exit 69; } @$(VENV)/bin/python -m pytest tests/ -m integration --collect-only -q >/dev/null 2>&1; \ rc=$$?; \ if [ "$$rc" = "5" ]; then \ echo "FAIL test-integration — selected 0 tests (marker renamed, moved, or lost — this is a defect, not a pass)"; \ exit 1; \ elif [ "$$rc" != "0" ]; then \ echo "FAIL test-integration — collection errored (rc=$$rc)"; \ exit $$rc; \ fi RUN_INTEGRATION_TESTS=1 $(VENV)/bin/python -m pytest tests/ -m integration -v .PHONY: lint lint: ## ruff check over the sources @test -x $(VENV)/bin/ruff || { echo "FAIL — ruff not installed; run: make setup"; exit 69; } $(VENV)/bin/ruff check src tests # git hands a hook a non-login shell, which never sees ~/.local/bin — where # gitleaks lands. Without this the scan reports "not installed" on every push, # which is a check that fails open (D-24). export PATH := $(HOME)/.local/bin:/usr/local/bin:$(PATH) .PHONY: secrets secrets: ## Scan the commits about to be pushed for credentials @ci/secrets.sh # The call surface is identical in every repo; what it runs is not. # # `secrets` runs first, deliberately: it is the only failure here that cannot be # undone by fixing it afterwards. A failed lint costs another commit; a pushed # credential is cached and indexed whether or not it is later deleted. # # Some of these fail today, and are left wired anyway. The state was measured # once and written down in T-56 rather than being worked around here — a gate # quietly narrowed to what already passes is a gate that reports success for # doing nothing, which is the failure this workspace keeps rediscovering. .PHONY: pre-push pre-push: secrets lint ## Everything the pre-push hook runs @echo " -- not gated here yet: test (T-56)"