D-26 requires `make test` to pass with no network; T-55's audit measured 426
passed/29 skipped with network vs. 412 passed/23 skipped/20 ERRORS inside an
unprivileged network namespace. All 20 errors trace to a real Bolt connection
opened at fixture setup (neo4j_client -> client.connect()), not to test logic.
The ticket's own summary said all 20 were in test_entity_linking.py; tracing
the actual error list showed only 5 were (TestEntityLinkingIntegration,
TestEntityLinkingMultiTenancy, plus the trailing module-level cleanup test).
The other 15 are every test in test_hybrid_rag.py, whose hybrid_rag_service
fixture resolves graph_service -> neo4j_client regardless of what the test
body itself exercises -- including the RRF-fusion and context-formatting
classes that read as pure logic. There is no unit/integration split inside
that file without restructuring its fixture graph, which is out of scope
here; the whole module is marked instead of picking classes apart from
underneath a shared fixture chain.
The fix is the mechanism this repo already had and had never wired to a
target: tests/conftest.py's `integration` pytest marker plus its
RUN_INTEGRATION_TESTS/TEST_TENANT gate (test_integration.py,
test_tenant_isolation_live.py, test_quality_report_live.py and
TestWikiChangeListenerIntegration already used it). Applying the same marker
here means `make test` skips these 20 the same way it already skipped the
other 23 -- no file move, no new fixture layer, matching repo precedent
exactly rather than inventing a second convention beside it.
`make test-integration` is the D-26 home: sets RUN_INTEGRATION_TESTS=1,
selects `-m integration`, and treats pytest's own "no tests collected" exit
code (5) as a hard failure rather than a pass, so a marker that gets renamed
or lost fails loudly instead of the target quietly collecting zero and going
green.
Verified (unshare -rn sh -c 'ip link set lo up; ...' after confirming the
positive control -- a live :8089 returning HTTP 200 outside returns curl exit
7 inside):
make test, no network: 412 passed, 43 skipped, exit 0 (was 20 ERRORS)
make test, with network: 412 passed, 43 skipped, exit 0 (unchanged; the 14
of these 20 that were previously counted in the 426 passed now skip by
default -- reclassified, not lost; the other 6 already skipped for an
unrelated reason before this change)
make test-integration, these 20, with network: 14 passed, 6 skipped
(test_wiki_page's own pytest.skip when it can't create a wiki page -- a
pre-existing soft-skip, unrelated to this change), 0 failed, exit 0
make test-integration mutated to select a nonexistent marker: FAIL,
"selected 0 tests", exit 2 -- confirmed loud, then reverted
Not fixed here: the other 23 tests already carrying `integration` include
three files (test_integration.py, test_tenant_isolation_live.py,
test_quality_report_live.py) that fail under `make test-integration` today
because they call the local dev server on :8778, which was not running in
this session -- a pre-existing "never proven runnable" gap this same ticket
family exists to find, but a different set of tests than the one measured
here.
Co-Authored-By: Claude <noreply@anthropic.com>
109 lines
5.4 KiB
Makefile
109 lines
5.4 KiB
Makefile
# library-desk — the repo's command surface (D-27).
|
|
#
|
|
# Note the port split, which is the trap this repo's CLAUDE.md leads with:
|
|
# `make run` serves on 8778 with reload, while 8089 is the *container*. Testing
|
|
# localhost:8089 on this box hits the deployed service, not your dev server.
|
|
#
|
|
# Paths resolve here (D-10): `python3` is 3.8 on this host and a bare `pytest`
|
|
# resolves only in a login shell, so both go through the venv explicitly.
|
|
|
|
VENV := $(CURDIR)/.venv
|
|
PYTHON ?= python3.12
|
|
|
|
.DEFAULT_GOAL := help
|
|
|
|
.PHONY: help
|
|
help: ## Show this help
|
|
@grep -hE '^[a-z][a-z0-9_-]*:.*?## ' $(MAKEFILE_LIST) \
|
|
| awk 'BEGIN{FS=":.*?## "}{printf " \033[36m%-14s\033[0m %s\n", $$1, $$2}'
|
|
|
|
.PHONY: setup
|
|
setup: ## Create the venv, install dependencies, and prove the result works
|
|
$(PYTHON) -m venv .venv
|
|
# requirements-dev.txt pulls in requirements.txt via -r, so this is still
|
|
# the full runtime set plus pytest/ruff. Installing only requirements.txt
|
|
# here (as this line originally did) left `make test` and `make lint`
|
|
# unreachable from a clean `make setup` since the Makefile's introduction
|
|
# in b9f55cb — pytest was never installed by setup at all. Found by the
|
|
# check below failing on its first clean-tree run; fixed in the same
|
|
# commit rather than filed separately, since the new check cannot pass
|
|
# honestly against the old line.
|
|
$(VENV)/bin/pip install -r requirements-dev.txt
|
|
# Exit 0 from pip install is not evidence (D-24) — it is the same exit code
|
|
# whether requirements.txt matches what's on disk or a dependency silently
|
|
# failed to install. Two cheap checks, for two different drift modes:
|
|
# pip check - installed packages satisfy each other's declared
|
|
# version constraints (a stale/partial install).
|
|
# pytest --collect-only - every test module actually imports, which
|
|
# walks the full src/ import graph and is exactly
|
|
# what catches a *missing* declared dependency
|
|
# (core-api's sqlalchemy case in T-47). It builds
|
|
# no client and opens no socket - dependencies.py
|
|
# wraps client construction in lru_cache getters,
|
|
# never called at collection time - so this needs
|
|
# none of the five backing services running.
|
|
$(VENV)/bin/pip check
|
|
$(VENV)/bin/python -m pytest tests/ --collect-only -q
|
|
|
|
.PHONY: run
|
|
run: ## Dev server on :8778 with reload (8089 is the container, not this)
|
|
./wakeup.sh
|
|
|
|
.PHONY: test
|
|
test: ## Run the test suite (no network needed — live tests are marked and self-skip)
|
|
@test -x $(VENV)/bin/python || { echo "FAIL — no venv; run: make setup"; exit 69; }
|
|
$(VENV)/bin/python -m pytest tests/
|
|
|
|
# The `integration` marker and its RUN_INTEGRATION_TESTS/TEST_TENANT gate already
|
|
# lived in tests/conftest.py before T-55 (see test_integration.py,
|
|
# test_tenant_isolation_live.py, test_quality_report_live.py, and the
|
|
# TestWikiChangeListenerIntegration class) — `make test` never ran them because
|
|
# `pytest_collection_modifyitems` skips anything carrying the marker unless
|
|
# RUN_INTEGRATION_TESTS=1. That gate made them silent under `make test`, but
|
|
# nothing ran them WITH the flag set either, so "runnable" had never been
|
|
# reasserted. This target is that home (D-26): it sets the flag, selects the
|
|
# marker, and — the part that matters — fails loudly if selection ever drops to
|
|
# zero, since a target that passes by collecting nothing is worse than one that
|
|
# needs a network (T-55).
|
|
.PHONY: test-integration
|
|
test-integration: ## Live tests against neo4j/qdrant/wikijs/searxng/ollama (needs network + services)
|
|
@test -x $(VENV)/bin/python || { echo "FAIL — no venv; run: make setup"; exit 69; }
|
|
@$(VENV)/bin/python -m pytest tests/ -m integration --collect-only -q >/dev/null 2>&1; \
|
|
rc=$$?; \
|
|
if [ "$$rc" = "5" ]; then \
|
|
echo "FAIL test-integration — selected 0 tests (marker renamed, moved, or lost — this is a defect, not a pass)"; \
|
|
exit 1; \
|
|
elif [ "$$rc" != "0" ]; then \
|
|
echo "FAIL test-integration — collection errored (rc=$$rc)"; \
|
|
exit $$rc; \
|
|
fi
|
|
RUN_INTEGRATION_TESTS=1 $(VENV)/bin/python -m pytest tests/ -m integration -v
|
|
|
|
.PHONY: lint
|
|
lint: ## ruff check over the sources
|
|
@test -x $(VENV)/bin/ruff || { echo "FAIL — ruff not installed; run: make setup"; exit 69; }
|
|
$(VENV)/bin/ruff check src tests
|
|
|
|
# git hands a hook a non-login shell, which never sees ~/.local/bin — where
|
|
# gitleaks lands. Without this the scan reports "not installed" on every push,
|
|
# which is a check that fails open (D-24).
|
|
export PATH := $(HOME)/.local/bin:/usr/local/bin:$(PATH)
|
|
|
|
.PHONY: secrets
|
|
secrets: ## Scan the commits about to be pushed for credentials
|
|
@ci/secrets.sh
|
|
|
|
# The call surface is identical in every repo; what it runs is not.
|
|
#
|
|
# `secrets` runs first, deliberately: it is the only failure here that cannot be
|
|
# undone by fixing it afterwards. A failed lint costs another commit; a pushed
|
|
# credential is cached and indexed whether or not it is later deleted.
|
|
#
|
|
# Some of these fail today, and are left wired anyway. The state was measured
|
|
# once and written down in T-56 rather than being worked around here — a gate
|
|
# quietly narrowed to what already passes is a gate that reports success for
|
|
# doing nothing, which is the failure this workspace keeps rediscovering.
|
|
.PHONY: pre-push
|
|
pre-push: secrets lint ## Everything the pre-push hook runs
|
|
@echo " -- not gated here yet: test (T-56)"
|