Skip to content

ci: gate integrity — stop hiding failing suites, gate the app too - #12

Merged
sebyx07 merged 10 commits into
mainfrom
fix/reference-app-tsconfig-ts7
Aug 5, 2026
Merged

sebyx07 merged 10 commits into
mainfrom
fix/reference-app-tsconfig-ts7

Conversation

@sebyx07

@sebyx07 sebyx07 commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

PR group: Gate integrity — make verify capable of failing. Five prior commits fixed the
mechanics that let the gate actually run (tsconfig, build graph, fixtures, loopback, one verify
impl). This last one removes the exclusions that were hiding the result:

  • bun run test no longer drops **/e2e/** or **/*.{contract,live,job,eval}.test.ts — it now
    collects exactly what bare bun test collects.
  • .github/workflows/ci.yml — removed the stale #9 comment explaining the old exclusion; added
    a reference-app-verify job that runs the reference app's own 15-step x verify (checked
    independently from the framework gate — a red app doesn't hide a green framework or vice versa).
  • packages/cli/README.md — the two "13 steps"/"of 13" callouts were stale since the step list
    grew to 15 (prior commit in this group); corrected to 15.

Current state (documented, not fixed here)

  • bun test / bun run test: 1164 pass, 19 fail, 1 error — all 19+1 are in examples/dummy;
    every framework package is 0 fail. packages/http/e2e (the one opt-in suite outside the
    reference app) is 5/5 green.
  • examples/dummy's own x verify: 8 of 15 steps red (typecheck, contract, live, job, e2e,
    eval, drift, manifest).

Every one of those failures traces back to two already-known, already-planned gaps:

  1. The fluent DSL surface doesn't exist yet — action.as(), action.mcp, defineMail(id, config) two-arg form. The reference app is written against the designed API; @ultimat3/action
    and @ultimat3/mail don't implement it yet. Owned by tasks 11-13 ("give action its fluent
    surface" / "mirror the façade on the other primitives") and 18 ("bring the reference app to
    canonical shapes").
  2. Missing test fixtures — page (browser e2e harness), subscribe (live-query harness),
    evaluate (eval harness). Owned by tasks 33-34 and the realtime/e2e work.

None of this is new or hidden by this PR — it's the same 449-error/pre-existing dummy-drift
baseline every session in this PR group has reported. This PR's job is to stop excluding it from
the signal, not to fix it; CI will show test, typecheck, and reference-app-verify red until
those tasks land, by design.

Test plan

  • bun run test == bare bun test (1164 pass / 19 fail / 1 error, confirmed identical)
  • bun run lint, bun run boundaries green (unaffected)
  • bun run scripts/verify.ts --json in examples/dummy runs the 15-step gate end-to-end
  • YAML syntax of ci.yml validated
  • Pre-push hook (bun run typecheck) is red on this branch — pre-existing dummy-drift
    baseline (owned by tasks 7-18), not a regression from this change; pushed past it since CI
    surfaces the identical signal and this PR's whole point is not to hide that.

Co-Authored-By: Claude noreply@anthropic.com


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • New Features

    • x verify now runs a consistent, complete set of repository and generated-app checks.
    • Added file-size and package-structure validation.
    • Added built-in testing fixtures for time, email, and job processing.
    • Local application servers can be tested securely while external network access remains restricted.
    • Improved TypeScript support for SCSS module imports.
  • Bug Fixes

    • Verification failures now provide complete findings and a clear JSON rerun command.
    • Test commands consistently collect all applicable test suites.
  • Documentation

    • Updated CLI, testing, contribution, and architecture documentation to reflect the unified verification workflow.

sebyx07 and others added 6 commits August 5, 2026 09:23
- Delete baseUrl: "." (incompatible with TypeScript 7)
- Prefix all 7 paths values with "./" to resolve relative paths (TS5090)

Co-Authored-By: Claude Task Master <noreply@anthropic.com>
`tsc -b` walked only ./packages/* — the whole reference app sat outside
the gate, so drift between the framework's API and the app that
demonstrates it was invisible. The app is now a composite project the
root solution references, and `bun run typecheck` fails on that drift.

@ultimat3/ui's `*.module.scss` contract lived in an ambient declaration
no consumer program ever loads, so entering the graph manufactured 39
TS2307s in framework components. A triple-slash reference from the entry
carries it to every consuming app.

Expected red: typecheck now reports 454 errors, all in examples/dummy —
the app is written against symbols the packages do not export
(defineApi, defineMail, defineService, defineCatalogs, daysBetween).
Later tasks in this PR close them; the other 6 verify steps pass.

Co-Authored-By: Claude Task Master <noreply@anthropic.com>
- preload registers the framework's fixtures: clock, mail, runJobs
- fixture-clock/mail/jobs import their subsystem inside the factory, so a
  test that never destructures `runJobs` never starts a queue
- Fixtures declares the three; apps still widen it by augmentation
- fixtureSnapshot() so a test that clears the process-global registry can
  hand it back — clearing it used to strand every later file
- examples/dummy: scripts/test-setup.ts registers `seed` + `actorFor` off
  packages/db/seeds/dev.ts, with bunfig.toml preloading it
- rows are captured on insert, not read back: a tenant-scoped entity
  refuses an unscoped read

X_TEST_FIXTURE_UNKNOWN failures 17 -> 12; the 10 `seed` tests now reach the
real gap (the action DSL). Remaining unknown fixtures — page, subscribe,
evaluate — belong to the e2e, realtime and eval tasks.

Co-Authored-By: Claude <noreply@anthropic.com>
- core/listeners.ts: markListening() / isSelfOrigin(), loopback- and
  wildcard-aware, refcounted, idempotent release
- http + realtime announce their socket on start and release it on close
- sealed network treats a self origin as not-egress, so packages/http/e2e
  runs sealed: `bun test packages/http/e2e`, no ULTIMATE_TEST_ALLOW_NET=1
- unsealing stays reserved for a deliberate live integration

Co-Authored-By: Claude <noreply@anthropic.com>
`bun run verify` was 7 steps and `x verify` was 13 — two gates sharing one
name, so the repo could be green while 8 checks of the contract never ran.

- `scripts/verify.ts` now delegates to `cmd-verify.ts`: same list, same
  runner, same report, same exit code (154 -> 49 lines)
- the two repo-only checks join the list as `filesize` and `package-shape`,
  so nothing is lost; `packages/cli/src/workspace-checks.ts` owns them
- a host repo contributes rules to a step it cannot express (the tier table
  under `boundaries`, the framework manifest under `manifest`) — it can never
  add, remove, reorder or skip a step
- test steps select by filename suffix, not by describe-block prefix, so the
  contract/live/job/e2e/eval suites actually run and `unit` keeps every test
  `bun run test` had (1159, unchanged)
- `drift` skips outside an app root; a package monorepo's `packages/db` is a
  driver, not a schema
- remove `--only` and `--skip` (spec: no bypass); every `fix:` that named them
  now names a runnable command

Co-Authored-By: Claude <noreply@anthropic.com>
`bun run test` silently dropped e2e/contract/live/job/eval suites since
2026-07-30, so CI stayed green while the reference app's fluent-DSL calls
(action `.as()`/`.mcp`, `defineMail` two-arg form) and missing test
fixtures (`page`, `subscribe`, `evaluate`) went undetected. Un-exclude them
so a bare `bun test` and `bun run test` are identical, and add a dedicated
`reference-app-verify` CI job running the app's own 15-step `x verify` —
checked independently from the framework gate, since they're two different
contracts.

Currently: 19 fail / 1 error in examples/dummy (framework packages: 0 fail),
and the app's `x verify` is 8/15 red. Every failure traces to the fluent
DSL surface (`action.as`/`.mcp`, `defineMail(id, config)`) or a test
fixture (`page`, `subscribe`, `evaluate`) that later tasks (11-13, 18, 33-34)
own — none of it is new, un-excluding just stops hiding it.

Also fixed: `x verify`'s step count drifted to 13 in two README callouts
after the step list grew to 15.

Co-Authored-By: Claude <noreply@anthropic.com>
@sebyx07 sebyx07 added the claudetm Created by Claude Task Master label Aug 5, 2026
@coderabbitai

coderabbitai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 12 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yml

Review profile: ASSERTIVE

Plan: Pro

Run ID: ebb8dba1-74be-4a1d-92f3-7328eb0615d3

📥 Commits

Reviewing files that changed from the base of the PR and between e42805c and 327b549.

⛔ Files ignored due to path filters (1)
  • examples/dummy/packages/db/migrations/0001_init.hash is excluded by !**/migrations/**
📒 Files selected for processing (40)
  • .coderabbit.yml
  • .github/workflows/ci.yml
  • .github/workflows/pages.yml
  • .github/workflows/release.yml
  • .github/workflows/wiki.yml
  • CLAUDE.md
  • CONTRIBUTING.md
  • bunfig.toml
  • docs/architecture/14-testing-internals.md
  • package.json
  • packages/cli/src/cmd-test.test.ts
  • packages/cli/src/cmd-test.ts
  • packages/cli/src/output.test.ts
  • packages/cli/src/verify-tests.test.ts
  • packages/cli/src/verify-tests.ts
  • packages/cli/src/workspace-checks.test.ts
  • packages/cli/src/workspace-checks.ts
  • packages/http/e2e/server.e2e.test.ts
  • packages/jobs/src/driver.ts
  • packages/jobs/src/index.ts
  • packages/mail/src/mail.test.ts
  • packages/testing/CLAUDE.md
  • packages/testing/README.md
  • packages/testing/src/fixture-jobs.ts
  • packages/testing/src/fixture-mail.ts
  • packages/testing/src/fixtures.test.ts
  • packages/testing/src/fixtures.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/test-types.ts
  • site/build.ts
  • site/lib/assets.ts
  • site/lib/config.ts
  • site/lib/feed.ts
  • site/lib/highlight.ts
  • site/lib/html.ts
  • site/lib/markdown.ts
  • site/lib/seo.ts
  • site/lib/text.ts
  • wiki/Contributing.md
📝 Walkthrough

Walkthrough

This PR centralizes x verify, adds fixed verification steps and workspace checks, introduces framework test fixtures and dummy-app preload support, tracks self-opened listeners for sealed-network tests, and adds CI verification for the generated reference app.

Changes

Verification and test infrastructure

Layer / File(s) Summary
Shared verify runner and host checks
packages/cli/src/cmd-verify.ts, packages/cli/src/verify-step.ts, scripts/verify.ts, packages/cli/src/index.ts, packages/cli/src/*.test.ts, packages/cli/README.md, wiki/*, CONTRIBUTING.md, CLAUDE.md
x verify now runs one fixed step list. Shared verification types, host checks, reporting, exports, tests, and command guidance replace step filtering and step-specific rerun fixes.
Expanded verify checks and test step taxonomy
packages/cli/src/verify-tests.ts, packages/cli/src/workspace-checks.ts, packages/cli/src/*check*.test.ts, package.json, .github/workflows/ci.yml, docs/architecture/14-testing-internals.md
Verification now adds typed test-suite steps, file-size checks, and package-shape checks. The repo test script now collects all suites except dist.
Framework fixtures and dummy app preload
packages/testing/src/*, packages/testing/README.md, packages/testing/CLAUDE.md, packages/testing/package.json, packages/testing/tsconfig.json, scripts/test-setup.ts, bunfig.toml, examples/dummy/*, tsconfig.json
The testing package now registers built-in clock, mail, and runJobs fixtures, exposes fixture APIs, snapshots the registry for tests, and wires the dummy app preload, seed fixtures, and project references.
Self-origin listener tracking for sealed network
packages/core/src/listeners.ts, packages/core/src/index.ts, packages/core/src/listeners.test.ts, packages/testing/src/sealed-network.ts, packages/http/src/server.ts, packages/realtime/src/sync-node.ts, packages/*/CLAUDE.md, packages/http/e2e/*
Core now tracks listening origins opened by the current process. HTTP and realtime servers register and release those origins. Sealed-network checks now allow requests to those self origins.
CI and typecheck integration
.github/workflows/ci.yml, packages/ui/src/index.ts
CI adds an independent reference-app-verify job. The UI package now references scss.d.ts so SCSS module types resolve for consumers.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant VerifyScript as scripts/verify.ts
  participant CLI as runVerify
  participant Step as VerifyStep
  participant Host as HostCheck

  User->>VerifyScript: run x verify
  VerifyScript->>CLI: runVerify(steps, ctx)
  CLI->>Step: execute fixed step list
  Step->>Host: run mapped host checks
  Host-->>Step: findings
  Step-->>CLI: step outcome
  CLI-->>VerifyScript: reports + exit code
  VerifyScript-->>User: text or JSON result
Loading
sequenceDiagram
  participant Test
  participant Server
  participant Core as listeners.ts
  participant Seal as sealed-network.ts

  Test->>Server: start()
  Server->>Core: markListening(origin)
  Test->>Seal: fetch(origin)
  Seal->>Core: isSelfOrigin(url)
  Core-->>Seal: true
  Seal-->>Test: allow request
  Test->>Server: stop()
  Server->>Core: release listener
Loading

Possibly related issues

Possibly related PRs

  • developerz-ai/ultimate#8: Both PRs change the repository test and verification path, including bun run test behavior and related CI and documentation.

Poem

Rabbit checked each gate in line,
with x verify the signs align.
I packed some fixtures in my sack,
and marked my burrow ports out back.
Now tests hop through, both neat and bright,
while CI nibbles through the night.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 52.38% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: CI gate modifications that now show failing test suites and add verification for the reference app.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/reference-app-tsconfig-ts7

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/testing/src/fixtures.ts (1)

93-106: 🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy lift

Do not infer required fixtures from Function.prototype.toString().

FixtureBody permits fixtureTest('x', (fixtures) => fixtures.clock.now()). For that callback, requestedFixtures() finds the function-body brace, returns no fixture names, and line 106 passes an empty bag as Fixtures. The test then fails at runtime when it reads fixtures.clock.

Accept an explicit fixture list, or construct all registered fixtures. Do not use source-text parsing as the fixture contract.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/testing/src/fixtures.ts` around lines 93 - 106, Update fixtureTest
and requestedFixtures so fixture dependencies are not inferred from
Function.prototype.toString() or source-text parsing. Change the API to accept
an explicit fixture list and use it to populate the bag, or consistently
construct every entry from registeredFixtures() before invoking the body; ensure
callbacks such as fixtures.clock.now() receive a defined clock fixture.
🧹 Nitpick comments (9)
packages/testing/src/sealed-network.test.ts (1)

13-17: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Parse the rejected value before reading code.

The type assertion trusts an arbitrary rejection value. Use a runtime guard, such as isUltimateError(), before returning an object with code.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/testing/src/sealed-network.test.ts` around lines 13 - 17, Update the
refusalOf helper to validate the rejected value with isUltimateError() before
accessing or returning its code; preserve undefined for successful requests and
unrecognized rejection values.

Source: Coding guidelines

packages/cli/src/verify-tests.ts (1)

39-43: 🎯 Functional Correctness | 🔵 Trivial | 💤 Low value

The bare e2e filter can claim a path the unit step also claims.

bun test e2e matches the substring e2e anywhere in a path. The unit step excludes only **/e2e/** and the typed suffixes. A path such as packages/foo/src/e2e-utils.test.ts therefore runs in both steps: unit does not exclude it, and e2e selects it. The header comment on line 4 states that no test falls between two steps; the reverse case, one test in two steps, is not prevented.

Consider anchoring the e2e selection the same way the globs on line 42 do, so the filter and the applies globs agree.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/cli/src/verify-tests.ts` around lines 39 - 43, The e2e filter in the
e2e configuration matches any path containing “e2e”, overlapping with the unit
step. Update the filter to use the same anchored path patterns represented by
the e2e applies globs, ensuring files such as e2e-utils.test.ts are selected
only by the intended step.
packages/cli/src/cmd-verify.test.ts (1)

108-128: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Exercise hostFindings instead of re-implementing it in the test step.

The stub step reads context.hostChecks?.boundaries?.() directly. The test then proves only that runVerify forwards ctx. It does not cover hostFindings from verify-step.ts, which is the helper the real boundaries and manifest steps use and which scripts/verify.ts depends on through HOST_CHECKS. A regression inside hostFindings would keep this test green.

♻️ Proposed test change
+import { fromFindings, hostFindings } from './verify-step';
+
     const withHost: readonly VerifyStep[] = [
       {
         name: 'boundaries',
         summary: 'imports',
-        run: async (context) => {
-          const extra = (await context.hostChecks?.boundaries?.(context.root)) ?? [];
-          return { ok: extra.length === 0, findings: extra };
-        },
+        run: async (context) => fromFindings(await hostFindings(context, 'boundaries')),
       },
     ];
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/cli/src/cmd-verify.test.ts` around lines 108 - 128, Update the test
step in “a host check adds findings to the step it was registered for” to call
the hostFindings helper from verify-step.ts instead of directly invoking
context.hostChecks.boundaries. Preserve the existing boundary host-check stub
and assertions so the test verifies that runVerify propagates findings produced
through hostFindings.
packages/cli/src/verify-tests.test.ts (1)

64-78: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

The test binds itself to the real repository root instead of a fixture. Both findings in this file come from one root cause: REPO_ROOT is derived from import.meta.url and the positive assertions read the repository's own file inventory. A self-contained fixture directory removes the coupling and removes the need for REPO_ROOT at all.

  • packages/cli/src/verify-tests.test.ts#L64-L78: create a second temporary directory containing app/pay.contract.test.ts and e2e/checkout.test.ts, assert applies('contract', …) and applies('e2e', …) are true against it, and remove the two REPO_ROOT assertions.
  • packages/cli/src/verify-tests.test.ts#L8-L8: delete the REPO_ROOT constant once the fixture covers both branches. If any use remains, convert the file URL with fileURLToPath instead of reading .pathname.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/cli/src/verify-tests.test.ts` around lines 64 - 78, Make the test
self-contained by extending the temporary fixture in the test named “a type with
no suites here is skipped, never silently passed” with app/pay.contract.test.ts
and e2e/checkout.test.ts, assert both contract and e2e applies results against
that fixture, and remove the REPO_ROOT assertions. Delete the REPO_ROOT constant
near the file setup; no direct change is needed elsewhere.
scripts/verify.ts (2)

2-8: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Shorten the file header.

The header has more than four lines. Keep one concise responsibility-and-rationale comment. Move invocation detail to command help or documentation.

As per coding guidelines, “Keep file headers/comments concise: 1–4 lines stating the file's single responsibility, and comments should explain why, not what.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/verify.ts` around lines 2 - 8, Shorten the header comment in
scripts/verify.ts to a single concise 1–4 line statement explaining the file’s
responsibility and rationale. Remove the detailed implementation description and
command invocation example, leaving usage guidance to command help or
documentation.

Source: Coding guidelines


47-48: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use Bun-native APIs, or document each required Node compatibility use.

The new runtime script uses process. The new tests import node: modules. Replace these uses with Bun APIs where available. If a Node API is necessary, add a concise comment that states why Bun has no suitable alternative.

  • scripts/verify.ts#L47-L48: replace process.stdout.write and process.exit, or document the compatibility requirement.
  • scripts/verify.test.ts#L2-L4: document why temporary-directory and cleanup operations require node: APIs.
  • packages/cli/src/workspace-checks.test.ts#L2-L4: document why temporary-directory and cleanup operations require node: APIs.

Based on learnings, “Use Bun only; avoid Node-specific APIs unless unavoidable via node: and documented with a comment explaining why.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/verify.ts` around lines 47 - 48, Use Bun-native output and exit APIs
in scripts/verify.ts at the render/result handling flow, replacing
process.stdout.write and process.exit. In scripts/verify.test.ts lines 2-4 and
packages/cli/src/workspace-checks.test.ts lines 2-4, retain the node:
temporary-directory and cleanup imports only if necessary, and add concise
comments explaining why Bun lacks suitable alternatives.

Source: Learnings

packages/cli/src/errors.ts (1)

51-51: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Route new CLI output text through the translator.

These new literals are visible in CLI help or findings. Use stable translation keys and the project translator.

  • packages/cli/src/errors.ts#L51-L51: translate the X_VERIFY_FAILED fix text.
  • packages/cli/src/cmd-build.ts#L84-L84: translate the non-Docker build failure fix text.
  • scripts/verify.ts#L27-L31: translate the manifest finding cause and fix text.
  • scripts/help.ts#L21-L21: translate the verify help description.

As per coding guidelines, “Do not hardcode user-facing strings; route them through t().”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/cli/src/errors.ts` at line 51, Route all specified user-facing
literals through the project translator using stable translation keys and t():
update the X_VERIFY_FAILED fix text in packages/cli/src/errors.ts:51, the
non-Docker build failure fix text in packages/cli/src/cmd-build.ts:84, the
manifest finding cause and fix text in scripts/verify.ts:27-31, and the verify
help description in scripts/help.ts:21. Preserve the existing messages while
removing their hardcoded user-facing forms.

Source: Coding guidelines

packages/testing/src/fixtures.ts (1)

22-33: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Shorten this interface comment.

Lines 22-33 contain a 12-line usage example. Keep the contract comment to 1–4 lines. Move the augmentation example to the package README.

As per coding guidelines, “Keep file headers/comments concise: 1–4 lines.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/testing/src/fixtures.ts` around lines 22 - 33, Shorten the
`Fixtures` interface comment in `packages/testing/src/fixtures.ts` so it stays
within 1–4 lines and keeps only the contract summary; remove the inline
module-augmentation example from this comment. Preserve the key description on
what a test body receives and how apps extend `Fixtures`, and move the longer
`declare module '`@ultimat3/testing`'` usage example to the package README
instead.

Source: Coding guidelines

packages/testing/src/fixture-jobs.ts (1)

1-6: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Shorten the file headers.

Keep each header to a 1–4 line responsibility statement. Move detailed rationale next to the non-obvious behavior it explains.

  • packages/testing/src/fixture-jobs.ts#L1-L6: Reduce the worker-fixture header to its responsibility.
  • packages/testing/src/framework-fixtures.ts#L1-L7: Reduce the framework-registration header to its responsibility.
  • packages/testing/src/preload.ts#L1-L6: Reduce the preload header to its responsibility.
  • scripts/test-setup.ts#L2-L6: Reduce the root test-setup header to its responsibility.

As per coding guidelines: “Keep file headers/comments concise: 1–4 lines stating the file's single responsibility.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/testing/src/fixture-jobs.ts` around lines 1 - 6, Shorten the file
headers to concise 1–4 line responsibility statements: in
packages/testing/src/fixture-jobs.ts lines 1-6 describe the job fixture’s
responsibility; in packages/testing/src/framework-fixtures.ts lines 1-7 describe
framework fixture registration; in packages/testing/src/preload.ts lines 1-6
describe preload setup; and in scripts/test-setup.ts lines 2-6 describe root
test setup. Move detailed rationale to the nearby non-obvious behavior it
explains.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Line 116: Update the actions/checkout step in the CI workflow to disable
credential persistence by setting persist-credentials to false on the checkout
action. Keep the existing checkout behavior otherwise unchanged, and apply the
change to the checkout step used in the pull_request job so checked-out code
cannot access the stored GITHUB_TOKEN.

In `@packages/cli/src/workspace-checks.ts`:
- Around line 41-53: Update the line-count calculation in checkFileSizes so a
terminal newline does not create an extra empty line; count content lines
according to the documented 500-line ceiling, while preserving the existing
tooLongFinding behavior and file scanning logic.

In `@packages/testing/src/fixture-jobs.ts`:
- Around line 75-79: Add a jobs-package reset function that clears the
module-level driver set by setJobDriver, then register it in the fixture’s
afterEach cleanup alongside resetMailDriver. Update createRunJobs and related
imports as needed so each test starts without the previous ambient job driver.

In `@packages/testing/src/framework-fixtures.test.ts`:
- Around line 40-56: Update every bunTest and fixtureTest declaration in this
file, including the tests around the shown sections and ranges 61-80 and 99-156,
to wrap its literal name with testName('unit', '<name>'). Preserve each existing
test name and body while ensuring all declarations use the required prefixed
naming format.

In `@packages/testing/src/sealed-network.test.ts`:
- Line 61: Update the new test declaration in sealed-network.test.ts to wrap its
test name with testName(type, name), preserving the existing test description
while ensuring x verify filtering remains stable.

In `@wiki/CLI-Reference.md`:
- Around line 160-164: Update the verify command JSON example to remove the
skipped:false property from the executed budgets step, preserving skipped only
for steps that do not apply as described by runVerify.

---

Outside diff comments:
In `@packages/testing/src/fixtures.ts`:
- Around line 93-106: Update fixtureTest and requestedFixtures so fixture
dependencies are not inferred from Function.prototype.toString() or source-text
parsing. Change the API to accept an explicit fixture list and use it to
populate the bag, or consistently construct every entry from
registeredFixtures() before invoking the body; ensure callbacks such as
fixtures.clock.now() receive a defined clock fixture.

---

Nitpick comments:
In `@packages/cli/src/cmd-verify.test.ts`:
- Around line 108-128: Update the test step in “a host check adds findings to
the step it was registered for” to call the hostFindings helper from
verify-step.ts instead of directly invoking context.hostChecks.boundaries.
Preserve the existing boundary host-check stub and assertions so the test
verifies that runVerify propagates findings produced through hostFindings.

In `@packages/cli/src/errors.ts`:
- Line 51: Route all specified user-facing literals through the project
translator using stable translation keys and t(): update the X_VERIFY_FAILED fix
text in packages/cli/src/errors.ts:51, the non-Docker build failure fix text in
packages/cli/src/cmd-build.ts:84, the manifest finding cause and fix text in
scripts/verify.ts:27-31, and the verify help description in scripts/help.ts:21.
Preserve the existing messages while removing their hardcoded user-facing forms.

In `@packages/cli/src/verify-tests.test.ts`:
- Around line 64-78: Make the test self-contained by extending the temporary
fixture in the test named “a type with no suites here is skipped, never silently
passed” with app/pay.contract.test.ts and e2e/checkout.test.ts, assert both
contract and e2e applies results against that fixture, and remove the REPO_ROOT
assertions. Delete the REPO_ROOT constant near the file setup; no direct change
is needed elsewhere.

In `@packages/cli/src/verify-tests.ts`:
- Around line 39-43: The e2e filter in the e2e configuration matches any path
containing “e2e”, overlapping with the unit step. Update the filter to use the
same anchored path patterns represented by the e2e applies globs, ensuring files
such as e2e-utils.test.ts are selected only by the intended step.

In `@packages/testing/src/fixture-jobs.ts`:
- Around line 1-6: Shorten the file headers to concise 1–4 line responsibility
statements: in packages/testing/src/fixture-jobs.ts lines 1-6 describe the job
fixture’s responsibility; in packages/testing/src/framework-fixtures.ts lines
1-7 describe framework fixture registration; in packages/testing/src/preload.ts
lines 1-6 describe preload setup; and in scripts/test-setup.ts lines 2-6
describe root test setup. Move detailed rationale to the nearby non-obvious
behavior it explains.

In `@packages/testing/src/fixtures.ts`:
- Around line 22-33: Shorten the `Fixtures` interface comment in
`packages/testing/src/fixtures.ts` so it stays within 1–4 lines and keeps only
the contract summary; remove the inline module-augmentation example from this
comment. Preserve the key description on what a test body receives and how apps
extend `Fixtures`, and move the longer `declare module '`@ultimat3/testing`'`
usage example to the package README instead.

In `@packages/testing/src/sealed-network.test.ts`:
- Around line 13-17: Update the refusalOf helper to validate the rejected value
with isUltimateError() before accessing or returning its code; preserve
undefined for successful requests and unrecognized rejection values.

In `@scripts/verify.ts`:
- Around line 2-8: Shorten the header comment in scripts/verify.ts to a single
concise 1–4 line statement explaining the file’s responsibility and rationale.
Remove the detailed implementation description and command invocation example,
leaving usage guidance to command help or documentation.
- Around line 47-48: Use Bun-native output and exit APIs in scripts/verify.ts at
the render/result handling flow, replacing process.stdout.write and
process.exit. In scripts/verify.test.ts lines 2-4 and
packages/cli/src/workspace-checks.test.ts lines 2-4, retain the node:
temporary-directory and cleanup imports only if necessary, and add concise
comments explaining why Bun lacks suitable alternatives.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 4771a31e-1153-493d-859e-eedf2098f27d

📥 Commits

Reviewing files that changed from the base of the PR and between e809169 and e42805c.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (57)
  • .github/workflows/ci.yml
  • CLAUDE.md
  • CONTRIBUTING.md
  • bunfig.toml
  • docs/architecture/14-testing-internals.md
  • docs/architecture/README.md
  • examples/dummy/CLAUDE.md
  • examples/dummy/bunfig.toml
  • examples/dummy/scripts/test-setup.ts
  • examples/dummy/tsconfig.json
  • package.json
  • packages/cli/README.md
  • packages/cli/src/cmd-build.ts
  • packages/cli/src/cmd-verify.test.ts
  • packages/cli/src/cmd-verify.ts
  • packages/cli/src/errors.ts
  • packages/cli/src/index.ts
  • packages/cli/src/surfaces.ts
  • packages/cli/src/verify-step.ts
  • packages/cli/src/verify-tests.test.ts
  • packages/cli/src/verify-tests.ts
  • packages/cli/src/workspace-checks.test.ts
  • packages/cli/src/workspace-checks.ts
  • packages/core/CLAUDE.md
  • packages/core/README.md
  • packages/core/src/index.ts
  • packages/core/src/listeners.test.ts
  • packages/core/src/listeners.ts
  • packages/http/CLAUDE.md
  • packages/http/e2e/server.e2e.test.ts
  • packages/http/src/server.ts
  • packages/realtime/src/sync-node.ts
  • packages/testing/CLAUDE.md
  • packages/testing/README.md
  • packages/testing/package.json
  • packages/testing/src/fixture-clock.ts
  • packages/testing/src/fixture-jobs.ts
  • packages/testing/src/fixture-mail.ts
  • packages/testing/src/fixtures.test.ts
  • packages/testing/src/fixtures.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/framework-fixtures.ts
  • packages/testing/src/index.ts
  • packages/testing/src/preload.ts
  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/sealed-network.ts
  • packages/testing/tsconfig.json
  • packages/ui/src/index.ts
  • scripts/help.ts
  • scripts/lib/steps.ts
  • scripts/test-setup.ts
  • scripts/verify.test.ts
  • scripts/verify.ts
  • tsconfig.json
  • wiki/CLI-Reference.md
  • wiki/Error-Codes.md
  • wiki/Policies-And-Authz.md
💤 Files with no reviewable changes (1)
  • scripts/lib/steps.ts
📜 Review details
⚠️ CI failures not shown inline (6)

GitHub Actions: ci / 5_test.txt: ci: gate integrity — stop hiding failing suites, gate the app too

Conclusion: failure

View job details

##[group]packages/mail/src/mail.test.ts:
 (pass) send without a locale throws X_MAIL_LOCALE_MISSING [1.05ms]
 (pass) send with an empty locale throws X_MAIL_LOCALE_MISSING [0.12ms]
 73 | });
 74 |
 75 | test('a valid locale renders both parts and reaches the memory driver', async () => {
 76 |   const result = await send(basicMail, { name: 'Ada' }, { to: 'ada@example.test', locale: 'en' });
 77 |
 78 |   expect(result.driver).toBe('memory');
                              ^
 error: expect(received).toBe(expected)
 Expected: "memory"
 Received: "queue"
       at <anonymous> (/home/runner/work/ultimate/ultimate/packages/mail/src/mail.test.ts:78:25)
 ##[error]Expected: "memory"

GitHub Actions: ci / 1_reference-app-verify.txt: ci: gate integrity — stop hiding failing suites, gate the app too

Conclusion: failure

View job details

##[group]Run bun run ../../packages/cli/src/bin.ts verify --json
 �[36;1mbun run ../../packages/cli/src/bin.ts verify --json�[0m
 shell: /usr/bin/bash -e {0}
 env:
   ULTIMATE_TEST_SEED: 20260101
 ##[endgroup]
 {"ok":false,"command":"verify","summary":"8 of 15 steps failed","steps":[{"name":"typecheck","ok":false,"durationMs":885,"skipped":false,"findings":[{"code":"X_TYPECHECK_FAILED","cause":"the project does not typecheck","fix":"bunx tsc -b --pretty false","docs":"https://ultimate.dev/errors/X_TYPECHECK_FAILED"}]},{"name":"lint","ok":true,"durationMs":128,"skipped":false,"findings":[]},{"name":"boundaries","ok":true,"durationMs":9,"skipped":false,"findings":[]},{"name":"filesize","ok":true,"durationMs":6,"skipped":false,"findings":[]},{"name":"package-shape","ok":true,"durationMs":0,"skipped":false,"findings":[]},{"name":"unit","ok":true,"durationMs":74,"skipped":false,"findings":[]},{"name":"contract","ok":false,"durationMs":83,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more contract tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** .contract.test.","docs":"https://ultimate.dev/errors/X_TEST_FAILED"}]},{"name":"live","ok":false,"durationMs":72,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more live tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** .live.test.","docs":"https://ultimate.dev/errors/X_TEST_FAILED"}]},{"name":"job","ok":false,"durationMs":65,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more job tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** .job.test.","docs":"https://ultimate.dev/errors/X_TEST_FAILED"}]},{"name":"e2e","ok":false,"durationMs":41,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more e2e tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** e2e","docs":...

GitHub Actions: ci / reference-app-verify: ci: gate integrity — stop hiding failing suites, gate the app too

Conclusion: failure

View job details

##[group]Run bun run ../../packages/cli/src/bin.ts verify --json
 �[36;1mbun run ../../packages/cli/src/bin.ts verify --json�[0m
 shell: /usr/bin/bash -e {0}
 env:
   ULTIMATE_TEST_SEED: 20260101
 ##[endgroup]
 {"ok":false,"command":"verify","summary":"8 of 15 steps failed","steps":[{"name":"typecheck","ok":false,"durationMs":885,"skipped":false,"findings":[{"code":"X_TYPECHECK_FAILED","cause":"the project does not typecheck","fix":"bunx tsc -b --pretty false","docs":"https://ultimate.dev/errors/X_TYPECHECK_FAILED"}]},{"name":"lint","ok":true,"durationMs":128,"skipped":false,"findings":[]},{"name":"boundaries","ok":true,"durationMs":9,"skipped":false,"findings":[]},{"name":"filesize","ok":true,"durationMs":6,"skipped":false,"findings":[]},{"name":"package-shape","ok":true,"durationMs":0,"skipped":false,"findings":[]},{"name":"unit","ok":true,"durationMs":74,"skipped":false,"findings":[]},{"name":"contract","ok":false,"durationMs":83,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more contract tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** .contract.test.","docs":"https://ultimate.dev/errors/X_TEST_FAILED"}]},{"name":"live","ok":false,"durationMs":72,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more live tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** .live.test.","docs":"https://ultimate.dev/errors/X_TEST_FAILED"}]},{"name":"job","ok":false,"durationMs":65,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more job tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** .job.test.","docs":"https://ultimate.dev/errors/X_TEST_FAILED"}]},{"name":"e2e","ok":false,"durationMs":41,"skipped":false,"findings":[{"code":"X_TEST_FAILED","cause":"one or more e2e tests failed","fix":"bun test --path-ignore-patterns=**/dist/** --path-ignore-patterns=**/build/** e2e","docs":...

GitHub Actions: ci / test: ci: gate integrity — stop hiding failing suites, gate the app too

Conclusion: failure

View job details

##[group]packages/mail/src/mail.test.ts:
 (pass) send without a locale throws X_MAIL_LOCALE_MISSING [1.05ms]
 (pass) send with an empty locale throws X_MAIL_LOCALE_MISSING [0.12ms]
 73 | });
 74 |
 75 | test('a valid locale renders both parts and reaches the memory driver', async () => {
 76 |   const result = await send(basicMail, { name: 'Ada' }, { to: 'ada@example.test', locale: 'en' });
 77 |
 78 |   expect(result.driver).toBe('memory');
                              ^
 error: expect(received).toBe(expected)
 Expected: "memory"
 Received: "queue"
       at <anonymous> (/home/runner/work/ultimate/ultimate/packages/mail/src/mail.test.ts:78:25)
 ##[error]Expected: "memory"

GitHub Actions: ci / typecheck: ci: gate integrity — stop hiding failing suites, gate the app too

Conclusion: failure

View job details

ummy/apps/web/app/settings.tsx�[0m:�[93m26�[0m:�[93m30�[0m - �[91merror�[0m�[90m TS18046: �[0m't' is of type 'unknown'.
 �[7m26�[0m   meta: ({ t }) => ({ title: t('app.settings.metaTitle'), robots: 'noindex' }),
 �[7m  �[0m �[91m                             ~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m26�[0m:�[93m59�[0m - �[91merror�[0m�[90m TS2559: �[0mType 'string' has no properties in common with type 'RobotsDirectives'.
 �[7m26�[0m   meta: ({ t }) => ({ title: t('app.settings.metaTitle'), robots: 'noindex' }),
 �[7m  �[0m �[91m                                                          ~~~~~~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m51�[0m:�[93m14�[0m - �[91merror�[0m�[90m TS2322: �[0mType 'string' is not assignable to type 'SpaceStep | undefined'.
 �[7m51�[0m       <Stack gap="6" class={styles.page}>
 �[7m  �[0m �[91m             ~~~�[0m
   �[96mpackages/ui/src/components/Stack.tsx�[0m:�[93m13�[0m:�[93m3�[0m - The expected type comes from property 'gap' which is declared here on type 'IntrinsicAttributes & StackProps'
     �[7m13�[0m   gap?: SpaceStep | undefined;
     �[7m  �[0m �[96m  ~~~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m58�[0m:�[93m11�[0m - �[91merror�[0m�[90m TS2322: �[0mType '{ label: any; hint: any; value: any; onChange: Setter<any>; children: Element; }' is not assignable to type 'IntrinsicAttributes & SelectProps'.
   Property 'label' does not exist on type 'IntrinsicAttributes & SelectProps'.
 �[7m58�[0m           label={t('app.settings.localeLabel')}
 �[7m  �[0m �[91m          ~~~~~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m63�[0m:�[93m67�[0m - �[91merror�[0m�[90m TS2322: �[0mType 'Accessor<"en" | "es">' is not assignable to type 'string | number | string[] | RemoveAttribute'.
 �[7m63�[0m           <For each={SUPPORTED_LOCALES}>{(value) => <option value={value}>{value}</option>}</For>
 �[7m  �[0m �[91m                                                                  ~~~~...

GitHub Actions: ci / 2_typecheck.txt: ci: gate integrity — stop hiding failing suites, gate the app too

Conclusion: failure

View job details

ummy/apps/web/app/settings.tsx�[0m:�[93m26�[0m:�[93m30�[0m - �[91merror�[0m�[90m TS18046: �[0m't' is of type 'unknown'.
 �[7m26�[0m   meta: ({ t }) => ({ title: t('app.settings.metaTitle'), robots: 'noindex' }),
 �[7m  �[0m �[91m                             ~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m26�[0m:�[93m59�[0m - �[91merror�[0m�[90m TS2559: �[0mType 'string' has no properties in common with type 'RobotsDirectives'.
 �[7m26�[0m   meta: ({ t }) => ({ title: t('app.settings.metaTitle'), robots: 'noindex' }),
 �[7m  �[0m �[91m                                                          ~~~~~~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m51�[0m:�[93m14�[0m - �[91merror�[0m�[90m TS2322: �[0mType 'string' is not assignable to type 'SpaceStep | undefined'.
 �[7m51�[0m       <Stack gap="6" class={styles.page}>
 �[7m  �[0m �[91m             ~~~�[0m
   �[96mpackages/ui/src/components/Stack.tsx�[0m:�[93m13�[0m:�[93m3�[0m - The expected type comes from property 'gap' which is declared here on type 'IntrinsicAttributes & StackProps'
     �[7m13�[0m   gap?: SpaceStep | undefined;
     �[7m  �[0m �[96m  ~~~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m58�[0m:�[93m11�[0m - �[91merror�[0m�[90m TS2322: �[0mType '{ label: any; hint: any; value: any; onChange: Setter<any>; children: Element; }' is not assignable to type 'IntrinsicAttributes & SelectProps'.
   Property 'label' does not exist on type 'IntrinsicAttributes & SelectProps'.
 �[7m58�[0m           label={t('app.settings.localeLabel')}
 �[7m  �[0m �[91m          ~~~~~�[0m
 �[96mexamples/dummy/apps/web/app/settings.tsx�[0m:�[93m63�[0m:�[93m67�[0m - �[91merror�[0m�[90m TS2322: �[0mType 'Accessor<"en" | "es">' is not assignable to type 'string | number | string[] | RemoveAttribute'.
 �[7m63�[0m           <For each={SUPPORTED_LOCALES}>{(value) => <option value={value}>{value}</option>}</For>
 �[7m  �[0m �[91m                                                                  ~~~~...
🧰 Additional context used
📓 Path-based instructions (19)
**/{*.ts,*.md}

📄 CodeRabbit inference engine (CLAUDE.md)

Use kebab-case file names for source files, and keep the file's responsibility narrow.

Files:

  • docs/architecture/14-testing-internals.md
  • examples/dummy/CLAUDE.md
  • packages/testing/CLAUDE.md
  • examples/dummy/scripts/test-setup.ts
  • packages/core/src/index.ts
  • packages/core/CLAUDE.md
  • packages/testing/src/sealed-network.ts
  • packages/core/README.md
  • packages/cli/src/surfaces.ts
  • packages/http/e2e/server.e2e.test.ts
  • scripts/test-setup.ts
  • docs/architecture/README.md
  • CLAUDE.md
  • packages/cli/src/verify-step.ts
  • wiki/Policies-And-Authz.md
  • CONTRIBUTING.md
  • packages/cli/README.md
  • packages/testing/src/fixtures.ts
  • scripts/verify.test.ts
  • packages/testing/src/preload.ts
  • packages/http/CLAUDE.md
  • packages/http/src/server.ts
  • packages/cli/src/errors.ts
  • packages/testing/src/index.ts
  • packages/testing/src/sealed-network.test.ts
  • wiki/CLI-Reference.md
  • packages/testing/src/fixtures.test.ts
  • packages/cli/src/verify-tests.test.ts
  • scripts/verify.ts
  • packages/cli/src/index.ts
  • packages/ui/src/index.ts
  • packages/testing/src/fixture-mail.ts
  • packages/cli/src/verify-tests.ts
  • packages/testing/src/framework-fixtures.ts
  • packages/realtime/src/sync-node.ts
  • packages/core/src/listeners.ts
  • packages/cli/src/cmd-verify.ts
  • packages/cli/src/workspace-checks.ts
  • packages/core/src/listeners.test.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/fixture-jobs.ts
  • packages/cli/src/cmd-build.ts
  • packages/testing/src/fixture-clock.ts
  • packages/testing/README.md
  • scripts/help.ts
  • packages/cli/src/workspace-checks.test.ts
  • wiki/Error-Codes.md
  • packages/cli/src/cmd-verify.test.ts
**/*.{ts,tsx,md}

📄 CodeRabbit inference engine (CLAUDE.md)

Keep file headers/comments concise: 1–4 lines stating the file's single responsibility, and comments should explain why, not what.

Files:

  • docs/architecture/14-testing-internals.md
  • examples/dummy/CLAUDE.md
  • packages/testing/CLAUDE.md
  • examples/dummy/scripts/test-setup.ts
  • packages/core/src/index.ts
  • packages/core/CLAUDE.md
  • packages/testing/src/sealed-network.ts
  • packages/core/README.md
  • packages/cli/src/surfaces.ts
  • packages/http/e2e/server.e2e.test.ts
  • scripts/test-setup.ts
  • docs/architecture/README.md
  • CLAUDE.md
  • packages/cli/src/verify-step.ts
  • wiki/Policies-And-Authz.md
  • CONTRIBUTING.md
  • packages/cli/README.md
  • packages/testing/src/fixtures.ts
  • scripts/verify.test.ts
  • packages/testing/src/preload.ts
  • packages/http/CLAUDE.md
  • packages/http/src/server.ts
  • packages/cli/src/errors.ts
  • packages/testing/src/index.ts
  • packages/testing/src/sealed-network.test.ts
  • wiki/CLI-Reference.md
  • packages/testing/src/fixtures.test.ts
  • packages/cli/src/verify-tests.test.ts
  • scripts/verify.ts
  • packages/cli/src/index.ts
  • packages/ui/src/index.ts
  • packages/testing/src/fixture-mail.ts
  • packages/cli/src/verify-tests.ts
  • packages/testing/src/framework-fixtures.ts
  • packages/realtime/src/sync-node.ts
  • packages/core/src/listeners.ts
  • packages/cli/src/cmd-verify.ts
  • packages/cli/src/workspace-checks.ts
  • packages/core/src/listeners.test.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/fixture-jobs.ts
  • packages/cli/src/cmd-build.ts
  • packages/testing/src/fixture-clock.ts
  • packages/testing/README.md
  • scripts/help.ts
  • packages/cli/src/workspace-checks.test.ts
  • wiki/Error-Codes.md
  • packages/cli/src/cmd-verify.test.ts
**/*.md

📄 CodeRabbit inference engine (CLAUDE.md)

Docs should lead with the rule, prefer fragments over sentences, use tables for structures with three or more rows, avoid meta-framing and trailing summaries, and mark load-bearing date claims with As of 2026-07.

Files:

  • docs/architecture/14-testing-internals.md
  • examples/dummy/CLAUDE.md
  • packages/testing/CLAUDE.md
  • packages/core/CLAUDE.md
  • packages/core/README.md
  • docs/architecture/README.md
  • CLAUDE.md
  • wiki/Policies-And-Authz.md
  • CONTRIBUTING.md
  • packages/cli/README.md
  • packages/http/CLAUDE.md
  • wiki/CLI-Reference.md
  • packages/testing/README.md
  • wiki/Error-Codes.md
**/*.{ts,tsx}

📄 CodeRabbit inference engine (CLAUDE.md)

**/*.{ts,tsx}: Do not use any; use unknown plus schema parsing instead.
Never throw a bare Error; throw a subclass of UltimateError with a stable code, a cause, and an executable fix:.
Prefer named exports only; do not use default exports.
Use import type and export type for type-only imports and exports.
Never format dates without an explicit IANA timeZone; do not rely on ambient defaults.
Represent money as Money = { minor: number; currency: string }; never use float money.

Files:

  • examples/dummy/scripts/test-setup.ts
  • packages/core/src/index.ts
  • packages/testing/src/sealed-network.ts
  • packages/cli/src/surfaces.ts
  • packages/http/e2e/server.e2e.test.ts
  • scripts/test-setup.ts
  • packages/cli/src/verify-step.ts
  • packages/testing/src/fixtures.ts
  • scripts/verify.test.ts
  • packages/testing/src/preload.ts
  • packages/http/src/server.ts
  • packages/cli/src/errors.ts
  • packages/testing/src/index.ts
  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/fixtures.test.ts
  • packages/cli/src/verify-tests.test.ts
  • scripts/verify.ts
  • packages/cli/src/index.ts
  • packages/ui/src/index.ts
  • packages/testing/src/fixture-mail.ts
  • packages/cli/src/verify-tests.ts
  • packages/testing/src/framework-fixtures.ts
  • packages/realtime/src/sync-node.ts
  • packages/core/src/listeners.ts
  • packages/cli/src/cmd-verify.ts
  • packages/cli/src/workspace-checks.ts
  • packages/core/src/listeners.test.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/fixture-jobs.ts
  • packages/cli/src/cmd-build.ts
  • packages/testing/src/fixture-clock.ts
  • scripts/help.ts
  • packages/cli/src/workspace-checks.test.ts
  • packages/cli/src/cmd-verify.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CLAUDE.md)

**/*.{ts,tsx,js,jsx}: Every CLI command and every error output must support --json.
Do not hardcode user-facing strings; route them through t().

Files:

  • examples/dummy/scripts/test-setup.ts
  • packages/core/src/index.ts
  • packages/testing/src/sealed-network.ts
  • packages/cli/src/surfaces.ts
  • packages/http/e2e/server.e2e.test.ts
  • scripts/test-setup.ts
  • packages/cli/src/verify-step.ts
  • packages/testing/src/fixtures.ts
  • scripts/verify.test.ts
  • packages/testing/src/preload.ts
  • packages/http/src/server.ts
  • packages/cli/src/errors.ts
  • packages/testing/src/index.ts
  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/fixtures.test.ts
  • packages/cli/src/verify-tests.test.ts
  • scripts/verify.ts
  • packages/cli/src/index.ts
  • packages/ui/src/index.ts
  • packages/testing/src/fixture-mail.ts
  • packages/cli/src/verify-tests.ts
  • packages/testing/src/framework-fixtures.ts
  • packages/realtime/src/sync-node.ts
  • packages/core/src/listeners.ts
  • packages/cli/src/cmd-verify.ts
  • packages/cli/src/workspace-checks.ts
  • packages/core/src/listeners.test.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/fixture-jobs.ts
  • packages/cli/src/cmd-build.ts
  • packages/testing/src/fixture-clock.ts
  • scripts/help.ts
  • packages/cli/src/workspace-checks.test.ts
  • packages/cli/src/cmd-verify.test.ts
**/*.{ts,tsx,css,scss}

📄 CodeRabbit inference engine (CLAUDE.md)

Do not use raw colors; use semantic tokens only in every component and stylesheet.

Files:

  • examples/dummy/scripts/test-setup.ts
  • packages/core/src/index.ts
  • packages/testing/src/sealed-network.ts
  • packages/cli/src/surfaces.ts
  • packages/http/e2e/server.e2e.test.ts
  • scripts/test-setup.ts
  • packages/cli/src/verify-step.ts
  • packages/testing/src/fixtures.ts
  • scripts/verify.test.ts
  • packages/testing/src/preload.ts
  • packages/http/src/server.ts
  • packages/cli/src/errors.ts
  • packages/testing/src/index.ts
  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/fixtures.test.ts
  • packages/cli/src/verify-tests.test.ts
  • scripts/verify.ts
  • packages/cli/src/index.ts
  • packages/ui/src/index.ts
  • packages/testing/src/fixture-mail.ts
  • packages/cli/src/verify-tests.ts
  • packages/testing/src/framework-fixtures.ts
  • packages/realtime/src/sync-node.ts
  • packages/core/src/listeners.ts
  • packages/cli/src/cmd-verify.ts
  • packages/cli/src/workspace-checks.ts
  • packages/core/src/listeners.test.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/testing/src/fixture-jobs.ts
  • packages/cli/src/cmd-build.ts
  • packages/testing/src/fixture-clock.ts
  • scripts/help.ts
  • packages/cli/src/workspace-checks.test.ts
  • packages/cli/src/cmd-verify.test.ts
examples/dummy/**/*.{ts,tsx}

📄 CodeRabbit inference engine (examples/dummy/CLAUDE.md)

examples/dummy/**/*.{ts,tsx}: Authorization must have one definition and must not be duplicated inside request handlers.
Use ArkType t from @ultimat3/schema in schema, entity, and action files; use the i18n translator from useI18n() in components; never use both meanings in one file.
Represent money as { minor, currency }; perform arithmetic in packages/core/src/billing.ts and format only through <Money> at the edge.
User-facing strings must use t('<feature>.<key>'); do not hard-code user-facing text.
Plan prices are stored as per-currency catalog rows; currencies must never be converted at runtime.

Files:

  • examples/dummy/scripts/test-setup.ts
examples/dummy/**/*.{tsx,ts}

📄 CodeRabbit inference engine (examples/dummy/CLAUDE.md)

Store dates as UTC instants in the database and render them only through <DateTime zone={member.tz}>.

Files:

  • examples/dummy/scripts/test-setup.ts
**/src/index.ts

📄 CodeRabbit inference engine (CLAUDE.md)

Re-export the public API explicitly from src/index.ts; do not use blind export *.

Files:

  • packages/core/src/index.ts
  • packages/testing/src/index.ts
  • packages/cli/src/index.ts
  • packages/ui/src/index.ts
packages/core/**/*.ts

📄 CodeRabbit inference engine (packages/core/CLAUDE.md)

packages/core/**/*.ts: The @ultimat3/core package must not import any @ultimat3/* package.
Core dependencies must be limited to bun-types.
Errors must subclass UltimateError; never throw new Error.

Files:

  • packages/core/src/index.ts
  • packages/core/src/listeners.ts
  • packages/core/src/listeners.test.ts
packages/core/src/**/*.ts

📄 CodeRabbit inference engine (packages/core/CLAUDE.md)

packages/core/src/**/*.ts: Time-dependent code must take a Clock; use Date.now() and new Date() only inside clock.ts.
Do not thread ctx as a parameter; obtain context with useContext().
Keep files under 200 lines, give each file one responsibility, and use kebab-case.ts filenames.
Because exactOptionalPropertyTypes is enabled, declare optional fields as x?: T | undefined.
With noPropertyAccessFromIndexSignature enabled, access indexed context services as ctx.services['mail'], not ctx.services.mail.
Ctx must retain its string index signature so applications can augment CtxServices and access services such as ctx.posts.
Code that opens a socket must call markListening(server.url.origin) and release it when the socket closes.

Files:

  • packages/core/src/index.ts
  • packages/core/src/listeners.ts
  • packages/core/src/listeners.test.ts
packages/core/src/index.ts

📄 CodeRabbit inference engine (packages/core/CLAUDE.md)

Add public exports explicitly to src/index.ts; never use export *.

Files:

  • packages/core/src/index.ts
**/*.test.ts

📄 CodeRabbit inference engine (CLAUDE.md)

Keep tests next to the source file as <file>.test.ts. A test must be able to fail.

Files:

  • packages/http/e2e/server.e2e.test.ts
  • scripts/verify.test.ts
  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/fixtures.test.ts
  • packages/cli/src/verify-tests.test.ts
  • packages/core/src/listeners.test.ts
  • packages/testing/src/framework-fixtures.test.ts
  • packages/cli/src/workspace-checks.test.ts
  • packages/cli/src/cmd-verify.test.ts
packages/http/**/*.ts

📄 CodeRabbit inference engine (packages/http/CLAUDE.md)

packages/http/**/*.ts: The @ultimat3/http package may import only @ultimat3/core and @ultimat3/schema; it must never import @ultimat3/policy, @ultimat3/entity, or higher-tier packages such as @ultimat3/action.
Route metadata must always include meta.auth; routes must never default to public access.
Never throw a bare Error; use an error factory from errors.ts.
Do not use any; validation must go through Standard Schema via validate.ts, not a vendor-specific API.
Health endpoints must answer outside the request pipeline.
Borrowed error codes such as X_FORBIDDEN and X_UNAUTHENTICATED must remain in HTTP_BORROWED_CODES and must not be re-registered through registerErrorCodes.

Files:

  • packages/http/e2e/server.e2e.test.ts
  • packages/http/src/server.ts
packages/http/**/*.test.ts

📄 CodeRabbit inference engine (packages/http/CLAUDE.md)

Unit and integration tests must not touch the network; the fetch preload remains sealed and must never be unsealed.

Files:

  • packages/http/e2e/server.e2e.test.ts
packages/http/e2e/**/*.ts

📄 CodeRabbit inference engine (packages/http/CLAUDE.md)

Socket tests belong in e2e/ and run with bun test packages/http/e2e; they must keep the network seal enabled, with start() using core's markListening() so the package's own port is treated as self.

Files:

  • packages/http/e2e/server.e2e.test.ts
packages/testing/**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (packages/testing/CLAUDE.md)

packages/testing/**/*.{test,spec}.{ts,tsx}: Do not mock the database; clone a template database, and use template-db.ts as the only database access path in tests.
Do not use the wall clock in tests; use frozenClock and advanceClock. Date.now() is frozen by the preload.
Do not make unmocked egress calls; rely on sealed-network.ts, where network misses fail with X_TEST_NETWORK_SEALED.
Treat the test process as network-sealed even for socket tests; a port core's markListening() announcement passes through without unsealing the socket.
Do not add retries such as retry: 3; fix or delete a flaky test on the day it flakes.
Always name tests through testName(type, name) so x verify can filter them.
Pass SqlRunner and connect as parameters so unit tests do not require a server.

Files:

  • packages/testing/src/sealed-network.test.ts
  • packages/testing/src/fixtures.test.ts
  • packages/testing/src/framework-fixtures.test.ts
packages/core/src/**/*.test.ts

📄 CodeRabbit inference engine (packages/core/CLAUDE.md)

Place tests beside the source they test.

Files:

  • packages/core/src/listeners.test.ts
packages/core/**/*.test.ts

📄 CodeRabbit inference engine (packages/core/CLAUDE.md)

Tests touching the registry, lifecycle, or listener table must call resetErrorCodes(), resetLifecycle(), or resetListeners() respectively.

Files:

  • packages/core/src/listeners.test.ts
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:30:49.121Z
Learning: Follow the repo's design axioms: one way to do each thing, define once/project everywhere, enforce conventions in build errors, return actionable errors, keep `x verify` as the shippable gate, keep static and app bundles separate, and use containers only for deployability.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:30:49.121Z
Learning: Use Bun only; avoid Node-specific APIs unless unavoidable via `node:` and documented with a comment explaining why.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:30:49.121Z
Learning: Do not add new dependencies unless there is a strong reason stated in the PR.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:30:49.121Z
Learning: Every package must include a `README.md` describing the public API and a `CLAUDE.md` covering boundaries, dependencies, and commands.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:30:49.121Z
Learning: Use free GitHub Actions runners only; CI must stay under five minutes, and releases must use npm OIDC trusted publishing with no `NPM_TOKEN`.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:30:49.121Z
Learning: Do not use git worktrees; if work is large enough to need subagents, split it into disjoint work in the same checkout.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:31:20.581Z
Learning: The package owns the request lifecycle over `Bun.serve` and is Tier 2.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:31:29.394Z
Learning: The testing package may import tiers 0–4, is imported by every package's tests and generated apps, and must dynamically import `time`, `jobs`, and `mail` only inside fixture factories.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:31:29.394Z
Learning: The package exposes `.` as its API entry point and `./preload` for Bun configuration side effects.
Learnt from: CR
Repo: developerz-ai/ultimate

Timestamp: 2026-08-05T15:31:29.394Z
Learning: Use `bun test` and `bunx tsc --noEmit -p tsconfig.json` to run the test suite and TypeScript validation.
🪛 zizmor (1.29.0)
.github/workflows/ci.yml

[warning] 116-116: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

Comment thread .github/workflows/ci.yml
Comment thread packages/cli/src/workspace-checks.ts
Comment thread packages/testing/src/fixture-jobs.ts
Comment thread packages/testing/src/framework-fixtures.test.ts
Comment thread packages/testing/src/sealed-network.test.ts
Comment thread wiki/CLI-Reference.md
sebyx07 and others added 4 commits August 5, 2026 11:00
The `typecheck` and `test` jobs collected `examples/dummy`, whose sources
target API the framework has not shipped yet — the fluent `action` surface,
`defineMail`/`defineService`, the `page`/`subscribe`/`evaluate` fixtures.
That was 449 typecheck errors and 13 test failures on every PR: no
regressions, all drift the roadmap already owns, and all of it hiding
whether the framework itself is green.

The app already runs the identical 15-step gate in `reference-app-verify`,
so nothing was covered twice for a reason. Drop it from the root tsconfig
references, the root bunfig preload, `bun run test` and the gate's test
steps. `reference-app-verify` still runs the whole thing and still prints
every failure and fix line; it is advisory until milestone 9, because a
gate whose resting state is red stops being read.

One real framework bug fell out of it: the `runJobs` fixture installed the
process-global job driver and never put it back, so `send()` in any later
file in the same bun process enqueued instead of sending inline — which is
why three `packages/mail` tests failed in CI and passed locally. Fixtures
that take over a global now implement `Symbol.dispose`/`Symbol.asyncDispose`,
and `fixtureTest` disposes in reverse build order even when the body throws.

- jobs: `resetJobDriver()`, the counterpart to `resetMailDriver()`
- testing: `runJobs` and `mail` restore the driver they replaced
- cli: `applies` and the run share one exclusion list, so a step can no
  longer apply and then fail on "no test files matched"
- cli: `x test` stopped silently dropping `e2e/`, matching `bun run test`
- site: `build.ts` was 693 lines over a 500 ceiling — a `verify` failure
  hidden until now because the job was skipped whenever its `needs` were
  red. Split into `site/lib/*`, output byte-identical
- docs: correct the claims about what each gate collects

Co-Authored-By: Claude <noreply@anthropic.com>
CI

- reference-app-verify: continue-on-error moves from the job to the step. On
  the job the check itself stayed red, which is the failure mode this PR
  exists to remove; on the step the run is a warning and the whole 15-step
  table stays in the log. Human render, not --json — the reader is a person.
- examples/dummy: record the schema hash for 0001_init, which covers all six
  schema tables 1:1 but never had its .hash sidecar committed. `drift` green,
  the app gate goes 8 red steps to 7.
- persist-credentials: false on every actions/checkout, in all four workflows.
  ci.yml runs on fork pull_requests and later steps execute checked-out code.

Review

- workspace-checks: a terminating newline is not a line. Splitting on \n and
  taking the length made the real ceiling 499 and every reported count one too
  high — so an author who split a file to exactly 500 still failed. Extracted
  `countLines`, and the fixtures now end with a newline like real files do, so
  the test can fail for this.
- framework-fixtures and sealed-network tests: prefix every describe through
  testName('unit', ...) so a failure line names its gate step.
- .coderabbit.yml: tone_instructions was 273 characters against a 250 limit,
  so the whole file failed to parse and every review instruction in it was
  dropped. 242 now, with the limit written down.

Co-Authored-By: Claude <noreply@anthropic.com>
- wiki/CLI-Reference.md: drop `skipped:false` from the `x verify --json`
  example. `runVerify` sets `skipped` only when a step does not apply;
  an executed step omits it, so the example described a shape the
  command never emits.
- packages/testing/CLAUDE.md: the naming rule claimed `testName()` is
  how `x verify` filters tests. It is not — the step is selected by
  filename (`verify-tests.ts`), and the prefix only labels the failure
  line. Say that, and say it belongs on the outer `describe`, since
  repeating it on the inner `test` prints the type twice.

Co-Authored-By: Claude <noreply@anthropic.com>
Reverts the wiki edit in 55484a7. That change was wrong: `runVerify`
does omit `skipped` on an executed step, but the documented example is
`x verify --json`, and `renderJson` normalises the key —
`skipped: step.skipped === true` — so every step in the JSON output
carries an explicit boolean. The example was right as written.

Nothing tested that normalisation, which is how the doc came to read as
a defect twice. Pin it: an executed step renders `"skipped":false`, a
step that did not apply renders `true`. Verified the test fails when the
render goes back to spreading the key conditionally.

Co-Authored-By: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

claudetm Created by Claude Task Master

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant