Skip to content

Run all DB-gated web tests in CI - #5683

Merged
lawrencecchen merged 1 commit into
mainfrom
feat-db-tests-small
Jun 9, 2026
Merged

lawrencecchen merged 1 commit into
mainfrom
feat-db-tests-small

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add a web DB behavior runner that discovers every CMUX_DB_TEST-gated test file
  • run that runner from the web-db-migrations CI job and local bun db:test
  • add a workflow guard so CI keeps using the discovery runner instead of a hard-coded subset

Coverage

Before, CI ran 4 DB-backed web test files in web-db-migrations. This branch runs all 7 CMUX_DB_TEST-gated files currently in web/tests.

This is a small split from the stale/conflicting broader CI branch at #4945.

Verification

  • bash tests/test_ci_self_hosted_guard.sh
  • bash -n web/scripts/run-db-behavior-tests.sh web/scripts/db-local.sh tests/test_ci_self_hosted_guard.sh
  • git diff --check
  • cd web && bun test
  • cd web && bun db:test

Deflake report

Flaky path:

  • Workflow/job: CI / web-db-migrations
  • Test(s): DB-backed web tests gated by CMUX_DB_TEST
  • Failure signature: tests were present but skipped unless explicitly enumerated in the DB CI job

Coverage preserved:

  • Kept DB tests active in web-db-migrations
  • Assertions preserved
  • No skips/disables/removals

Before:

After:

  • Attempts: local DB runner executed 7 files
  • Reliability: 1/1 local run passed
  • Timing: local bun db:test completed in 4.65s after dependencies were installed

Change:

  • Root cause: DB behavior coverage depended on a hard-coded file list
  • Fix: discover CMUX_DB_TEST-gated files and fail if any execute zero tests or still skip under CMUX_DB_TEST=1
  • Why this improves reliability without reducing coverage: new DB-backed tests automatically join the DB CI lane and the guard prevents silently narrowing coverage

View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

Cursor Bugbot is generating a summary for commit 52b2c6d. Configure here.


Summary by cubic

Run all CMUX_DB_TEST-gated web tests in CI by replacing hard-coded file lists with a discovery runner. Increases coverage in the web-db-migrations job from 4 files to all 7 DB-backed test files and prevents silent skips.

  • New Features
    • Added web/scripts/run-db-behavior-tests.sh to auto-discover tests gated by process.env.CMUX_DB_TEST and run them with CMUX_DB_TEST=1; fails on zero executed tests or if any are skipped.
    • Exposed test:db:behavior in web/package.json and run it in CI via bun run test:db:behavior; also used in db-local.sh.
    • Added a guard in tests/test_ci_self_hosted_guard.sh to ensure CI uses the discovery runner with CMUX_DB_TEST=1.

Written for commit 52b2c6d. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

Release Notes

  • Chores
    • Streamlined database behavior testing in CI by consolidating multiple test commands into a single unified test runner.
    • Enhanced CI validation with automated checks to ensure database behavior tests are correctly integrated and executed in the continuous integration pipeline.

@vercel

vercel Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Ready Ready Preview, Comment Jun 9, 2026 6:58am
cmux-staging Building Building Preview, Comment Jun 9, 2026 6:58am

@coderabbitai

coderabbitai Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR consolidates database behavior test execution by introducing a new gated runner script that discovers and validates DB-behavior tests, wiring it through npm scripts, local test workflows, CI pipelines, and adding regression guards to ensure the integration remains correct.

Changes

DB Behavior Test Runner Consolidation

Layer / File(s) Summary
Runner script implementation
web/scripts/run-db-behavior-tests.sh
New bash script requires DATABASE_URL or DIRECT_DATABASE_URL, sets CMUX_DB_TEST=1, discovers tests/**/*.test.ts(x) files containing process.env.CMUX_DB_TEST, runs bun test per file, and validates no zero-test runs, skipped tests, or failures occur before exiting.
npm script and local test wiring
web/package.json, web/scripts/db-local.sh
Adds test:db:behavior npm script invoking the runner; updates db-local.sh test command to call the new runner after drizzle migrations instead of inline test execution.
CI workflow integration
.github/workflows/ci.yml
"Database behavior tests" step replaces four separate inline bun test invocations with a single bun run test:db:behavior command.
CI guard validation
tests/test_ci_self_hosted_guard.sh
Adds check_web_db_behavior_tests function that enforces runner executability, npm script presence, workflow step presence with CMUX_DB_TEST=1, and verifies discovery is gated on environment variable rather than hardcoded; integrated into main guard suite.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 A runner script hops forth with gated might,
Discovering tests that bear the CMUX_DB_TEST light,
From package.json to CI's grand stage,
Guards watch every wiring on this modern page,
Zero tests caught, no skipped ones slide through!


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 1 warning)

Check name Status Explanation Resolution
Cmux User-Facing Error Privacy ❌ Error PR exposes internal environment variable names (DATABASE_URL, DIRECT_DATABASE_URL, CMUX_DB_TEST) in user-facing error messages in run-db-behavior-tests.sh, violating user-facing-errors.md rule. Replace error messages with generic terms: "Database configuration is required" and "No database behavior test files found" to avoid exposing environment variable names.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (19 passed)
Check name Status Explanation
Title check ✅ Passed The title "Run all DB-gated web tests in CI" directly and specifically describes the main objective of the changeset—expanding DB test discovery in CI from a hard-coded subset to all CMUX_DB_TEST-gated files.
Description check ✅ Passed The PR description covers all required template sections with substantial detail: Summary explains the changes (discovery runner, CI integration, workflow guard); Testing includes verification steps (shell script checks, syntax validation, local test runs); however, the Demo Video section is missing and the Checklist is incomplete—only partial verification is documented.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed No Swift files modified in this PR. Changes are to CI workflow YAML, shell scripts, and JSON config only. Swift actor isolation check not applicable.
Cmux Swift Blocking Runtime ✅ Passed PR contains only non-Swift changes (YAML workflow, JSON config, and shell scripts). The check requires Swift production code, so it does not apply.
Cmux Expensive Synchronous Load ✅ Passed PR contains no Swift code changes. Custom check is scoped to "production Swift changes" only; this PR modifies only YAML workflow, bash scripts, and JavaScript configs.
Cmux Cache Substitution Correctness ✅ Passed PR contains only test infrastructure and CI/CD changes with no production code involving cache substitution in persistence, history, undo, or snapshot paths.
Cmux No Hacky Sleeps ✅ Passed The wait_for_postgres sleep in web/scripts/db-local.sh is deterministic polling in explicit test-only scaffolding (local database setup) and falls under the rule's allowed exceptions.
Cmux Algorithmic Complexity ✅ Passed Test/CI harness with fixed 7-file collection. No nested scans, rescans, or algorithmic violations. Matches rule pass criteria for test scaffolding.
Cmux Swift Concurrency ✅ Passed This PR contains no Swift code changes—only YAML workflows, bash scripts, and JSON config files. The Swift concurrency check is not applicable.
Cmux Swift @Concurrent ✅ Passed PR contains no Swift files; custom check for Swift @concurrent annotation rules is not applicable to YAML, shell script, and JSON configuration changes.
Cmux Swift File And Package Boundaries ✅ Passed PR contains zero Swift files; all changes are YAML (CI workflow), JSON (package config), and Bash scripts. Swift file/package boundary rules do not apply.
Cmux Swift Logging ✅ Passed No Swift files are modified in this PR; all changes are YAML workflows, bash scripts, and JSON config. Check is not applicable to non-Swift code.
Cmux Full Internationalization ✅ Passed PR contains only developer-facing scripts, CI configuration, and test infrastructure with no user-facing text, UI changes, or localization-required content per full-internationalization.md rules.
Cmux Swiftui State Layout ✅ Passed PR contains no SwiftUI changes—only YAML workflow, bash scripts, and JSON configs. The SwiftUI state layout check is not applicable to non-Swift code.
Cmux Architecture Rethink ✅ Passed PR contains no Swift code or architectural changes; rule applies only to Swift changes and is not applicable to this web test infrastructure refactor.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR contains no Swift code changes. Modified files are YAML workflow config, bash scripts, and JSON package config—not Swift NSWindow/NSPanel/SwiftUI code subject to this check.
Cmux Source Artifacts ✅ Passed All five changed files are hand-written source code, test scripts, and configuration intentionally part of the product/test system; no local artifacts, logs, or generated output is committed.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat-db-tests-small

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @protobufjs/float is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@protobufjs/float@1.0.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@protobufjs/float@1.0.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @stackframe/stack-ui is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@stackframe/stack@2.8.89 → npm/@stackframe/stack-ui@2.8.89

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@stackframe/stack-ui@2.8.89. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @tanstack/table-core is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@stackframe/stack@2.8.89 → npm/@stackframe/js@2.8.89 → npm/@tanstack/table-core@8.21.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tanstack/table-core@8.21.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @typescript-eslint/eslint-plugin is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@typescript-eslint/eslint-plugin@8.55.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@typescript-eslint/eslint-plugin@8.55.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm better-sqlite3 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/drizzle-orm@1.0.0-beta.22 → npm/better-sqlite3@12.9.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/better-sqlite3@12.9.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm damerau-levenshtein is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/eslint-config-next@16.2.6 → npm/damerau-levenshtein@1.0.8

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/damerau-levenshtein@1.0.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm date-fns is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@stackframe/stack@2.8.89 → npm/date-fns@3.6.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/date-fns@3.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm date-fns is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@stackframe/stack@2.8.89 → npm/date-fns@3.6.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/date-fns@3.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm drizzle-kit is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: web/package.json → npm/drizzle-kit@1.0.0-beta.23

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/drizzle-kit@1.0.0-beta.23. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm effect is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: web/package.json → npm/effect@3.21.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/effect@3.21.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm es-abstract is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/eslint-config-next@16.2.6 → npm/es-abstract@1.24.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-abstract@1.24.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm eslint-plugin-react is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/eslint-config-next@16.2.6 → npm/eslint-plugin-react@7.37.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-react@7.37.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm json-schema is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ? → npm/@stackframe/stack@2.8.89 → npm/json-schema@0.4.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/json-schema@0.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm next is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: web/package.json → npm/next@16.2.6

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@16.2.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@greptile-apps

greptile-apps Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR replaces four hard-coded bun test <file> invocations in CI and the local db:test command with a discovery-based runner (run-db-behavior-tests.sh) that automatically finds every CMUX_DB_TEST-gated test file. A new CI guard (check_web_db_behavior_tests) is added to test_ci_self_hosted_guard.sh to enforce that future changes cannot silently narrow coverage back to a hard-coded subset.

  • Discovery runner (web/scripts/run-db-behavior-tests.sh): find tests + grep picks up all *.test.ts/*.test.tsx files referencing process.env.CMUX_DB_TEST, runs each under CMUX_DB_TEST=1, and fails if any file executes zero tests or still skips.
  • CI wiring: web-db-migrations job now runs bun run test:db:behavior; the defaults.run.working-directory: web setting means the script path resolves correctly.
  • Guard: test_ci_self_hosted_guard.sh verifies the runner exists, the package.json script is present, and ci.yml uses the discovery runner.

Confidence Score: 4/5

Safe to merge — the discovery runner correctly wires up DB-gated test expansion in both CI and local flows, and the guard prevents future regressions to hard-coded subsets.

The runner logic is sound and the CI integration is correct. Three observations in the runner are worth a follow-up: temp files created by mktemp have no trap for cleanup on interruption, the zero_test_files check exits before reporting simultaneously failing files, and the Bun summary-line regex could silently miss zero-test files if Bun changes its output format.

web/scripts/run-db-behavior-tests.sh deserves a second look on the error-reporting order and the Bun output format assumption.

Important Files Changed

Filename Overview
web/scripts/run-db-behavior-tests.sh New discovery runner — discovers CMUX_DB_TEST-gated test files, runs each under CMUX_DB_TEST=1, and enforces that every file runs non-zero tests without skips. Minor issues: no trap for mktemp cleanup on interruption, zero_test check suppresses failed_files output, and the Bun summary regex is format-sensitive.
.github/workflows/ci.yml Replaces four hard-coded bun test invocations with a single bun run test:db:behavior call in the web-db-migrations job; defaults.run.working-directory: web is already set, so the relative script path resolves correctly.
tests/test_ci_self_hosted_guard.sh Adds check_web_db_behavior_tests() guard that verifies the runner script exists and is executable, package.json exposes the right script name, ci.yml uses the discovery runner with CMUX_DB_TEST="1", and the runner script contains the grep-based discovery pattern.
web/scripts/db-local.sh Replaces four hard-coded bun test lines in the test case with a single call to run-db-behavior-tests.sh; ROOT_DIR resolution is correct since db-local.sh lives in web/scripts/.
web/package.json Adds test:db:behavior script; an existing db:test script already delegates to db-local.sh test, which now invokes the discovery runner.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    CI[CI: web-db-migrations job] -->|bun run test:db:behavior| PKG[web/package.json\ntest:db:behavior]
    LOCAL[Local: bun db:test] -->|bash db-local.sh test| DL[web/scripts/db-local.sh\ntest case]
    PKG -->|bash scripts/run-db-behavior-tests.sh| RUNNER
    DL -->|bash run-db-behavior-tests.sh| RUNNER
    RUNNER[run-db-behavior-tests.sh]
    RUNNER -->|find tests -name *.test.ts| FIND[find all *.test.ts files]
    FIND -->|grep process.env.CMUX_DB_TEST| GATE{CMUX_DB_TEST-gated?}
    GATE -->|No| SKIP[Skip file]
    GATE -->|Yes| RUN[bun test file\nwith CMUX_DB_TEST=1]
    RUN --> CHECK{Check output}
    CHECK -->|zero tests run| ZERO_FAIL[Exit: zero tests]
    CHECK -->|skips detected| SKIP_FAIL[Exit: skips remain]
    CHECK -->|non-zero exit| FAIL[Exit: tests failed]
    CHECK -->|all pass| NEXT[Next file]
    NEXT --> FIND
    GUARD[test_ci_self_hosted_guard.sh\ncheck_web_db_behavior_tests] -->|verifies| RUNNER
    GUARD -->|verifies| PKG
    GUARD -->|verifies| CI
Loading

Reviews (1): Last reviewed commit: "Run all DB-gated web tests in CI" | Re-trigger Greptile

Comment on lines +32 to +44
output_file="$(mktemp /tmp/cmux-db-behavior-test.XXXXXX.log)"
set +e
bun test "$test_file" 2>&1 | tee "$output_file"
test_status=${PIPESTATUS[0]}
set -e

if ! grep -Eq 'Ran [1-9][0-9]* tests? across [1-9][0-9]* files?' "$output_file"; then
zero_test_files+=("$test_file")
fi
if grep -Eq '^\(skip\) |^[[:space:]]*[1-9][0-9]* skips?$' "$output_file"; then
skipped_test_files+=("$test_file")
fi
rm -f "$output_file"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Temp file leaked on script interruption

mktemp is called inside the loop but there is no trap to remove $output_file on SIGINT, SIGTERM, or set -e exit. If the script is killed mid-iteration (e.g., by a CI timeout), the /tmp/cmux-db-behavior-test.*.log file from the current iteration stays on disk. Adding a trap 'rm -f "$output_file"' EXIT immediately after the mktemp call ensures cleanup on any exit path.

Comment on lines +38 to +54
if ! grep -Eq 'Ran [1-9][0-9]* tests? across [1-9][0-9]* files?' "$output_file"; then
zero_test_files+=("$test_file")
fi
if grep -Eq '^\(skip\) |^[[:space:]]*[1-9][0-9]* skips?$' "$output_file"; then
skipped_test_files+=("$test_file")
fi
rm -f "$output_file"

if [[ "$test_status" -ne 0 ]]; then
failed_files+=("$test_file")
fi
done

if [[ "${#zero_test_files[@]}" -gt 0 ]]; then
printf '\n%s DB behavior test file(s) executed zero tests:\n' "${#zero_test_files[@]}" >&2
printf ' %s\n' "${zero_test_files[@]}" >&2
exit 1

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 zero_test_files check fires before failed_files, hiding crash details

When bun test crashes (e.g., an import error) it exits non-zero AND produces no "Ran N tests across M files" line. The file lands in both zero_test_files and failed_files, but the zero_test_files check fires first and calls exit 1 — so the final error message says "executed zero tests" rather than "failed", and other files that genuinely failed (with tests running) are never listed. Checking or printing failed_files before exiting for zero_test_files would give a more complete picture in a single CI run.

Comment on lines +38 to +41
if ! grep -Eq 'Ran [1-9][0-9]* tests? across [1-9][0-9]* files?' "$output_file"; then
zero_test_files+=("$test_file")
fi
if grep -Eq '^\(skip\) |^[[:space:]]*[1-9][0-9]* skips?$' "$output_file"; then

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Zero-test detection is coupled to Bun's summary line format

The pattern 'Ran [1-9][0-9]* tests? across [1-9][0-9]* files?' matches Bun's current summary output, but if Bun changes the phrasing (e.g., to "Ran N tests in N files" or omits the line on empty suites), any test file that actually ran zero tests would silently pass this check. The PR's guard prevents adding new gated files that skip, but a format drift here would let a file with genuinely zero tests slip through without a CI failure.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@web/scripts/run-db-behavior-tests.sh`:
- Around line 7-10: Update the error message emitted by the conditional that
checks [[ -z "${DIRECT_DATABASE_URL:-${DATABASE_URL:-}}" ]] so it clearly states
that at least one of the environment variables must be provided; replace the
current echo ("DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior
tests") with a clearer message such as "At least one of DATABASE_URL or
DIRECT_DATABASE_URL must be set for DB behavior tests" and ensure the message
references the environment variable names DIRECT_DATABASE_URL and DATABASE_URL
used in the conditional.
- Around line 32-44: The temporary log file created into variable output_file
via mktemp in run-db-behavior-tests.sh isn’t removed if the script is
interrupted; add a shell trap that unconditionally removes "$output_file" on
EXIT and on common signals (INT, TERM) so cleanup runs for both normal and early
termination, and ensure the trap is set immediately after output_file is created
(before running bun test) and that rm -f "$output_file" remains for the normal
path; reference the output_file variable and the mktemp call when adding the
trap.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: f47c9277-2ee9-400c-8dea-b6f1500ebab6

📥 Commits

Reviewing files that changed from the base of the PR and between 4113398 and 52b2c6d.

📒 Files selected for processing (5)
  • .github/workflows/ci.yml
  • tests/test_ci_self_hosted_guard.sh
  • web/package.json
  • web/scripts/db-local.sh
  • web/scripts/run-db-behavior-tests.sh

Comment on lines +7 to +10
if [[ -z "${DIRECT_DATABASE_URL:-${DATABASE_URL:-}}" ]]; then
echo "DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior tests" >&2
exit 2
fi

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial | 💤 Low value

Consider clarifying the error message.

The current message "DATABASE_URL or DIRECT_DATABASE_URL is required" is correct, but could be more explicit that at least one of them must be set (not both).

📝 Optional clarity improvement
 if [[ -z "${DIRECT_DATABASE_URL:-${DATABASE_URL:-}}" ]]; then
-  echo "DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior tests" >&2
+  echo "At least one of DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior tests" >&2
   exit 2
 fi
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
if [[ -z "${DIRECT_DATABASE_URL:-${DATABASE_URL:-}}" ]]; then
echo "DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior tests" >&2
exit 2
fi
if [[ -z "${DIRECT_DATABASE_URL:-${DATABASE_URL:-}}" ]]; then
echo "At least one of DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior tests" >&2
exit 2
fi
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/scripts/run-db-behavior-tests.sh` around lines 7 - 10, Update the error
message emitted by the conditional that checks [[ -z
"${DIRECT_DATABASE_URL:-${DATABASE_URL:-}}" ]] so it clearly states that at
least one of the environment variables must be provided; replace the current
echo ("DATABASE_URL or DIRECT_DATABASE_URL is required for DB behavior tests")
with a clearer message such as "At least one of DATABASE_URL or
DIRECT_DATABASE_URL must be set for DB behavior tests" and ensure the message
references the environment variable names DIRECT_DATABASE_URL and DATABASE_URL
used in the conditional.

Comment on lines +32 to +44
output_file="$(mktemp /tmp/cmux-db-behavior-test.XXXXXX.log)"
set +e
bun test "$test_file" 2>&1 | tee "$output_file"
test_status=${PIPESTATUS[0]}
set -e

if ! grep -Eq 'Ran [1-9][0-9]* tests? across [1-9][0-9]* files?' "$output_file"; then
zero_test_files+=("$test_file")
fi
if grep -Eq '^\(skip\) |^[[:space:]]*[1-9][0-9]* skips?$' "$output_file"; then
skipped_test_files+=("$test_file")
fi
rm -f "$output_file"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick | 🔵 Trivial | ⚡ Quick win

Add trap for temp file cleanup on script interruption.

The temp file created at line 32 is only cleaned up at line 44 in the normal execution path. If the script is interrupted (Ctrl+C, SIGTERM, or early exit), temp files will accumulate in /tmp.

🔧 Recommended improvement for cleanup resilience
 printf 'Running %s DB behavior test file(s) with CMUX_DB_TEST=1\n' "${`#test_files`[@]}"
 failed_files=()
 zero_test_files=()
 skipped_test_files=()
+cleanup_files=()
+trap 'rm -f "${cleanup_files[@]}"' EXIT INT TERM
+
 for test_file in "${test_files[@]}"; do
   printf '\n==> bun test %s\n' "$test_file"
   output_file="$(mktemp /tmp/cmux-db-behavior-test.XXXXXX.log)"
+  cleanup_files+=("$output_file")
   set +e
   bun test "$test_file" 2>&1 | tee "$output_file"
   test_status=${PIPESTATUS[0]}
   set -e

   if ! grep -Eq 'Ran [1-9][0-9]* tests? across [1-9][0-9]* files?' "$output_file"; then
     zero_test_files+=("$test_file")
   fi
   if grep -Eq '^\(skip\) |^[[:space:]]*[1-9][0-9]* skips?$' "$output_file"; then
     skipped_test_files+=("$test_file")
   fi
-  rm -f "$output_file"

   if [[ "$test_status" -ne 0 ]]; then
     failed_files+=("$test_file")
   fi
 done
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@web/scripts/run-db-behavior-tests.sh` around lines 32 - 44, The temporary log
file created into variable output_file via mktemp in run-db-behavior-tests.sh
isn’t removed if the script is interrupted; add a shell trap that
unconditionally removes "$output_file" on EXIT and on common signals (INT, TERM)
so cleanup runs for both normal and early termination, and ensure the trap is
set immediately after output_file is created (before running bun test) and that
rm -f "$output_file" remains for the normal path; reference the output_file
variable and the mktemp call when adding the trap.

@lawrencecchen
lawrencecchen merged commit ed82f20 into main Jun 9, 2026
28 checks passed
@lawrencecchen
lawrencecchen deleted the feat-db-tests-small branch June 9, 2026 07:17

This branch was successfully deployed

1 active deployment
Preview – cmux — 52b2c6d1 Deployed Jun 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant