Skip to content

fix(ci): public upstream image for sample-e2e + fast red-proof gate - #45

Merged
omar-nahhas merged 3 commits into
mainfrom
fix/oss-public-ci
Aug 3, 2026
Merged

omar-nahhas merged 3 commits into
mainfrom
fix/oss-public-ci

Conversation

@omar-nahhas

Copy link
Copy Markdown
Contributor

Prepares the repo to go public.

1. sample-e2e must pass with NO secrets

sample-plugin-e2e.yml pinned A0_IMAGE to the private fork image and passed GHCR_PULL_TOKEN. Dependabot runs and fork PRs never receive secrets, so the pull 401d:

Error: unable to copy from source docker://ghcr.io/nuevanext/agent-zero:latest-nonroot:
  unable to retrieve auth token: invalid username/password: unauthorized

That is why PRs #42/#43/#44 are red — and it would be every external contributor once this repo is public.

Fix: use the DEC-019 default docker.io/agent0ai/agent-zero:latest (public, no creds). Consumers needing the ML-bundled fork still override A0_IMAGE per-plugin via .devkit.yml.

2. Fast red-proof (Gate 3) — semantics unchanged

The binding clock is Playwright's test-level timeout, not action/expect timeouts: a step passing an explicit per-call { timeout: N } cannot be overridden from config but is capped by the test timeout. Measured 12 x ~113s = 22m40s of a ~35min run.

Cap the test timeout for the red-proof pass only, and disable video/screenshot/trace there (expected failures, artifacts nobody reads).

Every scenario still runs; the assertion is still exactly 0 passes. Two guards make weakening impossible to miss:

  • Guard A — coverage parity: red-proof and the real run must cover the same scenario count. Catches any future filter/narrowing.
  • Guard B — cap adequacy: fails if the slowest genuinely-passing scenario exceeds 80% of the cap, since such a cap could clip an honest pass and mask a fake-green. Error message prints the value to raise it to.

Also restores the exec bit on run-bdd.sh (text_editor clears it).

Agent Zero and others added 3 commits August 1, 2026 23:20
sample-plugin-e2e pinned A0_IMAGE to the PRIVATE fork image and passed
GHCR_PULL_TOKEN. Dependabot runs and fork PRs never receive secrets, so
the pull 401d and the workflow was red for everyone outside the org --
which would be every external contributor once this repo is public.
Switch to the DEC-019 default docker.io/agent0ai/agent-zero:latest
(public, no creds). Consumers needing the ML-bundled fork still override
A0_IMAGE per-plugin via .devkit.yml.

Red-proof (Gate 3): the binding clock is Playwright test-level timeout,
not action/expect timeouts -- a step passing an explicit per-call timeout
cannot be overridden from config but IS capped by the test timeout.
Measured 12 x ~113s = 22m40s. Cap the test timeout for the red-proof pass
only; disable video/screenshot/trace capture there (expected failures,
artifacts nobody reads).

Semantics unchanged: every scenario still runs, still exactly 0 passes.
Two guards make weakening impossible to miss -- Guard A asserts red-proof
and real run cover the same scenario count; Guard B fails if the slowest
genuinely-passing scenario exceeds 80%% of the cap (a cap that could clip
an honest pass could mask a fake-green).

Also restores the exec bit on run-bdd.sh (text_editor clears it).
DEVKIT_IMAGE defaulted to ghcr.io/agent-zero-plugins/plugin-devkit:latest
but nothing ever published it, so the package did not exist: every
consumer make e2e died with manifest unknown, and CI only worked because
each workflow rebuilt the image inline (~85s per run).

Build devcontainer/Containerfile and push :latest + :sha-<12>, plus the
version tag on v* tags. Least privilege: contents:read + packages:write,
GITHUB_TOKEN only, no PAT.

The final step logs OUT and pulls anonymously, failing with actionable
instructions if the package is not public -- the no-auth consumer path is
the reason to publish at all, so it is proven rather than assumed.
LoginPage.login() asserted the top-nav "Plugins" button with Playwright's
bare 5000ms expect default -- the only post-login landmark in the suite left
on the default (PluginsPage uses explicit 8s/20s/10s).

On a cold nested A0 the WebUI hydrates ~5s AFTER the post-login redirect, so
that deadline straddles the render and flakes ~50%. Proven from run
30721063715's trace: page reached / at t=2.4s, top-nav rendered at t=7.755s,
default deadline ~7.4s -- missed by ~350ms. The passing run on the very next
commit touched no test/timeout/image config, confirming a coin-flip race
rather than an image behavioural difference.

The wait exists to surface a silent auth failure, not to measure hydration
speed, so bound it generously at 30s.
@omar-nahhas
omar-nahhas merged commit 5944aff into main Aug 3, 2026
@omar-nahhas
omar-nahhas deleted the fix/oss-public-ci branch August 3, 2026 00:43
omar-nahhas added a commit that referenced this pull request Aug 3, 2026
PR #45 accidentally committed e2e/node_modules as a mode-120000 symlink
pointing at /a0/usr/workdir/.bdd-deps/node_modules -- a machine-local dep
cache path that exists on exactly one machine. Every clone would carry a
dangling symlink.

.gitignore already had 'node_modules/', but the trailing slash matches only
real DIRECTORIES, so a symlink of the same name slips past. Added a bare
'node_modules' pattern alongside it so this cannot recur.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant