Skip to content

vm: assert deck's served apps from deps.lock and every .mattstack route - #447

Merged
m4ttheweric merged 13 commits into
mainfrom
rt-2-13-h-vm-served-assert
Sep 25, 2026
Merged

m4ttheweric merged 13 commits into
mainfrom
rt-2-13-h-vm-served-assert

Conversation

@m4ttheweric

@m4ttheweric m4ttheweric commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

VM assert checks the served apps the bundle ships (RT-284, spec section H)

Part of the 2.13.0 prod-readiness release (RT-279..284). The clean-room assert now fails unless deck serves exactly the bundle's catalog in prod, and it fetches every .mattstack route instead of the first.

What changed

Guest helper (rt-tray/vm/run/guest/)

  • Adds served-apps.sh, sourced by assert-installed.sh and trigger-update.sh
  • Adds jq/catalog.jq, jq/launchctl-print.jq, jq/served-verdict.jq (the guest has only the bundle's jq)
  • Derives the expected set from Contents/Resources/deps.lock serve rows; nothing names an app
  • Checks per app: rt-managed, health.ok, no dev-link issue, an advertised icon (the bundled identity resolved), <name>.mattstack route, argv [Helpers/<name>, ...serve.args], cwd ~/.mattstack/<name>, a pid; deck devMode: false
  • Fails any tool row (the gitq CLI) loaded as a com.mattstack.deck.<name> job, and any pending serve row

Wiring

  • assert-installed.sh: every route, served-app assert (90s poll), headless stated pass
  • trigger-update.sh: optional --headless; served-app assert (180s) and every route after the relaunch
  • walkthrough.sh passes --headless to the update leg

Tests

  • Host suites for all three jq programs and the helper (stub launchctl/curl, temp HOME), fixtures pasted from real captures, wired into check-vm-scripts.sh
  • scripts/lib/__tests__/vm-served-catalog.test.ts pins catalog.jq to parseDepsLock in CI (runs against deps.lock: serve field for bundled apps #442's fixture and the shipped lock)

Review fixes (stand-in Opus review; CodeRabbit was rate-limited)

  • Update leg records each app's launchd job before Sparkle runs and fails an app whose pid never moved (still on the deleted Helpers binary); the 180s poll waits for the post-update restart
  • assert-installed.sh polls the served set before fetching routes, so a route is not judged while its app is still starting
  • launchctl-print.jq finds the job header on any line, so a stderr warning cannot make a loaded tool read as unloaded
  • The no-app-name gate fails on a missing file instead of passing
  • The four host suites run in CI's unit-test step (and bun run test); the parity test honours VM_TEST_JQ

Verification

  • bash rt-tray/vm/check-vm-scripts.sh: all vm checks ok
  • bun test rt-tray/vm/run/helpers scripts/lib/__tests__/vm-served-catalog.test.ts: 39 pass, also 39 pass under the bundle's jq 1.8.2 (VM_TEST_JQ)
  • bun test scripts/lib/__tests__/vm-served-catalog.test.ts: 2 pass; dropping serve.args in catalog.jq makes the fixture case fail on argsdemo
  • bunx tsc --noEmit clean, bash scripts/repo-purity.sh ok

Not run here

No VM run: the assert goes green only on a bundle carrying the serve rows and deck 1.1.0 (units B, C, D and the deps.lock row PRs). The release walkthrough is its first real run. Until boxscore's row flips from pending to bundled, the assert fails it by name, as intended.

🤖 Generated with Claude Code

m4ttheweric and others added 9 commits September 25, 2026 03:44
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…k route

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…r relaunch

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 13 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 83 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 8f752df5-7e0c-4bb8-93a8-4ba4ed9cd994

📥 Commits

Reviewing files that changed from the base of the PR and between af8ffc9 and f7a1ea2.

📒 Files selected for processing (21)
  • .github/workflows/checks.yml
  • package.json
  • rt-tray/vm/README.md
  • rt-tray/vm/check-vm-scripts.sh
  • rt-tray/vm/run/guest/assert-installed.sh
  • rt-tray/vm/run/guest/jq/catalog.jq
  • rt-tray/vm/run/guest/jq/launchctl-print.jq
  • rt-tray/vm/run/guest/jq/served-verdict.jq
  • rt-tray/vm/run/guest/served-apps.sh
  • rt-tray/vm/run/guest/trigger-update.sh
  • rt-tray/vm/run/helpers/__tests__/catalog.test.ts
  • rt-tray/vm/run/helpers/__tests__/fixtures/deck-status-dev-lived.json
  • rt-tray/vm/run/helpers/__tests__/fixtures/launchctl-print-args.txt
  • rt-tray/vm/run/helpers/__tests__/fixtures/launchctl-print-chat.txt
  • rt-tray/vm/run/helpers/__tests__/fixtures/launchctl-print-missing.txt
  • rt-tray/vm/run/helpers/__tests__/jq.ts
  • rt-tray/vm/run/helpers/__tests__/launchctl-print.test.ts
  • rt-tray/vm/run/helpers/__tests__/served-apps-sh.test.ts
  • rt-tray/vm/run/helpers/__tests__/served-verdict.test.ts
  • rt-tray/vm/run/walkthrough.sh
  • scripts/lib/__tests__/vm-served-catalog.test.ts

Comment @coderabbitai help to get the list of available commands.

m4ttheweric and others added 4 commits September 25, 2026 04:05
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ng file

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@m4ttheweric
m4ttheweric merged commit 6343e24 into main Sep 25, 2026
7 checks passed
@m4ttheweric
m4ttheweric deleted the rt-2-13-h-vm-served-assert branch September 25, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant