Files
copilotkit__copilotkit/.github/workflows/static_intelligence-env-names.yml
Benjamin Taylor 84dd86f2ed test(examples): gate the starters' Intelligence wiring block on one shape (closes OSS-982)
The marked block that wires managed Intelligence is the region a hosted reader
copies verbatim, and nothing checked it. Both gaps were deliberate: the parity
manifest lists `src/app/api/copilotkit/**` under `allowedDivergence` for every
instance it tracks, and no `docker-compose.test.yml` sets
`COPILOTKIT_LICENSE_TOKEN`, so every smoke-tested starter takes the else arm and
the `intelligence:` arm has never run in CI.

The cost was already visible. The block's code was byte-identical in 21 of 22
starters, but its warning comment had drifted into five variants and the two
`ms-agent-framework-*` starters shipped the `demo-user` stub with no warning at
all. That drift is how the localhost default of OSS-981 survived in all 22
copies at once.

Add `scripts/validate-intelligence-wiring-block.ts`, which greps the opening
marker, compares every site against the north-star starter, and fails on the
first line that differs. Two normalisations keep it usable: the block is
dedented, because `agentcore` nests it deeper, and the else arm's runner name is
masked, because `agentcore` runs `AgentCoreRunner` in front of a Bedrock session
where an in-process runner has nothing to run. Everything else, comment text
included, must match to the byte.

Then unify the warning at all 22 sites on the fullest wording, which also says
the id must exist in Intelligence or thread operations can fail.

The check passes on day one, so it is a ratchet rather than a migration. It is a
shape gate, not a content gate: 22 identically wrong copies still pass. What it
guarantees is that a fix reaches all of them or none.

Not covered: enrolling the `intelligence:` arm in the smoke path. That needs a
license token in CI and a reachable endpoint from the compose network, and is
tracked separately.
2026-08-26 11:16:00 -05:00

61 lines
2.3 KiB
YAML

name: static / intelligence contracts
# Deliberately unfiltered. A non-canonical Intelligence key name can appear in
# any README, example, skill, or doc page, and the two workflows that would
# otherwise cover this both filter paths — plugin-skills-check by `paths:` and
# static/quality by `paths-ignore: examples/**`, which is precisely where the
# deprecated alias still lives. Scoping this job would re-open the hole it
# exists to close.
#
# The wiring-block check needs the same reach for the same reason. The starters'
# Intelligence block lives under `examples/**`, which static/quality ignores,
# and the parity drift check exempts the route it sits in (OSS-982).
on:
push:
branches: [main]
pull_request:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
check:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 20
cache: pnpm
- run: pnpm install --frozen-lockfile
# The rules are unit-tested here rather than by a general runner: nothing
# else executes scripts/__tests__, so a rule that silently stopped
# matching would leave the check below passing on an empty result.
- name: Test the validator's rules
run: pnpm exec vitest run scripts/__tests__/validate-intelligence-env-names.test.ts
- name: Check Intelligence env var names are canonical
run: pnpm check:intelligence-env-names
# Same reasoning as above: the rules are unit-tested here because nothing
# else executes scripts/__tests__, and a discovery grep that stopped
# matching would leave the check below passing on an empty file list.
- name: Test the wiring-block validator's rules
run: pnpm exec vitest run scripts/__tests__/validate-intelligence-wiring-block.test.ts
- name: Check the starters' Intelligence wiring block is one shape
run: pnpm check:intelligence-wiring-block