Skip to content

ci: run e2e on develop pushes; ratchet + extend coverage floors - #301

Merged
saadqbal merged 2 commits into
developfrom
wse/293-294-e2e-trigger-coverage-floors
Jul 14, 2026
Merged

ci: run e2e on develop pushes; ratchet + extend coverage floors#301
saadqbal merged 2 commits into
developfrom
wse/293-294-e2e-trigger-coverage-floors

Conversation

@LukasWodka

@LukasWodkaLukasWodka commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

e2e on develop pushes (#293). Scheduled workflows always execute the default branch's tree — main, currently ~46 commits behind develop. discovery_e2e_test.go, delete_e2e_test.go, and the whole delete-teardown job don't exist on main, so the nightly has never actually run them (the TokenRequest/offboard e2e included). This adds push: branches: [develop] to e2e.yml (existing schedule / dispatch / labeled-PR triggers kept), so the suite runs against the tree the tests were written for.

Coverage floor ratchet (#294). Bumps the two existing floors to just under current develop numbers and adds the two load-bearing packages that had no floor (internal/push is the 6.3k-LOC money path):

packagefloorcurrent (unit, as coverage-floor.sh measures, ubuntu CI runner)
internal/cli68 -> 8082.9%
internal/submit72 -> 7880.4%
internal/push87 (new)89.0%
internal/cluster73 (new)74.6%

Deviation from the ticket:internal/cluster gets 73, not the proposed 75. Its coverage is environment-dependent — the kubeconfig-resolution paths only execute on a machine with a real ~/.kube/config, so a dev laptop reads 78.5% while the bare CI runner reads 74.6% (caught by this PR's own first CI run). The floor gates on CI, so it's set to CI-actual − 1, per the ratchet policy. Documented in the script header.

Also updates the one-line step name in build.yml ("cli, submit, push, cluster must not rot") so it doesn't misname the floor set — expected trivial rebase vs sibling PRs touching this file — merge order flexible.

Test plan

Ran locally:

  • ./scripts/coverage-floor.sh — all four floors pass locally; first CI run then failed on internal/cluster (74.6% on the runner vs 78.5% locally), floor corrected to 73 — CI green is the real verification here.
  • YAML parse check on e2e.yml + build.yml.

NOT run locally: the e2e suite itself (needs kind/k3d); the new push trigger will exercise it on the first merge to develop.

Fixes#293
Fixes#294

🤖 Generated with Claude Code


Note

Low Risk
CI-only workflow and coverage-threshold changes; no runtime product behavior.

Overview
e2e on develop pushes (#293). Adds a push trigger on develop to the integration workflow so kind/k3d suites run against the branch where newer tests (discovery, delete, offboard teardown) actually live. Scheduled runs still use the default branch (main), which had been skipping that work; schedule, manual dispatch, and label-gated PR runs are unchanged.

Coverage ratchet (#294). Raises floors for internal/cli (80) and internal/submit (78) and adds floors for internal/push (87) and internal/cluster (73). The script header documents current CI percentages and sets internal/cluster from the bare Ubuntu runner (not a laptop with kubeconfig). The Build workflow step label is updated to mention all four gated packages.

Reviewed by Cursor Bugbot for commit d1d82e2. Bugbot is set up for automated code reviews on this repo. Configure here.

Scheduled workflows execute the default branch's tree (main), which
trails develop by ~46 commits — discovery_e2e_test.go,
delete_e2e_test.go, and the delete-teardown job don't exist there, so
the nightly never actually ran them. Add push: branches: [develop] to
e2e.yml so the suite runs against the tree it was written for.
Ratchet the coverage floors to just under current develop numbers and
add the two missing load-bearing packages:
internal/cli 68 -> 80 (current 82.9%)
internal/submit 72 -> 78 (current 80.4%)
internal/push NEW 87 (current 89.0%)
internal/cluster NEW 75 (current 78.5%)
Verified locally: ./scripts/coverage-floor.sh passes all four floors.
Fixes#293Fixes#294
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@LukasWodka
LukasWodka requested a review from saadqbalJuly 14, 2026 12:18
@LukasWodka

Copy link
Copy Markdown
ContributorAuthor

👋 Heads-up — Code review queue is at 37 / 30

Above the WIP limit. The team convention is to review existing PRs before opening new work.

Open PRs currently in Code review (oldest first):

  • averaging-service#181 — feat(weights): normalize-on-read — mixed cycles average instead of rejecting (SEC-03 §8 step 2) · author: @shujaatTracebloc · no reviewer assigned
  • averaging-service#182 — feat(weights): averaging writes SafeTensors (TF + PyTorch) — SEC-03 §8 step 4 · author: @shujaatTracebloc · no reviewer assigned
  • backend#1079 — feat(global_meta): edge dataset_meta exposure + attributes contract at ingest (#924 G4a) · author: @divyasinghds · no reviewer assigned
  • backend#1086 — docs(rfc): SafeTensors weight-format migration — SEC-03 Phase 1 (RFC 0004) · author: @shujaatTracebloc · no reviewer assigned
  • backend#1093 — chore(deps): bump django from 5.2.14 to 5.2.15 · author: @dependabot · no reviewer assigned
  • backend#1095 — feat(experiment): configurable preprocessing knobs incl. tabular scaler — RFC 0003 L1 + L1b (#1094) · author: @LukasWodka · no reviewer assigned
  • backend#1100 — fix(boot): pin SDK install to tracebloc==0.11.2, drop 404 dev line (#1098) · author: @LukasWodka · reviewer: @saqlainsyed007
  • backend#1105 — perf(api): query micro-fixes — notifications N+1, cached data_scientist, composite index, sampling (#975) · author: @aptracebloc · no reviewer assigned
  • cli#266 — main - > enhance CLI features and tests · author: @saadqbal · no reviewer assigned
  • cli#278 — fix(deps): toolchain go1.26.5 + x/net v0.57.0 — clear 6 reachable vulns; govulncheck CI gate · author: @LukasWodka · reviewer: @saadqbal

Pull from review before opening new work. (This is a nudge from the kanban WIP check, not a block.)

…8.5%
internal/cluster coverage is environment-dependent: the
kubeconfig-resolution paths only execute on a machine that has a real
~/.kube/config, so a dev laptop reads 78.5% while the bare ubuntu
runner reads 74.6% (first CI run on this PR). The floor gates on CI,
so it must be set against the CI number: 73 (= actual - 1), not the
ticket's proposed 75.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@LukasWodka

Copy link
Copy Markdown
ContributorAuthor

@BugBot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit d1d82e2. Configure here.

@LukasWodkaLukasWodka self-assigned this Jul 14, 2026

@saadqbalsaadqbal left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice — floors ratchet up (all set just under the CI numbers, and Test is green so they pass), and the push: develop trigger is the right fix for the schedule-runs-on-main gap. Good catch on the CI-vs-local cluster coverage delta. 👍

@saadqbal
saadqbal merged commit 2f28c1a into developJul 14, 2026
20 checks passed
@saadqbal
saadqbal deleted the wse/293-294-e2e-trigger-coverage-floors branch July 14, 2026 14:30
LukasWodka added a commit that referenced this pull request Jul 14, 2026
…findings
Pinned staticcheck@2025.1.1 joins the standalone lint set in both the
Makefile lint target and build.yml's lint job (-checks all,-ST1005),
mirroring the errcheck/ineffassign pin pattern. The golangci-lint OOM
story that originally disabled it is stale for the standalone binary:
a full run is ~12s wall locally.
Findings fixed (the full non-ST1005 set):
- ST1008: runSet (resources_set_test) returns (string, error), error last
- ST1003: CheckMaskIdColumn -> CheckMaskIDColumn (+ call sites/comments)
- ST1003: errors_as -> errorsAs, io_eof_or_similar -> ioEOFOrSimilar
- ST1020: CoreFloorText doc comment starts with the function name
ST1005 stays excluded: it flags ~58 customer-visible error strings that
need a wording review, not a mechanical sweep — separate follow-up.
Rebased onto develop: union-merged the lint job with develop's govulncheck
job (#278), coverage-floor step (#301) and deadcode advisory gate; kept the
audit comment #286 added above CheckMaskID*Column. The 'going back to the
action' comment in build.yml is KEPT (not deleted) — #6 is still open on
develop, so golangci-lint-action stays disabled and that rationale still
holds. Detached the four data_ingest_*.go header comments from the package
clause (#303 split) so the newly-enabled staticcheck gate is ST1000-clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
LukasWodka added a commit that referenced this pull request Jul 14, 2026
…findings
Pinned staticcheck@2025.1.1 joins the standalone lint set in both the
Makefile lint target and build.yml's lint job (-checks all,-ST1005),
mirroring the errcheck/ineffassign pin pattern. The golangci-lint OOM
story that originally disabled it is stale for the standalone binary:
a full run is ~12s wall locally.
Findings fixed (the full non-ST1005 set):
- ST1008: runSet (resources_set_test) returns (string, error), error last
- ST1003: CheckMaskIdColumn -> CheckMaskIDColumn (+ call sites/comments)
- ST1003: errors_as -> errorsAs, io_eof_or_similar -> ioEOFOrSimilar
- ST1020: CoreFloorText doc comment starts with the function name
ST1005 stays excluded: it flags ~58 customer-visible error strings that
need a wording review, not a mechanical sweep — separate follow-up.
Rebased onto develop: union-merged the lint job with develop's govulncheck
job (#278), coverage-floor step (#301) and deadcode advisory gate; kept the
audit comment #286 added above CheckMaskID*Column. The 'going back to the
action' comment in build.yml is KEPT (not deleted) — #6 is still open on
develop, so golangci-lint-action stays disabled and that rationale still
holds. Detached the four data_ingest_*.go header comments (#303 split) plus
exitcodes.go's (#284, which develop merged after this branch was cut) from
the package clause so the newly-enabled staticcheck gate is ST1000-clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
LukasWodka added a commit that referenced this pull request Jul 14, 2026
…findings
Pinned staticcheck@2025.1.1 joins the standalone lint set in both the
Makefile lint target and build.yml's lint job (-checks all,-ST1005),
mirroring the errcheck/ineffassign pin pattern. The golangci-lint OOM
story that originally disabled it is stale for the standalone binary:
a full run is ~12s wall locally.
Findings fixed (the full non-ST1005 set):
- ST1008: runSet (resources_set_test) returns (string, error), error last
- ST1003: CheckMaskIdColumn -> CheckMaskIDColumn (+ call sites/comments)
- ST1003: errors_as -> errorsAs, io_eof_or_similar -> ioEOFOrSimilar
- ST1020: CoreFloorText doc comment starts with the function name
ST1005 stays excluded: it flags ~58 customer-visible error strings that
need a wording review, not a mechanical sweep — separate follow-up.
Rebased onto develop: union-merged the lint job with develop's govulncheck
job (#278), coverage-floor step (#301) and deadcode advisory gate; kept the
audit comment #286 added above CheckMaskID*Column. The 'going back to the
action' comment in build.yml is KEPT (not deleted) — #6 is still open on
develop, so golangci-lint-action stays disabled and that rationale still
holds. Detached the four data_ingest_*.go header comments (#303 split) plus
exitcodes.go's (#284, which develop merged after this branch was cut) from
the package clause so the newly-enabled staticcheck gate is ST1000-clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
LukasWodka added a commit that referenced this pull request Jul 14, 2026
…findings (#302)
* ci: re-enable staticcheck (pinned standalone) + fix the 5 non-ST1005 findings
Pinned staticcheck@2025.1.1 joins the standalone lint set in both the
Makefile lint target and build.yml's lint job (-checks all,-ST1005),
mirroring the errcheck/ineffassign pin pattern. The golangci-lint OOM
story that originally disabled it is stale for the standalone binary:
a full run is ~12s wall locally.
Findings fixed (the full non-ST1005 set):
- ST1008: runSet (resources_set_test) returns (string, error), error last
- ST1003: CheckMaskIdColumn -> CheckMaskIDColumn (+ call sites/comments)
- ST1003: errors_as -> errorsAs, io_eof_or_similar -> ioEOFOrSimilar
- ST1020: CoreFloorText doc comment starts with the function name
ST1005 stays excluded: it flags ~58 customer-visible error strings that
need a wording review, not a mechanical sweep — separate follow-up.
Rebased onto develop: union-merged the lint job with develop's govulncheck
job (#278), coverage-floor step (#301) and deadcode advisory gate; kept the
audit comment #286 added above CheckMaskID*Column. The 'going back to the
action' comment in build.yml is KEPT (not deleted) — #6 is still open on
develop, so golangci-lint-action stays disabled and that rationale still
holds. Detached the four data_ingest_*.go header comments (#303 split) plus
exitcodes.go's (#284, which develop merged after this branch was cut) from
the package clause so the newly-enabled staticcheck gate is ST1000-clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* ci: goimports -local gate + Dependabot config (gomod weekly, actions monthly) (#304)
* ci: goimports -local gate + Dependabot config (gomod weekly, actions monthly)
goimports -local github.com/tracebloc/cli now blocks in both loops:
build.yml's lint job (pinned goimports@v0.48.0, same x/tools version as
the deadcode pin) and the Makefile's fmt-check target, with make fmt
extended to auto-fix. .golangci.yml already declared this grouping via
local-prefixes but nothing enforced it — 4 files had drifted (data.go,
data_test.go, ingestion_run_test.go, resources_set_test.go), fixed here
with import-grouping-only diffs.
.github/dependabot.yml extends the org's backend-only Dependabot pilot:
gomod weekly (k8s.io/* + sigs.k8s.io/* grouped, golang.org/x/* grouped),
github-actions monthly. Unlike backend's security-only config, the CLI
takes real version updates — customers install this binary, so staying
current is security posture (see #276). Org-wide rollout decision
flagged to Asad on the PR.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* ci: canonicalize import grouping in data_test.go for the goimports gate
Regroups imports into the layout goimports -local github.com/tracebloc/cli
emits (stdlib / third-party / tracebloc-local). gofmt and goimports only
sort within existing blank-line groups, so the manual groups passed
fmt-check as-is but were not the canonical single-block output; Bugbot and
our precheck both flagged the divergence. Verified idempotent under the
pinned goimports v0.48.0 and green on make fmt-check + go build ./...
Rebased onto ci/279 (post-#303 data.go split): data.go's import block is
already canonical from the #303 split, so its canonicalization here is a
no-op and dropped — this commit now regroups data_test.go only.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* ci: flip deadcode gate to blocking; delete the 3 dead #127 leftovers (#313)
* ci: goimports -local gate + Dependabot config (gomod weekly, actions monthly)
goimports -local github.com/tracebloc/cli now blocks in both loops:
build.yml's lint job (pinned goimports@v0.48.0, same x/tools version as
the deadcode pin) and the Makefile's fmt-check target, with make fmt
extended to auto-fix. .golangci.yml already declared this grouping via
local-prefixes but nothing enforced it — 4 files had drifted (data.go,
data_test.go, ingestion_run_test.go, resources_set_test.go), fixed here
with import-grouping-only diffs.
.github/dependabot.yml extends the org's backend-only Dependabot pilot:
gomod weekly (k8s.io/* + sigs.k8s.io/* grouped, golang.org/x/* grouped),
github-actions monthly. Unlike backend's security-only config, the CLI
takes real version updates — customers install this binary, so staying
current is security posture (see #276). Org-wide rollout decision
flagged to Asad on the PR.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* ci: canonicalize import grouping in data_test.go for the goimports gate
Regroups imports into the layout goimports -local github.com/tracebloc/cli
emits (stdlib / third-party / tracebloc-local). gofmt and goimports only
sort within existing blank-line groups, so the manual groups passed
fmt-check as-is but were not the canonical single-block output; Bugbot and
our precheck both flagged the divergence. Verified idempotent under the
pinned goimports v0.48.0 and green on make fmt-check + go build ./...
Rebased onto ci/279 (post-#303 data.go split): data.go's import block is
already canonical from the #303 split, so its canonicalization here is a
no-op and dropped — this commit now regroups data_test.go only.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* ci: flip deadcode gate to blocking; delete the 3 dead #127 leftovers
The deadcode CI step loses continue-on-error (and the Makefile target
its '|| true'): both now run scripts/deadcode-check.sh, which fails on
any function unreachable from ./cmd/tracebloc that isn't declared in
scripts/deadcode-allowlist.txt. The tool itself always exits 0, so the
old advisory step never could have blocked — the gate keys on output.
Deleted (verified still dead with the pinned deadcode@v0.48.0):
- config.clearAll + its three dedicated tests (TestClearAll,
TestClearAll_HomeError, TestClear) — logout uses Save, nothing else
ever called it
- push.allCategoryIDs — moved verbatim into category_registry_test.go
(the registry-pinning tests legitimately iterate every id; the
shipped binary shouldn't carry the helper)
- submit.isSubmitError — moved into client_test.go as the test-local
assertion helper it always was (orphaned 'errors' import dropped)
Allowlisted with reasons (the 4 legit findings): Status.String +
JobOutcome.String (fmt-reflection Stringers) and ReadLabelValues +
inferColumnType (di#349 test-only parity harnesses). Stale allowlist
entries warn without failing; line numbers are stripped so edits that
shift code don't red the gate.
Coverage floors still clear after the test deletions (cli 82.9% >= 68,
submit 80.3% >= 72).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@LukasWodka@saadqbal