Skip to content

test: isolate the suite from MOSHCODE_ENGINE_BIN_* overrides - #535

Merged
ralyodio merged 1 commit into
mainfrom
fix/tests-engine-bin-override
Sep 25, 2026
Merged

ralyodio merged 1 commit into
mainfrom
fix/tests-engine-bin-override

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

engines.mjs applies MOSHCODE_ENGINE_BIN_ at import (#530), and these
tests hand process.env to the CLI they spawn. With an override exported in
the shell running the suite, the stubs were swapped for the real build:

  • engines.test: ENGINES.codex.bin became an absolute path, so the codex
    stub was written to / and three codex launch tests failed.
  • mcp.test: the fan-out ran the real codex mcp add sentry against the
    operator's ~/.codex/config.toml instead of the stub.
  • tui-prd-errors: an empty PATH no longer meant "no engines"; /prd launched
    the real codex build.

Each file now drops MOSHCODE_ENGINE_BIN_* before it loads engines.mjs or
spawns the CLI. The override tests still set their own.

engines.mjs applies MOSHCODE_ENGINE_BIN_<KEY> at import (#530), and these
tests hand process.env to the CLI they spawn. With an override exported in
the shell running the suite, the stubs were swapped for the real build:

- engines.test: ENGINES.codex.bin became an absolute path, so the codex
  stub was written to <tmp>/<abs path> and three codex launch tests failed.
- mcp.test: the fan-out ran the real `codex mcp add sentry` against the
  operator's ~/.codex/config.toml instead of the stub.
- tui-prd-errors: an empty PATH no longer meant "no engines"; /prd launched
  the real codex build.

Each file now drops MOSHCODE_ENGINE_BIN_* before it loads engines.mjs or
spawns the CLI. The override tests still set their own.
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

1 finding(s) in the 3 file(s) this pull request changes.

MEDIUM: 1

Severity Rule Location
MEDIUM insecure-temp-file test/engines.test.mjs:164
100 pre-existing finding(s) elsewhere in the repository — **HIGH/CRITICAL**: 8 | **MEDIUM**: 81 | **LOW**: 11

Not introduced by this pull request. The full set is in the Security tab.

Severity Rule Location
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
HIGH sh-remote-script-execution install.sh:86
HIGH sh-remote-script-execution install.sh:90
HIGH sh-remote-script-execution install.sh:258
HIGH sh-remote-script-execution install.sh:269
HIGH sh-remote-script-execution install.sh:275
HIGH tls-verification-disabled src/dns.mjs:766
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:44
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:82
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:139
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:153
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:179
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:373
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:377
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:422
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:671
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:867
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:869
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:928

…and 80 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 13a49f9 into main Sep 25, 2026
6 checks passed
@ralyodio
ralyodio deleted the fix/tests-engine-bin-override branch September 25, 2026 06:55
ralyodio added a commit that referenced this pull request Sep 25, 2026
Swamp (swamp-club.com, github.com/systeminit/swamp) is a deterministic
automation CLI: typed models, workflow DAGs, versioned immutable runs, and a
vault that injects credentials at execution time so they never reach a prompt.

Wired as a TOOL rather than an engine. `/agents` is an alias for `engines`
(cli-schema.mjs:1751) and engines are interactive coding agents you land a herd
pane on. Swamp is driven BY an agent, ships skills into .claude/skills,
.cursor/skills and .agents/skills for Claude Code, Cursor, OpenCode and Codex,
and has no interactive session, so it belongs with railway, gh and supabase.
Moving it is a one-line change if that call is wrong.

Two installer details the entry has to carry: the vendor script prompts for
SWAMP CLUB signup partway through, which would stall a piped install, so
SWAMP_NONINTERACTIVE is set; and a non-root install lands in ~/.local/bin,
~/bin or ~/.swamp/bin depending on what is already on PATH, while the script
edits no shell rc, so all three are searched.

PRD 0019 covers what is worth taking. The lead item is heartbeat liveness:
moshcode infers engine state by regex-matching vendor output, which is why
Claude Code 2.1 broke detection when it overwrote the pane title and dropped
"? for shortcuts". Swamp tracks runs by heartbeat instead. Then immutable run
history, swarm pieces as a DAG rather than a fixed phase list, `moshcode
doctor`, and documented config precedence, which PR #535 paid for the lack of.

The binding constraint is in Non-Goals: swamp is AGPL-3.0 and moshcode is MIT,
so the ideas are rippable and the code is not.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant