Repository navigation
Expand file tree
/
Copy pathMakefile
More file actions
776 lines (687 loc) · 42.2 KB
/
Copy pathMakefile
File metadata and controls
776 lines (687 loc) · 42.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
.PHONY: help test test-cost test-fast test-unit billing-convergence-certify profile-only-check precommit-full test-precommit-extra test-postgres-migrations test-authority-postgres test-authority-postgres-direct test-authority-postgres-pooled qa-tests test-race test-fuzz test-reasoning-e2e-soak parity-checks parity-acp-plugin parity-cursorcliacp-plugin parity-cli-acp-plugins parity-openrouter-plugin parity-hosted-compatible-plugins parity-ollama-plugins parity-opencode-plugins parity-codex-plugins parity-local-compatible-plugins test-local-compatible-plugin-modules release-gates bench pgo-profile pgo-build node-independence quality-checks regex-hotpath-check arch-report qa vet lint vuln run hooks-install check-change-size backend-plugin-module-checks backend-plugin-absence-checks backend-plugin-security-checks backend-plugin-cross-platform-qa backend-plugin-release-gates-static backend-plugin-release-gates package-minimal package-full package-plugin-smoke docs-check knowledge-check example-config-check backend-plugin-example-check kiro-spec-check isolated-root-qa installed-plugin-smoke test-cursor-sdk-live test-cursor-sdk-live-bridge test-cursor-sdk-platform test-cursor-sdk-comparison-report tmp-clean test-openresponses-compliance test-openresponses-compliance-static
GO ?= go
# Explicit development scope, shared across Bash and PowerShell. No implicit
# full-suite fallback: agents must choose the package(s) they are iterating on.
PKGS ?=
MODULE ?= .
# Local shared VM budgets; CI and Windows retain their existing defaults.
ifneq ($(OS),Windows_NT)
LIP_LOCAL_AGENT_DEV := $(shell bash scripts/dev-cpu-defaults.sh --local)
endif
ifeq ($(LIP_LOCAL_AGENT_DEV),yes)
DEV_JOBS ?= 1
GOMAXPROCS ?= 2
LIP_TEST_PACKAGES ?= 1
LIP_TEST_PARALLEL ?= 2
export GOMAXPROCS
endif
DEV_JOBS ?= 4
DEV_REPEAT ?= 1
DEV_BASE ?=
DEV_PLAN ?= 0
DEV_FULL ?= 0
DEV_FRESH ?= 0
# Optional verification manifest. Set DEV_EVIDENCE=<path> to record the revision,
# dirty tree, scope, per-command results and per-step logs of a dev check.
DEV_EVIDENCE ?=
.PHONY: dev-test dev-test-changed dev-build dev-lint dev-doctor
dev-test:
$(GO) run -buildvcs=false ./tools/devcheck -task=test -module="$(MODULE)" -packages="$(PKGS)" -jobs=$(DEV_JOBS) -repeat=$(DEV_REPEAT) -evidence="$(DEV_EVIDENCE)"
dev-test-changed:
$(GO) run -buildvcs=false ./tools/devcheck -task=test -scope=changed -module="$(MODULE)" -packages="$(PKGS)" -base="$(DEV_BASE)" -plan=$(DEV_PLAN) -full=$(DEV_FULL) -fresh=$(DEV_FRESH) -jobs=$(DEV_JOBS) -repeat=$(DEV_REPEAT) -evidence="$(DEV_EVIDENCE)"
dev-build:
$(GO) run -buildvcs=false ./tools/devcheck -task=build -module="$(MODULE)" -packages="$(PKGS)" -jobs=$(DEV_JOBS) -repeat=$(DEV_REPEAT) -evidence="$(DEV_EVIDENCE)"
dev-lint:
$(GO) run -buildvcs=false ./tools/devcheck -task=lint -module="$(MODULE)" -packages="$(PKGS)" -jobs=$(DEV_JOBS) -repeat=$(DEV_REPEAT) -evidence="$(DEV_EVIDENCE)"
dev-doctor:
$(GO) run -buildvcs=false ./tools/devcheck -task=doctor -module="$(MODULE)" -evidence="$(DEV_EVIDENCE)"
# Test parallelism defaults to the machine's logical core count. The previous
# fixed -parallel=8 left >=8-core dev boxes half idle for t.Parallel-heavy
# suites (measured ~2.3x faster on a 16-core box). Override with
# LIP_TEST_PARALLEL=<n>, or replace the whole flag string via GO_TEST_FLAGS.
ifeq ($(OS),Windows_NT)
LIP_TEST_PARALLEL ?= $(if $(NUMBER_OF_PROCESSORS),$(NUMBER_OF_PROCESSORS),8)
else
LIP_TEST_PARALLEL ?= $(shell nproc 2>/dev/null || sysctl -n hw.ncpu 2>/dev/null || echo 8)
endif
# Package processes and parallel tests are separate budgets. Leave package
# concurrency at Go's native default unless measurements justify an override.
LIP_TEST_PACKAGES ?=
GO_TEST_FLAGS ?= -parallel=$(strip $(LIP_TEST_PARALLEL)) -timeout=10m $(if $(strip $(LIP_TEST_PACKAGES)),-p=$(strip $(LIP_TEST_PACKAGES)))
export GO_TEST_FLAGS
export LIP_TEST_PACKAGES
export LIP_TEST_PARALLEL
# Tests listed in .github/test-quarantine.txt fail on main and are skipped until
# their linked issue is fixed. GOFLAGS carries the -skip so every go test run
# from make targets and the scripts they call honours it without shell quoting.
LIP_TEST_QUARANTINE := $(filter Test% Fuzz% Benchmark% Example%,$(file < .github/test-quarantine.txt))
ifneq ($(LIP_TEST_QUARANTINE),)
LIP_EMPTY :=
LIP_SPACE := $(LIP_EMPTY) $(LIP_EMPTY)
GOFLAGS += -skip=^($(subst $(LIP_SPACE),|,$(LIP_TEST_QUARANTINE)))$$
export GOFLAGS
endif
# The Windows test-cost ratchet is explicit and opt-in. CI supplies the PR
# base SHA; local callers can override these values when comparing a known
# base or retaining artifacts outside the checkout.
TEST_COST_BASE_SHA ?=
TEST_COST_OUTPUT_ROOT ?=
TEST_COST_PARALLEL ?= 0
ifeq ($(OS),Windows_NT)
WINDOWS_TASK = powershell -NoProfile -ExecutionPolicy Bypass -File scripts/windows-task.ps1 -Target
endif
help:
@echo "Targets:"
@echo " make dev-test/dev-build/dev-lint PKGS='./path/...' [MODULE=connectors/name] [DEV_JOBS=4] [DEV_REPEAT=2] - scoped, measured iteration"
@echo " make dev-test-changed [DEV_BASE=origin/main] [DEV_PLAN=1] [DEV_FULL=1] [DEV_FRESH=1] - local affected-package tests; CI remains comprehensive"
@echo " make dev-doctor [MODULE=.] - effective toolchain/cache configuration and diagnostics"
@echo " make dev-test/dev-build/dev-lint [DEV_EVIDENCE=<path>] - additionally record revision, scope, results and per-step logs as a verification manifest"
@echo " make quality-checks - generate-feature-planes -check, gofmt, go mod tidy (no drift), go build, go vet, guard scripts, archtest; mod verify in CI or with LIP_VERIFY_MODULE_CACHE=1"
@echo " make profile-only-check [PROFILE_ONLY_BASE=<git-rev>] - fail-closed provider-profile change-surface ratchet"
@echo " make regex-hotpath-check - forbid regexp.MustCompile in frontends/runtime (see scripts/)"
@echo " make proto-check - buf lint + breaking + generation freshness for api/backendplugin/v1"
@echo " make test - quality-checks, full unit tests, and conformance parity checks"
@echo " make test-cost [TEST_COST_BASE_SHA=<git-rev>] [TEST_COST_OUTPUT_ROOT=<dir>] [TEST_COST_PARALLEL=<n>] - Windows-authoritative test-cost ratchet (opt-in; not part of make test)"
@echo " make test-fast - quality-checks then tests for staged packages (or all)"
@echo " make test-quick - single one-pass go test ./... for inner-loop feedback (no parity re-tags)"
@echo " make precommit-full - run the optional full local lint + vulnerability scan before commit"
@echo " make test-unit - go test $(GO_TEST_FLAGS) ./... (excludes //go:build precommit tests)"
@echo " make test-billing-schema - complete exhaustive schema and maximum-depth replay certification"
@echo " make billing-convergence-certify - fail-fast final billing architecture, integration, quality, docs, and race certification"
@echo " make test-db-parity-sqlite - canonical SQLite database parity tests across all registered components"
@echo " make test-db-parity-postgres-direct - repository-wide fail-closed direct PostgreSQL parity (DSN; Make sets LIP_REQUIRE_POSTGRES=1)"
@echo " make test-db-parity - repository-wide SQLite and direct PostgreSQL parity gate (the two backends run concurrently)"
@echo " make test-postgres-migrations - apply and verify dual-plane PostgreSQL migrations"
@echo " PostgreSQL gates are intentional opt-in: make test-authority-postgres-direct needs only a configured DSN (Make sets LIP_REQUIRE_POSTGRES=1); pooled/aggregate proof also requires LIP_TEST_POSTGRES_RUNTIME_IS_POOLER=1"
@echo " make test-authority-postgres-direct - direct PostgreSQL runtime proof (DSN; Make sets require flag)"
@echo " make test-authority-postgres-pooled - transaction-pooled runtime proof (requires LIP_TEST_POSTGRES_RUNTIME_IS_POOLER=1)"
@echo " make test-authority-postgres - aggregate direct + pooled proof (pooled attestation required)"
@echo " make test-precommit-extra - hygiene + executor matrices (-tags=precommit; also in pre-commit hook + CI)"
@echo " make test-race - race scan (skipped on Windows and dev hosts DESKTOP-I2CAJ6V/agent-dev, even with --strict; Linux/macOS CI: scripts/race-check.sh)"
@echo " make test-fuzz - short fuzz smoke (FUZZTIME=500ms locally; nightly CI uses 2s per target in .github/workflows/race-fuzz-nightly.yml)"
@echo " make test-reasoning-e2e-soak - opt-in reasoning preservation full-HTTP soak (sets LIP_REASONING_E2E_SOAK=1; not a PR/default gate; see docs/reasoning-output-preservation.md)"
@echo " make test-cursor-sdk-live - opt-in live Cursor SDK Node scenarios (CURSOR_SDK_LIVE=1 + CURSOR_API_KEY)"
@echo " make test-cursor-sdk-live-bridge - opt-in GoÔćĺNode live bridge lifecycle (-tags=cursorsdk_live_bridge; CURSOR_SDK_LIVE=1 + key)"
@echo " make test-cursor-sdk-platform - current-OS bridge platform smoke (fake bridge; no API key)"
@echo " make test-cursor-sdk-comparison-report - ACP vs SDK matrix report (synthetic/blocked offline; no credentials)"
@echo " make parity-checks - TCK certifications, protocol-owned parity suites, and bounded integration evidence"
@echo " make release-gates - conformance package + all critical fuzz targets (race is separate: test-race / CI; see docs/release-gates.md)"
@echo " make bench - benchmarks (testkit, stream, core runtime/routing/diag/toolcallrepair, frontend encoders)"
@echo " make pgo-profile - collect default.pgo from core benches (move under cmd/lipstd before build)"
@echo " make pgo-build - build cmd/lipstd (uses cmd/lipstd/default.pgo when present)"
@echo " make qa - quality-checks + one full test pass (-tags=precommit,integration) + lint + vuln + release-gates-static + OpenResponses compliance static gate"
@echo " make lint - mandatory correctness lint (golangci-lint if installed, else staticcheck)"
@echo " make lint-advisory - on-demand full lint incl. advisory style checks (modernize, paralleltest, thelper)"
@echo " make hooks-install - git config core.hooksPath .githooks (pre-commit: change-size + secrets + quality gate)"
@echo " make check-change-size - reject staged changes over 100 modified Go files (LIP_ALLOW_LARGE_CHANGE=1 to override)"
@echo " make kiro-spec-check SPEC=<name> - validate a Kiro spec development gate"
@echo " make isolated-root-qa - GOWORK=off QA on a temp root copy without connectors/support/Node/artifacts"
@echo " make node-independence - Linux: host build/unit/quality/package/CLI/smoke with every Node entry point masked out"
@echo " make installed-plugin-smoke - one lipstd binary; install release artifacts; same-binary inspect/doctor/invoke"
@echo " make docs-check - backend-plugin and extension-authoring documentation tests"
@echo " make knowledge-check - steering/ADR hybrid consistency"
@echo " make example-config-check - operator/example YAML + config/examples bootstrap inspect"
@echo " make backend-plugin-security-checks - executable-plugin threat-model adversarial + bounded fuzz"
@echo " make backend-plugin-cross-platform-qa - connector platform matrix compile/package + native lifecycle gates"
@echo " make backend-plugin-release-gates-static - release report/traceability/arch wiring (used by make qa)"
@echo " make backend-plugin-release-gates - full connector/support module matrix + root release suites"
@echo " make run - go run ./cmd/lipstd"
@echo " make tmp-clean - dry-run scan of stale project-owned TEMP residue (Windows; TMP_CLEAN_APPLY=1 or scripts/tmp-clean.ps1 -Apply to delete)"
# Validate a provider-profile-only change surface against a Git base. This is
# explicit rather than part of every quality run because the normal branch may
# intentionally contain core/ABI/composition work alongside profile work.
PROFILE_ONLY_BASE ?=
profile-only-check:
ifeq ($(strip $(PROFILE_ONLY_BASE)),)
$(GO) run ./internal/archtest/tools/changesurface/cmd -profile-only -json
else
$(GO) run ./internal/archtest/tools/changesurface/cmd -base "$(PROFILE_ONLY_BASE)" -profile-only -json
endif
quality-checks:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/quality-checks.ps1
else
@bash scripts/quality-checks.sh
endif
# Advisory architecture metrics report (non-failing). Run on demand to spot
# hotspot/line/import drift.
arch-report:
@$(GO) run ./scripts/arch-report.go
regex-hotpath-check:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/regex-hotpath-check.ps1
else
@bash scripts/regex-hotpath-check.sh
endif
proto-check:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/proto-check.ps1
else
@bash scripts/proto-check.sh
endif
quality-checks-fast: export LIP_SKIP_GO_COMPILE_CHECKS=1
quality-checks-fast: export LIP_SKIP_ARCHTEST=1
quality-checks-fast:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/quality-checks.ps1
else
@bash scripts/quality-checks.sh
endif
# The ratchet's PowerShell orchestrator is the Windows-authoritative
# comparison of the policy targets. Fail closed on other hosts so a local
# POSIX invocation cannot masquerade as authoritative evidence.
test-cost:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-cost-ratchet.ps1 -BaseSHA "$(TEST_COST_BASE_SHA)" -OutputRoot "$(TEST_COST_OUTPUT_ROOT)" -Parallel "$(TEST_COST_PARALLEL)"
else
@echo "make test-cost is Windows-only; Windows is authoritative for this ratchet." >&2
@exit 1
endif
test: quality-checks-fast test-unit parity-checks
test-fast: quality-checks-fast
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-staged.ps1
else
@bash scripts/test-staged.sh
endif
precommit-full:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/precommit-full.ps1
else
@LIP_PRECOMMIT_FULL=1 bash scripts/quality-gate.sh
endif
billing-convergence-certify:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/billing-convergence-certify.ps1
else
@bash scripts/billing-convergence-certify.sh
endif
# Exhaustive billing schema certification preserves every generated case and seam.
# It is separate from the default unit budget and remains part of integration QA.
BILLING_SCHEMA_TIMEOUT ?= 30m
# qa-tests runs the integration-tagged graph, which admits the exhaustive billing
# certification sweep (~636k production ratings, measured at ~90% of a 10m budget
# on an otherwise idle host). CI already isolates that sweep behind
# BILLING_SCHEMA_TIMEOUT via `make test-billing-schema`; the wide local gate must
# carry the same budget or it fails on cost, not on a defect. Only the -timeout
# value is replaced: every other flag, package list, and test selection stays
# unchanged.
QA_TESTS_GO_TEST_FLAGS = $(filter-out -timeout=%,$(GO_TEST_FLAGS)) -timeout=$(BILLING_SCHEMA_TIMEOUT)
.PHONY: test-billing-schema
test-billing-schema:
$(GO) test -count=1 -timeout=$(BILLING_SCHEMA_TIMEOUT) -tags=integration -run '^(TestGeneratedSchema|TestSchemaModel(Structure|Commercial)Sweep|TestSchemaModelOrderInvariance|TestMetamorphic(PricingMetamorphism|StructuralVerdictAgreesWithModel)|TestSupportAgreementShadowPredicate|TestReplayDeepestPublishableChainTraversalIsBounded)' ./internal/core/billing
test-unit:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) test-unit
else
$(GO) test $(GO_TEST_FLAGS) ./...
endif
# Inner-loop fast path: exactly one untagged repository test run, without the
# parity/conformance re-tag passes `make test` adds. `make test-unit` has the
# same selection; this alias exists so the fast path is discoverable and
# documented. Use `make test` (comprehensive) or `make qa` (wide) before
# delivery.
test-quick: test-unit
# Canonical repository-wide database dialect parity targets.
# Delegated directly to the catalog-driven runner (no duplicate package lists).
.PHONY: test-db-parity-sqlite test-db-parity-postgres-direct test-db-parity
test-db-parity-sqlite:
$(GO) run ./internal/testkit/dbparity/cmd sqlite
test-db-parity-postgres-direct:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -Command "[Environment]::SetEnvironmentVariable('LIP_REQUIRE_POSTGRES','1','Process'); if (-not [Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_TEST_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_MANAGED_POSTGRES_DSN','Process'),'Process') }; if (-not [Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_TEST_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_ADMIN_DSN','Process'),'Process') }; & '$(GO)' run ./internal/testkit/dbparity/cmd postgres-direct"
else
@LIP_REQUIRE_POSTGRES=1 LIP_TEST_POSTGRES_DSN="$${LIP_TEST_POSTGRES_DSN:-$${LIP_MANAGED_POSTGRES_DSN:-$$LIP_TEST_POSTGRES_ADMIN_DSN}}" $(GO) run ./internal/testkit/dbparity/cmd postgres-direct
endif
test-db-parity:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -Command "[Environment]::SetEnvironmentVariable('LIP_REQUIRE_POSTGRES','1','Process'); if (-not [Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_TEST_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_MANAGED_POSTGRES_DSN','Process'),'Process') }; if (-not [Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_TEST_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_ADMIN_DSN','Process'),'Process') }; & '$(GO)' run ./internal/testkit/dbparity/cmd all"
else
@LIP_REQUIRE_POSTGRES=1 LIP_TEST_POSTGRES_DSN="$${LIP_TEST_POSTGRES_DSN:-$${LIP_MANAGED_POSTGRES_DSN:-$$LIP_TEST_POSTGRES_ADMIN_DSN}}" $(GO) run ./internal/testkit/dbparity/cmd all
endif
# PostgreSQL is the required proof surface for cross-instance authority
# semantics. The test helper fails instead of skipping when this target is
# invoked without a configured DSN.
test-authority-postgres-direct:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -Command "[Environment]::SetEnvironmentVariable('LIP_REQUIRE_POSTGRES','1','Process'); if ([Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_ADMIN_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_TEST_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_ADMIN_DSN','Process'),'Process') }; & '$(GO)' test $(GO_TEST_FLAGS) -tags=integration -skip 'Pooled' ./internal/infra/usageauthority/authoritystore ./internal/infra/concurrencyauthority/leasestore ./internal/infra/metering/journalstore ./internal/infra/terminalwork/workstore"
else
@LIP_REQUIRE_POSTGRES=1 LIP_TEST_POSTGRES_DSN="$${LIP_TEST_POSTGRES_ADMIN_DSN:-$$LIP_TEST_POSTGRES_DSN}" $(GO) test $(GO_TEST_FLAGS) -tags=integration -skip 'Pooled' ./internal/infra/usageauthority/authoritystore ./internal/infra/concurrencyauthority/leasestore ./internal/infra/metering/journalstore ./internal/infra/terminalwork/workstore
endif
test-postgres-migrations:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -Command "if (-not [Environment]::GetEnvironmentVariable('LIP_MIGRATION_POSTGRES_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_MIGRATION_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_ADMIN_DSN','Process'),'Process') }; if (-not [Environment]::GetEnvironmentVariable('LIP_MIGRATION_POSTGRES_DSN','Process')) { [Environment]::SetEnvironmentVariable('LIP_MIGRATION_POSTGRES_DSN',[Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_DSN','Process'),'Process') }; & '$(GO)' run ./cmd/lipstd migrate --components usage-authority,concurrency,metering"
else
@LIP_MIGRATION_POSTGRES_DSN="$${LIP_MIGRATION_POSTGRES_DSN:-$${LIP_TEST_POSTGRES_ADMIN_DSN:-$$LIP_TEST_POSTGRES_DSN}}" $(GO) run ./cmd/lipstd migrate --components usage-authority,concurrency,metering
endif
# Transaction-pooled runtime proof. Requires LIP_TEST_POSTGRES_DSN to be an
# actual transaction-pooler endpoint and explicit topology attestation.
# Uses normal parallelism (-parallel=8 by default); do not force -parallel=1.
test-authority-postgres-pooled:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -Command "[Environment]::SetEnvironmentVariable('LIP_REQUIRE_POSTGRES_POOLER','1','Process'); if ([Environment]::GetEnvironmentVariable('LIP_TEST_POSTGRES_RUNTIME_IS_POOLER','Process') -ne '1') { throw 'set LIP_TEST_POSTGRES_RUNTIME_IS_POOLER=1 only when LIP_TEST_POSTGRES_DSN is a transaction-pooler endpoint' }; & '$(GO)' test $(GO_TEST_FLAGS) -tags=integration -run 'Pooled' ./internal/infra/usageauthority/authoritystore ./internal/infra/concurrencyauthority/leasestore ./internal/infra/metering/journalstore ./internal/infra/terminalwork/workstore ./internal/infra/runtimebundle"
else
@test "$${LIP_TEST_POSTGRES_RUNTIME_IS_POOLER:-}" = "1" || { echo "set LIP_TEST_POSTGRES_RUNTIME_IS_POOLER=1 only when LIP_TEST_POSTGRES_DSN is a transaction-pooler endpoint" >&2; exit 1; }
@LIP_REQUIRE_POSTGRES_POOLER=1 $(GO) test $(GO_TEST_FLAGS) -tags=integration -run 'Pooled' ./internal/infra/usageauthority/authoritystore ./internal/infra/concurrencyauthority/leasestore ./internal/infra/metering/journalstore ./internal/infra/terminalwork/workstore ./internal/infra/runtimebundle
endif
test-authority-postgres: test-postgres-migrations test-authority-postgres-direct test-authority-postgres-pooled
test-precommit-extra:
$(GO) test $(GO_TEST_FLAGS) -tags=precommit ./internal/qa/... ./internal/core/runtime/...
test-race:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/race-check.ps1
else
@bash scripts/race-check.sh
endif
# Short fuzz smoke (extend FUZZTIME locally, e.g. FUZZTIME=30s make test-fuzz)
# POSIX runs scripts/fuzz-smoke.sh: the canonical target list lives in
# scripts/fuzz-targets.tsv (shared with the Windows runner) and targets execute
# concurrently instead of paying per-target link/spawn cost serially.
FUZZTIME ?= 500ms
# Route each fuzz invocation through a wrapper that tolerates the Go fuzz
# engine's spurious "context deadline exceeded" at -fuzztime expiry
# (golang/go#75804, Go 1.25-1.26.x). On Windows `go test` runs directly: local
# fuzz smoke is short and a rare flake is cheap to re-run, and bash may be absent.
ifeq ($(OS),Windows_NT)
FUZZ_WRAPPER := $(GO) test
else
FUZZ_WRAPPER := bash "$(CURDIR)/scripts/fuzz-run.sh"
endif
# Opt-in reasoning-preservation full HTTP soak (1000├Ś100 default). Not part of
# make test / test-unit / qa / PR gates. Overrides: LIP_REASONING_E2E_SEEDS,
# LIP_REASONING_E2E_TURNS, LIP_REASONING_E2E_WORKERS. Single-seed replay:
# LIP_REASONING_E2E_MODE + LIP_REASONING_E2E_SEED.
REASONING_E2E_SOAK_TIMEOUT ?= 6h
test-reasoning-e2e-soak:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -Command "[Environment]::SetEnvironmentVariable('LIP_REASONING_E2E_SOAK','1','Process'); & '$(GO)' test -parallel=8 -timeout=$(REASONING_E2E_SOAK_TIMEOUT) -tags=precommit -run '^TestReasoningPreservationHTTP_Soak$$' -count=1 ./internal/stdhttp/"
else
@LIP_REASONING_E2E_SOAK=1 $(GO) test -parallel=8 -timeout=$(REASONING_E2E_SOAK_TIMEOUT) -tags=precommit -run '^TestReasoningPreservationHTTP_Soak$$' -count=1 ./internal/stdhttp/
endif
test-fuzz:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) test-fuzz
else
@bash "$(CURDIR)/scripts/fuzz-smoke.sh"
endif
test-cursor-sdk-live:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-cursor-sdk-live.ps1
else
@bash scripts/test-cursor-sdk-live.sh
endif
test-cursor-sdk-live-bridge:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-cursor-sdk-live-bridge.ps1
else
@bash scripts/test-cursor-sdk-live-bridge.sh
endif
test-cursor-sdk-platform:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-cursor-sdk-platform.ps1
else
@bash scripts/test-cursor-sdk-platform.sh
endif
test-cursor-sdk-comparison-report:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-cursor-sdk-comparison-report.ps1
else
@bash scripts/test-cursor-sdk-comparison-report.sh
endif
ifeq ($(OS),Windows_NT)
parity-checks:
@$(WINDOWS_TASK) parity-checks
else
parity-checks: parity-tcks parity-protocol-suites parity-connectors parity-sentinel
endif
parity-tcks:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-tcks
else
$(GO) test $(GO_TEST_FLAGS) ./internal/testkit/contract/...
$(GO) test $(GO_TEST_FLAGS) ./internal/providerprofiles/...
$(GO) test $(GO_TEST_FLAGS) ./pkg/lipsdk/backendplugin/contracttest/...
$(GO) test $(GO_TEST_FLAGS) ./internal/testkit/compatibleparity/... -run 'CompatibleParity'
endif
parity-protocol-suites:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-protocol-suites
else
$(GO) test $(GO_TEST_FLAGS) '-tags=precommit,integration' ./internal/testkit/conformance/...
endif
parity-connectors:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-connectors
else
@$(MAKE) parity-acp-plugin
@$(MAKE) parity-openrouter-plugin
@$(MAKE) parity-hosted-compatible-plugins
endif
parity-sentinel:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-sentinel
else
$(GO) test $(GO_TEST_FLAGS) '-tags=integration' ./internal/testkit/conformance -run '^TestBoundedSentinel'
endif
# Phase 6 ACP external connector parity (testemu/scripted ACP; not live Cursor/Gemini/Agy CLIs).
parity-acp-plugin:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-acp-plugin
else
cd connector-support/acp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'KillProcessTree_|ProcessTree_CrossCompile|PID|Pool|Cancel|Open_|MapSession|Scripted' ./...
cd connectors/acp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_' ./...
endif
parity-cursorcliacp-plugin:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-cursorcliacp-plugin
else
cd connector-support/acp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'KillProcessTree_|ProcessTree_CrossCompile' ./...
cd connectors/cursorcliacp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_' ./...
endif
parity-cli-acp-plugins:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-cli-acp-plugins
else
cd connectors/geminicliacp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_' ./...
cd connectors/agycliacp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_' ./...
cd connectors/cursorcliacp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_' ./...
endif
# Phase 7 OpenAI-compatible external connectors (deterministic emulators; not live providers).
parity-openrouter-plugin:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-openrouter-plugin
else
cd connector-support/openaicompat && GOWORK=off $(GO) test $(GO_TEST_FLAGS) ./...
cd connectors/openrouter && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestBilling_' ./...
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest -run 'OpenRouter|Phase7_'
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/runtimebundle -run 'TestPhase7_OpenRouter'
endif
parity-hosted-compatible-plugins:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-hosted-compatible-plugins
else
cd connectors/nvidia && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
cd connectors/huggingface && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest -run 'Phase7_'
endif
parity-ollama-plugins:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-ollama-plugins
else
cd connectors/ollama && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
endif
parity-opencode-plugins:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-opencode-plugins
else
cd connectors/opencode && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest -run 'OpenCode|Phase8_'
endif
parity-codex-plugins:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-codex-plugins
else
cd connectors/codex && GOWORK=off $(GO) test $(GO_TEST_FLAGS) ./...
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest -run 'Codex|Phase8_.*Codex|TestCodex_'
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/runtimebundle -run 'TestPhase8_Codex'
endif
test-local-compatible-plugin-modules:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) test-local-compatible-plugin-modules
else
cd connectors/llamacpp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
cd connectors/lmstudio && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
cd connectors/vllm && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'TestParity_|TestDescribe_|TestConfigure_|TestInventory_' ./...
endif
# The three local-compatible module tests run exactly once per parity
# invocation. On POSIX the prerequisite owns them and the recipe owns the Phase 7
# archtest; on Windows the windows-task.ps1 parity case owns both in one script
# call, so this prerequisite is guarded POSIX-only to avoid a double run.
ifneq ($(OS),Windows_NT)
parity-local-compatible-plugins: test-local-compatible-plugin-modules
endif
parity-local-compatible-plugins:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) parity-local-compatible-plugins
else
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest -run 'Phase7_'
endif
backend-plugin-absence-checks:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/backend-plugin-absence-checks.ps1
else
@bash scripts/backend-plugin-absence-checks.sh
endif
release-gates: parity-checks quality-checks
$(GO) test $(GO_TEST_FLAGS) ./internal/core/billing -run '^TestPhase7_DeterministicShadowRatingAcceptanceGate$$'
@$(MAKE) test-fuzz
bench:
$(GO) test -bench=. -benchmem -run=Benchmark ./internal/testkit/... ./internal/core/stream/... \
./internal/core/securesession/... \
./internal/core/runtime/... ./internal/core/routing/... ./internal/core/diag/... \
./internal/plugins/features/toolcallrepair/... \
./internal/infra/concurrencyauthority/leasestore/... \
./internal/infra/metering/journalstore/... \
./internal/infra/usageauthority/authoritystore/... \
./internal/plugins/frontends/openailegacy/... \
./internal/plugins/frontends/gemini/... \
./internal/plugins/frontends/openairesponses/... \
./internal/plugins/frontends/anthropic/...
# Collect a CPU profile suitable for placing as cmd/lipstd/default.pgo, then rebuild with PGO.
# Requires a representative bench/workload; do not commit synthetic profiles by default.
pgo-profile:
$(GO) test -cpuprofile=default.pgo -bench=. -benchtime=3s -run=^$$ ./internal/core/runtime/... ./internal/core/stream/...
@echo "Move default.pgo next to the main package (e.g. cmd/lipstd/default.pgo) before building."
pgo-build:
$(GO) build -o bin/lipstd ./cmd/lipstd
# Single test invocation matches CI (go test -tags=precommit,integration ./...) and avoids compiling twice.
# Static release-gate wiring only (no recursive full backend-plugin-release-gates / module matrix).
# The OpenResponses compliance static gate (Task 8.5) verifies the wiring and the
# release-ready evidence without re-running the huge tagged suites that qa-tests
# already covers; the full `test-openresponses-compliance` script remains the
# standalone Task 8.5 gate.
# The comprehensive lint target below owns lint once; the preliminary quality
# guards retain formatting, generation, module and repository-policy checks.
qa: export LIP_SKIP_LINT=1
qa: quality-checks-fast qa-tests lint vuln backend-plugin-release-gates-static test-openresponses-compliance-static
qa-tests:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) qa-tests
else
@if [ "$$LIP_SKIP_QA_TESTS" = "1" ]; then \
echo "Skipping duplicate root tests pass (LIP_SKIP_QA_TESTS=1); running tagged delta packages..."; \
$(GO) test $(QA_TESTS_GO_TEST_FLAGS) -tags=precommit,integration ./internal/qa/... ./internal/core/runtime/... ./internal/stdhttp/... ./internal/testkit/conformance/... ./tools/backendplugin/... ./internal/core/billing/...; \
else \
$(GO) test $(QA_TESTS_GO_TEST_FLAGS) -tags=precommit,integration ./...; \
fi
endif
vet:
$(GO) vet ./...
# Install golangci-lint (preferred) or staticcheck: https://golangci-lint.run/
lint:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) lint
else
@bash scripts/lint-all-modules.sh
endif
# On-demand advisory style lint (modernize/paralleltest/thelper). The canonical
# `make lint`/`quality-checks`/`qa`/`precommit-full` gates enforce the mandatory
# correctness linters only (scripts/lint-all-modules.* pass
# --disable=modernize,paralleltest,thelper); this target reports the full set
# without treating repository-wide style debt as a release blocker.
lint-advisory:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/lint-all-modules.ps1 -Advisory
else
@bash scripts/lint-all-modules.sh --advisory
endif
vuln:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) vuln
else
$(GO) tool govulncheck ./...
endif
run:
$(GO) run ./cmd/lipstd --config ./config/config.yaml
# Conservative cleanup of stale project-owned temp residue left by hard-killed
# tests. Dry-run by default; pass TMP_CLEAN_APPLY=1 to delete. Never invoked
# automatically by tests or serve. See scripts/tmp-clean.ps1.
tmp-clean:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/tmp-clean.ps1 $(if $(TMP_CLEAN_APPLY),-Apply,)
else
@echo "tmp-clean is Windows-only. On POSIX, review \$${TMPDIR:-/tmp} manually and remove only the allowlisted project prefixes listed in scripts/tmp-clean.ps1."
endif
hooks-install:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/install-hooks.ps1
else
@bash scripts/install-hooks.sh
endif
check-change-size:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/check-change-size.ps1 --staged
else
@bash scripts/check-change-size.sh --staged
endif
# Phase 5: structural connector module discovery + GOWORK=off isolation (no recursive make).
backend-plugin-module-checks:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/backend-plugin-module-checks.ps1
else
@LIP_DISABLE_VCS_STAMPING=1 bash scripts/backend-plugin-module-checks.sh
endif
PACKAGE_DEST ?= $(CURDIR)/.golip-package-staging
package-minimal:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/package-plugins.ps1 -Profile minimal -Dest "$(PACKAGE_DEST)/minimal"
else
@bash scripts/package-plugins.sh minimal "$(PACKAGE_DEST)/minimal"
endif
package-full:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/package-plugins.ps1 -Profile full -Dest "$(PACKAGE_DEST)/full"
else
@bash scripts/package-plugins.sh full "$(PACKAGE_DEST)/full"
endif
package-plugin-smoke: package-minimal package-full
@matches=$$($(GO) test $(GO_TEST_FLAGS) -tags=integration -list 'TestPackage_|TestDiscoverModules_' ./tools/backendplugin/ | awk '/^Test[A-Za-z0-9_]+$$/ { count++ } END { print count+0 }'); test "$$matches" -gt 0 || { echo "backend-plugin package selector matched zero tests" >&2; exit 1; }; $(GO) test $(GO_TEST_FLAGS) -tags=integration ./tools/backendplugin/ -run 'TestPackage_|TestDiscoverModules_'
docs-check:
$(GO) test $(GO_TEST_FLAGS) ./docs/backend-plugins/ -run 'TestDocs|TestExample|TestOperator|TestExampleConfig|TestThreat'
# Phase 9.3: executable-plugin threat model adversarial suite + bounded fuzz.
# Pair with `make test-fuzz` and `make test-race` (Windows race is skip-only).
backend-plugin-security-checks:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) backend-plugin-security-checks
else
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/backendplugins/...
$(GO) test $(GO_TEST_FLAGS) ./pkg/lipsdk/backendplugin/...
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/diagredact/...
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/runtimebundle/ -run 'TestBuild_localOnly|TestBuild_unknownBackendCredential|TestBuild_oauthUser|TestBuild_unsupportedBackend|TestBuild_staticBackend|TestBuild_noneBackend|TestBuild_strictAuthoritative'
$(GO) test $(GO_TEST_FLAGS) ./docs/backend-plugins/ -run 'TestThreat|TestOperator_|TestDocs_'
$(FUZZ_WRAPPER) -fuzz=^FuzzManifest$$ -fuzztime=$(FUZZTIME) -run=^$$ ./internal/infra/backendplugins/manifest
$(FUZZ_WRAPPER) -fuzz=^FuzzServerFrame$$ -fuzztime=$(FUZZTIME) -run=^$$ ./pkg/lipsdk/backendplugin
endif
# Phase 9.4: structural connector/support discovery, claimed GOOS/GOARCH compile matrix,
# host secure-profile false-claim rejection, package matrix match, native lifecycle/IPC gates.
# Emits machine-readable unsupported pairs to .golip-crossplatform-matrix.json (gitignored).
backend-plugin-cross-platform-qa:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) backend-plugin-cross-platform-qa
else
$(GO) run ./tools/backendplugin/crossplatform_qa -root . -out .golip-crossplatform-matrix.json -skip-native $(if $(filter 1,$(CROSS_PLATFORM_SKIP_COMPILE)),-skip-compile,) $(if $(strip $(CROSS_PLATFORM_SELECT)),-select "$(CROSS_PLATFORM_SELECT)",)
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/backendplugins/... -run 'TestAdversarial_|TestActivate_|TestStream_|TestDigest|TestManifest|TestDiscover|TestShutdown|TestReap|TestPeer|TestChannel|TestExact|TestUpgrade|TestRollback|TestUninstall|TestConfig|TestSecrecy|TestUnauthorized|TestProtected|TestLaunch|TestKill|TestCancel'
$(GO) test $(GO_TEST_FLAGS) ./pkg/lipsdk/backendplugin/... -run 'Test'
cd connector-support/acp && GOWORK=off $(GO) test $(GO_TEST_FLAGS) -run 'KillProcessTree_|ProcessTree_CrossCompile|Cancel' ./...
$(MAKE) package-plugin-smoke
@matches=$$($(GO) test $(GO_TEST_FLAGS) -tags=integration -list 'TestCrossPlatformQA_|TestPackage_|TestDiscoverModules_' ./tools/backendplugin/ | awk '/^Test[A-Za-z0-9_]+$$/ { count++ } END { print count+0 }'); test "$$matches" -gt 0 || { echo "backend-plugin cross-platform selector matched zero tests" >&2; exit 1; }; $(GO) test $(GO_TEST_FLAGS) -tags=integration ./tools/backendplugin/ -run 'TestCrossPlatformQA_|TestPackage_|TestDiscoverModules_'
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest/ -run 'TestBackendPluginCrossPlatform_'
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/backendplugins/processhost/ -run 'TestHostSecureProfiles_'
endif
# Phase 9.5 (fast): structural discovery + deterministic release report/traceability + wiring tests.
# Integrated into `make qa` without re-running the full module matrix or nested `make qa`.
backend-plugin-release-gates-static:
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) backend-plugin-release-gates-static
else
$(GO) run ./tools/backendplugin/release_gates -root . -out .golip-release-gates-report.json -mode=static
@matches=$$($(GO) test $(GO_TEST_FLAGS) -tags=integration -list 'TestReleaseGates_' ./tools/backendplugin/ | awk '/^Test[A-Za-z0-9_]+$$/ { count++ } END { print count+0 }'); test "$$matches" -gt 0 || { echo "backend-plugin release-gates selector matched zero tests" >&2; exit 1; }; $(GO) test $(GO_TEST_FLAGS) -tags=integration ./tools/backendplugin/ -run 'TestReleaseGates_'
$(GO) test $(GO_TEST_FLAGS) ./tools/backendplugin/release_gates/ -run 'TestParseRequirementIDs_|TestListMatchingTests_|TestValidateSelectors_'
$(GO) test $(GO_TEST_FLAGS) ./internal/archtest/ -run 'TestBackendPluginReleaseGates_'
endif
# Phase 9.5 (full local): orchestrated by release_gates -mode=full (module matrix + root package
# gates + package/security/absence/isolated/installed smoke + race honesty). Avoids fragile
# Makefile -run filters; selectors are validated via go test -list inside the tool.
backend-plugin-release-gates: backend-plugin-release-gates-static
ifeq ($(OS),Windows_NT)
@$(WINDOWS_TASK) backend-plugin-release-gates
else
$(GO) run ./tools/backendplugin/release_gates -root . -out .golip-release-gates-report.json -mode=full
endif
# Steering/ADR hybrid consistency (Phase 9.1).
knowledge-check:
$(GO) test $(GO_TEST_FLAGS) ./docs/knowledge/ -run 'TestKnowledge_'
# Operator guides + every config/examples YAML via bootstrap inspect (Phase 9.2).
example-config-check: docs-check
$(GO) test $(GO_TEST_FLAGS) ./internal/infra/runtimebundle/ -run 'TestConfigExamples_passBootstrapInspect'
# Validate Kiro specification artifacts. SPEC is required (e.g. cursor-sdk-backend).
kiro-spec-check:
ifndef SPEC
$(error SPEC is required, e.g. make kiro-spec-check SPEC=<spec-name>)
endif
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/kiro-spec-check.ps1 -Spec "$(SPEC)"
else
@bash scripts/kiro-spec-check.sh "$(SPEC)"
endif
backend-plugin-example-check: docs-check
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/backend-plugin-example-check.ps1
else
@bash scripts/backend-plugin-example-check.sh
endif
# Phase 8.5: isolated root module QA (no connectors/connector-support in the copied tree).
isolated-root-qa:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/isolated-root-qa.ps1
else
@bash scripts/isolated-root-qa.sh
endif
# Host no-Node verification (spec cursor-sdk-standalone, task 5.1): replays the
# documented host build/verification surface with every Node entry point removed
# inside an unprivileged private mount namespace, proven by negative controls.
# Linux-authoritative: no Windows host can provide the required namespaces, so the
# Windows route reports that instead of degrading to a PATH-only proof.
node-independence:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/check-node-independence.ps1
else
@bash scripts/check-node-independence.sh --set full
endif
# Phase 8.5: unchanged lipstd binary gains optional kinds solely via installed artifacts.
installed-plugin-smoke:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/installed-plugin-smoke.ps1
else
@bash scripts/installed-plugin-smoke.sh
endif
# OpenResponses full-path compliance suite (spec Phase 8, Task 8.5): independent
# client -> frontend -> core -> OpenResponses backend -> independent provider,
# the direct independent-emulator wire suites, the 45-cell matrix, and the
# emulator boundary gates.
test-openresponses-compliance:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-openresponses-compliance.ps1
else
@bash scripts/test-openresponses-compliance.sh
endif
# Fast Task 8.5 wiring/evidence gate wired into `make qa`: verifies the
# compliance scripts, Makefile wiring, and docs reference exist and runs the
# default-build evidence validators plus the emulator boundary gates, without
# re-running the huge tagged conformance/integration suites that qa-tests covers.
test-openresponses-compliance-static:
ifeq ($(OS),Windows_NT)
@powershell -NoProfile -ExecutionPolicy Bypass -File scripts/test-openresponses-compliance.ps1 -Static
else
@bash scripts/test-openresponses-compliance.sh -static
endif