ci+fix: run snapshot tests in CI and load .env only when recording

Holistic-review fixes for integration gaps the per-commit reviews missed:

- CI now runs `pnpm run test:snapshot` (a step after the coverage gate). It was
  wired into pre-push but not .github/workflows/ci.yml, so the RFC/AGENTS claim
  that snapshot replay runs in the default PR gate was only half-true — CI is
  the real gate.
- vitest.snapshot.config.ts loads the repo .env ONLY when DSH_SNAPSHOT=record.
  Loading it unconditionally contradicted the replay safety story (replay must
  never reach the network), and runScenario forwards process.env to the child.
  Non-ENOENT load errors now surface instead of being swallowed.
- start.ts: the graceful-shutdown comment said "RECORD runs" but the path
  applies to both snapshot modes (replay also closes stdin → dispose → exit).
- docs/development.md: list the new pre-push snapshot job and the CI snapshot
  gate.
This commit is contained in:
Tianyi Cui
2026-06-19 04:28:09 +08:00
parent f09cc81c03
commit 9a5a3835c8
4 changed files with 30 additions and 14 deletions
+11 -7
View File
@@ -8,13 +8,17 @@ import { defineConfig } from 'vitest/config'
// `pnpm run test:snapshot:record` (DSH_SNAPSHOT=record + -u) re-records the
// fixtures against the real API and refreshes the goldens.
//
// Replay loads no .env; record reads DEEPSEEK_API_KEY from the env or a
// gitignored repo-root .env (loaded here, mirroring the e2e config), so a
// contributor with a key only in .env can still record.
try {
process.loadEnvFile(new URL('.env', import.meta.url).pathname)
} catch {
// No .env — fine; replay needs no key and record reads it from the env.
// Replay loads no .env (it must never reach the network — a recorded fixture
// drives the model). Record reads DEEPSEEK_API_KEY from the env or a gitignored
// repo-root .env, so a contributor with a key only in .env can still record.
if (process.env.DSH_SNAPSHOT === 'record') {
try {
process.loadEnvFile(new URL('.env', import.meta.url).pathname)
} catch (error) {
// ENOENT (no .env) is fine — the key may already be in the environment.
// Surface any other failure rather than silently recording with wrong env.
if ((error as NodeJS.ErrnoException | null)?.code !== 'ENOENT') throw error
}
}
export default defineConfig({