Skip to content

test: add packaged host entry smoke check in workerd - #2

Merged
jlucaso1 merged 2 commits into
mainfrom
fm/cloudflare-example-issue4-consumer-r1
Sep 23, 2026
Merged

jlucaso1 merged 2 commits into
mainfrom
fm/cloudflare-example-issue4-consumer-r1

Conversation

@jlucaso1

@jlucaso1 jlucaso1 commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Intent

quero agora que olhe esse relatorio de revisão e spawne bots pra resolver tudo, tanto na baileyrs quanto no nosso exemplo https://github.com/jlucaso1/agent-workbox/issues/4

This lane owns the public example’s consumer-side proof. The report identifies a missing packaged /host workerd/Wrangler smoke with nodejs_compat off, a missing installed-tarball upstream-alias/deep-import check in baileyrs, and a gap between static host boundaries and actual Cloudflare runtime behavior. Inspect the already merged #1 to see whether it really exercises a packaged baileyrs preview in Workers and restart/auth behavior; close only gaps that belong in this minimal public bot example.

What Changed

  • Add npm run smoke:workerd to run the Worker with the installed baileyrs /host entry under local Wrangler/workerd without nodejs_compat, checking unauthorized access and authenticated Durable Object status.
  • Run the smoke check on pushes and pull requests with Node.js 22.3.0.
  • Document the smoke command and its limits, including no WhatsApp connection or Cloudflare deployment.

Risk Assessment

✅ Low: The change adds a bounded consumer runtime smoke, and the prior scratch-directory defect is correctly fixed without expanding scope.

Testing

Installed dependencies and ran the packaged smoke twice in local workerd without Node compatibility. Captured successful Durable Object status and rejected authentication attempts. Paired-account recovery remains outside this smoke's scope. No UI changed.

  • Live validation: ✅ go - 4 of 4 scenarios driven live against the product
Scenario Result Live Evidence
Run the installed preview in workerd without nodejs_compat when .wrangler does not exist ✅ pass live Fresh-checkout packaged workerd smoke
Request status without credentials and receive HTTP 401 ✅ pass live Live HTTP responses
Attempt status and bot startup with an incorrect token and receive HTTP 401 ✅ pass live Live HTTP responses
Request status with the valid token and receive HTTP 200 with Durable Object state stopped ✅ pass live Live HTTP responses
Evidence: Fresh-checkout packaged workerd smoke

> smoke:workerd
> node scripts/smoke-workerd.mjs

Packaged /host Worker bundle ran in workerd without nodejs_compat; auth and Durable Object status checks passed.
Evidence: Live HTTP responses
{"method":"GET","path":"/status","credential":"missing","status":401,"body":"Unauthorized"}
{"method":"GET","path":"/status","credential":"wrong","status":401,"body":"Unauthorized"}
{"method":"POST","path":"/start","credential":"wrong","status":401,"body":"Unauthorized"}
{"method":"GET","path":"/status","credential":"missing","status":401,"body":"Unauthorized"}
{"method":"GET","path":"/status","credential":"valid","status":200,"body":"{\"state\":\"stopped\"}"}
Packaged /host Worker bundle ran in workerd without nodejs_compat; auth and Durable Object status checks passed.

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

🔧 **Review** - 1 issue found → auto-fixed ✅
  • 🚨 scripts/smoke-workerd.mjs:8 - On a fresh checkout, .wrangler does not exist. mkdtemp creates only the final directory, so this throws ENOENT before Wrangler starts. The new CI workflow runs this exact sequence after npm ci, preventing the required runtime smoke from executing. Create .wrangler with recursive mkdir before calling mkdtemp.

🔧 Fix applied.
✅ Re-checked - no issues remain.

✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 4 of 4 scenarios driven live against the product
Scenario Result Live Evidence
Run the installed preview in workerd without nodejs_compat when .wrangler does not exist ✅ pass live Fresh-checkout packaged workerd smoke
Request status without credentials and receive HTTP 401 ✅ pass live Live HTTP responses
Attempt status and bot startup with an incorrect token and receive HTTP 401 ✅ pass live Live HTTP responses
Request status with the valid token and receive HTTP 200 with Durable Object state stopped ✅ pass live Live HTTP responses
  • Inspected the change, issue #4, and merged example PR #1 to establish consumer-side scope and prior validation limits.
  • npm ci --no-audit --no-fund
  • npm run smoke:workerd with no pre-existing .wrangler directory
  • Repeated the smoke through a fetch instrumentation wrapper, recording actual responses and asserting incorrect-token rejection on GET /status and POST /start.
  • Removed generated WASM and scratch directory; confirmed no source changes.
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.


Summary by cubic

Adds a workerd smoke check that runs the installed baileyrs /host entry without nodejs_compat, verifying the admin-token guard and Durable Object status route, and wires it into CI.

  • Creates the .wrangler directory before the scratch setup so the smoke script works on a fresh checkout.

Written for commit 4ce792c. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Tests
    • Added a smoke check that verifies the app runs in a local Worker runtime, rejects requests without an admin token, and returns status for authorized requests.
    • The check runs automatically on pull requests and pushes.
  • Documentation
    • Documented how to run the smoke check and what it covers.

@coderabbitai

coderabbitai Bot commented Sep 23, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 37ab0b9a-c73e-45e2-9511-69ded334dc49

📥 Commits

Reviewing files that changed from the base of the PR and between e85b56b and 4ce792c.

📒 Files selected for processing (4)
  • .github/workflows/workerd-smoke.yml
  • README.md
  • package.json
  • scripts/smoke-workerd.mjs
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T02:52:40.613774Z 4ce792c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jlucaso1
jlucaso1 merged commit 879c7f0 into main Sep 23, 2026
4 of 5 checks passed
@jlucaso1
jlucaso1 deleted the fm/cloudflare-example-issue4-consumer-r1 branch September 23, 2026 04:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant