Skip to content

feat(docs): replay the Evidence tutorials with the page runner - #1602

Merged
jeremi merged 7 commits into
mainfrom
feat/tutorial-runner-evidence
Sep 27, 2026
Merged

jeremi merged 7 commits into
mainfrom
feat/tutorial-runner-evidence

Conversation

@jeremi

@jeremi jeremi commented Sep 26, 2026

Copy link
Copy Markdown
Member

Stacked on #1573 (Casework): the first three commits belong to that PR; review the last four here.

Replaces check-evidence-tutorials.sh with the page-as-spec runner from #1572. Each replayed Evidence page now declares its journey in tutorial_test frontmatter and checks itself with annotations on the blocks a reader already sees.

What changes

  • Runner: test-file (a whole file the reader creates in their editor), test-background="<url>" (a command left running in another terminal; starting another one stops it, and the page end stops them all), and test-cwd="<dir>" (the directory the page tells the reader to return to).
  • Evidence toolset: the evidence, evidencectl, evidence-oid4vci, and interop-test binaries, the Python client wheel from REGISTRY_CLIENT_PY_WHEEL, and the FHIR mock on 8003 for every journey.
  • Pages: the 11 replayed pages carry test-file, test-expect, and test-excerpt; the old SPEC_ASSERTS became checks on output blocks the page shows. Several blocks had drifted from what the commands print today and now show the real output:
    • the application discovery JSON (audience, concept, handle, required, responseFormats);
    • the revoke line;
    • the OID4VCI milestones (TASK GRANT REFUSED);
    • the trace ID placeholder.
      The 12 pages the bash gate never replayed say why in tutorial_test.skip.
  • Gate removal: check-evidence-tutorials.sh and its test are deleted. evidence-tutorial-fence.sh stays, because the Relay gate still uses it until Relay migrates.
  • CI: the evidence-tutorials job runs npm ci, the runner tests, the dry run, and run-tutorial.mjs --gate evidence. ci_changes.py routes on the runner and the replayed pages, and its test reads the frontmatter instead of parsing the bash registry.

Verification

  • Runner tests: 80 pass. ci_changes tests: 118 pass. Gates inventory tests: 70 pass, and the inventory check passes.
  • Dry run of the evidence, breg, and casework gates is clean. npm test, check:draft-links, check:markdown, check:content, check:style, and the Evidence anchors check all pass.
  • Real gate on macOS: 7 of 9 journeys pass. refuse-unsafe-evidence-requests passes on retry. control-who-can-request-evidence could not get past a local ThunderID flake (below), so this job's CI run is the first full replay of that page's fixed blocks.

Known local flake (not in this PR)

On macOS with OrbStack, evidencectl dev start sometimes fails when it restarts in a project directory whose issuer state was just removed. ThunderID's setup.sh reports failed to ping database runtime_transient: unable to open database file (14) on the bind-mounted SQLite file. A 20-second pause does not reliably avoid it. registry-thunderid-tooling drops setup's stdout because it carries the admin credential, so the supervisor log only says setup did not complete. I have not seen it on Linux.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T06:15:44.230568Z 1c378dd New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7d12b850fa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/site/scripts/tutorial-runner/background.mjs Outdated
@jeremi
jeremi enabled auto-merge September 27, 2026 04:21

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

lines.push('set +e');
const status = file('status');
lines.push(`{\n${step.code}\n} >${out} 2>&1 </dev/null`);
lines.push(`printf '%s\\n' "$?" >${status}`, 'set -e');

P2 Badge Preserve errexit while checking an expected refusal

For a multi-command test-exit fence, disabling errexit for the entire brace group lets execution continue after an unexpected early failure. If a later command happens to return the annotated status, the runner accepts the fence and may execute side effects a reader running under the journey's normal set -e would never reach. Run the fence in a set -e subshell and capture that subshell's status instead.

AGENTS.md reference: docs/site/AGENTS.md:L54-L56

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/site/scripts/tutorial-runner/background.mjs
test-file writes a block the page shows as a whole file, test-background
keeps a fence running beside the journey until its ready URL answers, and
test-cwd names the directory the page tells the reader to return to. Every
process a journey starts is stopped when it ends, passing or failing.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…mock to tutorial journeys

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…kout scripts

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…tire the bash gate

Every replayed Evidence page now carries its own test-file, test-expect,
and test-excerpt annotations, the output blocks show what the commands
print today, and CI runs run-tutorial.mjs --gate evidence.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…wn live command

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…into its gate

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi force-pushed the feat/tutorial-runner-evidence branch from fb9ce1d to 650f5d1 Compare September 27, 2026 05:04
…is stopped

A background fence promises to keep running until the next one starts or
the page ends, but stop() only sent the group a signal and reported
success even when the group had already ended on its own. A service that
crashed after answering its readiness check was silently accepted. Check
liveness before stopping and fail with what the command printed when it
had already exited.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit 27e274c Sep 27, 2026
55 checks passed
@jeremi
jeremi deleted the feat/tutorial-runner-evidence branch September 27, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant