Skip to content

chore(deps): bump the minor-and-patch group with 2 updates #262

chore(deps): bump the minor-and-patch group with 2 updates

chore(deps): bump the minor-and-patch group with 2 updates #262

name: CI — [server] extras only
# Purpose: verify mnemon's production install (Fly Docker image) — which
# uses `mnemon-memory[server]` and NOTHING else — passes the suite that
# matters for production behavior.
#
# Driver: 2026-05-22 finding that `memory_check_contradictions` was
# silently broken on Fly because the LLM code path imported deps only
# available in the `[llm]` extra (NOT in `[server]`). All unit tests
# passed because they ran under `[dev]` extras, which include `[llm]`
# transitively in some operators' setups. This workflow runs the suite
# against ONLY the `[server]` extras + a minimal test framework — if a
# test fails here that passes in `ci.yml`, an optional dep has leaked
# into a production path.
#
# Composes with the all-tools integration canary in
# `tests/test_tools_integration.py` (PR #158): the canary catches
# tools that raise through their wrapper at the Python level; this
# workflow catches tools that work under `[dev]` but break under
# `[server]`.
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
jobs:
test-server-extras-only:
runs-on: ubuntu-latest
# Backstop: this job is a fast import/unit check, so a multi-minute
# run means something hung — fail in 15 min instead of stalling on
# GitHub's 6h default.
timeout-minutes: 15
env:
# Cache the embedder + NLI models (the non-integration suite still
# loads them in unit tests); avoids a ~100MB cold download — the
# source of an intermittent hang on this job.
FASTEMBED_CACHE_DIR: ${{ github.workspace }}/.model-cache/fastembed
HF_HOME: ${{ github.workspace }}/.model-cache/hf
steps:
- uses: actions/checkout@v7
- name: Cache embedder + NLI models
uses: actions/cache@v6
with:
path: ${{ github.workspace }}/.model-cache
key: mnemon-models-${{ runner.os }}-v1
- name: Set up Python 3.13
uses: actions/setup-python@v7
with:
python-version: "3.13"
# Install production-equivalent extras. The Fly Dockerfile runs
# `pip install ".[server]"` — this mirrors that exactly.
- name: Install [server] extras only (production-equivalent)
run: pip install -e ".[server]"
# Test framework installed SEPARATELY (not via `[dev]` extra) so
# we don't accidentally pull in anything via mnemon's own
# imports that would mask a server-only break. pytest itself is
# a test runner, not a mnemon runtime dep.
- name: Install test framework
run: pip install "pytest>=8.0" "pytest-asyncio>=0.23" "pytest-timeout>=2.3" "httpx>=0.27"
# Verify the [llm] extras are NOT installed. If a future PR
# accidentally moves llama-cpp-python or huggingface-hub into
# [server], this assertion catches it.
- name: Assert [llm] extras NOT installed
run: |
! pip show llama-cpp-python > /dev/null 2>&1 \
|| (echo "::error::llama-cpp-python is installed under [server] — it must remain in [llm]"; exit 1)
# Run the suite under [server]-only install. Any test that imports
# something only available in [llm]/[ui] fails here — that's a real
# bug worth catching at PR time, not after a Fly redeploy surfaces
# it client-side.
#
# `-m "not integration"` excludes the end-to-end tests that spawn a
# real `mnemon serve-remote` subprocess: on a fresh container they
# cold-download the embedder + NLI models (~100 MB) at server boot
# with no per-download timeout, which can stall this job for hours.
# Those tests are already covered in ci.yml ([dev]) and the clean
# wheel-install smoke runs in install-test.yml; this job's job is to
# catch optional-dep leaks into the [server] import path, which the
# unit suite (incl. the run_remote branch tests) already exercises
# under [server]-only.
- name: Run tests under [server]-only install
# --timeout backstop: a stalled cold model download fails that test
# fast instead of hanging the job to its 15-min cap.
run: pytest tests/ -v --tb=short -m "not integration" --timeout=300 --timeout-method=thread