Skip to content

test: install qpdf so the independent oracle actually runs - #33

Merged
tannevaled merged 1 commit into
mainfrom
test/qpdf-judge-in-ci
Sep 21, 2026
Merged

tannevaled merged 1 commit into
mainfrom
test/qpdf-judge-in-ci

Conversation

@tannevaled

Copy link
Copy Markdown
Contributor

The one check a stranger performs, and it never ran

TestObjectStreamsQPDF calls itself "a second, independent oracle when it is
installed"
: qpdf must report no syntax or stream-encoding error, and its
cross-reference must list every link annotation as compressed (type 2) and every
stream as uncompressed (type 1).

It had never run. The test skips when qpdf is absent; the lane installs nothing.
So the only check performed by an implementation other than this one skipped on
every push — under a green lane, and under a gate asserting exactly 100%
statement coverage
.

Both numbers were honest. Coverage counts lines that executed, and the
object-stream writer executes under the other tests too. What a coverage gate
cannot express is that the single test comparing our output against a foreign
reader did nothing at all.

The change

  • install qpdf in the lane;
  • set PDFKIT_REQUIRE_QPDF=1, so "qpdf not installed" is a failure there
    rather than a skip.

Verified both ways, locally

This machine has qpdf 12.4.1, so the guard was exercised before opening this:

PDFKIT_REQUIRE_QPDF=1 go test -run TestObjectStreamsQPDF
--- PASS: TestObjectStreamsQPDF (0.05s)

PATH=/usr/bin:/bin, flag still set
--- FAIL: objstm_test.go:350: PDFKIT_REQUIRE_QPDF is set but qpdf is not installed

How this was found

judgescan, a new fleet tool reporting every repository whose tests look for an
external tool its CI never installs. Of 901 repositories, 134 name such a tool
and 29 name one that is never installed. This is one of them.

🤖 Generated with Claude Code

TestObjectStreamsQPDF is described in its own comment as "a second,
independent oracle when it is installed": qpdf must find no syntax or
stream encoding error, and its cross-reference must list every link
annotation as compressed and every stream as not.

It had never run. The test skips when qpdf is absent and the lane
installs nothing, so the only check a stranger performs on what this
package emits skipped on every push, under a green lane and a gate
asserting exactly 100% statement coverage.

Both numbers were honest. Coverage counts lines that executed, and the
object-stream writer executes under the other tests too. What a
coverage gate cannot express is that the one test comparing our output
against another implementation did nothing.

Install qpdf in the lane, and set PDFKIT_REQUIRE_QPDF=1 so that "qpdf
not installed" is a failure there rather than a skip.

Verified both ways on this machine, which has qpdf 12.4.1:

    PDFKIT_REQUIRE_QPDF=1 go test -run TestObjectStreamsQPDF   --- PASS
    PATH=/usr/bin:/bin, flag still set                         --- FAIL

Found with judgescan, which reports repositories whose tests look for a
tool their CI never installs: 29 of the 134 that name one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@tannevaled
tannevaled merged commit f7d4217 into main Sep 21, 2026
1 check passed
@tannevaled
tannevaled deleted the test/qpdf-judge-in-ci branch September 21, 2026 11:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant