# Tests and CI The configured Tangled workflow, `.tangled/workflows/ci.yml`, runs for branch pushes, pull requests, and manual runs. Formatting, unit tests, both HTTP smoke suites, and the ARMv6 ReleaseSafe build must all pass before a push to `main` deploys to Fly. Pull requests, other branches, and manual workflow runs never deploy. Check the [deployment observation](deployment.md#october-1-deployment-observation) if a push does not start a pipeline. ## Local checks ```sh zig fmt --check build.zig build.zig.zon src bench tools just test just smoke-all git diff --check ``` `just smoke-all` builds the PDS and Spaces HTTP-signature helper once, then runs the public and permissioned suites concurrently. Each suite gets its own temporary database, blobstore, and response files. Default ports are 2585 (public PDS), 2586 (mock PLC), and 2587 (permissioned PDS). Both suites must succeed. Failed runs retain diagnostic files and print their directory; successful runs remove them. Avoid publishing raw diagnostics, which can contain test credentials. `just smoke` and `just smoke-permissioned` still work independently and build the binaries they need. The standalone permissioned suite defaults to 2586. Use `ZDS_SMOKE_PORT`, `ZDS_SMOKE_PLC_PORT`, and `ZDS_PERMISSIONED_SMOKE_PORT` to override the ports. The optional [October 1 SDK interop lane](permissioned-data.md#october-1-upgrade) checks signatures in both directions. The SDK installation is external to the repo; the default smoke suites do not require Node or npm. CI starts cold on every run. The workflow declares a `cache` entry for `.ci-cache` (compiler and package cache, keyed on `build.zig.zon` and `tools/ci-zig.sh`), and spindle.tangled.sh accepts the field, but as of 2026-09-18 it neither restores nor saves it, so the compiler and every dependency are downloaded each run. Four dependencies are tangled.org archives, whose endpoint rate-limits; `tools/ci-fetch.sh` runs `zig build --fetch` with six attempts and doubling backoff so a 429 costs minutes, not the pipeline. The compiler and build outputs are reused between steps within each run. Timings should distinguish cold compilation from warm test execution. No assertions, database durability settings, or cryptographic checks are relaxed for speed.