--- name: healthmd-cli-qa description: Test the standalone Health.md CLI, portable healthmd-mcp server, and direct mobile paths. Use for CLI/MCP QA, Rust↔Swift/Kotlin protocol compatibility, Manual IP/Tailscale pairing, typed query/UI/image checks, status/raw/extract/file/resume/cancel, wake notifications, cross-platform release gates, failure diagnosis, or physical-device plans without the Health.md macOS app. compatibility: Automated CLI checks require the independently locked shared-core and CLI Rust workspaces; mobile-side checks require the relevant Apple or Android build tools. Live E2E requires an exact compatible mobile build with Direct CLI Access, platform health/local-network permissions, and a disposable destination for file tests. --- # Standalone Health.md CLI QA Validate the Rust CLI, portable Rust MCP server, and iPhone/Android direct services. The macOS app, loopback API, Mac destination bookmark, and legacy Swift CLI are out of scope unless explicitly requested. ## Rules - Treat this as a three-component contract: shared protocol under `packages/healthmd-core-rust`, portable client under `apps/cli`, and the iPhone service/exporters under `apps/apple`. - Keep CLI commands bounded and non-interactive. On macOS/Linux use `NO_COLOR=1 TERM=dumb`, `timeout`, and stdin from `/dev/null`. - Use stdout JSON, artifacts, durable job records, and commit receipts as evidence. - Never put raw health payloads in logs, issues, fixtures, or reports. Record only counts, dates, statuses, diagnostics, and digests. - Separate automated checks from physical-iPhone checks. Never claim live coverage without observations. - Do not weaken crypto, digest, path, schema, peer-binding, or partial-result validation to pass a test. ## Layers 1. Independently locked shared-core and CLI Rust format/build/lint/workspace tests. 2. Swift-generated protocol-v1 export and protocol-v3 query fixture conformance from `healthmd-protocol`. 3. Connectivity package, focused direct-service/query/export tests, and iOS build. 4. Local CLI/MCP help, initialize/tools/resources, and offline trust smoke. 5. Live LAN pair/status/raw/extract/file/durability plus every direct MCP query/export/UI/PNG path. 6. Live Tailscale network coverage. 7. macOS/Linux/Windows release matrix with both packaged binaries. Do not insert a Mac-app control-server smoke test: the portable client listens directly for iPhone. ## Rust gate Validate the shared-core workspace first: ```bash cd packages/healthmd-core-rust cargo fmt --all --check cargo test --workspace --all-features --locked cargo clippy --workspace --all-targets --all-features --locked -- -D warnings rustup run 1.85.0 cargo check --workspace --all-features --locked cargo test -p healthmd-protocol --test swift_v1_vectors --locked cargo test -p healthmd-protocol --test swift_v3_query_vectors --locked ``` From the repository root run `make check-core-bindings`, then validate the CLI workspace separately: ```bash cd apps/cli cargo fmt --all --check cargo test --workspace --all-features --locked cargo clippy --workspace --all-targets --all-features --locked -- -D warnings rustup run 1.85.0 cargo check --workspace --all-features --locked dist plan --allow-dirty cargo run --bin healthmd -- --help cargo run --bin healthmd -- export cargo run --bin healthmd -- extract cargo run --bin healthmd -- query cargo run --bin healthmd -- query healthmd_sleep_sessions cargo run --bin healthmd -- resume cargo run --bin healthmd -- direct reset-trust cargo run --bin healthmd -- setup codex --help cargo run --bin healthmd -- mcp serve --help cargo run --bin healthmd-mcp -- --help python3 scripts/update-mcp-shared-assets.py --check ``` Never run these as one Cargo workspace or rewrite both lockfiles. The focused protocol test validates the canonical `packages/contracts/direct-protocol/v1/fixtures/swift-reference.json` through its byte-identical Rust packaging mirror: pairing proofs, Swift encoding, request fingerprints, and transfer frames. Changes to cryptographic transcripts, canonical JSON, enum layout, UUID/date encoding, or frames require protocol-version analysis. Never regenerate this fixture from Rust just to silence failure. CI must pass on macOS, Ubuntu, and Windows. Verify release checksums plus `healthmd --version`, `healthmd --help`, idempotent isolated `healthmd setup codex --skip-pairing`, same-binary and compatibility-launcher MCP handshakes, and isolated `healthmd direct devices`. `HEALTHMD_CLI_DATA_DIR` changes file state but does not namespace native credentials. ## iPhone-side gate From the monorepo root: ```bash cd apps/apple swift test --package-path Packages/HealthMdConnectivity xcodebuild -project HealthMd.xcodeproj \ -scheme HealthMd \ -configuration Debug \ -destination 'generic/platform=iOS' \ build CODE_SIGNING_ALLOWED=NO ``` Run focused tests relevant to the change, especially: - `apps/apple/Packages/HealthMdConnectivity/Tests/HealthMdConnectionCoreTests` - `apps/apple/Packages/HealthMdConnectivity/Tests/HealthMdDirectClientCoreTests` - `apps/apple/HealthMdTests/iOS/IPhoneDirectCLIReconnectPolicyTests.swift` - `apps/apple/HealthMdTests/Sync/ConnectedCorpus*Tests.swift` - `apps/apple/HealthMdTests/Sync/ConnectedTransferTests.swift` - touched exporter contracts The portable client does not require a macOS app build. If public exporter/metric/unit/JSON/CSV/Markdown/frontmatter/data-dictionary output changes, follow `apps/apple/docs/features/export-schema.md`, including schema bump/signature fixture when required. ## Offline CLI smoke ```bash NO_COLOR=1 TERM=dumb timeout 15 healthmd --version