Repository navigation
299 lines (265 loc) · 11.5 KB
/
Copy pathci.yml
File metadata and controls
299 lines (265 loc) · 11.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
name: ci
on:
push:
branches: [ main, master, 'cycle/**' ]
pull_request:
jobs:
build:
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@v4
- name: Install system depexts (libcurl for ezcurl)
# Pre-install libcurl4-openssl-dev so opam-depext / setup-ocaml
# does not need to resolve the (occasionally 404ing) gnutls flavour.
# See cycle #26 β observation and cycle #32 AC5.
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends libcurl4-openssl-dev pkg-config
- name: Set up OCaml
uses: ocaml/setup-ocaml@v3
with:
ocaml-compiler: "5.2"
- name: Install dependencies
working-directory: src/engine/ocaml
run: opam install . --deps-only --with-test -y
- name: Build
working-directory: src/engine/ocaml
run: opam exec -- dune build
- name: Test
working-directory: src/engine/ocaml
run: opam exec -- dune runtest
- name: Upload binary
uses: actions/upload-artifact@v4
with:
name: coh-linux-x64
path: src/engine/ocaml/_build/default/bin/main.exe
retention-days: 90
linkcheck:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Link check (Markdown)
# #108: linkcheck previously (a) checked only markdown at depth <= 2,
# (b) honored no --exclude-path value, and (c) stayed green with dozens
# of broken links. Causes: the runner shell's globstar is off (an
# unquoted **/*.md collapses to depth <= 2); the action's bundled lychee
# used glob (not regex) --exclude-path semantics; and lychee-action did
# not propagate lychee's error exit. Fixed by pinning lychee and running
# it directly: quoted globs let lychee recurse every depth; v0.20.1
# treats --exclude-path as a regex substring; a direct run propagates
# the non-zero exit. --offline checks relative/local links only (the
# exact class #108 is about), so the gate is deterministic and free of
# external-URL flakiness.
#
# Excluded (not reader-navigable Markdown surface): vendored
# .cdd .cn-sigma .cell .tsc, build output _build, the heldout corpus,
# kata negative-control inputs (listed explicitly), CHANGELOG.md,
# LICENSE. Live docs, spec/, src/**, conformance/, research/,
# katas/*/README.md and schemas/fixtures/** are checked.
run: |
set -euo pipefail
ver=lychee-v0.20.1
curl -fsSL "https://github.com/lycheeverse/lychee/releases/download/${ver}/lychee-x86_64-unknown-linux-gnu.tar.gz" | tar xz lychee
./lychee --version
./lychee --offline --no-progress --max-concurrency 4 \
--exclude-path '\.cdd/' \
--exclude-path '\.cn-sigma/' \
--exclude-path '\.cell/' \
--exclude-path '\.tsc/' \
--exclude-path '_build/' \
--exclude-path 'heldout/' \
--exclude-path 'katas/02-random-soup/input/' \
--exclude-path 'katas/03-comparative/input/' \
--exclude-path 'katas/05-adversarial/input/' \
--exclude-path 'CHANGELOG\.md' \
--exclude-path 'LICENSE' \
-- '*.md' '**/*.md'
spec-validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Check required spec files present
run: |
missing=0
for f in \
spec/c-equiv.md \
spec/tsc-core.md \
spec/tsc-oper.md \
spec/tsc-observation-dynamics.md \
spec/tsc-conformance.md \
spec/tsc-glossary.md \
spec/README.md; do
if [ ! -f "$f" ]; then
echo "MISSING: $f"
missing=$((missing + 1))
else
echo "OK: $f"
fi
done
if [ $missing -gt 0 ]; then
echo "spec-validate: $missing required spec file(s) missing"
exit 1
fi
echo "spec-validate: all required spec files present"
- name: Check spec status headers (4.1 draft cycle)
run: |
# During the 4.1 draft cycle the five normative bodies + the spec
# index read `**Status:** Draft`; the glossary reads
# `**Status:** Informative`. The ratification-only commit flips the
# bodies Draft -> Normative and this expected value with them.
# Guards against a partial or mixed status surface.
fail=0
check_status() {
local f="$1" want="$2" line
line=$(grep -m1 -E '^\*\*Status:\*\*' "$f" || true)
if [ "$line" != "**Status:** $want" ]; then
echo "STATUS MISMATCH: $f -> '$line' (expected '**Status:** $want')"
fail=$((fail + 1))
else
echo "OK: $f is $want"
fi
}
for f in \
spec/c-equiv.md \
spec/tsc-core.md \
spec/tsc-oper.md \
spec/tsc-observation-dynamics.md \
spec/tsc-conformance.md \
spec/README.md; do
check_status "$f" "Draft"
done
check_status spec/tsc-glossary.md "Informative"
if [ $fail -gt 0 ]; then
echo "spec-validate: $fail spec status header(s) inconsistent"
exit 1
fi
echo "spec-validate: all spec status headers consistent"
- name: Link check (spec/*.md)
uses: lycheeverse/lychee-action@v1
with:
args: >-
--verbose
--no-progress
--accept 200..299,403,429
--exclude-path "CHANGELOG.md|LICENSE"
-- spec/*.md
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# kata-check job removed in cycle #36 — consolidated into the dedicated
# `katas.yml` workflow which adds an OPAM + dune build cache and
# PR-only concurrency cancellation. See `.github/workflows/katas.yml`.
conformance-validate:
# Failure classes guarded (schemas/README.md):
# - a conformance fixture that no longer satisfies
# schemas/conformance-fixture.cue;
# - registry <-> manifest drift (dangling or orphan fixtures);
# - a fixture referencing a requirement ID absent from
# spec/tsc-conformance.md, or a covered requirement missing a
# positive or negative case;
# - an evidence-rule violation (a specified fixture carrying
# execution evidence, or a verified fixture without replayable
# PASS evidence and independent PASS review).
# Consumer: anyone reading conformance/ as the v4 proof surface.
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup CUE
uses: cue-lang/setup-cue@v1.0.1
with:
version: v0.13.2
- name: Validate v4 conformance fixtures
run: ./scripts/ci/validate-v4-conformance.sh
skill-validate:
# Failure classes guarded (schemas/README.md):
# - skill frontmatter that no longer satisfies schemas/skill.cue;
# - a measurement skill declaring signals/estimates the engine or
# scoring instruction does not carry (declaration drift);
# - rendered artifacts (scripts/coh-self,
# .github/workflows/tsc-self-measure.yml) hand-edited or stale
# relative to src/skills/self-measure/SKILL.md (render drift).
# Consumer: anyone reading a SKILL.md as the authority on behavior.
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup CUE
uses: cue-lang/setup-cue@v1.0.1
with:
version: v0.13.2
- name: Install Python deps (explicit — runner preinstall is not a contract)
run: python3 -m pip install --disable-pip-version-check PyYAML
- name: Schema self-test (positive + negative fixtures)
run: ./scripts/ci/validate-skill-frontmatter.sh --self-test
- name: Validate every SKILL.md frontmatter
run: ./scripts/ci/validate-skill-frontmatter.sh
- name: Render byte-identity (skill -> command + workflow)
run: ./scripts/render-self-measure.sh --check
self-measure-smoke:
# Failure class guarded: the rendered coh-self command or the external
# witness route (emit-prompt -> witness response -> ingest) regressing
# silently. The tsc-self-measure llm-witness job is gated off by
# default, so this credential-free smoke is the always-on proof of the
# route, including its refusal path (invalid response => validation-
# failure artifact, no report). Consumer: anyone touching
# src/engine/ocaml/bin/main.ml, scripts/coh-self, or the skill.
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@v4
- name: Install system depexts (libcurl for ezcurl)
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends libcurl4-openssl-dev pkg-config
- name: Set up OCaml
uses: ocaml/setup-ocaml@v3
with:
ocaml-compiler: "5.2"
- name: Install dependencies
working-directory: src/engine/ocaml
run: opam install . --deps-only -y
- name: Build engine
working-directory: src/engine/ocaml
run: opam exec -- dune build
- name: Self-measurement smoke (mechanical + external witness route)
run: ./scripts/ci/self-measure-smoke.sh
- name: CM admissibility self-test (five-attacker matrix)
# Failure class guarded: the CM selection rule crowning a
# non-measurer. Asserts the exact matrix — engine admitted;
# flatterer, path-gamer, boilerplate-gamer rejected;
# basename-gamer and cherry-pick-assassin ADMITTED (the two
# named residuals: held-out anchors and adjudication are their
# closures). src/skills/cm-of-cms/SKILL.md section 6.
run: ./scripts/cm-admissibility.sh --self-test
- name: Held-out anchor integrity (commitments vs reveals)
run: ./scripts/cm-heldout.sh verify
- name: Held-out matrix (memorizers must fail the unseen anchor)
# The second measured result, asserted permanently: on revealed
# fail-anchor hx-02 (sealed before the challengers registered),
# every memorization/inflation attacker misses while the engine
# hits. Standing earned: house-authored-blind-heldout —
# unmemorizability, not externality.
run: ./scripts/cm-heldout.sh self-test
forbidden-wording:
# v0.10.0 cutover (#54 AC7): forward-only check that rejects newly-added
# `"Operational acceptance"`, `"Operationally accepted"`,
# `"self-coherence ACCEPT"`, `"release criteria satisfied"` outside
# frozen-snapshot (`docs/{tier}/{bundle}/{X.Y.Z}/`) and archive
# (`docs/archive/`) paths. Historical occurrences in excluded paths
# do not fail the job — the check compares against the merge base /
# main branch and only inspects newly-added lines.
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# Fetch enough history so the base ref is resolvable. The script
# defaults to `origin/main`; PR runs need its tip in the local repo.
fetch-depth: 0
- name: Forbidden-wording (forward-only)
run: |
set -e
if [ "${{ github.event_name }}" = "pull_request" ]; then
base="origin/${{ github.base_ref }}"
else
# Push runs (including `cycle/**`): compare against origin/main.
base="origin/main"
fi
echo "Base ref: $base"
bash scripts/check-forbidden-wording.sh "$base"