Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
127 commits
Select commit Hold shift + click to select a range
60b66b6
docs(harbour): reject cross-model repair experiment
zedarvates Aug 24, 2026
ee3b4eb
docs(harbour): record fail-closed A06 reproduction
zedarvates Aug 24, 2026
1cdcb1b
docs(harbour): record blocked third-model probe
zedarvates Aug 25, 2026
ce6663b
feat(video-routing): add deterministic multi-subject strategy router
zedarvates Aug 27, 2026
4b54ab0
feat(video-routing): expose multi-subject routing primitives
zedarvates Aug 27, 2026
7d438ee
test(video-routing): cover multi-subject strategy decisions
zedarvates Aug 27, 2026
4202d3b
docs(harbour): record default-model corpus regression
zedarvates Aug 27, 2026
b8c8cd5
feat(video-routing): adapt existing shot specs to routing inputs
zedarvates Aug 27, 2026
c946da6
test(video-routing): cover shot-spec adapter
zedarvates Aug 27, 2026
1cf11e4
fix(video-routing): fail closed on non-boolean contact metadata
zedarvates Aug 27, 2026
96eaf1f
feat(video-routing): export shot-spec routing adapter
zedarvates Aug 27, 2026
1eed516
test(video-routing): reject ambiguous contact metadata
zedarvates Aug 27, 2026
2ee3bee
docs(harbour): record Gemma corpus rerun
zedarvates Aug 27, 2026
718eaa5
test(harbour): refine privacy-safe acceptance failures
zedarvates Aug 28, 2026
03c2c54
docs(harbour): record Anna draft revision 10
zedarvates Aug 28, 2026
76965d0
docs(harbour): refresh owner handoff and grants evidence
zedarvates Aug 28, 2026
cdaf4c0
test(harbour): run browser smokes sequentially
zedarvates Aug 28, 2026
13adb02
fix(harbour): preserve states in forced colours
zedarvates Aug 28, 2026
96df0e1
docs(harbour): record Anna draft revision 11
zedarvates Aug 28, 2026
17b7095
docs(harbour): refresh revision 11 demo evidence
zedarvates Aug 28, 2026
bef958f
fix(harbour): make repair prompt schema-complete
zedarvates Aug 29, 2026
234987a
test(harbour): lock schema-complete repair contract
zedarvates Aug 29, 2026
b4a41b7
docs(harbour): prepare Anna media requirements request
zedarvates Aug 29, 2026
291ceb4
Merge remote-tracking branch 'github/agent/storycore-harbour-bootstra…
zedarvates Aug 29, 2026
8847853
docs(harbour): record Anna draft revision 12
zedarvates Aug 29, 2026
5ce095e
feat(harbour): prepare validated Anna marketplace logo
zedarvates Aug 29, 2026
104a149
docs(harbour): record working-draft install path
zedarvates Aug 29, 2026
8cc3e87
docs(harbour): capture Anna manifest credential blocker
zedarvates Aug 29, 2026
67944e4
docs(harbour): close Anna manifest read blocker
zedarvates Aug 29, 2026
fa7984c
docs(harbour): update manifest reauthentication runbook
zedarvates Aug 29, 2026
3800320
docs(harbour): diagnose dev-install permission mismatch
zedarvates Aug 29, 2026
07897e0
feat(game-bridge): add src/game_bridge/__init__.py
zedarvates Aug 29, 2026
0854007
feat(game-bridge): add src/game_bridge/__main__.py
zedarvates Aug 29, 2026
06641c2
feat(game-bridge): add src/game_bridge/contract.py
zedarvates Aug 29, 2026
4566168
feat(game-bridge): add tests/game_bridge/test_contract.py
zedarvates Aug 29, 2026
4bd76ac
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/REA…
zedarvates Aug 29, 2026
238d011
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/sto…
zedarvates Aug 29, 2026
328fdb8
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/god…
zedarvates Aug 29, 2026
0e3bef1
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/god…
zedarvates Aug 29, 2026
fd07c88
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/god…
zedarvates Aug 29, 2026
f515a49
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/god…
zedarvates Aug 29, 2026
62a9fe4
feat(game-bridge): add fixtures/storycore-game/coinfall-chronicle/god…
zedarvates Aug 29, 2026
e97aec1
fix(game-bridge): constrain CLI paths and simplify validation
zedarvates Aug 30, 2026
06c5ef8
test(game-bridge): update tests/game_bridge/test_contract.py
zedarvates Aug 30, 2026
a87a37b
test(game-bridge): update fixtures/storycore-game/coinfall-chronicle/…
zedarvates Aug 30, 2026
ba62afd
ci: apply scoped PR44 path-safety fix
zedarvates Aug 30, 2026
3a44275
fix(game-fixture): satisfy strict Godot typing
zedarvates Aug 30, 2026
7639d6b
test(game-fixture): record verified Godot smoke in fixtures/storycore…
zedarvates Aug 30, 2026
ac53f62
test(game-fixture): record verified Godot smoke in tests/game_bridge/…
zedarvates Aug 30, 2026
6beffaf
test(game-fixture): add fixtures/storycore-game/coinfall-chronicle/go…
zedarvates Aug 30, 2026
129ae26
test(game-fixture): add fixtures/storycore-game/coinfall-chronicle/go…
zedarvates Aug 30, 2026
ce1abc6
ci: make scoped PR44 patch resilient
zedarvates Aug 30, 2026
7f44e7d
ci: rerun scoped PR44 security patch
zedarvates Aug 30, 2026
7f4100d
chore(ci): remove failed one-shot PR44 patch workflow
zedarvates Aug 30, 2026
6094fde
chore(ci): remove redundant one-shot PR44 patch workflow v2
zedarvates Aug 30, 2026
05fed06
ci: apply validated PR44 security patch v3
zedarvates Aug 30, 2026
cd10272
fix(game-bridge): harden CLI workspace paths
github-actions[bot] Aug 30, 2026
900e687
ci: remove one-shot PR44 security patch
zedarvates Aug 30, 2026
f6c1706
fix(game-bridge): close final symlink path boundary
zedarvates Aug 30, 2026
8c834d9
test(game-bridge): expose all CLI path regressions
zedarvates Aug 30, 2026
7de191c
test(game-bridge): isolate exception invocations for Sonar
zedarvates Aug 30, 2026
d0e2d03
docs(game-bridge): explain no-follow output protection
zedarvates Aug 30, 2026
0b76c86
docs(harbour): reconcile Anna draft-install guidance
zedarvates Aug 30, 2026
e384c7c
fix(harbour): confine marketplace logo renderer paths
zedarvates Aug 30, 2026
0d8d1de
fix(harbour): correct marketplace renderer imports
zedarvates Aug 30, 2026
6118b20
fix(harbour): confine marketplace logo validation path
zedarvates Aug 30, 2026
5df61e2
test(harbour): lock marketplace logo file contract
zedarvates Aug 30, 2026
ab63ce5
docs(harbour): record bounded Sonar security remediation
zedarvates Aug 30, 2026
9e80b54
docs(harbour): record suspected upstream Sonar autoscan failure
zedarvates Aug 30, 2026
6100dd9
chore(license): align package metadata with MIT
zedarvates Aug 30, 2026
09ef8fe
chore(license): align root lockfile metadata with MIT
zedarvates Aug 30, 2026
4334cf5
docs(harbour): close Sonar gate after clean analysis
zedarvates Aug 30, 2026
00abcea
fix(video-routing): reject contradictory subject counts
zedarvates Aug 30, 2026
33d8346
test(video-routing): cover contradictory counts and non-finite scores
zedarvates Aug 30, 2026
875a2dc
docs(harbour): record post-repair Gemma corpus
zedarvates Aug 31, 2026
ebf525a
docs(harbour): reject insufficient JSON punctuation recovery
zedarvates Aug 31, 2026
e076230
docs(harbour): map Anna structured-output boundary
zedarvates Sep 1, 2026
e4ee835
ci: add minimal repository checkout proof
zedarvates Sep 2, 2026
a3dc48a
fix(ci): remove stale GemReward gitlink
zedarvates Sep 2, 2026
c9c3fc7
docs(harbour): refresh Anna CLI 0.1.51 boundaries
zedarvates Sep 5, 2026
4146f43
docs(harbour): record Anna support escalation
zedarvates Sep 5, 2026
6f04c47
chore(deps): bump the npm_and_yarn group across 3 directories with 3 …
dependabot[bot] Sep 8, 2026
e3c158f
fix(harbour): exclude model-derived diagnostics from repair requests
zedarvates Sep 9, 2026
6ad9b3b
chore(rules): audit Harbour invariants at the exact PR head
zedarvates Sep 9, 2026
32dd839
docs(roadmap): plan structural storyboards and physical consistency
zedarvates Sep 10, 2026
5b6c83b
Merge pull request #52 from zedarvates/dependabot/npm_and_yarn/npm_an…
zedarvates Sep 12, 2026
0046d93
chore(deps): bump the npm_and_yarn group across 2 directories with 3 …
dependabot[bot] Sep 12, 2026
215fe13
fix(deps): update sharp lockfile to 0.35.4
zedarvates Sep 12, 2026
739b4c5
fix(deps): keep security updates on aligned Vitest 4.1.11
zedarvates Sep 12, 2026
8e0c662
docs(audio): define provider-neutral music planning layer
zedarvates Sep 13, 2026
ef37f79
feat(audio): add MusicPlan v1 interchange schema
zedarvates Sep 13, 2026
c026a4e
feat(audio): add model-free MusicPlan invariant validator
zedarvates Sep 13, 2026
da11709
test(audio): add full MusicPlan fixture
zedarvates Sep 13, 2026
f7dbfc0
test(audio): add guided MusicPlan fixture
zedarvates Sep 13, 2026
f9754b7
test(audio): add free MusicPlan fixture
zedarvates Sep 13, 2026
d492369
test(audio): validate MusicPlan invariants and licence boundary
zedarvates Sep 13, 2026
e9aa207
ci(audio): add isolated MusicPlan contract proof
zedarvates Sep 13, 2026
18a54be
feat(audio): add deterministic mock music provider contract
zedarvates Sep 13, 2026
8d8b86b
test(audio): prove explicit provider degradation contract
zedarvates Sep 13, 2026
ce7d71b
ci(audio): cover mock provider contract
zedarvates Sep 13, 2026
1151149
docs(audio): record mock provider proof boundary
zedarvates Sep 13, 2026
6c37dc3
ci(audio): include MusicPlan contract documentation in proof scope
zedarvates Sep 13, 2026
115ee32
fix(audio): compose JSON Schema validation and recursive execution de…
zedarvates Sep 13, 2026
1e41f9b
test(audio): cover schema and nested execution degradation
zedarvates Sep 13, 2026
d3b9bfe
ci(audio): validate Draft 2020-12 MusicPlan contract
zedarvates Sep 13, 2026
197f36b
feat(audio): add portable provider handoff envelope
zedarvates Sep 13, 2026
5cbaad5
test(audio): prove portable handoff stays non-activating
zedarvates Sep 13, 2026
079e063
test(audio): add deterministic MusicPlan mutation probe
zedarvates Sep 13, 2026
ea6867e
ci(audio): run controlled MusicPlan negative mutation probe
zedarvates Sep 13, 2026
401abcc
docs(audio): align MusicPlan proof and handoff status
zedarvates Sep 13, 2026
189d3d1
fix(ci): run MusicPlan mutation probe as a module
zedarvates Sep 13, 2026
d7af6f5
test(audio): add private holdout evaluator protocol
zedarvates Sep 13, 2026
385a2ea
ci(audio): verify private holdout evaluator protocol
zedarvates Sep 13, 2026
552a39f
fix(asset-creator): prepare Trellis templates before image upload
zedarvates Sep 13, 2026
d5bdfc5
fix(asset-creator): handle ComfyUI timeouts and terminal status
zedarvates Sep 17, 2026
1b8074e
Merge pull request #47 from zedarvates/codex/align-npm-license-mit
zedarvates Sep 21, 2026
aead4f3
Merge pull request #60 from zedarvates/fix/asset-creator-comfyui-wait
zedarvates Sep 21, 2026
6207147
Merge pull request #58 from zedarvates/fix/asset-creator-preflight-be…
zedarvates Sep 21, 2026
77507f6
Merge pull request #57 from zedarvates/feature/music-planning-contrac…
zedarvates Sep 21, 2026
4a422c5
Merge pull request #56 from zedarvates/fix/sharp-security-463
zedarvates Sep 21, 2026
271b1ef
Merge pull request #55 from zedarvates/dependabot/npm_and_yarn/npm_an…
zedarvates Sep 21, 2026
4ef2436
Merge pull request #54 from zedarvates/feature/scientific-transfer-20…
zedarvates Sep 21, 2026
830e28a
Merge pull request #49 from zedarvates/fix/remove-stale-gemreward-git…
zedarvates Sep 21, 2026
0cc9845
Merge pull request #44 from zedarvates/codex/storycore-game-contract-…
zedarvates Sep 21, 2026
4d237ea
Merge pull request #43 from zedarvates/codex/multi-subject-video-router
zedarvates Sep 21, 2026
37eb2f7
Merge pull request #37 from zedarvates/agent/storycore-harbour-bootstrap
zedarvates Sep 21, 2026
6d2cc0f
merge main into codex/rules-drift-20260909: reapply the diagnostic ha…
zedarvates Sep 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions .botte/engine-LICENSE.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) 2026 Sylvain Galliez

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
57 changes: 57 additions & 0 deletions .botte/engine.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
# Committed rule audit

The three dependency-free Python modules are copied unchanged from
[Botte Secrète PR #103](https://github.com/zedarvates/botte-secrete/pull/103),
source commit [`e121ea16cbd5a772ddb485414928c0938eace2d5`](https://github.com/zedarvates/botte-secrete/tree/e121ea16cbd5a772ddb485414928c0938eace2d5).
Python 3.10+ is required. The upstream MIT notice is retained in
`engine-LICENSE.txt`; it does not change this repository's licensing.

| Engine file | SHA-256 |
| --- | --- |
| `skills/console_utf8.py` | `80e0583b55e816b85193238abcca6f16ae84d38c382b792763e0f5e90e662eb5` |
| `skills/directives_audit/rules.py` | `6af048fa89d1214d21e5abb2a82144ebfde26bf9bfaec120a3f91ead61e18284` |
| `skills/directives_audit/rules_cli.py` | `28da4117cd51bd12f7392857bf82b144895353b44d04c5f4d378968e4347fea7` |

From the repository root:

```bash
PYTHONDONTWRITEBYTECODE=1 PYTHONPATH=. python -m skills.directives_audit.rules_cli audit . --json
```

## Verification boundary

The audit reads exact source statements, guard anchors, positive and negative
probe anchors, owner-boundary metadata and the replacement graph. It does not
execute probes, import project code, contact services or authorize an action.
`last_verified` records semantic source review, not runtime success or a CI SHA.
All initial `supersedes` lists are empty. These local data rules use
`owner_only: false`; that does not grant owner-only external authority.

The report must be `botte.rules-audit/v1`, with a present manifest, at least one
rule, and zero errors and warnings. A missing/empty manifest is BLOCKED/DRIFT,
even if its numeric score is 100. The CLI returns 2 for an absent manifest and 1
for errors, but warnings require the additional strict check used in CI.

The fingerprint is a deterministic rule/report receipt, not a hash of the entire
source tree. Always record `git rev-parse HEAD` alongside the report and actual
test results. A result from another SHA or a pull-request merge commit cannot
stand in for the tested head. Regenerate verification receipts only after source
review and relevant probes; do not refresh dates merely to silence drift.

## Registered scope and execution

This initial contract covers three Harbour invariants: source-only repair
context, project ID references, and public acceptance-output redaction. It is
not a complete inventory of StoryCore Engine rules. `AGENTS.md`, mission limits,
and owner decisions remain authoritative outside this registered scope.

Run the reviewed behavioral probes separately from the repository root:

```bash
node --test apps/storycore-harbour/tests/repair-prompt.test.mjs apps/storycore-harbour/tests/contracts.test.mjs apps/storycore-harbour/tests/acceptance-public-output.test.mjs
```

The existing Harbour CI checks out and verifies the exact PR head, runs this
audit, then retains the full contract/evaluator, official Anna strict-validation,
and browser mock gates. CI is separate evidence; none of those mock checks proves
real-model acceptance, Anna eligibility, publication, or owner approval.
119 changes: 119 additions & 0 deletions .botte/rules.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,119 @@
{
"schema": "botte.rules-manifest/v1",
"rules": [
{
"id": "harbour.repair-source-only",
"action": "repair-context",
"effect": "REQUIRE",
"scope": [
"harbour-repair-request"
],
"statement": "repair validation errors contain only the fixed categories\n`json_invalid` and `contract_invalid`; the exact normalized user input remains\nthe reconstruction source.",
"source_ref": "apps/storycore-harbour/DECISIONS.md#ADR-023",
"owner_only": false,
"enforced": true,
"enforcement_refs": [
"apps/storycore-harbour/bundle/repair-prompt.js#const validationErrors = [...new Set(errors.map(error => (",
"apps/storycore-harbour/bundle/app.js#createRepairPrompt(input, errors)"
],
"probes": [
{
"id": "harbour.repair-source-only.allow",
"polarity": "allow",
"evidence_ref": "apps/storycore-harbour/tests/repair-prompt.test.mjs#repair rebuilds from the exact user input without carrying truncated model output"
},
{
"id": "harbour.repair-source-only.deny",
"polarity": "deny",
"evidence_ref": "apps/storycore-harbour/tests/repair-prompt.test.mjs#repair excludes model-derived text in parser and reference diagnostics"
}
],
"supersedes": [],
"last_verified": {
"at": "2026-09-09T05:21:49+00:00",
"content_sha256": "ee1a2f6819fc9282355b5e97900c261e671d8c62863c722531cb20d98ebb3166",
"evidence_ref": ".botte/engine.md#Verification boundary"
}
},
{
"id": "harbour.project-references",
"action": "project-validation",
"effect": "REQUIRE",
"scope": [
"harbour-project-contract"
],
"statement": "all referenced character and location IDs must exist;",
"source_ref": "apps/storycore-harbour/ARCHITECTURE.md#all referenced character and location IDs must exist;",
"owner_only": false,
"enforced": true,
"enforcement_refs": [
"apps/storycore-harbour/bundle/project-contract.js#if (isText(id) && !knownIds.has(id)) {",
"apps/storycore-harbour/bundle/project-contract.js#if (isText(id) && !characterIds.has(id)) {",
"apps/storycore-harbour/bundle/project-contract.js#if (isText(scene.locationId) && !context.locationIds.has(scene.locationId)) {"
],
"probes": [
{
"id": "harbour.project-references.allow",
"polarity": "allow",
"evidence_ref": "apps/storycore-harbour/tests/contracts.test.mjs#sample project passes the contract"
},
{
"id": "harbour.project-references.deny",
"polarity": "deny",
"evidence_ref": "apps/storycore-harbour/tests/contracts.test.mjs#unknown scene location is rejected"
},
{
"id": "harbour.project-references.deny-scene-character",
"polarity": "deny",
"evidence_ref": "apps/storycore-harbour/tests/contracts.test.mjs#unknown scene character is rejected"
},
{
"id": "harbour.project-references.deny-shot-character",
"polarity": "deny",
"evidence_ref": "apps/storycore-harbour/tests/contracts.test.mjs#unknown shot character is rejected"
}
],
"supersedes": [],
"last_verified": {
"at": "2026-09-09T05:21:49+00:00",
"content_sha256": "aaed2b94d47a6089dac53d1df74223fb52eea8e4c80e89dab9c68322ec94b414",
"evidence_ref": ".botte/engine.md#Verification boundary"
}
},
{
"id": "harbour.public-acceptance-redaction",
"action": "acceptance-summary",
"effect": "REQUIRE",
"scope": [
"harbour-evaluator-public-output"
],
"statement": "Redact model-derived validation text and unknown identifiers from evaluator output.",
"source_ref": "apps/storycore-harbour/CODEX_TASKS.md#Redact model-derived validation text and unknown identifiers from evaluator output.",
"owner_only": false,
"enforced": true,
"enforcement_refs": [
"apps/storycore-harbour/scripts/evaluate-acceptance.mjs#function publicPromptId(value) {",
"apps/storycore-harbour/scripts/evaluate-acceptance.mjs#return PUBLIC_CATEGORIES.has(value) ? value : \"unknown\";",
"apps/storycore-harbour/scripts/evaluate-acceptance.mjs#reasonCount: Array.isArray(failure.reasons) ? failure.reasons.length : 0,"
],
"probes": [
{
"id": "harbour.public-acceptance-redaction.allow",
"polarity": "allow",
"evidence_ref": "apps/storycore-harbour/tests/acceptance-public-output.test.mjs#public acceptance output strips model-derived validation text"
},
{
"id": "harbour.public-acceptance-redaction.deny",
"polarity": "deny",
"evidence_ref": "apps/storycore-harbour/tests/acceptance-public-output.test.mjs#public acceptance output replaces unknown identifiers and categories"
}
],
"supersedes": [],
"last_verified": {
"at": "2026-09-09T05:21:49+00:00",
"content_sha256": "455c248ffa202f2b885f33ebe4f4decc71ea6808da63fb07dbaa46e2731276a8",
"evidence_ref": ".botte/engine.md#Verification boundary"
}
}
]
}
72 changes: 72 additions & 0 deletions .github/workflows/music-plan-contract.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
name: MusicPlan Contract

on:
pull_request:
branches: [main]
paths:
- "schemas/music-plan-v1.schema.json"
- "src/music_plan.py"
- "src/music_provider.py"
- "scripts/music_plan_mutation_probe.py"
- "scripts/music_plan_holdout_evaluator.py"
- "tests/test_music_plan.py"
- "tests/fixtures/music_plan/**"
- "docs/music-planning-layer-v1.md"
- ".github/workflows/music-plan-contract.yml"

permissions:
contents: read

jobs:
validate:
runs-on: ubuntu-latest
strategy:
matrix:
python-version: ["3.10", "3.12"]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
- name: Install focused validation dependencies
run: python -m pip install 'pytest>=8,<10' 'jsonschema>=4.23,<5'
- name: Compile model-free contracts
run: python -m py_compile src/music_plan.py src/music_provider.py scripts/music_plan_mutation_probe.py scripts/music_plan_holdout_evaluator.py
- name: Run MusicPlan contract tests
run: python -m pytest -q tests/test_music_plan.py
- name: Run controlled negative mutation probe
run: python -m scripts.music_plan_mutation_probe
- name: Verify private holdout evaluator protocol
run: |
python - <<'PY'
import json
import subprocess
import sys
from pathlib import Path

plan = json.loads(Path('tests/fixtures/music_plan/full.json').read_text(encoding='utf-8'))
request = {"id": "public-protocol-smoke", "input": {"plan": plan, "expected_valid": True}}
r = subprocess.run(
[sys.executable, '-m', 'scripts.music_plan_holdout_evaluator'],
input=json.dumps(request), text=True, capture_output=True, check=True,
)
response = json.loads(r.stdout)
assert response == {"passed": True}, response
print('holdout evaluator protocol OK')
PY
- name: Verify Draft 2020-12 schema and reference fixtures
run: |
python - <<'PY'
import json
from pathlib import Path
from jsonschema import Draft202012Validator

schema_path = Path('schemas/music-plan-v1.schema.json')
schema = json.loads(schema_path.read_text(encoding='utf-8'))
Draft202012Validator.check_schema(schema)
validator = Draft202012Validator(schema)
for path in sorted(Path('tests/fixtures/music_plan').glob('*.json')):
data = json.loads(path.read_text(encoding='utf-8'))
validator.validate(data)
print(f'OK {path}')
PY
19 changes: 19 additions & 0 deletions .github/workflows/repository-checkout-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
name: Repository Checkout CI

on:
pull_request:
paths:
- 'GemReward-Service-Repo'
- '.gitmodules'
- '.github/workflows/repository-checkout-ci.yml'
workflow_dispatch:

permissions:
contents: read

jobs:
checkout:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@v4
39 changes: 39 additions & 0 deletions .github/workflows/storycore-harbour-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ on:
pull_request:
paths:
- "apps/storycore-harbour/**"
- ".botte/**"
- "skills/console_utf8.py"
- "skills/directives_audit/rules.py"
- "skills/directives_audit/rules_cli.py"
- ".github/workflows/storycore-harbour-ci.yml"
workflow_dispatch:

Expand All @@ -26,6 +30,41 @@ jobs:
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false

- name: Verify the exact source revision
working-directory: ${{ github.workspace }}
shell: bash
env:
SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
set -euo pipefail
test "$(git rev-parse HEAD)" = "${SOURCE_SHA}"
printf 'SOURCE_SHA=%s\n' "${SOURCE_SHA}"

- name: Audit committed rule references
working-directory: ${{ github.workspace }}
shell: bash
env:
PYTHONPATH: .
PYTHONDONTWRITEBYTECODE: "1"
run: |
set -euo pipefail
python3 -m skills.directives_audit.rules_cli audit . --json > "${RUNNER_TEMP}/rules-audit.json"
cat "${RUNNER_TEMP}/rules-audit.json"
python3 - "${RUNNER_TEMP}/rules-audit.json" <<'PY'
import json, sys
with open(sys.argv[1], encoding="utf-8") as stream:
report = json.load(stream)
summary = report["summary"]
if (report["schema"] != "botte.rules-audit/v1"
or report["manifest_present"] is not True
or summary["rules"] < 1
or summary["errors"] != 0 or summary["warnings"] != 0):
raise SystemExit("BLOCKED/DRIFT: rule audit needs a present, nonempty, clean contract")
PY

- name: Set up Node.js 22
uses: actions/setup-node@v4
Expand Down
Loading
Loading