Skip to content

Phase 0 (2/9): six blocking CI gates - #36

Closed
Pal Lakatos-Toth (pallakatos) wants to merge 1 commit into
phase0/foundation-docsfrom
phase0/ci-gates
Closed

Pal Lakatos-Toth (pallakatos) wants to merge 1 commit into
phase0/foundation-docsfrom
phase0/ci-gates

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Phase 0 · six blocking CI gates

Adds the CI enforcement layer for the Phase 0+ principles (§0.2 #1–#10 in the implementation plan).

Gates added under ci/

  • check-loc.sh — enforces ci/loc-budget.yaml per-file caps. operator.ts, plugin.ts, reconciler.rs etc. each have a Phase-specific ceiling.
  • no-stubs.sh — rejects pseudo-impl markers (TODO: implement, unimplemented!(), stub return literals in capability paths).
  • no-custom-crypto.sh — rejects hand-rolled crypto; only sodium, ring, rustls, webpki, and the vendored Signal stack are allowed.
  • no-null-provider-prod.sh — rejects provider: null|noop|disabled|none in production manifests (docs/security-audits/ exempted).
  • vendored-patch-audit.sh — ensures every vendored SDK change has a matching patch entry in docs/agt-vendored-patch-audit.md.
  • security-audit-required.sh — when a PR touches capability paths (controller/reconcilers, router/governance|audit|trust|rate_limiter|safety, inference-router/src/providers), a docs/security-audits/YYYY-MM-DD-*.md must land in the same PR with two distinct Signed-off-by lines.

ci/loc-budget.yaml

Initial Phase 0 budget anchored from today's tree.

Verification

  • All six scripts run green against main in a clean clone.
  • Each is runnable locally with BASE_SHA=<origin/main> HEAD_SHA=<HEAD> bash ci/<gate>.sh.

Stack

PR 2/9 — bases on phase0/foundation-docs (PR 1).

Gates (all fail-hard, no continue-on-error):
  - ci/check-loc.sh              — LOC budget per ci/loc-budget.yaml
                                   on production paths. Override: // ci:stub-ok:
  - ci/no-custom-crypto.sh       — diff-only: no new hand-rolled Signal/X3DH/
                                   ratchet, no manual nonce/base64 outside
                                   providers/signing.rs, providers/mesh.rs,
                                   vendor/, tests/
  - ci/no-null-provider-prod.sh  — Null*/noop/disabled provider in manifests
                                   requires azureclaw.azure.com/dev-only=true
  - ci/security-audit-required.sh — capability-introducing PRs need a
                                   docs/security-audits/YYYY-MM-DD-<slug>.md
                                   with two distinct Signed-off-by emails
  - ci/vendored-patch-audit.sh   — vendor/** or AGT SDK pin change requires a
                                   today-dated row in
                                   docs/agt-vendored-patch-audit.md

ci/loc-budget.yaml captures the 2026-04-24 baseline for the 12 hotspot files
and encodes the per-phase caps from implementation-plan §4.2.

.github/workflows/ci-gates.yml runs all six in a matrix, each as a separate
required check on PRs. BASE_REF defaults to origin/<base_branch> on PRs and
HEAD~1 on push-to-main.

Locally smoke-tested: all six pass on a clean HEAD against main; plugin.ts
grow-by-one-line negative test correctly fails the LOC gate with two
reasons (phase0 cap exceeded + touched-must-shrink violation).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos

Copy link
Copy Markdown
Collaborator Author

Closing in favor of an integrated validation on the dev branch. This branch has been merged into dev (see origin/dev) and a single dev → main PR will land once CI is green on dev. No code is lost — every commit remains on its phase0/* branch and is reachable from dev.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants