PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 6s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 1s
The validate job runs with bash -e -o pipefail. `echo "$FM" | grep -q '^name:'` lets grep exit on first match, which can SIGPIPE the echo; pipefail then reports the pipeline non-zero and the || branch raises a false "Missing name/description". The flagged file set varied run to run (and included files untouched by the PR) while a fresh clone of the same commit passes the identical check. Reproduced: the old form failed 3 of 5 local runs under the same shell flags, the herestring form passed 5 of 5. Use herestrings so no pipe can be broken.
111 lines
4.1 KiB
YAML
111 lines
4.1 KiB
YAML
name: PR Pipeline — Authorize → Validate → Review → Merge
|
|
on:
|
|
push:
|
|
branches: [master]
|
|
paths:
|
|
- '**.prose.md'
|
|
- 'scripts/**.sh'
|
|
- '**.yaml'
|
|
- '**.yml'
|
|
pull_request:
|
|
types: [opened, synchronize, reopened]
|
|
paths:
|
|
- '**.prose.md'
|
|
- 'scripts/**.sh'
|
|
- '**.yaml'
|
|
- '**.yml'
|
|
|
|
jobs:
|
|
auth:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout repository
|
|
run: |
|
|
git clone --depth=50 "http://192.168.68.17:3000/${{ gitea.repository }}.git" .
|
|
git fetch origin "${{ gitea.ref }}" --depth=50
|
|
git checkout "${{ gitea.sha }}"
|
|
|
|
- name: Authorization check
|
|
run: bash scripts/prose-auth-check.sh
|
|
|
|
validate:
|
|
runs-on: ubuntu-latest
|
|
needs: auth
|
|
steps:
|
|
- name: Checkout repository
|
|
run: |
|
|
git clone --depth=50 "http://192.168.68.17:3000/${{ gitea.repository }}.git" .
|
|
git fetch origin "${{ gitea.ref }}" --depth=50
|
|
git checkout "${{ gitea.sha }}"
|
|
|
|
- name: YAML frontmatter validation
|
|
run: |
|
|
echo "=== Prose Contract Frontmatter Validation ==="
|
|
FAILED=0
|
|
for f in $(find . -name "*.prose.md" -not -path "./.git/*" -not -path "./runs/*"); do
|
|
# NOTE: use herestrings, not `echo "$FM" | grep ...`. Under the runner's
|
|
# `-e -o pipefail`, `grep -q` exits on first match and can SIGPIPE the
|
|
# producer, making the pipeline report non-zero and raising a false
|
|
# "Missing name/description" whose file set varies run to run.
|
|
FM=$(sed -n '/^---$/,/^---$/p' "$f" | sed '1d;$d')
|
|
[ -z "$FM" ] && { echo " ❌ $f: No YAML frontmatter"; FAILED=$((FAILED+1)); continue; }
|
|
|
|
KIND=$(grep '^kind:' <<< "$FM" | awk '{print $2}')
|
|
case "$KIND" in
|
|
function|responsibility|gateway|pattern|test|template|architecture|enforcement) echo " ✅ $f: kind=$KIND" ;;
|
|
*) echo " ❌ $f: Invalid kind='$KIND'"; FAILED=$((FAILED+1)) ;;
|
|
esac
|
|
|
|
grep -q '^name:' <<< "$FM" || { echo " ❌ $f: Missing name"; FAILED=$((FAILED+1)); }
|
|
grep -q '^description:' <<< "$FM" || { echo " ❌ $f: Missing description"; FAILED=$((FAILED+1)); }
|
|
done
|
|
[ $FAILED -gt 0 ] && { echo "❌ FRONTMATTER FAILED ($FAILED error(s))"; exit 1; }
|
|
echo "✅ Frontmatter validation passed"
|
|
|
|
lint:
|
|
runs-on: ubuntu-latest
|
|
needs: validate
|
|
steps:
|
|
- name: Checkout repository
|
|
run: |
|
|
git clone --depth=50 "http://192.168.68.17:3000/${{ gitea.repository }}.git" .
|
|
git fetch origin "${{ gitea.ref }}" --depth=50
|
|
git checkout "${{ gitea.sha }}"
|
|
|
|
- name: Structure + regression + consistency lint
|
|
run: bash scripts/prose-lint.sh
|
|
|
|
ai-review:
|
|
runs-on: ubuntu-latest
|
|
needs: validate
|
|
steps:
|
|
- name: Checkout repository
|
|
run: |
|
|
git clone --depth=50 "http://192.168.68.17:3000/${{ gitea.repository }}.git" .
|
|
git fetch origin "${{ gitea.ref }}" --depth=50
|
|
git checkout "${{ gitea.sha }}"
|
|
|
|
- name: AI-powered contract review
|
|
env:
|
|
LITELLM_URL: ${{ secrets.LITELLM_URL }}
|
|
LITELLM_KEY: ${{ secrets.LITELLM_KEY }}
|
|
run: bash scripts/prose-ai-review.sh
|
|
|
|
gate:
|
|
runs-on: ubuntu-latest
|
|
needs: [auth, validate, lint, ai-review]
|
|
if: success()
|
|
steps:
|
|
- name: Merge gate
|
|
run: |
|
|
echo "╔══════════════════════════════════════╗"
|
|
echo "║ ALL CHECKS PASSED — SAFE TO MERGE ║"
|
|
echo "╚══════════════════════════════════════╝"
|
|
echo ""
|
|
echo " ✅ auth — authorized agent"
|
|
echo " ✅ validate — frontmatter valid"
|
|
echo " ✅ lint — structure + no regressions"
|
|
echo " ✅ ai-review — no contradictions with ground truth"
|
|
echo ""
|
|
echo "Merge this PR to deploy to main."
|