Files
OBLITERATUS/WORKSPACE.md
T

87 lines
3.9 KiB
Markdown

# WORKSPACE.md
<!-- aiwg-managed -->
<!-- Generated structure by AIWG; operator content is protected by markers. -->
<!-- AIWG:workspace-context:start -->
## AIWG Context Graph
This file is the canonical provider-neutral home for project and operator context.
Provider startup files are generated adapters: they direct the harness here first,
then to AIWG.md for framework discovery and routing.
### Precedence
1. Provider, system, and organization instructions retain their native authority.
2. Root WORKSPACE.md supplies shared project/operator context.
3. AIWG.md supplies generated framework/discovery context.
4. Narrower linked files and provider-native subtree instructions govern their declared scope.
### Ownership
- Edit project-neutral notes only inside the protected Project Context section below.
- Keep detailed policies, runbooks, hooks, and quickrefs in linked files.
- Keep provider-only directives in `.aiwg/context/providers/`.
- Never store secrets, tokens, credentials, or machine-local sensitive values here.
### Linked Context
- [AIWG framework context](./AIWG.md)
- [AIWG project configuration](.aiwg/aiwg.config)
- [Project-local quickref](.aiwg/quickref.json) (when configured)
<!-- AIWG:workspace-context:end -->
<!-- AIWG:workspace-operator:start -->
## Project Context
OBLITERATUS is a Python research tool. The default pull-request baseline must be
CPU-safe, deterministic, and must not download models or require network,
accelerator, or remote-execution credentials.
Canonical required checks:
- the exact Ruff F and actionlint command set in [.github/workflows/ci.yml](.github/workflows/ci.yml);
- `python -m pytest` with at least 60% repository line coverage and 42% branch
coverage;
- at least 90% changed-line coverage plus no line or branch regression in any
touched production module, compared with coverage from the exact base commit;
- at least 80% line and 75% branch coverage for the documented mature
CPU-testable scope, plus a 70% selective mutation score and zero unexpected
warnings;
- `python -m build --sdist --wheel`
- `python -c 'import obliteratus; print(obliteratus.__version__)'`
- `python -m obliteratus --help`
CI additionally validates wheel and sdist metadata, installs each distribution
in an independent environment outside the checkout, exercises both CLI entry
paths, and retains the distributions plus evidence. Immutable CI action/tool
pins are recorded in [ci/digests.txt](ci/digests.txt).
The source-to-test ownership graph is versioned in
[ci/test-risk-map.json](ci/test-risk-map.json). Coverage, JUnit, repeat, and
mutation trends are normalized into project-owned JSON and retained for 90
days. Flake history and time-bounded quarantines are governed by
[ci/test-quality-policy.json](ci/test-quality-policy.json); a test observed
flaking twice in 30 days requires an active owner/issue-linked quarantine.
Python CI resolution is locked by `uv.lock`, including the official CPU-only
PyTorch source for Linux and Windows. The required Supply chain job scans all
supported Python versions for known vulnerabilities, scans the checkout for
secrets with fully redacted evidence, enforces the packaged-dependency license
allow list, and binds a CycloneDX SBOM to the built wheel. Exception and update
rules are documented in [docs/SUPPLY_CHAIN_POLICY.md](docs/SUPPLY_CHAIN_POLICY.md).
GPU, MPS, MLX, model-download, external-evaluation, network, operator-UI, and
remote-execution checks are conditional release or risk-surface gates, not part
of the default CPU job.
Use [.aiwg/bt6-maintainer.yaml](.aiwg/bt6-maintainer.yaml) and the project-local
`bt6-maintainer` bundle for issue, pull-request, provider, and merge-train work.
Maintainers may add missing tests to already-reviewed legacy pull requests as a
one-time transition courtesy. New changes must include relevant tests and keep
the complete required suite green.
<!-- AIWG:workspace-operator:end -->