mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-02 17:40:02 +02:00
* feat: add surface-aware exploratory QA and ship documentation gates * test: preserve delegated QA setup authority after main integration * fix(qa): clarify exploration order and preserve report artifacts * test(qa): follow the shared setup reference directly * refactor(ship): make verification and recovery routes explicit * test(ship): align evidence and review guards with explicit routes * fix(workflows): clarify ship recovery and functional QA evidence * fix(workflows): clarify approval recovery and full QA coverage * refactor(workflows): order review transactions and clarify ship state * fix(ship): clarify final verification and fail closed at publication * fix(evals): attribute native atomic documentation writes * fix(ship): clarify recovery and documentation lifecycle guidance * fix(test): preserve observed native placeholder styling in CI * fix(codex): report watchdog timeouts without a process-exit race * Checkpoint functional QA implementation and workflow validation repairs * Fix documentation and shared-review fixture contracts * docs: clarify judge reuse and evaluation supervision * test: align review evidence and selected case contracts * test: verify append-only documentation checkpoints and recovery * fix: qualify QA workflows and CI validation repairs * fix: launch shared-libs fixture scripts on Windows * fix: qualify QA deadlines, fixture isolation, and shard cleanup * fix: preserve qualified QA and cancellation repairs * fix: enforce functional fixture authority and share strict event decoding * fix: retain free-test evidence and explain recovery * fix: reject malformed native evidence after decoder consolidation * test: use reliable capture for telemetry privacy filters * test: refresh measured quick coverage and document validation costs * Fix native fixture receipts and preserve VM validation evidence * Align negative judge controls with upstream clarity policy * Fix report-only QA preparation and public evidence handling * Clarify QA-only preparation and current-report preservation * Stream Ship quality judgments with an explicit 64k response contract * Validate compact judge reasoning locally with supported wire schema * Align functional QA fixture instructions with evidence acceptance * Bind native browser diagnostics to execution evidence and align review verdicts * Preserve native diagnostic line boundaries * Serialize functional QA evidence from native captures * Keep large QA evidence fixture payload out of Windows argv
86 lines
3.7 KiB
Bash
Executable File
86 lines
3.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# gstack-review-log — atomically log a review result
|
|
# Usage: gstack-review-log '{"skill":"...","timestamp":"...","status":"..."}'
|
|
#
|
|
# Before reading a diff: gstack-review-log --start review
|
|
# After that pass: gstack-review-log '{...,"completed":true,"converged":true}' --finish TOKEN
|
|
# Diff reviews get wtree only from a consumed, matching start capture on an
|
|
# unchanged tree. Completion/convergence are reviewer-reported, not proof that
|
|
# a model read the code. Caller-supplied binding fields are always discarded.
|
|
# Plan-tier rows retain their legacy binding behavior.
|
|
set -euo pipefail
|
|
export GIT_OPTIONAL_LOCKS=0
|
|
export GIT_CONFIG_PARAMETERS="${GIT_CONFIG_PARAMETERS:+$GIT_CONFIG_PARAMETERS }'core.fsmonitor=false' 'core.untrackedCache=false'"
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
eval "$("$SCRIPT_DIR/gstack-slug" 2>/dev/null)"
|
|
GSTACK_HOME="${GSTACK_HOME:-$HOME/.gstack}"
|
|
mkdir -p "$GSTACK_HOME/projects/$SLUG"
|
|
|
|
INPUT="${1:-}"
|
|
export GSTACK_REVIEW_DIR="$GSTACK_HOME/projects/$SLUG"
|
|
export GSTACK_REVIEW_REPO="$(git rev-parse --show-toplevel 2>/dev/null || true)"
|
|
export GSTACK_REVIEW_BRANCH="$(git symbolic-ref --short HEAD 2>/dev/null || git rev-parse HEAD 2>/dev/null || true)"
|
|
export GSTACK_REVIEW_LIB="$SCRIPT_DIR/../lib/review-evidence.ts"
|
|
case "$(uname -s)" in
|
|
MINGW*|MSYS*|CYGWIN*)
|
|
if command -v cygpath >/dev/null 2>&1; then
|
|
GSTACK_REVIEW_LIB="$(cygpath -m "$GSTACK_REVIEW_LIB")"
|
|
GSTACK_REVIEW_DIR="$(cygpath -m "$GSTACK_REVIEW_DIR")"
|
|
fi
|
|
;;
|
|
esac
|
|
export GSTACK_REVIEW_LOG="$GSTACK_REVIEW_DIR/$BRANCH-reviews.jsonl"
|
|
|
|
# Compute binding fields (best-effort; empty outside a git repo).
|
|
COMMIT_FULL=$(git rev-parse HEAD 2>/dev/null || true)
|
|
TREE=""
|
|
WTREE=""
|
|
DIRTY=""
|
|
if [ -n "$COMMIT_FULL" ]; then
|
|
TREE=$(git rev-parse 'HEAD^{tree}' 2>/dev/null || true)
|
|
WTREE=$("$SCRIPT_DIR/gstack-wtree" 2>/dev/null || true)
|
|
if [ -n "$(git status --porcelain -uno 2>/dev/null | head -1)" ]; then
|
|
DIRTY="true"
|
|
else
|
|
DIRTY="false"
|
|
fi
|
|
fi
|
|
|
|
export GSTACK_STAMP_COMMIT_FULL="$COMMIT_FULL" GSTACK_STAMP_TREE="$TREE" GSTACK_STAMP_WTREE="$WTREE" GSTACK_STAMP_DIRTY="$DIRTY"
|
|
if [ "$INPUT" = --start ]; then
|
|
GSTACK_REVIEW_SKILL="${2:-}" bun -e '
|
|
const { captureReviewStart } = await import(process.env.GSTACK_REVIEW_LIB);
|
|
console.log(captureReviewStart(process.env.GSTACK_REVIEW_SKILL));
|
|
'
|
|
exit $?
|
|
fi
|
|
if [ "$INPUT" = --check-shared-libs ] && [ "$#" -eq 2 ]; then
|
|
GSTACK_REVIEW_TOKEN="$2" bun -e '
|
|
const { checkSharedLibsReuse } = await import(process.env.GSTACK_REVIEW_LIB);
|
|
console.log(JSON.stringify(checkSharedLibsReuse(JSON.parse(await Bun.stdin.text()), process.env.GSTACK_REVIEW_TOKEN)));
|
|
'
|
|
exit $?
|
|
fi
|
|
if [ "$#" -ne 1 ] && { [ "$#" -ne 3 ] || [ "${2:-}" != --finish ]; }; then
|
|
echo 'Usage: gstack-review-log JSON [--finish TOKEN] | --start SKILL | --check-shared-libs TOKEN < finding.json' >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Validate (reject malformed or injection attempts) AND stamp in one pass.
|
|
# Caller values for the binding keys are dropped before stamping.
|
|
STAMPED=$(printf '%s' "$INPUT" | GSTACK_REVIEW_TOKEN="${3:-}" bun -e "
|
|
const { bindReview } = await import(process.env.GSTACK_REVIEW_LIB);
|
|
const rec = JSON.parse(await Bun.stdin.text());
|
|
if (!rec || Array.isArray(rec) || typeof rec !== 'object') throw new Error('expected object');
|
|
console.log(JSON.stringify(bindReview(rec, process.env.GSTACK_REVIEW_TOKEN)));
|
|
" 2>/dev/null) || {
|
|
# Not valid JSON — refuse to append
|
|
echo "gstack-review-log: invalid JSON, skipping" >&2
|
|
exit 1
|
|
}
|
|
|
|
echo "$STAMPED" >> "$GSTACK_HOME/projects/$SLUG/$BRANCH-reviews.jsonl"
|
|
|
|
# gbrain-sync: enqueue for cross-machine sync (no-op if sync is off).
|
|
"$SCRIPT_DIR/gstack-brain-enqueue" "projects/$SLUG/$BRANCH-reviews.jsonl" 2>/dev/null &
|