mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-02 17:40:02 +02:00
* feat: add surface-aware exploratory QA and ship documentation gates * test: preserve delegated QA setup authority after main integration * fix(qa): clarify exploration order and preserve report artifacts * test(qa): follow the shared setup reference directly * refactor(ship): make verification and recovery routes explicit * test(ship): align evidence and review guards with explicit routes * fix(workflows): clarify ship recovery and functional QA evidence * fix(workflows): clarify approval recovery and full QA coverage * refactor(workflows): order review transactions and clarify ship state * fix(ship): clarify final verification and fail closed at publication * fix(evals): attribute native atomic documentation writes * fix(ship): clarify recovery and documentation lifecycle guidance * fix(test): preserve observed native placeholder styling in CI * fix(codex): report watchdog timeouts without a process-exit race * Checkpoint functional QA implementation and workflow validation repairs * Fix documentation and shared-review fixture contracts * docs: clarify judge reuse and evaluation supervision * test: align review evidence and selected case contracts * test: verify append-only documentation checkpoints and recovery * fix: qualify QA workflows and CI validation repairs * fix: launch shared-libs fixture scripts on Windows * fix: qualify QA deadlines, fixture isolation, and shard cleanup * fix: preserve qualified QA and cancellation repairs * fix: enforce functional fixture authority and share strict event decoding * fix: retain free-test evidence and explain recovery * fix: reject malformed native evidence after decoder consolidation * test: use reliable capture for telemetry privacy filters * test: refresh measured quick coverage and document validation costs * Fix native fixture receipts and preserve VM validation evidence * Align negative judge controls with upstream clarity policy * Fix report-only QA preparation and public evidence handling * Clarify QA-only preparation and current-report preservation * Stream Ship quality judgments with an explicit 64k response contract * Validate compact judge reasoning locally with supported wire schema * Align functional QA fixture instructions with evidence acceptance * Bind native browser diagnostics to execution evidence and align review verdicts * Preserve native diagnostic line boundaries * Serialize functional QA evidence from native captures * Keep large QA evidence fixture payload out of Windows argv
59 lines
3.3 KiB
TypeScript
59 lines
3.3 KiB
TypeScript
/** Extract the installed review workflow, handling carved and inline host renders. */
|
|
import * as fs from 'node:fs';
|
|
import * as path from 'node:path';
|
|
import { existsSync, mkdirSync, readFileSync, writeFileSync } from 'node:fs';
|
|
import { join } from 'node:path';
|
|
import { extractSkillSections } from './skill-fixture';
|
|
|
|
export function installOutsideReviewFixture(rendered: string, host: 'claude' | 'codex', repo: string, runtimeRoot: string): string {
|
|
const source = host === 'claude' ? join(rendered, 'review') : join(rendered, '.agents', 'skills', 'gstack-review');
|
|
const name = host === 'claude' ? 'review' : 'gstack-review';
|
|
const destination = join(repo, host === 'claude' ? '.claude' : '.agents', 'skills', name);
|
|
mkdirSync(destination, { recursive: true });
|
|
const head = extractSkillSections(source, ['Step 0: Detect platform and base branch', 'Step 3: Get the diff']);
|
|
const sectionPath = join(source, 'sections', 'adversarial.md');
|
|
const section = existsSync(sectionPath) ? readFileSync(sectionPath, 'utf8')
|
|
: extractSkillSections(source, ['Step 4.8: Adversarial review (always-on)']).replace(/^---\r?\n[\s\S]*?\r?\n---\r?\n/, '');
|
|
if (!section.includes('Adversarial review (always-on)')) throw new Error(`Missing adversarial workflow: ${source}`);
|
|
// Runtime paths are the only fixture substitution. Provider selection,
|
|
// caller controls, prompt, probes, and execution code stay generated verbatim.
|
|
const content = (head + '\n' + section)
|
|
.replaceAll('~/.claude/skills/gstack', runtimeRoot)
|
|
.replaceAll('$HOME/.claude/skills/gstack', runtimeRoot)
|
|
.replaceAll('${GSTACK_BIN}', join(runtimeRoot, 'bin'))
|
|
.replaceAll('$GSTACK_BIN', join(runtimeRoot, 'bin'))
|
|
.replaceAll('$GSTACK_ROOT', runtimeRoot);
|
|
writeFileSync(join(destination, 'SKILL.md'), content);
|
|
return destination;
|
|
}
|
|
|
|
// Each paid invocation must begin at the same committed authorization defect.
|
|
function git(cwd: string, ...args: string[]) {
|
|
const result = Bun.spawnSync(['git', ...args], { cwd, stdout: 'pipe', stderr: 'pipe', timeout: 10_000 });
|
|
if (result.exitCode !== 0) throw new Error(`git ${args[0]}: ${result.stderr.toString()}`);
|
|
}
|
|
|
|
export function createOutsideReviewRepo(fixtureRoot: string, host: 'claude' | 'codex'): string {
|
|
// Bun retries reuse beforeAll state; each attempt needs a new git repository.
|
|
const dir = fs.mkdtempSync(path.join(fixtureRoot, `${host}-`));
|
|
git(dir, 'init', '-b', 'main');
|
|
git(dir, 'config', 'user.email', 'eval@example.com');
|
|
git(dir, 'config', 'user.name', 'Outside Voice Eval');
|
|
const safe = `export async function readPrivateInvoice(db, actor, invoiceId) {
|
|
const invoice = await db.invoice.findUnique({ where: { id: invoiceId } });
|
|
if (!invoice) return null;
|
|
if (invoice.ownerId !== actor.id) throw new Error('Forbidden');
|
|
return { amount: invoice.amount, bankAccount: invoice.bankAccount };
|
|
}
|
|
`;
|
|
fs.writeFileSync(path.join(dir, 'invoice.ts'), safe);
|
|
git(dir, 'add', 'invoice.ts');
|
|
git(dir, 'commit', '-m', 'Protect private invoices by owner');
|
|
git(dir, 'update-ref', 'refs/remotes/origin/main', 'HEAD');
|
|
git(dir, 'checkout', '-b', 'feature/invoice-lookup');
|
|
fs.writeFileSync(path.join(dir, 'invoice.ts'), safe.replace(" if (invoice.ownerId !== actor.id) throw new Error('Forbidden');\n", ''));
|
|
git(dir, 'add', 'invoice.ts');
|
|
git(dir, 'commit', '-m', 'Simplify invoice lookup');
|
|
return dir;
|
|
}
|