← Files AkinatorARCHIVED FILE

.github/workflows/ci.yml

5.25 KB · Oct 3, 2026 · 06:33 UTC

↓ Download file

name: CI

# Knowledge enforcement runs HERE - in CI, off the developer's machine - and in
# the test suite. Never in a git hook. Git hooks gate code and must stay fast; a
# hook loaded with knowledge checks makes commits slow, which trains
# `--no-verify`, which takes down the code checks too.
# See rules/05-no-git-hook-complication.md and docs/adr/0003-enforcement-outside-git-hooks.md.

on:
  push:
    branches: [main]
  pull_request:

jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      # fetch-depth: 0 - a shallow (default) checkout gives git log a single
      # commit, so mine_git() in skills/everything/scripts/akinator_distil.py finds no fix:
      # history no matter how much really exists. Full history is what the
      # miner is testing against.
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - uses: actions/setup-python@v5
        with:
          python-version: '3.13'

      - name: Install test dependencies
        run: python -m pip install --quiet pytest

      # Structural and enforcement tests: the plugin satisfies the platform
      # contracts it claims, and every rule's named mechanism actually works.
      - name: Tests
        run: python -m pytest tests/ -q

      # The Codex pack must match the canonical skills. A hand-edit and a stale
      # pack produce the same symptom, so one check catches both.
      - name: Codex pack drift
        run: python scripts/build_codex_pack.py --check

      # The component map must match the tree.
      - name: Context map drift
        run: python scripts/extract_components.py --check

      # Every ledger record parses and carries its required fields. A
      # half-written record is a record that will not be found when it matters.
      - name: Ledger integrity
        run: python skills/everything/scripts/akinator_ledger.py verify

      # The brief is what a new session reads. A stale one is the worst
      # possible artifact to ship, because it is the most trusted.
      - name: Brief drift
        run: python skills/everything/scripts/build_brief.py --check

      # Anything that has happened twice and has no recorded decision needs
      # an answer - rule, skill, or an explicit 'neither'. Exit 1 means a
      # human owes the repository a decision, not that anything is broken.
      - name: Recurring failures awaiting a decision
        run: python skills/everything/scripts/akinator_distil.py detect

      # Rules whose scopes overlap and whose mandates disagree. Reported,
      # never auto-resolved - the resolution is a human decision.
      - name: Rule conflicts
        run: python skills/everything/scripts/akinator_rules.py conflicts

      # Dependencies and modules, extracted rather than described.
      - name: Stack map drift
        run: python skills/everything/scripts/extract_stack.py --check

      # One page per dependency: generated facts must match the manifests and
      # the imports. Curated sections are never checked, only preserved.
      - name: Library pages drift
        run: python skills/everything/scripts/extract_libraries.py --check

      # The wiki home must list every category and its current gap count.
      - name: Wiki index drift
        run: python skills/everything/scripts/akinator_wiki.py check

      # Eleven routers, one contract. Hand-editing any of them, or changing the
      # contract without re-rendering, fails here.
      - name: Router drift
        run: python scripts/render_routers.py --check

      # Every behavioral eval must at least be *parseable and runnable*. A suite
      # the runner cannot execute is documentation pretending to be a test.
      # Executing them needs an agent CLI and is a separate, manual step.
      - name: Eval suites are runnable
        run: python scripts/run_evals.py --dry-run --all

      # The knowledge invariants, against Akinator's own repository. The plugin
      # must not ship a layer it would reject in a target repo.
      # --strict, not the default --fail-on high. `reachability` and
      # `index-completeness` are MEDIUM, so the default tier would let an
      # unindexed artifact pass CI green - which was true of reachability from
      # the start and was never noticed until a review lens mutation-tested it.
      # MEDIUM is the right severity for a target repo onboarding gradually; it
      # is not the right bar for the plugin's own repo.
      - name: Coverage invariants
        run: python skills/everything/scripts/akinator_coverage.py . --strict

      # The fixture repositories carry planted defects on purpose. Assert the
      # checker still detects them - a checker whose detection has silently
      # broken reports green and everyone believes it.
      - name: Fixture defects are still detected
        run: |
          set -e
          if python skills/everything/scripts/akinator_coverage.py evals/fixtures/rotten; then
            echo "::error::the rotten fixture passed - the checker's detection has broken"
            exit 1
          fi
          echo "rotten fixture still fails as expected"

      # The fixtures' own suites must pass; a broken fixture invalidates the
      # evals that run against it.
      - name: Fixture suites
        run: |
          python -m pytest evals/fixtures/greenfield/tests -q
          python -m pytest evals/fixtures/rotten/tests -q

SHA-256: 4cddd3c64f357cb14dbc4fd75d10ebb8498ed7e57746c89ce1e3740d092e8ad4