Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions .agentic-loop.yml
Original file line number Diff line number Diff line change
Expand Up @@ -52,9 +52,8 @@ verification:
commands:
- "npx tsc --noEmit"
- "npm run lint"
- "npm run test:run"
- 'npm run quality:verify -- --base "${FALLOW_AUDIT_BASE:?Set the exact approved integration base SHA}"'
- "npm run build"
- 'FALLOW_AUDIT_BASE="${FALLOW_AUDIT_BASE:?Set the exact approved integration base SHA}" npm run fallow:audit'
- "git diff --check"

human:
Expand Down
7 changes: 4 additions & 3 deletions .codex/agents/delivery-worker.toml
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,12 @@ revision, source/test scope, exclusions, result, evidence path and provenance;
and the separate Standards and Spec review inputs. A body digest is computed
from the parsed GitHub body bytes without trimming or adding a CLI newline.
Use the exact starting origin/develop SHA in
FALLOW_AUDIT_BASE=<sha> npm run fallow:audit and verify Fallow's reported range.
npm run quality:verify -- --base <sha> and verify the retained bundle with
quality:check as described in docs/agents/quality-verification.md.

When every linked issue's acceptance criteria are satisfied, run relevant
focused checks plus npx tsc --noEmit, npm run lint, npm run test:run, npm run
build, FALLOW_AUDIT_BASE=<exact starting origin/develop SHA> npm run fallow:audit,
focused checks plus npx tsc --noEmit, npm run lint,
npm run quality:verify -- --base <exact starting origin/develop SHA>, npm run build,
and git diff --check. Keep the PR in draft, do not merge, and hand the complete
PR diff and exact head to pr-finalizer. Your task
ends at that handoff unless the workflow director explicitly returns a bounded
Expand Down
11 changes: 5 additions & 6 deletions .codex/agents/pr-finalizer.toml
Original file line number Diff line number Diff line change
Expand Up @@ -30,18 +30,17 @@ docs/agents/handoffs.md. Report Standards and Spec conclusions separately.
Finalizer findings name severity, evidence, affected requirement or standard,
and status; the Director verifies each finding and adds the disposition and
rationale. Use
FALLOW_AUDIT_BASE=<exact starting origin/develop SHA> npm run fallow:audit and
verify the report range; a bare, branch-upstream, or self-comparison audit is
not delivery evidence.
npm run quality:check -- --base <exact starting origin/develop SHA> --head <exact head>
and docs/agents/quality-verification.md to accept the retained bundle.

You may edit the PR branch only for a correction or simplification that is
directly required by the approved tickets, stays inside their write boundaries
and non-goals, preserves public behavior unless repairing a specified defect,
and has a convincing verification path. Prefer direct, boring code. Commit all
such finalizer changes in one focused commit, push the same branch, and rerun
the affected checks plus npx tsc --noEmit, npm run lint, npm run test:run, npm
run build, FALLOW_AUDIT_BASE=<exact starting origin/develop SHA> npm run
fallow:audit, and git diff --check.
the affected checks plus npx tsc --noEmit, npm run lint,
npm run quality:verify -- --base <exact starting origin/develop SHA>,
npm run build, and git diff --check.

Return exactly one verdict:

Expand Down
6 changes: 3 additions & 3 deletions .codex/agents/workflow-director.toml
Original file line number Diff line number Diff line change
Expand Up @@ -40,9 +40,9 @@ configuration, revision, measured scopes, exclusions, result, evidence
location, and provenance; and separate Standards and Spec findings with an
explicit disposition and rationale. Compare requirement content when its body
or governing decision changes. A changed head, wrong scope, absent evidence,
or wrong checkout invalidates affected approval and evidence. For local Fallow,
pin FALLOW_AUDIT_BASE to the exact starting origin/develop SHA and verify the
reported comparison range.
or wrong checkout invalidates affected approval and evidence. Use
docs/agents/quality-verification.md and quality:check with the exact starting
origin/develop base and candidate head to accept retained quality evidence.

Every delivery brief names the outcome, acceptance criteria, non-goals, write
boundaries, contract and runtime surfaces, decision and safety gates,
Expand Down
72 changes: 71 additions & 1 deletion .fallowrc.json
Original file line number Diff line number Diff line change
Expand Up @@ -25,5 +25,75 @@
"createRenderRoot",
"shouldUpdate",
"update"
]
],
"boundaries": {
"zones": [
{
"name": "browser",
"patterns": ["src/**"]
},
{
"name": "shared",
"patterns": ["shared/src/**"]
},
{
"name": "server",
"patterns": ["server/src/**"]
},
{
"name": "worker",
"patterns": ["workers/telemetry/src/**"]
},
{
"name": "tooling",
"patterns": ["scripts/**"]
},
{
"name": "root-tests",
"patterns": ["tests/**"]
},
{
"name": "server-tests",
"patterns": ["server/tests/**"]
},
{
"name": "shared-tests",
"patterns": ["shared/tests/**"]
}
],
"rules": [
{
"from": "browser",
"allow": ["browser", "shared"]
},
{
"from": "shared",
"allow": ["shared"]
},
{
"from": "server",
"allow": ["server", "shared"]
},
{
"from": "worker",
"allow": ["worker", "shared"]
},
{
"from": "tooling",
"allow": ["tooling", "shared"]
},
{
"from": "root-tests",
"allow": ["browser", "shared", "worker", "tooling", "root-tests"]
},
{
"from": "server-tests",
"allow": ["server", "shared", "server-tests"]
},
{
"from": "shared-tests",
"allow": ["shared", "shared-tests"]
}
]
}
}
45 changes: 26 additions & 19 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,12 +9,17 @@ permissions:
contents: read
pull-requests: read

env:
QUALITY_BASE: ${{ github.event.pull_request.base.sha || github.event.before }}
QUALITY_HEAD: ${{ github.event.pull_request.head.sha || github.sha }}

jobs:
checks:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false

Expand All @@ -28,47 +33,49 @@ jobs:
- name: Install Chromium for Browser Mode
run: npx playwright install --with-deps --only-shell chromium

- name: Shared workspace checks
run: npm run shared:check
- name: Shared typecheck
run: npm run shared:typecheck

- name: Server workspace checks
run: npm run server:check
- name: Server typecheck and lint
run: npm run server:typecheck && npm run server:lint

- name: Telemetry worker checks
run: npm run telemetry:typecheck && npm run telemetry:test && npm run telemetry:dry-run
- name: Telemetry worker typecheck and dry run
run: npm run telemetry:typecheck && npm run telemetry:dry-run

- name: Typecheck
run: npx tsc --noEmit

- name: Lint
run: npm run lint

- name: Tests
run: npm run test:run
- name: Quality evidence
run: |
npm run quality:verify -- --base "$QUALITY_BASE"
npm run quality:check -- --base "$QUALITY_BASE" --head "$QUALITY_HEAD"

- name: Browser tests
run: npm run test:browser
- name: Retain quality evidence
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: quality-${{ env.QUALITY_HEAD }}-${{ github.run_id }}-${{ github.run_attempt }}
path: .fallow/quality
include-hidden-files: true
if-no-files-found: error
retention-days: 14

- name: Build
run: npm run build

- name: Fallow audit
uses: fallow-rs/fallow@v2
with:
command: audit
version: 3.2.0
artifacts-dir: .fallow/ci
no-cache: true

server-container:
runs-on: ubuntu-latest
timeout-minutes: 15
env:
PIXEL_FORGE_IMAGE_REVISION: ${{ github.sha }}
PIXEL_FORGE_IMAGE_REVISION: ${{ github.event.pull_request.head.sha || github.sha }}
PIXEL_FORGE_SMOKE_PROJECT_NAME: pixel-forge-container-smoke-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false

- name: Build and smoke the linux/amd64 server image
Expand Down
5 changes: 3 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -124,14 +124,15 @@ failures, and a regression test for each confirmed bug.
or externally visible identifiers that lack a compatibility path. Preserve
the existing contract or add an explicit versioned migration.

Before collecting or accepting quality evidence, read
[`docs/agents/quality-verification.md`](docs/agents/quality-verification.md).
Before handoff, run the relevant focused checks plus:

```sh
npx tsc --noEmit
npm run lint
npm run test:run
npm run quality:verify -- --base <exact-starting-origin-develop-sha>
npm run build
npm run fallow:audit
git diff --check
```

Expand Down
2 changes: 1 addition & 1 deletion docs/agents/change-map.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ the listed tests and runner still cover the intended behavior.

- **Interface:** [`docs/operations/codex-agent-workflow.md`](../../docs/operations/codex-agent-workflow.md) is the canonical policy; [`AGENTS.md`](../../AGENTS.md), [`.agentic-loop.yml`](../../.agentic-loop.yml), and [`.codex/agents/`](../../.codex/agents/) provide entry, command, and role configuration.
- **Callers:** Workflow Director/Sol shapes and reconciles GitHub state; delivery-worker/Luna implements one approved delivery slice; pr-finalizer/Terra reviews the complete draft PR. GitHub issues, PRs, checks, and retained artifacts are the durable readers and writers.
- **Tests:** `.agentic-loop.yml` configures repository gates; focused Markdown/configuration checks validate links and profile parsing, while the application and workspace runners above prove product behavior. `npm run fallow:audit` must use the exact handed-off `FALLOW_AUDIT_BASE` and record its report scope.
- **Tests:** `.agentic-loop.yml` configures repository gates; focused Markdown/configuration checks validate links and profile parsing, while the application and workspace runners above prove product behavior. `npm run quality:verify -- --base <exact-sha>` collects the five profiles and constraints through [`scripts/quality-evidence.mjs`](../../scripts/quality-evidence.mjs). Public refusal exercises run with `npm run quality:test`; see [quality verification](quality-verification.md) before collection or downloaded-bundle acceptance.
- **Governing:** Root [`AGENTS.md`](../../AGENTS.md), [`docs/agents/issue-tracker.md`](../../docs/agents/issue-tracker.md), [`docs/agents/triage-labels.md`](../../docs/agents/triage-labels.md), and the live delivery issue govern readiness, task order, evidence, review, and the explicit human merge gate.

Browser, shared workspace, server integration, and telemetry Worker commands
Expand Down
5 changes: 5 additions & 0 deletions docs/agents/handoffs.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,11 @@ can review the new identity.

## Verification record

For collection, downloaded-bundle acceptance, and finalizer rechecks, follow
[quality verification](quality-verification.md). Record the bundle path, manifest
and certification digests, five separate producer scopes, and CI artifact ID,
digest and expiry alongside the command records below.

Each command is an attributable record, not just a pass label:

| Field | Required value |
Expand Down
Loading
Loading