Skip to content

feat(ci): validate aw contracts - #3245

Merged
kongche-jbw merged 2 commits into
agentic-os-org:mainfrom
kongche-jbw:feature/ci/aw-contract-checks
Sep 14, 2026
Merged

kongche-jbw merged 2 commits into
agentic-os-org:mainfrom
kongche-jbw:feature/ci/aw-contract-checks

Conversation

@kongche-jbw

@kongche-jbw kongche-jbw commented Sep 12, 2026 •

Copy link
Copy Markdown
Collaborator

Why

AW contracts landed in #3214, but their checks still need a shared local/CI entry and an explicit result gate. This PR adds that CI layer on top of the merged contracts without changing their Rust implementation or schemas.

Commit guide

  1. d4b830476 — feat(ci): add aw contract check entry
    Introduce scripts/check.py as the shared entry for formatting, Clippy, Rust tests, cross-language canonical vectors and rustdoc. Pin the Rust toolchain, check that each contract test target has runnable tests, and reject missing tools, empty vectors and skipped self-tests. Force pushes run the full gate without relying on an unreachable old head. Behavior tests cover scope selection, bounded command failures and result aggregation; canonical validation also works under Python optimization.
  2. b98dbb78d — feat(ci): wire aw contract checks
    Connect that entry to push, pull-request and merge-group events through three jobs: AW / scope selects relevant changes, AW / contracts runs the checks, and AW / required validates the result against the tested candidate SHA. Use anolisa-k8s-general-ci-x64 for all three upstream jobs and GitHub-hosted Ubuntu 24.04 for forks without that runner. Use the same official Rust distribution endpoints as the main CI to avoid stale runner mirror metadata. Update both READMEs with the local command, runner selection and required-check setup.

The first commit owns the check behavior; the second owns GitHub Actions wiring and contributor instructions. Together they touch seven files. Core and native integration remain in subsequent PRs.

Related issue

Part of #3124; follows merged #3214. The umbrella issue remains open for later AW stages.

User / Agent impact and compatibility

No runtime or contract changes. Contributors gain a reproducible check command and a stable Actions result. Repository administrators must separately configure branch protection to require AW / required; this PR does not modify repository settings.

Validation

  • Runner update: workflow YAML parses, all three job selectors match the upstream runner label; git diff --check passed. Eight Python behavior tests passed, including force pushes with an unavailable old head and mismatched candidate rejection. Current Actions must validate this revision on the self-hosted runner.

  • Linux ARM64, Rust 1.97.1, Python 3.12.3, Node.js 24.15.0.

  • cd src/aw && timeout --kill-after=10 600 python3 -B scripts/check.py passed at 756e8bc9f: 8 Python behavior tests, 28 Rust tests, fmt, Clippy, Python/JavaScript canonical vectors and rustdoc.

  • git diff --check up/main...HEAD passed; the branch contains exactly the two commits above.

  • Actions results are reported in this PR. Local failure-path tests do not claim live Actions cancellation or branch-protection acceptance.

Documentation and rollback

The English and Chinese AW READMEs explain the shared check command and CI result. Module AGENTS and changelogs remain deferred until the broader module wiring is ready. Revert the workflow commit first, then the check-entry commit; if branch protection has since adopted AW / required, adjust that rule before removing the workflow.

@github-actions github-actions Bot added scope:ci ./.github/ scope:documentation ./docs/|./*.md|./NOTICE labels Sep 12, 2026
@kongche-jbw
kongche-jbw requested review from Forrest-ly and Zhilinlinlin and removed request for Zhilinlinlin September 12, 2026 03:26
@kongche-jbw

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T00:00:39.307615Z 756e8bc Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 756e8bc9f2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@ikunkun-sys ikunkun-sys left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

结论:APPROVE

审查了 756e8bc 的全部 7 个改动文件,覆盖路径筛选、失败传播、测试清单、候选提交与受测 SHA 汇总逻辑,未发现需要修改的问题。

本地 Linux x86_64、Rust 1.97.1、Python 3.11.13、Node.js 24.15.0 下,禁用受本机权限限制的 sccache 后,完整检查入口通过:8 项 Python 行为测试、28 项 Rust 测试、fmt、Clippy、Python/JavaScript 摘要向量和 rustdoc。

托管 AW CI 的 scope、contracts、required 作业均通过;日志确认候选 SHA 和受测 SHA 均为合成 merge 提交 2de7103。提交 review 前已刷新确认 head/base 未变化,无已有 review 或未解决线程。

验证边界:未实测在线取消工作流和分支保护配置。

@kongche-jbw
kongche-jbw force-pushed the feature/ci/aw-contract-checks branch 2 times, most recently from 87831bc to 58205e0 Compare September 14, 2026 09:57
- Reuse contract checks through one bounded entry and pin the Rust toolchain.
- Reject empty tests and vectors, including under Python optimization.
- Share scope and result checks without adding runtime dependencies.

Signed-off-by: kongche-jbw <kongche.jbw@alibaba-inc.com>
- Run fixed scope, contract and required jobs on pushes and merge candidates.
- Bind results to the tested commit and reject incomplete runs.
- Use self-hosted upstream runners and hosted fork runners; document the gate.

Signed-off-by: kongche-jbw <kongche.jbw@alibaba-inc.com>
@kongche-jbw
kongche-jbw force-pushed the feature/ci/aw-contract-checks branch from 58205e0 to b98dbb7 Compare September 14, 2026 10:00
@kongche-jbw
kongche-jbw merged commit 8790f21 into agentic-os-org:main Sep 14, 2026
28 checks passed
@kongche-jbw
kongche-jbw deleted the feature/ci/aw-contract-checks branch September 14, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scope:ci ./.github/ scope:documentation ./docs/|./*.md|./NOTICE

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants