9897df04b2
The prior VERIFY stage was diff-scoped: it checked the phase diff only
and never re-ran underlying platform capability. This structural defect
(D-091) let 8 NFR-patch phases (v1.9.1-v1.9.8, deck rework) pass VERIFY
while the platform they described decayed underneath.
Phase 52 remediation:
- core/regression_verify.py: regression-class VERIFY with 10 seeded
local-tier capability checks (CAP-001..CAP-010). Tags each
Verified/Decayed/Broken; fails closed on any non-Verified.
- scripts/run_regression.sh: shell wrapper; writes
.ciagent/REGRESSION_REPORT.{md,json}; exits non-zero on decay.
- tests/test_verify_regression_mode.py: 11 tests (8 fast + 3 slow).
Confirms the gate catches decay (fails closed) and that regression
mode is additive (diff-scoped VERIFY behavior preserved).
- pyproject.toml: slow marker registered; run_ci.sh excludes slow
tests to avoid recursion.
Verified: 502 fast tests pass (was 493 at v1.9; +9 new). 3 slow
integration tests pass. run_regression.sh reports all 10 seeded
local-tier capabilities Verified against current code. The
decay-surfacing test injects a broken cloud-backed check and confirms
the run tags it Broken and fails closed.
Cloud-backed capability re-verification (live ECS, DynamoDB writes,
Lambda invocation) lands in Phase 54 (D-093).
---ci---
project: acdl
phase: 52
milestone: v1.10
status: verify
requirements:
covered: [REQ-112]
partial: []
decisions: [D-091]
regression:
- { capability: CAP-001, status: Verified }
- { capability: CAP-002, status: Verified }
- { capability: CAP-003, status: Verified }
- { capability: CAP-004, status: Verified }
- { capability: CAP-005, status: Verified }
- { capability: CAP-006, status: Verified }
- { capability: CAP-007, status: Verified }
- { capability: CAP-008, status: Verified }
- { capability: CAP-009, status: Verified }
- { capability: CAP-010, status: Verified }
---/ci---
70 lines
2.1 KiB
Bash
Executable File
70 lines
2.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# scripts/run_ci.sh - reproduce the CI pipeline locally.
|
|
#
|
|
# Mirrors the central pipeline contract (pipelines/ci.yaml) which both
|
|
# .gitea/workflows/ci.yml (Gitea Actions, dev) and
|
|
# .github/workflows/ci.yml (GitHub Actions, production) implement.
|
|
#
|
|
# Runs the same three stages in the same order:
|
|
# 1. lint — py_compile all Python files
|
|
# 2. test — pytest test suite (offline)
|
|
# 3. check-only — run_platform.sh --check-only (offline, no AWS)
|
|
#
|
|
# Fails on the first stage that errors. Exits 0 with "CI PIPELINE OK"
|
|
# when all stages pass.
|
|
#
|
|
# Usage:
|
|
# bash scripts/run_ci.sh # run all stages
|
|
# bash scripts/run_ci.sh --quiet # suppress per-stage banners
|
|
set -euo pipefail
|
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
cd "$ROOT"
|
|
|
|
QUIET=0
|
|
for arg in "$@"; do
|
|
case "$arg" in
|
|
--quiet) QUIET=1 ;;
|
|
*) echo "FAIL: unknown argument: $arg" >&2; exit 1 ;;
|
|
esac
|
|
done
|
|
|
|
banner() {
|
|
[ "$QUIET" = "1" ] || echo ""
|
|
echo "── $1 ──"
|
|
[ "$QUIET" = "1" ] || echo ""
|
|
}
|
|
|
|
fail() { echo "FAIL: $*" >&2; exit 1; }
|
|
|
|
echo "=== ACDL CI Pipeline (local reproduction) ==="
|
|
echo "contract: pipelines/ci.yaml (3 stages)"
|
|
echo ""
|
|
|
|
banner "Stage 1/3: lint (py_compile)"
|
|
python3 -m py_compile \
|
|
core/confidence_signal.py \
|
|
core/outbox_writer.py \
|
|
core/output_publisher.py \
|
|
core/contract_resolver.py \
|
|
core/lambda/contract_ingestor.py \
|
|
adapters/terraform/adapter.py \
|
|
adapters/terraform/policy/checkov_adapter.py \
|
|
adapters/terraform/policy/custom_rules/acdl_tagging.py \
|
|
adapters/wiz/wiz_adapter.py \
|
|
adapters/kyverno/kyverno_adapter.py \
|
|
scripts/push_consumer_image.py \
|
|
|| fail "lint: py_compile failed"
|
|
echo "lint: OK"
|
|
|
|
banner "Stage 2/3: test (pytest)"
|
|
python3 -m pytest tests/ -v --tb=short -m "not slow" || fail "test: pytest failed"
|
|
echo "test: OK"
|
|
|
|
banner "Stage 3/3: check-only (run_platform.sh --check-only)"
|
|
bash scripts/run_platform.sh --check-only || fail "check-only: run_platform.sh failed"
|
|
echo "check-only: OK"
|
|
|
|
echo ""
|
|
echo "=== CI PIPELINE OK ==="
|
|
echo "3 stages passed: lint, test, check-only"
|
|
exit 0 |