diff --git a/.github/workflows/sovereign-reviewer.yml b/.github/workflows/sovereign-reviewer.yml new file mode 100644 index 0000000..23d1511 --- /dev/null +++ b/.github/workflows/sovereign-reviewer.yml @@ -0,0 +1,156 @@ +name: Sovereign Gatekeeper & Automated Reviewer + +on: + pull_request_target: + types: [opened, synchronize] + issues: + types: [opened] + issue_comment: + types: [created] + +permissions: + pull-requests: write + issues: write + contents: read + +jobs: + pr-reviewer: + if: github.event_name == 'pull_request_target' + runs-on: ubuntu-latest + steps: + - name: Checkout Repository + uses: actions/checkout@v4 + + - name: Checkout Sovereign Inquisitor Core + uses: actions/checkout@v4 + with: + repository: aien-dev/aien-sovereign-core + path: sovereign-core + + - name: Build Sovereign Inquisitor + run: cargo build --release --manifest-path sovereign-core/Cargo.toml -p spark-inquisitor + + - name: Verify Cargo Test Suite + run: cargo test --verbose + + - name: Fetch PR Diff + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + gh pr diff "${{ github.event.pull_request.number }}" > pr.diff + + - name: Execute Sovereign Code Review + id: review + continue-on-error: true + run: | + ./sovereign-core/target/release/spark-inquisitor review --author "${{ github.event.pull_request.user.login }}" --pr "${{ github.event.pull_request.number }}" --title "${{ github.event.pull_request.title }}" --diff pr.diff --output comment.md --output-labels labels.txt + + - name: Post PR Review Comment + if: always() && steps.review.conclusion != 'skipped' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + if [ -f comment.md ]; then + gh pr comment "${{ github.event.pull_request.number }}" --body-file comment.md + fi + + - name: Apply Review Labels + if: always() && steps.review.conclusion != 'skipped' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + if [ -f labels.txt ]; then + LABELS=$(cat labels.txt) + if [ -n "$LABELS" ]; then + gh pr edit "${{ github.event.pull_request.number }}" --add-label "$LABELS" || true + fi + fi + + - name: Verify Audit Invariants + run: | + if [ "${{ steps.review.outcome }}" != "success" ]; then + echo "Constitutional diff audit detected violations. See PR comment for details." + exit 1 + fi + + issue-triage: + if: github.event_name == 'issues' && github.event.action == 'opened' + runs-on: ubuntu-latest + steps: + - name: Checkout Sovereign Inquisitor Core + uses: actions/checkout@v4 + with: + repository: aien-dev/aien-sovereign-core + + - name: Build Sovereign Inquisitor + run: cargo build --release -p spark-inquisitor + + - name: Extract Issue Payload Safely + run: | + jq -r '.issue.body // ""' "$GITHUB_EVENT_PATH" > issue_body.txt + + - name: Execute Sovereign Issue Triage + run: | + ./target/release/spark-inquisitor triage-issue --author "${{ github.event.issue.user.login }}" --issue "${{ github.event.issue.number }}" --title "${{ github.event.issue.title }}" --body issue_body.txt --output-comment issue_reply.md --output-labels issue_labels.txt + + - name: Post Issue Triage Comment + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + if [ -f issue_reply.md ]; then + gh issue comment "${{ github.event.issue.number }}" --body-file issue_reply.md + fi + + - name: Apply Issue Labels + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + if [ -f issue_labels.txt ]; then + LABELS=$(cat issue_labels.txt) + if [ -n "$LABELS" ]; then + gh issue edit "${{ github.event.issue.number }}" --add-label "$LABELS" || true + fi + fi + + comment-evaluator: + if: github.event_name == 'issue_comment' && github.event.action == 'created' && github.event.issue.pull_request != null && github.event.comment.user.login != 'github-actions[bot]' && github.event.comment.user.login != 'aien-dev' + runs-on: ubuntu-latest + steps: + - name: Checkout Sovereign Inquisitor Core + uses: actions/checkout@v4 + with: + repository: aien-dev/aien-sovereign-core + + - name: Build Sovereign Inquisitor + run: cargo build --release -p spark-inquisitor + + - name: Extract Comment Payload Safely + run: | + jq -r '.comment.body // ""' "$GITHUB_EVENT_PATH" > comment_body.txt + + - name: Evaluate Contributor Testimony + id: eval + continue-on-error: true + run: | + ./target/release/spark-inquisitor evaluate --testimony comment_body.txt --author "${{ github.event.comment.user.login }}" --output-comment verdict.md --output-labels verdict_labels.txt + + - name: Post Verdict Comment + if: always() && steps.eval.conclusion != 'skipped' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + if [ -f verdict.md ]; then + gh pr comment "${{ github.event.issue.number }}" --body-file verdict.md + fi + + - name: Update PR Labels + if: always() && steps.eval.conclusion != 'skipped' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + if [ -f verdict_labels.txt ]; then + LABELS=$(cat verdict_labels.txt) + if [ -n "$LABELS" ]; then + gh pr edit "${{ github.event.issue.number }}" --add-label "$LABELS" || true + fi + fi