From aa453dc09a434b8f0f6185593359db68198b6b7a Mon Sep 17 00:00:00 2001 From: chaoz23 Date: Fri, 21 Aug 2026 14:46:42 -0700 Subject: [PATCH] ci: run the family conformance gate on every PR Nothing executed SKILL.md's claims. The clause-7 acceptance test checks that an agent can *invoke* this tool from the file; it does not check that what the file promises is *true*. Every family member passed the former while failing the latter, which is how this repo's exit-contract defects shipped. Runs srdcheck's canonical gate against this repo and fails if SKILL.md and the CLI disagree. Currently waived, each naming the issue that tracks it: - MISSING_PIPE -> chaoz23/dmcheck#14 - HONEST_LANE_OVERLOAD -> chaoz23/dmcheck#15 The gate and its waiver list are read from srdcheck rather than copied, per FAMILY.md's pin-by-link rule. srdcheck is pinned by SHA, matching the existing cross-repo convention here: a new rule landing in srdcheck must not turn this repo's CI red on an unrelated PR. Blocking, so a NEW divergence fails. A waiver that stops firing also fails, so fixing any of the above requires shrinking the waiver list rather than leaving stale permission behind. Co-Authored-By: Claude Opus 5 --- .github/workflows/ci.yml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index fb980c0..d5b4607 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,6 +5,39 @@ permissions: contents: read jobs: + family-conformance: + # Executes this repo's documented exit contract against its real CLI and + # fails if SKILL.md's claims and the tool's behaviour disagree. The clause-7 + # acceptance test checks an agent can *invoke* this tool; this checks that + # what SKILL.md promises is *true*. Every family member passed the former + # while failing the latter. + # + # The gate and its waiver list are canonical in srdcheck and read from there + # rather than copied, per FAMILY.md's pin-by-link rule. srdcheck is pinned by + # SHA, matching the existing cross-repo convention: a new rule landing in + # srdcheck must not turn this repo's CI red on an unrelated PR. + runs-on: ubuntu-latest + steps: + - name: Check out this repo + uses: actions/checkout@v5 + with: + path: candidate + - name: Check out pinned srdcheck (canonical gate + baseline) + uses: actions/checkout@v5 + with: + repository: chaoz23/srdcheck + ref: 27dee98cb7cb86e6ef86e34568d08954179f9a82 + path: srdcheck-src + - uses: actions/setup-python@v6 + with: + python-version: "3.12" + - name: Install so the gate probes the real console script + run: pip install -e ./candidate + - name: SKILL.md claims match the CLI + run: | + python srdcheck-src/scripts/family_conformance.py candidate \ + --baseline srdcheck-src/family-conformance-baseline.json + test: runs-on: ubuntu-latest strategy: