Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
root = true

[*]
charset = utf-8
end_of_line = lf
insert_final_newline = true
trim_trailing_whitespace = true
indent_style = space
indent_size = 2

[*.md]
trim_trailing_whitespace = false
17 changes: 17 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Normalize line endings: LF in the repository, LF on checkout.
* text=auto eol=lf

# Sources that must stay byte-stable (content hashes depend on them)
*.md text eol=lf
*.jsonl text eol=lf
*.json text eol=lf
*.toml text eol=lf
*.yml text eol=lf

# Generated artifacts: hide from diffs and language stats
PHILOSOPHY.lock.json linguist-generated=true

# Binary assets
*.png binary
*.jpg binary
*.gif binary
141 changes: 141 additions & 0 deletions .github/workflows/agent-e2e.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,141 @@
name: Actual agent validation

on:
workflow_dispatch:
inputs:
candidate_run_id:
description: Successful trusted candidate workflow run for this exact source
required: true
type: string
manifest_sha256:
description: Approved canonical release manifest digest
required: true
type: string
matrix:
description: Validation scope
required: true
default: smoke
type: choice
options: [smoke, full]
probe:
description: Authentication/process probe only (never release evidence)
required: true
default: true
type: boolean

permissions:
contents: read
actions: read

concurrency:
group: agent-validation-${{ github.ref }}-${{ inputs.matrix }}-${{ inputs.probe }}
cancel-in-progress: false

jobs:
actual-agents:
if: github.repository == 'shendeguize/AgentOrganon' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release/1.0.0')
environment: agent-validation
timeout-minutes: 150
strategy:
fail-fast: false
matrix:
agent: [codex, claude, cursor, copilot, gemini, opencode]
os: ${{ fromJSON(inputs.matrix == 'full' && '["ubuntu-24.04"]' || '["ubuntu-24.04", "macos-15", "windows-2025"]') }}
runs-on: ${{ matrix.os }}
env:
RELEASE_MANIFEST_SHA256: ${{ inputs.manifest_sha256 }}
CANDIDATE_RUN_ID: ${{ inputs.candidate_run_id }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ github.sha }}
persist-credentials: false
submodules: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Verify trusted source workflow before downloading artifacts
id: candidate
shell: bash
env:
GITHUB_TOKEN: ${{ github.token }}
run: node scripts/agents/verify-candidate.mjs --run-id "$CANDIDATE_RUN_ID"
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
with:
artifact-ids: ${{ steps.candidate.outputs.candidate_artifact_id }}
merge-multiple: true
run-id: ${{ inputs.candidate_run_id }}
github-token: ${{ github.token }}
path: candidate
- name: Verify approved manifest and clean source identity
shell: bash
env:
GITHUB_TOKEN: ${{ github.token }}
SELECTED_ATTEMPT: ${{ steps.candidate.outputs.candidate_run_attempt }}
SELECTED_ARTIFACT: ${{ steps.candidate.outputs.candidate_artifact_id }}
run: node scripts/agents/verify-candidate.mjs --run-id "$CANDIDATE_RUN_ID" --attempt "$SELECTED_ATTEMPT" --artifact-id "$SELECTED_ARTIFACT" --manifest candidate/release-manifest.json
- name: Set temporary agent tools directory
shell: bash
run: node -e 'require("node:fs").appendFileSync(process.env.GITHUB_ENV,"ORGANON_AGENT_TOOLS="+require("node:path").join(process.env.RUNNER_TEMP,"organon-agent-tools")+"\n")'
- name: Install pinned CLI in temporary home without credentials
shell: bash
run: node scripts/agents/setup.mjs --agent "${{ matrix.agent }}"
- name: Actual codex invocation
if: matrix.agent == 'codex'
shell: bash
env:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
CODEX_MODEL: ${{ vars.CODEX_MODEL }}
run: node scripts/agents/run.mjs --agent codex --matrix "${{ inputs.matrix }}" ${{ inputs.probe && '--probe' || '' }} --package-dir candidate --manifest candidate/release-manifest.json --out "candidate/evidence/codex-${{ runner.os }}-${{ inputs.matrix }}" || test "$?" -eq 3
- name: Actual claude invocation
if: matrix.agent == 'claude'
shell: bash
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
ANTHROPIC_MODEL: ${{ vars.ANTHROPIC_MODEL }}
run: node scripts/agents/run.mjs --agent claude --matrix "${{ inputs.matrix }}" ${{ inputs.probe && '--probe' || '' }} --package-dir candidate --manifest candidate/release-manifest.json --out "candidate/evidence/claude-${{ runner.os }}-${{ inputs.matrix }}" || test "$?" -eq 3
- name: Actual cursor invocation
if: matrix.agent == 'cursor'
shell: bash
env:
CURSOR_API_KEY: ${{ secrets.CURSOR_API_KEY }}
CURSOR_MODEL: ${{ vars.CURSOR_MODEL }}
run: node scripts/agents/run.mjs --agent cursor --matrix "${{ inputs.matrix }}" ${{ inputs.probe && '--probe' || '' }} --package-dir candidate --manifest candidate/release-manifest.json --out "candidate/evidence/cursor-${{ runner.os }}-${{ inputs.matrix }}" || test "$?" -eq 3
- name: Actual copilot invocation
if: matrix.agent == 'copilot'
shell: bash
env:
COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
COPILOT_MODEL: ${{ vars.COPILOT_MODEL }}
run: node scripts/agents/run.mjs --agent copilot --matrix "${{ inputs.matrix }}" ${{ inputs.probe && '--probe' || '' }} --package-dir candidate --manifest candidate/release-manifest.json --out "candidate/evidence/copilot-${{ runner.os }}-${{ inputs.matrix }}" || test "$?" -eq 3
- name: Actual gemini invocation
if: matrix.agent == 'gemini'
shell: bash
env:
GEMINI_API_KEY: ${{ secrets.GEMINI_API_KEY }}
GEMINI_MODEL: ${{ vars.GEMINI_MODEL }}
run: node scripts/agents/run.mjs --agent gemini --matrix "${{ inputs.matrix }}" ${{ inputs.probe && '--probe' || '' }} --package-dir candidate --manifest candidate/release-manifest.json --out "candidate/evidence/gemini-${{ runner.os }}-${{ inputs.matrix }}" || test "$?" -eq 3
- name: Actual opencode invocation
if: matrix.agent == 'opencode'
shell: bash
env:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
OPENCODE_MODEL: ${{ vars.OPENCODE_MODEL }}
run: node scripts/agents/run.mjs --agent opencode --matrix "${{ inputs.matrix }}" ${{ inputs.probe && '--probe' || '' }} --package-dir candidate --manifest candidate/release-manifest.json --out "candidate/evidence/opencode-${{ runner.os }}-${{ inputs.matrix }}" || test "$?" -eq 3
# Exit 3 means completed invocation awaiting independent review, never release approval.
- name: Preserve raw captured evidence including failures and pending review
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: agent-${{ matrix.agent }}-${{ runner.os }}-${{ inputs.matrix }}-${{ github.run_attempt }}
path: candidate/evidence/
if-no-files-found: warn
retention-days: 30
- name: Preserve CLI installation diagnostics
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: agent-setup-${{ matrix.agent }}-${{ runner.os }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/organon-agent-tools/${{ matrix.agent }}/installation.json
if-no-files-found: warn
retention-days: 30
107 changes: 107 additions & 0 deletions .github/workflows/candidate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
name: Candidate validation
on:
workflow_dispatch:
inputs:
approved_rc_version:
description: For stable preparation only, exact previously approved RC
required: false
permissions:
contents: read
actions: read
concurrency:
group: candidate-${{ github.sha }}
cancel-in-progress: false
jobs:
build:
if: github.repository == 'shendeguize/AgentOrganon' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release/1.0.0')
runs-on: ubuntu-24.04
timeout-minutes: 45
outputs:
artifact_id: ${{ steps.packages.outputs.artifact-id }}
attempt: ${{ steps.identity.outputs.attempt }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ github.sha }}
submodules: recursive
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- run: npm ci --ignore-scripts
working-directory: OrganonCore/tools/site
- name: Install pinned Lean toolchain in temporary runner storage
env:
ELAN_HOME: ${{ runner.temp }}/organon-elan
run: |
mkdir -p "$RUNNER_TEMP/organon-elan-bootstrap"
curl --proto '=https' --tlsv1.2 --fail --location https://github.com/leanprover/elan/releases/download/v4.2.4/elan-x86_64-unknown-linux-gnu.tar.gz --output "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz"
echo "42b94d4244e8353142c456ec0e4ca6528fd898a6c604d4059f494e706e431f63 $RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" | sha256sum --check --strict
tar -xzf "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" -C "$RUNNER_TEMP/organon-elan-bootstrap"
"$RUNNER_TEMP/organon-elan-bootstrap/elan-init" -y --no-modify-path --default-toolchain leanprover/lean4:v4.33.1
"$ELAN_HOME/bin/elan" toolchain install leanprover/lean4:v4.33.1
echo "ELAN_HOME=$ELAN_HOME" >> "$GITHUB_ENV"
echo "$ELAN_HOME/bin" >> "$GITHUB_PATH"
- name: Source, declaration and reader gates
run: |
npm test
npm --prefix OrganonCore test
npm --prefix AdvisedOrganons test
node OrganonCore/skills/organon-core-leanify-prove/scripts/check.js OrganonCore/lean/philosophy --manuscript manuscript.json
node OrganonCore/skills/organon-core-leanify-prove/scripts/check.js AdvisedOrganons/SoftwareEngineering/lean/philosophy --manuscript manuscript.json
- name: Freeze identical channel packages and gate reports
env:
GH_TOKEN: ${{ github.token }}
GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }}
APPROVED_RC_VERSION: ${{ inputs.approved_rc_version }}
APPROVED_RC_MANIFEST_SHA256: ${{ vars.APPROVED_RC_MANIFEST_SHA256 }}
run: node scripts/release/candidate.mjs --out candidate
- id: identity
run: node -e 'require("node:fs").appendFileSync(process.env.GITHUB_OUTPUT,"attempt="+process.env.GITHUB_RUN_ATTEMPT+"\n")'
- id: packages
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: candidate-packages-${{ github.run_attempt }}
path: candidate/
if-no-files-found: error
retention-days: 30
- name: Display candidate identity for subsequent explicit validation
run: node --input-type=module -e 'import {digest,readJSON} from "./scripts/release/lib.mjs"; console.log(digest(readJSON("candidate/release-manifest.json")))'
install:
needs: build
strategy:
fail-fast: false
matrix:
os: [ubuntu-24.04, macos-15, windows-2025]
runs-on: ${{ matrix.os }}
timeout-minutes: 30
steps:
- run: |
git config --global core.autocrlf false
git config --global core.symlinks true
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ github.sha }}
submodules: recursive
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Require a complete rerun attempt
env:
BUILD_ATTEMPT: ${{ needs.build.outputs.attempt }}
run: node -e 'if(process.env.BUILD_ATTEMPT!==process.env.GITHUB_RUN_ATTEMPT) throw Error("Use Rerun all jobs; cannot borrow build artifacts from an older attempt")'
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
with:
artifact-ids: ${{ needs.build.outputs.artifact_id }}
merge-multiple: true
path: candidate
- name: Actual isolated install lifecycle
run: node scripts/release/install-matrix.mjs --manifest candidate/release-manifest.json --out candidate/reports/install-${{ runner.os }}.json
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
if: always()
with:
name: install-${{ runner.os }}-${{ github.run_attempt }}
path: candidate/reports/install-*
if-no-files-found: error
retention-days: 30
83 changes: 83 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
name: Repository
on:
pull_request:
push:
branches: [main, 'dev*', 'dev**/**', 'release*', 'release**/**', 'codex/**']
workflow_dispatch:
permissions:
contents: read
concurrency:
group: repository-${{ github.ref }}
cancel-in-progress: true
jobs:
install-platforms:
name: Installer / ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-24.04, macos-15, windows-2025]
runs-on: ${{ matrix.os }}
timeout-minutes: 30
steps:
- run: |
git config --global core.autocrlf false
git config --global core.symlinks true
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
submodules: recursive
persist-credentials: false
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Native isolated package and installer lifecycle
run: npm run test:install
verify:
needs: install-platforms
name: Repository / verify
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
path: product
persist-credentials: false
submodules: recursive
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: '22.23.2'
- name: Install pinned Lean toolchain in temporary runner storage
env:
ELAN_HOME: ${{ runner.temp }}/organon-elan
run: |
mkdir -p "$RUNNER_TEMP/organon-elan-bootstrap"
curl --proto '=https' --tlsv1.2 --fail --location https://github.com/leanprover/elan/releases/download/v4.2.4/elan-x86_64-unknown-linux-gnu.tar.gz --output "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz"
echo "42b94d4244e8353142c456ec0e4ca6528fd898a6c604d4059f494e706e431f63 $RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" | sha256sum --check --strict
tar -xzf "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" -C "$RUNNER_TEMP/organon-elan-bootstrap"
"$RUNNER_TEMP/organon-elan-bootstrap/elan-init" -y --no-modify-path --default-toolchain leanprover/lean4:v4.33.1
"$ELAN_HOME/bin/elan" toolchain install leanprover/lean4:v4.33.1
echo "ELAN_HOME=$ELAN_HOME" >> "$GITHUB_ENV"
echo "$ELAN_HOME/bin" >> "$GITHUB_PATH"
- name: Source tests and human-document links
working-directory: product
env:
ORGANON_WORKSPACE_ROOT: ${{ github.workspace }}/product
ORGANON_CORE_ROOT: ${{ github.workspace }}/product/OrganonCore
run: |
npm test
npm run check:content
- name: Install locked site build dependencies
working-directory: product/OrganonCore/tools/site
run: npm ci --ignore-scripts
- name: Build and validate released-site paths
working-directory: product
env:
ORGANON_CORE_ROOT: ${{ github.workspace }}/product/OrganonCore
run: npm run check:site
- name: Check current Lean evidence and four reader editions
run: node product/OrganonCore/skills/organon-core-leanify-prove/scripts/check.js product/OrganonCore/lean/philosophy --manuscript manuscript.json
- name: Keep development site preview
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: development-site-AgentOrganon-${{ github.run_attempt }}
path: product/dist/site/
if-no-files-found: error
Loading
Loading