Files
WeHub Mirror abf0e694a2
Hetzner Agent E2E / Provision + deploy + healthcheck (push) Has been cancelled
Hetzner Agent E2E / Teardown (push) Has been cancelled
Scenario PR E2E / Classify changed paths (push) Has been cancelled
Scenario PR E2E / Zero-Key unit + UI coverage (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser core (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser view lifecycle (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser all-pages (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser feature interactions (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser cloud keyless (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser ratcheted (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser auto-discovered specs (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser dashboard device matrix (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser Pixel-7 real-touch lane (push) Has been cancelled
Scenario PR E2E / Zero-Key app browser WebKit lane (push) Has been cancelled
Scenario PR E2E / Zero-Key accounts UI e2e (real API + pool + disk) (push) Has been cancelled
Scenario PR E2E / Zero-Key full-walkthrough (mock lane) (push) Has been cancelled
Scenario PR E2E / Zero-Key app diagnostics (push) Has been cancelled
Scenario PR E2E / Zero-Key scenario runner E2E (push) Has been cancelled
Scenario PR E2E / Zero-Key Deterministic E2E (push) Has been cancelled
Docker CI Smoke / Classify changed paths (push) Has been cancelled
Docker CI Smoke / Build production Docker image (+ smoke boot) (push) Has been cancelled
Build libelizainference (Android, FFI) / prepare-matrix (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Orchestrator multi-account / multi-account selection e2e (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Tests / Classify changed paths (push) Has been cancelled
UI Extended Fixture E2E / fixture-e2e (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
CUDA Coverage Continuity / Fail-closed manifest contracts (push) Has been cancelled
CUDA Coverage Continuity / Exact-head CUDA fixtures + runtime graph (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Homepage / build-and-deploy (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
Tests / Remote Capability Provider Live E2E (push) Has been cancelled
Training Stack / CPU smoke (lint + import) (push) Has been cancelled
Training Stack / GPU build (QJL nvcc + Triton JIT) (push) Has been cancelled
UI Core Fixture E2E / ui-core-fixture-e2e (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/core typecheck bun run --cwd packages/shared typecheck bun run --cwd packages/cloud/shared typecheck bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-coding-tools build node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=1 node packages/scripts/run-python.mjs --version node packages… (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Tests / Test-runner vacuous-green guard (push) Has been cancelled
Tests / Server Tests (push) Has been cancelled
Tests / Client Tests (push) Has been cancelled
Tests / Plugin Tests (1/4) (push) Has been cancelled
Tests / Plugin Tests (2/4) (push) Has been cancelled
Tests / Plugin Tests (3/4) (push) Has been cancelled
Tests / Plugin Tests (4/4) (push) Has been cancelled
Tests / Plugin Tests (push) Has been cancelled
Tests / Integration Lane (personal-assistant) (push) Has been cancelled
Tests / Electrobun Desktop Contract (push) Has been cancelled
Tests / Zero-Key unit + UI coverage (push) Has been cancelled
Tests / Zero-Key app browser (push) Has been cancelled
Tests / Zero-Key diagnostics (push) Has been cancelled
Tests / Zero-Key scenario runner (push) Has been cancelled
Tests / Zero-Key harness E2E (push) Has been cancelled
Tests / Zero-Key Deterministic E2E (push) Has been cancelled
Build libelizainference (Android, FFI) / ${{ matrix.abi }} (push) Has been cancelled
Tests / Cloud Live E2E (Eliza Cloud) (push) Has been cancelled
Tests / Remote Capability GitHub Live Artifact Validator (push) Has been cancelled
Tests / Script Tests (Linux) (push) Has been cancelled
Tests / Merge Queue Quality Gate (push) Has been cancelled
Tests / ci-ok (push) Has been cancelled
WeHub snapshot of 9298cb46af86e1bd3a40a60e135ea855d70f229a
2026-08-07 16:49:07 +08:00

242 lines
7.7 KiB
JavaScript

#!/usr/bin/env node
/**
* Commit-drift check for the develop→main certification gate (#14547). A
* certification signs one exact commit, but a promotion branch may pick up
* non-source commits after signing (README and docs touch-ups). This
* helper decides whether the PR head is still covered by the certification:
* pass iff head == cert.commit, or cert.commit is an ancestor of head and
* every path in `git diff cert.commit..head` matches the docs-only allowlist.
*
* The allowlist is deliberately narrow: docs/**, packages/docs/**, any *.md,
* and the certification artifacts. GitHub workflow/policy/config drift must
* force re-certification, never ride the docs allowlist.
*
* Consumed by .github/workflows/certification-verify.yml; it reads the
* certification only to extract `commit` — all cryptographic and schema
* verification stays in `packages/evidence certify:verify`.
*/
import { execFileSync } from "node:child_process";
import { appendFileSync, readFileSync, writeFileSync } from "node:fs";
import { pathToFileURL } from "node:url";
/** Paths that may change after certification without re-certifying. */
export function isAllowedDriftPath(filePath) {
// Trust anchor and gate plumbing: never allowed as post-certification drift.
if (filePath.startsWith(".github/certification/")) return false;
if (filePath === ".github/workflows/certification-verify.yml") return false;
if (filePath.startsWith("scripts/certification/")) return false;
// The certification artifacts themselves necessarily land AFTER the
// certified commit (the signature covers the commit sha, so the commit that
// adds the file can never be the signed one). Their integrity is enforced
// cryptographically — signature over the payload, bundleSha over the bundle
// — not by the drift rule, so allowing them here weakens nothing.
if (filePath === "certification.json") return true;
if (filePath.startsWith("evidence/bundle/")) return true;
if (filePath.startsWith("docs/")) return true;
if (filePath.startsWith("packages/docs/")) return true;
if (filePath.endsWith(".md")) return true;
return false;
}
const SHA_RE = /^[0-9a-f]{40}$/;
function git(repoDir, args) {
return execFileSync("git", args, {
cwd: repoDir,
encoding: "utf8",
stdio: ["ignore", "pipe", "pipe"],
});
}
/** Read `commit` out of a certification.json without validating anything else. */
export function readCertCommit(certPath) {
let raw;
try {
raw = readFileSync(certPath, "utf8");
} catch (error) {
return { error: `certification unreadable: ${error.message}` };
}
let parsed;
try {
parsed = JSON.parse(raw);
} catch (error) {
return { error: `certification is not valid JSON: ${error.message}` };
}
const commit = parsed?.commit;
if (typeof commit !== "string" || !SHA_RE.test(commit)) {
return {
error: `certification \`commit\` is not a full 40-hex sha: ${JSON.stringify(commit)}`,
};
}
return { commit };
}
/**
* Evaluate drift between the certified commit and the PR head.
* Result shape: { result, certCommit, headCommit, driftPaths, disallowedPaths, detail }
* where result is one of:
* match | allowed-drift → covered by the certification
* cert-commit-unknown | not-ancestor | disallowed-drift → not covered
*/
export function evaluateCommitDrift({ certCommit, headCommit, repoDir }) {
const base = {
certCommit,
headCommit,
driftPaths: [],
disallowedPaths: [],
};
if (certCommit === headCommit) {
return {
...base,
result: "match",
detail: "certification commit equals the PR head",
};
}
try {
git(repoDir, ["cat-file", "-e", `${certCommit}^{commit}`]);
} catch {
// A cert for a commit this repository has never seen (or outside the
// fetched history window) cannot cover this head. Shallow clones can
// produce this for very old certs — that fails safe: stale certs must
// re-certify anyway.
return {
...base,
result: "cert-commit-unknown",
detail: `certified commit ${certCommit} is not present in this repository's fetched history`,
};
}
let isAncestor = true;
try {
git(repoDir, ["merge-base", "--is-ancestor", certCommit, headCommit]);
} catch (error) {
if (error.status === 1) {
isAncestor = false;
} else {
throw error;
}
}
if (!isAncestor) {
return {
...base,
result: "not-ancestor",
detail: `certified commit ${certCommit} is not an ancestor of head ${headCommit} — the certified tree was never part of this branch`,
};
}
const driftPaths = git(repoDir, [
"diff",
"--name-only",
"-z",
certCommit,
headCommit,
])
.split("\0")
.filter((entry) => entry.length > 0);
const disallowedPaths = driftPaths.filter(
(entry) => !isAllowedDriftPath(entry),
);
if (disallowedPaths.length > 0) {
return {
...base,
driftPaths,
disallowedPaths,
result: "disallowed-drift",
detail: `${disallowedPaths.length} of ${driftPaths.length} drifted path(s) fall outside the docs-only allowlist — re-certify at the current head`,
};
}
return {
...base,
driftPaths,
result: "allowed-drift",
detail: `${driftPaths.length} drifted path(s), all inside the docs-only allowlist`,
};
}
function parseArgs(argv) {
const args = { repoDir: process.cwd() };
for (let index = 0; index < argv.length; index += 1) {
const flag = argv[index];
const value = () => {
const next = argv[index + 1];
if (next === undefined) {
console.error(`${flag} requires a value`);
process.exit(2);
}
index += 1;
return next;
};
if (flag === "--cert") args.certPath = value();
else if (flag === "--head") args.headCommit = value();
else if (flag === "--repo") args.repoDir = value();
else if (flag === "--json-out") args.jsonOut = value();
else if (flag === "--github-output") args.githubOutput = value();
else {
console.error(`unknown argument: ${flag}`);
process.exit(2);
}
}
if (args.certPath === undefined || args.headCommit === undefined) {
console.error(
"Usage: check-commit-drift.mjs --cert <certification.json> --head <sha> [--repo <dir>] [--json-out <file>] [--github-output <file>]",
);
process.exit(2);
}
if (!SHA_RE.test(args.headCommit)) {
console.error(`--head must be a full 40-hex sha, got: ${args.headCommit}`);
process.exit(2);
}
return args;
}
function main() {
const args = parseArgs(process.argv.slice(2));
const certRead = readCertCommit(args.certPath);
const outcome =
"error" in certRead
? {
result: "cert-unreadable",
certCommit: null,
headCommit: args.headCommit,
driftPaths: [],
disallowedPaths: [],
detail: certRead.error,
}
: evaluateCommitDrift({
certCommit: certRead.commit,
headCommit: args.headCommit,
repoDir: args.repoDir,
});
if (args.jsonOut !== undefined) {
writeFileSync(args.jsonOut, `${JSON.stringify(outcome, null, 2)}\n`);
}
if (args.githubOutput !== undefined) {
appendFileSync(
args.githubOutput,
`cert-commit=${outcome.certCommit ?? ""}\nresult=${outcome.result}\n`,
);
}
const ok = outcome.result === "match" || outcome.result === "allowed-drift";
console.log(`[check-commit-drift] ${outcome.result}: ${outcome.detail}`);
for (const entry of outcome.driftPaths) {
const marker = outcome.disallowedPaths.includes(entry)
? "DISALLOWED"
: "allowed ";
console.log(` ${marker} ${entry}`);
}
process.exit(ok ? 0 : 1);
}
if (
process.argv[1] &&
import.meta.url === pathToFileURL(process.argv[1]).href
) {
main();
}