Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
d6d266e
chore: pin stock OpenCode 2.0.23
bateau84 Oct 6, 2026
f9dc9bf
docs: define trusted-checkout evaluation model
bateau84 Oct 6, 2026
97589bb
docs: replace TRUST-001 with trusted-checkout evidence contract
bateau84 Oct 6, 2026
b6e6f85
test: expect stock OpenCode 2.0.23
bateau84 Oct 6, 2026
bda7264
docs: retain stock 2.0.23 observation findings
bateau84 Oct 6, 2026
618b2e9
docs: link retained stock observation assessment
bateau84 Oct 6, 2026
dc48cdf
refactor: integrate trusted runtime evidence
bateau84 Oct 6, 2026
4f79b0d
fix: reconcile runtime evidence accounting
bateau84 Oct 6, 2026
7c6cb3e
fix: load acceptance contract from repo root
bateau84 Oct 6, 2026
d765fec
fix: import sys in acceptance driver
bateau84 Oct 6, 2026
d109f46
fix: read v1 actor field in acceptance gate
bateau84 Oct 6, 2026
a3c93da
fix: avoid single Code Mode fixture deadlock
bateau84 Oct 6, 2026
2f96dab
fix: sanitize Code Mode error identity
bateau84 Oct 6, 2026
39dbd4f
fix: reject reversed runtime terminals
bateau84 Oct 6, 2026
1ebf260
test: cover ambiguous runtime sequencing
bateau84 Oct 6, 2026
d417184
fix: normalize duplicate observation sequences
bateau84 Oct 6, 2026
b10c52d
refactor: tighten integrated runtime evidence authority (#52)
bateau84 Oct 6, 2026
b10c8e9
fix: observe outer Code Mode execute evidence (#54)
bateau84 Oct 6, 2026
e3eb017
fix: close final runtime evidence blockers (#55)
bateau84 Oct 6, 2026
a67c931
docs: close runtime-evidence product-readiness contract gap (#56)
bateau84 Oct 6, 2026
2547810
docs: document complete invocation interface (#57)
bateau84 Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 10 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,14 +16,14 @@ jobs:

- name: Python checks
run: |
python3 -m py_compile runner/cli.py container/invoke.py
python3 -m py_compile runner/cli.py container/invoke.py container/evidence_safety.py container/native_observer.py container/runtime_evidence.py tests/integration/run_code_mode_observer_probe.py tests/integration/run_runtime_evidence_acceptance.py
python3 -m unittest discover -s tests -p 'test_*.py'

- name: Build fake Copilot transport for action smoke test
run: |
cat > /tmp/Containerfile.fake-copilot <<'EOF'
FROM alpine:3.22
ENTRYPOINT ["/bin/sh", "-c", "if [ -z \"$GITHUB_TOKEN\" ] || [ -n \"$COPILOT_GITHUB_TOKEN\" ] || [ -n \"$GH_TOKEN\" ] || [ \"$EVAL_REASONING\" != \"medium\" ]; then exit 42; fi; printf '%s\\n' '{\"schema\":\"opencode-eval-runner/v1\",\"transport\":\"github-copilot-cli\",\"model\":\"fake\",\"reasoning\":\"medium\",\"reasoning_source\":\"explicit\",\"agent\":\"eval-runner\",\"skill\":null,\"exit_code\":0,\"session_id\":null,\"text\":\"fake action smoke\",\"tools\":[],\"actions\":[],\"skills_loaded\":[],\"stderr\":\"\",\"stdout\":\"\"}'"]
ENTRYPOINT ["/bin/sh", "-c", "if [ -z \"$GITHUB_TOKEN\" ] || [ -n \"$COPILOT_GITHUB_TOKEN\" ] || [ -n \"$GH_TOKEN\" ] || [ \"$EVAL_REASONING\" != \"medium\" ]; then exit 42; fi; printf '%s\\n' '{\"schema\":\"opencode-eval-runner/v1\",\"transport\":\"github-copilot-cli\",\"model\":\"fake\",\"reasoning\":\"medium\",\"reasoning_source\":\"explicit\",\"agent\":\"eval-runner\",\"skill\":null,\"exit_code\":0,\"session_id\":null,\"text\":\"fake action smoke\",\"tools\":[],\"actions\":[],\"skills_loaded\":[],\"stderr\":\"\",\"stdout\":\"\",\"runtime_evidence\":{\"schema\":\"opencode-eval-runner/runtime-evidence/v1\",\"status\":\"unsupported\",\"evidence_eligible\":false,\"observations\":[],\"coverage\":{\"observation_closed\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"process_state\":\"unsupported\",\"starts\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"missing_terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"observer_failures\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"callback_failures\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"losses\":[],\"unsupported\":[\"observer_not_implemented\"],\"boundaries\":{\"native\":{\"status\":\"unsupported\",\"evidence_eligible\":false,\"starts\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"missing_terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"issues\":[\"observer_not_implemented\"]},\"code_mode_execution\":{\"status\":\"unsupported\",\"evidence_eligible\":false,\"starts\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"missing_terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"issues\":[\"observer_not_implemented\"]},\"code_mode_finality\":{\"status\":\"unsupported\",\"evidence_eligible\":false,\"starts\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"missing_terminals\":{\"state\":\"unsupported\",\"reason\":\"observer_not_implemented\"},\"issues\":[\"observer_not_implemented\"]}}}}}'"]
EOF
docker build -f /tmp/Containerfile.fake-copilot -t opencode-eval-runner:fake-copilot /tmp
printf '%s\n' 'action smoke prompt' > /tmp/action-smoke-prompt.txt
Expand Down Expand Up @@ -64,11 +64,19 @@ jobs:
assert result["reasoning"] == "medium"
assert result["reasoning_source"] == "explicit"
assert result["text"] == "fake action smoke"
assert result["runtime_evidence"]["status"] == "unsupported"
assert result["runtime_evidence"]["evidence_eligible"] is False
PY

- name: Build OpenCode transport image
run: docker build -f Containerfile --target opencode -t opencode-eval-runner:opencode-test .

- name: Probe stock Code Mode inner observation boundary
run: |
python3 tests/integration/run_code_mode_observer_probe.py \
--image opencode-eval-runner:opencode-test \
--output /tmp/code-mode-observer-probe

- name: Build Copilot transport image
run: docker build -f Containerfile --target copilot -t opencode-eval-runner:copilot-test .

Expand Down
53 changes: 53 additions & 0 deletions .github/workflows/native-observer-integration.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
name: Stock native observer integration

on:
pull_request:
paths:
- 'container/invoke.py'
- 'container/native_observer.py'
- 'container/native_observer.ts'
- 'tests/integration/native_observer_probe.ts'
- 'tests/integration/run_native_observer_probe.py'
- 'tests/test_native_observer.py'
- '.github/workflows/native-observer-integration.yml'

permissions:
contents: read

jobs:
stock-native-observer:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false

- name: Verify probe syntax
run: python3 -m py_compile container/native_observer.py tests/integration/run_native_observer_probe.py

- name: Build runner with stock OpenCode 2.0.23
run: docker build -f Containerfile --target opencode -t opencode-eval-runner:native-observer-probe .

- name: Run provider-free native observer probe
run: |
docker run --rm \
--network none \
--tmpfs /tmp:rw,exec,nosuid,nodev,size=1g,mode=1777 \
--tmpfs /workspace:rw,nosuid,nodev,size=64m,mode=1777 \
--volume "$PWD:/probe-repo:ro" \
--entrypoint python3 \
opencode-eval-runner:native-observer-probe \
/probe-repo/tests/integration/run_native_observer_probe.py \
> native-observer-probe.json
cat native-observer-probe.json

- name: Preserve probe report
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: native-observer-${{ github.event.pull_request.head.sha }}
path: native-observer-probe.json
if-no-files-found: warn
retention-days: 14
47 changes: 47 additions & 0 deletions .github/workflows/runtime-evidence-acceptance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: Provider-free runtime evidence acceptance

on:
pull_request:
paths:
- 'Containerfile'
- 'container/**'
- 'runner/**'
- 'tests/integration/**'
- 'tests/test_runtime_evidence_acceptance.py'
- '.github/workflows/runtime-evidence-acceptance.yml'
workflow_dispatch:

permissions:
contents: read

jobs:
provider-free-acceptance:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
persist-credentials: false

- name: Check acceptance driver
run: |
python3 -m py_compile tests/integration/run_runtime_evidence_acceptance.py
python3 -m unittest discover -s tests -p 'test_runtime_evidence_acceptance.py' -v

- name: Build stock OpenCode 2.0.23 runner image
run: docker build -f Containerfile --target opencode -t opencode-eval-runner:runtime-evidence-acceptance .

- name: Run provider-free acceptance gate
run: |
python3 tests/integration/run_runtime_evidence_acceptance.py \
--image opencode-eval-runner:runtime-evidence-acceptance \
--output runtime-evidence-acceptance

- name: Preserve sanitized acceptance report
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: runtime-evidence-acceptance-${{ github.event.pull_request.head.sha || github.sha }}
path: runtime-evidence-acceptance/
if-no-files-found: error
retention-days: 14
2 changes: 1 addition & 1 deletion Containerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
FROM node:24-bookworm-slim@sha256:0e0ff40c39bc087845bfb27465a0df4ea419520094bc35842ff83dd8cbe6f9b6 AS opencode-builder
ARG OPENCODE_VERSION=2.0.18
ARG OPENCODE_VERSION=2.0.23
RUN npm install --global "@opencode/cli@${OPENCODE_VERSION}" \
&& resolved="$(readlink -f "$(command -v opencode)")" \
&& test -x "$resolved" \
Expand Down
Loading
Loading