Research-Stack/scripts/math-first/test_validate_deepseek_receipts.py
Devin AI c946319be1 Add math-first tooling: receipt schema, claims registry, pre-commit, CI, MCP
Adds automated guardrails so mathematical rigor is enforced by tooling
instead of by convention. See docs/math-first-tooling.md for the full
contract.

Schemas + registry:
- shared-data/schemas/deepseek-review-receipt.schema.json
  Draft 2020-12 schema for the existing ollama_deepseek_review_receipt_v1
  and ollama_deepseek_review_continuation_receipt_v1 receipt formats. Pins
  sha256:<hex> hashes, non-negative token counts, repo-relative POSIX
  paths, and rejects additional fields.
- shared-data/schemas/claims-registry.schema.json
  Schema for claims.yaml. Requires review_receipts when status is
  verified-by-ai and a lean source when status is formally-proven.
- claims.yaml
  Initial registry entry: prime-gap-entropy-collapse (verified-by-ai)
  linked to the two existing receipts under
  shared-data/artifacts/deepseek_review/.

Validators (scripts/math-first/):
- validate_deepseek_receipts.py: validates tracked or passed receipts
  against the JSON Schema; shared by pre-commit and CI.
- test_validate_deepseek_receipts.py: positive + 7 negative fixtures
  asserting exit-code behaviour.
- validate_claims_registry.py: schema check + unique id check + on-disk
  existence check for every referenced repo-relative path.
- require_math_evidence.py: gate that requires a DeepSeek receipt, a
  Lean change, or a claims.yaml update alongside edits to math-track
  surfaces (Lean Semantics kernels, ArithmeticSpec docs, stack
  solidification receipts).

Pre-commit (.pre-commit-config.yaml):
- check-json, check-yaml, end-of-file-fixer, trim trailing whitespace,
  detect-private-key (scoped to math-first files only per AGENTS.md
  Do Not Sweep).
- Local hooks wiring all three math-first validators above.

CI (.github/workflows/math-check.yml):
- validate-schemas: compiles every schema, runs both validators, runs
  the validator self-tests, then re-invokes the canonical Ollama
  emitter in --verify-only mode against every tracked receipt to
  re-check answer_sha256 against the answer-file bytes on disk.
- require-evidence: enforces the math-track evidence rule at PR scope.
- pre-commit: runs all pre-commit hooks against the PR diff so the
  contract holds even for contributors who skip installing hooks
  locally.

MCP (.mcp.json):
- filesystem, sympy, wolfram-alpha, lean, deepseek-review entries
  pointing at off-the-shelf upstream servers and at the canonical
  ollama_deepseek_review_emitter.py. Secrets stay in the runtime env
  (WOLFRAM_ALPHA_APPID, OLLAMA_API_KEY) and are never embedded.

Docs (docs/math-first-tooling.md):
- Philosophy, surfaces, schema reference, registry workflow, hook
  catalogue, CI catalogue, MCP catalogue, end-to-end verify command.

shared-data/schemas/*.schema.json and claims.yaml live under paths the
top-level .gitignore would normally exclude; they are force-added via
git add -f the same way existing promoted receipts under
shared-data/artifacts/deepseek_review/ are tracked (per AGENTS.md).

Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
2026-05-12 04:25:52 +00:00

134 lines
4.4 KiB
Python
Executable file

#!/usr/bin/env python3
"""Self-checks for ``validate_deepseek_receipts.py``.
Run with::
uv run --python 3.11 --with "jsonschema>=4.21" --with "rfc3339-validator" \
python3 scripts/math-first/test_validate_deepseek_receipts.py
The test builds positive and negative receipt fixtures in a temporary
directory, invokes the validator as a subprocess, and asserts the exit code
matches the expected outcome. The fixtures are derived from
``shared-data/artifacts/deepseek_review/`` so they exercise the same shape
that ships in the repo.
"""
from __future__ import annotations
import json
import subprocess
import sys
import tempfile
from pathlib import Path
REPO_ROOT = Path(__file__).resolve().parents[2]
VALIDATOR = REPO_ROOT / "scripts" / "math-first" / "validate_deepseek_receipts.py"
GOOD_PRIMARY = {
"schema": "ollama_deepseek_review_receipt_v1",
"created_at": "2026-05-12T03:35:51+00:00",
"model": "deepseek-v3.2",
"endpoint": "https://ollama.com/v1/chat/completions",
"prompt_sha256": "sha256:" + "a" * 64,
"answer_sha256": "sha256:" + "b" * 64,
"usage": {"prompt_tokens": 1, "completion_tokens": 1, "total_tokens": 2},
"context_files": ["docs/example.md"],
"answer_path": "shared-data/artifacts/deepseek_review/example.md",
}
GOOD_CONTINUATION = {
"schema": "ollama_deepseek_review_continuation_receipt_v1",
"created_at": "2026-05-12T03:38:49+00:00",
"model": "deepseek-v4-flash",
"endpoint": "https://ollama.com/v1/chat/completions",
"prompt_sha256": "sha256:" + "c" * 64,
"answer_sha256": "sha256:" + "d" * 64,
"usage": {"prompt_tokens": 1, "completion_tokens": 1, "total_tokens": 2},
"previous_answer_path": "shared-data/artifacts/deepseek_review/example.md",
"answer_path": "shared-data/artifacts/deepseek_review/example_continuation.md",
"message_keys": ["role", "content", "reasoning"],
}
def _write(tmp: Path, name: str, payload: dict | str) -> Path:
path = tmp / name
if isinstance(payload, str):
path.write_text(payload, encoding="utf-8")
else:
path.write_text(json.dumps(payload), encoding="utf-8")
return path
def _run(path: Path) -> subprocess.CompletedProcess[str]:
return subprocess.run(
[sys.executable, str(VALIDATOR), str(path)],
capture_output=True,
text=True,
check=False,
)
def main() -> int:
failures: list[str] = []
with tempfile.TemporaryDirectory() as raw:
tmp = Path(raw)
cases: list[tuple[str, dict | str, int]] = [
("good_primary.receipt.json", GOOD_PRIMARY, 0),
("good_continuation.receipt.json", GOOD_CONTINUATION, 0),
(
"bad_sha256.receipt.json",
{**GOOD_PRIMARY, "prompt_sha256": "not-a-hash"},
1,
),
(
"bad_schema_id.receipt.json",
{**GOOD_PRIMARY, "schema": "made_up_schema_id"},
1,
),
(
"bad_missing_usage.receipt.json",
{k: v for k, v in GOOD_PRIMARY.items() if k != "usage"},
1,
),
(
"bad_negative_tokens.receipt.json",
{**GOOD_PRIMARY, "usage": {"prompt_tokens": -1, "completion_tokens": 1, "total_tokens": 0}},
1,
),
(
"bad_answer_path_ext.receipt.json",
{**GOOD_PRIMARY, "answer_path": "shared-data/artifacts/deepseek_review/example.txt"},
1,
),
(
"bad_extra_field.receipt.json",
{**GOOD_PRIMARY, "stray": 1},
1,
),
("bad_not_json.receipt.json", "{not json}", 1),
]
for name, payload, expected in cases:
path = _write(tmp, name, payload)
result = _run(path)
if result.returncode != expected:
failures.append(
f"{name}: expected exit {expected}, got {result.returncode}\n"
f" stdout: {result.stdout.strip()}\n"
f" stderr: {result.stderr.strip()}"
)
else:
print(f"OK {name} (exit {result.returncode})")
if failures:
print("\nFailures:")
for line in failures:
print(line)
return 1
print("\nAll validator self-checks passed.")
return 0
if __name__ == "__main__":
raise SystemExit(main())