Research-Stack/.github/workflows/math-check.yml
dependabot[bot] ed3458ade2 Bump actions/setup-python from 5 to 6
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit 67a24b308d43cd54281f31ca472338fb6d394d03)
2026-05-20 23:03:34 -05:00

181 lines
6.1 KiB
YAML

name: Math-First Checks
on:
pull_request:
paths:
- '0-Core-Formalism/lean/Semantics/**'
- '6-Documentation/docs/distilled/**'
- 'shared-data/artifacts/deepseek_review/**'
- 'shared-data/data/stack_solidification/**'
- 'shared-data/schemas/**'
- 'scripts/math-first/**'
- 'claims.yaml'
- '.pre-commit-config.yaml'
- '.github/workflows/math-check.yml'
push:
branches:
- main
- distilled
paths:
- '0-Core-Formalism/lean/Semantics/**'
- '6-Documentation/docs/distilled/**'
- 'shared-data/artifacts/deepseek_review/**'
- 'shared-data/data/stack_solidification/**'
- 'shared-data/schemas/**'
- 'scripts/math-first/**'
- 'claims.yaml'
- '.pre-commit-config.yaml'
- '.github/workflows/math-check.yml'
workflow_dispatch:
permissions:
contents: read
pull-requests: write
concurrency:
group: math-check-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
validate-schemas:
name: Validate DeepSeek receipts and claims registry
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
fetch-depth: 0
submodules: false
- name: Setup Python 3.11
uses: actions/setup-python@v6
with:
python-version: '3.11'
- name: Install validator dependencies
run: |
python -m pip install --upgrade pip
python -m pip install "jsonschema>=4.21" "rfc3339-validator" "PyYAML"
- name: Validate JSON Schema files compile
run: |
python - <<'PY'
import json, sys
from pathlib import Path
from jsonschema import Draft202012Validator
for path in sorted(Path("shared-data/schemas").glob("*.schema.json")):
schema = json.loads(path.read_text())
Draft202012Validator.check_schema(schema)
print(f"OK {path}")
PY
- name: Validate all tracked DeepSeek review receipts
run: |
python3 scripts/math-first/validate_deepseek_receipts.py
- name: Self-tests for receipt validator
run: |
python3 scripts/math-first/test_validate_deepseek_receipts.py
- name: Self-tests for require_math_evidence (incl. regression)
run: |
python3 scripts/math-first/test_require_math_evidence.py
- name: Validate claims registry
run: |
python3 scripts/math-first/validate_claims_registry.py
- name: Verify receipt SHA-256 integrity against answer files
# Re-run the canonical emitter in --verify-only mode against every
# tracked receipt. This is the AGENTS.md contract for promoted
# Ollama/DeepSeek review receipts: answer_sha256 must match the bytes
# of the answer file on disk.
run: |
set -euo pipefail
shopt -s nullglob
emitter="5-Applications/tools-scripts/llm/ollama_deepseek_review_emitter.py"
if [ ! -x "$emitter" ] && [ ! -f "$emitter" ]; then
echo "skip: $emitter not present (nothing to verify)"
exit 0
fi
receipts=(shared-data/artifacts/deepseek_review/*.receipt.json)
if [ "${#receipts[@]}" -eq 0 ]; then
echo "no receipts to verify"
exit 0
fi
failures=0
for receipt in "${receipts[@]}"; do
if python3 "$emitter" --verify-only "$receipt"; then
echo "OK $receipt"
else
echo "FAIL $receipt"
failures=$((failures + 1))
fi
done
if [ "$failures" -gt 0 ]; then
echo "$failures receipt(s) failed --verify-only" >&2
exit 1
fi
require-evidence:
name: Require math evidence on math-track PRs
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Setup Python 3.11
uses: actions/setup-python@v6
with:
python-version: '3.11'
- name: Require receipt or Lean change alongside math-track edits
run: |
python3 scripts/math-first/require_math_evidence.py \
--from-git-diff origin/${{ github.base_ref }}
pre-commit:
name: Run pre-commit hooks on changed files
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
fetch-depth: 0
# We deliberately do not smudge LFS pointers here -- the pre-commit
# hooks never need the actual binary content, and pulling LFS would
# add noise. The next step disables the LFS smudge filters locally
# so pre-commit's stash/pop cycle does not trip over pointer files.
lfs: false
- name: Disable LFS filters for pre-commit
# pre-commit stashes unstaged changes before running hooks and pops
# them back after. When the working tree contains LFS pointer files
# but Git's LFS smudge filter is configured (per .gitattributes), the
# stash/pop cycle reports a phantom diff against the binary content
# Git thinks it should smudge, and the pop fails. Clearing the
# filters locally for this job removes the disagreement without
# mutating the repository or any LFS-tracked files.
run: |
git config --local filter.lfs.smudge ""
git config --local filter.lfs.clean ""
git config --local filter.lfs.process ""
git config --local filter.lfs.required false
- name: Setup Python 3.11
uses: actions/setup-python@v6
with:
python-version: '3.11'
- name: Install pre-commit
run: python -m pip install --upgrade pip "pre-commit>=3.7"
- name: Run pre-commit on changed files
run: |
base="origin/${{ github.base_ref }}"
head="HEAD"
pre-commit run --from-ref "$base" --to-ref "$head" --show-diff-on-failure