Research-Stack/.github/workflows/math-check.yml
Devin AI 9e5a30cc24 ci: disable LFS smudge filters in pre-commit job
pre-commit stashes unstaged changes, runs hooks, then pops the stash.
When the runner's working tree has LFS pointer files but git's LFS
smudge filter is configured (per .gitattributes), the stash/pop cycle
reports a phantom diff against the binary content git thinks it
should smudge, and the pop fails with
"the patch applies to ... which does not match the current contents".

All hooks themselves pass on this PR (validated locally and visible in
the previous CI run for #10). Clearing the LFS filters locally for the
pre-commit job removes the disagreement without mutating the repo or
any LFS-tracked files.

Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
2026-05-12 04:28:19 +00:00

177 lines
5.9 KiB
YAML

name: Math-First Checks
on:
pull_request:
paths:
- '0-Core-Formalism/lean/Semantics/**'
- '6-Documentation/docs/distilled/**'
- 'shared-data/artifacts/deepseek_review/**'
- 'shared-data/data/stack_solidification/**'
- 'shared-data/schemas/**'
- 'scripts/math-first/**'
- 'claims.yaml'
- '.pre-commit-config.yaml'
- '.github/workflows/math-check.yml'
push:
branches:
- main
- distilled
paths:
- '0-Core-Formalism/lean/Semantics/**'
- '6-Documentation/docs/distilled/**'
- 'shared-data/artifacts/deepseek_review/**'
- 'shared-data/data/stack_solidification/**'
- 'shared-data/schemas/**'
- 'scripts/math-first/**'
- 'claims.yaml'
- '.pre-commit-config.yaml'
- '.github/workflows/math-check.yml'
workflow_dispatch:
permissions:
contents: read
pull-requests: write
concurrency:
group: math-check-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
validate-schemas:
name: Validate DeepSeek receipts and claims registry
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
submodules: false
- name: Setup Python 3.11
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install validator dependencies
run: |
python -m pip install --upgrade pip
python -m pip install "jsonschema>=4.21" "rfc3339-validator" "PyYAML"
- name: Validate JSON Schema files compile
run: |
python - <<'PY'
import json, sys
from pathlib import Path
from jsonschema import Draft202012Validator
for path in sorted(Path("shared-data/schemas").glob("*.schema.json")):
schema = json.loads(path.read_text())
Draft202012Validator.check_schema(schema)
print(f"OK {path}")
PY
- name: Validate all tracked DeepSeek review receipts
run: |
python3 scripts/math-first/validate_deepseek_receipts.py
- name: Self-tests for receipt validator
run: |
python3 scripts/math-first/test_validate_deepseek_receipts.py
- name: Validate claims registry
run: |
python3 scripts/math-first/validate_claims_registry.py
- name: Verify receipt SHA-256 integrity against answer files
# Re-run the canonical emitter in --verify-only mode against every
# tracked receipt. This is the AGENTS.md contract for promoted
# Ollama/DeepSeek review receipts: answer_sha256 must match the bytes
# of the answer file on disk.
run: |
set -euo pipefail
shopt -s nullglob
emitter="5-Applications/tools-scripts/llm/ollama_deepseek_review_emitter.py"
if [ ! -x "$emitter" ] && [ ! -f "$emitter" ]; then
echo "skip: $emitter not present (nothing to verify)"
exit 0
fi
receipts=(shared-data/artifacts/deepseek_review/*.receipt.json)
if [ "${#receipts[@]}" -eq 0 ]; then
echo "no receipts to verify"
exit 0
fi
failures=0
for receipt in "${receipts[@]}"; do
if python3 "$emitter" --verify-only "$receipt"; then
echo "OK $receipt"
else
echo "FAIL $receipt"
failures=$((failures + 1))
fi
done
if [ "$failures" -gt 0 ]; then
echo "$failures receipt(s) failed --verify-only" >&2
exit 1
fi
require-evidence:
name: Require math evidence on math-track PRs
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Python 3.11
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Require receipt or Lean change alongside math-track edits
run: |
python3 scripts/math-first/require_math_evidence.py \
--from-git-diff origin/${{ github.base_ref }}
pre-commit:
name: Run pre-commit hooks on changed files
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
# We deliberately do not smudge LFS pointers here -- the pre-commit
# hooks never need the actual binary content, and pulling LFS would
# add noise. The next step disables the LFS smudge filters locally
# so pre-commit's stash/pop cycle does not trip over pointer files.
lfs: false
- name: Disable LFS filters for pre-commit
# pre-commit stashes unstaged changes before running hooks and pops
# them back after. When the working tree contains LFS pointer files
# but Git's LFS smudge filter is configured (per .gitattributes), the
# stash/pop cycle reports a phantom diff against the binary content
# Git thinks it should smudge, and the pop fails. Clearing the
# filters locally for this job removes the disagreement without
# mutating the repository or any LFS-tracked files.
run: |
git config --local filter.lfs.smudge ""
git config --local filter.lfs.clean ""
git config --local filter.lfs.process ""
git config --local filter.lfs.required false
- name: Setup Python 3.11
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install pre-commit
run: python -m pip install --upgrade pip "pre-commit>=3.7"
- name: Run pre-commit on changed files
run: |
base="origin/${{ github.base_ref }}"
head="HEAD"
pre-commit run --from-ref "$base" --to-ref "$head" --show-diff-on-failure