Research-Stack/.github/workflows/math-check.yml
Devin AI 87960676b4 Add math-first tooling: receipt schema, claims registry, pre-commit, CI, MCP
Adds automated guardrails so mathematical rigor is enforced by tooling
instead of by convention. See docs/math-first-tooling.md for the full
contract.

Schemas + registry:
- shared-data/schemas/deepseek-review-receipt.schema.json
  Draft 2020-12 schema for the existing ollama_deepseek_review_receipt_v1
  and ollama_deepseek_review_continuation_receipt_v1 receipt formats. Pins
  sha256:<hex> hashes, non-negative token counts, repo-relative POSIX
  paths, and rejects additional fields.
- shared-data/schemas/claims-registry.schema.json
  Schema for claims.yaml. Requires review_receipts when status is
  verified-by-ai and a lean source when status is formally-proven.
- claims.yaml
  Initial registry entry: prime-gap-entropy-collapse (verified-by-ai)
  linked to the two existing receipts under
  shared-data/artifacts/deepseek_review/.

Validators (scripts/math-first/):
- validate_deepseek_receipts.py: validates tracked or passed receipts
  against the JSON Schema; shared by pre-commit and CI.
- test_validate_deepseek_receipts.py: positive + 7 negative fixtures
  asserting exit-code behaviour.
- validate_claims_registry.py: schema check + unique id check + on-disk
  existence check for every referenced repo-relative path.
- require_math_evidence.py: gate that requires a DeepSeek receipt, a
  Lean change, or a claims.yaml update alongside edits to math-track
  surfaces (Lean Semantics kernels, ArithmeticSpec docs, stack
  solidification receipts).

Pre-commit (.pre-commit-config.yaml):
- check-json, check-yaml, end-of-file-fixer, trim trailing whitespace,
  detect-private-key (scoped to math-first files only per AGENTS.md
  Do Not Sweep).
- Local hooks wiring all three math-first validators above.

CI (.github/workflows/math-check.yml):
- validate-schemas: compiles every schema, runs both validators, runs
  the validator self-tests, then re-invokes the canonical Ollama
  emitter in --verify-only mode against every tracked receipt to
  re-check answer_sha256 against the answer-file bytes on disk.
- require-evidence: enforces the math-track evidence rule at PR scope.
- pre-commit: runs all pre-commit hooks against the PR diff so the
  contract holds even for contributors who skip installing hooks
  locally.

MCP (.mcp.json):
- filesystem, sympy, wolfram-alpha, lean, deepseek-review entries
  pointing at off-the-shelf upstream servers and at the canonical
  ollama_deepseek_review_emitter.py. Secrets stay in the runtime env
  (WOLFRAM_ALPHA_APPID, OLLAMA_API_KEY) and are never embedded.

Docs (docs/math-first-tooling.md):
- Philosophy, surfaces, schema reference, registry workflow, hook
  catalogue, CI catalogue, MCP catalogue, end-to-end verify command.

shared-data/schemas/*.schema.json and claims.yaml live under paths the
top-level .gitignore would normally exclude; they are force-added via
git add -f the same way existing promoted receipts under
shared-data/artifacts/deepseek_review/ are tracked (per AGENTS.md).

Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
2026-05-12 04:25:52 +00:00

158 lines
4.8 KiB
YAML

name: Math-First Checks
on:
pull_request:
paths:
- '0-Core-Formalism/lean/Semantics/**'
- '6-Documentation/docs/distilled/**'
- 'shared-data/artifacts/deepseek_review/**'
- 'shared-data/data/stack_solidification/**'
- 'shared-data/schemas/**'
- 'scripts/math-first/**'
- 'claims.yaml'
- '.pre-commit-config.yaml'
- '.github/workflows/math-check.yml'
push:
branches:
- main
- distilled
paths:
- '0-Core-Formalism/lean/Semantics/**'
- '6-Documentation/docs/distilled/**'
- 'shared-data/artifacts/deepseek_review/**'
- 'shared-data/data/stack_solidification/**'
- 'shared-data/schemas/**'
- 'scripts/math-first/**'
- 'claims.yaml'
- '.pre-commit-config.yaml'
- '.github/workflows/math-check.yml'
workflow_dispatch:
permissions:
contents: read
pull-requests: write
concurrency:
group: math-check-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
validate-schemas:
name: Validate DeepSeek receipts and claims registry
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
submodules: false
- name: Setup Python 3.11
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install validator dependencies
run: |
python -m pip install --upgrade pip
python -m pip install "jsonschema>=4.21" "rfc3339-validator" "PyYAML"
- name: Validate JSON Schema files compile
run: |
python - <<'PY'
import json, sys
from pathlib import Path
from jsonschema import Draft202012Validator
for path in sorted(Path("shared-data/schemas").glob("*.schema.json")):
schema = json.loads(path.read_text())
Draft202012Validator.check_schema(schema)
print(f"OK {path}")
PY
- name: Validate all tracked DeepSeek review receipts
run: |
python3 scripts/math-first/validate_deepseek_receipts.py
- name: Self-tests for receipt validator
run: |
python3 scripts/math-first/test_validate_deepseek_receipts.py
- name: Validate claims registry
run: |
python3 scripts/math-first/validate_claims_registry.py
- name: Verify receipt SHA-256 integrity against answer files
# Re-run the canonical emitter in --verify-only mode against every
# tracked receipt. This is the AGENTS.md contract for promoted
# Ollama/DeepSeek review receipts: answer_sha256 must match the bytes
# of the answer file on disk.
run: |
set -euo pipefail
shopt -s nullglob
emitter="5-Applications/tools-scripts/llm/ollama_deepseek_review_emitter.py"
if [ ! -x "$emitter" ] && [ ! -f "$emitter" ]; then
echo "skip: $emitter not present (nothing to verify)"
exit 0
fi
receipts=(shared-data/artifacts/deepseek_review/*.receipt.json)
if [ "${#receipts[@]}" -eq 0 ]; then
echo "no receipts to verify"
exit 0
fi
failures=0
for receipt in "${receipts[@]}"; do
if python3 "$emitter" --verify-only "$receipt"; then
echo "OK $receipt"
else
echo "FAIL $receipt"
failures=$((failures + 1))
fi
done
if [ "$failures" -gt 0 ]; then
echo "$failures receipt(s) failed --verify-only" >&2
exit 1
fi
require-evidence:
name: Require math evidence on math-track PRs
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Python 3.11
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Require receipt or Lean change alongside math-track edits
run: |
python3 scripts/math-first/require_math_evidence.py \
--from-git-diff origin/${{ github.base_ref }}
pre-commit:
name: Run pre-commit hooks on changed files
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Python 3.11
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install pre-commit
run: python -m pip install --upgrade pip "pre-commit>=3.7"
- name: Run pre-commit on changed files
run: |
base="origin/${{ github.base_ref }}"
head="HEAD"
pre-commit run --from-ref "$base" --to-ref "$head" --show-diff-on-failure