mirror of
https://github.com/Sea-Haven-Industries/shoc-pr-review-runner.git
synced 2026-09-30 04:43:12 +00:00
Manually-dispatched GitHub Actions workflow that reviews SHOC pull requests in a clean environment: exact-head checkout of shoc-frontend-new and shoc-backend, clean build/test gates, a truthful evidence report, a single-shot Fireworks review, deterministic output validation, and published artifacts. The runner never writes to the product repositories or their pull requests. The review checklists move here from the reviewers' local Cursor commands so the instructions live outside both product repos. Phase 1 does not provision a database, start either application, or run live browser flows; the evidence report records those as NOT_RUN so a review cannot claim them. Security architecture: building a PR executes its author's code, so the workflow is split. The gates job runs that code holding no Fireworks key and revokes its App token first; the review job holds the key, executes no product code, and re-checks out this repo fresh. Product checkouts live outside the workspace, the App token is downscoped at mint time, gate results fail closed on any duplicate key, changed files are read from git objects rather than the filesystem, and the validator re-checks every claim against the gate table.
61 lines
2.9 KiB
Bash
Executable file
61 lines
2.9 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Tests for scripts/validate-review-output.sh (spec §20).
|
|
#
|
|
# The "invalid-*" cases are regressions for bypasses found by the pre-push
|
|
# security review: verdict laundering, duplicate sections, shared Fix/Test
|
|
# lines, gate-contradicting prose, spliced delimiters, and a tampered gate
|
|
# table.
|
|
|
|
set -euo pipefail
|
|
TESTS_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
REPO_DIR="$(cd "$TESTS_DIR/.." && pwd)"
|
|
FIX="$TESTS_DIR/fixtures"
|
|
|
|
pass=0
|
|
fail=0
|
|
|
|
# run_case <expect: ok|err> <name> <review-fixture> <gates-fixture>
|
|
run_case() {
|
|
local expect="$1" name="$2" review="$3" gates="$4"
|
|
local tmp
|
|
tmp="$(mktemp -d)"
|
|
mkdir -p "$tmp/artifacts" "$tmp/state"
|
|
cp "$FIX/artifacts/frontend-pr.json" "$tmp/artifacts/"
|
|
cp "$FIX/artifacts/$gates" "$tmp/state/gate-status.tsv"
|
|
local rc=0
|
|
env -i PATH="$PATH" HOME="$HOME" \
|
|
WORKSPACE_DIR="$tmp" \
|
|
ARTIFACTS_DIR="$tmp/artifacts" \
|
|
STATE_DIR="$tmp/state" \
|
|
REVIEW_TYPE="frontend" \
|
|
"$REPO_DIR/scripts/validate-review-output.sh" "$FIX/reviews/$review" >/dev/null 2>&1 || rc=$?
|
|
local got="ok"
|
|
[ "$rc" -eq 0 ] || got="err"
|
|
if [ "$got" = "$expect" ]; then
|
|
pass=$((pass + 1))
|
|
else
|
|
echo "FAIL: $name (expected $expect, got $got, rc=$rc)"
|
|
fail=$((fail + 1))
|
|
fi
|
|
rm -rf "$tmp"
|
|
}
|
|
|
|
run_case ok "valid APPROVE, all gates pass" valid-approve.md gates-all-pass.tsv
|
|
run_case ok "valid REQUEST_CHANGES with blocker" valid-request-changes.md gates-all-pass.tsv
|
|
run_case ok "valid RC even with failed gate" valid-request-changes.md gates-lint-fail.tsv
|
|
run_case err "missing section 2 heading" invalid-missing-heading.md gates-all-pass.tsv
|
|
run_case err "full 40-char SHA present" invalid-full-sha.md gates-all-pass.tsv
|
|
run_case err "REQUEST_CHANGES without blocker" invalid-rc-no-blocker.md gates-all-pass.tsv
|
|
run_case err "blocker missing Fix line" invalid-blocker-no-fix.md gates-all-pass.tsv
|
|
run_case err "APPROVE while lint gate failed" valid-approve.md gates-lint-fail.tsv
|
|
run_case err "claims live browser validation" invalid-live-claim.md gates-all-pass.tsv
|
|
run_case err "verdict laundering (COMMENT + APPROVE)" invalid-verdict-laundering.md gates-lint-fail.tsv
|
|
run_case err "duplicate spoofed sections" invalid-duplicate-sections.md gates-lint-fail.tsv
|
|
run_case err "Fix/Test shared across blockers" invalid-shared-fixtest.md gates-all-pass.tsv
|
|
run_case err "claims failed gate is clean" invalid-gate-claim.md gates-lint-fail.tsv
|
|
run_case err "spliced extraction delimiters" invalid-spliced-delimiters.md gates-all-pass.tsv
|
|
run_case err "claims the app started" invalid-startup-claim.md gates-all-pass.tsv
|
|
run_case err "tampered gate table (duplicate keys)" valid-approve.md gates-tampered.tsv
|
|
|
|
echo "output-validation: $pass passed, $fail failed"
|
|
[ "$fail" -eq 0 ]
|