mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-06 15:02:20 +02:00
Merge commit 'refs/phase3/pre-ajax/publication-tip' into integration/pre-ajax-release
# Conflicts: # routes/chat_routes.py # routes/session_routes.py # src/agent_loop.py # src/agent_tools/filesystem_tools.py # src/teacher_escalation.py # src/tool_capabilities.py # src/tool_execution.py # tests/test_mcp_add_server_args_validation.py # tests/test_token_cache_atomic_swap.py
This commit is contained in:
@@ -4,12 +4,16 @@
|
||||
|
||||
## Target branch
|
||||
|
||||
- [ ] This PR targets **`dev`**, not `main`. All PRs land in `dev`; `main` is curated by the maintainer at each release. If your PR is on `main` by accident, click "Edit" on this PR and change the base.
|
||||
- [ ] This PR targets the correct integration branch: **`lab`** in the private maintainer-preview repository, or **`dev`** in the public repository. `main` remains release-curated.
|
||||
|
||||
## Linked Issue
|
||||
|
||||
<!-- Every PR should be linked to an issue.
|
||||
Use one of: Fixes #NNN | Part of #NNN | Closes #NNN -->
|
||||
<!-- Public-repository PRs must link an issue:
|
||||
Fixes #NNN | Part of #NNN | Closes #NNN
|
||||
|
||||
Private maintainer-preview PRs may instead use:
|
||||
N/A — maintainer integration work
|
||||
-->
|
||||
|
||||
Fixes #
|
||||
|
||||
@@ -25,7 +29,7 @@ Fixes #
|
||||
## Checklist
|
||||
|
||||
- [ ] I searched [open issues](https://github.com/odysseus-dev/odysseus/issues) and [open PRs](https://github.com/odysseus-dev/odysseus/pulls) — this is not a duplicate.
|
||||
- [ ] This PR targets `dev`
|
||||
- [ ] This PR targets the correct integration branch (`lab` in maintainer-preview; `dev` in the public repository)
|
||||
- [ ] My changes are limited to the scope described above — no unrelated refactors or whitespace changes mixed in.
|
||||
- [ ] I actually ran the app (`docker compose up` or `uvicorn app:app`) and verified the change works end-to-end. Type-checks and unit tests are not enough.
|
||||
- [ ] I did not run the app/runtime validation and stated that gap in **How to Test**. Leave this unchecked when the app-run box above is checked.
|
||||
|
||||
@@ -8,6 +8,9 @@ module.exports = async ({ github, context, core }) => {
|
||||
const MARKER = '<!-- pr-description-check-bot -->';
|
||||
const owner = context.repo.owner;
|
||||
const repo = context.repo.repo;
|
||||
const isMaintainerPreview =
|
||||
owner === 'pewdiepie-archdaemon'
|
||||
&& repo === 'odysseus-maintainer-preview';
|
||||
|
||||
// Strip HTML comments so placeholder text does not count as content.
|
||||
function strip(text) {
|
||||
@@ -28,13 +31,30 @@ module.exports = async ({ github, context, core }) => {
|
||||
descriptionProblems.push('**Summary** is empty or too short — describe what changed and why.');
|
||||
}
|
||||
|
||||
// 2. Linked Issue must reference a real issue. Accept a bare #NNN, a closing
|
||||
// keyword + #NNN, or a full issue URL (e.g. .../issues/123) — the strict
|
||||
// keyword-prefixed form previously false-flagged correctly-linked PRs.
|
||||
// 2. Public contributor PRs must reference a real issue. The private
|
||||
// maintainer-preview repository may explicitly opt out for fast maintainer
|
||||
// integration work while still requiring the section to state that intent.
|
||||
const linkedSection = section('Linked Issue');
|
||||
const hasIssueRef = /#\d+\b/.test(linkedSection) || /\/issues\/\d+/.test(linkedSection);
|
||||
if (!linkedSection || !hasIssueRef) {
|
||||
descriptionProblems.push('**Linked Issue** — add a reference like `Fixes #NNN`, a bare `#NNN`, or a link to the issue.');
|
||||
const hasMaintainerNA = /^N\/A\b/i.test(linkedSection);
|
||||
|
||||
if (!linkedSection) {
|
||||
descriptionProblems.push(
|
||||
'**Linked Issue** — fill this section. Public PRs require an issue reference; ' +
|
||||
'maintainer-preview PRs may use `N/A — maintainer integration work`.'
|
||||
);
|
||||
} else if (isMaintainerPreview) {
|
||||
if (!hasIssueRef && !hasMaintainerNA) {
|
||||
descriptionProblems.push(
|
||||
'**Linked Issue** — use an issue reference or `N/A — maintainer integration work` ' +
|
||||
'in the private maintainer-preview repository.'
|
||||
);
|
||||
}
|
||||
} else if (!hasIssueRef) {
|
||||
descriptionProblems.push(
|
||||
'**Linked Issue** — add a reference like `Fixes #NNN`, a bare `#NNN`, ' +
|
||||
'or a link to the issue.'
|
||||
);
|
||||
}
|
||||
|
||||
// 3. At least one Type of Change box must be checked.
|
||||
|
||||
@@ -101,9 +101,19 @@ jobs:
|
||||
done
|
||||
|
||||
python-tests:
|
||||
name: Python tests (pytest)
|
||||
runs-on: ubuntu-latest
|
||||
name: Python tests (pytest ${{ matrix.shard }})
|
||||
# Keep the namespace/AppArmor setup tied to the audited Ubuntu release.
|
||||
runs-on: ubuntu-24.04
|
||||
# Make Python test validation authoritative for the configured scope.
|
||||
strategy:
|
||||
# Report every failing section in one run instead of cancelling the rest
|
||||
# the moment one shard goes red.
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# Shards partition the suite by test file, so the four together run
|
||||
# every test exactly once. tests/_shards.py owns the partition and
|
||||
# tests/test_shards.py pins this list to its DEFAULT_SHARD_COUNT.
|
||||
shard: ["1/4", "2/4", "3/4", "4/4"]
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
@@ -140,7 +150,77 @@ jobs:
|
||||
cache: pip
|
||||
- run: pip install -r requirements.txt
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
with:
|
||||
node-version: "20"
|
||||
cache: npm
|
||||
- run: npm ci
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- run: npx playwright install --with-deps chromium
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- run: mkdir -p data # sqlite DB lives at ./data/app.db
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
- run: python -m pytest -q
|
||||
- name: Install FFmpeg for media integration tests
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends ffmpeg
|
||||
command -v ffmpeg
|
||||
ffmpeg -version | head -n 1
|
||||
|
||||
- name: Establish functional bubblewrap containment
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends bubblewrap
|
||||
bwrap --version
|
||||
sysctl kernel.unprivileged_userns_clone user.max_user_namespaces \
|
||||
kernel.apparmor_restrict_unprivileged_userns
|
||||
if [ "$(sysctl -n kernel.unprivileged_userns_clone)" != 1 ] || \
|
||||
[ "$(sysctl -n user.max_user_namespaces)" -eq 0 ]; then
|
||||
echo '::error::The pytest runner must allow unprivileged user namespaces; kernel namespace support is disabled.'
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Match containment._bwrap_available(): PID and mount namespaces,
|
||||
# including fresh proc/dev mounts, as the unprivileged runner user.
|
||||
bwrap_probe() {
|
||||
timeout 3s bwrap --die-with-parent --unshare-pid --ro-bind / / \
|
||||
--proc /proc --dev /dev /bin/true
|
||||
}
|
||||
|
||||
if ! bwrap_probe && [ "$(sysctl -n kernel.apparmor_restrict_unprivileged_userns)" = 1 ]; then
|
||||
# Ubuntu 24.04 restricts userns for unconfined applications. Allow
|
||||
# only the distro bwrap entry point on this ephemeral pytest VM;
|
||||
# retain the global restriction and all unrelated AppArmor policy.
|
||||
sudo tee /etc/apparmor.d/odysseus-ci-bwrap > /dev/null <<'PROFILE'
|
||||
abi <abi/4.0>,
|
||||
include <tunables/global>
|
||||
profile odysseus-ci-bwrap /usr/bin/bwrap flags=(unconfined) {
|
||||
userns,
|
||||
}
|
||||
PROFILE
|
||||
sudo apparmor_parser -r /etc/apparmor.d/odysseus-ci-bwrap
|
||||
fi
|
||||
|
||||
if ! bwrap_probe; then
|
||||
echo '::error::Functional bubblewrap PID/mount namespaces are required for pytest; containment setup failed.'
|
||||
exit 1
|
||||
fi
|
||||
# Also gate on the runtime probe so a future requirements change
|
||||
# cannot silently leave this job without real containment coverage.
|
||||
python - <<'PY'
|
||||
from src import containment
|
||||
if not containment._bwrap_available():
|
||||
raise SystemExit("::error::Runtime bubblewrap functionality probe failed; pytest must not start.")
|
||||
print("Runtime bubblewrap PID/mount namespace probe passed.")
|
||||
PY
|
||||
|
||||
- name: pytest (shard ${{ matrix.shard }})
|
||||
if: steps.docs-check.outputs.docs_only != 'true'
|
||||
env:
|
||||
PYTEST_SHARD: ${{ matrix.shard }}
|
||||
run: python -m pytest -q -rs --shard "$PYTEST_SHARD"
|
||||
|
||||
@@ -62,6 +62,8 @@ jobs:
|
||||
|
||||
- name: Set up Buildx
|
||||
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
|
||||
with:
|
||||
driver: docker
|
||||
|
||||
# Build without pushing so a broken Dockerfile is caught here, and the
|
||||
# exact image we ship is what gets scanned.
|
||||
@@ -73,6 +75,9 @@ jobs:
|
||||
load: true
|
||||
tags: odysseus:ci
|
||||
|
||||
- name: Free build cache before vulnerability database download
|
||||
run: docker builder prune --all --force
|
||||
|
||||
- name: Scan image with Trivy
|
||||
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
|
||||
with:
|
||||
@@ -103,6 +108,8 @@ jobs:
|
||||
|
||||
- name: Set up Buildx
|
||||
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
|
||||
with:
|
||||
driver: docker
|
||||
|
||||
- name: Build image
|
||||
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
|
||||
@@ -112,6 +119,9 @@ jobs:
|
||||
load: true
|
||||
tags: odysseus:ci
|
||||
|
||||
- name: Free build cache before vulnerability database download
|
||||
run: docker builder prune --all --force
|
||||
|
||||
- name: Scan image with Trivy
|
||||
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
|
||||
with:
|
||||
|
||||
@@ -30,7 +30,10 @@ jobs:
|
||||
dependency-review:
|
||||
name: dependency-review (PR gate)
|
||||
# Only meaningful on a pull request -- it needs a base..head diff to review.
|
||||
if: github.event_name == 'pull_request'
|
||||
# dependency-review-action requires GitHub dependency-review support.
|
||||
# Keep the blocking gate on the canonical repository; forks and maintainer
|
||||
# preview mirrors still run the advisory pip-audit job below.
|
||||
if: github.event_name == 'pull_request' && github.repository == 'odysseus-dev/odysseus'
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
Reference in New Issue
Block a user