Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
141 changes: 141 additions & 0 deletions .github/workflows/platform-matrix.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,141 @@
name: platform-matrix

on:
push:
branches: [main, feat/management-layer]
pull_request:
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
quality:
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip
- run: python -m pip install --upgrade pip
- run: pip install -e ".[dev]"
- run: ruff check --no-cache src tests scripts
- run: ruff format --check --no-cache src tests scripts
- run: python -m compileall -q src tests scripts

tests-linux:
runs-on: ubuntu-22.04
env:
ZERO_ENV: test
PYTHONDONTWRITEBYTECODE: "1"
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip
- run: python -m pip install --upgrade pip && pip install -e ".[dev]"
- name: git identity for worktree tests
run: |
git config --global user.email "ci@example.invalid"
git config --global user.name "CI"
- run: pytest -p no:cacheprovider --tb=short

tests-arm64:
runs-on: ubuntu-24.04-arm
continue-on-error: false
env:
ZERO_ENV: test
PYTHONDONTWRITEBYTECODE: "1"
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- run: python -m pip install --upgrade pip && pip install -e ".[dev]"
- run: pytest -p no:cacheprovider --tb=short -q

tests-debian12:
runs-on: ubuntu-22.04
container:
image: debian:12
env:
ZERO_ENV: test
PYTHONDONTWRITEBYTECODE: "1"
steps:
- run: apt-get update -y && apt-get install -y python3 python3-venv python3-pip git ca-certificates
- uses: actions/checkout@v4
- run: python3 -m venv /tmp/venv && /tmp/venv/bin/pip install -U pip && /tmp/venv/bin/pip install -e ".[dev]"
- run: /tmp/venv/bin/python -m pytest -p no:cacheprovider -q --tb=short

windows-dev:
runs-on: windows-latest
continue-on-error: true # development-only target; POSIX-gated tests self-skip
env:
ZERO_ENV: test
PYTHONDONTWRITEBYTECODE: "1"
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip
- run: pip install -e ".[dev]"
- run: pytest -p no:cacheprovider --tb=short -q

installer-container:
runs-on: ubuntu-22.04
container:
image: debian:12
steps:
- uses: actions/checkout@v4
- name: run installer (no systemd inside container)
run: sh scripts/install.sh
env:
ZERO_INSTALL_BASE: ""
- name: verify entrypoints + migrations
run: |
/opt/zero/venv/bin/zero-develop --version
/opt/zero/venv/bin/zero --version
sudo -u zero env ZERO_HOME=/var/lib/zero \
/opt/zero/venv/bin/zero-develop migrate | grep '"applied"'
test -f /etc/systemd/system/zero.service || \
echo "systemd absent in container; unit file still written"

upgrade-path:
runs-on: ubuntu-22.04
env:
ZERO_ENV: test
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: install previous commit
run: |
git checkout HEAD~1
pip install -e ".[dev]"
- name: migrate on old schema
run: |
export ZERO_DATABASE_URL="sqlite:///$RUNNER_TEMP/upg.db"
python -c "from zero.cli import main; main(['migrate'])"
- name: upgrade to current and re-migrate (idempotent)
run: |
git checkout "$GITHUB_SHA"
pip install -e ".[dev]" --force-reinstall
python -c "from zero.cli import main; print(main(['migrate']))"
python -c "from zero.cli import main; main(['migrate'])"

security-audit:
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- run: pip install pip-audit
- run: pip-audit --skip-editable || true # advisory report; gate separately once baseline clean
22 changes: 22 additions & 0 deletions docker-compose.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
services:
zero:
image: python:3.12-slim
working_dir: /app
environment:
ZERO_ENV: production
ZERO_HOME: /data
ZERO_DATABASE_URL: sqlite:////data/zero.db
env_file:
- ./zero.env
volumes:
- ./:/app
- zero-data:/data
ports:
- "127.0.0.1:8000:8000"
command: >
sh -lc "pip install --no-cache-dir -e . &&
zero-develop migrate &&
uvicorn zero.main:app --host 0.0.0.0 --port 8000"
restart: unless-stopped
volumes:
zero-data:
46 changes: 0 additions & 46 deletions docs/CURRENT_STATE_LEDGER.md
Original file line number Diff line number Diff line change
@@ -1,46 +0,0 @@
# Zero Develop — Audited Current-State Ledger

This ledger reports behavior exercised in the current effective source tree. `VERIFIED` means
verified by deterministic local tests or a named local probe; it does not mean production
readiness or live external integration.

| # | Milestone | State | Evidence boundary |
|---|---|---|---|
| 0 | Foundation ingestion and build readiness | VERIFIED | Foundation inventory and repository audit |
| 1 | Repository bootstrap and executable skeleton | VERIFIED | Configuration, migrations, health, source, and installed-artifact gates |
| 2 | Identity and project isolation | VERIFIED | Backend and authenticated HTTP isolation tests |
| 3 | Authorization, secrets, tools, audit | PARTIAL | Auth, capability, and redaction tests; arbitrary in-process handler timeouts unsupported |
| 4 | Plan lifecycle and Main Planner | PARTIAL | Lifecycle and rollback tests; concurrent transition hardening remains |
| 5 | Main Worker and durable execution graph | PARTIAL | State, lease, retry, and recovery tests; claim/completion races remain |
| 6 | Isolated branch/worktree execution | VERIFIED | Local Git/worktree and execution-boundary tests |
| 7 | Dynamic Sub Agent Type lifecycle | PARTIAL | Deterministic lifecycle passes; concurrency and complete knowledge rollback remain |
| 8 | Artifact store, memory, project RAG | VERIFIED | Deterministic local isolation and rebuild tests |
| 9 | Retrieval, context, budgeting, compaction | VERIFIED | Deterministic context and recovery tests |
| 10 | Provider adapters and usage reconciliation | PARTIAL | Fake adapter, replay, cancellation, and accounting tests; no billing truth |
| 11 | Integration review and controlled merge | VERIFIED | Local deterministic integration, provenance, and lineage tests |
| 12 | Primary website vertical slices | PARTIAL | ASGI tests; no browser/mobile/accessibility audit |
| 13 | Telegram/Discord secondary adapters | PARTIAL | Canonical event and deterministic adapter tests; no live platform run |
| 14 | Observability, recovery, security hardening | PARTIAL | Recovery, redaction, migration, and database-lineage tests; backup requires configured encryption authority |
| 15 | End-to-end verification and controlled rollout | PARTIAL | Post-audit remediation suite (563 tests) and release gates; no production rollout rehearsal |

## Current verification evidence

- **563 tests passed, 16 platform-skipped** under `ZERO_ENV=test`. Reference-grounded additions (Anthropic adapter, LLM compaction summarizer, tool-round nudge) plus coherent retry lifecycle: retry-aware execution pausing, blocked-dependency revival, expired-lease terminal recording, worktree cleanup wired into recovery.
- Python compilation, full scoped Ruff, and Ruff formatting checks pass for `src`, `tests`, and
`scripts`.
- The effective schema contains **30** migration files (including `0027_remaining_project_lineage` and `0028_secret_key_versioning`). Migration IDs use complete filename stems;
numeric prefixes alone are not unique because three migrations begin with `0012`.
- Direct SQL lineage tests cover both INSERT and UPDATE mismatch attempts for the identified
denormalized project-scoped tables.
- The final staged wheel/sdist artifact gate passed: both artifacts contain exactly 30 migrations and
all required runtime modules; the sdist also contains the key scripts and lineage regressions.
- The final installed wheel passed import, fresh migration/rerun/integrity, fail-closed configuration,
and loopback root/health/readiness probes.
- Fresh, rerun, atomicity, concurrency, and populated-upgrade probes passed for the 30-migration set.

## Deployment boundary

Deployment remains a separate owner-authorized action and is blocked by the `PARTIAL` items above:
live external adapters, browser/accessibility coverage, concurrency hardening, external persistence,
and disaster-recovery rehearsal. Backup operations additionally require separately protected
`ZERO_SECRET_KEY` authority.
Loading
Loading