Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
a81ecf9
test(orm): record nightly capability gates and compatibility baseline
logbie Sep 20, 2026
052ba8d
test(orm): define field and exact identity contracts
logbie Sep 20, 2026
afb4f9d
test(orm): capture model relationship isolation failure
logbie Sep 20, 2026
3f2ad08
test(orm): expose numeric ordering regression in exact identity queries
logbie Sep 20, 2026
54d5ea7
feat(orm): preserve numeric ordering and batch explicit relationships
logbie Sep 20, 2026
72a2d6d
test(migrations): require audited legacy adoption
logbie Sep 20, 2026
ffeebbb
test(database): expose identity loss and partial installation
logbie Sep 20, 2026
c0d0603
test(db): preserve review regressions before compatibility fixes
logbie Sep 20, 2026
6f37620
test(http): exercise CMS workflows entirely in WFL
logbie Sep 20, 2026
547ceec
feat(testing): run the complete regression suite in WFL
logbie Sep 20, 2026
c70240b
feat(database): integrate ORM records and preserve legacy contracts
logbie Sep 20, 2026
02c2be8
test(http): preserve extension and theme contracts during legacy upgrade
logbie Sep 20, 2026
2bf9dee
test(testing): retain timeout diagnostics and cover runtime gates
logbie Sep 20, 2026
9de5c72
feat(migrations): add audited SQLite schema lifecycle and legacy adop…
logbie Sep 20, 2026
af2b6ac
test(migrations): expose historical managed index drift
logbie Sep 20, 2026
e3e8a6a
fix(migrations): reject historical index drift and verify read-only a…
logbie Sep 20, 2026
81f75c1
docs(review): record verified migration safety remedies
logbie Sep 20, 2026
af53673
docs: clarify upgrade recovery and harden probe cleanup
logbie Sep 20, 2026
3bc7b4f
test(orm): verify runtime prerequisites and complete acceptance audit
logbie Sep 20, 2026
26bc1c2
docs(validation): record complete WFL candidate pass
logbie Sep 20, 2026
040e81a
docs(testing): state the effective whole-run time limit
logbie Sep 20, 2026
99b63b0
docs(validation): record official nightly prerequisite failure
logbie Sep 20, 2026
b9e7903
test: deliberately fail WFL CI propagation proof
logbie Sep 20, 2026
b977d50
fix(ci): resolve official nightly assets from canonical publication
logbie Sep 20, 2026
2c76cda
docs(validation): align records with merged runtime prerequisites
logbie Sep 20, 2026
07e8adc
fix(ci): refresh nightly metadata before immutable provisioning
logbie Sep 20, 2026
147b15c
test(http): verify configured upload rejection across platforms
logbie Sep 20, 2026
2d1d6e2
docs(test): record portable media rejection evidence
logbie Sep 20, 2026
df8039c
test(tooling): request a finite full-suite execution budget
logbie Sep 20, 2026
c3b06d3
docs(validation): record reviewed runtime budget and approved merge
logbie Sep 20, 2026
5836206
docs(runtime): verify the published WFL 26.9.16 prerequisite
logbie Sep 20, 2026
304a5fd
test(ci): remove the proven deliberate assertion and record remote ev…
logbie Sep 20, 2026
fd1a65e
style: remove trailing blank lines from the final diff
logbie Sep 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 62 additions & 2 deletions .github/workflows/governance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
- os: windows-latest
runner: windows-latest
runs-on: ${{ matrix.runner }}
timeout-minutes: 10
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
with:
Expand All @@ -35,7 +35,67 @@ jobs:
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Provision the current WFL nightly
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'
# The GitHub daily release is an immutable mirror. The canonical
# publisher can release a newer runtime on the same day to this CDN.
$cdn = 'https://wfl.nyc3.cdn.digitaloceanspaces.com'
# A previously cached pointer can retain the CDN's older one-hour TTL.
$publicationUri = "$cdn/status.json?request=$([guid]::NewGuid().ToString('N'))"
$publication = Invoke-RestMethod -Uri $publicationUri
if ($publication.result -ne 'success' -or $publication.branch -ne 'main' -or
$publication.version -notmatch '^\d+\.\d+\.\d+$' -or
$publication.sha -notmatch '^[a-f0-9]{40}$') {
throw 'Invalid official WFL publication record'
}
$releaseVersion = [regex]::Escape($publication.version)
$pattern = if ($IsWindows) { "^wfl-$releaseVersion\.msi$" } else { "^wfl-$releaseVersion-linux-x86_64-[a-f0-9]{7,40}\.tar\.gz$" }
$assets = @($publication.message -split '\s+' | Where-Object { $_ -match $pattern })
if ($assets.Count -ne 1) { throw 'Publication must name one immutable platform-specific WFL asset' }
$assetName = $assets[0]
if (-not $IsWindows -and $assetName -match '-linux-x86_64-([a-f0-9]{7,40})\.tar\.gz$') {
if (-not $publication.sha.StartsWith($Matches[1])) { throw 'WFL artifact revision does not match publication' }
}
$assetUrl = "$cdn/releases/$assetName"
$checksum = (Invoke-WebRequest -Uri "$assetUrl.sha256").Content.Trim()
$checksumPattern = '^([a-fA-F0-9]{64})\s+\*?' + [regex]::Escape($assetName) + '$'
if ($checksum -notmatch $checksumPattern) { throw 'Invalid immutable WFL checksum sidecar' }
$expectedDigest = $Matches[1].ToLowerInvariant()
$runtimeRoot = Join-Path $env:RUNNER_TEMP 'scriptorium-wfl'
New-Item -ItemType Directory -Path $runtimeRoot -Force | Out-Null
$archive = Join-Path $runtimeRoot $assetName
Invoke-WebRequest -Uri $assetUrl -OutFile $archive
$digest = (Get-FileHash -LiteralPath $archive -Algorithm SHA256).Hash.ToLowerInvariant()
if ($expectedDigest -ne $digest) { throw 'WFL release asset digest mismatch' }
if ($IsWindows) {
$expanded = Join-Path $runtimeRoot 'expanded'
$arguments = @('/a', "`"$archive`"", '/qn', "TARGETDIR=`"$expanded`"")
$installer = Start-Process msiexec.exe -ArgumentList $arguments -Wait -PassThru -WindowStyle Hidden
if ($installer.ExitCode -ne 0) { throw "WFL extraction failed: $($installer.ExitCode)" }
$programs = @(Get-ChildItem -LiteralPath $expanded -Filter wfl.exe -File -Recurse)
} else {
tar -xzf $archive -C $runtimeRoot
if ($LASTEXITCODE -ne 0) { throw 'WFL extraction failed' }
$programs = @(Get-ChildItem -LiteralPath $runtimeRoot -Filter wfl -File -Recurse)
}
if ($programs.Count -ne 1) { throw 'Expected one extracted WFL executable' }
$runtimePath = $programs[0].FullName
$programs[0].DirectoryName | Out-File -FilePath $env:GITHUB_PATH -Append
$version = & $runtimePath --version
if ($LASTEXITCODE -ne 0) { throw 'Extracted WFL runtime did not start' }
if ($version -ne "WebFirst Language (WFL) version $($publication.version)") { throw 'WFL executable version does not match publication' }
@(
'### Governance runtime',
"- Publication: $cdn/status.json",
"- WFL revision: $($publication.sha)",
"- Asset: $assetUrl",
"- SHA256: $digest",
"- Runtime: $version",
"- Scriptorium: $env:GITHUB_SHA"
) | Out-File -FilePath $env:GITHUB_STEP_SUMMARY -Append
- name: Test repository tooling
run: python -m unittest discover -s tests/tooling -v
run: wfl scripts/run_tests.wfl --group tooling
- name: Check repository hygiene
run: python scripts/check_repo_hygiene.py
92 changes: 92 additions & 0 deletions .github/workflows/runtime-capabilities.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
name: WFL ORM capability gates

on:
push:
branches: [codex/wfl-orm-migrations]
workflow_dispatch:

permissions:
contents: read

concurrency:
group: orm-capabilities-${{ github.ref }}
cancel-in-progress: true

jobs:
runtime:
name: Resolve current nightly
runs-on: blacksmith-2vcpu-ubuntu-2404
timeout-minutes: 5
outputs:
image: ${{ steps.runtime.outputs.image }}
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
submodules: recursive
- name: Pull nightly and record provenance
id: runtime
shell: bash
run: |
docker pull bsbyrdwfl/wfl:nightly
image="$(docker image inspect --format '{{index .RepoDigests 0}}' bsbyrdwfl/wfl:nightly)"
echo "image=$image" >> "$GITHUB_OUTPUT"
version="$(docker run --rm --network none "$image" --version)"
{
echo '### ORM prerequisite evidence (not completed ORM validation)'
echo "- Image: $image"
echo "- Runtime: $version"
echo "- Scriptorium: $(git rev-parse HEAD)"
echo "- Scribe: $(git -C lib/scribe rev-parse HEAD)"
echo '- Every probe, fixture, HTTP driver and assertion is WFL.'
echo '- Unmet capability assertions fail their jobs without suppression.'
} | tee -a "$GITHUB_STEP_SUMMARY"

probes:
name: ${{ matrix.suite }}
needs: runtime
runs-on: blacksmith-2vcpu-ubuntu-2404
timeout-minutes: 5
strategy:
fail-fast: false
matrix:
include:
- suite: orm-native-baseline
path: tests/runtime/orm-native-baseline.test.wfl
- suite: transaction-validation-capability
path: tests/runtime/transaction-validation-capability.test.wfl
- suite: rebuild-foreign-keys-capability
path: tests/runtime/rebuild-foreign-keys-capability.test.wfl
- suite: process-capabilities
path: tests/runtime/process-capabilities.test.wfl
- suite: http-redirect-capability
path: tests/runtime/http-redirect-capability.test.wfl
- suite: media-body-limit
path: tests/integration/media.test.wfl
env:
RESOLVED_IMAGE: ${{ needs.runtime.outputs.image }}
PROBE_SUITE: ${{ matrix.path }}
TEST_CONTAINER: scriptorium-probe-${{ github.run_id }}-${{ github.run_attempt }}-${{ strategy.job-index }}
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
submodules: recursive
- name: Invoke WFL capability suite
shell: bash
run: |
docker pull "$RESOLVED_IMAGE"
docker run --rm --init --name "$TEST_CONTAINER" \
--user 0:0 --entrypoint /bin/sh \
--mount "type=bind,source=$GITHUB_WORKSPACE,target=/source,readonly" \
--env PROBE_SUITE --workdir /work "$RESOLVED_IMAGE" -ec '
cp -a /source/. /work/
exec wfl --test "$PROBE_SUITE"
'
- name: Clean up disposable container
if: always()
shell: bash
run: |
if docker container inspect "$TEST_CONTAINER" >/dev/null 2>&1; then
docker container rm --force "$TEST_CONTAINER"
fi
4 changes: 2 additions & 2 deletions .github/workflows/update-scribe.yml
Original file line number Diff line number Diff line change
Expand Up @@ -136,8 +136,8 @@ jobs:
echo
echo '| Check or exact command | Result and evidence |'
echo '|---|---|'
echo '| `python3 scripts/run_tests.py --include-scribe` | Pending — this workflow prepares the dependency bump. Link WFL tests results for the current revision, including the nightly image digest and runtime version; record failures. |'
echo '| `python -m unittest discover -s tests/tooling -v` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
echo '| `wfl --execution-timeout 1200 scripts/run_tests.wfl` | Pending — this workflow prepares the dependency bump. Link WFL tests results for the current revision, including the nightly image digest and runtime version; record failures. |'
echo '| `wfl scripts/run_tests.wfl --group tooling` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
echo '| `python scripts/check_repo_hygiene.py` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
echo '| Affected HTTP/UI rendering journeys | Not run — upstream diff review is needed to identify affected paths. Record setup, expected/actual outcome, and evidence. |'
echo
Expand Down
24 changes: 14 additions & 10 deletions .github/workflows/wfl-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
wfl-tests:
name: WFL nightly (Blacksmith)
runs-on: blacksmith-2vcpu-ubuntu-2404
timeout-minutes: 15
timeout-minutes: 30
env:
WFL_IMAGE: bsbyrdwfl/wfl:nightly
TEST_CONTAINER: scriptorium-tests-${{ github.run_id }}-${{ github.run_attempt }}
Expand All @@ -36,36 +36,40 @@ jobs:
image="$(docker image inspect --format '{{index .RepoDigests 0}}' "$WFL_IMAGE")"
echo "image=$image" >> "$GITHUB_OUTPUT"
version="$(docker run --rm --network none "$image" --version)"
runtime_revision="$(docker image inspect --format '{{index .Config.Labels "org.opencontainers.image.revision"}}' "$image")"
[[ "$runtime_revision" =~ ^[a-f0-9]{40}$ ]] || { echo 'Official image is missing its WFL source revision'; exit 1; }
{
echo '### WFL nightly test environment'
echo
echo "- Image: $image"
echo "- Runtime: $version"
echo "- WFL revision: $runtime_revision"
echo "- Scriptorium: $(git rev-parse HEAD)"
echo "- Scribe: $(git -C lib/scribe rev-parse HEAD)"
echo '- Runner: blacksmith-2vcpu-ubuntu-2404 (Linux x64)'
echo '- Command: python3 scripts/run_tests.py --include-scribe'
echo '- HTTP checks: python3 -m unittest discover -s tests/integration -v'
echo '- Command: wfl --execution-timeout 1200 scripts/run_tests.wfl'
echo '- Coverage: application, ORM/migrations/recovery, HTTP integration, tooling, examples, pinned Scribe'
} | tee -a "$GITHUB_STEP_SUMMARY"

- name: Run WFL suites and HTTP configuration checks
- name: Run the complete WFL suite
shell: bash
env:
RESOLVED_IMAGE: ${{ steps.runtime.outputs.image }}
run: |
# The published image is a minimal runtime with a WFL entrypoint.
# Install Python only in this disposable container. Scribe fixtures
# go to its temporary directory; the checkout stays read-only.
# Python is only the implementation of the repository hygiene checker.
# Every scenario, fixture, assertion and test driver is WFL. A writable
# disposable copy keeps synthetic databases/Git indexes off the checkout.
docker run --rm --init --name "$TEST_CONTAINER" \
--user 0:0 --entrypoint /bin/sh \
--mount "type=bind,source=$GITHUB_WORKSPACE,target=/work,readonly" \
--mount "type=bind,source=$GITHUB_WORKSPACE,target=/source,readonly" \
--workdir /work "$RESOLVED_IMAGE" -ec '
apt-get update
apt-get install --yes --no-install-recommends python3
apt-get install --yes --no-install-recommends python3 python-is-python3 git
cp -a /source/. /work/
python3 --version
wfl --version
python3 scripts/run_tests.py --include-scribe
python3 -m unittest discover -s tests/integration -v
wfl --execution-timeout 1200 scripts/run_tests.wfl
'

- name: Clean up test container
Expand Down
7 changes: 4 additions & 3 deletions .repo-hygiene.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ allowed-files = [
"REPOSITORY_HYGIENE.md", "SECURITY.md", "main.wfl", "testing.md",
]
allowed-dirs = [
".github", "admin", "app", "docs", "lib", "scripts", "static",
".github", "admin", "app", "docs", "examples", "lib", "scripts", "static",
"TestPrograms", "tests", "themes",
]

Expand All @@ -21,8 +21,9 @@ files = [
"CONTRIBUTING.md", "GOVERNANCE.md", "LICENSE", "README.md",
"REPOSITORY_HYGIENE.md", "SECURITY.md", "main.wfl", "testing.md",
"docs/ARCHITECTURE.md", "docs/PROJECT-LAYOUT.md", "docs/THEMING.md",
"scripts/check_repo_hygiene.py", "scripts/run_tests.py",
"tests/tooling/test_repo_hygiene.py", "tests/tooling/test_run_tests.py",
"scripts/check_repo_hygiene.py", "scripts/run_tests.wfl",
"scripts/test_support.wfl", "scripts/resolve_runtime.wfl", "scripts/.wflcfg",
"tests/tooling/hygiene.test.wfl", "tests/tooling/runner.test.wfl", "tests/tooling/.wflcfg",
".github/pull_request_template.md", ".github/workflows/governance.yml",
]
# These paths must remain Git gitlinks; their contents are upstream-owned.
Expand Down
2 changes: 1 addition & 1 deletion .wflcfg
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Scriptorium configuration (WFL runtime and application settings)
timeout_seconds = 60
logging_enabled = false
execution_logging = false
debug_report_enabled = false
log_level = info

Expand Down
19 changes: 11 additions & 8 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,14 +74,17 @@ violate the standard.
- **Scribe is a submodule.** Don't edit `lib/scribe/` in place; changes go
upstream to WebFirstLanguage/Scribe, then bump via
`scripts/update-scribe.sh`.
- **Checks:** `python scripts/run_tests.py` runs every Scriptorium WFL suite;
add `--include-scribe` for dependency updates. Run
`python -m unittest discover -s tests/tooling -v` and
`python scripts/check_repo_hygiene.py` for repository tooling and hygiene.
Python 3.11+ is needed for tooling; `wfl` is needed for application tests.
The Governance workflow runs tooling tests and hygiene on Blacksmith Linux
and GitHub-hosted Windows. The WFL tests workflow runs the application and
pinned Scribe suites on Blacksmith using a freshly pulled `bsbyrdwfl/wfl:nightly` image;
- **Checks:** `wfl --execution-timeout 1200 scripts/run_tests.wfl` runs the complete suite: application,
ORM/migrations/recovery, HTTP integration, tooling, executable examples, and
pinned Scribe. `--group tooling` or `--group application` selects a focused
run. Run `python scripts/check_repo_hygiene.py` for the repository hygiene gate.
Every test, fixture, assertion, helper and driver is WFL. Python 3.11+ and Git
are required only for the hygiene checker's implementation subject. The runner
uses the WFL executable that launched it, with an optional `--wfl` override.
It needs the owned-process completion and `current_executable` runtime APIs.
Governance provisions WFL and runs tooling and hygiene on Blacksmith Linux
and GitHub-hosted Windows. WFL tests runs the complete suite on Blacksmith
using a freshly pulled `bsbyrdwfl/wfl:nightly` image;
its summary records the resolved image digest, runtime version, and source
revisions. See
[testing.md](testing.md) for commands, coverage limits, and merge evidence.
Expand Down
11 changes: 5 additions & 6 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ the baseline suites:

```sh
wfl --version
python scripts/run_tests.py
wfl --execution-timeout 1200 scripts/run_tests.wfl
```

Use `--wfl /absolute/path/to/wfl` if the interpreter is not on `PATH`; use
Expand Down Expand Up @@ -106,17 +106,16 @@ the PR:

```sh
python scripts/check_repo_hygiene.py
python -m unittest discover -s tests/tooling -v
python scripts/run_tests.py
wfl --execution-timeout 1200 scripts/run_tests.wfl
```

For a Scribe pin, rendering, or template-engine integration change, also run:
The complete command includes pinned Scribe. For a focused Scribe check, run:

```sh
python scripts/run_tests.py --include-scribe
wfl scripts/run_tests.wfl --group scribe
```

The extra suite runs the pinned Scribe tests in a temporary copy because they
The Scribe group runs the pinned tests in a temporary copy because they
write fixtures. Follow [testing.md](testing.md) for HTTP, UI, security, migration,
and recovery checks triggered by the change. Prose-only changes need relevant
link, command, and hygiene checks; they do not need invented application tests.
Expand Down
Loading
Loading