23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
174 lines
8.2 KiB
YAML
174 lines
8.2 KiB
YAML
# ADR-164 architectural constraint enforcement.
|
|
#
|
|
# "Ruflo remains operational if the agentbbs package is removed."
|
|
#
|
|
# This workflow asserts three architectural rules from ADR-164 §5.1.1:
|
|
# 1. agentbbs lives in `optionalDependencies`, NEVER `dependencies`
|
|
# 2. Every code path that touches agentbbs in v3/@claude-flow/cli/src/
|
|
# is preceded by `loadAgentbbs()` (or a dynamic `import('agentbbs')`)
|
|
# 3. Runtime drill: with `--no-optional` / unreachable registry, the smoke
|
|
# contract exits 0 (graceful degradation).
|
|
#
|
|
# If this job ever fails, an agentbbs API has accidentally been promoted to
|
|
# a hard runtime requirement — breaking the optional-dep playbook from
|
|
# ADR-150 / agenticow / metaharness. The fix is either to make the new code
|
|
# path graceful, or to write a new ADR that supersedes the constraint.
|
|
name: no-agentbbs-smoke
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- 'plugins/ruflo-bbs-federation/**'
|
|
- 'v3/@claude-flow/cli/src/mcp-tools/agentbbs-tools.ts'
|
|
- 'v3/@claude-flow/cli/src/mcp-client.ts'
|
|
- 'v3/@claude-flow/cli/src/mcp-tools/index.ts'
|
|
- 'v3/@claude-flow/cli/package.json'
|
|
- 'scripts/smoke-agentbbs.sh'
|
|
- '.github/workflows/no-agentbbs-smoke.yml'
|
|
pull_request:
|
|
paths:
|
|
- 'plugins/ruflo-bbs-federation/**'
|
|
- 'v3/@claude-flow/cli/src/mcp-tools/agentbbs-tools.ts'
|
|
- 'v3/@claude-flow/cli/src/mcp-client.ts'
|
|
- 'v3/@claude-flow/cli/src/mcp-tools/index.ts'
|
|
- 'v3/@claude-flow/cli/package.json'
|
|
- 'scripts/smoke-agentbbs.sh'
|
|
- '.github/workflows/no-agentbbs-smoke.yml'
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
smoke-without-agentbbs:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
|
|
- name: Rule 1 — agentbbs must NOT appear in non-optional dependencies anywhere
|
|
# Static check: every package.json that could carry the dep must list
|
|
# agentbbs only under optionalDependencies. If it appears in
|
|
# `dependencies` anywhere, we've broken the architectural constraint.
|
|
run: |
|
|
node -e "
|
|
const { readFileSync, readdirSync, statSync } = require('fs');
|
|
const { join } = require('path');
|
|
const candidates = [
|
|
'package.json',
|
|
'ruflo/package.json',
|
|
'v3/@claude-flow/cli/package.json',
|
|
];
|
|
try {
|
|
for (const p of readdirSync('plugins')) {
|
|
const pj = join('plugins', p, 'package.json');
|
|
try { statSync(pj); candidates.push(pj); } catch {}
|
|
}
|
|
} catch {}
|
|
const offenders = [];
|
|
for (const c of candidates) {
|
|
let json;
|
|
try { json = JSON.parse(readFileSync(c, 'utf-8')); } catch { continue; }
|
|
for (const dep of Object.keys(json.dependencies || {})) {
|
|
if (/^agentbbs$/.test(dep)) {
|
|
offenders.push({ file: c, dep });
|
|
}
|
|
}
|
|
}
|
|
if (offenders.length) {
|
|
console.error('ADR-164 architectural constraint violated:');
|
|
for (const o of offenders) console.error(' ' + o.file + ' → ' + o.dep + ' in dependencies (must be optionalDependencies)');
|
|
process.exit(1);
|
|
}
|
|
console.log('OK — agentbbs is not in non-optional dependencies anywhere.');
|
|
"
|
|
|
|
- name: Rule 2 — every `agentbbs` usage in cli/src must be guarded by loadAgentbbs / dynamic import
|
|
# Walk every .ts under v3/@claude-flow/cli/src that mentions agentbbs.
|
|
# For each match, the SAME file must also reference loadAgentbbs() OR
|
|
# use a dynamic import('agentbbs'). Static `import ... from 'agentbbs'`
|
|
# is forbidden — it would make the dep mandatory.
|
|
run: |
|
|
node -e "
|
|
const { readFileSync, readdirSync, statSync } = require('fs');
|
|
const { join } = require('path');
|
|
const root = 'v3/@claude-flow/cli/src';
|
|
const offenders = [];
|
|
function walk(dir) {
|
|
for (const e of readdirSync(dir)) {
|
|
const p = join(dir, e);
|
|
const st = statSync(p);
|
|
if (st.isDirectory()) { walk(p); continue; }
|
|
if (!p.endsWith('.ts')) continue;
|
|
const src = readFileSync(p, 'utf-8');
|
|
// Static import — forbidden:
|
|
if (/^\s*import\s+[^;]*from\s+['\"]agentbbs['\"]/m.test(src)) {
|
|
offenders.push({ file: p, reason: 'static import of agentbbs' });
|
|
continue;
|
|
}
|
|
// If file mentions agentbbs at all, require a guard — except
|
|
// for files that ONLY re-export our own agentbbsTools symbol
|
|
// (the symbol itself contains the loadAgentbbs guard).
|
|
if (/agentbbs/.test(src)) {
|
|
// Strip benign re-exports + comment mentions, then check the rest.
|
|
// Patterns we treat as safe (do not require their own loadAgentbbs guard):
|
|
// - `export { agentbbsTools } from './agentbbs-tools.js';`
|
|
// - `import { agentbbsTools } from './mcp-tools/agentbbs-tools.js';`
|
|
// - `...agentbbsTools,`
|
|
// - any comment line mentioning agentbbs
|
|
const stripped = src
|
|
.replace(/^\s*\/\/.*$/gm, '') // single-line comments
|
|
.replace(/\/\*[\s\S]*?\*\//g, '') // block comments
|
|
.replace(/export\s+\{[^}]*agentbbsTools[^}]*\}\s+from\s+['\"][^'\"]+agentbbs-tools[^'\"]*['\"];?/g, '')
|
|
.replace(/import\s+\{[^}]*agentbbsTools[^}]*\}\s+from\s+['\"][^'\"]+agentbbs-tools[^'\"]*['\"];?/g, '')
|
|
.replace(/\.\.\.agentbbsTools,?/g, '');
|
|
if (/agentbbs/.test(stripped)) {
|
|
const guarded = /loadAgentbbs|import\(['\"]agentbbs['\"]\)/m.test(src);
|
|
if (!guarded) {
|
|
offenders.push({ file: p, reason: 'agentbbs reference without loadAgentbbs/dynamic import guard' });
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|
|
walk(root);
|
|
if (offenders.length) {
|
|
console.error('ADR-164 rule 2 violated:');
|
|
for (const o of offenders) console.error(' ' + o.file + ': ' + o.reason);
|
|
process.exit(1);
|
|
}
|
|
console.log('OK — every agentbbs reference under ' + root + ' is dynamically guarded.');
|
|
"
|
|
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 8
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '20'
|
|
cache: 'pnpm'
|
|
cache-dependency-path: v3/pnpm-lock.yaml
|
|
|
|
- name: Rule 3 — runtime drill (surgically remove agentbbs only, run smoke)
|
|
# Install everything (so other optional deps like agentdb stay available
|
|
# for transitive consumers — they have their own degradation paths)
|
|
# but DELETE node_modules/agentbbs to force loadAgentbbs() to return null.
|
|
# smoke-agentbbs.sh accepts DEGRADED:agentbbs-not-found as a PASS for
|
|
# step 8, so the whole script should still exit 0.
|
|
# Uses pnpm (the v3/ workspace's real package manager) since some root
|
|
# deps use the `workspace:*` protocol that npm doesn't support.
|
|
run: |
|
|
set -e
|
|
(cd v3 && pnpm install --frozen-lockfile)
|
|
# Build whole workspace dep-first (cli has cross-package deps the
|
|
# `...` filter can't discover from package.json alone)
|
|
(cd v3 && pnpm -r --no-bail build || pnpm --filter @claude-flow/cli build)
|
|
# Surgically remove agentbbs from every install location it landed.
|
|
find v3 -type d -name agentbbs -path '*node_modules*' -exec rm -rf {} + 2>/dev/null || true
|
|
# Sanity check — the package really is gone
|
|
if find v3 -type d -name agentbbs -path '*node_modules*' 2>/dev/null | grep -q . ; then
|
|
echo "ERROR: agentbbs still in node_modules"; exit 1
|
|
fi
|
|
bash scripts/smoke-agentbbs.sh
|