mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 21:36:24 +00:00
6fb26115ce
Phase 2 configures forge for the agents (operator only sets a credential_ref + optional version pin) and lets them drive a junior→senior→deploy workflow: - Credential resolution/injection (control/credentials.py): credential_ref pointers (env:/file:/cmd:) resolved only at spawn, injected as FORGE_TOKEN + host var, with a forge-host-scoped git credential helper reading the token from env (never on disk / in the DB). Resolution is a fail-fast spawn gate. - Role-based forge skills committed into the managed repo (control/skills_gen.py, `handler forge-init`): forge-junior/senior/deploy + a workflow overview. - Hard approval gate (hooks/gate.py, approvals table, migration 0002): merge/deploy — and direct pushes to protected branches — are denied unless a DIFFERENT agent has an `approved` record for the branch, pinned to the reviewed commit (approved_sha). Senior records verdicts via `handler approve`/`reject`. - forge/git seams (control/forge.py, control/gitops.py) matching the Phase 1 seam pattern. - CI status poller (control/poller.py, `handler poll-ci [--watch]`) backfilling ci_status/ci_checked_at via `forge ci list`. - Fix: migrations/env.py commits explicitly after run_migrations — pysqlite on Py 3.12+ was rolling back the final migration's DDL + alembic_version stamp (latent in Phase 1). Reviewed via a separate code-reviewer pass; gate-bypass and credential-scoping findings addressed. 106 tests, ruff clean, verified end-to-end against real git + migrations.
33 lines
1.1 KiB
Python
33 lines
1.1 KiB
Python
"""Role-based forge skills generation (committed into the managed repo)."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from handler.control import skills_gen
|
|
|
|
|
|
def test_skill_files_cover_every_role():
|
|
files = skills_gen.skill_files()
|
|
paths = set(files)
|
|
for role in ("forge-workflow", "forge-junior", "forge-senior", "forge-deploy"):
|
|
assert f".claude/skills/{role}/SKILL.md" in paths
|
|
|
|
|
|
def test_skill_files_have_frontmatter():
|
|
for _, contents in skills_gen.skill_files().items():
|
|
assert contents.startswith("---\nname: ")
|
|
assert "description:" in contents
|
|
|
|
|
|
def test_senior_skill_references_the_approval_command():
|
|
senior = skills_gen.skill_files()[".claude/skills/forge-senior/SKILL.md"]
|
|
assert "handler approve" in senior
|
|
assert "handler reject" in senior
|
|
|
|
|
|
def test_write_skills_materializes_files(tmp_path):
|
|
written = skills_gen.write_skills(str(tmp_path))
|
|
assert len(written) == 4
|
|
junior = tmp_path / ".claude" / "skills" / "forge-junior" / "SKILL.md"
|
|
assert junior.exists()
|
|
assert "junior developer" in junior.read_text()
|