Files
thanhnvandClaude Opus 4.8 36a4812ef3 refactor(structure): promote app to repo root + remove redundant workspace cruft
Standard production layout: the OKR app (was nested under AINative_OKR_CASAN5/) is now
the repository root. No more wrapper directory.

- Promote AINative_OKR_CASAN5/* -> repo root (backend/ frontend/ packages/ apps/
  .specify/ docs/ infra/ nginx/ scripts/ + configs). Merge tool dirs: .gitea (kept the
  active deploy ci.yml, added harness-ci.yml + runbooks), .claude (agents/commands +
  launch.json), .github moved up.
- Remove redundant: 00_SUBMISSION_PACKAGE, scattered root notes (FPT_CASAN_Full.md,
  tu-tuong-casan.md, casan-tu-sinh..., casan_harness_assessment.md, source-review...,
  README_CASAN5_REFINED.md), casan-next-plans/ and optimize-docs/ (competition/planning
  artifacts — roadmap + design history preserved in git log / commit messages).
- Update all references to the old layout:
  - .gitea/workflows/{ci,harness-ci}.yml, .github/workflows/{ci,deploy}.yml:
    working-directory .; drop AINative_OKR_CASAN5/ prefix; .specify/{tests,scripts}
    -> packages/casan-harness/... (.specify/logs state kept)
  - .claude/launch.json, .gitea/*-runbook.md: path prefixes
  - CLAUDE.md, README.md: docs/input -> apps/okr/domain/input
  - policy-bundle.yaml: 8 policy paths -> packages/casan-harness/...; manifest re-signed
- secrets-scan.sh: fixture excludes -> new package/domain paths.

Full gate from the new root: PASS=64 FAIL=0 SKIP=3.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-08 13:26:36 +09:00

70 lines
2.6 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
# CASAN H1 context validator.
# Before a sub-agent trusts pipeline-context.yaml, verify every referenced
# artifact / trace file actually exists on disk, and (optionally) is not
# staler than CASAN_CONTEXT_TTL_SECONDS relative to the context file itself.
# Catches renamed/deleted/missing artifacts before they cause a silent bad read.
#
# Usage: context-validate.sh <pipeline-context.yaml>
# Exit: 0 all good, 2 a referenced path is missing, 3 a referenced path is stale.
CTX="${1:-}"
if [[ -z "$CTX" || ! -f "$CTX" ]]; then
echo "Usage: context-validate.sh <pipeline-context.yaml>" >&2
exit 64
fi
CTX_DIR="$(cd "$(dirname "$CTX")" && pwd)"
# Resolve paths relative to the repo root (3 levels up from this script).
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
source "$SCRIPT_DIR/casan-paths.sh"
PROJECT_ROOT="$CASAN_APP_ROOT"
python - "$CTX" "$PROJECT_ROOT" "${CASAN_CONTEXT_TTL_SECONDS:-0}" <<'PY'
import os, re, sys, subprocess
ctx, root, ttl = sys.argv[1], sys.argv[2], int(sys.argv[3])
ctx_mtime = os.path.getmtime(ctx)
missing, stale, checked = [], [], 0
def path_exists(p):
"""Check existence using both Python and bash (handles MSYS2/Windows path mismatch)."""
if os.path.exists(p):
return True
# On Windows+MSYS2, /tmp maps to AppData/Local/Temp but Windows Python resolves it as C:\tmp.
# Fall back to bash test for absolute paths that Python can't find.
try:
r = subprocess.run(["bash", "-c", f"test -e {repr(p)}"], capture_output=True, timeout=3)
return r.returncode == 0
except Exception:
return False
with open(ctx, encoding="utf-8") as fh:
for line in fh:
m = re.match(r"\s*(?:artifact|trace_file|path|data-model|spec|plan):\s*(\S+)", line)
if not m:
continue
ref = m.group(1).strip().strip('"').strip("'")
if ref in ("", "null", "<from", "pipeline-context>"):
continue
if "<" in ref or ref.endswith(">"):
continue # unresolved template placeholder, not a concrete path
cand = ref if os.path.isabs(ref) else os.path.join(root, ref)
checked += 1
if not path_exists(cand):
missing.append(ref)
continue
if ttl > 0 and (ctx_mtime - os.path.getmtime(cand)) > ttl:
stale.append(ref)
if missing:
sys.stderr.write("CONTEXT_INVALID missing=%d: %s\n" % (len(missing), ", ".join(missing)))
raise SystemExit(2)
if stale:
sys.stderr.write("CONTEXT_STALE stale=%d: %s\n" % (len(stale), ", ".join(stale)))
raise SystemExit(3)
print(f"CONTEXT_VALID checked={checked} all referenced artifacts present")
PY