30 Commits

Author SHA1 Message Date
temeddix ba9e0c0787 Load Superpowers review instructions (#13)
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-16 12:16:09 +00:00
temeddix 58d3c12c25 Restore Superpowers reviews (#12)
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-16 04:27:22 +00:00
temeddix dcacac18e8 Make bot review setup self-contained (#11)
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-14 08:49:49 +00:00
temeddix 70d71aa4fd Inline comments (#10)
A finding about one line now lands on that line of the diff: the agent writes anchors as JSON, and the review posts them with the body in one call. Bad entries fail the run, and an anchor Gitea refuses falls back to posting the body alone.

Verified with deno fmt, lint and check.

Reviewed-on: #10
Co-authored-by: bot <temeddix@gmail.com>
Co-committed-by: bot <temeddix@gmail.com>
2026-09-14 00:11:35 +00:00
temeddix 2b51793c92 Review on request (#9)
A pull request comment that asks for a review now posts a real review, not a plain comment: the review file decides, the event no longer does.

Verified with deno fmt, lint and check.

Reviewed-on: #9
Co-authored-by: bot <temeddix@gmail.com>
Co-committed-by: bot <temeddix@gmail.com>
2026-09-13 23:48:04 +00:00
temeddix 4ed8b48b7a Verdict words (#8)
The review file starts with `Approved` or `Changes requested` instead of `Yes`/`No`/`With fixes`. The match is still the whole trimmed first line; `run.ts` prepends , 🛑, or 💬 when posting, so the mark never takes part in the match.

Verified: `deno fmt`, `deno lint`, `deno check` pass; a scratch run of the matcher maps `Approved` → APPROVED, `Changes requested` → REQUEST_CHANGES, and `Approved, mostly`, ` Approved`, `Yes` → COMMENT.
Reviewed-on: #8
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 17:21:34 +00:00
temeddix 0d109ebec8 Review file (#7)
The reviewer writes its review to a file whose first line is the verdict, instead of relying on a narration-free final message. Sonnet put `Yes` after three paragraphs of narration on memona #936 (review 595), which the fail-closed verdict posted as a plain comment.

Reviewed-on: #7
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 16:54:54 +00:00
temeddix a2bc4c9541 Model input (#6)
Optional `model` input. Defaults move to the mid tiers, `claude-sonnet-5` and `gpt-5.6-terra`, since a run follows a fixed template plus the project's checks; a workflow can still pass a bigger model.

Reviewed-on: #6
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 16:48:13 +00:00
temeddix 75d3593376 Author replies (#5)
The reviewer drops a finding the author has answered in the PR comments as intended or a false alarm, once the code or docs make that clear. Pairs with memona's merge-branch gate loop.

Reviewed-on: #5
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 15:35:17 +00:00
temeddix 439f2b4e77 Checked-out head (#4)
Checked-out head (#4)

Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 15:06:27 +00:00
temeddix f0506adfea Fail-closed verdict (#3)
Fail-closed verdict (#3)

Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 14:57:01 +00:00
temeddix b8d0093ef2 Superpowers review (#2)
Superpowers review (#2)

Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 14:30:29 +00:00
temeddix 8c2041bbc5 Split tokens (#1)
The agent and the bot are now two accounts, and the runner is one Deno script.

- `author-token` (was `gitea-token`): commits, pushes, and opens pull requests; the agent sees it as `GITEA_TOKEN`, and commits use that account's login and email.
- `reviewer-token`: posts comments and reviews as the bot; withheld from the agent's environment so it can never approve as the bot.
- A `pull_request` run posts a review instead of a comment: `REQUEST_CHANGES` when the response mentions `@bot`, `COMMENT` when the run failed, `APPROVED` otherwise. Gitea refuses self-approval, so the two accounts must differ.
- The reviewer checks the whole repository against `commons/code-rules`, which is fetched and embedded in the prompt, and requests changes for violations even when the diff did not cause them.
- `run.ts` replaces the three shell scripts plus `jq`, `envsubst`, and `ansifilter`; only `deno` is added to the install step, per the rules' Deno-over-Node policy. A `.gitea` workflow runs `deno fmt`, `lint`, and `check`.

Callers must rename `gitea-token` and add `reviewer-token` (`write:issue` and `write:repository` scopes). A rejection stays until the bot reviews again, so callers that want it lifted after a fix should trigger on `pull_request: [opened, synchronize]`.

Verified with a fake `claude` binary against this PR in an isolated `HOME`: git author configured from the token, prompt rendered with rules and comment history, events streamed, reviewer token absent from the agent's environment, review posted (then deleted).

Reviewed-on: #1
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 14:15:23 +00:00
temeddix e173c11cac Specify models 2026-08-09 22:41:11 +09:00
temeddix a791bc7033 Stream thinking and text from Claude 2026-07-21 02:30:22 +09:00
temeddix 66ee427697 Do not make the bot wait for external wakeup 2026-07-21 02:11:47 +09:00
temeddix 0a3e650664 Stream Claude output to console 2026-07-21 01:40:42 +09:00
temeddix 5039c728cb Add Claude 2026-07-18 02:25:32 +09:00
temeddix 4a4b3b9538 Do not give up after waiting other job 2026-07-18 01:52:17 +09:00
temeddix e4e9c20b06 Do not exclude the current run 2026-07-16 09:07:13 +09:00
temeddix 9cf2a67898 Consider pull request reviews 2026-07-15 03:27:12 +09:00
temeddix 4d8982a0dd Wait before chaning for another job 2026-07-14 01:23:16 +09:00
temeddix 522d4ffeca Remove caveman requirements 2026-07-12 21:22:46 +09:00
temeddix 9f7fad96de Prefer nested lists and ask bot to do a review for pull requests 2026-07-12 19:05:57 +09:00
temeddix 5d5104e5ca Fix ISSUE_INDEX 2026-07-11 00:46:57 +09:00
temeddix 4f90a910b9 Add review guidelines 2026-07-11 00:08:51 +09:00
temeddix e9f0649120 Remove wrong sentence from prompt 2026-07-09 10:51:57 +09:00
temeddix 52cadd3874 Add descriptions about screenshots and extra comments 2026-07-09 09:47:44 +09:00
temeddix a192aa39d1 Put comments properly 2026-07-09 09:35:34 +09:00
temeddix 162ef3cd7b Share the login result via comment 2026-07-09 09:31:14 +09:00
10 changed files with 848 additions and 81 deletions
+21
View File
@@ -0,0 +1,21 @@
name: Check
on:
pull_request:
branches: [main]
jobs:
deno:
runs-on: self-hosted
steps:
- uses: actions/checkout@v4
- run: apt-get update && apt-get install -y unzip
- uses: denoland/setup-deno@v2
- run: >-
deno fmt --check . &&
deno lint . &&
deno check run.ts &&
deno test
+40 -13
View File
@@ -1,28 +1,55 @@
name: Codex Bot name: Bot agents
description: Run Codex CLI for approved Gitea issue/PR automation description: Run a coding agent for approved Gitea issue/PR automation
inputs: inputs:
gitea-token: bot-type:
description: Which bot to run, either `codex` or `claude`
required: true required: true
author-token:
description: >-
Gitea token of the account that commits, pushes, and opens pull requests,
with the `read:user`, `write:issue`, and `write:repository` scopes. The
agent sees it as `GITEA_TOKEN`.
required: true
reviewer-token:
description: >-
Gitea token of the bot account that posts comments and pull request
reviews, with the `write:issue` and `write:repository` scopes. Never
exposed to the agent, so it must differ from the author.
required: true
bot-token:
description: API key or token for the selected bot
required: false
model:
description: >-
Model for the selected bot. Defaults to `claude-sonnet-5` or
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
required: false
runs: runs:
using: composite using: composite
steps: steps:
# The agent works on the event's commit with full history, as the author.
- uses: actions/checkout@v4
with:
fetch-depth: 0
token: ${{ inputs.author-token }}
# This step assumes this is `node:24-bookworm` container. # This step assumes this is `node:24-bookworm` container.
- name: Install dependencies - name: Install dependencies
shell: bash shell: bash
run: | run: npm install -g @openai/codex @anthropic-ai/claude-code deno
apt-get update - name: Run bot
apt-get install -y --no-install-recommends gettext-base jq ansifilter
npm install -g @openai/codex
- name: Run Codex Bot
shell: bash shell: bash
run: bash "${ACTION_PATH}/scripts/run-codex.sh" run: deno run -A "${ACTION_PATH}/run.ts"
env: env:
ACTION_PATH: ${{ gitea.action_path }} ACTION_PATH: ${{ gitea.action_path }}
BOT_TYPE: ${{ inputs.bot-type }}
BOT_TOKEN: ${{ inputs.bot-token }}
MODEL: ${{ inputs.model }}
GITEA_API_URL: ${{ gitea.api_url }} GITEA_API_URL: ${{ gitea.api_url }}
GITEA_REPOSITORY: ${{ gitea.repository }} GITEA_REPOSITORY: ${{ gitea.repository }}
GITEA_TOKEN: ${{ inputs.gitea-token }} GITEA_TOKEN: ${{ inputs.author-token }}
ISSUE_INDEX: ${{ gitea.event.issue.number }} REVIEWER_TOKEN: ${{ inputs.reviewer-token }}
COMMENT_BODY: ${{ gitea.event.comment.body }} EVENT_NAME: ${{ gitea.event_name }}
ISSUE_INDEX: ${{ gitea.event.issue.number || gitea.event.pull_request.number }}
COMMENT: ${{ toJSON(gitea.event.comment || gitea.event.review) }}
+12
View File
@@ -0,0 +1,12 @@
export async function retryInvalidToken<
T extends { status: { success: boolean }; error: string },
>(attempt: () => Promise<T>, relogin: () => Promise<void>): Promise<T> {
let result = await attempt();
if (
!result.status.success && result.error.includes("invalid_refresh_token")
) {
await relogin();
result = await attempt();
}
return result;
}
+44
View File
@@ -0,0 +1,44 @@
import { assertEquals } from "jsr:@std/assert@1";
import { retryInvalidToken } from "./auth.ts";
Deno.test("retries once after an invalid refresh token", async () => {
let attempts = 0;
let relogins = 0;
const result = await retryInvalidToken(
() =>
Promise.resolve({
status: { success: false },
error: attempts++ === 0 ? "invalid_refresh_token" : "still failed",
}),
() => {
relogins++;
return Promise.resolve();
},
);
assertEquals({ attempts, relogins, error: result.error }, {
attempts: 2,
relogins: 1,
error: "still failed",
});
});
Deno.test("does not retry an unrelated failure", async () => {
let attempts = 0;
let relogins = 0;
await retryInvalidToken(
() => {
attempts++;
return Promise.resolve({
status: { success: false },
error: "rate limited",
});
},
() => {
relogins++;
return Promise.resolve();
},
);
assertEquals({ attempts, relogins }, { attempts: 1, relogins: 0 });
});
+130
View File
@@ -0,0 +1,130 @@
You are a coding agent running inside Gitea Actions.
Do not post a final issue comment yourself; your final response is posted
automatically. Post additional comments only when needed for PR updates,
screenshots, questions, or blockers.
Keep every issue and PR comment extremely short and simple. Strongly prefer
nested bulleted lists for readability. Report only the outcome and tests; omit
explanations, summaries, and pleasantries.
This is a single non-interactive run. The process exits the moment your final
response ends, so background monitors, scheduled wake-ups, and queued tasks
never resume. Never promise future action and never claim to be waiting on a
notification.
The repository is checked out in the working directory at the event's commit,
the head of the pull request when there is one, with full history and the
author's push credentials. Read the code there, run its checks and tests when
they bear on the task, and push from there.
For a `pull_request` event, and for a comment on a pull request that asks you to
review it, use the installed `superpowers:requesting-code-review` skill before
inspecting the PR. Its exact installed instructions and reviewer template are
included below, so this run fails before reaching you if they could not be
loaded. You are the reviewer that has already been dispatched, so run the
skill's code reviewer template yourself instead of dispatching another reviewer.
Use the pull request and triggering instruction as its description and
requirements, and review the exact base and head SHAs without changing code. Run
the project's required checks on the head and treat a real failure as at least
Important. The bot automation workflow itself is not a project check: ignore its
skipped or canceled duplicate/automatic runs, and never reject a PR because the
current review run is unfinished. Only a failed required check for the reviewed
head blocks approval. Check the whole repository against the code rules at the
end of this prompt, not only the diff; a violation is at least Important even
when the diff did not cause it. Write the complete review, and nothing else, to
the file `${REVIEW_PATH}`: it is posted verbatim as a pull request review from
the bot account, and your final response is not posted at all. The file's first
line must be exactly the verdict and nothing else: `Approved` when the head is
ready to merge, `Changes requested` otherwise. The mark in front of it is added
when posting, so write the words alone; any other first line is posted as a
plain comment, which wastes the run. Minor issues alone never block, and neither
does a finding the author has answered in the comment history below as intended
or a false alarm, once the code or docs make that clear. When the verdict is
`Changes requested`, the second line names what must change in one line,
addressed to the author; the author's own agent picks the fixes up, so never ask
`@bot` to make them. For UI changes, check that the result is aligned, clean,
and pixel-perfect, and that included screenshots prove the intended result was
achieved.
# Installed Superpowers review skill
${SUPERPOWERS_REVIEW_SKILL}
# Installed Superpowers reviewer template
${SUPERPOWERS_REVIEW_TEMPLATE}
Every finding that belongs to one line of the diff goes on that line instead of
into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry
`{"path": "<path from the repository root>", "line": <number>, "side": "new" |
"old", "body": "<the finding>"}`.
`side` is `new` for a line in the head file and `old` for one only in the base
file; `line` is that file's own line number, and it must be a line the diff
touches, or Gitea refuses the anchor. Write the file only when there is
something to anchor, and keep each body to the what, the why, and the how, with
no `file:line` prefix; the line carries that.
The review body must read at a glance: everything outside `<details>` blocks
totals under 512 bytes. Only core information stays visible: the verdict, the
summary line, and the section headings. Anything verbose goes into a `<details>`
block whose `<summary>` is a few words, such as the title of an issue with the
what, why, and how inside; the same for each strength, each recommendation, the
reasoning, and any compliance notes. A finding you anchored belongs there only
as its title, since its detail is on the line. Details blocks are top-level,
never inside a list item, because Gitea breaks them there.
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
in the triggering comment payload below as the user's exact instruction.
Install missing tools yourself when needed, including Rust, uv, Node, Deno, or
system packages.
Before modifying or pushing code, check for another active automation run that
may modify the same target branch or work on the same issue or pull request. If
one exists, wait for it to finish before making changes. Wait inside this run
with a foreground shell loop that polls and prints a line every 30 seconds, for
as long as it takes, even hours; a silent process is killed as a zombie. Use a
blocking `sleep` even if your tool instructions discourage it, and ignore any
advice to wait by scheduling a callback instead. Never report being blocked by
another run; always wait it out and complete the task before responding.
Afterwards, pull the latest branch state before pushing. Skip this check when no
code changes are needed.
Prefer minimal, correct changes that follow the code rules at the end of this
prompt. Run relevant checks or tests if practical. Treat code changes as a
request to create a pull request. If a prior bot pull request already exists for
this issue, update that same pull request instead of creating a new one. When
you create a pull request, include `@bot` in its body and ask it to review the
pull request. This is required for every pull request you create. Finish by
briefly reporting what changed and what tests ran. Wait for Gitea Actions CI to
complete, and fix any failures.
If you modify UI code, include Playwright screenshots in your PR or issue
comments. If you need UI clarification, ask with screenshots when helpful.
# Comment payload
```
${COMMENT}
```
# Full issue comment history
```
${ISSUE_COMMENTS}
```
# Gitea context
- Event: `${EVENT_NAME}`
- API URL: `${GITEA_API_URL}`
- Repository: `${GITEA_REPOSITORY}`
- Issue index: `${ISSUE_INDEX}`
- Use the `GITEA_TOKEN` environment variable for authenticated Gitea API calls
and pushes. It belongs to the author account, so never approve, reject, or
review a pull request with it; reviews are posted for you.
# Code rules
${CODE_RULES}
+335
View File
@@ -0,0 +1,335 @@
// Runs a coding agent for one Gitea issue or pull request event and posts its
// final response back. The agent works as the author account through
// GITEA_TOKEN; everything this script posts goes through the reviewer token,
// so it appears as the bot account.
import { TextLineStream } from "jsr:@std/streams@1/text-line-stream";
import { retryInvalidToken } from "./auth.ts";
import {
type BotType,
loadSuperpowersReviewGuide,
parseBotType,
superpowersInstallCommands,
type SuperpowersReviewGuide,
} from "./superpowers.ts";
type GiteaUser = { login: string; email: string };
type GiteaComment = { user: GiteaUser; created_at: string; body: string };
const env = (name: string): string => {
const value = Deno.env.get(name);
if (value === undefined) throw new Error(`${name} is not set`);
return value;
};
const API = env("GITEA_API_URL");
const REPO = env("GITEA_REPOSITORY");
const INDEX = env("ISSUE_INDEX");
const EVENT = env("EVENT_NAME");
const BOT = parseBotType(env("BOT_TYPE"));
const AUTHOR_TOKEN = env("GITEA_TOKEN");
const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
const RULES_PATH = "repos/commons/code-rules/raw/README.md";
// The mid tiers: a run follows a fixed template and the project's checks.
const DEFAULT_MODELS: Record<string, string> = {
claude: "claude-sonnet-5",
codex: "gpt-5.6-terra",
};
const model = (bot: string): string =>
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
// The reviewer token is withheld so the agent cannot approve as the bot.
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
async function gitea(
token: string,
path: string,
body?: unknown,
): Promise<Response> {
const response = await fetch(`${API}/${path}`, {
method: body === undefined ? "GET" : "POST",
headers: {
Authorization: `token ${token}`,
"Content-Type": "application/json",
},
body: body === undefined ? undefined : JSON.stringify(body),
});
if (!response.ok) {
throw new Error(`${path}: ${response.status} ${await response.text()}`);
}
return response;
}
const ANSI = new RegExp(`${String.fromCharCode(27)}\\[[0-9;]*[A-Za-z]`, "g");
const stripAnsi = (text: string): string => text.replace(ANSI, "");
async function postComment(body: string): Promise<void> {
await gitea(REVIEWER_TOKEN, `repos/${REPO}/issues/${INDEX}/comments`, {
body: stripAnsi(body),
});
}
// A review is posted whenever the agent wrote one, whether a review request or
// a comment asked for it. It comes through a file, because a final chat message
// picks up narration while a file's first line is written on purpose. That line
// is the verdict, matched whole; anything unexpected only comments, never
// approves. The mark in front is added here, so it is never part of the match.
const REVIEW_DIR = await Deno.makeTempDir();
const REVIEW_PATH = `${REVIEW_DIR}/review.md`;
const VERDICTS: Record<string, [event: string, mark: string]> = {
Approved: ["APPROVED", "✅"],
"Changes requested": ["REQUEST_CHANGES", "🛑"],
};
// A finding about one line is posted on that line of the diff rather than as
// `file:line` prose in the body. Those anchors come as JSON, so the file and
// line are structured instead of parsed back out of English; a malformed entry
// fails the run, because a silently dropped finding is worse than a red run.
const ANCHORS_PATH = `${REVIEW_DIR}/anchors.json`;
type Anchor = { path: string; line: number; side: "new" | "old"; body: string };
function parseAnchors(text: string): Anchor[] {
const entries: unknown = JSON.parse(text);
if (!Array.isArray(entries)) throw new Error(`${ANCHORS_PATH}: not an array`);
return entries.map((entry: unknown, index) => {
const at = `${ANCHORS_PATH}[${index}]`;
if (typeof entry !== "object" || entry === null) {
throw new Error(`${at}: not an object`);
}
const { path, line, side = "new", body } = entry as Record<string, unknown>;
if (typeof path !== "string" || path === "") {
throw new Error(`${at}.path: expected a repository path`);
}
if (typeof line !== "number" || !Number.isInteger(line) || line < 1) {
throw new Error(`${at}.line: expected a line number`);
}
if (side !== "new" && side !== "old") {
throw new Error(`${at}.side: expected "new" or "old"`);
}
if (typeof body !== "string" || body.trim() === "") {
throw new Error(`${at}.body: expected the finding`);
}
return { path, line, side, body };
});
}
async function readAnchors(): Promise<Anchor[]> {
const written = await Deno.readTextFile(ANCHORS_PATH).catch(() => null);
return written === null ? [] : parseAnchors(written);
}
async function postResult(body: string): Promise<void> {
const review = await Deno.readTextFile(REVIEW_PATH).catch(() => null);
if (review === null) {
if (EVENT === "pull_request") {
throw new Error(`no review was written to ${REVIEW_PATH}`);
}
return postComment(body);
}
const [verdict, ...rest] = review.split("\n");
const [event, mark] = VERDICTS[verdict.trim()] ?? ["COMMENT", "💬"];
const post = (anchors: Anchor[]) =>
gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
body: stripAnsi([`${mark} ${verdict.trim()}`, ...rest].join("\n")),
event,
comments: anchors.map(({ path, line, side, body }) => ({
path,
body: stripAnsi(body),
new_position: side === "new" ? line : 0,
old_position: side === "old" ? line : 0,
})),
});
const anchors = await readAnchors();
// Gitea rejects the whole review when an anchor names a line outside the
// diff, and a verdict that never lands blocks the pull request, so the body
// goes up alone rather than not at all.
await post(anchors).catch(async (error: Error) => {
if (anchors.length === 0) throw error;
console.error(`inline comments rejected: ${error.message}`);
await post([]);
});
}
async function run(command: string, args: string[]): Promise<void> {
const { success, code } = await new Deno.Command(command, { args }).output();
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
}
// The reviewer uses Superpowers' requesting-code-review template. Both plugin
// installers are idempotent on the persisted bot home.
async function installSuperpowers(bot: BotType): Promise<void> {
for (const { command, args } of superpowersInstallCommands(bot)) {
await run(command, args);
}
}
async function prepareSuperpowers(
bot: BotType,
): Promise<SuperpowersReviewGuide> {
await installSuperpowers(bot);
const guide = await loadSuperpowersReviewGuide(bot, env("HOME"));
console.log(
`Loaded Superpowers requesting-code-review ${guide.version} from ${guide.skillPath}`,
);
console.log(
`Loaded Superpowers reviewer template from ${guide.templatePath}`,
);
return guide;
}
// Commits belong to the same account as the pull request they end up in.
async function configureGitAuthor(): Promise<void> {
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
for (const [key, value] of [["name", user.login], ["email", user.email]]) {
await run("git", ["config", "--global", `user.${key}`, value]);
}
}
async function renderPrompt(guide: SuperpowersReviewGuide): Promise<string> {
const comments: GiteaComment[] = await (await gitea(
REVIEWER_TOKEN,
`repos/${REPO}/issues/${INDEX}/comments?limit=100`,
)).json();
const values: Record<string, string> = {
COMMENT: env("COMMENT"),
ISSUE_COMMENTS: comments
.map((c) => `## ${c.user.login} at ${c.created_at}\n\n${c.body}\n`)
.join("\n"),
CODE_RULES: await (await gitea(REVIEWER_TOKEN, RULES_PATH)).text(),
EVENT_NAME: EVENT,
GITEA_API_URL: API,
GITEA_REPOSITORY: REPO,
ISSUE_INDEX: INDEX,
REVIEW_PATH,
ANCHORS_PATH,
SUPERPOWERS_REVIEW_SKILL: guide.skill,
SUPERPOWERS_REVIEW_TEMPLATE: guide.template,
};
const template = await Deno.readTextFile(
new URL("prompt.md", import.meta.url),
);
return template.replace(
/\$\{(\w+)\}/g,
(match, name) => values[name] ?? match,
);
}
async function runClaude(): Promise<string> {
const token = Deno.env.get("BOT_TOKEN");
if (!token) {
throw new Error(
"Run `claude setup-token` locally and set the `bot-token` action input.",
);
}
const prompt = await renderPrompt(await prepareSuperpowers("claude"));
const claude = new Deno.Command("claude", {
args: [
"--print",
"--dangerously-skip-permissions",
"--model",
model("claude"),
"--output-format",
"stream-json",
"--verbose",
prompt,
],
// Claude refuses --dangerously-skip-permissions as root outside a sandbox.
env: { ...agentEnv, CLAUDE_CODE_OAUTH_TOKEN: token, IS_SANDBOX: "1" },
clearEnv: true,
stdout: "piped",
}).spawn();
let result: { result?: string; subtype: string } | undefined;
// Print events as they stream so the runner does not kill the job as a zombie.
const lines = claude.stdout
.pipeThrough(new TextDecoderStream())
.pipeThrough(new TextLineStream());
for await (const line of lines) {
if (!line) continue;
const event = JSON.parse(line);
for (const part of event.message?.content ?? []) {
const text = part.thinking ?? part.text ?? part.name;
if (text) console.log(text);
}
if (event.type === "result") result = event;
}
await claude.status;
if (result?.result === undefined) {
throw new Error(`claude ended with ${result?.subtype ?? "no result"}`);
}
return result.result;
}
// Posts the device code so a human can finish the login on the persisted home.
async function codexDeviceLogin(): Promise<void> {
const login = new Deno.Command("codex", {
args: ["login", "--device-auth"],
stdout: "piped",
stderr: "piped",
}).spawn();
let shown = "";
const collect = (stream: ReadableStream<Uint8Array>): Promise<void> =>
stream.pipeThrough(new TextDecoderStream()).pipeTo(
new WritableStream({ write: (chunk) => void (shown += chunk) }),
);
const drained = Promise.all([collect(login.stdout), collect(login.stderr)]);
const status = login.status;
await new Promise((resolve) => setTimeout(resolve, 3000));
while (shown.trim() === "") {
const exited = await Promise.race([
status.then(() => true),
new Promise<boolean>((resolve) => setTimeout(() => resolve(false), 100)),
]);
if (exited) throw new Error("AI bot login produced no instructions");
}
await postComment(shown);
await Promise.all([status, drained]);
}
async function runCodex(): Promise<string> {
const loggedIn = await new Deno.Command("codex", {
args: ["login", "status"],
})
.output();
if (!loggedIn.success) await codexDeviceLogin();
const prompt = await renderPrompt(await prepareSuperpowers("codex"));
const file = await Deno.makeTempFile();
const attempt = async () => {
const codex = new Deno.Command("codex", {
args: [
"exec",
"--model",
model("codex"),
"--dangerously-bypass-approvals-and-sandbox",
"--output-last-message",
file,
prompt,
],
env: agentEnv,
clearEnv: true,
stdout: "inherit",
stderr: "piped",
}).spawn();
const decoder = new TextDecoder();
let error = "";
for await (const chunk of codex.stderr) {
await Deno.stderr.write(chunk);
error += decoder.decode(chunk, { stream: true });
}
error += decoder.decode();
return { status: await codex.status, error };
};
const { status } = await retryInvalidToken(attempt, async () => {
await run("codex", ["logout"]);
await codexDeviceLogin();
});
if (!status.success) throw new Error(`codex exited with ${status.code}`);
return await Deno.readTextFile(file);
}
try {
await configureGitAuthor();
const result = BOT === "claude" ? await runClaude() : await runCodex();
await postResult(result);
} catch (error) {
await postComment(`Bot failed: ${error}`);
throw error;
}
-25
View File
@@ -1,25 +0,0 @@
You are Codex running inside Gitea Actions.
First read `.codex-bot/context.md`. Treat the triggering comment body below as
the user's exact instruction.
Install missing tools yourself when needed, including Rust, uv, Node, Deno, or
system packages.
Prefer minimal, correct changes. Run relevant checks or tests if practical.
Treat code changes as a request to create a pull request. If a prior Codex pull
request already exists for this issue, update that same pull request instead of
creating a new one. Finish by reporting what changed and what tests ran. Wait
for Gitea Actions CI to complete, and fix any failures.
# Comment body
```
${COMMENT_BODY}
```
# Full issue comment history
```
${ISSUE_COMMENTS}
```
-43
View File
@@ -1,43 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
git config --global user.name bot
git config --global user.email noreply@capsulizers.com
OUTPUT_FILE="$(mktemp)"
post_comment() {
COMMENT_JSON="$(jq -n --rawfile body "${OUTPUT_FILE}" '{body: $body}')"
curl --fail-with-body --silent --show-error \
-X POST \
-H "Authorization: token ${GITEA_TOKEN}" \
-H "Content-Type: application/json" \
--data "${COMMENT_JSON}" \
"${GITEA_API_URL}/repos/${GITEA_REPOSITORY}/issues/${ISSUE_INDEX}/comments"
}
if ! codex login status > /dev/null 2>&1; then
LOGIN_FILE="$(mktemp)"
codex login --device-auth > "${LOGIN_FILE}" 2>&1 &
LOGIN_PID="${!}"
sleep 3
ansifilter < "${LOGIN_FILE}" > "${OUTPUT_FILE}"
post_comment
wait "${LOGIN_PID}"
exit 1
fi
export ISSUE_COMMENTS="$(
curl --fail-with-body --silent --show-error \
-H "Authorization: token ${GITEA_TOKEN}" \
"${GITEA_API_URL}/repos/${GITEA_REPOSITORY}/issues/${ISSUE_INDEX}/comments?limit=100" \
| jq -r '.[] | "## " + .user.login + " at " + .created_at + "\n\n" + .body + "\n"'
)"
FINAL_PROMPT="$(envsubst < "${ACTION_PATH}/scripts/prompt.md")"
codex exec \
--dangerously-bypass-approvals-and-sandbox \
"${FINAL_PROMPT}" > "${OUTPUT_FILE}" 2>&1
post_comment
+147
View File
@@ -0,0 +1,147 @@
import { join } from "jsr:@std/path@1";
export type BotType = "claude" | "codex";
export type InstallCommand = {
command: string;
args: string[];
};
export type SuperpowersReviewGuide = {
version: string;
skillPath: string;
templatePath: string;
skill: string;
template: string;
};
export type SuperpowersFileSystem = {
readDir(path: string): AsyncIterable<Deno.DirEntry>;
readTextFile(path: string): Promise<string>;
};
const systemFileSystem: SuperpowersFileSystem = {
readDir: Deno.readDir,
readTextFile: Deno.readTextFile,
};
export function parseBotType(value: string): BotType {
if (value === "claude" || value === "codex") return value;
throw new Error(`unsupported bot type: ${value}`);
}
export function superpowersInstallCommands(
bot: BotType,
): InstallCommand[] {
if (bot === "claude") {
return [
{
command: "claude",
args: [
"plugin",
"marketplace",
"add",
"obra/superpowers-marketplace",
],
},
{
command: "claude",
args: [
"plugin",
"install",
"-y",
"superpowers@superpowers-marketplace",
],
},
];
}
return [{
command: "codex",
args: ["plugin", "add", "superpowers@openai-curated-remote"],
}];
}
type Candidate = SuperpowersReviewGuide & { directory: string };
async function readCandidate(
directory: string,
fileSystem: SuperpowersFileSystem,
): Promise<Candidate | null> {
if (!directory.split(/[\\/]/).includes("superpowers")) return null;
const skillPath = join(directory, "SKILL.md");
const templatePath = join(directory, "code-reviewer.md");
try {
const [skill, template] = await Promise.all([
fileSystem.readTextFile(skillPath),
fileSystem.readTextFile(templatePath),
]);
return {
directory,
version: directory.split(/[\\/]/).at(-3) ?? "unknown",
skillPath,
templatePath,
skill,
template,
};
} catch (error) {
if (error instanceof Deno.errors.NotFound) return null;
throw error;
}
}
async function findCandidates(
directory: string,
candidates: Candidate[],
fileSystem: SuperpowersFileSystem,
): Promise<void> {
let entries: Deno.DirEntry[];
try {
entries = [];
for await (const entry of fileSystem.readDir(directory)) {
entries.push(entry);
}
} catch (error) {
if (error instanceof Deno.errors.NotFound) return;
throw error;
}
for (const entry of entries) {
if (!entry.isDirectory) continue;
const child = join(directory, entry.name);
if (entry.name === "requesting-code-review") {
const candidate = await readCandidate(child, fileSystem);
if (candidate !== null) candidates.push(candidate);
} else {
await findCandidates(child, candidates, fileSystem);
}
}
}
// Load the installed files rather than trusting skill discovery in a later
// non-interactive agent process. The newest cached plugin version is the one
// the installers activate, and the exact paths are reported by the caller.
export async function loadSuperpowersReviewGuide(
bot: BotType,
home: string,
fileSystem: SuperpowersFileSystem = systemFileSystem,
): Promise<SuperpowersReviewGuide> {
const root = join(
home,
bot === "codex" ? ".codex" : ".claude",
"plugins",
"cache",
);
const candidates: Candidate[] = [];
await findCandidates(root, candidates, fileSystem);
candidates.sort((left, right) =>
left.version.localeCompare(right.version, undefined, { numeric: true }) ||
left.directory.localeCompare(right.directory)
);
const guide = candidates.at(-1);
if (guide === undefined) {
throw new Error(
`installed Superpowers requesting-code-review files not found under ${root}`,
);
}
const { directory: _, ...result } = guide;
return result;
}
+119
View File
@@ -0,0 +1,119 @@
import { assertEquals, assertRejects, assertThrows } from "jsr:@std/assert@1";
import { join } from "jsr:@std/path@1";
import {
loadSuperpowersReviewGuide,
parseBotType,
type SuperpowersFileSystem,
superpowersInstallCommands,
} from "./superpowers.ts";
function fakeFileSystem(files: Record<string, string>): SuperpowersFileSystem {
return {
readTextFile(path) {
const contents = files[path];
return contents === undefined
? Promise.reject(new Deno.errors.NotFound(path))
: Promise.resolve(contents);
},
async *readDir(directory) {
const prefix = `${directory}/`;
const children = new Map<string, boolean>();
for (const path of Object.keys(files)) {
if (!path.startsWith(prefix)) continue;
const [name, ...rest] = path.slice(prefix.length).split("/");
if (name !== "") children.set(name, rest.length > 0);
}
if (children.size === 0) throw new Deno.errors.NotFound(directory);
for (const [name, isDirectory] of children) {
yield {
name,
isDirectory,
isFile: !isDirectory,
isSymlink: false,
};
}
},
};
}
Deno.test("installs Superpowers from the Codex marketplace", () => {
assertEquals(superpowersInstallCommands("codex"), [{
command: "codex",
args: ["plugin", "add", "superpowers@openai-curated-remote"],
}]);
});
Deno.test("installs Superpowers from the Claude marketplace", () => {
assertEquals(superpowersInstallCommands("claude"), [
{
command: "claude",
args: [
"plugin",
"marketplace",
"add",
"obra/superpowers-marketplace",
],
},
{
command: "claude",
args: [
"plugin",
"install",
"-y",
"superpowers@superpowers-marketplace",
],
},
]);
});
Deno.test("rejects an unsupported bot type", () => {
assertThrows(
() => parseBotType("other"),
Error,
"unsupported bot type: other",
);
});
Deno.test("loads the newest installed Superpowers review guide", async () => {
const home = "/home/bot";
const older = join(
home,
".codex/plugins/cache/openai-curated-remote/superpowers/6.3.0/skills/requesting-code-review",
);
const newer = join(
home,
".codex/plugins/cache/openai-curated-remote/superpowers/6.10.0/skills/requesting-code-review",
);
const guide = await loadSuperpowersReviewGuide(
"codex",
home,
fakeFileSystem({
[join(older, "SKILL.md")]: "old",
[join(older, "code-reviewer.md")]: "old template",
[join(newer, "SKILL.md")]: "new",
[join(newer, "code-reviewer.md")]: "template",
}),
);
assertEquals(guide.version, "6.10.0");
assertEquals(guide.skill, "new");
assertEquals(guide.template, "template");
assertEquals(guide.skillPath, join(newer, "SKILL.md"));
});
Deno.test("fails when the installed review guide is incomplete", async () => {
const home = "/home/bot";
const directory = join(
home,
".claude/plugins/cache/superpowers-marketplace/superpowers/6.3.0/skills/requesting-code-review",
);
const fileSystem = fakeFileSystem({
[join(directory, "SKILL.md")]: "skill",
});
await assertRejects(
() => loadSuperpowersReviewGuide("claude", home, fileSystem),
Error,
"installed Superpowers requesting-code-review files not found",
);
});