Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 6f782c35ef | |||
| c637553b5f | |||
| 743c60e8a5 | |||
| 419439baf6 | |||
| 70d71aa4fd | |||
| 2b51793c92 | |||
| 4ed8b48b7a | |||
| 0d109ebec8 |
@@ -0,0 +1,12 @@
|
|||||||
|
export async function retryInvalidToken<
|
||||||
|
T extends { status: { success: boolean }; error: string },
|
||||||
|
>(attempt: () => Promise<T>, relogin: () => Promise<void>): Promise<T> {
|
||||||
|
let result = await attempt();
|
||||||
|
if (
|
||||||
|
!result.status.success && result.error.includes("invalid_refresh_token")
|
||||||
|
) {
|
||||||
|
await relogin();
|
||||||
|
result = await attempt();
|
||||||
|
}
|
||||||
|
return result;
|
||||||
|
}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
import { assertEquals } from "jsr:@std/assert@1";
|
||||||
|
import { retryInvalidToken } from "./auth.ts";
|
||||||
|
|
||||||
|
Deno.test("retries once after an invalid refresh token", async () => {
|
||||||
|
let attempts = 0;
|
||||||
|
let relogins = 0;
|
||||||
|
const result = await retryInvalidToken(
|
||||||
|
() =>
|
||||||
|
Promise.resolve({
|
||||||
|
status: { success: false },
|
||||||
|
error: attempts++ === 0 ? "invalid_refresh_token" : "still failed",
|
||||||
|
}),
|
||||||
|
() => {
|
||||||
|
relogins++;
|
||||||
|
return Promise.resolve();
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
assertEquals({ attempts, relogins, error: result.error }, {
|
||||||
|
attempts: 2,
|
||||||
|
relogins: 1,
|
||||||
|
error: "still failed",
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
Deno.test("does not retry an unrelated failure", async () => {
|
||||||
|
let attempts = 0;
|
||||||
|
let relogins = 0;
|
||||||
|
await retryInvalidToken(
|
||||||
|
() => {
|
||||||
|
attempts++;
|
||||||
|
return Promise.resolve({
|
||||||
|
status: { success: false },
|
||||||
|
error: "rate limited",
|
||||||
|
});
|
||||||
|
},
|
||||||
|
() => {
|
||||||
|
relogins++;
|
||||||
|
return Promise.resolve();
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
assertEquals({ attempts, relogins }, { attempts: 1, relogins: 0 });
|
||||||
|
});
|
||||||
@@ -18,34 +18,44 @@ the head of the pull request when there is one, with full history and the
|
|||||||
author's push credentials. Read the code there, run its checks and tests when
|
author's push credentials. Read the code there, run its checks and tests when
|
||||||
they bear on the task, and push from there.
|
they bear on the task, and push from there.
|
||||||
|
|
||||||
For a `pull_request` event, review the PR without changing code, using the
|
For a `pull_request` event, and for a comment on a pull request that asks you to
|
||||||
`requesting-code-review` skill from superpowers: run its code reviewer template
|
review it, review the PR without changing code against its base and head. Run
|
||||||
against the PR's base and head, and make its complete output your final response
|
the project's checks on the head and treat a failure as at least Important.
|
||||||
instead of the short comment style above. Run the project's checks on the head
|
Check the whole repository against the code rules at the end of this prompt, not
|
||||||
and treat a failure as at least Important. Check the whole repository against
|
only the diff; a violation is at least Important even when the diff did not
|
||||||
the code rules at the end of this prompt, not only the diff; a violation is at
|
cause it. Write the complete review, and nothing else, to the file
|
||||||
least Important even when the diff did not cause it. Your final response is
|
`${REVIEW_PATH}`: it is posted verbatim as a pull request review from the bot
|
||||||
posted verbatim as a pull request review from the bot account, so it is the
|
account, and your final response is not posted at all. The file's first line
|
||||||
review text and nothing else: no narration about what you did, verified, or are
|
must be exactly the verdict and nothing else: `Approved` when the head is ready
|
||||||
about to post, whether you reviewed yourself or relayed a reviewer subagent. Its
|
to merge, `Changes requested` otherwise. The mark in front of it is added when
|
||||||
first line must be exactly the template's verdict and nothing else: `Yes`, `No`,
|
posting, so write the words alone; any other first line is posted as a plain
|
||||||
or `With fixes`. `Yes` approves and the other two request changes; any other
|
comment, which wastes the run. Minor issues alone never block, and neither does
|
||||||
first line is posted as a plain comment, which wastes the run. Minor issues
|
a finding the author has answered in the comment history below as intended or a
|
||||||
alone never block, and neither does a finding the author has answered in the
|
false alarm, once the code or docs make that clear. When the verdict is
|
||||||
comment history below as intended or a false alarm, once the code or docs make
|
`Changes requested`, the second line names what must change in one line,
|
||||||
that clear. When the verdict is not `Yes`, the second line names what must
|
addressed to the author; the author's own agent picks the fixes up, so never ask
|
||||||
change in one line, addressed to the author; the author's own agent picks the
|
`@bot` to make them. For UI changes, check that the result is aligned, clean,
|
||||||
fixes up, so never ask `@bot` to make them. For UI changes, check that the
|
and pixel-perfect, and that included screenshots prove the intended result was
|
||||||
result is aligned, clean, and pixel-perfect, and that included screenshots prove
|
achieved.
|
||||||
the intended result was achieved.
|
|
||||||
|
|
||||||
The review must read at a glance: everything outside `<details>` blocks totals
|
Every finding that belongs to one line of the diff goes on that line instead of
|
||||||
under 512 bytes. Only core information stays visible: the verdict, the summary
|
into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry
|
||||||
line, and the section headings. Anything verbose goes into a `<details>` block
|
`{"path": "<path from the repository root>", "line": <number>, "side": "new" |
|
||||||
whose `<summary>` is a few words, such as the `file:line` and title of an issue
|
"old", "body": "<the finding>"}`.
|
||||||
with the what, why, and how inside; the same for each strength, each
|
`side` is `new` for a line in the head file and `old` for one only in the base
|
||||||
recommendation, the reasoning, and any compliance notes. Details blocks are
|
file; `line` is that file's own line number, and it must be a line the diff
|
||||||
top-level, never inside a list item, because Gitea breaks them there.
|
touches, or Gitea refuses the anchor. Write the file only when there is
|
||||||
|
something to anchor, and keep each body to the what, the why, and the how, with
|
||||||
|
no `file:line` prefix; the line carries that.
|
||||||
|
|
||||||
|
The review body must read at a glance: everything outside `<details>` blocks
|
||||||
|
totals under 512 bytes. Only core information stays visible: the verdict, the
|
||||||
|
summary line, and the section headings. Anything verbose goes into a `<details>`
|
||||||
|
block whose `<summary>` is a few words, such as the title of an issue with the
|
||||||
|
what, why, and how inside; the same for each strength, each recommendation, the
|
||||||
|
reasoning, and any compliance notes. A finding you anchored belongs there only
|
||||||
|
as its title, since its detail is on the line. Details blocks are top-level,
|
||||||
|
never inside a list item, because Gitea breaks them there.
|
||||||
|
|
||||||
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
||||||
in the triggering comment payload below as the user's exact instruction.
|
in the triggering comment payload below as the user's exact instruction.
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
// GITEA_TOKEN; everything this script posts goes through the reviewer token,
|
// GITEA_TOKEN; everything this script posts goes through the reviewer token,
|
||||||
// so it appears as the bot account.
|
// so it appears as the bot account.
|
||||||
import { TextLineStream } from "jsr:@std/streams@1/text-line-stream";
|
import { TextLineStream } from "jsr:@std/streams@1/text-line-stream";
|
||||||
|
import { retryInvalidToken } from "./auth.ts";
|
||||||
|
|
||||||
type GiteaUser = { login: string; email: string };
|
type GiteaUser = { login: string; email: string };
|
||||||
type GiteaComment = { user: GiteaUser; created_at: string; body: string };
|
type GiteaComment = { user: GiteaUser; created_at: string; body: string };
|
||||||
@@ -59,21 +60,84 @@ async function postComment(body: string): Promise<void> {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// A pull request event is a review request, so the response becomes a review.
|
// A review is posted whenever the agent wrote one, whether a review request or
|
||||||
// Its first line is the verdict; anything unexpected only comments, never
|
// a comment asked for it. It comes through a file, because a final chat message
|
||||||
// approves.
|
// picks up narration while a file's first line is written on purpose. That line
|
||||||
const VERDICTS: Record<string, string> = {
|
// is the verdict, matched whole; anything unexpected only comments, never
|
||||||
Yes: "APPROVED",
|
// approves. The mark in front is added here, so it is never part of the match.
|
||||||
No: "REQUEST_CHANGES",
|
const REVIEW_DIR = await Deno.makeTempDir();
|
||||||
"With fixes": "REQUEST_CHANGES",
|
const REVIEW_PATH = `${REVIEW_DIR}/review.md`;
|
||||||
|
const VERDICTS: Record<string, [event: string, mark: string]> = {
|
||||||
|
Approved: ["APPROVED", "✅"],
|
||||||
|
"Changes requested": ["REQUEST_CHANGES", "🛑"],
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// A finding about one line is posted on that line of the diff rather than as
|
||||||
|
// `file:line` prose in the body. Those anchors come as JSON, so the file and
|
||||||
|
// line are structured instead of parsed back out of English; a malformed entry
|
||||||
|
// fails the run, because a silently dropped finding is worse than a red run.
|
||||||
|
const ANCHORS_PATH = `${REVIEW_DIR}/anchors.json`;
|
||||||
|
type Anchor = { path: string; line: number; side: "new" | "old"; body: string };
|
||||||
|
|
||||||
|
function parseAnchors(text: string): Anchor[] {
|
||||||
|
const entries: unknown = JSON.parse(text);
|
||||||
|
if (!Array.isArray(entries)) throw new Error(`${ANCHORS_PATH}: not an array`);
|
||||||
|
return entries.map((entry: unknown, index) => {
|
||||||
|
const at = `${ANCHORS_PATH}[${index}]`;
|
||||||
|
if (typeof entry !== "object" || entry === null) {
|
||||||
|
throw new Error(`${at}: not an object`);
|
||||||
|
}
|
||||||
|
const { path, line, side = "new", body } = entry as Record<string, unknown>;
|
||||||
|
if (typeof path !== "string" || path === "") {
|
||||||
|
throw new Error(`${at}.path: expected a repository path`);
|
||||||
|
}
|
||||||
|
if (typeof line !== "number" || !Number.isInteger(line) || line < 1) {
|
||||||
|
throw new Error(`${at}.line: expected a line number`);
|
||||||
|
}
|
||||||
|
if (side !== "new" && side !== "old") {
|
||||||
|
throw new Error(`${at}.side: expected "new" or "old"`);
|
||||||
|
}
|
||||||
|
if (typeof body !== "string" || body.trim() === "") {
|
||||||
|
throw new Error(`${at}.body: expected the finding`);
|
||||||
|
}
|
||||||
|
return { path, line, side, body };
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
async function readAnchors(): Promise<Anchor[]> {
|
||||||
|
const written = await Deno.readTextFile(ANCHORS_PATH).catch(() => null);
|
||||||
|
return written === null ? [] : parseAnchors(written);
|
||||||
|
}
|
||||||
|
|
||||||
async function postResult(body: string): Promise<void> {
|
async function postResult(body: string): Promise<void> {
|
||||||
if (EVENT !== "pull_request") return postComment(body);
|
const review = await Deno.readTextFile(REVIEW_PATH).catch(() => null);
|
||||||
const [verdict] = body.split("\n", 1);
|
if (review === null) {
|
||||||
await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
|
if (EVENT === "pull_request") {
|
||||||
|
throw new Error(`no review was written to ${REVIEW_PATH}`);
|
||||||
|
}
|
||||||
|
return postComment(body);
|
||||||
|
}
|
||||||
|
const [verdict, ...rest] = review.split("\n");
|
||||||
|
const [event, mark] = VERDICTS[verdict.trim()] ?? ["COMMENT", "💬"];
|
||||||
|
const post = (anchors: Anchor[]) =>
|
||||||
|
gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
|
||||||
|
body: stripAnsi([`${mark} ${verdict.trim()}`, ...rest].join("\n")),
|
||||||
|
event,
|
||||||
|
comments: anchors.map(({ path, line, side, body }) => ({
|
||||||
|
path,
|
||||||
body: stripAnsi(body),
|
body: stripAnsi(body),
|
||||||
event: VERDICTS[verdict.trim()] ?? "COMMENT",
|
new_position: side === "new" ? line : 0,
|
||||||
|
old_position: side === "old" ? line : 0,
|
||||||
|
})),
|
||||||
|
});
|
||||||
|
const anchors = await readAnchors();
|
||||||
|
// Gitea rejects the whole review when an anchor names a line outside the
|
||||||
|
// diff, and a verdict that never lands blocks the pull request, so the body
|
||||||
|
// goes up alone rather than not at all.
|
||||||
|
await post(anchors).catch(async (error: Error) => {
|
||||||
|
if (anchors.length === 0) throw error;
|
||||||
|
console.error(`inline comments rejected: ${error.message}`);
|
||||||
|
await post([]);
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -90,19 +154,6 @@ async function configureGitAuthor(): Promise<void> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// The superpowers plugin gives the agent its skills, including the code review
|
|
||||||
// one that the prompt asks for. Both installs are idempotent on the persisted
|
|
||||||
// home.
|
|
||||||
async function installSuperpowers(bot: string): Promise<void> {
|
|
||||||
const commands = bot === "claude"
|
|
||||||
? [
|
|
||||||
["plugin", "marketplace", "add", "obra/superpowers-marketplace"],
|
|
||||||
["plugin", "install", "-y", "superpowers@superpowers-marketplace"],
|
|
||||||
]
|
|
||||||
: [["plugin", "add", "superpowers@openai-curated-remote"]];
|
|
||||||
for (const args of commands) await run(bot, args);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function renderPrompt(): Promise<string> {
|
async function renderPrompt(): Promise<string> {
|
||||||
const comments: GiteaComment[] = await (await gitea(
|
const comments: GiteaComment[] = await (await gitea(
|
||||||
REVIEWER_TOKEN,
|
REVIEWER_TOKEN,
|
||||||
@@ -118,6 +169,8 @@ async function renderPrompt(): Promise<string> {
|
|||||||
GITEA_API_URL: API,
|
GITEA_API_URL: API,
|
||||||
GITEA_REPOSITORY: REPO,
|
GITEA_REPOSITORY: REPO,
|
||||||
ISSUE_INDEX: INDEX,
|
ISSUE_INDEX: INDEX,
|
||||||
|
REVIEW_PATH,
|
||||||
|
ANCHORS_PATH,
|
||||||
};
|
};
|
||||||
const template = await Deno.readTextFile(
|
const template = await Deno.readTextFile(
|
||||||
new URL("prompt.md", import.meta.url),
|
new URL("prompt.md", import.meta.url),
|
||||||
@@ -135,7 +188,6 @@ async function runClaude(prompt: string): Promise<string> {
|
|||||||
"Run `claude setup-token` locally and set the `bot-token` action input.",
|
"Run `claude setup-token` locally and set the `bot-token` action input.",
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
await installSuperpowers("claude");
|
|
||||||
const claude = new Deno.Command("claude", {
|
const claude = new Deno.Command("claude", {
|
||||||
args: [
|
args: [
|
||||||
"--print",
|
"--print",
|
||||||
@@ -186,12 +238,17 @@ async function codexDeviceLogin(): Promise<void> {
|
|||||||
new WritableStream({ write: (chunk) => void (shown += chunk) }),
|
new WritableStream({ write: (chunk) => void (shown += chunk) }),
|
||||||
);
|
);
|
||||||
const drained = Promise.all([collect(login.stdout), collect(login.stderr)]);
|
const drained = Promise.all([collect(login.stdout), collect(login.stderr)]);
|
||||||
|
const status = login.status;
|
||||||
await new Promise((resolve) => setTimeout(resolve, 3000));
|
await new Promise((resolve) => setTimeout(resolve, 3000));
|
||||||
|
while (shown.trim() === "") {
|
||||||
|
const exited = await Promise.race([
|
||||||
|
status.then(() => true),
|
||||||
|
new Promise<boolean>((resolve) => setTimeout(() => resolve(false), 100)),
|
||||||
|
]);
|
||||||
|
if (exited) throw new Error("AI bot login produced no instructions");
|
||||||
|
}
|
||||||
await postComment(shown);
|
await postComment(shown);
|
||||||
await Promise.all([login.status, drained]);
|
await Promise.all([status, drained]);
|
||||||
const status = await new Deno.Command("codex", { args: ["login", "status"] })
|
|
||||||
.output();
|
|
||||||
await postComment(new TextDecoder().decode(status.stdout));
|
|
||||||
}
|
}
|
||||||
|
|
||||||
async function runCodex(prompt: string): Promise<string> {
|
async function runCodex(prompt: string): Promise<string> {
|
||||||
@@ -200,9 +257,9 @@ async function runCodex(prompt: string): Promise<string> {
|
|||||||
})
|
})
|
||||||
.output();
|
.output();
|
||||||
if (!loggedIn.success) await codexDeviceLogin();
|
if (!loggedIn.success) await codexDeviceLogin();
|
||||||
await installSuperpowers("codex");
|
|
||||||
const file = await Deno.makeTempFile();
|
const file = await Deno.makeTempFile();
|
||||||
const status = await new Deno.Command("codex", {
|
const attempt = async () => {
|
||||||
|
const codex = new Deno.Command("codex", {
|
||||||
args: [
|
args: [
|
||||||
"exec",
|
"exec",
|
||||||
"--model",
|
"--model",
|
||||||
@@ -215,8 +272,21 @@ async function runCodex(prompt: string): Promise<string> {
|
|||||||
env: agentEnv,
|
env: agentEnv,
|
||||||
clearEnv: true,
|
clearEnv: true,
|
||||||
stdout: "inherit",
|
stdout: "inherit",
|
||||||
stderr: "inherit",
|
stderr: "piped",
|
||||||
}).spawn().status;
|
}).spawn();
|
||||||
|
const decoder = new TextDecoder();
|
||||||
|
let error = "";
|
||||||
|
for await (const chunk of codex.stderr) {
|
||||||
|
await Deno.stderr.write(chunk);
|
||||||
|
error += decoder.decode(chunk, { stream: true });
|
||||||
|
}
|
||||||
|
error += decoder.decode();
|
||||||
|
return { status: await codex.status, error };
|
||||||
|
};
|
||||||
|
const { status } = await retryInvalidToken(attempt, async () => {
|
||||||
|
await run("codex", ["logout"]);
|
||||||
|
await codexDeviceLogin();
|
||||||
|
});
|
||||||
if (!status.success) throw new Error(`codex exited with ${status.code}`);
|
if (!status.success) throw new Error(`codex exited with ${status.code}`);
|
||||||
return await Deno.readTextFile(file);
|
return await Deno.readTextFile(file);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user