Compare commits
13 Commits
split-tokens
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| ba9e0c0787 | |||
| 58d3c12c25 | |||
| dcacac18e8 | |||
| 70d71aa4fd | |||
| 2b51793c92 | |||
| 4ed8b48b7a | |||
| 0d109ebec8 | |||
| a2bc4c9541 | |||
| 75d3593376 | |||
| 439f2b4e77 | |||
| f0506adfea | |||
| b8d0093ef2 | |||
| 8c2041bbc5 |
@@ -0,0 +1,21 @@
|
||||
name: Check
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
deno:
|
||||
runs-on: self-hosted
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- run: apt-get update && apt-get install -y unzip
|
||||
|
||||
- uses: denoland/setup-deno@v2
|
||||
|
||||
- run: >-
|
||||
deno fmt --check . &&
|
||||
deno lint . &&
|
||||
deno check run.ts &&
|
||||
deno test
|
||||
+28
-9
@@ -5,32 +5,51 @@ inputs:
|
||||
bot-type:
|
||||
description: Which bot to run, either `codex` or `claude`
|
||||
required: true
|
||||
gitea-token:
|
||||
description: Gitea access token for API calls and pushes
|
||||
author-token:
|
||||
description: >-
|
||||
Gitea token of the account that commits, pushes, and opens pull requests,
|
||||
with the `read:user`, `write:issue`, and `write:repository` scopes. The
|
||||
agent sees it as `GITEA_TOKEN`.
|
||||
required: true
|
||||
reviewer-token:
|
||||
description: >-
|
||||
Gitea token of the bot account that posts comments and pull request
|
||||
reviews, with the `write:issue` and `write:repository` scopes. Never
|
||||
exposed to the agent, so it must differ from the author.
|
||||
required: true
|
||||
bot-token:
|
||||
description: API key or token for the selected bot
|
||||
required: false
|
||||
model:
|
||||
description: >-
|
||||
Model for the selected bot. Defaults to `claude-sonnet-5` or
|
||||
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
|
||||
required: false
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
# The agent works on the event's commit with full history, as the author.
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
token: ${{ inputs.author-token }}
|
||||
# This step assumes this is `node:24-bookworm` container.
|
||||
- name: Install dependencies
|
||||
shell: bash
|
||||
run: |
|
||||
apt-get update
|
||||
apt-get install -y --no-install-recommends gettext-base jq ansifilter
|
||||
npm install -g @openai/codex @anthropic-ai/claude-code
|
||||
run: npm install -g @openai/codex @anthropic-ai/claude-code deno
|
||||
- name: Run bot
|
||||
shell: bash
|
||||
run: bash "${ACTION_PATH}/scripts/run-${{ inputs.bot-type }}.sh"
|
||||
run: deno run -A "${ACTION_PATH}/run.ts"
|
||||
env:
|
||||
ACTION_PATH: ${{ gitea.action_path }}
|
||||
BOT_TYPE: ${{ inputs.bot-type }}
|
||||
BOT_TOKEN: ${{ inputs.bot-token }}
|
||||
MODEL: ${{ inputs.model }}
|
||||
GITEA_API_URL: ${{ gitea.api_url }}
|
||||
GITEA_REPOSITORY: ${{ gitea.repository }}
|
||||
GITEA_TOKEN: ${{ inputs.gitea-token }}
|
||||
BOT_TOKEN: ${{ inputs.bot-token }}
|
||||
GITEA_TOKEN: ${{ inputs.author-token }}
|
||||
REVIEWER_TOKEN: ${{ inputs.reviewer-token }}
|
||||
EVENT_NAME: ${{ gitea.event_name }}
|
||||
ISSUE_INDEX: ${{ gitea.event.issue.number || gitea.event.pull_request.number }}
|
||||
COMMENT: ${{ toJSON(gitea.event.comment || gitea.event.review) }}
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
export async function retryInvalidToken<
|
||||
T extends { status: { success: boolean }; error: string },
|
||||
>(attempt: () => Promise<T>, relogin: () => Promise<void>): Promise<T> {
|
||||
let result = await attempt();
|
||||
if (
|
||||
!result.status.success && result.error.includes("invalid_refresh_token")
|
||||
) {
|
||||
await relogin();
|
||||
result = await attempt();
|
||||
}
|
||||
return result;
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
import { assertEquals } from "jsr:@std/assert@1";
|
||||
import { retryInvalidToken } from "./auth.ts";
|
||||
|
||||
Deno.test("retries once after an invalid refresh token", async () => {
|
||||
let attempts = 0;
|
||||
let relogins = 0;
|
||||
const result = await retryInvalidToken(
|
||||
() =>
|
||||
Promise.resolve({
|
||||
status: { success: false },
|
||||
error: attempts++ === 0 ? "invalid_refresh_token" : "still failed",
|
||||
}),
|
||||
() => {
|
||||
relogins++;
|
||||
return Promise.resolve();
|
||||
},
|
||||
);
|
||||
|
||||
assertEquals({ attempts, relogins, error: result.error }, {
|
||||
attempts: 2,
|
||||
relogins: 1,
|
||||
error: "still failed",
|
||||
});
|
||||
});
|
||||
|
||||
Deno.test("does not retry an unrelated failure", async () => {
|
||||
let attempts = 0;
|
||||
let relogins = 0;
|
||||
await retryInvalidToken(
|
||||
() => {
|
||||
attempts++;
|
||||
return Promise.resolve({
|
||||
status: { success: false },
|
||||
error: "rate limited",
|
||||
});
|
||||
},
|
||||
() => {
|
||||
relogins++;
|
||||
return Promise.resolve();
|
||||
},
|
||||
);
|
||||
|
||||
assertEquals({ attempts, relogins }, { attempts: 1, relogins: 0 });
|
||||
});
|
||||
@@ -0,0 +1,130 @@
|
||||
You are a coding agent running inside Gitea Actions.
|
||||
|
||||
Do not post a final issue comment yourself; your final response is posted
|
||||
automatically. Post additional comments only when needed for PR updates,
|
||||
screenshots, questions, or blockers.
|
||||
|
||||
Keep every issue and PR comment extremely short and simple. Strongly prefer
|
||||
nested bulleted lists for readability. Report only the outcome and tests; omit
|
||||
explanations, summaries, and pleasantries.
|
||||
|
||||
This is a single non-interactive run. The process exits the moment your final
|
||||
response ends, so background monitors, scheduled wake-ups, and queued tasks
|
||||
never resume. Never promise future action and never claim to be waiting on a
|
||||
notification.
|
||||
|
||||
The repository is checked out in the working directory at the event's commit,
|
||||
the head of the pull request when there is one, with full history and the
|
||||
author's push credentials. Read the code there, run its checks and tests when
|
||||
they bear on the task, and push from there.
|
||||
|
||||
For a `pull_request` event, and for a comment on a pull request that asks you to
|
||||
review it, use the installed `superpowers:requesting-code-review` skill before
|
||||
inspecting the PR. Its exact installed instructions and reviewer template are
|
||||
included below, so this run fails before reaching you if they could not be
|
||||
loaded. You are the reviewer that has already been dispatched, so run the
|
||||
skill's code reviewer template yourself instead of dispatching another reviewer.
|
||||
Use the pull request and triggering instruction as its description and
|
||||
requirements, and review the exact base and head SHAs without changing code. Run
|
||||
the project's required checks on the head and treat a real failure as at least
|
||||
Important. The bot automation workflow itself is not a project check: ignore its
|
||||
skipped or canceled duplicate/automatic runs, and never reject a PR because the
|
||||
current review run is unfinished. Only a failed required check for the reviewed
|
||||
head blocks approval. Check the whole repository against the code rules at the
|
||||
end of this prompt, not only the diff; a violation is at least Important even
|
||||
when the diff did not cause it. Write the complete review, and nothing else, to
|
||||
the file `${REVIEW_PATH}`: it is posted verbatim as a pull request review from
|
||||
the bot account, and your final response is not posted at all. The file's first
|
||||
line must be exactly the verdict and nothing else: `Approved` when the head is
|
||||
ready to merge, `Changes requested` otherwise. The mark in front of it is added
|
||||
when posting, so write the words alone; any other first line is posted as a
|
||||
plain comment, which wastes the run. Minor issues alone never block, and neither
|
||||
does a finding the author has answered in the comment history below as intended
|
||||
or a false alarm, once the code or docs make that clear. When the verdict is
|
||||
`Changes requested`, the second line names what must change in one line,
|
||||
addressed to the author; the author's own agent picks the fixes up, so never ask
|
||||
`@bot` to make them. For UI changes, check that the result is aligned, clean,
|
||||
and pixel-perfect, and that included screenshots prove the intended result was
|
||||
achieved.
|
||||
|
||||
# Installed Superpowers review skill
|
||||
|
||||
${SUPERPOWERS_REVIEW_SKILL}
|
||||
|
||||
# Installed Superpowers reviewer template
|
||||
|
||||
${SUPERPOWERS_REVIEW_TEMPLATE}
|
||||
|
||||
Every finding that belongs to one line of the diff goes on that line instead of
|
||||
into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry
|
||||
`{"path": "<path from the repository root>", "line": <number>, "side": "new" |
|
||||
"old", "body": "<the finding>"}`.
|
||||
`side` is `new` for a line in the head file and `old` for one only in the base
|
||||
file; `line` is that file's own line number, and it must be a line the diff
|
||||
touches, or Gitea refuses the anchor. Write the file only when there is
|
||||
something to anchor, and keep each body to the what, the why, and the how, with
|
||||
no `file:line` prefix; the line carries that.
|
||||
|
||||
The review body must read at a glance: everything outside `<details>` blocks
|
||||
totals under 512 bytes. Only core information stays visible: the verdict, the
|
||||
summary line, and the section headings. Anything verbose goes into a `<details>`
|
||||
block whose `<summary>` is a few words, such as the title of an issue with the
|
||||
what, why, and how inside; the same for each strength, each recommendation, the
|
||||
reasoning, and any compliance notes. A finding you anchored belongs there only
|
||||
as its title, since its detail is on the line. Details blocks are top-level,
|
||||
never inside a list item, because Gitea breaks them there.
|
||||
|
||||
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
||||
in the triggering comment payload below as the user's exact instruction.
|
||||
|
||||
Install missing tools yourself when needed, including Rust, uv, Node, Deno, or
|
||||
system packages.
|
||||
|
||||
Before modifying or pushing code, check for another active automation run that
|
||||
may modify the same target branch or work on the same issue or pull request. If
|
||||
one exists, wait for it to finish before making changes. Wait inside this run
|
||||
with a foreground shell loop that polls and prints a line every 30 seconds, for
|
||||
as long as it takes, even hours; a silent process is killed as a zombie. Use a
|
||||
blocking `sleep` even if your tool instructions discourage it, and ignore any
|
||||
advice to wait by scheduling a callback instead. Never report being blocked by
|
||||
another run; always wait it out and complete the task before responding.
|
||||
Afterwards, pull the latest branch state before pushing. Skip this check when no
|
||||
code changes are needed.
|
||||
|
||||
Prefer minimal, correct changes that follow the code rules at the end of this
|
||||
prompt. Run relevant checks or tests if practical. Treat code changes as a
|
||||
request to create a pull request. If a prior bot pull request already exists for
|
||||
this issue, update that same pull request instead of creating a new one. When
|
||||
you create a pull request, include `@bot` in its body and ask it to review the
|
||||
pull request. This is required for every pull request you create. Finish by
|
||||
briefly reporting what changed and what tests ran. Wait for Gitea Actions CI to
|
||||
complete, and fix any failures.
|
||||
|
||||
If you modify UI code, include Playwright screenshots in your PR or issue
|
||||
comments. If you need UI clarification, ask with screenshots when helpful.
|
||||
|
||||
# Comment payload
|
||||
|
||||
```
|
||||
${COMMENT}
|
||||
```
|
||||
|
||||
# Full issue comment history
|
||||
|
||||
```
|
||||
${ISSUE_COMMENTS}
|
||||
```
|
||||
|
||||
# Gitea context
|
||||
|
||||
- Event: `${EVENT_NAME}`
|
||||
- API URL: `${GITEA_API_URL}`
|
||||
- Repository: `${GITEA_REPOSITORY}`
|
||||
- Issue index: `${ISSUE_INDEX}`
|
||||
- Use the `GITEA_TOKEN` environment variable for authenticated Gitea API calls
|
||||
and pushes. It belongs to the author account, so never approve, reject, or
|
||||
review a pull request with it; reviews are posted for you.
|
||||
|
||||
# Code rules
|
||||
|
||||
${CODE_RULES}
|
||||
@@ -0,0 +1,335 @@
|
||||
// Runs a coding agent for one Gitea issue or pull request event and posts its
|
||||
// final response back. The agent works as the author account through
|
||||
// GITEA_TOKEN; everything this script posts goes through the reviewer token,
|
||||
// so it appears as the bot account.
|
||||
import { TextLineStream } from "jsr:@std/streams@1/text-line-stream";
|
||||
import { retryInvalidToken } from "./auth.ts";
|
||||
import {
|
||||
type BotType,
|
||||
loadSuperpowersReviewGuide,
|
||||
parseBotType,
|
||||
superpowersInstallCommands,
|
||||
type SuperpowersReviewGuide,
|
||||
} from "./superpowers.ts";
|
||||
|
||||
type GiteaUser = { login: string; email: string };
|
||||
type GiteaComment = { user: GiteaUser; created_at: string; body: string };
|
||||
|
||||
const env = (name: string): string => {
|
||||
const value = Deno.env.get(name);
|
||||
if (value === undefined) throw new Error(`${name} is not set`);
|
||||
return value;
|
||||
};
|
||||
|
||||
const API = env("GITEA_API_URL");
|
||||
const REPO = env("GITEA_REPOSITORY");
|
||||
const INDEX = env("ISSUE_INDEX");
|
||||
const EVENT = env("EVENT_NAME");
|
||||
const BOT = parseBotType(env("BOT_TYPE"));
|
||||
const AUTHOR_TOKEN = env("GITEA_TOKEN");
|
||||
const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
|
||||
const RULES_PATH = "repos/commons/code-rules/raw/README.md";
|
||||
// The mid tiers: a run follows a fixed template and the project's checks.
|
||||
const DEFAULT_MODELS: Record<string, string> = {
|
||||
claude: "claude-sonnet-5",
|
||||
codex: "gpt-5.6-terra",
|
||||
};
|
||||
const model = (bot: string): string =>
|
||||
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
|
||||
|
||||
// The reviewer token is withheld so the agent cannot approve as the bot.
|
||||
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
|
||||
|
||||
async function gitea(
|
||||
token: string,
|
||||
path: string,
|
||||
body?: unknown,
|
||||
): Promise<Response> {
|
||||
const response = await fetch(`${API}/${path}`, {
|
||||
method: body === undefined ? "GET" : "POST",
|
||||
headers: {
|
||||
Authorization: `token ${token}`,
|
||||
"Content-Type": "application/json",
|
||||
},
|
||||
body: body === undefined ? undefined : JSON.stringify(body),
|
||||
});
|
||||
if (!response.ok) {
|
||||
throw new Error(`${path}: ${response.status} ${await response.text()}`);
|
||||
}
|
||||
return response;
|
||||
}
|
||||
|
||||
const ANSI = new RegExp(`${String.fromCharCode(27)}\\[[0-9;]*[A-Za-z]`, "g");
|
||||
const stripAnsi = (text: string): string => text.replace(ANSI, "");
|
||||
|
||||
async function postComment(body: string): Promise<void> {
|
||||
await gitea(REVIEWER_TOKEN, `repos/${REPO}/issues/${INDEX}/comments`, {
|
||||
body: stripAnsi(body),
|
||||
});
|
||||
}
|
||||
|
||||
// A review is posted whenever the agent wrote one, whether a review request or
|
||||
// a comment asked for it. It comes through a file, because a final chat message
|
||||
// picks up narration while a file's first line is written on purpose. That line
|
||||
// is the verdict, matched whole; anything unexpected only comments, never
|
||||
// approves. The mark in front is added here, so it is never part of the match.
|
||||
const REVIEW_DIR = await Deno.makeTempDir();
|
||||
const REVIEW_PATH = `${REVIEW_DIR}/review.md`;
|
||||
const VERDICTS: Record<string, [event: string, mark: string]> = {
|
||||
Approved: ["APPROVED", "✅"],
|
||||
"Changes requested": ["REQUEST_CHANGES", "🛑"],
|
||||
};
|
||||
|
||||
// A finding about one line is posted on that line of the diff rather than as
|
||||
// `file:line` prose in the body. Those anchors come as JSON, so the file and
|
||||
// line are structured instead of parsed back out of English; a malformed entry
|
||||
// fails the run, because a silently dropped finding is worse than a red run.
|
||||
const ANCHORS_PATH = `${REVIEW_DIR}/anchors.json`;
|
||||
type Anchor = { path: string; line: number; side: "new" | "old"; body: string };
|
||||
|
||||
function parseAnchors(text: string): Anchor[] {
|
||||
const entries: unknown = JSON.parse(text);
|
||||
if (!Array.isArray(entries)) throw new Error(`${ANCHORS_PATH}: not an array`);
|
||||
return entries.map((entry: unknown, index) => {
|
||||
const at = `${ANCHORS_PATH}[${index}]`;
|
||||
if (typeof entry !== "object" || entry === null) {
|
||||
throw new Error(`${at}: not an object`);
|
||||
}
|
||||
const { path, line, side = "new", body } = entry as Record<string, unknown>;
|
||||
if (typeof path !== "string" || path === "") {
|
||||
throw new Error(`${at}.path: expected a repository path`);
|
||||
}
|
||||
if (typeof line !== "number" || !Number.isInteger(line) || line < 1) {
|
||||
throw new Error(`${at}.line: expected a line number`);
|
||||
}
|
||||
if (side !== "new" && side !== "old") {
|
||||
throw new Error(`${at}.side: expected "new" or "old"`);
|
||||
}
|
||||
if (typeof body !== "string" || body.trim() === "") {
|
||||
throw new Error(`${at}.body: expected the finding`);
|
||||
}
|
||||
return { path, line, side, body };
|
||||
});
|
||||
}
|
||||
|
||||
async function readAnchors(): Promise<Anchor[]> {
|
||||
const written = await Deno.readTextFile(ANCHORS_PATH).catch(() => null);
|
||||
return written === null ? [] : parseAnchors(written);
|
||||
}
|
||||
|
||||
async function postResult(body: string): Promise<void> {
|
||||
const review = await Deno.readTextFile(REVIEW_PATH).catch(() => null);
|
||||
if (review === null) {
|
||||
if (EVENT === "pull_request") {
|
||||
throw new Error(`no review was written to ${REVIEW_PATH}`);
|
||||
}
|
||||
return postComment(body);
|
||||
}
|
||||
const [verdict, ...rest] = review.split("\n");
|
||||
const [event, mark] = VERDICTS[verdict.trim()] ?? ["COMMENT", "💬"];
|
||||
const post = (anchors: Anchor[]) =>
|
||||
gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
|
||||
body: stripAnsi([`${mark} ${verdict.trim()}`, ...rest].join("\n")),
|
||||
event,
|
||||
comments: anchors.map(({ path, line, side, body }) => ({
|
||||
path,
|
||||
body: stripAnsi(body),
|
||||
new_position: side === "new" ? line : 0,
|
||||
old_position: side === "old" ? line : 0,
|
||||
})),
|
||||
});
|
||||
const anchors = await readAnchors();
|
||||
// Gitea rejects the whole review when an anchor names a line outside the
|
||||
// diff, and a verdict that never lands blocks the pull request, so the body
|
||||
// goes up alone rather than not at all.
|
||||
await post(anchors).catch(async (error: Error) => {
|
||||
if (anchors.length === 0) throw error;
|
||||
console.error(`inline comments rejected: ${error.message}`);
|
||||
await post([]);
|
||||
});
|
||||
}
|
||||
|
||||
async function run(command: string, args: string[]): Promise<void> {
|
||||
const { success, code } = await new Deno.Command(command, { args }).output();
|
||||
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
|
||||
}
|
||||
|
||||
// The reviewer uses Superpowers' requesting-code-review template. Both plugin
|
||||
// installers are idempotent on the persisted bot home.
|
||||
async function installSuperpowers(bot: BotType): Promise<void> {
|
||||
for (const { command, args } of superpowersInstallCommands(bot)) {
|
||||
await run(command, args);
|
||||
}
|
||||
}
|
||||
|
||||
async function prepareSuperpowers(
|
||||
bot: BotType,
|
||||
): Promise<SuperpowersReviewGuide> {
|
||||
await installSuperpowers(bot);
|
||||
const guide = await loadSuperpowersReviewGuide(bot, env("HOME"));
|
||||
console.log(
|
||||
`Loaded Superpowers requesting-code-review ${guide.version} from ${guide.skillPath}`,
|
||||
);
|
||||
console.log(
|
||||
`Loaded Superpowers reviewer template from ${guide.templatePath}`,
|
||||
);
|
||||
return guide;
|
||||
}
|
||||
|
||||
// Commits belong to the same account as the pull request they end up in.
|
||||
async function configureGitAuthor(): Promise<void> {
|
||||
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
|
||||
for (const [key, value] of [["name", user.login], ["email", user.email]]) {
|
||||
await run("git", ["config", "--global", `user.${key}`, value]);
|
||||
}
|
||||
}
|
||||
|
||||
async function renderPrompt(guide: SuperpowersReviewGuide): Promise<string> {
|
||||
const comments: GiteaComment[] = await (await gitea(
|
||||
REVIEWER_TOKEN,
|
||||
`repos/${REPO}/issues/${INDEX}/comments?limit=100`,
|
||||
)).json();
|
||||
const values: Record<string, string> = {
|
||||
COMMENT: env("COMMENT"),
|
||||
ISSUE_COMMENTS: comments
|
||||
.map((c) => `## ${c.user.login} at ${c.created_at}\n\n${c.body}\n`)
|
||||
.join("\n"),
|
||||
CODE_RULES: await (await gitea(REVIEWER_TOKEN, RULES_PATH)).text(),
|
||||
EVENT_NAME: EVENT,
|
||||
GITEA_API_URL: API,
|
||||
GITEA_REPOSITORY: REPO,
|
||||
ISSUE_INDEX: INDEX,
|
||||
REVIEW_PATH,
|
||||
ANCHORS_PATH,
|
||||
SUPERPOWERS_REVIEW_SKILL: guide.skill,
|
||||
SUPERPOWERS_REVIEW_TEMPLATE: guide.template,
|
||||
};
|
||||
const template = await Deno.readTextFile(
|
||||
new URL("prompt.md", import.meta.url),
|
||||
);
|
||||
return template.replace(
|
||||
/\$\{(\w+)\}/g,
|
||||
(match, name) => values[name] ?? match,
|
||||
);
|
||||
}
|
||||
|
||||
async function runClaude(): Promise<string> {
|
||||
const token = Deno.env.get("BOT_TOKEN");
|
||||
if (!token) {
|
||||
throw new Error(
|
||||
"Run `claude setup-token` locally and set the `bot-token` action input.",
|
||||
);
|
||||
}
|
||||
const prompt = await renderPrompt(await prepareSuperpowers("claude"));
|
||||
const claude = new Deno.Command("claude", {
|
||||
args: [
|
||||
"--print",
|
||||
"--dangerously-skip-permissions",
|
||||
"--model",
|
||||
model("claude"),
|
||||
"--output-format",
|
||||
"stream-json",
|
||||
"--verbose",
|
||||
prompt,
|
||||
],
|
||||
// Claude refuses --dangerously-skip-permissions as root outside a sandbox.
|
||||
env: { ...agentEnv, CLAUDE_CODE_OAUTH_TOKEN: token, IS_SANDBOX: "1" },
|
||||
clearEnv: true,
|
||||
stdout: "piped",
|
||||
}).spawn();
|
||||
let result: { result?: string; subtype: string } | undefined;
|
||||
// Print events as they stream so the runner does not kill the job as a zombie.
|
||||
const lines = claude.stdout
|
||||
.pipeThrough(new TextDecoderStream())
|
||||
.pipeThrough(new TextLineStream());
|
||||
for await (const line of lines) {
|
||||
if (!line) continue;
|
||||
const event = JSON.parse(line);
|
||||
for (const part of event.message?.content ?? []) {
|
||||
const text = part.thinking ?? part.text ?? part.name;
|
||||
if (text) console.log(text);
|
||||
}
|
||||
if (event.type === "result") result = event;
|
||||
}
|
||||
await claude.status;
|
||||
if (result?.result === undefined) {
|
||||
throw new Error(`claude ended with ${result?.subtype ?? "no result"}`);
|
||||
}
|
||||
return result.result;
|
||||
}
|
||||
|
||||
// Posts the device code so a human can finish the login on the persisted home.
|
||||
async function codexDeviceLogin(): Promise<void> {
|
||||
const login = new Deno.Command("codex", {
|
||||
args: ["login", "--device-auth"],
|
||||
stdout: "piped",
|
||||
stderr: "piped",
|
||||
}).spawn();
|
||||
let shown = "";
|
||||
const collect = (stream: ReadableStream<Uint8Array>): Promise<void> =>
|
||||
stream.pipeThrough(new TextDecoderStream()).pipeTo(
|
||||
new WritableStream({ write: (chunk) => void (shown += chunk) }),
|
||||
);
|
||||
const drained = Promise.all([collect(login.stdout), collect(login.stderr)]);
|
||||
const status = login.status;
|
||||
await new Promise((resolve) => setTimeout(resolve, 3000));
|
||||
while (shown.trim() === "") {
|
||||
const exited = await Promise.race([
|
||||
status.then(() => true),
|
||||
new Promise<boolean>((resolve) => setTimeout(() => resolve(false), 100)),
|
||||
]);
|
||||
if (exited) throw new Error("AI bot login produced no instructions");
|
||||
}
|
||||
await postComment(shown);
|
||||
await Promise.all([status, drained]);
|
||||
}
|
||||
|
||||
async function runCodex(): Promise<string> {
|
||||
const loggedIn = await new Deno.Command("codex", {
|
||||
args: ["login", "status"],
|
||||
})
|
||||
.output();
|
||||
if (!loggedIn.success) await codexDeviceLogin();
|
||||
const prompt = await renderPrompt(await prepareSuperpowers("codex"));
|
||||
const file = await Deno.makeTempFile();
|
||||
const attempt = async () => {
|
||||
const codex = new Deno.Command("codex", {
|
||||
args: [
|
||||
"exec",
|
||||
"--model",
|
||||
model("codex"),
|
||||
"--dangerously-bypass-approvals-and-sandbox",
|
||||
"--output-last-message",
|
||||
file,
|
||||
prompt,
|
||||
],
|
||||
env: agentEnv,
|
||||
clearEnv: true,
|
||||
stdout: "inherit",
|
||||
stderr: "piped",
|
||||
}).spawn();
|
||||
const decoder = new TextDecoder();
|
||||
let error = "";
|
||||
for await (const chunk of codex.stderr) {
|
||||
await Deno.stderr.write(chunk);
|
||||
error += decoder.decode(chunk, { stream: true });
|
||||
}
|
||||
error += decoder.decode();
|
||||
return { status: await codex.status, error };
|
||||
};
|
||||
const { status } = await retryInvalidToken(attempt, async () => {
|
||||
await run("codex", ["logout"]);
|
||||
await codexDeviceLogin();
|
||||
});
|
||||
if (!status.success) throw new Error(`codex exited with ${status.code}`);
|
||||
return await Deno.readTextFile(file);
|
||||
}
|
||||
|
||||
try {
|
||||
await configureGitAuthor();
|
||||
const result = BOT === "claude" ? await runClaude() : await runCodex();
|
||||
await postResult(result);
|
||||
} catch (error) {
|
||||
await postComment(`Bot failed: ${error}`);
|
||||
throw error;
|
||||
}
|
||||
@@ -1,68 +0,0 @@
|
||||
You are a coding agent running inside Gitea Actions.
|
||||
|
||||
Do not post a final issue comment yourself; your final response is posted
|
||||
automatically. Post additional comments only when needed for PR updates,
|
||||
screenshots, questions, or blockers.
|
||||
|
||||
Keep every issue and PR comment extremely short and simple. Strongly prefer
|
||||
nested bulleted lists for readability. Report only the outcome and tests; omit
|
||||
explanations, summaries, and pleasantries.
|
||||
|
||||
This is a single non-interactive run. The process exits the moment your final
|
||||
response ends, so background monitors, scheduled wake-ups, and queued tasks
|
||||
never resume. Never promise future action and never claim to be waiting on a
|
||||
notification.
|
||||
|
||||
For a `pull_request` event, review the newly opened PR without changing code. If
|
||||
changes are needed, include `@bot` in the final response with instructions to
|
||||
fix the findings. Otherwise, do not mention `@bot`. For UI changes, check that
|
||||
the result is aligned, clean, and pixel-perfect, and that included screenshots
|
||||
prove the intended result was achieved.
|
||||
|
||||
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
||||
in the triggering comment payload below as the user's exact instruction.
|
||||
|
||||
Install missing tools yourself when needed, including Rust, uv, Node, Deno, or
|
||||
system packages.
|
||||
|
||||
Before modifying or pushing code, check for another active automation run that
|
||||
may modify the same target branch or work on the same issue or pull request. If
|
||||
one exists, wait for it to finish before making changes. Wait inside this run
|
||||
with a foreground shell loop that polls and prints a line every 30 seconds, for
|
||||
as long as it takes, even hours; a silent process is killed as a zombie. Use a
|
||||
blocking `sleep` even if your tool instructions discourage it, and ignore any
|
||||
advice to wait by scheduling a callback instead. Never report being blocked by
|
||||
another run; always wait it out and complete the task before responding.
|
||||
Afterwards, pull the latest branch state before pushing. Skip this check when no
|
||||
code changes are needed.
|
||||
|
||||
Prefer minimal, correct changes. Run relevant checks or tests if practical.
|
||||
Treat code changes as a request to create a pull request. If a prior bot pull
|
||||
request already exists for this issue, update that same pull request instead of
|
||||
creating a new one. When you create a pull request, include `@bot` in its body
|
||||
and ask it to review the pull request. This is required for every pull request
|
||||
you create. Finish by briefly reporting what changed and what tests ran. Wait
|
||||
for Gitea Actions CI to complete, and fix any failures.
|
||||
|
||||
If you modify UI code, include Playwright screenshots in your PR or issue
|
||||
comments. If you need UI clarification, ask with screenshots when helpful.
|
||||
|
||||
# Comment payload
|
||||
|
||||
```
|
||||
${COMMENT}
|
||||
```
|
||||
|
||||
# Full issue comment history
|
||||
|
||||
```
|
||||
${ISSUE_COMMENTS}
|
||||
```
|
||||
|
||||
# Gitea context
|
||||
|
||||
- Event: `${EVENT_NAME}`
|
||||
- API URL: `${GITEA_API_URL}`
|
||||
- Repository: `${GITEA_REPOSITORY}`
|
||||
- Issue index: `${ISSUE_INDEX}`
|
||||
- Use the `GITEA_TOKEN` environment variable for authenticated Gitea API calls.
|
||||
@@ -1,49 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
git config --global user.name bot
|
||||
git config --global user.email noreply@capsulizers.com
|
||||
|
||||
COMMENT_FILE="$(mktemp)"
|
||||
|
||||
post_comment() {
|
||||
COMMENT_JSON="$(jq -n --rawfile body "${COMMENT_FILE}" '{body: $body}')"
|
||||
curl --fail-with-body --silent --show-error \
|
||||
-X POST \
|
||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
--data "${COMMENT_JSON}" \
|
||||
"${GITEA_API_URL}/repos/${GITEA_REPOSITORY}/issues/${ISSUE_INDEX}/comments"
|
||||
}
|
||||
|
||||
if [ -z "${BOT_TOKEN:-}" ]; then
|
||||
echo 'Run `claude setup-token` locally and set the `bot-token` action input.' > "${COMMENT_FILE}"
|
||||
post_comment
|
||||
exit 1
|
||||
fi
|
||||
export CLAUDE_CODE_OAUTH_TOKEN="${BOT_TOKEN}"
|
||||
|
||||
export ISSUE_COMMENTS="$(
|
||||
curl --fail-with-body --silent --show-error \
|
||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
||||
"${GITEA_API_URL}/repos/${GITEA_REPOSITORY}/issues/${ISSUE_INDEX}/comments?limit=100" \
|
||||
| jq -r '.[] | "## " + .user.login + " at " + .created_at + "\n\n" + .body + "\n"'
|
||||
)"
|
||||
|
||||
FINAL_PROMPT="$(envsubst < "${ACTION_PATH}/scripts/prompt.md")"
|
||||
|
||||
# Claude refuses --dangerously-skip-permissions as root outside a sandbox.
|
||||
export IS_SANDBOX=1
|
||||
|
||||
# Stream events so the runner sees output and does not kill the job as a zombie.
|
||||
STREAM_FILE="$(mktemp)"
|
||||
|
||||
claude --print --dangerously-skip-permissions --model claude-fable-5 \
|
||||
--output-format stream-json --verbose "${FINAL_PROMPT}" \
|
||||
| tee "${STREAM_FILE}" \
|
||||
| jq -r --unbuffered '.message.content[]? | .thinking // .text // .name // empty'
|
||||
|
||||
jq -r 'select(.type == "result") | .result // ("Bot failed: " + .subtype)' "${STREAM_FILE}" \
|
||||
| ansifilter > "${COMMENT_FILE}"
|
||||
|
||||
post_comment
|
||||
@@ -1,43 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
git config --global user.name bot
|
||||
git config --global user.email noreply@capsulizers.com
|
||||
|
||||
COMMENT_FILE="$(mktemp)"
|
||||
|
||||
post_comment() {
|
||||
COMMENT_JSON="$(jq -n --rawfile body "${COMMENT_FILE}" '{body: $body}')"
|
||||
curl --fail-with-body --silent --show-error \
|
||||
-X POST \
|
||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
--data "${COMMENT_JSON}" \
|
||||
"${GITEA_API_URL}/repos/${GITEA_REPOSITORY}/issues/${ISSUE_INDEX}/comments"
|
||||
}
|
||||
|
||||
if ! codex login status > /dev/null 2>&1; then
|
||||
codex login --device-auth 2>&1 | ansifilter > "${COMMENT_FILE}" &
|
||||
LOGIN_PID="${!}"
|
||||
sleep 3
|
||||
post_comment
|
||||
wait "${LOGIN_PID}"
|
||||
codex login status 2>&1 | ansifilter > "${COMMENT_FILE}"
|
||||
post_comment
|
||||
fi
|
||||
|
||||
export ISSUE_COMMENTS="$(
|
||||
curl --fail-with-body --silent --show-error \
|
||||
-H "Authorization: token ${GITEA_TOKEN}" \
|
||||
"${GITEA_API_URL}/repos/${GITEA_REPOSITORY}/issues/${ISSUE_INDEX}/comments?limit=100" \
|
||||
| jq -r '.[] | "## " + .user.login + " at " + .created_at + "\n\n" + .body + "\n"'
|
||||
)"
|
||||
|
||||
FINAL_PROMPT="$(envsubst < "${ACTION_PATH}/scripts/prompt.md")"
|
||||
|
||||
codex exec --model gpt-5.5 \
|
||||
--dangerously-bypass-approvals-and-sandbox \
|
||||
--output-last-message "${COMMENT_FILE}" \
|
||||
"${FINAL_PROMPT}"
|
||||
|
||||
post_comment
|
||||
+147
@@ -0,0 +1,147 @@
|
||||
import { join } from "jsr:@std/path@1";
|
||||
|
||||
export type BotType = "claude" | "codex";
|
||||
|
||||
export type InstallCommand = {
|
||||
command: string;
|
||||
args: string[];
|
||||
};
|
||||
|
||||
export type SuperpowersReviewGuide = {
|
||||
version: string;
|
||||
skillPath: string;
|
||||
templatePath: string;
|
||||
skill: string;
|
||||
template: string;
|
||||
};
|
||||
|
||||
export type SuperpowersFileSystem = {
|
||||
readDir(path: string): AsyncIterable<Deno.DirEntry>;
|
||||
readTextFile(path: string): Promise<string>;
|
||||
};
|
||||
|
||||
const systemFileSystem: SuperpowersFileSystem = {
|
||||
readDir: Deno.readDir,
|
||||
readTextFile: Deno.readTextFile,
|
||||
};
|
||||
|
||||
export function parseBotType(value: string): BotType {
|
||||
if (value === "claude" || value === "codex") return value;
|
||||
throw new Error(`unsupported bot type: ${value}`);
|
||||
}
|
||||
|
||||
export function superpowersInstallCommands(
|
||||
bot: BotType,
|
||||
): InstallCommand[] {
|
||||
if (bot === "claude") {
|
||||
return [
|
||||
{
|
||||
command: "claude",
|
||||
args: [
|
||||
"plugin",
|
||||
"marketplace",
|
||||
"add",
|
||||
"obra/superpowers-marketplace",
|
||||
],
|
||||
},
|
||||
{
|
||||
command: "claude",
|
||||
args: [
|
||||
"plugin",
|
||||
"install",
|
||||
"-y",
|
||||
"superpowers@superpowers-marketplace",
|
||||
],
|
||||
},
|
||||
];
|
||||
}
|
||||
return [{
|
||||
command: "codex",
|
||||
args: ["plugin", "add", "superpowers@openai-curated-remote"],
|
||||
}];
|
||||
}
|
||||
|
||||
type Candidate = SuperpowersReviewGuide & { directory: string };
|
||||
|
||||
async function readCandidate(
|
||||
directory: string,
|
||||
fileSystem: SuperpowersFileSystem,
|
||||
): Promise<Candidate | null> {
|
||||
if (!directory.split(/[\\/]/).includes("superpowers")) return null;
|
||||
const skillPath = join(directory, "SKILL.md");
|
||||
const templatePath = join(directory, "code-reviewer.md");
|
||||
try {
|
||||
const [skill, template] = await Promise.all([
|
||||
fileSystem.readTextFile(skillPath),
|
||||
fileSystem.readTextFile(templatePath),
|
||||
]);
|
||||
return {
|
||||
directory,
|
||||
version: directory.split(/[\\/]/).at(-3) ?? "unknown",
|
||||
skillPath,
|
||||
templatePath,
|
||||
skill,
|
||||
template,
|
||||
};
|
||||
} catch (error) {
|
||||
if (error instanceof Deno.errors.NotFound) return null;
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
async function findCandidates(
|
||||
directory: string,
|
||||
candidates: Candidate[],
|
||||
fileSystem: SuperpowersFileSystem,
|
||||
): Promise<void> {
|
||||
let entries: Deno.DirEntry[];
|
||||
try {
|
||||
entries = [];
|
||||
for await (const entry of fileSystem.readDir(directory)) {
|
||||
entries.push(entry);
|
||||
}
|
||||
} catch (error) {
|
||||
if (error instanceof Deno.errors.NotFound) return;
|
||||
throw error;
|
||||
}
|
||||
for (const entry of entries) {
|
||||
if (!entry.isDirectory) continue;
|
||||
const child = join(directory, entry.name);
|
||||
if (entry.name === "requesting-code-review") {
|
||||
const candidate = await readCandidate(child, fileSystem);
|
||||
if (candidate !== null) candidates.push(candidate);
|
||||
} else {
|
||||
await findCandidates(child, candidates, fileSystem);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Load the installed files rather than trusting skill discovery in a later
|
||||
// non-interactive agent process. The newest cached plugin version is the one
|
||||
// the installers activate, and the exact paths are reported by the caller.
|
||||
export async function loadSuperpowersReviewGuide(
|
||||
bot: BotType,
|
||||
home: string,
|
||||
fileSystem: SuperpowersFileSystem = systemFileSystem,
|
||||
): Promise<SuperpowersReviewGuide> {
|
||||
const root = join(
|
||||
home,
|
||||
bot === "codex" ? ".codex" : ".claude",
|
||||
"plugins",
|
||||
"cache",
|
||||
);
|
||||
const candidates: Candidate[] = [];
|
||||
await findCandidates(root, candidates, fileSystem);
|
||||
candidates.sort((left, right) =>
|
||||
left.version.localeCompare(right.version, undefined, { numeric: true }) ||
|
||||
left.directory.localeCompare(right.directory)
|
||||
);
|
||||
const guide = candidates.at(-1);
|
||||
if (guide === undefined) {
|
||||
throw new Error(
|
||||
`installed Superpowers requesting-code-review files not found under ${root}`,
|
||||
);
|
||||
}
|
||||
const { directory: _, ...result } = guide;
|
||||
return result;
|
||||
}
|
||||
@@ -0,0 +1,119 @@
|
||||
import { assertEquals, assertRejects, assertThrows } from "jsr:@std/assert@1";
|
||||
import { join } from "jsr:@std/path@1";
|
||||
import {
|
||||
loadSuperpowersReviewGuide,
|
||||
parseBotType,
|
||||
type SuperpowersFileSystem,
|
||||
superpowersInstallCommands,
|
||||
} from "./superpowers.ts";
|
||||
|
||||
function fakeFileSystem(files: Record<string, string>): SuperpowersFileSystem {
|
||||
return {
|
||||
readTextFile(path) {
|
||||
const contents = files[path];
|
||||
return contents === undefined
|
||||
? Promise.reject(new Deno.errors.NotFound(path))
|
||||
: Promise.resolve(contents);
|
||||
},
|
||||
async *readDir(directory) {
|
||||
const prefix = `${directory}/`;
|
||||
const children = new Map<string, boolean>();
|
||||
for (const path of Object.keys(files)) {
|
||||
if (!path.startsWith(prefix)) continue;
|
||||
const [name, ...rest] = path.slice(prefix.length).split("/");
|
||||
if (name !== "") children.set(name, rest.length > 0);
|
||||
}
|
||||
if (children.size === 0) throw new Deno.errors.NotFound(directory);
|
||||
for (const [name, isDirectory] of children) {
|
||||
yield {
|
||||
name,
|
||||
isDirectory,
|
||||
isFile: !isDirectory,
|
||||
isSymlink: false,
|
||||
};
|
||||
}
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
Deno.test("installs Superpowers from the Codex marketplace", () => {
|
||||
assertEquals(superpowersInstallCommands("codex"), [{
|
||||
command: "codex",
|
||||
args: ["plugin", "add", "superpowers@openai-curated-remote"],
|
||||
}]);
|
||||
});
|
||||
|
||||
Deno.test("installs Superpowers from the Claude marketplace", () => {
|
||||
assertEquals(superpowersInstallCommands("claude"), [
|
||||
{
|
||||
command: "claude",
|
||||
args: [
|
||||
"plugin",
|
||||
"marketplace",
|
||||
"add",
|
||||
"obra/superpowers-marketplace",
|
||||
],
|
||||
},
|
||||
{
|
||||
command: "claude",
|
||||
args: [
|
||||
"plugin",
|
||||
"install",
|
||||
"-y",
|
||||
"superpowers@superpowers-marketplace",
|
||||
],
|
||||
},
|
||||
]);
|
||||
});
|
||||
|
||||
Deno.test("rejects an unsupported bot type", () => {
|
||||
assertThrows(
|
||||
() => parseBotType("other"),
|
||||
Error,
|
||||
"unsupported bot type: other",
|
||||
);
|
||||
});
|
||||
|
||||
Deno.test("loads the newest installed Superpowers review guide", async () => {
|
||||
const home = "/home/bot";
|
||||
const older = join(
|
||||
home,
|
||||
".codex/plugins/cache/openai-curated-remote/superpowers/6.3.0/skills/requesting-code-review",
|
||||
);
|
||||
const newer = join(
|
||||
home,
|
||||
".codex/plugins/cache/openai-curated-remote/superpowers/6.10.0/skills/requesting-code-review",
|
||||
);
|
||||
const guide = await loadSuperpowersReviewGuide(
|
||||
"codex",
|
||||
home,
|
||||
fakeFileSystem({
|
||||
[join(older, "SKILL.md")]: "old",
|
||||
[join(older, "code-reviewer.md")]: "old template",
|
||||
[join(newer, "SKILL.md")]: "new",
|
||||
[join(newer, "code-reviewer.md")]: "template",
|
||||
}),
|
||||
);
|
||||
|
||||
assertEquals(guide.version, "6.10.0");
|
||||
assertEquals(guide.skill, "new");
|
||||
assertEquals(guide.template, "template");
|
||||
assertEquals(guide.skillPath, join(newer, "SKILL.md"));
|
||||
});
|
||||
|
||||
Deno.test("fails when the installed review guide is incomplete", async () => {
|
||||
const home = "/home/bot";
|
||||
const directory = join(
|
||||
home,
|
||||
".claude/plugins/cache/superpowers-marketplace/superpowers/6.3.0/skills/requesting-code-review",
|
||||
);
|
||||
const fileSystem = fakeFileSystem({
|
||||
[join(directory, "SKILL.md")]: "skill",
|
||||
});
|
||||
|
||||
await assertRejects(
|
||||
() => loadSuperpowersReviewGuide("claude", home, fileSystem),
|
||||
Error,
|
||||
"installed Superpowers requesting-code-review files not found",
|
||||
);
|
||||
});
|
||||
Reference in New Issue
Block a user