1 Commits

Author SHA1 Message Date
temeddix 78dcb3a2b3 Honor author replies
Check / deno (pull_request) Successful in 40s
2026-09-14 00:20:25 +09:00
8 changed files with 74 additions and 332 deletions
+1 -5
View File
@@ -14,8 +14,4 @@ jobs:
- uses: denoland/setup-deno@v2 - uses: denoland/setup-deno@v2
- run: >- - run: deno fmt --check . && deno lint . && deno check run.ts
deno fmt --check . &&
deno lint . &&
deno check run.ts &&
deno test
-6
View File
@@ -20,11 +20,6 @@ inputs:
bot-token: bot-token:
description: API key or token for the selected bot description: API key or token for the selected bot
required: false required: false
model:
description: >-
Model for the selected bot. Defaults to `claude-sonnet-5` or
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
required: false
runs: runs:
using: composite using: composite
@@ -45,7 +40,6 @@ runs:
ACTION_PATH: ${{ gitea.action_path }} ACTION_PATH: ${{ gitea.action_path }}
BOT_TYPE: ${{ inputs.bot-type }} BOT_TYPE: ${{ inputs.bot-type }}
BOT_TOKEN: ${{ inputs.bot-token }} BOT_TOKEN: ${{ inputs.bot-token }}
MODEL: ${{ inputs.model }}
GITEA_API_URL: ${{ gitea.api_url }} GITEA_API_URL: ${{ gitea.api_url }}
GITEA_REPOSITORY: ${{ gitea.repository }} GITEA_REPOSITORY: ${{ gitea.repository }}
GITEA_TOKEN: ${{ inputs.author-token }} GITEA_TOKEN: ${{ inputs.author-token }}
-12
View File
@@ -1,12 +0,0 @@
export async function retryInvalidToken<
T extends { status: { success: boolean }; error: string },
>(attempt: () => Promise<T>, relogin: () => Promise<void>): Promise<T> {
let result = await attempt();
if (
!result.status.success && result.error.includes("invalid_refresh_token")
) {
await relogin();
result = await attempt();
}
return result;
}
-44
View File
@@ -1,44 +0,0 @@
import { assertEquals } from "jsr:@std/assert@1";
import { retryInvalidToken } from "./auth.ts";
Deno.test("retries once after an invalid refresh token", async () => {
let attempts = 0;
let relogins = 0;
const result = await retryInvalidToken(
() =>
Promise.resolve({
status: { success: false },
error: attempts++ === 0 ? "invalid_refresh_token" : "still failed",
}),
() => {
relogins++;
return Promise.resolve();
},
);
assertEquals({ attempts, relogins, error: result.error }, {
attempts: 2,
relogins: 1,
error: "still failed",
});
});
Deno.test("does not retry an unrelated failure", async () => {
let attempts = 0;
let relogins = 0;
await retryInvalidToken(
() => {
attempts++;
return Promise.resolve({
status: { success: false },
error: "rate limited",
});
},
() => {
relogins++;
return Promise.resolve();
},
);
assertEquals({ attempts, relogins }, { attempts: 1, relogins: 0 });
});
+27 -44
View File
@@ -18,51 +18,34 @@ the head of the pull request when there is one, with full history and the
author's push credentials. Read the code there, run its checks and tests when author's push credentials. Read the code there, run its checks and tests when
they bear on the task, and push from there. they bear on the task, and push from there.
For a `pull_request` event, and for a comment on a pull request that asks you to For a `pull_request` event, review the PR without changing code, using the
review it, invoke the installed `superpowers:requesting-code-review` skill `requesting-code-review` skill from superpowers: run its code reviewer template
before inspecting the PR. You are the reviewer that has already been dispatched, against the PR's base and head, and make its complete output your final response
so run the skill's code reviewer template yourself instead of dispatching instead of the short comment style above. Run the project's checks on the head
another reviewer. Use the pull request and triggering instruction as its and treat a failure as at least Important. Check the whole repository against
description and requirements, and review the exact base and head SHAs without the code rules at the end of this prompt, not only the diff; a violation is at
changing code. Run the project's required checks on the head and treat a real least Important even when the diff did not cause it. Your final response is
failure as at least Important. The bot automation workflow itself is not a posted verbatim as a pull request review from the bot account, so it is the
project check: ignore its skipped or canceled duplicate/automatic runs, and review text and nothing else: no narration about what you did, verified, or are
never reject a PR because the current review run is unfinished. Only a failed about to post, whether you reviewed yourself or relayed a reviewer subagent. Its
required check for the reviewed head blocks approval. Check the whole repository first line must be exactly the template's verdict and nothing else: `Yes`, `No`,
against the code rules at the end of this prompt, not only the diff; a violation or `With fixes`. `Yes` approves and the other two request changes; any other
is at least Important even when the diff did not cause it. Write the complete first line is posted as a plain comment, which wastes the run. Minor issues
review, and nothing else, to the file `${REVIEW_PATH}`: it is posted verbatim as alone never block, and neither does a finding the author has answered in the
a pull request review from the bot account, and your final response is not comment history below as intended or a false alarm, once the code or docs make
posted at all. The file's first line must be exactly the verdict and nothing that clear. When the verdict is not `Yes`, the second line names what must
else: `Approved` when the head is ready to merge, `Changes requested` otherwise. change in one line, addressed to the author; the author's own agent picks the
The mark in front of it is added when posting, so write the words alone; any fixes up, so never ask `@bot` to make them. For UI changes, check that the
other first line is posted as a plain comment, which wastes the run. Minor result is aligned, clean, and pixel-perfect, and that included screenshots prove
issues alone never block, and neither does a finding the author has answered in the intended result was achieved.
the comment history below as intended or a false alarm, once the code or docs
make that clear. When the verdict is `Changes requested`, the second line names
what must change in one line, addressed to the author; the author's own agent
picks the fixes up, so never ask `@bot` to make them. For UI changes, check that
the result is aligned, clean, and pixel-perfect, and that included screenshots
prove the intended result was achieved.
Every finding that belongs to one line of the diff goes on that line instead of The review must read at a glance: everything outside `<details>` blocks totals
into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry under 512 bytes. Only core information stays visible: the verdict, the summary
`{"path": "<path from the repository root>", "line": <number>, "side": "new" | line, and the section headings. Anything verbose goes into a `<details>` block
"old", "body": "<the finding>"}`. whose `<summary>` is a few words, such as the `file:line` and title of an issue
`side` is `new` for a line in the head file and `old` for one only in the base with the what, why, and how inside; the same for each strength, each
file; `line` is that file's own line number, and it must be a line the diff recommendation, the reasoning, and any compliance notes. Details blocks are
touches, or Gitea refuses the anchor. Write the file only when there is top-level, never inside a list item, because Gitea breaks them there.
something to anchor, and keep each body to the what, the why, and the how, with
no `file:line` prefix; the line carries that.
The review body must read at a glance: everything outside `<details>` blocks
totals under 512 bytes. Only core information stays visible: the verdict, the
summary line, and the section headings. Anything verbose goes into a `<details>`
block whose `<summary>` is a few words, such as the title of an issue with the
what, why, and how inside; the same for each strength, each recommendation, the
reasoning, and any compliance notes. A finding you anchored belongs there only
as its title, since its detail is on the line. Details blocks are top-level,
never inside a list item, because Gitea breaks them there.
For an `issue_comment` or `pull_request_review_comment` event, treat the `body` For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
in the triggering comment payload below as the user's exact instruction. in the triggering comment payload below as the user's exact instruction.
+46 -139
View File
@@ -3,12 +3,6 @@
// GITEA_TOKEN; everything this script posts goes through the reviewer token, // GITEA_TOKEN; everything this script posts goes through the reviewer token,
// so it appears as the bot account. // so it appears as the bot account.
import { TextLineStream } from "jsr:@std/streams@1/text-line-stream"; import { TextLineStream } from "jsr:@std/streams@1/text-line-stream";
import { retryInvalidToken } from "./auth.ts";
import {
type BotType,
parseBotType,
superpowersInstallCommands,
} from "./superpowers.ts";
type GiteaUser = { login: string; email: string }; type GiteaUser = { login: string; email: string };
type GiteaComment = { user: GiteaUser; created_at: string; body: string }; type GiteaComment = { user: GiteaUser; created_at: string; body: string };
@@ -23,17 +17,9 @@ const API = env("GITEA_API_URL");
const REPO = env("GITEA_REPOSITORY"); const REPO = env("GITEA_REPOSITORY");
const INDEX = env("ISSUE_INDEX"); const INDEX = env("ISSUE_INDEX");
const EVENT = env("EVENT_NAME"); const EVENT = env("EVENT_NAME");
const BOT = parseBotType(env("BOT_TYPE"));
const AUTHOR_TOKEN = env("GITEA_TOKEN"); const AUTHOR_TOKEN = env("GITEA_TOKEN");
const REVIEWER_TOKEN = env("REVIEWER_TOKEN"); const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
const RULES_PATH = "repos/commons/code-rules/raw/README.md"; const RULES_PATH = "repos/commons/code-rules/raw/README.md";
// The mid tiers: a run follows a fixed template and the project's checks.
const DEFAULT_MODELS: Record<string, string> = {
claude: "claude-sonnet-5",
codex: "gpt-5.6-terra",
};
const model = (bot: string): string =>
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
// The reviewer token is withheld so the agent cannot approve as the bot. // The reviewer token is withheld so the agent cannot approve as the bot.
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject(); const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
@@ -66,84 +52,21 @@ async function postComment(body: string): Promise<void> {
}); });
} }
// A review is posted whenever the agent wrote one, whether a review request or // A pull request event is a review request, so the response becomes a review.
// a comment asked for it. It comes through a file, because a final chat message // Its first line is the verdict; anything unexpected only comments, never
// picks up narration while a file's first line is written on purpose. That line // approves.
// is the verdict, matched whole; anything unexpected only comments, never const VERDICTS: Record<string, string> = {
// approves. The mark in front is added here, so it is never part of the match. Yes: "APPROVED",
const REVIEW_DIR = await Deno.makeTempDir(); No: "REQUEST_CHANGES",
const REVIEW_PATH = `${REVIEW_DIR}/review.md`; "With fixes": "REQUEST_CHANGES",
const VERDICTS: Record<string, [event: string, mark: string]> = {
Approved: ["APPROVED", "✅"],
"Changes requested": ["REQUEST_CHANGES", "🛑"],
}; };
// A finding about one line is posted on that line of the diff rather than as
// `file:line` prose in the body. Those anchors come as JSON, so the file and
// line are structured instead of parsed back out of English; a malformed entry
// fails the run, because a silently dropped finding is worse than a red run.
const ANCHORS_PATH = `${REVIEW_DIR}/anchors.json`;
type Anchor = { path: string; line: number; side: "new" | "old"; body: string };
function parseAnchors(text: string): Anchor[] {
const entries: unknown = JSON.parse(text);
if (!Array.isArray(entries)) throw new Error(`${ANCHORS_PATH}: not an array`);
return entries.map((entry: unknown, index) => {
const at = `${ANCHORS_PATH}[${index}]`;
if (typeof entry !== "object" || entry === null) {
throw new Error(`${at}: not an object`);
}
const { path, line, side = "new", body } = entry as Record<string, unknown>;
if (typeof path !== "string" || path === "") {
throw new Error(`${at}.path: expected a repository path`);
}
if (typeof line !== "number" || !Number.isInteger(line) || line < 1) {
throw new Error(`${at}.line: expected a line number`);
}
if (side !== "new" && side !== "old") {
throw new Error(`${at}.side: expected "new" or "old"`);
}
if (typeof body !== "string" || body.trim() === "") {
throw new Error(`${at}.body: expected the finding`);
}
return { path, line, side, body };
});
}
async function readAnchors(): Promise<Anchor[]> {
const written = await Deno.readTextFile(ANCHORS_PATH).catch(() => null);
return written === null ? [] : parseAnchors(written);
}
async function postResult(body: string): Promise<void> { async function postResult(body: string): Promise<void> {
const review = await Deno.readTextFile(REVIEW_PATH).catch(() => null); if (EVENT !== "pull_request") return postComment(body);
if (review === null) { const [verdict] = body.split("\n", 1);
if (EVENT === "pull_request") { await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
throw new Error(`no review was written to ${REVIEW_PATH}`); body: stripAnsi(body),
} event: VERDICTS[verdict.trim()] ?? "COMMENT",
return postComment(body);
}
const [verdict, ...rest] = review.split("\n");
const [event, mark] = VERDICTS[verdict.trim()] ?? ["COMMENT", "💬"];
const post = (anchors: Anchor[]) =>
gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
body: stripAnsi([`${mark} ${verdict.trim()}`, ...rest].join("\n")),
event,
comments: anchors.map(({ path, line, side, body }) => ({
path,
body: stripAnsi(body),
new_position: side === "new" ? line : 0,
old_position: side === "old" ? line : 0,
})),
});
const anchors = await readAnchors();
// Gitea rejects the whole review when an anchor names a line outside the
// diff, and a verdict that never lands blocks the pull request, so the body
// goes up alone rather than not at all.
await post(anchors).catch(async (error: Error) => {
if (anchors.length === 0) throw error;
console.error(`inline comments rejected: ${error.message}`);
await post([]);
}); });
} }
@@ -152,14 +75,6 @@ async function run(command: string, args: string[]): Promise<void> {
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`); if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
} }
// The reviewer uses Superpowers' requesting-code-review template. Both plugin
// installers are idempotent on the persisted bot home.
async function installSuperpowers(bot: BotType): Promise<void> {
for (const { command, args } of superpowersInstallCommands(bot)) {
await run(command, args);
}
}
// Commits belong to the same account as the pull request they end up in. // Commits belong to the same account as the pull request they end up in.
async function configureGitAuthor(): Promise<void> { async function configureGitAuthor(): Promise<void> {
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json(); const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
@@ -168,6 +83,19 @@ async function configureGitAuthor(): Promise<void> {
} }
} }
// The superpowers plugin gives the agent its skills, including the code review
// one that the prompt asks for. Both installs are idempotent on the persisted
// home.
async function installSuperpowers(bot: string): Promise<void> {
const commands = bot === "claude"
? [
["plugin", "marketplace", "add", "obra/superpowers-marketplace"],
["plugin", "install", "-y", "superpowers@superpowers-marketplace"],
]
: [["plugin", "add", "superpowers@openai-curated-remote"]];
for (const args of commands) await run(bot, args);
}
async function renderPrompt(): Promise<string> { async function renderPrompt(): Promise<string> {
const comments: GiteaComment[] = await (await gitea( const comments: GiteaComment[] = await (await gitea(
REVIEWER_TOKEN, REVIEWER_TOKEN,
@@ -183,8 +111,6 @@ async function renderPrompt(): Promise<string> {
GITEA_API_URL: API, GITEA_API_URL: API,
GITEA_REPOSITORY: REPO, GITEA_REPOSITORY: REPO,
ISSUE_INDEX: INDEX, ISSUE_INDEX: INDEX,
REVIEW_PATH,
ANCHORS_PATH,
}; };
const template = await Deno.readTextFile( const template = await Deno.readTextFile(
new URL("prompt.md", import.meta.url), new URL("prompt.md", import.meta.url),
@@ -208,7 +134,7 @@ async function runClaude(prompt: string): Promise<string> {
"--print", "--print",
"--dangerously-skip-permissions", "--dangerously-skip-permissions",
"--model", "--model",
model("claude"), "claude-fable-5",
"--output-format", "--output-format",
"stream-json", "stream-json",
"--verbose", "--verbose",
@@ -253,17 +179,12 @@ async function codexDeviceLogin(): Promise<void> {
new WritableStream({ write: (chunk) => void (shown += chunk) }), new WritableStream({ write: (chunk) => void (shown += chunk) }),
); );
const drained = Promise.all([collect(login.stdout), collect(login.stderr)]); const drained = Promise.all([collect(login.stdout), collect(login.stderr)]);
const status = login.status;
await new Promise((resolve) => setTimeout(resolve, 3000)); await new Promise((resolve) => setTimeout(resolve, 3000));
while (shown.trim() === "") {
const exited = await Promise.race([
status.then(() => true),
new Promise<boolean>((resolve) => setTimeout(() => resolve(false), 100)),
]);
if (exited) throw new Error("AI bot login produced no instructions");
}
await postComment(shown); await postComment(shown);
await Promise.all([status, drained]); await Promise.all([login.status, drained]);
const status = await new Deno.Command("codex", { args: ["login", "status"] })
.output();
await postComment(new TextDecoder().decode(status.stdout));
} }
async function runCodex(prompt: string): Promise<string> { async function runCodex(prompt: string): Promise<string> {
@@ -274,35 +195,21 @@ async function runCodex(prompt: string): Promise<string> {
if (!loggedIn.success) await codexDeviceLogin(); if (!loggedIn.success) await codexDeviceLogin();
await installSuperpowers("codex"); await installSuperpowers("codex");
const file = await Deno.makeTempFile(); const file = await Deno.makeTempFile();
const attempt = async () => { const status = await new Deno.Command("codex", {
const codex = new Deno.Command("codex", { args: [
args: [ "exec",
"exec", "--model",
"--model", "gpt-5.5",
model("codex"), "--dangerously-bypass-approvals-and-sandbox",
"--dangerously-bypass-approvals-and-sandbox", "--output-last-message",
"--output-last-message", file,
file, prompt,
prompt, ],
], env: agentEnv,
env: agentEnv, clearEnv: true,
clearEnv: true, stdout: "inherit",
stdout: "inherit", stderr: "inherit",
stderr: "piped", }).spawn().status;
}).spawn();
const decoder = new TextDecoder();
let error = "";
for await (const chunk of codex.stderr) {
await Deno.stderr.write(chunk);
error += decoder.decode(chunk, { stream: true });
}
error += decoder.decode();
return { status: await codex.status, error };
};
const { status } = await retryInvalidToken(attempt, async () => {
await run("codex", ["logout"]);
await codexDeviceLogin();
});
if (!status.success) throw new Error(`codex exited with ${status.code}`); if (!status.success) throw new Error(`codex exited with ${status.code}`);
return await Deno.readTextFile(file); return await Deno.readTextFile(file);
} }
@@ -310,7 +217,7 @@ async function runCodex(prompt: string): Promise<string> {
try { try {
await configureGitAuthor(); await configureGitAuthor();
const prompt = await renderPrompt(); const prompt = await renderPrompt();
const result = BOT === "claude" const result = env("BOT_TYPE") === "claude"
? await runClaude(prompt) ? await runClaude(prompt)
: await runCodex(prompt); : await runCodex(prompt);
await postResult(result); await postResult(result);
-42
View File
@@ -1,42 +0,0 @@
export type BotType = "claude" | "codex";
export type InstallCommand = {
command: string;
args: string[];
};
export function parseBotType(value: string): BotType {
if (value === "claude" || value === "codex") return value;
throw new Error(`unsupported bot type: ${value}`);
}
export function superpowersInstallCommands(
bot: BotType,
): InstallCommand[] {
if (bot === "claude") {
return [
{
command: "claude",
args: [
"plugin",
"marketplace",
"add",
"obra/superpowers-marketplace",
],
},
{
command: "claude",
args: [
"plugin",
"install",
"-y",
"superpowers@superpowers-marketplace",
],
},
];
}
return [{
command: "codex",
args: ["plugin", "add", "superpowers@openai-curated-remote"],
}];
}
-40
View File
@@ -1,40 +0,0 @@
import { assertEquals, assertThrows } from "jsr:@std/assert@1";
import { parseBotType, superpowersInstallCommands } from "./superpowers.ts";
Deno.test("installs Superpowers from the Codex marketplace", () => {
assertEquals(superpowersInstallCommands("codex"), [{
command: "codex",
args: ["plugin", "add", "superpowers@openai-curated-remote"],
}]);
});
Deno.test("installs Superpowers from the Claude marketplace", () => {
assertEquals(superpowersInstallCommands("claude"), [
{
command: "claude",
args: [
"plugin",
"marketplace",
"add",
"obra/superpowers-marketplace",
],
},
{
command: "claude",
args: [
"plugin",
"install",
"-y",
"superpowers@superpowers-marketplace",
],
},
]);
});
Deno.test("rejects an unsupported bot type", () => {
assertThrows(
() => parseBotType("other"),
Error,
"unsupported bot type: other",
);
});