Clear signing AI CI pipeline - #3057
marcocastignoli wants to merge 5 commits into
Conversation
First step of the AI review of descriptor pull requests. The new AI Review workflow runs on workflow_run of Descriptor Tests, from the default branch, with a read-only token and no secrets. Its gate job decides whether a review can happen: Registry Checks and Descriptor Tests concluded with success for the head commit (Registry Checks is waited for when still running, and any other failed pull_request workflow stops the review too), the pull request changes only files under registry/ and ercs/, and the test report bundle of the commit exists on the test-reports branch. The bundle is uploaded as an artifact for the next job. A gate that does not pass is a skip with the reason in the job summary, never a failed check. workflow_dispatch with a pull request number runs the same job on demand, which tests a branch of the workflow before it reaches master. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…checks A run started by workflow_run is recorded against the default branch, so the first version of the AI Review workflow never appeared among the checks of the pull request it reviewed. pull_request_target, the event the queued note and the labels use, starts with the pull request and shows there, and it also runs the workflow file of the base branch with secrets, which the review needs. The safety rule is the same as before: nothing from the pull request is executed and nothing from it reaches a shell line. The gate now starts alongside Registry Checks and Descriptor Tests, so it waits for both, with a grace period for the runs to be listed, then for the bundle as before. The pull request number comes from the event, the head commit from the API. The workflow runs only when a descriptor or a shared file changed, the same filter as Descriptor Tests. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Manuel's proposal. The review job is bound to the Environment ai-review, so every descriptor pull request shows the AI Review check as waiting until a maintainer approves, and nothing runs before the click. After the click the job reads GitHub once instead of polling: the changed files through tj-actions/changed-files (any file outside registry/ and ercs/ stops it), the latest pull_request runs of the head commit through the API (Registry Checks and Descriptor Tests must be green, any other failed workflow stops it too), and the test report bundle of the commit through a sparse checkout of the test-reports branch. Each condition that does not hold fails the job with its reason in the summary; a maintainer re-runs it later, which asks for approval again. The bundle lands one to three minutes after the tests, and the message for that case says to wait and re-run. This removes the gate script, the wait loop and the workflow_dispatch trigger. The security rule is unchanged: nothing from the pull request is executed, nothing from it reaches a shell line, and the only checkout is the test-reports branch. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
@manuelwedler implemented what we agreed: Posted with Claude Code |
|
The new approach in 4250435 looks good: approval first, then one read of GitHub, no polling, no gate script, and the check shows on the PR. The two approved runs on the fork go through all steps. Two small points:
|
Manuel's review of the approval-first version. tj-actions/changed-files was a third-party action for one API call that gh already makes, and the stop step expanded the file names unquoted in a shell loop, the one place where pull request data touched a shell line. Now one gh api call lists the files with previous_filename for renames, jq filters the ones outside registry/ and ercs/, and jq writes the summary, with the names restricted to safe characters. The error annotation carries only the count. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Both points taken. 3a9377a replaces Posted with Claude Code |
* docs: describe the AI review pipeline One page for readers in a hurry: the gate, the information retrieval and the review, each in a few lines with the details in expandable sections; the fourteen checks in one table; how deployments are grouped into review units; what the model must not report; how the comment is kept safe; what a unit costs; how to change the prompt. The prompt itself sits next to it, linked from the page, until it finds its final place. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * docs: shorten the AI review page after review Drop the status line, the reasons behind the workflow shape, the note on unverified deployments, the case for Markdown, the comment safety paragraph, the prompt change procedure and the file list; every note is a question for the reviewer. The answer's "What was reviewed" section becomes "What could not be reviewed", present only when something limited the review; the prompt copy follows. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
A language model reviews the descriptors of a pull request and posts what it finds as a comment. It runs after the deterministic checks pass, only when a maintainer approves it, and it never blocks a merge. What it does and how is on the docs page of #3071; the model comparison and the prompt are in #3069; the design note is "clear-signing-ci-ai-pipeline" on notes.argot.org.
This is the integration pull request. It stays a draft while the steps below land on its branch
ci/ai-review, each as its own pull request onto that branch, so reviewers see one step at a time. Nothing reachesmasteruntil this pull request merges.Until then every step is tested on Marco's fork, marcocastignoli/clear-signing-erc7730-registry: its default branch is
ci/ai-review, it has the Environmentai-reviewwith Marco as reviewer, and a test pull request there runs the whole thing, approval included.One rule holds in every job: nothing from the pull request is executed and nothing from it reaches a shell line. The jobs read pull request data through the GitHub API, and the only checkouts are the
test-reportsbranch and the base branch.Plan
Step 0: setup
ci/ai-reviewand this pull request.ai-reviewwith required reviewers on this repository. This must exist before the merge: without it GitHub creates the Environment unprotected and the review runs without a click.Step 1: the gate (in this pull request)
pull_request_targetfor descriptor changes and waits for a maintainer's approval on every pull request.registry/andercs/changed, Registry Checks and Descriptor Tests green, the test report bundle published. Each failure says why; a re-run asks for approval again.Step 2: collect the inputs (#3061)
ai-review-inputs.ci/ai-review.Step 3: the benchmark (#3069)
Step 4: hello world end to end (#3070)
other.postjob withpull-requests: writeand no key posts one comment per model, headed as AI-generated and advisory, with its cost.ANTHROPIC_WORKSPACE_IDset.ci/ai-review.Step 5: make the review better
Step 6: production
docs/ai-review/README.md(docs: describe the AI review pipeline #3071), kept current with every change.🤖 Generated with Claude Code