fix(opencode): use same-repo status credential - #1227
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Caution Review failedAn error occurred during the review process. Please try again later. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…s credential Resolve CHANGELOG and the opencode-review-dispatch blob pin after a normal merge of origin/main. The job-scoped github.token same-repo status path remains the PR change; the dispatch workflow pin now matches the merged blob SHA.
|
@opencode-agent @cwl-noema-review current-head review for Wait — re-read live SHA. This comment is for the merge commit that lands origin/main into #1227 without dropping the same-repo |
|
@opencode-agent @cwl-noema-review current-head review for Normal merge of origin/main resolved CHANGELOG and the |
|
@opencode-agent @cwl-noema-review current-head review for Same-repo |
|
Independent current-head review request for exact HEAD Gap G-03: required Strix still fail-closes 0-vuln complete scans on |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
5974bee1dbc2f28b33f69f1aab08066bdedaab70. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32644317344/job/97210369391)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32644317344/job/97210369391)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: opencode-review-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: opencode-review-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: opencode-same-repository-status-credential.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: opencode-same-repository-status-credential.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: opencode-review-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: opencode-review-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: opencode-same-repository-status-credential.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: opencode-same-repository-status-credential.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
5974bee1dbc2f28b33f69f1aab08066bdedaab70. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix: FAILURE (https://github.com/ContextualWisdomLab/.github/actions/runs/32644317344/job/97210369391)
- Strix Security Scan/strix: failure (https://github.com/ContextualWisdomLab/.github/actions/runs/32644317344/job/97210369391)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: opencode-review-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: opencode-review-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file: CHANGELOG.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file: CHANGELOG.md"]
R2 --> V2["required checks"]
Evidence --> S3["Docs: opencode-same-repository-status-credential.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: opencode-same-repository-status-credential.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test (2 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (2 files)"]
R4 --> V4["targeted test run"]
* docs: refresh gap baseline after #1252 merged to main Bind the live 95-PR inventory to protected main 9f8f840. The SHA table is a snapshot, not merge authorization. * docs: align G-02 with BEHIND inventory and bind 99 live PRs Record GitHub CLEAN #1265 as snapshot metadata, not merge authorization, and keep #1162/#1227/#1215 as BEHIND after #1252. * docs: bind live 98-PR inventory while #1265 waits for OpenCode Keep GitHub CLEAN #1265 as snapshot metadata, not merge authorization, and record that required Strix CRs remain G-03. * docs: correct live PR 1263 head evidence
…o-status-token # Conflicts: # CHANGELOG.md # tests/test_pr_review_autofix_nvidia_nim_contract.py
|
Resolved the stale merge conflict against current 1 conflicting file — purely mechanical, a pinned-blob-hash test constant:
Verified the merge is otherwise a clean fast-forward-style catch-up: Test evidence (worktree, head
Note on mechanics: the previous manual merge left this branch mid-merge in an unusual worktree state (branch-ref switch during an in-progress merge discarded Generated by Claude Code |
…tern (#1499) Bypass-merged per explicit owner authorization: opencode-review is blocked by a pre-existing, org-wide opencode-app credential 403 (fix pending in #1227) and an org-wide Actions queue backlog, neither caused by this PR's diff. Fully validated locally: test_strix_quick_gate PASS, coverage run -m pytest tests 2126 passed/1 skipped, 100% coverage, 100% docstrings.
|
@claude Please refresh this root-cause fix non-destructively onto current protected |
…o-status-token # Conflicts: # CHANGELOG.md # tests/test_pr_review_autofix_nvidia_nim_contract.py
The merge conflict resolution left a placeholder in REVIEW_DISPATCH_BLOB_SHA pending a fresh git hash-object of the merged opencode-review-dispatch.yml (neither side's pinned value was still correct once both changes combined). Filled in with the actual post-merge blob hash.
|
Refreshed non-destructively as requested — no force-push, all 49 commits of central governance evolution since divergence preserved via a real merge ( What happenedMerged current protected
Verification on the new head (
|
…o-status-token # Conflicts: # tests/test_pr_review_autofix_nvidia_nim_contract.py
Protected main regressed to 99% scripts/ci coverage after #1546 added live_head_matches, a no-active/no-stale fall-through in prepare_autofix_slot, and an "already queued or running" wait branch to pr_review_fix_scheduler.py without covering them, while the pre-existing inspect_pr conflicted-draft/conflicted-unauthorized returns and pr_review_merge_scheduler.py's fetch_workflow_names_by_check_suite_rest pagination/filtering/ permission-denied paths stayed untested. Every PR rebasing onto main inherits this via the coverage-evidence required check regardless of its own diff. Test-only change; no production code touched. (cherry picked from commit db106d5)
Raise scoped docstring coverage for the newly added scheduler REST regression helpers to 100% without changing test behavior or production code. (cherry picked from commit 6f40a06)
RCA: the #1567 exact-head Hourly NVIDIA NIM Review Repair run failed in test_scheduler_wake_reuses_trusted_receipt_predicate with exit 141. The production block pipes jq JSON into gh api --input -, while the test fake exited without reading stdin. Under pipefail that can SIGPIPE jq. Reuse the already RED/GREEN-verified #1569 fixture blob and drain stdin before recording the fake dispatch. This makes #1567 self-contained so the central 100% coverage repair no longer depends on a separate PR that itself inherits the coverage failure. (cherry picked from commit 6948175)
|
Resolved the merge conflict against current That merge inherited the same pre-existing, org-wide Verification on the new head ( This PR's own scope (2-line same-repo status token credential precedence fix + tests/changelog/doctoring) is unchanged. Generated by Claude Code |
…o-status-token # Conflicts: # CHANGELOG.md
|
Resolved another merge conflict against current Main now already carries the Verification on the new head ( This PR's own scope (2-line same-repo status token credential precedence fix) is unchanged. Generated by Claude Code |
…o-status-token # Conflicts: # CHANGELOG.md
|
Rebased onto current Verified on the merged head: Generated by Claude Code |
Stale infrastructure-only review evidence: this review is bound to predecessor head 5974bee and cites only a failed Strix infrastructure check. The live PR head is 5c7eb11; no source/security finding is stated in the review body. Retiring it without converting it to approval so current-head review/check evidence can govern.
Bring the mention-router PR current with main (advanced via #1227, #1617, and other independently merged fixes) so its stalled/queued checks re-run against an up-to-date head instead of a stale one. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KPmJErfkcHer4UVEgrQxUX
Outcome
Use the job-scoped github.token for OpenCode commit-status publication when the repository_dispatch target is the central .github repository. Cross-repository targets retain the existing PAT/App credential chain.
Root cause
Run 32560612401 declared statuses: write but selected the separate OpenCode App token for a same-repository POST /statuses/{sha}; GitHub returned HTTP 403 because that installation token did not have commit-status write permission.
Verification
No new credential, permission, retry, or fallback path is introduced.