Skip to content

ci: Enforce shared Codex review policy over caller inputs #46

Description

@idy

Background

The reusable PR reviewer currently lets each caller choose its review model, reasoning effort, and maximum complete-diff size. Changing the shared review policy then requires edits in every caller. The shared workflow should own these three policy values while retaining its legacy input names for callers that already pass them.

Goal

The shared reviewer always runs with gpt-6-sol, low reasoning effort (the supported Codex value for the requested light setting), and a 100,000,000-byte complete-diff limit. Caller-provided model, effort, and max-diff-bytes values are accepted for compatibility but cannot override the shared policy. Existing callers should not need to remove or change these three inputs when they adopt the updated reusable workflow.

Non-goals

This change does not alter caller-owned review instructions, chunk target size, permissions, trigger events, or the release mechanism for pinned workflow references. It does not update every consuming repository's pinned workflow SHA.

Code Changes Tree

.github/
├── workflows/
│   ├── codex-openai-review.yml      # retain legacy inputs but enforce fixed policy in review, restore, diff preparation, readiness, and publication
│   └── openai-pr-review-dispatch.yml # remove redundant policy inputs from this repository's own caller example
└── scripts/
    └── pr-review/
        └── test.mjs                  # reject caller-input references and assert fixed values across review and publication paths
README.md                             # document the enforced shared policy, compatibility inputs, and pinned-reference adoption

Design

Keep the three workflow_call inputs declared so existing caller YAML remains valid. Set review-job policy variables to gpt-6-sol, low, and 100000000 directly in the reusable workflow. Feed those variables to Codex execution, session identity/validation, readiness evidence, diff preparation, and publication metadata; never read the three legacy input values in those paths. The publish job uses the same fixed model and effort. A diff over the fixed limit fails before Codex runs, even if a caller requests a larger limit. Only a consuming repository's workflow uses reference determines which published revision it runs; adopting this revision must not require changing the three passed parameters.

Test And Acceptance Criteria

Acceptance Criteria

  • A caller passing any values for model, effort, or max-diff-bytes still runs with gpt-6-sol, low, and the 100,000,000-byte limit.
  • Legacy callers can retain the three inputs without workflow validation errors.
  • Session restoration, readiness evidence, and published review metadata report the enforced model and effort.
  • The repository's caller example and README describe the final policy consistently.

Validation

Run node .github/scripts/pr-review/test.mjs, node .github/scripts/pr-readiness/test.mjs, node .github/scripts/issue-review/test.mjs, actionlint on .github/workflows/*.yml, and git diff --check. Confirm the PR's native same-repository closing-Issue relationship and all live checks on its current head.

Activity

  1. added theissue type on Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions