Skip to content

ci: Skip large-diff approval for private callers #51

Description

@idy

Background

The shared reviewer now counts binary-aware patches and requires exact-head admin approval above 5,000,000 bytes in every caller repository. GizClaw/h6infra is a private repository on GitHub Team, where Environment required reviewers cannot provide the native waiting approval experience. Its frontend PR #4 has an 18,621,002-byte binary-aware patch and is blocked despite the repository's controlled access. The caller's repository visibility is available from the trusted GitHub pull-request API response.

Goal

Apply the 5,000,000-byte automatic-review approval gate only to public caller repositories. Private caller repositories may review larger patches automatically, while the shared 100,000,000-byte hard ceiling remains in force. Determine privacy from the target/base repository returned by GitHub, not from caller-controlled workflow inputs or the fork head.

Non-goals

Do not change the admin command for public repositories, the binary-aware size measurement, model/effort policy, numeric limits, or GitHub repository settings. Do not assert that every private repository is inaccessible to outside collaborators.

Code Changes Tree

.github/
├── workflows/
│   └── codex-openai-review.yml       # pass trusted base-repository privacy from PR resolve to review preparation
└── scripts/
    └── pr-review/
        ├── prepare.mjs               # apply the 5MB gate only to public repositories while always enforcing 100MB
        └── test.mjs                  # cover public rejection, private exemption, approval and hard-ceiling behavior
README.md                             # document public-only approval and private automatic review behavior

Design

The resolve job fetches the live PR with GitHub's pull-request API and emits private_repository=true only when pr.base.repo.private === true; missing or uncertain data fails closed as public. The review job passes this trusted value to the diff preparation script. The script first enforces the 100,000,000-byte binary-aware hard ceiling for all callers. It then enforces the 5,000,000-byte automatic gate only when the base repository is public and no exact-head admin approval was verified. The head fork's visibility and legacy caller inputs do not affect this decision.

Test And Acceptance Criteria

Acceptance Criteria

  • Public PR patches above 5,000,000 bytes still require the admin command before model work.
  • Private caller PR patches above 5,000,000 and below 100,000,000 bytes proceed automatically.
  • Every caller, public or private, is rejected above 100,000,000 bytes.
  • Unknown privacy data is treated as public.
  • Existing caller YAML requires no new input, secret or event.

Validation

Run pr-review, review-request, pr-readiness and issue-review tests; run actionlint and git diff --check. Verify GizClaw/h6infra PR #4's target repository reports private=true, then verify the new shared revision reviews that PR without the admin-size gate after release.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions