Skip to content

ci: require admin approval for large PR reviews - #48

Merged
idy merged 1 commit into
mainfrom
codex/large-diff-admin-approval
Sep 25, 2026
Merged

idy merged 1 commit into
mainfrom
codex/large-diff-admin-approval

Conversation

@idy

@idy idy commented Sep 25, 2026

Copy link
Copy Markdown
Member

Closes #47

Summary

  • Keep the shared 100,000,000-byte total diff ceiling, but automatically review only complete diffs up to 5,000,000 bytes.
  • For a larger diff, require an unquoted @codex review approve <current full head SHA> PR comment from a user with admin permission in the calling repository. Permission lookup and head matching happen in the trusted reusable workflow; failed lookups deny approval.
  • Reject unapproved large diffs before Codex bootstrap. Preserve existing caller events and inputs; no Environment or per-repository reviewer configuration is required.
  • Expand diff read buffers to accommodate the existing 100 MB approved ceiling, and document the admin command.

Validation

  • node .github/scripts/review-request/test.mjs
  • node .github/scripts/pr-review/test.mjs
  • node .github/scripts/pr-readiness/test.mjs
  • node .github/scripts/issue-review/test.mjs
  • actionlint -ignore 'property "workflow_(repository|sha)" is not defined' .github/workflows/*.yml
  • git diff --check

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ OpenAI PR Review: PASS

Conclusion: Ready from the OpenAI review perspective. PR format, linked Issue design, and code/plan conformance passed with no actionable findings.

Review checks

Check Result
PR format ✅ PASS
Issue design ✅ PASS
Code & plan conformance ✅ PASS

Scope: 9689093ad0 · ac4d5d7411..9689093ad0 · full · 1 diff chunk

Usage: 1m 14s · 439,679 tokens · 86.1% cache hit · credits unavailable

Summary

The complete diff review found no actionable code findings or Issue-plan-conformance blockers.

Review metadata
  • Commit: 9689093ad0
  • Range: ac4d5d7411..9689093ad0
  • Mode: full
  • Diff chunks: 1
  • Model: gpt-6-sol
  • Reasoning effort: low
  • Session: repo-1309321116-pr-48-v2
  • Generation: 4e417b4f21095454e71445573a19610b4a71ce9c7f21b569ea3942ce2661825d
  • Evidence: da1b6d97136bb29893fbe60018e8422217ba52e41098f6cd8c629699ba2b2d37

Totals

  • Input: 436,472
  • Cached input: 375,592
  • Cache write: 59,724
  • Output: 3,207
  • Reasoning: 712
  • Total: 439,679
  • Estimated credits: unavailable for this model
Token and cache details
Stage Mode Target Time Input Cached Hit Output Total Credits
pr deterministic format rules 0s 0 0 0.0% 0 0 N/A
pr full pr 13s 57,747 42,272 73.2% 572 58,319 N/A
issue full Issue #47 14s 54,287 49,024 90.3% 537 54,824 N/A
code full chunk 1/1 32s 170,814 135,257 79.2% 1,574 172,388 N/A
code full aggregate 15s 153,624 149,039 97.0% 524 154,148 N/A

@idy
idy merged commit d371c53 into main Sep 25, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: Require admin approval for large PR reviews

1 participant