From bebb00d30cbe03cfd15d1d9d098fc985cf69f88f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 10 Jul 2026 10:28:07 +0900 Subject: [PATCH] fix opencode required workflow bootstrap --- .github/workflows/opencode-review.yml | 7 +++++++ scripts/ci/test_strix_quick_gate.sh | 2 ++ tests/test_opencode_agent_contract.py | 2 ++ 3 files changed, 11 insertions(+) diff --git a/.github/workflows/opencode-review.yml b/.github/workflows/opencode-review.yml index d7c4a4c358..e687931e34 100644 --- a/.github/workflows/opencode-review.yml +++ b/.github/workflows/opencode-review.yml @@ -44,6 +44,13 @@ permissions: contents: read jobs: + required-workflow-bootstrap: + name: required-workflow-bootstrap + if: github.event_name == 'pull_request_target' && github.event.action != 'closed' + runs-on: ubuntu-latest + steps: + - run: echo "Required OpenCode workflow run materialized for this PR event." + cancel-closed-pr-runs: if: github.event_name == 'pull_request_target' && github.event.action == 'closed' runs-on: ubuntu-latest diff --git a/scripts/ci/test_strix_quick_gate.sh b/scripts/ci/test_strix_quick_gate.sh index ab8b511609..be3c25bffb 100755 --- a/scripts/ci/test_strix_quick_gate.sh +++ b/scripts/ci/test_strix_quick_gate.sh @@ -379,6 +379,8 @@ assert_opencode_review_uses_codegraph_and_gpt5_fallback() { assert_file_not_contains "$workflow_file" "Wait for trusted OpenCode approval review" "opencode pull_request bridge was removed to avoid duplicate required-check resource use" assert_file_not_contains "$workflow_file" "Trusted OpenCode requested changes for head" "opencode pull_request bridge no longer reconsumes stale trusted review state" assert_file_not_contains "$workflow_file" "github.event.pull_request.number == 240" "opencode review workflow must not hard-code repository-specific PR bypasses" + assert_file_contains "$workflow_file" "required-workflow-bootstrap:" "opencode required workflow materializes at least one job for pull_request_target ruleset runs" + assert_file_contains "$workflow_file" "Required OpenCode workflow run materialized for this PR event." "opencode required workflow bootstrap documents why the sentinel job exists" assert_file_contains "$workflow_file" 'github.event.pull_request.base.repo.full_name || github.event.inputs.target_repository || github.repository' "opencode review scopes concurrency by target repository" assert_file_contains "$workflow_file" "format('pr-{0}-{1}', github.event.pull_request.number, github.event.pull_request.head.sha)" "opencode review scopes pull_request_target concurrency by current head" assert_file_contains "$workflow_file" "format('pr-{0}-{1}', github.event.inputs.pr_number, github.event.inputs.pr_head_sha)" "opencode review scopes manual concurrency by target PR head" diff --git a/tests/test_opencode_agent_contract.py b/tests/test_opencode_agent_contract.py index e353df1d8e..efcf87ee86 100644 --- a/tests/test_opencode_agent_contract.py +++ b/tests/test_opencode_agent_contract.py @@ -149,6 +149,8 @@ def test_opencode_manual_dispatch_canonical_ref_overrides_workflow_ref(): def test_opencode_target_coverage_materializes_merge_tree_without_checkout_action(): """Avoid pull_request_target action checkouts of untrusted PR refs.""" workflow = Path(".github/workflows/opencode-review.yml").read_text(encoding="utf-8") + assert "required-workflow-bootstrap:" in workflow + assert "Required OpenCode workflow run materialized for this PR event." in workflow assert ( "github.event.pull_request.head.repo.full_name == " "github.event.pull_request.base.repo.full_name"