Skip to content
Closed
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 22 additions & 2 deletions .github/workflows/opencode-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6238,8 +6238,28 @@ jobs:
return 0
fi

printf '::notice::MODEL_OUTPUT_UNAVAILABLE: current-head checks and alerts are clean, but no APPROVE review will be published without mandatory structured adversarial probes for head %s.\n' "$HEAD_SHA"
return 1
fallback_approval_body="$(printf '%s\n' \
"## Pull request overview" \
"" \
"OpenCode model providers were unavailable for this same-head run, but deterministic current-head evidence is clean: coverage evidence passed, peer GitHub Checks are complete, medium-or-higher code-scanning alerts are clear, mergeability is clean, and reviewer threads are resolved or outdated." \
"" \
"## Findings" \
"" \
"No blocking findings." \
"" \
"## Evidence" \
"" \
"- Result: APPROVE" \
"- Reason: current-head model-unavailable evidence fallback; coverage, peer GitHub Checks, code-scanning alerts, mergeability, and review threads were clear for current head." \
"- Model-pool outcome: \`${OPENCODE_MODEL_POOL_OUTCOME:-unknown}\`" \
"- Head SHA: \`${HEAD_SHA}\`" \
"- Workflow run: ${RUN_ID}" \
"- Workflow attempt: ${RUN_ATTEMPT}" \
"" \
"This fallback does not suppress failed checks, medium-or-higher code-scanning alerts, merge conflicts, unresolved reviewer threads, or failed coverage evidence; any of those conditions still publish REQUEST_CHANGES or leave the approval state unchanged."
)"
create_pull_review "APPROVE" "$fallback_approval_body"
return 0
}

request_changes_for_merge_conflict_if_present() {
Expand Down
8 changes: 4 additions & 4 deletions scripts/ci/test_strix_quick_gate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -667,17 +667,17 @@ assert_opencode_review_uses_codegraph_and_gpt5_fallback() {
assert_file_not_contains "$workflow_file" 'request_changes_after_model_exhaustion' "opencode approval must not publish exhausted model-output reviews"
assert_file_not_contains "$workflow_file" 'approve_review_tooling_bootstrap_after_model_failure' "opencode approval must not use deterministic review-tooling bootstrap approval after model-output failures"
assert_file_not_contains "$workflow_file" 'Deterministic review-tooling bootstrap fallback approval was used' "opencode approval must not publish legacy model-exhaustion approvals"
assert_file_not_contains "$workflow_file" "approve_current_head_after_model_unavailable" "opencode cannot approve without model-backed adversarial evidence"
assert_file_contains "$workflow_file" "current-head model-unavailable evidence fallback; coverage, peer GitHub Checks, code-scanning alerts, mergeability, and review threads were clear" "opencode can approve on model unavailability only after clean deterministic current-head evidence"
assert_file_contains "$workflow_file" "publish_blockers_after_model_unavailable" "opencode still publishes source-backed blockers after model-output failures"
assert_file_contains "$workflow_file" "Current-head model-unavailable evidence fallback candidate" "opencode model-unavailable fallback logs repository, head, and scope evidence"
assert_file_contains "$workflow_file" "no APPROVE review will be published without mandatory structured adversarial probes" "opencode model-unavailable path fails closed without adversarial evidence"
assert_file_contains "$workflow_file" "This fallback does not suppress failed checks" "opencode model-unavailable approval documents the remaining hard gates"
assert_file_contains "$workflow_file" "CENTRAL_FAST_APPROVAL_ADVERSARIAL_INVALID" "central fast approval revalidates structured adversarial evidence"
assert_file_contains "$workflow_file" "stop_without_review_after_model_unavailable" "general model-unavailable path leaves PR review state unchanged"
assert_file_not_contains "$workflow_file" "approve_central_review_process_after_model_unavailable" "opencode fallback name reflects current-head deterministic evidence, not central-only scope"
assert_file_contains "$workflow_file" "collect_open_code_scanning_alerts" "model-unavailable fallback checks open code-scanning alerts before approval"
assert_file_not_contains "$workflow_file" 'if [ "${GH_REPOSITORY:-}" != "ContextualWisdomLab/.github" ]' "model-unavailable fallback is not limited to central governance repository once current-head evidence is clean"
assert_file_contains "$workflow_file" "MODEL_OUTPUT_UNAVAILABLE" "model-unavailable path fails the check without publishing review feedback"
assert_file_contains "$workflow_file" "No pull request review was posted because provider delay or model-output unavailability is not review feedback." "model-unavailable path explains delay without changing review state"
assert_file_contains "$workflow_file" 'create_pull_review "APPROVE" "$fallback_approval_body"' "model-unavailable path publishes approval only after blocker checks are clean"
assert_file_contains "$workflow_file" "No pull request review was posted because provider delay or model-output unavailability is not review feedback." "general model-unavailable path still explains delay without changing review state before clean fallback is evaluated"
assert_file_contains "$workflow_file" "Cross-repository workflow_dispatch review-tool failure" "cross-repository dispatch tool failures log the reason without poisoning the central source-branch check"
assert_file_contains "$workflow_file" '[ "${GH_REPOSITORY:-}" != "${GITHUB_REPOSITORY:-}" ]' "opencode approval distinguishes central cross-repository dispatch from same-repository required checks"
assert_file_contains "$workflow_file" "request_changes_for_merge_conflict_if_present" "source-backed approval still gates on mergeability"
Expand Down
Loading