Skip to content

docs: correct rule 10's host count and generalise the deep-review skip condition - #608

Merged
allxsmith merged 3 commits into
mainfrom
docs/578-rule10-host-count-and-stale-review-branches
Aug 30, 2026
Merged

allxsmith merged 3 commits into
mainfrom
docs/578-rule10-host-count-and-stale-review-branches

Conversation

@allxsmith

@allxsmith allxsmith commented Aug 30, 2026 •

Copy link
Copy Markdown
Owner

Two inaccuracies now on main, both found by exercising the jobs #578 flipped rather than by
reading the files. Docs only, no workflow behaviour changes.

1. Rule 10 said "the same eight hosts". It is nine.

Copilot caught during #602's review that the eight-host Claude-session list omits nodejs.org,
which actions/setup-node falls back to when the toolcache misses and the actions/node-versions
lookup fails. The workflows were fixed; that sentence in rule 10 was not, so main currently
claims eight while all six jobs carry nine.

The corrected text also says why measurement could not have found it, which matters more than
the number: none of ai-scan/scan, ai-triage/triage or claude-repro/author runs
setup-node, so their list never needed the host. Across six audit runs the toolcache hit every
time, so the fallback never executed and left no endpoint in any log. Review caught it, measurement
could not have. That is worth stating plainly next to a rule whose entire subject is measuring
allowlists.

Caught by the respond verification session, which quoted the stale line back while confirming its
own job's state.

2. The deep-review skip condition was too narrow, and it is biting right now

CLAUDE.md said a PR that modifies claude-review.yml is not deep-reviewed. The real
condition is a PR whose copy of that file differs from the default branch's, because the
workflow runs from the PR head. A branch that merely predates a change to the file is equally
stale and equally silent: green job, no review, no signal.

Not hypothetical. #578's flip changed claude-review.yml, so every PR opened before e5ed56b now
inherits a skipped deep review. Reproduced on #605:

  • 33289561563 — "egress_policy":"audit" (the branch's own stale copy), session skipped, job green
  • merged main into the branch, re-ran: 33289641518 — block, assertion green, session ran

At the time of writing #601, #584, #551, #469 and #461 are all in that state.

3. Blob host rotation, seventh name

The claude verification run produced productionresultssa17, joining sa3/6/7/9/11/13. Recorded,
since it strengthens the existing "cannot be pinned even in principle" argument. Phrased as a
growing list rather than a fixed enumeration, because it will keep growing.

Verification evidence this came out of

Three of the six #578 jobs are now confirmed under enforcement, each read from a real run rather
than from YAML — assertion green, "egress_policy":"block", zero Reverted changes/timed out
in the agent log, and the session completing real work:

Job Run
claude-review / review 33289641518
bestaxbot-reply / respond 33314880876
claude / claude 33314864756

Tracked in #607, along with a gotcha worth keeping: grep the Post Harden runner section for
Reverted changes, not the whole run log — the assertion step's own error string contains that
phrase, so an unscoped grep always self-matches. Same shape as the grep egress-policy: block
trap the rule already documents.

Refs #578

Summary by CodeRabbit

  • Documentation
    • Expanded harden-runner inventory guidance with additional measured hosts and rotating Azure blob-host examples.
    • Clarified when deep reviews are skipped due to outdated workflow configuration.
    • Added guidance to update branches before relying on successful deep-review results.
    • Documented relevant incident references.

Two inaccuracies on main, both found by exercising the jobs #578 flipped rather
than by reading the files.

**Rule 10 said "the same eight hosts".** It is nine. Copilot caught during
review that the eight-host Claude-session list omits `nodejs.org`, which
setup-node falls back to when the toolcache misses and the
`actions/node-versions` lookup fails. The workflows were fixed; that sentence
was not. It now names the ninth host and says why measurement could not have
found it: none of the three jobs the list was copied from runs setup-node, and
across six audit runs the toolcache hit every time, so the fallback left no
endpoint in any log. Review caught it, not measurement. That is worth stating
next to a rule whose whole subject is measuring allowlists.

**The deep-review skip condition was too narrow.** CLAUDE.md said a PR that
MODIFIES claude-review.yml is not deep-reviewed. The real condition is a PR
whose copy of that file differs from the default branch's, because the workflow
runs from the PR head. A branch that merely predates a change to the file is
equally stale and equally silent -- green job, no review, no signal.

That is not hypothetical: #578's flip changed claude-review.yml, so every PR
opened before it now inherits a skipped review. #605 reproduced it exactly
(its own branch copy still read `egress-policy: audit`, session skipped), and
merging main into the branch fixed it.

Also records the blob host rotation reaching a seventh distinct name (sa17,
from the `claude` verification run), which strengthens the existing "cannot be
pinned even in principle" argument.
@coderabbitai

coderabbitai Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

Next included review available in 1 minute.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: d092bbb7-8321-44c4-a0f1-88c06a3137b7

📥 Commits

Reviewing files that changed from the base of the PR and between 7305999 and 9cadfb4.

📒 Files selected for processing (3)
  • .github/CLAUDE.md
  • .github/workflows/claude-review.yml
  • CLAUDE.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: f531a366-7ac4-4cec-88fc-a1fd3864533d

📥 Commits

Reviewing files that changed from the base of the PR and between e5ed56b and 7305999.

📒 Files selected for processing (2)
  • .github/CLAUDE.md
  • CLAUDE.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The PR updates harden-runner host measurements and Azure blob-host examples. It also clarifies deep-review skip conditions, stale workflow copies, related incidents, and branch update guidance.

Changes

Harden-runner inventory

Layer / File(s) Summary
Host and blob-host measurements
.github/CLAUDE.md
The inventory adds nodejs.org for actions/setup-node fallback behavior. The Azure blob-host examples add sa17.

Deep-review workflow guidance

Layer / File(s) Summary
Deep-review skip condition
CLAUDE.md
The documentation explains that stale claude-review.yml copies skip deep review, cites incidents #578 and #605, and advises updating branches before trusting a green job.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 73059

This is a documentation-only correction with no workflow behavior change, and no actionable merge-blocking risk remains after normal checks and review.

Suggested reviewers: claude

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies both primary documentation changes: correcting Rule 10's host count and broadening the deep-review skip condition.
Description check ✅ Passed The description provides a detailed summary, affected documentation scope, related issue references, rationale, and verification evidence. It does not use all template headings or checklist items, but…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description provides a detailed summary, affected documentation scope, related issue references, rationale, and verification evidence. It does not use all template headings or checklist items, but the substantive information is mostly complete.

Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/578-rule10-host-count-and-stale-review-branches

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Two passages still conflate branch age or measured endpoints with the actual conditions.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Updates automation documentation based on observed workflow behavior.

Changes:

  • Clarifies stale workflow copies can silently skip deep reviews.
  • Corrects the egress allowlist to nine hosts.
  • Records another rotating Actions blob hostname.
File summaries
File Description
CLAUDE.md Documents the generalized deep-review skip condition.
.github/CLAUDE.md Updates allowlist and rotating-host guidance.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread CLAUDE.md Outdated
Comment thread .github/CLAUDE.md Outdated
@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://655a83d1.bestax.pages.dev

Copilot caught two accuracy defects in a PR whose entire subject is accuracy,
which is a fair thing to have happen.

**Branch age is not the criterion.** The example said a branch that "predates" a
change to claude-review.yml is stale, which contradicts the precise condition
stated two sentences earlier. Age is neither necessary nor sufficient: an old
branch that has merged or rebased the current version is fine, and a branch
opened minutes ago off a stale base is not. What matters is only whether the
head's retained copy still matches the default branch.

**Measured set is not the allowlist.** The inventory said all six jobs "landed
on the same nine hosts", which conflates what the runs produced with what the
list contains -- and contradicts the next two sentences, which say nodejs.org
never appeared in any run. The runs surfaced six application hosts, a strict
subset of the eight already in use; nodejs.org is on the list despite never
being observed, and that gap is the whole reason the paragraph exists.
Copilot AI review requested due to automatic review settings August 30, 2026 14:36
@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://b7be1e1c.bestax.pages.dev

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The workflow’s inline documentation still retains the obsolete modifies-only explanation.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Balanced

Comment thread CLAUDE.md
Copilot's point, and a fair one: this PR corrected the misconception in
CLAUDE.md while leaving it intact at claude-review.yml:534, which is exactly
where someone editing the workflow would read it.

The comment said the action skips "when the PR modifies this workflow file".
The real condition is whether the PR head's copy differs from the default
branch's, whether or not the PR touched it. Now says so, and names the incident:
#578's flip changed this workflow, and every PR still carrying the pre-flip copy
started getting silently skipped reviews without having touched the file.

Comment-only change. No logic, triggers, permissions or action SHAs, and the
harden-runner step still reads block with nine hosts and its assertion
immediately after.
Copilot AI review requested due to automatic review settings August 30, 2026 14:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation-only changes are consistent with the workflow configuration and supplied run evidence.

Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://63b24b4b.bestax.pages.dev

@allxsmith
allxsmith merged commit c1d4278 into main Aug 30, 2026
24 checks passed
@allxsmith
allxsmith deleted the docs/578-rule10-host-count-and-stale-review-branches branch August 30, 2026 14:53
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 4.2.4 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 2.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 5.12.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.2.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants