Skip to content

ci: adapt GitHub reviews into review fabric receipts - #13524

Closed
teamleaderleo wants to merge 1 commit into
mainfrom
ci/review-fabric-github-adapter
Closed

teamleaderleo wants to merge 1 commit into
mainfrom
ci/review-fabric-github-adapter

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Stack the first real input adapter on #13522.

This converts cmux's existing trusted GitHub review ledger into the provider-neutral review-fabric receipt format without changing the current merge gate yet.

What gets adapted

  • structured GitHub bot review submissions -> external reviewer runs;
  • exact review commit SHA -> run head identity;
  • Greptile's mutable summary -> exact reviewed-head evidence through the existing trusted parser;
  • current inline bot findings -> provider-neutral findings;
  • existing truthful states -> pending, answered_unverified, resolved_unverified, resolved_unanswered, outdated, or unavailable.

Fail-closed provenance

An active thread does not imply that its provider reviewed the current head.

The adapter anchors a thread to a real structured review record. If it cannot establish that provenance, receipt capture becomes incomplete instead of inventing a current-head review session.

Old-head reviews remain old-head runs while their still-active findings can remain current obligations.

Deliberately conservative

  • external provider runs are capability class external, not frontier;
  • provider finding severity is unknown unless a later verifier supplies evidence;
  • a reply or GitHub resolution stays unverified;
  • external reviews alone cannot satisfy the default fabric policy from ci: add provider-neutral review fabric receipts #13522.

Testing

Adds 12 focused adapter tests covering:

  • current vs stale review identity;
  • current finding sourced from an old review;
  • missing provenance failing capture closed;
  • answered/resolved/outdated states;
  • changes-requested runs;
  • Greptile exact-head summary evidence;
  • ignored/dismissed reviewers;
  • unknown severity;
  • default fabric policy refusing external-only coverage.

Stacked on #13522.

Refs #13088.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Adapts the trusted GitHub review ledger into provider-neutral review-fabric receipts — the first input adapter for review fabric — without changing the current merge gate.

  • Structured bot reviews become external runs pinned to the exact reviewed commit; old reviews stay old-head runs while their still-active findings remain current obligations. Re-reviews of the same head share one session.
  • Greptile's mutable summary provides exact reviewed-head evidence through the existing trusted parser.
  • Inline comments anchor to their parent review record by pulling the review ID through the GraphQL query; anchoring is scoped by provider, so a comment attributed to a different review bot makes capture incomplete instead of mis-attributing the finding.
  • Provider severity stays unknown, and replies or GitHub resolutions stay unverified until a later verifier supplies evidence.
  • A thread without an anchored review record makes capture incomplete instead of fabricating a current-head review session.
  • External reviews alone can't satisfy the default fabric policy; two independent sessions and a frontier-class lane are still required.
  • Adds 14 tests covering current vs stale review identity, exact parent-review attribution, fail-closed provenance, lifecycle states, and policy refusal.

Written for commit b1963b9. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 7 seconds.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c42929b3-7133-487d-aa0c-9886b1ed2450

📥 Commits

Reviewing files that changed from the base of the PR and between 2c4282e and b1963b9.

📒 Files selected for processing (6)
  • .github/review-fabric.md
  • .github/scripts/agent-pr-review-gate.py
  • .github/scripts/github_review_receipt.py
  • .github/workflows/ci-guards.yml
  • scripts/ci/detect_linux_guard_changes.py
  • tests/test_github_review_receipt.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

3 similar comments
@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Sep 22, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@teamleaderleo
teamleaderleo changed the base branch from ci/review-fabric-receipts to main September 22, 2026 02:16
Squashed onto current main after #13522 merged.
@teamleaderleo
teamleaderleo force-pushed the ci/review-fabric-github-adapter branch from 52466e9 to b1963b9 Compare September 22, 2026 02:27
@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Copy link
Copy Markdown
Collaborator Author

@greptileai review

Copy link
Copy Markdown
Collaborator Author

@greptile-apps review

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Closing: depends on .github/scripts/agent-pr-review-gate.py, which #13641 removed. Can be revived on a different base if the review-fabric idea comes back.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant