Skip to content

OSAC-2815: Run EP review from osac-workspace context - #122

Merged
openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
ItzikEzra-rh:fix/OSAC-2815-ep-review-workspace-context
Jul 16, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
ItzikEzra-rh:fix/OSAC-2815-ep-review-workspace-context

Conversation

@ItzikEzra-rh

@ItzikEzra-rh ItzikEzra-rh commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Copy the osac-workspace clone as the workdir base so Claude Code starts its session with full project context (CLAUDE.md, AGENTS.md, .claude/rules/, skills/)
  • Fix stale ep-review -> design-review references in detect_skills() and validate_scores() (closes OSAC-2814)
  • Rename workflow step "Clone skills repo" -> "Clone workspace"

Problem

The EP review GitHub Action cloned osac-workspace only to grab skill files, but Claude Code ran from a bare /workspace with no project context. After the skill rename (ep-review -> design-review in OSAC-1986), the skill file copy also broke silently — Claude reviewed without any skill criteria.

OTEL evidence from run 29440385042:

  • Read /workspace/.context/skill-prompt.md -> "File does not exist"
  • First LLM call cache_read=0 (no project context loaded)

Fix

Instead of work_dir.mkdir(), copy the osac-workspace clone as the workdir base via shutil.copytree. When agentic-ci mounts it as /workspace, Claude Code sees the full workspace natively.

Verified

Tested on fork PR ItzikEzra-rh#20 — OTEL from run 29493446005:

  • Read /workspace/.context/skill-prompt.md -> success (no errors)
  • First LLM call cache_read=28,861 (CLAUDE.md + AGENTS.md + rules loaded)
  • Zero tool errors
  • verdict.json written successfully

Closes: OSAC-2814

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Improved review handling for design-focused evaluations.
    • Corrected score validation when determining the appropriate review type.
    • Ensured each review runs with a refreshed workspace for more consistent results.
  • Chores

    • Updated workflow labeling to reflect workspace setup more accurately.

The EP review GitHub Action cloned osac-workspace only to grab skill
files, but Claude Code ran from a bare /workspace with no project
context. After the skill rename (ep-review -> design-review in
OSAC-1986), the skill file copy also broke silently.

Fix both issues:
- Copy the osac-workspace clone as the workdir base so Claude Code
  starts its session with CLAUDE.md, AGENTS.md, .claude/rules/,
  and skills/ all present
- Update stale ep-review references to design-review in
  detect_skills() and validate_scores()

Closes: OSAC-2814

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Itzik Ezra <iezra@redhat.com>
@openshift-ci-robot

openshift-ci-robot commented Jul 16, 2026 •

Copy link
Copy Markdown

@ItzikEzra-rh: This pull request references OSAC-2815 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Copy the osac-workspace clone as the workdir base so Claude Code starts its session with full project context (CLAUDE.md, AGENTS.md, .claude/rules/, skills/)
  • Fix stale ep-review -> design-review references in detect_skills() and validate_scores() (closes OSAC-2814)
  • Rename workflow step "Clone skills repo" -> "Clone workspace"

Problem

The EP review GitHub Action cloned osac-workspace only to grab skill files, but Claude Code ran from a bare /workspace with no project context. After the skill rename (ep-review -> design-review in OSAC-1986), the skill file copy also broke silently — Claude reviewed without any skill criteria.

OTEL evidence from run 29440385042:

  • Read /workspace/.context/skill-prompt.md -> "File does not exist"
  • First LLM call cache_read=0 (no project context loaded)

Fix

Instead of work_dir.mkdir(), copy the osac-workspace clone as the workdir base via shutil.copytree. When agentic-ci mounts it as /workspace, Claude Code sees the full workspace natively.

Verified

Tested on fork PR ItzikEzra-rh#20 — OTEL from run 29493446005:

  • Read /workspace/.context/skill-prompt.md -> success (no errors)
  • First LLM call cache_read=28,861 (CLAUDE.md + AGENTS.md + rules loaded)
  • Zero tool errors
  • verdict.json written successfully

Closes: OSAC-2814

🤖 Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from danmanor and mennyaboush July 16, 2026 11:33
@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 3878fd0f-38fa-4750-bb39-3746955a638f

📥 Commits

Reviewing files that changed from the base of the PR and between b861fd5 and c6df563.

📒 Files selected for processing (3)
  • .github/scripts/ep_hooks.py
  • .github/scripts/ep_review.py
  • .github/workflows/ep-review.yml

Walkthrough

The review action now selects the design-review skill, aligns fallback score validation with that name, and rebuilds each skill workspace by copying the skills tree while excluding .git. The workflow clone step label now refers to the workspace.

Changes

Design review execution

Layer / File(s) Summary
Design skill selection and score validation
.github/scripts/ep_review.py, .github/scripts/ep_hooks.py
Design detection selects design-review, while score validation uses DESIGN_KEYS for that skill and PRD_KEYS otherwise.
Per-skill workspace rebuilding
.github/scripts/ep_review.py, .github/workflows/ep-review.yml
Existing per-skill workspaces are removed and repopulated from SKILLS_PATH excluding .git; the workflow step is renamed to “Clone workspace”.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested labels: approved, lgtm

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: running EP review from the osac-workspace context.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed Touched files only reference GitHub secrets/env vars; no hardcoded keys, passwords, tokens, embedded creds, or long base64 literals were added.
No-Weak-Crypto ✅ Passed Touched files only use commit SHA/label comparisons and file-copy logic; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret/tokens comparisons found.
No-Injection-Vectors ✅ Passed No added injection vectors found: the changed Python code uses argv-list subprocess calls and adds no shell=True, eval/exec, pickle/yaml load, os.system, or dangerous HTML.
Container-Privileges ✅ Passed Changed files are only Python/workflow; no container/K8s manifests or privileged settings were added.
No-Sensitive-Data-In-Logs ✅ Passed The patch adds no new logging of secrets/PII; existing prints only surface PR/sha/skill status, not credentials or customer data.
Ai-Attribution ✅ Passed PR commit c6df563 includes an Assisted-by trailer for Claude Code, and the PR range has no Co-Authored-By AI attribution.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@eranco74 eranco74 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue 1 (skill name mismatch): FIXED. The Read of /workspace/.context/skill-prompt.md succeeds in the new run (it failed in the old one). The workdir name also changed from workdir-ep-review to workdir-design-review, confirming detect_skills() now maps
to the correct skill name.

Issue 2 (osac-workspace as working directory): NOT FIXED. The working directory is still /workspace (a bare container directory). There's no evidence that CLAUDE.md or .claude/ from osac-workspace was loaded — no file reads to those paths, and the
container still runs with the same agent.backend: podman setup writing .context/ into a bare /workspace. The osac-workspace repo is only used to extract skills/design-review/SKILL.md into .context/skill-prompt.md, but the workspace itself (with its
CLAUDE.md, project configuration, and guidelines) is not the container's working directory.


- name: Clone skills repo
- name: Clone workspace
run: git clone --depth 1 https://github.com/osac-project/osac-workspace /opt/skills

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this the working dir??
Seems like this is where it's going to look for skills

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Never mind

Summary of the EP review OTEL investigation:

  • Issue 1 (skill name mismatch): Fixed in pr20. detect_skills() was mapping design docs to "ep-review" but the skill in osac-workspace is "design-review". The new run shows skill-prompt.md loading successfully and the workdir is named
    workdir-design-review.

  • Issue 2 (osac-workspace as working directory): Was already working, just not visible in OTEL. Claude Code loads CLAUDE.md and .claude/rules/ into the system prompt automatically - they appear as cached tokens (~9k token increase from 34k to 43k), not
    as Read tool calls. The agentic-ci chain copies osac-workspace contents into the workdir, which gets bind-mounted as /workspace in the container.

One architectural note: /opt/skills (the osac-workspace clone) serves double duty - it's both the skills source for resolving SKILL.md files and the workspace template that gets copied into the container.
This works because both live in the same repo, but it's a hidden coupling. The variable name skills_path is also misleading since it points at the repo root, not the skills/ subdirectory.

@eranco74

Copy link
Copy Markdown
Contributor

/lgtm
/approve

@openshift-ci

openshift-ci Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eranco74, ItzikEzra-rh

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit cf09184 into osac-project:main Jul 16, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants