Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 3 additions & 9 deletions .github/workflows/claude-code-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,6 @@ on:
- 'docs/**'
- '*.lock'
- 'mkdocs.yml'
# Allow maintainers to trigger Claude review for fork PRs via 'ci-approved' label.
pull_request_target:
types: [labeled, synchronize]
issue_comment:
types: [created]
pull_request_review_comment:
Expand All @@ -27,12 +24,10 @@ jobs:
review:
name: Claude PR Review
if: >-
github.repository == 'lightseekorg/smg'
github.event_name == 'pull_request'
&& github.repository == 'lightseekorg/smg'
&& github.actor != 'dependabot[bot]'
&& (
(github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork)
|| (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'ci-approved'))
)
&& !github.event.pull_request.head.repo.fork
runs-on: k8s-runner-cpu
timeout-minutes: 30
concurrency:
Expand All @@ -42,7 +37,6 @@ jobs:
- name: Checkout
uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha }}
fetch-depth: 0
Comment on lines 37 to 40

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Pin checkout to PR head SHA for incremental review

Removing the ref from actions/checkout makes pull_request runs check out GitHub’s synthetic merge ref instead of the PR head commit, but this workflow’s prompt still relies on git diff ${{ github.event.before }}..HEAD to review only the latest push. On synchronize events for long-lived PRs, HEAD now includes merge-base updates from main, so Claude can re-review unrelated upstream changes and post noisy/incorrect inline comments. Keeping checkout pinned to github.event.pull_request.head.sha avoids that regression.

Useful? React with 👍 / 👎.


- name: Export API key from pod env
Expand Down
45 changes: 3 additions & 42 deletions .github/workflows/pr-test-rust.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,46 +14,27 @@ on:
- "docs/**"
- "mkdocs.yml"
- "*.md"
# Allow maintainers to trigger CI for fork PRs by adding the 'ci-approved' label.
# pull_request_target runs in the base branch context, bypassing the fork approval gate.
# 'synchronize' re-runs CI on subsequent pushes while the label is present.
pull_request_target:
branches: [ main ]
types: [labeled, synchronize]
workflow_dispatch:

permissions:
contents: read

concurrency:
group: gateway-tests-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
group: gateway-tests-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

env:
RUSTC_WRAPPER: sccache
SCCACHE_GHA_ENABLED: "true"
GENAI_BENCH_IMAGE: ghcr.io/moirai-internal/genai-bench:0.0.4

jobs:
# Gate job: for pull_request_target, only proceed if 'ci-approved' label is present.
# All other triggers (push, pull_request, workflow_dispatch) pass through unconditionally.
ci-gate:
runs-on: ubuntu-latest
if: >-
github.event_name != 'pull_request_target' ||
contains(github.event.pull_request.labels.*.name, 'ci-approved')
steps:
- run: echo "CI gate passed"

pre-commit:
needs: [ci-gate]
runs-on: k8s-runner-cpu
permissions:
contents: read
steps:
- uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up Python
uses: actions/setup-python@v6
Expand All @@ -69,14 +50,11 @@ jobs:
run: pre-commit run --all-files --show-diff-on-failure

python-lint:
needs: [ci-gate]
runs-on: k8s-runner-cpu
permissions:
contents: read
steps:
- uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up Python
uses: actions/setup-python@v6
Expand All @@ -99,14 +77,11 @@ jobs:
run: mypy bindings/python/ --config-file mypy.ini

grpc-proto-build-check:
needs: [ci-gate]
runs-on: k8s-runner-cpu
permissions:
contents: read
steps:
- uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up Python
uses: actions/setup-python@v6
Expand All @@ -128,14 +103,11 @@ jobs:
python -c "from smg_grpc_proto import sglang_scheduler_pb2; print('OK')"

build-wheel:
needs: [ci-gate]
runs-on: k8s-runner-gpu
permissions:
contents: read
steps:
- uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Cache wheel and Go FFI artifacts
id: cache-wheel
Expand Down Expand Up @@ -261,14 +233,11 @@ jobs:
pytest -q tests --cov=smg --cov-config=.coveragerc --cov-report=term-missing --cov-fail-under=80

unit-tests:
needs: [ci-gate]
runs-on: k8s-runner-cpu
permissions:
contents: read
steps:
- uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

- name: Set up Python
uses: actions/setup-python@v6
Expand Down Expand Up @@ -390,9 +359,8 @@ jobs:
retention-days: 7

detect-changes:
needs: [ci-gate]
runs-on: ubuntu-latest
if: github.event_name == 'pull_request' || github.event_name == 'pull_request_target'
if: github.event_name == 'pull_request'
permissions:
contents: read
pull-requests: read
Expand Down Expand Up @@ -465,7 +433,6 @@ jobs:
&& needs.build-wheel.result == 'success'
&& github.actor != 'dependabot[bot]'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.chat-completions == 'true')))
Expand Down Expand Up @@ -526,7 +493,6 @@ jobs:
&& needs.build-wheel.result == 'success'
&& github.actor != 'dependabot[bot]'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.embeddings == 'true')))
Expand Down Expand Up @@ -557,7 +523,6 @@ jobs:
&& needs.build-wheel.result == 'success'
&& github.actor != 'dependabot[bot]'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.chat-completions == 'true')))
Expand Down Expand Up @@ -611,7 +576,6 @@ jobs:
&& needs.build-wheel.result == 'success'
&& github.actor != 'dependabot[bot]'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.agentic == 'true')))
Expand All @@ -633,7 +597,6 @@ jobs:
&& !cancelled()
&& needs.e2e-1gpu-gateway.result == 'success'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.chat-completions == 'true')))
Expand Down Expand Up @@ -702,7 +665,6 @@ jobs:
&& needs.build-wheel.result == 'success'
&& github.actor != 'dependabot[bot]'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.agentic == 'true')))
Expand Down Expand Up @@ -850,7 +812,6 @@ jobs:
&& needs.build-wheel.result == 'success'
&& github.actor != 'dependabot[bot]'
&& (github.event_name != 'pull_request'
&& github.event_name != 'pull_request_target'
|| (needs.detect-changes.result == 'success'
&& (needs.detect-changes.outputs.common == 'true'
|| needs.detect-changes.outputs.go-bindings == 'true')))
Expand Down
Loading