Skip to content

ci: remove check-ci gate, drop run-ci label, skip e2e for Dependabot - #550

Merged
slin1237 merged 1 commit into
mainfrom
fix/simplify-ci-gating
Feb 27, 2026
Merged

slin1237 merged 1 commit into
mainfrom
fix/simplify-ci-gating

Conversation

@CatherineSue

@CatherineSue CatherineSue commented Feb 26, 2026 •

Copy link
Copy Markdown
Member

Description

Problem

The custom check-ci action has bugs — it uses github.event.pull_request.author_association which returns the PR author's association, not the event actor's. This means repo owners/members triggering CI on behalf of external PRs (e.g. Dependabot) still get gated. The run-ci label was a workaround but added manual overhead.

Additionally, Dependabot PRs only have access to Dependabot-scoped secrets (not repo secrets), so e2e tests that require HF_TOKEN, OPENAI_API_KEY, etc. will always fail.

Solution

  • Remove check-ci entirely — rely on GitHub's native "Require approval for outside collaborators" setting for fork PR gating
  • Remove run-ci label — no longer needed without check-ci
  • Skip e2e jobs for Dependabot PRs — they can't access repo secrets anyway

Changes

  • Delete .github/actions/check-ci/action.yml
  • Remove check-ci job and all needs/if references from pr-test-rust.yml
  • Remove check-ci job from 5 benchmark workflows (benchmark-tokenizer, benchmark-radix-tree, benchmark-tool-parser, benchmark-manual-policy, benchmark-request-processing)
  • Remove labeled from PR trigger types (no longer needed without run-ci label)
  • Add if: github.actor != 'dependabot[bot]' to gateway-e2e and go-bindings-e2e jobs
  • Update finish job to remove check-ci dependency

Test Plan

  • Internal PR (this one): All non-e2e jobs run unconditionally; e2e jobs run normally
  • Dependabot PR: Lint, unit-tests, build-wheel run; e2e jobs are skipped; finish passes (skipped != failure)
  • Fork PR: Blocked by GitHub's native "Require approval for outside collaborators" setting
Checklist
  • cargo +nightly fmt passes
  • cargo clippy --all-targets --all-features -- -D warnings passes
  • (Optional) Documentation updated

Manual setup required

After merging, enable "Require approval for all outside collaborators" in repo Settings > Actions > General > Fork pull request workflows.

Summary by CodeRabbit

Release Notes

  • Chores
    • Removed CI gating logic that controlled workflow execution based on contributor status and labels
    • Simplified workflow dependencies by eliminating intermediate validation steps across benchmark and test workflows
    • Streamlined GitHub Actions configuration for more direct and efficient pipeline execution

- Delete .github/actions/check-ci/ (buggy and redundant with GitHub's
  native fork approval)
- Remove check-ci job and all needs/if references from pr-test-rust.yml
  and 5 benchmark workflows
- Remove 'labeled' trigger type (no longer needed without run-ci label)
- Skip gateway-e2e and go-bindings-e2e for Dependabot PRs (no repo
  secrets available)

Signed-off-by: Chang Su <chang.s.su@oracle.com>
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request streamlines the continuous integration (CI) workflow by addressing issues with a custom CI gating mechanism and optimizing Dependabot PRs. It eliminates a buggy custom action, removes a redundant label, and intelligently skips e2e tests for Dependabot to prevent unnecessary failures, ultimately making the CI process more efficient and reliable.

Highlights

  • CI Gate Removal: The custom check-ci GitHub Action has been removed due to a bug where it incorrectly gated CI runs for repo members triggering CI on behalf of external PRs. Gating will now rely on GitHub's native "Require approval for outside collaborators" setting.
  • run-ci Label Deprecation: The run-ci label, previously used as a workaround for the check-ci action's limitations, has been removed as it is no longer necessary.
  • Dependabot E2E Skip: End-to-end (e2e) tests are now skipped for Dependabot pull requests because Dependabot lacks access to necessary repository secrets (e.g., HF_TOKEN, OPENAI_API_KEY), which caused these tests to consistently fail.
Changelog
  • .github/actions/check-ci/action.yml
    • Removed the custom check-ci GitHub Action definition.
  • benchmark-manual-policy.yml
    • Removed the check-ci job.
  • benchmark-radix-tree.yml
    • Removed the check-ci job.
  • benchmark-request-processing.yml
    • Removed the check-ci job.
  • benchmark-tokenizer.yml
    • Removed the check-ci job.
  • benchmark-tool-parser.yml
    • Removed the check-ci job.
  • pr-test-rust.yml
    • Removed the check-ci job and all its needs and if references.
    • Removed labeled from the pull request trigger types.
    • Added a condition to skip gateway-e2e and go-bindings-e2e jobs for Dependabot PRs.
    • Updated the finish job to remove its dependency on check-ci.
Ignored Files
  • Ignored by pattern: .github/workflows/** (6)
    • .github/workflows/benchmark-manual-policy.yml
    • .github/workflows/benchmark-radix-tree.yml
    • .github/workflows/benchmark-request-processing.yml
    • .github/workflows/benchmark-tokenizer.yml
    • .github/workflows/benchmark-tool-parser.yml
    • .github/workflows/pr-test-rust.yml
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@coderabbitai

coderabbitai Bot commented Feb 26, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 0a35337 and 2069dae.

📒 Files selected for processing (7)
  • .github/actions/check-ci/action.yml
  • .github/workflows/benchmark-manual-policy.yml
  • .github/workflows/benchmark-radix-tree.yml
  • .github/workflows/benchmark-request-processing.yml
  • .github/workflows/benchmark-tokenizer.yml
  • .github/workflows/benchmark-tool-parser.yml
  • .github/workflows/pr-test-rust.yml
💤 Files with no reviewable changes (1)
  • .github/actions/check-ci/action.yml

📝 Walkthrough

Walkthrough

Removes the check-ci GitHub Action that gated CI execution based on pull_request context, actor identity, and run-ci labels. Updates six workflow files (five benchmark workflows and pr-test-rust.yml) to eliminate this centralized gate, replacing it with simplified repository-specific conditions or direct job dependencies.

Changes

Cohort / File(s) Summary
Removed check-ci action
.github/actions/check-ci/action.yml
Removed composite action that computed should_run boolean based on event type, actor (dependabot exemption), author association (OWNER/MEMBER/COLLABORATOR), and run-ci label presence; controlled whether CI should execute for external contributors.
Updated benchmark workflows
.github/workflows/benchmark-*.yml
Removed check-ci job dependency across five benchmark workflows (manual-policy, radix-tree, request-processing, tokenizer, tool-parser); simplified job conditions to run unconditionally for repository lightseekorg/smg.
Updated PR test workflow
.github/workflows/pr-test-rust.yml
Removed check-ci job and dependency chain; updated job conditionals to use direct job dependencies (build-wheel) or removed needs entirely; adjusted finish job to evaluate individual job results instead of check-ci output; excluded dependabot via actor checks instead of centralized gate.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

Suggested labels

ci, tests

Suggested reviewers

  • slin1237
  • XinyueZhang369
  • key4ng

Poem

🐰 A gate that once guarded the CI's great run,
Now vanishes quietly—its work finally done!
Workflows flow simpler, straight as can be,
No labels or checks, just repository spree! ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: removing the check-ci gate, dropping the run-ci label, and skipping e2e jobs for Dependabot PRs, which are the core objectives of this changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/simplify-ci-gating

Comment @coderabbitai help to get the list of available commands and usage tips.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request improves the CI/CD pipeline by removing a buggy custom GitHub action (check-ci) and replacing it with GitHub's native functionality for gating pull requests from external collaborators. It also intelligently skips end-to-end tests for Dependabot PRs, which lack the necessary secrets to run them successfully. These changes simplify the CI configuration, remove the need for manual workarounds like the run-ci label, and make the process more robust and maintainable.

@github-actions github-actions Bot added the ci CI/CD configuration changes label Feb 26, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2069daede2

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread .github/workflows/pr-test-rust.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants