Skip to content

ci(jules): keep provider controls out of feedback relay - #242

Merged
timerloggedout-spec merged 3 commits into
masterfrom
manus/jules-provider-control-guard
Aug 18, 2026
Merged

timerloggedout-spec merged 3 commits into
masterfrom
manus/jules-provider-control-guard

Conversation

@timerloggedout-spec

@timerloggedout-spec timerloggedout-spec commented Aug 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

This is a focused follow-up to merged PR #241. PR #241 merged before the remaining Jules relay guard could be added, so this branch is rebuilt cleanly from current master and contains only that guard.

The workflow now distinguishes provider controls from substantive review feedback. A CodeRabbit comment containing its provider checkboxId, Trigger review, and automatic-review eligibility notice exits before it can summon Jules. The control remains in the separate authorized Operator Action path introduced by PR #241.

The amendment also extends Jules feedback recognition to Qodo and edited provider comments, so substantive provider feedback can be relayed after it is posted or updated. It retains the current durable context_key and continue-only Jules behavior.

Validation

Security boundary

The workflow does not select provider UI controls or access browser cookies/session material. It only suppresses relay of the recognized control-only notice.

Summary by CodeRabbit

  • Improvements

    • Improved automated review coordination with more reliable event tracking and completion checks.
    • Added stronger validation for review sources, pull request revisions, review cycles, and operator actions.
    • Prevented duplicate review relays and ignored irrelevant provider notifications.
    • Added a verified follow-up review pass after required provider reviews are complete.
  • Documentation

    • Clarified operator authorization requirements and configuration options for interactive actions.

Agent-Identity: Manus

Task-Ref: interactive-peer-gate
Signed-off-by: Manus <manus@manus.im>
@blocksorg

blocksorg Bot commented Aug 18, 2026

Copy link
Copy Markdown

Mention Blocks like a regular teammate with your question or request:

@blocks review this pull request
@blocks make the following changes ...
@blocks create an issue from what was mentioned in the following comment ...
@blocks explain the following code ...
@blocks are there any security or performance concerns?

Run @blocks /help for more information.

Workspace settings | Disable this message

@vercel

vercel Bot commented Aug 18, 2026

Copy link
Copy Markdown

Deployment failed for project termux-monorepo with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 9d474e39-68f9-4183-9c1b-88f4c6126821

📥 Commits

Reviewing files that changed from the base of the PR and between a3af6bd and 0c0c1f2.

📒 Files selected for processing (4)
  • .github/workflows/agent-review-auto-jules.yml
  • .github/workflows/gemini-after-peers.yml
  • .github/workflows/peer-review-orchestrator.yml
  • docs/ops/OPERATOR_INTERACTIVE_ACTIONS.md

📝 Walkthrough

Walkthrough

The workflows now validate trusted review providers, track source revisions, bind peer evidence to cycles and head SHAs, enforce exact operator authorization, and dispatch the Gemini second pass through validated manual inputs.

Changes

Review automation hardening

Layer / File(s) Summary
Provider relay validation
.github/workflows/agent-review-auto-jules.yml
Edited feedback is accepted from four allowlisted providers. Control notices are filtered. Relay deduplication uses provider source revisions and includes source metadata in Jules comments.
Cycle-bound provider collection
.github/workflows/peer-review-orchestrator.yml, docs/ops/OPERATOR_INTERACTIVE_ACTIONS.md
Provider identities, check applications, operator logins, actions, acknowledgements, timestamps, and current head SHAs are validated before collection completes.
State publication and second-pass dispatch
.github/workflows/peer-review-orchestrator.yml
Cycle start data is persisted. State updates require matching cycle and SHA values. The workflow dispatches Gemini with the PR number, head SHA, and cycle ID.
Manual Gemini second-pass validation
.github/workflows/gemini-after-peers.yml
Gemini runs through validated manual dispatch inputs. Peer-state comments must match the GitHub Actions bot, cycle ID, and head SHA.

Estimated code review effort: 4 (Complex) | ~60 minutes

Possibly related issues

  • timerloggedout-spec/termux-monorepo#95 — The changes address stale bot-review governance through stricter provider identity and SHA-bound validation.

Possibly related PRs

Suggested labels: gh, ActionsWorkflows

Suggested reviewers: cjwtrust

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch manus/jules-provider-control-guard

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

context_key: pr-242-manusjules-provider-control-guard
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
New work-context pr-242-manusjules-provider-control-guard — create session if none exists, then prefer continue thereafter.
Bot feedback from coderabbitai[bot] on PR #242 (branch manus/jules-provider-control-guard).

Feedback excerpt

<!-- This is an auto-generated comment: summarize by coderabbit.ai -->
<!-- This is an auto-generated comment: skip review by coderabbit.ai -->

> [!IMPORTANT]
> - [ ] <!-- {"checkboxId":"e9bb8d72-00e8-4f67-9cb2-caf3b22574fe"} --> 🔍 Trigger review
> 
> This repository does not receive automatic reviews because it has fewer than 10 stars.
> 
> <details>
> <summary>⚙️ Run configuration</summary>
> 
> **Configuration used**: Path: .coderabbit.yaml
> 
> **Review profile**: ASSERTIVE
> 
> **Plan**: Pro Plus
> 
> **Run ID**: `a9f83316-2c61-47f2-9c76-d7e0d24785be`
> 
> </details>

<!-- end of auto-generated comment: skip review by coderabbit.ai -->

<!-- tips_start -->

---

Thanks for using [CodeRabbit](https://coderabbit.ai?utm_source=oss&utm_medium=github&utm_campaign=timerloggedout-spec/termux-monorepo&utm_content=242)! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

<details>
<summary>❤️ Share</summary>

- [X](https://twitter.com/intent/tweet?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20cod

Instructions

  1. Address open review disposition / threads (CodeRabbit, Devin, Copilot). Ignore pure analysis-chain dumps.
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch manus/jules-provider-control-guard. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
  6. Non-empty diff required — empty commits are rejected.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok
    Signed-off-by: Grok (OPERATOR) session-auto-jules / context_key=pr-242-manusjules-provider-control-guard

@gitar-bot

gitar-bot Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Gitar is working

Gitar

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Keep provider controls out of the Jules feedback relay

🐞 Bug fix ✨ Enhancement ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Prevent CodeRabbit control-only notices from triggering the Jules feedback relay.
• Relay Qodo feedback and edited provider reviews or comments.
• Preserve authorized operator controls and durable continue-only Jules context.
Diagram

graph TD
  A["Provider Event"] --> B{"Recognized Bot?"} -- "Yes" --> D{"Control Only?"} -- "No" --> F["Durable Context"] --> G["Jules Relay"]
  B -- "No" --> C["Skip Workflow"]
  D -- "Yes" --> E["Operator Path"]
Loading
High-Level Assessment

The focused conjunctive fingerprint is appropriate for this follow-up: it suppresses only the known provider-control template before API and cache work while preserving substantive feedback. Broader text exclusions could hide real reviews, and moving provider controls into this workflow would violate the established operator authorization boundary.

Files changed (1) +19 / -4

Bug fix (1) +19 / -4
agent-review-auto-jules.ymlFilter provider controls and expand substantive feedback recognition +19/-4

Filter provider controls and expand substantive feedback recognition

• Adds edited-event handling and explicit Qodo recognition across review feedback triggers. Detects CodeRabbit control-only notices before PR lookup, context restoration, or Jules invocation, leaving those controls in the authorized operator path.

.github/workflows/agent-review-auto-jules.yml

@qodo-code-review

qodo-code-review Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Debounce discards edited feedback ✓ Resolved 🐞 Bug ≡ Correctness
Description
An edited provider comment within 20 minutes of the previous relay passes detection but the posting
step returns solely because a recent generated marker exists. The edited body is never relayed to
Jules, defeating the newly advertised support for feedback updates.
Code

.github/workflows/agent-review-auto-jules.yml[19]

+    types: [created, edited]
Relevance

●●● Strong

Accepted history favors preserving updated feedback despite recent-marker debounce; similar marker
suppression was narrowed by source identity or SHA.

PR-#93
PR-#193

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The new trigger starts a run for an edited review comment, but the relay queries generated comments
and returns whenever the newest marker is under 20 minutes old. It never compares the source comment
ID, updated_at, or edited body, so the update is omitted.

.github/workflows/agent-review-auto-jules.yml[17-21]
.github/workflows/agent-review-auto-jules.yml[147-184]
.github/workflows/agent-review-auto-jules.yml[189-223]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new edited-comment trigger is defeated by the existing PR-wide 20-minute debounce, which ignores the updated feedback body.

## Issue Context
Deduplication should identify the source review/comment and its revision, updated timestamp, or body hash. It should suppress only an already-relayed revision, not every provider update occurring shortly after another relay.

## Fix Focus Areas
- .github/workflows/agent-review-auto-jules.yml[17-21]
- .github/workflows/agent-review-auto-jules.yml[147-184]
- .github/workflows/agent-review-auto-jules.yml[189-223]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. Qodo substring authorizes humans ✓ Resolved 🐞 Bug ⛨ Security
Description
The new unanchored contains(..., 'qodo') checks classify any human account whose login contains
that substring as a provider bot. Their comments can consequently generate a trusted @jules
instruction that asks Jules to push commits to the PR branch.
Code

.github/workflows/agent-review-auto-jules.yml[35]

+          contains(github.event.review.user.login, 'qodo') ||
Relevance

●●● Strong

PR #193 explicitly accepted tightening unanchored bot or agent substring detection to prevent human
false positives.

PR-#193

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The added Qodo substring is an alternative to the Bot type check, so a matching human login passes
the job condition. The resulting generated comment tells @jules to address feedback and push
commits, and past PR #193 documents the same accepted false-positive pattern for unanchored
agent-login matching.

.github/workflows/agent-review-auto-jules.yml[31-60]
.github/workflows/agent-review-auto-jules.yml[189-223]
PR-#193

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The workflow recognizes Qodo using an unanchored login substring, allowing unrelated human accounts with `qodo` in their usernames to trigger the automated Jules write path.

## Issue Context
The same predicate was added for reviews, inline review comments, and issue comments. Match exact known provider logins and/or require GitHub's `Bot` user type rather than trusting a substring.

## Fix Focus Areas
- .github/workflows/agent-review-auto-jules.yml[31-60]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Control variants still relay ✓ Resolved 🐞 Bug ≡ Correctness
Description
isProviderControlOnly requires all three signatures simultaneously, while the existing authorized
operator path classifies either the checkbox-plus-trigger form or the automatic-review eligibility
notice as control-only. Those already-recognized control variants therefore continue into the Jules
relay instead of remaining in the operator path.
Code

.github/workflows/agent-review-auto-jules.yml[R94-97]

+            const isProviderControlOnly =
+              /<!--\s*\{[^}]*"checkboxId"[^}]*\}\s*-->/i.test(rawProviderBody) &&
+              /\btrigger review\b/i.test(rawProviderBody) &&
+              /\bdoes not receive automatic reviews\b/i.test(rawProviderBody);
Relevance

●●● Strong

The guard’s AND predicate conflicts with established OR control classification, a concrete
correctness gap in the stated control-only intent.

PR-#93

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The new guard combines its three tests with &&, but the repository's operator-path isControlOnly
predicate recognizes checkboxId...Trigger review or does not receive automatic reviews. After a
partial match fails here, metadata resolution sets should_invoke=true, enabling the relay.

.github/workflows/agent-review-auto-jules.yml[93-115]
.github/workflows/peer-review-orchestrator.yml[193-209]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The relay guard and operator-action path use inconsistent definitions of provider control-only content, allowing recognized controls to reach Jules.

## Issue Context
The operator workflow uses an OR between the checkbox/Trigger review pattern and the automatic-review notice, whereas the new relay guard requires all components. Consolidate or exactly align these predicates while preserving the intended control-only boundary.

## Fix Focus Areas
- .github/workflows/agent-review-auto-jules.yml[93-102]
- .github/workflows/peer-review-orchestrator.yml[193-195]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

4. Concurrent edits lose feedback ✓ Resolved 🐞 Bug ☼ Reliability
Description
All newly enabled edit events for a PR share one concurrency group, and GitHub retains only one
pending run even when cancel-in-progress is false. If different provider comments are edited while
another run is active, an older pending edit is canceled and its payload is never enumerated or
relayed.
Code

.github/workflows/agent-review-auto-jules.yml[R19-21]

+    types: [created, edited]
  issue_comment:
-    types: [created]
+    types: [created, edited]
Relevance

●●● Strong

Recent workflow history accepts concurrency changes when side-effecting runs can silently discard
distinct work.

PR-#31
PR-#193

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The edit triggers use a PR-number concurrency group, while each run processes only its own
context.payload.review or context.payload.comment. GitHub documents that a concurrency group has
at most one running and one pending workflow and that a newer queued run replaces the existing
pending run by default.

.github/workflows/agent-review-auto-jules.yml[17-25]
.github/workflows/agent-review-auto-jules.yml[174-184]
🌐 GitHub states that only one run may be pending in a concurrency group and a newly queued run replaces the existing pending run by default.

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
PR-wide concurrency can cancel pending edited-feedback runs, permanently dropping their event-specific payloads.

## Issue Context
Either configure concurrency to retain queued runs, use source comment/review identity in the group, or aggregate all unprocessed provider feedback when a surviving run executes.

## Fix Focus Areas
- .github/workflows/agent-review-auto-jules.yml[17-25]
- .github/workflows/agent-review-auto-jules.yml[174-184]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Compliance rules (platform): 11 rules
✅ Web pages:
  +2 more
Review mode: ⚖️ Balanced: This changes a GitHub Actions relay trigger and classifier/security boundary across multiple event paths, so it carries real behavioral risk but not enough independent logic for extended review.

Grey Divider

Tip of the day
💡 Did you know, you can keep summaries lean with Finding overflow, which tucks the rest behind 'View more'

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread .github/workflows/agent-review-auto-jules.yml Outdated
Comment thread .github/workflows/agent-review-auto-jules.yml Outdated
Comment thread .github/workflows/agent-review-auto-jules.yml
Comment thread .github/workflows/agent-review-auto-jules.yml
Agent-Identity: Manus

Review-Source: qodo-code-review[bot]

Task-Ref: PR-242
Signed-off-by: Manus <manus@manus.im>
@vercel

vercel Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
termux-monorepo Ready Ready Preview, v0 Aug 18, 2026 8:38pm

Agent-Identity: Manus

Review-Source: Qodo findings plus run 32183375134

Task-Ref: PR-242
Signed-off-by: Manus <manus@manus.im>
@github-actions

Copy link
Copy Markdown
Contributor

context_key: pr-242-manusjules-provider-control-guard
source_id: 5333610724
source_revision: 5333610724:2026-08-19T01:06:28Z
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
New work-context pr-242-manusjules-provider-control-guard — create session if none exists, then prefer continue thereafter.
Bot feedback from coderabbitai[bot] on PR #242 (branch manus/jules-provider-control-guard).

Feedback excerpt

<!-- This is an auto-generated comment: summarize by coderabbit.ai -->
<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/timerloggedout-spec/termux-monorepo/pull/242?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- This is an auto-generated comment: failure by coderabbit.ai -->

> [!CAUTION]
> ## Review failed
> 
> The pull request is closed.

<!-- end of auto-generated comment: failure by coderabbit.ai -->

<!-- recent_review_start -->

<details>
<summary>ℹ️ Recent review info</summary>

<details>
<summary>⚙️ Run configuration</summary>

**Configuration used**: Path: .coderabbit.yaml

**Review profile**: ASSERTIVE

**Plan**: Pro Plus

**Run ID**: `9d474e39-68f9-4183-9c1b-88f4c6126821`

</details>

<details>
<summary>📥 Commits</summary>

Reviewing files that changed from the base of the PR and between a3af6bdce76b06493b5005802dddd8bc0b7b241e and 0c0c1f224c499a5a3b6e185515d21543c397f625.

</details>

<details>
<summary>📒 Files selected for processing (4)</summary>

* `.github/work

Instructions

  1. Address open review disposition / threads (CodeRabbit, Devin, Copilot). Ignore pure analysis-chain dumps.
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch manus/jules-provider-control-guard. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
  6. Non-empty diff required — empty commits are rejected.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok
    Signed-off-by: Grok (OPERATOR) session-auto-jules / context_key=pr-242-manusjules-provider-control-guard

@github-actions

Copy link
Copy Markdown
Contributor

context_key: pr-242-manusjules-provider-control-guard
source_id: 5333610724
source_revision: 5333610724:2026-08-19T01:06:33Z
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
New work-context pr-242-manusjules-provider-control-guard — create session if none exists, then prefer continue thereafter.
Bot feedback from coderabbitai[bot] on PR #242 (branch manus/jules-provider-control-guard).

Feedback excerpt

<!-- This is an auto-generated comment: summarize by coderabbit.ai -->
<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/timerloggedout-spec/termux-monorepo/pull/242?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- This is an auto-generated comment: failure by coderabbit.ai -->

> [!CAUTION]
> ## Review failed
> 
> The pull request is closed.

<!-- end of auto-generated comment: failure by coderabbit.ai -->

<!-- recent_review_start -->

<details>
<summary>ℹ️ Recent review info</summary>

<details>
<summary>⚙️ Run configuration</summary>

**Configuration used**: Path: .coderabbit.yaml

**Review profile**: ASSERTIVE

**Plan**: Pro Plus

**Run ID**: `9d474e39-68f9-4183-9c1b-88f4c6126821`

</details>

<details>
<summary>📥 Commits</summary>

Reviewing files that changed from the base of the PR and between a3af6bdce76b06493b5005802dddd8bc0b7b241e and 0c0c1f224c499a5a3b6e185515d21543c397f625.

</details>

<details>
<summary>📒 Files selected for processing (4)</summary>

* `.github/work

Instructions

  1. Address open review disposition / threads (CodeRabbit, Devin, Copilot). Ignore pure analysis-chain dumps.
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch manus/jules-provider-control-guard. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
  6. Non-empty diff required — empty commits are rejected.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok
    Signed-off-by: Grok (OPERATOR) session-auto-jules / context_key=pr-242-manusjules-provider-control-guard

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants