feat(actions): add provider command library - #278
Conversation
|
Mention Blocks like a regular teammate with your question or request: @blocks review this pull request Run |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important Approval pendingCodeRabbit has no unresolved comments, but it has not reviewed the latest commit. Use the checkbox below to review the latest commit. CodeRabbit will approve the changes if it finds no blocking issues.
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Proposal process checklist
Refs: PROCESS · CONSENSUS · registry.yaml |
|
cycle_id: pr-278-4d35cd86092c Agent peer response gateProvider state:
Pending: Authorized interactive controls:
A provider-owned checkbox/button requires an authorized Operator Action Executor. The second-pass reviewer remains blocked until matching provider completion evidence is ingested for this SHA. |
|
cycle_id: pr-278-4d35cd86092c @coderabbitai full review Requested by the OPERATOR automation after CodeRabbit exposed an interactive review control. This requests a complete provider pass; await substantive provider output and do not treat the request as completed review. |
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
|
PR Summary by QodoAdd governed provider command library and dispatch workflow
AI Description
Diagram
High-Level Assessment
Files changed (6)
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptHigh-Level Assessmen ``` ### Instructions 1. Address **open review disposition / threads** (CodeRabbit, Devin, Copilot). Ignore pure analysis-chain dumps. 2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched. 3. Push commits to branch `manus/provider-command-library`. Do not retarget away from the PR base without cause. 4. If conflicts with base exist, resolve them. 5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes. 6. **Non-empty diff required** — empty commits are rejected. Monikers: docs/ops/AGENT-MONIKERS.md Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok Signed-off-by: Grok (OPERATOR) session-auto-jules / context_key=pr-278-manusprovider-command-library |
Administrator notePeer-review gate is intentionally failing until CodeRabbit + Devin complete current-SHA evidence (Qodo already completed). Core gates on this PR: verify, termux-smoke, hygiene, actionlint, CodeQL advisory — success. Once provider evidence lands for head SHA Agent-Identity: Grok (Administrator) |
|
cycle_id: pr-278-fdcb7358b4cc Agent peer response gateProvider state:
Pending: Authorized interactive controls:
A provider-owned checkbox/button requires an authorized Operator Action Executor. The second-pass reviewer remains blocked until matching provider completion evidence is ingested for this SHA. |
|
cycle_id: pr-278-fdcb7358b4cc @coderabbitai full review Requested by the OPERATOR automation after CodeRabbit exposed an interactive review control. This requests a complete provider pass; await substantive provider output and do not treat the request as completed review. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '=== PR metadata and commit range ==='
git status --short
git branch --show-current
git log --oneline --decorate -8
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'BASE=%s\nHEAD=%s\n' "$base" "$(git rev-parse HEAD)"
echo '=== Changed files ==='
git diff --name-status "$base"...HEAD
echo '=== Diff statistics ==='
git diff --stat "$base"...HEAD
echo '=== Source and test outlines for changed Python and workflow files ==='
git diff --name-only "$base"...HEAD \
| grep -E '\.(py|ya?ml)$' \
| while IFS= read -r file; do
echo "--- $file"
case "$file" in
*.py) ast-grep outline "$file" --items all || true ;;
*.yml|*.yaml) sed -n '1,240p' "$file" ;;
esac
doneLength of output: 1793 🏁 Script executed: #!/bin/bash
set -euo pipefail
base="origin/master"
echo "=== Range ==="
printf 'BASE=%s (%s)\nHEAD=%s\n' "$base" "$(git rev-parse "$base")" "$(git rev-parse HEAD)"
echo '=== Changed files ==='
git diff --name-status "$base"...HEAD
echo '=== Diff statistics ==='
git diff --stat "$base"...HEAD
echo '=== Changed Python outlines ==='
git diff --name-only "$base"...HEAD | grep -E '\.py$' | while IFS= read -r file; do
echo "--- $file"
ast-grep outline "$file" --items all || true
done
echo '=== Full diff ==='
git diff --find-renames --find-copies --unified=80 "$base"...HEADLength of output: 34982 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '=== Relevant workflow and policy files ==='
fd -t f . .github tests scripts | sort | grep -E '(workflow|actionlint|policy|dispatch|gate|test_).*\.((ya?ml)|(py))$' | head -n 200
echo '=== Authorization, token, and receipt references ==='
rg -n -C 4 -i \
'OPERATOR_EXECUTOR_LOGINS|OPERATOR_COMMAND_ACTIONS|operator-provider-command|github-actions\[bot\]|github\.actor|repository_dispatch|workflow_dispatch|alreadyRecorded' \
.github tests scripts docs \
-g '*.yml' -g '*.yaml' -g '*.py' -g '*.md' || true
echo '=== Existing workflow test structure ==='
for file in $(fd -t f -e py . tests | grep -E '(workflow|actionlint|policy)' | head -n 20); do
echo "--- $file"
ast-grep outline "$file" --items all || true
done
echo '=== Provider workflow with numbered lines ==='
nl -ba .github/workflows/provider-command-dispatch.yml | sed -n '35,205p'Length of output: 88923
I found two blocking issues.
You are interacting with an AI system. |
|
context_key: pr-278-manusprovider-command-library
Feedback excerptLength of output: 1793 🏁 Script executed: #!/bin/bash
set -euo pipefail
base="origin/master"
echo "=== Range ==="
printf 'BASE=%s (%s)\nHEAD=%s\n' "$base" "$(git rev-parse "$base")" "$(git rInstructions
|
Code Review by Qodo
1. Stale controls get activated
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue description
Issue ContextWorkflow accepts Fix Focus Areas
|
|
context_key: pr-278-manusprovider-command-library Feedback excerpt(see review threads — prefer disposition over probe scripts) Instructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue descriptionPR Compliance ID 2783439 requires using the designated recon resources before nontrivial changes and ensuring the change is acknowledged/updated there. This PR adds a new governed workflow surface ( Issue ContextThe required recon references are:
Fix Focus Areas
|
Implements: AR-11 Agent-Identity: Manus Task-Ref: AR-11 Signed-off-by: Manus <manus@manus.im>
Implements: AR-11 Agent-Identity: Manus Task-Ref: AR-11 Signed-off-by: Manus <manus@manus.im>
Implements: AR-11 Agent-Identity: Manus Task-Ref: AR-11 Signed-off-by: Manus <manus@manus.im>
bfb5008 to
971d2ed
Compare
|
cycle_id: pr-278-971d2ed6b5d4 Agent peer response gateProvider state:
Pending: Authorized interactive controls:
A provider-owned checkbox/button requires an authorized Operator Action Executor. The second-pass reviewer remains blocked until matching provider completion evidence is ingested for this SHA. |
|
@coderabbitai full review cycle_id: pr-278-971d2ed6b5d4 Autonomous OPERATOR-token request for a current-SHA provider review. A command request is not review completion; await provider evidence. |
|
/agentic_review cycle_id: pr-278-971d2ed6b5d4 Autonomous OPERATOR-token request for a current-SHA provider review. A command request is not review completion; await provider evidence. |
|
/devin review cycle_id: pr-278-971d2ed6b5d4 Autonomous OPERATOR-token request for a current-SHA provider review. A command request is not review completion; await provider evidence. |
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
| name: Provider command dispatch | ||
|
|
||
| # Executes only explicit, allowlisted provider operations. The library is read | ||
| # from the trusted default branch, never from a pull-request head. |
There was a problem hiding this comment.
1. Missing sentinel/pr0b3 ci jobs 📘 Rule violation ▣ Testability
This PR adds a new GitHub Actions workflow but the repository CI configuration does not include required Sentinel and Pr0b3 scanning jobs. This violates the requirement that automated security scanners must pass before merging deployment/integration configuration changes.
Agent Prompt
## Issue description
The repo’s CI/CD configuration does not run Sentinel and Pr0b3 as required, yet this PR introduces a new GitHub Actions workflow (a pipeline/configuration change).
## Issue Context
Compliance requires Sentinel and Pr0b3 to be present and blocking (non-optional) for relevant changes.
## Fix Focus Areas
- .github/workflows/provider-command-dispatch.yml[1-48]
- .github/workflows/repo-gate.yml[1-50]
- .github/workflows/termux-smoke.yml[1-42]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| "control": { | ||
| "comment_kind": "issue_comment", | ||
| "labels": ["🔍 Trigger review", "Trigger review"] |
There was a problem hiding this comment.
2. Review modes share control 🐞 Bug ≡ Correctness
review_full and review_incremental declare identical checkbox labels, while the dispatcher chooses controls using only that label. A full-review request can therefore patch the generic incremental/default control instead of posting @coderabbitai full review, recording the requested action even though a different review mode was activated.
Agent Prompt
## Issue description
CodeRabbit incremental and full review actions share the same generic control labels, so the dispatcher cannot determine which review mode the checkbox represents.
## Issue Context
The documented commands distinguish incremental and full review, but control selection compares only visible label text.
## Fix Focus Areas
- .github/agentic/provider-command-library.json[12-28]
- .github/workflows/provider-command-dispatch.yml[162-176]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| const checkboxes = [...comment.body.matchAll(/^- \[ \] (<!--\s*\{"checkboxId":"([^"]+)"\}\s*-->)\s*(.+)$/gm)]; | ||
| const checkbox = checkboxes.find(candidate => labels.includes(candidate[3].trim())); |
There was a problem hiding this comment.
3. Stale controls get activated 🐞 Bug ☼ Reliability
The dispatcher searches every historical provider comment and selects a matching unchecked checkbox without checking the comment's SHA, timestamp, or active review cycle. A stale control can be patched successfully and suppress the documented-command fallback even when the provider no longer treats that control as actionable.
Agent Prompt
## Issue description
Provider checkbox selection is not bound to the current review cycle or current-SHA provider response, allowing historical controls to be patched.
## Issue Context
A successful GitHub comment PATCH is treated as successful dispatch, so selecting an obsolete control prevents the documented command fallback.
## Fix Focus Areas
- .github/workflows/provider-command-dispatch.yml[123-164]
- .github/workflows/provider-command-dispatch.yml[179-195]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| INPUT_HEAD_SHA: ${{ github.event.inputs.head_sha || github.event.client_payload.head_sha }} | ||
| INPUT_CONFIRM_BRANCH_WRITE: ${{ github.event.inputs.confirm_branch_write || github.event.client_payload.confirm_branch_write || 'false' }} | ||
| with: | ||
| github-token: ${{ secrets.ARCHWIZ_GITHUB_TOKEN || secrets.OPERATOR_GITHUB_TOKEN || secrets.OPERATOR_TOKEN || github.token }} |
There was a problem hiding this comment.
4. Devin fallback cannot trigger 🐞 Bug ☼ Reliability
The token chain allows github.token to post /devin review without verifying that the commenting identity is linked to Devin, although the recorded provider contract requires a linked account with repository write access. The workflow can therefore create a successful dispatch receipt while Devin ignores the command.
Agent Prompt
## Issue description
The Devin command path can use an identity that does not satisfy Devin's linked-account prerequisite and still record the command as dispatched.
## Issue Context
The repository-token fallback comments as the Actions bot, while Devin requires the commenter identity to be linked and authorized.
## Fix Focus Areas
- .github/workflows/provider-command-dispatch.yml[60-60]
- .github/workflows/provider-command-dispatch.yml[197-219]
- docs/ops/PROVIDER_COMMAND_LIBRARY.md[38-42]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| const checkboxes = [...comment.body.matchAll(/^- \[ \] (<!--\s*\{"checkboxId":"([^"]+)"\}\s*-->)\s*(.+)$/gm)]; | ||
| const checkbox = checkboxes.find(candidate => labels.includes(candidate[3].trim())); |
There was a problem hiding this comment.
5. Control parser rejects valid checkboxes 🐞 Bug ≡ Correctness
The checkbox regex requires "checkboxId":"..." with no whitespace after the colon, but existing CodeRabbit controls use "checkboxId": "..."; consequently no declared CodeRabbit control matches and every such dispatch falls back to posting the documented command. This defeats the workflow’s configured provider-control route and records a documented-command execution instead of activating the existing control.
Agent Prompt
## Issue description
The provider-control regex only matches a compact JSON `checkboxId` field, whereas stored CodeRabbit controls include whitespace around the colon. Make the checkbox parser accept normal JSON whitespace while retaining the unchecked-state, provider-author, and exact-label restrictions.
## Issue Context
The existing peer-review orchestrator already uses a whitespace-tolerant checkbox matcher, and captured CodeRabbit comments demonstrate the format the dispatcher must handle.
## Fix Focus Areas
- .github/workflows/provider-command-dispatch.yml[162-163]
- .github/workflows/peer-review-orchestrator.yml[204-220]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
|
Code review by qodo was updated up to the latest commit 971d2ed |
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue descriptionThe repo’s CI/CD configuration does not run Sentinel and Pr0b3 as required, yet this PR introduces a new GitHub Actions workflow (a pipeline/configuration change). Issue ContextCompliance requires Sentinel and Pr0b3 to be present and blocking (non-optional) for relevant changes. Fix Focus Areas
Instructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue descriptionCodeRabbit incremental and full review actions share the same generic control labels, so the dispatcher cannot determine which review mode the checkbox represents. Issue ContextThe documented commands distinguish incremental and full review, but control selection compares only visible label text. Fix Focus Areas
Instructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue descriptionThe provider-control regex only matches a compact JSON Issue ContextThe existing peer-review orchestrator already uses a whitespace-tolerant checkbox matcher, and captured Co |
|
context_key: pr-278-manusprovider-command-library Feedback excerpt(see review threads — prefer disposition over probe scripts) Instructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue descriptionThe Devin command path can use an identity that does not satisfy Devin's linked-account prerequisite and still record the command as dispatched. Issue ContextThe repository-token fallback comments as the Actions bot, while Devin requires the commenter identity to be linked and authorized. Fix Focus Areas
Instructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptInstructions
|
|
context_key: pr-278-manusprovider-command-library Feedback excerptIssue descriptionProvider checkbox selection is not bound to the current review cycle or current-SHA provider response, allowing historical controls to be patched. Issue ContextA successful GitHub comment PATCH is treated as successful dispatch, so selecting an obsolete control prevents the documented command fallback. Fix Focus Areas
Instructions
|
Summary
This introduces a governed provider command library instead of adding provider capabilities through polling loops or scattered hard-coded command maps.
The trusted default-branch catalog defines each provider’s known actions, expected effect, trusted provider authors, documented command, and optional interactive-control labels.
Provider command dispatchaccepts only explicit allowlisted inputs, validates the open PR and live head SHA, and records an attributable receipt.For matching provider controls, the dispatcher first attempts an exact provider-comment checkbox patch through GitHub’s documented issue-comment update API. If that path is unavailable or rejected, it posts the provider’s documented command. The initial library includes CodeRabbit incremental/full review, AutoFix, Fix CI, and conflict-resolution actions; Qodo review; and Devin review/Auto-Fix configuration metadata.
Branch-changing CodeRabbit operations require
confirm_branch_write=true. The dispatcher cannot merge, cannot execute arbitrary text, and reads its library only from the default branch.Validation
python3 -m unittest tests/test_provider_command_library.py -vpython3 scripts/ci/repo_gate.pypython3 scripts/ci/termux_smoke.pygit diff --checkScope
This is a separate AR-11 implementation, intentionally independent of AR-09 repository-surface reconciliation and AR-10 baseline peer-review trigger automation.
Implements: AR-11
Agent-Identity: Manus
Task-Ref: AR-11