diff --git a/.github/workflows/opencode.yml b/.github/workflows/opencode.yml index e40bd342f0..a3cf79dcc4 100644 --- a/.github/workflows/opencode.yml +++ b/.github/workflows/opencode.yml @@ -37,7 +37,6 @@ jobs: cancel-in-progress: true runs-on: ubuntu-latest permissions: - id-token: write contents: read pull-requests: write issues: write @@ -117,11 +116,14 @@ jobs: if: github.event_name != 'workflow_dispatch' uses: anomalyco/opencode/github@77fc88c8ade8e5a620ebbe1197f3a572d29ae91a env: + GITHUB_TOKEN: ${{ github.token }} NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }} PROMPT: >- - ${{ github.event_name == 'pull_request' && 'Perform an exact-head code review of this pull request. Read the complete diff and relevant surrounding code. Report only actionable correctness, security, regression, maintainability, or missing-test findings. For every actionable finding, use the GitHub API or gh CLI to create a pull-request review comment directly on the relevant changed RIGHT-side diff line; include a concise explanation and a valid suggested patch when appropriate. Do not merely list findings in the final summary, do not comment on unchanged lines, and do not modify, push, or change labels. Use the final PR comment only for an overall verdict and a count of inline findings. End that verdict with exactly OPENCODE_REVIEW: PASS when there are zero actionable inline findings, or OPENCODE_REVIEW: CHANGES_REQUIRED when one or more actionable inline findings were posted.' || '' }} + ${{ github.event_name == 'pull_request' && 'Perform an exact-head code review of this pull request. Read the complete diff and relevant surrounding code. Report only actionable correctness, security, regression, maintainability, or missing-test findings. For every actionable finding, use the GitHub API or gh CLI to create a pull-request review comment directly on the relevant changed RIGHT-side diff line; include a concise explanation and a valid suggested patch when appropriate. Do not merely list findings in the final summary, do not comment on unchanged lines, and do not modify, push, merge, or change labels. Your FINAL response MUST begin with exactly OPENCODE_REVIEW: PASS when there are zero actionable inline findings, or exactly OPENCODE_REVIEW: CHANGES_REQUIRED when one or more actionable inline findings were posted. After that first line, you may include a concise overall verdict and finding count.' || '' }} with: model: ${{ steps.model.outputs.model }} + agent: pr-reviewer + use_github_token: true - name: Reconcile automatic review stage if: github.event_name == 'pull_request' @@ -135,18 +137,14 @@ jobs: echo "PR moved from ${EXPECTED_HEAD} to ${current_head}; refusing to tag a stale review." >&2 exit 1 fi - verdict="$(gh api \ - "repos/${GITHUB_REPOSITORY}/issues/${PR_NUMBER}/comments?per_page=100" | \ - jq -r --arg run "/actions/runs/${GITHUB_RUN_ID}" \ - '.[] | select(.user.login == "opencode-agent[bot]" and (.body | contains($run))) | .body' | \ - tail -n 1)" - if grep -q 'OPENCODE_REVIEW: CHANGES_REQUIRED' <<< "$verdict"; then + finding_count="$(gh api --paginate \ + "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/comments?per_page=100" | \ + jq -s --arg head "$EXPECTED_HEAD" \ + '[.[][] | select((.user.login == "opencode-agent[bot]" or .user.login == "github-actions[bot]") and .commit_id == $head)] | length')" + if (( finding_count > 0 )); then target_stage='factory:changes-requested' - elif grep -q 'OPENCODE_REVIEW: PASS' <<< "$verdict"; then - target_stage='factory:ci' else - echo 'OpenCode omitted the required exact-head verdict marker; leaving factory:review in place.' >&2 - exit 1 + target_stage='factory:ci' fi for label in factory:building factory:review factory:changes-requested factory:ci factory:ready; do gh api --method DELETE \ diff --git a/.opencode/agents/pr-reviewer.md b/.opencode/agents/pr-reviewer.md new file mode 100644 index 0000000000..edd04aef90 --- /dev/null +++ b/.opencode/agents/pr-reviewer.md @@ -0,0 +1,18 @@ +--- +description: Read-only pull request reviewer that may post GitHub review findings +mode: primary +permission: + edit: deny + task: deny + external_directory: deny + question: deny + bash: + "*": deny + "gh api *": allow + "git diff*": allow + "git log*": allow + "git show*": allow + "git status*": allow +--- + +Review the current pull request without modifying the working tree. Use native read, search, and language tools to inspect code. You may use the allowed read-only git commands for history and diffs, and `gh api` only when the review prompt requires posting an inline pull-request review comment. Never edit files, create commits, push branches, merge pull requests, or change labels. diff --git a/docs/changelog.d/2026-08-09-1040.md b/docs/changelog.d/2026-08-09-1040.md new file mode 100644 index 0000000000..750e653344 --- /dev/null +++ b/docs/changelog.d/2026-08-09-1040.md @@ -0,0 +1,5 @@ +## 2026-08-09 + +### Factory reliability + +- [#1040](https://github.com/JoshCLWren/comic-pile/pull/1040) lets the automatic OpenCode reviewer use the workflow GitHub token, so factory PR reviews can post their findings instead of failing on an unprivileged bot identity.