Repository navigation
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1ed8e4ab15
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0ba564e740
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aef3f41227
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 67f96b44c0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| prAutomation: z | ||
| .object({ | ||
| enabled: z.boolean().optional().default(false), |
There was a problem hiding this comment.
Wire the enabled automation into a user-facing flow
At this commit, setting endpoints.agents.prAutomation.enabled to true has no observable effect: a repo-wide search finds the new enable/claim operations only in their definitions and tests, while production consumers call only stop/delete during cleanup. There is no route, webhook orchestration, or frontend entry point that enables a record or starts a round, so administrators can opt into a capability that no user can invoke. Add the owning backend flow and frontend controls, or defer exposing this configuration until they ship.
AGENTS.md reference: AGENTS.md:L49-L52
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0dd2e9bc17
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Adds the endpoints.agents.prAutomation config block (off by default) and a per-conversation record that holds the automation state, round counter, trust level and per-repository bot allowlist. Round claims are a single conditional update so racing or duplicate deliveries cannot exceed the cap.
Round completions now settle only the round that owns them, a user stop is unconditional and requires a stop code, claimed heads are remembered so a delayed delivery of an earlier head cannot start a round, approved bots are cleared when the conversation is bound to a different repository, the approved bot limit is configurable, and the record is removed with its conversation and with its user. Import order is fixed for the static check.
Binding a conversation to another pull request starts a fresh run and writes the repository and number in one conditional update, and each claim carries a run id so a completion from a replaced run cannot settle the new one. Conversation and account deletion stop the record first and remove it only after the delete commits, so a failed delete keeps the stored state.
A round claim now names the pull request it is for and applies only while the record is still bound to it, so an event delivered after a rebind cannot spend the new pull request's budget. Enabling a record applies its reset and binding in one conditional write per case, so a stopped record stays stopped when the new binding is rejected. The unique index is ensured before the first write, because automatic index creation can be disabled.
Enabling a record no longer clears a conversation or account deletion fence, and a deletion fence replaces an earlier user stop. A bot approval names the repository it was authorized for and applies only while the record is still bound to it. A round claim removes the record instead of starting work when its conversation was removed by the retention index or is past its retention date.
0dd2e9b to
d7f62b8
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d7f62b8aff
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
An event-driven stop names the pull request it is for and applies only while the record is still bound to it, while a user stop stays unconditional. A bot removal names its repository like an approval does. Disabling no longer removes a deletion fence. The time window opens in the same atomic write as the first claimed round. Account deletion removes the records before the account so a failed cleanup is retried instead of being swallowed.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 861c21342a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…e Enables A deletion now writes a tombstone for a conversation that has no record yet, so an enable already in flight cannot create an idle record under it. When the delete settles, the fence is released: a record whose conversation is gone is removed, and one whose conversation survived becomes a restartable stop with the deletion_aborted code. Account deletion removes the records only after the user delete committed. A claim for a subagent thread also requires its parent and root conversations to be active. The schema rejects a fractional pull request number.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ae01737684
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…letions Conversation and account deletion no longer write fences or tombstones. They remove records after the delete commits, in bounded batches, so a deletion of a conversation that never used the feature writes nothing. A round claim now checks, before and after its atomic write, that the owner has no account deletion in progress and that the conversation and its ancestors are active; a claim that loses that race hands its round back and never starts work. The auth cache is invalidated before the fallible cleanup, and the redundant user index is dropped.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b27446a135
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c93db00f3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Summary
There is no place to store per-conversation state for an automation that fixes CI failures and review comments on a conversation's pull request, and no administrator setting that controls it. Both are needed before any behavior can be built, and the round cap in particular has to live in storage: a counter held in a prompt or a run is reset by every new turn.
This adds the
endpoints.agents.prAutomationconfig block and aPRAutomationrecord per user and conversation. The config block is absent by default and itsenabledfield defaults tofalse. The record holds the state (idle,waiting,fixing,needs_user,stopped), a stable stop code, the round counter, the start of the time window, the last head SHA, the trust level, and a per-repository allowlist of approved bots keyed by numeric account id. Nothing reads either one yet, so this PR changes no behavior. It is the first of a stack: the code-host adapter and webhook, the stop rules and the UI follow.Starting a round is one conditional update that checks the state, the round cap, the time window and the head SHA together. Racing deliveries cannot exceed the cap, a duplicate delivery for a head that was already claimed is rejected, and the caller gets a stable code (
round_cap,time_cap,stale_head,not_active,not_found) instead of an exception. A stopped record only leaves that state through an explicit enable, which restarts the counter and the window.maxTrustis the widest author trust an administrator allows (approvedBots,collaborators,anyone), defaulting to the narrowest.clampPRAutomationTrustreturns the narrower of a user's choice and that ceiling. The methods store whatever level they are given, so the API layer in the next PR must call it.Related to #16792.
Type of change
Testing
Tested environments/configuration:
lc netAutomated tests:
packages/data-schemas/src/methods/prAutomation.spec.ts(29 tests): enable is idempotent and restarts a stopped record, a duplicate head is rejected, eight concurrent claims on one head produce one winner, concurrent claims on different heads cannot pass the cap, the round cap and the time window stop a claim, a stopped record is not revived by a state change, the bot allowlist is capped and idempotent by id when a login is renamed, and records of different users and conversations stay apart.packages/data-provider/src/prAutomation.spec.ts(20 tests): the config defaults, the bounds on rounds and minutes, the trust ceiling values, andclampPRAutomationTrust.data-providersuite passes, andtsc --noEmitandlc lintare clean for both packages.data-schemasrun had four failing suites.prAutomation.spec.tsandfile.acl.spec.tshit the 15 secondbeforeAlltimeout while MongoMemoryServer started under load, and both pass when run on their own.toolApprovalGrant.spec.tsandscheduleConsent.spec.tsfail in both runs because mongod exits with code 2 when started with--nounixsocketin this environment, before any test code runs; neither touches these files. I did not run them on a cleandev.Screenshots / recordings
No user-facing change.
Risk / compatibility
New collection and unique index on
{ user, conversationId }; nothing writes to it yet. The config block is optional with a disabled default, so existinglibrechat.yamlfiles are unaffected. The record is not listed in the tenant index migration because the siblingToolFavoriteandSchedulemodels are not either. The record stores no credentials. Tested against MongoDB only, not DocumentDB.Checklist