Skip to content

fix(opencode-review-dispatch): fold same-trust-level jobs to cut a queue-wait hop - #2228

Merged
seonghobae merged 1 commit into
mainfrom
seonghobae/actions-capacity-job-fold-20260917
Sep 17, 2026
Merged

seonghobae merged 1 commit into
mainfrom
seonghobae/actions-capacity-job-fold-20260917

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Summary

  • Root cause (docs/doctoring/actions-capacity-root-cause-20260917.md, this session): under saturation, opencode-review-dispatch.yml's multi-hour duration was ~97.5% inter-job global runner-queue wait, paid once per needs: edge (3 boundaries across 4 jobs: validate-pr-metadata → coverage-source-tree → coverage-evidence → opencode-review-target).
  • One of those three boundaries sits entirely on the same side of the workflow's trust boundary: validate-pr-metadata and coverage-source-tree both only ever exchange the OpenCode app token for read-scoped data (id-token: write, contents: read) and neither executes untrusted PR-head content. This PR folds them into one job.
  • The boundary that must stay separate is untouched: coverage-evidence still runs untrusted PR-head test/build code with only actions: read (no app token, no write token), isolated from both the merged read-token job and opencode-review-target's write-capable publication job (issues: write, pull-requests: write, statuses: write, ...). No permission was added to any job beyond what it already had.
  • Net effect: 4 jobs → 3; 3 needs:-chained queue-wait boundaries → 2. This removes one of the three multi-hour queue waits measured in the doctoring record, not all of them — the remaining two boundaries cross the trust isolation and cannot be folded further without letting untrusted code run in a process holding or having recently held elevated tokens.
  • tests/test_pr_review_autofix_nvidia_nim_contract.py::test_independent_review_agent_workflow_matches_reviewed_blob deliberately pins this workflow's exact git blob SHA so any change gets a conscious re-review; re-pinned to the new blob hash here rather than left to fail silently or bypassed.
  • Bandscope item B (task requested a root cause for its 7-required-workflow re-trigger / 89% cancellation rate): checked via GraphQL commit + check-suite timestamps on 5 open PRs — cancellation fires within 1-3 seconds of each push, before any runner could plausibly be assigned. The high cancellation rate is the existing concurrency groups correctly debouncing a fast same-session commit cadence (6-10 commits in 5-10 minutes from one identity, consistent with this org's documented shared agent-session identity actively iterating — not a bot loop or webhook misfire). It is not wasting runner-seconds, so no workflow change is proposed for it.
  • Per maintainer steering, a capacity-reservation concurrency cap is deliberately not included in this PR: root cause first. Given the remaining two queue-wait boundaries can't be folded away (real trust isolation, not incidental job splitting), whether a cap is still needed will depend on post-merge measurement of queued-vs-in_progress and chain wall time on live traffic, which requires new PR runs through this workflow after merge.

Test plan

  • pytest tests -k "opencode or dispatch or coverage or nim_contract" — 977 passed, 1 skipped
  • python3 -c "import yaml; yaml.safe_load(open('.github/workflows/opencode-review-dispatch.yml'))" — parses, 3 jobs (was 4)
  • Full suite (coverage run -m pytest tests) reached 45% (no failures) before being killed by sandbox memory pressure unrelated to this change; the targeted run above covers every test file that references this workflow or the files it touches.

…eue-wait hop

docs/doctoring/actions-capacity-root-cause-20260917.md measured that this
workflow's multi-hour durations are ~97.5% inter-job global runner-queue
wait, compounding once per needs: edge under org-wide saturation. Of its
3 job boundaries, one (validate-pr-metadata -> coverage-source-tree) sits
entirely within the same trust level: both jobs only ever exchange the
OpenCode app token for READ-scoped data (target-repository metadata, then
the PR merge tree) via id-token: write, and neither executes untrusted
PR-head content or holds a write-capable token. Folding them into one job
removes that queue-wait hop without touching the trust boundary that must
stay separate: coverage-evidence (untrusted test/build execution,
actions: read only) stays isolated from both the merged read-token job and
opencode-review-target's write-capable publication job.

4 jobs -> 3; 3 needs:-chained queue-wait boundaries -> 2. The remaining
two (into coverage-evidence, into opencode-review-target) cross a real
trust boundary and cannot be folded further without letting untrusted
PR-head code run in a process that holds or recently held elevated
tokens.

Also re-pins REVIEW_DISPATCH_BLOB_SHA in
test_pr_review_autofix_nvidia_nim_contract.py to this workflow's new blob
hash -- that test deliberately pins the reviewed dispatch workflow
byte-for-byte so a change like this one gets a conscious re-pin rather
than passing silently.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015gdR6WuShb6HH6niXc1wkj
@coderabbitai

coderabbitai Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 26 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0481b6e0-e362-4ed5-ac9e-5c77363761ad

📥 Commits

Reviewing files that changed from the base of the PR and between 45f612f and 51dacbf.

📒 Files selected for processing (3)
  • .github/workflows/opencode-review-dispatch.yml
  • tests/test_opencode_agent_contract.py
  • tests/test_pr_review_autofix_nvidia_nim_contract.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant