fix(opencode-review-dispatch): fold same-trust-level jobs to cut a queue-wait hop - #2228
Merged
Merged
Conversation
…eue-wait hop docs/doctoring/actions-capacity-root-cause-20260917.md measured that this workflow's multi-hour durations are ~97.5% inter-job global runner-queue wait, compounding once per needs: edge under org-wide saturation. Of its 3 job boundaries, one (validate-pr-metadata -> coverage-source-tree) sits entirely within the same trust level: both jobs only ever exchange the OpenCode app token for READ-scoped data (target-repository metadata, then the PR merge tree) via id-token: write, and neither executes untrusted PR-head content or holds a write-capable token. Folding them into one job removes that queue-wait hop without touching the trust boundary that must stay separate: coverage-evidence (untrusted test/build execution, actions: read only) stays isolated from both the merged read-token job and opencode-review-target's write-capable publication job. 4 jobs -> 3; 3 needs:-chained queue-wait boundaries -> 2. The remaining two (into coverage-evidence, into opencode-review-target) cross a real trust boundary and cannot be folded further without letting untrusted PR-head code run in a process that holds or recently held elevated tokens. Also re-pins REVIEW_DISPATCH_BLOB_SHA in test_pr_review_autofix_nvidia_nim_contract.py to this workflow's new blob hash -- that test deliberately pins the reviewed dispatch workflow byte-for-byte so a change like this one gets a conscious re-pin rather than passing silently. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015gdR6WuShb6HH6niXc1wkj
Contributor
|
Warning Review limit reachedNext included review available in 26 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
deleted the
seonghobae/actions-capacity-job-fold-20260917
branch
September 17, 2026 00:42
This was referenced Sep 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docs/doctoring/actions-capacity-root-cause-20260917.md, this session): under saturation,opencode-review-dispatch.yml's multi-hour duration was ~97.5% inter-job global runner-queue wait, paid once perneeds:edge (3 boundaries across 4 jobs:validate-pr-metadata→coverage-source-tree→coverage-evidence→opencode-review-target).validate-pr-metadataandcoverage-source-treeboth only ever exchange the OpenCode app token for read-scoped data (id-token: write,contents: read) and neither executes untrusted PR-head content. This PR folds them into one job.coverage-evidencestill runs untrusted PR-head test/build code with onlyactions: read(no app token, no write token), isolated from both the merged read-token job andopencode-review-target's write-capable publication job (issues: write,pull-requests: write,statuses: write, ...). No permission was added to any job beyond what it already had.needs:-chained queue-wait boundaries → 2. This removes one of the three multi-hour queue waits measured in the doctoring record, not all of them — the remaining two boundaries cross the trust isolation and cannot be folded further without letting untrusted code run in a process holding or having recently held elevated tokens.tests/test_pr_review_autofix_nvidia_nim_contract.py::test_independent_review_agent_workflow_matches_reviewed_blobdeliberately pins this workflow's exact git blob SHA so any change gets a conscious re-review; re-pinned to the new blob hash here rather than left to fail silently or bypassed.Test plan
pytest tests -k "opencode or dispatch or coverage or nim_contract"— 977 passed, 1 skippedpython3 -c "import yaml; yaml.safe_load(open('.github/workflows/opencode-review-dispatch.yml'))"— parses, 3 jobs (was 4)coverage run -m pytest tests) reached 45% (no failures) before being killed by sandbox memory pressure unrelated to this change; the targeted run above covers every test file that references this workflow or the files it touches.