Repository navigation
ci(repo): fix codex-action v1.12 hang (downgrade to v1.11), adjudicate on >=1 review - #6380
Merged
Merged
Conversation
Contributor
Supabase CLI previewnpx --yes https://pkg.pr.new/supabase/cli/supabase@cc8ae01e22be790f78b5bc9d817f972c521f7435Preview package for commit |
jgoux
approved these changes
Aug 28, 2026
pull Bot
pushed a commit
to oogalieboogalie/cli
that referenced
this pull request
Sep 9, 2026
…base#6538) ## What kind of change does this PR introduce? CI reliability fix. ## What is the current behavior? AI Review's Codex jobs (`codex-review`, `adjudicate`) intermittently hang and get killed on job timeout, discarding a completed review. Most recently: [run 34323125644](https://github.com/supabase/cli/actions/runs/34323125644) on supabase#6535 died at ~55 minutes against a 45-minute timeout. This is a regression. supabase#6380 deliberately pinned `openai/codex-action` to v1.11 because v1.12 had a confirmed hang bug (openai/codex-action#150). supabase#6484 — a Dependabot `actions-major` group bump bundling 6 unrelated action updates — silently reverted that pin back to v1.12; the workflow's own comments (still saying "pinned to v1.11, NOT v1.12") went stale rather than catching the drift, since nothing diffed them against the actual `uses:` line. Checking upstream today turned up two separate, still-open v1.12 regressions, both matching this workflow's exact config (`safety-strategy: drop-sudo`, `sandbox: read-only`, `output-schema-file`): - openai/codex-action#151 — the v1.12 wrapper waits on the child process's `close` event with inherited stdio; a lingering descendant keeps the step alive forever after Codex has already written its output and finished. - openai/codex-action#160 — v1.12's `drop-sudo` rewrite chmods root-owned `/run` service sockets, breaking `systemd-resolved` on the GitHub-hosted runner itself, which kills the job 52-65 minutes in regardless of the job's own timeout — matching our job's 55-minute death exactly. Neither has a released fix. Both are action-level bugs independent of the pinned Codex CLI version (reproduced across CLI versions 0.147.0-0.150.1 in the upstream threads). This is not a diff-size or token-limit problem: supabase#6535's diff was only ~2200 lines, and v1.11 has cleanly handled 130k-270k-token diffs in under 15 minutes per the upstream reports and our own prior testing. ## What is the new behavior? - Re-pin `openai/codex-action` to v1.11 (`52fe01ec70a42f454c9d2ebd47598f9fd6893d56`) in both Codex jobs — verified it's a safe drop-in, since v1.11's `action.yml` supports every input this workflow uses. - Refresh the stale inline comments to cite the actual issues (#151, #160) instead of just the original #150. - Add `openai/codex-action` to `.github/dependabot.yml`'s `ignore` list (no `update-types` restriction, so it blocks all automated bumps) so a grouped bump can't silently regress this pin again. Any future bump now requires a deliberate PR that checks the upstream changelog/issue tracker first.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the AI-review pipeline. Two changes.
1. Downgrade
codex-actionv1.12 → v1.11On the large PR (#6366, ~130k-token diff) the
codex-reviewstep ran to completion — Codex finished the turn, wrote its output file, printed its final message and token count — then sat idle until the 45-minute job timeout, discarding a completed review. That is a confirmed v1.12 regression: openai/codex-action#150 ("v1.12: Linux run never returns after the turn completes; job dies on timeout with the output file already written"). The reporter confirms v1.11 handles the same heavy workload cleanly, and there is no released fix above v1.12.v1.11 (
52fe01ec…) supports every input we use (safety-strategy,sandbox,output-schema-file,output-file,codex-version,working-directory,effort), so this is a drop-in pin change in both Codex jobs.2. Adjudicate on ≥1 independent review (graceful degradation)
Previously
adjudicaterequired BOTHclaude-reviewandcodex-reviewto succeed, so one flaky model job sank the whole review. Now it runs when at least one independent pass succeeded: each findings download is guarded by its job's result, and the stage step substitutes an empty findings set for any review that didn't complete, so the adjudicator reconciles one or two. The prompt notes the one-review case and records it in its summary.Together: a Codex hiccup no longer wastes a 45-minute run or blocks Claude's (working) review from being posted.