Skip to content

ci(repo): fix codex-action v1.12 hang (downgrade to v1.11), adjudicate on >=1 review - #6380

Merged
Coly010 merged 2 commits into
developfrom
ci/fix-codex-action-hang
Aug 28, 2026
Merged

Coly010 merged 2 commits into
developfrom
ci/fix-codex-action-hang

Conversation

@Coly010

@Coly010 Coly010 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Follow-up to the AI-review pipeline. Two changes.

1. Downgrade codex-action v1.12 → v1.11

On the large PR (#6366, ~130k-token diff) the codex-review step ran to completion — Codex finished the turn, wrote its output file, printed its final message and token count — then sat idle until the 45-minute job timeout, discarding a completed review. That is a confirmed v1.12 regression: openai/codex-action#150 ("v1.12: Linux run never returns after the turn completes; job dies on timeout with the output file already written"). The reporter confirms v1.11 handles the same heavy workload cleanly, and there is no released fix above v1.12.

v1.11 (52fe01ec…) supports every input we use (safety-strategy, sandbox, output-schema-file, output-file, codex-version, working-directory, effort), so this is a drop-in pin change in both Codex jobs.

2. Adjudicate on ≥1 independent review (graceful degradation)

Previously adjudicate required BOTH claude-review and codex-review to succeed, so one flaky model job sank the whole review. Now it runs when at least one independent pass succeeded: each findings download is guarded by its job's result, and the stage step substitutes an empty findings set for any review that didn't complete, so the adjudicator reconciles one or two. The prompt notes the one-review case and records it in its summary.

Together: a Codex hiccup no longer wastes a 45-minute run or blocks Claude's (working) review from being posted.

@Coly010
Coly010 requested a review from a team as a code owner August 28, 2026 14:40
@github-actions

Copy link
Copy Markdown
Contributor

Supabase CLI preview

npx --yes https://pkg.pr.new/supabase/cli/supabase@cc8ae01e22be790f78b5bc9d817f972c521f7435

Preview package for commit cc8ae01.

@Coly010 Coly010 self-assigned this Aug 28, 2026
@Coly010
Coly010 added this pull request to the merge queue Aug 28, 2026
Merged via the queue into develop with commit 7a16903 Aug 28, 2026
27 checks passed
@Coly010
Coly010 deleted the ci/fix-codex-action-hang branch August 28, 2026 15:19
pull Bot pushed a commit to oogalieboogalie/cli that referenced this pull request Sep 9, 2026
…base#6538)

## What kind of change does this PR introduce?

CI reliability fix.

## What is the current behavior?

AI Review's Codex jobs (`codex-review`, `adjudicate`) intermittently
hang and get killed on job timeout, discarding a completed review. Most
recently: [run
34323125644](https://github.com/supabase/cli/actions/runs/34323125644)
on supabase#6535 died at ~55 minutes against a 45-minute timeout.

This is a regression. supabase#6380 deliberately pinned `openai/codex-action` to
v1.11 because v1.12 had a confirmed hang bug (openai/codex-action#150).
supabase#6484 — a Dependabot `actions-major` group bump bundling 6 unrelated
action updates — silently reverted that pin back to v1.12; the
workflow's own comments (still saying "pinned to v1.11, NOT v1.12") went
stale rather than catching the drift, since nothing diffed them against
the actual `uses:` line.

Checking upstream today turned up two separate, still-open v1.12
regressions, both matching this workflow's exact config
(`safety-strategy: drop-sudo`, `sandbox: read-only`,
`output-schema-file`):
- openai/codex-action#151 — the v1.12 wrapper waits on the child
process's `close` event with inherited stdio; a lingering descendant
keeps the step alive forever after Codex has already written its output
and finished.
- openai/codex-action#160 — v1.12's `drop-sudo` rewrite chmods
root-owned `/run` service sockets, breaking `systemd-resolved` on the
GitHub-hosted runner itself, which kills the job 52-65 minutes in
regardless of the job's own timeout — matching our job's 55-minute death
exactly.

Neither has a released fix. Both are action-level bugs independent of
the pinned Codex CLI version (reproduced across CLI versions
0.147.0-0.150.1 in the upstream threads). This is not a diff-size or
token-limit problem: supabase#6535's diff was only ~2200 lines, and v1.11 has
cleanly handled 130k-270k-token diffs in under 15 minutes per the
upstream reports and our own prior testing.

## What is the new behavior?

- Re-pin `openai/codex-action` to v1.11
(`52fe01ec70a42f454c9d2ebd47598f9fd6893d56`) in both Codex jobs —
verified it's a safe drop-in, since v1.11's `action.yml` supports every
input this workflow uses.
- Refresh the stale inline comments to cite the actual issues (#151,
#160) instead of just the original #150.
- Add `openai/codex-action` to `.github/dependabot.yml`'s `ignore` list
(no `update-types` restriction, so it blocks all automated bumps) so a
grouped bump can't silently regress this pin again. Any future bump now
requires a deliberate PR that checks the upstream changelog/issue
tracker first.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants