Skip to content

feat(github): add Review Provider and CI evidence loop - #122

Merged
Qiyuanqiii merged 3 commits into
mainfrom
codex/issue-118-github-review-provider
Aug 21, 2026
Merged

Qiyuanqiii merged 3 commits into
mainfrom
codex/issue-118-github-review-provider

Conversation

@Qiyuanqiii

@Qiyuanqiii Qiyuanqiii commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

Summary

  • add a Go-owned GitHub Review Provider with GitHub App Device Flow as the preferred authentication path and OS credential references only
  • capture bounded, sanitized, immutable PR/CI snapshots and bind them to local merge-base, diff/hunk, worktree/conflict, and optional LSP evidence
  • expose model-invocable local evidence list/read tools while keeping remote review writes behind an explicit connection write gate, Code/Deliver policy, exact preview, one-time approval, CAS, and observation-only recovery
  • wire the provider through CLI, OpenAPI/HTTP, Desktop/React, SQLite v124, built-in review/focused-checks Skills, README, guide, and ADR

Security boundaries

  • connections are disabled/read-only by default; hosts, installation repository membership, permissions, pagination, response bytes, log archives, redirects, sanitized text, and aggregate persisted list projections are bounded and fail closed
  • GitHub App permissions are qualified exactly; OAuth/PAT remains a read-only migration path because token write scopes cannot be proven reliably
  • credentials remain in the OS credential store and are never persisted in snapshots, evidence, write ledgers, model context, or receipts
  • remote mutations require allow-write plus runtime network authority and a fresh one-time operator approval; interrupted writes are reconciled by observation and are never blindly replayed

Verification

  • Store full suite: 994.677s; Application full suite: 565.790s; HTTP API full suite: 188.155s; CLI App full suite: 128.640s
  • GitHub Review package and ledger/migration/race checks passed
  • Desktop-tag tests, affected-package go vet, and go mod verify passed
  • Web: 66 test files / 289 tests, strict TypeScript, production build, and production npm audit (0 vulnerabilities)
  • deterministic OpenAPI/TypeScript generation: 155 paths / 172 operations / 469 schemas
  • follow-up real-smoke fixes: full Application package passed in 533.178s; HTTP API in 135.916s; CLI App in 97.148s; focused GitHub Review and ledger tests plus affected-package go vet passed
  • the concurrent Store package run reached its existing 10-minute package timeout in an unrelated script-process migration test; the changed GitHub Review ledger test passed separately in 1.243s, and CI remains authoritative for the complete post-push matrix

External acceptance evidence

  • created GitHub App Traverse Board · 针路簿 (App ID 4669358) with Device Flow and installed it only on the private disposable repository Qiyuanqiii/prayu-github-review-smoke (installation 155395300)
  • qualified the exact installation and repository with actions:read, checks:read, contents:read, metadata:read, and pull_requests:write; push remained unavailable
  • pinned disposable PR bug(browser): Windows WFP 受限浏览器生产探针尚未通过验收 #1 at head f11a75dc85afde65eb1d07754b56f73276d0af1a; captured one passing check and one intentional failing job with a verified, bounded, redacted log
  • persisted verified snapshot ghs-bc16efacdf22ad4cc056616870128980 and verified local evidence graph ghg-3c257896865c74428461d3d2c0ca4267
  • executed one approval-gated COMMENT review and stored receipt ghr-5bc2072e989d4954730c4cef9086c48e; replay returned the same operation/receipt and the remote idempotency marker count remained exactly one
  • restart reconciliation found no dangling operation after completion; a fixture-backed crash-uncertain path now verifies one recovery followed by zero-repeat reconciliation
  • the credential stayed in Windows Credential Manager (plaintext_returned: false); a credential-shaped scan of the complete smoke runtime found zero matching files
  • the real smoke exposed and fixed GitHub's extended Device Flow pending response, Actions log capability initialization, invalid review-thread GraphQL syntax/schema, and terminal write replay approval binding

The Windows host uses a configured system proxy; smoke network processes received the same proxy through process-local HTTP(S)_PROXY variables. No proxy address or credential was written to the evidence ledger.

The post-push CI matrix for commit a62827bdc84a82eee5be9464f5fb6bdf0b34968b is green; this PR is ready for review.

Parent roadmap: #107
Dependencies: #116 and #117 are merged/closed.

Closes #118

@Qiyuanqiii
Qiyuanqiii marked this pull request as ready for review August 21, 2026 10:02
@Qiyuanqiii
Qiyuanqiii merged commit 93ab9af into main Aug 21, 2026
12 checks passed
@Qiyuanqiii
Qiyuanqiii deleted the codex/issue-118-github-review-provider branch August 21, 2026 10:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(github): Review Provider、CI 证据与修复闭环

1 participant