This is an automated email from the ASF dual-hosted git repository.

shuke987 pushed a commit to branch codex/review-goal-package-canary
in repository https://gitbox.apache.org/repos/asf/doris.git

commit c986cc43b108bd86b19f9d4c4e809379e36a2038
Author: shuke <[email protected]>
AuthorDate: Mon Sep 28 14:40:46 2026 +0800

    Add isolated Codex package runtime canary
---
 .github/workflows/code-review-runner.yml | 176 +++++++++++++++++++++++++++++--
 1 file changed, 166 insertions(+), 10 deletions(-)

diff --git a/.github/workflows/code-review-runner.yml 
b/.github/workflows/code-review-runner.yml
index 75461551e89..fadbb23de06 100644
--- a/.github/workflows/code-review-runner.yml
+++ b/.github/workflows/code-review-runner.yml
@@ -5,14 +5,19 @@ on:
     types: [created]
   workflow_dispatch:
     inputs:
+      runtime_canary:
+        description: Test the staged Codex package without submitting a review.
+        required: false
+        type: boolean
+        default: false
       pr_number:
-        required: true
+        required: false
         type: string
       head_sha:
-        required: true
+        required: false
         type: string
       base_sha:
-        required: true
+        required: false
         type: string
       review_focus:
         required: false
@@ -35,6 +40,154 @@ env:
   REVIEW_TIMEOUT_MINUTES: 120
 
 jobs:
+  runtime-canary:
+    if: ${{ github.event_name == 'workflow_dispatch' && inputs.runtime_canary 
== true }}
+    runs-on: ubuntu-24.04
+    timeout-minutes: 25
+    permissions:
+      contents: read
+    steps:
+      - name: Install ossutil
+        run: |
+          tmp_dir="$(mktemp -d)"
+          trap 'rm -rf "$tmp_dir"' EXIT
+          curl -fsSL -o "$tmp_dir/ossutil.zip" 
https://gosspublic.alicdn.com/ossutil/1.7.19/ossutil-v1.7.19-linux-amd64.zip
+          unzip -q "$tmp_dir/ossutil.zip" -d "$tmp_dir"
+          sudo install -m 0755 "$tmp_dir/ossutil-v1.7.19-linux-amd64/ossutil" 
/usr/local/bin/ossutil
+
+      - name: Install staged Codex package
+        env:
+          OSS_AK: ${{ secrets.OSS_AK }}
+          OSS_SK: ${{ secrets.OSS_SK }}
+          OSS_ENDPOINT: oss-cn-hongkong.aliyuncs.com
+        run: |
+          set -euo pipefail
+          archive="$RUNNER_TEMP/codex-exec-goal.tar.gz"
+          package="$RUNNER_TEMP/codex-exec-goal"
+          ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \
+            cp -f 
oss://doris-community-ci/codex/releases/codex-exec-goal-0.156.1-a310d33f7ebb-x86_64-unknown-linux-gnu.tar.gz
 "$archive"
+          echo 
"2ee3073479bc8c94436684b55a13d7a3f299e768d04436d90e0427814a3954bc  $archive" | 
sha256sum --check
+          mkdir -p "$package"
+          tar -xzf "$archive" -C "$package"
+          (cd "$package" && sha256sum --check SHA256SUMS)
+          test "$(jq -r .version "$package/codex-package.json")" = 0.156.1
+          "$package/bin/codex" --version
+          "$package/bin/codex" exec --help | grep -q -- '--goal'
+          echo "CODEX_CANARY_BIN=$package/bin/codex" >> "$GITHUB_ENV"
+
+      - name: Load one review auth snapshot
+        id: auth
+        env:
+          OSS_AK: ${{ secrets.OSS_AK }}
+          OSS_SK: ${{ secrets.OSS_SK }}
+          OSS_ENDPOINT: oss-cn-hongkong.aliyuncs.com
+        run: |
+          set -euo pipefail
+          umask 077
+          home="$RUNNER_TEMP/codex-canary-home"
+          install -m 700 -d "$home"
+          ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \
+            cp -f oss://doris-community-ci/codex/auth.json.4 "$home/auth.json" 
>/dev/null
+          jq -e '
+            .auth_mode == "chatgpt"
+            and (.tokens.access_token | type == "string" and length > 0)
+            and (.tokens.refresh_token | type == "string" and length > 0)
+          ' "$home/auth.json" >/dev/null
+          sha256sum "$home/auth.json" | awk '{print $1}' \
+            > "$RUNNER_TEMP/codex-canary-auth-original.sha256"
+          cat > "$home/config.toml" <<'EOF'
+          cli_auth_credentials_store = "file"
+          approval_policy = "never"
+          [features]
+          code_mode_only = true
+          code_mode_host = true
+          memories = false
+          apps = false
+          plugins = false
+          [otel]
+          exporter = "none"
+          trace_exporter = "none"
+          metrics_exporter = "none"
+          EOF
+          echo "CODEX_HOME=$home" >> "$GITHUB_ENV"
+
+      - name: Test ChatGPT model access and goal mode without GitHub writes
+        timeout-minutes: 12
+        run: |
+          set -uo pipefail
+          run_model() {
+            local label="$1" model="$2" goal="$3"
+            local events="$RUNNER_TEMP/codex-canary-$label.jsonl"
+            local final="$RUNNER_TEMP/codex-canary-$label.txt"
+            local args=(exec --skip-git-repo-check --json --model "$model"
+              --config model_reasoning_effort=low --sandbox read-only
+              --color never --output-last-message "$final")
+            if [ "$goal" = true ]; then
+              args+=(--goal)
+            fi
+            local prompt="Reply with exactly OK. Do not access files or 
external services."
+            if [ "$goal" = true ]; then
+              prompt="Create a goal to reply OK, mark it complete, then reply 
OK. Do not access files or external services."
+            fi
+            timeout --signal=INT --kill-after=10s 180s \
+              env -u GH_TOKEN -u GITHUB_TOKEN "$CODEX_CANARY_BIN" \
+              "${args[@]}" "$prompt" > "$events" 2> 
"$RUNNER_TEMP/codex-canary-$label.stderr"
+            local status=$?
+            echo "$label: exit_status=$status"
+            jq -r 'select(.type == "turn.failed" or .type == "error") |
+              .error.message // .message // empty' "$events" | tail -n 2 || 
true
+            if [ "$status" -ne 0 ] ||
+               ! jq -e 'select(.type == "turn.completed")' "$events" 
>/dev/null; then
+              return 1
+            fi
+            return 0
+          }
+
+          run_model sol gpt-6-sol false
+          sol_status=$?
+          run_model prior-sol gpt-5.6-sol false
+          prior_status=$?
+          goal_status=1
+          if [ "$sol_status" -eq 0 ]; then
+            run_model sol-goal gpt-6-sol true
+            goal_status=$?
+          fi
+          echo "model_canary: gpt-6-sol=$sol_status gpt-5.6-sol=$prior_status 
gpt-6-sol-goal=$goal_status"
+          test "$sol_status" -eq 0 && test "$goal_status" -eq 0
+
+      - name: Sync refreshed canary auth
+        if: ${{ always() && steps.auth.outcome == 'success' }}
+        env:
+          OSS_AK: ${{ secrets.OSS_AK }}
+          OSS_SK: ${{ secrets.OSS_SK }}
+          OSS_ENDPOINT: oss-cn-hongkong.aliyuncs.com
+        run: |
+          set -euo pipefail
+          auth_object=oss://doris-community-ci/codex/auth.json.4
+          jq -e '
+            .auth_mode == "chatgpt"
+            and (.tokens.access_token | type == "string" and length > 0)
+            and (.tokens.refresh_token | type == "string" and length > 0)
+          ' "$CODEX_HOME/auth.json" >/dev/null
+          original_hash="$(cat 
"$RUNNER_TEMP/codex-canary-auth-original.sha256")"
+          local_hash="$(sha256sum "$CODEX_HOME/auth.json" | awk '{print $1}')"
+          if [ "$local_hash" = "$original_hash" ]; then
+            echo "Canary auth was unchanged."
+            exit 0
+          fi
+          remote_auth="$(mktemp "$RUNNER_TEMP/codex-canary-current.XXXXXX")"
+          trap 'rm -f "$remote_auth"' EXIT
+          ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \
+            cp -f "$auth_object" "$remote_auth" >/dev/null
+          remote_hash="$(sha256sum "$remote_auth" | awk '{print $1}')"
+          if [ "$remote_hash" != "$original_hash" ]; then
+            echo "::error::Auth changed concurrently; refusing to overwrite 
it."
+            exit 1
+          fi
+          ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \
+            cp -f "$CODEX_HOME/auth.json" "$auth_object" >/dev/null
+          echo "Synced refreshed canary auth."
+
   code-review:
     runs-on: ubuntu-latest
     outputs:
@@ -46,15 +199,18 @@ jobs:
     # leaving 12 minutes for runner setup and post-job cleanup.
     timeout-minutes: 238
     if: >-
-      inputs.pr_number != '' ||
+      inputs.runtime_canary != true &&
       (
-        github.event_name == 'issue_comment' &&
-        github.event.issue.pull_request &&
-        startsWith(github.event.comment.body, '/review') &&
+        inputs.pr_number != '' ||
         (
-          github.event.comment.author_association == 'MEMBER' ||
-          github.event.comment.author_association == 'OWNER' ||
-          github.event.comment.author_association == 'COLLABORATOR'
+          github.event_name == 'issue_comment' &&
+          github.event.issue.pull_request &&
+          startsWith(github.event.comment.body, '/review') &&
+          (
+            github.event.comment.author_association == 'MEMBER' ||
+            github.event.comment.author_association == 'OWNER' ||
+            github.event.comment.author_association == 'COLLABORATOR'
+          )
         )
       )
     steps:


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to