This is an automated email from the ASF dual-hosted git repository. shuke987 pushed a commit to branch codex/review-goal-package-canary in repository https://gitbox.apache.org/repos/asf/doris.git
commit c986cc43b108bd86b19f9d4c4e809379e36a2038 Author: shuke <[email protected]> AuthorDate: Mon Sep 28 14:40:46 2026 +0800 Add isolated Codex package runtime canary --- .github/workflows/code-review-runner.yml | 176 +++++++++++++++++++++++++++++-- 1 file changed, 166 insertions(+), 10 deletions(-) diff --git a/.github/workflows/code-review-runner.yml b/.github/workflows/code-review-runner.yml index 75461551e89..fadbb23de06 100644 --- a/.github/workflows/code-review-runner.yml +++ b/.github/workflows/code-review-runner.yml @@ -5,14 +5,19 @@ on: types: [created] workflow_dispatch: inputs: + runtime_canary: + description: Test the staged Codex package without submitting a review. + required: false + type: boolean + default: false pr_number: - required: true + required: false type: string head_sha: - required: true + required: false type: string base_sha: - required: true + required: false type: string review_focus: required: false @@ -35,6 +40,154 @@ env: REVIEW_TIMEOUT_MINUTES: 120 jobs: + runtime-canary: + if: ${{ github.event_name == 'workflow_dispatch' && inputs.runtime_canary == true }} + runs-on: ubuntu-24.04 + timeout-minutes: 25 + permissions: + contents: read + steps: + - name: Install ossutil + run: | + tmp_dir="$(mktemp -d)" + trap 'rm -rf "$tmp_dir"' EXIT + curl -fsSL -o "$tmp_dir/ossutil.zip" https://gosspublic.alicdn.com/ossutil/1.7.19/ossutil-v1.7.19-linux-amd64.zip + unzip -q "$tmp_dir/ossutil.zip" -d "$tmp_dir" + sudo install -m 0755 "$tmp_dir/ossutil-v1.7.19-linux-amd64/ossutil" /usr/local/bin/ossutil + + - name: Install staged Codex package + env: + OSS_AK: ${{ secrets.OSS_AK }} + OSS_SK: ${{ secrets.OSS_SK }} + OSS_ENDPOINT: oss-cn-hongkong.aliyuncs.com + run: | + set -euo pipefail + archive="$RUNNER_TEMP/codex-exec-goal.tar.gz" + package="$RUNNER_TEMP/codex-exec-goal" + ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \ + cp -f oss://doris-community-ci/codex/releases/codex-exec-goal-0.156.1-a310d33f7ebb-x86_64-unknown-linux-gnu.tar.gz "$archive" + echo "2ee3073479bc8c94436684b55a13d7a3f299e768d04436d90e0427814a3954bc $archive" | sha256sum --check + mkdir -p "$package" + tar -xzf "$archive" -C "$package" + (cd "$package" && sha256sum --check SHA256SUMS) + test "$(jq -r .version "$package/codex-package.json")" = 0.156.1 + "$package/bin/codex" --version + "$package/bin/codex" exec --help | grep -q -- '--goal' + echo "CODEX_CANARY_BIN=$package/bin/codex" >> "$GITHUB_ENV" + + - name: Load one review auth snapshot + id: auth + env: + OSS_AK: ${{ secrets.OSS_AK }} + OSS_SK: ${{ secrets.OSS_SK }} + OSS_ENDPOINT: oss-cn-hongkong.aliyuncs.com + run: | + set -euo pipefail + umask 077 + home="$RUNNER_TEMP/codex-canary-home" + install -m 700 -d "$home" + ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \ + cp -f oss://doris-community-ci/codex/auth.json.4 "$home/auth.json" >/dev/null + jq -e ' + .auth_mode == "chatgpt" + and (.tokens.access_token | type == "string" and length > 0) + and (.tokens.refresh_token | type == "string" and length > 0) + ' "$home/auth.json" >/dev/null + sha256sum "$home/auth.json" | awk '{print $1}' \ + > "$RUNNER_TEMP/codex-canary-auth-original.sha256" + cat > "$home/config.toml" <<'EOF' + cli_auth_credentials_store = "file" + approval_policy = "never" + [features] + code_mode_only = true + code_mode_host = true + memories = false + apps = false + plugins = false + [otel] + exporter = "none" + trace_exporter = "none" + metrics_exporter = "none" + EOF + echo "CODEX_HOME=$home" >> "$GITHUB_ENV" + + - name: Test ChatGPT model access and goal mode without GitHub writes + timeout-minutes: 12 + run: | + set -uo pipefail + run_model() { + local label="$1" model="$2" goal="$3" + local events="$RUNNER_TEMP/codex-canary-$label.jsonl" + local final="$RUNNER_TEMP/codex-canary-$label.txt" + local args=(exec --skip-git-repo-check --json --model "$model" + --config model_reasoning_effort=low --sandbox read-only + --color never --output-last-message "$final") + if [ "$goal" = true ]; then + args+=(--goal) + fi + local prompt="Reply with exactly OK. Do not access files or external services." + if [ "$goal" = true ]; then + prompt="Create a goal to reply OK, mark it complete, then reply OK. Do not access files or external services." + fi + timeout --signal=INT --kill-after=10s 180s \ + env -u GH_TOKEN -u GITHUB_TOKEN "$CODEX_CANARY_BIN" \ + "${args[@]}" "$prompt" > "$events" 2> "$RUNNER_TEMP/codex-canary-$label.stderr" + local status=$? + echo "$label: exit_status=$status" + jq -r 'select(.type == "turn.failed" or .type == "error") | + .error.message // .message // empty' "$events" | tail -n 2 || true + if [ "$status" -ne 0 ] || + ! jq -e 'select(.type == "turn.completed")' "$events" >/dev/null; then + return 1 + fi + return 0 + } + + run_model sol gpt-6-sol false + sol_status=$? + run_model prior-sol gpt-5.6-sol false + prior_status=$? + goal_status=1 + if [ "$sol_status" -eq 0 ]; then + run_model sol-goal gpt-6-sol true + goal_status=$? + fi + echo "model_canary: gpt-6-sol=$sol_status gpt-5.6-sol=$prior_status gpt-6-sol-goal=$goal_status" + test "$sol_status" -eq 0 && test "$goal_status" -eq 0 + + - name: Sync refreshed canary auth + if: ${{ always() && steps.auth.outcome == 'success' }} + env: + OSS_AK: ${{ secrets.OSS_AK }} + OSS_SK: ${{ secrets.OSS_SK }} + OSS_ENDPOINT: oss-cn-hongkong.aliyuncs.com + run: | + set -euo pipefail + auth_object=oss://doris-community-ci/codex/auth.json.4 + jq -e ' + .auth_mode == "chatgpt" + and (.tokens.access_token | type == "string" and length > 0) + and (.tokens.refresh_token | type == "string" and length > 0) + ' "$CODEX_HOME/auth.json" >/dev/null + original_hash="$(cat "$RUNNER_TEMP/codex-canary-auth-original.sha256")" + local_hash="$(sha256sum "$CODEX_HOME/auth.json" | awk '{print $1}')" + if [ "$local_hash" = "$original_hash" ]; then + echo "Canary auth was unchanged." + exit 0 + fi + remote_auth="$(mktemp "$RUNNER_TEMP/codex-canary-current.XXXXXX")" + trap 'rm -f "$remote_auth"' EXIT + ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \ + cp -f "$auth_object" "$remote_auth" >/dev/null + remote_hash="$(sha256sum "$remote_auth" | awk '{print $1}')" + if [ "$remote_hash" != "$original_hash" ]; then + echo "::error::Auth changed concurrently; refusing to overwrite it." + exit 1 + fi + ossutil -i "$OSS_AK" -k "$OSS_SK" -e "$OSS_ENDPOINT" \ + cp -f "$CODEX_HOME/auth.json" "$auth_object" >/dev/null + echo "Synced refreshed canary auth." + code-review: runs-on: ubuntu-latest outputs: @@ -46,15 +199,18 @@ jobs: # leaving 12 minutes for runner setup and post-job cleanup. timeout-minutes: 238 if: >- - inputs.pr_number != '' || + inputs.runtime_canary != true && ( - github.event_name == 'issue_comment' && - github.event.issue.pull_request && - startsWith(github.event.comment.body, '/review') && + inputs.pr_number != '' || ( - github.event.comment.author_association == 'MEMBER' || - github.event.comment.author_association == 'OWNER' || - github.event.comment.author_association == 'COLLABORATOR' + github.event_name == 'issue_comment' && + github.event.issue.pull_request && + startsWith(github.event.comment.body, '/review') && + ( + github.event.comment.author_association == 'MEMBER' || + github.event.comment.author_association == 'OWNER' || + github.event.comment.author_association == 'COLLABORATOR' + ) ) ) steps: --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
