shuke987 opened a new pull request, #68547:
URL: https://github.com/apache/doris/pull/68547

   ## Why
   
   The review runner installs a current Codex CLI, then overwrites its 
executable with an older standalone goal binary. That binary reports version 
0.0.0 and sends `gpt-6-sol` through a legacy request path, resulting in ChatGPT 
account 400 errors.
   
   ## Change
   
   - Download the complete Codex 0.156.1 goal package from a pinned OSS release 
key on Ubuntu 24.04.
   - Verify the archive and every package file before adding its `bin` 
directory to PATH.
   - Verify the runtime binary hash and goal CLI before loading review auth.
   - Keep a separate dispatch canary that never submits a PR review or status.
   
   The old production `codex-goal` object remains untouched. An immutable 
backup is at 
`oss://doris-community-ci/codex/backups/codex-goal-59647a8003ae3af0aa8885c957ed8c85a48df362b62564e96c9f5b09c289b421`.
   
   ## Validation
   
   - [Canary 1](https://github.com/apache/doris/actions/runs/36387696663) and 
[canary 2](https://github.com/apache/doris/actions/runs/36388015864) passed 
with an existing review ChatGPT account. Both completed `gpt-6-sol`, 
`gpt-5.6-sol`, and `gpt-6-sol --goal` with exit status 0. Review and aggregate 
jobs were skipped; auth was unchanged.
   - Workflow YAML parsed, shell run blocks passed `bash -n`, and `git diff 
--check` passed.
   - Package source: [release candidate 
workflow](https://github.com/shuke987/codex/actions/runs/35856759367), commit 
`a310d33f7ebbeafa0e5dbc7c159ec6f4cf10c0f1`.
   
   Rollback: revert this workflow change. The old OSS object is still available.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to