Skip to content

fix(sdk): reuse authored CLI probes for each run so concurrent f.llm never outlives its lease (#561) #636

fix(sdk): reuse authored CLI probes for each run so concurrent f.llm never outlives its lease (#561)

fix(sdk): reuse authored CLI probes for each run so concurrent f.llm never outlives its lease (#561) #636

name: Review swarm wrapper guard

Check warning on line 1 in .github/workflows/review-swarm-wrapper-guard.yml

View workflow run for this annotation

GitHub Actions / Review swarm wrapper guard

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
on:
pull_request_target:
types: [opened, synchronize, reopened, ready_for_review]
permissions:
contents: read
pull-requests: read
jobs:
guard:
runs-on: ubuntu-latest
steps:
# pull_request_target always reads this workflow and script from the PR
# base. A candidate therefore cannot relax the guard that evaluates it.
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.base.sha }}
persist-credentials: false
- name: Reject candidate-owned wrapper changes
env:
GH_TOKEN: ${{ github.token }}
REVIEW_PR_NUMBER: ${{ github.event.pull_request.number }}
run: .github/workflows/scripts/swarm-wrapper-guard.sh "$REVIEW_PR_NUMBER"
# #218: the pre-swarm runner and the post-push swarm YAML carry the same
# three lens contracts. If they drift, the weaker prompt can hold the
# auto-merge gate while the stricter pre-check yells into the void.
# Enforce that workflows/review-swarm.yaml role blocks retain every
# canonical clause from ops/preswarm-check/lens-prompts/. Runs from base
# (same pull_request_target invariant) so a candidate cannot relax it.
- name: Enforce lens parity between pre-swarm runner and post-push swarm
run: sh ops/preswarm-check/lens-parity-check.sh
# flows#255: same drift shape, different axis. The prompt can match while
# the CLIs disagree — and a lens whose CLI is not available in either
# runner produces MISSING transcripts on every PR, keeping `review`
# unpassable by construction. `structure = opencode` was that failure
# mode. Enforce the runner and the swarm agree on the CLI per lens.
# PRESWARM_ALLOW_MISSING_CLI=1 here because THIS workflow runs on the
# generic GitHub Actions runner which never has claude/codex/opencode
# on PATH — the CLI-presence half of the check belongs to the actual
# pre-swarm runner env, which sets this to 0 (its default).
- name: Enforce lens CLI parity between pre-swarm runner and post-push swarm
env:
PRESWARM_ALLOW_MISSING_CLI: "1"
run: sh ops/preswarm-check/lens-cli-parity-check.sh