fix(sdk): reuse authored CLI probes for each run so concurrent f.llm never outlives its lease (#561) #636
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Review swarm wrapper guard | ||
|
Check warning on line 1 in .github/workflows/review-swarm-wrapper-guard.yml
|
||
| on: | ||
| pull_request_target: | ||
| types: [opened, synchronize, reopened, ready_for_review] | ||
| permissions: | ||
| contents: read | ||
| pull-requests: read | ||
| jobs: | ||
| guard: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| # pull_request_target always reads this workflow and script from the PR | ||
| # base. A candidate therefore cannot relax the guard that evaluates it. | ||
| - uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.event.pull_request.base.sha }} | ||
| persist-credentials: false | ||
| - name: Reject candidate-owned wrapper changes | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| REVIEW_PR_NUMBER: ${{ github.event.pull_request.number }} | ||
| run: .github/workflows/scripts/swarm-wrapper-guard.sh "$REVIEW_PR_NUMBER" | ||
| # #218: the pre-swarm runner and the post-push swarm YAML carry the same | ||
| # three lens contracts. If they drift, the weaker prompt can hold the | ||
| # auto-merge gate while the stricter pre-check yells into the void. | ||
| # Enforce that workflows/review-swarm.yaml role blocks retain every | ||
| # canonical clause from ops/preswarm-check/lens-prompts/. Runs from base | ||
| # (same pull_request_target invariant) so a candidate cannot relax it. | ||
| - name: Enforce lens parity between pre-swarm runner and post-push swarm | ||
| run: sh ops/preswarm-check/lens-parity-check.sh | ||
| # flows#255: same drift shape, different axis. The prompt can match while | ||
| # the CLIs disagree — and a lens whose CLI is not available in either | ||
| # runner produces MISSING transcripts on every PR, keeping `review` | ||
| # unpassable by construction. `structure = opencode` was that failure | ||
| # mode. Enforce the runner and the swarm agree on the CLI per lens. | ||
| # PRESWARM_ALLOW_MISSING_CLI=1 here because THIS workflow runs on the | ||
| # generic GitHub Actions runner which never has claude/codex/opencode | ||
| # on PATH — the CLI-presence half of the check belongs to the actual | ||
| # pre-swarm runner env, which sets this to 0 (its default). | ||
| - name: Enforce lens CLI parity between pre-swarm runner and post-push swarm | ||
| env: | ||
| PRESWARM_ALLOW_MISSING_CLI: "1" | ||
| run: sh ops/preswarm-check/lens-cli-parity-check.sh | ||