From b99105c2587df62bc68d67cb2d0d1304886a7f63 Mon Sep 17 00:00:00 2001 From: kjgbot Date: Sun, 30 Aug 2026 20:49:30 +0200 Subject: [PATCH] drive: cloud run e2cd862d Work produced by cloud run e2cd862d-6d10-497b-a16c-230a92f1084e in a workflow sandbox and delivered from this host, because a sandbox has no remote and no GitHub token. Verification and adversarial review ran in-run; see ops/reviews/ in the diff. --- ops/NEEDS_HUMAN.md | 19 +++++++++++ sdk/ops/NEXT.md | 78 ++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 97 insertions(+) create mode 100644 ops/NEEDS_HUMAN.md create mode 100644 sdk/ops/NEXT.md diff --git a/ops/NEEDS_HUMAN.md b/ops/NEEDS_HUMAN.md new file mode 100644 index 000000000..e6d0945d8 --- /dev/null +++ b/ops/NEEDS_HUMAN.md @@ -0,0 +1,19 @@ +# Gate 3 worker package is already shipped + +This checkout cannot honestly complete `ops/NEXT.md` as written: + +1. `ops/TARGET.md` identifies the SDK agent worker as already merged in PR #53 + at `9681f11` and explicitly says not to rewrite, replace, or fix it. The + requested files and live test are already present, and the full definition- + of-done test commands pass after restoring executable fixture modes lost by + this propagated checkout. +2. Definition-of-done item 7 requires literal evidence that every new test + failed against the pre-change code. This checkout contains only the shipped + implementation and test, so no honest pre-change failure can be captured. +3. The checkout's `.git` file points to `/home/daytona/.project-git`, which is + absent. Therefore the required final `git status --porcelain` cannot produce + repository status. + +Human action: provide a checkout with valid Git metadata and the pre-`9681f11` +baseline if this historical package must be reproduced, or replace stale +`ops/NEXT.md` with the current work package from `ops/TARGET.md`. diff --git a/sdk/ops/NEXT.md b/sdk/ops/NEXT.md new file mode 100644 index 000000000..87304ece9 --- /dev/null +++ b/sdk/ops/NEXT.md @@ -0,0 +1,78 @@ +# Work package — gate 3, review-swarm GitHub Actions integration + +**Scope from target:** Wire the review-swarm to fire on PR open via GitHub Actions + `agent-relay cloud run`. CODE task, `.github/workflows/`-side. + +## Objective + +Add `.github/workflows/review-swarm.yml` that triggers the existing `workflows/review-swarm.yaml` workflow on PR events, runs it via `agent-relay cloud run`, and posts the review transcripts as PR comments. This is the only file this tick should create; the workflow it invokes already exists. + +## Files in scope + +- `.github/workflows/review-swarm.yml` — NEW, the GitHub Actions workflow +- `.github/workflows/scripts/swarm-post.sh` (or inline shell) — NEW, companion script to post comments +- `README.md` or `docs/` — EDIT one sentence to document `RELAY_WORKSPACE_KEY` secret + +## Definition of done (ALL required) + +1. `.github/workflows/review-swarm.yml` exists +2. Passes `actionlint` if installed, or `yamllint` otherwise. Literal command and output: + ``` + actionlint .github/workflows/review-swarm.yml + [paste exact output] + ``` +3. `README.md` or `docs/` describes the required repo secret (`RELAY_WORKSPACE_KEY`) and what it does — one sentence is enough +4. The workflow's `jobs.review.if` correctly gates on drive-loop author only. Test the expression by hand and show it evaluates true for kjgbot and false for khaliqgant: + ``` + [paste literal test command and output showing true/false results] + ``` +5. A dry-run test proving the shell logic works against an EXISTING completed cloud run. Literal command and output: + ``` + bash .github/workflows/scripts/swarm-post.sh + [paste exact output including posted comment URL] + ``` +6. `npm test` green (unaffected by this change). Literal command and output: + ``` + npm test + [paste exact summary showing Test Files passed/failed counts] + ``` + Note: tests requiring kernel binaries will fail in this sandbox environment; what matters is that core SDK tests remain green. +7. As LAST action, run `git status --porcelain` and paste it: + ``` + git status --porcelain + [paste exact output] + ``` + +## Workflow specification + +Trigger: +- `pull_request` events: `opened`, `synchronize`, `reopened` +- Only run if `github.event.pull_request.user.login` is a drive-loop author (`kjgbot`, `miyaontherelay`) +- Concurrency group per PR so a second push cancels the first review + +Job steps: +1. Checkout the PR's head at the merge commit +2. Install `agent-relay` (check if this repo uses `mise` via `.mise.toml`, or curl the release) +3. `echo "$PR_NUMBER" > .review-target` +4. `agent-relay cloud run workflows/review-swarm.yaml` with `RELAY_WORKSPACE_KEY` from repo secret; capture the runId +5. Poll `agent-relay cloud status --json` every 30s until `status == completed` or 45 min elapse +6. `agent-relay cloud sync ` to fetch the run's artifacts +7. Read `ops/reviews/*-pr-*.md` produced by the swarm; post each as a PR comment via `gh pr comment` +8. Post one aggregate marker comment: `🎯 review-swarm: PASSED|FAILED (M: H: S:)` — grep the aggregate step output for `SWARM_PASSED` or `SWARM_FAILED` + +## Prerequisites this brief cannot satisfy + +If either of these is missing, write ops/NEEDS_HUMAN.md and still end with ASSESS_DONE: + +1. **`RELAY_WORKSPACE_KEY` must exist as a GitHub Actions secret** on `AgentWorkforce/flows`. Cannot be created from this sandbox. +2. **`agent-relay cloud run` invoked from GHA must reach the same cloud workspace as the laptop.** If the run fails with an auth error, DO NOT invent a workaround — file it as NEEDS_HUMAN. + +## Explicitly OUT of scope + +- Building the kernel +- Running kernel tests +- Modifying `workflows/review-swarm.yaml` (it already exists) +- Modifying preflight logic (`ops/preflight.sh` or SDK preflight) +- Touching `sdk/src/work-package-validator.ts` (closed by PR #50) +- Touching `kernel/relayflowd/src/server/tests.rs` or `server.rs` (closed by PR #48) +- Touching `sdk/src/worker.ts` (closed by PR #53) +- Any work on gates other than gate 3