Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 98 additions & 0 deletions .github/workflows/review-swarm.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
name: Review swarm

on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]

permissions:
contents: read
pull-requests: write

concurrency:
group: review-swarm-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
review:
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
# Ordering invariant: swarm 60m < poll 65m < job 75m.
timeout-minutes: 75
steps:
- name: Check out pull request
uses: actions/checkout@v4
with:
path: pull-request

# The judged PR cannot alter the gate or scripts that judge it.
- name: Check out immutable gate from main
uses: actions/checkout@v4
with:
ref: main
path: review-gate

- name: Validate cloud authentication
env:
RELAY_WORKSPACE_KEY: ${{ secrets.RELAY_WORKSPACE_KEY }}
run: |
if [ -z "$RELAY_WORKSPACE_KEY" ]; then
echo "RELAY_WORKSPACE_KEY secret not configured; see README §Review swarm secret" >&2
exit 1
fi

- name: Prepare PR evidence on launching host
working-directory: review-gate
env:
GH_TOKEN: ${{ github.token }}
run: sh .github/workflows/scripts/swarm-prepare.sh '${{ github.event.pull_request.number }}'

- name: Install Agent Relay CLI
run: npm install --global agent-relay

- name: Launch cloud swarm
id: launch
working-directory: review-gate
env:
RELAY_WORKSPACE_KEY: ${{ secrets.RELAY_WORKSPACE_KEY }}
run: |
response=$(agent-relay cloud run workflows/review-swarm.yaml --sync-code --json)
run_id=$(printf '%s' "$response" | jq -r '.runId // .id // empty')
if [ -z "$run_id" ]; then
echo "cloud launch returned no run id: $response" >&2
exit 1
fi
echo "run_id=$run_id" >> "$GITHUB_OUTPUT"

- name: Wait for cloud swarm
id: wait
if: always() && steps.launch.outputs.run_id != ''
env:
RELAY_WORKSPACE_KEY: ${{ secrets.RELAY_WORKSPACE_KEY }}
run: |
# Ordering invariant: swarm 3600s < this 3900s poll deadline < job 75m.
deadline=$((SECONDS + 3900))
swarm_status=timeout
while [ "$SECONDS" -lt "$deadline" ]; do
status=$(agent-relay cloud status '${{ steps.launch.outputs.run_id }}' 2>/dev/null \
| sed -n 's/^Status:[[:space:]]*//p' | head -n 1)
case "$status" in
completed|failed|cancelled) swarm_status=$status; break ;;
esac
sleep 30
done
echo "swarm_status=$swarm_status" >> "$GITHUB_OUTPUT"
exit 0

- name: Sync and post transcripts
if: always() && steps.launch.outputs.run_id != ''
working-directory: review-gate
env:
GH_TOKEN: ${{ github.token }}
RELAY_WORKSPACE_KEY: ${{ secrets.RELAY_WORKSPACE_KEY }}
run: sh .github/workflows/scripts/swarm-post.sh '${{ steps.launch.outputs.run_id }}' '${{ github.event.pull_request.number }}' '${{ github.repository }}'

- name: Enforce terminal status
if: always() && steps.wait.outputs.swarm_status != 'completed'
run: |
echo "review swarm did not complete: ${{ steps.wait.outputs.swarm_status }}" >&2
exit 1
55 changes: 55 additions & 0 deletions .github/workflows/scripts/swarm-post.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
#!/bin/sh
# Sync a completed cloud run and upsert its three lens transcripts on the PR.
set -eu

run_id=${1:?usage: swarm-post.sh RUN_ID PR_NUMBER REPOSITORY}
pr_number=${2:?usage: swarm-post.sh RUN_ID PR_NUMBER REPOSITORY}
repository=${3:?usage: swarm-post.sh RUN_ID PR_NUMBER REPOSITORY}

sync_started=.review-target/sync-start
agent-relay cloud sync "$run_id"

. .github/workflows/scripts/swarm-verdict.sh
overall=PASSED
swarm_evaluate ops/reviews "$pr_number" "$sync_started" || overall=FAILED

upsert_comment() {
anchor=$1
body_file=$2
comment_id=$(gh api --paginate "repos/$repository/issues/$pr_number/comments" \
--jq ".[] | select(.body | contains(\"$anchor\")) | .id" | head -n 1)
if [ -n "$comment_id" ]; then
gh api --method PATCH "repos/$repository/issues/comments/$comment_id" \
--raw-field "body=$(cat "$body_file")" >/dev/null
else
gh api --method POST "repos/$repository/issues/$pr_number/comments" \
--raw-field "body=$(cat "$body_file")" >/dev/null
fi
}

for lens in maintainability history structure; do
transcript=$(swarm_latest_transcript ops/reviews "$pr_number" "$lens")
comment_file=$(mktemp)
{
echo "<!-- swarm-lens: $lens -->"
echo "### Review swarm: $lens"
echo
if [ -n "$transcript" ] && swarm_is_fresh "$transcript" "$sync_started"; then
cat "$transcript"
else
echo "SWARM_FAILED: no fresh transcript was produced for this run."
fi
} > "$comment_file"
upsert_comment "<!-- swarm-lens: $lens -->" "$comment_file"
rm -f "$comment_file"
done

marker_file=$(mktemp)
{
echo '<!-- review-swarm -->'
echo "Review swarm run \`$run_id\`: **$overall**"
} > "$marker_file"
upsert_comment '<!-- review-swarm -->' "$marker_file"
rm -f "$marker_file"

[ "$overall" = PASSED ]
14 changes: 14 additions & 0 deletions .github/workflows/scripts/swarm-prepare.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
#!/bin/sh
# Fetch PR evidence where GitHub authentication exists and stage it for upload.
set -eu

pr_number=${1:?usage: swarm-prepare.sh PR_NUMBER}
case "$pr_number" in *[!0-9]*|'') echo "invalid PR number: $pr_number" >&2; exit 1 ;; esac

mkdir -p .review-target
printf '%s\n' "$pr_number" > .review-target/pr-number
gh pr diff "$pr_number" > .review-target/pr.diff
gh pr view "$pr_number" --json headRefName,headRefOid,title,url > .review-target/pr.json
touch .review-target/sync-start
git add -f .review-target/pr-number .review-target/pr.diff \
.review-target/pr.json .review-target/sync-start
58 changes: 58 additions & 0 deletions .github/workflows/scripts/swarm-verdict.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
#!/bin/sh
# Shared, fail-closed transcript selection and verdict extraction.

swarm_latest_transcript() {
transcript_dir=$1
pr_number=$2
lens=$3
find "$transcript_dir" -maxdepth 1 -type f \
-name "*-pr${pr_number}-${lens}.md" -print 2>/dev/null | LC_ALL=C sort | tail -n 1
}

swarm_transcript_verdict() {
transcript=$1
token=$(awk 'NF { token=$NF } END { print token }' "$transcript")
case "$token" in
REVIEW_PASSED) printf '%s\n' PASSED ;;
REVIEW_FAILED) printf '%s\n' FAILED ;;
*) printf '%s\n' UNCLEAR ;;
esac
}

swarm_is_fresh() {
transcript=$1
sync_start=$2
[ -f "$sync_start" ] || return 1
[ "$(stat -c %Y "$transcript")" -ge "$(stat -c %Y "$sync_start")" ]
}

swarm_evaluate() {
transcript_dir=$1
pr_number=$2
sync_start=$3
swarm_failed=0

for lens in maintainability history structure; do
transcript=$(swarm_latest_transcript "$transcript_dir" "$pr_number" "$lens")
if [ -z "$transcript" ]; then
echo "SWARM_FAILED: $lens produced no transcript"
swarm_failed=1
continue
fi
if ! swarm_is_fresh "$transcript" "$sync_start"; then
echo "SWARM_FAILED: $lens transcript predates sync start ($transcript)"
swarm_failed=1
continue
fi
verdict=$(swarm_transcript_verdict "$transcript")
if [ "$verdict" = PASSED ]; then
echo "ok: $lens passed ($transcript)"
else
echo "SWARM_FAILED: $lens verdict is $verdict ($transcript)"
swarm_failed=1
fi
done

[ "$swarm_failed" -eq 0 ] && { echo SWARM_PASSED; return 0; }
return 1
}
2 changes: 0 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,6 @@ dist/
.env
.agentworkforce/
.cargo-home/
.review-target

# Toolchains materialize inside the workspace in a cloud sandbox and must never
# be committed or delivered. Run f18ec684's patch carried .rustup-home/ files;
# ops/deliver-run.sh scrubs them too, but ignoring them is the durable fix.
Expand Down
14 changes: 14 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,3 +30,17 @@ Nine gates, in `docs/RFC-0001` §3. Gate 1 first: a relayflow can run — the he
ladder survives `kill -9` at every boundary.

Private while we build. YC 2026-09-15 runs on this base.

## Review swarm secret

The pull-request review swarm requires the repository Actions secret
`RELAY_WORKSPACE_KEY`. Obtain the key for the canonical cloud workspace on an
authenticated operator machine, then store it in GitHub:

```bash
agent-relay workspace key
agent-relay workspace key | gh secret set RELAY_WORKSPACE_KEY
```

The workflow fails before launching a cloud run when the secret is absent or
empty. Rotate it by running the second command again with the replacement key.
Loading
Loading