From 4b9fc9f3c355649018b99df0734b28d37ea002d7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sun, 27 Sep 2026 19:50:22 +0900 Subject: [PATCH] fix(ci): admit trusted review mention forwarding to self-hosted runners --- .github/workflows/agent-mention-noema-dispatch.yml | 2 +- .../workflows/agent-mention-opencode-dispatch.yml | 2 +- tests/test_agent_mention_downstream_idempotency.py | 13 +++++++++++++ 3 files changed, 15 insertions(+), 2 deletions(-) diff --git a/.github/workflows/agent-mention-noema-dispatch.yml b/.github/workflows/agent-mention-noema-dispatch.yml index ad8abc7b25..c9514a47a1 100644 --- a/.github/workflows/agent-mention-noema-dispatch.yml +++ b/.github/workflows/agent-mention-noema-dispatch.yml @@ -28,7 +28,7 @@ permissions: jobs: validate-and-forward: if: github.repository == 'ContextualWisdomLab/.github' - runs-on: ubuntu-24.04 + runs-on: ${{ github.repository == 'ContextualWisdomLab/.github' && endsWith(github.workflow_ref, '@refs/heads/main') && fromJSON('{"group":"CWL MCP remediation","labels":["self-hosted","linux","x64"]}') || fromJSON('["ubuntu-24.04"]') }} timeout-minutes: 5 permissions: actions: read diff --git a/.github/workflows/agent-mention-opencode-dispatch.yml b/.github/workflows/agent-mention-opencode-dispatch.yml index 05461c9551..3b21667832 100644 --- a/.github/workflows/agent-mention-opencode-dispatch.yml +++ b/.github/workflows/agent-mention-opencode-dispatch.yml @@ -28,7 +28,7 @@ permissions: jobs: validate-and-forward: if: github.repository == 'ContextualWisdomLab/.github' - runs-on: ubuntu-24.04 + runs-on: ${{ github.repository == 'ContextualWisdomLab/.github' && endsWith(github.workflow_ref, '@refs/heads/main') && fromJSON('{"group":"CWL MCP remediation","labels":["self-hosted","linux","x64"]}') || fromJSON('["ubuntu-24.04"]') }} timeout-minutes: 5 permissions: actions: read diff --git a/tests/test_agent_mention_downstream_idempotency.py b/tests/test_agent_mention_downstream_idempotency.py index cb3c31763e..28c9084a9b 100644 --- a/tests/test_agent_mention_downstream_idempotency.py +++ b/tests/test_agent_mention_downstream_idempotency.py @@ -129,3 +129,16 @@ def test_quality_gate_runs_full_suite_for_docs_and_exact_diff() -> None: coverage_config = text.split("[run]\n", 1)[1].split("[report]\n", 1)[0] assert "scripts/ci/agent_mention_router.py" in coverage_config assert "scripts/ci/agent_mention_sweep.py" in coverage_config + + +def test_forwarders_restrict_self_hosted_admission_to_trusted_main() -> None: + """Branch workflows cannot select the main-only privileged runner group.""" + for path in (NOEMA_WORKFLOW, OPENCODE_WORKFLOW): + text = path.read_text(encoding="utf-8") + selector = next(line for line in text.splitlines() if "runs-on:" in line) + assert "github.repository == 'ContextualWisdomLab/.github'" in selector + assert "endsWith(github.workflow_ref, '@refs/heads/main')" in selector + assert '"group":"CWL MCP remediation"' in selector + assert '"labels":["self-hosted","linux","x64"]' in selector + assert "|| fromJSON('[\"ubuntu-24.04\"]')" in selector + assert "actions/checkout@" not in text