Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
101 changes: 73 additions & 28 deletions .github/workflows/ci-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,28 @@ permissions:

jobs:
review:
name: ${{ matrix.name }}
strategy:
fail-fast: false
matrix:
include:
- kind: code
name: Code review
instructions: |
检查本次代码改动的正确性、仓库设计规则及已有 CI 结果。先读取 AGENTS.md 和 CONTRIBUTING.md,再查看相关实现和测试。
用 gh pr checks 查询这个 PR 已有的检查结果,必要时读取 Actions 日志。检查失败、缺失或尚未完成时如实报告,不把合并当作检查通过的证据。
报告包括实际行为变化(1–3 条)、代码审查结论和 CI 状态。全部正常时保持简短;有问题时给出文件与行号、证据和最小修改建议。
- kind: docs
name: Docs review
instructions: |
每次都检查文档与本次代码变化是否一致,即使 PR 没改文档。读取相关实现、测试和完整文档,核对平台、命令、配置、路径、默认值、接口和操作流程,找出遗漏更新或已经过时的说明。
文档有修改(包括新增、删除和重命名)时,再检查文档内部及同主题文档间的矛盾、重复维护的事实、主题归属和中英文含义。按 AGENTS.md 和 CONTRIBUTING.md 的 Documentation ownership 表判断位置。必要的概述加链接、中英文对照和同一来源生成的文档不算重复。
分别报告“文档与代码一致性”和“文档矛盾、重复与归属”。未改文档时,第二项写“本次未修改文档”。只报告本次修改引入或使之过时的、有依据的问题,给出文件与行号、对应代码或文档依据,以及最小修改建议。测试或链接检查通过不代表语义一致。
if: github.event.pull_request.merged == true
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-24.04' || 'blacksmith-2vcpu-ubuntu-2404' }}
timeout-minutes: 30
env:
# allowed_non_write_users turns on a subprocess secret scrub; opt out so Claude's
# commands can read GH_TOKEN and the Feishu webhook.
# Keep GH_TOKEN available to read the PR and Actions logs.
CLAUDE_CODE_SUBPROCESS_ENV_SCRUB: '0'
steps:
# The triggering revision is already on main, so its rules and code are trusted.
Expand All @@ -30,14 +46,15 @@ jobs:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 2
persist-credentials: false
- name: Review and send Feishu card with Claude Code
# Notification is best effort: a failed review or delivery never fails the job.
- name: Prepare the report schema
id: schema
run: python3 scripts/ci_review.py schema >> "$GITHUB_OUTPUT"
- name: Review with Claude Code
id: llm
continue-on-error: true
timeout-minutes: 25
uses: anthropics/claude-code-action@12dd8d74c712f5f3669365b2369b558c495b1104 # v1
env:
FEISHU_WEBHOOK_URL: ${{ secrets.FEISHU_WEBHOOK_URL }}
FEISHU_WEBHOOK_SECRET: ${{ secrets.FEISHU_WEBHOOK_SECRET }}
ANTHROPIC_BASE_URL: https://api.minimax.cn/anthropic
ANTHROPIC_AUTH_TOKEN: ${{ secrets.MINIMAX_API_KEY }}
CLAUDE_CODE_AUTO_COMPACT_WINDOW: '524288'
Expand All @@ -54,29 +71,57 @@ jobs:
allowed_bots: '*'
allowed_non_write_users: '*'
prompt: |
你是 CI 的负责人,负责审核 CI 结果并给出结论。
仓库 ${{ github.repository }} 的 PR #${{ github.event.pull_request.number }} 已合入 main:
- PR:https://github.com/${{ github.repository }}/pull/${{ github.event.pull_request.number }}
- 合并 commit:${{ github.event.pull_request.merge_commit_sha }}(已 checkout 到当前目录)

用 gh pr checks ${{ github.event.pull_request.number }} --repo ${{ github.repository }} 查询这个 PR 已有的检查结果,必要时读取对应 Actions 日志。不要触发新的 CI,也不要把合并本身当作检查通过的证据;管理员可能绕过门禁。检查失败、缺失或尚未完成时如实报告。
你负责本次 PR 的 ${{ matrix.name }},在独立上下文中完成审查。
仓库:${{ github.repository }};PR:#${{ github.event.pull_request.number }}。
合并提交:${{ github.event.pull_request.merge_commit_sha }},已检出到当前目录。
先用 gh pr diff ${{ github.event.pull_request.number }} --repo ${{ github.repository }} 读取变更清单与完整差异,再检查相关文件。

任务:给飞书群发一张中文卡片(Card 2.0)总结这次 CI,尽量在 10 轮以内给出结论,工具调用尽可能的并行。
环境里有 gh(已登录,GH_TOKEN)、git、node 和完整的仓库代码。
${{ matrix.instructions }}

卡片要让手机上的读者快速看懂,如果一切正常,表达的尽可能简单,如果没有问题,尽量简洁:
1. 哪个 PR(github id + PR 标题 + 链接)
- 如:`github id: jing332, PR 标题: 添加一个新功能, 链接: https://github.com/org/repo/pull/123`
2. 改了什么(实际行为变化,1–3 条)
- 如:`添加了一个新功能、修改了 web 和 backend 的 CI`
3. 是否符合仓库规则(AGENTS.md、CONTRIBUTING.md 及相关文档):未发现明确违规 / 发现需修复问题 / 信息不足,无法确认
- 如:`符合仓库规则`
4. CI 哪里失败、可能的原因(可以看日志),全部通过就直接说通过,不要给出细节。如果 CI 失败,则详细说明。
- 如:`CI 失败,具体是哪几个失败;全部通过 ✅`

发送:webhook 地址在环境变量 FEISHU_WEBHOOK_URL。
响应 code=0 才算成功,失败就排查并重试,直到发出去。最后用一句中文说明结果,如:`CI 结果已发送至飞书群`。
不要在输出里打印 webhook 地址和密钥。
按 JSON schema 返回中文报告。status 为 ok(未发现问题)、issues(发现有证据的问题)或 incomplete(审查失败、范围未检查完整或检查结果尚未完成)。有问题且仍有未检查项时,用 issues 并在 summary 中说明缺项。summary 无问题时简短,有问题时保留依据和建议,遵守 schema 的长度限制。
只读审查,不修改仓库,不触发新的 CI,不发送消息。两份报告会由后续 job 合并发送。
claude_args: >-
--allowedTools Bash Read Write Edit Glob Grep WebFetch WebSearch
--allowedTools Bash Read Glob Grep
--max-turns 30
--json-schema '${{ steps.schema.outputs.schema }}'
- name: Save the review result
if: always()
env:
REVIEW_OUTCOME: ${{ steps.llm.outcome }}
REVIEW_RESULT: ${{ steps.llm.outputs.structured_output }}
run: python3 scripts/ci_review.py collect "$RUNNER_TEMP/review-${{ matrix.kind }}.json"
- uses: actions/upload-artifact@v6
if: always()
with:
name: ci-review-${{ matrix.kind }}
path: ${{ runner.temp }}/review-${{ matrix.kind }}.json
if-no-files-found: error
overwrite: true
retention-days: 7

notify:
name: Combined Feishu notification
needs: review
if: always() && github.event.pull_request.merged == true
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-24.04' || 'blacksmith-2vcpu-ubuntu-2404' }}
timeout-minutes: 5
permissions:
contents: read
actions: read
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
persist-credentials: false
- uses: actions/download-artifact@v6
continue-on-error: true
with:
pattern: ci-review-*
merge-multiple: true
path: ${{ runner.temp }}/reviews
- name: Send one card with both results
continue-on-error: true
env:
FEISHU_WEBHOOK_URL: ${{ secrets.FEISHU_WEBHOOK_URL }}
FEISHU_WEBHOOK_SECRET: ${{ secrets.FEISHU_WEBHOOK_SECRET }}
run: python3 scripts/ci_review.py notify "$RUNNER_TEMP/reviews"
4 changes: 3 additions & 1 deletion docs/maintainers.md
Original file line number Diff line number Diff line change
Expand Up @@ -192,7 +192,9 @@ The final `check` runs even when planning or a dependency fails. It requires a s

Use **Actions → core-check → Run workflow** for a manual full check. For a transient failure, use GitHub's **Re-run failed jobs** so successful jobs remain completed. PR updates cancel the superseded run through Actions concurrency. Build and dependency caches speed execution; they do not stand in for successful tests. Native release installers are passed between jobs using Actions artifacts, within the same release workflow.

The `CI review and Feishu notification` workflow runs once after a PR merges into main. It checks out the merged commit, reads that PR's existing checks and logs, and reports their actual status. It does not trigger another test run. Closing an unmerged PR does not invoke the review. The workflow uses `pull_request_target` only for the merged event and never checks out an unmerged PR head with notification credentials.
The `CI review and Feishu notification` workflow runs after a PR merges into main. A matrix runs **Code review** and **Docs review** in independent LLM contexts with `fail-fast: false`. Both read the merged commit and PR diff. Code review checks implementation, repository rules and existing CI results; it does not start another test run. Docs review checks changed behavior against documentation even when no docs changed. When docs change, it also checks contradictions, duplicated facts, topic ownership under CONTRIBUTING, and English/Chinese agreement. Findings include file and line references, supporting evidence and a minimal correction. Reviews read the repository without editing it.

Each review returns a structured result (`ok`, `issues` or `incomplete`) and a Chinese summary, retained as an Actions artifact for seven days. **Combined Feishu notification** waits for both jobs and sends one Card 2.0 message containing both results through the existing `FEISHU_WEBHOOK_URL`; `FEISHU_WEBHOOK_SECRET` optionally signs it. Only this notification job receives the webhook secrets. Failed, missing or invalid reports appear as incomplete, alongside any available result from the other review. The notification job runs even when a review fails. Delivery requires Feishu's `code=0` response; a failed or ambiguous request is not automatically retried, avoiding duplicate messages. Review and delivery failures do not block merges, and closing an unmerged PR does not trigger this workflow. The workflow checks out only the merged commit with notification credentials.

Browser jobs own separate fixtures and servers; increasing workers against the shared mutable fixture is unsafe. Failed browser jobs retain reports/traces for seven days. Native failure phase summaries are retained for seven days and detailed output stays in the Actions logs; credentials and temporary installation trees are not uploaded. Successful native archives are uploaded only for explicit manual packaging or releases, without recompressing the compressed archive. Release distribution artifacts retain their existing recovery policy; failed publication can reuse the original build as described above.

Expand Down
6 changes: 4 additions & 2 deletions docs/zh/maintainers.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: "构建并发布 OpenAgentCore"
source: docs/maintainers.md
source_hash: 4f9fd38af5afd47e21589160930347f6693dd4786f56fb2dff2abd4853b3f72f
source_hash: bfe6a890a27ff93640636197e72241c71f94c14ca62385be54c69f203ee563e1
---

本指南面向负责构建和发布 OpenAgentCore 的维护者。要安装 Core 和 Web,请使用 [安装指南](getting-started/install.md)。安装器代码遵循的规则见 [部署](https://github.com/MiniMax-AI/OpenAgentCore/blob/main/deploy/README.md) 和 [节点安装器](https://github.com/MiniMax-AI/OpenAgentCore/blob/main/deploy/node/README.md);必需检查见 [CONTRIBUTING](https://github.com/MiniMax-AI/OpenAgentCore/blob/main/CONTRIBUTING.md#required-checks)。
Expand Down Expand Up @@ -196,7 +196,9 @@ Go 模块和工作区输入会选择后端、API(包括容器)、原生和

要手动执行完整检查,请使用 **Actions → core-check → Run workflow**。遇到暂时性故障时,请使用 GitHub 的 **Re-run failed jobs**,这样已成功的作业可保持完成状态。PR 更新后,Actions 并发机制会取消已被取代的运行。构建和依赖项缓存可加快执行,但不能替代成功的测试。原生发布安装器通过 Actions 构建产物在同一发布工作流的不同作业之间传递。

`CI review and Feishu notification` 工作流仅在 PR 合并到 main 后运行一次。它检出合并后的提交,读取该 PR 已有的检查和日志,并报告实际状态,不会触发另一轮测试。关闭未合并 PR 不触发审查。该工作流只针对合并事件使用 `pull_request_target`,绝不在持有通知凭据时检出未合并 PR 的 head。
`CI review and Feishu notification` 工作流在 PR 合入 main 后运行。矩阵中的 **Code review** 和 **Docs review** 使用独立的 LLM 上下文,并设置 `fail-fast: false`。两者读取合并后的提交和 PR 差异。代码审查检查实现、仓库规则和已有 CI 结果,不触发新一轮测试。文档审查会核对行为变化与文档是否一致,即使没有修改文档;修改文档时,还会检查矛盾、重复维护的事实、CONTRIBUTING 规定的主题归属及中英文含义。每项问题包含文件和行号、依据及最小修改建议。审查只读取仓库,不修改文件。

每项审查返回结构化结果(`ok`、`issues` 或 `incomplete`)及中文摘要,作为 Actions 构建产物保留七天。**Combined Feishu notification** 等待两项审查结束,通过已有的 `FEISHU_WEBHOOK_URL` 发送一张包含两份结果的 Card 2.0 卡片;可选的 `FEISHU_WEBHOOK_SECRET` 用于签名。只有通知 job 能读取 webhook 密钥。审查失败、报告缺失或格式无效时标为未完成,另一项已有的结果照常展示。某项审查失败时,通知 job 仍会运行。只有飞书返回 `code=0` 才确认送达;请求失败或送达状态不明时不自动重试,以免重复发消息。审查和发送失败不会阻止合并;关闭未合并的 PR 不触发此流程。持有通知凭据时,工作流只检出合并后的提交。

浏览器作业各自拥有独立的固定数据和服务;对共享可变固定数据增加 worker 数不安全。失败的浏览器作业保留报告与 trace 七天。原生失败阶段摘要保留七天,详细输出留在 Actions 日志中;凭据和临时安装目录不上传。成功的原生归档仅用于显式手动打包或发布时上传,不重新压缩已压缩的归档。发布分发产物保留现有恢复策略;失败发布可以按前述方式复用原构建。

Expand Down
Loading
Loading