Repository navigation
Reviewer: port the hardened harness from bookplayer-android (247 tests, trust split) - #1611
Merged
Merged
Conversation
…s, trust split) Replaces the first-generation reviewer (review.mjs + github.mjs from July: no sandbox, bypassPermissions, model pinned to claude-opus-4-8, SDK "latest", no lockfile, no tests) with bookplayer-android's develop copy (7f1996c0). The 18 shared files are byte-identical to the android, api and support-pipeline copies; the per-repository files are repo.mjs, review-guide.md, the README's local-run example and the workflow's branch list. Workflow: pull_request_target on develop only; the harness and guide run from the base branch, the PR tree is checked out beside them as data, and the secrets live in the `reviewer` environment (deployment-branch policy develop). Fork, draft and Dependabot PRs are skipped. Release PRs into main stay unreviewed, as before. repo.mjs: Debug.xcconfig is a secret file (the template stays readable; Release.xcconfig is tracked with placeholders and stays reviewable). Shapes: the Sentry DSN with or without its scheme, because the xcconfig stores it without https:// and AppDelegate prepends it, and the RevenueCat/store keys. review-guide.md: the agent no longer has gh or an origin/develop ref, so the diff instructions point at the file the harness writes; the iOS focus list the old prompt carried (weak self, stored cancellables, @mainactor and DB threading, AVAudioSession lifecycle, the BookPlayerKit boundary) moves into "How to review", since the shared prompt names no repository; the Release.xcconfig wording matches what the file is; "Reporting findings" describes the verification pass that now closes threads.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A copy, not a merge. The reviewer harness is repository-agnostic, so this PR replaces the first-generation
.github/claude/reviewer/(two files from July, no tests) withbookplayer-android'sdevelopcopy (7f1996c0), andclaude-review.ymlwith its workflow. It's the same port asbookplayer-api#40andbookplayer-support-pipeline#16.develop)review.mjs+github.mjs, 462 lines, no testsbypassPermissions, the agent holdsGH_TOKENcanUseToolgrammar gate + PreToolUse hook, reads confined to the checkout + diff file, write tokens withheld, redaction on every post and log lineclaude-opus-4-8, SDKlatest, no lockfile, 50 turnseffort: high, 12-min deadlinepull_request, PR-head harness, repo-level secretspull_request_target, harness + guide fromdevelop, PR tree as data, secrets in thereviewerenvironment, fork/draft/Dependabot skipped,harness-testsjob without secretsThe per-repository files
repo.mjs(new):Debug.xcconfig.Debug.template.xcconfigstays readable.Release.xcconfigis deliberately not listed: it is tracked withreplace.meplaceholders despite its.gitignoreentry, so it stays reviewable.https://. The xcconfig stores it without the scheme andAppDelegateprepends it, so android's scheme-required pattern would miss this repository's form.appl_…).review-guide.md: the rubric is kept, with four edits:gh pr diff, "Diff againstorigin/develop") now point at the diff file the harness writes. The agent no longer hasghor a base ref.[weak self], stored cancellables,@MainActor/DB threading, AVAudioSession, the BookPlayerKit boundary. The shared prompt names no repository.Release.xcconfigwording now matches reality.[develop]) and the env-policy and local-run lines.Trust split: done, and what happens on merge
reviewerenvironment exists on this repo with deployment-branch policydevelop. It holdsANTHROPIC_API_KEYandREVIEW_RESOLVE_TOKEN, piped from SSM; the key is stored under/anthropic/github-reviewer-bookplayer-ios.develop's file has nopull_request_target, and this branch's has nopull_request. The new workflow's first live run is the first PR after the merge.mainstay unreviewed, as today. Addingmainwould make the first release PR fail its review check untilmaincarries this harness.ANTHROPIC_API_KEYandREVIEW_RESOLVE_TOKEN.pull_request_targetthey would receive the secrets.Verification
npm ci --ignore-scripts && node smoke.mjs && node --test test/on Node 20: the SDK loads, the native CLI runs, 247/247 tests pass.repo.mjs: each of 6 deliberate breaks turns the suite red. The breaks were the scheme-required android DSN pattern, a non-global regex, a keeps line that matches a DSN, droppingappl, raising the key length past the example, and an empty secret-file list.Debug.xcconfig, without printing values: the DSN and RevenueCat key are redacted, and the file is refused by Bash and Read.🤖 Generated with Claude Code