gardener: Answer reviews on Gardener's pull requests (Gardener 0.1.10) - #188
Conversation
|
| task-source: ".gardener/tasks/pr-review-fix/TASK.md" | ||
| task-bundle-hash: 2e496b0e60cf0e1022d276ab65a0543c8b0c8c8a26f768337232bc938f2b4d66 | ||
| plan-timeout-minutes: 40 | ||
| checkout-ref: ${{ github.event.pull_request.head.sha }} |
There was a problem hiding this comment.
🔴 Queued review feedback gets stranded
When an earlier round pushes before a queued review starts, checkout-ref still points at the review event's old head. The queued round exits on the head check, leaving feedback posted after the earlier thread fetch unanswered.
Learn more
The job checks out the SHA stored in the review webhook, while the branch check compares that checkout against the current pull request head. Jobs for one pull request are serialized, so a running job can push a commit before a queued review job starts. The queued job then exits as stale even if the earlier job did not see the later review threads. GitHub-token pushes do not start another review run.
Example: Review A starts a job and fetches threads. Review B is submitted while A writes a fix; B's job queues with the old SHA. A pushes, then B starts, detects a different head, and exits without answering B.
Recommended fix: Checkout the current pull request head when the queued job begins, validate it is the guarded PR branch, and use that exact checkout SHA as expectedHeadSha. Preserve the stale-head refusal at commit time if another actor moves the branch.
Was this helpful? React with 👍 or 👎 to provide feedback.
| 3. **Read the unresolved review threads** with the provider API's GraphQL transport: the pull | ||
| request's `reviewThreads` (`isResolved`, `path`, `line`, and each thread's comments with author | ||
| and body). Answer every unresolved thread, not only those from the review that started this | ||
| run: a round can absorb a review whose own run GitHub dropped. |
There was a problem hiding this comment.
🟡 General review feedback goes unanswered
When a reviewer submits feedback only in the review body, reviewThreads contains none of it. The task has no review-body read, so it posts an empty round and never addresses that feedback.
Learn more
A submitted pull request review can contain a general body without any inline comments. GitHub's reviewThreads collection contains inline conversations, not that general review body. The task reads only threads after it counts rounds. It can therefore spend a round without evaluating the triggering review's feedback.
Example: A maintainer submits “Please update the migration docs” in the review body with no inline comments. reviewThreads is empty, so the task proposes a round reply but makes no change and does not discuss the request.
Recommended fix: Include the triggering review's body and any applicable review-level feedback in the findings the task verifies; distinguish reviewed feedback from unrelated text, and do not count a round without processing the review.
Was this helpful? React with 👍 or 👎 to provide feedback.
| tools: | ||
| - repository.list_files | ||
| - repository.read_file | ||
| - repository.exec |
There was a problem hiding this comment.
🟨 Unrestricted network access for review-triggered shell commands
A submitted review can trigger repository.exec with unrestricted network access despite no explicit user request. The task policy requires an explicit request and disclosure before granting that tool, exposing review runs to unintended network activity.
Was this helpful? React with 👍 or 👎 to provide feedback.
commit: |
Adds a
pr-review-fixtask, so Gardener answers reviews on the pull requests it opens. When a maintainer or Devin reviews one, Gardener checks each unresolved review thread against the code. It fixes the findings it can reproduce, with tests, and pushes one commit onto the pull request's branch. It declines the rest with a reason, then replies once. After three rounds it hands the pull request to a maintainer and stops.How the task is scoped:
devin-ai-integration[bot], and only on pull requests opened bygithub-actions[bot]whose branch starts withgardener/. The generated workflow skips reviews on any other pull request before a job starts..gardener/.This PR is the
gardener upgradeto 0.1.10, plus the new task:gardener:generatenow points at@scuffi/gardener@0.1.10..gardener/SKILL.mdis new: a guide to the task format for coding agents.mention-replyandtriageare unchanged, with the same bundle hashes.GitHub doesn't run checks on its own for commits made with a workflow's token, so a maintainer approves CI on Gardener's commits.
A review starts a run only once the pull request's merge ref includes this workflow. Pull requests opened before this merges, such as #185, need their branch updated first.
Tested on a demo repository first: