From b9accf60b20dc08df6553d006e19d7631e08e290 Mon Sep 17 00:00:00 2001 From: bdchatham Date: Thu, 1 Oct 2026 10:02:06 -0700 Subject: [PATCH 1/2] ci: review uci's own pull requests with seidroid, retire ai-review uci reviewed its pull requests with the legacy ai-review workflow at v0.0.22, while every repository that calls seidroid-review moved to it. seidroid.yml calls seidroid-review.yml at v0.0.26, the same way sei-internal-skills does. The pin is a released commit, so a pull request that changes the review workflow is reviewed by the last release. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ai-review-self.yml | 27 --------- .github/workflows/seidroid.yml | 90 ++++++++++++++++++++++++++++ 2 files changed, 90 insertions(+), 27 deletions(-) delete mode 100644 .github/workflows/ai-review-self.yml create mode 100644 .github/workflows/seidroid.yml diff --git a/.github/workflows/ai-review-self.yml b/.github/workflows/ai-review-self.yml deleted file mode 100644 index 6004c1c..0000000 --- a/.github/workflows/ai-review-self.yml +++ /dev/null @@ -1,27 +0,0 @@ -name: AI Review -on: - pull_request: - types: [ opened, ready_for_review, synchronize, reopened ] - issue_comment: - types: [ created ] - pull_request_review_comment: - types: [ created ] - pull_request_review: - types: [ submitted ] -jobs: - ai-review: - if: github.event_name != 'issue_comment' || github.event.issue.pull_request != null - # See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22 - uses: sei-protocol/uci/.github/workflows/ai-review.yml@4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d - permissions: - contents: read - pull-requests: write - checks: write - id-token: write - secrets: inherit - with: - # See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22 - uci-ref: 4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d - allowed-team: 'sei-protocol/sei-core' - allowed-bots: '["dependabot[bot]"]' - enable-cursor: false # Disabled for now since there is a dedicated Bugbot flow built into Cursor currently enabled on repo. diff --git a/.github/workflows/seidroid.yml b/.github/workflows/seidroid.yml new file mode 100644 index 0000000..7e2de31 --- /dev/null +++ b/.github/workflows/seidroid.yml @@ -0,0 +1,90 @@ +# Wiring only. The review logic is this repository's seidroid-review.yml, called at a +# released commit so a pull request that changes it is reviewed by the last release, +# not by itself. The reviewer binary is sei-internal-skills' sei-agent-driver. +# +# @seidroid review review this pull request +# @seidroid review close destroy this pull request's session now +name: seidroid review + +on: + issue_comment: + types: [created] + pull_request: + types: [opened, ready_for_review, synchronize, reopened, closed] + +permissions: {} + +jobs: + # A run Dependabot triggers (opening or updating its pull request) gets + # Dependabot secrets only, so the review would fail on the missing machine + # credential; it is skipped. GitHub picks the secrets by who triggered the + # run, so a person's push, or `@seidroid review`, on a Dependabot pull request + # still reviews it. + seidroid-review: + if: >- + (github.event_name == 'pull_request' && + github.event.action != 'closed' && + github.actor != 'dependabot[bot]') || + (github.event_name == 'issue_comment' && + github.event.issue.pull_request != null && + contains(github.event.comment.body, '@seidroid review') && + !contains(github.event.comment.body, '@seidroid review close')) + uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6 # v0.0.26 + permissions: + contents: read + pull-requests: write + checks: write + issues: write + secrets: + OMNIGENT_MACHINE_CLIENT_SECRET: ${{ secrets.OMNIGENT_MACHINE_CLIENT_SECRET }} + SEIDROID_APP_ID: ${{ secrets.PLATFORM_CODE_AGENT_APP_ID }} + SEIDROID_APP_PRIVATE_KEY: ${{ secrets.PLATFORM_CODE_AGENT_APP_PK }} + with: + mode: review + approve-on-success: true + allowed-team: 'sei-protocol/sei-core' + + seidroid-review-close: + if: >- + github.event_name == 'issue_comment' && + github.event.issue.pull_request != null && + contains(github.event.comment.body, '@seidroid review close') + uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6 # v0.0.26 + permissions: + contents: read + pull-requests: write + checks: write + issues: write + secrets: + OMNIGENT_MACHINE_CLIENT_SECRET: ${{ secrets.OMNIGENT_MACHINE_CLIENT_SECRET }} + SEIDROID_APP_ID: ${{ secrets.PLATFORM_CODE_AGENT_APP_ID }} + SEIDROID_APP_PRIVATE_KEY: ${{ secrets.PLATFORM_CODE_AGENT_APP_PK }} + with: + mode: close + allowed-team: 'sei-protocol/sei-core' + + # Does not cover a fork: GitHub withholds secrets from a `pull_request` run whose + # head is a fork, so the close fails and the sandbox is left running. On a fork + # pull request, comment `@seidroid review close` before merging. + seidroid-review-reclaim: + # Skipped only when Dependabot itself closes the pull request (a superseded + # update), because that run lacks the secrets. When a person merges or + # closes it, the run has them and reclaims any session a manual review made. + # After a manual review, comment `@seidroid review close` if Dependabot may + # supersede the pull request, or that session stays open until its Pod expires. + if: >- + github.event_name == 'pull_request' && + github.event.action == 'closed' && + github.actor != 'dependabot[bot]' + uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6 # v0.0.26 + permissions: + contents: read + pull-requests: write + checks: write + issues: write + secrets: + OMNIGENT_MACHINE_CLIENT_SECRET: ${{ secrets.OMNIGENT_MACHINE_CLIENT_SECRET }} + SEIDROID_APP_ID: ${{ secrets.PLATFORM_CODE_AGENT_APP_ID }} + SEIDROID_APP_PRIVATE_KEY: ${{ secrets.PLATFORM_CODE_AGENT_APP_PK }} + with: + mode: close From 4211d740559e8084c97cfaef86664b7f48c53b75 Mon Sep 17 00:00:00 2001 From: bdchatham Date: Thu, 1 Oct 2026 10:35:02 -0700 Subject: [PATCH 2/2] ci: take review commands from review threads, anchor close, bump the assistant The caller now also listens for pull_request_review_comment and pull_request_review, as the retired ai-review caller did. The close job fires only on a comment that starts with the close command, so a review comment that quotes it later runs neither job. ai-assist.yml moves from v0.0.22 to v0.0.26, which no longer answers `@seidroid review close`. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ai-assist.yml | 8 +++---- .github/workflows/seidroid.yml | 42 +++++++++++++++++++-------------- 2 files changed, 28 insertions(+), 22 deletions(-) diff --git a/.github/workflows/ai-assist.yml b/.github/workflows/ai-assist.yml index 70082cf..624e5aa 100644 --- a/.github/workflows/ai-assist.yml +++ b/.github/workflows/ai-assist.yml @@ -8,8 +8,8 @@ on: types: [ submitted ] jobs: assistant: - # See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22 - uses: sei-protocol/uci/.github/workflows/ai-assistant.yml@4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d + # See: https://github.com/sei-protocol/uci/releases/tag/v0.0.26 + uses: sei-protocol/uci/.github/workflows/ai-assistant.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6 permissions: contents: read pull-requests: write @@ -17,6 +17,6 @@ jobs: id-token: write secrets: inherit with: - # See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22 - uci-ref: 4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d + # See: https://github.com/sei-protocol/uci/releases/tag/v0.0.26 + uci-ref: 0dc48cfb58b6c88f528b6def9784524d444ed0f6 allowed-team: 'sei-protocol/sei-core' diff --git a/.github/workflows/seidroid.yml b/.github/workflows/seidroid.yml index 7e2de31..b0fa620 100644 --- a/.github/workflows/seidroid.yml +++ b/.github/workflows/seidroid.yml @@ -9,26 +9,32 @@ name: seidroid review on: issue_comment: types: [created] + pull_request_review_comment: + types: [created] + pull_request_review: + types: [submitted] pull_request: types: [opened, ready_for_review, synchronize, reopened, closed] permissions: {} jobs: - # A run Dependabot triggers (opening or updating its pull request) gets - # Dependabot secrets only, so the review would fail on the missing machine - # credential; it is skipped. GitHub picks the secrets by who triggered the - # run, so a person's push, or `@seidroid review`, on a Dependabot pull request - # still reviews it. + # A run Dependabot triggers gets Dependabot's secrets only, so the review would fail + # on the missing machine credential; it is skipped. A person's push, or + # `@seidroid review`, on a Dependabot pull request still reviews it. seidroid-review: if: >- (github.event_name == 'pull_request' && github.event.action != 'closed' && github.actor != 'dependabot[bot]') || - (github.event_name == 'issue_comment' && - github.event.issue.pull_request != null && - contains(github.event.comment.body, '@seidroid review') && - !contains(github.event.comment.body, '@seidroid review close')) + (((github.event_name == 'issue_comment' && + github.event.issue.pull_request != null) || + github.event_name == 'pull_request_review_comment' || + github.event_name == 'pull_request_review') && + contains(github.event.comment.body || github.event.review.body, + '@seidroid review') && + !contains(github.event.comment.body || github.event.review.body, + '@seidroid review close')) uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6 # v0.0.26 permissions: contents: read @@ -44,11 +50,15 @@ jobs: approve-on-success: true allowed-team: 'sei-protocol/sei-core' + # Anchored, unlike the review job's `contains`: the reusable workflow does not + # re-derive the mode from the body, so a comment that starts with `@seidroid review` + # and quotes the close command later must not reach this destructive job. Such a + # comment runs neither job. seidroid-review-close: if: >- github.event_name == 'issue_comment' && github.event.issue.pull_request != null && - contains(github.event.comment.body, '@seidroid review close') + startsWith(github.event.comment.body, '@seidroid review close') uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6 # v0.0.26 permissions: contents: read @@ -63,15 +73,11 @@ jobs: mode: close allowed-team: 'sei-protocol/sei-core' - # Does not cover a fork: GitHub withholds secrets from a `pull_request` run whose - # head is a fork, so the close fails and the sandbox is left running. On a fork - # pull request, comment `@seidroid review close` before merging. + # Skipped when Dependabot closes its own pull request, because that run lacks the + # secrets. After a manual review of a Dependabot pull request, comment + # `@seidroid review close` if Dependabot may supersede it. A fork pull request gets + # no secrets either, so close it the same way before merging. seidroid-review-reclaim: - # Skipped only when Dependabot itself closes the pull request (a superseded - # update), because that run lacks the secrets. When a person merges or - # closes it, the run has them and reclaims any session a manual review made. - # After a manual review, comment `@seidroid review close` if Dependabot may - # supersede the pull request, or that session stays open until its Pod expires. if: >- github.event_name == 'pull_request' && github.event.action == 'closed' &&