Skip to content

ci: Add Codex review gate - #19

Draft
BenWestgate wants to merge 1 commit into
masterfrom
codex/codex-review-gate
Draft

BenWestgate wants to merge 1 commit into
masterfrom
codex/codex-review-gate

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • create a pending codex-review-gate check for each open, non-draft pull request to master
  • pass only on a clean Codex result that names the current head commit
  • fail when Codex posts inline review findings for the current head commit
  • leave quota-limited reviews pending and retry at most one pull request per hourly run
  • wait 90 minutes for the normal automatic review, then use a 5.5-hour retry cooldown

The repository already requires branches to be up to date with master. This workflow deliberately relies on that rule instead of implementing a second base-branch race and retry state machine.

Human-review status

The code is ready for human review. This PR is intentionally left draft only to avoid triggering another automatic Codex review while the bootstrap ruleset is circular.

Live Protect master ruleset 23646498 has no bypass actors and currently requires both Codex review coordinator and codex-review-gate. Before merge, temporarily remove both Codex required contexts. After the maintainer reviews/signs/merges this workflow, add back only codex-review-gate. Requiring the coordinator job name as a second status is redundant.

The remaining automated-review suggestions are deliberately deferred rather than expanded into this bootstrap PR: no privileged comment override is added, branch-to-branch PRs remain out of scope, and stale prototype check runs on non-master PRs are historical only.

Validation

  • current head 55b4c8e is one focused commit on current master after ci: Restrict legacy master workflow permissions #58
  • the PR changes only .github/workflows/codex-review-gate.yml (296 added lines)
  • the exact current workflow parses successfully as YAML
  • git diff --check passes against current master

Because this workflow does not exist on master yet, GitHub cannot execute the new pull_request_target workflow from this PR head. Earlier prototype runs therefore are not claimed as validation of this exact 296-line file; the current workflow still needs the maintainer’s code review before bootstrap/merge.

The legacy Python package / Pylint Python 3.13 failures are outside this diff: they fail while installing master’s existing requirements.txt, which still contains bip32. The release line removes that Python wallet dependency in #7; this PR intentionally does not mix that work into the review gate.

The previous 23-commit prototype was replaced by this single focused commit. No additional Codex review requests were made while preparing this refresh.

Human scope approval: the maintainer approved the master target and requested the simplified design. AI tools assisted implementation and validation. The single commit remains for the maintainer to review and sign before merge.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ee2e413df7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml
Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate
BenWestgate force-pushed the codex/codex-review-gate branch from ee2e413 to 2439bcd Compare September 21, 2026 21:01
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2439bcdd5e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate
BenWestgate force-pushed the codex/codex-review-gate branch from 2439bcd to 5404b10 Compare September 21, 2026 21:09
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5404b105c1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

2 similar comments
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d6c989d9c3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

1 similar comment
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 11f88afda5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e817eb867b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

1 similar comment
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

Reviewed commit: 384c4306d1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1c7028a9bf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7623312411

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bcf7909a8f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 83422eb993

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml
Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4df67b7a84

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 69d33664b3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a4ad381b02

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 689cee6d6f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d498af5cf5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/codex-review-gate.yml Outdated
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@BenWestgate BenWestgate reopened this Sep 22, 2026
@BenWestgate
BenWestgate marked this pull request as draft September 22, 2026 00:39
@BenWestgate BenWestgate added the area: ci Continuous integration and workflow configuration. label Sep 24, 2026
@BenWestgate
BenWestgate force-pushed the codex/codex-review-gate branch from 02c4a65 to 1341256 Compare September 25, 2026 15:40

Copy link
Copy Markdown
Owner Author

Bootstrap check: the current Protect master ruleset already requires both Codex review coordinator and codex-review-gate, while this PR is the change that first installs the workflow on master. With no bypass actor, that is circular and will prevent this PR from satisfying its own merge requirements.

Before merging #19, temporarily remove those Codex-required checks from the master ruleset. After the maintainer reviews/signs/merges this PR, add only codex-review-gate back as the required Codex status, matching this PR's Bootstrap section. Requiring the workflow job name as a second gate is redundant and makes the configuration more brittle.

The current PR itself is otherwise in the intended simplified state: one 296-line workflow, one focused commit, all inline review threads resolved. Its Python 3.13 failure is the pre-existing legacy-master dependency failure, not caused by this workflow diff.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

Needs discussion (draft, 1341256).

  • No override: any inline Codex finding on the head fails the gate, and only a new push resets it. Once the check is required, a false-positive P2 blocks merge. Consider an OWNER-only override comment, or failing only on P0/P1.
  • Scope: it only covers PRs into master. Almost all open work targets reviewability-v1/gui-reference-v1, so it gates little until those land.
  • Stale runs: #10, #11, #12 and #16 carry codex-review-gate check runs stuck in_progress from an earlier prototype. Close them before making the check required anywhere.
  • pull_request_target is safe here: no checkout of PR code, and token scopes are minimal.
  • The red build (3.13) is master's own failure, not this PR's.

Keep a commit-scoped required check pending until managed Codex posts a clean result or review findings for the pull request head. Leave quota-limited reviews pending and retry at most one pull request per hourly run after a cooldown.

Rely on the existing strict up-to-date branch rule instead of duplicating base-branch race handling in the workflow. This keeps the coordinator small enough to audit and avoids duplicate review requests on every push.

Validation: YAML parse, embedded JavaScript syntax, and git diff --check.
@BenWestgate
BenWestgate force-pushed the codex/codex-review-gate branch from 1341256 to 55b4c8e Compare September 28, 2026 00:45
@BenWestgate

Copy link
Copy Markdown
Owner Author

Release-gate disposition of the remaining Claude notes:

  • No override: intentionally deferred. The maintainer asked for the simple gate and explicitly asked us to stop review churn. An OWNER-only override adds another privileged state transition, parser, and audit path to a workflow whose job is only to require a current-head Codex result. If a real false-positive problem appears, override semantics can be designed separately from this bootstrap PR.
  • Scope: intentionally master only. This is a merge gate for the protected release branch; branch-to-branch development/reviewability PRs are deliberately outside this workflow.
  • Stale prototype runs: not a blocker. They are historical check runs on non-master-target PRs and are not required by the master ruleset; deleting/recreating history would not improve the installed gate.
  • pull_request_target: accepted as safe for this workflow because it never checks out or executes PR code and has explicit minimal permissions.

The live Protect master ruleset (23646498) is the only bootstrap blocker: it has no bypass actors and currently requires both Codex review coordinator and codex-review-gate. Before merging #19, temporarily remove both Codex contexts; after the maintainer reviews/signs/merges #19, require only codex-review-gate. The PR stays draft meanwhile so marking it ready does not trigger another automatic Codex review.

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review, posted at the maintainer's request.

ACK 55b4c8e. The remaining bootstrap ruleset change is an explicit human pre/post-merge step, not a code blocker.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci Continuous integration and workflow configuration.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant