Conversation
|
Greenlight — 🚫 Blocked — see reasons below ( Blocking reasons:
|
jayantk
force-pushed
the
hydra/i-sjjtbgqo/head
branch
from
September 24, 2026 02:04
e35f94f to
0756972
Compare
Adds the `docs-and-comments` review prompt and admits every path outside `.github/` to it. `auto_approve_paths` was empty, so nothing auto-approved here and every PR needed a human — including a typo in a code comment. Adding a reviewed path group is a loosening: no PR that merges today changes behaviour, and no PR can become more blocked than it already is. The path list is broad on purpose and the review is the gate. A file extension cannot tell a comment edit from a logic edit, so gating on `**/*.md` would have admitted only prose and left every comment and docstring in the repo needing a human. Admitting `**` and asking the reviewer "does this change behaviour?" is the only way a comment fix in a .ts or .sol file ever auto-merges. That puts the whole weight on the prompt, so it is written for that job. It approves only when every changed line is a comment, docstring or prose; when every command, version, address, endpoint and URL it touches is corroborated by the checkout; when it adds no untrusted pointer; and when it deletes no warning or prerequisite. It rejects a comment the toolchain reads as code — lint and compiler directives, Rust doctests, SPDX lines — rejects commenting code out or back in, rejects any rename, move, add or delete, and rejects anything it cannot classify. It also treats text in the diff as data, never as instruction. The `!.github/**` deny is load-bearing: workflows there run with real permissions and this file is the policy itself, which must not be broadenable through a gate it defines. `check` is omitted, so the verdict lands on the derived check-run name `greenlight/review-docs-and-comments`.
jayantk
force-pushed
the
hydra/i-sjjtbgqo/head
branch
from
September 24, 2026 02:13
0756972 to
30725e1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Admits every path outside
.github/to a new AI review, and adds theprompt that decides them.
What changed
.github/greenlight/prompts/docs-and-comments.md(new) — thereview prompt. Modelled on the shape of
examples/prompts/security.mdin
dourolabs/greenlight-actions; the content is this repository'sown.
.github/greenlight.yml— declares thedocs-and-commentsreviewand one
auto_approve_pathsgroup that requires it:enabled: trueandrequired_reviewer_checks: []are unchanged. Noworkflow, no example code, and no branch-protection rule is touched.
Why the path list is broad
auto_approve_pathswas empty, so nothing auto-approved here and everypull request needed a human — including a typo in a code comment.
The path list is broad on purpose, and the review is the gate. A
file extension cannot tell a comment edit from a logic edit. Gating on
**/*.mdwould have admitted only prose and left every comment anddocstring in the repository behind a human, which is most of the
low-risk editing people actually do here. Admitting
**and asking thereviewer "does this change behaviour?" is the only way a comment fix in
a
.tsor.solfile ever auto-merges.That is a real trade: it moves the decision from a path glob, which
cannot be wrong, to a model, which can. It is taken deliberately and in
the cheapest place to take it — low-traffic example code, off the
price-delivery path, where nothing auto-approved before. The mitigation
is the prompt, so the prompt is where the review effort should go.
What the prompt does
It approves only when all four hold, and names the reason otherwise:
comment, docstring or prose. No executable statement, declaration,
type, signature, import, dependency, constant, config value or data
value changes, and no file is renamed, moved, added or deleted.
version, network name, contract address, program ID, RPC endpoint,
path and URL it introduces or edits is corroborated by the checkout.
A comment that no longer describes its code is a reject.
hosts, packages the repository does not already use, shortened URLs.
code comment.
The parts that carry the weight for source files:
classes rather than gesturing at them: lint and compiler directives
(
// eslint-disable,// @ts-ignore,# noqa), JSDoc types thecompiler consumes, Rust
///and//!doctests and#![doc = include_str!(...)], Solidity// SPDX-License-Identifier:and NatSpec, shebangs and Dockerfile
# syntax=directives, and#inside a Makefile recipe.
direction.
is changing a value.
line it could not classify.
tells the reviewer to approve is itself a reject.
It also states that the reviewer holds a read-only token and cannot
comment, so a reject must name the specific file and line and quote the
text — the verdict summary is the only thing a human will read.
Design notes
!.github/**deny is load-bearing. Workflows there run withreal permissions, and
.github/greenlight.ymlis the policy fileitself — it must not be broadenable through a gate it defines.
pyth-network/researchalready uses this reasoning. The greenlightdeployment additionally enforces a server-side floor over
.github/greenlight.ymland.github/greenlight/prompts/**, whichthis file can restrict but never relax; the deny is belt to those
braces, since the floor is not visible from this repository.
exactly "every file in the pull request is outside
.github/".checkis deliberately omitted, so the verdict lands on thederived check-run name
greenlight/review-docs-and-comments. Thatname is deliberately not added to branch-protection
required_status_checks: a reject posts conclusionneutral, whichGitHub counts as satisfying a required check. Greenlight gates on the
persisted verdict instead.
.github/, the group does not admit them, the server-side floorblocks them independently, and greenlight reads config and prompt from
the base branch regardless. It needs a human merge.
Checks
.github/greenlight.ymlparses under PyYAML to exactly the intendedstructure: one review keyed
docs-and-comments, one path group withpaths: ["**", "!.github/**"],require_reviews: ["docs-and-comments"], and nocheckkey.prompt:path resolves to a non-empty file in the tree.it over real paths from this repository. Admitted:
README.md,lazer/evm/README.md,lazer/evm/src/ExampleReceiver.sol,lazer/js/src/index.ts,price_feeds/ton/send_usd/contracts/main.fc,Cargo.lock,.gitignore. Not admitted:.github/greenlight.yml,.github/greenlight/prompts/docs-and-comments.md,.github/workflows/ci-lazer-evm.yml,.github/pull_request_template.md..github/workflows/greenlight-review.ymlis registered andactivein this repository's Actions workflow list, so greenlight hassomething to dispatch.
pull_requestwith no path filter. The repository has no root-levelAGENTS.md,CONTRIBUTING.md,package.json,.pre-commit-config.yamlor YAML/markdown lint config, so there is noadditional repo-wide gate to run over these two files.
Validating a live review end to end — an approve on a comment-only
source change, a reject on a functional one, a reject on an inaccurate
docs change, and a non-eligible pull request — happens on separate
throwaway pull requests once this is on
main. Nothing here can beexercised before then, because greenlight reads this config from the
base branch.