Skip to content

chore(ci): run PR Hygiene's engine from master - #1099

Merged
shumkov merged 1 commit into
devfrom
chore/pr-hygiene-engine-from-master
Oct 2, 2026
Merged

shumkov merged 1 commit into
devfrom
chore/pr-hygiene-engine-from-master

Conversation

@shumkov

@shumkov shumkov commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

What

This repo's PR Hygiene caller now runs the shared engine from master of dashpay/stale_prs_are_bad instead of a pinned commit:

- uses: dashpay/stale_prs_are_bad/.github/workflows/pr-review-reusable.yml@3b987722c37e91755785c031abb3f98fb08ea763
+ uses: dashpay/stale_prs_are_bad/.github/workflows/pr-review-reusable.yml@master

Why

With a pinned commit, every engine fix needs a re-pin PR here before it takes effect. The engine fixes merged this week (review bots that open PRs, "your part" per area, branch patterns) haven't reached this repo yet. Meanwhile the review policy is already read live from that same master, so pinned engines and the live policy can drift apart.

Security trade-off (please review)

Naming a branch instead of a SHA means engine upgrades are reviewed in dashpay/stale_prs_are_bad, not here. The controls there:

  • protect-master: changes need a pull request with code-owner review and the required test/check CI. Force-push and deletion are blocked.
  • no-tag-shadows-master: a master tag is forbidden, with no bypass. GitHub would resolve a tag before the branch.
  • The reusable workflow's bootstrap still refuses any commit not merged to that master (feat: a caller may run the engine from master stale_prs_are_bad#73).

Verified in a real run: dashpay/grovedb run 36953611829, caller on @master, succeeded.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated the pull request review workflow to use the shared workflow’s current version. The change affects the review process; no end-user features or interface changes are included.

PR Hygiene · 80bf2d2

  • Bots — coderabbitai ✓
  • Self-review — post /self-reviewed
  • Within your 5 open PRs
  • Build green
  • Approvals
    • github (.github/workflows/pr-review-policy.yml) — ktechmidas

When every box is checked the PR Hygiene check passes and this can merge.

The caller pinned the shared engine to one commit, so every engine fix
needed a re-pin here before it took effect. The engine is now named by
`master` of dashpay/stale_prs_are_bad — the protected branch the review
policy is already read from — and the reusable workflow still requires
the commit it runs to be merged there (dashpay/stale_prs_are_bad#73).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: dashpay/rust-dashcore/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: ba938a0e-53fb-4cf2-bd56-cb5e567ab368

📥 Commits

Reviewing files that changed from the base of the PR and between aa90a98 and 80bf2d2.

📒 Files selected for processing (1)
  • .github/workflows/pr-review-policy.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The PR review policy workflow now references the reusable workflow from the master branch instead of a pinned commit.

Changes

PR review policy workflow

Layer / File(s) Summary
Update reusable workflow reference
.github/workflows/pr-review-policy.yml
The policy job now uses the reusable workflow reference from master instead of the specified commit SHA.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 80bf2

No actionable issue was established with the workflow change; it is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 80bf2

The change permits automatic upstream engine updates without changing this repository’s declared permissions. No exploit is confirmed, but the upstream branch and tag protections that now govern workflow selection have not been independently verified.

Retained concerns

  • Low · security · inferred: Replacing the immutable engine reference with master makes upstream ref governance responsible for selecting privileged workflow code. The claimed protection against tag shadowing remains unverified, so the effectiveness of this new control boundary is unresolved rather than a confirmed vulnerability.
Security review details

Security Blast Radius

  • inferred — An unauthorized engine revision could potentially act on this repository’s pull requests, issues, and statuses within the permissions granted to the job. The supplied evidence does not establish organization-wide authority, production credentials, or additional downstream privileges.

Security Findings and Attack Paths

  • inferred — The deferred attack hypothesis requires unauthorized control of upstream workflow selection, such as permission to create a shadowing master tag if effective protections allow it. That could select unintended privileged workflow code. Ordinary PR or comment input alone is not shown to provide this authority, and exploit reachability remains unknown.

Trust Boundaries and Controls

  • observed — The PR reports code-owner review and required checks for upstream master, blocked force-push and deletion, a no-bypass prohibition on master tags, and bootstrap rejection of commits not merged to master. These are asserted controls, not independently verified configurations. The reported successful run supports operability, not resistance to unauthorized ref selection.

Resilience and Maintainability Implications

  • inferred — The caller delegates reconciliation to the external engine. Its unchanged declarations cannot establish validation before privileged effects or ownership, atomicity, cleanup, and recovery guarantees across interrupted, repeated, concurrent, or cross-revision runs. These remain coverage gaps, not demonstrated defects introduced by this PR.

Hardening Proposals

  • proposed — Verify effective upstream branch and tag rules, including bypass authority, and validation ordering before privileged actions. Preserve a known-good immutable reference for rollback; if these assurances cannot be maintained, retain SHA-based engine selection.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: updating CI to run the PR Hygiene engine from the master branch.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the waiting-bots Waiting for the review bots to report on this head label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bots are done — your move: post /self-reviewed.
Full checklist in the description.

@github-actions github-actions Bot added waiting-self-review Waiting for the author to post /self-reviewed and removed waiting-bots Waiting for the review bots to report on this head labels Oct 2, 2026
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.38%. Comparing base (aa90a98) to head (80bf2d2).

Additional details and impacted files
@@            Coverage Diff             @@
##              dev    #1099      +/-   ##
==========================================
- Coverage   77.39%   77.38%   -0.01%     
==========================================
  Files         320      320              
  Lines       81343    81343              
==========================================
- Hits        62956    62949       -7     
- Misses      18387    18394       +7     
Flag Coverage Δ
core 78.90% <ø> (ø)
ffi 50.77% <ø> (-0.01%) ⬇️
rpc 20.00% <ø> (ø)
spv 91.63% <ø> (-0.03%) ⬇️
wallet 80.22% <ø> (ø)
see 8 files with indirect coverage changes

@shumkov
shumkov merged commit bd02c9b into dev Oct 2, 2026
37 of 39 checks passed
@shumkov
shumkov deleted the chore/pr-hygiene-engine-from-master branch October 2, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

waiting-self-review Waiting for the author to post /self-reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant