Skip to content

A Claude review that posted nothing no longer finishes green — main half of the #3650 pair (cherry-pick of c39de4c8) - #3662

Closed
erikdarlingdata wants to merge 1 commit into
mainfrom
fix/3650-main
Closed

erikdarlingdata wants to merge 1 commit into
mainfrom
fix/3650-main

Conversation

@erikdarlingdata

Copy link
Copy Markdown
Owner

The main half of landing #3650's workflow fix on both branches together, so the guard's drift arm (which hard-fails every non-editing PR while dev's claude-review.yml differs from main's) never opens a window.

This branch is cut from main and carries exactly one cherry-picked commit: c39de4c from fix/3650-lane, the same commit PR #3657 delivers to dev. One file, .github/workflows/claude-review.yml, byte-identical content on both halves.

Replaces #3656, which pointed the dev-cut lane branch at main and therefore carried 69 unreleased commits — merging it would have been an accidental release. Closed with a comment saying so.

Sequencing: merge this and #3657 together (either order, minimal gap) — the drift window exists only while the two branches' copies differ. Closes nothing by keyword; #3650 is closed by hand when both halves are in.

…ly tools end the denial churn, the job fails when no verdict was submitted, and the transcript survives the runner (#3650)

The prompt told the reviewer the branch was checked out and asked for a correctness,
parity and security review, while --allowedTools permitted only four gh verbs and the
inline-comment tool. Every Read, Grep, Glob and git call was a permission denial; the
swallowed runs' result blocks read 50 turns / 18 denials, 39 / 21, 18 / 17, each ending
subtype=success with nothing posted. Three PRs, about thirteen paid runs in one night.

- --allowedTools gains Read, Grep, Glob, Bash(git diff:*), Bash(git log:*), Bash(git show:*).
  Nothing that writes.
- A step after the action fails the job when claude[bot] submitted no non-empty-bodied
  review since the run's own start stamp, and prints the transcript's result block. A
  refusal-to-run (this file differing from the default branch's copy) is named separately.
- claude-execution-output.json is uploaded as the claude-review-transcript artifact, 7 days.

Lands on main and dev together: claude-code-action refuses to run whenever this file
differs from the default branch's copy, so a dev-only edit would disable review on every PR
until the next release.
@erikdarlingdata

Copy link
Copy Markdown
Owner Author

Closing per maintainer's call: no PRs target main. #3650's workflow fix rides #3657 (dev) alone and reaches main at the next dev→main release sync.

auto-merge was automatically disabled September 18, 2026 23:25

Pull request was closed

@erikdarlingdata
erikdarlingdata deleted the fix/3650-main branch September 18, 2026 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant