open-swe/agent/tools/request_pr_review.py
Adam Moussa 0f0f616cd4
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
feat(open-swe): explicit-request reviewer verdicts + shell verdict guard (#214)
* feat(reviewer): explicit-request verdicts + shell verdict guard

Mention-triggered reviews that explicitly ask for a verdict now submit a
real APPROVE/REQUEST_CHANGES through publish_review; auto-reviews stay
advisory (COMMENT). Authorization is enforced in code: publish_review
honors a verdict only when the dispatching webhook set verdict_requested,
which only the explicit-mention path does.

- request_pr_review gains instructions (forwarded verbatim into an escaped
  requester_instructions data block) and request_verdict
- self-review guard downgrades verdicts on Open SWE-authored PRs; stale
  APPROVEs are best-effort dismissed when later findings land
- new PullRequestVerdictGuardMiddleware blocks gh pr review
  --approve/-a/--request-changes/-r, gh api, and curl verdict fallbacks on
  both the coding-agent and reviewer graphs
- shared escape helper moved to agent/utils/prompt_data.py

* fix(reviewer): harden verdict path against security-review findings

Adversarial security review (detector fan-out + proof-or-kill verifier)
of the verdict feature surfaced several verdict-integrity gaps; resolve
the confirmed ones:

- head-drift (high): a mid-run push moves the resolved head, so an APPROVE
  could anchor to an unreviewed commit. Downgrade any verdict to a comment
  when the resolved head differs from the reviewed head (verdict_ignored
  reason head_moved); the push's own re-review submits a fresh verdict.
- self-review fail-open: downgrade to comment when the PR author cannot be
  confirmed (author_unknown), and compare bot logins case-insensitively.
- verdict_submitted now reflects GitHub's returned review state, not just
  the event we asked for, so a coerced APPROVE isn't reported as submitted.
- an authorized verdict whose findings all anchor outside the diff now
  posts as a bodied review with zero inline comments instead of failing.
- add finding_reply to the shared data-block escape tag superset.
2026-07-20 15:28:00 -04:00

74 lines
2.6 KiB
Python

from typing import Any
from langgraph.config import get_config
from agent.utils.slack import GitHubPrRef, parse_github_pr_url
async def trigger_pr_review_from_ref(
pr_ref: GitHubPrRef,
*,
source: str,
github_login: str = "",
github_user_id: int | None = None,
slack_channel_id: str = "",
slack_thread_ts: str = "",
instructions: str = "",
request_verdict: bool = False,
) -> dict[str, Any]:
from agent.webhooks.github import trigger_pr_review_from_ref as _trigger_pr_review_from_ref
return await _trigger_pr_review_from_ref(
pr_ref,
source=source,
github_login=github_login,
github_user_id=github_user_id,
slack_channel_id=slack_channel_id,
slack_thread_ts=slack_thread_ts,
instructions=instructions,
request_verdict=request_verdict,
)
async def request_pr_review(
pr_url: str,
instructions: str = "",
request_verdict: bool = False,
) -> dict[str, Any]:
"""Start the reviewer agent for a GitHub pull request URL.
Args:
pr_url: The pull request URL, e.g.
``https://github.com/OWNER/REPO/pull/NUMBER``.
instructions: The requesting user's review instructions, passed
VERBATIM (do not paraphrase, summarize, or add your own). They may
set review focus, a merge bar, or verdict criteria for the
reviewer.
request_verdict: Set True ONLY when the user explicitly asked for a
review verdict (approve / request changes) in their own words.
Never infer it from tone or context. When True, the reviewer run
is authorized to submit a real GitHub APPROVE or REQUEST_CHANGES;
otherwise it publishes an advisory comment review. Never attempt
to approve or request changes yourself via ``gh pr review`` or the
GitHub API — that path is blocked.
"""
pr_ref = parse_github_pr_url(pr_url)
if not pr_ref:
return {
"success": False,
"error": "Expected a GitHub PR URL like https://github.com/OWNER/REPO/pull/NUMBER",
}
configurable = get_config().get("configurable", {})
source = configurable.get("source") or "agent"
slack_thread = configurable.get("slack_thread") or {}
return await trigger_pr_review_from_ref(
pr_ref,
source=source,
github_login=configurable.get("github_login", ""),
github_user_id=configurable.get("github_user_id"),
slack_channel_id=slack_thread.get("channel_id", ""),
slack_thread_ts=slack_thread.get("thread_ts", ""),
instructions=instructions,
request_verdict=request_verdict,
)