Remove or replace inherited Bunny Review workflows #2

Open
opened 2026-08-05 08:32:00 -04:00 by fidget · 0 comments
Owner

Problem

Guksu Motor currently carries an inherited Bunny Review stack that was built around Marinara Engine's GitHub infrastructure and cannot operate as a reliable Guksu/Forgejo review path.

Files on main:

  • .github/workflows/bunny-review-auto.yml
  • .github/workflows/bunny-review-command.yml
  • .github/workflows/bunny-review.yml
  • .github/bunny-review/bunny_review.py
  • .github/bunny-review/requirements.txt
  • .github/bunny-review/reviewer-prompt.md
  • .github/bunny-review/rules.json
  • .github/bunny-review/ci-checks.json

The workflows assume infrastructure and API behavior Guksu does not provide:

  • runs-on: ubuntu-latest rather than Guksu's self-hosted Forgejo runner labels
  • GitHub CLI commands such as gh workflow run, gh pr view, and gh api
  • secrets.GITHUB_TOKEN and GitHub-specific workflow permissions
  • GitHub check-runs/status endpoints and pull/<number>/head refs
  • Marinara-specific reviewer secrets/model configuration (OPENAI_API_KEY, LLM_BASE_URL, hard-coded gpt-5.5)
  • inherited expected CI check names and review rules

The live Forgejo Actions history reinforces this: among the 37 current runs, there is one cancelled bunny-review-auto.yml run and no bunny-review-command.yml or bunny-review.yml runs. The review chain is effectively dead infrastructure.

Impact

  • PR review automation appears available but cannot be relied upon.
  • Dead workflow and helper code add substantial inherited maintenance surface.
  • Bunny status checks or slash commands can mislead contributors and maintainers.
  • Trying to patch this piecemeal risks preserving GitHub-specific trust assumptions around write tokens and untrusted PR code.

Proposed resolution

Choose one deliberate path:

  1. Remove Bunny Review

    • Delete the three workflows and .github/bunny-review/ tooling.
    • Remove Bunny commands, status requirements, documentation, and regressions that assume it exists.
    • Keep review outside CI until a Guksu-owned replacement is ready.
  2. Replace it with a Guksu-owned alternative

    • Design for the live Forgejo instance and self-hosted runner from the start.
    • Use Forgejo-compatible dispatch, PR lookup, comments, and status APIs.
    • Use Guksu-owned secret/model configuration and Guksu's actual CI check names.
    • Preserve the trusted-base/untrusted-PR boundary: PR code must not receive write credentials or control reviewer tooling.

Do not treat this as a mechanical GitHub-to-Forgejo rename. The event model, API surface, runner environment, permissions, and trust boundary all need explicit validation.

Acceptance criteria

  • No shipped workflow depends on Marinara-owned review infrastructure.
  • No review job requests unavailable ubuntu-latest capacity.
  • No stale Bunny command, required status, documentation, or helper files remain if removal is chosen.
  • If replaced, PR-open/update and manual-review paths are exercised against the live Forgejo repository.
  • The replacement uses Guksu-owned runner labels, API paths, secrets, model configuration, and CI check names.
  • Untrusted PR code cannot access write credentials or modify the trusted reviewer implementation before execution.
  • A real test PR produces an auditable review result/status on Forgejo.
## Problem Guksu Motor currently carries an inherited Bunny Review stack that was built around Marinara Engine's GitHub infrastructure and cannot operate as a reliable Guksu/Forgejo review path. Files on `main`: - `.github/workflows/bunny-review-auto.yml` - `.github/workflows/bunny-review-command.yml` - `.github/workflows/bunny-review.yml` - `.github/bunny-review/bunny_review.py` - `.github/bunny-review/requirements.txt` - `.github/bunny-review/reviewer-prompt.md` - `.github/bunny-review/rules.json` - `.github/bunny-review/ci-checks.json` The workflows assume infrastructure and API behavior Guksu does not provide: - `runs-on: ubuntu-latest` rather than Guksu's self-hosted Forgejo runner labels - GitHub CLI commands such as `gh workflow run`, `gh pr view`, and `gh api` - `secrets.GITHUB_TOKEN` and GitHub-specific workflow permissions - GitHub check-runs/status endpoints and `pull/<number>/head` refs - Marinara-specific reviewer secrets/model configuration (`OPENAI_API_KEY`, `LLM_BASE_URL`, hard-coded `gpt-5.5`) - inherited expected CI check names and review rules The live Forgejo Actions history reinforces this: among the 37 current runs, there is one cancelled `bunny-review-auto.yml` run and no `bunny-review-command.yml` or `bunny-review.yml` runs. The review chain is effectively dead infrastructure. ## Impact - PR review automation appears available but cannot be relied upon. - Dead workflow and helper code add substantial inherited maintenance surface. - Bunny status checks or slash commands can mislead contributors and maintainers. - Trying to patch this piecemeal risks preserving GitHub-specific trust assumptions around write tokens and untrusted PR code. ## Proposed resolution Choose one deliberate path: 1. **Remove Bunny Review** - Delete the three workflows and `.github/bunny-review/` tooling. - Remove Bunny commands, status requirements, documentation, and regressions that assume it exists. - Keep review outside CI until a Guksu-owned replacement is ready. 2. **Replace it with a Guksu-owned alternative** - Design for the live Forgejo instance and self-hosted runner from the start. - Use Forgejo-compatible dispatch, PR lookup, comments, and status APIs. - Use Guksu-owned secret/model configuration and Guksu's actual CI check names. - Preserve the trusted-base/untrusted-PR boundary: PR code must not receive write credentials or control reviewer tooling. Do not treat this as a mechanical GitHub-to-Forgejo rename. The event model, API surface, runner environment, permissions, and trust boundary all need explicit validation. ## Acceptance criteria - [ ] No shipped workflow depends on Marinara-owned review infrastructure. - [ ] No review job requests unavailable `ubuntu-latest` capacity. - [ ] No stale Bunny command, required status, documentation, or helper files remain if removal is chosen. - [ ] If replaced, PR-open/update and manual-review paths are exercised against the live Forgejo repository. - [ ] The replacement uses Guksu-owned runner labels, API paths, secrets, model configuration, and CI check names. - [ ] Untrusted PR code cannot access write credentials or modify the trusted reviewer implementation before execution. - [ ] A real test PR produces an auditable review result/status on Forgejo.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
fidget/Guksu-Motor#2
No description provided.