Skip to content

fix(claude-lanes): drop the repo-wide code-review queue - #651

Merged
kyle-sexton merged 2 commits into
mainfrom
ci/claude-review-no-repo-queue
Sep 28, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
ci/claude-review-no-repo-queue

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

No related issue: reviews on claude-code-plugins stalled behind a repo-wide queue (47 pending runs)

Summary

The code-review callers (components/claude-lanes/claude-review.yml, components/claude-lanes-hosted/claude-review.yml, and this repo's own .github/workflows/claude-review.yml) had a job-level concurrency group claude-review-${{ github.repository }} with queue: max. That runs every pull request's review one at a time across the whole repository. On claude-code-plugins, 47 reviews were pending behind one running review.

Fix

  • Remove the job-level queue block from all three code-review callers. The workflow-level per-PR group (cancel-in-progress: true) stays, so a newer push still supersedes an older review.
  • Update the security-caller notes and distribution/README.md, which described the code-review queue.
  • Remove the claude-lanes.test.sh control case that asserted synced lane callers need the actionlint queue suppression; no lane caller uses queue now. The suppression in .github/actionlint.yaml stays for other uses.

A usage limit (429) already fails fast in the ci-workflows reusable (continue-on-error, classified rate-limit), and the lane is advisory (github-iac ADR 0011), so parallel reviews contending for the seat produce a red advisory check, never a blocked merge. The security lane is unchanged: it never had a repo-wide queue.

Verification

  • actionlint .github/workflows/claude-review.yml passes.
  • claude-lanes.test.sh could not run cleanly in the local sandbox (56 failures on unmodified main, 55 with this change: the removed control assertion). CI is the check of record.

Related

  • Consumers pick this up through the sync PR that sync.yml opens on push to main.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LnQjBqtHLbX5UWPWggk7vg

The code-review callers carried a job-level concurrency group keyed on the
repository with `queue: max`, so every pull request's review ran one at a
time across the whole repository. On claude-code-plugins 47 reviews sat
pending behind a single running one.

Reviews now run in parallel. The workflow-level per-PR group still cancels
superseded runs. A usage limit (429) already fails fast in the reusable
workflow (continue-on-error, classified as rate-limit) and the lane is
advisory, so contention for the shared seat costs a red advisory check,
never a blocked merge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LnQjBqtHLbX5UWPWggk7vg
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T22:31:45.746686Z 5160624 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 39s —— View job


Security review (/review:security-review)

  • Gather context (PR diff via git diff origin/main...HEAD, read changed files)
  • Determine change scope and security-relevant surface
  • Apply skip gate / report result

Result: no security-relevant surface — skip gate applies, no findings.

This PR only removes the job-level concurrency: {group: claude-review-${{ github.repository }}, queue: max} block from the three code-review callers (.github/workflows/claude-review.yml, components/claude-lanes/claude-review.yml, components/claude-lanes-hosted/claude-review.yml), updates comments/docs describing that queue, and drops the now-obsolete claude-lanes.test.sh control case. Verified for each modified workflow:

  • permissions: blocks are unchanged (contents: read, pull-requests: write, id-token: write at the job level; contents: read at the workflow level).
  • on: triggers are unchanged (pull_request: [opened, synchronize, ready_for_review, reopened]) — no pull_request_target/workflow_run involved.
  • Secret handling is unchanged — still secrets: { CLAUDE_CODE_OAUTH_TOKEN: ... }, not secrets: inherit.
  • The reusable-workflow pin (ci-workflows/.github/workflows/claude-review.yml@35880dc...) is unchanged.
  • The remaining workflow-level concurrency group (${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}, cancel-in-progress: true) is untouched — it's per-PR, not repo-wide, and was already in place.

The only behavioral effect is that PR reviews across the repo/org no longer serialize behind a shared job-scoped queue; they now run concurrently (each still capped by its own per-PR cancel group). That's a scheduling/throughput change, not a trust-boundary, authz, or injection-surface change — a usage-limit (429) from seat contention already fails fast and advisory-only per the PR description. The distribution/README.md and inline-comment edits are documentation-only, matching the code change.

No CRITICAL / IMPORTANT / SUGGESTION findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5160624151

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread distribution/README.md
…site

No lane caller carries `concurrency.queue` now, so ci-runner's actionlint
config no longer needs the `queue` ignore for the hosted review caller.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LnQjBqtHLbX5UWPWggk7vg
@claude

claude Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Claude finished @kyle-sexton's task in 31s —— View job


Security review (/review:security-review)

  • Gather context (PR diff via git diff origin/main...HEAD, read changed files)
  • Determine change scope and security-relevant surface
  • Apply skip gate / report result

Result: no security-relevant surface — skip gate applies, no findings.

This is a re-run triggered by the new commit 6f49827, pushed after the prior security review on 5160624. That commit only removes obsolete documentation:

No code, permissions, triggers, or secret handling are touched by this commit — it's a prose/comment deletion addressing the earlier Codex review note that the queue-ignore prerequisite was now obsolete.

Combined with the rest of the PR (already reviewed at 5160624): removing the job-level concurrency: {group: claude-review-${{ github.repository }}, queue: max} block from the three code-review callers, plus the corresponding doc/test cleanup. Permissions, triggers, secret handling, and the reusable-workflow pin are all unchanged; the remaining per-PR cancel-in-progress concurrency group is untouched. This is a scheduling/throughput change, not a trust-boundary, authz, or injection-surface change.

No CRITICAL / IMPORTANT / SUGGESTION findings.

@kyle-sexton
kyle-sexton enabled auto-merge (squash) September 28, 2026 23:11
@kyle-sexton
kyle-sexton merged commit 6e469b1 into main Sep 28, 2026
49 of 50 checks passed
@kyle-sexton
kyle-sexton deleted the ci/claude-review-no-repo-queue branch September 28, 2026 23:11
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
No related issue: consistency follow-up to #651

## Summary

Every synced code-review caller and this repository's own
security-review caller skip draft pull requests. This repository's own
code-review caller did not.

## Fix

Add `if: github.event.pull_request.draft == false` to the `review` job
in `.github/workflows/claude-review.yml`, with the same comment the
components carry.

## Verification

- `actionlint .github/workflows/claude-review.yml` passes.
- With comments stripped, the caller now differs from
`components/claude-lanes/claude-review.yml` only in the documented
`runner` deviation.

## Related

- #651

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01LnQjBqtHLbX5UWPWggk7vg

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant