Comfy-Org / Comfy-Org/github-workflows
cursor-review: label-scoped concurrency lets a veto race an in-flight panel; workflows_ref duplicates the uses: SHA by hand
- 主要言語
- Shell
- スター
- 6
- フォーク
- 1
- 平均マージ
- 14時間 4分
- マージ済み PR(30日)
- 98
説明
Two findings from the Cursor panel reviewing a thin caller (comfy-typescript-sdk#111), both properties of the shared pattern rather than of any one caller, so filing here where the fix can land once.
## 1. The documented caller concurrency group can't cancel across labels
The recommended caller sets:
```yaml
group: cursor-review-pr-${{ github.event.pull_request.number }}-${{ github.event.label.name }}
```
The label in the group is load-bearing (this workflow fires on every `labeled`/`unlabeled` event, and a shared per-PR group with `cancel-in-progress: true` would let ANY label add kill an in-flight panel). But it also means the two events that interact — `labeled: cursor-review` and the veto/unblock label — land in different groups and never cancel each other: applying `skip-cursor-review` while a panel is mid-flight runs a Gate that vetoes nothing already running, and toggling both within a panel's runtime can land two full reviews (the head-SHA dedupe is check-then-act, evaluated before either posts). Since the Gate owns the label semantics, the clean fix is probably Gate-side: on a veto event, cancel the PR's in-flight review runs via the API rather than relying on group collision.
## 2. `workflows_ref` is a hand-maintained duplicate of the `uses:` SHA
Every caller pins the reusable workflow by SHA and must copy the same SHA into `workflows_ref` so prompts/scripts load from the same commit — enforced only by a comment. A bump that updates one and not the other silently runs the workflow definition from one commit and its scripts from another. Options: default `workflows_ref` to the workflow's own ref where resolvable, or add a startup assertion that the two match and fail loudly.
Raised by: gpt-5.6-sol-max + claude-opus-5-thinking-max + kimi-k3-high panel legs on the caller PR.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
コントリビューションガイド
調査の方向性
共有の Gate エントリポイントと、workflows_ref に対する再利用可能な workflow の処理から始めます。ラベル付きイベントとラベルなしイベントがどのように並行性グループを形成するか、また呼び出し元が uses: と workflows_ref をどのように対応付けるかを追跡します。完了条件は、拒否によって進行中の PR レビューがキャンセルされ、SHA のドリフトが検出または排除され、イベント間の競合と ref の不一致の両方がカバーされることです。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- github-actions
- 領域
- ci-cd, devops
- issue の種類
- バグ
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 35/100