Repository navigation
ci(docs): add a manual document review bridge - #1609
Conversation
Provide a maintainer-only entry point for advisory documentation review at an immutable main revision. Reuse the protected dispatch environment and keep the SDK, inference credentials, and review reports in private CI without changing merge gates. Signed-off-by: chaofengw <chaofengw@nvidia.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review. 📝 Walkthrough
WalkthroughAdds a manually triggered GitHub Actions workflow that checks maintainer authorization and source SHA before dispatching the SHA to private CI. Adds documentation about the advisory review and its privacy boundaries, plus a test for the workflow configuration. ChangesAdvisory Documentation Review
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
actor Maintainer
participant DocumentationCheck as Documentation Check workflow
participant PrivateCI as Private CI workflow
Maintainer->>DocumentationCheck: Manually dispatch on main
DocumentationCheck->>DocumentationCheck: Check repository, role, credentials, and source SHA
DocumentationCheck->>PrivateCI: Dispatch validated source SHA on main
PrivateCI-->>DocumentationCheck: Results remain in private CI
Merge Risk: ⚪ Minimal · up to The advisory review bridge has no identified merge-blocking issue. Its private CI integration still needs an end-to-end manual run after rollout. 🚥 Pre-merge checks | ✅ 8 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (8 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (3 skipped: 3 unsupported.)
Comment |
Background
Maintainers need an optional documentation review entry point without introducing private dependencies or inference credentials into public CI.
Exit Criteria
Implementation
Add a main-only manual dispatch workflow using the existing protected
ci-dispatchenvironment, maintainer authorization, and exact source revision. Add contributor instructions and a regression test for the trust boundary. Source documents are data, never credential-bearing executable code.Change categories
Validation
Commands and Results
PYTHONPATH=core/builder:apps/benchmark:. PYTHONDONTWRITEBYTECODE=1 python -m pytest tools/tests/test_architecture.py tools/tests/test_family_impact.py tools/tests/test_community_ci.py tools/tests/test_public_source_hygiene.py tools/tests/test_new_ci.py tools/tests/test_pr_metadata.py -q -p no:cacheprovider: 299 passed.ruff check tools/tests/test_community_ci.py: passed..github/workflows/doc-check.yml: passed.python tools/legal_headers.py --check: passed, zero findings.python -m tools.model_ci validate: passed.npm --prefix website run test:model-support: passed.npm --prefix website run build: passed after installing the unchanged lockfile-pinned dependencies with scripts disabled; 34 diagrams verified and the static site generated.git diff --cached --check: passed before the DCO-signed commit.Hardware, Environment, and Revisions
Source head:
a3c2d20ee1f019d119cb702d5076730d1eb0fa9d, based on9b083a7fdac56f9d0f14084e61e2aa9dc0dc8816. Local Linux CPU checks, Python 3.12, Node 22.23.2. No GPU, CUDA, TensorRT, model, or dataset qualification is claimed. Website dependency revisions remain those in the existing lockfile.Not Run / Remaining Gaps
The new manual workflow is not yet available on main. Complete Source-to-private dispatch and private runner/service reachability remain unqualified until the companion workflow and this PR merge, followed by an actual manual run. Current-head premerge is not claimed as passed.
Contributor Self-Review
Reviewed the staged diff, authorization, immutable revision handling, private evidence boundary, and regression results. Existing test criteria were not weakened.
Notes For Future Readers
Merge the companion protected workflow before this public entry point. A successful dispatch is not a completed documentation review. Findings are advisory and require human review; setup or service errors fail the private job. Reports are never published to Pages, and no required checks are added.
Risk level
This adds a credentialed cross-repository dispatch path. Main-only execution, maintainer authorization, a protected environment, and no contributor checkout limit exposure; live dispatch still needs qualification.