Skip to content

ci(docs): add a manual document review bridge - #1609

Merged
chaofengw-nv merged 1 commit into
NVIDIA:mainfrom
chaofengw-nv:ci/llm-doc-check
Oct 8, 2026
Merged

chaofengw-nv merged 1 commit into
NVIDIA:mainfrom
chaofengw-nv:ci/llm-doc-check

Conversation

@chaofengw-nv

Copy link
Copy Markdown
Collaborator

Background

Maintainers need an optional documentation review entry point without introducing private dependencies or inference credentials into public CI.

Exit Criteria

  • A maintainer can manually request review of README, Quick Start, and Build from Source at one immutable main commit.
  • Source CI remains metadata-only; credentials, SDK execution, and reports stay in the companion protected CI environment.
  • Existing merge gates and GitHub Pages behavior are unchanged.

Implementation

Add a main-only manual dispatch workflow using the existing protected ci-dispatch environment, maintainer authorization, and exact source revision. Add contributor instructions and a regression test for the trust boundary. Source documents are data, never credential-bearing executable code.

Change categories

  • CI or developer tooling

Validation

Commands and Results

  • PYTHONPATH=core/builder:apps/benchmark:. PYTHONDONTWRITEBYTECODE=1 python -m pytest tools/tests/test_architecture.py tools/tests/test_family_impact.py tools/tests/test_community_ci.py tools/tests/test_public_source_hygiene.py tools/tests/test_new_ci.py tools/tests/test_pr_metadata.py -q -p no:cacheprovider: 299 passed.
  • ruff check tools/tests/test_community_ci.py: passed.
  • Actionlint 1.7.12 validation of .github/workflows/doc-check.yml: passed.
  • python tools/legal_headers.py --check: passed, zero findings.
  • python -m tools.model_ci validate: passed.
  • npm --prefix website run test:model-support: passed.
  • npm --prefix website run build: passed after installing the unchanged lockfile-pinned dependencies with scripts disabled; 34 diagrams verified and the static site generated.
  • git diff --cached --check: passed before the DCO-signed commit.

Hardware, Environment, and Revisions

Source head: a3c2d20ee1f019d119cb702d5076730d1eb0fa9d, based on 9b083a7fdac56f9d0f14084e61e2aa9dc0dc8816. Local Linux CPU checks, Python 3.12, Node 22.23.2. No GPU, CUDA, TensorRT, model, or dataset qualification is claimed. Website dependency revisions remain those in the existing lockfile.

Not Run / Remaining Gaps

The new manual workflow is not yet available on main. Complete Source-to-private dispatch and private runner/service reachability remain unqualified until the companion workflow and this PR merge, followed by an actual manual run. Current-head premerge is not claimed as passed.

Contributor Self-Review

  • I have completed a self-review of this change.

Reviewed the staged diff, authorization, immutable revision handling, private evidence boundary, and regression results. Existing test criteria were not weakened.

Notes For Future Readers

Merge the companion protected workflow before this public entry point. A successful dispatch is not a completed documentation review. Findings are advisory and require human review; setup or service errors fail the private job. Reports are never published to Pages, and no required checks are added.

Risk level

  • Medium

This adds a credentialed cross-repository dispatch path. Main-only execution, maintainer authorization, a protected environment, and no contributor checkout limit exposure; live dispatch still needs qualification.

Provide a maintainer-only entry point for advisory documentation review at an immutable main revision. Reuse the protected dispatch environment and keep the SDK, inference credentials, and review reports in private CI without changing merge gates.

Signed-off-by: chaofengw <chaofengw@nvidia.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/TensorRT-Model-Connect/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: bdb596ff-043d-447a-b727-8e3648b847cd
📥 Commits

Reviewing files that changed from the base of the PR and between 9b083a7 and a3c2d20.

📒 Files selected for processing (4)
  • .github/documentation-check.md
  • .github/workflows/doc-check.yml
  • CONTRIBUTING.md
  • tools/tests/test_community_ci.py

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

⚠️ A high-level summary could not be generated for this review. CodeRabbit will regenerate it on the next update, or you can request a refresh with @coderabbitai summary.

Walkthrough

Adds a manually triggered GitHub Actions workflow that checks maintainer authorization and source SHA before dispatching the SHA to private CI. Adds documentation about the advisory review and its privacy boundaries, plus a test for the workflow configuration.

Changes

Advisory Documentation Review

Layer / File(s) Summary
Manual dispatch bridge
.github/workflows/doc-check.yml, .github/documentation-check.md, CONTRIBUTING.md, tools/tests/test_community_ci.py
The workflow checks the repository, branch, actor role, credentials, and source SHA before dispatching to private CI. The documentation describes the review scope, private results, and its non-gating status. The test checks the workflow trigger, permissions, conditions, and source-level exclusions.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  actor Maintainer
  participant DocumentationCheck as Documentation Check workflow
  participant PrivateCI as Private CI workflow
  Maintainer->>DocumentationCheck: Manually dispatch on main
  DocumentationCheck->>DocumentationCheck: Check repository, role, credentials, and source SHA
  DocumentationCheck->>PrivateCI: Dispatch validated source SHA on main
  PrivateCI-->>DocumentationCheck: Results remain in private CI
Loading

Merge Risk: ⚪ Minimal · up to a3c2d

The advisory review bridge has no identified merge-blocking issue. Its private CI integration still needs an end-to-end manual run after rollout.

🚥 Pre-merge checks | ✅ 8 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (3 skipped: 3 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (8 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: adding a manual documentation review bridge in CI.
Description check ✅ Passed The description covers the required background, exit criteria, implementation, change category, validation, environment, remaining gaps, self-review, rollout notes, and risk. It also clearly states im…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Family Ownership Boundary ✅ Passed PASS — The pull request changes only documentation, a manual workflow, contributor guidance, and a CI test. The workflow dispatches a documentation review for an immutable commit and does not import, …
Shared Semantic Neutrality ✅ Passed PASS — The changed shared surfaces are model-agnostic. The new workflow only authorizes a maintainer, validates a commit SHA, and dispatches a documentation review request; it does not configure model…
Benchmark Validation Integrity ✅ Passed PASS: The pull request adds a manual documentation-review dispatch, contributor guidance, and a metadata-only workflow test. The changed documentation explicitly excludes performance review and states…
Shared Change Blast Radius ✅ Passed The change is project-wide documentation and CI infrastructure, not family-local behavior. The description identifies the model-agnostic need: review the shared README, Quick Start, and Build from Sou…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (3 skipped: 3 unsupported.)

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@chaofengw-nv
chaofengw-nv marked this pull request as ready for review October 8, 2026 08:42
@chaofengw-nv chaofengw-nv added the run-internal-ci Maintainer-approved dispatch to internal CI label Oct 8, 2026
@github-actions github-actions Bot removed the run-internal-ci Maintainer-approved dispatch to internal CI label Oct 8, 2026
@chaofengw-nv
chaofengw-nv merged commit 48765e7 into NVIDIA:main Oct 8, 2026
56 of 65 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant