From 249c4b3dbd8dcfa17df4acedb3b0ff524111bdb7 Mon Sep 17 00:00:00 2001 From: Sunny Kolattukudy Date: Tue, 15 Sep 2026 17:03:54 -0400 Subject: [PATCH 1/3] fix(ci): use real GitHub MCP review tool names in claude-review mcp__github__pull_request_review_write does not exist in the GitHub MCP server pinned by claude-code-action v1.0.213, so the agent never had a working path to a formal review. Also enable show_full_output to surface the remaining Bash gh permission denials. Refs #464 Co-Authored-By: Claude Fable 5.1 --- .github/workflows/claude-review.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index 61cf6a9..2e65b6e 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -72,6 +72,8 @@ jobs: bot_name: github-actions[bot] allowed_bots: 'imagile-bot' track_progress: true + # Diagnostic: print the agent transcript so permission denials are visible. + show_full_output: true classify_inline_comments: 'true' include_fix_links: 'true' plugin_marketplaces: | @@ -116,7 +118,7 @@ jobs: Do not leave a PR without a formal APPROVE or REQUEST_CHANGES state. claude_args: | - --model sonnet --allowedTools "mcp__github__pull_request_review_write,mcp__github__add_comment_to_pending_review,mcp__github__add_issue_comment,mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr review:*),Bash(gh api repos/*/issues/*/comments:*),Bash(gh api repos/*/issues/comments/*:*),Bash(gh api repos/*/pulls/*/reviews:*),Bash(gh api repos/*/pulls/*/comments:*)" + --model sonnet --allowedTools "mcp__github__get_issue_comments,mcp__github__get_pull_request_reviews,mcp__github__get_pull_request_diff,mcp__github__create_and_submit_pull_request_review,mcp__github__create_pending_pull_request_review,mcp__github__add_comment_to_pending_review,mcp__github__submit_pending_pull_request_review,mcp__github__add_issue_comment,mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr review:*),Bash(gh api repos/*/issues/*/comments:*),Bash(gh api repos/*/issues/comments/*:*),Bash(gh api repos/*/pulls/*/reviews:*),Bash(gh api repos/*/pulls/*/comments:*)" # Reviews from the default GITHUB_TOKEN raise no workflow events, so the # feedback loop must be kicked explicitly (see header). Deterministic step From be90eed9cf24545773bff4ab22e25d99e6adc9d4 Mon Sep 17 00:00:00 2001 From: Sunny Kolattukudy Date: Tue, 15 Sep 2026 17:10:00 -0400 Subject: [PATCH 2/3] fix(ci): make claude-review's gh api allow rules actually match Claude Code only treats the `:*` suffix as a wildcard on a literal prefix, so every rule with a mid-pattern `*` (gh api repos/*/issues/*/comments:*) silently matched nothing and the agent could never fetch, delete or dismiss its own stale feedback. Switch those rules to the trailing-space form, add the dismissals and graphql endpoints the cleanup steps need, and point the prompt at the MCP review tool that does exist. Closes #464 Co-Authored-By: Claude Fable 5.1 --- .github/workflows/claude-review.yml | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index 2e65b6e..9504ecc 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -72,8 +72,6 @@ jobs: bot_name: github-actions[bot] allowed_bots: 'imagile-bot' track_progress: true - # Diagnostic: print the agent transcript so permission denials are visible. - show_full_output: true classify_inline_comments: 'true' include_fix_links: 'true' plugin_marketplaces: | @@ -96,8 +94,11 @@ jobs: EXCEPTIONS — never delete: - the tracking comment for THIS run (the one you update via update_claude_comment) - any comment containing "claude-pr-feedback-round" (round-limit markers used by the feedback workflow) - 4. Dismiss any previous formal review from github-actions[bot] on this PR. - 5. Resolve any outdated inline review comment threads from previous reviews. + 4. Dismiss any previous formal review from github-actions[bot] on this PR. List them with: + gh api repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/reviews --jq '.[] | select(.user.login == "github-actions[bot]" and (.state == "APPROVED" or .state == "CHANGES_REQUESTED")) | .id' + and dismiss each with: + gh api repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/reviews//dismissals -X PUT -f message="Superseded by a newer automated review" + 5. Resolve any outdated inline review comment threads from previous reviews (use `gh api graphql` with the resolveReviewThread mutation). **Now review the pull request:** @@ -112,13 +113,23 @@ jobs: Leave inline comments on specific lines and a top-level summary. Skip nitpicks; prioritize substantive feedback. - **When you are done, submit a GitHub review using one of:** - - `gh pr review ${{ github.event.pull_request.number }} --approve --body "..."` — if no substantive issues found - - `gh pr review ${{ github.event.pull_request.number }} --request-changes --body "..."` — if there are blocking problems + **When you are done, submit a formal GitHub review.** Prefer the MCP tool + `mcp__github__create_and_submit_pull_request_review` (owner/repo/pullNumber from + the header above) with event `APPROVE` if no substantive issues were found, or + `REQUEST_CHANGES` if there are blocking problems. `gh pr review ${{ github.event.pull_request.number }} --approve|--request-changes --body "..."` + is the fallback if the MCP tool is unavailable. Do not leave a PR without a formal APPROVE or REQUEST_CHANGES state. + # Bash rule shapes matter here. Claude Code only treats `:*` as a + # wildcard on an otherwise-literal prefix: a `*` earlier in the rule + # combined with a `:*` suffix never matches anything (verified on + # 2.1.258/2.1.261 — every `gh api repos/...` call was denied with "This + # command requires approval" while `gh pr view:*` worked). Rules with a + # mid-pattern `*` must use the trailing-space form (`... *`) instead. + # The `gh api` rules stay scoped to issues/pulls endpoints so the + # token's `actions: write` scope is still unreachable from the agent. claude_args: | - --model sonnet --allowedTools "mcp__github__get_issue_comments,mcp__github__get_pull_request_reviews,mcp__github__get_pull_request_diff,mcp__github__create_and_submit_pull_request_review,mcp__github__create_pending_pull_request_review,mcp__github__add_comment_to_pending_review,mcp__github__submit_pending_pull_request_review,mcp__github__add_issue_comment,mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr review:*),Bash(gh api repos/*/issues/*/comments:*),Bash(gh api repos/*/issues/comments/*:*),Bash(gh api repos/*/pulls/*/reviews:*),Bash(gh api repos/*/pulls/*/comments:*)" + --model sonnet --allowedTools "mcp__github__get_issue_comments,mcp__github__get_pull_request_reviews,mcp__github__get_pull_request_diff,mcp__github__create_and_submit_pull_request_review,mcp__github__create_pending_pull_request_review,mcp__github__add_comment_to_pending_review,mcp__github__submit_pending_pull_request_review,mcp__github__add_issue_comment,mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr review:*),Bash(gh api graphql *),Bash(gh api repos/*/issues/*/comments *),Bash(gh api repos/*/issues/comments/* *),Bash(gh api repos/*/pulls/*/reviews *),Bash(gh api repos/*/pulls/*/reviews/*/dismissals *),Bash(gh api repos/*/pulls/*/comments *)" # Reviews from the default GITHUB_TOKEN raise no workflow events, so the # feedback loop must be kicked explicitly (see header). Deterministic step From 3114c8f8e9344f4d6c615b011080322c038ed69f Mon Sep 17 00:00:00 2001 From: Sunny Kolattukudy Date: Tue, 15 Sep 2026 17:16:14 -0400 Subject: [PATCH 3/3] fix(ci): mark inline-thread resolution best-effort in claude-review prompt The workflow token is refused on the resolveReviewThread mutation, so the step cannot be made reliable; stop the agent from reporting it as a failure. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/claude-review.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index 9504ecc..17de613 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -98,7 +98,7 @@ jobs: gh api repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/reviews --jq '.[] | select(.user.login == "github-actions[bot]" and (.state == "APPROVED" or .state == "CHANGES_REQUESTED")) | .id' and dismiss each with: gh api repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/reviews//dismissals -X PUT -f message="Superseded by a newer automated review" - 5. Resolve any outdated inline review comment threads from previous reviews (use `gh api graphql` with the resolveReviewThread mutation). + 5. Best effort only: try to resolve outdated inline review comment threads from previous reviews with `gh api graphql` (resolveReviewThread mutation). The workflow token is often refused on that mutation; if it fails, move on without reporting it as a problem. **Now review the pull request:**