Repository navigation
Migrate Kimi-K3 AgentX recipe benchmark placement for srt-slurm v2.43.4 / 迁移 Kimi-K3 AgentX 配置的 benchmark placement 以适配 srt-slurm v2.43.4 #12187
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CODEOWNER Sign-off Verify | |
| on: | |
| issue_comment: | |
| types: [created, edited] | |
| pull_request_review: | |
| types: [submitted, edited] | |
| pull_request_review_comment: | |
| types: [created, edited] | |
| workflow_dispatch: | |
| inputs: | |
| pr-number: | |
| description: PR number | |
| required: true | |
| type: number | |
| comment_url: | |
| description: >- | |
| URL of the sign-off comment/review to verify, e.g. | |
| https://github.com/OWNER/REPO/pull/123#issuecomment-456 (also accepts | |
| #pullrequestreview-<id> and #discussion_r<id> review URLs). | |
| required: true | |
| type: string | |
| permissions: | |
| contents: read | |
| jobs: | |
| verify: | |
| name: Check sign-off | |
| if: | | |
| github.event_name == 'workflow_dispatch' || | |
| (github.event_name == 'issue_comment' && github.event.issue.pull_request && | |
| contains(github.event.comment.body || '', 'As a PR reviewer and CODEOWNER')) || | |
| (github.event_name == 'pull_request_review' && | |
| contains(github.event.review.body || '', 'As a PR reviewer and CODEOWNER')) || | |
| (github.event_name == 'pull_request_review_comment' && | |
| contains(github.event.comment.body || '', 'As a PR reviewer and CODEOWNER')) | |
| runs-on: ubuntu-latest | |
| concurrency: | |
| group: codeowner-signoff-pr-${{ github.event.pull_request.number || github.event.issue.number || inputs.pr-number }} | |
| cancel-in-progress: false | |
| # The verifier agent reads untrusted PR content, so this job's token is read-only. | |
| # The separate publish job holds the write permissions. | |
| permissions: | |
| contents: read | |
| pull-requests: read # Read PR metadata, diff, and review comments. | |
| issues: read # Read PR conversation comments. | |
| actions: read # Read workflow runs and artifacts. | |
| checks: read # Read check-runs on PR commits. | |
| outputs: | |
| proceed: ${{ steps.resolve.outputs.proceed }} | |
| pr-number: ${{ steps.scope.outputs.pr-number }} | |
| head-sha: ${{ steps.scope.outputs.head-sha }} | |
| signoff-key: ${{ steps.resolve.outputs.signoff-key }} | |
| verification-succeeded: ${{ steps.outcome.outputs.succeeded }} | |
| steps: | |
| - name: Checkout trusted workflow code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| ref: ${{ github.event.repository.default_branch }} | |
| persist-credentials: false | |
| - name: Select Python project | |
| run: | | |
| python_project="$GITHUB_WORKSPACE" | |
| if [[ -f "$python_project/inferencex-e2e/pyproject.toml" ]]; then | |
| python_project="$python_project/inferencex-e2e" | |
| fi | |
| test -f "$python_project/pyproject.toml" | |
| echo "INFERENCEX_PYTHON_PROJECT=$python_project" >> "$GITHUB_ENV" | |
| - name: Set up uv | |
| uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| cache-dependency-glob: | | |
| pyproject.toml | |
| uv.lock | |
| inferencex-e2e/pyproject.toml | |
| inferencex-e2e/uv.lock | |
| - name: Check changed-file ownership | |
| id: scope | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: uv run --project "$INFERENCEX_PYTHON_PROJECT" --locked --extra workflows python -m infx.workflows.signoff_scope | |
| - name: Resolve PR state and sign-off metadata | |
| id: resolve | |
| if: steps.scope.outputs.required == 'true' | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| SCOPED_HEAD_SHA: ${{ steps.scope.outputs.head-sha }} | |
| run: uv run --project "$INFERENCEX_PYTHON_PROJECT" --locked --extra workflows python -m infx.workflows.signoff_resolve | |
| - name: Render verifier prompt | |
| if: steps.resolve.outputs.proceed == 'true' | |
| env: | |
| REPO: ${{ github.repository }} | |
| PR_NUMBER: ${{ steps.scope.outputs.pr-number }} | |
| HEAD_SHA: ${{ steps.scope.outputs.head-sha }} | |
| SIGNOFF_AUTHOR: ${{ steps.resolve.outputs.signoff-author }} | |
| SIGNOFF_KIND: ${{ steps.resolve.outputs.signoff-kind }} | |
| SIGNOFF_FETCH_CMD: ${{ steps.resolve.outputs.signoff-fetch-cmd }} | |
| run: | | |
| # These placeholders must remain literal for envsubst. | |
| # shellcheck disable=SC2016 | |
| envsubst '${REPO} ${PR_NUMBER} ${HEAD_SHA} ${SIGNOFF_AUTHOR} ${SIGNOFF_KIND} ${SIGNOFF_FETCH_CMD}' \ | |
| < .github/codeowner-signoff-verify-prompt.md \ | |
| > /tmp/codeowner-signoff-verify-prompt.md | |
| grep -q "PR #${PR_NUMBER}" /tmp/codeowner-signoff-verify-prompt.md | |
| wc -c /tmp/codeowner-signoff-verify-prompt.md | |
| - name: Install Claude Code 2.1.282 | |
| id: claude_cli | |
| if: steps.resolve.outputs.proceed == 'true' | |
| run: | # zizmor: ignore[adhoc-packages] Claude CLI and its native packages are pinned to 2.1.282 | |
| npm install --prefix "$RUNNER_TEMP/claude-code" --no-audit --no-fund @anthropic-ai/claude-code@2.1.282 | |
| claude_cli="$RUNNER_TEMP/claude-code/node_modules/.bin/claude" | |
| test "$("$claude_cli" --version)" = "2.1.282 (Claude Code)" | |
| echo "path=$claude_cli" >> "$GITHUB_OUTPUT" | |
| - name: Verify sign-off with Claude | |
| id: claude | |
| if: steps.resolve.outputs.proceed == 'true' | |
| uses: anthropics/claude-code-action@9171db3e57d6a3140a37ddc2ba92788584e0ead6 # v1.0.234 | |
| env: | |
| # Read-only job token: the agent reads untrusted PR content and never publishes. | |
| GH_TOKEN: ${{ github.token }} | |
| GITHUB_TOKEN: ${{ github.token }} | |
| BASH_DEFAULT_TIMEOUT_MS: "1800000" | |
| BASH_MAX_TIMEOUT_MS: "3600000" | |
| with: | |
| # Repository verifier credential; trusted code checks writer authorization before this step. | |
| anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} # zizmor: ignore[secrets-outside-env] | |
| github_token: ${{ github.token }} | |
| path_to_claude_code_executable: ${{ steps.claude_cli.outputs.path }} | |
| track_progress: false | |
| allowed_bots: '' | |
| additional_permissions: | | |
| actions: read | |
| settings: | | |
| {"fastMode": true} | |
| # Bash is limited to the read-only commands the verifier prompt uses. | |
| # /proc is denied so file tools cannot read credentials from process environments. | |
| claude_args: | | |
| --model 'claude-opus-5-5' | |
| --mcp-config '{"mcpServers": {"fetch": {"command": "npx", "args": ["-y", "@anthropic-ai/mcp-server-fetch@latest"]}}}' | |
| --allowedTools "Read,Write,Glob,Grep,WebFetch,mcp__github_ci__*,mcp__fetch__*,Bash(gh pr view:*),Bash(gh pr diff:*),Bash(gh api:*),Bash(gh run view:*),Bash(gh run list:*),Bash(gh run download:*),Bash(git log:*),Bash(git show:*),Bash(uv run --project inferencex-e2e --locked python -m infx.workflows.pareto_coverage:*)" | |
| --disallowedTools "Read(//proc/**),Write(//proc/**)" | |
| prompt: | | |
| Read the file /tmp/codeowner-signoff-verify-prompt.md and follow the | |
| instructions in it exactly — it is your complete task specification, | |
| already rendered with this run's PR number, head SHA, and sign-off | |
| metadata. | |
| # The publisher reads the verdict only when verification succeeded, so success | |
| # here guarantees an uploaded verdict artifact for the publish job. | |
| - name: Record verification outcome | |
| id: outcome | |
| if: always() && steps.resolve.outputs.proceed == 'true' | |
| env: | |
| CLAUDE_SUCCEEDED: ${{ steps.claude.outcome == 'success' }} | |
| VERDICT_PATH: /tmp/codeowner-signoff-verdict.md | |
| run: | | |
| succeeded=false | |
| if [[ "$CLAUDE_SUCCEEDED" == true && -f "$VERDICT_PATH" ]]; then | |
| succeeded=true | |
| fi | |
| echo "succeeded=$succeeded" >> "$GITHUB_OUTPUT" | |
| - name: Upload verdict | |
| if: always() && steps.outcome.outputs.succeeded == 'true' | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: codeowner-signoff-verdict | |
| path: /tmp/codeowner-signoff-verdict.md | |
| if-no-files-found: error | |
| retention-days: 7 | |
| publish: | |
| name: Publish sign-off verdict | |
| needs: verify | |
| if: always() && needs.verify.outputs.proceed == 'true' | |
| runs-on: ubuntu-latest | |
| concurrency: | |
| group: codeowner-signoff-publish-pr-${{ needs.verify.outputs.pr-number }} | |
| cancel-in-progress: false | |
| permissions: | |
| contents: read | |
| pull-requests: write # Publish PR feedback. | |
| issues: write # Post a new verdict comment. | |
| steps: | |
| - name: Checkout trusted workflow code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.repository.default_branch }} | |
| persist-credentials: false | |
| - name: Select Python project | |
| run: | | |
| python_project="$GITHUB_WORKSPACE" | |
| if [[ -f "$python_project/inferencex-e2e/pyproject.toml" ]]; then | |
| python_project="$python_project/inferencex-e2e" | |
| fi | |
| test -f "$python_project/pyproject.toml" | |
| echo "INFERENCEX_PYTHON_PROJECT=$python_project" >> "$GITHUB_ENV" | |
| - name: Set up uv | |
| uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| cache-dependency-glob: | | |
| pyproject.toml | |
| uv.lock | |
| inferencex-e2e/pyproject.toml | |
| inferencex-e2e/uv.lock | |
| # Any download failure fails this job rather than posting a false rejection. | |
| - name: Download verdict | |
| if: needs.verify.outputs.verification-succeeded == 'true' | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: codeowner-signoff-verdict | |
| path: /tmp | |
| - name: Post verdict comment | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| HEAD_SHA: ${{ needs.verify.outputs.head-sha }} | |
| PR_NUMBER: ${{ needs.verify.outputs.pr-number }} | |
| SIGNOFF_KEY: ${{ needs.verify.outputs.signoff-key }} | |
| VERIFICATION_SUCCEEDED: ${{ needs.verify.outputs.verification-succeeded == 'true' }} | |
| VERDICT_PATH: /tmp/codeowner-signoff-verdict.md | |
| run: uv run --project "$INFERENCEX_PYTHON_PROJECT" --locked --extra workflows python -m infx.workflows.signoff_publish |