Skip to content

fix(ce-code-review): cover adversarial after quota or auth no-review - #1380

Merged
tmchow merged 6 commits into
mainfrom
tmchow/debug-issue-1343
Aug 15, 2026
Merged

fix(ce-code-review): cover adversarial after quota or auth no-review#1380
tmchow merged 6 commits into
mainfrom
tmchow/debug-issue-1343

Conversation

@tmchow

@tmchow tmchow commented Aug 14, 2026

Copy link
Copy Markdown
Collaborator

When a cross-model peer starts and then dies on session quota or execution-context auth, the adversarial lens is no longer treated as covered. Fold-in announces the next eligible different-family peer, or runs the local reviewer if none remains.

An explicit user-named recipient still fails clearly instead of switching providers. A plain 429 rate limit stays a same-route retry.

The worker now emits peer skip class: so fold-in does not have to guess from free text.

Fixes #1343

Related: #1344

Validation

Focused suites tests/skills/ce-code-review-cross-model-routes.test.ts and tests/review-skill-contract.test.ts: 127 passed.

Security Disclosure

No security-relevant changes. Skip-class state is a log token only. No new persistence, credentials, or payload handling.

Agent Disclosure

  • Model: Grok Build · grok-4.6

Compound Engineering

A started peer that dies on session quota or execution-context auth
no longer keeps exclusive ownership of the adversarial lens. Fold-in
announces the next eligible peer or restores the local reviewer.
@cursor

cursor Bot commented Aug 14, 2026

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes adversarial review orchestration and fold-in routing when peers fail, but rules are explicit and capped (one replacement, no silent provider hopping on explicit user choice).

Overview
When a cross-model adversarial peer starts but exits without a fold-in artifact because of session quota or execution-context auth, fold-in no longer treats the adversarial lens as satisfied.

The worker now logs a structured peer skip class: token (session_quota, execution_context_auth, transient_rate_limit, other) so orchestration does not infer failure mode from free text. Skill and reference docs define a did-not-run fallback: retry one alternate attested-different peer (unless the user explicitly named the failed recipient), then run in-process adversarial-reviewer; plain 429 rate limits stay on the existing same-route retry path.

Contract and route tests lock in the new log token, fallback rules, and classification behavior.

Reviewed by Cursor Bugbot for commit 9773f83. Bugbot is set up for automated code reviews on this repo. Configure here.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f32b82a9f0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/ce-code-review/scripts/cross-model-adversarial-review.sh Outdated
Comment thread skills/ce-code-review/references/cross-model-review.md
Comment thread skills/ce-code-review/references/cross-model-review.md
Comment thread skills/ce-code-review/scripts/cross-model-adversarial-review.sh Outdated
- Classify bare HTTP 401/Unauthorized as execution-context auth
- Treat weekly/Opus/hit-your-* limits as session quota
- Wait and fold the one replacement peer; if it also dies, go local

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9773f83a67

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/ce-code-review/scripts/cross-model-adversarial-review.sh Outdated
Comment thread skills/ce-code-review/scripts/cross-model-adversarial-review.sh Outdated
Comment thread skills/ce-code-review/scripts/cross-model-adversarial-review.sh Outdated
- Keep "hit your rate limit" as transient_rate_limit
- Match 401 Unauthorized, not every "unauthorized" mention

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 876e22b12c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread skills/ce-code-review/references/cross-model-review.md Outdated
tmchow added 2 commits August 14, 2026 17:09
Drop the keyword skip-class matcher. The worker still prints bounded
skip evidence; fold-in judges quota vs auth vs rate limit from that
text and keeps the did-not-run fallback.
A throttle no longer leaves the adversarial lens uncovered: retry the
already disclosed route once, then restore the local reviewer.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 71e9614. Configure here.

Comment thread skills/ce-code-review/references/cross-model-review.md
- Allow late in-process adversarial restore after a failed same-route rate-limit retry
- Keep 429 out of the quota/auth did-not-run fallback so it does not switch recipients
@tmchow
tmchow merged commit 9154a7c into main Aug 15, 2026
5 checks passed
@github-actions github-actions Bot mentioned this pull request Aug 15, 2026
ethras added a commit to ethras/compound-engineering-orca that referenced this pull request Aug 16, 2026
* fix(ce-commit-push-pr): root PR stacks on the parent PR the user named (EveryInc#1365)

* fix(ce-babysit-pr): decode gh output as UTF-8 on Windows (EveryInc#1368)

* fix(ce-prototype): cover decisions settled by seeing, not just driving (EveryInc#1369)

* perf(tests): cut suite wall time by splitting the largest test file (EveryInc#1370)

* fix(tests): stop the cross-model routes test reading the working tree (EveryInc#1371)

* fix(ce-doc-review): ask only where a real choice exists, batch the rest (EveryInc#1373)

* chore(orca): re-pin upstream provenance baseline to 421a337

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ce-doc-review): align Orca ownership wording with Apply routing

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(ce-prototype): add a seeing-mode craft floor and durable storage (EveryInc#1374)

* fix(ce-pov): stop the panel guessing the cross-model host argument (EveryInc#1375)

* chore(cross-model): pin the Grok peer to 4.6 (EveryInc#1376)

* docs(skills): rewrite user skill pages for accuracy and clearer use (EveryInc#1377)

* fix(commit): append known plan unit ids to commit subjects (EveryInc#1379)

* fix(ce-work): stop sandboxed workers committing in linked worktrees (EveryInc#1382)

* fix(ce-doc-review): edit HTML plans in native format (EveryInc#1381)

* fix(ce-code-review): cover adversarial after quota or auth no-review (EveryInc#1380)

* fix(skills): correct a rejected dispatch instead of spending the fallback (EveryInc#1383)

* fix(ce-compound): find Claude sessions started outside the repo root (EveryInc#1378)

* ci(windows-native): retry peer-job-runner smoke on ctypes flake (EveryInc#1384)

* fix(ce-debug): stop asking at the handoff, stop shipping unoffered work (EveryInc#1385)

* docs(solutions): record why skill gates state conditions, not git commands (EveryInc#1386)

* fix(skills): drop the residual-findings record file for real sinks (EveryInc#1387)

* fix(ce-doc-review): run the cross-model pass when CROSS_MODEL_PEERS is unset (EveryInc#1389)

* fix(ce-proof): sync with current Proof v3 contract (EveryInc#1390)

* fix(skill-authoring): make goal-first the default when authoring and reviewing skills (EveryInc#1391)

* fix(cross-model): let reviews run on Fable and pin model/effort from CE config (EveryInc#1392)

* docs(cross-model): point superseded peer benchmarks at the luna/xhigh decision (EveryInc#1393)

* fix(cross-model): discover the Codex.app-bundled codex CLI and name the peer-CLI requirement (EveryInc#1395)

* feat(cross-model): add cross_model_review_mode checkout egress gate (EveryInc#1396)

* fix(ce-compound-refresh): compare knowledge-track learnings against guidance they name (EveryInc#1399)

* docs(solutions): capture the named-guidance contradiction-check learning (EveryInc#1400)

* fix(ce-compound): prefer the repo's own frontmatter vocabulary over the Rails-era enums (EveryInc#1394)

* fix(ce-work): stop asking about branches before starting work (EveryInc#1397)

* fix(review): answer covered cases on skill prose with the condition, not a patch (EveryInc#1401)

* fix(scratch): fall back to $TMPDIR when /tmp cannot host the scratch root (EveryInc#1398)

* feat(ce-skill-work): repo-local skill for authoring, editing, reviewing, and responding to review on skills (EveryInc#1402)

* fix(ce-pov): reject non-final peer positions instead of folding them in (EveryInc#1403)

* feat(manifest): add Agent Plugins v1.0.0 manifest support (EveryInc#1345)

* chore: release main (EveryInc#1354)

* fix(ce-work): run cross-model verification on warm checkouts (EveryInc#1404)

* fix(orca): reconcile upstream skill contracts

* fix(orca): preserve additive Codex session roots

---------

Co-authored-by: Trevin Chow <trevin@trevinchow.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ce-code-review: detect exhausted peer routes before review payload egress

1 participant