Skip to content

cursor-review: label-scoped concurrency lets a veto race an in-flight panel; workflows_ref duplicates the uses: SHA by hand #251

Description

@mattmillerai

Two findings from the Cursor panel reviewing a thin caller (comfy-typescript-sdk#111), both properties of the shared pattern rather than of any one caller, so filing here where the fix can land once.

1. The documented caller concurrency group can't cancel across labels

The recommended caller sets:

group: cursor-review-pr-${{ github.event.pull_request.number }}-${{ github.event.label.name }}

The label in the group is load-bearing (this workflow fires on every labeled/unlabeled event, and a shared per-PR group with cancel-in-progress: true would let ANY label add kill an in-flight panel). But it also means the two events that interact — labeled: cursor-review and the veto/unblock label — land in different groups and never cancel each other: applying skip-cursor-review while a panel is mid-flight runs a Gate that vetoes nothing already running, and toggling both within a panel's runtime can land two full reviews (the head-SHA dedupe is check-then-act, evaluated before either posts). Since the Gate owns the label semantics, the clean fix is probably Gate-side: on a veto event, cancel the PR's in-flight review runs via the API rather than relying on group collision.

2. workflows_ref is a hand-maintained duplicate of the uses: SHA

Every caller pins the reusable workflow by SHA and must copy the same SHA into workflows_ref so prompts/scripts load from the same commit — enforced only by a comment. A bump that updates one and not the other silently runs the workflow definition from one commit and its scripts from another. Options: default workflows_ref to the workflow's own ref where resolvable, or add a startup assertion that the two match and fail loudly.

Raised by: gpt-5.6-sol-max + claude-opus-5-thinking-max + kimi-k3-high panel legs on the caller PR.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions