Establish a bounded review lifecycle for CLI runners
The CLI currently exposes a per-runner invocation timeout, but a GitHub review can execute multiple passes and retry failed runner calls. A caller that sets the per-call timeout can therefore still wait substantially longer than expected, and an external watchdog may terminate the process while the GitHub check remains in_progress.
Please document and/or standardize a bounded lifecycle contract for GitHub reviews:
- Keep
NEEDLEFISH_TIMEOUT_MS as the per-runner invocation timeout.
- Support
NEEDLEFISH_REVIEW_TIMEOUT_MS as an absolute deadline shared by all passes, retries, repair calls, and critic calls.
- When the deadline is exhausted, stop retries and return a deterministic operational failure.
- Ensure cancellation escalates from TERM to KILL and the CLI resolves even when a descendant keeps inherited pipes open.
- Provide a documented high-volume mode such as
NEEDLEFISH_NO_RETRY=1 for lanes where predictable completion is preferred over retry recovery.
- In GitHub mode, make timeout/termination failures update the existing Needlefish check to a terminal failure instead of leaving an in-progress check behind.
A reference deployment uses a 20-minute per-call limit, a longer absolute review deadline, no-retry for its high-volume lane, and a watchdog with termination grace. The contract should remain provider-neutral and work with CLIProxyAPI as well as other supported runners.
This issue intentionally omits repository names, PR numbers, internal endpoints, and credentials.
Establish a bounded review lifecycle for CLI runners
The CLI currently exposes a per-runner invocation timeout, but a GitHub review can execute multiple passes and retry failed runner calls. A caller that sets the per-call timeout can therefore still wait substantially longer than expected, and an external watchdog may terminate the process while the GitHub check remains
in_progress.Please document and/or standardize a bounded lifecycle contract for GitHub reviews:
NEEDLEFISH_TIMEOUT_MSas the per-runner invocation timeout.NEEDLEFISH_REVIEW_TIMEOUT_MSas an absolute deadline shared by all passes, retries, repair calls, and critic calls.NEEDLEFISH_NO_RETRY=1for lanes where predictable completion is preferred over retry recovery.A reference deployment uses a 20-minute per-call limit, a longer absolute review deadline, no-retry for its high-volume lane, and a watchdog with termination grace. The contract should remain provider-neutral and work with CLIProxyAPI as well as other supported runners.
This issue intentionally omits repository names, PR numbers, internal endpoints, and credentials.