fix(strix): honor incomplete-retry log-only severity - #956
Conversation
A midstream NIM retry can print boxed Severity:/Vulnerabilities N TUI lines and then fail before writing a report artifact. The gate already calls those markers incomplete evidence, but the outer workflow grepped the full console tee and failed the required check. Honor that trusted verdict, classify GitHub Models 410 retirement brownout as backend unavailability, and keep accepted findings fail-closed.
|
Warning Review limit reached
Next review available in: 98 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Indented <<'PY' closers are valid after Actions strips run-block indent, but a raw bash -n of strix.yml treated the trusted-source resolver as an unclosed heredoc through EOF. Quote those three programs as python3 -c so the shell sees a closed string, and execute the extracted trusted-source, executable-hash, and Vertex credential snippets on real inputs.
|
@cwl-noema-review @opencode-agent Please review this exact current head ( Buyer-felt miss: required Strix failed closed after a midstream NIM retry left boxed Accepted findings without that gate verdict stay fail-closed. Reviewers remain |
Live router run 31672030631 queued Noema for #9560c253f0 and then failed OpenCode with HTTP 422: repository_dispatch allows 10 client_payload properties and the review-only flags made 14. Nest those flags under review_contract, bind the wrapper to that object, and leave the flat invocation-key claim unchanged.
The gate prints "failed after provider infrastructure or failure-signal output" after NVIDIA NIM exit 2. The outer regex only listed the sibling "emitted ..." wording, so required CI treated that line as a non-backend fail. Fold #957 into this neutralization.
|
@cwl-noema-review Please review this exact current head ( This head honors leftover-TUI incomplete-evidence verdicts, classifies GitHub Models |
|
@cwl-noema-review exact current head is |
Record that a mid-retry Severity TUI line cannot override the trusted incomplete-log-only verdict. Force the trusted-uv installer tests onto the linux x86_64 runner path and add the control-plane architecture diagram.
A mid-retry Severity: line plus the exact gate sentence failed after provider infrastructure still blocked neutralization. Include that sentence and the hyphenated incomplete-evidence token in the log-only override so leftover TUI is not treated as an accepted finding.
|
@cwl-noema-review exact current head |
|
@cwl-noema-review exact current head |
Materialize a base Python lock only when every package line is an exact SHA-256 pin or a two-token relative -r/--requirement include of a candidate lock path. A lone --require-hashes directive, ./dotted paths, and -r other-hashes.txt no longer enter the trusted build context.
|
@cwl-noema-review exact current head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
145d11e354fe5cc9d08dd247fc53f46c46d74f59. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Bandit (Python SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315948/job/94495743696)
- Close Empty PR/close-empty: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714313213/job/94494997613)
- CodeQL PR/Detect CodeQL languages: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315911/job/94495005968)
- Detect CodeQL languages check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315911/job/94495005968)
- Detect Python check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315948/job/94495005909)
- OSV-Scanner PR/osv-scan / osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714316295/job/94495007685)
- Python Security/Bandit (Python SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315948/job/94495743696)
- Python Security/Detect Python: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315948/job/94495005909)
- Python Security/pip-audit (Python dependency audit): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315948/job/94495743971)
- SAST Semgrep/Semgrep (multi-language SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315917/job/94495005865)
- SBOM Generation/generate-sbom: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315919/job/94495006275)
- Scorecard PR/Scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315878/job/94495005773)
- Scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315878/job/94495005773)
- Secret Scan/gitleaks (secret scan): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714316106/job/94495007315)
- Security Scan/dependency-review: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006227)
- Security Scan/osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006292)
- Security Scan/scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006530)
- Security Scan/trivy-fs: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006322)
- Semgrep (multi-language SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315917/job/94495005865)
- close-empty check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714313213/job/94494997613)
- dependency-review check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006227)
- generate-sbom check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315919/job/94495006275)
- gitleaks (secret scan) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714316106/job/94495007315)
- osv-scan / osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714316295/job/94495007685)
- osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006292)
- pip-audit (Python dependency audit) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315948/job/94495743971)
- scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006530)
- trivy-fs check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31714315959/job/94495006322)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (4 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (4 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: materialize_base_python_requirements.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: materialize_base_python_requirements.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (4 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (4 files)"]
R5 --> V5["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: strix.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: strix.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (4 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (4 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["CI script: materialize_base_python_requirements.py"]
S4 --> I4["review and security gate shell path"]
I4 --> R4["Review risk: CI script: materialize_base_python_requirements.py"]
R4 --> V4["bash -n plus Strix self-test"]
Evidence --> S5["Test (4 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test (4 files)"]
R5 --> V5["targeted test run"]
|
|
Returned to Draft because the exact current tree mixes the incomplete-retry evidence classifier with an unrelated trusted-uv materializer branch. The valid fail-closed boundary is narrow: only when the trusted inner gate explicitly reports incomplete log-only evidence and zero accepted findings may stale TUI severity be ignored during a provider-family outage; standalone Rebuild from protected |
|
Closing as superseded by the fail-closed evidence architecture in #965. This branch's outer wrapper deliberately exits 0 when a provider-unavailability signal coexists with a trusted |
Summary
Required Strix on #930f745422 (run 31665090829) selected NVIDIA NIM, printed leftover TUI
Severity: HIGH/Vulnerabilities 2from a midstream retry that never wrote a report artifact, then hit GitHub Models410 github_models_retirement_brownout. The trusted gate already said those markers are incomplete log-only evidence and that zero accepted vulnerabilities preceded the provider failure. The outer workflow grepped the full console tee, treated the leftover TUI lines as findings, and failed the required check for a non-backend reason.This change:
github_models_retirement_brownoutas backend unavailabilityVulnerabilities 1/Severity: HIGHwithout that gate verdict fail-closedDoes not lower the two-approval ruleset. Review agents remain
edit: deny. NVIDIA NIM remains the live public-scan provider.Test plan
pytest tests/test_strix_nvidia_nim_not_found_fallback.py tests/test_required_workflow_queue_contract.py tests/test_opencode_agent_contract.py tests/test_central_required_workflow_ruleset_audit.pybash -nis not the workflow contract; YAML was edited only in the Run Strix neutralization blockCloses the current-head Strix fail shape seen on #930, #949, #941, and #934.