fix(review): require line-anchored current-head REQUEST_CHANGES findings - #959
fix(review): require line-anchored current-head REQUEST_CHANGES findings#959seonghobae wants to merge 5 commits into
Conversation
GitHub rejects inline review comments on unchanged paths or past-EOF lines with HTTP 422. Fail-close those findings in the trusted normalizer so blockers attach on Files changed.
|
@cwl-noema-review please review this current head. REQUEST_CHANGES findings must now name an exact current-head changed file and a line that exists in that file so GitHub can attach the inline comment. |
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Record that a REQUEST_CHANGES path and line must be consistent with the trusted current-head artifact. Force the trusted-uv installer tests onto the linux x86_64 runner path and add the control-plane architecture diagram.
finding_location_error deferred line-shape checks to the caller. Line 0 passes the EOF probe because 0 > line_count is false, so a current-head path could be treated as anchored. Reject bool and non-positive lines inside the helper.
Materialize a base Python lock only when every package line is an exact SHA-256 pin or a two-token relative -r/--requirement include of a candidate lock path. A lone --require-hashes directive, ./dotted paths, and -r other-hashes.txt no longer enter the trusted build context.
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
67367344cba0be95c81832187436f85c31d65c9a. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Bandit (Python SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662486/job/94493317981)
- Close Empty PR/close-empty: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713661437/job/94492776099)
- CodeQL PR/Detect CodeQL languages: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662539/job/94492779549)
- Detect CodeQL languages check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662539/job/94492779549)
- Detect Python check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662486/job/94492779420)
- OSV-Scanner PR/osv-scan / osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662996/job/94492782193)
- Python 3.10 compatibility contract check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662547/job/94492779718)
- Python 3.14 full quality gate check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662547/job/94492780298)
- Python Security/Bandit (Python SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662486/job/94493317981)
- Python Security/Detect Python: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662486/job/94492779420)
- Python Security/pip-audit (Python dependency audit): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662486/job/94493318674)
- SAST Semgrep/Semgrep (multi-language SAST): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662755/job/94492780023)
- SBOM Generation/generate-sbom: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662430/job/94492779145)
- Scorecard PR/Scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662592/job/94492779827)
- Scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662592/job/94492779827)
- Secret Scan/gitleaks (secret scan): CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662411/job/94492779155)
- Security Scan/dependency-review: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779497)
- Security Scan/osv-scan: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779573)
- Security Scan/scorecard: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779371)
- Security Scan/trivy-fs: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779514)
- Semgrep (multi-language SAST) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662755/job/94492780023)
- Strix Changed Path Quality CI/exact-head-path-policy: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662451/job/94492779276)
- Trusted uv Materializer Quality CI/Python 3.10 compatibility contract: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662547/job/94492779718)
- Trusted uv Materializer Quality CI/Python 3.14 full quality gate: CANCELLED (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662547/job/94492780298)
- close-empty check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713661437/job/94492776099)
- coverage-source-tree check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713661441/job/94493341312)
- dependency-review check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779497)
- exact-head-path-policy check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662451/job/94492779276)
- generate-sbom check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662430/job/94492779145)
- gitleaks (secret scan) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662411/job/94492779155)
- osv-scan / osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662996/job/94492782193)
- osv-scan check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779573)
- pip-audit (Python dependency audit) check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662486/job/94493318674)
- required-workflow-bootstrap check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713661441/job/94492776765)
- scorecard check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779371)
- trivy-fs check run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/31713662497/job/94492779514)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (4 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (4 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: review-line-anchored-findings.md"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: review-line-anchored-findings.md"]
R2 --> V2["docs review"]
Evidence --> S3["CI script (4 files)"]
S3 --> I3["review and security gate shell path"]
I3 --> R3["Review risk: CI script (4 files)"]
R3 --> V3["bash -n plus Strix self-test"]
Evidence --> S4["Test (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (3 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed. Findings1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
Failed checks:
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Changed file (4 files)"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Changed file (4 files)"]
R1 --> V1["required checks"]
Evidence --> S2["Docs: review-line-anchored-findings.md"]
S2 --> I2["operator or user guidance"]
I2 --> R2["Review risk: Docs: review-line-anchored-findings.md"]
R2 --> V2["docs review"]
Evidence --> S3["CI script (4 files)"]
S3 --> I3["review and security gate shell path"]
I3 --> R3["Review risk: CI script (4 files)"]
R3 --> V3["bash -n plus Strix self-test"]
Evidence --> S4["Test (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (3 files)"]
R4 --> V4["targeted test run"]
|
|
Returned to Draft because the exact current tree mixes the line-anchored REQUEST_CHANGES contract with an unrelated trusted-uv materializer branch. The valid publication boundary is bounded: each blocking finding must target a non-empty exact current-head changed path and a line that exists in that current-head file; invalid locations must be rejected before GitHub receives the review. Head Rebuild from protected |
|
Draft blockers at exact head
Add RED regressions, then reject or persist the exact validated path and fail closed when changed-file evidence is unavailable for non-empty REQUEST_CHANGES findings. Preserve byte/Unicode Git path identity, source-root containment, symlink, regular-file, size, and EOF boundaries. Keep Draft until focused/full exact coverage and current-head reviews pass. @opencode-agent review |
Rate Limit Exceeded
|
Buyer-visible gap
OpenCode already emits inline
REQUEST_CHANGESfindings, but the trusted normalizer accepted arbitrary non-empty paths and positive line numbers. GitHub can then reject unchanged paths or past-EOF lines with HTTP 422, leaving blockers absent from Files changed.This Draft proposes:
Exact identity and bounded scope
main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;a3b93b70b84a679f39faf32aa5e86adb4eaa97ac;CHANGELOG.md.Unrelated central AGENTS/CLAUDE/Architecture and trusted-lock materializer production/test changes entered the branch. The current ordinary forward commit restores those paths to protected-main content. No force-push, rebase, history rewrite, predecessor evidence transfer, or gate weakening was used.
Current blocking correctness findings
This Draft is not ready for integration.
finding_location_error(str(finding["path"]).strip(), line)but appends the original finding object unchanged. A model path such as" scripts/ci/example.py "can be validated against the stripped current-head path and then published with whitespace, still risking GitHub HTTP 422. The normalized finding must carry the exact canonical path that was validated, or non-canonical path text must be rejected.finding_location_error()checks membership only whencurrent_changed_files()is non-empty. If the trusted changed-file artifact is absent/unsafe while the manifest and source root remain available, a REQUEST_CHANGES finding on an unchanged source path can pass the membership gate. For inline current-head findings, missing changed-file evidence should fail closed unless a separately reviewed contract proves an intentional no-diff mode.Required TDD repair
Before Ready:
finding["path"]with the exact validated canonical value before publication;Do not mark Ready or enable auto-merge while these blockers remain. No administrative bypass, self-approval, or relaxation of line anchoring is requested.