-
Notifications
You must be signed in to change notification settings - Fork 3.1k
fix(ci): give each job its own proxy wrapper directory #7951
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[Suggestion] No test asserts that the triage workflow's proxy wrappers use container-local
/tmprather thanRUNNER_TEMP. — Failure scenario: if a future edit reverts this line to${RUNNER_TEMP:-/tmp}/qwen-network-bin.XXXXXX(matching the review workflow's pattern, which looks like the more defensive choice), the original bug recurs — root-owned files on the host via theRUNNER_TEMPbind mount cause EACCES for every subsequent non-container review job on that runner.The triage test file (
scripts/tests/qwen-triage-workflow.test.js) has zero assertions onproxy_bin,configure_qwen_network, ornetwork-bin, despite assertingRUNNER_TEMPpaths for 22 other concerns — showing the established pattern for guarding path choices.中文说明
[Suggestion] 没有测试断言 triage workflow 的代理脚本包装器使用的是容器内的
/tmp而不是RUNNER_TEMP。—— 失败场景:如果未来的编辑将此行改回${RUNNER_TEMP:-/tmp}/qwen-network-bin.XXXXXX(与 review workflow 的模式一致,看起来更像更稳妥的选择),原来的 bug 就会重现 —— 通过RUNNER_TEMPbind mount 在宿主机上留下 root 所属的文件,导致该 runner 上所有后续的非容器 review job 出现 EACCES。triage 测试文件 (
scripts/tests/qwen-triage-workflow.test.js) 对proxy_bin、configure_qwen_network或network-bin没有任何断言,尽管它对 22 个其他路径使用了RUNNER_TEMP断言 —— 说明已有现成的路径保护模式可以复用。— qwen3.7-max via Qwen Code /review