Repository navigation
fix(release): fail closed when draft state lookup fails - #5763
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe release workflow checks the output of ChangesRelease draft-state check
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The release step now fails on lookup errors and unexpected draft states. No actionable merge-blocking risk remains after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change makes release publication stop when draft state cannot be confirmed. The existing upload-before-publication sequence remains intact, and no new security exposure was identified. Live GitHub behavior was not verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
리뷰 · 우선순위 64 / 80이 풀리퀘스트는 바탕이 예전 문장은 초안인지 묻는 명령을 이제는 조회 결과를
라인 - 라인 - 메인테이너의 판단이 필요한 지점 조회가 성공했는데 값이 파일 업로드는 조회보다 먼저예요 (684행). 조회가 실패하면 파일은 초안 릴리스에 붙어 있고, 단계만 실패해요. 다시 돌리면 너의 추천 방향은 맞아요. 바탕 693행에서 이 댓글은 grok-bot이 작성했습니다 |
A successful draft-state query that answers neither true nor false — an empty body or an unexpected shape — used to skip the publish step and leave the release a silent draft. Only an explicit false may pass now; anything else fails the step. The contract test covers the unexpected value alongside the existing failing-query case.
|
Applied your suggestion: only an explicit "false" passes now — a successful query returning anything else (empty body, unexpected shape) fails the step instead of leaving a silent draft. The contract test covers the unexpected-value case alongside the failing-query case. |
|
리뷰 반영 확인: 236aa05951에서 693행을 |
…ash regressions Keep the existing release workflow fix unchanged. Separate static contracts from shell execution, find native Git Bash on Windows, and refuse silently skipped shell coverage on CI. Mock only the expected gh commands in an empty working directory with no inherited credentials or executable search path. Assert success paths, command order, six malformed states, and upload/view/edit failure propagation. Add subprocess time and output bounds. Local preliminary validation: TypeScript syntax and 12 checks through a Node adapter invoking actual Bash passed; restoring the original bug or making the script always fail was detected. Native Bun cross-platform validation pending.
|
Follow-up applied in f1690aa as a non-force fast-forward. The production fail-closed correction already addressed the earlier review; this follow-up leaves that workflow unchanged and repairs the verification gap in the existing test file:
Exact-commit native validation: https://github.com/luvs01/opencodex/actions/runs/36090520098 Linux, macOS and Windows each ran the same 21 tests: 21 passed, 0 failed, no skipped tests, 154 assertions with project-pinned Bun 1.4.0. Project typecheck, privacy scan and structure checks passed on Linux. All three hosts checked out The PR description now records these results instead of the old 8-pass/1-fail Windows result. Full repository CI remains separate: Service lifecycle and React Doctor passed on the new head; Cross-platform CI is still running. No real release command, release/tag mutation, paid review setting change, or merge was performed. @Ingwannu @lidge-jun Please review the updated head once the required checks settle. Existing reviewer requests are preserved. @coderabbitai review |
|
Ingwannu
left a comment
There was a problem hiding this comment.
Approved on exact head f1690aae69b1fd16a5ec27fbd351aaadd0e903e7.
Moving the draft-state lookup out of the if condition restores Bash fail-fast behavior when gh release view fails, and the explicit three-way case permits publication only from a literal true while accepting an already-public literal false idempotently.
Focused validation under a 2-CPU / 4 GiB cgroup passed: 21 tests, 0 failures. The portable shell harness covers lookup/upload/edit failures, malformed successful output, draft publication exactly once, and the already-public path. I found no remaining blocker.
Summary
gh release view --json isDraft --jq .isDrafttodraft_stateoutside a conditional preserves its failing exit status underset -euo pipefail, rather than silently leaving the release as a draft.truepublishes the draft and onlyfalsecompletes without an edit. Empty, null, malformed or otherwise unexpected output fails the step. The original production workflow correction is unchanged by the latest follow-up.f1690aae69b1fd16a5ec27fbd351aaadd0e903e7changes only the existing release contract test file. It separates static contracts from executable Bash checks, discovers native Git Bash on Windows without invoking the System32 WSL launcher, and adds success, command-order and failure-path coverage.ghoperations. No real release upload or publication is performed.Verification
Latest follow-up:
f1690aae69b1fd16a5ec27fbd351aaadd0e903e7, applied as a non-force fast-forward from236aa05951a19b50e91125057daeb56d0b5887fd.Native Bun 1.4.0 verification of this exact commit:
https://github.com/luvs01/opencodex/actions/runs/36090520098
All three read-only hosted jobs checked out
f1690aadirectly, not the helper workflow commit:The 21 tests comprise the nine existing static contracts, one shell-availability guard and eleven shell cases. They cover lookup failure even with
trueon stdout; six unexpected values including empty/null/multiline output; normal draft publication; the no-edit path after an explicitfalse; upload failure stopping before lookup; and edit failure preserving the failing result. Exact command order/arguments and whether execution reaches completion are asserted, not only exit codes.Also passed on Linux:
git diff --exit-codepassed after validation on all three hosts. The uploaded test blob matches the locally prepared source (2296c027de35e4e7bbedce1cdf61029e905adef2). The isolated helper workflow is a later commit on a separate validation branch; it is absent from this PR's source tree and commit ancestry.Full repository tests and
test:changedwere not run in the isolated helper: this follow-up is one test file exercising a bounded release-shell change, and the local container has neither Bun nor network access. The relevant source-as-data test was run explicitly on all three platforms; the full repository matrix remains the upstream PR CI's responsibility. This is not an end-to-end production release run and does not establish that external GitHub operations will succeed.The previous head's cancelled CI is not passing evidence. On the new head, Service lifecycle and React Doctor have passed; Cross-platform CI is still in progress at this update. Required current-head checks and maintainer review remain necessary before merge.
Security scope review: this follow-up introduces no production trigger, permission, publication destination or credential change. The existing workflow correction preserves verified-bundle/receipt ordering and fails on unknown publication state. The test subprocess receives no GitHub token and mocks
gh. No release workflow was dispatched, no release/tag was changed and no merge was performed. Independent maintainer review of the release workflow is still required.Checklist
Summary by CodeRabbit