ci(openwiki): fix provider config + apply openwiki#33 workaround so generation succeeds - #5536
Conversation
The first dispatched run failed: openwiki defaults to OpenRouter unless OPENWIKI_PROVIDER is set, and its Anthropic model ids (src/constants.ts) are claude-haiku-4-5 / claude-sonnet-5 / claude-opus-4.8 — not the raw API id claude-sonnet-4-6. Set OPENWIKI_PROVIDER=anthropic, default model claude-haiku-4-5, and add a model_id dispatch input so the exact id can be tuned without another PR. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…IBLE_API_KEY The Anthropic path failed on openwiki's malformed document content block (400 invalid_request_error, Anthropic-format-specific). Switch to openwiki's OpenAI provider pointed at NEAR AI's OpenAI-compatible endpoint using the existing LIVE_OPENAI_COMPATIBLE_API_KEY repo secret (base https://cloud-api.near.ai/v1, model Qwen/Qwen3.5-122B-A10B) — the same key/host/model live-canary.yml uses. No new secret needed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…hing Root cause was never the Anthropic provider (it authenticated and ran) — openwiki's read_file tool wraps binary files as media/document content blocks, and it read tests/fixtures/hello.pdf, producing a document block Anthropic rejects (400, media_type must be application/pdf). openwiki has no ignore config, so strip non-text assets from the ephemeral checkout before generating. Revert provider to Anthropic (ANTHROPIC_API_KEY, claude-haiku-4-5). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The recurring Anthropic 400 (document.source.base64.media_type must be application/pdf) is a known openwiki bug (langchain-ai/openwiki#33): the bundled deepagents read-tool maps extensionless/unmapped text files (Makefile, Dockerfile, LICENSE, *.lock) to application/octet-stream and sends them as base64 document blocks. Apply the issue's confirmed workaround — patch the installed deepagents bundle's MIME fallback to text/plain — then keep the binary strip for genuine binaries. Stays on Anthropic (which was never the problem). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe OpenWiki update workflow gains a ChangesOpenWiki Update Workflow
Estimated code review effort: 2 (Simple) | ~10 minutes No sandbox/trust/secrets/egress/migration invariant from CLAUDE.md/AGENTS.md is implicated — this is a CI-only workflow file (YAML), outside Rust review scope. Flagging one CI-specific concern: patching a third-party dependency's ( Poem
🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/openwiki-update.yml:
- Around line 87-95: The “Strip binary assets openwiki must not attach” step is
filtering by filename extension only, so it misses binary blobs with other or no
extensions. Update the workflow’s find/delete logic to detect and remove
unsupported files by MIME/type content rather than relying on names, while
keeping the existing openwiki asset stripping step structure intact.
- Around line 68-82: The MIME fallback patch in the workflow currently only
emits a warning when it does not apply, but this is the same fallback that can
trigger 400s in the later openwiki run. Update the patch step to fail closed:
after the loop in the openwiki-update workflow, verify the deepagents bundle
under the openwiki node_modules path no longer contains
application/octet-stream, and if the patch count is zero or the old MIME string
still exists, stop the job before the expensive openwiki execution. Use the
existing patch block that touches deepagents bundle files as the location to
enforce this check.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 9962a712-1540-4a99-b66d-bacb6451d567
📒 Files selected for processing (1)
.github/workflows/openwiki-update.yml
| - name: Patch deepagents MIME fallback (openwiki#33 workaround) | ||
| run: | | ||
| B="$(npm root -g)/openwiki/node_modules/deepagents/dist" | ||
| patched=0 | ||
| for f in "$B"/*.js "$B"/*.cjs; do | ||
| [ -f "$f" ] || continue | ||
| if grep -q 'toLocaleLowerCase()] || "application/octet-stream"' "$f"; then | ||
| sed -i 's#toLocaleLowerCase()\] || "application/octet-stream"#toLocaleLowerCase()] || "text/plain"#g' "$f" | ||
| patched=$((patched+1)) | ||
| fi | ||
| done | ||
| echo "patched ${patched} deepagents bundle file(s): octet-stream -> text/plain" | ||
| if [ "${patched}" -eq 0 ]; then | ||
| echo "::warning::openwiki#33 patch matched nothing — deepagents bundle layout may have changed; run may 400 on extensionless files" | ||
| fi |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Fail closed when the MIME patch does not apply.
Line 80 only warns, but Lines 63-67 identify this fallback as the 400 trigger. Verify the bundle no longer contains application/octet-stream, and stop before the expensive openwiki run if it does.
Proposed hardening
echo "patched ${patched} deepagents bundle file(s): octet-stream -> text/plain"
- if [ "${patched}" -eq 0 ]; then
- echo "::warning::openwiki#33 patch matched nothing — deepagents bundle layout may have changed; run may 400 on extensionless files"
+ if grep -RIn 'application/octet-stream' "$B" --include='*.js' --include='*.cjs' 2>/dev/null; then
+ echo "::error::openwiki#33 patch incomplete — deepagents can still emit application/octet-stream"
+ exit 1
+ fi
+ if [ "${patched}" -eq 0 ]; then
+ echo "::notice::openwiki#33 patch matched nothing; no octet-stream fallback remains"
fi📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Patch deepagents MIME fallback (openwiki#33 workaround) | |
| run: | | |
| B="$(npm root -g)/openwiki/node_modules/deepagents/dist" | |
| patched=0 | |
| for f in "$B"/*.js "$B"/*.cjs; do | |
| [ -f "$f" ] || continue | |
| if grep -q 'toLocaleLowerCase()] || "application/octet-stream"' "$f"; then | |
| sed -i 's#toLocaleLowerCase()\] || "application/octet-stream"#toLocaleLowerCase()] || "text/plain"#g' "$f" | |
| patched=$((patched+1)) | |
| fi | |
| done | |
| echo "patched ${patched} deepagents bundle file(s): octet-stream -> text/plain" | |
| if [ "${patched}" -eq 0 ]; then | |
| echo "::warning::openwiki#33 patch matched nothing — deepagents bundle layout may have changed; run may 400 on extensionless files" | |
| fi | |
| - name: Patch deepagents MIME fallback (openwiki#33 workaround) | |
| run: | | |
| B="$(npm root -g)/openwiki/node_modules/deepagents/dist" | |
| patched=0 | |
| for f in "$B"/*.js "$B"/*.cjs; do | |
| [ -f "$f" ] || continue | |
| if grep -q 'toLocaleLowerCase()] || "application/octet-stream"' "$f"; then | |
| sed -i 's#toLocaleLowerCase()\] || "application/octet-stream"`#toLocaleLowerCase`()] || "text/plain"`#g`' "$f" | |
| patched=$((patched+1)) | |
| fi | |
| done | |
| echo "patched ${patched} deepagents bundle file(s): octet-stream -> text/plain" | |
| if grep -RIn 'application/octet-stream' "$B" --include='*.js' --include='*.cjs' 2>/dev/null; then | |
| echo "::error::openwiki#33 patch incomplete — deepagents can still emit application/octet-stream" | |
| exit 1 | |
| fi | |
| if [ "${patched}" -eq 0 ]; then | |
| echo "::notice::openwiki#33 patch matched nothing; no octet-stream fallback remains" | |
| fi |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/openwiki-update.yml around lines 68 - 82, The MIME
fallback patch in the workflow currently only emits a warning when it does not
apply, but this is the same fallback that can trigger 400s in the later openwiki
run. Update the patch step to fail closed: after the loop in the openwiki-update
workflow, verify the deepagents bundle under the openwiki node_modules path no
longer contains application/octet-stream, and if the patch count is zero or the
old MIME string still exists, stop the job before the expensive openwiki
execution. Use the existing patch block that touches deepagents bundle files as
the location to enforce this check.
| - name: Strip binary assets openwiki must not attach | ||
| run: | | ||
| find . -type f \( \ | ||
| -name '*.pdf' -o -name '*.png' -o -name '*.jpg' -o -name '*.jpeg' \ | ||
| -o -name '*.gif' -o -name '*.webp' -o -name '*.ico' -o -name '*.svg' \ | ||
| -o -name '*.wasm' -o -name '*.woff' -o -name '*.woff2' -o -name '*.ttf' \ | ||
| -o -name '*.otf' -o -name '*.gz' -o -name '*.zip' -o -name '*.zst' \ | ||
| -o -name '*.mp4' -o -name '*.mov' -o -name '*.pdf' \) \ | ||
| -not -path './.git/*' -delete |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Strip by MIME, not extension.
Lines 89-95 miss binary files with other or no extensions (*.bin, *.db, generated blobs). That leaves the same unsupported-document path open.
Proposed hardening
- find . -type f \( \
- -name '*.pdf' -o -name '*.png' -o -name '*.jpg' -o -name '*.jpeg' \
- -o -name '*.gif' -o -name '*.webp' -o -name '*.ico' -o -name '*.svg' \
- -o -name '*.wasm' -o -name '*.woff' -o -name '*.woff2' -o -name '*.ttf' \
- -o -name '*.otf' -o -name '*.gz' -o -name '*.zip' -o -name '*.zst' \
- -o -name '*.mp4' -o -name '*.mov' -o -name '*.pdf' \) \
- -not -path './.git/*' -delete
+ find . -type f -not -path './.git/*' -print0 |
+ while IFS= read -r -d '' f; do
+ mime="$(file --brief --mime-type "$f")"
+ case "$mime" in
+ text/*|application/json|application/xml|application/x-yaml|application/toml|application/javascript|application/typescript|application/x-sh|inode/x-empty)
+ ;;
+ *)
+ rm -f -- "$f"
+ ;;
+ esac
+ done📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Strip binary assets openwiki must not attach | |
| run: | | |
| find . -type f \( \ | |
| -name '*.pdf' -o -name '*.png' -o -name '*.jpg' -o -name '*.jpeg' \ | |
| -o -name '*.gif' -o -name '*.webp' -o -name '*.ico' -o -name '*.svg' \ | |
| -o -name '*.wasm' -o -name '*.woff' -o -name '*.woff2' -o -name '*.ttf' \ | |
| -o -name '*.otf' -o -name '*.gz' -o -name '*.zip' -o -name '*.zst' \ | |
| -o -name '*.mp4' -o -name '*.mov' -o -name '*.pdf' \) \ | |
| -not -path './.git/*' -delete | |
| - name: Strip binary assets openwiki must not attach | |
| run: | | |
| find . -type f -not -path './.git/*' -print0 | | |
| while IFS= read -r -d '' f; do | |
| mime="$(file --brief --mime-type "$f")" | |
| case "$mime" in | |
| text/*|application/json|application/xml|application/x-yaml|application/toml|application/javascript|application/typescript|application/x-sh|inode/x-empty) | |
| ;; | |
| *) | |
| rm -f -- "$f" | |
| ;; | |
| esac | |
| done |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/openwiki-update.yml around lines 87 - 95, The “Strip
binary assets openwiki must not attach” step is filtering by filename extension
only, so it misses binary blobs with other or no extensions. Update the
workflow’s find/delete logic to detect and remove unsupported files by MIME/type
content rather than relying on names, while keeping the existing openwiki asset
stripping step structure intact.
Reborn integration-tier coverageLine coverage (Reborn crates): 15.11% — 9538 / 63132 lines Per-crate breakdown (12 crates, lowest-covered first)
This signal is informational: coverage never gates the PR — not the percentage, not the per-crate holes, not the 0-coverage callout. |
What this fixes
The OpenWiki workflow merged in #5532 never actually generated — it failed on the first file read. This makes it work, and it just produced the first wiki: #5535 (+3,062 lines).
The bug (langchain-ai/openwiki#33)
openwiki's bundled
deepagentsread-tool maps any unmapped/extensionless file (Makefile,Dockerfile,LICENSE,*.lock, …) toapplication/octet-streamand sends it as a base64documentcontent block. The Anthropic Messages API only acceptsapplication/pdffor base64 documents, so the agent 400s on the first such file. (NEAR AI's OpenAI-compatible endpoint rejects the same shape.)The fix
Three additions to
.github/workflows/openwiki-update.yml:OPENWIKI_PROVIDER: anthropic— without it openwiki defaults to OpenRouter (and demanded a key we don't have). Correct model idclaude-haiku-4-5(openwiki's own id, viasrc/constants.ts), overridable by amodel_iddispatch input.octet-stream→text/plainso extensionless text files are inlined as text, not attached as documents..png/.pdf/...are also sent as document blocks and onlyapplication/pdfis accepted). The real repo is untouched.Provider stays Anthropic (it was never the problem — auth and generation both work once #33 is patched). Publishing is unchanged: a human-reviewed PR via the GH App, no auto-merge (SOC 2).
Validation
Dispatched from this branch end-to-end: patch ✓, strip ✓,
Regenerate wiki✓ (ran to completion, not the prior 5-second crash), and it opened #5535.🤖 Generated with Claude Code