Skip to content

OSAC-2870: check-ep-naming grandfather against live main, not just stale base_sha - #147

Merged
openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
tchughesiv:fix/ep-naming-live-grandfather
Jul 22, 2026
Merged

openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
tchughesiv:fix/ep-naming-live-grandfather

Conversation

@tchughesiv

@tchughesiv tchughesiv commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes a false-positive class of check-ep-naming CI failure: a long-lived PR that hasn't been pushed to since some other, unrelated PR merged a still-non-compliant enhancements/ directory into main fails on that unrelated directory — even though the PR never touches it, and it's already correctly grandfathered on main itself.

Observed concretely on #121, which fails check-ep-naming on enhancements/storage-control-plane-osac-2872 (merged non-compliant by #134) despite never touching that path — because #121's base.sha (captured at its last open/synchronize event, 2026-07-16) predates #134's merge.

Root cause

PRE_COMMIT_PR_BASE_SHA (set from github.event.pull_request.base.sha) is a snapshot taken at the PR's last open/synchronize event. It does not advance just because main gains new commits, and re-running an old CI job replays that same stale payload rather than refreshing it. The naming check's grandfather logic only checked this one, potentially stale, reference — so anything that landed on main after that snapshot looks "new" to the script, regardless of whether the current PR touches it.

Fix

Grandfathering now checks two references instead of one — a path is grandfathered if it exists at either:

  1. PRE_COMMIT_PR_BASE_SHA (existing behavior, unchanged), or
  2. PRE_COMMIT_LIVE_BASE_REF — the live tip of the base branch (origin/main), fetched fresh at the start of every CI run (new).

This keeps enforcement scoped to genuinely new paths. It's purely additive/supplementary: if the live ref isn't available for any reason (not fetched, older workflow run, local pre-commit install without network), it silently falls back to base-SHA-only behavior — no new failure mode introduced.

Critically, this also protects contributors who are actively fixing their own directory's naming (as prompted by the review comments just posted on #13, #46, #54, #61, #70, #81, #88, #91, #117, #118, #119, #126, #127): renaming their own non-compliant directory to a compliant one should never be blocked by an unrelated pre-existing violation elsewhere in the repo picked up by --all-files.

Changes

  • .github/workflows/pre-commit.yaml — add PRE_COMMIT_LIVE_BASE_REF: origin/${{ github.event.pull_request.base.ref }} env var (relies on the existing fetch-depth: 0 checkout, which already fetches all branches).
  • .github/scripts/check_ep_naming.py — new is_grandfathered() helper checks both references; validate_paths() and main() thread the new live_base_ref parameter through. Docstring expanded to explain the staleness mechanism and fix.
  • .github/scripts/test_check_ep_naming.py — 3 new tests: the exact OSAC-2766: Design - Type-Safe Resource References #121 false-positive scenario (grandfathered on live main, absent at stale base_sha → not flagged), a regression check that genuinely-new bad names are still flagged when absent from both refs, and a fallback check when the live ref isn't resolvable. 22 → 25 tests, all passing.
  • CONTRIBUTING.md — one-sentence clarification that grandfathering checks both the PR's base commit and the current tip of main.

Testing

  • python3 -m unittest test_check_ep_naming — 25/25 pass.
  • pre-commit run --all-files locally — all hooks pass, including check-ep-naming and yamllint on the workflow file.
  • Ran check_ep_naming.py directly against every current enhancements/* file with PRE_COMMIT_LIVE_BASE_REF=origin/main — clean exit 0.

Notes for reviewers

  • Not able to fully verify in this PR's own CI run whether origin/${{ github.event.pull_request.base.ref }} resolves as expected post-checkout (should, per actions/checkout's documented fetch-depth: 0 → full-history-all-branches behavior, and the existing fetch-depth: 0 step is unchanged) — worth confirming the check-ep-naming step doesn't log the "PR base SHA ... not available" warning-path when this PR's own CI runs. If for some reason the live ref doesn't resolve, the fallback is silent and behavior is unchanged from today (i.e., this PR is a strict improvement, never a regression).
  • Doesn't fix #121 directly (that's still blocked until either it's rebased, or OSAC-2553: Design: Catalog Items — UI Management #128 — which already renames the offending directory — merges); this PR fixes the underlying mechanism so this class of false positive stops recurring for any future PR in the same situation.

Summary by CodeRabbit

  • Bug Fixes

    • Improved enhancement naming checks in CI by recognizing directories already present on the current base branch, even when the pull request’s base revision is outdated.
    • Preserved validation for newly introduced directories with invalid names.
    • Added graceful fallback when the current base branch reference cannot be resolved.
  • Documentation

    • Clarified which pre-existing directories are exempt from naming validation and how unrelated legacy violations are handled.

PRE_COMMIT_PR_BASE_SHA is a snapshot from the pull_request webhook
payload, captured at the PR's last open/synchronize event. It doesn't
advance as main gains new commits, and re-running an old CI job replays
that same stale payload rather than refreshing it.

This caused a false-positive class of failure: a long-lived PR that
hasn't been pushed to since some other, unrelated PR merged a
still-non-compliant enhancements/ directory into main would fail
check-ep-naming on that unrelated directory, even though the PR never
touches it and it's already correctly grandfathered on main itself.
Observed concretely on PR osac-project#121, which failed on
enhancements/storage-control-plane-osac-2872 (merged by PR osac-project#134) despite
never touching that path.

Fix: grandfathering now also checks the live tip of the base branch
(PRE_COMMIT_LIVE_BASE_REF, e.g. origin/main, fetched fresh at the start
of every CI run) in addition to the stale base SHA — a path is
grandfathered if it exists at either reference. This keeps enforcement
scoped to genuinely new paths, so contributors actively fixing their own
directory's naming are never blocked by an unrelated pre-existing
violation elsewhere in the repo.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Tommy Hughes <tohughes@redhat.com>
@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@tchughesiv, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 51 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: d362e19d-3b31-4d96-ab54-c3f9bc03e478

📥 Commits

Reviewing files that changed from the base of the PR and between 5ec95e0 and 352c289.

📒 Files selected for processing (3)
  • .github/scripts/check_ep_naming.py
  • .github/scripts/test_check_ep_naming.py
  • CONTRIBUTING.md

Walkthrough

Changes

Naming validation

Layer / File(s) Summary
Live-base grandfathering logic
.github/scripts/check_ep_naming.py
Naming validation resolves an optional live base ref and grandfather-checks directories and lowercase filenames against either the stale base SHA or live ref.
Dual-reference test coverage
.github/scripts/test_check_ep_naming.py
Tests model independent path existence at both refs, including unresolved live-ref fallback behavior.
CI wiring and enforcement text
.github/workflows/pre-commit.yaml, CONTRIBUTING.md
Pre-commit receives the live base branch ref, and enforcement guidance documents the expanded grandfathering rules.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant PreCommit as pre-commit/action
  participant Main as main
  participant Validator as validate_paths
  participant Git as git refs
  PreCommit->>Main: provide PRE_COMMIT_LIVE_BASE_REF
  Main->>Validator: pass base SHA and live base ref
  Validator->>Git: resolve live base ref
  Validator->>Git: check path at base SHA or live ref
  Git-->>Validator: path existence results
  Validator-->>Main: naming violations
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (10 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets, tokens, passwords, private keys, base64 blobs, or credentialed URLs were added in the modified files.
No-Weak-Crypto ✅ Passed Changed files contain no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret-comparison code.
No-Injection-Vectors ✅ Passed No injection vectors found: the Python change uses subprocess with argv lists, and the diff contains no shell=True, eval/exec, pickle.loads, yaml.load, os.system, or unsafe HTML/SQL patterns.
Container-Privileges ✅ Passed No container/K8s manifests changed; the workflow diff adds only an env var and contains no privileged settings.
No-Sensitive-Data-In-Logs ✅ Passed Only stderr output is the existing base-SHA warning and violation messages; they don't expose passwords, tokens, PII, or host/customer data.
Ai-Attribution ✅ Passed The sole PR commit includes Assisted-by: Claude Code and Signed-off-by, with no Co-Authored-By AI trailer found.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: grandfathering check-ep-naming against the live base branch instead of only the stale base SHA.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@tchughesiv tchughesiv changed the title check-ep-naming: grandfather against live main, not just stale base_sha OSAC-2870: check-ep-naming grandfather against live main, not just stale base_sha Jul 22, 2026
@openshift-ci-robot

openshift-ci-robot commented Jul 22, 2026 •

Copy link
Copy Markdown

@tchughesiv: This pull request references OSAC-2870 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the sub-task to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

Fixes a false-positive class of check-ep-naming CI failure: a long-lived PR that hasn't been pushed to since some other, unrelated PR merged a still-non-compliant enhancements/ directory into main fails on that unrelated directory — even though the PR never touches it, and it's already correctly grandfathered on main itself.

Observed concretely on #121, which fails check-ep-naming on enhancements/storage-control-plane-osac-2872 (merged non-compliant by #134) despite never touching that path — because #121's base.sha (captured at its last open/synchronize event, 2026-07-16) predates #134's merge.

Root cause

PRE_COMMIT_PR_BASE_SHA (set from github.event.pull_request.base.sha) is a snapshot taken at the PR's last open/synchronize event. It does not advance just because main gains new commits, and re-running an old CI job replays that same stale payload rather than refreshing it. The naming check's grandfather logic only checked this one, potentially stale, reference — so anything that landed on main after that snapshot looks "new" to the script, regardless of whether the current PR touches it.

Fix

Grandfathering now checks two references instead of one — a path is grandfathered if it exists at either:

  1. PRE_COMMIT_PR_BASE_SHA (existing behavior, unchanged), or
  2. PRE_COMMIT_LIVE_BASE_REF — the live tip of the base branch (origin/main), fetched fresh at the start of every CI run (new).

This keeps enforcement scoped to genuinely new paths. It's purely additive/supplementary: if the live ref isn't available for any reason (not fetched, older workflow run, local pre-commit install without network), it silently falls back to base-SHA-only behavior — no new failure mode introduced.

Critically, this also protects contributors who are actively fixing their own directory's naming (as prompted by the review comments just posted on #13, #46, #54, #61, #70, #81, #88, #91, #117, #118, #119, #126, #127): renaming their own non-compliant directory to a compliant one should never be blocked by an unrelated pre-existing violation elsewhere in the repo picked up by --all-files.

Changes

  • .github/workflows/pre-commit.yaml — add PRE_COMMIT_LIVE_BASE_REF: origin/${{ github.event.pull_request.base.ref }} env var (relies on the existing fetch-depth: 0 checkout, which already fetches all branches).
  • .github/scripts/check_ep_naming.py — new is_grandfathered() helper checks both references; validate_paths() and main() thread the new live_base_ref parameter through. Docstring expanded to explain the staleness mechanism and fix.
  • .github/scripts/test_check_ep_naming.py — 3 new tests: the exact OSAC-2766: Design - Type-Safe Resource References #121 false-positive scenario (grandfathered on live main, absent at stale base_sha → not flagged), a regression check that genuinely-new bad names are still flagged when absent from both refs, and a fallback check when the live ref isn't resolvable. 22 → 25 tests, all passing.
  • CONTRIBUTING.md — one-sentence clarification that grandfathering checks both the PR's base commit and the current tip of main.

Testing

  • python3 -m unittest test_check_ep_naming — 25/25 pass.
  • pre-commit run --all-files locally — all hooks pass, including check-ep-naming and yamllint on the workflow file.
  • Ran check_ep_naming.py directly against every current enhancements/* file with PRE_COMMIT_LIVE_BASE_REF=origin/main — clean exit 0.

Notes for reviewers

  • Not able to fully verify in this PR's own CI run whether origin/${{ github.event.pull_request.base.ref }} resolves as expected post-checkout (should, per actions/checkout's documented fetch-depth: 0 → full-history-all-branches behavior, and the existing fetch-depth: 0 step is unchanged) — worth confirming the check-ep-naming step doesn't log the "PR base SHA ... not available" warning-path when this PR's own CI runs. If for some reason the live ref doesn't resolve, the fallback is silent and behavior is unchanged from today (i.e., this PR is a strict improvement, never a regression).
  • Doesn't fix #121 directly (that's still blocked until either it's rebased, or OSAC-2553: Design: Catalog Items — UI Management #128 — which already renames the offending directory — merges); this PR fixes the underlying mechanism so this class of false positive stops recurring for any future PR in the same situation.

Summary by CodeRabbit

  • Bug Fixes

  • Improved enhancement naming checks in CI by recognizing directories already present on the current base branch, even when the pull request’s base revision is outdated.

  • Preserved validation for newly introduced directories with invalid names.

  • Added graceful fallback when the current base branch reference cannot be resolved.

  • Documentation

  • Clarified which pre-existing directories are exempt from naming validation and how unrelated legacy violations are handled.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/scripts/check_ep_naming.py:
- Line 128: Update the base-reference resolution flow around
resolve_live_base_ref so an unresolved base SHA preserves fail-closed behavior
and does not enable live-ref grandfathering; alternatively, if the fallback is
intentional, revise the warning to describe it accurately and add a regression
test covering the fallback.

In @.github/scripts/test_check_ep_naming.py:
- Around line 186-227: Add a test alongside
test_pre_existing_on_live_main_but_absent_at_stale_base_sha_is_not_flagged that
uses a DESIGN.md or PRD.md path whose filename exists only at live_base_ref,
with the stale base lacking it, and assert no violations are reported. Ensure
the case specifically exercises live-ref filename grandfathering rather than
only directory grandfathering.

In @.github/workflows/pre-commit.yaml:
- Line 19: Update the pre-commit action reference in the workflow to use the
full release commit SHA instead of the mutable v3.0.1 tag, while preserving the
existing action version and workflow behavior.

In `@CONTRIBUTING.md`:
- Around line 44-47: Update the documentation paragraph describing pre-existing
files so it refers to files currently on the PR’s base branch rather than files
currently on main, matching the checker’s use of
github.event.pull_request.base.ref.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 383e0908-af74-4eb1-b5ef-d28cc9e3e4a8

📥 Commits

Reviewing files that changed from the base of the PR and between a56fc0e and 5ec95e0.

📒 Files selected for processing (4)
  • .github/scripts/check_ep_naming.py
  • .github/scripts/test_check_ep_naming.py
  • .github/workflows/pre-commit.yaml
  • CONTRIBUTING.md

Comment thread .github/scripts/check_ep_naming.py Outdated
Comment thread .github/scripts/test_check_ep_naming.py
Comment thread .github/workflows/pre-commit.yaml
Comment thread CONTRIBUTING.md Outdated
… wording

- check_ep_naming.py: when the base SHA is unresolvable (CI misconfig,
  e.g. a shallow checkout), also disable live-ref grandfathering, not
  just the base-SHA one. The warning already claims grandfathering is
  fully disabled and every path is validated as new — the code now
  actually matches that, instead of silently falling back to a partial
  (live-ref-only) grandfather check.
- test_check_ep_naming.py: add coverage for live-ref grandfathering of
  the filename-casing check specifically (a separate code path from
  directory grandfathering), and a regression test proving the
  fail-closed guarantee above holds even when the live ref would
  otherwise have grandfathered the path. 25 -> 27 tests, all passing.
- CONTRIBUTING.md: say 'the PR's base branch' instead of 'main', since
  the checker keys off github.event.pull_request.base.ref rather than
  a hardcoded branch name.

Addresses CodeRabbit review comments on PR osac-project#147.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Tommy Hughes <tohughes@redhat.com>
@openshift-ci

openshift-ci Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: tchughesiv

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit d17b902 into osac-project:main Jul 22, 2026
3 checks passed
slintes pushed a commit to slintes/enhancement-proposals that referenced this pull request Jul 27, 2026
… wording

- check_ep_naming.py: when the base SHA is unresolvable (CI misconfig,
  e.g. a shallow checkout), also disable live-ref grandfathering, not
  just the base-SHA one. The warning already claims grandfathering is
  fully disabled and every path is validated as new — the code now
  actually matches that, instead of silently falling back to a partial
  (live-ref-only) grandfather check.
- test_check_ep_naming.py: add coverage for live-ref grandfathering of
  the filename-casing check specifically (a separate code path from
  directory grandfathering), and a regression test proving the
  fail-closed guarantee above holds even when the live ref would
  otherwise have grandfathered the path. 25 -> 27 tests, all passing.
- CONTRIBUTING.md: say 'the PR's base branch' instead of 'main', since
  the checker keys off github.event.pull_request.base.ref rather than
  a hardcoded branch name.

Addresses CodeRabbit review comments on PR osac-project#147.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Tommy Hughes <tohughes@redhat.com>
empovit pushed a commit to empovit/osac-enhancement-proposals that referenced this pull request Aug 2, 2026
… wording

- check_ep_naming.py: when the base SHA is unresolvable (CI misconfig,
  e.g. a shallow checkout), also disable live-ref grandfathering, not
  just the base-SHA one. The warning already claims grandfathering is
  fully disabled and every path is validated as new — the code now
  actually matches that, instead of silently falling back to a partial
  (live-ref-only) grandfather check.
- test_check_ep_naming.py: add coverage for live-ref grandfathering of
  the filename-casing check specifically (a separate code path from
  directory grandfathering), and a regression test proving the
  fail-closed guarantee above holds even when the live ref would
  otherwise have grandfathered the path. 25 -> 27 tests, all passing.
- CONTRIBUTING.md: say 'the PR's base branch' instead of 'main', since
  the checker keys off github.event.pull_request.base.ref rather than
  a hardcoded branch name.

Addresses CodeRabbit review comments on PR osac-project#147.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Tommy Hughes <tohughes@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants