Repository navigation
fix: Core ID assignment — SHA-256 content-addressed IDs (ADR-006) - #6
Conversation
🤖 CodeAnt AI — Review Status
|
|
Warning Review limit reached
Next review available in: 39 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (14)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
Running ultrareview automatically — This rewrites core ID assignment and dependency resolution to content-addressed op- IDs, changing public ID semantics and duplicate-operation behavior across every planned workflow — high blast radius if a hashing, canonicalization, or edge-resolution bug slips through.. I'll post findings when complete. |
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | -10 |
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
PR Summary by QodoFix core operation ID assignment with ADR-006 SHA-256 content-addressed IDs
AI Description
Diagram
High-Level Assessment
Files changed (12)
|
There was a problem hiding this comment.
Pull Request Overview
The PR implementation of SHA-256 content-addressed IDs is currently not up to standards, primarily due to a logic flaw in the ID context generation and failure of cross-package consistency checks.
Critical Blocking Issues
- ID Collision Risk: The 'contextFor' function in 'plan.ts' omits critical fields like 'env', 'image', and 'workingDir'. This causes different operations to hash to the same ID, which will trigger composition errors or incorrect cache behavior.
- Test Resolution Failure: The consistency test in the IR package cannot resolve the core module, meaning the cross-package verification required by ADR-006 is not actually executing in CI.
- Complexity & Coverage: 'packages/core/src/internal/canonical.ts' has been identified as a complex file with significant uncovered logic, posing a maintenance risk for such a critical component of the hashing system.
- Platform Compatibility: The use of 'node:crypto' and ES2017 features (like 'padStart') may break the package's requirements for isomorphic or legacy environment support.
About this PR
- The implementation of 'canonicalStringify' is manually duplicated between the core and ir packages. While this avoids circular dependencies, any future changes to the canonical format (ADR-006) must be manually synced in both locations to prevent ID mismatches.
Test suggestions
- Verify computeOperationId produces the same hash for identical inputs regardless of key insertion order in context
- Verify matrix expansion produces distinct, deterministic IDs for each combination
- Verify planning fails when duplicate user-provided spec.id aliases are defined
- Verify planning fails when two operations have identical kind, name, and context (true duplicates)
- Verify dependsOn strings correctly resolve user-provided spec.id aliases to the resulting op- IDs
- Verify cross-package consistency: core and ir implementations of computeOperationId produce identical outputs
- Verify canonicalStringify correctly escapes control characters and quotes per JSON spec
- Address code coverage gaps in 'packages/core/src/internal/canonical.ts'
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Address code coverage gaps in 'packages/core/src/internal/canonical.ts'
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Code Review by Qodo
1. Missing positional index causes false duplicate rejection
|
MergerNeeds Review The shipped planner rejects any multi-value matrix operation carrying a user-provided Commit |
There was a problem hiding this comment.
Ultrareview completed in 9m 37s
5 issues found across 12 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="packages/core/src/internal/ids.ts">
<violation number="1" location="packages/core/src/internal/ids.ts:25">
P2: Operation IDs collide when a name or string context value contains an unpaired surrogate: the canonical serializer writes it raw, and the UTF-8 hash conversion replaces it with U+FFFD. As a result, for example, `"\uD800"` and `"\uFFFD"` hash to the same operation ID despite being distinct inputs. Escaping unpaired surrogates in `canonicalStringify` (as `JSON.stringify` does), or rejecting them before hashing, would preserve content addressing.</violation>
</file>
<file name="packages/core/src/internal/plan.ts">
<violation number="1" location="packages/core/src/internal/plan.ts:265">
P1: A matrix operation with a user-provided `id` can no longer be planned: every expanded child inherits that ID, and the second child is treated as a duplicate alias even though its matrix context gives it a distinct `op-` ID. The alias representation needs to account for a matrix alias resolving to multiple child IDs (and expand a dependency on it accordingly), or matrix-child aliases need to be handled separately so an otherwise valid matrix does not fail during ID assignment.</violation>
<violation number="2" location="packages/core/src/internal/plan.ts:306">
P1: Two otherwise identical operations that use different environments are now rejected as duplicate operations, even though their emitted specs execute with different `env` values. `contextFor()` only hashes `command` and `args` beyond the name, so it needs to include the other execution-discriminating fields (such as `env`, image, working directory, and runtime policy) or retain another documented uniqueness discriminator before duplicate detection.</violation>
<violation number="3" location="packages/core/src/internal/plan.ts:354">
P2: A user alias that happens to equal an existing `op-` ID is silently resolved as the generated ID, so a `dependsOn` edge can point at the wrong operation. Since `spec.id` accepts arbitrary strings and aliases are now supported, detect this namespace collision and reject it (or introduce an unambiguous alias syntax) instead of giving generated IDs implicit precedence.</violation>
</file>
<file name="packages/ir/src/__tests__/core-consistency.test.ts">
<violation number="1" location="packages/ir/src/__tests__/core-consistency.test.ts:21">
P3: The cross-consistency test only asserts `core === ir`, so it guards against one copy drifting but cannot detect a correlative drift where both copies change identically (e.g., a shared change to the `op-` prefix or the hashing/canonicalization). Since ids.test.ts already validates the `op-` + 64-hex format for the ir copy, consider anchoring at least one Consistency test case to a golden expected hash (computed from ADR-006) — or asserting the format directly here — so a simultaneous regression in both packages is caught, not just divergence between them.</violation>
</file>
Tip: instead of fixing issues one by one fix them all with cubic
Re-trigger cubic
909e11f to
6eb38ac
Compare
6eb38ac to
c29c404
Compare
c29c404 to
f3f1bb3
Compare
f3f1bb3 to
62b3a48
Compare
62b3a48 to
9e01481
Compare
9e01481 to
861df23
Compare
861df23 to
0713582
Compare
b62958f to
6817dad
Compare
d31ef9d to
b11116b
Compare
de7531f to
77cbd9d
Compare
77cbd9d to
adb2275
Compare
adb2275 to
7e355f1
Compare
Core's assignId/assignIds used human-readable string derivation
(kind:name-or-command-or-index with collision counter) and passed
user spec.id through as-is, violating ADR-006. Now uses SHA-256
content-addressed ids: op-<64 hex> via node:crypto.createHash over
canonical JSON of {kind, name, context}, with spec.id folded into
hash context as userId.
- Created packages/core/src/internal/canonical.ts (computeOperationId)
- Rewrote packages/core/src/internal/ids.ts + plan.ts for SHA-256
- Exported computeOperationId from core public index.ts
- Fixed all tests to assert op-<64hex> format (90 core tests pass)
- Added cross-consistency test: core === ir computeOperationId (87 ir tests)
- Full monorepo: 16 projects test+typecheck+build green
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
… surrogates) and update runtime-modes expectations Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
7e355f1 to
fe92e6b
Compare
|



User description
Summary
packages/core/src/internal/canonical.tswithcomputeOperationId(SHA-256 via node:crypto.createHash)ids.ts+plan.ts: op-<64 hex> format, spec.id folded into hash context as userId (not used as-is)computeOperationIdfrom core public APIcomputeOperationId=== ircomputeOperationIdfor identical inputsTest plan
Stacked on #5
Generated with Devin
Summary by cubic
Switched core operation IDs to SHA‑256 content‑addressed IDs (
op-<64hex>) per ADR‑006, and unified ID/serialization primitives across@sverka/coreand@sverka/irfor consistent planning, execution, and compilation.New Features
@sverka/core: Deterministic IDs fromcomputeOperationId(kind, name, context)using canonical JSON (sorted keys, compact; objects omit undefined; arrays emit null for undefined; rejects NaN/Infinity/BigInt). Context includes matrix dims,userId(fromspec.id),command, andargs. True duplicates (same kind/name/context) fail. Legacy derived IDs and matrix suffix logic were removed. Public API exportscomputeOperationIdandcanonicalStringify.dependsOnstrings that reference either op IDs orspec.idaliases; duplicate or unknown aliases fail. Cycle detection runs on resolved op IDs.@sverka/ir: Re‑exportscanonicalStringifyandcomputeOperationIdfrom@sverka/core; added a cross‑package test to ensure identical op IDs.Migration
op-<64hex>; update any consumers expecting readable IDs or previous formatting.dependsOnmay reference op IDs orspec.idaliases; aliases must be unique and resolvable.computeOperationIdfrom@sverka/coreto recompute IDs;@sverka/coreand@sverka/irnow produce identical results.Written for commit fe92e6b. Summary will update on new commits.
CodeAnt-AI Description
Use stable content-based operation IDs across planning, execution, and compilation
What Changed
op-IDs generated from their content instead of readable command-based IDs or user IDs.dependsOncan reference either generated operation IDs or user-provided aliases; cycles and unresolved references are validated against the resolved IDs.Impact
✅ Stable operation IDs across planning and execution✅ Reliable matrix and dependency tracking✅ Consistent IDs between core and IR🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.