chore(autofix): reconcile protected main into #2170 - #2199
Conversation
…2194) Let a repository declare literal path prefixes in .github/edge-policy-artifact-paths.txt that hold research/data artifacts (SPSS .sav, serialized model objects, numeric arrays, ...) not shaped like documentation, and admit binary content there on the same evidence terms documentation paths already get. Security property: evaluate_pull_request now threads an optional base_ref and resolves the declaration only from that ref, never the pull-request head, so a PR cannot self-authorize admission of its own binary by adding or widening the declaration in the same diff. A new test proves the same-PR case is refused. .github/workflows/opencode- review.yml threads the pull_request_target event's already-available github.event.pull_request.base.sha with no new permissions. Suffix decision: a declared-prefix file whose suffix has no BINARY_DOCUMENT_MAGIC entry (most research formats) is admitted only on "no diff patch + fetched bytes are not valid UTF-8" evidence, so a file that decodes as valid UTF-8 is always still content-scanned. Runtime-named files (_runtime_path_rule) stay rejected inside a declared prefix exactly as inside docs/ today. Declaration parsing is bounded (64 entries, 8-segment depth) and rejects absolute paths, ".." traversal, and globs with a PolicyError naming the offending entry; a missing declaration file behaves identically to before this feature existed. pingora_edge_policy.py stays at 100% branch coverage and 100% interrogate docstring coverage. Refs #2193, #2149, #2116. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
c346b83
into
test/autofix-required-opencode-coverage-rca
There was a problem hiding this comment.
🟡 Large declared artifacts remain unmergeable
When a declared non-PDF artifact exceeds 1 MiB, _binary_documentation_evidence_confirms rejects its exemption without reading it. The subsequent text fetch raises the same size error, so legitimate large research artifacts block every pull request.
(Refers to this code)
Learn more
The declared-path feature fetches artifact bytes through _load_raw_file_bytes, whose Contents API contract caps inline data at 1 MiB. ContentSizeExceededError currently exempts only PDFs, so declared .sav, .rds, and .npz files above that cap fall through and fail on the identical fetch. This contradicts the feature's admission contract for declared research artifacts.
Example: A base declaration contains local, and a pull request adds local/model.rds with a 4 MiB blob and no patch. The first fetch raises ContentSizeExceededError; the fallback returns false because the suffix is not .pdf; the second fetch raises again instead of admitting or evaluating the artifact.
Recommended fix: Add a bounded large-blob evidence path for declared artifacts, such as GitHub's raw/blob endpoint with an explicit maximum and streamed byte limit. Apply the non-UTF-8 test to those fetched bytes. Do not trust size and path alone unless the policy explicitly accepts that weaker evidence.
Was this helpful? React with 👍 or 👎 to provide feedback.
| if isinstance(exc, HTTPError) and exc.code == 404: | ||
| raise ArtifactDeclarationNotFoundError( | ||
| f"GitHub API reported no resource for policy evidence at {url}" | ||
| ) from exc |
There was a problem hiding this comment.
🟥 Runtime evidence 404s use declaration exemption
A 404 for any requested content becomes ArtifactDeclarationNotFoundError, although only the base declaration is optional. Callers can misclassify missing runtime evidence as an absent declaration and bypass fail-closed handling.
Was this helpful? React with 👍 or 👎 to provide feedback.
Ordinary non-force reconciliation of protected
main@91be6442906c7b6b4f600272c953699708394327into canonical Required OpenCode coverage-RCA ownertest/autofix-required-opencode-coverage-rca. Preserve #2170's causal scheduler/full-suite dependency delta. No predecessor checks/reviews transfer; #2170 must reacquire exact-head acceptance after merge.