reviewer-bot: workflow_dispatch reads default-branch code for explore tools (set REVIEW_CONTENT_ROOT)
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 84/100
Direzione di ricerca
Inizia da reviewer-bot.yml e ispeziona il percorso workflow_dispatch insieme al comportamento di _content_root() in review_bot/run_review.py. Verifica come viene ottenuto HEAD_SHA e come dovrebbero essere collegati il checkout separato e REVIEW_CONTENT_ROOT senza modificare il checkout primario considerato attendibile. Il lavoro è completato quando il dispatch manuale esplora l'head della PR mentre il comportamento di pull_request rimane invariato.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Follow-up from PR #862 review (thread on reviewer-bot.yml).
Problem
On the workflow_dispatch (manual) trigger, reviewer-bot.yml does a single actions/checkout with no ref:, which resolves to the default branch — not the PR being reviewed. The PR head is resolved separately (HEAD_SHA = gh pr view ... --json headRefOid).
Result:
- The review diff and comment anchors are correct — the engine fetches them from the GitHub compare API keyed on
HEAD_SHA(repos/{repo}/compare/...), independent of the checkout. - But the agent's explore tools (
read_paths/grep) read from the engine's_content_root(), which falls back to the primary checkout (= default branch on dispatch) whenREVIEW_CONTENT_ROOTis unset. So on manual dispatch, the agent explores default-branch code, not the PR head.
The automatic pull_request trigger (the normal case) is unaffected — its checkout already is the PR merge ref.
Why the engine expects this
Per reviewer_bot/run_review.py _content_root(), workflow_dispatch is meant to check the PR head into a separate directory and export its path as REVIEW_CONTENT_ROOT, while engine code keeps running from the trusted default-branch checkout. This is a deliberate security boundary: dispatch is exempt from the fork guard, so the PR's own code must not run/read from the primary checkout dir.
Fix
On the dispatch path, add a second checkout of HEAD_SHA into a separate dir and export REVIEW_CONTENT_ROOT pointing at it (mirroring the engine's documented pattern).
Severity
Low — only manual dispatch is affected, and only the explore-tool reads (diff/anchors are always correct). Deferred from #862 as a follow-up.
- Lingua principale
- Python
- Stelle
- 233
- Fork
- 152
- Merge medio
- 21h 5m
- PR unite (30g)
- 10
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di databricks/databricks-sql-python
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
engineer-bot
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
databricks/databricks-sql-python#860 · 3 commenti ·
Tutte le issue di databricks/databricks-sql-python
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
PolicyEngine/policyengine-us#9559 ·
-
priority: p3
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
googleapis/librarian#7636 ·
-
from:qa priority:P2 reliability tech-debt
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
spec-kitty/spec-kitty#4874 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100