fix(dispatch): skip stale dispatches for closed PRs or superseded heads - #2382
seonghobae wants to merge 27 commits into
Conversation
Semgrep OSS and Bandit B310 Medium alerts on main flagged dynamic urllib use in CodeQL identity and Strix evidence helpers. Fail closed unless the URL is https://api.github.com so file:// and arbitrary hosts cannot reach urlopen. Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.0 to 4.14.2. - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.14.0...4.14.2) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Replace retired urllib urlopen monkeypatches with direct CodeQL and Strix dedicated-opener patches. Remove the PR-specific global conftest bridge so both security helpers exercise the same explicit transport boundary without live network access.
Clears Bandit/Semgrep B310 on shared scripts/ci urlopen so the anyio bump is not blocked by unrelated SAST.
Restore the unrelated #2269 URL-opener paths to protected main while retaining the AnyIO 4.14.2 pin and hashes. The URL/redirect responsibility remains in canonical #2279; this PR owns only the dependency security update. Validated with 56 focused tests, 3,335 full tests plus 28 skipped/40 subtests, warnings-as-errors, diff check, and pip-audit reporting no known vulnerabilities.
Remove the unused queue-health collector and CLI, validate run IDs at the shared parsing boundary, and exercise document-reader and scheduler edge cases. The main baseline failed the 100% gate before PR #2358.
…tead of failures
A dispatch whose target PR is closed, or whose live head has moved strictly
past the dispatched head, ends validate with a ::notice:: and stale=true;
later jobs are gated on that output so the run concludes success.
A head mismatch alone is not treated as stale: GitHub can briefly serve the
previous head right after a push. Retirement requires the compare API
(repos/{target}/compare/{dispatched}...{live}) to answer status "ahead" with
behind_by 0 and ahead_by >= 1. Behind (API lag), diverged (force-push), or a
failed/malformed compare keeps the original fail-closed head_sha mismatch.
The OpenCode side keeps its EVENT_NAME == repository_dispatch guard because
its authorization and supplied-head binding are nested under that check;
CodeQL triggers only on repository_dispatch and authorizes unconditionally,
so it needs no guard. Tests pin both premises. Draft PRs are not stale.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (20)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughCodeQL과 OpenCode dispatch 검증이 닫힌 PR 또는 compare API로 확인된 후속 head를 stale로 표시합니다. stale dispatch에서는 관련 scan, coverage 및 review 작업을 건너뜁니다. CodeQL은 분석 읽기 권한이 있는 인증 정보를 선택합니다. Queue-health 코드, coverage 이미지 입력, Strix 의존성 및 계약 테스트도 갱신합니다. ChangesStale dispatch 처리 및 CodeQL 인증
OpenCode coverage 이미지 입력
Actions queue-health 수집 코드
Strix CI 의존성 갱신
기타 계약 및 문서 테스트 갱신
Priority: ⬇️ Low Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant Dispatch
participant ValidateDispatch
participant GitHubCompareAPI
participant Scan
participant CredentialProbe
participant GHASIdentityCheck
Dispatch->>ValidateDispatch: PR 메타데이터 전달
ValidateDispatch->>GitHubCompareAPI: head 불일치 시 SHA 비교
GitHubCompareAPI-->>ValidateDispatch: compare 결과 반환
ValidateDispatch-->>Scan: stale가 아니면 scan 실행
Scan->>CredentialProbe: SARIF gate 통과 후 분석 읽기 권한 확인
CredentialProbe-->>GHASIdentityCheck: 확인된 인증 정보 전달
Merge Risk: ⚪ Minimal · up to No actionable issue remains from this review. Merge after the required exact-head hosted checks pass. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The dispatch paths now skip only closed PRs or heads proven superseded, while other mismatches continue through validation. No introduced security finding was established. Some upstream authorization and deployment details remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 77.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 66 functions across 16 files. (6 skipped: 6 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
- Select a target-scoped credential that can actually read code-scanning analyses before the GHAS base/head configuration identity check, instead of the first non-empty token (the OpenCode app token returns 403). Ported from #2275. - Replace the set-membership URL assertion flagged by CodeQL py/incomplete-url-substring-sanitization with an issubset check. Ported from #2351.
Preserve #2385, #2359, and #2286 as explicit parents while composing their byte-identical overlapping locks and endpoint contract. This creates one exact-head bootstrap stack for the coverage-image, 100% coverage, AnyIO audit, and CodeQL dispatch failures without force-push, rebase, or delta disposal.
seonghobae
left a comment
There was a problem hiding this comment.
P1 dependency / single-writer repair — current exact head 3d0352198303ad055e751f1f5580313a687a2638 cannot be accepted on protected main@e6334e22….
Exact-log RCA for Python Security run 36220837176, job 108362326873, shows the hard gate audited requirements-strix-ci-hashes.txt and found AnyIO 4.14.0 vulnerable to CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349; all require 4.14.2. This is a real dependency finding, not queue saturation or transport failure.
Canonical lock/source repair already exists in #2385@8e1aba9c: it adds anyio==4.14.2 to the source requirements, updates the hashed lock, and pins source↔lock parity. Do not copy a second lock repair here. The heads are diverged at main@e6334e22…: this PR is ahead 1 / behind 25 relative to #2385, and both modify .github/workflows/opencode-review-dispatch.yml.
Required order: settle #2385 first, then ordinary/non-force restack this branch on its accepted head while preserving only the unique stale-dispatch retirement delta and reconciling the shared OpenCode workflow. Re-run every exact-head gate after reconciliation; predecessor receipts do not transfer. Runtime Quality 36220837157, SAST 36220837165, and Security 36220837182 passed, but Python Security failed and CodeQL 36220837170 remains queued. Ready is review admission only; no merge, auto-merge, bypass, synthetic status, or blind rerun is authorized.
|
Exact-head admission correction for Exact-head Python Security run The PR stays open with its complete delta and review evidence preserved. Draft is Proposed/not merge-admissible, not completion. No rerun, bypass, synthetic status, force update, review dismissal, or Close is performed. |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head/base dependency finding for 3d0352198303ad055e751f1f5580313a687a2638.
Canonical foundation parent #2385 is still open at 8e1aba9ce1d52acb36f095da32511da06958733f. A direct base retarget was tested and GitHub reported the child unmergeable. The cause is concrete three-path ownership overlap:
.github/workflows/codeql-scan-dispatch.yml.github/workflows/opencode-review-dispatch.ymltests/test_pr_review_autofix_nvidia_nim_contract.py
The child’s six-path stale-dispatch delta remains preserved: the base was restored to protected main@e6334e229581a918e2f22de18733b76fa65d7e71, the head was never moved or rewritten, and GitHub recomputed the PR as mergeable on that original base. Pre-parent Checks cannot be used as post-convergence evidence.
Required order: settle #2385 normally; then create an ordinary non-force successor/restack that resolves the three overlapping paths while preserving both the foundation and stale-dispatch contracts; finally acquire fresh exact-head/base Checks and independent review. Do not force-push, drop the child delta, or treat #2385 evidence as inherited passing proof.
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/codeql-scan-dispatch.yml— GitHub Actions review job.github/workflows/opencode-review-dispatch.yml— GitHub Actions review jobCHANGELOG.d/20260926-dispatch-stale-head-skip.md— repository behaviortests/test_codeql_scan_dispatch_workflow_contract.py— regression suitetests/test_opencode_review_dispatch_stale_skip.py— regression suitetests/test_pr_review_autofix_nvidia_nim_contract.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
S3 --> I3["repository behavior"]
I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
R3 --> V3["required checks"]
Evidence --> S4["Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
3d0352198303ad055e751f1f5580313a687a2638 - Workflow run: 36234093075
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
S3 --> I3["repository behavior"]
I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
R3 --> V3["required checks"]
Evidence --> S4["Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
Ordinary-forward integrates PR #2385 into draft PR #2382 so the canonical Noema coverage build-context repair and the stale-dispatch retirement remain one reviewable lineage. The only textual conflict was the workflow blob identity contract; it is pinned to the computed merged workflow blob b22750e.
|
Ordinary-forward convergence evidence for exact head
The PR remains Draft / Proposed. No Force Push, destructive rebase, rerun, self-approval, bypass, or merge was used. |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for d9e31329e2e0361e904aef3072984ec1b4e076cd (COMMENT, not approval).
The ordinary-forward successor preserves canonical #2385 exact 8e1aba9c… and leaves only the six stale-dispatch paths as the effective delta: ahead 2 / behind 0. The two dispatch validators retire only a closed PR or a head mismatch proven by GitHub compare as ahead with behind_by: 0 and ahead_by >= 1; API lag (behind), force-push divergence, contradictory/malformed compare evidence, lookup failure, unauthorized sender, and other identity mismatches remain fail closed. Current exact remote verification: Python AST 3/3, workflow YAML 2/2, and bash -n for both changed validation shell blocks 2/2.
The prior OpenCode CHANGES_REQUESTED review is anchored to predecessor 3d035219… / run 36234093075 and explicitly reports no source-backed product finding; it is stale after the non-force #2385 convergence. Dismissing it does not satisfy coverage, hosted Checks, or independent approval. Current exact Runtime Quality, Security, Python Security, SAST, and CodeQL runs remain queued, so this PR stays Draft/Proposed and is not merge-authorized.
Dismissed as stale exact-head evidence after ordinary-forward convergence. This review is anchored to predecessor 3d03521 / run 36234093075 and explicitly states that no source-backed product finding was synthesized. Current exact d9e3132 has a fresh COMMENT review; queued hosted Checks, coverage, and independent approval remain mandatory.
|
Ready / Proposed admission correction for unchanged exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/codeql-scan-dispatch.yml— GitHub Actions review job.github/workflows/opencode-review-dispatch.yml— GitHub Actions review jobCHANGELOG.d/20260926-dispatch-stale-head-skip.md— repository behaviorCHANGELOG.md— repository behaviordocs/product-technical-gap-baseline.md— operator or user guidancerequirements-strix-ci-hashes.txt— repository behaviorrequirements-strix-ci.txt— repository behaviorscripts/ci/actions_queue_health.py— review and security gate shell pathscripts/ci/actions_queue_health_core.py— review and security gate shell pathtests/test_actions_queue_health_cancelled_before_runner.py— regression suitetests/test_actions_queue_health_post_evidence_retry.py— regression suitetests/test_actions_queue_health_snapshot_consistency.py— regression suitetests/test_actions_queue_health_terminal_preexecution.py— regression suitetests/test_codeql_scan_dispatch_ghas_credential_contract.py— regression suitetests/test_codeql_scan_dispatch_workflow_contract.py— regression suitetests/test_noema_document_review_context.py— regression suitetests/test_noema_review_document_boundaries.py— regression suitetests/test_opencode_agent_contract.py— regression suitetests/test_opencode_review_dispatch_stale_skip.py— regression suitetests/test_organization_commercial_readiness_loop_receipt_contract.py— regression suitetests/test_pr_review_autofix_nvidia_nim_contract.py— regression suitetests/test_pr_review_merge_scheduler.py— regression suitetests/test_strix_runtime_dependencies.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
S3 --> I3["repository behavior"]
I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
R3 --> V3["required checks"]
Evidence --> S4["Repository file: CHANGELOG.md"]
S4 --> I4["repository behavior"]
I4 --> R4["Review risk: Repository file: CHANGELOG.md"]
R4 --> V4["required checks"]
Evidence --> S5["Docs: product-technical-gap-baseline.md"]
S5 --> I5["operator or user guidance"]
I5 --> R5["Review risk: Docs: product-technical-gap-baseline.md"]
R5 --> V5["docs review"]
Evidence --> S6["Repository file: requirements-strix-ci-hashes.txt"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: requirements-strix-ci-hashes.txt"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: requirements-strix-ci.txt"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: requirements-strix-ci.txt"]
R7 --> V7["required checks"]
Evidence --> S8["CI script: actions_queue_health.py"]
S8 --> I8["review and security gate shell path"]
I8 --> R8["Review risk: CI script: actions_queue_health.py"]
R8 --> V8["bash -n plus Strix self-test"]
Evidence --> S9["CI script: actions_queue_health_core.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: actions_queue_health_core.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
R10 --> V10["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
d9e31329e2e0361e904aef3072984ec1b4e076cd - Workflow run: 36308944761
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
S3 --> I3["repository behavior"]
I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
R3 --> V3["required checks"]
Evidence --> S4["Repository file: CHANGELOG.md"]
S4 --> I4["repository behavior"]
I4 --> R4["Review risk: Repository file: CHANGELOG.md"]
R4 --> V4["required checks"]
Evidence --> S5["Docs: product-technical-gap-baseline.md"]
S5 --> I5["operator or user guidance"]
I5 --> R5["Review risk: Docs: product-technical-gap-baseline.md"]
R5 --> V5["docs review"]
Evidence --> S6["Repository file: requirements-strix-ci-hashes.txt"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: requirements-strix-ci-hashes.txt"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: requirements-strix-ci.txt"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: requirements-strix-ci.txt"]
R7 --> V7["required checks"]
Evidence --> S8["CI script: actions_queue_health.py"]
S8 --> I8["review and security gate shell path"]
I8 --> R8["Review risk: CI script: actions_queue_health.py"]
R8 --> V8["bash -n plus Strix self-test"]
Evidence --> S9["CI script: actions_queue_health_core.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: actions_queue_health_core.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
R10 --> V10["targeted test run"]
|
Exact-head admission correction — Ready is review admission only. Fresh audit against base
This PR is moved to Draft/Proposed until the causal owner repair is present on a successor exact head and re-audited. Queued/pending work is neither an additional blocker nor passing evidence. No Close, force push, destructive rebase, manual rerun, synthetic status/approval, merge, auto-merge, or bypass was performed. |
Status
Ready / Proposed. Ordinary-forward convergence at exact head
d9e31329e2e0361e904aef3072984ec1b4e076cdis review-admissible; fresh exact-head Checks and independent approval remain merge gates, not Ready prerequisites.Stack
main@e6334e229581a918e2f22de18733b76fa65d7e713d0352198303ad055e751f1f5580313a687a26388e1aba9ce1d52acb36f095da32511da06958733f1e07dc0fd4b4b676931834d25059a6c0a889b8e6tests/test_pr_review_autofix_nvidia_nim_contract.py; its immutable workflow identity is recomputed from the merged OpenCode workflow blobb22750e16ca5bb4765436d7bd4479e6591d59052.Summary
aheadwithbehind_by0), now exits with a notice instead of failing.EVENT_NAMEasymmetry between the CodeQL and OpenCode dispatch workflows is intentional.Validation
541 passed, 2 skipped.3402 passed, 28 skipped, 40 subtests passed.cargo, so 25 Rust materializer tests skip and the report is 99%; hosted exact-head evidence must settle that environment.python -m interrogateis unavailable in this runner; hosted Runtime Quality remains authoritative.compileall, staged/unstagedgit diff --check, merge-parent identity, and six-path successor delta checks passed.Note
Open PR #2363 also edits
opencode-review-dispatch.ymland its pinned hash, so whichever of the two merges second needs a rebase.Summary by CodeRabbit