Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions .github/workflows/opencode-review-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -479,11 +479,11 @@ jobs:
- name: Prepare pull request merge tree for coverage measurement
env:
COVERAGE_SOURCE_ARCHIVE: ${{ runner.temp }}/opencode-coverage-artifact/opencode-coverage-source.tar
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/pr-head
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/opencode-coverage-${{ github.run_id }}-${{ github.run_attempt }}
run: |
set -euo pipefail
rm -rf "$COVERAGE_SOURCE_WORKDIR"
mkdir -p "$COVERAGE_SOURCE_WORKDIR"
# Each attempt owns a fresh tree; never delete another job's checkout.
mkdir "$COVERAGE_SOURCE_WORKDIR"
# The archive contains pull-request-controlled paths. Validate every
# member before extraction so a symlink, hardlink, device, FIFO, or
# traversal path cannot redirect a later trusted host-side parser.
Expand Down Expand Up @@ -533,7 +533,7 @@ jobs:
env:
PR_BASE_SHA: ${{ needs.validate-pr-metadata.outputs.base_sha }}
PR_HEAD_SHA: ${{ needs.validate-pr-metadata.outputs.head_sha }}
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/pr-head
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/opencode-coverage-${{ github.run_id }}-${{ github.run_attempt }}
# Dependency resolution may consume wheels/packages, but PR-defined
# install/build hooks are never executed implicitly.
UV_NO_BUILD: "1"
Expand Down Expand Up @@ -568,7 +568,7 @@ jobs:
- name: Enforce changed-file syntax gate
env:
PR_BASE_SHA: ${{ needs.validate-pr-metadata.outputs.base_sha }}
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/pr-head
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/opencode-coverage-${{ github.run_id }}-${{ github.run_attempt }}
run: |
set -euo pipefail
# Deterministic per-file syntax check on the PR's changed files. The
Expand Down Expand Up @@ -600,7 +600,7 @@ jobs:
env:
PR_BASE_SHA: ${{ needs.validate-pr-metadata.outputs.base_sha }}
PR_HEAD_SHA: ${{ needs.validate-pr-metadata.outputs.head_sha }}
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/pr-head
COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/opencode-coverage-${{ github.run_id }}-${{ github.run_attempt }}
# Apply wheel-only resolution in the same step that consumes
# pull-request dependency metadata. A value on an earlier step does
# not cross the GitHub Actions step boundary.
Expand Down
8 changes: 7 additions & 1 deletion tests/test_opencode_agent_contract.py
Original file line number Diff line number Diff line change
Expand Up @@ -568,7 +568,13 @@ def test_opencode_target_coverage_materializes_only_after_authorized_dispatch():
assert "GH_TOKEN:" not in measure_step
assert "ACTIONS_RUNTIME_TOKEN GH_TOKEN GITHUB_TOKEN" in measure_step
assert "secrets." not in measure_step
assert "COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/pr-head" in workflow
assert (
"COVERAGE_SOURCE_WORKDIR: ${{ runner.temp }}/opencode-coverage-"
"${{ github.run_id }}-${{ github.run_attempt }}" in workflow
)
prepare = workflow.split(" - name: Prepare pull request merge tree for coverage measurement", 1)[1].split(" - name:", 1)[0]
assert 'mkdir "$COVERAGE_SOURCE_WORKDIR"' in prepare
assert 'rm -rf "$COVERAGE_SOURCE_WORKDIR"' not in prepare
assert (
'python3 -I - "$COVERAGE_SOURCE_ARCHIVE" "$COVERAGE_SOURCE_WORKDIR"' in workflow
)
Expand Down
2 changes: 1 addition & 1 deletion tests/test_pr_review_autofix_nvidia_nim_contract.py
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
DOCTORING_RECORD = Path("docs/doctoring/hourly-nvidia-nim-autofix.md")
CHANGELOG = Path("CHANGELOG.md")
REVIEW_DISPATCH_WORKFLOW = Path(".github/workflows/opencode-review-dispatch.yml")
REVIEW_DISPATCH_BLOB_SHA = "a74d6eaf1a6c998b59d7db152cbb173bdfba7bf8"
REVIEW_DISPATCH_BLOB_SHA = "0ac2ec1fd69e60b228ac30b0b797403988d1a7ce"


def _workflow_text(path: Path) -> str:
Expand Down
Loading