Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 26 additions & 3 deletions .github/workflows/opencode-review-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -675,6 +675,20 @@ jobs:
"$coverage_build_dir/install-base-python-locks.py"
install -m 0755 "$trusted_vcs_import_root_resolver" \
"$coverage_build_dir/resolve-opencode-base-vcs-import-root.sh"
trusted_cargo_fixture="${GITHUB_WORKSPACE}/tests/fixtures/coverage-cargo"
if [ -L "$trusted_cargo_fixture" ] || [ -L "$trusted_cargo_fixture/src" ]; then
echo "::error::Trusted Cargo coverage fixture directories must not be symlinks."
exit 1
fi
for fixture_file in Cargo.toml Cargo.lock src/lib.rs; do
if [ ! -f "$trusted_cargo_fixture/$fixture_file" ] ||
[ -L "$trusted_cargo_fixture/$fixture_file" ]; then
echo "::error::Trusted Cargo coverage fixture is missing or not a regular file."
exit 1
fi
install -D -m 0644 "$trusted_cargo_fixture/$fixture_file" \
"$coverage_build_dir/coverage-cargo-fixtures/$fixture_file"
done
python_change_files="${RUNNER_TEMP}/opencode-python-change-files"
if ! git -C "$COVERAGE_SOURCE_WORKDIR" diff \
--name-only --diff-filter=ACMRTUXBD -z "$PR_BASE_SHA" HEAD \
Expand Down Expand Up @@ -783,6 +797,11 @@ jobs:
vulkan-tools \
xz-utils \
&& rm -rf /var/lib/apt/lists/*
COPY coverage-cargo-fixtures /tmp/coverage-cargo-fixtures
RUN CARGO_HOME=/opt/coverage-cargo-home cargo fetch --locked \
--manifest-path /tmp/coverage-cargo-fixtures/Cargo.toml \
&& rm -rf /tmp/coverage-cargo-fixtures \
&& chmod -R a+rX /opt/coverage-cargo-home
ENV LLVM_COV=/usr/bin/llvm-cov-19
ENV LLVM_PROFDATA=/usr/bin/llvm-profdata-19
ENV COREPACK_HOME=/opt/corepack
Expand Down Expand Up @@ -973,19 +992,23 @@ jobs:
chown -R root:root /work/.git
chmod -R go-w /work/.git
fi
rm -rf -- /work/.opencode-sandbox-home
mkdir -p "$RUNNER_TEMP" /work/.opencode-sandbox-home /work/.opencode-sandbox-cache
chown "$OPENCODE_SANDBOX_UID:$OPENCODE_SANDBOX_GID" /work/.opencode-sandbox-home /work/.opencode-sandbox-cache
# `run_and_capture`/`run_and_capture_advisory` below pin CARGO_HOME to
# /work/.opencode-sandbox-home/.cargo, which lives on the mutable /work bind mount, not
# the read-only image -- so the baked offline vendor config from
# /opt/base-rust-dependencies (see materialize_base_rust_dependencies.py) has to be
# copied there explicitly rather than set as an image ENV default.
mkdir -p /work/.opencode-sandbox-home/.cargo
cp -a /opt/coverage-cargo-home/. /work/.opencode-sandbox-home/.cargo/
if [ -s /opt/base-rust-dependencies/cargo-config.toml ]; then
mkdir -p /work/.opencode-sandbox-home/.cargo
install -m 0444 /opt/base-rust-dependencies/cargo-config.toml \
install -m 0644 /opt/base-rust-dependencies/cargo-config.toml \
/work/.opencode-sandbox-home/.cargo/config.toml
chown -R "$OPENCODE_SANDBOX_UID:$OPENCODE_SANDBOX_GID" /work/.opencode-sandbox-home/.cargo
fi
printf '\n[net]\noffline = true\n' >>/work/.opencode-sandbox-home/.cargo/config.toml
chmod 0444 /work/.opencode-sandbox-home/.cargo/config.toml
chown -R "$OPENCODE_SANDBOX_UID:$OPENCODE_SANDBOX_GID" /work/.opencode-sandbox-home/.cargo
chmod 0700 "$RUNNER_TEMP"
: >"$GITHUB_OUTPUT"
chmod 0600 "$GITHUB_OUTPUT"
Expand Down
55 changes: 55 additions & 0 deletions docs/doctoring/opencode-coverage-cargo-fixtures-20260928.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# OpenCode coverage Cargo fixture intake (2026-09-28)

## Incident

The current-head `.github#1026` OpenCode dispatch run `36348910783`, job
`108722448709`, reached the isolated coverage sandbox. Its full suite reported
four failures in `test_materialize_base_rust_dependencies.py` and
`test_maturin_offline_build_contract.py`, each before the tested behavior at
`cargo generate-lockfile` (3,538 passed, 4 failed, 4 skipped). The PR does not
change either test file. Both files construct registry-backed crates (`itoa`,
`ryu`, and PyO3) during the test, while the sandbox runs with `--network=none`
and its base-repository Rust materializer finds no Cargo lock in this PR's
validated base tree.

With a fresh `CARGO_HOME` and `CARGO_NET_OFFLINE=true`, the two representative
tests failed at the same command. A direct `cargo generate-lockfile` on the
`itoa` fixture reported `no matching package named itoa found` in the offline
crates.io index. This establishes missing registry fixture input, rather than
a product-code assertion failure. The original hosted test helper captures
Cargo stderr, so the hosted log alone does not identify the missing crate.

## Repair and trust boundary

A trusted, lockfile-pinned fixture manifest covers the three registry crates
used by these tests. The networked coverage image build fetches that exact
closure with `cargo fetch --locked`. The PR tree never enters that build
context. The later untrusted test container still has `--network=none` and
receives only the trusted image's cached registry artifacts, copied into its
isolated `CARGO_HOME` after removing any PR-supplied sandbox home. Its trusted
Cargo config enables offline registry resolution, so a lockfile generated by a
test cannot attempt an index refresh against the disconnected network. Tests
that intentionally create a separate Cargo home can still resolve local Git
fixtures before their own offline build step. Existing base-repository Rust
vendor configuration and the sandbox's credentials and network restrictions
remain in force.

The image build fails if the trusted fixture files are absent, symbolic links,
or cannot be fetched against their checksummed lock. It does not turn a failed
test into a pass.

## Verification boundary

An initial PyO3 extension build exceeded its 600-second limit on a loaded
macOS host. A later run with the project-local pinned maturin completed that
test in 32 seconds. With a fresh `CARGO_HOME` populated only by the locked
fixture and its trusted offline config, the complete two-file Rust dependency
and PyO3 suite passed all 29 tests with `GITHUB_ACTIONS=true`. The first
attempt at global `CARGO_NET_OFFLINE=true` failed one local Git dependency
fixture; scoping offline resolution to the default trusted Cargo home fixed
that failure. A terminal hosted rerun is still required before claiming the
coverage gate repaired. The targeted workflow contract suite passed 77 tests
with `GITHUB_ACTIONS=true` after this change.
The fixture crate's own `cargo llvm-cov --all-features --fail-under-lines 100`
run passed locally with one test and 100% line coverage, exercising its cached
`itoa` and `ryu` dependencies.
194 changes: 194 additions & 0 deletions tests/fixtures/coverage-cargo/Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

9 changes: 9 additions & 0 deletions tests/fixtures/coverage-cargo/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
[package]
name = "coverage-cargo-fixtures"
version = "0.0.0"
edition = "2021"

[dependencies]
itoa = "=1.0.15"
ryu = "=1.0.20"
pyo3 = { version = "=0.22.6", features = ["extension-module", "abi3-py310"] }
13 changes: 13 additions & 0 deletions tests/fixtures/coverage-cargo/src/lib.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
pub fn fixture() -> String {
let mut integer = itoa::Buffer::new();
let mut float = ryu::Buffer::new();
format!("{}:{}", integer.format(42), float.format(1.5))
}

#[cfg(test)]
mod tests {
#[test]
fn cached_formatters_link() {
assert_eq!(super::fixture(), "42:1.5");
}
}
5 changes: 5 additions & 0 deletions tests/test_opencode_agent_contract.py
Original file line number Diff line number Diff line change
Expand Up @@ -841,6 +841,11 @@ def test_opencode_target_coverage_materializes_only_after_authorized_dispatch():
in measure_step
)
assert "CARGO_HOME=/work/.opencode-sandbox-home/.cargo" in measure_step
assert "printf '\\n[net]\\noffline = true\\n' >>/work/.opencode-sandbox-home/.cargo/config.toml" in measure_step
assert "CARGO_NET_OFFLINE=true \\" not in measure_step
assert measure_step.index('rm -rf -- /work/.opencode-sandbox-home') < measure_step.index(
'cp -a /opt/coverage-cargo-home/. /work/.opencode-sandbox-home/.cargo/'
)
assert "docker run --rm --init --network=none" in measure_step
sandbox_runtime = measure_step.split(
" export OPENCODE_SANDBOX_UID=65532", 1
Expand Down
2 changes: 1 addition & 1 deletion tests/test_pr_review_autofix_nvidia_nim_contract.py
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
DOCTORING_RECORD = Path("docs/doctoring/hourly-nvidia-nim-autofix.md")
CHANGELOG = Path("CHANGELOG.md")
REVIEW_DISPATCH_WORKFLOW = Path(".github/workflows/opencode-review-dispatch.yml")
REVIEW_DISPATCH_BLOB_SHA = "0ac2ec1fd69e60b228ac30b0b797403988d1a7ce"
REVIEW_DISPATCH_BLOB_SHA = "58f11efc9072e35db6ec6365630db9f97d16f652"


def _workflow_text(path: Path) -> str:
Expand Down
Loading