fix(strix): accept a changed file named by its path suffix - #2500
seonghobae wants to merge 2 commits into
Conversation
#2474 required a completed PR report to contain the full repo-relative path of a changed file. Scanners routinely abbreviate a scoped file to its basename (`check_telemetry_ownership.py`), so #2357 failed closed with "Vulnerabilities 0" even though the report assessed exactly the changed files. Match any component-boundary suffix of the changed path instead, rejecting partial names such as `test_x.py` for `x.py` or `x.pyc`. Also bring the module to in-process coverage and add the missing `validate` docstring. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dnm2df79qqeCJtSxfttJxW
|
Warning Review limit reachedNext included review available in 41 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Keeps the new cases valid if #2492's placeholder check lands first. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dnm2df79qqeCJtSxfttJxW
|
Second independent reproduction, from contextual-orchestrator#1227 at head
This is local evidence from one job log, not hosted acceptance of this PR. |
Why
#2474 made a completed PR scan fail closed unless
penetration_test_report.mdcontains the full repo-relative path of a changed file. Scanners routinely abbreviate a scoped file to its basename. On #2357 (head4748a022), Strix reportedVulnerabilities 0, and its report text assessedcheck_telemetry_ownership.pyandopencode_repository_dispatch_targets.jsonby name. The gate still failed:(run 36393793492, job 108888653481)
The scope dir keeps the repo layout (
scope_root / relative_pathincopy_changed_file_into_scope), so the model could see the full path but shortened it. The contract rejects a report that names the right file, so this failure is not caused by #2357.What
names_changed_pathaccepts the full path or any component-boundary suffix of it (ci/x.py,x.py). It still rejects:test_x.py/i/x.py(the name continues past a path boundary)x.pyc(a longer extension)The full path is also accepted under an absolute scan root (
/workspace/scope/scripts/ci/x.py), which the old substring check allowed.The module is now at 100% in-process coverage. Before this PR it was exercised only through a subprocess and measured 0%.
validatealso gets the docstring it was missing.Relation to open PRs
Verification
pytest tests/test_strix_report_scope.py: 4 passed (fixtures already include the four finish-tool fields fix(strix): reject template reports and request PR source evidence #2492 will require);coverage report --include=scripts/ci/strix_report_scope.py: 100%interrogate scripts/ci/strix_report_scope.py: 100%bash scripts/ci/test_strix_quick_gate.sh: PASScoverage run -m pytest tests(measured before the fixture follow-up commit): 5096 passed. I did not use the local repo-wide TOTAL as evidence. CI reports coverage per module with--include, and my local environment is missing some fixtures (4 tests skipped).Follow-up (not in this PR)
run_strix_scanreturns 1 on a scope mismatch without trying another model, so one weak-model report fails the whole required check.🤖 Generated with Claude Code
https://claude.ai/code/session_01Dnm2df79qqeCJtSxfttJxW