Repository navigation
fix(release): retain Binding RC evidence without brace globs - #316
Conversation
upload-artifact does not expand bash brace patterns, so the evidence partition upload found zero files after a green offline rehearsal. List evidence/ and node-addons/ explicitly. Co-authored-by: Cursor <cursoragent@cursor.com>
WalkthroughThe CI storage policy test now parses multiline YAML block-scalar fields and validates artifact upload paths using multiline evidence and node-addon directory values. ChangesStorage policy validation
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/ci/test-ci-storage-policy.py`:
- Around line 135-145: Update the scalar handling in the policy parser around
the value check to reject folded YAML scalars ("?>" and ">-") unless their YAML
folding semantics are correctly implemented; preferably restrict accepted
artifact path blocks to literal styles "|" and "|-". Preserve the existing
collection behavior for supported literal scalars and add or update tests to
cover rejection of folded styles.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 36d1ca8a-fe91-480d-a39f-8483025b3706
⛔ Files ignored due to path filters (3)
.github/workflows/binding-release-candidate.ymlis excluded by!**/.github/**CHANGELOG.mdis excluded by!**/*.mddocs/reference/changelog.mdis excluded by!**/*.md,!**/docs/**
📒 Files selected for processing (1)
scripts/ci/test-ci-storage-policy.py
| if value in {"|", "|-", ">", ">-"}: | ||
| indent = len(line) - len(line.lstrip()) | ||
| collected: list[str] = [] | ||
| for follow in step[index + 1 :]: | ||
| if not follow.strip(): | ||
| continue | ||
| follow_indent = len(follow) - len(follow.lstrip()) | ||
| if follow_indent <= indent: | ||
| break | ||
| collected.append(follow.strip()) | ||
| matched = "\n".join(collected) |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
while IFS= read -r file; do
rg -n -C 4 '^[[:space:]-]*(path|pattern|name):[[:space:]]*>-?[[:space:]]*$' "$file" || true
done < <(fd -t f -e yml -e yaml .)Repository: CurateLabs/graphforge
Length of output: 211
🏁 Script executed:
set -euo pipefail
printf '%s\n' '--- target context ---'
sed -n '100,175p' scripts/ci/test-ci-storage-policy.py
printf '%s\n' '--- YAML files ---'
git ls-files '*.yml' '*.yaml' | sort
printf '%s\n' '--- folded scalar candidates ---'
while IFS= read -r file; do
grep -n -E '^[[:space:]-]*(path|pattern|name):[[:space:]]*>-?[[:space:]]*$' "$file" || true
done < <(git ls-files '*.yml' '*.yaml')
printf '%s\n' '--- parser references ---'
grep -n -E 'def field|field\(|artifact|upload-artifact|path:' scripts/ci/test-ci-storage-policy.pyRepository: CurateLabs/graphforge
Length of output: 6465
🏁 Script executed:
set -euo pipefail
sed -n '135,230p' scripts/ci/test-ci-storage-policy.py
git ls-files '*.yml' '*.yaml' > /tmp/graphforge-yaml-files
printf '%s\n' '--- folded scalar candidates ---'
while IFS= read -r file; do
grep -n -E '^[[:space:]-]*(path|pattern|name):[[:space:]]*>-?[[:space:]]*$' "$file" || true
done < /tmp/graphforge-yaml-files
printf '%s\n' '--- artifact path declarations ---'
while IFS= read -r file; do
grep -n -E '^[[:space:]-]*path:' "$file" || true
done < /tmp/graphforge-yaml-files
printf '%s\n' '--- tests and callers ---'
grep -RIn -E 'artifact_contracts|def field|field\(' -- scripts tests 2>/dev/null | head -200 || trueRepository: CurateLabs/graphforge
Length of output: 15161
🏁 Script executed:
set -euo pipefail
printf '%s\n' '--- relevant workflow block ---'
sed -n '600,640p' .github/workflows/m1-release-certification.yml
printf '%s\n' '--- literal and folded path scalar headers in workflows ---'
git ls-files '.github/workflows/*.yml' '.github/workflows/*.yaml' > /tmp/graphforge-workflows
while IFS= read -r file; do
grep -n -E '^[[:space:]-]*path:[[:space:]]*[|>][-+]?[[:space:]]*$' "$file" || true
done < /tmp/graphforge-workflows
printf '%s\n' '--- behavioral probe for the exact field logic ---'
python3 - <<'PY'
def field(step: list[str], name: str) -> str | None:
matched: str | None = None
for index, line in enumerate(step):
stripped = line.strip().removeprefix("- ")
if not stripped.startswith(name + ":"):
continue
value = stripped.split(":", 1)[1].strip().strip("'\"")
if value in {"|", "|-", ">", ">-"}:
indent = len(line) - len(line.lstrip())
collected: list[str] = []
for follow in step[index + 1:]:
if not follow.strip():
continue
follow_indent = len(follow) - len(follow.lstrip())
if follow_indent <= indent:
break
collected.append(follow.strip())
matched = "\n".join(collected)
else:
matched = value
return matched
for indicator in ("|", "|-", ">", ">-"):
step = [
" - uses: actions/upload-artifact@v7",
f" path: {indicator}",
" candidate/release-artifacts/evidence/",
" candidate/release-artifacts/node-addons/",
]
print(indicator, repr(field(step, "path")))
PYRepository: CurateLabs/graphforge
Length of output: 640
🏁 Script executed:
set -euo pipefail
printf '%s\n' '--- workflow files with literal path blocks ---'
git ls-files '.github/workflows/*.yml' '.github/workflows/*.yaml' | while IFS= read -r file; do
grep -Hn -E '^[[:space:]-]*path:[[:space:]]*[|>][-+]?[[:space:]]*$' "$file" || true
done
printf '%s\n' '--- relevant literal block context ---'
git grep -n -A5 -B2 -E '^[[:space:]-]*path:[[:space:]]*\|[-+]?[[:space:]]*$' -- '.github/workflows/*.yml' '.github/workflows/*.yaml' | head -120
printf '%s\n' '--- behavioral probe for the exact field logic ---'
python3 - <<'PY'
def field(step, name):
matched = None
for index, line in enumerate(step):
stripped = line.strip().removeprefix("- ")
if not stripped.startswith(name + ":"):
continue
value = stripped.split(":", 1)[1].strip().strip("'\"")
if value in {"|", "|-", ">", ">-"}:
indent = len(line) - len(line.lstrip())
collected = []
for follow in step[index + 1:]:
if not follow.strip():
continue
follow_indent = len(follow) - len(follow.lstrip())
if follow_indent <= indent:
break
collected.append(follow.strip())
matched = "\n".join(collected)
else:
matched = value
return matched
for indicator in ("|", "|-", ">", ">-"):
step = [
" - uses: actions/upload-artifact@v7",
" path: " + indicator,
" candidate/release-artifacts/evidence/",
" candidate/release-artifacts/node-addons/",
]
print(indicator, repr(field(step, "path")))
PYRepository: CurateLabs/graphforge
Length of output: 5795
Do not accept folded scalars without parsing their semantics.
field accepts > and >-, but joins content with \n. YAML folds ordinary lines to spaces. A future upload-artifact path: >- block could therefore pass a different value to the policy test than to GitHub Actions.
Restrict artifact path lists to | and |-, or implement folded-scalar semantics and add tests.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@scripts/ci/test-ci-storage-policy.py` around lines 135 - 145, Update the
scalar handling in the policy parser around the value check to reject folded
YAML scalars ("?>" and ">-") unless their YAML folding semantics are correctly
implemented; preferably restrict accepted artifact path blocks to literal styles
"|" and "|-". Preserve the existing collection behavior for supported literal
scalars and add or update tests to cover rejection of folded styles.
Summary
9736041completed offline rehearsal and candidate validation (release-candidate: valid … nodes=24), then failed only on evidence artifact retention.actions/upload-artifactdoes not expandcandidate/release-artifacts/{evidence,node-addons}/; switch to an explicit multiline path.Related to #192 (does not close the release tracker).
Test plan
python3 scripts/ci/test-ci-storage-policy.pyMade with Cursor
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit
Note
Fix Binding RC evidence upload by replacing brace glob with explicit multiline paths
upload-artifactdoes not expand bash brace globs, socandidate/release-artifacts/{evidence,node-addons}/was not uploading both directories.evidence/andnode-addons/as separate lines in a YAML block scalar.fieldparser in test-ci-storage-policy.py is updated to handle YAML block scalars (|,|-,>,>-) and return the last matching field when duplicates exist.Macroscope summarized 219e8ee.