Repository navigation
Fix: Improve CVE eligibility error message and prevent duplicate comments - #776
Conversation
PR Summary by QodoHandle CVE eligibility failures without duplicate Jira comments
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Code Review by Qodo
1.
|
65b26b8 to
dd40088
Compare
|
/agentic_review |
|
Code review by qodo was updated up to the latest commit dd40088 |
a75faf7 to
8737834
Compare
The error message 'CVE has no target release specified' was ambiguous and didn't indicate which Jira field needed to be fixed. This caused confusion when investigating triage errors. Updated the message to explicitly mention 'Fix Versions field is empty' so users can immediately identify and fix the missing field. Context: Discovered during investigation of RHEL-246615, RHEL-246616, RHEL-246377, RHEL-246559, and RHEL-246383, which all failed eligibility check after component changes cleared their Fix Versions field. Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
…ty failures CVE eligibility errors fall into two categories: 1. Human-correctable (missing Fix Versions field) - non-retriable 2. Operational/transient (network, API failures) - retriable Previously, ALL eligibility errors triggered retry logic, causing duplicate comments for human-correctable errors that don't benefit from retries. This change distinguishes between the two: - Missing Fix Versions field → CLARIFICATION_NEEDED (non-retriable) - Posts comment exactly once - Maps to ymir_needs_attention label (data incomplete, needs human fix) - Provides clear guidance to fix and retry manually - Clone/dependency check failures → ERROR (retriable) - Triggers normal retry logic for transient failures - Maps to ymir_triage_errored label after max retries exhausted - May recover without human intervention Resolution mapping handles all label transitions - no manual label setting. This prevents duplicate comment spam for issues like RHEL-246615 where the same 'CVE has no target release specified' error was posted 3 times, while preserving automatic retry for operational failures. Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Extend test_eligibility_no_fix_version to verify that both 'reason' and 'error' fields contain the clarified 'Fix Versions field is empty' message. This prevents regression if the improved error message is accidentally reverted. Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
8737834 to
7019db8
Compare
Summary
Improves the CVE eligibility error handling to provide clearer feedback and prevent duplicate error comments.
Changes
1. Clarified error message for missing Fix Version/s field
File:
ymir/tools/privileged/jira.pyChanged the error message from:
to:
This makes it immediately clear which Jira field needs to be fixed when investigating triage errors.
2. Prevented duplicate error comments
File:
ymir/agents/triage_agent.pyProblem: CVE eligibility errors (like missing Fix Version/s) were triggering retry logic, causing the same error comment to be posted 3 times (once per retry attempt).
Solution: Changed eligibility errors from
Resolution.ERROR(retriable) toResolution.CLARIFICATION_NEEDED(non-retriable), which:ymir_triage_erroredlabel immediatelyContext
Discovered during investigation of RHEL-246615, RHEL-246616, RHEL-246377, RHEL-246559, and RHEL-246383, which all failed eligibility check after component changes cleared their Fix Version/s field. The same error message was posted 3 times per issue, causing confusion about which field was missing and creating comment spam.
Test plan
🤖 Generated with Claude Code