Skip to content

Fix: Improve CVE eligibility error message and prevent duplicate comments - #776

Merged
majamassarini merged 3 commits into
packit:mainfrom
majamassarini:fix/improve-triage-error-message-missing-fix-version
Aug 26, 2026
Merged

majamassarini merged 3 commits into
packit:mainfrom
majamassarini:fix/improve-triage-error-message-missing-fix-version

Conversation

@majamassarini

Copy link
Copy Markdown
Member

Summary

Improves the CVE eligibility error handling to provide clearer feedback and prevent duplicate error comments.

Changes

1. Clarified error message for missing Fix Version/s field

File: ymir/tools/privileged/jira.py

Changed the error message from:

CVE has no target release specified

to:

CVE has no target release specified (Fix Version/s field is empty)

This makes it immediately clear which Jira field needs to be fixed when investigating triage errors.

2. Prevented duplicate error comments

File: ymir/agents/triage_agent.py

Problem: CVE eligibility errors (like missing Fix Version/s) were triggering retry logic, causing the same error comment to be posted 3 times (once per retry attempt).

Solution: Changed eligibility errors from Resolution.ERROR (retriable) to Resolution.CLARIFICATION_NEEDED (non-retriable), which:

  • Skips the retry loop - these errors need human intervention, not automatic retries
  • Posts the error comment exactly once
  • Sets ymir_triage_errored label immediately
  • Provides clear guidance: "Please fix the issue and retry manually (e.g., via ymir_todo label)"

Context

Discovered during investigation of RHEL-246615, RHEL-246616, RHEL-246377, RHEL-246559, and RHEL-246383, which all failed eligibility check after component changes cleared their Fix Version/s field. The same error message was posted 3 times per issue, causing confusion about which field was missing and creating comment spam.

Test plan

  • Manual test: Create a CVE tracker without Fix Version/s field, trigger triage via ymir_todo
  • Verify error comment is posted exactly once
  • Verify error message mentions "Fix Version/s field is empty"
  • Verify ymir_triage_errored label is set
  • Verify no retry attempts occur

🤖 Generated with Claude Code

@qodo-for-packit

Copy link
Copy Markdown

PR Summary by Qodo

Handle CVE eligibility failures without duplicate Jira comments

🐞 Bug fix 🕐 10-20 Minutes

Grey Divider

AI Description

• Treat CVE eligibility failures as non-retriable requests requiring manual correction.
• Identify an empty Jira Fix Version/s field in eligibility feedback.
• Set the triage error state and post one actionable Jira comment.
Diagram

graph TD
  A["Jira CVE"] --> B["Eligibility check"] --> C{"Fix versions?"}
  C -- Yes --> D["Continue triage"]
  C -- No --> E["Clarification result"] --> F["Jira feedback"]
Loading
High-Level Assessment

The chosen approach is appropriate because a missing Fix Version/s value requires human action and cannot benefit from retries. Suppressing duplicate comments inside the retry loop was considered conceptually, but would still waste retry attempts; classifying the outcome as clarification-needed stops the retry at its source while preserving actionable Jira feedback.

Files changed (2) +19 / -5

Bug fix (2) +19 / -5
triage_agent.pyRoute eligibility failures outside the retry loop +17/-3

Route eligibility failures outside the retry loop

• Converts CVE eligibility errors from a retriable error into a clarification-needed result with manual remediation guidance. It immediately applies the triage error label, removes the in-progress label, and allows the workflow to post the feedback once instead of once per retry.

ymir/agents/triage_agent.py

jira.pyName the missing Jira field in eligibility errors +2/-2

Name the missing Jira field in eligibility errors

• Extends the missing-target-release reason and error text to explicitly identify an empty Fix Version/s field, making the required Jira correction clear.

ymir/tools/privileged/jira.py

@qodo-for-packit

qodo-for-packit Bot commented Aug 25, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Transient failures stop retrying ✓ Resolved 🐞 Bug ☼ Reliability
Description
The new branch converts every CVEEligibilityResult.error into non-retriable
CLARIFICATION_NEEDED, but this field is also populated when clone dependency or fix-approach
checks raise arbitrary Jira, Koji, configuration, or network exceptions. Those transient failures
now tell users to edit the issue and require a manual retry instead of using the existing automatic
retry path.
Code

ymir/agents/triage_agent.py[R597-599]

+                # CVE eligibility errors are not transient - they require human intervention
+                # (e.g., setting Fix Version/s field). Use CLARIFICATION_NEEDED instead of ERROR
+                # to avoid retry loop, and set error label directly.
Relevance

●●● Strong

Recent triage precedent accepts preserving retry behavior and distinguishing transient failures from
terminal outcomes.

PR-#540
PR-#581

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The eligibility tool catches arbitrary exceptions from dependency checks and serializes them into
the same error field used by the missing Fix Version/s result. The changed agent branch tests only
whether that field is non-empty, so all such operational failures become terminal clarifications.

ymir/agents/triage_agent.py[520-528]
ymir/agents/triage_agent.py[596-616]
ymir/tools/privileged/jira.py[777-785]
ymir/tools/privileged/jira.py[889-900]
ymir/tools/privileged/jira.py[1063-1075]
ymir/tools/privileged/jira.py[598-611]
ymir/tools/privileged/jira.py[679-681]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Only human-correctable eligibility failures should bypass automatic retries. Internal or transient dependency-check failures currently also carry `CVEEligibilityResult.error` and must continue returning `Resolution.ERROR`.

## Issue Context
Distinguish missing/invalid Jira-field conditions from operational exceptions rather than treating every non-empty `error` identically.

## Fix Focus Areas
- ymir/agents/triage_agent.py[596-616]
- ymir/tools/privileged/jira.py[889-900]
- ymir/tools/privileged/jira.py[1063-1075]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

2. Conflicting terminal labels remain ✓ Resolved 🐞 Bug ≡ Correctness
Description
This branch adds ymir_triage_errored, then returning CLARIFICATION_NEEDED makes normal
completion also add ymir_needs_attention without removing the error label. The issue therefore
ends with two contradictory terminal labels and subsequent non-user-triggered processing treats the
stale error label as a completion anchor.
Code

ymir/agents/triage_agent.py[R601-604]

+                    await tasks.set_jira_labels(
+                        jira_issue=state.jira_issue,
+                        labels_to_add=[JiraLabels.TRIAGE_ERRORED.value],
+                        labels_to_remove=[JiraLabels.TRIAGE_IN_PROGRESS.value],
Relevance

●●● Strong

Recent triage precedent explicitly treats terminal labels as deduplication anchors requiring
consistent terminal-state labeling.

PR-#540

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The resolution map and both direct and queued completion paths add ymir_needs_attention for
clarification while removing only ymir_triage_in_progress. The newly added earlier write therefore
leaves ymir_triage_errored alongside it, and deduplication recognizes both as terminal Ymir
labels.

ymir/agents/triage_agent.py[116-125]
ymir/agents/triage_agent.py[596-616]
ymir/agents/triage_agent.py[1214-1229]
ymir/agents/triage_agent.py[1291-1313]
ymir/agents/triage_agent.py[1477-1512]
ymir/agents/tasks.py[625-668]
PR-#540

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Eligibility clarification currently writes `ymir_triage_errored` directly and later receives the resolution-mapped `ymir_needs_attention` label. Ensure the final issue state contains exactly the terminal label intended for this outcome.

## Issue Context
The generic completion path maps `CLARIFICATION_NEEDED` to `NEEDS_ATTENTION` and removes only `TRIAGE_IN_PROGRESS`; label additions do not replace other terminal labels.

## Fix Focus Areas
- ymir/agents/triage_agent.py[600-616]
- ymir/agents/triage_agent.py[116-125]
- ymir/agents/triage_agent.py[1477-1512]
- ymir/agents/triage_agent.py[1214-1229]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Missing Jira message assertion ✓ Resolved 📘 Rule violation ▣ Testability
Description
The privileged Jira error message changed without a corresponding test update that asserts the new
Fix Version/s field is empty text. The existing no-fix-version test only checks eligibility and
that an error exists, so reverting the new wording would not fail the test.
Code

ymir/tools/privileged/jira.py[R783-784]

+                    reason="CVE has no target release specified (Fix Version/s field is empty)",
+                    error="CVE has no target release specified (Fix Version/s field is empty)",
Relevance

●● Moderate

Privileged-tool tests are often requested for changed behavior, but a recent Jira test-coverage
suggestion was rejected.

PR-#727
PR-#670

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
PR Compliance ID 1589 requires changed behavior under ymir/tools/privileged/ to have a
corresponding test that fails if the behavior is removed. The production code adds the clarified
text at lines 783-784, while the existing test at lines 1100-1107 only asserts eligibility and
non-null error, without asserting the changed message; the PR diff contains no test modification.

Rule 1589: Require unit tests for changes to privileged tools (ymir/tools/privileged/, esp. distgit.py)
ymir/tools/privileged/jira.py[783-784]
ymir/tools/privileged/tests/unit/test_jira.py[1100-1107]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The changed missing-Fix-Version error message in the privileged Jira tool is not protected by a unit-test assertion.

## Issue Context
Extend the existing `test_eligibility_no_fix_version` test to assert that both the returned `reason` and `error` contain or equal the clarified `Fix Version/s field is empty` message, ensuring the test fails if this behavior is reverted.

## Fix Focus Areas
- ymir/tools/privileged/jira.py[783-784]
- ymir/tools/privileged/tests/unit/test_jira.py[1100-1107]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Compliance rules (platform): 8 rules

Grey Divider

Tip of the day
💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread ymir/tools/privileged/jira.py Outdated
Comment thread ymir/agents/triage_agent.py Outdated
Comment thread ymir/agents/triage_agent.py Outdated
@majamassarini
majamassarini force-pushed the fix/improve-triage-error-message-missing-fix-version branch 2 times, most recently from 65b26b8 to dd40088 Compare August 25, 2026 13:39
@majamassarini

Copy link
Copy Markdown
Member Author

/agentic_review

@qodo-for-packit

Copy link
Copy Markdown

Code review by qodo was updated up to the latest commit dd40088

Comment thread ymir/agents/triage_agent.py Outdated
@majamassarini
majamassarini force-pushed the fix/improve-triage-error-message-missing-fix-version branch 2 times, most recently from a75faf7 to 8737834 Compare August 26, 2026 09:19

@opohorel opohorel left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

The error message 'CVE has no target release specified' was ambiguous
and didn't indicate which Jira field needed to be fixed. This caused
confusion when investigating triage errors.

Updated the message to explicitly mention 'Fix Versions field is empty'
so users can immediately identify and fix the missing field.

Context: Discovered during investigation of RHEL-246615, RHEL-246616,
RHEL-246377, RHEL-246559, and RHEL-246383, which all failed eligibility
check after component changes cleared their Fix Versions field.

Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
…ty failures

CVE eligibility errors fall into two categories:
1. Human-correctable (missing Fix Versions field) - non-retriable
2. Operational/transient (network, API failures) - retriable

Previously, ALL eligibility errors triggered retry logic, causing duplicate
comments for human-correctable errors that don't benefit from retries.

This change distinguishes between the two:
- Missing Fix Versions field → CLARIFICATION_NEEDED (non-retriable)
  - Posts comment exactly once
  - Maps to ymir_needs_attention label (data incomplete, needs human fix)
  - Provides clear guidance to fix and retry manually
- Clone/dependency check failures → ERROR (retriable)
  - Triggers normal retry logic for transient failures
  - Maps to ymir_triage_errored label after max retries exhausted
  - May recover without human intervention

Resolution mapping handles all label transitions - no manual label setting.

This prevents duplicate comment spam for issues like RHEL-246615 where
the same 'CVE has no target release specified' error was posted 3 times,
while preserving automatic retry for operational failures.

Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Extend test_eligibility_no_fix_version to verify that both 'reason'
and 'error' fields contain the clarified 'Fix Versions field is empty'
message. This prevents regression if the improved error message is
accidentally reverted.

Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
@majamassarini
majamassarini force-pushed the fix/improve-triage-error-message-missing-fix-version branch from 8737834 to 7019db8 Compare August 26, 2026 12:25
@majamassarini
majamassarini merged commit ed460f6 into packit:main Aug 26, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants