Repository navigation
fix(guard): prepare the resident state dir before package-authority requests - #4061
zerocodefast wants to merge 1 commit into
Conversation
…equests Package-authority requests went to the resident runtime without first creating the guard home's resident state directory. On a fresh home the runtime refused with native_resident_state_dir_create_failed, so package intent parsing returned nothing and contained runner checks lost their intent. Call ensure_resident_prerequisite the same way the other resident clients do. Signed-off-by: ZCF <291624129+zerocodefast@users.noreply.github.com>
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 37 minutes. View limit details
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Summary by QodoPrepare resident state before package-authority requests
AI Description
Diagram
High-Level Assessment
Files changed (3)
|
CI failed: One test failure in the guard package-intent extraction: an npm install was detected when the selected guard home should have yielded no intent; relationship to this PR is unclear.OverviewOne unique error template was found across 1 analyzed log (commit b7e4130). The CI run had 1 failed test and 120 passing, with 1 rerun. The setup and dependency steps succeeded, so the failure is confined to the test run. Failurestest_extract_uses_selected_guard_home_over_ambient_home (confidence: medium)
Summary
Code Review ✅ Approved🟡 Medium risk · Preparing the resident state directory changes package-authority request flow; a failed prerequisite could suppress package intent results. Adds a call to Tip Comment OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source |
Code Review by Qodo
1. Package requests can overrun their deadline
|
| if not ensure_resident_prerequisite(guard_home): | ||
| return None |
There was a problem hiding this comment.
1. Package requests can overrun their deadline 🐞 Bug ☼ Reliability
_resident_request calls ensure_resident_prerequisite before calculating the remaining request budget, and provisioning has no deadline. On a fresh guard home, secret initialization can wait up to 30 seconds for a file lock, so an intent or advisory request can remain blocked well beyond its caller's deadline or configured timeout.
Agent Prompt
## Issue description
Package-authority prerequisite provisioning can block beyond the request's deadline before the transport budget is calculated.
## Fix Focus Areas
- src/codex_plugin_scanner/guard/native_package_authority.py[57-81]
- src/codex_plugin_scanner/guard/native_context.py[259-305]
- src/codex_plugin_scanner/guard/store_base.py[904-924]
## Recommended Fix
Make prerequisite provisioning respect the effective request deadline, including waits for secret initialization, and return without contacting the resident when the budget expires. Add a test covering contention during provisioning with a short inherited deadline.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
Summary
Package-authority requests (
package_intent_parse_nativeand friends) went to the resident runtime without callingensure_resident_prerequisite. Every other resident client does this first. On a fresh guard home the runtime refuses the request withnative_resident_state_dir_create_failed. The Python side then returns no intent.That is why the nightly "Linux contained runners" job fails at
assert intent is not Noneinci/containment/test_linux_containment.py. CI runners start with a fresh home.Change
_resident_requestinnative_package_authority.pynow callsensure_resident_prerequisite(guard_home)after the feature check, the same way the data-flow, policy-bundle, supply-chain and git-inspection clients do.tests/test_native_package_authority_prerequisite.pychecks that the prerequisite runs before the runtime is contacted, and that a failed prerequisite skips the request.tests/test_native_stream_deadline.pystubs the prerequisite for the pool-exhaustion deadline test, which uses a fake runtime path.Before / after
Reproduced with a release
hol-guard-runtimebuild,HOL_GUARD_NATIVE=force, an emptyHOME, andnpx --no-install vitest run boundary.test.ts --reporter=dot:{"error":"native_resident_state_dir_create_failed","retryable":false}; intentNone.status: ok;PackageIntent(package_manager='npx', intent_kind='execute', ...).Local suite over the 34 test files that touch package authority: failures and errors are identical before and after (these are local-only native-binary fixtures); there are 2 new passes.