reviewer-bot: workflow_dispatch reads default-branch code for explore tools (set REVIEW_CONTENT_ROOT)

Offen Anfängerfreundlich
#865 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Anfängerfreundlichkeit
84/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Ruhig
Tech-Stack
github-actions, python
Bereich
ci-cd, security

Rechercherichtung

Beginne in reviewer-bot.yml und untersuche den workflow_dispatch-Pfad zusammen mit dem Verhalten von review_bot/run_review.py's _content_root(). Überprüfe, wie HEAD_SHA ermittelt wird und wie der separate Checkout und REVIEW_CONTENT_ROOT verdrahtet werden sollten, ohne den vertrauenswürdigen primären Checkout zu ändern. Als erledigt gilt, dass der manuelle Dispatch den PR-Head untersucht, während das Verhalten von pull_request unverändert bleibt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Follow-up from PR #862 review (thread on reviewer-bot.yml).

Problem

On the workflow_dispatch (manual) trigger, reviewer-bot.yml does a single actions/checkout with no ref:, which resolves to the default branch — not the PR being reviewed. The PR head is resolved separately (HEAD_SHA = gh pr view ... --json headRefOid).

Result:

  • The review diff and comment anchors are correct — the engine fetches them from the GitHub compare API keyed on HEAD_SHA (repos/{repo}/compare/...), independent of the checkout.
  • But the agent's explore tools (read_paths / grep) read from the engine's _content_root(), which falls back to the primary checkout (= default branch on dispatch) when REVIEW_CONTENT_ROOT is unset. So on manual dispatch, the agent explores default-branch code, not the PR head.

The automatic pull_request trigger (the normal case) is unaffected — its checkout already is the PR merge ref.

Why the engine expects this

Per reviewer_bot/run_review.py _content_root(), workflow_dispatch is meant to check the PR head into a separate directory and export its path as REVIEW_CONTENT_ROOT, while engine code keeps running from the trusted default-branch checkout. This is a deliberate security boundary: dispatch is exempt from the fork guard, so the PR's own code must not run/read from the primary checkout dir.

Fix

On the dispatch path, add a second checkout of HEAD_SHA into a separate dir and export REVIEW_CONTENT_ROOT pointing at it (mirroring the engine's documented pattern).

Severity

Low — only manual dispatch is affected, and only the explore-tool reads (diff/anchors are always correct). Deferred from #862 as a follow-up.

Vorherrschende Sprache
Python
Sterne
233
Forks
152
Ø Merge
21 Std. 5 Min.
Gemergte PRs (30 T.)
10

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus databricks/databricks-sql-python

Alle Issues in databricks/databricks-sql-python

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.