[quality] the bundle e2e suite never drives root-OWNERS authorization on an issue or the OWNERS-based /lgtm refusal on a pull request through dist/index.js
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Ferma
- Stack tecnologico
- github, typescript
- Ambito
- security, testing-qa
Direzione di ricerca
Start with src/utils/auth.ts and the existing bundle tests, especially bundle.test.ts and triggerTestAndLgtmCancel.test.ts. Add tests/bundle/ownersAuth.test.ts using the listed helpers, then run npm run test:coverage:e2e. Done means the three specified issue and pull-request OWNERS authorization cases execute through dist/index.js with the expected comments, label behavior, and API reads.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Finding
src/utils/auth.ts holds the OWNERS-based authorization behind /lgtm, /approve and the /test//retest triggers (assertAuthorizedByOwnersOrMembership, L244). Three of its arms are unit-covered but never run through the committed dist/index.js:
assertRootOwner+retrieveOwnersFile(L271–290, L338–364) — on an issue (not a pull request) the rootOWNERSfile of the default branch is read throughGET …/contents/OWNERS, base64-decoded, parsed, and the commenter is matched against the role. The only bundle route for that path answers404(bundle.test.ts:443, the author-refusal case), so the membership fallback is alldist/ever exercises on issues; no bundle test sends/lgtmto a plain issue at all.assertPullRequestOwner's refusal (L321–322) — on a pull request whose OWNERS files cover the changed files but list neither the commenter as reviewer nor approver,Cannot apply the lgtm label because Error: <login> is not a reviewer or approver for any changed file. Every bundle/lgtmon an OWNERS repository is by a listed reviewer; the OWNERS-less refusal (triggerTestAndLgtmCancel.test.ts:293) goes through the membership arm instead.
Evidence
- Unit:
npx vitest run --coverageonmain@ ec76a3b (vitest 5.0.3,@vitest/coverage-v8) →src/utils/auth.ts100 % lines / 98.43 % branches.__tests__/utils/auth.test.ts:361-387and__tests__/label/lgtm.test.ts:348exercise all three arms with mocked octokit. - End-to-end:
npm run test:coverage:e2e(thevitest.e2e-coverage.config.mjsrecipe from #274: source-mapped bundle built from__tests__/bundle/coverageEntry/, same revision,__tests__/bundleonly) →src/utils/auth.ts63.1 % lines / 53.12 % branches; unreached statement lines include271-290,321-322,338-364(fromcoverage/coverage-final.json). The two runs are reported separately by design (vitest.e2e-coverage.config.mjsheader): their statement maps come from different transforms and do not line-merge.
Unit-covered, not e2e-covered → medium.
Recommendation
- Add
__tests__/bundle/ownersAuth.test.ts(new file, importingcomment,helpersFor,ownersProbe,ownersReads,queueRead,repo,tokenfrom./helpers) with three cases driving/lgtmthroughdist/index.js:- issue, root
OWNERSlists the commenter as reviewer →GET …/contents/OWNERS(200, base64),GET …/labels,POST …/issues/1/labels {labels:['lgtm']}, no/orgs/…/membersor/collaboratorsread, then the post-command config reads; - issue, root
OWNERSdoes not list the commenter → exit 1, one refusal comment naming the login and role, no label write, no membership fallback; - pull request,
OWNERS+sdk/OWNERScoveringsdk/file.go, commenter in neither → exit 1, refusal comment… is not a reviewer or approver for any changed file, nocontents/OWNERSread, no membership read, then the config reads and tide's gate.
- issue, root
Measured with those three cases on the same recipe: auth.ts e2e rises to 79.61 % lines / 70.31 % branches; what remains unreached in the file are throw/catch arms (L22, 42-43, 61, 64, 98, 101, 135-139, 179, 208-222, 279, 311, 348-359) that the unit suite already pins.
Disjoint from the open hold-gated PRs: #230 (vitest.config.mjs), #242 (cronJobsInput.test.ts), #244 (meow.test.ts), #246 (labelCommands.test.ts, helpers.ts repoLabels).
Priority
- Impact: medium — authorization is the gate in front of every label and merge command; the OWNERS branch of it has never been exercised by the shipped bundle
- Effort: low
Filed by quality agent (hold-gated mode)
hive: close-on-merge
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Lingua principale
- TypeScript
- Stelle
- 132
- Fork
- 23
- Merge medio
- 1g 2h
- PR unite (30g)
- 98
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di cncf/prow-github-actions
-
agent/quality hive/hosted-available-lke648397-260827-5q9t kind/failing-test quality testing
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
cncf/prow-github-actions#329 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[quality] bundle e2e never drives plain /close or the /milestone refusals through dist/index.jsForse già presa @hivecommons-hive l’ha presa 3 giorni fa. Apertaagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
cncf/prow-github-actions#295 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[quality] the cron dispatcher's jobs-input error arms and the push event route are never driven through dist/index.jsForse già presa @hivecommons-hive l’ha presa 7 giorni fa. Apertaagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t needs-kind quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
cncf/prow-github-actions#241 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent/quality hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
cncf/prow-github-actions#213 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup needs-decision quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
cncf/prow-github-actions#209 · 5 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di cncf/prow-github-actions
Issue simili
-
refactor
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
tomnewport/memprot-topo#55 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
WalletConnect/walletconnect-monorepo#7368 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
BU-Spark/se-chem-apll#47 ·
-
embed: handleTurboSignMessage header comment says the signing page posts to '*' (it never does)Apertadocumentation
Difficoltà 2/5 Meno di un'ora Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 Mezza giornata Idoneità per principianti 70/100
udistrital/paginaweb_root#23 ·