[deep-report] Secret-redaction directory scan crashes with stack overflow, likely largest driver_exit failure source
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 86/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- javascript
Direzione di ricerca
Inizia da actions/setup/js/redact_secrets.cjs, in particolare da findFiles() e dal relativo ramo ricorsivo delle directory. Leggi redact_secrets_test.go e aggiungi un caso di regressione per una nidificazione profonda, quindi verifica che l'attraversamento venga completato senza un overflow dello stack, mantenendo il comportamento di scansione esistente.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
actions/setup/js/redact_secrets.cjs's findFiles() (lines 19-46) recursively walks /tmp/gh-aw and ${RUNNER_TEMP}/gh-aw before every artifact upload, using plain JS recursion with no depth limit:
function findFiles(dir, extensions) {
...
} else if (entry.isDirectory()) {
results.push(...findFiles(fullPath, extensions)); // unbounded recursion depth
}
...
} catch (error) {
throw new Error(`${ERR_VALIDATION}: Failed to scan directory ${dir}: ${getErrorMessage(error)}`, { cause: error });
}
}
This crashed with Maximum call stack size exceeded while scanning /tmp/gh-aw/aw-mcp in two independent production runs on two different engines, both times after the agent itself had already completed its task successfully:
- run 36395018370 — "Daily Storify" (Codex engine)
- run 36377939174 — "Safe Output Health Monitor" (Claude engine)
Because this redaction step runs on every workflow before artifact upload, a Weekly Workflow Analysis fleet sample (100 runs, 2026-09-28) attributes this as likely the single largest contributor to driver_exit failures — 65% of the 31 failures in the sample were driver_exit (infra/CLI crash) rather than genuine agent errors, spread thin across ~30 different workflows (consistent with one shared infra bug, not per-workflow logic errors).
Expected Impact
Fixing this converts a meaningful share of fleet-wide driver_exit failures into successes — these are runs where the agent's actual work already succeeded but the run is marked failure purely because of this post-processing crash, wasting the failure-triage attention of every downstream analytics/audit workflow that reads run status.
Suggested Fix
Convert findFiles() from recursive to iterative (explicit stack/queue-based) directory traversal so scan depth is no longer bounded by the JS call stack. aw-mcp's internal cache/log structure likely produces enough directory nesting to exceed V8's default stack size; an iterative version has no such limit (or add an explicit max-depth cutoff with a warning if that's preferred over full traversal).
Suggested Agent
Any Go/JS-capable coding agent — this is a self-contained, single-file refactor with a clear existing unit-test file (redact_secrets_test.go) to extend with a deep-nesting regression case.
Estimated Effort
Medium (1-4 hours) — includes adding a regression test that reproduces stack overflow at depth (e.g. 10,000+ nested dirs) before the fix and passes after.
Data Source
DeepReport Intelligence Briefing 2026-09-28 (~18:00Z incremental cycle), sourced from discussion #63984 ("Weekly Workflow Analysis: 2026-09-28 sample"). Root cause independently verified by reading actions/setup/js/redact_secrets.cjs on main before filing.
Generated by 🔬 Deep Report · claude · agent · 198.5 AIC · ⌖ 8.81 AIC · ⊞ 13K · ◷
- expires on Sep 30, 2026, 10:48 AM UTC-08:00
- Lingua principale
- Go
- Stelle
- 5.2k
- Fork
- 547
- Merge medio
- 5h 46m
- PR unite (30g)
- 658
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/gh-aw
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
automation code-quality cookie improvement quick-win task-mining
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
[deep-report] Fix stale pkg/workflow/js/ references in 4 skill files (3rd recurrence, count growing)Apertaautomation code-quality cookie improvement quick-win task-mining
Difficoltà 2/5 Meno di un'ora Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di github/gh-aw
Issue simili
-
bug needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
DataDog/dd-trace-go#5469 ·
I maintainer di solito rispondono entro 1 giorno
-
bug tests
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
l3montree-dev/devguard#3101 ·
I maintainer di solito rispondono entro 1 giorno
-
area:*of bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
oapi-codegen/oapi-codegen#2593 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
DaoCloud/DaoCloud-docs#7432 ·
I maintainer di solito rispondono entro 1 giorno