Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[quality] a 0-byte OWNERS file fails every OWNERS-reading run with "invalid OWNERS file returned from GitHub API" (decode treats content "" as missing)

オープン
#404 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
55/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
github-actions, typescript
領域
devtools

調査の方向性

Start at the two truthiness checks in src/utils/owners.ts (around lines 161-167, in loadOwnersTree/probeOwners) and src/utils/auth.ts (around lines 493-495, in retrieveOwnersFile), then read parseOwners at owners.ts:39 to see the empty-document arm. Done when a blob with content '' decodes to an empty string and is treated as an OWNERS file listing nobody, with new cases in tests/utils/ownersAuth.test.ts and tests/utils/auth.test.ts, and npm run build followed by npm run pack passes.

索引モデルが issue の本文から書いたものです。

説明

agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t needs-kind quality testing

Finding

A 0-byte OWNERS file makes every OWNERS-reading run fail with invalid OWNERS file returned from GitHub API, instead of being read as an OWNERS file that lists nobody.

Both decode sites test the blob's content for truthiness:

// src/utils/owners.ts:161-167  (loadOwnersTree / probeOwners, via git/blobs and contents)
if (!file.content || !file.encoding) {
  throw new Error(`invalid OWNERS file returned from GitHub API for ${path}`)
}
// src/utils/auth.ts:493-495  (retrieveOwnersFile, root OWNERS via contents)
if (!data.content || !data.encoding) {
  throw new Error(`invalid OWNERS file returned from GitHub API: ${data}`)
}

but GitHub returns an empty blob with content: "" (which is falsy) and encoding: "base64". Verified against the real API on this repository with the universal empty-blob SHA:

$ gh api repos/cncf/prow-github-actions/git/blobs/e69de29bb2d1d6434b8b29ae775ad8c2e48c5391
{"sha":"e69de29bb2d1d6434b8b29ae775ad8c2e48c5391","size":0,"content":"","encoding":"base64",…}

Driven through dist/index.js on main @ 20d49e7 with /approve by alice on a pull request whose base has a root OWNERS of 0 bytes (fake GitHub serving { encoding: 'base64', content: '' } for the blob, i.e. exactly the shape above):

::error::TypeError: error handling issue comment: Error: error loading OWNERS files at basesha: Error: invalid OWNERS file returned from GitHub API for OWNERS

exit 1, no comment, no label — whereas the same file holding a single newline ("\n") is parsed by parseOwners (contents.trim() === '' ? {} : yaml.load(contents), owners.ts:39) as an OWNERS file that names nobody, and the run refuses alice normally (alice is not an approver for any changed file). The trim() === '' arm exists precisely to accept an empty file, but the decoder in front of it never lets a genuinely empty one through.

Blast radius: loadOwnersTree is shared by /approve, /lgtm under OWNERS, the approve/ownersLabel/blunderbuss pull-request plugins and the pull-request OWNERS authorization, so one 0-byte OWNERS anywhere under a changed file's ancestor directories fails all of them; retrieveOwnersFile additionally gates issue-side commands on the root OWNERS. A 0-byte placeholder (touch OWNERS) is a common way to stage the file.

The unit suite pins the current check only for the missing-key shape: __tests__/utils/ownersAuth.test.ts:296 and __tests__/utils/auth.test.ts:362 both serve a blob without a content key. No unit or bundle test serves content: "".

Recommendation

One deliverable (the same one-token edit at both sites plus the tests that pin it):

  • src/utils/owners.ts:163: if (file.content === undefined || !file.encoding) (or typeof file.content !== 'string') so "" decodes to "" and reaches parseOwners's empty-document arm
  • src/utils/auth.ts:493: the same change for the root OWNERS read
  • add a content: '' case to __tests__/utils/ownersAuth.test.ts and __tests__/utils/auth.test.ts asserting the file is treated as listing nobody (and that retrieveOwnersFile returns '', which its callers already treat as "no root OWNERS")
  • npm run build && npm run pack so the dist/ drift gate passes

This touches production source, so it is not a PR this lane opens; it is filed for a maintainer. The companion bundle PR (__tests__/bundle/ownersParseArms.test.ts) drives the whitespace-only, list, scalar and non-string-role shapes of parseOwners through dist/index.js and deliberately leaves the 0-byte shape out, naming this issue, so that the test does not pin the current failure as expected behaviour.

Priority

  • Impact: medium (one 0-byte OWNERS file disables every OWNERS-backed command on the paths it covers; the error message blames the GitHub API, so it is hard to diagnose)
  • Effort: low

🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: unknown

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

主要言語
TypeScript
スター
132
フォーク
23
平均マージ
1日 20時間
マージ済み PR(30日)
134

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

cncf/prow-github-actions のほかの issue

cncf/prow-github-actions の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。