Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[deep-report] Secret-redaction directory scan crashes with stack overflow, likely largest driver_exit failure source

已关闭 适合新手
#64,066 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
86/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
javascript
领域
ci-cd, devops

调研方向

从 actions/setup/js/redact_secrets.cjs 开始,重点查看 findFiles() 及其递归目录分支。阅读 redact_secrets_test.go 并添加一个深度嵌套的回归用例,然后验证遍历能够在不发生栈溢出的情况下完成,同时保持现有的扫描行为。

由索引模型根据 Issue 内容生成。

描述

automation code-quality cookie improvement quick-win task-mining
Description

actions/setup/js/redact_secrets.cjs's findFiles() (lines 19-46) recursively walks /tmp/gh-aw and ${RUNNER_TEMP}/gh-aw before every artifact upload, using plain JS recursion with no depth limit:

function findFiles(dir, extensions) {
  ...
  } else if (entry.isDirectory()) {
    results.push(...findFiles(fullPath, extensions));  // unbounded recursion depth
  }
  ...
  } catch (error) {
    throw new Error(`${ERR_VALIDATION}: Failed to scan directory ${dir}: ${getErrorMessage(error)}`, { cause: error });
  }
}

This crashed with Maximum call stack size exceeded while scanning /tmp/gh-aw/aw-mcp in two independent production runs on two different engines, both times after the agent itself had already completed its task successfully:

Because this redaction step runs on every workflow before artifact upload, a Weekly Workflow Analysis fleet sample (100 runs, 2026-09-28) attributes this as likely the single largest contributor to driver_exit failures — 65% of the 31 failures in the sample were driver_exit (infra/CLI crash) rather than genuine agent errors, spread thin across ~30 different workflows (consistent with one shared infra bug, not per-workflow logic errors).

Expected Impact

Fixing this converts a meaningful share of fleet-wide driver_exit failures into successes — these are runs where the agent's actual work already succeeded but the run is marked failure purely because of this post-processing crash, wasting the failure-triage attention of every downstream analytics/audit workflow that reads run status.

Suggested Fix

Convert findFiles() from recursive to iterative (explicit stack/queue-based) directory traversal so scan depth is no longer bounded by the JS call stack. aw-mcp's internal cache/log structure likely produces enough directory nesting to exceed V8's default stack size; an iterative version has no such limit (or add an explicit max-depth cutoff with a warning if that's preferred over full traversal).

Suggested Agent

Any Go/JS-capable coding agent — this is a self-contained, single-file refactor with a clear existing unit-test file (redact_secrets_test.go) to extend with a deep-nesting regression case.

Estimated Effort

Medium (1-4 hours) — includes adding a regression test that reproduces stack overflow at depth (e.g. 10,000+ nested dirs) before the fix and passes after.

Data Source

DeepReport Intelligence Briefing 2026-09-28 (~18:00Z incremental cycle), sourced from discussion #63984 ("Weekly Workflow Analysis: 2026-09-28 sample"). Root cause independently verified by reading actions/setup/js/redact_secrets.cjs on main before filing.

Generated by 🔬 Deep Report · claude · agent · 198.5 AIC · ⌖ 8.81 AIC · ⊞ 13K · ◷

  • expires on Sep 30, 2026, 10:48 AM UTC-08:00
主要语言
Go
星标
5.3k
派生
568
平均合并
5 小时 57 分钟
30 天内合并 PR
647

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

  • 提供 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/gh-aw 的其他 Issue

查看 github/gh-aw 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。