[deep-report] Secret-redaction directory scan crashes with stack overflow, likely largest driver_exit failure source
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 86/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- javascript
调研方向
从 actions/setup/js/redact_secrets.cjs 开始,重点查看 findFiles() 及其递归目录分支。阅读 redact_secrets_test.go 并添加一个深度嵌套的回归用例,然后验证遍历能够在不发生栈溢出的情况下完成,同时保持现有的扫描行为。
由索引模型根据 Issue 内容生成。
描述
Description
actions/setup/js/redact_secrets.cjs's findFiles() (lines 19-46) recursively walks /tmp/gh-aw and ${RUNNER_TEMP}/gh-aw before every artifact upload, using plain JS recursion with no depth limit:
function findFiles(dir, extensions) {
...
} else if (entry.isDirectory()) {
results.push(...findFiles(fullPath, extensions)); // unbounded recursion depth
}
...
} catch (error) {
throw new Error(`${ERR_VALIDATION}: Failed to scan directory ${dir}: ${getErrorMessage(error)}`, { cause: error });
}
}
This crashed with Maximum call stack size exceeded while scanning /tmp/gh-aw/aw-mcp in two independent production runs on two different engines, both times after the agent itself had already completed its task successfully:
- run 36395018370 — "Daily Storify" (Codex engine)
- run 36377939174 — "Safe Output Health Monitor" (Claude engine)
Because this redaction step runs on every workflow before artifact upload, a Weekly Workflow Analysis fleet sample (100 runs, 2026-09-28) attributes this as likely the single largest contributor to driver_exit failures — 65% of the 31 failures in the sample were driver_exit (infra/CLI crash) rather than genuine agent errors, spread thin across ~30 different workflows (consistent with one shared infra bug, not per-workflow logic errors).
Expected Impact
Fixing this converts a meaningful share of fleet-wide driver_exit failures into successes — these are runs where the agent's actual work already succeeded but the run is marked failure purely because of this post-processing crash, wasting the failure-triage attention of every downstream analytics/audit workflow that reads run status.
Suggested Fix
Convert findFiles() from recursive to iterative (explicit stack/queue-based) directory traversal so scan depth is no longer bounded by the JS call stack. aw-mcp's internal cache/log structure likely produces enough directory nesting to exceed V8's default stack size; an iterative version has no such limit (or add an explicit max-depth cutoff with a warning if that's preferred over full traversal).
Suggested Agent
Any Go/JS-capable coding agent — this is a self-contained, single-file refactor with a clear existing unit-test file (redact_secrets_test.go) to extend with a deep-nesting regression case.
Estimated Effort
Medium (1-4 hours) — includes adding a regression test that reproduces stack overflow at depth (e.g. 10,000+ nested dirs) before the fix and passes after.
Data Source
DeepReport Intelligence Briefing 2026-09-28 (~18:00Z incremental cycle), sourced from discussion #63984 ("Weekly Workflow Analysis: 2026-09-28 sample"). Root cause independently verified by reading actions/setup/js/redact_secrets.cjs on main before filing.
Generated by 🔬 Deep Report · claude · agent · 198.5 AIC · ⌖ 8.81 AIC · ⊞ 13K · ◷
- expires on Sep 30, 2026, 10:48 AM UTC-08:00
- 主要语言
- Go
- 星标
- 5.3k
- 派生
- 568
- 平均合并
- 5 小时 57 分钟
- 30 天内合并 PR
- 647
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/gh-aw 的其他 Issue
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
automation documentation
难度 1/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
automation code-quality cookie improvement quick-win task-mining
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
-
automation code-quality cookie improvement quick-win task-mining
难度 2/5 1 小时以内 新手友好度 88/100
维护者通常 1 天内回复
-
automation code-quality cookie improvement quick-win task-mining
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 90/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
NVIDIA/k8s-device-plugin#2076 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
area/release kind/bug
难度 2/5 1-3 小时 新手友好度 82/100
kubernetes-sigs/kueue#16455 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 74/100
aws/eks-node-monitoring-agent#289 ·
维护者通常 2 天内回复