Skip to content

fix(applier): fail closed when a repo's workflows cannot be read - #1127

Merged
hyperpolymath merged 3 commits into
mainfrom
fix/applier-fail-closed
Oct 1, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
fix/applier-fail-closed

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

fetch_workflows in scripts/apply-workflow-pins-remote.sh returned 0 on every REST failure. A rate-limited repo therefore read as "no workflows": it was dropped from the pin census while walked N still counted it. Measured on 2026-10-02, when the shared 5,000/h token ran out partway through an audit run.

  • Only a 404 means "no workflows". Any other failure, including a file that will not download, writes a FETCH-FAILED row and the repo is not classified.
  • If enumeration returns zero repositories, the run stops as fatal instead of reporting an empty census.
  • main is guarded on BASH_SOURCE, so the fetch path can be sourced and tested with a stub gh.
  • tests/test_apply_workflow_pins_remote.sh section 3 adds four known-answer cases (ok, 404, rate-limited listing, failed file download). It also adds a mutant that puts back the fail-open return 0 on a failed listing; that mutant turns red. Locally all sections pass and docstring coverage is 100%.

Not changed here: if list_repos is rate-limited partway through pagination, the list can still come back incomplete. The new guard only catches a list that is completely empty.

🤖 Generated with Claude Code

https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP

fetch_workflows returned 0 on every REST failure, so a rate-limited repo
read as "no workflows" and vanished from the pin census while `walked N`
still counted it. Only a 404 now means "nothing here"; any other failure
records a FETCH-FAILED row. An empty enumeration is fatal instead of an
empty census. main is source-guarded so the fetch path is testable; the
suite adds four known-answer cases and a fail-open mutant that turns red.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4add6128-4629-482e-9376-fd0024839c8a

📥 Commits

Reviewing files that changed from the base of the PR and between 56b767f and 0bbc67c.

📒 Files selected for processing (2)
  • scripts/apply-workflow-pins-remote.sh
  • tests/test_apply_workflow_pins_remote.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 1, 2026 23:48
@hyperpolymath
hyperpolymath merged commit 11ba299 into main Oct 1, 2026
50 checks passed
@hyperpolymath
hyperpolymath deleted the fix/applier-fail-closed branch October 1, 2026 23:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant