Repository navigation
fix(ci): strict preflight refuses an APPROVE body that names no full head SHA - #457
Merged
Merged
Conversation
…head SHA DSR (CC-124 902e531e), independently re-verifying #452: an APPROVE whose body contains no 40-hex SHA exited 0 in strict mode - the leg only WARNed and fell back to commit timestamps, which a backdated committer date defeats silently. Merges therefore still needed a manual "does the body name the full head" check on top of preflight 0. Strict mode now FAILs when the newest APPROVE body names no full SHA; --ci keeps the WARN (it is a report, and every fresh approval starts there). A body naming a different full SHA already failed. Fixtures (+4, suite now 52): - no SHA / only an 8-char head prefix -> FAIL (both exit 0 on origin/main: the pre-fix column, i.e. fail-open closed by this commit) - different full SHA -> FAIL (unchanged), full head -> PASS (control) 52/52 on this head; origin/main script: 50/52, the two misses being exactly the two new fail-open cells. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0177oe2fF7ywx8M9VSKcEbij
clestons
approved these changes
Oct 9, 2026
clestons
left a comment
Collaborator
There was a problem hiding this comment.
APPROVE — #457(head 8dbbadb4d35bfa543e429bd3d6e84742d9bebe37)
意图:DSR CC-124 对 #452 的跟进——严格模式下,APPROVE 正文没有写完整 40 位 head SHA 时只 WARN、退出码仍是 0,靠回退到 commit 时间戳判断,而时间戳可被伪造的 committer date 静默绕过。本 PR 让严格模式在这种情况下直接 FAIL;--ci 模式保持 WARN(因为它只是报告,不是门禁,且每次刚 approve 都处于这个状态)。
亲自验证
- 读了
merge-preflight.sh的全局结构:fail=0初始化(:58),exit "$fail"(:558)是唯一出口;本 PR 新增的else分支在非CI_MODE下执行fail=1,和脚本里其余处理同类问题的既有写法(如 :327[ "$CI_MODE" -eq 1 ] || fail=1)完全一致的模式,确认会真实传导到脚本最终退出码。 - 亲自跑了
scripts/test_merge_preflight_strict.py:52/52 通过,与 PR 自称一致。四个新场景逐一核对:无 SHA → FAIL;只写 8 位缩写 → FAIL;写的是另一个完整 SHA → FAIL(且断言了具体报出的是哪个错误 SHA);写的是完整 head(对照组)→ PASS。 test_merge_preflight_strict.py自身的改动(给sc()加一个可选extra参数)是向后兼容的扫描——默认None,旧场景不受影响,只有新增的 4 条场景传了这个参数去额外断言 FAIL/OK 那一行的具体文案。
R1a
0 findings。GATE 全 NO(不涉及并发/安全面/隐藏状态),TRIAGE 标"significant"是因为这改变了合并门禁从 WARN 到 FAIL 的行为,但这正是本 PR 的明确目的,不是意外副作用。
pre-pr-check
0 block / 1 review(B1,merge-preflight.sh:211 的断言性注释——PR 的 diff 本身就是那条注释对应的代码,commit message 和注释逐字对应,不阻塞)。
结论
APPROVE。门禁行为变更(WARN→FAIL)经真实测试套件验证(52/52,含 4 个新场景的精确断言),退出码传导路径亲自读代码确认正确。
本评审只给结论,不做合并。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #452 requested by DSR (CC-124 comment 902e531e).
问题:在严格模式下,如果 APPROVE 的正文里没有任何完整 SHA,脚本只打印 WARN,然后退回到用 commit 时间戳判断,最终退出码仍是 0。而时间戳可以被伪造的 committer date 静默绕过。所以 #452 之后,每次合并仍要额外人工确认「正文里写的是完整 head」。
修复:严格模式下,最新一个 APPROVE 的正文必须写出完整的 40 位 head SHA,否则 FAIL。
--ci模式保持 WARN,因为它只是报告,并且每次刚 approve 时都会处于这个状态。测试:夹具新增 4 个场景,共 52 个。
本 head 52/52;origin/main 50/52,没对上的正好是两个新的放行场景。
影响:只影响严格模式下的这一项检查。#446 本来就因为「正文写的是另一个完整 SHA」而 FAIL,结论不变。
head:
8dbbadb4d35bfa543e429bd3d6e84742d9bebe37🤖 Generated with Claude Code
https://claude.ai/code/session_0177oe2fF7ywx8M9VSKcEbij