Conversation
Coverage Report
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan includes up to 2 reviews per rolling hour; 1 remains after this review. 📝 WalkthroughWalkthroughThe change adds index-age calculation and interval parsing. ChangesIndex refresh scheduling
Container execution
Tooling and CI maintenance
Estimated code review effort: 3 (Moderate) | ~30 minutes Merge Risk: ⚪ Minimal · up to This change is merge-ready after normal checks and review; no actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 2 | ❌ 2❌ Failed checks (2 inconclusive)
✅ Passed checks (2 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 437e2037-40cf-4aa8-8c2e-b2736c47df65
📒 Files selected for processing (7)
README.mdsrc/index.pysrc/process_manager.pysrc/utils/config.pytests/test_index.pytests/test_process_manager.pytests/utils/test_config.py
There was a problem hiding this comment.
Actionable comments posted: 1
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: c01545d5-e572-4b01-91be-07b0f8fa0d4d
📒 Files selected for processing (10)
.github/workflows/build-and-push.yml.github/workflows/check-releases.yml.github/workflows/full-test-jsonl.yml.github/workflows/full-test.yml.github/workflows/lint.yml.github/workflows/pytest.yml.github/workflows/release-drafter.ymlDockerfilemise.tomlrenovate.json
There was a problem hiding this comment.
Code review is billed via overage credits. To resume reviews, an organization admin can raise the monthly limit at claude.ai/admin-settings/claude-code.
Once credits are available, push a new commit or reopen this pull request to trigger a review.
There was a problem hiding this comment.
Code review is billed via overage credits. To resume reviews, an organization admin can raise the monthly limit at claude.ai/admin-settings/claude-code.
Once credits are available, push a new commit or reopen this pull request to trigger a review.
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
Dockerfile (1)
1-1: 🔒 Security & Privacy | 🔵 TrivialDocument the intentional root bootstrap.
The final image has no
USERinstruction. The entrypoint requires root to applyPUIDandPGIDchanges, then launches the application withgosu photon. AddingUSER photonwould bypass this setup.If root startup is an accepted container contract, document the
DS-0002exception and add a container test that confirms the application process runs asphoton. Otherwise, redesign the UID/GID setup before adding an explicit non-rootUSER.Source: Linters/SAST tools
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: ec175466-02b6-4532-9a23-e621c545cfa7
📒 Files selected for processing (12)
.github/workflows/build-and-push.yml.github/workflows/check-releases.yml.github/workflows/full-test-jsonl.yml.github/workflows/full-test.yml.github/workflows/lint.yml.github/workflows/pytest.yml.github/workflows/release-drafter.yml.pre-commit-config.ymlDockerfileentrypoint.shmise.tomlpyproject.toml
🚧 Files skipped from review as they are similar to previous changes (2)
- .github/workflows/build-and-push.yml
- mise.toml
Included review availability: Your plan includes up to 2 reviews per rolling hour; 0 remain after this review.
| if [ "$RUNNING_AS_ROOT" = true ]; then | ||
| chown -R photon:photon /photon | ||
| exec gosu photon "$@" | ||
| fi | ||
|
|
||
| exec "$@" |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
Guard the data migration before starting a non-root process.
Line 46 is reached only after Lines 28-39 attempt the migration. If /photon/data/node_1 exists, a non-root caller may not be able to run rm, mkdir, or mv. The script does not stop when these commands fail, so it can start Photon with the old layout still present. Move the migration into the root-only branch, or detect this state and exit with an explicit migration error before exec "$@".
There was a problem hiding this comment.
Code review is billed via overage credits. To resume reviews, an organization admin can raise the monthly limit at claude.ai/admin-settings/claude-code.
Once credits are available, push a new commit or reopen this pull request to trigger a review.
No description provided.