fix: download archives outside workspace - #4
Merged
Merged
Conversation
审查者指南该操作现在会将经过验证的 verified-bot-commit 归档下载到 RUNNER_TEMP,在不创建工作区文件的情况下解压并删除归档,并使用 v0.2.1。CI 会运行专门的静态检查,覆盖 Windows 和 Unix 归档流程。 临时 verified-bot-commit 归档下载时序图sequenceDiagram
participant Action
participant Temp as RUNNER_TEMP
participant Release as GitHub Release
participant Workspace
participant Tool as verified_bot_commit
Action->>Release: curl archive URL for v0.2.1
Release-->>Temp: Save archive
Action->>Temp: Extract archive
Action->>Temp: rm -f archive
Action->>Tool: Execute extracted binary
Note over Workspace: No archive output is created or read
文件级变更
提示和命令与 Sourcery 交互
自定义你的使用体验访问你的控制面板以:
获取帮助Original review guide in EnglishReviewer's GuideThe action now downloads verified-bot-commit archives into RUNNER_TEMP, extracts and removes them without creating workspace files, and uses v0.2.1. CI runs focused static checks covering both Windows and Unix archive flows. Sequence diagram for temporary verified-bot-commit archive downloadsequenceDiagram
participant Action
participant Temp as RUNNER_TEMP
participant Release as GitHub Release
participant Workspace
participant Tool as verified_bot_commit
Action->>Release: curl archive URL for v0.2.1
Release-->>Temp: Save archive
Action->>Temp: Extract archive
Action->>Temp: rm -f archive
Action->>Tool: Execute extracted binary
Note over Workspace: No archive output is created or read
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
嘿——我发现了 2 个问题
面向 AI Agent 的提示
请处理本次代码审查中的评论:
## 单独评论
### 评论 1
<location path="tests/action_download_test.py" line_range="4-15" />
<code_context>
+from pathlib import Path
+
+
+action = Path("action.yml").read_text()
+
+assert 'VERSION="v0.2.1"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"' in action
+assert 'unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"' in action
+assert 'tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"' in action
+assert action.count('rm -f "$ARCHIVE_PATH"') == 2
+assert '-o archive.zip' not in action
+assert '-o archive.tar.gz' not in action
</code_context>
<issue_to_address>
**问题(测试):** CI 测试只会在 `action.yml` 中搜索命令字符串;它从未执行下载、解压、清理或工作区隔离行为。因此,只要预期的代码片段仍然存在,即使 shell 脚本格式错误或顺序被打乱,也可能通过 CI。
**触发条件:** 归档下载实现发生回归,但被断言的命令文本未被移除时。
**建议修复:** 在隔离的临时工作区中使用模拟下载来运行下载逻辑,然后断言二进制文件已解压、归档已删除,并且工作区中不存在归档文件。
</issue_to_address>
### 评论 2
<location path="action.yml" line_range="125-134" />
<code_context>
if [ "$RUNNER_OS" = "Windows" ]; then
- curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o archive.zip
- unzip -o archive.zip -d "$RUNNER_TEMP"
+ ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
+ curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
+ unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
+ rm -f "$ARCHIVE_PATH"
BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
else
- curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o archive.tar.gz
</code_context>
<issue_to_address>
**小问题(错误风险):** 只有在解压成功后才会删除归档。如果 `curl`、`unzip` 或 `tar` 留下部分或损坏的归档并失败,shell 会在执行 `rm -f` 之前退出,导致归档留在某些会保留或重复使用该目录的运行器的 `RUNNER_TEMP` 中。
**触发条件:** 在持久化的自托管运行器上下载或解压归档失败时。
**建议修复:** 在分配 `ARCHIVE_PATH` 后立即通过 shell `trap` 注册清理操作,以便在成功和失败时都删除归档。
```suggestion
ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
trap 'rm -f "$ARCHIVE_PATH"' EXIT
curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
rm -f "$ARCHIVE_PATH"
BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
else
ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"
trap 'rm -f "$ARCHIVE_PATH"' EXIT
curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"
tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"
rm -f "$ARCHIVE_PATH"
```
</issue_to_address>Original comment in English
Hey - I've found 2 issues
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="tests/action_download_test.py" line_range="4-15" />
<code_context>
+from pathlib import Path
+
+
+action = Path("action.yml").read_text()
+
+assert 'VERSION="v0.2.1"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"' in action
+assert 'unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"' in action
+assert 'tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"' in action
+assert action.count('rm -f "$ARCHIVE_PATH"') == 2
+assert '-o archive.zip' not in action
+assert '-o archive.tar.gz' not in action
</code_context>
<issue_to_address>
**issue (testing):** The CI test only searches for command strings in `action.yml`; it never executes the download, extraction, cleanup, or workspace-isolation behavior. A malformed or reordered shell script can therefore pass CI as long as the expected snippets remain present.
**Triggers:** When the archive-download implementation regresses without removing the asserted command text.
**Suggested fix:** Run the download logic in an isolated temporary workspace with mocked downloads, then assert the extracted binary, archive removal, and absence of workspace archive files.
</issue_to_address>
### Comment 2
<location path="action.yml" line_range="125-134" />
<code_context>
if [ "$RUNNER_OS" = "Windows" ]; then
- curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o archive.zip
- unzip -o archive.zip -d "$RUNNER_TEMP"
+ ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
+ curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
+ unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
+ rm -f "$ARCHIVE_PATH"
BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
else
- curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o archive.tar.gz
</code_context>
<issue_to_address>
**nitpick (bug_risk):** The archive is removed only after extraction succeeds. If `curl`, `unzip`, or `tar` leaves a partial/corrupt archive and fails, the shell exits before `rm -f`, leaving the archive in `RUNNER_TEMP` on runners where that directory is retained or reused.
**Triggers:** When downloading or extracting an archive fails on a persistent self-hosted runner.
**Suggested fix:** Register cleanup with a shell `trap` immediately after assigning `ARCHIVE_PATH`, so the archive is removed on both success and failure.
```suggestion
ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
trap 'rm -f "$ARCHIVE_PATH"' EXIT
curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
rm -f "$ARCHIVE_PATH"
BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
else
ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"
trap 'rm -f "$ARCHIVE_PATH"' EXIT
curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"
tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"
rm -f "$ARCHIVE_PATH"
```
</issue_to_address>
wyf9
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sourcery 总结
在工作区之外下载 verified-bot-commit 归档文件,并在 CI 中验证其行为。
错误修复:
增强功能:
CI:
测试:
Original summary in English
Sourcery 总结
在工作区之外下载 verified-bot-commit 归档文件,并在 CI 中验证相关行为。
Bug 修复:
增强功能:
CI:
测试:
Original summary in English
Sourcery 摘要
将 verified-bot-commit 归档下载保存在工作区之外,并在 CI 中验证相关行为。
错误修复:
改进:
CI:
测试:
Original summary in English
Summary by Sourcery
Keep verified-bot-commit archive downloads outside the workspace and validate the behavior in CI.
Bug Fixes:
Enhancements:
CI:
Tests: