Skip to content

fix: download archives outside workspace - #4

Merged
wyf9 merged 2 commits into
mainfrom
fix/temp-download-archive
Oct 2, 2026
Merged

wyf9 merged 2 commits into
mainfrom
fix/temp-download-archive

Conversation

@RhenCloud

@RhenCloud RhenCloud commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Sourcery 总结

在工作区之外下载 verified-bot-commit 归档文件,并在 CI 中验证其行为。

错误修复:

  • 将下载的归档文件存储在运行器临时目录中,使操作执行不会修改工作区或依赖工作区。

增强功能:

  • 将 verified-bot-commit 依赖项更新至 v0.2.1。

CI:

  • 将归档文件下载验证作为 CI 的一部分运行。

测试:

  • 增加测试覆盖,验证临时归档路径、提取、清理,以及移除工作区中的归档输出文件。
Original summary in English

Sourcery 总结

在工作区之外下载 verified-bot-commit 归档文件,并在 CI 中验证相关行为。

Bug 修复:

  • 将下载的 verified-bot-commit 归档文件存储在运行器的临时目录中,并在解压后删除它们,以确保操作不会修改工作区文件或依赖工作区文件。

增强功能:

  • 将 verified-bot-commit 依赖更新至 v0.2.1。

CI:

  • 在 CI 中运行归档文件下载验证。

测试:

  • 增加对临时归档路径、解压、清理以及不生成工作区归档文件的测试覆盖。
Original summary in English

Sourcery 摘要

将 verified-bot-commit 归档下载保存在工作区之外,并在 CI 中验证相关行为。

错误修复:

  • 将 verified-bot-commit 归档下载到运行器的临时目录,并在解压后删除,以确保该操作不会修改工作区。

改进:

  • 将 verified-bot-commit 依赖项更新至 v0.2.1。

CI:

  • 在 CI 中运行归档下载验证。

测试:

  • 增加对临时归档处理、解压、清理以及下载失败情况的覆盖。
Original summary in English

Summary by Sourcery

Keep verified-bot-commit archive downloads outside the workspace and validate the behavior in CI.

Bug Fixes:

  • Download verified-bot-commit archives into the runner’s temporary directory and remove them after extraction so the action does not modify the workspace.

Enhancements:

  • Update the verified-bot-commit dependency to v0.2.1.

CI:

  • Run archive download validation in CI.

Tests:

  • Add coverage for temporary archive handling, extraction, cleanup, and failed downloads.

@sourcery-ai

sourcery-ai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

审查者指南

该操作现在会将经过验证的 verified-bot-commit 归档下载到 RUNNER_TEMP,在不创建工作区文件的情况下解压并删除归档,并使用 v0.2.1。CI 会运行专门的静态检查,覆盖 Windows 和 Unix 归档流程。

临时 verified-bot-commit 归档下载时序图

sequenceDiagram
    participant Action
    participant Temp as RUNNER_TEMP
    participant Release as GitHub Release
    participant Workspace
    participant Tool as verified_bot_commit

    Action->>Release: curl archive URL for v0.2.1
    Release-->>Temp: Save archive
    Action->>Temp: Extract archive
    Action->>Temp: rm -f archive
    Action->>Tool: Execute extracted binary
    Note over Workspace: No archive output is created or read
Loading

文件级变更

变更 详细信息 文件
将下载的平台归档移入运行器临时目录,并在解压后删除。
  • 为 Windows 和 Unix 下载构建位于 RUNNER_TEMP 下的归档路径。
  • 直接从临时路径解压归档,并清理两种归档格式。
  • 将解压后的二进制文件保留在 RUNNER_TEMP 中,同时保留特定于平台的处理方式和权限。
action.yml
更新操作所使用的内置 verified-bot-commit 版本。
  • 将下载版本从 v0.2.0 更改为 v0.2.1。
action.yml
在 CI 中添加归档下载行为的自动验证。
  • 在 CI 测试作业中运行 Python 归档下载断言。
  • 验证临时路径、解压命令、清理操作,以及工作区中不存在归档输出。
.github/workflows/ci.yml
tests/action_download_test.py

提示和命令

与 Sourcery 交互

  • 触发新的审查: 在拉取请求中评论 @sourcery-ai review。
  • 继续讨论: 直接回复 Sourcery 的审查评论。
  • 根据审查评论生成 GitHub issue: 回复审查评论,请 Sourcery 根据该评论创建 issue。你也可以使用 @sourcery-ai issue 回复审查评论,以根据该评论创建 issue。
  • 生成拉取请求标题: 在拉取请求标题的任意位置写入 @sourcery-ai,即可随时生成标题。你也可以在拉取请求中评论 @sourcery-ai title,以随时(重新)生成标题。
  • 生成拉取请求摘要: 在拉取请求正文的任意位置写入 @sourcery-ai summary,即可在你指定的位置随时生成 PR 摘要。你也可以在拉取请求中评论 @sourcery-ai summary,以随时(重新)生成摘要。
  • 生成审查者指南: 在拉取请求中评论 @sourcery-ai guide,即可随时(重新)生成审查者指南。
  • 解决所有 Sourcery 评论: 在拉取请求中评论 @sourcery-ai resolve,即可解决所有 Sourcery 评论。如果你已经处理完所有评论且不想再看到它们,此功能非常有用。
  • 忽略所有 Sourcery 审查: 在拉取请求中评论 @sourcery-ai dismiss,即可忽略所有现有的 Sourcery 审查。如果你想从头开始新的审查,这尤其有用——别忘了评论 @sourcery-ai review 以触发新的审查!

自定义你的使用体验

访问你的控制面板以:

  • 启用或禁用审查功能,例如 Sourcery 生成的拉取请求摘要、审查者指南等。
  • 更改审查语言。
  • 添加、删除或编辑自定义审查说明。
  • 调整其他审查设置。

获取帮助

Original review guide in English

Reviewer's Guide

The action now downloads verified-bot-commit archives into RUNNER_TEMP, extracts and removes them without creating workspace files, and uses v0.2.1. CI runs focused static checks covering both Windows and Unix archive flows.

Sequence diagram for temporary verified-bot-commit archive download

sequenceDiagram
    participant Action
    participant Temp as RUNNER_TEMP
    participant Release as GitHub Release
    participant Workspace
    participant Tool as verified_bot_commit

    Action->>Release: curl archive URL for v0.2.1
    Release-->>Temp: Save archive
    Action->>Temp: Extract archive
    Action->>Temp: rm -f archive
    Action->>Tool: Execute extracted binary
    Note over Workspace: No archive output is created or read
Loading

File-Level Changes

Change Details Files
Move downloaded platform archives into the runner temporary directory and remove them after extraction.
  • Construct archive paths under RUNNER_TEMP for Windows and Unix downloads.
  • Extract archives directly from the temporary paths and clean up both archive formats.
  • Keep extracted binaries in RUNNER_TEMP while preserving platform-specific handling and permissions.
action.yml
Update the bundled verified-bot-commit release used by the action.
  • Change the download version from v0.2.0 to v0.2.1.
action.yml
Add automated validation for archive download behavior to CI.
  • Run the Python archive-download assertions in the CI test job.
  • Verify temporary paths, extraction commands, cleanup, and absence of workspace archive outputs.
.github/workflows/ci.yml
tests/action_download_test.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

嘿——我发现了 2 个问题

面向 AI Agent 的提示
请处理本次代码审查中的评论:

## 单独评论

### 评论 1
<location path="tests/action_download_test.py" line_range="4-15" />
<code_context>
+from pathlib import Path
+
+
+action = Path("action.yml").read_text()
+
+assert 'VERSION="v0.2.1"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"' in action
+assert 'unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"' in action
+assert 'tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"' in action
+assert action.count('rm -f "$ARCHIVE_PATH"') == 2
+assert '-o archive.zip' not in action
+assert '-o archive.tar.gz' not in action
</code_context>
<issue_to_address>
**问题(测试):** CI 测试只会在 `action.yml` 中搜索命令字符串;它从未执行下载、解压、清理或工作区隔离行为。因此,只要预期的代码片段仍然存在,即使 shell 脚本格式错误或顺序被打乱,也可能通过 CI。

**触发条件:** 归档下载实现发生回归,但被断言的命令文本未被移除时。

**建议修复:** 在隔离的临时工作区中使用模拟下载来运行下载逻辑,然后断言二进制文件已解压、归档已删除,并且工作区中不存在归档文件。
</issue_to_address>

### 评论 2
<location path="action.yml" line_range="125-134" />
<code_context>
       if [ "$RUNNER_OS" = "Windows" ]; then
-        curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o archive.zip
-        unzip -o archive.zip -d "$RUNNER_TEMP"
+        ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
+        curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
+        unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
+        rm -f "$ARCHIVE_PATH"
         BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
       else
-        curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o archive.tar.gz
</code_context>
<issue_to_address>
**小问题(错误风险):** 只有在解压成功后才会删除归档。如果 `curl`、`unzip` 或 `tar` 留下部分或损坏的归档并失败,shell 会在执行 `rm -f` 之前退出,导致归档留在某些会保留或重复使用该目录的运行器的 `RUNNER_TEMP` 中。

**触发条件:** 在持久化的自托管运行器上下载或解压归档失败时。

**建议修复:** 在分配 `ARCHIVE_PATH` 后立即通过 shell `trap` 注册清理操作,以便在成功和失败时都删除归档。

```suggestion
        ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
        trap 'rm -f "$ARCHIVE_PATH"' EXIT
        curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
        unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
        rm -f "$ARCHIVE_PATH"
        BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
      else
        ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"
        trap 'rm -f "$ARCHIVE_PATH"' EXIT
        curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"
        tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"
        rm -f "$ARCHIVE_PATH"
```
</issue_to_address>

Sourcery 对开源项目免费——如果您喜欢我们的审查,请考虑分享它们 ✨
Original comment in English

Hey - I've found 2 issues

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="tests/action_download_test.py" line_range="4-15" />
<code_context>
+from pathlib import Path
+
+
+action = Path("action.yml").read_text()
+
+assert 'VERSION="v0.2.1"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"' in action
+assert 'unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"' in action
+assert 'ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"' in action
+assert 'curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"' in action
+assert 'tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"' in action
+assert action.count('rm -f "$ARCHIVE_PATH"') == 2
+assert '-o archive.zip' not in action
+assert '-o archive.tar.gz' not in action
</code_context>
<issue_to_address>
**issue (testing):** The CI test only searches for command strings in `action.yml`; it never executes the download, extraction, cleanup, or workspace-isolation behavior. A malformed or reordered shell script can therefore pass CI as long as the expected snippets remain present.

**Triggers:** When the archive-download implementation regresses without removing the asserted command text.

**Suggested fix:** Run the download logic in an isolated temporary workspace with mocked downloads, then assert the extracted binary, archive removal, and absence of workspace archive files.
</issue_to_address>

### Comment 2
<location path="action.yml" line_range="125-134" />
<code_context>
       if [ "$RUNNER_OS" = "Windows" ]; then
-        curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o archive.zip
-        unzip -o archive.zip -d "$RUNNER_TEMP"
+        ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
+        curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
+        unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
+        rm -f "$ARCHIVE_PATH"
         BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
       else
-        curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o archive.tar.gz
</code_context>
<issue_to_address>
**nitpick (bug_risk):** The archive is removed only after extraction succeeds. If `curl`, `unzip`, or `tar` leaves a partial/corrupt archive and fails, the shell exits before `rm -f`, leaving the archive in `RUNNER_TEMP` on runners where that directory is retained or reused.

**Triggers:** When downloading or extracting an archive fails on a persistent self-hosted runner.

**Suggested fix:** Register cleanup with a shell `trap` immediately after assigning `ARCHIVE_PATH`, so the archive is removed on both success and failure.

```suggestion
        ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.zip"
        trap 'rm -f "$ARCHIVE_PATH"' EXIT
        curl -fsSL "${BASE_URL}/${ARCHIVE}.zip" -o "$ARCHIVE_PATH"
        unzip -o "$ARCHIVE_PATH" -d "$RUNNER_TEMP"
        rm -f "$ARCHIVE_PATH"
        BINARY="$RUNNER_TEMP/verified_bot_commit.exe"
      else
        ARCHIVE_PATH="$RUNNER_TEMP/${ARCHIVE}.tar.gz"
        trap 'rm -f "$ARCHIVE_PATH"' EXIT
        curl -fsSL "${BASE_URL}/${ARCHIVE}.tar.gz" -o "$ARCHIVE_PATH"
        tar -xzf "$ARCHIVE_PATH" -C "$RUNNER_TEMP"
        rm -f "$ARCHIVE_PATH"
```
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread tests/action_download_test.py Outdated
Comment thread action.yml Outdated
@wyf9
wyf9 merged commit 040ae82 into main Oct 2, 2026
5 checks passed
@RhenCloud
RhenCloud deleted the fix/temp-download-archive branch October 2, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants