docs: correct the service URL and PR-input rows of the environment table #37
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/env-table-accuracy"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Answers the review of #34 (claims
01M44EVPVQHRSTQHN71HRTHTSKand01M44EX41M27Y04WKDRRFP5MMH): two rows of the environment contract table claimed more than the code does.REVIEW_SERVICE_URLis rejected when its path ends in/v1/as well as/v1. Onworkflow_dispatchthe event payload supplies onlypr_number; the head SHA, branches, repository and state come from the forge.🤖 Generated with Claude Code
Review
01M44K67TVFXDNS7B3NBWNEKB8— head3f7917649d79a22a45854022bfcae70f9f6cf023Review — j4k-oss/review-wrapper @
bed47dc989Scope: diff against base tree
e69943819640Status: dispatched — coverage complete (5/5 slots terminal)
Facts: current review-wide projection
Computed under:
Findings (7)
medium — Outcome table restates the executable result and exit-code set
01M44NTXBKSY1RFQ9C2QVKM4TVREADME.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The grounded README row is part of a reported table that copies all eleven OUTCOMES members and their OUTCOME_EXIT values from src/contract/types.ts. A separate superseded flag row does not undo the duplicated outcome set. The copies currently agree, so medium fits; point to the constants and retain only behavior they do not explain.medium — Environment contract repeats the variables read by the wrapper
01M44NVTCNYZBJXSB7XHSA1MZ7README.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The grounded README sentence and reported table repeat the environment names read in src/credentials.ts, src/wrapper/event-context.ts, and src/main.ts. Expanding GITHUB_EVENT_* yields the reported source members; the body initially says nine but explicitly counts ten, a harmless count slip in its explanation. Point to the readers while keeping the fork-gate and failure behavior. The earlier same-anchor verdict supplies no contrary evidence.medium — Action inputs table copies the manifest input
01M44NWD3WEGT6QN7XK59DECMZREADME.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The grounded README row lists expected-service-origin, and the reported comparison says action.yml defines that sole input and repeats its description. The manifest is the input source, so the README table is a second editable set. Point to action.yml. Earlier same-anchor allegations about URL validation concern a separate wording defect and do not refute this duplication.medium — Recovery table restates the failure remedy map
01M44NX49DRD0K5WWFPPH4FFEEREADME.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The reported executionRemedies map in src/wrapper/remedies.ts defines four named failure remedies plus a fallback, while the grounded README table and reported comparison cover the displayed counterparts. That is a second remedy inventory. The external display-label mapping is unverified, but either a matching or mismatching label leaves this duplicated or stale table defective; follow the emitted remedy and point to formatExecutionRecovery. Medium fits the reported agreement.medium — Composition summary restates the reconciler set
01M44NXG523X5YEG67PQVVG1W1README.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The grounded composition excerpt and reported source comparison show README counts and names summary, inline, and dispositions as the complete reconciler set wired in src/main.ts and WrapperDeps. A code change can leave that count and list stale. Point to the wiring and retain the distinct orchestration and exit-code facts.medium — Dispatch description omits the required PR-number input
01M44NYTXV5Y34CWS7D96BEY3HREADME.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The grounded row says a workflow_dispatch run fetches the PR from the forge, while the reported readWrapperInputs trace first requires payload.inputs.pr_number and rejects its absence. A workflow author could omit that prerequisite and get a failed manual run. Add only that required input before the fetch description; the code pointer alone does not communicate it.medium — Empty origin pin still enforces more than the HTTPS scheme
01M44NZSG9QBYDHYT0A2YFHB4KREADME.md(snippet)01M44P1PDV8E80FJQNBT4DZ626· valid: The grounded row says an empty origin pin leaves only HTTPS enforcement. The reported call trace says reviewCredentials always calls serviceOrigin first, and it rejects an HTTPS URL ending in /v1 even with no pin; the reported test covers that rejection. The row therefore overstates what disabling the pin allows. Say it skips only the origin match and keep URL validation at its source. Earlier same-anchor input-inventory claims describe a different defect.Other claims
Coverage
Coverage pass: 01M44NHF06BM7C3G4SANAGC4BE
Accounting: complete
Slot health: healthy
@ -22,1 +15,3 @@| `GITHUB_RUN_ATTEMPT` | Forgejo run attempt (1-based). Required on every path. The wrapper re-triages stalled or failed triage only when this is ≥ 2. || Variable | Meaning || ------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- || `REVIEW_SERVICE_URL` | Base URL of the review service (an org-managed variable). Must parse as an `https:` URL whose path does not end in `/v1` or `/v1/`, because the client appends `/v1`. |medium — The service URL guidance copies the forbidden path suffixes
lens
restated-sets· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44FQEVVASXA9MEHF4ZEM43Vof review01M44FFYXGJXA6XHKADPDH94A0Fixed in
c02a237@ -23,0 +18,4 @@| `REVIEW_CAPABILITY_TOKEN` | Capability token for the service's `/v1` API (an org secret). || `FORGEJO_TOKEN` | The job's own task token, used for every forge write. || `GITHUB_API_URL` | Forge API base, supplied by the runner. || `GITHUB_EVENT_*`, `GITHUB_RUN_ID`, … | Runner event environment. `pull_request_target` reads PR details from the payload; `workflow_dispatch` reads only `pr_number` and fetches the rest from the forge. |medium — The event environment guidance copies both supported event modes
lens
restated-sets· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44FQXBGDK887K5NNM7ZB7SPof review01M44FFYXGJXA6XHKADPDH94A0medium — The dispatch guidance copies the sole payload input
lens
restated-sets· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44FS7MGTRS78178F7M3XCSRof review01M44FFYXGJXA6XHKADPDH94A0Fixed in
c02a237Fixed in
c02a237@ -23,3 +21,5 @@| `GITHUB_EVENT_*`, `GITHUB_RUN_ID`, … | Runner event environment. `pull_request_target` reads PR details from the payload; `workflow_dispatch` reads only `pr_number` and fetches the rest from the forge. || `GITHUB_RUN_ATTEMPT` | Forgejo run attempt (1-based). Required on every path. The wrapper re-triages stalled or failed triage only when this is ≥ 2. |The forge and runner variables — `FORGEJO_TOKEN`, `GITHUB_API_URL`, `GITHUB_EVENT_*`,`GITHUB_RUN_ID`, `GITHUB_RUN_ATTEMPT`, `GITHUB_REPOSITORY`, `GITHUB_SERVER_URL` — aremedium — The required environment-variable list duplicates the input checks
lens
writing-quality· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44GZQPJCBT3V27HCJ8KY3GTof review01M44FFYXGJXA6XHKADPDH94A0Valid. The list of required variables predates this PR, which changes only two rows of the table above it. #32 replaces the list with pointers to
forgeCredentials,readWrapperInputsandsrc/main.ts.This is review
01M44FFYXGJXA6XHKADPDH94A0of6c997aa. Dispatch run 64023 completed it after run 63863 lost its writing-quality slot to model capacity. The three findings on this PR's two table rows are fixed inc02a237and answered in their threads, and #123845 is answered in its thread. The four summary-only findings are about README text this PR doesn't change, and the PR that owns each text already handles it:01M44GYJ3E9AJ5D1B7BM6RVJTJ(outcome table) is valid. #30 replaces the table with a pointer toOUTCOMESandOUTCOME_EXIT.01M44GZA3SC497K2CQ6KTZ55KP(action-input table) is valid. #34 points the README ataction.yml.01M44H03Q3R3CW3Q54S7WVKBSR(composition paragraph) is valid. #32 points atWrapperDeps.01M44H13H1D9ZVDJVWZQV5TJS4(recovery table) is valid. #34 replaces the table with the remedy printed on the failure log line.The four duplicate claims,
01M44GVCF6NTE12F7BW1NWSAYZ,01M44GX697RYJDZ04F855R941Q,01M44GVN20E2HERV6AXANA7KH6and01M44GWSQB5Y1SSKK2119KW503, are covered by the threads of the findings they duplicate.@ -23,0 +18,4 @@| `REVIEW_CAPABILITY_TOKEN` | Capability token for the service's `/v1` API (an org secret). || `FORGEJO_TOKEN` | The job's own task token, used for every forge write. || `GITHUB_API_URL` | Forge API base, supplied by the runner. || `GITHUB_EVENT_*`, `GITHUB_RUN_ID`, … | Runner event environment. `readWrapperInputs` in `src/wrapper/event-context.ts` derives the PR inputs from it for each event the wrapper supports. |low — Environment table misstates where workflow dispatch gets PR state
lens
general-bug· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44HW31SG0SQ794AF4N3BKQPof review01M44HQNME6B9VAE2MGYCZKPXJFixed in
3f79176. The row now says the event environment identifies the pull request, and that aworkflow_dispatchrun fetches the PR's current state from the forge. It points atreadWrapperInputsfor how the inputs are derived.@ -23,3 +21,5 @@| `GITHUB_EVENT_*`, `GITHUB_RUN_ID`, … | Runner event environment. `readWrapperInputs` in `src/wrapper/event-context.ts` derives the PR inputs from it for each event the wrapper supports. || `GITHUB_RUN_ATTEMPT` | Forgejo run attempt (1-based). Required on every path. The wrapper re-triages stalled or failed triage only when this is ≥ 2. |The forge and runner variables — `FORGEJO_TOKEN`, `GITHUB_API_URL`, `GITHUB_EVENT_*`,`GITHUB_RUN_ID`, `GITHUB_RUN_ATTEMPT`, `GITHUB_REPOSITORY`, `GITHUB_SERVER_URL` — aremedium — Required environment variables are copied into README prose
lens
writing-quality· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44HZ794Q1MQD16Q0FH8VFAXof review01M44HQNME6B9VAE2MGYCZKPXJValid. The sentence predates this PR, which changes only two cells of the table above it. #32 already replaces the variable list with pointers to
forgeCredentials,readWrapperInputsandsrc/main.ts.This is review
01M44HQNME6B9VAE2MGYCZKPXJofc02a237. The two findings with threads are answered there. The event row's dispatch error is fixed in3f79176, and the duplicate claim01M44J5WZVJ4SF3J565Y5C1WKEis covered by that thread. The other six are summary-only, about README text this PR doesn't change:01M44HZS0KRSTSY2G3CBCT79VW(action-input table) and01M44J1TARJ7VX7DT4DJNJHGRB(recovery table) are valid. #34 points the README atinputsinaction.ymland at the remedy printed on the failure log line.01M44J0F1W6H9S1VC9JC0AHSJN(outcome table) is valid. #30 replaces the table with a pointer toOUTCOMESandOUTCOME_EXIT.01M44J18M9V43V0RPG7MKTG48R(composition paragraph) is valid. #32 points atWrapperDeps.01M44J46M5G05CVCBP3JFRC5R5(the fork-gate bullet says no credentials module runs before the gate) is valid:forgeCredentials()reads the forge token first. #33 corrects the bullet to namereviewCredentials().01M44J54BBK4B8V4BDJEWYP7XH(an unset origin pin still validates the URL) is valid:reviewCredentials()always callsserviceOrigin(), which rejects a/v1suffix with or without the pin. #34 removes the README's copy of that sentence, and #41 corrects the original inaction.yml. It targetsmain, because the sentence is older than this PR.@ -23,0 +18,4 @@| `REVIEW_CAPABILITY_TOKEN` | Capability token for the service's `/v1` API (an org secret). || `FORGEJO_TOKEN` | The job's own task token, used for every forge write. || `GITHUB_API_URL` | Forge API base, supplied by the runner. || `GITHUB_EVENT_*`, `GITHUB_RUN_ID`, … | Runner event environment. It identifies the pull request; a `workflow_dispatch` run fetches the PR's current state from the forge. `readWrapperInputs` in `src/wrapper/event-context.ts` derives the PR inputs. |medium — Dispatch description omits the required PR-number input
lens
writing-quality· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44NYTXV5Y34CWS7D96BEY3Hof review01M44K67TVFXDNS7B3NBWNEKB8@ -23,3 +21,5 @@| `GITHUB_EVENT_*`, `GITHUB_RUN_ID`, … | Runner event environment. It identifies the pull request; a `workflow_dispatch` run fetches the PR's current state from the forge. `readWrapperInputs` in `src/wrapper/event-context.ts` derives the PR inputs. || `GITHUB_RUN_ATTEMPT` | Forgejo run attempt (1-based). Required on every path. The wrapper re-triages stalled or failed triage only when this is ≥ 2. |The forge and runner variables — `FORGEJO_TOKEN`, `GITHUB_API_URL`, `GITHUB_EVENT_*`,`GITHUB_RUN_ID`, `GITHUB_RUN_ATTEMPT`, `GITHUB_REPOSITORY`, `GITHUB_SERVER_URL` — aremedium — Environment contract repeats the variables read by the wrapper
lens
writing-quality· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M44NVTCNYZBJXSB7XHSA1MZ7of review01M44K67TVFXDNS7B3NBWNEKB8Valid for the sentence after the table, which predates this PR. #32 already replaces its variable list with pointers to
forgeCredentials,readWrapperInputsandsrc/main.ts.Replacing the table itself is held, not applied, as
01M44DH5HKQFA3T9JJSGAEFP8Mwas on #30: the table is the only place that tells a calling workflow which variables to set and what each must hold.Valid:
readWrapperInputsreadsinputs.pr_numberon aworkflow_dispatchevent andparsePrNumberthrows when it is absent, and the README never names the input. #43 adds the requirement to the Notes paragraph that already says what a dispatch run needs and refuses. It targetsmain, so it doesn't wait for this PR.This is review
01M44K67TVFXDNS7B3NBWNEKB8of3f79176. Dispatch run 64696 completed it after an event run and two dispatch runs lost slots to model capacity and sandbox failures. The two findings with threads are answered there: the dispatch row's missingpr_numberprerequisite goes to #43, and the variable list after the table to #32. The other five are summary-only. Each repeats a finding of the previous review about README text this PR doesn't change:01M44NTXBKSY1RFQ9C2QVKM4TV(outcome table): #30 replaces the table with a pointer toOUTCOMESandOUTCOME_EXIT.01M44NWD3WEGT6QN7XK59DECMZ(action-input table) and01M44NX49DRD0K5WWFPPH4FFEE(recovery table): #34 points the README atinputsinaction.ymland at the remedy printed on the failure log line.01M44NXG523X5YEG67PQVVG1W1(composition paragraph): #32 points atWrapperDeps.01M44NZSG9QBYDHYT0A2YFHB4K(an unset origin pin still validates the URL): #34 removes the README's copy of that sentence, and #41 corrects the original inaction.yml.The half held above is declined: the environment table stays. It is the usage contract for someone wiring the action into another repository, and no single definition exists to point at, because
src/credentials.ts,src/wrapper/event-context.tsandsrc/main.tseach read part of the set. The sentence after the table still gets its pointers in #32.