A startup failure exits with a raw stack trace instead of the outcome line #57

Open
opened 2026-10-06 05:35:54 +00:00 by jercik · 0 comments
Owner

Everything that runs before runWrapper is outside its error handler. A failure there prints Node's uncaught-exception output, with a file path into the bundle, a source line and a stack, and no outcome line or remedy.

What happens

runWrapper catches errors and prints one line that names the outcome and the remedy (src/wrapper/orchestrator.ts:142-164). The setup in main.ts runs before it: the forge credentials and repository slug at module scope (src/main.ts:15-22) and readWrapperInputs as a top-level await (src/main.ts:27). A throw in either rejects the module.

That covers a missing environment variable, an unsupported event name, a malformed pr_number (src/wrapper/event-context.ts:47-61), a dispatch for a pull request that is merged, closed or of unknown state (src/wrapper/event-context.ts:74-88), and a failed forge read during a dispatch (src/wrapper/event-context.ts:123).

Reproduced at 9f272a52 with the committed bundle on Node 24.21.0 (s3-dispatch-fork-merged, and every s8 rejection): a dispatch for a merged pull request printed file:///…/dist/index.mjs:6239, the throw line, the stack and Node.js v24.21.0, and exited 1.

What it should do instead

Run input derivation inside the same handler, or catch it in main.ts, so each of these ends with one line that names the cause and exits 1. The exit code stays as it is. Refusing a merged pull request is correct; only how it is reported changes.

Why it matters

The outcome line is what a person reads first in the job log, and the failure table in the README promises one. A stack trace into a bundled file hides the cause (pull request #7 is already merged) behind frames that name no source file. It has no security effect.

🤖 Generated with Claude Code

Everything that runs before `runWrapper` is outside its error handler. A failure there prints Node's uncaught-exception output, with a file path into the bundle, a source line and a stack, and no outcome line or remedy. ## What happens `runWrapper` catches errors and prints one line that names the outcome and the remedy ([`src/wrapper/orchestrator.ts:142-164`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/src/wrapper/orchestrator.ts#L142-L164)). The setup in `main.ts` runs before it: the forge credentials and repository slug at module scope ([`src/main.ts:15-22`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/src/main.ts#L15-L22)) and `readWrapperInputs` as a top-level `await` ([`src/main.ts:27`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/src/main.ts#L27)). A throw in either rejects the module. That covers a missing environment variable, an unsupported event name, a malformed `pr_number` ([`src/wrapper/event-context.ts:47-61`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/src/wrapper/event-context.ts#L47-L61)), a dispatch for a pull request that is merged, closed or of unknown state ([`src/wrapper/event-context.ts:74-88`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/src/wrapper/event-context.ts#L74-L88)), and a failed forge read during a dispatch ([`src/wrapper/event-context.ts:123`](https://code.j4k.dev/j4k-oss/review-wrapper/src/commit/9f272a522e8ed6f748533761de45ee3e94fd7481/src/wrapper/event-context.ts#L123)). Reproduced at `9f272a52` with the committed bundle on Node 24.21.0 (`s3-dispatch-fork-merged`, and every `s8` rejection): a dispatch for a merged pull request printed `file:///…/dist/index.mjs:6239`, the `throw` line, the stack and `Node.js v24.21.0`, and exited 1. ## What it should do instead Run input derivation inside the same handler, or catch it in `main.ts`, so each of these ends with one line that names the cause and exits 1. The exit code stays as it is. Refusing a merged pull request is correct; only how it is reported changes. ## Why it matters The outcome line is what a person reads first in the job log, and the failure table in the README promises one. A stack trace into a bundled file hides the cause (`pull request #7 is already merged`) behind frames that name no source file. It has no security effect. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
j4k-oss/review-wrapper#57
No description provided.