docs(#3503): document RPM lockfile scope for UBI bump PRs - #3575
fullsend-ai-coder[bot] wants to merge 3 commits into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Risk Assessment: low (1/5) DetailsTier 1 signals unchanged from prior review — documentation-only bot PR with no code impact; since-prior delta is two heading capitalizations only, Tier 2/3 provide no escalation reason, preserving prior composite score of 1. Previous runRisk Assessment: low (1/5) DetailsPurely additive documentation PR by a bot adding 62 lines to AGENTS.md to document an undocumented workflow, with no source, CI, security-sensitive, or dependency changes; composite weighted score of 1.38 rounds to 1. Previous run (2)Risk Assessment: moderate (2/5) DetailsPurely additive documentation change to AGENTS.md tightly scoped to a well-defined issue; the only elevated signals are bot authorship and modification of a protected agent-instructions file. |
ReviewDocumentation-only change to FindingsMedium
Low
Previous runReviewDocumentation-only change to FindingsMedium
Low
Next steps:
Previous run (2)ReviewFindingsMedium
|
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
|
||
| ### RPM lockfile scope | ||
|
|
||
| `rpms.lock.yaml` is generated from `rpms.in.yaml` and only tracks the packages |
There was a problem hiding this comment.
/fs-fix The lockfile also contains resolved dependencies (for example, oniguruma), not only packages explicitly listed in rpms.in.yaml. Please clarify the scope accordingly.
|
/fs-fix The lockfile also contains resolved dependencies (for example, oniguruma), not only packages explicitly listed in rpms.in.yaml. Please clarify the scope accordingly. |
2 similar comments
|
/fs-fix The lockfile also contains resolved dependencies (for example, oniguruma), not only packages explicitly listed in rpms.in.yaml. Please clarify the scope accordingly. |
|
/fs-fix The lockfile also contains resolved dependencies (for example, oniguruma), not only packages explicitly listed in rpms.in.yaml. Please clarify the scope accordingly. |
🔧 Fix agent — iteration 1 (human-triggered)Updated AGENTS.md 'RPM lockfile scope' section to reflect that rpms.lock.yaml also contains resolved transitive dependencies (e.g. oniguruma pulled in by jq), not only the packages explicitly listed in rpms.in.yaml. Verified the claim directly against the repo's rpms.lock.yaml, which contains jq, gzip, and oniguruma. Also updated the follow-on 'no diff' explanation so 'tracked packages' unambiguously covers both explicitly listed packages and their transitive dependencies. Fixed (1):
Tests: passed CI inspections (14):
Decision points
Next steps:
|
Reviewer pointed out that rpms.lock.yaml carries not only the packages explicitly listed in rpms.in.yaml (ca-certificates, jq, gzip) but also their resolved transitive dependencies (e.g. oniguruma pulled in as a dependency of jq). Update the 'RPM lockfile scope' section in AGENTS.md to spell out both kinds of entries, define 'tracked packages' as the union of the two, and update the follow-on 'no diff' explanation so it covers transitive-dependency version changes as well. Note: pre-commit hooks were not run because the sandbox could not fetch the conforma/hooks repository (HTTP 403). The only configured hook is check-commit-message; no file-content hook applies to this docs change. Addresses #3575
|
🤖 Finished Review · ✅ Success · Started 12:44 PM UTC · Completed 12:52 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.84 |
|
🤖 Finished Fix · ✅ Success · Started 12:55 PM UTC · Completed 12:59 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.17 |
Rename "### RPM lockfile scope" to "### RPM Lockfile Scope" and "### Review guidance for UBI bump PRs" to "### Review Guidance for UBI Bump PRs" for consistency with the majority title-case pattern used by other multi-word H3 headings in AGENTS.md (e.g. "Acceptance Tests", "Test Tags", "Format"). Addresses two [naming-convention] findings from the review of PR #3575. The two [intent-coherence] and one [protected-path] findings are recorded as disagreements in the fix agent's structured output — they call for external coordination or human approval rather than a content change here. Note: pre-commit could not fetch its hook repositories (network blocked in sandbox); the sole configured hook (check-commit-message, commit-msg stage) has no file-scoped fallback. Tests and Go linters were not run because this change is heading text in AGENTS.md only, with no code paths affected. Addresses #3575
🔧 Fix agent — iteration 2 (bot-triggered)Renamed two new H3 headings added to AGENTS.md to title case to match the majority pattern in the file. Recorded disagreements for the protected-path merge-gate finding (only human approval can resolve it) and the two intent-coherence findings (they call for external coordination or are explicitly flagged as bounded/no-remediation). No code paths affected; tests and Go linters were not run because the change is heading text in AGENTS.md only. Pre-commit could not fetch its hook repositories (sandbox network policy); the sole configured hook (check-commit-message) is commit-msg-stage only and has no file-scoped fallback. Fixed (2):
Disagreed (3):
Tests: passed CI inspections (11):
Decision points
Next steps:
|
|
🤖 Finished Review · ✅ Success · Started 1:01 PM UTC · Completed 1:08 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.45 |
Superseded by updated review
|
/fs-fix rebase this pr |
Add a UBI Base Image Updates section to AGENTS.md that explains the relationship between hack/ubi-base-image-bump.sh, hack/update-rpm-lock.sh, and the scope of rpms.lock.yaml. The section documents that rpms.lock.yaml is regenerated from rpms.in.yaml and only tracks the explicitly listed packages (ca-certificates, jq, gzip). RPMs that live inside the ubi-minimal base image are not tracked, so a digest bump that only ships updates to base-image-bundled RPMs produces no diff in the lockfile even when regeneration ran successfully. The absence of documentation for this behavior led to a false-positive review finding on PR #3499 that claimed the lockfile was not regenerated, costing ~1.5 hours of reviewer back-and-forth. The added section gives reviewers (human and automated) enough context to dismiss the same finding on future UBI bump PRs. Also carries the release-v* branch guidance so all UBI-bump review context lives in one place. Note: pre-commit hooks were not run. `pre-commit` could not fetch the conforma/hooks repository (HTTP 403 from the sandbox), and the only configured hook (check-commit-message) runs at the commit-msg stage, not against files. The 'resolves: #3503' trailer below is formatted to satisfy that hook when it runs in CI. resolves: #3503
Reviewer pointed out that rpms.lock.yaml carries not only the packages explicitly listed in rpms.in.yaml (ca-certificates, jq, gzip) but also their resolved transitive dependencies (e.g. oniguruma pulled in as a dependency of jq). Update the 'RPM lockfile scope' section in AGENTS.md to spell out both kinds of entries, define 'tracked packages' as the union of the two, and update the follow-on 'no diff' explanation so it covers transitive-dependency version changes as well. Note: pre-commit hooks were not run because the sandbox could not fetch the conforma/hooks repository (HTTP 403). The only configured hook is check-commit-message; no file-content hook applies to this docs change. Addresses #3575
Rename "### RPM lockfile scope" to "### RPM Lockfile Scope" and "### Review guidance for UBI bump PRs" to "### Review Guidance for UBI Bump PRs" for consistency with the majority title-case pattern used by other multi-word H3 headings in AGENTS.md (e.g. "Acceptance Tests", "Test Tags", "Format"). Addresses two [naming-convention] findings from the review of PR #3575. The two [intent-coherence] and one [protected-path] findings are recorded as disagreements in the fix agent's structured output — they call for external coordination or human approval rather than a content change here. Note: pre-commit could not fetch its hook repositories (network blocked in sandbox); the sole configured hook (check-commit-message, commit-msg stage) has no file-scoped fallback. Tests and Go linters were not run because this change is heading text in AGENTS.md only, with no code paths affected. Addresses #3575
🔧 Fix agent — iteration 3 (human-triggered)Rebased PR #3575 onto origin/main at the human's request. All 3 PR commits replayed cleanly with no conflicts; AGENTS.md remains the only changed file. No code edits were made. The post-script will force-push with --force-with-lease. Fixed (1):
Tests: passed CI inspections (14):
Decision points
Next steps:
|
0c7c9a6 to
709e1be
Compare
|
🤖 Finished Review · ❌ Failure (ensuring provider "vertex-ai": provider create "vertex-ai" failed: exit status 1 (output: Error: × code: 'Client specified an invalid argument', message: "provider │ credentials are not declared by pr…) · Started 11:43 AM UTC · Completed 11:43 AM UTC Commit: Effort: high |
What:
Add a UBI Base Image Updates section to
AGENTS.mdthat documents:ubi-minimaldigest and the bumpworkflow (
hack/ubi-base-image-bump.sh→hack/update-rpm-lock.sh).rpms.lock.yaml— it is generated fromrpms.in.yamland only tracks the packages listed there (
ca-certificates,jq,gzip). RPMs that live inside the base image itself(
curl-minimal,glib2,libcurl-minimal,libnghttp2, etc.) arenot tracked.
rpms.lock.yamlafter a UBIdigest bump is the expected outcome when no tracked package's version
changed, and should not be flagged as "lockfile was not regenerated."
release-v*branches, bumps mayintentionally skip the acceptance Dockerfile.
Why:
On PR #3499, an automated reviewer flagged
rpms.lock.yamlas notregenerated after a UBI base image digest bump. The lockfile was
regenerated but produced no diff because the updated RPMs
(
curl-minimal,glib2,libcurl-minimal,libnghttp2) live insidethe base image and are not tracked in
rpms.in.yaml. The trackedpackages (
ca-certificates,jq,gzip) were unaffected. Dismissingthis false positive cost ~1.5 hours of reviewer back-and-forth.
The root cause is a documentation gap: nothing in the repo explained
what
rpms.lock.yamlactually tracks or why a no-diff regeneration isexpected. Documenting this in
AGENTS.mdgives both automatedreviewers and humans enough context to dismiss the same finding on
future UBI bump PRs without contacting the author.
Related work: PR #3504 adds a broader UBI Base Image Updates section
covering release-branch behavior. This PR focuses on the RPM lockfile
scope. If both land, the sections should be reconciled — the topics
are complementary.
Tickets:
Issue #3503.
Testing:
Documentation-only change to
AGENTS.md; no code paths are affected.Verified the added section renders as intended in the diff and that
the file has no other changes.
Closes #3503
Post-script verification
agent/3503-document-rpm-lockfile-scope)65cf118af7ebe9efb68a3fd396d0eb249a001ca5..HEAD)