Skip to content

Commit 2cdd38a

Browse files
committed
Merge branch 'pr1871latest'
# Conflicts: # tests/test_pr_review_autofix_nvidia_nim_contract.py
2 parents a9aeee8 + 9eba818 commit 2cdd38a

22 files changed

Lines changed: 944 additions & 40 deletions

‎scripts/ci/audit_codeql_default_setup_rollout.py‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -269,6 +269,7 @@ def load_payload(path: Path | None, stdin: TextIO) -> list[dict[str, Any]]:
269269

270270

271271
def parse_args(argv: list[str] | None = None) -> argparse.Namespace:
272+
"""Parse CLI arguments for either the file-payload or live-collection mode."""
272273
parser = argparse.ArgumentParser(description=__doc__)
273274
parser.add_argument("snapshots_json", nargs="?", type=Path)
274275
parser.add_argument("--repository")
@@ -277,6 +278,7 @@ def parse_args(argv: list[str] | None = None) -> argparse.Namespace:
277278

278279

279280
def main(argv: list[str] | None = None) -> int:
281+
"""Audit CodeQL rollout state from file or live snapshots and print verdicts."""
280282
args = parse_args(argv)
281283
try:
282284
live_mode = args.repository is not None or args.pr is not None

‎scripts/ci/noema_review_gate.py‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,6 @@
2424

2525
from scripts.ci.opencode_review_normalize_output import changed_file_is_material
2626

27-
2827
PRIMARY_REVIEW_AUTHORS = {
2928
"opencode-agent[bot]",
3029
"opencode-agent",
@@ -1636,7 +1635,10 @@ def call_llm(
16361635
gateway_telemetry: dict[str, str | int] = {}
16371636
if isinstance(exc, urllib.error.HTTPError):
16381637
active_phase = "response_error"
1639-
gateway_telemetry = _extract_http_error_telemetry(exc)
1638+
try:
1639+
gateway_telemetry = _extract_http_error_telemetry(exc)
1640+
finally:
1641+
exc.close()
16401642
model_value = gateway_telemetry.get("served_model")
16411643
served_model = model_value if isinstance(model_value, str) else None
16421644
elapsed = time.monotonic() - attempt_started

‎scripts/ci/pingora_edge_policy.py‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -304,6 +304,8 @@ def _github_open_json(url: str, token: str) -> object:
304304
with github_opener.open(request, timeout=30) as response:
305305
payload = response.read(MAX_RESPONSE_BYTES + 1)
306306
except (HTTPError, URLError, TimeoutError) as exc:
307+
if isinstance(exc, HTTPError):
308+
exc.close()
307309
raise PolicyError(f"GitHub API request failed for policy evidence: {type(exc).__name__}") from exc
308310
if len(payload) > MAX_RESPONSE_BYTES:
309311
raise PolicyError("GitHub API policy response exceeded the bounded response size")

‎scripts/ci/pr_review_merge_scheduler_core.py‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ class SchedulerAdmissionGate:
4747
"""Persist and bound review-worker leases for one scheduler execution."""
4848

4949
def __init__(self, state_path: Path, *, sequence: int, dispatch_budget: int) -> None:
50+
"""Bind this gate to one durable state file, run sequence, and worker budget."""
5051
if sequence < 1:
5152
raise ValueError("admission sequence must be positive")
5253
if dispatch_budget < 0:
@@ -68,6 +69,7 @@ def admit(self, component: str, repository: str, pr: dict[str, Any]) -> bool:
6869
selected: list[DispatchLease] = []
6970

7071
def lease(state):
72+
"""Apply this request to `state` and record any lease it wins."""
7173
plan = plan_dispatches(
7274
state,
7375
[request],
@@ -88,6 +90,7 @@ def reconcile(self, repository: str, prs: Sequence[dict[str, Any]]) -> None:
8890
live_prs = {int(pr["number"]): pr for pr in prs}
8991

9092
def reconcile_state(state):
93+
"""Mark exact-head dispatched leases complete and superseded ones stale."""
9194
records = dict(state.records)
9295
latest = dict(state.latest_sequences)
9396
for identity, record in tuple(records.items()):

‎scripts/ci/reconcile_repository_metadata.py‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,9 @@
1616
import sys
1717
from pathlib import Path
1818
from typing import Any
19-
from urllib.error import URLError
19+
from urllib.error import HTTPError, URLError
2020
from urllib.request import HTTPRedirectHandler, Request, build_opener
2121

22-
2322
ORGANIZATION = "ContextualWisdomLab"
2423
REPOSITORY_RE = re.compile(r"^[A-Za-z0-9_.-]+$")
2524
TOPIC_RE = re.compile(r"^[a-z0-9][a-z0-9-]{0,49}$")
@@ -247,6 +246,8 @@ def _pages_publication_ready(repository: str, current: dict[str, Any]) -> None:
247246
if not response.read(1):
248247
raise RuntimeError(f"GitHub Pages returned empty content for {repository}")
249248
except (URLError, TimeoutError, OSError) as exc:
249+
if isinstance(exc, HTTPError):
250+
exc.close()
250251
raise RuntimeError(f"GitHub Pages is not reachable for {repository}") from exc
251252

252253

‎scripts/ci/review_admission_controller.py‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,15 @@
2020

2121
@dataclass(frozen=True)
2222
class WorkerBoundary:
23+
"""The credential, permission set, and concurrency namespace one review worker runs under."""
24+
2325
credential: str
2426
permissions: tuple[str, ...]
2527
concurrency_namespace: str
2628
cancel_in_progress: bool = True
2729

2830
def concurrency_group(self, request: AdmissionRequest) -> str:
31+
"""Return this worker's `{namespace}-{repository}-{pull_request}` concurrency group."""
2932
return (
3033
f"{self.concurrency_namespace}-{request.repository}-{request.pull_request}"
3134
)
@@ -52,6 +55,8 @@ def concurrency_group(self, request: AdmissionRequest) -> str:
5255

5356
@dataclass(frozen=True)
5457
class AdmissionRequest:
58+
"""One validated request to admit a review worker onto a specific PR head."""
59+
5560
repository: str
5661
pull_request: int
5762
head_sha: str
@@ -68,6 +73,7 @@ def create(
6873
component: str,
6974
sequence: int,
7075
) -> AdmissionRequest:
76+
"""Validate and normalize raw fields into an `AdmissionRequest`."""
7177
if isinstance(pull_request, bool) or not isinstance(pull_request, int):
7278
raise TypeError("pull request must be an integer")
7379
if isinstance(sequence, bool) or not isinstance(sequence, int):
@@ -87,35 +93,45 @@ def create(
8793

8894
@property
8995
def identity(self) -> str:
96+
"""Return the unique key identifying this exact request (including its sequence)."""
9097
return f"{self.repository}#{self.pull_request}@{self.head_sha}:{self.component}"
9198

9299
@property
93100
def stream(self) -> str:
101+
"""Return the key identifying this request's PR+component stream across sequences."""
94102
return f"{self.repository}#{self.pull_request}:{self.component}"
95103

96104

97105
@dataclass(frozen=True)
98106
class RequestRecord:
107+
"""An admission request paired with its current lifecycle status."""
108+
99109
request: AdmissionRequest
100110
status: str
101111

102112

103113
@dataclass(frozen=True)
104114
class DispatchLease:
115+
"""A request that has been granted a worker boundary to run under."""
116+
105117
request: AdmissionRequest
106118
boundary: WorkerBoundary
107119

108120

109121
@dataclass(frozen=True)
110122
class ControllerState:
123+
"""The durable admission controller's full state: known records and per-stream sequences."""
124+
111125
records: dict[str, RequestRecord]
112126
latest_sequences: dict[str, int]
113127

114128
@classmethod
115129
def empty(cls) -> ControllerState:
130+
"""Return the initial state with no records and no sequences observed yet."""
116131
return cls({}, {})
117132

118133
def to_json(self) -> str:
134+
"""Serialize this state to its canonical, deterministically-ordered JSON form."""
119135
payload = {
120136
"latest_sequences": self.latest_sequences,
121137
"records": {
@@ -130,6 +146,7 @@ def to_json(self) -> str:
130146

131147
@classmethod
132148
def from_json(cls, value: str) -> ControllerState:
149+
"""Parse and fully validate a state snapshot, rejecting any inconsistent JSON."""
133150
payload = json.loads(value)
134151
if not isinstance(payload, dict):
135152
raise TypeError("durable admission state must be an object")
@@ -204,6 +221,7 @@ def _open_regular_nofollow(path: Path, flags: int, mode: int = 0o600) -> int:
204221

205222

206223
def _read_state(path: Path) -> ControllerState:
224+
"""Read and parse one state file, rejecting a symlink and non-UTF-8 content."""
207225
descriptor = _open_regular_nofollow(path, os.O_RDONLY)
208226
try:
209227
with os.fdopen(descriptor, encoding="utf-8") as stream:
@@ -282,6 +300,8 @@ def update_state_file(
282300

283301
@dataclass(frozen=True)
284302
class DispatchPlan:
303+
"""The result of one admission pass: the updated state, grants, and rejections."""
304+
285305
state: ControllerState
286306
dispatches: tuple[DispatchLease, ...]
287307
rejections: dict[str, str]

‎scripts/ci/sandboxed_web_e2e.py‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,9 +7,9 @@
77
import json
88
import os
99
import platform
10-
import signal
11-
import shutil
1210
import shlex
11+
import shutil
12+
import signal
1313
import socket
1414
import subprocess
1515
import sys
@@ -27,7 +27,6 @@
2727

2828
from scripts.ci import sandboxed_verify
2929

30-
3130
RESULT_MARKER = "SANDBOXED_WEB_E2E_RESULT"
3231
SANDBOX_MOUNT = "/workspace"
3332

@@ -584,7 +583,9 @@ def wait_for_url(url: str, timeout: int, service: Service) -> bool:
584583
if 200 <= response.status < 500:
585584
return True
586585
time.sleep(1)
587-
except (urllib.error.URLError, TimeoutError):
586+
except (urllib.error.URLError, TimeoutError) as exc:
587+
if isinstance(exc, urllib.error.HTTPError):
588+
exc.close()
588589
time.sleep(1)
589590
return False
590591

0 commit comments

Comments
 (0)