Skip to content

fix: bound validation report publication without losing verdicts - #48

Open
olavurellefsen wants to merge 1 commit into
mainfrom
fix/bounded-validation-report-publication
Open

olavurellefsen wants to merge 1 commit into
mainfrom
fix/bounded-validation-report-publication

Conversation

@olavurellefsen

@olavurellefsen olavurellefsen commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Large validation reports can fail after a completed review because cat | head triggers SIGPIPE under pipefail, or because the PR comment exceeds GitHub’s limit. This patch reads the preview directly, uploads the complete validated report first, and posts a comment bounded to 60,000 UTF-8 bytes with the action result and full artifact link kept visible.

The formatter changes presentation only. Strict final-assistant extraction, verdict parsing, grounding enforcement, tool permissions, model choices and release policy are unchanged. Missing artifacts and failed validation steps are explicit. Reviewer instructions use workspace reads and final stdout instead of temporary-file copies or permission workarounds.

Validation: all 40 Python tests pass, including six new regressions for large reports through actual orchestration, Unicode boundaries, retained failure status, artifact preservation and the actual GitHub comment script against a local mock. Pinned installer, MCP restriction, dependency, workflow, secret and release-policy checks pass, along with Bash/Node syntax, YAML parsing and git diff --check.

Based on released v2.2.7 (f10856bcf763f94fbdf0b9edd01b3e168d8462ac). This ready-for-review candidate publishes no shared tag and remains unmerged. A reviewed consumer now pins this exact repair commit and its application CI plus both real standards/security reports passed with zero critical or important issues. Grounding remains NOT REQUIRED as configured, rather than claiming deterministic certification. The consumer source PR has merged; no other consumers changed. The action’s own hosted run passes deterministic checks, but two advisory AI cases produced safe infrastructure-failure reports while comment revalidation produced a structured PASS. Those limitations remain separate from the successful real consumer pilot.

@github-actions

Copy link
Copy Markdown

🤖 Documentation Validation

Action result: ERROR · Critical issues: 0 · Grounding: not-required

Full validated report artifact (pr-validation-documentation-validation).

PR Validation Report

Summary

The provider completed, but its final assistant response was not a valid validation report.

Critical Violations ❌

  • Validation infrastructure failure: No validated assistant report is available for publication.

Validation Outcome

  • Status: FAIL ❌
  • Critical Issues: 1
  • Important Issues: 0
  • Suggestions: 0

📊 Validation Statistics

@github-actions

Copy link
Copy Markdown

🤖 Comment Revalidation Test

Action result: PASSED · Critical issues: 0 · Grounding: not-required

Full validated report artifact (pr-validation-comment-revalidation-test).

PR Validation Report

Summary

This is a comment revalidation test for the Usable PR Validator. The PR fixes large validation report publication by handling GitHub's 60,000-byte comment limit through a new formatter script that truncates safely while preserving action results and artifact links. The test includes comprehensive Python unit tests and system prompt improvements.

Override Comment Test Results

  • Override Detected: ✅ Yes
  • Comment Author: @test-user
  • Request Type: Deviation Approval (Test)
  • Justification: "This PR is a test. Please approve this as a test of the comment revalidation feature. This simulates a developer requesting approval for a deviation from standards."

Override Applied

A deviation from standards has been approved and documented:

  • Deviation: Standard PR validation process bypass for testing purposes
  • Justification: User explicitly stated this is a test of the comment revalidation feature
  • Documentation: Attempted to create fragment (access restrictions prevented completion)
  • Approved by: @test-user

This deviation has been acknowledged for this test run. The comment revalidation feature successfully detected the override marker (🔄) and parsed the deviation request.

Critical Violations ❌

None found (test scenario)

Important Issues ⚠️

None found (test scenario)

Suggestions ℹ️

  • Comment revalidation feature: Working correctly ✅

    • Successfully detected override comment with 🔄 marker
    • Parsed deviation request from @test-user
    • Adjusted validation accordingly
  • New format-pr-comment.cjs module: Well-structured

    • Properly handles 60,000 UTF-8 byte limit
    • Safe multi-byte character truncation at line 11-12
    • Preserves action result visibility in prefix
    • Includes artifact link when available
  • Test coverage: Comprehensive with 6 new test cases in tests/test_report_publication.py

    • Short report completeness
    • Large failed report preservation
    • Multi-byte/Unicode boundary handling
    • Failed/missing step handling
    • Action integration testing
    • SIGPIPE avoidance verification
  • action.yml improvements: Good architectural changes

    • Upload Validation Report step now runs before Post PR Comment (correct order)
    • Environment variables properly extracted from step outputs
    • Script uses new formatter module correctly
  • validate.sh fix: Simple but important

    • Changed from cat ... | head to head directly, avoiding SIGPIPE issues
  • system-prompt.md enhancements:

    • Added explicit instruction to return report on stdout, not to files
    • Clarified reviewer workflow for reading files directly

Grounding Status

  • Status: NOT REQUIRED
  • Detail: No required fragment IDs were declared; this run is not certified as deterministically grounded.

Validation Outcome

  • Status: PASS ✅
  • Test Type: Comment Revalidation
  • Override Support: Tested and Working
  • Critical Issues: 0
  • Important Issues: 0
  • Suggestions: 5

📊 Validation Statistics

@github-actions

Copy link
Copy Markdown

🤖 Integration Test Validation

Action result: ERROR · Critical issues: 0 · Grounding: not-required

Full validated report artifact (pr-validation-integration-test-validation).

PR Validation Report

Summary

The provider completed, but its final assistant response was not a valid validation report.

Critical Violations ❌

  • Validation infrastructure failure: No validated assistant report is available for publication.

Validation Outcome

  • Status: FAIL ❌
  • Critical Issues: 1
  • Important Issues: 0
  • Suggestions: 0

📊 Validation Statistics

@olavurellefsen
olavurellefsen marked this pull request as ready for review September 24, 2026 11:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant