Skip to content

chore: release v4.16.2 - #226

Merged
Chachamaru127 merged 5 commits into
mainfrom
release/v4.16.2-phase103
Jun 24, 2026
Merged

Chachamaru127 merged 5 commits into
mainfrom
release/v4.16.2-phase103

Conversation

@Chachamaru127

@Chachamaru127 Chachamaru127 commented Jun 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

Release candidate for v4.16.2.

This promotes the local dogfood runtime safety change to the public release line while keeping the redesign branch separate.

Changes

Boundary

Verification

  • bash tests/test-release-verify-publish.sh: PASS
  • bash tests/test-release-skill-no-gh-release.sh: PASS
  • bash scripts/sync-skill-mirrors.sh --check: PASS
  • bash scripts/sync-version.sh check: PASS
  • go test ./go/internal/runtimefloor ./go/internal/guardrail: PASS
  • bash tests/validate-plugin.sh: PASS (104 passed)
  • bash scripts/ci/check-consistency.sh: PASS
  • bash scripts/release-preflight.sh --check-adapters: 19 PASS / 5 WARN / 0 FAIL
  • claude plugin validate .claude-plugin/plugin.json: PASS with existing CLAUDE.md root warning
  • claude plugin tag .claude-plugin --dry-run: PASS, tag claude-code-harness--v4.16.2

Warnings / residual risk

release-preflight warnings are existing project-surface warnings, not release-candidate failures:

  • .env.example not found; env parity skipped
  • healthcheck command not configured
  • runtime residual scan warns on existing TODO/local/mock regex hits
  • sprint-contract schema scan skipped
  • CI status unavailable before branch push

Release execution plan after merge

  • Verify main contains the release commits.
  • Create Claude plugin tag claude-code-harness--v4.16.2 from main.
  • Create semver tag v4.16.2 from main for the release workflow.
  • Push tags.
  • Verify the workflow-published release has draft=false and at least 4 assets.

Summary by CodeRabbit

リリースノート

  • New Features
    • ランタイムアクションの実行前にコマンドを自動評価し、危険操作(金銭取引、外部への通信、秘密情報の読み取り、本番公開・デプロイ、作業ツリー外の削除など)では人間のエスカレーションを必須化しました。
  • Bug Fixes
    • /harness-release の自動完走失敗を解消するため、公開確認をワークフローの verify に委譲しました。
  • Documentation
    • runtime hard floor とリリース確認手順の説明を更新しました。
  • Chores
    • バージョンを 4.16.2 に更新しました。

Chachamaru127 and others added 4 commits June 23, 2026 15:53
…ase 92.2.1)

- go/internal/runtimefloor: 新規 package。Bash command の pattern-match で
  money-billing / egress / secret-read / prod-deploy / worktree-escape の
  5 カテゴリを実行前 (PreToolUse) に hard-stop し human escalation を強制
  - CheckCommand は disable flag / env var / config 読込を構造的に持たない
    (override 不可を if 文ではなく API 設計で保証)
  - egress 検出は scheme 付き URL + schemeless host authority (curl/wget)
    両方を扱い、allowlist は localhost / 127.0.0.1 のみハードコード
  - worktree-escape は ctx.WorktreeRoot prefix と filepath.Abs で判定、
    相対パス rm は worktree 内とみなし通過
- go/internal/guardrail/pre_tool.go: EvaluatePreTool 冒頭で runtimefloor
  を呼び、Stopped 時は permissionDecision=ask + Reason="RUNTIME_FLOOR:<cat>: ..."
  を返す。既存 R01-R13 評価は通常どおり続行
- go/internal/floor/floor.go: package doc / Gate doc を "PRE-MERGE POLICY GATE"
  に改名し、runtimefloor との区別を明記 (Two distinct floors の構造化)

TDD red evidence: 5 カテゴリ各代表 command + override 不可 (任意 env 設定でも
止まり続けることを t.Setenv で確認) を red→green。
Lead 1 次 adversarial round で発見した schemeless curl/wget bypass 修正済み
(round 2 で red→green、Lead 再独立検証で PASS)。

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
(cherry picked from commit a81ab11)
@coderabbitai

coderabbitai Bot commented Jun 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5b180b7a-6d65-44bf-b45a-95358ea3fac8

📥 Commits

Reviewing files that changed from the base of the PR and between 1138cbf and 631ed79.

📒 Files selected for processing (2)
  • CHANGELOG.md
  • go/internal/runtimefloor/runtimefloor_test.go

ウォークスルー

新パッケージ runtimefloor を追加し、Bash コマンドを5カテゴリ(課金・egress・秘密読み取り・本番デプロイ・worktree 外破壊的 rm)で検査する非オーバーライドのハードフロアを実装。EvaluatePreTool の先頭でこの判定を行い、既存ルール評価前に早期返却する。あわせてバージョンを 4.16.2 へバンプし、関連ドキュメント・SKILL.md・CHANGELOG を更新した。

変更内容

Runtime Floor Guardrail の実装

Layer / File(s) Summary
runtimefloor の型・定数・正規表現パターン
go/internal/runtimefloor/runtimefloor.go
Category 型、5つのカテゴリ定数、Context/Decision 構造体、および各チェッカーが使用する全正規表現パターンを新規定義。
CheckCommand のディスパッチと各カテゴリチェッカー
go/internal/runtimefloor/runtimefloor.go
CheckCommand エントリポイント、stop ヘルパー、checkMoneyBilling・checkEgress(スキームレス URL 検出・ホワイトリスト照合含む)・extractHostAuthority/isAllowlistedHost・checkSecretRead・checkProdDeploy・checkWorktreeEscape(許可済み一時ルート解決・rm ターゲット抽出含む)を実装。
runtimefloor ユニットテスト
go/internal/runtimefloor/runtimefloor_test.go
全5停止カテゴリ・安全コマンド許可・worktree 内パス許可・環境変数による非オーバーライド・空コマンド・OS 一時ディレクトリ・TMPDIR・ユーザキャッシュ・キャッシュ外ホームディレクトリ停止・スキームレス egress を網羅するテストを追加。
EvaluatePreTool への組み込みと統合テスト
go/internal/guardrail/pre_tool.go, go/internal/guardrail/pre_tool_test.go
runtimefloor をインポートし、EvaluatePreTool 先頭に早期返却ロジック(RUNTIME_FLOOR:<category>: <reason> 形式)を追加。統合テストで hard-stop 挙動を検証。

バージョン 4.16.2 へのバンプとリリースドキュメント更新

Layer / File(s) Summary
全マニフェストおよび VERSION のバンプ
VERSION, harness.toml, .claude-plugin/marketplace.json, .claude-plugin/plugin.json, .codex-plugin/plugin.json, .cursor-plugin/plugin.json
バージョン文字列を 4.16.1 から 4.16.2 へ一括更新。
CHANGELOG のリリースノートとバージョンリンク
CHANGELOG.md
[4.16.2] セクション見出しと比較リンクを追加。Unreleased セクションに Runtime action hard floor 昇格とリリースワークフロー委譲の説明を追記。
spec.md・SKILL.md のリリースドキュメント更新
spec.md, skills/harness-release/SKILL.md, opencode/skills/harness-release/SKILL.md, codex/.codex/skills/harness-release/SKILL.md
spec.md の verify 手順を GitHub CLI API endpoint と release サブコマンド終端の文言で明確化。SKILL.md では Revert 条件をPublish step 委譲の検討へ統一。

シーケンス図

sequenceDiagram
  participant AIAgent as AI エージェント
  participant EvaluatePreTool as EvaluatePreTool
  participant CheckCommand as runtimefloor.CheckCommand
  participant GuardrailRules as 既存ガードルール

  AIAgent->>EvaluatePreTool: Bash コマンド実行要求
  EvaluatePreTool->>CheckCommand: cmd, Context{WorktreeRoot}
  CheckCommand-->>EvaluatePreTool: Decision{Stopped, Category, Reason}
  alt Stopped == true
    EvaluatePreTool-->>AIAgent: DecisionAsk "RUNTIME_FLOOR:<category>: <reason>"
  else Stopped == false
    EvaluatePreTool->>GuardrailRules: BuildContext → EvaluateRules
    GuardrailRules-->>AIAgent: 通常の決定結果
  end
Loading

レビュー工数の見積もり

🎯 4 (Complex) | ⏱️ ~60 minutes

関連する可能性のある PR

  • Chachamaru127/claude-code-harness#225: harness-release スキルから gh release create を除去し release-verify-publish.sh を追加した PR で、本 PR の prod-deploy カテゴリによるブロックおよびリリース verify 手順と直接対応している。

🐰 お祝いの詩

🐇 ぴょんと跳ねて守るゲート
rm も gh release も、フロアでストップ!
五つのカテゴリ、しっかり番兵 🛡️
worktree の外は許可しないよ
v4.16.2、安全にリリース! 🎉

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 10.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PRタイトル「chore: release v4.16.2」は、変更の主要な目的であるv4.16.2リリースを正確に反映しており、バージョン番号更新、ランタイムフロア機能追加、ワークツリーエスケープ対策、およびメタデータ更新をまとめて説明しています。
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch release/v4.16.2-phase103

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain modules listed in go.work or their selected dependencies"


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1138cbf6c6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +257 to +259
expanded, ok := expandPathTarget(target)
if !ok {
continue

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Resolve relative rm targets before skipping them

When the rm target is relative, e.g. rm -rf ../old-worktree from inside a task worktree, expandPathTarget returns ok=false and this branch silently skips the target, so no worktree-escape runtime-floor ask is raised even though the delete is outside the worktree. In work mode the later R05 rm guard is skipped, so this bypasses the advertised non-overridable protection for repo-adjacent data-loss paths.

Useful? React with 👍 / 👎.


func TestCheckWorktreeEscape_StopsHomeDirectoriesOutsideCache(t *testing.T) {
worktree := testWorktreeRoot(t)
home := t.TempDir()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use a non-temp HOME in this test

On Linux, t.TempDir() is under /tmp, and /tmp is allowlisted by allowlistedTempRoots; with HOME set to this value, the Desktop and Documents cases below are treated as scratch cleanup and go test ./go/internal/runtimefloor fails. Use a synthetic HOME outside the temp allowlist or check home data paths before applying the temp-root allowlist so the new package tests pass on Linux CI.

Useful? React with 👍 / 👎.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🧹 Nitpick comments (1)
go/internal/runtimefloor/runtimefloor_test.go (1)

163-196: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

TMPDIR / ユーザーキャッシュのテストが空振りで通っており、意図したロジックを検証できていません。

custom := t.TempDir() と home := t.TempDir() はいずれも /tmp 配下を返すため、対象パスはハードコードされた /tmp 許可リストにより許可されます。つまりこれらのテストは TMPDIR オーバーライド分岐や ~/.cache / ~/Library/Caches 分岐を実際には通らずに pass しています。前述の失敗テストと同じ修正方針(temp ルート外の合成パスを使い、TMPDIR/HOME を明示的に分離する)で、本来検証したい分岐を確実にカバーできます。

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go/internal/runtimefloor/runtimefloor_test.go` around lines 163 - 196, The
tests TestCheckWorktreeEscape_AllowsTMPDIROverride and
TestCheckWorktreeEscape_AllowsUserCacheRoots are passing trivially because
t.TempDir() returns paths under /tmp which are already allowed by a hardcoded
/tmp allowlist, so the actual TMPDIR override and user cache directory branches
are never exercised. Fix these tests by creating synthetic paths outside the
temp root (not using t.TempDir()), then explicitly set TMPDIR in the first test
and HOME in the second test to these synthetic paths outside the allowlist. This
ensures the intended code branches for TMPDIR override handling and cache
directory validation are actually being tested rather than bypassed by the
default allowlist.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@CHANGELOG.md`:
- Line 5037: The reference definition for `[4.16.2]` in the CHANGELOG.md file is
unused and triggers a markdownlint warning. Remove the entire line containing
the unused reference definition `[4.16.2]:
https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2`
since it is not referenced anywhere in the document body.

In `@go/internal/guardrail/pre_tool.go`:
- Around line 187-193: The project root resolution logic in the worktreeRoot
initialization (lines 187-193) is inconsistent with the BuildContext root
resolution logic (lines 109-118) because it lacks the os.Getwd() fallback.
Extract the root resolution logic into a common helper function that includes
all fallback options in the correct order: input CWD, HARNESS_PROJECT_ROOT
environment variable, PROJECT_ROOT environment variable, and os.Getwd(). Use
this common helper function in both the BuildContext initialization and the
worktreeRoot assignment to ensure consistent root resolution across the pre_tool
file, including the additional location at lines 209-210.

In `@go/internal/runtimefloor/runtimefloor_test.go`:
- Around line 198-220: The
TestCheckWorktreeEscape_StopsHomeDirectoriesOutsideCache test fails because HOME
is set to t.TempDir() which returns paths under /tmp, causing paths like
$HOME/Desktop/important.pdf to be considered within the /tmp allowlist. Since
CheckCommand uses string-based path checking (not stat), modify the test to set
HOME to a synthetic path that is logically outside any temp or cache roots (for
example, a hardcoded path like /home/testuser or /nonexistent/home) instead of
using t.TempDir(). This ensures the test properly validates that home directory
paths are correctly identified as worktree escape attempts rather than being
allowlisted as temporary directories.

In `@go/internal/runtimefloor/runtimefloor.go`:
- Line 59: The regular expression pattern for the git push origin check is
matching any branch name that starts with `v` (like `verify-fix` or
`validate-branch`), not just version tags. In the pattern
`(?i)\bgit\s+push\b.*\borigin\s+v`, modify the part that matches `origin\s+v` to
require a digit immediately after the `v` (for example, use `v\d` instead of
just `v`) so that it only matches actual version tags like `v1.0.0` while
excluding regular branch names that happen to start with the letter `v`.

---

Nitpick comments:
In `@go/internal/runtimefloor/runtimefloor_test.go`:
- Around line 163-196: The tests TestCheckWorktreeEscape_AllowsTMPDIROverride
and TestCheckWorktreeEscape_AllowsUserCacheRoots are passing trivially because
t.TempDir() returns paths under /tmp which are already allowed by a hardcoded
/tmp allowlist, so the actual TMPDIR override and user cache directory branches
are never exercised. Fix these tests by creating synthetic paths outside the
temp root (not using t.TempDir()), then explicitly set TMPDIR in the first test
and HOME in the second test to these synthetic paths outside the allowlist. This
ensures the intended code branches for TMPDIR override handling and cache
directory validation are actually being tested rather than bypassed by the
default allowlist.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 2f87dfd9-a272-4806-a15a-4f971e3b74ef

📥 Commits

Reviewing files that changed from the base of the PR and between ef79f61 and 1138cbf.

⛔ Files ignored due to path filters (1)
  • bin/harness-windows-amd64.exe is excluded by !**/*.exe
📒 Files selected for processing (18)
  • .claude-plugin/marketplace.json
  • .claude-plugin/plugin.json
  • .codex-plugin/plugin.json
  • .cursor-plugin/plugin.json
  • CHANGELOG.md
  • VERSION
  • bin/harness-darwin-amd64
  • bin/harness-darwin-arm64
  • bin/harness-linux-amd64
  • codex/.codex/skills/harness-release/SKILL.md
  • go/internal/guardrail/pre_tool.go
  • go/internal/guardrail/pre_tool_test.go
  • go/internal/runtimefloor/runtimefloor.go
  • go/internal/runtimefloor/runtimefloor_test.go
  • harness.toml
  • opencode/skills/harness-release/SKILL.md
  • skills/harness-release/SKILL.md
  • spec.md

Comment thread CHANGELOG.md

[Unreleased]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...HEAD
[Unreleased]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.2...HEAD
[4.16.2]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

未使用の参照定義を削除してください。

[4.16.2] は本文から参照されておらず、markdownlint の unused reference 警告が残ります。リンクとして使う予定がないなら削除してください。

♻️ 修正案
-[4.16.2]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
[4.16.2]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 5037-5037: Link and image reference definitions should be needed
Unused link or image reference definition: "4.16.2"

(MD053, link-image-reference-definitions)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@CHANGELOG.md` at line 5037, The reference definition for `[4.16.2]` in the
CHANGELOG.md file is unused and triggers a markdownlint warning. Remove the
entire line containing the unused reference definition `[4.16.2]:
https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2`
since it is not referenced anywhere in the document body.

Source: Linters/SAST tools

Comment on lines +187 to +193
worktreeRoot := input.CWD
if worktreeRoot == "" {
worktreeRoot = os.Getenv("HARNESS_PROJECT_ROOT")
}
if worktreeRoot == "" {
worktreeRoot = os.Getenv("PROJECT_ROOT")
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

project root 解決ロジックが BuildContext と不一致です。

Line 187-193 は BuildContext(Line 109-118)と異なり os.Getwd() フォールバックがないため、同じ入力でも runtime floor と EvaluateRules で基準 root がズレます。root 解決処理を共通ヘルパーに寄せて、両方で同一値を使うようにしてください。

差分例
+func resolveProjectRoot(input hookproto.HookInput) string {
+	projectRoot := input.CWD
+	if projectRoot == "" {
+		projectRoot = os.Getenv("HARNESS_PROJECT_ROOT")
+	}
+	if projectRoot == "" {
+		projectRoot = os.Getenv("PROJECT_ROOT")
+	}
+	if projectRoot == "" {
+		projectRoot, _ = os.Getwd()
+	}
+	return projectRoot
+}
+
 func BuildContext(input hookproto.HookInput) hookproto.RuleContext {
-	projectRoot := input.CWD
-	if projectRoot == "" {
-		projectRoot = os.Getenv("HARNESS_PROJECT_ROOT")
-	}
-	if projectRoot == "" {
-		projectRoot = os.Getenv("PROJECT_ROOT")
-	}
-	if projectRoot == "" {
-		projectRoot, _ = os.Getwd()
-	}
+	projectRoot := resolveProjectRoot(input)
 	...
 }
 
 func EvaluatePreTool(input hookproto.HookInput) hookproto.HookResult {
 	if input.ToolName == "Bash" {
 		if command, ok := input.ToolInput["command"].(string); ok {
-			worktreeRoot := input.CWD
-			if worktreeRoot == "" {
-				worktreeRoot = os.Getenv("HARNESS_PROJECT_ROOT")
-			}
-			if worktreeRoot == "" {
-				worktreeRoot = os.Getenv("PROJECT_ROOT")
-			}
+			worktreeRoot := resolveProjectRoot(input)
 			if decision := runtimefloor.CheckCommand(command, runtimefloor.Context{
 				WorktreeRoot: worktreeRoot,
 			}); decision.Stopped {

Also applies to: 209-210

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go/internal/guardrail/pre_tool.go` around lines 187 - 193, The project root
resolution logic in the worktreeRoot initialization (lines 187-193) is
inconsistent with the BuildContext root resolution logic (lines 109-118) because
it lacks the os.Getwd() fallback. Extract the root resolution logic into a
common helper function that includes all fallback options in the correct order:
input CWD, HARNESS_PROJECT_ROOT environment variable, PROJECT_ROOT environment
variable, and os.Getwd(). Use this common helper function in both the
BuildContext initialization and the worktreeRoot assignment to ensure consistent
root resolution across the pre_tool file, including the additional location at
lines 209-210.

Comment thread go/internal/runtimefloor/runtimefloor_test.go
{"kubectl apply", regexp.MustCompile(`(?i)\bkubectl\s+apply\b`)},
{"terraform apply", regexp.MustCompile(`(?i)\bterraform\s+apply\b`)},
{"git push --tags", regexp.MustCompile(`(?i)\bgit\s+push\b.*--tags\b`)},
{"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v`)},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor

🧩 Analysis chain

🏁 Script executed:

# First, examine the file to understand the context
cat -n go/internal/runtimefloor/runtimefloor.go | sed -n '50,70p'

Repository: Chachamaru127/claude-code-harness

Length of output: 1455


🏁 Script executed:

# Also check the overall structure of the file
ast-grep outline go/internal/runtimefloor/runtimefloor.go --view expanded

Repository: Chachamaru127/claude-code-harness

Length of output: 2238


🏁 Script executed:

# Test the regex patterns with example inputs to confirm the false positive
python3 << 'PY'
import re

# Current regex pattern
current_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v'
# Suggested fix pattern
suggested_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v\d'

test_cases = [
    # Should match (version tags)
    "git push origin v1.0.0",
    "git push origin v2.5.0-rc1",
    "git push origin v3",
    # Should NOT match (regular branches starting with v)
    "git push origin verify-fix",
    "git push origin validate-branch",
    "git push origin vendor-update",
]

print("=== Current Pattern ===")
current = re.compile(current_pattern)
for test in test_cases:
    match = current.search(test)
    print(f"'{test}': {bool(match)}")

print("\n=== Suggested Pattern ===")
suggested = re.compile(suggested_pattern)
for test in test_cases:
    match = suggested.search(test)
    print(f"'{test}': {bool(match)}")
PY

Repository: Chachamaru127/claude-code-harness

Length of output: 222


🏁 Script executed:

# Check the log file for the full Python output
cat /tmp/coderabbit-shell-logs/shell-output-R0GBk

Repository: Chachamaru127/claude-code-harness

Length of output: 249


🏁 Script executed:

# Test the regex patterns with example inputs to confirm the false positive
python3 << 'PY'
import re

# Current regex pattern
current_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v'
# Suggested fix pattern
suggested_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v\d'

test_cases = [
    # Should match (version tags)
    "git push origin v1.0.0",
    "git push origin v2.5.0-rc1",
    "git push origin v3",
    # Should NOT match (regular branches starting with v)
    "git push origin verify-fix",
    "git push origin validate-branch",
    "git push origin vendor-update",
]

print("=== Current Pattern ===")
current = re.compile(current_pattern)
for test in test_cases:
    match = current.search(test)
    print(f"'{test}': {bool(match)}")

print("\n=== Suggested Pattern ===")
suggested = re.compile(suggested_pattern)
for test in test_cases:
    match = suggested.search(test)
    print(f"'{test}': {bool(match)}")
PY

Repository: Chachamaru127/claude-code-harness

Length of output: 222


🏁 Script executed:

# Check the full log to see the complete output
cat /tmp/coderabbit-shell-logs/shell-output-p0B0q7

Repository: Chachamaru127/claude-code-harness

Length of output: 222


🏁 Script executed:

# Let me capture the output differently
tail -50 /tmp/coderabbit-shell-logs/shell-output-U6J742

Repository: Chachamaru127/claude-code-harness

Length of output: 222


🏁 Script executed:

# Test the regex patterns with a simpler approach
python3 << 'PY'
import re

current_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v'
suggested_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v\d'

tests = [
    "git push origin v1.0.0",
    "git push origin verify-fix",
    "git push origin validate-branch",
]

current = re.compile(current_pattern)
suggested = re.compile(suggested_pattern)

for test in tests:
    c = bool(current.search(test))
    s = bool(suggested.search(test))
    print(f"{test:<40} | Current: {c} | Suggested: {s}")
PY

Repository: Chachamaru127/claude-code-harness

Length of output: 171


🏁 Script executed:

# Check the full log file directly
wc -l /tmp/coderabbit-shell-logs/shell-output-xst8NB && head -100 /tmp/coderabbit-shell-logs/shell-output-xst8NB && tail -50 /tmp/coderabbit-shell-logs/shell-output-xst8NB

Repository: Chachamaru127/claude-code-harness

Length of output: 220


🏁 Script executed:

# Simpler test without heredoc
python3 -c "import re; p = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v'); print('verify-fix matches:', bool(p.search('git push origin verify-fix'))); print('v1.0.0 matches:', bool(p.search('git push origin v1.0.0')))"

Repository: Chachamaru127/claude-code-harness

Length of output: 171


🏁 Script executed:

cat /tmp/coderabbit-shell-logs/shell-output-whJHHn

Repository: Chachamaru127/claude-code-harness

Length of output: 171


🏁 Script executed:

# Let me look at how this pattern is used in the code
cat -n go/internal/runtimefloor/runtimefloor.go | sed -n '230,250p'

Repository: Chachamaru127/claude-code-harness

Length of output: 886


🏁 Script executed:

# Look for tests or documentation that explain the intent of prodDeployPatterns
find . -name "*runtimefloor*" -o -name "*test*" | grep -E "\.(go|md)$"

Repository: Chachamaru127/claude-code-harness

Length of output: 4485


🏁 Script executed:

# Search for any tests related to prod deploy patterns
rg -A 5 -B 5 "git push origin v" go/

Repository: Chachamaru127/claude-code-harness

Length of output: 171


🏁 Script executed:

# Check the test file for runtimefloor
cat -n go/internal/runtimefloor/runtimefloor_test.go | head -100

Repository: Chachamaru127/claude-code-harness

Length of output: 4853


🏁 Script executed:

# Search for any tests that might test branch names starting with 'v' that should NOT be stopped
grep -n "verify\|validate\|vendor" go/internal/runtimefloor/runtimefloor_test.go

Repository: Chachamaru127/claude-code-harness

Length of output: 171


🏁 Script executed:

# Look at the entire test file to see if there are any tests for branches starting with v that should be allowed
wc -l go/internal/runtimefloor/runtimefloor_test.go && tail -100 go/internal/runtimefloor/runtimefloor_test.go

Repository: Chachamaru127/claude-code-harness

Length of output: 3161


🏁 Script executed:

# Let me directly test the regex patterns inline
python3 << 'EOF'
import re

# Test the patterns
current = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v')
suggested = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v\d')

test_cases = [
    "git push origin v1.0.0",        # version tag - should match both
    "git push origin verify-fix",    # branch - should only match current (false positive)
    "git push origin validate-branch", # branch - should only match current (false positive)
    "git push origin vendor-update", # branch - should only match current (false positive)
    "git push origin v",             # edge case
]

print("Testing regex patterns:")
print("-" * 80)
for test in test_cases:
    curr_match = bool(current.search(test))
    sugg_match = bool(suggested.search(test))
    print(f"Command: {test}")
    print(f"  Current pattern matches: {curr_match}")
    print(f"  Suggested pattern matches: {sugg_match}")
    print()
EOF

Repository: Chachamaru127/claude-code-harness

Length of output: 276


🏁 Script executed:

# Let me try with direct Python invocation
python3 -c "
import re
curr = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v')
sugg = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v\d')
print('v1.0.0 current:', bool(curr.search('git push origin v1.0.0')))
print('v1.0.0 suggested:', bool(sugg.search('git push origin v1.0.0')))
print('verify-fix current:', bool(curr.search('git push origin verify-fix')))
print('verify-fix suggested:', bool(sugg.search('git push origin verify-fix')))
"

Repository: Chachamaru127/claude-code-harness

Length of output: 171


🏁 Script executed:

tail -20 /tmp/coderabbit-shell-logs/shell-output-btNHhh

Repository: Chachamaru127/claude-code-harness

Length of output: 171


git push origin v パターンが v で始まるブランチ名を誤検知します。

正規表現 \borigin\s+v は git push origin v1.0.0 のようなバージョンタグだけでなく、git push origin verify-fix や git push origin validate-branch のように v で始まる通常のブランチ push も prod-deploy として人間エスカレーションに回してしまいます。バージョンタグを意図しているなら数字を要求して絞り込むのが安全です。

🔧 提案する修正
-		{"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v`)},
+		{"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v\d`)},
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
{"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v`)},
{"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v\d`)},
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go/internal/runtimefloor/runtimefloor.go` at line 59, The regular expression
pattern for the git push origin check is matching any branch name that starts
with `v` (like `verify-fix` or `validate-branch`), not just version tags. In the
pattern `(?i)\bgit\s+push\b.*\borigin\s+v`, modify the part that matches
`origin\s+v` to require a digit immediately after the `v` (for example, use
`v\d` instead of just `v`) so that it only matches actual version tags like
`v1.0.0` while excluding regular branch names that happen to start with the
letter `v`.

@Chachamaru127
Chachamaru127 merged commit 78a8c3b into main Jun 24, 2026
9 of 10 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Jun 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant