Repository navigation
chore: release v4.16.2 - #226
Conversation
…ase 92.2.1)
- go/internal/runtimefloor: 新規 package。Bash command の pattern-match で
money-billing / egress / secret-read / prod-deploy / worktree-escape の
5 カテゴリを実行前 (PreToolUse) に hard-stop し human escalation を強制
- CheckCommand は disable flag / env var / config 読込を構造的に持たない
(override 不可を if 文ではなく API 設計で保証)
- egress 検出は scheme 付き URL + schemeless host authority (curl/wget)
両方を扱い、allowlist は localhost / 127.0.0.1 のみハードコード
- worktree-escape は ctx.WorktreeRoot prefix と filepath.Abs で判定、
相対パス rm は worktree 内とみなし通過
- go/internal/guardrail/pre_tool.go: EvaluatePreTool 冒頭で runtimefloor
を呼び、Stopped 時は permissionDecision=ask + Reason="RUNTIME_FLOOR:<cat>: ..."
を返す。既存 R01-R13 評価は通常どおり続行
- go/internal/floor/floor.go: package doc / Gate doc を "PRE-MERGE POLICY GATE"
に改名し、runtimefloor との区別を明記 (Two distinct floors の構造化)
TDD red evidence: 5 カテゴリ各代表 command + override 不可 (任意 env 設定でも
止まり続けることを t.Setenv で確認) を red→green。
Lead 1 次 adversarial round で発見した schemeless curl/wget bypass 修正済み
(round 2 で red→green、Lead 再独立検証で PASS)。
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
(cherry picked from commit a81ab11)
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
ウォークスルー新パッケージ 変更内容Runtime Floor Guardrail の実装
バージョン 4.16.2 へのバンプとリリースドキュメント更新
シーケンス図sequenceDiagram
participant AIAgent as AI エージェント
participant EvaluatePreTool as EvaluatePreTool
participant CheckCommand as runtimefloor.CheckCommand
participant GuardrailRules as 既存ガードルール
AIAgent->>EvaluatePreTool: Bash コマンド実行要求
EvaluatePreTool->>CheckCommand: cmd, Context{WorktreeRoot}
CheckCommand-->>EvaluatePreTool: Decision{Stopped, Category, Reason}
alt Stopped == true
EvaluatePreTool-->>AIAgent: DecisionAsk "RUNTIME_FLOOR:<category>: <reason>"
else Stopped == false
EvaluatePreTool->>GuardrailRules: BuildContext → EvaluateRules
GuardrailRules-->>AIAgent: 通常の決定結果
end
レビュー工数の見積もり🎯 4 (Complex) | ⏱️ ~60 minutes 関連する可能性のある PR
🐰 お祝いの詩
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 golangci-lint (2.12.2)level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain modules listed in go.work or their selected dependencies" Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1138cbf6c6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| expanded, ok := expandPathTarget(target) | ||
| if !ok { | ||
| continue |
There was a problem hiding this comment.
Resolve relative rm targets before skipping them
When the rm target is relative, e.g. rm -rf ../old-worktree from inside a task worktree, expandPathTarget returns ok=false and this branch silently skips the target, so no worktree-escape runtime-floor ask is raised even though the delete is outside the worktree. In work mode the later R05 rm guard is skipped, so this bypasses the advertised non-overridable protection for repo-adjacent data-loss paths.
Useful? React with 👍 / 👎.
|
|
||
| func TestCheckWorktreeEscape_StopsHomeDirectoriesOutsideCache(t *testing.T) { | ||
| worktree := testWorktreeRoot(t) | ||
| home := t.TempDir() |
There was a problem hiding this comment.
Use a non-temp HOME in this test
On Linux, t.TempDir() is under /tmp, and /tmp is allowlisted by allowlistedTempRoots; with HOME set to this value, the Desktop and Documents cases below are treated as scratch cleanup and go test ./go/internal/runtimefloor fails. Use a synthetic HOME outside the temp allowlist or check home data paths before applying the temp-root allowlist so the new package tests pass on Linux CI.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Actionable comments posted: 4
🧹 Nitpick comments (1)
go/internal/runtimefloor/runtimefloor_test.go (1)
163-196: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win
TMPDIR/ ユーザーキャッシュのテストが空振りで通っており、意図したロジックを検証できていません。
custom := t.TempDir()とhome := t.TempDir()はいずれも/tmp配下を返すため、対象パスはハードコードされた/tmp許可リストにより許可されます。つまりこれらのテストはTMPDIRオーバーライド分岐や~/.cache/~/Library/Caches分岐を実際には通らずに pass しています。前述の失敗テストと同じ修正方針(temp ルート外の合成パスを使い、TMPDIR/HOMEを明示的に分離する)で、本来検証したい分岐を確実にカバーできます。🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@go/internal/runtimefloor/runtimefloor_test.go` around lines 163 - 196, The tests TestCheckWorktreeEscape_AllowsTMPDIROverride and TestCheckWorktreeEscape_AllowsUserCacheRoots are passing trivially because t.TempDir() returns paths under /tmp which are already allowed by a hardcoded /tmp allowlist, so the actual TMPDIR override and user cache directory branches are never exercised. Fix these tests by creating synthetic paths outside the temp root (not using t.TempDir()), then explicitly set TMPDIR in the first test and HOME in the second test to these synthetic paths outside the allowlist. This ensures the intended code branches for TMPDIR override handling and cache directory validation are actually being tested rather than bypassed by the default allowlist.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Line 5037: The reference definition for `[4.16.2]` in the CHANGELOG.md file is
unused and triggers a markdownlint warning. Remove the entire line containing
the unused reference definition `[4.16.2]:
https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2`
since it is not referenced anywhere in the document body.
In `@go/internal/guardrail/pre_tool.go`:
- Around line 187-193: The project root resolution logic in the worktreeRoot
initialization (lines 187-193) is inconsistent with the BuildContext root
resolution logic (lines 109-118) because it lacks the os.Getwd() fallback.
Extract the root resolution logic into a common helper function that includes
all fallback options in the correct order: input CWD, HARNESS_PROJECT_ROOT
environment variable, PROJECT_ROOT environment variable, and os.Getwd(). Use
this common helper function in both the BuildContext initialization and the
worktreeRoot assignment to ensure consistent root resolution across the pre_tool
file, including the additional location at lines 209-210.
In `@go/internal/runtimefloor/runtimefloor_test.go`:
- Around line 198-220: The
TestCheckWorktreeEscape_StopsHomeDirectoriesOutsideCache test fails because HOME
is set to t.TempDir() which returns paths under /tmp, causing paths like
$HOME/Desktop/important.pdf to be considered within the /tmp allowlist. Since
CheckCommand uses string-based path checking (not stat), modify the test to set
HOME to a synthetic path that is logically outside any temp or cache roots (for
example, a hardcoded path like /home/testuser or /nonexistent/home) instead of
using t.TempDir(). This ensures the test properly validates that home directory
paths are correctly identified as worktree escape attempts rather than being
allowlisted as temporary directories.
In `@go/internal/runtimefloor/runtimefloor.go`:
- Line 59: The regular expression pattern for the git push origin check is
matching any branch name that starts with `v` (like `verify-fix` or
`validate-branch`), not just version tags. In the pattern
`(?i)\bgit\s+push\b.*\borigin\s+v`, modify the part that matches `origin\s+v` to
require a digit immediately after the `v` (for example, use `v\d` instead of
just `v`) so that it only matches actual version tags like `v1.0.0` while
excluding regular branch names that happen to start with the letter `v`.
---
Nitpick comments:
In `@go/internal/runtimefloor/runtimefloor_test.go`:
- Around line 163-196: The tests TestCheckWorktreeEscape_AllowsTMPDIROverride
and TestCheckWorktreeEscape_AllowsUserCacheRoots are passing trivially because
t.TempDir() returns paths under /tmp which are already allowed by a hardcoded
/tmp allowlist, so the actual TMPDIR override and user cache directory branches
are never exercised. Fix these tests by creating synthetic paths outside the
temp root (not using t.TempDir()), then explicitly set TMPDIR in the first test
and HOME in the second test to these synthetic paths outside the allowlist. This
ensures the intended code branches for TMPDIR override handling and cache
directory validation are actually being tested rather than bypassed by the
default allowlist.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 2f87dfd9-a272-4806-a15a-4f971e3b74ef
⛔ Files ignored due to path filters (1)
bin/harness-windows-amd64.exeis excluded by!**/*.exe
📒 Files selected for processing (18)
.claude-plugin/marketplace.json.claude-plugin/plugin.json.codex-plugin/plugin.json.cursor-plugin/plugin.jsonCHANGELOG.mdVERSIONbin/harness-darwin-amd64bin/harness-darwin-arm64bin/harness-linux-amd64codex/.codex/skills/harness-release/SKILL.mdgo/internal/guardrail/pre_tool.gogo/internal/guardrail/pre_tool_test.gogo/internal/runtimefloor/runtimefloor.gogo/internal/runtimefloor/runtimefloor_test.goharness.tomlopencode/skills/harness-release/SKILL.mdskills/harness-release/SKILL.mdspec.md
|
|
||
| [Unreleased]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...HEAD | ||
| [Unreleased]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.2...HEAD | ||
| [4.16.2]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2 |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
未使用の参照定義を削除してください。
[4.16.2] は本文から参照されておらず、markdownlint の unused reference 警告が残ります。リンクとして使う予定がないなら削除してください。
♻️ 修正案
-[4.16.2]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| [4.16.2]: https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2 |
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 5037-5037: Link and image reference definitions should be needed
Unused link or image reference definition: "4.16.2"
(MD053, link-image-reference-definitions)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@CHANGELOG.md` at line 5037, The reference definition for `[4.16.2]` in the
CHANGELOG.md file is unused and triggers a markdownlint warning. Remove the
entire line containing the unused reference definition `[4.16.2]:
https://github.com/Chachamaru127/claude-code-harness/compare/v4.16.1...v4.16.2`
since it is not referenced anywhere in the document body.
Source: Linters/SAST tools
| worktreeRoot := input.CWD | ||
| if worktreeRoot == "" { | ||
| worktreeRoot = os.Getenv("HARNESS_PROJECT_ROOT") | ||
| } | ||
| if worktreeRoot == "" { | ||
| worktreeRoot = os.Getenv("PROJECT_ROOT") | ||
| } |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
project root 解決ロジックが BuildContext と不一致です。
Line 187-193 は BuildContext(Line 109-118)と異なり os.Getwd() フォールバックがないため、同じ入力でも runtime floor と EvaluateRules で基準 root がズレます。root 解決処理を共通ヘルパーに寄せて、両方で同一値を使うようにしてください。
差分例
+func resolveProjectRoot(input hookproto.HookInput) string {
+ projectRoot := input.CWD
+ if projectRoot == "" {
+ projectRoot = os.Getenv("HARNESS_PROJECT_ROOT")
+ }
+ if projectRoot == "" {
+ projectRoot = os.Getenv("PROJECT_ROOT")
+ }
+ if projectRoot == "" {
+ projectRoot, _ = os.Getwd()
+ }
+ return projectRoot
+}
+
func BuildContext(input hookproto.HookInput) hookproto.RuleContext {
- projectRoot := input.CWD
- if projectRoot == "" {
- projectRoot = os.Getenv("HARNESS_PROJECT_ROOT")
- }
- if projectRoot == "" {
- projectRoot = os.Getenv("PROJECT_ROOT")
- }
- if projectRoot == "" {
- projectRoot, _ = os.Getwd()
- }
+ projectRoot := resolveProjectRoot(input)
...
}
func EvaluatePreTool(input hookproto.HookInput) hookproto.HookResult {
if input.ToolName == "Bash" {
if command, ok := input.ToolInput["command"].(string); ok {
- worktreeRoot := input.CWD
- if worktreeRoot == "" {
- worktreeRoot = os.Getenv("HARNESS_PROJECT_ROOT")
- }
- if worktreeRoot == "" {
- worktreeRoot = os.Getenv("PROJECT_ROOT")
- }
+ worktreeRoot := resolveProjectRoot(input)
if decision := runtimefloor.CheckCommand(command, runtimefloor.Context{
WorktreeRoot: worktreeRoot,
}); decision.Stopped {Also applies to: 209-210
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@go/internal/guardrail/pre_tool.go` around lines 187 - 193, The project root
resolution logic in the worktreeRoot initialization (lines 187-193) is
inconsistent with the BuildContext root resolution logic (lines 109-118) because
it lacks the os.Getwd() fallback. Extract the root resolution logic into a
common helper function that includes all fallback options in the correct order:
input CWD, HARNESS_PROJECT_ROOT environment variable, PROJECT_ROOT environment
variable, and os.Getwd(). Use this common helper function in both the
BuildContext initialization and the worktreeRoot assignment to ensure consistent
root resolution across the pre_tool file, including the additional location at
lines 209-210.
| {"kubectl apply", regexp.MustCompile(`(?i)\bkubectl\s+apply\b`)}, | ||
| {"terraform apply", regexp.MustCompile(`(?i)\bterraform\s+apply\b`)}, | ||
| {"git push --tags", regexp.MustCompile(`(?i)\bgit\s+push\b.*--tags\b`)}, | ||
| {"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v`)}, |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor
🧩 Analysis chain
🏁 Script executed:
# First, examine the file to understand the context
cat -n go/internal/runtimefloor/runtimefloor.go | sed -n '50,70p'Repository: Chachamaru127/claude-code-harness
Length of output: 1455
🏁 Script executed:
# Also check the overall structure of the file
ast-grep outline go/internal/runtimefloor/runtimefloor.go --view expandedRepository: Chachamaru127/claude-code-harness
Length of output: 2238
🏁 Script executed:
# Test the regex patterns with example inputs to confirm the false positive
python3 << 'PY'
import re
# Current regex pattern
current_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v'
# Suggested fix pattern
suggested_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v\d'
test_cases = [
# Should match (version tags)
"git push origin v1.0.0",
"git push origin v2.5.0-rc1",
"git push origin v3",
# Should NOT match (regular branches starting with v)
"git push origin verify-fix",
"git push origin validate-branch",
"git push origin vendor-update",
]
print("=== Current Pattern ===")
current = re.compile(current_pattern)
for test in test_cases:
match = current.search(test)
print(f"'{test}': {bool(match)}")
print("\n=== Suggested Pattern ===")
suggested = re.compile(suggested_pattern)
for test in test_cases:
match = suggested.search(test)
print(f"'{test}': {bool(match)}")
PYRepository: Chachamaru127/claude-code-harness
Length of output: 222
🏁 Script executed:
# Check the log file for the full Python output
cat /tmp/coderabbit-shell-logs/shell-output-R0GBkRepository: Chachamaru127/claude-code-harness
Length of output: 249
🏁 Script executed:
# Test the regex patterns with example inputs to confirm the false positive
python3 << 'PY'
import re
# Current regex pattern
current_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v'
# Suggested fix pattern
suggested_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v\d'
test_cases = [
# Should match (version tags)
"git push origin v1.0.0",
"git push origin v2.5.0-rc1",
"git push origin v3",
# Should NOT match (regular branches starting with v)
"git push origin verify-fix",
"git push origin validate-branch",
"git push origin vendor-update",
]
print("=== Current Pattern ===")
current = re.compile(current_pattern)
for test in test_cases:
match = current.search(test)
print(f"'{test}': {bool(match)}")
print("\n=== Suggested Pattern ===")
suggested = re.compile(suggested_pattern)
for test in test_cases:
match = suggested.search(test)
print(f"'{test}': {bool(match)}")
PYRepository: Chachamaru127/claude-code-harness
Length of output: 222
🏁 Script executed:
# Check the full log to see the complete output
cat /tmp/coderabbit-shell-logs/shell-output-p0B0q7Repository: Chachamaru127/claude-code-harness
Length of output: 222
🏁 Script executed:
# Let me capture the output differently
tail -50 /tmp/coderabbit-shell-logs/shell-output-U6J742Repository: Chachamaru127/claude-code-harness
Length of output: 222
🏁 Script executed:
# Test the regex patterns with a simpler approach
python3 << 'PY'
import re
current_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v'
suggested_pattern = r'(?i)\bgit\s+push\b.*\borigin\s+v\d'
tests = [
"git push origin v1.0.0",
"git push origin verify-fix",
"git push origin validate-branch",
]
current = re.compile(current_pattern)
suggested = re.compile(suggested_pattern)
for test in tests:
c = bool(current.search(test))
s = bool(suggested.search(test))
print(f"{test:<40} | Current: {c} | Suggested: {s}")
PYRepository: Chachamaru127/claude-code-harness
Length of output: 171
🏁 Script executed:
# Check the full log file directly
wc -l /tmp/coderabbit-shell-logs/shell-output-xst8NB && head -100 /tmp/coderabbit-shell-logs/shell-output-xst8NB && tail -50 /tmp/coderabbit-shell-logs/shell-output-xst8NBRepository: Chachamaru127/claude-code-harness
Length of output: 220
🏁 Script executed:
# Simpler test without heredoc
python3 -c "import re; p = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v'); print('verify-fix matches:', bool(p.search('git push origin verify-fix'))); print('v1.0.0 matches:', bool(p.search('git push origin v1.0.0')))"Repository: Chachamaru127/claude-code-harness
Length of output: 171
🏁 Script executed:
cat /tmp/coderabbit-shell-logs/shell-output-whJHHnRepository: Chachamaru127/claude-code-harness
Length of output: 171
🏁 Script executed:
# Let me look at how this pattern is used in the code
cat -n go/internal/runtimefloor/runtimefloor.go | sed -n '230,250p'Repository: Chachamaru127/claude-code-harness
Length of output: 886
🏁 Script executed:
# Look for tests or documentation that explain the intent of prodDeployPatterns
find . -name "*runtimefloor*" -o -name "*test*" | grep -E "\.(go|md)$"Repository: Chachamaru127/claude-code-harness
Length of output: 4485
🏁 Script executed:
# Search for any tests related to prod deploy patterns
rg -A 5 -B 5 "git push origin v" go/Repository: Chachamaru127/claude-code-harness
Length of output: 171
🏁 Script executed:
# Check the test file for runtimefloor
cat -n go/internal/runtimefloor/runtimefloor_test.go | head -100Repository: Chachamaru127/claude-code-harness
Length of output: 4853
🏁 Script executed:
# Search for any tests that might test branch names starting with 'v' that should NOT be stopped
grep -n "verify\|validate\|vendor" go/internal/runtimefloor/runtimefloor_test.goRepository: Chachamaru127/claude-code-harness
Length of output: 171
🏁 Script executed:
# Look at the entire test file to see if there are any tests for branches starting with v that should be allowed
wc -l go/internal/runtimefloor/runtimefloor_test.go && tail -100 go/internal/runtimefloor/runtimefloor_test.goRepository: Chachamaru127/claude-code-harness
Length of output: 3161
🏁 Script executed:
# Let me directly test the regex patterns inline
python3 << 'EOF'
import re
# Test the patterns
current = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v')
suggested = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v\d')
test_cases = [
"git push origin v1.0.0", # version tag - should match both
"git push origin verify-fix", # branch - should only match current (false positive)
"git push origin validate-branch", # branch - should only match current (false positive)
"git push origin vendor-update", # branch - should only match current (false positive)
"git push origin v", # edge case
]
print("Testing regex patterns:")
print("-" * 80)
for test in test_cases:
curr_match = bool(current.search(test))
sugg_match = bool(suggested.search(test))
print(f"Command: {test}")
print(f" Current pattern matches: {curr_match}")
print(f" Suggested pattern matches: {sugg_match}")
print()
EOFRepository: Chachamaru127/claude-code-harness
Length of output: 276
🏁 Script executed:
# Let me try with direct Python invocation
python3 -c "
import re
curr = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v')
sugg = re.compile(r'(?i)\bgit\s+push\b.*\borigin\s+v\d')
print('v1.0.0 current:', bool(curr.search('git push origin v1.0.0')))
print('v1.0.0 suggested:', bool(sugg.search('git push origin v1.0.0')))
print('verify-fix current:', bool(curr.search('git push origin verify-fix')))
print('verify-fix suggested:', bool(sugg.search('git push origin verify-fix')))
"Repository: Chachamaru127/claude-code-harness
Length of output: 171
🏁 Script executed:
tail -20 /tmp/coderabbit-shell-logs/shell-output-btNHhhRepository: Chachamaru127/claude-code-harness
Length of output: 171
git push origin v パターンが v で始まるブランチ名を誤検知します。
正規表現 \borigin\s+v は git push origin v1.0.0 のようなバージョンタグだけでなく、git push origin verify-fix や git push origin validate-branch のように v で始まる通常のブランチ push も prod-deploy として人間エスカレーションに回してしまいます。バージョンタグを意図しているなら数字を要求して絞り込むのが安全です。
🔧 提案する修正
- {"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v`)},
+ {"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v\d`)},📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| {"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v`)}, | |
| {"git push origin v*", regexp.MustCompile(`(?i)\bgit\s+push\b.*\borigin\s+v\d`)}, |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@go/internal/runtimefloor/runtimefloor.go` at line 59, The regular expression
pattern for the git push origin check is matching any branch name that starts
with `v` (like `verify-fix` or `validate-branch`), not just version tags. In the
pattern `(?i)\bgit\s+push\b.*\borigin\s+v`, modify the part that matches
`origin\s+v` to require a digit immediately after the `v` (for example, use
`v\d` instead of just `v`) so that it only matches actual version tags like
`v1.0.0` while excluding regular branch names that happen to start with the
letter `v`.
Summary
Release candidate for v4.16.2.
This promotes the local dogfood runtime safety change to the public release line while keeping the redesign branch separate.
Changes
Boundary
Verification
Warnings / residual risk
release-preflight warnings are existing project-surface warnings, not release-candidate failures:
Release execution plan after merge
Summary by CodeRabbit
リリースノート
/harness-releaseの自動完走失敗を解消するため、公開確認をワークフローの verify に委譲しました。