Skip to content

fix(orb): isolate APR transfer probe failures so polls never throw (#8331)#8461

Merged
JSONbored merged 2 commits into
JSONbored:mainfrom
jsdevninja:fix/apr-probe-never-throws
Jul 24, 2026
Merged

fix(orb): isolate APR transfer probe failures so polls never throw (#8331)#8461
JSONbored merged 2 commits into
JSONbored:mainfrom
jsdevninja:fix/apr-probe-never-throws

Conversation

@jsdevninja

Copy link
Copy Markdown
Contributor

Summary

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage locally; codecov/patch requires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:build
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

  • Focused: npx vitest run test/unit/orb-apr-repo-transfer.test.ts --coverage --coverage.include=src/orb/apr-repo-transfer.ts100% statements/branches/functions/lines on apr-repo-transfer.ts (36 tests). No UI change.

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

N/A — Orb backend poll/probe fix only; no visible UI change.

Notes

  • Per-item failure logging uses the existing Orb structured console.error(JSON.stringify({ level, event, ... })) convention (apr_repo_transfer_poll_item_failed).

@jsdevninja
jsdevninja requested a review from JSONbored as a code owner July 24, 2026 14:05
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jul 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.60%. Comparing base (9adcccb) to head (c08b7b4).
⚠️ Report is 26 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8461      +/-   ##
==========================================
- Coverage   92.50%   89.60%   -2.90%     
==========================================
  Files         791       98     -693     
  Lines       79333    22761   -56572     
  Branches    23960     3892   -20068     
==========================================
- Hits        73386    20396   -52990     
+ Misses       4807     2187    -2620     
+ Partials     1140      178     -962     
Flag Coverage Δ
shard-1 100.00% <100.00%> (+44.48%) ⬆️
shard-2 1.81% <0.00%> (-48.09%) ⬇️
shard-3 3.63% <0.00%> (-53.24%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/orb/apr-repo-transfer.ts 100.00% <100.00%> (ø)

... and 693 files with indirect coverage changes

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 24, 2026
@loopover-orb

loopover-orb Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Warning

⏸️ LoopOver review result - manual review recommended

Review updated: 2026-07-24 15:00:47 UTC

2 files · 1 AI reviewer · no blockers · CI green · clean

⏸️ Suggested Action - Manual Review

Review summary
This PR wraps `probeAprRepoTransfer`'s body in a try/catch so token-mint or fetch rejections resolve to `{ state: "pending" }` instead of throwing, and wraps each iteration of `pollPendingAprRepoTransfers`'s loop in try/catch so one bad transfer logs and continues rather than aborting the batch. Both changes are correctly targeted at the two failure modes named in #8331 (unguarded IO in the probe, and one throw stalling the whole poll), and the new tests exercise the real code paths (rejecting `createInstallationToken`, rejecting `fetch`, a rejecting probe mid-batch, and a rejecting `markResolved` mid-batch) rather than fabricating unreachable states. The `console.error` in the catch is real production logging (not debug leftover) since it's the only observability into a swallowed per-item failure.

Nits — 5 non-blocking
  • src/orb/apr-repo-transfer.ts: the catch block in `pollPendingAprRepoTransfers` swallows failures from `deps.setDispatchPaused` too (not just probe/markResolved) — worth confirming that's intended, since a paused-repo write failure silently leaving dispatch un-paused could matter operationally.
  • The `console.error` JSON blob has no correlation id / transfer.newOwner or installationId — consider including installationId for faster triage of which App installation is failing.
  • Two magic numbers (`404`, `response.ok`'s 200 range) are pre-existing style in this file, not introduced by this diff in a way that needs a new constant.
  • Consider distinguishing a token-mint failure from a fetch failure in the probe's catch (e.g. log the error) since both silently collapse to `pending`, which is correct behaviorally but makes root-causing outages harder in production.
  • In `pollPendingAprRepoTransfers`, consider whether a failed `setDispatchPaused` should be retried or surfaced differently than a failed probe/markResolved, since it's a different kind of failure (write vs read).

Decision drivers

  • ✅ Code review — No blockers (1 reviewer)
  • ✅ Gate result — Passing (No configured blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #8331
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (1 linked issue).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 223 registered-repo PR(s), 133 merged, 39 issue(s).
Contributor context ✅ Confirmed Gittensor contributor jsdevninja; Gittensor profile; 223 PR(s), 39 issue(s).
Improvement ✅ Minor risk: clean · value: minor
Linked issue satisfaction

Addressed
The diff wraps createInstallationToken/timeoutFetch in try/catch returning {state:"pending"} in probeAprRepoTransfer, and wraps each per-transfer loop body in pollPendingAprRepoTransfers in try/catch with logging and continue, matching both requirements.

Review context
  • Author: jsdevninja
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: not available
  • Official Gittensor activity: 223 PR(s), 39 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Triage stale or unlinked PRs.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb loopover-orb Bot added the manual-review Gittensor contributor context label Jul 24, 2026
@JSONbored
JSONbored merged commit c6f4ee2 into JSONbored:main Jul 24, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. manual-review Gittensor contributor context

Projects

None yet

Development

Successfully merging this pull request may close these issues.

probeAprRepoTransfer claims Never throws but its calls are unguarded, and one bad probe stalls the whole poll batch

2 participants