[repository-quality] Repository Quality: Uncancellable Subprocess Execution (exec.Command Without Context) #64279
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
🎯 Repository Quality Improvement Report - Uncancellable Subprocess Execution (exec.Command Without Context)
Analysis Date: 2026-09-29
Focus Area: Uncancellable Subprocess Execution
Strategy Type: Custom
Custom Area: Yes — the repo already ships an
execcommandwithoutcontextlinter that is enabled in CI, but it only flags calls inside functions that already take acontext.Context. The debt lives in functions that have no ctx at all, which the linter cannot see.Executive Summary
Non-test code under
pkg/contains 93exec.Command(calls (83 inpkg/cli, 10 inpkg/workflow/pkg/gitutil/pkg/parser) versus only 41exec.CommandContext(calls inpkg/cli. About 67 of the calls rungit. Many are network-bound operations (git pull --rebase,git push --force,git fetch,git ls-remote,docker pull,npm view,pip index versions) with no cancellation or timeout, so Ctrl-C and command timeouts cannot stop a hung child process.The CI linter gate is green because the analyzer requires an enclosing ctx parameter. The real gap is ctx not being threaded through helper layers such as
pkg/cli/git.go,pr_command.go,trial_repository.go,trial_helpers.goandadd_interactive_git.go. Prioritise network-bound git/docker/npm/pip calls first, then thread ctx through the helpers.Full Analysis Report
Focus Area: Uncancellable Subprocess Execution
Current State Assessment
Metrics Collected:
exec.Command(in non-testpkg/code (excl. linter testdata)exec.CommandContext(inpkg/clinon-testexec.Command("git"...)callscli/pr_command.go,cli/git.gocli/trial_repository.go/trial_helpers.go/add_interactive_git.gopkg/workflowvalidators (docker,npm,pip)context.Background()in non-test codeexeccommandwithoutcontextlinter in CI (cgo.yml)Findings
Strengths
execcommandwithoutcontext,ctxbackground,nilctxpassedandtimesleepnocontextexist and are gated in CI.Areas for Improvement
pkg/cli/trial_repository.go:635-700,trial_helpers.go:473-480,add_interactive_git.go:258-309,pr_command.go:289-294.reset --hard,clean -fd,push --force) atpr_command.go:264-267,trial_repository.go:700run non-cancellably.pkg/workflow/{docker,npm,pip}_validation.gohit the network with no timeout.pkg/cli/git.gohas 20 wrappers that should be the ctx-aware choke point.Detailed Analysis
Because the analyzer only walks
Enclosing(FuncDecl, FuncLit)to find a ctx parameter, exec calls in ctx-less helpers are never reported. Threading ctx from cobracmd.Context()down through helpers fixes this and lets the existing linter enforce it thereafter.🤖 Tasks for Copilot Agent
NOTE TO PLANNER AGENT: Split the following tasks into individual work items.
Improvement Tasks
Task 1: Thread context through
pkg/cli/git.gowrappersPriority: High
Estimated Effort: Medium
Focus Area: Uncancellable Subprocess Execution
Description: Convert the 20
exec.Commandgit wrappers to acceptctx context.Contextand useexec.CommandContext; update callers.Acceptance Criteria:
exec.Command(remains inpkg/cli/git.gocmd.Context()or an existing ctxmake test-unitpassesCode Region:
pkg/cli/git.goTask 2: Context-aware network git operations in trial/add-interactive/pr flows
Priority: High
Estimated Effort: Medium
Focus Area: Uncancellable Subprocess Execution
Description: Convert pull/push/fetch/ls-remote/checkout calls to CommandContext.
Acceptance Criteria:
exec.Command(in the four files belowCode Region:
pkg/cli/trial_repository.go,pkg/cli/trial_helpers.go,pkg/cli/add_interactive_git.go,pkg/cli/pr_command.goTask 3: Add timeouts/ctx to external-tool validators
Priority: Medium
Estimated Effort: Small
Focus Area: Uncancellable Subprocess Execution
Description:
docker image inspect/pull,npm view,pip index versions,uv pip showshould use CommandContext with a bounded timeout.Acceptance Criteria:
Code Region:
pkg/workflow/docker_validation.go,npm_validation.go,pip_validation.goTask 4: Close the linter blind spot
Priority: Medium
Estimated Effort: Medium
Focus Area: Uncancellable Subprocess Execution
Description: Add an opt-in mode (or new analyzer) reporting exec.Command in non-test production code even without a ctx parameter, in packages already migrated, so regressions are caught.
Acceptance Criteria:
cgo.ymlLINTER_FLAGS for migrated packages onlyCode Region:
pkg/linters/execcommandwithoutcontext/,.github/workflows/cgo.yml📊 Historical Context
Previous Focus Areas
🎯 Recommendations
Immediate Actions (This Week)
pkg/cli/git.goand network git flows — Priority: HighShort-term Actions (This Month)
Long-term Actions (This Quarter)
📈 Success Metrics
exec.Command(in pkg/: 93 → 0 (excluding intentional cases)Next Steps
Generated by Repository Quality Improvement Agent
Next analysis: 2026-09-30 — Focus area selected by diversity algorithm
All reactions