Repository navigation
[repository-quality] Repository Quality Improvement Report - Compiler Panic Containment #65022
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-03T13:05:33.412Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
🎯 Repository Quality Improvement Report - Compiler Panic Containment ("BUG:" Exemption Loophole)
Analysis Date: 2026-10-02
Focus Area: Compiler Panic Containment
Strategy Type: Custom
Custom Area: Yes — the
panicinlibrarycodelinter is CI-enabled, but a message-prefix exemption plus no top-levelrecover()in the native compile path means invariant panics crashgh aw compilewith a raw stack trace.Executive Summary
pkg/workflowcontains 11 productionpanic()calls that bypasspanicinlibrarycode. Most are exempt only because the message starts with"BUG:"(panicMessageStartsWithBUGinpkg/linters/panic-in-library-code/panic-in-library-code.go). The linter therefore cannot tell a real build-time invariant from a panic reachable from user input.Several of these sit on the per-workflow compile path:
mustGetAllowedDomainsForEngineWithModel(domains.go:691, called fromuniversal_llm_consumer_engine.go:295,pi_engine.go:423,behavior_defined_engine.go:734),claude_tools.go:142, andcache_config.go:46. Their safety depends on validation running earlier. The native CLI has norecover()around compile. The only compile-level recovery is incmd/gh-aw-wasm/compile_recovery.go. In a 299-workflow batch compile, one bad invariant aborts the whole run with a Go stack trace and no workflow file context.Recommendation: convert the reachable panics to returned errors, and add a recovery boundary that reports the workflow path. Then tighten the linter so the
BUG:prefix alone no longer exempts a panic.Full Analysis Report
Focus Area: Compiler Panic Containment
Current State Assessment
Metrics Collected:
panic(inpkg/cmd(excluding linter testdata)panicinlibrarycodeenabled in cgo.ymlBUG:prefix, documented panic contractrecover()around native compile of each workflowcmd/gh-aw-wasm/compile_recovery.go)os.Exitin library codeFindings
Strengths
os.Exit/log.Fatallinters are clean.sync.Once, init, or embedded-data loaders. A failure there points at a broken build, not user input.cacheMemoryDirForpanic is documented and tested (cache_id_validation_test.go:88).Areas for Improvement
domains.go:691panics on model errors that "should have been caught by validation". It has three callers, one of which (behavior_defined_engine.go:729) panics again at its own call site. A custom engine definition or a model alias edge case that bypassesvalidateModelAliasMapkills the process.claude_tools.go:142panics on a tool-map shape check. It only logs "ERROR" first, so it should return an error.BUG:prefix exemption makes the linter unable to flag the panics above. It also encourages mislabelling.compileSpecificFilesor the equivalent. A panic aborts remaining workflows and loses the file name.cacheMemoryDirForis called from 8 sites incache_memory.goandsandbox.go. Validation is at parse time, so the risk is small, but the string-returning API forces a panic.🤖 Tasks for Copilot Agent
NOTE TO PLANNER AGENT: Split the following tasks into individual work items.
Improvement Tasks
Task 1: Add per-workflow panic recovery to native compile
Priority: High
Estimated Effort: Small
Focus Area: Compiler Panic Containment
Description: Wrap the per-file compile in the CLI so a panic becomes a normal compile error that names the workflow file, instead of aborting the whole batch with a stack trace. Reuse the approach in
cmd/gh-aw-wasm/compile_recovery.go.Acceptance Criteria:
Code Region:
pkg/cli/compile_*.go(compileSpecificFiles / single-file compile),cmd/gh-aw-wasm/compile_recovery.goTask 2: Convert reachable invariant panics to returned errors
Priority: High
Estimated Effort: Medium
Focus Area: Compiler Panic Containment
Description: Replace
mustGetAllowedDomainsForEngineWithModel(callers inuniversal_llm_consumer_engine.go,pi_engine.go,behavior_defined_engine.go) with error propagation. MakecomputeAllowedClaudeToolsStringreturn an error instead of panicking.Acceptance Criteria:
panicremains indomains.goorclaude_tools.go.Code Region:
pkg/workflow/domains.go,pkg/workflow/claude_tools.go,pkg/workflow/behavior_defined_engine.go,pkg/workflow/pi_engine.go,pkg/workflow/universal_llm_consumer_engine.goTask 3: Tighten the panicinlibrarycode
BUG:exemptionPriority: Medium
Estimated Effort: Small
Focus Area: Compiler Panic Containment
Description: Stop
panicMessageStartsWithBUGfrom exempting a panic by message alone. Require a(nolint/redacted):panicinlibrarycode // <reason>justification instead, or limit the exemption to init, sync.Once, or package-level initialization contexts. Update the linter testdata.Acceptance Criteria:
BUG:prefix alone no longer suppresses the diagnostic.make golint-custompass.Code Region:
pkg/linters/panic-in-library-code/,pkg/workflow/*.gopanic sitesTask 4: Make cacheMemoryDirFor non-panicking
Priority: Low
Estimated Effort: Small
Focus Area: Compiler Panic Containment
Description: Return
(string, error)fromcacheMemoryDirFor. Update the 8 callers incache_memory.goandsandbox.go, and changeTestCacheMemoryDirFor_InvalidIDPanicsto assert an error.Acceptance Criteria:
cache_config.go.Code Region:
pkg/workflow/cache_config.go:37,pkg/workflow/cache_memory.go,pkg/workflow/sandbox.go:340📊 Historical Context
Previous Focus Areas
🎯 Recommendations
Immediate Actions (This Week)
Short-term Actions (This Month)
BUG:exemption — Priority: MediumLong-term Actions (This Quarter)
📈 Success Metrics
BUG:prefix: ~6 → 0Next Steps
Generated by Repository Quality Improvement Agent
Next analysis: 2026-10-03 — Focus area selected by diversity algorithm
All reactions