Skip to content

fix(cli): record skipped files in the report bundle manifest - #1161

Merged
aviggiano merged 2 commits into
mainfrom
fix/report-bundle-omissions
Sep 28, 2026
Merged

aviggiano merged 2 commits into
mainfrom
fix/report-bundle-omissions

Conversation

@mrthankyou

@mrthankyou mrthankyou commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #1101

Problem

ultrafuzz report bundle skips files it cannot safely package (e.g. an engine log over the 64 MiB per-file limit) and reports that only as a REPORT_BUNDLE_FILE_SKIPPED / REPORT_BUNDLE_SYMLINK_SKIPPED CLI diagnostic. Nothing is written into bundle-manifest.json, so a recipient holding only the ZIP cannot tell which evidence is missing or why.

Change

  • bundle-manifest.json now carries omitted_files: [{ path, reason, bytes? }], recorded at exactly the points that already emit a skip diagnostic.
    • path is run-relative; engine logs use their neutral engine-logs/<name> source path (same form as path_mappings), so the manifest does not name the orchestration engine.
    • reason is one of file-size-limit, symlink, not-regular-file, unsafe-path, unreadable.
    • bytes is the source size when it is known.
  • Intentional exclusions remain in excluded_roots / excluded_patterns, so they stay distinct from skipped files.
  • Schema: omitted_files is an optional, closed property of the v3 manifest (same approach as scope / verification in feat(runtime): default to best-effort runs with agent-written PARTIAL reports #1120), so existing v3 bundles still validate. It must be empty for scope: "report-only" bundles.
  • Resource limits and source files are unchanged. Chunked logs and a separate logs archive are not included here.

Testing

  • New test report bundle manifest records files it could not package: a 64 MiB + 1 sparse engine log and a symlinked log are listed with the right reasons and size, the manifest validates against the schema, an unknown reason is rejected, and the source log stays on disk.
  • The existing portable-ZIP test now asserts that its intentionally unsafe bad\name.txt is recorded as unsafe-path.
  • Locally (macOS): CLI build (including verify-schema-registry), the other report bundle tests, the stats bundle test, and cli-contracts (14/14) pass. ESLint and Prettier are clean.
  • The portable-ZIP test fails locally only at its pre-existing Trace.log / trace.log assertion, because APFS is case-insensitive. The new assertion in that test passes. It should pass on Linux CI.

Not changed

The CLI skip diagnostic still includes the absolute smithers/logs/... path. That is pre-existing and left for a separate change.

🤖 Generated with Claude Code

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no new actionable issue remains, and both previous threads are resolved.

Summary

The PR adds skipped-file details to full report-bundle manifests and documents the new field. The changes since the previous review route non-regular entries through omission recording, align unsafe-path classification with packaging order, and extend the test coverage.

Reviews (2) · Last reviewed commit: "fix(cli): record non-regular and unsafe-..."

report bundle skipped oversized, symlinked, non-regular, unsafely named,
or unreadable files with only a CLI diagnostic, so a recipient holding
just the ZIP could not tell which evidence was missing or why. The
manifest now carries an omitted_files list with the run-relative path
(engine logs under their neutral engine-logs/ prefix), a reason code,
and the source size when known. The field is optional in the v3 schema
so existing bundles still validate, and must be empty for report-only
bundles.

Closes #1101

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@mrthankyou
mrthankyou requested a review from a team as a code owner September 26, 2026 17:35
Comment thread packages/cli/src/commands/report/bundle.ts Outdated
Comment thread packages/cli/src/commands/report/bundle.ts Outdated
…ission reason

Directory walks now route FIFOs, sockets and devices through addBundleFile so
they are recorded as not-regular-file instead of disappearing, and a file that
is both oversized and badly named is recorded as unsafe-path, matching the
check that actually rejects it first.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@greptile-apps

greptile-apps Bot commented Sep 28, 2026

Copy link
Copy Markdown

Want your agent to iterate on Greptile's feedback? Start a greploop in Claude Code and it will work through the open comments and keep going until this PR reviews clean.

@aviggiano aviggiano left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Both Greptile findings reproduced and fixed in cdd41a5: FIFOs/sockets/devices in walked directories are now recorded as not-regular-file, and an oversized file with an unsafe archive name is recorded as unsafe-path (the check that rejects it first). The extended test covers both and fails on the previous head; the source-log-stays-on-disk assertion is kept.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Report bundle does not record oversized-file omissions inside the ZIP

2 participants