Skip to content

fix: issue with upload local bundled policy files as artifacts - #100

Merged
reecebedding merged 1 commit into
mainfrom
fix/upload-local-tar-policy-artifact
Oct 2, 2026
Merged

reecebedding merged 1 commit into
mainfrom
fix/upload-local-tar-policy-artifact

Conversation

@reecebedding

Copy link
Copy Markdown
Member

No description provided.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:13
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 951eafa9-6b5e-4b6c-9511-73d560ac5a0a

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The change is small, correctly distinguishes bundle files from directories, and is covered by a focused new test alongside existing directory-based tests.

Review effort: Balanced
Findings: None

What changed in this PR

This PR fixes a bug in the agent's policy artifact uploader. Previously, storeEvaluation always ran the policy path through tarDirectory, which assumes a directory. When a local policy is a pre-built bundle archive (e.g. opa build's bundle.tar.gz), tarDirectory would walk the single file and wrap it inside a second tar with a broken entry name, corrupting the uploaded bundle. The new packageBundle helper inspects the path: a regular file (bundle archive) is uploaded as-is, while a directory (e.g. an extracted OCI policy) is archived via tarDirectory. This fits into the broader artifact-upload flow where the agent hashes and uploads the bundle, input, and policy data once per evaluation.

Changes:

  • Added packageBundle, which sends a regular file as-is and tars a directory, replacing the direct tarDirectory call in storeEvaluation.
  • Added a writeBundleArchive test helper that produces a gzipped tar bundle.
  • Added TestCreateEvidenceUploadsABundleArchiveAsIs asserting a bundle archive's digest matches the raw file (not a re-wrapped tar).
File Description
runner/​policy_artifacts.go Introduces packageBundle to distinguish bundle archives (sent as-is) from directories (archived), fixing double-wrapping of local bundle files.
runner/​policy_artifacts_test.go Adds a gzipped-tar bundle helper and a test verifying a bundle archive is uploaded unchanged.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@reecebedding
reecebedding force-pushed the fix/upload-local-tar-policy-artifact branch from f23d92a to c315b3a Compare October 2, 2026 12:18
@reecebedding
reecebedding merged commit fb2ce98 into main Oct 2, 2026
5 checks passed
@reecebedding
reecebedding deleted the fix/upload-local-tar-policy-artifact branch October 2, 2026 13:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants