Repository navigation
fix: issue with upload local bundled policy files as artifacts - #100
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change is small, correctly distinguishes bundle files from directories, and is covered by a focused new test alongside existing directory-based tests.
Review effort: Balanced
Findings: None
What changed in this PR
This PR fixes a bug in the agent's policy artifact uploader. Previously, storeEvaluation always ran the policy path through tarDirectory, which assumes a directory. When a local policy is a pre-built bundle archive (e.g. opa build's bundle.tar.gz), tarDirectory would walk the single file and wrap it inside a second tar with a broken entry name, corrupting the uploaded bundle. The new packageBundle helper inspects the path: a regular file (bundle archive) is uploaded as-is, while a directory (e.g. an extracted OCI policy) is archived via tarDirectory. This fits into the broader artifact-upload flow where the agent hashes and uploads the bundle, input, and policy data once per evaluation.
Changes:
- Added
packageBundle, which sends a regular file as-is and tars a directory, replacing the directtarDirectorycall instoreEvaluation. - Added a
writeBundleArchivetest helper that produces a gzipped tar bundle. - Added
TestCreateEvidenceUploadsABundleArchiveAsIsasserting a bundle archive's digest matches the raw file (not a re-wrapped tar).
| File | Description |
|---|---|
| runner/policy_artifacts.go | Introduces packageBundle to distinguish bundle archives (sent as-is) from directories (archived), fixing double-wrapping of local bundle files. |
| runner/policy_artifacts_test.go | Adds a gzipped-tar bundle helper and a test verifying a bundle archive is uploaded unchanged. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
f23d92a to
c315b3a
Compare
No description provided.