Skip to content

fix(github): stop the open-issues GraphQL supplement when endCursor is missing#8410

Merged
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
RealDiligent:fix/critical-issue-endcursor-guard-8312
Jul 24, 2026
Merged

fix(github): stop the open-issues GraphQL supplement when endCursor is missing#8410
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
RealDiligent:fix/critical-issue-endcursor-guard-8312

Conversation

@RealDiligent

Copy link
Copy Markdown
Contributor

Summary

  • supplementOpenIssuesFromGraphQl (src/github/backfill.ts:1831) ended its pagination loop on hasNextPage alone. If GitHub reports hasNextPage: true with a null/absent endCursor, JSON.stringify(undefined) serializes to the string undefined, producing a malformed , after: undefined follow-up query. That request fails, the function throws, and supplementUnderCountIfNeeded's catch discards the entire supplement attempt — including every issue already fetched on prior pages — leaving only a generic warning.
  • Backports the guard its sibling supplementOpenPullRequestsFromGraphQl (:1897) already has: if (!issues?.pageInfo?.hasNextPage || !issues.pageInfo.endCursor) break; — the exact same condition shape. The PR-side function was added two days after the issues one as a close copy and picked up the guard; it was never backported.
  • On the anomaly the loop now breaks and the existing return supplemented; keeps whatever prior pages accumulated — the graceful partial stop the sibling already achieves. No other logic change; the /* v8 ignore start/stop */ scope is untouched.
  • Adds a regression test to test/unit/backfill.test.ts alongside the existing sparse-payload supplement test: page 1 returns pageInfo: { hasNextPage: true, endCursor: null } with one issue, and the follow-up after:-bearing request is stubbed to fail (502). With the guard that request is never issued and the segment completes partial with fetchedCount: 1, the issue persisted; without the guard the malformed query fires, throws, and the whole supplement is discarded.

Closes #8312

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage locally; codecov/patch requires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:build
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

  • This diff touches only src/github/backfill.ts (one line) and test/unit/backfill.test.ts, so actionlint (no workflow change), build:mcp/test:mcp-pack (no MCP change), ui:* (no UI/OpenAPI change), test:workers (no worker change), and npm audit (no dependency change) are not exercised by it.
  • Codecov note (per the issue's own Test Coverage Requirements): the changed line sits inside this function's pre-existing /* v8 ignore start … stop */ block — the file's established convention for defensive GraphQL-payload-normalization code, matching the sibling PR-supplement function's identical treatment. It is therefore intentionally outside Codecov's branch-count gate and should not be read as uncovered patch code. The behavioral coverage is the real regression test above, which is exactly how this file already tests other ignored-block code (e.g. the fetchLiveReviewThreadBlockers cursor-guard test in backfill-2.test.ts).
  • test/unit/backfill.test.ts passes in full (133 tests). I also verified the new test genuinely pins the fix: reverting the one-line guard makes it fail, restoring it makes it pass. Root tsc --noEmit is clean for the changed files.

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

Not applicable — backend-only pagination guard in src/github/backfill.ts; no visible UI, frontend, docs, or extension change.

Notes

  • Pure parity backport: the fix is character-for-character the sibling's condition, so the two supplement helpers now handle the same GitHub GraphQL anomaly identically. The same anomaly class is already guarded a third time in this file by fetchLiveReviewThreadBlockers's if (!nextCursor || …) break;.

@RealDiligent
RealDiligent requested a review from JSONbored as a code owner July 24, 2026 11:49
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

…s missing

supplementOpenIssuesFromGraphQl broke pagination on hasNextPage alone, so a
GitHub response claiming another page with a null/absent endCursor serialized
into a malformed 'after: undefined' query. That request fails, the function
throws, and supplementUnderCountIfNeeded's catch discards the entire supplement
attempt including every issue already fetched on prior pages.

Mirrors the guard its sibling supplementOpenPullRequestsFromGraphQl already has
(added two days later as a close copy and never backported), so the issues path
degrades gracefully and keeps what it fetched. Adds a regression test that fails
without the guard.

Closes JSONbored#8312
@codecov

codecov Bot commented Jul 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.92%. Comparing base (af270b9) to head (727a2fe).
⚠️ Report is 6 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8410      +/-   ##
==========================================
- Coverage   92.42%   89.92%   -2.50%     
==========================================
  Files         791       98     -693     
  Lines       79250    23996   -55254     
  Branches    23946     4369   -19577     
==========================================
- Hits        73243    21579   -51664     
+ Misses       4868     2194    -2674     
+ Partials     1139      223     -916     
Flag Coverage Δ
shard-1 89.45% <ø> (+33.08%) ⬆️
shard-2 28.44% <ø> (-24.63%) ⬇️
shard-3 50.07% <ø> (-2.98%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/github/backfill.ts 95.96% <ø> (ø)

... and 693 files with indirect coverage changes

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 24, 2026
@loopover-orb

loopover-orb Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Tip

✅ LoopOver review result - approve/merge recommended

Review updated: 2026-07-24 12:15:32 UTC

2 files · 1 AI reviewer · no blockers · readiness 95/100 · CI green · clean

✅ Suggested Action - Approve/Merge

  • safe to merge

Review summary
This is a one-line guard fix backporting the exact `!issues.pageInfo.endCursor` check that the sibling PR-supplement function already has, closing the gap where a `hasNextPage: true` + null `endCursor` response would serialize to a malformed `after: undefined` GraphQL query, throw, and cause `supplementUnderCountIfNeeded`'s catch to discard all previously-fetched pages. The included regression test correctly reproduces this exact scenario (page 1 with `endCursor: null`, a stubbed 502 on any `after:`-bearing follow-up) and asserts the guard prevents the malformed request and preserves the partial result. The fix is minimal, correctly mirrors existing sibling logic, and is well-targeted to the stated issue.

Nits — 2 non-blocking
  • The PR closes fix(github): supplementOpenIssuesFromGraphQl is missing the endCursor null-guard its PR-side twin has #8312 as required by scope conventions, and the fix/test pairing is tight — no notable nits beyond the routine 'long file' size flag on backfill.ts, which predates this diff and isn't caused by it.
  • Consider whether `supplementOpenPullRequestsFromGraphQl` and `supplementOpenIssuesFromGraphQl` could share this pagination-guard logic to prevent future drift between the two near-duplicate functions, though that's a larger refactor out of scope for this fix.

Decision drivers

  • ✅ Code review — No blockers (1 reviewer)
  • ✅ Gate result — Passing (No configured blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #8312
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (1 linked issue).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 354 registered-repo PR(s), 137 merged, 37 issue(s).
Contributor context ✅ Confirmed Gittensor contributor RealDiligent; Gittensor profile; 354 PR(s), 37 issue(s).
Improvement ✅ Minor risk: clean · value: minor · LLM: moderate
Linked issue satisfaction

Addressed
The one-line diff adds exactly the required `!issues.pageInfo.endCursor` guard matching the sibling function's condition, and a regression test is added simulating the null-cursor anomaly and asserting a graceful partial stop with the accumulated issue preserved.

Review context
  • Author: RealDiligent
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: not available
  • Official Gittensor activity: 354 PR(s), 37 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Triage stale or unlinked PRs.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb loopover-orb Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LoopOver approves — the gate is satisfied and CI is green.

@loopover-orb
loopover-orb Bot merged commit 424078c into JSONbored:main Jul 24, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(github): supplementOpenIssuesFromGraphQl is missing the endCursor null-guard its PR-side twin has

1 participant