trunk-merge/pr-110638/5f4de5de-d4c7-40d5-a69d-f54c0fb69415-bisection - #110787
trunk-io[bot] wants to merge 15 commits into
Conversation
The context-mill manifest test downloaded the real GitHub release inside the MCP integration suite, so a slow GitHub turned the required MCP Tests Pass check red. It now lives in tests/live with its own vitest config and runs from a scheduled, non-required MCP live canary workflow that posts to Slack when the test fails. A unit test covers the unzip, manifest and filter path against an in-memory archive. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The hono integration harness booted the app with the live context-mill release, so a GitHub failure emptied the resource catalog and a slow GitHub ran the suite's beforeAll out of time. The harness now serves a small context-mill archive from a local server and points POSTHOG_MCP_LOCAL_SKILLS_URL at it. getEnv now forwards that variable, which the hono runtime silently dropped before, so the documented dev:local-resources flow also takes effect. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Generated-By: PostHog Desktop Task-Id: ca4abf89-95ed-41ef-b2f2-4a4344ed8474
Generated-By: PostHog Desktop Task-Id: ca4abf89-95ed-41ef-b2f2-4a4344ed8474
6 updated Run: 4d988756-6cf5-4cce-bf8e-d38a08518f2b Co-authored-by: sakce <49978945+sakce@users.noreply.github.com>
Generated-By: PostHog Desktop Task-Id: ca4abf89-95ed-41ef-b2f2-4a4344ed8474
Generated-By: PostHog Desktop Task-Id: ca4abf89-95ed-41ef-b2f2-4a4344ed8474
2 updated Run: 8c3721a2-5a71-4685-a39b-49254730b6df Co-authored-by: sakce <49978945+sakce@users.noreply.github.com>
Generated-By: PostHog Desktop Task-Id: ca4abf89-95ed-41ef-b2f2-4a4344ed8474
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Generated-By: PostHog Desktop Task-Id: 043260f0-bf7c-4ceb-bf67-ae92c93a6192
…e8d2c64bc-bisection
…c0fb69415-bisection
…c0fb69415-bisection
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (18)📝 WalkthroughWalkthroughThe data modeling lineage graph now supports optional node dragging, saved positions, reset controls, external links, and focus fitting. The data modeling tab connects these interactions to feature-flagged state and move analytics. MCP changes add local resource archive configuration and integration coverage, plus a dedicated live-test configuration and scheduled GitHub Actions workflow. Priority: ➖ Normal Merge Risk: 🔵 Low · up to Restore the archive URL after harness use and add the ready-for-review trigger before merging. The remaining test assertion would strengthen protection for local archive loading. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The main risk is configuration isolation: an alternate archive can populate resource storage consumed by other MCP instances if they share a Redis database. Ordinary requests do not control the archive URL. Lineage movement remains client-side, and Slack credentials are used only for scheduled failure notifications. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ❌ 1❌ Failed checks (1 warning)
Full details: Description checkExplanation The description only documents Trunk Merge batch-bisection metadata. It does not explain the MCP and data-modeling changes, user impact, testing, release status, or agent context required by the repository template. Resolution Replace or supplement the Trunk Merge text with a complete description using the required sections: Problem, Changes, How did you test this code?, Test rationale, Release status, Automatic notifications, Docs update, and Agent context when applicable. Include frontend screenshots and testing evidence where required.
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Usage-based review receipt
Note This review exceeded your plan’s limits and used usage-based reviews—free during trial. After your trial, your Enterprise plan’s existing billing terms apply. Manage usage-based reviews. Comment |
There was a problem hiding this comment.
Note
Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.
🟡 Other comments (2)
.github/workflows/ci-mcp-live-canary.yml-15-16 (1)
15-16: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winInclude
ready_for_reviewin the PR trigger.The default
pull_requestevent types omitready_for_review. If a draft skips CI, marking it ready will not dispatch this canary until another listed event occurs. Declareopened,synchronize,reopened, andready_for_reviewwhile keeping the path filter.As per coding guidelines, “Still add
ready_for_reviewto thepull_requesttypes.”Source: Coding guidelines
services/mcp/tests/integration/harness/hono.ts-67-67 (1)
67-67: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick winRestore
POSTHOG_MCP_LOCAL_SKILLS_URLduring cleanup.
stop()closescontextMillArchivebut leaves the environment variable set to its stopped URL. A laterMcpDispatchercan construct aResourceCatalogwith that URL and fail to load ContextMill resources. Save the previous value and restore it instop(), including when startup fails after the assignment.Suggested fix
export async function startHonoHarness(env: IntegrationEnv): Promise<IntegrationHarness> { process.env.POSTHOG_API_BASE_URL = env.apiBaseUrl + const previousLocalSkillsUrl = process.env.POSTHOG_MCP_LOCAL_SKILLS_URL // ResourceCatalog snapshots this URL at construction. ... const stop = async (): Promise<void> => { await new Promise<void>((resolve) => server.close(() => resolve())) await skillArchive?.stop().catch(() => undefined) await contextMillArchive?.stop().catch(() => undefined) + if (previousLocalSkillsUrl === undefined) { + delete process.env.POSTHOG_MCP_LOCAL_SKILLS_URL + } else { + process.env.POSTHOG_MCP_LOCAL_SKILLS_URL = previousLocalSkillsUrl + } await redis?.quit().catch(() => undefined) }
🧹 Nitpick comments (1)
services/mcp/tests/unit/context-mill-archive.test.ts (1)
48-50: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winAssert that extraction fetches
ARCHIVE_URL.The fetch stub returns the same archive for every URL. This test can pass if the loader fetches
CONTEXT_MILL_URLinstead ofARCHIVE_URL. Assert the requested URL after the call.Suggested test assertion
const entries = await fetchAndExtractEntries(ARCHIVE_URL) + expect(vi.mocked(fetch).mock.calls[0]?.[0]).toBe(ARCHIVE_URL) expect(entries.map((entry) => entry.id)).toEqual(['bundled', 'inline'])
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
Review profile: QUIET
Plan: Enterprise
Run ID: 73d8a81f-2a82-4cda-a298-20a1b977b063
📒 Files selected for processing (20)
.github/workflows/ci-mcp-live-canary.ymlfrontend/snapshots.ymlfrontend/src/lib/constants.tsxproducts/data_modeling/frontend/lineage/LineageGraph.stories.tsxproducts/data_modeling/frontend/lineage/LineageGraph.tsxproducts/data_modeling/frontend/lineage/LineageNode.tsxproducts/data_modeling/frontend/lineage/ModelsLineageTab.tsxproducts/data_modeling/frontend/lineage/modelsLineageLogic.test.tsproducts/data_modeling/frontend/lineage/modelsLineageLogic.tsservices/mcp/package.jsonservices/mcp/src/hono/constants.tsservices/mcp/src/hono/resource-catalog.tsservices/mcp/src/tools/types.tsservices/mcp/tests/hono/integration-harness.test.tsservices/mcp/tests/integration/harness/hono.tsservices/mcp/tests/integration/harness/skill-archive.tsservices/mcp/tests/live/context-mill-manifest.live.test.tsservices/mcp/tests/unit/context-mill-archive.test.tsservices/mcp/vitest.config.mtsservices/mcp/vitest.live.config.mts
Limit details: You’ve used all 12 included reviews currently available.
This pull request was created and is being managed by Trunk Merge.
This pull request is based on the master branch at SHA 1830cfd7be9848bd447c33b37e218156da32d806.
See more details here.
When CI completes, this pull request will be closed automatically.
Pull Requests Being Tested
This pull request is testing the changes from pull request 110638.
Dependencies
This pull request depends on the changes from pull request 110199.
Batch Bisection
This pull request is in a batch bisection. Pull requests successfully tested by this PR will re-enter the main queue.