Skip to content

fix(mirror): get_file_at_commit בודק את גודל האובייקט לפני git show, וקובץ מעל התקרה אינו נטען כלל (#3433, פריט 9) - #3437

Closed
amirbiron wants to merge 1 commit into
mainfrom
claude/gracious-einstein-sevk8p-3433
Closed

amirbiron wants to merge 1 commit into
mainfrom
claude/gracious-einstein-sevk8p-3433

Conversation

@amirbiron

@amirbiron amirbiron commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

✨ תיאור קצר

📦 שינויים עיקריים

  • קוד (Backend)
  • בוט טלגרם
  • מסד נתונים/מיגרציות
  • תיעוד (docs/)
  • DevOps/CI/CD

פירוט נקודות (רשימת תבליטים):

  • _object_size (חדש): git cat-file -s <sha>:<path> מחזיר את גודל האובייקט מהמאגר בלי לקרוא אותו. שתי הפקודות פונות לאותו sha שנפתר פעם אחת ב-_validate_ref_with_git — לא ל-HEAD — ולכן אין חלון בין הבדיקה לקריאה שסנכרון של המראה יכול להיכנס בו: אובייקט בקומיט נתון אינו משתנה. TOCTOU נבחן ונדחה מהסיבה הזאת, וטסט מקבע ששתי הפקודות נושאות את אותו sha ושהבדיקה קודמת לקריאה.
  • בין cat-file ל-show נבחר cat-file (האישו הציע גם קריאה בזרם עם תקרת בתים): הוא נותן את הגודל המדויק לתשובת file_too_large — כמו היום — במקום "יותר מהתקרה", אינו דורש הרג של תת-תהליך באמצע זרם, ומחירו תהליך git אחד קצר לכל קריאה במסלול שהוא אדמין (lines=/outline) או 500KB לכל היותר (docs_get_section).
  • כשל בבדיקת הגודל הוא סירוב, לא נפילה לקריאה בלי תקרה (silent-fallback-to-worse-path): stderr ממופה באותה מפה של git show, ופלט שאינו מספר הוא git_error ולא אפס (U3: פלט של תת-תהליך הוא קלט חיצוני, ו"אפס" היה עובר את התקרה בשקט). המיפוי אוחד ל-_object_read_error — הגדרה אחת לשתי הפקודות (R6) — אחרי שנמדד ש-git 2.43 מדפיס את אותן הודעות לשתיהן: path 'x' does not exist in '<sha>' על נתיב חסר, ו-exists on disk, but not in על קומיט שאינו מכיל אותו.
  • החסם על מה שמוחזר נשאר, בנוסף לחסם על מה שנקרא: לנתיב של תיקייה cat-file -s מודד את אובייקט העץ ואילו git show מדפיס רשימה מעוצבת. מה שחוזר מהפונקציה לעולם אינו גדול מ-max_size, יהיה סוג האובייקט אשר יהיה; טסט מקבע זאת עם מאגר "שמשקר", ומוטציה שמוחקת את הבדיקה מפילה אותו.
  • התשובות לא זזו: מתחת לתקרה — תוכן, קידוד, size, lines, resolved_commit זהים (בקרה); מעל התקרה — אותו dict עם size של הבלוב; נתיב חסר — file_not_in_commit. repo_backend והוובאפ (repo_browser.py) צורכים את אותם שדות ולא נגעתי בהם.
  • תיעוד והערות שתיארו "טוענת את ה-blob כולו לפני בדיקת הגודל" עודכנו: ה-docstring של max_size, ההערה ליד RANGE_READ_MAX_BYTES ב-repo_backend.py, ההערה ליד _PARSE_COST_BYTES ב-server.py (שהפנתה ל-מעקב אחרי סקירת PR #3429 (מאגר הקריאות של ה-MCP): שמונה הצעות שלא תוקנו ב-PR, וחסימת קריאת המראה במקור #3433 כפתוח), הפסקה ב-"מודל הריצה של הכלים" ב-docs/mcp-server.rst, ו-docs/whats-new.rst. ההחלטה מ-fix(mcp): מאגר הקריאות נגזר ממכסת הזיכרון של הקונטיינר, לא ממעבדי המארח (#3391) #3429 שהמחלק נשאר מתומחר לפי הפרסור עומדת — ההחזקה של קובץ מתחת לתקרה (7MB ← 37MiB) לא השתנתה, ומה שנעלם הוא ההחזקה של קובץ שנדחה.
  • ממצא מחוץ להיקף, לדיווח ולא לתיקון כאן: get_file_content (הקורא השני, דרך _run_git_command עם text=True) עדיין קורא בלי שום תקרה. הקוראים שלו: repo_sync_service (אינדוקס), webapp/app.py ו-repo_browser.py. פריט 9 מדבר על get_file_at_commit, והוספת תקרה ל-get_file_content היא שינוי התנהגות לקוראים שאין להם max_size בכלל — ראוי לאישו משלו.

🧪 בדיקות

  • tests/test_git_mirror_service.py (7 טסטים חדשים) על מראה git אמיתית שנבנית ב-tmp_path (bare clone, כמו בייצור) עם מרגל על subprocess.run שרושם אילו פקודות git רצו — כי התכונה הנבדקת היא מה לא נקרא, ואת זה רואים רק ברשימת הפקודות: קובץ מעל התקרה נדחה מ-cat-file ו-git show אינו רץ; מתחת לתקרה נקרא בדיוק כמו קודם (בקרה); נתיב חסר ממופה ל-file_not_in_commit דרך הבדיקה; שתי הפקודות נושאות את אותו sha שנפתר, והבדיקה קודמת לקריאה; כשל בבדיקה אינו נופל לקריאה; גודל שאינו מספר הוא כשל; ומה שמוחזר נבדק מול התקרה גם כשהמאגר דיווח גודל קטן.
  • על הקוד הישן (worktree מנותק על origin/main = 1a45c28c): ארבעה נופלים (הסירוב לפני git show, אותו sha והסדר, כשל בבדיקה, גודל שאינו מספר), ושלושה עוברים שם בכוונה — שתי הבקרות והפין של החסם השני.
  • מוטציה (worktree על הקוד החדש, החסם על מה שמוחזר נמחק): הפין שלו נופל, וטסט הסירוב-לפני-הקריאה ממשיך לעבור — כלומר כל אחד משני החסמים נמדד בנפרד.
  • מדידה לפני/אחרי (VmHWM בתהליך נקי, מראה bare עם קבצי JS טקסטואליים):
קובץ תקרה לפני אחרי
12MB 500KB 20.2MiB שיא, file_too_large 0.0MiB, file_too_large, אותו size
12MB 10MiB 20.4MiB שיא, file_too_large 0.0MiB, file_too_large, אותו size
7MB (מתחת) 10MiB 14.2MiB, נקרא במלואו 14.5MiB, נקרא במלואו
  • סוויטות: 703 טסטים ב-test_git_mirror_service, test_git_mirror_last_commit, test_git_history, test_repo_browser_multi, test_mcp_repo_backend, test_mcp_additive_params, test_mcp_outline, test_mcp_docs_handlers, test_mcp_search_total, test_mcp_search_pattern_mode, test_mcp_repo_policy, test_mcp_server_build, test_mcp_to_thread — ירוקים. flake8 עם ה-selection של CI (E9,F63,F7,F82) — 0. (ב-git_mirror_service.py יש F841/W391 קיימים מלפני, מחוץ לדיף; ב-server.py E302 מ-feat(mcp): docs_get_section קורא גם Markdown, לפי מדיניות נתיבים לכל ריפו #3428 שכבר מתוקן בשני PRים פתוחים.) docutils על שני עמודי התיעוד — 0 אזהרות.
  • לא אימתתי: את המסלול בייצור מול המראות האמיתיות (md_preview.bundle.js.map של 11.7MB) — הקומפוזיציה זהה למדידה כאן (bare mirror, git cat-file -s ואז git show), ו-git בייצור הוא כזה שמדפיס את אותן הודעות (הטסט על נתיב חסר מקבע את המיפוי דרך git אמיתי).
  • Unit
  • Integration
  • Manual

🧪 בדיקות נדרשות ב‑PR

  • 🔍 Code Quality & Security
  • Unit Tests (3.11)
  • Unit Tests (3.12)

📝 סוג שינוי

  • feat: פיצ'ר חדש
  • fix: תיקון באג
  • docs: שינוי תיעוד בלבד
  • refactor: שינוי קוד ללא שינוי התנהגות
  • perf: שיפור ביצועים
  • chore/ci: תשתית/CI
  • breaking change: שינוי שובר תאימות

✅ צ'קליסט

  • הקוד עוקב אחרי הסגנון (Black/isort/flake8/mypy)
  • בדיקות רצות ועוברות
  • תיעוד עודכן (README/Docs)
  • אם נוספו ג'ובים חדשים (Background Jobs) – לא נוספו
  • אם נוספו/שונו משתני סביבה – לא נוספו
  • אם נוספו/השתנו טוקנים – לא רלוונטי
  • אין סודות/מפתחות בקוד
  • אין מחיקות מסוכנות/פעולות על root (ראו .cursorrules)
  • הודעת הקומיט תואמת Conventional Commits (ע"פ הטבלה)
  • CHANGELOG עודכן אם נדרש — docs/whats-new.rst עודכן
  • כל ה‑Required Checks לעיל ירוקים — ייבדק ב-CI
  • צילום/וידאו UI מצורף אם רלוונטי — לא רלוונטי
  • עיינתי במסמכי אתר התיעוד — נתיב: AI-MAP.md, docs/mcp-server.rst ("מודל הריצה של הכלים", טבלת הגבולות), docs/doc-authoring.rst, docs/versioning-stable-anchors.rst | המשפט: "והמראה טוענת את ה-blob כולו לזיכרון לפני בדיקת הגודל" — המשפט שהשתנה
  • לא נדרש עיון — התנאי התקיים (התנהגות מתועדת)

דפוסי באגים שנקראו ומה שקבעו בקוד: CRITICAL-PATTERNS.md K11 + bugbot-rules/return-value-failure-unchecked.md — subprocess.run מחזיר returncode ואינו זורק: הוא נבדק בשני המקומות, ו-_object_size מחזיר ערך כשל שהקורא בודק ("error" in probe); bugbot-rules/silent-fallback-to-worse-path.md — כשל בבדיקה אינו נופל ל-git show בלי תקרה; CORE-PATTERNS.md U1 + bugbot-rules/race-toctou.md — check-then-act על <sha>:<path> שאינו משתנה, לכן לא ממצא, וזה מקובע בטסט על אותו sha; CORE-PATTERNS.md U3 + bugbot-rules/external-input-isinstance.md — פלט cat-file מפוענח תחת except ValueError צר, ופלט פגום הוא כשל; bugbot-rules/silent-truncation-at-sink.md — התקרה דוחה ואינה חותכת, בשני החסמים; bugbot-rules/work-disproportionate-to-answer.md (R8) — הממצא עצמו: 20MiB שנקראו בשביל תשובה של "גדול מדי"; CRITICAL-PATTERNS.md K13 — ה-stderr עובר _sanitize_output לפני שהוא נכנס לתשובה או ללוג, כמו קודם; RECURRING-PATTERNS.md R6 — מיפוי השגיאות אוחד לפונקציה אחת במקום להיכתב פעם שנייה; bugbot-rules/state-record-without-state-change.md — ההערות והתיעוד שתיארו "נטען לפני הבדיקה" עודכנו יחד עם הקוד; claude-md-snippets/testing.md §5 + TESTING-PATTERNS.md T2 — ריצה על הקוד הישן ומוטציה; bugbot-rules/widened-exception-scope.md — לא הורחב אף except.

🧩 השפעות/סיכונים

  • ייצור: תהליך git cat-file -s נוסף לפני כל git show ב-get_file_at_commit — כמה מילישניות על מראה חמה; בתמורה, קובץ מעל התקרה אינו נטען עוד לזיכרון של חוט הקריאה (20MiB לקובץ של 12MB, נמדד). התשובות ללקוחות זהות.
  • מה לא השתנה: get_file_content, max_size של הקוראים, RANGE_READ_MAX_BYTES, ותמחור מאגר הקריאות.

🔗 קישורים

🧯 סיכון / החזרה לאחור (Rollback)

  • revert של הקומיט היחיד מחזיר את הקריאה-ואז-בדיקה. אין מיגרציה ואין משתנה סביבה.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SfJTSpDAhDr2yhtmpFkwTx


Generated by Claude Code

Review in cubic

Summary by Sourcery

Enforce file-size limits before reading Git objects while preserving existing responses and safeguards.

Bug Fixes:

  • Prevent oversized files from being loaded into memory by checking their Git object size before reading file contents.
  • Treat object-size probe failures and invalid output as Git errors instead of falling back to an unbounded read.

Enhancements:

  • Retain the response-size safeguard after reading and centralize Git object error mapping for consistent behavior.

Documentation:

  • Update runtime-model, memory-limit, and release documentation to describe the pre-read size enforcement.

Tests:

  • Add integration coverage for pre-read rejection, unchanged under-limit behavior, shared commit resolution, probe failures, malformed sizes, missing paths, and response-size enforcement.

…וקובץ מעל התקרה אינו נטען כלל (#3433, פריט 9)

עד היום git show נטען כולו לזיכרון (capture_output=True) ורק אז max_size
נבדק, כלומר התקרה הייתה בדיקה בדיעבד ולא חסם על הזיכרון: קובץ של 12MB
שנדחה עלה 20MiB שיא בחוט הקריאה לפני שהתשובה הייתה file_too_large. זה
השורש של WARN-003 בסקירת #3429, ומה שהניח את "קריאה אחת עולה לכל היותר X"
כהערה ולא כתכונה של הקוד.

- _object_size: git cat-file -s <sha>:<path> מחזיר את גודל האובייקט
  מהמאגר בלי לקרוא אותו. שתי הפקודות פונות לאותו sha שנפתר פעם אחת
  ב-_validate_ref_with_git, ולכן אין חלון בין הבדיקה לקריאה שסנכרון של
  המראה יכול להיכנס בו (TOCTOU נבחן ונדחה: אובייקט בקומיט נתון אינו משתנה).
- כשל בבדיקת הגודל הוא סירוב באותה מפה של git show, לא נפילה לקריאה בלי
  תקרה; פלט שאינו מספר הוא כשל ולא אפס (U3). מיפוי ה-stderr אוחד
  ל-_object_read_error, כי git 2.43 מדפיס את אותן הודעות לשתי הפקודות על
  נתיב חסר ועל קומיט שאינו מכיל אותו (נמדד).
- החסם על מה שמוחזר נשאר: לנתיב של תיקייה cat-file -s מודד את אובייקט
  העץ ואילו git show מדפיס רשימה, ומה שחוזר לעולם אינו גדול מ-max_size.
- אותה תשובה ואותו size בסירוב (גודל הבלוב), ואותה תשובה מתחת לתקרה.

נמדד (VmHWM, תהליך נקי, מראה bare עם קבצי טקסט): 12MB מול תקרה של 500KB
ושל 10MiB — 20.2 ו-20.4MiB שיא לפני, 0.0 אחרי; 7MB מתחת לתקרה — 14.2
לפני ו-14.5 אחרי, כי אותו כן קוראים.

טסטים על מראה git אמיתית ב-tmp_path עם מרגל על subprocess.run: ארבעה
נופלים על origin/main (הסירוב לפני git show, אותו sha לשתי הפקודות והסדר
ביניהן, כשל בבדיקה שאינו נופל לקריאה, גודל שאינו מספר), ושלושה עוברים
שם בכוונה כבקרות (מתחת לתקרה, נתיב חסר, החסם על מה שמוחזר); מוטציה שמוחקת
את החסם השני מפילה את הפין שלו. התיעוד וההערות שתיארו את "טוענת את ה-blob
כולו לפני בדיקת הגודל" עודכנו.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SfJTSpDAhDr2yhtmpFkwTx
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @amirbiron, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 hour and 42 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@github-actions

Copy link
Copy Markdown
Contributor

🧯 Dangerous deletes guard report

Policy: see .cursorrules — dangerous deletions are blocked unless wrapped safely.

Summary:

  • Flagged findings (blocking): 0
    0
  • Excluded matches (not blocking): 15
  • Total matches (all files): 128

Flagged findings (file:line:snippet):
(none)

Excluded matches (by path pattern)
./webapp/static/js/md_preview.bundle.js.map:4:  "sourcesContent": ["// Markdown-it plugin to render GitHub-style task lists; see\n//\n// https://github.com/blog/1375-task-lists-in-gfm-issues-pulls-comments\n// https://github.com/blog/1825-t … [truncated]
./docs/DOCUMENTATION_GUIDE.md:453:rm -rf _build
./docs/Makefile:24:	rm -rf $(BUILDDIR)
./Dockerfile:42:    rm -rf /var/lib/apt/lists/*
./Dockerfile:121:    rm -rf /var/lib/apt/lists/*
./node_modules/katex/package.json:153:    "build": "rimraf dist/ && mkdirp dist && cp README.md dist && rollup -c --failAfterWarnings && webpack && node update-sri.js package dist/README.md",
./node_modules/katex/src/fonts/Makefile:139:	rm -rf pfa ff otf ttf woff woff2
./node_modules/mermaid/dist/mermaid.js.map:4:  "sourcesContent": ["/**\n* Default values for dimensions\n*/\nconst defaultIconDimensions = Object.freeze({\n\tleft: 0,\n\ttop: 0,\n\twidth: 16,\n\theight: 16\n});\n/**\n* Default values for tr … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm/chunk-2M32CCKP.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequence d … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm.min/chunk-4HFYJGYH.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequen … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.esm.min/chunk-4HFYJGYH.mjs:1:var r={name:"mermaid",version:"11.12.0",description:"Markdown-ish syntax for generating flowcharts, mindmaps, sequence diagrams, class diagrams, gantt charts, git graph … [truncated]
./node_modules/mermaid/dist/chunks/mermaid.core/chunk-KS23V3DP.mjs.map:4:  "sourcesContent": ["{\n  \"name\": \"mermaid\",\n  \"version\": \"11.12.0\",\n  \"description\": \"Markdown-ish syntax for generating flowcharts, mindmaps, sequence  … [truncated]
./node_modules/mermaid/dist/mermaid.min.js:1524:`,"getStyles"),c1e=RQe});var h1e={};dr(h1e,{diagram:()=>NQe});var NQe,f1e=N(()=>{"use strict";$ge();a1e();l1e();u1e();NQe={parser:Fge,db:n1e,renderer:o1e,styles:c1e}});var m1e,g1e=N(()=>{"use  … [truncated]
./node_modules/mermaid/dist/mermaid.min.js.map:4:  "sourcesContent": ["/**\n* Default values for dimensions\n*/\nconst defaultIconDimensions = Object.freeze({\n\tleft: 0,\n\ttop: 0,\n\twidth: 16,\n\theight: 16\n});\n/**\n* Default values fo … [truncated]
./README.md:842:find . -name "__pycache__" -exec rm -rf {} +

@sourcery-ai

sourcery-ai Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

Reviewer's Guide

The PR changes get_file_at_commit from read-then-check to check-then-read by probing the Git object size with cat-file before git show, preventing oversized files from entering memory while preserving response semantics, error mappings, and a defensive output-size check. Tests validate command ordering and skipped reads using real bare mirrors, and documentation reflects the improved memory behavior.

Sequence diagram for bounded Git file retrieval

sequenceDiagram
    participant Caller
    participant MirrorService
    participant Git

    Caller->>MirrorService: get_file_at_commit(repo_name, file_path, commit, max_size)
    MirrorService->>Git: _validate_ref_with_git(commit)
    Git-->>MirrorService: resolved_commit
    MirrorService->>Git: _object_size(resolved_commit, safe_file_path)
    Git-->>MirrorService: cat-file size or error
    alt size probe fails
        MirrorService-->>Caller: file_not_in_commit or git_error
    else file_size > max_size
        MirrorService-->>Caller: file_too_large with size
    else file_size <= max_size
        MirrorService->>Git: git show resolved_commit:safe_file_path
        Git-->>MirrorService: raw content
        MirrorService-->>Caller: content or file_too_large
    end
Loading

File-Level Changes

Change Details Files
Adds a pre-read object-size check so files exceeding max_size are rejected before their contents are loaded.
  • Introduces git cat-file -s against the resolved commit SHA and path before git show.
  • Returns file_too_large with the repository-reported size without invoking git show for oversized objects.
  • Retains a second size check on returned output to cover non-blob objects and protect the response-size invariant.
services/git_mirror_service.py
Hardens and centralizes Git object-read error handling.
  • Shares stderr mapping between cat-file and git show.
  • Treats probe failures and non-numeric size output as errors rather than falling back to an unbounded read.
  • Continues sanitizing subprocess stderr before exposing it.
services/git_mirror_service.py
Adds integration-oriented tests for ordering, safety, compatibility, and failure behavior.
  • Uses real temporary bare mirrors and subprocess spying to verify cat-file precedes show and show is skipped for oversized files.
  • Covers unchanged under-cap responses, missing paths, shared resolved SHAs, probe failures, malformed size output, and the retained output-size guard.
tests/test_git_mirror_service.py
Updates runtime and documentation comments to describe the new memory bound.
  • Documents that max_size limits bytes read from the source, not only bytes returned.
  • Updates MCP runtime and release documentation while preserving existing downstream interfaces and pricing assumptions.
mcp_server/repo_backend.py
mcp_server/server.py
docs/mcp-server.rst
docs/whats-new.rst

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8e2e753c-a298-4a56-8ff4-c6be487510e6

📥 Commits

Reviewing files that changed from the base of the PR and between 1a45c28 and f8cdf9c.

📒 Files selected for processing (6)
  • docs/mcp-server.rst
  • docs/whats-new.rst
  • mcp_server/repo_backend.py
  • mcp_server/server.py
  • services/git_mirror_service.py
  • tests/test_git_mirror_service.py

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Changes

השינוי מעביר את בדיקת גודל האובייקט לפני git show ב־get_file_at_commit. קבצים גדולים נדחים ללא טעינת תוכן. נוספו מיפוי שגיאות, בדיקות, ותיעוד מעודכן. עבודת הקידוד של Claude Code מתועדת היטב בבדיקות ההתנהגות.

קריאת קבצים מוגבלת בגודל

Layer / File(s) Summary
בדיקת גודל וטיפול בשגיאות
services/git_mirror_service.py
git cat-file -s בודק את גודל האובייקט לפני git show. כשל בבדיקה מוחזר כ־git_error ללא קריאה לא מוגבלת. אובייקט גדול מחזיר file_too_large.
אימות סדר הקריאות ומגבלת התוצאה
tests/test_git_mirror_service.py
הבדיקות מאמתות את סדר הפקודות, טיפול בנתיבים חסרים ובשגיאות, קריאה מתחת לתקרה, וחסימה של תוצאה גדולה גם כאשר הפרוב מדווח גודל שגוי.
תיעוד ההתנהגות
docs/mcp-server.rst, docs/whats-new.rst, mcp_server/repo_backend.py, mcp_server/server.py
התיעוד מציין שקבצים מעל התקרה נדחים לפני טעינה, וקבצים מתחת לתקרה נקראים כרגיל.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 68.42% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 19 functions across 4 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed כותרת ה-PR מתארת באופן ברור ומדויק את השינוי המרכזי: בדיקת גודל האובייקט לפני git show ודחיית קובץ שחורג מהתקרה.
Description check ✅ Passed תיאור ה-PR מלא ומובנה לפי התבנית. הוא כולל את מטרת השינוי, פירוט טכני, בדיקות, סיכונים, קישורים ותוכנית Rollback. בדיקות ה-CI מסומנות כמתוכננות ולא כאילו הושלמו, ולכן אין בכך חוסר דיוק בתיאור.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 68.42% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 19 functions across 4 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

לפני הקריאה הגודל נבדק,
קובץ גדול נשאר בחוץ,
קובץ קטן ממשיך במסלול,
השגיאות קיבלו מיפוי ברור,
Claude Code כתב בדיקות חדות,
CodeKeeper forever 💫

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

⏱️ Performance report

(No performance test durations collected. Mark tests with @pytest.mark.performance.)

@github-actions

Copy link
Copy Markdown
Contributor

📖 Documentation Preview

The documentation has been built successfully!

To view locally:

  1. Download the artifacts
  2. Extract the zip file
  3. Open index.html in your browser

@codecov

codecov Bot commented Sep 20, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 86.95652% with 3 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
services/git_mirror_service.py 86.95% 2 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@amirbiron

Copy link
Copy Markdown
Owner Author

נכנס דרך #3443

@amirbiron amirbiron closed this Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants