Fix silently swallowed and lossy error handling - #6
Open
devin-ai-integration[bot] wants to merge 3 commits into
Open
devin-ai-integration[bot] wants to merge 3 commits into
devin-ai-integration[bot] wants to merge 3 commits into
Conversation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Audit of every
catchinsrc/plus the paths where a failure was either discarded or allowed to take down more than itself. Six behavioral fixes:One unreadable file no longer destroys a whole scan.
runScanawaitedreadFileunguarded, so a permission error or a file deleted mid-scan threw and every other file's results were lost. Failures are now collected and the scan continues:ScanReport.fileErrors/ScanSummary.filesFailedare new (breaking for programmatic consumers constructing these types) and are surfaced in all three report formats. Crucially they also fail the run — CLIexitCode = 2,core.setFailedin the Action — so a partially-failed scan can't look green.HEAD errors were thrown away.
performRequesthad a barecatch {}around the HEAD request that blind-retried with GET, so the original failure vanished and a timeout got retried, silently spending twice the caller's--timeoutbudget. Now timeout/abort/cancel rethrow immediately, and a failed GET carries the HEAD error ascause.error as AxiosErrorwas a lie. A thrown non-Error madeaxiosError.messageundefinedand the result reported"Unknown network error"instead of the actual value; timeout detection relied on amessage.includes('timeout')substring and missedETIMEDOUT/ERR_CANCELED. Now usesaxios.isAxiosError, classifies by code, and propagates the code asCheckResult.errorCode(also in the JSON report).Promise.allinrunWithConcurrencylost errors — the first rejection returned while the rest of the pool kept running unobserved. Replaced with settle-all plus anAggregateError, and a worker that throws unexpectedly is converted into abrokenresult for that URL rather than aborting the scan.Auxiliary Action failures masked the verdict. A PR-comment or step-summary failure called
setFailed, reporting a link-check failure that never happened; both are nowcore.warning. ConverselygetBooleanInputsilently read any non-truevalue asfalseandgetNumberInputsilently fell back on garbage — both now reject invalid input with the offending value.Only
error.messageever reached the user. Newsrc/errors.tsrenders the fullcausechain and nestedAggregateError.errors(stacks behind--verbose/core.debug), Zod config failures print as one readable line per bad option instead of a raw dump, numeric CLI options are validated against the flag name rather than reaching Zod asNaN, and report writers create the parent directory and name which report/path failed.npm run lint,typecheck,test(61 tests),build,format:checkall pass.Link to Devin session: https://app.devin.ai/sessions/35b225657ebf4551a926985790de4095
Requested by: @lahcenassmira