Skip to content

fix(search): reject incomplete AWS recommendation menus - #37

Merged
cristim merged 2 commits into
mainfrom
test/aws-recommendation-completeness
Oct 3, 2026
Merged

cristim merged 2 commits into
mainfrom
test/aws-recommendation-completeness

Conversation

@cristim

@cristim cristim commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

AWS recommendation parsing can reject a malformed detail while returning a successful short menu. Pin the published AWS SDK completeness fix so the existing strict MCP error path rejects incomplete selected and six-combination searches. Valid and genuinely empty results remain successful.

Refs LeanerCloud/cloud-commitments-go#54. The parent issue remains open for the CLI and Platform rollout.

Independent gpt-6-astra review approved exact SHA dee33b0c4900574cd7f97d352b1b9e519ae47ff9 after two source and two index passes. Fresh registered MCP protocol tests passed all eight cases at that SHA using synthetic responses at the SDK HTTP boundary. The same regression fails for all four malformed cases against the parent dependency and a diagnostic-drop mutation; valid/empty controls pass in both probes. This is connected local verification, with no live cloud calls.

Full race tests, build, golangci-lint 2.10.1 and all installed commit hooks passed. Standalone GOWORK=off module selection uses published AWS v0.0.0-20261002152209-006ef5c8d0a2 and pkg v0.0.0-20260929105827-b3b4cb5e3d80, with no replacements. Lint configuration validation could not download its schema in the confined local environment; CI must confirm that check.

Summary by CodeRabbit

  • Chores
    • Updated supporting components used by AWS integrations, logging, and monitoring to newer versions, keeping these integrations aligned with their updated foundations.
  • Tests
    • Expanded checks for AWS recommendation searches with valid, empty, mixed, and invalid responses, verifying that results and errors are handled as expected.

Pin the published AWS completeness diagnostics and verify valid, empty,
mixed, and all-invalid results through the registered MCP tool.

Refs LeanerCloud/cloud-commitments-go#54
@cristim cristim added urgency/this-sprint Within the current sprint triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm impact/many Affects most users effort/m Days type/bug Defect labels Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: LeanerCloud/cloud-commitments-mcp/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: e1ebf82c-3653-4047-af81-0ecd0afc31bb
📥 Commits

Reviewing files that changed from the base of the PR and between dee33b0 and d04d15b.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The change updates Go module dependency declarations and adds protocol tests for AWS RDS recommendation searches. The tests cover selected and unselected scopes and valid, empty, mixed-validity, and all-invalid responses.

Changes

AWS recommendation search

Layer / File(s) Summary
Recommendation search protocol test
tools/search_recommendations_completeness_test.go
The test checks requested scopes. It verifies structured menus for valid and empty responses, and checks that mixed-validity and all-invalid responses return errors with diagnostics and no structured result.

Go module dependencies

Layer / File(s) Summary
Dependency declarations and versions
go.mod
The AWS SDK v2 core dependency is declared directly. go-logr/logr, OpenTelemetry, cloud-commitments, and AWS provider dependencies use updated versions or revisions.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to d04d1

Selected and full-scope AWS recommendation searches now have coverage for malformed, valid, and empty responses, with dependencies pinned to updated releases. No concrete behavior requiring a pre-merge fix is established.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: rejecting incomplete AWS recommendation menus.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

Resolve GO-2026-6505 with the SDK 1.45.0 requirement closure while
preserving the published shared-library and provider pins.
@cristim

cristim commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

Published the reviewed OTEL repair at d04d15bb6fec29e99ee7a3a7d21a5ecdf3b44a4a, preserving all four producer pins and changing only go.mod and go.sum relative to dee33b0.

The earlier independent gpt-6-astra functional review at dee33b0c4900574cd7f97d352b1b9e519ae47ff9 remains recorded in the original PR verification summary. The new independent review covers the two-manifest dependency repair, with two clean staged passes and a clean exact-commit verdict. It does not claim a new static review of the earlier feature.

Independent native macOS Go 1.26.6 verification at d04d15b: the full count=1 race suite passed all three packages; the registered MCP protocol replay passed all eight selected/unselected valid, empty, mixed and all-invalid cases; and the actual ./cmd/cudly-mcp build passed. Synthetic fixtures reject external cloud traffic. No live cloud calls or purchases were made.

govulncheck v1.1.4 source and actual-binary scans both passed against the same frozen advisory database. A fresh clean-parent scan reproduced GO-2026-6505 at SDK 1.44.0 with exit 3; treatment selects SDK 1.45.0. Module verification and tidy no-diff passed, and every resolved external module path is covered by the snapshot. Database manifest SHA256: b159496761b1a95103213d552d3b8314fdfdf672b646b985bf2e283b577aa294.

The command was built with -buildvcs=false and external clean SHA/tree/manifest provenance before and after. Binary SHA256: 840392184a59155416eec09b33b297ee03797346fa3eca587a62d5d0fe357de4. All applicable normal commit hooks passed. Per the authorized independent-review path, no additional CodeRabbit review was requested. Exact-head CI remains required before merge.

@cristim

cristim commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

Final verification at exact head d04d15bb6fec29e99ee7a3a7d21a5ecdf3b44a4a:

  • pre-commit passed.
  • CI - Build & Test passed, including Linux/macOS builds, unit/integration tests, lint and security scanning.
  • Independent gpt-6-astra full-PR supplement approved the actual three-file range b94f5d4c2ee6c4a35aa4b9fcc65a3119a1fa3e39..d04d15bb6fec29e99ee7a3a7d21a5ecdf3b44a4a with no actionable findings across the six review dimensions. It checked the published AWS producer implementation and confirmed the functional/test bytes match the previously reviewed dee33b0.
  • Fresh registered-protocol replay passed all eight cases at the final head. Independent parent-dependency and diagnostic-drop controls each failed all four malformed cases while passing all four valid/empty controls. These connected synthetic-fixture checks made no live cloud calls or purchases.

The repair verification comment records the frozen-database baseline/treatment scans, actual command build provenance, binary hash and two-manifest repair review separately. All local runtime handles and both CI watchers have completed. Fresh PR metadata reports CLEAN and MERGEABLE; merge remains with the coordinating agent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/m Days impact/many Affects most users priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/bug Defect urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant