Skip to content

fix(review): report unknown risk when requested paths are not indexed - #1084

Open
azizur100389 wants to merge 1 commit into
tirth8205:stagingfrom
azizur100389:codex/fix-unmatched-risk
Open

azizur100389 wants to merge 1 commit into
tirth8205:stagingfrom
azizur100389:codex/fix-unmatched-risk

Conversation

@azizur100389

@azizur100389 azizur100389 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Linked issue

Closes #983.

What & why

Mistyped and unindexed file paths currently receive an apparent low-risk all-clear. Return risk=unknown when no requested file matches, expose unmatched_files in both response detail levels, and name misses in a bounded summary. Mixed requests retain the risk measured for the indexed subset. Preserve the old path-resolution wrapper for other callers.

How it was tested

Applied the same regression/affected-module/full-baseline methodology used in my previous PRs (#274, #276, #279, #353 and #354), against unchanged staging 6b12d11625cbec3b6773e076cb3d136464fa90e5.

  • Final regression module: 17 passed. Bugs reproduce on unchanged staging; compatibility guards cover existing behavior.
  • Affected modules: 275 passed. Failure identities are a subset of the unchanged-staging affected baseline (1,169 passed, 15 Windows failures); no new failures.
  • Ruff clean; Bandit zero findings; git diff --check clean.
  • Mypy: the same three pre-existing Windows fcntl LOCK_EX/LOCK_NB/flock errors in daemon.py as staging; no new errors.
  • Schema remains version 13.
python -m pytest tests/test_unmatched_risk.py tests/test_tools.py tests/test_review_risk_budget.py tests/test_uncertainty.py tests/test_pr_review_workflows.py -q --tb=short
$env:GIT_CEILING_DIRECTORIES = $env:TEMP.Replace('\\', '/') + ';' + (Split-Path $PWD).Replace('\\', '/')
python -m pytest -q --tb=short -m 'not browser and not upgrade' --cov=code_review_graph --cov-report=term --cov-fail-under=65
ruff check code_review_graph tests/test_unmatched_risk.py
mypy code_review_graph --ignore-missing-imports --no-strict-optional
bandit -r code_review_graph -c pyproject.toml

GitHub CI: 17 applicable checks passed on the final commit, including Python 3.10–3.13, browser tests, native Windows tests, and the three MCP-client platforms. Python 3.13: 4,285 passed, 804 skipped, 46 deselected, 2 xfailed, 2 xpassed; 85.93% coverage (65% required). The manual upgrade job is skipped by design.

Full local Windows suite: 4,160 passed, 110 failed, 819 skipped, 46 deselected, 2 xfailed, 2 xpassed; 86% coverage. Unchanged staging full baseline: 4,143 passed, 110 failed. Failure identities match unchanged staging; no new failures. An earlier parallel local attempt ended without a final report in the watch tests. This complete rerun used per-test diagnostics and short temporary paths; the earlier partial log is retained. PATH/PYTHONPATH select the isolated checkout, and Git ceilings keep fixture repositories away from the enclosing home Git repository. Browser tests passed in CI; browser and opt-in upgrade tests were excluded locally.

All ten issue fixes were additionally tested together: 283 regression checks passed, and the combined affected suite had 1,142 passed / 25 unchanged-staging Windows failures, with no new failure identities. The tested combination is preserved in this integration branch.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

code-review-graph review

Overall risk: 0.75 (HIGH) — 9 changed function(s)/class(es), 35 affected flow(s), 2 test gap(s) (0 with no tested caller found, 2 reached only through a caller)

Risk-scored changes

Risk Level Symbol Location Tested
0.75 high code_review_graph/tools/query.py::get_impact_radius code_review_graph/tools/query.py:206 yes
0.65 medium code_review_graph/tools/_common.py::_resolve_graph_file_paths code_review_graph/tools/_common.py:232 yes
0.65 medium code_review_graph/tools/_common.py::_unmatched_file_warning code_review_graph/tools/_common.py:291 indirect
0.55 medium code_review_graph/tools/review.py::get_review_context code_review_graph/tools/review.py:427 yes
0.40 medium code_review_graph/tools/_common.py::_resolve_graph_file_paths_with_unmatched code_review_graph/tools/_common.py:239 indirect
0.30 low tests/test_unmatched_risk.py::test_unmatched_path_is_unknown tests/test_unmatched_risk.py:33 (test)
0.30 low tests/test_unmatched_risk.py::test_partial_match_keeps_measured_risk_and_names_miss tests/test_unmatched_risk.py:42 (test)
0.25 low tests/test_unmatched_risk.py::test_compatibility_wrapper_resolves_duplicate_relative_and_absolute_paths tests/test_unmatched_risk.py:48 (test)
0.05 low tests/test_unmatched_risk.py::graph tests/test_unmatched_risk.py:12 (test)

Affected execution flows

  • build_or_update_graph_tool — criticality 0.73, 617 node(s) across 24 file(s)
  • main — criticality 0.72, 923 node(s) across 40 file(s)
  • query_graph_tool — criticality 0.69, 98 node(s) across 11 file(s)
  • semantic_search_nodes_tool — criticality 0.68, 85 node(s) across 13 file(s)
  • benchmark_debug_workflow — criticality 0.68, 147 node(s) across 16 file(s)
  • ...and 30 more affected flow(s)

Reached only through a caller

No test names these directly, but a tested caller reaches them along the call path shown. That is a path in the call graph, not a record of execution -- the caller's tests may never take this branch. Treat it as where to look, not as coverage: these count as gaps and are scored as untested.

  • code_review_graph/tools/_common.py::_resolve_graph_file_paths_with_unmatched (code_review_graph/tools/_common.py:239) — via code_review_graph/tools/_common.py::_resolve_graph_file_paths, 1 hop(s)
  • code_review_graph/tools/_common.py::_unmatched_file_warning (code_review_graph/tools/_common.py:291) — via code_review_graph/tools/query.py::get_impact_radius, 1 hop(s)

Powered by code-review-graph — local-first analysis; no code leaves the CI runner.

@azizur100389
azizur100389 marked this pull request as ready for review October 1, 2026 17:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

get_impact_radius and get_review_context say a change is low risk when the path they were given matches nothing at all

1 participant