Repository navigation
Final beta-readiness pass: enable publication, Gemini-safe rate limiting, CI stabilization - #64
Merged
Merged
Conversation
…ling Production evidence: PatchFrog's own specialist-role fan-out and bounded retries can exceed Gemini's free-tier per-minute quota on their own, with no external traffic. Adds an opt-in, process-wide sliding-window requests-per-minute limiter (patchfrog/review/rate_limiter.py) wrapping real provider construction in both the production (routing/router.py) and CLI (review/provider_factory.py) paths, gated by a new operator-only PATCHFROG_PROVIDER_RATE_LIMIT_RPM setting (unset = unthrottled, unchanged default). Also teaches call_with_retry to honor a provider-reported retry-after hint (Gemini's RetryInfo.retryDelay, Anthropic/OpenAI's Retry-After header) instead of blind exponential backoff, capped so one delay can't consume a whole run's elapsed-time budget. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
No .patchfrog.yml existed in this repo, so publish.enabled fell back to its safe-by-default False (patchfrog/publishing/config.py) -- production logged review_publish_disabled_by_config on every run. Adds .patchfrog.yml with publish.enabled: true and nothing else (no other publication control weakened). Closes the one gap found while auditing GitHub-publication test coverage: nothing previously exercised PUBLISH mode with publication disabled by config and asserted the explicit SKIPPED_DISABLED outcome (never a silent success) against a fake GitHub publisher. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
CI run 35781841389 failed at "Verify required static analyzers": `semgrep --version` crashed with ModuleNotFoundError: pkg_resources. Newer semgrep releases pin mcp==1.29.0. Once mcp 1.30.0 was published, pip kept the newest mcp allowed by our own `mcp>=1.29,<2.0` and backtracked semgrep from 1.177.0 to 1.136.0, the last pre-mcp release. That release depends on opentelemetry-instrumentation 0.46b0, which imports pkg_resources; setuptools 84 (pulled in via `setuptools>=16`) no longer ships it (removed in 82). The Docker images install the same dependency set, so the runtime semgrep analyzer was broken there too. Raise the semgrep floor to 1.173 (opentelemetry 0.58b0, no pkg_resources) so the resolver can no longer select the broken line. The analyzer verification step is unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Final beta-readiness pass before AA, covering four goals:
.patchfrog.ymlwithpublish.enabled: true-- this repo had no config at all, sopublish.enabledfell back to its safe-by-defaultFalseand every run loggedreview_publish_disabled_by_config.patchfrog/review/rate_limiter.py-- an opt-in, process-wide sliding-window requests-per-minute limiter wrapping real provider construction (production and CLI paths), gated by a newPATCHFROG_PROVIDER_RATE_LIMIT_RPMoperator setting (unset = unthrottled, today's behavior unchanged).call_with_retrynow honors a provider-reported retry-after hint (Gemini'sRetryInfo.retryDelay, Anthropic/OpenAI'sRetry-Afterheader) instead of blind exponential backoff, capped at 65s.mypy --strict, Alembic single-head migration against a real Postgres, full pytest suite, both Docker image builds, Celery task registration, oracle-provider eval sanity) -- all green, 2523 tests passed, 0 skipped, 0 real product regressions found. One local-only false-failure mode diagnosed and documented (a developer's own.envleaking real provider keys intoSettings()viaenv_file=".env", defeating "credential absent" test assumptions -- never reproducible in CI, which has no.env).publish.enabled=falseinPUBLISHmode produces an explicitSKIPPED_DISABLEDresult rather than a silent no-op.Full audit, findings, and scope notes:
validation/final_beta_readiness/latest-summary.md.patchfrog-cloudwas not touched -- every change here is review-behavior config or engine code that determines how PatchFrog reviews code, not hosted-SaaS lifecycle.Test plan
ruff check .cleanmypy . --strictclean (663 source files)alembic upgrade headagainst real Postgres;alembic headsshows exactly one headpytest -q-- 2523 passed, 0 skipped, 0 failedapi,worker) build cleanpublish.enabled=falseinPUBLISHmode is an explicit skip, never a silent successNot merging automatically -- awaiting review per project workflow.
🤖 Generated with Claude Code