Skip to content

Extract hardcoded file paths to named constants - #39938

Merged
pelikhan merged 4 commits into
mainfrom
copilot/lint-monster-extract-hardcoded-paths
Jun 18, 2026
Merged

Extract hardcoded file paths to named constants#39938
pelikhan merged 4 commits into
mainfrom
copilot/lint-monster-extract-hardcoded-paths

Conversation

CopilotAI commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

120 hardcoded file path literals were scattered across 55 files, creating maintenance risk and making path configuration opaque. This PR centralizes all path definitions as named constants.

New constants (pkg/constants/constants.go)

~40 constants added in four logical groups:

  • Repository dirs: GithubDir, WorkflowsDir, WorkflowsDirSlash, AgentsDir, WorkflowsLockYmlGlob, WorkflowsLockYmlGitAttributesEntry
  • Runtime temp paths (/tmp/gh-aw/…): TmpGhAwDirSlash, TmpGhAwAgentDir, AwPromptsFile, TmpMcpServersJsonPath, TmpProxyLogsDir, TmpProxyTLSDir, TmpProxyTLSCACert, TmpRepoMemoryDir, ThreatDetectionLogPath, etc.
  • Shell/Actions expression forms (${RUNNER_TEMP}/…, ${{ runner.temp }}/…): GhAwRootDirShellSlash, ShellMcpServersJsonPath, McpServersJsonPathExpr, CodexMcpConfigTomlPath, etc.
  • System paths: CopilotBinaryPath, BashCompletionDir, BashCompletionGhAwPath, HomebrewPrefix, UsrLocalPrefix

Two workflow-scoped constants added to pkg/workflow/setup_action_paths.go: SafeJobsDownloadDirExpr, SafeOutputsUploadArtifactsDir.

Bug fix (compiler_difc_proxy.go)

The exclusion glob for the proxy TLS directory was using broken runtime string slicing. Fixed using the new TmpProxyTLSDir constant:

// Before (broken)"!/"+constants.TmpProxyTLSCACert[1:len(constants.TmpProxyTLSCACert)-len("ca.crt")]
// After"!"+constants.TmpProxyTLSDir

Replacements

All hardcoded literals replaced with constant references across:

  • pkg/workflow/ — 30+ files
  • pkg/parser/remote_fetch.go, mcp.go, include_expander.go, import_field_extractor.go
  • pkg/cli/shell_completion.go, git.go, logs_run_processor.go, includes.go, trial_repository.go, mcp_tools_privileged.go

Files that didn't previously import pkg/constants had the import added.

Linter self-reference

pkg/linters/hardcodedfilepath/hardcodedfilepath.go defines the canonical path prefixes it detects. Those definitions are now annotated //nolint:hardcodedfilepath since they are the pattern source, not path usage. A log message string in git.go containing .github/aw/logs/.gitignore (not a real path) gets the same treatment.


\npr-sous-chef requested a branch update during run https://github.com/github/gh-aw/actions/runs/27735451041

Generated by 👨‍🍳 PR Sous Chef ·


Changeset\n\n- Type: patch\n- Description: Centralized hardcoded file paths into named constants and fixed a proxy TLS directory exclusion bug.

Generated by 📋 Changeset Generator for issue #39938 ·



✨ PR Review Safe Output Test - Run 27737100396

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude ·

CopilotAIand others added 2 commits June 18, 2026 01:11
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
CopilotAI changed the title [WIP] Extract hardcoded file paths to named constantsExtract hardcoded file paths to named constantsJun 18, 2026
CopilotAI requested a review from pelikhanJune 18, 2026 01:26
@pelikhan
pelikhan marked this pull request as ready for review June 18, 2026 01:35
CopilotAI review requested due to automatic review settings June 18, 2026 01:35

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR centralizes previously hardcoded filesystem/workspace path literals into named constants (primarily in pkg/constants/constants.go) and updates workflow/compiler/parser/CLI code to reference those constants, including a small DIFC proxy log exclusion fix.

Changes:

  • Added grouped path constants for repo-relative dirs, /tmp/gh-aw runtime layout, shell/env/action-expression forms, and a few system paths.
  • Replaced hardcoded path literals across workflow compilation/rendering, parser path handling, and CLI utilities with constant references.
  • Fixed DIFC proxy log artifact exclusion construction by using a dedicated proxy TLS directory constant rather than runtime string slicing.
Show a summary per file
FileDescription
pkg/workflow/threat_detection.goUses centralized threat detection log path constant.
pkg/workflow/step_order_validation.goReplaces hardcoded temp/path prefixes with constants for redaction scanning rules.
pkg/workflow/setup_action_paths.goAdds workflow-scoped constants for safe-jobs and upload-artifacts staging paths.
pkg/workflow/safe_outputs_steps.goUses temp dir constant for artifact download path.
pkg/workflow/safe_outputs_config_generation.goUses repo-memory temp dir constant when generating config paths.
pkg/workflow/safe_jobs.goUses new safe-jobs download constants for expression-based paths.
pkg/workflow/runtime_import_validation.goUses .github/ prefix constant for normalization logic.
pkg/workflow/repo_memory.goUses repo-memory temp dir constant for memory directories/artifact paths.
pkg/workflow/pi_engine.goUses constants for prompt and Pi agent dir paths.
pkg/workflow/opencode_mcp.goUses constant for MCP servers JSON config path.
pkg/workflow/mcp_renderer_builtin.goUses GhAwBinaryPath constant for release-mode entrypoint.
pkg/workflow/mcp_environment.goUses constant for Codex MCP config directory path.
pkg/workflow/mcp_config_playwright_renderer.goUses constant for Playwright MCP logs output dir.
pkg/workflow/gemini_mcp.goUses constant for MCP servers JSON config path (shell form).
pkg/workflow/gemini_logs.goUses constant for agent stdio log path.
pkg/workflow/gemini_engine.goUses constants for prompt path and Gemini error glob.
pkg/workflow/frontmatter_extraction_metadata.goUses .github/ prefix constant for source URL construction.
pkg/workflow/engine_output.goUses temp dir prefix constant when filtering output files.
pkg/workflow/crush_mcp.goUses constant for MCP servers JSON config path.
pkg/workflow/crush_engine.goUses constant for prompt file path.
pkg/workflow/copilot_logs.goUses constant for sandbox agent logs directory.
pkg/workflow/copilot_engine.goUses .github/ prefix constant for manifest path prefixes.
pkg/workflow/copilot_engine_execution.goUses constants for temp dirs, prompt path, and Copilot binary path.
pkg/workflow/compiler_yaml.goUses .github/ prefix constant in path normalization / workspace root resolution.
pkg/workflow/compiler_yaml_main_job.goUses constants for prompt/log paths and artifact collection globs/dirs.
pkg/workflow/compiler_safe_outputs_job.goUses temp dir constant for patch artifact download paths.
pkg/workflow/compiler_main_job.goUses constant for safe-outputs MCP log dir env var.
pkg/workflow/compiler_difc_proxy.goUses constants for proxy TLS CA path and fixes log exclusion glob building.
pkg/workflow/codex_mcp.goUses constant for MCP servers JSON config path (shell form).
pkg/workflow/codex_engine.goUses constants for MCP config/log dirs and prompt/TOML paths.
pkg/workflow/claude_mcp.goUses constant for MCP servers JSON config path (shell form).
pkg/workflow/claude_engine.goUses constant for MCP servers JSON Actions-expression path.
pkg/workflow/awf_helpers.goUses constants for RUNNER_TEMP gh-aw root and DIFC proxy CA cert path.
pkg/workflow/antigravity_mcp.goUses constant for MCP servers JSON config path (shell form).
pkg/workflow/antigravity_logs.goUses constant for agent stdio log path.
pkg/workflow/antigravity_engine.goUses constants for prompt path and Antigravity error glob.
pkg/workflow/agentic_engine.goUses constant for default agent stdio log path.
pkg/parser/remote_fetch.goUses constants for workflows/agents dir detection and .github/ prefix checks.
pkg/parser/mcp.goUses constant for Playwright MCP logs docker volume mount spec.
pkg/parser/include_expander.goUses .github/ prefix constant when resolving imports.
pkg/parser/import_field_extractor.goUses .github/ prefix constant when computing import-relative paths.
pkg/linters/hardcodedfilepath/hardcodedfilepath.goAdds //nolint:hardcodedfilepath annotations to linter’s own canonical prefixes.
pkg/constants/constants.goAdds grouped path constants and updates GetWorkflowDir() to return WorkflowsDir.
pkg/cli/trial_repository.goUses workflows dir constant for trial compilation markdown path.
pkg/cli/shell_completion.goUses constants for Homebrew prefixes and bash completion paths.
pkg/cli/mcp_tools_privileged.goUses constant for MCP logs output directory in privileged tools.
pkg/cli/logs_run_processor.goUses workflows dir constant when inferring lockfile paths.
pkg/cli/includes.goUses .github/ prefix constant when resolving shared includes.
pkg/cli/git.goUses workflow dir/gitattributes constants and adds a nolint on a log string.
actions/setup-cli/install.shAdjusts header comment related to script sync/copy instructions.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 50/50 changed files
  • Comments generated: 1

Comment threadactions/setup-cli/install.sh Outdated
set +o histexpand

# Kept in sync with install-gh-aw.sh — edit that file, then copy to this path.
# Kept in sync with actions/setup-cli/install.sh — edit this file, then copy to that path.
@github-actions

Copy link
Copy Markdown
Contributor

\nPlease summarize the remaining blockers after the review note is addressed.

Generated by 👨‍🍳 PR Sous Chef ·

@github-actions

Copy link
Copy Markdown
Contributor

\n@copilot review all comments and address the unresolved review note, then rebase/push an update.

Generated by 👨‍🍳 PR Sous Chef ·

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot merge main and recompile

…extract-hardcoded-paths
# Conflicts:
#	actions/setup-cli/install.sh
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Jun 18, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot merge main and recompile

Done — merged origin/main into the branch (21318e4) and recompiled. The only conflict was in actions/setup-cli/install.sh (the sync comment), which I resolved using main's correct version (matching the reviewer's feedback). All checks pass.

@github-actions

github-actionsBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

@github-actions

github-actionsBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke GeminiMISSION COMPLETE! Gemini has spoken. ✨

@github-actions

github-actionsBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

🎬 THE ENDSmoke ClaudeMISSION: ACCOMPLISHED! The hero saves the day! ✨

@github-actions

github-actionsBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke AntigravityMISSION COMPLETE! Antigravity has spoken. ✨

@github-actions

github-actionsBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke PiMISSION COMPLETE! Pi delivered. 🥧

@github-actions

github-actionsBot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot - AOAI (apikey) is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot - AOAI (Entra) is now investigating this pull request. Sources say the story is developing...

@pelikhan
pelikhan merged commit 742d36c into mainJun 18, 2026
168 checks passed
@pelikhan
pelikhan deleted the copilot/lint-monster-extract-hardcoded-paths branch June 18, 2026 04:42
@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results

  • GitHub Reads: ✅
  • Web Fetch: ✅
  • File Writing: ✅
  • Bash Verification: ✅
  • Build gh-aw: ❌

Overall Status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "localhost"

See Network Configuration for more information.

Smoke Gemini — Powered by Gemini ·

@github-actions

Copy link
Copy Markdown
Contributor

Agent Container Tool Check

ToolStatusVersion
bash5.2.21
shavailable
git2.54.0
jq1.7
yq4.53.3
curl8.5.0
gh2.94.0
node22.22.3
python33.11.15 (PyPy 7.3.23)
go1.24.13
java21.0.11
dotnet10.0.301

Result: 12/12 tools available ✅

Overall Status: PASS

🔧 Tool validation by Agent Container Smoke Test ·

@github-actions

Copy link
Copy Markdown
Contributor

💥 Smoke Test: Claude — Run 27737100396

Core #1-12: all ✅
PR Review #13-18: all ✅ | #19⚠️ skipped

Overall: PARTIAL (1 skipped)

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude ·

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude

Comment threadpkg/cli/git.go
// Find git root and add .github/workflows relative to it
if gitRoot, err := gitutil.FindGitRoot(); err == nil {
workflowsPath := filepath.Join(gitRoot, ".github/workflows/")
workflowsPath := filepath.Join(gitRoot, constants.WorkflowsDirSlash)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice — extracting .github/workflows/ into constants.WorkflowsDirSlash improves consistency.

Comment threadpkg/cli/git.go

gitAttributesPath := filepath.Join(gitRoot, ".gitattributes")
lockYmlEntry := ".github/workflows/*.lock.yml linguist-generated=true merge=ours"
lockYmlEntry := constants.WorkflowsLockYmlGitAttributesEntry

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good use of constants.WorkflowsLockYmlGitAttributesEntry for the gitattributes entry.

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Copilot: Extract hardcoded file paths to named constants
1 ❌ GitHub MCP, 2 ✅ mcpscripts, 3 ✅ Serena, 4 ✅ Playwright, 5 ❌ web fetch tool
6 ✅ file/bash, 7 ✅ discussion, 8 ✅ build, 9 ✅ artifact, 10 ✅ discussion create
11 ✅ dispatch, 12 ✅ review tools, 13 ✅ comment memory, 14 ✅ README sub-agent, 15 ✅ check run
Overall: FAIL
Author: @app/copilot-swe-agent
Assignees: @pelikhan@Copilot

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot ·

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test: FAIL
PRs:

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex ·

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Silent build hums on
GitHub pages shimmer awake
Tests drift into green

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex ·

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Stone tests beat all night
Small bots stack sparks into dawn
Green smoke crowns the run

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot ·

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke Copilot review: tool paths, build, and safe outputs all exercised.

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test results:\n✅ Test1 ❌ Test2 ❌ Test3 ✅ Test4 ✅ Test5 ✅ Test6 ❌ Test7 ✅ Test8\nOverall: FAIL\n\ncc: @app/copilot-swe-agent, @pelikhan, @Copilot

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot - AOAI (Entra) ·

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pelikhan