Skip to content

Extract shared base for access and firewall log summaries - #46079

Merged
pelikhan merged 3 commits into
mainfrom
copilot/deep-report-extract-shared-base
Jul 17, 2026
Merged

Extract shared base for access and firewall log summaries#46079
pelikhan merged 3 commits into
mainfrom
copilot/deep-report-extract-shared-base

Conversation

CopilotAI commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

pkg/cli/logs_report_firewall.go had two near-duplicate summary structs that carried the same request/domain aggregate fields with inconsistent counter names. This refactor consolidates the shared shape into one embedded base and aligns access-log summary counters with the firewall summary.

  • Shared summary base

    • Introduces FirewallSummaryBase for:
      • TotalRequests
      • AllowedRequests
      • BlockedRequests
      • AllowedDomains
      • BlockedDomains
    • Embeds the base in both AccessLogSummary and FirewallLogSummary
  • Counter name alignment

    • Renames access summary counters from AllowedCount / BlockedCount to AllowedRequests / BlockedRequests
    • Keeps firewall-specific data (RequestsByDomain) only on FirewallLogSummary
    • Keeps per-workflow payloads specific to each summary type
  • Construction updates

    • Updates both summary builders to populate the embedded base from the shared aggregation helper instead of duplicating field assignment
  • Focused coverage

    • Updates access-summary expectations to use the aligned field names
    • Adds a JSON serialization check to confirm embedded fields stay flattened and emit allowed_requests / blocked_requests
typeFirewallSummaryBasestruct {
TotalRequestsint`json:"total_requests"`AllowedRequestsint`json:"allowed_requests"`BlockedRequestsint`json:"blocked_requests"`AllowedDomains []string`json:"allowed_domains"`BlockedDomains []string`json:"blocked_domains"`
}
typeAccessLogSummarystruct {
FirewallSummaryBaseByWorkflowmap[string]*DomainAnalysis`json:"by_workflow,omitempty"`
}

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
CopilotAI changed the title [WIP] Refactor AccessLogSummary and FirewallLogSummary into shared baseExtract shared base for access and firewall log summariesJul 16, 2026
CopilotAI requested a review from pelikhanJuly 16, 2026 20:00
@pelikhan
pelikhan marked this pull request as ready for review July 16, 2026 21:12
CopilotAI review requested due to automatic review settings July 16, 2026 21:12

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Consolidates shared access and firewall summary fields while aligning counter names.

Changes:

  • Adds the embedded FirewallSummaryBase.
  • Renames access counters and verifies flattened JSON serialization.
  • Updates both summary builders to initialize the shared base.
Show a summary per file
FileDescription
pkg/cli/logs_report_firewall.goDefines and populates the shared summary base.
pkg/cli/logs_report_test.goUpdates assertions and tests JSON field names.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Medium

@github-actions

This comment has been minimized.

@github-actions

Copy link
Copy Markdown
Contributor

Hey @copilot-swe-agent -- great work refactoring the duplicate summary structs in pkg/cli/logs_report_firewall.go! Introducing FirewallSummaryBase as a shared embedded base and aligning the counter names is a clean improvement. The PR is focused, well-described, and includes test coverage. Looks ready for review!

Generated by ✅ Contribution Check · 155.6 AIC · ⌖ 8.97 AIC · ⊞ 6.2K ·

@pelikhan

Copy link
Copy Markdown
Collaborator

/matt

@pelikhan

Copy link
Copy Markdown
Collaborator

/review

@github-actions

github-actionsBot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

@github-actions

github-actionsBot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

PR Code Quality Reviewer completed the code quality review.

@github-actions

Copy link
Copy Markdown
Contributor

🧪 Test Quality Sentinel Report

Test Quality Score: 88/100 — Excellent

Analyzed 5 test(s): 5 design, 0 implementation, 0 violation(s).

📊 Metrics (5 tests)
MetricValue
Analyzed5 (Go: 5, JS: 0)
✅ Design5 (100%)
⚠️ Implementation0 (0%)
Edge/error coverage3 (60%)
Duplicate clusters0
InflationNo (1.48:1)
🚨 Violations0
TestFileClassificationIssues
TestAggregateDomainStatslogs_report_test.go:504design_test / high_valueNone
TestConvertDomainsToSortedSliceslogs_report_test.go:627design_test / high_valueNone
TestBuildAccessLogSummaryWithSharedHelperlogs_report_test.go:683design_test / high_valueNone
TestAccessLogSummaryJSONUsesEmbeddedBaseFieldslogs_report_test.go:752design_test / high_valueNone
TestBuildFirewallLogSummaryWithSharedHelperlogs_report_test.go:788design_test / high_valueNone

Verdict

Passed. 0% implementation tests (threshold: 30%). All 5 new tests are behavioral contract tests covering the refactored shared aggregateDomainStats helper. Build tag present (//go:build !integration). No mock violations. Test inflation ratio 1.48:1 (below 2:1 threshold).

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "awmgmcpg"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel · 34.3 AIC · ⌖ 10.2 AIC · ⊞ 6.8K ·
Comment /review to run again

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Test Quality Sentinel: 88/100. 0% implementation tests (threshold: 30%). All 5 new tests cover behavioral contracts of the refactored shared aggregation helper.

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /tdd and /codebase-design — one minor suggestion on test coverage symmetry.

📋 Key Themes & Highlights

Key Themes

  • Good deduplication: FirewallSummaryBase cleanly eliminates the duplicate struct fields and aligns counter names across both summary types.
  • Test coverage gap: TestAccessLogSummaryJSONUsesEmbeddedBaseFields covers only AccessLogSummary JSON serialization; FirewallLogSummary lacks a parallel test for the same embedded fields.

Positive Highlights

  • FirewallSummaryBase embedding is the right abstraction — single source of truth for shared fields.
  • ✅ Counter name alignment (AllowedRequests / BlockedRequests) improves consistency across the API surface.
  • ✅ JSON serialization test correctly asserts that legacy field names are absent from the output.
  • ✅ Constructor functions cleanly populate the base literal rather than scattering assignments.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · 19.6 AIC · ⌖ 4.57 AIC · ⊞ 6.7K
Comment /matt to run again

github-actions[bot]
github-actionsBot previously requested changes Jul 16, 2026

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two issues require attention before merging

The refactor cleanly eliminates duplication, but has a breaking wire-format change and a naming problem.

1. Silent breaking JSON rename (high) — AccessLogSummary previously serialized AllowedCount as allowed_count and BlockedCount as blocked_count. After this PR those keys become allowed_requests and blocked_requests. Any consumer parsing the old keys will silently see zeros. No migration path or deprecation notice is provided.

2. Misleading shared-base name (medium) — FirewallSummaryBase is now embedded in AccessLogSummary, which is not a firewall type. The name implies firewall ownership. Rename to something neutral like RequestSummaryBase.

🔎 Code quality review by PR Code Quality Reviewer · 56.2 AIC · ⌖ 4.61 AIC · ⊞ 5.6K
Comment /review to run again

@github-actions

Copy link
Copy Markdown
Contributor

🤖 PR Triage

FieldValue
Categoryrefactor
Risk🟢 Low
Score43/100
Actionauto_merge

Score breakdown: Impact 18 + Urgency 10 + Quality 15

Rationale: Consolidates near-duplicate structs in pkg/cli/logs_report_firewall.go into a shared base. No behavior change. CI passes (30 checks, all green). Safe to auto-merge.

Run §29545908133

Generated by 🔧 PR Triage Agent · 181.7 AIC · ⌖ 5.04 AIC · ⊞ 5.6K ·

@pelikhan
pelikhan merged commit 295c718 into mainJul 17, 2026
56 of 58 checks passed
@pelikhan
pelikhan deleted the copilot/deep-report-extract-shared-base branch July 17, 2026 02:41
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.82.12

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deep-report] [Code Quality] Extract shared base for AccessLogSummary/FirewallLogSummary in logs_report_firewall.go

3 participants

@pelikhan