Skip to content

feat: report invoked tools in project commands - #1650

Merged
Malte Janz (MalteJanz) merged 7 commits into
mainfrom
feat/report-invoked-tools-in-project-commands
Oct 6, 2026
Merged

Malte Janz (MalteJanz) merged 7 commits into
mainfrom
feat/report-invoked-tools-in-project-commands

Conversation

@MalteJanz

@MalteJanz Malte Janz (MalteJanz) commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What changed?

  • Project validate, fix, and format report invoked and skipped tools.
Fixers:
  eslint       skipped  not selected by --only
  rector       invoked
  stylelint    skipped  not selected by --only
  symfony-xml  skipped  not selected by --only
  • Tool selections are checked before setup; unsupported names and empty selections return errors.
  • Added --exclude to project fix and format.
  • Properly invoke the builtin tool on all (non-ignored) extensions in the project validate command, similar to other tools like PHPStan. Previously the tool was silently skipped as it only worked for a single extension validate command.
  • Added debug level logging for all project / extension commands like validate + fix + format, which is only visible with --verbose flag.
    • It prints all the important directories and extensions passed to the tools (which are part of the used ToolConfig)
    • It also prints all command executions inside our tools, e.g. to see how the PHPStan process was created and which arguments it got
    • which makes it easier to troubleshoot what is actually happening / executing and on which source directories

Why?

Align the project commands with their extension counterparts and make tool selection and execution visible.

How was this tested?

  • Built the CLI and checked invalid selections, exclusions, empty selections, and that builtin now works for project validate.
  • Tests passed.

Related issue or discussion

Closes #1502.

Inspired by the extension command changes in #1611 and #1616.

AI disclosure

Part of the change was made by Codex GPT-6.1-Sol

Summary by CodeRabbit

  • New Features
    • Added an --exclude option to project fix and format commands, letting you remove tools from the selected set when used with --only.
    • Fix and format commands now show a status table for tool selection and execution.
  • Bug Fixes
    • Validation checks each configured extension independently, so one extension’s ignore rules don’t hide results for another.
    • Project validation includes eligible local extensions while excluding vendor extensions and configured exclusions.
    • Invalid tool selections are reported before checks, fixes, or formatting begin.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 120b36b6-a918-4e51-bb88-44dd946a28d5
📥 Commits

Reviewing files that changed from the base of the PR and between 5a51425 and 475f25e.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 80100b65-b162-408e-91dd-480a16cf0394
📥 Commits

Reviewing files that changed from the base of the PR and between e6dd2a2 and 5a51425.

📒 Files selected for processing (6)
  • cmd/extension/extension_fix.go
  • cmd/extension/extension_format.go
  • cmd/extension/extension_validate.go
  • cmd/project/project_fix.go
  • cmd/project/project_format.go
  • cmd/project/project_validate.go
🚧 Files skipped from review as they are similar to previous changes (6)
  • cmd/extension/extension_fix.go
  • cmd/project/project_validate.go
  • cmd/extension/extension_format.go
  • cmd/extension/extension_validate.go
  • cmd/project/project_format.go
  • cmd/project/project_fix.go

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Validation commands now check tool selections before execution. Project fix, format, and validation commands support exclusions and report invocation statuses. Verifier configuration stores multiple extensions, and built-in validation checks each configured extension separately.

Changes

Verifier tooling

Layer / File(s) Summary
Configure extensions and project roots
internal/verifier/tool.go, internal/verifier/extension.go, internal/verifier/project.go, internal/verifier/project_test.go, internal/extension/project.go, cmd/extension/extension_validate.go, internal/verifier/symfony_xml.go, internal/verifier/symfony_xml_test.go
ToolConfig stores multiple extensions. Project configuration resolves and filters extension roots. Extension conversion receives context, and Symfony XML conversion reads configured extensions.
Validate configured extensions
internal/verifier/builtin.go, internal/verifier/builtin_test.go, internal/verifier/project_test.go
Built-in validation runs separately for each configured extension, applies per-extension ignores, and rebases result paths. Tests cover ignore scope and project extension selection.
Select tools and report invocation status
cmd/extension/extension_fix.go, cmd/extension/extension_format.go, cmd/extension/extension_validate.go, cmd/project/project_tool_invocation.go, cmd/project/project_fix.go, cmd/project/project_fix_test.go, cmd/project/project_format.go, cmd/project/project_validate.go
Extension and project commands validate selections before execution. Project commands support --exclude and report invocation statuses. Validation generates its report after checks complete and returns the check error before the report error.
Log verifier subprocess commands
internal/verifier/tool.go, internal/verifier/composer.go, internal/verifier/eslint.go, internal/verifier/phpcsfixer.go, internal/verifier/phpstan.go, internal/verifier/prettier.go, internal/verifier/rector.go, internal/verifier/stylelint.go
A shared CommandContext wrapper logs command names and arguments. Verifier commands use the wrapper to create context-aware processes.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant projectValidateCmd
  participant selectProjectTools
  participant VerifierTools
  participant DoCheckReport
  projectValidateCmd->>selectProjectTools: Select tools and build invocation statuses
  selectProjectTools-->>projectValidateCmd: Return selected tools and statuses
  projectValidateCmd->>VerifierTools: Set up tools and run selected checks
  VerifierTools-->>projectValidateCmd: Return check results and run error
  projectValidateCmd->>DoCheckReport: Report filtered results and invocation statuses
Loading

Merge Risk: ⚪ Minimal · up to 5a514

Tool selections now fail clearly when invalid or empty, and valid selections receive invocation reporting. No identified issue blocks merging after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 94d77

The changes preserve the inspected selection, exclusion, credential-handling, and Git-review controls. No introduced security exploit was established. Linked extensions can extend the affected filesystem scope, and verbose-output handling and failure recovery remain important operational considerations.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected authority is that of the invoking CLI process, not a newly introduced remote identity. Scope is not necessarily confined to the project directory: discovered symlink targets, configured source/resource paths, extra bundles, and relative XML imports can reach other accessible filesystem locations. These mechanisms predate the PR, although the XML fixer's eligible plugin set changes.

Trust Boundaries and Controls

  • observed — Project configuration compares resolved extension roots against the resolved vendor root and its descendants before populating Extensions. Per-extension ignores are applied before merging, preventing one extension's ignore rules from filtering another extension's results.
  • observed — Verbose logs newly expose configured paths, extension names, and command arguments without redaction. The CLI installs the standard development logger, suppresses debug output when verbose mode is off, and configures no custom shared sink in the inspected logger setup. External collection and access controls are not established by this source.

Resilience and Maintainability Implications

  • observed — XML conversion plans all files before writing and rejects existing YAML targets. Its unchanged commit protocol then writes YAML and removes XML separately, without rollback or locking; interruption or I/O failure can leave mixed state, and the fixer logs conversion errors while continuing. This is a pre-existing recovery limitation, not an established new security finding.

Hardening Proposals

  • proposed — If verbose output is retained in shared CI logs, apply an explicit access and redaction policy for project paths and arguments. For configuration conversion, consider staged writes and recoverable commit handling before claiming all-or-nothing filesystem behavior.
🚥 Pre-merge checks | ✅ 3 | ❌ 1 | ❓ 1

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 7.14% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 28 functions across 25 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive Issue #1502 asks explicit selections to run or fail clearly, coverage reporting, and coverage in machine-readable output and project upgrade. The PR adds project tool selection checks and statuses; … Evidence is needed from the report format handlers and the project upgrade path to determine whether both expose the coverage statuses.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: reporting which tools project commands invoked or skipped.
Description check ✅ Passed The description covers what changed, why, how it was tested, and the related issue. It also includes a CLI output example.
Out of Scope Changes check ✅ Passed The changes support issue #1502 or the PR's stated tool reporting, selection validation, and debugging goals. The builtin multi-extension changes support project validation coverage. The command-con…
Full details: Linked Issues check

Explanation

Issue #1502 asks explicit selections to run or fail clearly, coverage reporting, and coverage in machine-readable output and project upgrade. The PR adds project tool selection checks and statuses; project validate passes statuses to DoCheckReport, and project fix/format print invocation tables. The change summary also reports extension selection validation and invocation reporting. The builtin validator now handles all configured project extensions. The available evidence does not show whether machine-readable report formats include these statuses or whether project upgrade exposes them. Those requirements remain unresolved.

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread cmd/project/project_validate.go Outdated
@MalteJanz
Malte Janz (MalteJanz) marked this pull request as ready for review October 5, 2026 15:57
@codecov-commenter

Codecov Comments Bot (codecov-commenter) commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 46.66667% with 88 lines in your changes missing coverage. Please review.
✅ Project coverage is 66.03%. Comparing base (5f78808) to head (475f25e).

Files with missing lines Patch % Lines
cmd/extension/extension_validate.go 5.88% 16 Missing ⚠️
cmd/project/project_validate.go 11.11% 16 Missing ⚠️
cmd/project/project_format.go 6.66% 14 Missing ⚠️
cmd/project/project_fix.go 37.50% 10 Missing ⚠️
cmd/extension/extension_fix.go 14.28% 6 Missing ⚠️
cmd/extension/extension_format.go 14.28% 6 Missing ⚠️
cmd/project/project_tool_invocation.go 76.19% 5 Missing ⚠️
internal/verifier/tool.go 75.00% 4 Missing ⚠️
internal/verifier/composer.go 0.00% 2 Missing ⚠️
internal/verifier/eslint.go 0.00% 2 Missing ⚠️
... and 6 more
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1650      +/-   ##
==========================================
+ Coverage   66.00%   66.03%   +0.03%     
==========================================
  Files         463      464       +1     
  Lines       31111    31176      +65     
==========================================
+ Hits        20534    20587      +53     
- Misses      10577    10589      +12     
Flag Coverage Δ
go-test 66.03% <46.66%> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread cmd/project/project_fix.go
Comment thread cmd/project/project_fix.go Outdated
Comment thread cmd/project/project_fix.go
Comment thread cmd/project/project_format.go
Comment thread cmd/extension/extension_fix.go Outdated
Comment thread cmd/extension/extension_fix.go
@MalteJanz
Malte Janz (MalteJanz) merged commit f20f5ba into main Oct 6, 2026
7 checks passed
@MalteJanz
Malte Janz (MalteJanz) deleted the feat/report-invoked-tools-in-project-commands branch October 6, 2026 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validation tells developers what actually ran

4 participants