Skip to content

refactor(compile): reduce complexity of build_canonical_jobs in agentic_pipeline.rs - #2311

Draft
github-actions[bot] wants to merge 1 commit into
mainfrom
refactor/reduce-complexity-build-canonical-jobs-361963d05b4f307f
Draft

github-actions[bot] wants to merge 1 commit into
mainfrom
refactor/reduce-complexity-build-canonical-jobs-361963d05b4f307f

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection results could not be parsed.

Review the workflow run logs for details.

What

Refactors build_canonical_jobs in src/compile/agentic_pipeline.rs, which Clippy flagged with clippy::too_many_lines at 116 lines (threshold 100) — the largest untouched, non-duplicated candidate in the codebase (see Context below).

Why

The function mixed three distinct concerns in one body: assembling the canonical job list (Setup/Agent/Detection/ManualReview/custom jobs), deciding how Stage 3 safe-output execution splits across automatic vs. manual-review-gated variants (tool partitioning, create-pull-request/GitHub-issue-tool bucketing, variant construction), and wiring dependencies/the Conclusion job based on that split. The middle concern — safe-output job shape — was ~45 lines of local state threaded through two downstream call sites, making it hard to read or extend independently of the job-assembly orchestration.

Changes

Extracted the safe-output job-shape logic into a new helper:

  • push_safeoutputs_jobs(jobs, front_matter, cfg, p) — partitions configured safe-output tools into automatic/reviewed buckets (excluding custom tools), decides whether create-pull-request and GitHub-issue tools run in the automatic or reviewed variant, and pushes either a single SafeOutputs job or a split SafeOutputs + SafeOutputs_Reviewed pair. Returns a new SafeOutputsShape { has_reviewed_job, waits_for_review } struct.

build_canonical_jobs now calls this helper once and reads the two booleans it needs (previously two separately-named locals: has_reviewed_safeoutputs_job, safeoutputs_waits_for_review) from the returned struct for the Conclusion-job and dependency-wiring calls that follow.

Behaviour

No behavior change — this is a pure decomposition. Every filter, partition order, and variant-construction argument is preserved exactly.

Verification

  • cargo test --bin ado-aw — all 3406 tests pass (0 failed, 1 ignored), including the 79 compile::agentic_pipeline::tests::* tests covering job graph shape, dependency wiring, and custom-job classification, unmodified.
  • cargo clippy --all-targets --all-features — clean, no warnings.
  • clippy::too_many_lines re-check: build_canonical_jobs no longer appears in the violations list for src/compile/agentic_pipeline.rs (previously 116/100).

Before/after

Before After
build_canonical_jobs 116 lines (flagged) not flagged
New helper (push_safeoutputs_jobs) n/a ~60 lines, single responsibility

Context

Checked for existing/duplicate work first: PRs #2272 (build_agent_job), #2267 (build_safeoutputs_job), and #2243 (check_pipeline) are already open targeting other large functions in this codebase, so this PR picks a different, untouched function. Several closed PRs (#1946, #1895, #1886, #1938) previously targeted create_pull_request.rs::execute_impl (the single largest candidate at 599 lines) but were closed as "stale ... conflicts with the current architecture and was unsafe to transplant" per a maintainer comment — that function was deliberately skipped here.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • spsprodeus21.vssps.visualstudio.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "spsprodeus21.vssps.visualstudio.com"

See Network Configuration for more information.

Generated by Cyclomatic Complexity Reducer · auto · 151 AIC · ⌖ 16.5 AIC · ⊞ 11.1K · ◷

…ic_pipeline.rs

Extracts the Stage 3 safe-output job-shape logic (auto/reviewed tool
partitioning, variant selection, and job pushing) from
build_canonical_jobs into a new push_safeoutputs_jobs helper returning
a small SafeOutputsShape struct. This drops build_canonical_jobs from
116 lines (clippy::too_many_lines, threshold 100) below the flagged
threshold with no behavior change — every branch, filter, and ordering
is preserved verbatim.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Threat detection produced a warning for this pull request output.

These changes need to be scrutinized before merge and only merged after a careful manual review.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants