Skip to content

🐛 The review job cannot load its Plugin: a compiled binary resolves --plugin against its own image #832

Description

@taras

The review job has failed on every pull request since 2026-09-15. It is reproducible, not intermittent: the compiled binary cannot load the Plugin the workflow asks it for.

The failure

.github/workflows/review.yml runs:

./dist/xmd run .reviews/ReviewPR.md \
  --plugin ./packages/code-review-agent/mod.ts \
  -j .reviews/journal.jsonl \
  --verbose

and the run reports:

Module not found: file:///tmp/deno-compile-xmd/packages/code-review-agent/mod.ts at ext:core/01_core.js:404:7
##[error]Process completed with exit code 1.

dist/xmd is a deno compile binary. It resolves a relative specifier against its own embedded virtual root — /tmp/deno-compile-xmd/ — rather than against the working directory, so ./packages/code-review-agent/mod.ts names a path inside the binary's image where nothing exists. The checkout's copy is never consulted.

The step's own output is otherwise complete: the job reaches the review document, prints the PR diff and an oxlint report, and then exits 1 on the missing module.

When it started

The last green run was agent/issue-818-plugins at 2026-09-15T03:00:45Z. The next run of the same branch, at 03:58:19Z, failed, and all 16 runs since have failed across 6 branches:

Conclusion Runs Branches
success 8 agent/issue-83-trusted-review, agent/issue-811-terminology, agent/issue-818-plugins
failure 16 (consecutive) agent/issue-818-plugins, agent/755-root-codex-launch, agent/dec-016-withdraw-terminal-grid, agent/issue-443-source-bundle, agent/issue-828-session-configuration, agent/issue-822-git-plugin

The onset window falls inside #818, which introduced --plugin. The likely change is the review workflow moving to --plugin against the compiled binary — a combination that cannot resolve an on-disk module.

Why it has stayed invisible

review is not among the green aggregate's needs in .github/workflows/ci.yml, so a PR can show every required check green with this job red. It has been red for a week on every branch, including agent/issue-443-source-bundle, which merged as c00fa822.

What would fix it

Some way for the compiled binary to be handed a Plugin that is not embedded in it, or for this job to stop using the compiled binary:

  • run the review through the Deno source entrypoint (deno run … packages/cli/src/deno.ts), where a relative --plugin resolves against the checkout; or
  • embed the code-review-agent Plugin in the compiled binary and select it by a reserved name, the way git is selected; or
  • give --plugin an explicit way to name a filesystem path that a compiled binary resolves against the working directory.

The first is the smallest and restores the job's previous behavior. The third is the real gap, since --plugin <path> silently means something different depending on which build is running it.

Not a flake

Every run since onset has failed the same way, and the cause is a resolution rule rather than timing or resources. It is separate from #830, which is a genuine intermittent abort in a different job.

Found while delivering #822; it is unrelated to that work and predates the branch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions