From 23483a773d2eaee030fee5a66fdb684a1d32736c Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 6 Aug 2026 15:35:12 -0500 Subject: [PATCH] fix(tools/git): issue-close.sh silently dropped the closing comment `tea issue comment` is not a subcommand -- tea 0.11.x exposes only list/create/edit/reopen/close under `tea issue`, and comments are the top-level `tea comment`. The call therefore always failed. Its result was never checked, so the script went on to `tea issue close`, which IS valid: the issue closed and the record of why it closed was silently lost. Route the comment through the existing gitea_issue_comment_api() helper on both branches. It is login-independent and was already the mechanism used by the no-login fallback. Both call sites now fail closed: if the comment cannot be posted, the issue is not closed. Verified behaviourally against the live provider, both directions: negative -- comment cannot post => "NOT closing (fail closed)", exit 1, issue left open positive -- comment posts and issue closes => state=closed, comments=1, exit 0 Refs #1081 Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Amf1Neca162odgcbCWMk1y --- .../mosaic/framework/tools/git/issue-close.sh | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/packages/mosaic/framework/tools/git/issue-close.sh b/packages/mosaic/framework/tools/git/issue-close.sh index 646c8b09..05788e6d 100755 --- a/packages/mosaic/framework/tools/git/issue-close.sh +++ b/packages/mosaic/framework/tools/git/issue-close.sh @@ -91,13 +91,27 @@ elif [[ "$PLATFORM" == "gitea" ]]; then GITEA_LOGIN_NAME=$(get_gitea_login || true) if [[ -n "$GITEA_LOGIN_NAME" ]]; then if [[ -n "$COMMENT" ]]; then - tea issue comment "$ISSUE_NUMBER" "$COMMENT" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME" + # `tea issue comment` is NOT a subcommand (tea 0.11.x lists only + # list/create/edit/reopen/close); comments are the top-level `tea comment`. + # The call therefore always failed, was unchecked, and the script proceeded + # to close the issue anyway -- losing the record of WHY it was closed. + # Route through the authenticated API helper: it is login-independent and is + # already the mechanism used by the no-login branch below. + gitea_issue_comment_api || { + echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2 + exit 1 + } fi tea issue close "$ISSUE_NUMBER" --repo "$OWNER/$REPO" --login "$GITEA_LOGIN_NAME" else echo "No tea login configured for $(get_remote_host); using authenticated Gitea API fallback." >&2 if [[ -n "$COMMENT" ]]; then - gitea_issue_comment_api + # Fail closed here too: an unchecked comment lets the issue close without its + # audit trail, which is the same defect as the tea path above. + gitea_issue_comment_api || { + echo "Error: failed to post comment on #$ISSUE_NUMBER -- NOT closing (fail closed)." >&2 + exit 1 + } fi gitea_issue_close_api fi