What happened?
Running /review <pr> --comment (high effort, worktree mode), the presubmit step's --new-findings flag was given the canonical Step 6 findings artifact (qwen review findings --out …-findings.json), because that is the file the skill's own example writes the anchor list to — the example literally redirects echo '[{"path":…,"line":…}, …]' into .qwen/tmp/qwen-review-{target}-findings.json, the same path convention as the canonicalized findings artifact. The CLI rejected it:
findingsFileInvalid: true
downgradeApprove: true with reason "the --new-findings file was malformed — overlap dedup was disabled and anchor-risk defaulted to at-risk; regenerate it and re-run"
That forced a second presubmit run with a hand-built minimal [{path, line}] file before the downgrade flags were safe to hand to compose-review. Had the first report not been read carefully, the spurious downgradeApprove: true would have leaked into the compose state and capped an otherwise clean verdict.
Observed on PR #9204 at commit 40ad8fd (2026-08-15).
What did you expect to happen?
One of:
- presubmit accepts the findings artifact's shape directly (
file/line, locations[]) and derives the anchors itself — removing a hand-transcription step entirely; or
- the flag keeps the minimal shape, but the skill's example writes to a distinct filename (e.g.
…-new-findings.json) so the two artifacts cannot be confused, and the invalid-file report prints the expected schema so the fix is mechanical.
Client information
Client Information
$ qwen /about
qwen-code v0.21.12 (npm install), glm-5.3
Platform: Linux 6.12.63+deb13-amd64 · Node v22.22.2 · npm 10.9.7
Session: interactive /review skill run, worktree mode, high effort
Login information
N/A — API-key/model-service session.
Anything else we need to know?
The findings artifact already carries everything the overlap check needs (single-location entries have file + line/anchor; aggregates have locations[]). Accepting it would also close the subtle gap where a body-only Critical's file must be manually added to the minimal list for drift anchor-risk to see it — the artifact already names it.
中文
发生了什么?
运行 /review <pr> --comment(high effort、worktree 模式)时,presubmit 步骤的 --new-findings 传入的是 Step 6 的规范化 findings 产物(qwen review findings --out …-findings.json)——因为 skill 自己的示例就是把锚点列表写进这个文件:示例明确将 echo '[{"path":…,"line":…}, …]' 重定向到 .qwen/tmp/qwen-review-{target}-findings.json,与规范化 findings 产物的路径约定同名。CLI 拒绝了它:
findingsFileInvalid: true
downgradeApprove: true,原因 "the --new-findings file was malformed — overlap dedup was disabled and anchor-risk defaulted to at-risk; regenerate it and re-run"
这迫使第二次运行 presubmit(手工构造最小 [{path, line}] 文件)之后降级标志才能安全交给 compose-review。若第一次报告没有被仔细阅读,虚假的 downgradeApprove: true 会漏进 compose state,封顶一个本应干净的裁决。
在 PR #9204(commit 40ad8fd,2026-08-15)观察到。
期望的行为?
以下之一:
- presubmit 直接接受 findings 产物的形状(
file/line、locations[])并自行派生锚点——彻底消灭一次手工转录;或
- 旗标保持最小形状,但 skill 示例改用独立文件名(如
…-new-findings.json),两个产物不再可能混淆,且 invalid 报告打印期望 schema,使修复变成机械操作。
其他
findings 产物已携带 overlap 检查所需的一切(单位置条目有 file + line/anchor;聚合有 locations[])。接受它还能顺带关闭一个细微缺口:body-only Critical 的文件必须被手工加进最小列表,drift 的 anchor-risk 才能看到它——产物本来就已命名它。
What happened?
Running
/review <pr> --comment(high effort, worktree mode), the presubmit step's--new-findingsflag was given the canonical Step 6 findings artifact (qwen review findings --out …-findings.json), because that is the file the skill's own example writes the anchor list to — the example literally redirectsecho '[{"path":…,"line":…}, …]'into.qwen/tmp/qwen-review-{target}-findings.json, the same path convention as the canonicalized findings artifact. The CLI rejected it:findingsFileInvalid: truedowngradeApprove: truewith reason "the --new-findings file was malformed — overlap dedup was disabled and anchor-risk defaulted to at-risk; regenerate it and re-run"That forced a second presubmit run with a hand-built minimal
[{path, line}]file before the downgrade flags were safe to hand to compose-review. Had the first report not been read carefully, the spuriousdowngradeApprove: truewould have leaked into the compose state and capped an otherwise clean verdict.Observed on PR #9204 at commit
40ad8fd(2026-08-15).What did you expect to happen?
One of:
file/line,locations[]) and derives the anchors itself — removing a hand-transcription step entirely; or…-new-findings.json) so the two artifacts cannot be confused, and the invalid-file report prints the expected schema so the fix is mechanical.Client information
Client Information
Login information
N/A — API-key/model-service session.
Anything else we need to know?
The findings artifact already carries everything the overlap check needs (single-location entries have
file+line/anchor; aggregates havelocations[]). Accepting it would also close the subtle gap where a body-only Critical's file must be manually added to the minimal list for drift anchor-risk to see it — the artifact already names it.中文
发生了什么?
运行
/review <pr> --comment(high effort、worktree 模式)时,presubmit 步骤的--new-findings传入的是 Step 6 的规范化 findings 产物(qwen review findings --out …-findings.json)——因为 skill 自己的示例就是把锚点列表写进这个文件:示例明确将echo '[{"path":…,"line":…}, …]'重定向到.qwen/tmp/qwen-review-{target}-findings.json,与规范化 findings 产物的路径约定同名。CLI 拒绝了它:findingsFileInvalid: truedowngradeApprove: true,原因 "the --new-findings file was malformed — overlap dedup was disabled and anchor-risk defaulted to at-risk; regenerate it and re-run"这迫使第二次运行 presubmit(手工构造最小
[{path, line}]文件)之后降级标志才能安全交给 compose-review。若第一次报告没有被仔细阅读,虚假的downgradeApprove: true会漏进 compose state,封顶一个本应干净的裁决。在 PR #9204(commit
40ad8fd,2026-08-15)观察到。期望的行为?
以下之一:
file/line、locations[])并自行派生锚点——彻底消灭一次手工转录;或…-new-findings.json),两个产物不再可能混淆,且 invalid 报告打印期望 schema,使修复变成机械操作。其他
findings 产物已携带 overlap 检查所需的一切(单位置条目有
file+line/anchor;聚合有locations[])。接受它还能顺带关闭一个细微缺口:body-only Critical 的文件必须被手工加进最小列表,drift 的 anchor-risk 才能看到它——产物本来就已命名它。