Skip to content

[aw] Ponytail Reviewer had a request rejected #67458

Description

@github-actions

Workflow Failure

Workflow: Ponytail Reviewer
Branch: copilot/add-yaml-json-schemas
Run: https://github.com/github/gh-aw/actions/runs/38062199481
Pull Request: #67439

Warning

Task Could Not Be Completed: The workflow recorded a report_incomplete signal: the task was not completed or completion could not be confirmed. See the reported reason and diagnostics below.

Error details:
invalid_safe_outputs
Agent finished without emitting a terminal safe output; task completion could not be confirmed.
safeoutputs MCP gateway registered 0 tools during setup; the agent could not emit any safe outputs. This is a gateway infrastructure failure, not a normal no-op. Check the MCP gateway startup logs for ECONNRESET errors or delayed backend registration and re-run the workflow.
bash: /bin/bash -lc 'safeoutputs noop --help': /bin/bash: line 1: safeoutputs: command not found

bash: /bin/bash -lc "safeoutputs noop '{\"message\":\"Lean already. Ship.\"}'": /bin/bash: line 1: safeoutputs: command not found

Driver exit code: 0
Failure classification: request_rejection
Retry attempts observed: 0

This is a structured incompletion signal (report_incomplete), not confirmation of a completed task. Do not treat accompanying safe outputs (e.g., comments) as evidence that the requested review or action was completed.

Action Required

Assign this issue to an agent to debug and fix the issue.

Debug with any coding agent

Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):

Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md

The failed workflow run is at https://github.com/github/gh-aw/actions/runs/38062199481
Manually invoke the agent

Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.

Tip

Stop reporting this workflow as a failure

To stop a workflow from creating failure issues, set report-failure-as-issue: false in its frontmatter:

safe-outputs:
  report-failure-as-issue: false

Generated from Ponytail Reviewer · codex · 17.2 AIC · ◷

  • expires on Oct 11, 2026, 3:12 AM UTC

Activity

  1. github-actions commented on Oct 10, 2026

    @github-actions
    ContributorAuthor

    Agent job 38073742082 failed.

    Warning

    Task Could Not Be Completed: The workflow recorded a report_incomplete signal: the task was not completed or completion could not be confirmed. See the reported reason and diagnostics below.

    Error details:
    invalid_safe_outputs
    Agent finished without emitting a terminal safe output; task completion could not be confirmed.
    safeoutputs MCP gateway registered 0 tools during setup; the agent could not emit any safe outputs. This is a gateway infrastructure failure, not a normal no-op. Check the MCP gateway startup logs for ECONNRESET errors or delayed backend registration and re-run the workflow.
    bash: /bin/bash -lc 'safeoutputs create_pull_request_review_comment --help && safeoutputs submit_pull_request_review --help': /bin/bash: line 1: safeoutputs: command not found
    
    bash: /bin/bash -lc "safeoutputs noop '{\"message\":\"Unable to submit the review because the safeoutputs CLI is unavailable in this environment.\"}'": /bin/bash: line 1: safeoutputs: command not found
    
    Driver exit code: 0
    Failure classification: request_rejection
    Retry attempts observed: 0
    

    This is a structured incompletion signal (report_incomplete), not confirmation of a completed task. Do not treat accompanying safe outputs (e.g., comments) as evidence that the requested review or action was completed.

    Generated from Ponytail Reviewer · codex · 8.68 AIC · ◷

  2. github-actions commented on Oct 10, 2026

    @github-actions
    ContributorAuthor

    Agent job 38076469660 failed.

    Warning

    Task Could Not Be Completed: The workflow recorded a report_incomplete signal: the task was not completed or completion could not be confirmed. See the reported reason and diagnostics below.

    Error details:
    invalid_safe_outputs
    Agent finished without emitting a terminal safe output; task completion could not be confirmed.
    safeoutputs MCP gateway registered 0 tools during setup; the agent could not emit any safe outputs. This is a gateway infrastructure failure, not a normal no-op. Check the MCP gateway startup logs for ECONNRESET errors or delayed backend registration and re-run the workflow.
    bash: /bin/bash -lc "sed -n '261,620p' /tmp/gh-aw/agent/pr-diff.patch && git diff --check 3e35095cc3ca380a57e59c73e0609c228329164e"'^ 3e35095cc3ca380a57e59c73e0609c228329164e': +        for path in GUIDES:
    +            with self.subTest(path=path):
    +                text = checklist(path.read_text())
    +                for failure in case["failures"]:
    +                    field_start = text.index(f"`{failure['field']}`")
    +                    boundary = text.find("\n", field_start) if path == GUIDES[0] else text.index("point", field_start)
    +                    self.assertIn(failure["step"], text[field_start:boundary])
    +                self.assertIn("1.0.x", text)
    +                self.assertIn("vX.Y.Z", text)
    +                self.assertIn("gh-aw-firewall", text)
    +                self.assertIn(f"There is no `{case['invalid_field']}` field", text)
    +                self.assertIn("remove", text)
    +                self.assertIn("compiled default", text)
    +
    +    def test_routing_and_evidence_links(self):
    +        routing = SKILL.joinpath("SKILL.md").read_text()
    +        line = next(line for line in routing.splitlines() if ANCHOR in line)
    +        for symptom in ("AWF 400s", "model: auto", "install-step 404s", "version fields"):
    +            self.assertIn(symptom, line)
    +        self.assertTrue((SKILL / "../../aw/debug-agentic-workflow.md").resolve().is_file())
    +        full = GUIDES[0].read_text()
    +        for section in ("Collect Existing Evidence", "Identify the First Failing Boundary"):
    +            content = full.split(f"## {section}\n", 1)[1].split("\n## ", 1)[0]
    +            self.assertIn(ANCHOR, content)
    +        self.assertIn(f".github/aw/debug-agentic-workflow.md{ANCHOR}", GUIDES[1].read_text())
    +
    +
    +if __name__ == "__main__":
    +    unittest.main()
    
    diff --git a/debug.md b/debug.md
    --- a/debug.md
    +++ b/debug.md
    @@ -30,7 +30,9 @@ If it is installed, run:
     gh extension upgrade aw
     ```
     
    -to upgrade to latest. If it is not installed, run the installation script from the main branch of the gh-aw repository:
    +to upgrade to the latest non-prerelease. This can lag behind prereleases; see
    +[Model and engine misconfiguration](#model-and-engine-misconfiguration).
    +If it is not installed, run the installation script from the main branch of the gh-aw repository:
     
     ```bash
     curl -sL https://raw.githubusercontent.com/github/gh-aw/main/install-gh-aw.sh | bash
    @@ -83,6 +85,57 @@ gh aw compile <workflow-name>
     
     3. Check for syntax errors or validation warnings.
     
    +## Model and engine misconfiguration
    +
    +For AWF model/endpoint 400s, `model: auto` failures, install-step 404s after a
    +version pin, or questions about version fields, use the
    +[full checklist](.github/aw/debug-agentic-workflow.md#model-and-engine-misconfiguration):
    +
    +1. **Check the compiler first.** Read `compiler_version` from the lock file's
    +   `gh-aw-metadata` header and `cli_version` from `aw_info.json`. Compare with
    +   `gh release list --repo github/gh-aw --limit 20`, including prereleases.
    +   `gh extension install` and `gh extension upgrade` default to the latest
    +   non-prerelease. To install a specific prerelease, use
    +   `gh extension install github/gh-aw --force --pin TAG`, then verify and recompile.
    +   In the October 2026 case, v0.89.21 predated wire-API inference
    +   ([#64177](https://github.com/github/gh-aw/pull/64177)); v0.91.7 was the reported
    +   newest prerelease, not a permanent latest tag.
    +2. **Check model/endpoint compatibility.** The harness resolves `auto` to a
    +   concrete model. Wire-API precedence is explicit `engine.env` override →
    +   catalog `wire_api` → `-utility` base-model catalog fallback → `gpt-5+` name rule
    +   → CLI default `/chat/completions`. `COPILOT_PROVIDER_WIRE_API=responses` uses
    +   `/responses`; `completions` uses `/chat/completions`. One wire API applies to the
    +   whole session, including sub-agents; replace an incompatible sub-agent with a
    +   model supporting the main session's endpoint. For `engine.model-routing`, inspect AWF's
    +   selected endpoint too. `Cannot translate Copilot request feature`,
    +   `Unsupported Responses custom tool`, `model_policy_violation`, and
    +   `not accessible via the ... endpoint` warrant model/endpoint or model-policy
    +   investigation, not transient retries or prompt tuning. For
    +   `model_policy_violation`, check the model allowlist/denylist and rejected model;
    +   policy rejection alone does not establish an endpoint mismatch.
    +3. **Apply fixes in this order:**
    +   1. **Upgrade gh-aw and recompile.**
    +   2. **Pin a model that supports the required endpoint.**
    +   3. **Remove a conflicting `COPILOT_PROVIDER_WIRE_API` override.**
    +   4. **Use sub-agent models from the main model's family.** Verify endpoint
    +      compatibility; see [github/gh-aw#67460](https://github.com/github/gh-aw/issues/67460)
    +      and [github/copilot-cli#5103](https://github.com/github/copilot-cli/issues/5103).
    +   **Switching to an older model is a last resort** if these fail: leading with
    +   `model: gpt-4.1` trades capability for a workaround and leaves the
    +   underlying misconfiguration in place.
    +4. **Check the version field.** `engine.version` is the agent CLI version
    +   (Copilot CLI, 1.0.x in the customer case): **Install GitHub Copilot CLI** 404s
    +   point here. `sandbox.agent.version` is the AWF release in `vX.Y.Z` form and
    +   must match a GitHub release of `github/gh-aw-firewall`: **Install AWF binary**
    +   failures point here. There is no `engine.copilot.version` field. Usually remove
    +   the misplaced pin and recompile to use the compiled default.
    +5. **Read the evidence.** Inspect `[copilot-harness]` alias and
    +   `COPILOT_PROVIDER_WIRE_API` lines in `agent-stdio.log`; model and path per request
    +   in `sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl`; and `model`,
    +   `requested_model`, `cli_version` (gh-aw), `version` (agent CLI), and `awf_version`
    +   in `aw_info.json`. Use `gh aw audit RUN_ID` for the combined view. Older runs may
    +   omit diagnostics; do not assume routing was correct.
    +
     ## Step 4: Commit and Push Changes
     
     Commit the changes, e.g.
    
    fatal: unable to access 'https://github.com/github/gh-aw.git/': server certificate verification failed. CAfile: none CRLfile: none
    fatal: could not fetch ff6724948a5a3acf14e690d378f824d5d39df7fc from promisor remote
    
    bash: /bin/bash -lc 'safeoutputs create_pull_request_review_comment --help && safeoutputs submit_pull_request_review --help': /bin/bash: line 1: safeoutputs: command not found
    
    Driver exit code: 0
    Failure classification: request_rejection
    Retry attempts observed: 0
     ```
    

    This is a structured incompletion signal (report_incomplete), not confirmation of a completed task. Do not treat accompanying safe outputs (e.g., comments) as evidence that the requested review or action was completed.

    Generated from Ponytail Reviewer · codex · 7.44 AIC · ◷

  3. github-actions commented on Oct 10, 2026

    @github-actions
    ContributorAuthor

    Agent job 38078122938 failed.

    Warning

    Task Could Not Be Completed: The workflow recorded a report_incomplete signal: the task was not completed or completion could not be confirmed. See the reported reason and diagnostics below.

    Error details:
    invalid_safe_outputs
    Agent finished without emitting a terminal safe output; task completion could not be confirmed.
    safeoutputs MCP gateway registered 0 tools during setup; the agent could not emit any safe outputs. This is a gateway infrastructure failure, not a normal no-op. Check the MCP gateway startup logs for ECONNRESET errors or delayed backend registration and re-run the workflow.
    bash: /bin/bash -lc 'jq . /tmp/gh-aw/agent/pr-review-comments.json && safeoutputs noop --help': []
    /bin/bash: line 1: safeoutputs: command not found
    
    Driver exit code: 0
    Failure classification: request_rejection
    Retry attempts observed: 0
    

    This is a structured incompletion signal (report_incomplete), not confirmation of a completed task. Do not treat accompanying safe outputs (e.g., comments) as evidence that the requested review or action was completed.

    Generated from Ponytail Reviewer · codex · 8.71 AIC · ◷

  4. github-actions commented on Oct 11, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-10-11T03:12:21.909Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions