Skip to content

Route model-routing workflows to version-matched, pinned images - #66291

Merged
lpcox merged 5 commits into
mainfrom
copilot/fix-model-routing-issue-again
Oct 6, 2026
Merged

lpcox merged 5 commits into
mainfrom
copilot/fix-model-routing-issue-again

Conversation

Copilot AI commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Model-routing workflows previously used hardcoded AWF v0.28.30 images and an unversioned router image, regardless of the effective AWF version. This left routing behavior and image overrides out of sync.

  • Version-matched AWF images: Resolve routing images from the effective AWF version and its digest pins; report a clear compile error when pins are unavailable.
  • Pinned, configurable router: Pin gh-aw-router at v0.1.3 and allow sandbox.agent.images.router overrides.
  • Current defaults: Bump the default AWF version to v0.28.37, add image digests, and regenerate workflow locks.
sandbox:
  agent:
    version: v0.28.35
    images:
      router: registry.example.com/approved/router:v0.1.3@sha256:<64-hex-digest>

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix model routing to run correct AWF versions Route model-routing workflows to version-matched, pinned images Oct 6, 2026
Copilot AI requested a review from lpcox October 6, 2026 22:18
@lpcox
lpcox marked this pull request as ready for review October 6, 2026 22:27
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Container-pin maintenance will prune the unreferenced router pin, breaking the new default routing path.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Routes model-routing workflows through version-matched, digest-pinned AWF and router images.

Changes:

  • Resolves routed images from the effective AWF version and validates missing pins.
  • Adds a configurable, pinned router image and schema coverage.
  • Bumps AWF to v0.28.37 and regenerates locks.
File Description
.github/​aw/​actions-lock.json Adds AWF and router pins.
.github/​workflows/​*.lock.yml (323 files) Regenerates workflows for AWF v0.28.37.
pkg/​actionpins/​data/​action_pins.json Embeds updated pins.
pkg/​constants/​version_constants.go Updates AWF and router defaults.
pkg/​constants/​version_constants_test.go Tests version constants.
pkg/​parser/​schemas/​main_workflow_schema.json Allows router overrides.
pkg/​parser/​schema_test.go Tests router schema support.
pkg/​workflow/​data/​action_pins.json Embeds workflow pin data.
pkg/​workflow/​model_routing_test.go Tests routing image resolution.
pkg/​workflow/​sandbox_agent_images.go Implements version-matched image selection and validation.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/aw/actions-lock.json Outdated
Comment on lines +763 to +766
"ghcr.io/githubnext/gh-aw-router:0.1.3": {
"image": "ghcr.io/githubnext/gh-aw-router:0.1.3",
"digest": "sha256:c934c8c9f77ee6b2ed9e07c21dbd896faa4ccd63b4206518f05da0bcebb4a553",
"pinned_image": "ghcr.io/githubnext/gh-aw-router:0.1.3@sha256:c934c8c9f77ee6b2ed9e07c21dbd896faa4ccd63b4206518f05da0bcebb4a553"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implemented in commit 7cd6f1c: canonical gh-aw-router pins are now exempt from stale-pin pruning, with regression coverage; the router pin catalog is also kept lexically sorted.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (.github/aw/actions-lock.json:766): This new router pin will be deleted by the next container-pin refresh. PruneStaleContainerPins preserves only images referenced by checked-in lock files or under DefaultFirewallRegistry (pkg/workflow/action_cache.go:178-186); no checked-in lock references gh-aw-router, and this image is under githubnext. Once sync-action-pins propagates that pruning, routed workflows using the default router will fail with the new missing-pin validation. Exempt the canonical router pins from pruning (and add a regression test), as is already done for AWF pins. - Route model-routing workflows to version-matched, pinned images #66291 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 0e6d629
Sous-chef work: 09c2bef52daed64991478517d45e4f93bae2cdf83a6fe5d00a631ad1b37055bf
Sous-chef state: 98f8bce9ed42db545b1ac9eff3c72d175afebb4f71cb03102f6dcde442f64d78

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 4.72 AIC · ⌖ 7.64 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 6, 2026 23:00
…ting-issue-again

# Conflicts:
#	.github/workflows/daily-spec-coverage-kiro.lock.yml

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Copilot AI requested a review from gh-aw-bot October 6, 2026 23:15
@pelikhan

pelikhan commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

/matt

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@lpcox
lpcox merged commit eb63040 into main Oct 6, 2026
37 checks passed
@lpcox
lpcox deleted the copilot/fix-model-routing-issue-again branch October 6, 2026 23:40

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Triage was unavailable in this run, so I applied the fallback heuristic directly against the pre-fetched PR data. The only non-lock-file source change in this PR is .github/aw/actions-lock.json (25 additions, 0 deletions) — new pinned digests for AWF v0.28.37 images and the gh-aw-router:0.1.3 canonical pin. All other 335 changed files are regenerated .lock.yml artifacts.

No actionable /tdd, /codebase-design, /diagnosing-bugs, or /improve-codebase-architecture issues found:

📋 Verification details
  • Router pruning exemption (flagged in a prior review comment on this PR) is already implemented via DefaultRouterRegistry prefix check in PruneStaleContainerPins (pkg/workflow/action_cache.go), with dedicated regression coverage in TestPruneStaleContainerPins (pkg/workflow/action_cache_container_pin_test.go) asserting the stale router pin survives pruning.
  • Container-pin keys in actions-lock.json remain lexically sorted (verified programmatically), consistent with the prior review comment's resolution.
  • The diff itself contains no new abstractions, logic, or control flow — only data additions (digests) and mechanical lock-file regeneration, so there's nothing to assess against deep-module or test-coverage criteria beyond what's already covered.

No blocking issues. Approving.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 35 AIC · ⌖ 13.6 AIC · ⊞ 10.1K
Comment /matt to run again

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Model routing: routed workflows run stale AWF and router images regardless of the AWF version

5 participants