Skip to content

Add fix codemods for Copilot web-fetch and reserved inputs - #66556

Merged
pelikhan merged 5 commits into
mainfrom
copilot/aw-top-10-add-codemods
Oct 7, 2026
Merged

pelikhan merged 5 commits into
mainfrom
copilot/aw-top-10-add-codemods

Conversation

Copilot AI commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Compatibility audits found strict-compilation failures from native Copilot web-fetch settings and user-declared workflow_dispatch.inputs.aw_context. Add automatic fixes for both; Codex bash allow-list restrictions retain their existing guided, manual remediation.

  • Copilot: Remove tools.web-fetch for Copilot CLI workflows; preserve it for Copilot SDK mode and other engines.
  • Reserved input: Remove aw_context from on.workflow_dispatch.inputs, preserving other inputs and comments.
  • Codex: Keep the existing manual guidance; automatically widening bash permissions would change workflow behavior.
# Before
engine:
  id: copilot
tools:
  web-fetch:
on:
  workflow_dispatch:
    inputs:
      aw_context:
        type: string

# After gh aw fix
engine:
  id: copilot
on:
  workflow_dispatch:

Copilot AI linked an issue Oct 7, 2026 that may be closed by this pull request
2 tasks
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Add codemods for audited compile gaps Add fix codemods for Copilot web-fetch and reserved inputs Oct 7, 2026
Copilot AI requested a review from pelikhan October 7, 2026 12:34
@pelikhan
pelikhan marked this pull request as ready for review October 7, 2026 13:56
Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The migrations can delete compatible settings or unrelated text and leave some compilation failures unresolved.

Review effort: Balanced
Findings: 4 Medium severity

Open (4)
What changed in this PR

Adds gh aw fix migrations for two audited compilation failures while retaining manual guidance for Codex bash restrictions.

Changes:

  • Removes unsupported Copilot CLI web-fetch settings and reserved aw_context inputs.
  • Registers both migrations and adds preservation, idempotence, and strict-compilation tests.
File Description
pkg/​cli/​fix_codemods.go Registers both migrations.
pkg/​cli/​fix_codemods_test.go Updates registry and ordering expectations.
pkg/​cli/​codemod_workflow_dispatch_aw_context.go Removes reserved dispatch inputs.
pkg/​cli/​codemod_workflow_dispatch_aw_context_test.go Tests input removal and compilation.
pkg/​cli/​codemod_copilot_web_fetch.go Removes unsupported Copilot fetch settings.
pkg/​cli/​codemod_copilot_web_fetch_test.go Tests removal and compatible configurations.

Comment thread pkg/cli/codemod_copilot_web_fetch.go Outdated
Comment on lines +17 to +21
if extractEngineIDFromFrontmatter(frontmatter) != "copilot" {
return content, false, nil
}

_, engineConfig, _ := (&workflow.Compiler{}).ExtractEngineConfig(frontmatter)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved the effective engine and SDK settings through ApplyWithContext; when resolution fails, the codemod now preserves tools.web-fetch. Added import/include coverage in daa2f746.

Comment thread pkg/cli/codemod_copilot_web_fetch.go Outdated
}

newContent, applied, err := applyFrontmatterLineTransform(content, func(lines []string) ([]string, bool) {
result, modified := removeFieldFromBlock(lines, "web-fetch", "tools")

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Both removals now edit YAML mapping nodes, covering flow maps and quoted keys while retaining siblings. Regression cases were added in daa2f746.

return lines, false
}
dispatchEnd := frontmatterBlockEnd(lines, dispatchLine, len(getIndentation(lines[dispatchLine])))
block, modified := removeFieldFromBlock(lines[dispatchLine:dispatchEnd], "aw_context", "inputs")

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The removals now follow the actual YAML mapping path, so matching text inside block scalars remains untouched. Added literal-text regression tests in daa2f746.

Comment on lines +46 to +49
block, modified := removeFieldFromBlock(lines[dispatchLine:dispatchEnd], "aw_context", "inputs")
if !modified {
return lines, false
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When the reserved input is the only entry, the codemod now leaves inputs: {} and preserves header/surviving comments. Added compiler-valid regression cases in daa2f746.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/cli/codemod_copilot_web_fetch.go:21): With no local engine declaration, these checks default to Copilot CLI even when an import or markdown include supplies Copilot SDK or another engine. A compatible workflow with local tools.web-fetch therefore loses a supported tool. The compiler resolves these inherited settings in resolveEngineFromIncludesAndImports. Use ApplyWithContext to resolve the effective engine and SDK setting before removing the tool, and preserve the setting if resolution fails. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)
  3. Review (pkg/cli/codemod_copilot_web_fetch.go:39): The parsed preconditions accept valid YAML forms that these line-based transforms cannot remove. For example, tools: {web-fetch: true} and a block entry web-fetch: true remain unchanged. The reserved-input codemod likewise misses on: {workflow_dispatch: {inputs: {aw_context: {type: string}}}} because it searches only subsequent lines. In each case gh aw fix leaves the original compiler error unresolved. Support flow mappings and quoted keys in both removals while preserving siblings and comments, and add regression cases. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)
  4. Review (pkg/cli/codemod_workflow_dispatch_aw_context.go:46): removeFieldFromBlock treats matching text at any depth as a YAML key. If a sibling task input has a description: | containing aw_context: example, removing the reserved input also deletes that description line. The new web-fetch codemod has the same problem: passing all frontmatter lines can delete a tools: / web-fetch: example inside a top-level multiline description. Restrict both removals to the actual mapping entries using YAML-aware boundaries, and test that literal text remains unchanged. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)
  5. Review (pkg/cli/codemod_workflow_dispatch_aw_context.go:49): When aw_context is the only input, an inline comment on inputs: or a surviving comment underneath it makes the helper retain an empty header. YAML parses that as null, but the workflow_dispatch schema requires inputs to be an object. The fix reports success while compilation still fails. Rewrite the retained header as inputs: {} while preserving comments, and add regression cases for both comment forms. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 4b88a27
Sous-chef work: 0b157b59aec97704ab535dfb401bfe3319372d8569d12fbb723b8b1073659d0c 6261fe9675c197634fa2fac82956be79d27adecc55739e60c2cd1ff8728f82d0 a5b10f7e5aaac0e4079ff0c349cc3a004caba737eaf97fc87a0415bc9a0f7928 b5e3b45053c256a6fd32920bac11fb56c465fae41383cd97c281b8842904f2e5
Sous-chef state: c9841d98ef10469c894592bc9cbaab79c0f43d00aab4a04b0d5b35720bcdda2f

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 3.67 AIC · ⌖ 7.25 AIC · ⊞ 1K · ◷
Comment /souschef to run again

…-codemods

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/cli/codemod_copilot_web_fetch.go:21): With no local engine declaration, these checks default to Copilot CLI even when an import or markdown include supplies Copilot SDK or another engine. A compatible workflow with local tools.web-fetch therefore loses a supported tool. The compiler resolves these inherited settings in resolveEngineFromIncludesAndImports. Use ApplyWithContext to resolve the effective engine and SDK setting before removing the tool, and preserve the setting if resolution fails. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)
  3. Review (pkg/cli/codemod_copilot_web_fetch.go:39): The parsed preconditions accept valid YAML forms that these line-based transforms cannot remove. For example, tools: {web-fetch: true} and a block entry web-fetch: true remain unchanged. The reserved-input codemod likewise misses on: {workflow_dispatch: {inputs: {aw_context: {type: string}}}} because it searches only subsequent lines. In each case gh aw fix leaves the original compiler error unresolved. Support flow mappings and quoted keys in both removals while preserving siblings and comments, and add regression cases. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)
  4. Review (pkg/cli/codemod_workflow_dispatch_aw_context.go:46): removeFieldFromBlock treats matching text at any depth as a YAML key. If a sibling task input has a description: | containing aw_context: example, removing the reserved input also deletes that description line. The new web-fetch codemod has the same problem: passing all frontmatter lines can delete a tools: / web-fetch: example inside a top-level multiline description. Restrict both removals to the actual mapping entries using YAML-aware boundaries, and test that literal text remains unchanged. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)
  5. Review (pkg/cli/codemod_workflow_dispatch_aw_context.go:49): When aw_context is the only input, an inline comment on inputs: or a surviving comment underneath it makes the helper retain an empty header. YAML parses that as null, but the workflow_dispatch schema requires inputs to be an object. The fix reports success while compilation still fails. Rewrite the retained header as inputs: {} while preserving comments, and add regression cases for both comment forms. - Add fix codemods for Copilot web-fetch and reserved inputs #66556 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 92f6331
Sous-chef work: 0b157b59aec97704ab535dfb401bfe3319372d8569d12fbb723b8b1073659d0c 6261fe9675c197634fa2fac82956be79d27adecc55739e60c2cd1ff8728f82d0 a5b10f7e5aaac0e4079ff0c349cc3a004caba737eaf97fc87a0415bc9a0f7928 b5e3b45053c256a6fd32920bac11fb56c465fae41383cd97c281b8842904f2e5
Sous-chef state: c28447fc517927b23c6da38bdaa9e0b31e276e28bb613d846334a7f403f43bbc

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 4.09 AIC · ⌖ 6.51 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Copilot AI requested a review from gh-aw-bot October 7, 2026 16:14
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Fix failing check github-advanced-security (FAILURE): https://github.com/github/gh-aw/actions/runs/37650223259/job/112891323309.

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: daa2f74
Sous-chef work: 960a6fe297781e0f1e1c8c03fa3740110735e1332e99a040b5aa7b1b6d14a3f2
Sous-chef state: 8d0b18933b1c4c1587ce4345cbfef389a243ef67596603bc07c0955e5afcdd95

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 2.88 AIC · ⌖ 7.46 AIC · ⊞ 1K · ◷
Comment /souschef to run again

…-codemods

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@pelikhan
pelikhan merged commit d10c61b into main Oct 7, 2026
1 of 2 checks passed
@pelikhan
pelikhan deleted the copilot/aw-top-10-add-codemods branch October 7, 2026 16:44

Copilot AI commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes....

Merged the latest main in b52582f. The advanced-security logs show make deps-dev failed during go mod download with an HTTP/2 INTERNAL_ERROR from proxy.golang.org, before the build; local build, lint, workflow drift checks, and impacted tests pass, so there is no code change to make for this transient registry failure. The four review findings already have substantive replies and fixes from daa2f74; this environment does not expose a review-thread resolution operation, so those threads remain unresolved. CI needs a human-triggered rerun.

Copilot AI restored the copilot/aw-top-10-add-codemods branch October 7, 2026 16:51
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AW Top 10] 02 Add codemods for audited compile gaps

4 participants