Repository navigation
Align workflow tool allowlists with required operations #67472
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -30,7 +30,7 @@ tools: | |
| cli-proxy: true | ||
| github: | ||
| mode: local | ||
| toolsets: [default] | ||
| toolsets: [default, actions] | ||
| bash: ["*"] | ||
| edit: | ||
| sandbox: | ||
|
|
@@ -157,9 +157,7 @@ Before doing anything: | |
| 1. **If CI Status is "success"**: CI was passing at activation time — call `noop` immediately with "CI is passing on main branch - no cleanup needed" and **stop**. | ||
| 2. **If CI Status is "failure"**: Proceed with the repair sequence below using the CI Run ID from the pre-check. | ||
| 3. **If CI Status is missing or ambiguous**: Re-verify using the live API: | ||
| ```bash | ||
| gh run list --workflow=ci.yml --branch=main --limit=2 --json conclusion,status,databaseId | ||
| ``` | ||
| use the GitHub Actions MCP tools to list completed runs for `ci.yml` on `main`; do not use `gh run list`. | ||
| - **If both completed runs are "success"**: CI has self-healed. Call `noop` and **stop**. | ||
| - **Otherwise**: Proceed with the repair sequence below. | ||
|
|
||
|
|
@@ -193,16 +191,17 @@ git diff --name-only HEAD origin/main | grep '^\.github/workflows/.*\.md$' | |
|
|
||
| ## Step 3: Inspect the failing CI run first (mandatory) | ||
|
|
||
| Use the CI Run ID from pre-check and identify the first failed job and failing signal before running any local validation: | ||
| Use the GitHub Actions MCP tools, not `gh run view` (the agent's `gh` CLI is unauthenticated), and identify the first failed job and failing signal before running any local validation: | ||
|
|
||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This swaps out the unauthenticated 💡 Why this blocks the workflowThere is no prior-art usage ofmethod: list_workflow_jobs or resource_id in this repo, while generated manifests expose Actions reads as dedicated MCP tools such as mcp__github__actions_list and mcp__github__get_job_logs. If the agent follows the literal contract here, it will burn a denial or validation error and noop instead of triaging CI. Please describe the actual tool shape the runtime exposes, or keep the step tool-agnostic instead of inventing parameter names. |
||
| ```bash | ||
| gh run view "${{ needs.check_ci_status.outputs.ci_run_id }}" --json jobs | ||
| ``` | ||
| 1. Call `actions_list` with `method: list_workflow_jobs` and `resource_id` set to the CI Run ID from pre-check. | ||
| 2. Identify the first failed job. | ||
| 3. Call `get_job_logs` with that job's ID and inspect the failing output. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. [/diagnosing-bugs] This mandatory step still invokes 💡 Root cause checkCompare with the compiled lock file: @copilot please address this. |
||
|
|
||
| Then inspect only the failing job logs and extract the concrete failure category (formatting, lint, tests, wasm golden, compile, or other). | ||
|
|
||
| - If the failure is not actionable or is clearly infra/transient (network outage, rate limit, runner outage), call `noop` with a brief explanation and stop. | ||
| - If actionable, apply the smallest fix that maps directly to the failure signal. | ||
| - If an Actions tool is unavailable, keep the denial text and name the exact allowlist entry needed: add `actions` to `tools.github.toolsets`. | ||
|
|
||
| ## Step 4: Format sources (only when relevant) | ||
|
|
||
|
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
[/diagnosing-bugs] Good:
toolsets: [default, actions]now matches theactions: readpermission already granted at the top of this file, closing the denial. One gap remains — the "If an Actions tool is unavailable" fallback text (previously at the end of Step 3) that named the exact missing allowlist entry was deleted in this PR, even though the issue's "Done when" criterion requires "Missing tool reports name the exact allowlist entry to add." Consider keeping a short fallback note for future regressions (e.g. ifactionstoolset access is revoked again).@copilot please address this.