Visitar URL original
Implement mandatory fair DAG work queues with Claim-scoped effects by pelikhan · Pull Request #66024 · github/gh-aw · GitHub
Skip to content

Implement mandatory fair DAG work queues with Claim-scoped effects - #66024

Merged
pelikhan merged 54 commits into
mainfrom
pelikhan-work-queue-fairness
Oct 8, 2026
Merged

pelikhan merged 54 commits into
mainfrom
pelikhan-work-queue-fairness

Conversation

@pelikhan

@pelikhan pelikhan commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Motivation

Independent agentic workflows need one durable way to prioritize eligible work, share assignment opportunities fairly, and recover without losing ownership or repeating unsafe writes. This PR implements the mandatory fair DAG queue described by the specification; it is no longer specification-only.

Implementation

  • Scheduling, ownership, observations and recovery share the sole causal work-queue.jsonl authority. Native Go and JavaScript engines use one closed version-3 contract and exact integer scheduling; the Go CLI does not depend on Node.
  • FIFO-like defaults, weighted/strict priority, accounting-key fairness, fresh CAS retry selection and bounded fair-prefix packing produce immutable compatible assignments. Each assignment is an object containing a claims array. Charges count durable Claims, including failed launches—not CPU time or successful completions.
  • Work, Issue and Pull Request DAG vertices support atomic admission, fresh typed observations and verified Result barriers. Completion alone cannot release successors.
  • Approved workers bind to the exact repository/workflow/revision/principal and attempt 1. One sender is fenced before launch; uncertainty retains reservations until definitive nonlaunch or exact termination.
  • Built-in, custom/deferred, prepared code/tree, GraphQL/REST, native asset, persistent-memory and queue-control paths retain original Claim attribution. Mixed outcomes settle independently, with private native delivery readback. Queue-disabled paths preserve ordinary behavior; an existing private Claim frame cannot escape scope by changing ambient flags.
  • Compiler/MCP/operator/explain/trace/reporting surfaces, read-only observers, memory restoration, current-only transition guidance, a major changeset, Temporal/HPC research and diagrams are wired. Earlier file-by-file review and scratch cleanup are retained; resolved main-merge lock backups were removed. /.queue-validation-cache/ is ignored.
flowchart LR
    Ready["Work Results and observed Issue/PR milestones"] --> Fair["Priority and fair-share selection"]
    Fair --> Log[("Durable Claims in work-queue.jsonl")]
    Log --> Assignment["Immutable compatible assignment"]
    Assignment --> Worker["Authenticated attempt-1 worker"]
    Worker --> Scoped["Independent Claim-scoped effects"]
    Scoped --> Results["Verified Results release DAG successors"]
Loading

Documentation and formal review

The onboarding Policy previously violated the mandatory empty-key weight and six runtime resource limits. Its template now uses "": 1, default producer entitlement and supported ceilings; a test feeds the actual example to the real policy validator. Documentation distinguishes assignment objects from Claim arrays, hard limits from tunable proposals, historical evidence from current-source captures, and bounded models from runtime refinement. Four missing ESLint rule-table links are restored and automatically checked.

The original 60-configuration review record remains unchanged. The separate refinement and checkpoint-recovery record records the current 61 configurations: 16 exhausted positive searches, 34 exact negative controls, nine exact guarded witnesses and two unfinished searches. FairDAGGitHub now exhausts 1,055,182 distinct states at depth 20 in 8m39s, with zero states remaining and its original bounds, constraints and safety conjuncts retained. TLC fingerprint assumptions are recorded, not presented as mathematical certainty.

Evaluation refinements retain phase guards and exact default-selection algebra. A deterministic projection is uniquely derived from the transaction log on every transition and independently checked by complete replay; it has no separate authority. Five original/revised union-graph comparisons and two exact mutation controls passed. The default batch graph remains 13,662 distinct states at depth 20. Eighteen new seeded simulations emitted 309 sampled states, and nine guarded witness traces matched. Model/configuration/tool identities remain bound to the evidence after the latest main merge; these comparisons are not TLAPS certificates or native runtime refinement proofs.

WorkQueue and QueueOrdering remain unfinished, not passes. Both successfully restored complete pinned local TLC checkpoints and continued for another 1,200 seconds. Their latest progress is respectively 38,640,894 distinct states with 7,079,332 queued, and 51,756,372 with 23,003,758 queued. These are actual continuations, not sums of independent searches; checkpoint restoration can precede the last interrupted progress report. Portable checkpoint archives remain unvalidated. Earlier nominal 1,800-second searches actually ran about 2,226–2,227 seconds; both requested and measured times are retained.

The ESLint factory model and executable comparison exhaust six bounded graphs (31,730 distinct states), checks nine negative controls/seven witnesses, and independently replays/tamper-checks 16 traces. Parent validation confirms all 22 expected model verdicts and six comparison/mutation tests. Actual probes cover 66 registered/configured/documented rules, CJS/non-test coverage, warning-only exit-zero behavior, Claim authority and collector per-Claim bounds. Installed Policy/producers/profiles and complete protected native readback remain assumptions. There is no automatic miner→refiner→monster DAG; quality bars and the monster's three-total-assignment instruction remain prompt obligations rather than global runtime guarantees.

Validation and evidence

  • Latest main 303b4028106137af47924a4bc079b8d3fdd8884c is merged in 179a891db0; generated conflicts in daily-choice-test, eslint-refiner and windows-grower were regenerated from merged sources. All 328 workflows compile and isolated drift checking passes. Refinement evidence and synchronized documentation are published in ef75172f34; the remote head matches the clean local tree.
  • The merged final test gate ran 2,323 setup-JavaScript tests in 56 files: 2,322 passed and the real multi-repository repo-memory race fixture exceeded its 10-second deadline. The isolated unchanged fixture also reproduced the timeout; it passed in approximately 11 seconds with a diagnostic longer deadline. A fixture-local 30-second budget preserves all assertions and production retry behavior; all 109 repo-memory tests subsequently pass.
  • Impacted Go tests, build, TypeScript typecheck, standard Go lint, JavaScript/shell lint and schema freshness passed. Pre-merge custom-lint diagnostics came from nine files byte-identical to main that the old merge-base calculation included. After committing the merge, the normal no-test gate passed change-scoped custom lint and full workflow drift. The initial failed aggregate invocations remain failed records; completed components and corrected/rechecked failures are reported separately without repeating Go unit tests or claiming global custom lint is clean.
  • The earlier SDK project-view type error is fixed without casts. Genuine TypeScript 7.0.2 typecheck and 36 project tests cover validated layout literals and endpoint-derived request typing. The earlier merge's component capture passed 2,122 setup-JavaScript tests in 52 files.
  • Earlier comprehensive safe-output review passed 3,206 tests/86 files with eight skips, and its disabled collector differential matched 24/24 baseline cases. Those captures predate the latest main merge; they are not a fresh full-suite run.
  • Earlier native capture passed 286 conformance cases/50 operating checks with 136 hashes stable during that capture. Safe-output changes invalidate current-source identity; these are historical evidence, not current release qualification. Mocked contention and local measurements are not hosted SLOs.
  • Generated contract drift passes. Earlier pinned TypeSpec 1.16.0 supported-subset comparison covers all 41 schemas, not arbitrary schema/runtime equivalence. Existing @types/node 26.6.3 remains because the approved feed lacks pinned 26.6.4; pins/TLS settings were not weakened.

Static compilation review from the earlier main merge

The following records the earlier generated-manifest review, not a new audit of every latest-main change. It is not comprehensive security sign-off or live credential-isolation verification. No secret values or repository secret resources were created/changed.

New per-workflow references were ANTHROPIC_API_KEY, CODEX_API_KEY, GEMINI_API_KEY, OPENAI_API_KEY, GH_AW_DEFAULT_OTLP_ENDPOINT, GH_AW_DEFAULT_OTLP_HEADERS, GH_AW_GITHUB_MCP_SERVER_TOKEN, GH_AW_GITHUB_TOKEN and GITHUB_TOKEN. Provider references support upstream model routing; flagged smoke launch commands explicitly exclude provider keys from the agent environment. OTLP references support configured telemetry; GitHub references support trusted automation/MCP. The reusable caller explicitly forwards declared secrets, including Anthropic for its Claude target, rather than secrets: inherit; caller permissions reflect the called jobs. These uses were consistent with that merge's sources, but deployment token scopes, telemetry destinations, live host boundaries and secret handling still require human verification.

Removed per-workflow references comprised ANTHROPIC_API_KEY, CODEX_API_KEY, OPENAI_API_KEY, COPILOT_GITHUB_TOKEN, GH_AW_CI_TRIGGER_TOKEN, GH_AW_DEFAULT_OTLP_ENDPOINT, GH_AW_DEFAULT_OTLP_HEADERS, GH_AW_GITHUB_MCP_SERVER_TOKEN, GH_AW_GITHUB_TOKEN, GITHUB_TOKEN, and the Grafana/Sentry endpoint/authorization pairs. These removals arose from upstream dev configuration changes and the obsolete ruflo-backed-task deletion; they do not delete secrets from GitHub.

New action references used existing standard pinned implementations: actions/cache/{restore,save}@55cc8345863c7cc4c66a329aec7e433d2d1c52a9, actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1, actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c, actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3, actions/setup-node@820762786026740c76f36085b0efc47a31fe5020, and actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a. Five standard-action references disappeared with the obsolete workflow; no new third-party action repository was introduced in that review. Their placement matched setup/cache/artifact/trusted-script purposes; remote implementation/signature audits are not asserted.

That merge moved AWF agent/API-proxy/CLI-proxy/squid images from 0.28.37 to digest-pinned 0.28.44. Existing MCP-gateway/node images were reused; some previous GitHub-MCP and Alpine-node references disappeared. Xberg moved from digest-pinned latest to digest-pinned 1.3.6. Pins prevent mutable tag resolution, but remote image contents/signatures and runtime behavior were not audited and remain flagged for human review. The ai-moderator redirect to githubnext/agentics/workflows/ai-moderator.md@main was pre-existing and unchanged, not a newly approved redirect.

Remaining release obligations

The complete formal/refinement suite is not passed. Partial/daily searches do not accumulate proof. Local results do not establish host/runtime refinement, CPU-time fairness, deployment SLOs or atomic/exactly-once effects.

Automated queue-branch writer-restriction verification/provisioning remains user-deferred and unimplemented. Workflow administrator bootstrap is unsupported; explicit authenticated operator/trusted-host initialization is required. Live immutable-SHA dispatch and the pinned run-details response remain unverified. Earlier fleet security sign-off remains incomplete; no approval is inferred from its interrupted review. No remote workflow was manually triggered.

See the implementation coverage and release checklist.



✨ PR Review Safe Output Test - Run 37789661275

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 63 AIC · ⌖ 7.4 AIC · ⊞ 853 · ◷
Comment /smoke-claude to run again

pelikhan and others added 9 commits October 5, 2026 15:26
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add verified result barriers, typed external gates, forward references, and dependency-specific controls. Document exhausted checks and the two non-exhausted searches without weakening their bounds.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run FairDAGGitHub and QueueOrdering on parallel five-hour jobs, preserve explicit verdicts and bounded checkpoint evidence, and publish a read-only agent handoff for later analysis.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Initialize verification paths on the runner instead of using the unsupported runner context in job-level env.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pelikhan
pelikhan marked this pull request as ready for review October 6, 2026 05:27
Copilot AI balanced review requested due to automatic review settings October 6, 2026 05:27
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

No ADR enforcement needed: PR #66024 lacks the 'implementation' label (has_implementation_label=false) and has 0 new lines in default business logic directories (default_business_additions=0, threshold=100), per /tmp/gh-aw/agent/adr-prefetch-summary.json. No custom .design-gate.yml present.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Generated by Ponytail Reviewer for #66024

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

L23-30: delete: unused WorkVertex/DependencyVertices abstraction. Nothing replaces it.

net: -5 lines possible.

Generated by ✂️ Ponytail Reviewer for #66024 · codex · gpt56 · 20 AIC · ⌖ 6.49 AIC · ⊞ 13.4K
Comment /ponytail to run again

Comment thread specs/work-queue/FairWorkQueue.tla Outdated
@github-actions github-actions Bot mentioned this pull request Oct 6, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes

The collector can misclassify a real TLC counterexample as a generic tooling failure, and the new tests still never exercise the QueueOrdering path this workflow runs daily.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 92.3 AIC · ⌖ 5.5 AIC · ⊞ 21.1K
Comment /review to run again

Comment thread .github/scripts/work-queue-formal-check.test.cjs Outdated
Comment thread .github/scripts/work-queue-formal-check.cjs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The evidence collector can mislabel incomplete checkpoints and lose or misreport failure evidence under checksum or disk-pressure conditions.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Specifies bounded fair work-queue scheduling models, Claim-scoped worker behavior, and daily TLC evidence collection.

Changes:

  • Adds TLA+ models, positive configurations, negative controls, and reachability witnesses.
  • Extends the verification harness and documentation.
  • Adds a daily workflow and tested evidence collector for expensive checks.
File Description
specs/​work-queue/​SingleClaimScopeWitness.cfg Tests automatic single-Claim scope reachability.
specs/​work-queue/​README.md Documents models, results, and daily evidence.
specs/​work-queue/​PartialCompletionWitness.cfg Tests partial batch completion reachability.
specs/​work-queue/​MixedClaimDAGWitness.cfg Tests mixed-outcome DAG progress.
specs/​work-queue/​FairWorkQueue.tla Models fair scheduling, DAGs, batching, and recovery.
specs/​work-queue/​FairThreeClaim.cfg Checks three-Claim batches.
specs/​work-queue/​FairStrict.cfg Checks strict-priority selection.
specs/​work-queue/​FairPriority.cfg Checks weighted selection.
specs/​work-queue/​FairGitHubDependencies.cfg Checks Issue/PR gates.
specs/​work-queue/​FairDAGGitHub.cfg Combines DAG and external dependencies.
specs/​work-queue/​FairDAGForward.cfg Checks forward references.
specs/​work-queue/​FairDAGFork.cfg Checks fork scheduling.
specs/​work-queue/​FairDAGChain.cfg Checks chained dependencies.
specs/​work-queue/​FairBatch.cfg Checks competing batched dispatch.
specs/​work-queue/​DAGJoinWitness.cfg Demonstrates join reachability.
specs/​work-queue/​ClaimScopeSingle.cfg Checks single-Claim output scope.
specs/​work-queue/​ClaimScopeMixed.cfg Checks mixed Claim outcomes.
specs/​work-queue/​ClaimScopedWorker.tla Models Claim-scoped outputs and Results.
specs/​work-queue/​check.sh Integrates filtering and new TLC cases.
specs/​work-queue/​BrokenPRClosedAsMerged.cfg Controls closed-unmerged PR handling.
specs/​work-queue/​BrokenMixedDAGAdmission.cfg Controls closure-based DAG admission.
specs/​work-queue/​BrokenMissingClaimScope.cfg Controls missing multi-Claim scope.
specs/​work-queue/​BrokenLastOpenClaimScope.cfg Controls last-open scope inference.
specs/​work-queue/​BrokenForeignClaimScope.cfg Controls foreign selectors.
specs/​work-queue/​BrokenExternalDependency.cfg Controls unsatisfied external gates.
specs/​work-queue/​BrokenDAGResult.cfg Controls unverified Results.
specs/​work-queue/​BrokenDAGDependency.cfg Controls premature successor claims.
specs/​work-queue/​BrokenDAGCycle.cfg Verifies cycle rejection.
specs/​work-queue/​BrokenClaimEffects.cfg Controls cross-Claim effects.
specs/​work-queue/​BrokenCancelledClaimOutput.cfg Controls cancelled-Claim effects.
specs/​work-queue/​BrokenBatchSelection.cfg Controls selection bypass.
specs/​work-queue/​BrokenBatchRelease.cfg Controls premature run release.
specs/​work-queue/​BrokenBatchCAS.cfg Controls stale batch publication.
specs/​work-queue/​BrokenAssignmentHandle.cfg Controls foreign Claim closure.
specs/​work-queue/​BatchedAssignmentWitness.cfg Demonstrates batched assignment.
.github/​workflows/​daily-work-queue-formal-verification.md Defines daily evidence collection and handoff.
.github/​workflows/​daily-work-queue-formal-verification.lock.yml Compiles the workflow into pinned Actions YAML.
.github/​scripts/​work-queue-formal-check.test.cjs Tests verdict and archive handling.
.github/​scripts/​work-queue-formal-check.cjs Runs TLC and packages evidence.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/scripts/work-queue-formal-check.cjs
Comment thread .github/scripts/work-queue-formal-check.cjs Outdated
Comment thread .github/scripts/work-queue-formal-check.cjs Outdated

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /tdd (and briefly /codebase-design) to this spec/verification-infrastructure PR — requesting changes on one concrete, reproducible test-harness bug; everything else is solid.

📋 Key Themes & Highlights

Key Themes

  • Test fixture not hermetic: work-queue-formal-check.test.cjs doesn't isolate GITHUB_STEP_SUMMARY, so 4 of 9 node --test cases throw ENOENT when run inside any real GitHub Actions step (where that env var is always set). Verified locally: 5 pass / 4 fail with the var set, 9/9 pass with it unset. This means the PR's "all 9 tests passed" validation claim doesn't hold for the actual CI/workflow execution context the script was written for.

Positive Highlights

  • ✅ Pure specification/verification-tooling change (no runtime behavior touched) scoped tightly to specs/work-queue/ and a new, isolated daily workflow — low blast radius.
  • ✅ check.sh additions (TLC_MODEL_FILTER/TLC_CONFIG_FILTER, explicit "no matching configuration" guard) are a clean, backward-compatible extension of the existing harness.
  • ✅ Pinned TLC jar SHA-256 is consistent across the collector script, workflow YAML, and README docs — no drift between provenance checks.
  • ✅ Thorough, honest reporting of incomplete searches (FairDAGGitHub, QueueOrdering) — the README is explicit that these are not proofs, which is good practice for formal-verification evidence.
  • ✅ Daily workflow correctly separates deterministic TLC collection (no-write) from the read-only handoff agent, with noop as the required terminal action.

Recommend fixing the inline test-isolation issue before merge so the formal-check harness's own test suite is trustworthy when it actually runs in CI (ironic given the PR's broader theme of rigorous, bounded verification evidence).

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 181.8 AIC · ⌖ 14.7 AIC · ⊞ 10.2K
Comment /matt to run again

Comment thread .github/scripts/work-queue-formal-check.test.cjs Outdated

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Impeccable review (audit/critique)

Reviewed the new .github/scripts/work-queue-formal-check.cjs + tests, the daily-work-queue-formal-verification.md workflow, specs/work-queue/check.sh changes, and the TLA+ specs/docs.

Verified:

  • node --test .github/scripts/work-queue-formal-check.test.cjs — 9/9 pass.
  • make recompile — all 321 workflows compile cleanly, including the new one.
  • Timeout/SIGINT→SIGKILL handling, TLC jar checksum pinning, and the classify() status logic are conservative: timeouts/signals/parsing errors never get misclassified as passed, and partial searches are never promoted to a proof.
  • Checkpoint archival correctly refuses to mark state resumable unless both vars.chkpt and queue.chkpt are present and under the size cap.
  • check.sh module/config filtering (TLC_MODEL_FILTER/TLC_CONFIG_FILTER) and the new FairWorkQueue/ClaimScopedWorker runs don’t break the existing WorkQueue/Recovery defaults.
  • State-count claims in specs/work-queue/README.md are internally consistent with the .cfg/check.sh wiring.

No blocking correctness, security, or reliability issues found in the diff. Nice, honest framing throughout (setup_incomplete/timed_out/tool_error are explicitly distinguished from passed, and the PR is careful not to claim an unbounded proof from a finite search).

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · copilot · sonnet50 · 165.7 AIC · ⌖ 13.2 AIC · ⊞ 8.2K

pelikhan and others added 2 commits October 5, 2026 22:46
Distinguish TLC invariant setup failures, cover both daily configurations, record actual jar provenance, label checkpoint candidates honestly, and protect final metadata space through archiving.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Honor invocation-local summary destinations and subprocess environment, keep production summary errors explicit, and test isolation from Actions runner summary paths without mutating global environment.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Intermediate implementation checkpoint: preserve the current-only contract, generated schemas, canonical fixtures, native verification drivers, and service/lifecycle formal models. Full runtime integration and every-file review remain in progress; exhaustive FairDAGGitHub and QueueOrdering evidence is not claimed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot Auto completed successfully!

Generated by Smoke Copilot Auto for #66024

@github-actions github-actions Bot removed the smoke label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Smoke Pi MISSION COMPLETE! Pi delivered. 🥧

Smoke test completed with mixed results; a detailed issue has been created.

🥧 Smoke Pi — Powered by Pi

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🔮 The ancient spirits stir... Smoke Codex awakens to divine this pull request...

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • clients2.google.com
  • host.docker.internal

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"
    - "host.docker.internal"

See Network Configuration for more information.

🔧 Tool validation by Agent Container Smoke Test

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

✨ Gemini awakens... Smoke Gemini begins its journey on this pull request...

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🧪 Agentic Commands has started processing this pull request

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Claims queue in line,
Fair DAG shares the burden,
Work finds its true owner.

Inspired by the fair DAG work queue implementation in this PR.

Generated by 🌸 Smoke Copilot Auto for #66024 · copilot · auto · 9.13 AIC · ⌖ 3.76 AIC · ⊞ 6.3K · ◷
Add label smoke to run again

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor
  1. GitHub CLI Testing: ✅
  2. Web Fetch Testing: ❌
  3. File Writing Testing: ✅
  4. Bash Tool Testing: ❌
  5. Build gh-aw: ❌
  6. Codemode Testing: ❌

Overall Status: FAIL

🥧 Smoke Pi — Powered by Pi · pi · auto · 0.954 AIC · ⌖ 4.9 AIC · ⊞ 6.8K · ◷
Comment /smoke-pi to run again

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Agent Container Tool Check

Tool Status Version
bash ✅ 5.2.21
sh ✅ available
git ✅ 2.55.0
jq ✅ 1.7
yq ✅ 4.54.1
curl ✅ 8.5.0
gh ✅ 2.102.0
node ✅ 24.21.0
python3 ✅ 3.11.17
go ✅ 1.24.13
java ✅ 21.x (via installed JDK)
dotnet ✅ 10.0.401

Result: 12/12 tools available ✅

Playwright Title Validation

  • Expected: playwright-F99b3gT_7xRc3oEb2NJ4K9fIAR5zKdMg
  • Actual: ERROR: The requested URL could not be retrieved
  • Status: FAIL (title mismatch; browser was closed after check)

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • clients2.google.com
  • host.docker.internal

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"
    - "host.docker.internal"

See Network Configuration for more information.

🔧 Tool validation by Agent Container Smoke Test · pi · mai11 · 1.72 AIC · ⌖ 0.34 AIC · ⊞ 7.6K · ◷
Comment /smoke-test-tools to run again

@github-actions

This comment has been minimized.

@github-actions
github-actions Bot requested a balanced review from Copilot October 8, 2026 14:18
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

💥 Smoke Test 37789661275 — Results

Test Status
1. GitHub MCP (last 2 merged PRs) ✅
2. GH CLI (gh pr list) ✅
3. Make Build ✅
4. Playwright (github.com title) ✅
5. Tavily Web Search ✅
6. File Writing ✅
7. Bash Tool ✅
8. Discussion Interaction ✅
9. Agentic Workflows MCP ✅
10. Slack Safe Output ✅
11. Code Scanning Alert ✅
12. Check Run ✅
13. Update PR ✅
14. PR Review Comments (2) ✅
15. Submit PR Review ✅
16. Resolve Review Thread ⚠️ GraphQL reviewThreads API returned null
17. Add Reviewer ✅
18. Push to PR Branch ❌ Branch has files outside allowed-files config
19. Close PR ⚠️ Skipped — no safe PR to close

Overall: PARTIAL (1 failed, 2 skipped)

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 63 AIC · ⌖ 7.4 AIC · ⊞ 853 · ◷
Comment /smoke-claude to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 63 AIC · ⌖ 7.4 AIC · ⊞ 853
Comment /smoke-claude to run again

"gh-aw": major
---

Replace the experimental work queue with the current-only fair DAG protocol.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Good summary line — clearly describes the intent of replacing the experimental work queue with the fair DAG protocol. Consider adding a brief migration note for operators upgrading from the old implementation.

Comment thread .github/aw/context.md
@@ -73,7 +73,7 @@ description: GitHub context expression variables and Handlebars-style template c
- **`${{ steps.* }}`** - Any outputs from previous steps (e.g., `${{ steps.my-step.outputs.result }}`)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 The context variable documentation update looks good. Consider adding an example of how ${{ steps.my-step.outputs.result }} is consumed in a downstream step for better discoverability.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It changes queue authority and credentialed effect paths while formal searches, writer-boundary enforcement, and live security verification remain incomplete.

0 open findings

3 resolved since last review

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@pelikhan
pelikhan merged commit 546e3d3 into main Oct 8, 2026
291 of 299 checks passed
@pelikhan
pelikhan deleted the pelikhan-work-queue-fairness branch October 8, 2026 14:35
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants