Skip to content

[ci-scan-feedback] Fix fixer self-dedup blinded by integrity gate (duplicate [ci-fix] artifacts) #132919

Description

@github-actions

Triggering signals

Root cause: the fixer's Step 3 self-dedup enumerates its OWN prior [ci-fix] PRs and hand-off comments through the integrity-gated github MCP (min-integrity: approved). Those artifacts are authored by github-actions[bot] (association CONTRIBUTOR), so every one is silently [Filtered]. The dedup map is built blind, and the workflow re-files a duplicate PR or posts a second hand-off.

Proposed edits

  • .github/workflows/ci-failure-fix.md (Step 3, dedup preamble) — add a rule that first-party [ci-fix] PRs / hand-off comments must be enumerated with ungated gh (the workflow's own outputs are not maintainer content), keep the integrity-gated github MCP only for maintainer-authored signals, and fail closed (emit nothing) when a self-dedup read can't complete.
  • .github/workflows/ci-failure-fix.md (Step 3, check 6) — enumerate prior hand-off comments via ungated gh api .../comments; fail closed on read failure.
  • .github/workflows/ci-failure-fix.md (tools.bash allowlist) — add gh, scoped by comment to first-party self-dedup enumeration only; NOT for reading maintainer-supplied content.

Expected behavior change

The next fixer run will build a complete self-dedup map from its own prior artifacts instead of a blind one, so it will stop opening a second [ci-fix] PR or a second hand-off comment for a KBE it has already handled. When a self-dedup read cannot be verified, the run defers rather than risking a duplicate. Maintainer-supplied content continues to pass through the integrity gate unchanged.

Note

This PR was generated by an AI agent (GitHub Copilot).

Generated by CI Outer-Loop Failure Scanner — Feedback · opus48 · 436.4 AIC · ⌖ 27.2 AIC · ⊞ 20.6K · ◷


Note

This was originally intended as a pull request, but the git push operation failed.

Original error: The process '/usr/bin/git' failed with exit code 1

Workflow Run: View run details and download bundle artifact

The bundle file is available in the agent artifact in the workflow run linked above.

To create a pull request with the changes:

# Download the artifact from the workflow run
gh run download 33253668646 -n agent -D /tmp/agent-33253668646

# Fetch the bundle into a temporary ref, then update the local branch
git fetch /tmp/agent-33253668646/aw-ci-scan-feedback-fixer-selfdedup-gate.bundle refs/heads/ci-scan-feedback/fixer-selfdedup-gate:refs/bundles/create-pr-ci-scan-feedback-fixer-selfdedup-gate-367423584055b653-0e53fba2
git update-ref refs/heads/ci-scan-feedback/fixer-selfdedup-gate-367423584055b653 refs/bundles/create-pr-ci-scan-feedback-fixer-selfdedup-gate-367423584055b653-0e53fba2
git checkout ci-scan-feedback/fixer-selfdedup-gate-367423584055b653
# Ensure the working tree matches the updated branch
git reset --hard
# Remove the temporary bundle ref
git update-ref -d refs/bundles/create-pr-ci-scan-feedback-fixer-selfdedup-gate-367423584055b653-0e53fba2

# Push the branch to origin
git push origin ci-scan-feedback/fixer-selfdedup-gate-367423584055b653

# Create the pull request
gh pr create --title '[ci-scan-feedback] Fix fixer self-dedup blinded by integrity gate (duplicate [ci-fix] artifacts)' --base main --head ci-scan-feedback/fixer-selfdedup-gate-367423584055b653 --repo dotnet/runtime

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions