You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Root cause: the fixer's Step 3 self-dedup enumerates its OWN prior [ci-fix] PRs and hand-off comments through the integrity-gated github MCP (min-integrity: approved). Those artifacts are authored by github-actions[bot] (association CONTRIBUTOR), so every one is silently [Filtered]. The dedup map is built blind, and the workflow re-files a duplicate PR or posts a second hand-off.
Proposed edits
.github/workflows/ci-failure-fix.md (Step 3, dedup preamble) — add a rule that first-party [ci-fix] PRs / hand-off comments must be enumerated with ungated gh (the workflow's own outputs are not maintainer content), keep the integrity-gated github MCP only for maintainer-authored signals, and fail closed (emit nothing) when a self-dedup read can't complete.
.github/workflows/ci-failure-fix.md (Step 3, check 6) — enumerate prior hand-off comments via ungated gh api .../comments; fail closed on read failure.
.github/workflows/ci-failure-fix.md (tools.bash allowlist) — add gh, scoped by comment to first-party self-dedup enumeration only; NOT for reading maintainer-supplied content.
Expected behavior change
The next fixer run will build a complete self-dedup map from its own prior artifacts instead of a blind one, so it will stop opening a second [ci-fix] PR or a second hand-off comment for a KBE it has already handled. When a self-dedup read cannot be verified, the run defers rather than risking a duplicate. Maintainer-supplied content continues to pass through the integrity gate unchanged.
Note
This PR was generated by an AI agent (GitHub Copilot).
The bundle file is available in the agent artifact in the workflow run linked above.
To create a pull request with the changes:
# Download the artifact from the workflow run
gh run download 33253668646 -n agent -D /tmp/agent-33253668646
# Fetch the bundle into a temporary ref, then update the local branch
git fetch /tmp/agent-33253668646/aw-ci-scan-feedback-fixer-selfdedup-gate.bundle refs/heads/ci-scan-feedback/fixer-selfdedup-gate:refs/bundles/create-pr-ci-scan-feedback-fixer-selfdedup-gate-367423584055b653-0e53fba2
git update-ref refs/heads/ci-scan-feedback/fixer-selfdedup-gate-367423584055b653 refs/bundles/create-pr-ci-scan-feedback-fixer-selfdedup-gate-367423584055b653-0e53fba2
git checkout ci-scan-feedback/fixer-selfdedup-gate-367423584055b653
# Ensure the working tree matches the updated branch
git reset --hard
# Remove the temporary bundle ref
git update-ref -d refs/bundles/create-pr-ci-scan-feedback-fixer-selfdedup-gate-367423584055b653-0e53fba2
# Push the branch to origin
git push origin ci-scan-feedback/fixer-selfdedup-gate-367423584055b653
# Create the pull request
gh pr create --title '[ci-scan-feedback] Fix fixer self-dedup blinded by integrity gate (duplicate [ci-fix] artifacts)' --base main --head ci-scan-feedback/fixer-selfdedup-gate-367423584055b653 --repo dotnet/runtime
Triggering signals
[ci-fix]kind: helpPRs opened for the same KBE. Maintainerkotlarmiloson [ci-fix] Needs review: select gen-debug-dump-docs Helix post-command shell by WindowsShell (refs #131382) #131981: "Duplicate [ci-fix] Stop dump-doc collection on unsupported Helix targets (refs #131382) #131515." (#131981, #131515)[ci-fix]PRs. Maintainervcsjones: "duplicate of [ci-fix] Needs review: Fix Android X509 DynamicChainTests name-constraint status mismatch (refs #128890) #129523." (#129651)[ci-scan]KBE carries twoci-fixhand-off comments (2026-06-19 legacy + 2026-08-09), violating Hard rule 5 ("at most one loop-in comment per KBE"). (#129385)Root cause: the fixer's Step 3 self-dedup enumerates its OWN prior
[ci-fix]PRs and hand-off comments through the integrity-gatedgithubMCP (min-integrity: approved). Those artifacts are authored bygithub-actions[bot](associationCONTRIBUTOR), so every one is silently[Filtered]. The dedup map is built blind, and the workflow re-files a duplicate PR or posts a second hand-off.Proposed edits
.github/workflows/ci-failure-fix.md(Step 3, dedup preamble) — add a rule that first-party[ci-fix]PRs / hand-off comments must be enumerated with ungatedgh(the workflow's own outputs are not maintainer content), keep the integrity-gatedgithubMCP only for maintainer-authored signals, and fail closed (emit nothing) when a self-dedup read can't complete..github/workflows/ci-failure-fix.md(Step 3, check 6) — enumerate prior hand-off comments via ungatedgh api .../comments; fail closed on read failure..github/workflows/ci-failure-fix.md(tools.bashallowlist) — addgh, scoped by comment to first-party self-dedup enumeration only; NOT for reading maintainer-supplied content.Expected behavior change
The next fixer run will build a complete self-dedup map from its own prior artifacts instead of a blind one, so it will stop opening a second
[ci-fix]PR or a second hand-off comment for a KBE it has already handled. When a self-dedup read cannot be verified, the run defers rather than risking a duplicate. Maintainer-supplied content continues to pass through the integrity gate unchanged.Note
This PR was generated by an AI agent (GitHub Copilot).
Note
This was originally intended as a pull request, but the git push operation failed.
Original error: The process '/usr/bin/git' failed with exit code 1
Workflow Run: View run details and download bundle artifact
The bundle file is available in the
agentartifact in the workflow run linked above.To create a pull request with the changes: