Skip to content

[aw-failures] P1: Copilot agents aborted by guard.tool_denials_exceeded reading repo source — 3 daily analysis workflows fail #39667

Description

@github-actions

Problem statement

Three daily code-analysis workflows running on the GitHub Copilot CLI engine are aborted mid-session by the tool-permission guard guard.tool_denials_exceeded (denialCount=5, threshold=5). The agents try to read repository source files they are meant to analyse, the workflow tool-permission policy denies the read()/shell(sed/cat) calls, and after 5 denials the SDK session is killed:

permission denied by workflow tool permissions: read(/home/runner/work/gh-aw/gh-aw/pkg/actionpins/actionpins.go)
guard.tool_denials_exceeded {"denialCount":5,"threshold":5}
[copilot-sdk-driver] max tool denials threshold reached (5/5); stopping SDK session early
[copilot-harness] attempt 1: detected numerous permission-denied issues — not retrying
##[error]Process completed with exit code 1

Affected workflows and run IDs

Workflow Run Denied target (representative)
Daily Testify Uber Super Expert §27641213363 read/shell on pkg/actionpins/actionpins.go (11 denials)
Daily SPDD Spec Planner §27636155593 shell(sed ... /tmp/copilot-tool-output-*.txt)
Daily Formal Spec Verifier §27634779077 read(pkg/cli/logs_command.go), pkg/cli/token_usage.go (13 denials)

All three: GitHub Copilot CLI 1.0.60 / claude-sonnet-4.6, read-only posture, 0 firewall blocks (network allowed) — so this is a tool-permission guard trip, not a network/MCP policy issue.

Probable root cause

These workflows are designed to inspect repository Go source (and their own /tmp/copilot-tool-output-*.txt tool output), but their compiled tool-permission allowlist does not grant read/shell access to those paths. Copilot's guard counts each denial and hard-stops the session at 5, so a workflow whose core task is "read and analyse source" cannot make progress. The harness explicitly classifies this as a missing tool/permission issue and does not retry, so every scheduled run fails. Likely a regression or omission in the shared tool-permission preset these three workflows import (the denied paths — pkg/actionpins, pkg/cli — are ordinary in-repo source, and /tmp/copilot-tool-output-*.txt is Copilot's own scratch output).

Proposed remediation

  1. Grant repo-source read access: extend the workflows' (or the shared preset's) tool permissions to allow read/shell(sed|cat) of the checked-out repo tree (/home/runner/work/gh-aw/gh-aw/**) for these read-only analysis workflows.
  2. Allowlist Copilot scratch output: permit reads of /tmp/copilot-tool-output-*.txt — denying Copilot's own tool-output files is almost certainly unintended.
  3. Raise/soften the denial guard for read-only analysis workflows, or surface a single upfront "these paths are denied" preflight so the agent stops requesting them instead of burning the 5-denial budget.

Success criteria / verification

  • Re-run all three workflows: the agent completes without hitting guard.tool_denials_exceeded, and produces its intended safe outputs.
  • read/shell of in-repo source and /tmp/copilot-tool-output-*.txt are permitted (no permission denied by workflow tool permissions for those paths).
  • No guard.tool_denials_exceeded aborts across these workflows for 48h.

Evidence

audit on all three runs confirms the identical guard.tool_denials_exceeded (5/5) signature; flags isMCPPolicyError=false, isAuthError=false, hasNumerousPermissionDenied=true; read-only posture, 0 firewall blocks.

Parent: #29109. Filed by the [aw] Failure Investigator (6h), lookback 2026-06-16 13:58–19:58Z.
Related to #29109

Generated by 🔍 [aw] Failure Investigator (6h) ·

  • expires on Jun 23, 2026, 12:16 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions