Skip to content

Enforce workspace-wide strict mode through aw.json - #59253

Merged
pelikhan merged 2 commits into
mainfrom
copilot/add-strict-field-in-aw-json
Sep 7, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/add-strict-field-in-aw-json

Conversation

Copilot AI commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Allow repositories to enforce strict compilation across all workflows, preventing per-workflow strict: false opt-outs.

  • Configuration

    • Add top-level strict support to .github/workflows/aw.json.
    • Accept only true; reject false during schema validation.
  • Enforcement

    • Apply repository strict mode across CLI and direct compiler entry points.
    • Ensure strict-mode validations consistently use repository precedence.
  • Documentation

    • Document workspace-wide strict mode and its precedence over frontmatter.
{
  "strict": true
}

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 42.9 AIC · ⌖ 8.65 AIC · ⊞ 8.9K · ◷
Comment /souschef to run again

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title Enforce workspace strict mode through aw.json Enforce workspace-wide strict mode through aw.json Sep 7, 2026
@pelikhan
pelikhan marked this pull request as ready for review September 7, 2026 15:44
Copilot AI balanced review requested due to automatic review settings September 7, 2026 15:44
Copilot AI requested a review from pelikhan September 7, 2026 15:44
@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

No ADR enforcement needed: PR does not have the 'implementation' label and has ≤100 new lines of code in business logic directories.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

Warning

Firewall blocked 4 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com/ghapi
  • github.com
  • pypi.org
  • github.com/ghraw

[!TIP]
github.com/ghapi is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding github.com/ghapi to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to github.com/ghapi:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com/ghapi"
    - "github.com"
    - "pypi.org"
    - "github.com/ghraw"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #59253

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ponytail pass focused on deletable complexity in changed lines only.

net: -15 lines possible.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by ✂️ Ponytail Reviewer for #59253 · codex · gpt53codex · 5.03 AIC · ⌖ 3.23 AIC · ⊞ 12.8K
Comment /ponytail to run again

@@ -17,7 +18,8 @@ var compileOrchestratorLog = logger.New("cli:compile_orchestrator")
var compileUpdateContainerPins = updateContainerPins

// CompileWorkflows compiles workflows based on the provided configuration

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pkg/cli/compile_orchestrator.go:L20: yagni: workspace strict config loading embedded in CLI orchestrator. Reuse compiler-level strict resolution only; remove applyWorkspaceStrictMode from CLI.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Direct compiler entry points still execute several strict-sensitive paths using non-effective strict state.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds repository-wide strict compilation through aw.json, overriding workflow-level opt-outs.

Changes:

  • Adds and validates the repository strict setting.
  • Applies repository precedence across compilation and security checks.
  • Adds tests and documentation.
File summaries
File Description
pkg/workflow/repo_config.go Parses repository strict mode.
pkg/workflow/repo_config_test.go Tests accepted and rejected values.
pkg/workflow/pull_request_target_validation.go Uses effective strict precedence.
pkg/workflow/pull_request_target_validation_test.go Updates precedence expectations.
pkg/workflow/compiler_yaml_policy.go Incorporates repository strict mode.
pkg/workflow/compiler_repo_config_test.go Tests repository override behavior.
pkg/parser/schemas/repo_config_schema.json Defines the strict setting schema.
pkg/cli/compile_permissions_integration_test.go Tests CLI enforcement.
pkg/cli/compile_orchestrator.go Applies workspace strict mode to CLI compilation.
docs/src/content/docs/reference/frontmatter.md Documents workspace enforcement.
Review details
  • Files reviewed: 10/10 changed files
  • Comments generated: 2
  • Review effort level: Balanced

Comment on lines +17 to +20
if repoConfig, err := c.loadRepoConfig(); err == nil && repoConfig.Strict {
compilerYAMLPolicyLog.Print("Strict mode enforced by repository config")
return true
}
Comment on lines 62 to 64
// When the workflow frontmatter sets strict: false, effectiveStrictMode is lowered so the
// dangerous-trigger strict-only warning is skipped; the insecure-checkout check still runs
// and emits a non-strict warning when checkout is not explicitly disabled.
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🧪 Test Quality Sentinel Report

Summary

Test Quality Score: ✅ 85/100 — Excellent

Verdict: ✅ APPROVE — Strong test coverage with design-focused assertions, proper error handling, and good edge-case coverage.


Test Coverage Overview

Files Analyzed

  • ✅ pkg/cli/compile_permissions_integration_test.go (+24 lines)
  • ✅ pkg/workflow/compiler_repo_config_test.go (+18 lines)
  • ✅ pkg/workflow/pull_request_target_validation_test.go (+5, -3 lines)
  • ✅ pkg/workflow/repo_config_test.go (+17 lines)

Total: 4 test files modified, 64 lines added, 3 lines deleted

New & Modified Test Functions Reviewed

Click to expand test classification table
Test Name File Type Design Invariant Value Coverage
TestCompileDefaultsToStrictMode compile_permissions_integration_test.go NEW behavioral_contract high_value Error + assertion on strict mode default
TestCompileWorkspaceStrictModeOverridesFrontmatter compile_permissions_integration_test.go NEW behavioral_contract high_value Error + assertion on workspace override
TestCompilerRepoConfigStrictOverridesFrontmatter compiler_repo_config_test.go NEW behavioral_contract high_value Direct assertion of override logic
TestCompilerLoadRepoConfig_CachesResult compiler_repo_config_test.go Modified design_test high_value Verifies caching invariant
TestLoadRepoConfig_StrictTrue repo_config_test.go NEW behavioral_contract high_value Direct config loading validation
TestLoadRepoConfig_StrictFalseRejected repo_config_test.go NEW behavioral_contract high_value Error assertion for invalid state

Quality Findings

✅ Strengths

  1. Strong Design Contracts (100% design tests)

    • New strict mode tests validate user-facing behavior, not implementation details
    • Integration tests (TestCompileDefaultsToStrictMode, TestCompileWorkspaceStrictModeOverridesFrontmatter) exercise the full compilation pipeline
    • Unit tests (TestLoadRepoConfig_StrictTrue, TestLoadRepoConfig_StrictFalseRejected) enforce schema invariants
  2. Proper Error Handling

    • Error cases covered: workspace override rejection (require.Error), invalid config rejection
    • Assertion messages are descriptive ("compile without --strict should reject write permissions")
  3. Edge-Case Coverage

    • Workspace-level config precedence over workflow frontmatter
    • Default strict mode behavior when field is omitted
    • Caching behavior verified in config loading tests
  4. Build Tags Present

    • All new/modified Go test files have correct (go/redacted):build tags:
      • (go/redacted):build integration (compile_permissions_integration_test.go)
      • (go/redacted):build !integration (all unit tests)
  5. No Mock Library Violations

    • Tests use require/assert from testify for assertions only
    • No gomock or .EXPECT() calls detected
    • File I/O uses real temp directories (not mocked)

Scoring Breakdown

design_tests / total_new_tests:     6/6 = 100% → 40 points
tests_with_edge_cases / total:      5/6 = 83% → 25 points
duplication penalty:                0 clusters → 20 points
inflation ratio penalty (< 2:1):    0 instances → 10 points
────────────────────────────────────────────────
Total: 95 points (quality-adjusted to 85/100)

Approval Criteria Met

✅ No Go mock library usage (gomock, testify/mock, .EXPECT(), .On())
✅ All new Go test files have required (go/redacted):build tags on line 1
✅ No assertions without descriptive failure context
✅ Implementation tests = 0% (all are design tests; threshold ≤ 30%)
✅ Test inflation ratio < 2:1 (all ratios acceptable)
✅ Edge-case coverage present (error paths validated)


Recommendation

Approve — The PR introduces well-structured tests for workspace-wide strict mode enforcement. Tests verify both the default behavior and the precedence rules (workspace config overrides workflow frontmatter). Error handling is properly validated, and code organization follows gh-aw conventions.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧪 Test quality analysis by Test Quality Sentinel · copilot · haiku45 · 24.3 AIC · ⌖ 10.2 AIC · ⊞ 8.4K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Test Quality Sentinel: 85/100. 100% design tests (0% implementation tests; threshold: 30%). All approval criteria met: no mock library violations, proper build tags, descriptive assertions, and excellent edge-case coverage.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-09-07T15:50:35Z
review_event: COMMENT
top_themes:
  - no-actionable-findings
files_reviewed:
  - docs/src/content/docs/reference/frontmatter.md
  - pkg/cli/compile_orchestrator.go
  - pkg/cli/compile_permissions_integration_test.go
  - pkg/parser/schemas/repo_config_schema.json
  - pkg/workflow/compiler_repo_config_test.go
  - pkg/workflow/compiler_yaml_policy.go
  - pkg/workflow/pull_request_target_validation.go
  - pkg/workflow/pull_request_target_validation_test.go
  - pkg/workflow/repo_config.go
  - pkg/workflow/repo_config_test.go
comment_count: 0

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 4 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com/ghapi
  • github.com
  • pypi.org
  • github.com/ghraw

[!TIP]
github.com/ghapi is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding github.com/ghapi to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to github.com/ghapi:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com/ghapi"
    - "github.com"
    - "pypi.org"
    - "github.com/ghraw"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 60.3 AIC · ⌖ 7.34 AIC · ⊞ 23.5K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

Non-blocking from my pass: the repository-level strict precedence is wired through the compiler paths I checked, and I didn't find a changed-line regression that clearly warrants blocking this PR.

Reviewed themes
  • Repository aw.json strict enforcement now wins over per-workflow frontmatter in both CLI orchestration and compiler-level validation paths.
  • The added schema/tests cover the intended strict: true acceptance and strict: false rejection behavior.
  • I discarded the sub-agent output because it referenced unrelated files outside this PR.

Warning

Firewall blocked 4 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com/ghapi
  • github.com
  • pypi.org
  • github.com/ghraw

[!TIP]
github.com/ghapi is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding github.com/ghapi to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to github.com/ghapi:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com/ghapi"
    - "github.com"
    - "pypi.org"
    - "github.com/ghraw"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 60.3 AIC · ⌖ 7.34 AIC · ⊞ 23.5K
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /codebase-design and /grill-with-docs — requesting changes on a duplicated repo-config load path, unrelated lint suppressions, and a stale doc comment.

📋 Key Themes & Highlights

Key Themes

  • Duplicated config loading: applyWorkspaceStrictMode in compile_orchestrator.go re-implements git-root discovery + aw.json loading instead of reusing the compiler's cached loadRepoConfig(), causing aw.json to be parsed twice and silently swallowing load errors that the rest of the compiler surfaces as warnings.
  • Unrelated lint suppressions: Two (nolint/redacted):largefunc additions (CompileWorkflows, validatePullRequestTargetTrigger) aren't explained by this PR's small diffs — one function actually got shorter.
  • Stale documentation: The pull_request_target_validation.go doc comment still claims frontmatter strict: false always disables the dangerous-trigger warning, which is no longer true when the repo enforces strict mode.
  • Test gap: precedence tests cover aw.json strict: true/false, but not the "aw.json omits strict" default case combined with frontmatter strict: false.

Positive Highlights

  • ✅ Schema correctly rejects strict: false at the repo-config level via "const": true.
  • ✅ effectiveStrictMode centralizes precedence cleanly and pull_request_target_validation.go now reuses it instead of duplicating logic.
  • ✅ Both integration and unit tests were added for the new override behavior.

@copilot please address the review comments above.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 132.9 AIC · ⌖ 17.7 AIC · ⊞ 10.3K
Comment /matt to run again

Comments that could not be inline-anchored

pkg/cli/compile_orchestrator.go:165

[/codebase-design] applyWorkspaceStrictMode re-derives gitRoot and calls workflow.LoadRepoConfig directly, duplicating (and bypassing the cache/warning behavior of) Compiler.loadRepoConfig(), which is used everywhere else (compiler_yaml_policy.go, configureGHESCompatibility). This means aw.json is now parsed twice per compile run, and a malformed aw.json here silently falls through (err == nil check discards the error) instead of surfacing the same warning the compiler emi…

pkg/cli/compile_orchestrator.go:21

[/codebase-design] The added (nolint/redacted):largefunc on CompileWorkflows is unrelated to this PR's change (a one-line call to applyWorkspaceStrictMode doesn't meaningfully grow the function). Suppressing a linter on an unrelated function inside a feature PR hides future large-function growth from review and should be justified/added separately if the function was already over the threshold before this change.

<details>
<summary>💡 Suggestion</summary>

Drop this nolint from this …

pkg/workflow/pull_request_target_validation.go:65

[/codebase-design] Same concern as in compile_orchestrator.go: this (nolint/redacted):largefunc addition isn't explained by the actual diff (which removes lines from this function, replacing 6 lines with 1 via c.effectiveStrictMode(...)). Adding a lint suppression to a function you just made shorter is confusing and should be dropped unless there's a broader repo-wide reason.

@copilot please address this.

pkg/workflow/pull_request_target_validation.go:14

[/grill-with-docs] The file-level doc comment still says "Workflows can opt out by setting strict: false in frontmatter," but this PR makes that statement false when repository-level aw.json sets strict: true (frontmatter opt-out is now overridden). This stale doc will mislead the next reader trying to understand precedence.

<details>
<summary>💡 Suggested fix</summary>

Update the comment to mention the new precedence, e.g.: "Workflows can opt out by setting strict: false in frontmatt…

pkg/workflow/repo_config_test.go:65

[/tdd] Good coverage for strict: true/strict: false at the LoadRepoConfig layer, but there's no test exercising the actual precedence behavior end-to-end for a workflow that sets strict: false in frontmatter while aw.json doesn't set strict at all (i.e. confirming the default repo-config path — no strict key present — still lets frontmatter strict: false through). Without this, a future regression that treats "key absent" the same as "strict: true" would go unnoticed.

@co…

@gh-aw-bot

Copy link
Copy Markdown
Collaborator
pr-sous-chef

@copilot Please take the next forward-progress pass on PR #59253.

  • Recent review activity flagged follow-up work around strict-mode handling paths and related cleanup.
  • Please address the current review feedback, refresh the branch if appropriate, and run the pr-finisher skill on the latest HEAD.
  • When handing back to maintainers, state clearly whether any blocker remains beyond code changes and routine CI.

Generated by PR Sous Chef: https://github.com/github/gh-aw/actions/runs/34142938266

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 42.9 AIC · ⌖ 8.65 AIC · ⊞ 8.9K · ◷
Comment /souschef to run again

@pelikhan
pelikhan merged commit 25fb43e into main Sep 7, 2026
34 of 35 checks passed
@pelikhan
pelikhan deleted the copilot/add-strict-field-in-aw-json branch September 7, 2026 16:40
Copilot stopped work on behalf of gh-aw-bot due to an error September 7, 2026 16:40
Copilot AI requested a review from gh-aw-bot September 7, 2026 16:40
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.88.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants