Skip to content

Prevent base config restore from clobbering an external root checkout - #65069

Merged
pelikhan merged 12 commits into
mainfrom
copilot/restore-agent-config-folders
Oct 3, 2026
Merged

pelikhan merged 12 commits into
mainfrom
copilot/restore-agent-config-folders

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

In a multi-checkout workflow, the generated restore step could replace the root target repository’s tracked agent-config files with a snapshot from the workflow repository. The preceding PR checkout step also operates on the workspace root.

  • Checkout safety: Suppress both generated steps when the root checkout cannot be confirmed as github.repository. Preserve them when the workflow repository is at root.
  • Regression coverage: Cover an external target at root with the workflow repository in a subpath, plus the same-repository root layout.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 24.5 AIC · ⌖ 8.62 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/37067406087

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 26.8 AIC · ⌖ 8.9 AIC · ⊞ 9.2K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 20.2 AIC · ⌖ 8.51 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 58.6 AIC · ⌖ 8.77 AIC · ⊞ 9.9K · ◷
Comment /souschef to run again


https://github.com/github/gh-aw/actions/runs/37090420907 -->

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 58.6 AIC · ⌖ 8.77 AIC · ⊞ 9.9K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 91.8 AIC · ⌖ 8.59 AIC · ⊞ 9.9K · ◷
Comment /souschef to run again


https://github.com/github/gh-aw/actions/runs/37093662552 -->

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 91.8 AIC · ⌖ 8.59 AIC · ⊞ 9.9K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 81.2 AIC · ⌖ 8.71 AIC · ⊞ 10.1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 2, 2026 17:23
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix restoring agent config folders from base branch Prevent base config restore from clobbering an external root checkout Oct 2, 2026
Copilot AI requested a review from pelikhan October 2, 2026 17:33
@pelikhan
pelikhan marked this pull request as ready for review October 2, 2026 17:37
Copilot AI balanced review requested due to automatic review settings October 2, 2026 17:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Custom checkout steps and cross-platform root-path normalization leave clobbering scenarios unresolved.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Prevents generated PR checkout and config-restore steps from overwriting an external root checkout.

Changes:

  • Detects whether the workspace root belongs to github.repository.
  • Adds multi-checkout regression coverage.
File Description
pkg/​workflow/​pr.go Gates generated PR checkout and restore steps.
pkg/​workflow/​pr_test.go Tests external and same-repository root layouts.

Comment thread pkg/workflow/pr.go Outdated
Comment on lines +27 to +28
for _, checkout := range data.CheckoutConfigs {
if checkout == nil || (filepath.Clean(checkout.Path) != "." && !strings.Contains(checkout.Path, "${{")) {

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a ContainsCheckout guard in pkg/workflow/pr.go and a compile regression confirming both generated steps are omitted for an external custom checkout. The affected lockfiles were recompiled. Commit: 38ae3bb.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Branch refresh has been requested for this PR. Please verify the updated branch state and run the pr-finisher skill before handing off.

Generated by 👨🍳 PR Sous Chef
Comment /souschef to run again

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 24.5 AIC · ⌖ 8.62 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Branch refresh has been requested for this PR. Please verify the updated branch state and run the pr-finisher skill before handing off.

Generated by [👨🍳 PR Sous Chef](https://githu...

Verified the refreshed branch and completed the local PR-finisher checks. The custom-checkout review finding is fixed in 38ae3bb and replied to; the review thread remains unresolved because the available GitHub tools do not expose thread resolution. CI has no checks on the new head yet, and parallel CodeQL validation timed out.

Copilot AI requested a review from gh-aw-bot October 2, 2026 18:32
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please take another pass on this PR. Please refresh the branch if needed, address any outstanding review feedback, and then run the pr-finisher skill before handing back to maintainers.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 22.3 AIC · ⌖ 8.59 AIC · ⊞ 9.4K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Please take another pass on this PR. Please refresh the branch if needed, address any outstanding review feedback, and then run the pr-finisher skill before handing back to maintainers.

...

Verified the branch is based on the current main and addressed the outstanding path-normalization finding in 4318ca1. Root detection now normalizes backslashes before cleaning, with a regression for an external checkout at \., while the existing custom-checkout guard remains in place. make fmt, make lint, focused tests, make test-unit, make test, make recompile, and make agent-report-progress passed. The review thread is outdated but remains unresolved; the available tools do not support resolving it. Post-push CI needs a maintainer-triggered rerun.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please take another pass on this PR. Please refresh the branch if needed, address any outstanding review feedback, and then run the pr-finisher skill before handing back to maintainers.

Generated by PR Sous Chef for #65069: Prevent base config restore from clobbering an external root checkout

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 27.1 AIC · ⌖ 8.64 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Please take another pass on this PR. Please refresh the branch if needed, address any outstanding review feedback, and then run the pr-finisher skill before handing back to maintainers.

Ge...

Verified the branch is current at 4318ca1 and clean; no refresh or additional code change was needed. The existing ContainsCheckout fix and path-normalization regression cover the review feedback, and make fmt, make lint, make test-unit, make test, and make recompile all pass. The Copilot check is still running, and the review thread remains unresolved because this environment has no thread-resolution API or authenticated gh access.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please take another pass on this PR. Review feedback appears addressed in follow-up replies, but the review thread is still unresolved. Please verify the resolution on the current head, resolve any remaining thread feedback, refresh the branch if needed, and then run the pr-finisher skill before handing back to maintainers.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 26.8 AIC · ⌖ 8.9 AIC · ⊞ 9.2K · ◷
Comment /souschef to run again

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Please take another pass on this PR. Review feedback appears addressed in follow-up replies, but the review thread is still unresolved. Please verify the resolution on the current head, resol...

Verified current HEAD 6ef079f includes the fixes for the outstanding checkout/path-normalization feedback and is based on the current PR base; the worktree is clean. The existing substantive thread reply is present, but I cannot resolve the thread because the available GitHub tools expose no thread-resolution operation and gh has no GH_TOKEN in this session. make fmt, make lint, make test-unit, and make recompile passed. make test is blocked by inherited failures from main commit b874bb5 (fprintferrorunchecked is registered but missing from the linter docs/CI registry). CI has one successful security check and one Copilot check still in progress.

@pelikhan

pelikhan commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

@copilot add a frontmatter field that allows to completely turn off the generation of this step. Under checkout.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot add a frontmatter field that allows to completely turn off the generation of this step. Under checkout.

Added checkout.pull-request: false to suppress the generated PR checkout and its base-config snapshot/restore steps while leaving normal checkout enabled. Parser, schema, docs, and regression tests are updated in 4b02574.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please take another pass on this PR. Review feedback appears addressed in follow-up replies, but the review thread is still unresolved. Please verify the current head, resolve any remaining thread feedback, refresh the branch if needed, and then run the pr-finisher skill before handing back to maintainers.

Generated by 👨🍳 PR Sous Chef
Comment /souschef to run again

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 17.7 AIC · ⌖ 8.68 AIC · ⊞ 9.2K · ◷
Comment /souschef to run again

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Please take another pass on this PR. Review feedback appears addressed in follow-up replies, but the review thread is still unresolved. Please verify the current head, resolve any remaining t...

Verified current head af30c7d matches the remote branch and includes current main; the worktree remains clean. The review concern is addressed by the existing substantive reply and fix, and the thread is outdated, but this session exposes no thread-resolution operation and gh is unauthenticated, so I could not resolve it. make fmt, make lint, make test-unit, focused checkout regressions, and make recompile passed. make test remains blocked by the unrelated existing fprintferrorunchecked linter documentation/CI registry mismatch. Current CI has action_required runs with no jobs plus a Copilot check in progress.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please take another pass on this PR. Review feedback appears addressed in follow-up replies, but the thread is still unresolved. Please verify the current head, resolve any remaining thread feedback, refresh the branch if needed, and then run the \ skill before handing back to maintainers.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 58.6 AIC · ⌖ 8.77 AIC · ⊞ 9.9K · ◷
Comment /souschef to run again

…-config-folders

# Conflicts:
#	.github/workflows/unbloat-docs.lock.yml

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Please take another pass on this PR. Review feedback appears addressed in follow-up replies, but the thread is still unresolved. Please verify the current head, resolve any remaining thread f...

Refreshed the branch with latest main and published merge commit 1dc0b05; the regenerated workflow lock compiles and the prior full-test failure is resolved upstream. make fmt, make lint, make test-unit, make test, and make recompile pass. The final make agent-report-progress gate still flags custom-linter warnings on unchanged lines in the touched checkout files. The Copilot review concern is already fixed and replied to, but I cannot resolve the thread because no thread-resolution operation is available here. PR state is open and now based on latest main, but GitHub reports it blocked.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot please take another pass on this PR.

GitHub still shows an unresolved review thread that already has a follow-up response:

Please resolve any remaining open review threads, refresh the branch if GitHub offers it, and run the pr-finisher skill before handing this back to maintainers.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 91.8 AIC · ⌖ 8.59 AIC · ⊞ 9.9K · ◷
Comment /souschef to run again

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

@copilot please take another pass on this PR.

GitHub still shows an unresolved review thread that already has a follow-up response:...

Verified the pushed head 92ace3a is clean, matches the remote branch, and includes the current PR base; no refresh was needed. The outdated checkout finding is addressed by the existing fix and substantive reply. make fmt, make lint, make test-unit, make test, and make recompile pass. I could not resolve the thread: this session has no thread-resolution operation and gh is unauthenticated. The latest Actions run is action_required with no jobs; the Copilot check is still in progress.

@pelikhan
pelikhan merged commit c98b6dd into main Oct 3, 2026
22 checks passed
@pelikhan
pelikhan deleted the copilot/restore-agent-config-folders branch October 3, 2026 13:34
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Restore agent config folders from base branch clobbers the root checkout when it is not github.repository

4 participants