Skip to content

Preserve repo-memory files during safe-output validation - #65462

Merged
pelikhan merged 4 commits into
mainfrom
copilot/deep-report-fix-push-repo-memory
Oct 4, 2026
Merged

pelikhan merged 4 commits into
mainfrom
copilot/deep-report-fix-push-repo-memory

Conversation

Copilot AI commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

push_repo_memory validation could delete files excluded by persistence filters, leaving the working directory empty while reporting success. Validation should measure eligible changes without removing the agent’s files.

  • Validation and staging: Apply extension and glob filters to the validation set and stage only eligible paths; leave excluded files untouched.
  • Regression coverage: Verify excluded files—including legacy-path copies—remain unchanged after validation.
if (!isEligibleFile(relPath)) {
  continue; // Exclude from validation without deleting from disk
}

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix silent wipe of repo-memory working directory in push_repo_memory Preserve repo-memory files during safe-output validation Oct 4, 2026
Copilot AI requested a review from pelikhan October 4, 2026 02:35
@pelikhan
pelikhan marked this pull request as ready for review October 4, 2026 03:19
Copilot AI balanced review requested due to automatic review settings October 4, 2026 03:19
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Lean already. Ship.

Generated by Ponytail Reviewer for #65462

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer failed during the skills-based review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

🔎 Code quality review by PR Code Quality Reviewer

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Excluded files still affect formatting, custom validation, and patch-size measurement when already staged.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Addresses #65458 by replacing destructive repo-memory filtering with eligibility checks during safe-output validation.

Changes:

  • Filters file counting and staging without deleting excluded files.
  • Adds preservation regressions, including legacy-path copies.
File Description
actions/​setup/​js/​safe_outputs_handlers.test.cjs Verifies excluded files survive validation.
actions/​setup/​js/​safe_outputs_handlers.cjs Applies eligibility checks instead of deleting files.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +1845 to +1846
const { compiledPatterns } = compileFileGlobPatterns(fileGlobFilter);
const isEligibleFile = relativePath => isMemoryFileEligible(relativePath, allowedExtensions, compiledPatterns).eligible;

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated formatJSONFiles to receive the eligibility predicate and skip excluded JSON before reading or rewriting it. Regression coverage confirms excluded JSON remains byte-for-byte unchanged while eligible JSON formats successfully. Fixed in 1371073.

Comment on lines +1899 to +1901
if (!isEligibleFile(relPath)) {
continue;
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Custom validation now runs on a temporary view containing only eligible files, preserving paths relative to the memory root and the validator's read-only check. Added coverage for malformed excluded JSON and read-only behavior. Fixed in 1371073.

if (filesToStage.length > 0) {
execGitSync(["add", "--sparse", "--all", "--", ...filesToStage.map(file => `:(literal)${file}`)], { cwd: memoryDir, stdio: "pipe" });
}
patchSizeBytes = getStagedPatchDiffSizeBytes({ execGitSyncFn: execGitSync, cwd: memoryDir });

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Patch sizing now scopes git diff --cached to literal eligible pathspecs, including eligible files already staged, and returns zero when none qualify without changing excluded index entries. Added a pre-staged excluded-file regression. Fixed in 1371073.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-10-04T03:22:52Z
review_event: REQUEST_CHANGES
top_themes:
  - excluded repo-memory files still affect format_json/custom validation
files_reviewed:
  - actions/setup/js/safe_outputs_handlers.cjs
  - actions/setup/js/safe_outputs_handlers.test.cjs
comment_count: 1

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 52.1 AIC · ⌖ 7.18 AIC · ⊞ 19.4K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes

The preflight now preserves ineligible repo-memory files, but it still lets those excluded files participate in later validation phases, so push_repo_memory can fail or rewrite content that the eventual push would ignore.

Blocking theme

allowed_extensions/file_glob are now applied to the file-count and staging pass only. formatJSONFiles(...) still walks the whole directory, and validation.script still receives the full memoryDir. In practice that means a legacy or sidecar file outside the persistence filter can still be reformatted or make custom validation fail, even though the later push path would drop it.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 52.1 AIC · ⌖ 7.18 AIC · ⊞ 19.4K
Comment /review to run again

Comment on lines +1843 to +1846
// Persistence filters apply to validation and staging, but validation must
// not delete files from the agent's working directory.
const { compiledPatterns } = compileFileGlobPatterns(fileGlobFilter);
const isEligibleFile = relativePath => isMemoryFileEligible(relativePath, allowedExtensions, compiledPatterns).eligible;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This still lets excluded files change or fail validation, because only the size/count scan is filtered while formatJSONFiles(...) and the custom validator still walk the entire memory directory.

💡 Apply the same persistence filter to every validation phase

With this patch, a file excluded by allowed_extensions or file_glob is preserved on disk, but it is still visible to later validation steps. format_json will still reformat excluded *.json files, and validation.script still receives the full memoryDir, so it can fail on files the later push would silently drop. That means push_repo_memory can still reject or mutate content outside the effective persistence set.

A safe fix is to keep the original files in place, but run formatting/custom validation against the same filtered view used for counting and staging.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All persistence filters now apply to formatting, custom validation, size/count checks, patch measurement, and staging; excluded files remain untouched in the working tree and index. Fixed in 1371073.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed with impeccable critique/audit lens (closest fit for this bug_fix/refactor_cleanup change, applied as a correctness/robustness review since there's no UI surface).

What changed: push_repo_memory validation no longer deletes ineligible files (via filterIneligibleMemoryFiles) before scanning. Instead, isMemoryFileEligible is applied inline during the scanDir walk to exclude ineligible files from the counted/validated set, and only eligible + already-tracked-eligible paths are staged with git add --sparse --all -- :(literal).... This matches the PR's stated goal: validation measures eligible changes without destructively removing files from the agent's working directory.

Verification performed:

  • Walked the diff against memory_file_eligibility.cjs and push_repo_memory.cjs to confirm the push job's own filtering (filterIneligibleMemoryFiles there) is unchanged and still the single place where ineligible files are actually dropped before a push — so excluded files remain in the agent's checkout but are still correctly never pushed.
  • Confirmed git ls-files -z + explicit :(literal) pathspecs correctly stage both new eligible files and already-tracked eligible files, and that an untracked/deleted file under an eligible pattern is handled consistently (git add --all tracks deletions too).
  • Ran actions/setup/js/safe_outputs_handlers.test.cjs — all push_repo_memory tests pass, including the new regression test asserting mixed-eligibility directories keep excluded files on disk after validation.

No blocking or high-signal issues found; the change is well-scoped, the explanation is clear, and test coverage directly targets the described bug (#65458). Nothing actionable to flag inline.

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · copilot · sonnet50 · 143.6 AIC · ⌖ 13.1 AIC · ⊞ 8.1K

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (actions/setup/js/safe_outputs_handlers.cjs:1846): With format_json: true and file_glob: "state.json", an excluded legacy.json is still processed by formatJSONFiles(memoryDir, maxFileSize) before eligibility is checked. It can be rewritten or cause validation to fail if its formatted size exceeds the limit. Pass the eligibility predicate into the formatter and skip excluded files before reading or writing them. Add a regression asserting excluded JSON remains byte-for-byte unchanged and does not affect validation. - Preserve repo-memory files during safe-output validation #65462 (comment)
  3. Review (actions/setup/js/safe_outputs_handlers.cjs:1901): This filters the built-in size/count checks, but runCustomMemoryValidation still receives the unfiltered memoryDir. With file_glob: "state.json", a validator parsing all root-level JSON files also reads an excluded malformed legacy.json and can reject valid memory. The push job removes excluded files before invoking the validator, so the two paths now validate different content. Run custom validation against an eligible-only temporary view while preserving the live files and the validator's relative-path and read-only behavior. - Preserve repo-memory files during safe-output validation #65462 (comment)
  4. Review (actions/setup/js/safe_outputs_handlers.cjs:1979): Restricting git add leaves previously staged excluded files in the index. getStagedPatchDiffSizeBytes then runs unrestricted git diff --cached, so an excluded file staged by the agent can exceed max_patch_size and reject otherwise valid memory. Scope patch measurement to eligible paths, returning zero when there are none, without changing excluded files or their index entries. Add regression coverage for a previously staged excluded file. - Preserve repo-memory files during safe-output validation #65462 (comment)
  5. Review (actions/setup/js/safe_outputs_handlers.cjs:1846): This still lets excluded files change or fail validation, because only the size/count scan is filtered while formatJSONFiles(...) and the custom validator still walk the entire memory directory. - Preserve repo-memory files during safe-output validation #65462 (comment)
  6. Fix failing check agent (FAILURE): https://github.com/github/gh-aw/actions/runs/37173732058/job/111352215721.

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: fcca3aa
Sous-chef work: 34f38971738f6a752a646bd7797a6c8d47fb096e4eb6f91e946a91255433c8c4 3611649bac49ae0e75260316713b131a6d18335a367e1793d3362214db911708 52262a386f74e115b6d8ab8cf9b04e81b3632cb75d24da5125fe94cd08046d0f b566c98e57ec6a6bc8707578e6bf2960e9d36600a0dd07a6781e6ddd1c4558b5 cb4bada102f8e0d85e144b94e0be1d91df58783d8e3a1d83356ec75da5a8c8b3
Sous-chef state: 08632c9653682d9da443a0fe99bb69560d7612a0add8ce10322d214b2313bca0

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 8.35 AIC · ⌖ 13.4 AIC · ⊞ 3K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 4, 2026 08:57
…ix-push-repo-memory

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Copilot AI requested a review from gh-aw-bot October 4, 2026 09:16
@pelikhan
pelikhan merged commit 2ddff38 into main Oct 4, 2026
12 checks passed
@pelikhan
pelikhan deleted the copilot/deep-report-fix-push-repo-memory branch October 4, 2026 13:02
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deep-report] push_repo_memory safe-output silently wipes the repo-memory working directory instead of validating it (data loss)

4 participants