Skip to content

Restore ledger push handoff and correct smoke projection checks - #65405

Merged
pelikhan merged 5 commits into
mainfrom
copilot/fix-push-ledger-changes
Oct 3, 2026
Merged

pelikhan merged 5 commits into
mainfrom
copilot/fix-push-ledger-changes

Conversation

Copilot AI commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Ledger pushes failed because the safe-output job did not load the ledger handler, leaving push_ledger_changes without a transaction artifact. Ledger smokes also lacked a usable SQLite query runtime and expected new writes in a projection created before those writes were persisted.

  • Push handoff: Pass standalone ledger configuration to the safe-output handler so it emits validated transactions. Recompile affected workflows.
  • Smoke checks: Configure a Python SQLite runtime and verify persisted records on subsequent runs rather than expecting same-run visibility.
  • Regression coverage: Assert that the handler receives the same ledger definitions as the agent.

Copilot AI and others added 2 commits October 3, 2026 19:20
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix push ledger changes and ledger smoke failures Restore ledger push handoff and correct smoke projection checks Oct 3, 2026
Copilot AI requested a review from pelikhan October 3, 2026 19:24
@pelikhan
pelikhan marked this pull request as ready for review October 3, 2026 19:44
Copilot AI balanced review requested due to automatic review settings October 3, 2026 19:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The zero-message ledger path still omits the required transaction artifact, and the unrelated skill edit removes work-queue routing.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Restores standalone ledger transaction handoff and makes ledger smoke checks use persisted, cross-run projections.

Changes:

  • Adds standalone ledger definitions to safe-output handler configuration with regression coverage.
  • Adds Python SQLite runtimes and corrects smoke-test projection expectations.
  • Regenerates all affected workflow lock files.
File Description
pkg/​workflow/​safe_outputs_config_runtime.go Wires ledger handlers into runtime configuration.
pkg/​workflow/​ledger_test.go Verifies handler ledger definitions.
.github/​workflows/​smoke-repo-memory-ledger.md Updates runtime and cross-run checks.
.github/​workflows/​smoke-repo-memory-ledger.lock.yml Regenerates the workflow.
.github/​workflows/​smoke-builtin-ledgers.md Adds Python-based SQLite checks.
.github/​workflows/​smoke-builtin-ledgers.lock.yml Regenerates the workflow.
.github/​workflows/​daily-mcp-concurrency-analysis.lock.yml Adds ledger handler configuration.
.github/​workflows/​daily-caveman-optimizer.lock.yml Adds ledger handler configuration.
.github/​workflows/​daily-awf-spec-compiler-surfacing.lock.yml Adds ledger handler configuration.
.github/​workflows/​copilot-centralization-optimizer.lock.yml Adds ledger handler configuration.
.github/​workflows/​audit-workflows.lock.yml Adds ledger handler configuration.
.github/​skills/​agentic-workflows/​SKILL.md Reorders one reference but removes work-queue routing.

if handlerConfig := buildLedgerRequestCompactionHandlerConfig(data.LedgerConfig); handlerConfig != nil {
config[ledgerRequestCompactionHandlerKey] = handlerConfig
}
addStandaloneLedgerConfigs(config, data.LedgerConfig)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implemented in actions/setup/js/safe_output_handler_manager.cjs: empty-message runs now finalize the configured ledger append handler and write the empty versioned transaction artifact. Added regression coverage. Commit: 6411e8a.

Comment thread .github/skills/agentic-workflows/SKILL.md
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer failed during the skills-based review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Lean already. Ship.

Generated by Ponytail Reviewer for #65405

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

Review submission was blocked: submit_pull_request_review failed twice with a permission denial, so no GitHub write was emitted.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-10-03T20:01:50Z
review_event: REQUEST_CHANGES
top_themes:
  - ledger handoff still breaks empty-message runs
  - work-queue routing hint removed from agentic-workflows skill
files_reviewed:
  - .github/skills/agentic-workflows/SKILL.md
  - .github/workflows/smoke-builtin-ledgers.md
  - .github/workflows/smoke-repo-memory-ledger.md
  - pkg/workflow/ledger_test.go
  - pkg/workflow/safe_outputs_config_runtime.go
comment_count: 0

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 73.1 AIC · ⌖ 7.18 AIC · ⊞ 20.2K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Impeccable Review Summary

This is primarily a Go-backend/infra fix (no UI), so standard Impeccable UX modes do not apply directly. I ran a correctness/reliability review instead, prioritizing security > correctness > reliability > maintainability, and verified findings against the actual source.

Verification performed

  • go build ./... — passes
  • go test ./pkg/workflow/... -run TestStandaloneLedgerWiresValidationArtifactAndPersistenceJobs — passes
  • Recompiled smoke-builtin-ledgers.md and smoke-repo-memory-ledger.md — generated .lock.yml matches committed files exactly (no diff)
  • Traced safe_output_handler_manager.cjs main() early-return path and ledger_append.cjs finalize() logic to confirm a pre-existing, still-open correctness gap

Findings

# Severity File Lines Issue Confidence
1 🟠 HIGH pkg/workflow/safe_outputs_config_runtime.go 108 Pre-existing, unaddressed gap: when a ledger-enabled run emits zero safe-output messages, safe_output_handler_manager.cjs returns before loadHandlers() runs, so ledger_append.finalize() never executes and ledger-transactions.json is never written — yet the safe-outputs job's artifact-upload step uses if-no-files-found: error, and buildPushLedgerChangesJob requires that artifact. This will fail any ledger-enabled run with no other safe outputs. 7/10
2 🟡 MEDIUM .github/skills/agentic-workflows/SKILL.md ~93-109 Reordering work-queue.md in the file list and re-adding its routing bullet is fine, but double-check this doesn't silently drop/duplicate the entry relative to upstream source:-managed content if this SKILL.md is provenance-managed elsewhere. 4/10

Both items were flagged by prior automated review comments already on this PR and remain valid/unresolved by the current diff — I did not duplicate them as new inline comments.

Scope-checked changes (no new issues)

  • pkg/workflow/safe_outputs_config_runtime.go: correctly reuses addStandaloneLedgerConfigs (shared with generateSafeOutputsConfig) instead of only calling buildLedgerRequestCompactionHandlerConfig, fixing the actual PR regression (missing ledger_append key in GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG). Verified via the new/updated test.
  • pkg/workflow/ledger_test.go: new assertion correctly validates ledger_append.ledgers is present and matches between config.json and the handler-manager env var.
  • Smoke workflow .md changes (Python runtime addition, cloud-hypervisor removal, projection-timing guidance correction) are internally consistent and match the .lock.yml diffs; recompilation confirms no drift.

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · copilot · sonnet50 · 131 AIC · ⌖ 13.3 AIC · ⊞ 8.1K

@pelikhan

pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

@copilot run pr-finished skill

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

@copilot fix chi failures

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor Author

@copilot fix chi failures

Fixed the stale JavaScript token-field and Go workflow-model test expectations in d826510; focused tests and the full local JavaScript and Go test runs pass. The remaining CI Go custom-lint failure reports 294 unchecked write results across 27 files, including files untouched by this PR, so it remains a repository-wide issue.

@copilot run pr-finished skill

Ran the PR finisher pass. Local formatting, lint, Go tests, JavaScript tests, and workflow recompilation pass. The PR is not merge-ready yet: its prior Go custom-lint check reports 294 unchecked write results across 27 files, and an in-scope review thread remains unresolved. CI on the pushed HEAD also needs a maintainer re-trigger. Test corrections are in d826510.

@pelikhan
pelikhan merged commit 31e5fda into main Oct 3, 2026
1 check passed
@pelikhan
pelikhan deleted the copilot/fix-push-ledger-changes branch October 3, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AW Top 10] 05 Fix push_ledger_changes and ledger smoke failures

3 participants