Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
58521aa
Initial plan
Copilot Sep 25, 2026
b3d36a9
feat(engine): add runtime Copilot model controls
Copilot Sep 25, 2026
5cff95b
docs(engine): document runtime model controls
Copilot Sep 25, 2026
3fd4545
test(shell): validate runtime model metadata script
Copilot Sep 25, 2026
c2d4cf2
fix(engine): harden runtime model selection
Copilot Sep 25, 2026
d34ee67
style(engine): use raw string for runtime model preamble
Copilot Sep 25, 2026
cd04b82
test(engine): cover runtime model feedback
Copilot Sep 26, 2026
2de9d8b
fix(engine): resolve detection model in detection scope
jamesadevine Sep 30, 2026
407d67c
fix(engine): align runtime model selection
jamesadevine Oct 1, 2026
0d2007a
fix(compile): tolerate missing agent metadata
jamesadevine Oct 1, 2026
4cc781d
fix(workflows): inherit parent models for sub-agents
jamesadevine Oct 1, 2026
31a3bdb
refactor(engine): invoke copilot through bundled harness
jamesadevine Oct 1, 2026
a12235c
fix(test): repair copilot invoker smoke fixtures
jamesadevine Oct 1, 2026
22768d5
fix(engine): harden copilot invoker boundaries
jamesadevine Oct 1, 2026
2274fef
fix(compile): isolate Copilot control plane from AWF
jamesadevine Oct 4, 2026
67acc66
fix(compile): harden Copilot invocation review gaps
jamesadevine Oct 5, 2026
ce0ade7
fix(compile): preserve Copilot execution failures
jamesadevine Oct 5, 2026
36ba851
test(compile): scope MCPG command assertions
jamesadevine Oct 5, 2026
e1ee471
test(ado-script): cover Copilot protocol edge cases
jamesadevine Oct 6, 2026
fb4e64b
test(smoke): verify live runtime model variables
jamesadevine Oct 6, 2026
cfde682
test(smoke): retain detection in runtime model cases
jamesadevine Oct 6, 2026
6edf0ed
test(smoke): assert concrete runtime model overrides
jamesadevine Oct 6, 2026
42400dd
fix(smoke): encode queue variables as build parameters
jamesadevine Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/workflows/copilot-cli-safeoutputs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ on:
pull_request:
paths:
- "src/**"
- "scripts/ado-script/**"
- "tests/**"
- "Cargo.toml"
- "Cargo.lock"
Expand Down Expand Up @@ -62,6 +63,13 @@ jobs:
mcpg:MCPG_VERSION:src/compile/common.rs
VERSIONS

- name: Build Copilot controller and runner bundles
run: |
set -euo pipefail
npm --prefix scripts/ado-script ci
npm --prefix scripts/ado-script run build:copilot-controller
npm --prefix scripts/ado-script run build:copilot-runner

- name: Install compiler-pinned GitHub Copilot CLI
run: |
set -euo pipefail
Expand Down Expand Up @@ -108,9 +116,12 @@ jobs:
- name: Run handwritten AWF + Copilot + SafeOutputs contract
env:
ADO_AW_COPILOT_CLI_ARTIFACT_DIR: ${{ runner.temp }}/copilot-cli-safeoutputs
ADO_AW_COPILOT_CLI_CONTROL_DIR: ${{ runner.temp }}/copilot-cli-control
ADO_AW_BIN: ${{ github.workspace }}/target/debug/ado-aw
AWF_BIN: ${{ runner.temp }}/bin/awf
COPILOT_BIN: ${{ runner.temp }}/bin/copilot
COPILOT_CONTROLLER_BUNDLE: ${{ github.workspace }}/scripts/ado-script/copilot-controller.js
COPILOT_RUNNER_BUNDLE: ${{ github.workspace }}/scripts/ado-script/copilot-runner.js
AWF_VERSION: ${{ steps.versions.outputs.awf }}
MCPG_VERSION: ${{ steps.versions.outputs.mcpg }}
run: bash tests/awf-copilot-safeoutputs/run.sh
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-sous-chef.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 0 additions & 1 deletion .github/workflows/pr-sous-chef.md
Original file line number Diff line number Diff line change
Expand Up @@ -368,7 +368,6 @@ recommendations visible; wrap verbose detail in
## agent: `pr-processor`
---
description: Decides skip/nudge actions for a single pull request using a minimal number of API calls
model: small
---
You are given one PR number and its compact metadata. Decide what should happen
to it, using as few tool calls as possible.
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/review-rust.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 0 additions & 1 deletion .github/workflows/review-rust.md
Original file line number Diff line number Diff line change
Expand Up @@ -169,7 +169,6 @@ and the themes in a `<details>` block.
## agent: `rust-critic`
---
description: Hostile first-pass Rust reviewer that mines merge-blocking defects from changed lines
model: small
---
You are a hostile senior Rust reviewer performing a first-pass audit.

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/review-typescript.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 0 additions & 1 deletion .github/workflows/review-typescript.md
Original file line number Diff line number Diff line change
Expand Up @@ -171,7 +171,6 @@ wrong output; otherwise `COMMENT`.
## agent: `ts-critic`
---
description: Hostile first-pass TypeScript reviewer for bundled Azure DevOps runtime helpers
model: small
---
You are a hostile senior TypeScript reviewer performing a first-pass audit of
code that is bundled and executed on Azure DevOps build agents.
Expand Down
12 changes: 10 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -319,6 +319,9 @@ fail-closed and only pauses when the agent actually proposed a reviewed output.
│ ├── conclusion/ # Conclusion-job reporter source (bundled to conclusion.js)
│ ├── approval-summary/ # Safe-outputs summary renderer (bundled to approval-summary.js; end-of-Agent-job summary tab)
│ ├── github-app-token/ # GitHub App token minter (bundled to github-app-token.js; mints installation token in Agent + Detection when engine.github-app-token is set)
│ ├── copilot-shared/ # Strict schema-v2 request/prepared/result protocol, model resolution, typed argv/env, atomic writes shared by the controller and runner
│ ├── copilot-controller/ # Trusted host control plane (bundled to copilot-controller.js): prepare + read-result only; never mounted into AWF
│ ├── copilot-runner/ # Sandbox-only process harness (bundled to copilot-runner.js): run only, self-removal, typed argv, signal forwarding, exact exit propagation
│ ├── executor-e2e/ # Stage 3 safe-output E2E test harness (not a bundle; runs deterministic scenarios against a real ADO project and files a GitHub issue on failure)
│ ├── compiler-smoke-e2e/ # Smoke E2E orchestrator (not a bundle): stages each case in `tests/smoke/cases.json` to the fixed `.smoke/pipeline.yml` path on its own per-case `ado-aw-mirror` ref, queues it against its credential *lane* definition, and asserts they go green. Two modes via `SMOKE_COMPILER_SOURCE`: `candidate` (compiler built from this commit, pinned pipeline-artifact) and `released` (latest release asset, release URLs required). Built to `test-bin/` by `build:compiler-smoke-e2e`, listed in `NON_BUNDLE_DIRS`.
│ ├── prepare-pr-base/ # create-pull-request preparer (bundled to prepare-pr-base.js): Agent mode uses ADO diff metadata + bounded fallback; SafeOutputs fetches the target tip; cross-org targets use isolated credentials + exact remote matching
Expand Down Expand Up @@ -463,7 +466,8 @@ index to jump to the right page.
(`gate.js`, `import.js`, the execution-context `exec-context-*.js`
bundles, `conclusion.js`, `approval-summary.js`,
`github-app-token.js`, `prepare-pr-base.js`, and
`azure-wif-refresh.js`), schemars-driven
`azure-wif-refresh.js`, `copilot-controller.js`, `copilot-runner.js`),
schemars-driven
type codegen, the A2 design decision, the bundle env contract
modelled in `src/compile/ado_bundle.rs`, and the `trigger-e2e/`
gate-spec drift guard (kept in sync via `export-fact-catalog`).
Expand Down Expand Up @@ -533,7 +537,11 @@ Following the gh-aw security model:
assume deletion will make the exchange safe. This trap has caused repeated
incorrect designs in credential-bearing work. Stream private material over
stdin or use a container-private volume; publish only intentionally public
files (for example the interception CA certificate) under `/tmp`.
files (for example the interception CA certificate) under `/tmp`. The same
boundary applies to integrity, not only secrecy: after AWF starts, never
execute host-side code from `/tmp` or treat `/tmp` metadata as authoritative.
Copy trusted executables and results beneath `$(Agent.TempDirectory)` before
AWF and consume only those private copies afterward.
3. **Tool Allow-listing**: Agents have access to a limited, controlled set of
tools — see [`docs/tools.md`](docs/tools.md) and
[`docs/mcp.md`](docs/mcp.md).
Expand Down
Loading
Loading