open-swe/agent
seahaven-openswe[bot] 0651de2ebf
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
feat: surface attributed PR creation failures (#180)
* feat: surface attributed PR creation failures

Port upstream #1659: adds PullRequestCreationGuardMiddleware that
blocks shell fallbacks (gh pr create, gh api /pulls, curl) when
open_pull_request fails, keeping failures visible. Also adds preflight
branch/repo visibility checks in open_pull_request with structured
failure payloads, and updates the prompt to forbid PR creation
fallbacks.

Refs: #134

* fix: fall back to core GitHub App scope when optional grants missing (#1701)

* fix: fall back to core GitHub App scope when optional grants missing

Proxy-token minting requested workflows:write and actions:read in the
permission set used for every sandbox. GitHub 422s a token request that
asks for a permission the installation hasn't granted, so any install
without workflows:write failed to mint a token and every run died in
before-agent setup with "GitHub App installation token is unavailable".

_resolve_proxy_token now walks a permission ladder (full -> +workflows ->
core) and returns the first scope that mints, recording the granted scope
so hourly proxy refreshes stay consistent. A missing optional grant now
degrades to the install-time core scope instead of failing the run;
workflow-file HITL pushes still require workflows:write and fail at push
time when it is absent.

* refactor: flatten proxy-token ladder loop with continue

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935)

Sea Haven fork deviation: upstream #1701 folds workflows:write into the
standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write
OUT of the standing permission ladder (RUNTIME = core + actions:read;
LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push
.github/workflows/* during normal operation. workflows:write is minted only
transiently by WorkflowPushGuardMiddleware for an approved HITL push and
dropped on restore, preserving token scope as a backstop for the workflow-
push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross
review); the standing-scope-carries-workflows:write bypass was blocked.

* fix(open-swe): harden proxy-token restore and mint error handling

Two low-severity follow-ups from the security review of the #1701 port.

Restore the recorded baseline scope after a workflow-push elevation instead
of a hardcoded RUNTIME. An install granted workflows:write but not actions:read
resolves its standing token to core; hardcoding RUNTIME on restore requested the
ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope"
error on every approved workflow push before the core fallback recovered. The
guard now captures the run's recorded scope before elevating (via the new
get_recorded_proxy_permissions) and restores exactly that, falling back to the
guaranteed core scope only when the baseline restore fails.

Classify installation-token mint failures. get_github_app_installation_token_
with_expiry now treats HTTP 422 (a permission the installation hasn't granted)
as the ladder's expected descend signal and keeps it at debug, while a non-422
failure (network/5xx/timeout) is surfaced at WARNING even when errors are
otherwise suppressed — so a transient blip no longer silently downscopes a whole
run under a debug-only trace. The reduced-scope warning no longer asserts a
missing grant as the sole cause.

* chore(triage): mark upstream #1701 landed on this branch

Ported via PR #181 as Option A (workflows:write kept out of the standing
proxy-token scope). Regenerated triage.md from triage.jsonl.

* fix: restructure PR creation to POST-first with diagnose-on-failure

Move preflight checks from an authoritative gate (before POST) to a
diagnostic run after POST failure. This avoids false-positive failures
when a just-pushed head branch is momentarily invisible to GitHub ref
endpoints, and eliminates 2-3 extra serial API round-trips on the happy
path.

Also drop unused _PR_CREATED_FALSE indirection and add a docstring to
pr_creation_guard acknowledging the fail-open detection design.

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-13 14:45:19 -04:00
..
dashboard feat(open-swe): re-add Fable 5 behind an admin toggle (Bedrock) (#172) 2026-07-10 14:05:20 -04:00
integrations chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
middleware feat: surface attributed PR creation failures (#180) 2026-07-13 14:45:19 -04:00
skills feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
tools feat: surface attributed PR creation failures (#180) 2026-07-13 14:45:19 -04:00
utils fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181) 2026-07-13 14:24:37 -04:00
webhooks feat: Re-land deferred upstream features on modular webhooks (#80) (#128) 2026-07-08 18:32:43 -04:00
analyzer.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
chat.py feat(open-swe): re-add Fable 5 behind an admin toggle (Bedrock) (#172) 2026-07-10 14:05:20 -04:00
ci_autofix.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
ci_monitor.py feat: CI auto-fix and PR babysitting for agent PRs (#1530) 2026-06-15 13:53:50 -07:00
completion.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
dispatch.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
encryption.py feat: support TOKEN_ENCRYPTION_KEY rotation via MultiFernet [closes AB-2323] (#1275) 2026-05-08 14:29:23 -07:00
prompt.py feat: surface attributed PR creation failures (#180) 2026-07-13 14:45:19 -04:00
reconcile.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
review_style_collector.py feat: PR review page (#1495) 2026-06-11 16:11:10 -07:00
review_style_guidance.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
reviewer.py feat(open-swe): re-add Fable 5 behind an admin toggle (Bedrock) (#172) 2026-07-10 14:05:20 -04:00
reviewer_diff.py fix: reviewer reviews full diff; fix review UI scroll + dark-mode composer (#1575) 2026-06-18 19:24:52 -07:00
reviewer_eval_store.py feat: Run reviewer eval in a GitHub Action; dashboard becomes read-only (#1556) 2026-06-16 19:38:36 -07:00
reviewer_findings.py fix: Reviews tab — anchored finding card, paginated list, file tree truncation (#1507) 2026-06-11 17:52:20 -07:00
reviewer_groups.py fix: Simplify review explanation: full-width, plain prose, no diff links (#1547) 2026-06-16 15:32:24 -07:00
reviewer_publish.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
reviewer_reconcile.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
reviewer_trace_context.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
scheduler.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
server.py feat: surface attributed PR creation failures (#180) 2026-07-13 14:45:19 -04:00
webapp.py feat: Re-land deferred upstream features on modular webhooks (#80) (#128) 2026-07-08 18:32:43 -04:00