mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 06:53:14 +00:00
|
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* feat: surface attributed PR creation failures Port upstream #1659: adds PullRequestCreationGuardMiddleware that blocks shell fallbacks (gh pr create, gh api /pulls, curl) when open_pull_request fails, keeping failures visible. Also adds preflight branch/repo visibility checks in open_pull_request with structured failure payloads, and updates the prompt to forbid PR creation fallbacks. Refs: #134 * fix: fall back to core GitHub App scope when optional grants missing (#1701) * fix: fall back to core GitHub App scope when optional grants missing Proxy-token minting requested workflows:write and actions:read in the permission set used for every sandbox. GitHub 422s a token request that asks for a permission the installation hasn't granted, so any install without workflows:write failed to mint a token and every run died in before-agent setup with "GitHub App installation token is unavailable". _resolve_proxy_token now walks a permission ladder (full -> +workflows -> core) and returns the first scope that mints, recording the granted scope so hourly proxy refreshes stay consistent. A missing optional grant now degrades to the install-time core scope instead of failing the run; workflow-file HITL pushes still require workflows:write and fail at push time when it is absent. * refactor: flatten proxy-token ladder loop with continue --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> (cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935) Sea Haven fork deviation: upstream #1701 folds workflows:write into the standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write OUT of the standing permission ladder (RUNTIME = core + actions:read; LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push .github/workflows/* during normal operation. workflows:write is minted only transiently by WorkflowPushGuardMiddleware for an approved HITL push and dropped on restore, preserving token scope as a backstop for the workflow- push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross review); the standing-scope-carries-workflows:write bypass was blocked. * fix(open-swe): harden proxy-token restore and mint error handling Two low-severity follow-ups from the security review of the #1701 port. Restore the recorded baseline scope after a workflow-push elevation instead of a hardcoded RUNTIME. An install granted workflows:write but not actions:read resolves its standing token to core; hardcoding RUNTIME on restore requested the ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope" error on every approved workflow push before the core fallback recovered. The guard now captures the run's recorded scope before elevating (via the new get_recorded_proxy_permissions) and restores exactly that, falling back to the guaranteed core scope only when the baseline restore fails. Classify installation-token mint failures. get_github_app_installation_token_ with_expiry now treats HTTP 422 (a permission the installation hasn't granted) as the ladder's expected descend signal and keeps it at debug, while a non-422 failure (network/5xx/timeout) is surfaced at WARNING even when errors are otherwise suppressed — so a transient blip no longer silently downscopes a whole run under a debug-only trace. The reduced-scope warning no longer asserts a missing grant as the sole cause. * chore(triage): mark upstream #1701 landed on this branch Ported via PR #181 as Option A (workflows:write kept out of the standing proxy-token scope). Regenerated triage.md from triage.jsonl. * fix: restructure PR creation to POST-first with diagnose-on-failure Move preflight checks from an authoritative gate (before POST) to a diagnostic run after POST failure. This avoids false-positive failures when a just-pushed head branch is momentarily invisible to GitHub ref endpoints, and eliminates 2-3 extra serial API round-trips on the happy path. Also drop unused _PR_CREATED_FALSE indirection and add a docstring to pr_creation_guard acknowledging the fail-open detection design. --------- Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev> Co-authored-by: Adam Moussa <adam@seahavenind.com> |
||
|---|---|---|
| .. | ||
| e2e | ||
| middleware | ||
| conftest.py | ||
| test_account_link.py | ||
| test_agent_assembly_context.py | ||
| test_agent_instructions.py | ||
| test_agent_schedules.py | ||
| test_agent_subagent_models.py | ||
| test_agent_thread_pr_state.py | ||
| test_agent_usage.py | ||
| test_agents_md.py | ||
| test_analyzer_cron.py | ||
| test_analyzer_skills.py | ||
| test_anthropic_effort.py | ||
| test_anthropic_model.py | ||
| test_api_standards_skill.py | ||
| test_app_bot_identity.py | ||
| test_auth_error_leak.py | ||
| test_auth_sources.py | ||
| test_authorship.py | ||
| test_autofix_state.py | ||
| test_autofix_webhook.py | ||
| test_check_message_queue.py | ||
| test_ci_autofix.py | ||
| test_completion_webhook.py | ||
| test_corridor_mcp.py | ||
| test_currents_tools.py | ||
| test_dashboard_admin.py | ||
| test_dashboard_csrf.py | ||
| test_dashboard_links.py | ||
| test_dashboard_oauth_redirect.py | ||
| test_dashboard_org_login_gate.py | ||
| test_dashboard_repo_optional.py | ||
| test_dashboard_repos.py | ||
| test_dashboard_reviews.py | ||
| test_dashboard_run_email.py | ||
| test_dashboard_thread_api.py | ||
| test_dashboard_thread_api_activity.py | ||
| test_dashboard_web_handoff.py | ||
| test_daytona_integration.py | ||
| test_dispatch.py | ||
| test_encryption.py | ||
| test_ensure_no_empty_msg.py | ||
| test_eval_jobs.py | ||
| test_eval_store_reporter.py | ||
| test_fireworks_model.py | ||
| test_gateway.py | ||
| test_github_app.py | ||
| test_github_checks.py | ||
| test_github_ci.py | ||
| test_github_comment_prompts.py | ||
| test_github_feedback.py | ||
| test_github_http.py | ||
| test_github_issue_webhook.py | ||
| test_github_oauth_refresh.py | ||
| test_github_proxy_refresh.py | ||
| test_github_token_ttl.py | ||
| test_http_security.py | ||
| test_langsmith_sandbox_config.py | ||
| test_langsmith_sandbox_timeout.py | ||
| test_langsmith_trace_url.py | ||
| test_linear_webhook_replay.py | ||
| test_local_integration.py | ||
| test_model_fallback_middleware.py | ||
| test_model_fallback_resolution.py | ||
| test_multimodal.py | ||
| test_normalize_repo.py | ||
| test_notify_step_limit_middleware.py | ||
| test_notion_oauth.py | ||
| test_observability_tools.py | ||
| test_open_pull_request.py | ||
| test_plan_mode.py | ||
| test_plan_review.py | ||
| test_pr_creation_guard.py | ||
| test_pr_ready_auto_review.py | ||
| test_prompt_default_repo.py | ||
| test_proxy_auth.py | ||
| test_public_repo_org_gate.py | ||
| test_recent_comments.py | ||
| test_reconcile_sweep.py | ||
| test_refresh_slack_status_middleware.py | ||
| test_repair_orphaned_tool_calls.py | ||
| test_repo_binding_isolation.py | ||
| test_repo_extraction.py | ||
| test_repo_prep.py | ||
| test_repo_snapshots.py | ||
| test_report_platform_issue_tool.py | ||
| test_review_api.py | ||
| test_review_chat.py | ||
| test_review_style_collector.py | ||
| test_review_style_sync.py | ||
| test_review_styles_store.py | ||
| test_reviewer.py | ||
| test_reviewer_diff.py | ||
| test_reviewer_eval_run.py | ||
| test_reviewer_eval_target.py | ||
| test_reviewer_findings.py | ||
| test_reviewer_groups.py | ||
| test_reviewer_outcomes.py | ||
| test_reviewer_publish.py | ||
| test_reviewer_reconcile.py | ||
| test_reviewer_tools.py | ||
| test_reviewer_trace_context.py | ||
| test_reviewer_watch.py | ||
| test_sandbox_paths.py | ||
| test_sanitize_fireworks_messages.py | ||
| test_sanitize_openai_responses.py | ||
| test_sanitize_thinking_blocks.py | ||
| test_sanitize_tool_inputs.py | ||
| test_schedule_thread_wakeup.py | ||
| test_slack_add_reaction_tool.py | ||
| test_slack_assistants_status.py | ||
| test_slack_context.py | ||
| test_slack_feedback.py | ||
| test_slack_oauth.py | ||
| test_slack_start_new_thread_tool.py | ||
| test_slack_thread_reply_tool.py | ||
| test_slack_webhook_errors.py | ||
| test_stale_sandbox_creating.py | ||
| test_subdir_agents_middleware.py | ||
| test_team_credentials.py | ||
| test_team_settings_fable.py | ||
| test_team_settings_grouping.py | ||
| test_team_settings_org_guidelines.py | ||
| test_tool_artifact_middleware.py | ||
| test_user_credentials.py | ||
| test_user_mappings.py | ||
| test_workflow_push_guard.py | ||