open-swe/agent/middleware
Adam Moussa e9da186b5f
fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181)
* fix: fall back to core GitHub App scope when optional grants missing (#1701)

* fix: fall back to core GitHub App scope when optional grants missing

Proxy-token minting requested workflows:write and actions:read in the
permission set used for every sandbox. GitHub 422s a token request that
asks for a permission the installation hasn't granted, so any install
without workflows:write failed to mint a token and every run died in
before-agent setup with "GitHub App installation token is unavailable".

_resolve_proxy_token now walks a permission ladder (full -> +workflows ->
core) and returns the first scope that mints, recording the granted scope
so hourly proxy refreshes stay consistent. A missing optional grant now
degrades to the install-time core scope instead of failing the run;
workflow-file HITL pushes still require workflows:write and fail at push
time when it is absent.

* refactor: flatten proxy-token ladder loop with continue

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935)

Sea Haven fork deviation: upstream #1701 folds workflows:write into the
standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write
OUT of the standing permission ladder (RUNTIME = core + actions:read;
LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push
.github/workflows/* during normal operation. workflows:write is minted only
transiently by WorkflowPushGuardMiddleware for an approved HITL push and
dropped on restore, preserving token scope as a backstop for the workflow-
push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross
review); the standing-scope-carries-workflows:write bypass was blocked.

* fix(open-swe): harden proxy-token restore and mint error handling

Two low-severity follow-ups from the security review of the #1701 port.

Restore the recorded baseline scope after a workflow-push elevation instead
of a hardcoded RUNTIME. An install granted workflows:write but not actions:read
resolves its standing token to core; hardcoding RUNTIME on restore requested the
ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope"
error on every approved workflow push before the core fallback recovered. The
guard now captures the run's recorded scope before elevating (via the new
get_recorded_proxy_permissions) and restores exactly that, falling back to the
guaranteed core scope only when the baseline restore fails.

Classify installation-token mint failures. get_github_app_installation_token_
with_expiry now treats HTTP 422 (a permission the installation hasn't granted)
as the ladder's expected descend signal and keeps it at debug, while a non-422
failure (network/5xx/timeout) is surfaced at WARNING even when errors are
otherwise suppressed — so a transient blip no longer silently downscopes a whole
run under a debug-only trace. The reduced-scope warning no longer asserts a
missing grant as the sole cause.

* chore(triage): mark upstream #1701 landed on this branch

Ported via PR #181 as Option A (workflows:write kept out of the standing
proxy-token scope). Regenerated triage.md from triage.jsonl.

---------

Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
2026-07-13 14:24:37 -04:00
..
__init__.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
check_message_queue.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
ensure_no_empty_msg.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
exclude_tools.py feat: add reviewer graph + eval target wiring (#1241) 2026-05-06 10:15:58 -07:00
model_fallback.py feat: port model-fallback resilience from upstream (#1694, #1695) (#161) 2026-07-09 18:28:21 -04:00
notify_step_limit.py fix: notify users via Slack when agent hits model call step limit (#1204) 2026-05-01 14:24:25 -07:00
plan_mode.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
refresh_github_proxy.py fix: refresh sandbox GitHub proxy token before mid-run expiry (#1496) 2026-06-11 10:59:21 -07:00
refresh_slack_status.py feat: add Slack reaction tool (#1650) 2026-07-03 15:38:56 -04:00
repair_orphaned_tool_calls.py fix: repair orphaned tool calls before model calls (#1604) 2026-06-24 12:58:10 -07:00
sandbox_circuit_breaker.py fix: recover from mid-run sandbox death (#1274) 2026-05-08 12:55:36 -07:00
sanitize_fireworks_messages.py feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) (#155) 2026-07-09 14:44:15 -04:00
sanitize_openai_responses.py feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) (#155) 2026-07-09 14:44:15 -04:00
sanitize_thinking_blocks.py feat: migrate model providers to Bedrock (Claude) + Fireworks (everything else) (#62) 2026-06-29 15:57:19 -04:00
sanitize_tool_inputs.py fix: coerce malformed integer strings in read_file offset/limit params (#1216) 2026-05-01 14:29:48 -07:00
settle_review_check.py fix: settle incomplete review check as neutral, not failure (#1501) 2026-06-11 13:03:34 -07:00
subdir_agents.py feat: re-land scoped AGENTS auto-load (#1684) + platform issue reporting tool (#1685) (#129) 2026-07-08 18:52:01 -04:00
task_retry.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
timeout_wrapup.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
tool_artifact.py feat(open-swe): stream agent chat via @langchain/react v2 protocol (#1475) 2026-06-11 09:54:35 -07:00
tool_error_handler.py fix: keep sandbox backend stable across recovery (#1294)w 2026-05-11 16:03:38 -07:00
workflow_push_guard.py fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181) 2026-07-13 14:24:37 -04:00