open-swe/agent/utils
Adam Moussa e9da186b5f
fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181)
* fix: fall back to core GitHub App scope when optional grants missing (#1701)

* fix: fall back to core GitHub App scope when optional grants missing

Proxy-token minting requested workflows:write and actions:read in the
permission set used for every sandbox. GitHub 422s a token request that
asks for a permission the installation hasn't granted, so any install
without workflows:write failed to mint a token and every run died in
before-agent setup with "GitHub App installation token is unavailable".

_resolve_proxy_token now walks a permission ladder (full -> +workflows ->
core) and returns the first scope that mints, recording the granted scope
so hourly proxy refreshes stay consistent. A missing optional grant now
degrades to the install-time core scope instead of failing the run;
workflow-file HITL pushes still require workflows:write and fail at push
time when it is absent.

* refactor: flatten proxy-token ladder loop with continue

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935)

Sea Haven fork deviation: upstream #1701 folds workflows:write into the
standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write
OUT of the standing permission ladder (RUNTIME = core + actions:read;
LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push
.github/workflows/* during normal operation. workflows:write is minted only
transiently by WorkflowPushGuardMiddleware for an approved HITL push and
dropped on restore, preserving token scope as a backstop for the workflow-
push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross
review); the standing-scope-carries-workflows:write bypass was blocked.

* fix(open-swe): harden proxy-token restore and mint error handling

Two low-severity follow-ups from the security review of the #1701 port.

Restore the recorded baseline scope after a workflow-push elevation instead
of a hardcoded RUNTIME. An install granted workflows:write but not actions:read
resolves its standing token to core; hardcoding RUNTIME on restore requested the
ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope"
error on every approved workflow push before the core fallback recovered. The
guard now captures the run's recorded scope before elevating (via the new
get_recorded_proxy_permissions) and restores exactly that, falling back to the
guaranteed core scope only when the baseline restore fails.

Classify installation-token mint failures. get_github_app_installation_token_
with_expiry now treats HTTP 422 (a permission the installation hasn't granted)
as the ladder's expected descend signal and keeps it at debug, while a non-422
failure (network/5xx/timeout) is surfaced at WARNING even when errors are
otherwise suppressed — so a transient blip no longer silently downscopes a whole
run under a debug-only trace. The reduced-scope warning no longer asserts a
missing grant as the sole cause.

* chore(triage): mark upstream #1701 landed on this branch

Ported via PR #181 as Option A (workflows:write kept out of the standing
proxy-token scope). Regenerated triage.md from triage.jsonl.

---------

Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
2026-07-13 14:24:37 -04:00
..
agents_md.py feat: reviewer enforces AGENTS.md/CLAUDE.md repo rules as mandatory pass (#1569) 2026-06-18 11:13:58 -07:00
analyzer_skills.py feat: managed LangGraph Cloud + Vercel migration (PR2 — code fixes + docs) (#65) 2026-06-29 19:58:38 -04:00
api_standards_skill.py feat: apply API standards skill in PR reviews for API changes (#1452) 2026-06-08 14:37:04 -07:00
auth.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
authorship.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
comments.py chore: Drop monorepo (#1029) 2026-03-06 16:10:34 -08:00
dashboard_handoff.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
dashboard_links.py feat: port plan-review & workflow-approval UX (#159) 2026-07-09 16:03:13 -04:00
deferred_model.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
gateway.py feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) (#155) 2026-07-09 14:44:15 -04:00
github_app.py fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181) 2026-07-13 14:24:37 -04:00
github_checks.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_ci.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_comments.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
github_feedback.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
github_http.py feat: shared GitHub HTTP helper with retries, rate-limit handling [closes OPE-45] (#1565) 2026-06-17 14:45:57 -07:00
github_org_membership.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
github_proxy.py fix(open-swe): port core GitHub-App scope fallback (#1701), workflows:write kept out of standing scope (#181) 2026-07-13 14:24:37 -04:00
github_token.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
http.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
langsmith.py feat: plan mode with model-driven entry and collaborative review (#1580) 2026-06-23 12:06:58 -07:00
linear.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
linear_team_repo_map.py chore: Add langsmith deployments data plane linear project (#1044) 2026-03-09 18:36:00 -07:00
model.py feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) (#155) 2026-07-09 14:44:15 -04:00
multimodal.py feat: Re-land deferred upstream features on modular webhooks (#80) (#128) 2026-07-08 18:32:43 -04:00
repo.py feat: extract repo parsing into shared util, add linear comment repo override (#1103) 2026-03-20 13:34:00 -07:00
repo_prep.py fix: reviewer can silently review a stale checkout on reused sandboxes (#1503) 2026-06-11 13:42:10 -07:00
reviewer_outcomes.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
sandbox.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
sandbox_paths.py fix: better custom backend support (#1071) 2026-03-17 11:55:36 -07:00
sandbox_state.py fix: resolve security-review findings (sandbox isolation, IAM list scope, webhook replay, info-leak) (#54) 2026-06-29 12:21:19 -04:00
slack.py fix(security): fence and neutralize untrusted Slack channel description in agent prompt 2026-07-03 16:08:35 -04:00
slack_feedback.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
thread_ids.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
thread_ops.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
tracing.py feat: route graphs to separate LangSmith tracing projects (#1508) 2026-06-11 17:57:16 -07:00
url_safety.py feat: Re-land deferred upstream features on modular webhooks (#80) (#128) 2026-07-08 18:32:43 -04:00