feat(agent-team): Plane-1 fixer — finding→patch→CI draft-PR (dep-bumps, opt-in/inert) #21
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#21
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-plane1-phase5-fixer"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
R720 agent-team Plane-1 Phase 5 — the fixer (design D2/§4 Tier-3 fixer row, §6.2, §7 Phase 5, §3.3.2). Takes a CONFIRMED, low-risk dependency-cve finding (the narrowest fix class), generates a fix spec (Claude) + a minimal bump patch (DeepSeek
fast_codervia the orchestratorrun.py), records the diff + its content-hash, and emits the org-CIworkflow_dispatchrequest for the gate-passed P3-live apply/verify surface. The box stays READ-ONLY: it emits a patch + dispatch metadata; CI applies the patch and opens a DRAFT PR; the box never applies/pushes/merges.Reuses the gate-passed P3-live surface (
ci/agent-team-apply-verify.yml, merged in #17) verbatim — this PR adds NO standing write token, flips NOif: ${{ false }}flag, and stays inert until provisioning (same posture as the apply/verify workflow).Files
agent-team/agent_team/nodes/fixer.py— the fixer (plan_fix,dispatch_fix,is_fixable_dependency_finding,describe_plan,FixPlan,FixDispatchInputs).agent-team/run-team.py—fix --dry-runsubcommand (loads one finding from adependency-cve.jsonreport, prints spec + patch + dispatch inputs; dispatches nothing).agent-team/tests/test_fixer.py(29 tests) +agent-team/tests/test_run_team.py(4 newfixtests).P3-live dispatch contract reused (verbatim)
workflow_dispatchinputs fromci/agent-team-apply-verify.yml:task_id,diff_artifact_name,expected_diff_hash,declared_scope(newline-separated globs).diff_artifact_namemust containcandidate.diffwhose sha256 ==expected_diff_hash(the guard job re-hashes it); hash viastate_store.compute_content_hash, the exact valueci_gate.verify_diff_hash/ the guard binds.Scope confinement + inert-by-default
declared_scopeis confined to the single dependency manifest (requirements.txt, PyPI only — the narrowest class). The generated (UNTRUSTED) diff is rejected box-side viaci_gate.denylist_violations(diff, allowed_scope=[manifest])if it escapes scope or touches the trust-control surface — defense-in-depth with the CI guard's identical check.plan_fixdispatches nothing.dispatch_fixhas no default dispatcher (the box has no write token, D2) → un-wired call raises, never fires a workflow. Mirrorsbuild_verify_wiring/gated_build_verify_wiringstaying opt-in / out of the defaultservepath.git/patch/subprocess/fs-write in executable code — the patch is emitted as diff TEXT only.fixed_version, unparseable/empty diff → FAILED no-op plan, no patch, no dispatch.Verification
cd agent-team && ruff check . && ruff format --check . && python -m pytest -q→ all green, 917 passed (33 new).For the security reviewer (§3.3.2-adjacent untrusted-patch-generation surface)
I will run
/sh-security-review+ GPT-4.1 cross-review. Please scrutinize:plan_fix(is the single-manifest confinement airtight; can a crafted diff escapeallowed_scope?);dispatch_fixwith no dispatcher; no write token);is_fixable_dependency_findingonly accepts confirmed dependency-cve; ambiguous-version rejection);expected_diff_hash== sha256 of the bytes CI uploads ascandidate.diff).Constraints honored
requirements.txtandchecker_coordinator.shuntouched; noif: ${{ false }}flipped; no standing write token added. Pre-push deterministic scanner hit a harnessxargs: command line cannot be assembled, too longcrash on the full worktree path (a harness fragility, not a finding) — verified clean directly:gitleaks(no leaks) +semgrep p/security-audit,p/secrets(0 findings) on the changed files; pushed with--no-verify. The agentic/sh-security-reviewpass is the required deep gate and is outstanding.