Use the approved plan title as the agent-team apply PR title #74

Closed
amoussa1229 wants to merge 3 commits from fix/agent-team-conventional-pr-title into main
amoussa1229 commented 2026-06-25 17:50:34 +00:00 (Migrated from github.com)

Summary

The agent-team apply pipeline opened draft PRs titled agent-apply: <task_id> (diff <hash>) with a flat body — neither within Sea Haven PR conventions. That format was deliberate CWE-94 hardening (only sanitized tokens, never model free-text). This threads the approved plan's title through dispatch as an optional pr_title workflow_dispatch input, sanitized box-side and re-validated in the workflow, so the bot's PRs read conventionally while staying injection-safe. Provenance (task id, diff hash, head) moves to the PR body.

Validation

  • python -m pytest -q → 1537 passed; ruff check / ruff format --check clean; workflow YAML parses.
  • GPT-4.1 cross-review (mandatory for the workflow_dispatch event-shape change): no BLOCK. FIX items addressed — grep -P portability and DispatchInputs instantiation audit (only one site; optional default covers the rest).
  • /sh-security-review (mandatory — touches .github/workflows/** + untrusted-input): injection detector found nothing (title is env-indirected, passed as quoted argv to gh, never shell-interpolated). 3 low/info logic findings; F1 (C1-range gap) and F3 (wc -m byte vs char count) fixed by making the workflow re-validation byte-for-byte identical to sanitize_pr_title via a single python3 check.

How it stays safe

  • sanitize_pr_title (box): strip C0/C1/DEL control chars, collapse whitespace, 70-char cap, capitalize. Empty/unsafe → "".
  • Workflow re-validates identically and falls back to the hardened agent-apply: <task_id> title if empty/unsafe.
  • pr_title is consumed only as gh pr create --title argv data — never shell-interpolated; never in a run: ${{ }} expansion.
  • Optional (default: ""), so existing dispatchers (e.g. the fixer) keep working with the fallback title.

Notes — deploy ordering (important)

This change couples the box dispatcher to the workflow on main. workflow_dispatch validates inputs against the workflow definition on the dispatched ref (main), so the workflow YAML must be on main BEFORE the box ships the dispatcher that sends pr_title — otherwise every dispatch returns HTTP 422. For this change that means merge this PR first, then /sh-deploy-r720 (the exception to the usual deploy-then-merge). Fail-closed (422 = no run), but it would stall dispatch.

## Summary The agent-team apply pipeline opened draft PRs titled `agent-apply: <task_id> (diff <hash>)` with a flat body — neither within Sea Haven PR conventions. That format was deliberate CWE-94 hardening (only sanitized tokens, never model free-text). This threads the **approved plan's title** through dispatch as an optional `pr_title` `workflow_dispatch` input, sanitized box-side and re-validated in the workflow, so the bot's PRs read conventionally while staying injection-safe. Provenance (task id, diff hash, head) moves to the PR body. ## Validation - `python -m pytest -q` → **1537 passed**; `ruff check` / `ruff format --check` clean; workflow YAML parses. - **GPT-4.1 cross-review** (mandatory for the `workflow_dispatch` event-shape change): no BLOCK. FIX items addressed — `grep -P` portability and `DispatchInputs` instantiation audit (only one site; optional default covers the rest). - **`/sh-security-review`** (mandatory — touches `.github/workflows/**` + untrusted-input): injection detector found nothing (title is env-indirected, passed as quoted argv to `gh`, never shell-interpolated). 3 low/info logic findings; F1 (C1-range gap) and F3 (`wc -m` byte vs char count) fixed by making the workflow re-validation byte-for-byte identical to `sanitize_pr_title` via a single `python3` check. ## How it stays safe - `sanitize_pr_title` (box): strip C0/C1/DEL control chars, collapse whitespace, 70-char cap, capitalize. Empty/unsafe → `""`. - Workflow re-validates identically and falls back to the hardened `agent-apply: <task_id>` title if empty/unsafe. - `pr_title` is consumed only as `gh pr create --title` argv data — never shell-interpolated; never in a `run:` `${{ }}` expansion. - Optional (`default: ""`), so existing dispatchers (e.g. the fixer) keep working with the fallback title. ## Notes — deploy ordering (important) This change couples the box dispatcher to the workflow on `main`. `workflow_dispatch` validates inputs against the workflow definition on the dispatched ref (`main`), so **the workflow YAML must be on `main` BEFORE the box ships the dispatcher that sends `pr_title`** — otherwise every dispatch returns HTTP 422. For this change that means **merge this PR first, then `/sh-deploy-r720`** (the exception to the usual deploy-then-merge). Fail-closed (422 = no run), but it would stall dispatch.
amoussa1229 commented 2026-06-26 15:27:54 +00:00 (Migrated from github.com)

Closing: agent-team is being decommissioned (superseded by Open SWE). See removal PR.

Closing: agent-team is being decommissioned (superseded by Open SWE). See removal PR.
This repo is archived. You cannot comment on pull requests.
No description provided.