* feat(agent-team): durable GitHub-issue intake de-dup (schema v2) The intake poller de-duped ingested issues in an in-memory set that does not survive a process restart. A scheduled/cron intake (each run a fresh process) would therefore re-ingest every still-open labeled issue on every run and spawn duplicate pipeline tasks. Since the box is read-only (no write token to remove the intake label), durable de-dup is the only correct guard. - schema v2: new ingested_issues(source, issue_id, ingested_at) table + issue_already_ingested / record_issue_ingested helpers; migrate() adds the table to a legacy v1 DB and restamps; init_db creates it. - github_intake: pluggable IngestStore seam (in-memory default preserved for tests/one-off; durable build_ledger_ingest_store for production). Record is after start_task succeeds, so a failed intake stays retryable. - run-team.py intake-github wires the ledger store keyed by github:owner/repo, making a scheduled timer idempotent across runs. 978 tests pass (ruff clean). * fix(agent-team): harden github intake per /sh-security-review (CWE-918, idempotency) Fixes from the high-recall detector fan-out on the durable-dedup change: - INTAKE-LOGIC-01 (idempotency): switch the IngestStore seam from check-then-record (seen/mark) to claim-then-do (claim/release). The id is now reserved BEFORE the non-idempotent start_task side effect, so a crash in that window cannot re-spawn a duplicate task on the next run; a raising start_task releases the claim so transient failures stay retryable. Adds delete_issue_ingested to the schema layer for the release path. - INTAKE-SSRF-001 / INTAKE-PATHSPLICE-002 (CWE-918) in build_default_issue_client: drop the caller-overridable api_root (hardcode GITHUB_API_ROOT) and validate owner/repo against an anchored charset before splicing them into the token-bearing API URL — mirrors the sibling ci_fetcher BLOCK-3/FIX-3 fixes. Tests cover cross-process duplicate prevention, release-on-failure retry, and the owner/repo + api_root rejection. 982 tests pass, ruff clean. Follow-up (pre-existing, not introduced here): the label-only intake has no author allowlist (cf. AGENT_TEAM_SLACK_OWNER_IDS on the Slack listener); the Slack answer gate bounds the blast radius. Track as separate hardening. |
||
|---|---|---|
| .. | ||
| sim | ||
| __init__.py | ||
| conftest.py | ||
| test_apply_verify_workflow_hardening.py | ||
| test_billing.py | ||
| test_build_verify_subgraph.py | ||
| test_builders.py | ||
| test_builders_llm.py | ||
| test_checker_intake.py | ||
| test_ci_fetcher.py | ||
| test_ci_gate.py | ||
| test_ci_gate_workflow.py | ||
| test_clarifier.py | ||
| test_clarifier_llm.py | ||
| test_claude_code_adapter.py | ||
| test_claude_code_live.py | ||
| test_coordinator.py | ||
| test_deadline_timer.py | ||
| test_fixer.py | ||
| test_github_adapter.py | ||
| test_github_intake.py | ||
| test_github_live.py | ||
| test_graph.py | ||
| test_invoker.py | ||
| test_ledger.py | ||
| test_operator_cli.py | ||
| test_planner.py | ||
| test_recovery.py | ||
| test_responder.py | ||
| test_resume_worker.py | ||
| test_review_loop.py | ||
| test_review_loop_llm.py | ||
| test_run_team.py | ||
| test_schema.py | ||
| test_slack_adapter.py | ||
| test_slack_listener.py | ||
| test_slack_live.py | ||
| test_state_store.py | ||
| test_task_model.py | ||
| test_transport_base.py | ||
| test_verifier.py | ||
| test_verifier_llm.py | ||