You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[windows-integration] Update windows-cli-integration workflow to use safe issue creation and strengthen matrix-driven chaos assertions #62312
The existing .github/workflows/windows-cli-integration.yml already implements most required behavior (daily schedule + dispatch, multi-job orchestration, Ubuntu build artifact, Windows integration checks, broad shell/environment/path chaos coverage, timeout protections, and an if: always() conclusion job).
However, it still needs updates to fully satisfy repository/runtime constraints and improve debuggability guarantees.
Required updates
Replace gh issue create in the conclusion job with a repository-approved write path (safe-outputs based issue declaration) because cloud-agent runs must use safe outputs for GitHub writes.
Keep permissions minimal while preserving ability to create failure issues.
Preserve existing job structure and current scenario coverage.
Add clearer failure diagnostics around matrix scenario identity and timeout context so shell-specific hangs are immediately attributable.
Ensure at least one intentionally adversarial negative chaos case remains explicitly asserted as fast-failing and debuggable in step summary output.
Why this is needed
Current conclusion behavior performs a direct GitHub write via gh issue create, which is incompatible with the run constraints requiring safe-output write intents.
Existing matrix and timeout scaffolding are strong, but failure attribution can be more explicit for rapid triage.
Acceptance criteria
conclusion job still runs with if: always() and fails workflow when required upstream jobs fail.
On failure, workflow records failed job names and creates a GitHub issue through approved safe-output mechanism (not direct gh issue create).
Integration checks continue to cover shell × launch mode × env shape × path style matrix and include explicit timeout/hang detection.
Summary
The existing
.github/workflows/windows-cli-integration.ymlalready implements most required behavior (daily schedule + dispatch, multi-job orchestration, Ubuntu build artifact, Windows integration checks, broad shell/environment/path chaos coverage, timeout protections, and anif: always()conclusion job).However, it still needs updates to fully satisfy repository/runtime constraints and improve debuggability guarantees.
Required updates
gh issue createin theconclusionjob with a repository-approved write path (safe-outputs based issue declaration) because cloud-agent runs must use safe outputs for GitHub writes.Why this is needed
gh issue create, which is incompatible with the run constraints requiring safe-output write intents.Acceptance criteria
conclusionjob still runs withif: always()and fails workflow when required upstream jobs fail.gh issue create).Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
ab.chatgpt.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.