Skip to content

[AW Top 10] 04 Fix redact-secrets step failing after successful agent runs #66818

Description

@github-actions

Priority 4/10 | 6 source issues | Impact 4/5 | Confidence 3/5 | Effort 2/5

One assignment, one coherent fix

A post-execution secret redaction step fails the agent job across several engines even after the agent completed its work.

Implementation scope

Make the redaction script tolerate non-writable and replaced files, fail only on real leaks, and add a regression test using the firewall sandbox file layout from the report.

Done when

  • Runs whose agent succeeded no longer fail in the redaction step.
  • A unit test covers non-writable files in the scanned directories.

Why now

The report documents four distinct workflows and three engines failing identically, and it is novel; matching failed-job issues corroborate it, though their cause was not individually verified.

AW source issues and corroborating reports

#66273 #66282 #66305 #66479 #66706 #66880

No corroborating AW discussion; evidence comes from the source issues.

Unchanged AW sources close only after this summary is completed. Newer source activity and not-planned retirement do not trigger source closure. Assigned summaries are frozen; unassign to allow reclustering.

Generated by AW Essential Issue Clustering · copilot · auto · 28.2 AIC · ⌖ 0.588 AIC · ⊞ 8.9K · ◷

Activity

  1. pelikhan commented on Oct 10, 2026

    @pelikhan
    Collaborator

    Closing as already fixed. Root cause: PR #66160 made writable-file preparation in redact_secrets.cjs unconditional, so unchanged/secret-free files in read-only directories (e.g. the firewall sandbox's sandbox/firewall/audit/*) were rewritten in place; when that unnecessary rewrite failed and fallback cleanup also failed, it escalated to a job-failing ERR_VALIDATION: Failed to remove artifact source after secret redaction failed, despite the agent itself succeeding.

    Fix: PR #66995 (merged 2026-10-08, building on #66160/#66698) gates file rewriting behind totalRedactions > 0 || prepareForCustomMasking, leaving unchanged read-only files untouched. Confirmed present on current main. Regression coverage validated locally: redact_secrets.test.cjs (82/82 passing) and Go TestSecretRedactionPreparesFilesOnlyForCustomMasking both cover the non-writable-file-in-scanned-directory scenario from this issue. No new recurrence since the fix merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentic-workflowsautomationaw-essentialEssential AW-generated issue clusters: assign one to resolve related findingscookieIssue Monster Loves Cookies!

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions