Repository navigation
feat: report dispatch coordinator operations in logs and audit - #65163
Conversation
Download coordinator snapshots, finish intents, and workflow diagnostics with the dispatch-coordinator artifact set. Extract timestamped operations into text and JSON reports and preserve evidence across cached reports. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@copilot call it work-queue |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Renamed the artifact selector and report fields to |
|
✅ Ponytail Reviewer completed successfully! Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.
|
|
✅ PR Code Quality Reviewer completed the code quality review.
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅
|
🏗️ ADR required — draft addedA draft ADR has been added at Why this PR is gated
Evidence used
Next action
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Coordinator evidence can be spoofed, malformed snapshots accepted, and cache/download state misidentified.
Review effort: Balanced
Findings: 5
Open (5)
Reject snapshots with omitted required fields · New Restrict coordinator message extraction to trusted log paths · New Preserve artifact selection when detecting coordinator requests · New Use atomic completion tracking for workflow log extraction · New Escape control characters in work and claim IDs · New
What changed in this PR
Adds dispatch coordinator evidence to logs and audit reports.
Changes:
- Adds
work-queueartifact collection, extraction, caching, and rendering. - Extends JSON schemas and cache versions.
- Adds tests and documentation.
| File | Description |
|---|---|
schemas/logs.schema.json |
Adds work-queue schema. |
schemas/logs-jsonl.schema.json |
Adds work-queue fields and v3. |
schemas/audit.schema.json |
Adds audit work-queue schema. |
pkg/cli/mcp_tools_privileged.go |
Exposes the artifact set through MCP. |
pkg/cli/logs_run_processor.go |
Backfills and persists coordinator evidence. |
pkg/cli/logs_report.go |
Adds coordinator data and rendering. |
pkg/cli/logs_orchestrator_filters.go |
Propagates coordinator reports. |
pkg/cli/logs_models.go |
Adds coordinator report fields. |
pkg/cli/logs_format_compact.go |
Renders compact work-queue output. |
pkg/cli/logs_download.go |
Downloads diagnostic workflow logs. |
pkg/cli/logs_dispatch_coordinator.go |
Extracts and validates evidence. |
pkg/cli/logs_dispatch_coordinator_test.go |
Tests extraction and propagation. |
pkg/cli/logs_dispatch_coordinator_render.go |
Renders coordinator reports. |
pkg/cli/logs_cached_json.go |
Caches coordinator data in JSONL. |
pkg/cli/logs_cached_json_test.go |
Updates cache-version tests. |
pkg/cli/logs_artifact_set.go |
Defines work-queue. |
pkg/cli/logs_artifact_set_test.go |
Tests artifact-set registration. |
pkg/cli/audit.go |
Adds coordinator analysis results. |
pkg/cli/audit_summary_build.go |
Propagates results into summaries. |
pkg/cli/audit_run_pipeline.go |
Backfills cached audits. |
pkg/cli/audit_report.go |
Adds structured audit output. |
pkg/cli/audit_report_render.go |
Renders audit work-queue sections. |
pkg/cli/audit_render_output.go |
Merges cached coordinator reports. |
pkg/cli/audit_cache.go |
Updates audit cache handling. |
pkg/cli/audit_analysis_fanout.go |
Runs coordinator extraction. |
docs/src/content/docs/setup/cli.md |
Documents artifact selection. |
docs/src/content/docs/reference/audit.md |
Documents report fields and usage. |
There was a problem hiding this comment.
Request changes
The new work-queue reporting has two blocking cache-path regressions: the default cached audit path can still skip backfilling coordinator evidence entirely, and the compact logs path now leaks cached coordinator data into usage-only runs.
🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 69.2 AIC · ⌖ 6.96 AIC · ⊞ 20.2K
Comment /review to run again
There was a problem hiding this comment.
Skills-Based Review 🧠
Applied /tdd and /codebase-design on the new logs_dispatch_coordinator*.go module and its wiring into audit/logs. Requesting changes on one correctness/security concern in the operation-extraction trust model; everything else is solid.
📋 Key Themes & Highlights
Key Themes
- Trust boundary on log-derived evidence:
extractDispatchCoordinatorOperationsaccepts any job-log line matching a timestamp + known-prefix pattern as genuine coordinator evidence, with no restriction to a specific step/job source. Since this report is meant to be authoritative audit evidence ("operations observed... not operations performed by the audited run" per the PR description), a forged line with a real-looking timestamp from attacker-influenced job output could be indistinguishable from genuine coordinator output. - Flag coupling:
renderAuditReport's new coordinator-report backfill write is silently gated byopts.NoBaseline, an unrelated flag, without explaining the relationship. - Test coverage: the existing
forgedfixture only demonstrates the (less interesting) timestamp-missing rejection path, not the actual risk of a well-formed forged timestamp.
Positive Highlights
- ✅ Careful separation of activation-time queue facts (snapshot/transactions), agent intent (finish_intent), and runtime observations (operations) — a clear, well-documented domain model.
- ✅ Strong validation of snapshot/transaction/finish-intent shapes (
parseDispatchCoordinatorTransaction,parseDispatchCoordinatorSnapshot) with comprehensive table-driven tests. - ✅ Thoughtful backfill/merge/dedup handling across cache schema bumps (
backfillDispatchCoordinatorReport,mergeDispatchCoordinatorReport), with an end-to-end propagation test (TestDispatchCoordinatorReportPropagation) covering the whole pipeline. - ✅ Schema, docs, and CLI help text updated consistently alongside the new
work-queueartifact set.
Findings are flagged inline. Fallback note: pr-triage ran successfully, so no fallback heuristic was needed.
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 148.1 AIC · ⌖ 14.7 AIC · ⊞ 10K
Comment /matt to run again
Require nullable snapshot properties, accept operations only from coordinator-owned step logs, and escape control characters in text reports. Preserve explicit work-queue selection, backfill default audit downloads, and atomically publish completed workflow log archives. Refresh cache schema versions and regression fixtures without exposing cached work queue evidence in usage-only logs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@copilot Please review this PR for forward progress: check unresolved review feedback, failed checks, and whether the branch needs a refresh. If action is needed, please continue with the pr-finisher skill.
|
…perations-reports Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Refreshed the branch from |
|
🎉 This pull request is included in a new release. Release: |

Why
Dispatcher work coordinator evidence is spread across activation snapshots, agent finish-intent files, and workflow job logs.
gh aw logsandgh aw auditneed to collect and expose that evidence so queue publication and worker reconciliation can be investigated from a single report.Approach
dispatch-coordinatorartifact set to download activation and agent artifacts plus workflow logs, including missing diagnostic logs for previously cached runs.dispatch_coordinatorin JSON and text reports.Activation transactions are historical queue facts, not operations performed by the audited run. A finish intent is an agent request, not a verified completion; publication and reconciliation diagnostics are reported separately. The compact
logsdefault remains unchanged, while defaultauditdownloads include this evidence.Usage
Validation
Passed:
make buildandmake fmtgo test ./pkg/cli -run 'Test(DispatchCoordinator|DownloadDispatchCoordinator|DownloadRunArtifacts|CollectAuditAnalysisResults|AuditUsesRunSummaryCache|CachedAudit|LoadCachedAuditData|WriteLogsAuditFiles|RenderLogsCompact|LogsCompact)' -count=1go test -race ./pkg/cli -run 'Test(DispatchCoordinator|CollectAuditAnalysisResults)' -count=1golangci-lint run --allow-parallel-runners ./pkg/cligit diff --checkmake agent-report-progressran, including impacted unit tests. The full gate remains blocked by pre-existing custom-linter findings in touched files, including oversized existing functions, slice-index diagnostics, and an explicitly discardedClose()error. New coordinator-specific lint findings were corrected. A subsequent standard Go lint run passed with zero issues.