Skip to content

feat: report dispatch coordinator operations in logs and audit - #65163

Merged
pelikhan merged 7 commits into
mainfrom
pelikhan-dispatcher-operations-reports
Oct 3, 2026
Merged

pelikhan merged 7 commits into
mainfrom
pelikhan-dispatcher-operations-reports

Conversation

@pelikhan

@pelikhan pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Why

Dispatcher work coordinator evidence is spread across activation snapshots, agent finish-intent files, and workflow job logs. gh aw logs and gh aw audit need to collect and expose that evidence so queue publication and worker reconciliation can be investigated from a single report.

Approach

  • Add the dispatch-coordinator artifact set to download activation and agent artifacts plus workflow logs, including missing diagnostic logs for previously cached runs.
  • Extract queue snapshot transactions, worker assignments, finish intents, and timestamped coordinator operations into dispatch_coordinator in JSON and text reports.
  • Deduplicate whole-job/per-step log copies, retain source-file provenance, and backfill partial cached reports. Bump the audit cache schema to regenerate older reports.
  • Validate malformed coordinator data and document the artifact selection and report fields.

Activation transactions are historical queue facts, not operations performed by the audited run. A finish intent is an agent request, not a verified completion; publication and reconciliation diagnostics are reported separately. The compact logs default remains unchanged, while default audit downloads include this evidence.

Usage

gh aw logs <run-id> --artifacts dispatch-coordinator --json
gh aw audit <run-id> --artifacts dispatch-coordinator --json

Validation

Passed:

  • make build and make fmt
  • go test ./pkg/cli -run 'Test(DispatchCoordinator|DownloadDispatchCoordinator|DownloadRunArtifacts|CollectAuditAnalysisResults|AuditUsesRunSummaryCache|CachedAudit|LoadCachedAuditData|WriteLogsAuditFiles|RenderLogsCompact|LogsCompact)' -count=1
  • go test -race ./pkg/cli -run 'Test(DispatchCoordinator|CollectAuditAnalysisResults)' -count=1
  • golangci-lint run --allow-parallel-runners ./pkg/cli
  • git diff --check

make agent-report-progress ran, including impacted unit tests. The full gate remains blocked by pre-existing custom-linter findings in touched files, including oversized existing functions, slice-index diagnostics, and an explicitly discarded Close() error. New coordinator-specific lint findings were corrected. A subsequent standard Go lint run passed with zero issues.

Download coordinator snapshots, finish intents, and workflow diagnostics with the dispatch-coordinator artifact set. Extract timestamped operations into text and JSON reports and preserve evidence across cached reports.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot call it work-queue

Copilot AI and others added 2 commits October 3, 2026 00:52
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@copilot call it work-queue

Renamed the artifact selector and report fields to work-queue / work_queue in commit 6b06fae.

@pelikhan
pelikhan marked this pull request as ready for review October 3, 2026 00:58
Copilot AI balanced review requested due to automatic review settings October 3, 2026 00:58
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Generated by Ponytail Reviewer for #65163

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor
🏗️ ADR required — draft added

A draft ADR has been added at docs/adr/65163-report-dispatch-coordinator-operations-in-audit-and-logs.md.

Why this PR is gated

  • ADR enforcement applies because this PR adds more than 100 new lines in business-logic directories (pkg/ additions: 867 lines).
  • No ADR reference was found in the PR body.
  • The existing dispatch-coordinator ADRs (docs/adr/64955-git-backed-dispatch-work-coordination.md and docs/adr/dispatch-work-coordinator-protocol-upgrades.md) cover queue coordination and protocol upgrades, but not this new reporting decision.

Evidence used

  • PR title/body: reporting dispatch coordinator operations in gh aw logs and gh aw audit
  • Diff: new DispatchCoordinatorReport / work_queue output, new work-queue artifact set, cache-schema bumps, and backfill logic for cached reports

Next action

  • Review and refine the draft ADR, especially the decision scope and trade-offs, then keep it with this PR as the explicit design record for the reporting change.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · gpt54 · 22.8 AIC · ⌖ 10.9 AIC · ⊞ 10.4K · ◷
Comment /review to run again

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Coordinator evidence can be spoofed, malformed snapshots accepted, and cache/download state misidentified.

Review effort: Balanced
Findings: 5 Medium severity

Open (5)
What changed in this PR

Adds dispatch coordinator evidence to logs and audit reports.

Changes:

  • Adds work-queue artifact collection, extraction, caching, and rendering.
  • Extends JSON schemas and cache versions.
  • Adds tests and documentation.
File Description
schemas/​logs.schema.json Adds work-queue schema.
schemas/​logs-jsonl.schema.json Adds work-queue fields and v3.
schemas/​audit.schema.json Adds audit work-queue schema.
pkg/​cli/​mcp_tools_privileged.go Exposes the artifact set through MCP.
pkg/​cli/​logs_run_processor.go Backfills and persists coordinator evidence.
pkg/​cli/​logs_report.go Adds coordinator data and rendering.
pkg/​cli/​logs_orchestrator_filters.go Propagates coordinator reports.
pkg/​cli/​logs_models.go Adds coordinator report fields.
pkg/​cli/​logs_format_compact.go Renders compact work-queue output.
pkg/​cli/​logs_download.go Downloads diagnostic workflow logs.
pkg/​cli/​logs_dispatch_coordinator.go Extracts and validates evidence.
pkg/​cli/​logs_dispatch_coordinator_test.go Tests extraction and propagation.
pkg/​cli/​logs_dispatch_coordinator_render.go Renders coordinator reports.
pkg/​cli/​logs_cached_json.go Caches coordinator data in JSONL.
pkg/​cli/​logs_cached_json_test.go Updates cache-version tests.
pkg/​cli/​logs_artifact_set.go Defines work-queue.
pkg/​cli/​logs_artifact_set_test.go Tests artifact-set registration.
pkg/​cli/​audit.go Adds coordinator analysis results.
pkg/​cli/​audit_summary_build.go Propagates results into summaries.
pkg/​cli/​audit_run_pipeline.go Backfills cached audits.
pkg/​cli/​audit_report.go Adds structured audit output.
pkg/​cli/​audit_report_render.go Renders audit work-queue sections.
pkg/​cli/​audit_render_output.go Merges cached coordinator reports.
pkg/​cli/​audit_cache.go Updates audit cache handling.
pkg/​cli/​audit_analysis_fanout.go Runs coordinator extraction.
docs/​src/​content/​docs/​setup/​cli.md Documents artifact selection.
docs/​src/​content/​docs/​reference/​audit.md Documents report fields and usage.

Comment thread pkg/cli/logs_dispatch_coordinator.go
Comment thread pkg/cli/logs_dispatch_coordinator.go Outdated
Comment thread pkg/cli/logs_dispatch_coordinator.go Outdated
Comment thread pkg/cli/logs_dispatch_coordinator.go Outdated
Comment thread pkg/cli/logs_dispatch_coordinator_render.go Outdated

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request changes

The new work-queue reporting has two blocking cache-path regressions: the default cached audit path can still skip backfilling coordinator evidence entirely, and the compact logs path now leaks cached coordinator data into usage-only runs.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 69.2 AIC · ⌖ 6.96 AIC · ⊞ 20.2K
Comment /review to run again

Comment thread pkg/cli/audit_run_pipeline.go Outdated
Comment thread pkg/cli/logs_format_compact.go

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /tdd and /codebase-design on the new logs_dispatch_coordinator*.go module and its wiring into audit/logs. Requesting changes on one correctness/security concern in the operation-extraction trust model; everything else is solid.

📋 Key Themes & Highlights

Key Themes

  • Trust boundary on log-derived evidence: extractDispatchCoordinatorOperations accepts any job-log line matching a timestamp + known-prefix pattern as genuine coordinator evidence, with no restriction to a specific step/job source. Since this report is meant to be authoritative audit evidence ("operations observed... not operations performed by the audited run" per the PR description), a forged line with a real-looking timestamp from attacker-influenced job output could be indistinguishable from genuine coordinator output.
  • Flag coupling: renderAuditReport's new coordinator-report backfill write is silently gated by opts.NoBaseline, an unrelated flag, without explaining the relationship.
  • Test coverage: the existing forged fixture only demonstrates the (less interesting) timestamp-missing rejection path, not the actual risk of a well-formed forged timestamp.

Positive Highlights

  • ✅ Careful separation of activation-time queue facts (snapshot/transactions), agent intent (finish_intent), and runtime observations (operations) — a clear, well-documented domain model.
  • ✅ Strong validation of snapshot/transaction/finish-intent shapes (parseDispatchCoordinatorTransaction, parseDispatchCoordinatorSnapshot) with comprehensive table-driven tests.
  • ✅ Thoughtful backfill/merge/dedup handling across cache schema bumps (backfillDispatchCoordinatorReport, mergeDispatchCoordinatorReport), with an end-to-end propagation test (TestDispatchCoordinatorReportPropagation) covering the whole pipeline.
  • ✅ Schema, docs, and CLI help text updated consistently alongside the new work-queue artifact set.

Findings are flagged inline. Fallback note: pr-triage ran successfully, so no fallback heuristic was needed.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 148.1 AIC · ⌖ 14.7 AIC · ⊞ 10K
Comment /matt to run again

Comment thread pkg/cli/logs_dispatch_coordinator.go Outdated
Comment thread pkg/cli/audit_render_output.go
Comment thread pkg/cli/logs_dispatch_coordinator_test.go
Require nullable snapshot properties, accept operations only from coordinator-owned step logs, and escape control characters in text reports. Preserve explicit work-queue selection, backfill default audit downloads, and atomically publish completed workflow log archives. Refresh cache schema versions and regression fixtures without exposing cached work queue evidence in usage-only logs.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Please review this PR for forward progress: check unresolved review feedback, failed checks, and whether the branch needs a refresh. If action is needed, please continue with the pr-finisher skill.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 11.4 AIC · ⌖ 8.58 AIC · ⊞ 9.4K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 3, 2026 01:47
…perations-reports

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@copilot Please review this PR for forward progress: check unresolved review feedback, failed checks, and whether the branch needs a refresh. If action is needed, please continue with the pr-finisher ...

Refreshed the branch from main (now at 250e582) and pushed merge commit 5fea602, plus a NoBaseline cache-backfill clarification in 493525d. The open findings are fixed or clarified and replies have been posted. make fmt, make lint, make test, and make recompile passed; the final make agent-report-progress check still reports the pre-existing custom Go linter findings in touched files. The previous PR checks had no failures, but this push has no CI checks yet. CodeQL validation timed out; the available validation tool says not to rerun it.

Copilot AI requested a review from gh-aw-bot October 3, 2026 02:03
@pelikhan
pelikhan merged commit 4f7ee4b into main Oct 3, 2026
21 checks passed
@pelikhan
pelikhan deleted the pelikhan-dispatcher-operations-reports branch October 3, 2026 02:21
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants