Skip to content

Avoid GHES masking of cross-job workflow outputs - #66678

Closed
pelikhan with Copilot wants to merge 10 commits into
mainfrom
copilot/cross-job-output-masking
Closed

pelikhan with Copilot wants to merge 10 commits into
mainfrom
copilot/cross-job-output-masking

Conversation

Copilot AI commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

GHES can blank activation outputs whose values match registered secrets. Downstream jobs then request unprefixed artifacts or receive an empty target repository, even when the activation outputs are declared.

  • Artifact names: Compute the existing workflow-call prefix in each downstream job after Setup Scripts. Downloads and uploads use ${{ steps.artifact-prefix.outputs.prefix }}agent rather than a cross-job prefix output.
  • Repository resolution: Resolve the host repository within downstream jobs. Checkout, GitHub App, and dispatch paths fall back to activation outputs and GitHub context if local resolution is empty.
  • Dev-mode checkouts: Restore the local setup action after downstream jobs replace the workspace, preserving its post-step.

Copilot AI linked an issue Oct 7, 2026 that may be closed by this pull request
Copilot AI and others added 2 commits October 7, 2026 20:17
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix cross-job output masking issue Avoid GHES masking of cross-job workflow outputs Oct 7, 2026
Copilot AI requested a review from pelikhan October 7, 2026 20:29
@pelikhan
pelikhan marked this pull request as ready for review October 7, 2026 22:15
Copilot AI balanced review requested due to automatic review settings October 7, 2026 22:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Attempt-dependent local prefixes cause partial reruns to request artifacts that successful upstream jobs never uploaded.

1 open finding
What changed in this PR

This PR makes compiled reusable workflows more resilient to GHES secret masking of cross-job outputs, addressing #38345.

Changes:

  • Compute artifact prefixes locally in downstream jobs.
  • Resolve target repositories locally with activation and GitHub-context fallbacks.
  • Restore development-mode setup actions after workspace replacement and update regression tests.
File Description
pkg/​workflow/​threat_detection_job_test.go Expect local detection artifact prefixes.
pkg/​workflow/​safe_outputs_jobs.go Use repository-name fallbacks for App tokens.
pkg/​workflow/​safe_outputs_config_runtime.go Add dispatch repository fallbacks.
pkg/​workflow/​safe_output_helpers_test.go Expect local agent artifact prefixes.
pkg/​workflow/​safe_jobs.go Add local setup and development-mode restoration.
pkg/​workflow/​safe_jobs_test.go Check prefix computation before downloads.
pkg/​workflow/​publish_code_coverage.go Initialize local coverage artifact prefixes.
pkg/​workflow/​publish_code_coverage_test.go Check coverage setup ordering.
pkg/​workflow/​notify_comment_work_queue_test.go Update work-queue artifact expectations.
pkg/​workflow/​notify_comment_test.go Update conclusion artifact expectations.
pkg/​workflow/​notify_comment_conclusion_helpers.go Add conclusion App repository fallbacks.
pkg/​workflow/​github_app_owner_derivation.go Use resilient repository expressions.
pkg/​workflow/​github_app_owner_derivation_test.go Update repository fallback assertions.
pkg/​workflow/​create_code_scanning_alert.go Add local setup and action restoration.
pkg/​workflow/​compiler_yaml_step_generation.go Generate downstream prefix and repository steps.
pkg/​workflow/​compiler_yaml_checkout.go Use repository fallbacks for checkout.
pkg/​workflow/​compiler_workflow_call.go Centralize local prefix and repository expressions.
pkg/​workflow/​compiler_workflow_call_test.go Test downstream setup generation.
pkg/​workflow/​compiler_safe_outputs_steps.go Add mention-token repository fallbacks.
pkg/​workflow/​compiler_safe_outputs_job.go Update downloads, token fallbacks, and setup ordering.
pkg/​workflow/​compiler_safe_outputs_job_test.go Check local resolution and restoration ordering.
pkg/​workflow/​compiler_main_job_helpers.go Expose the agent’s locally computed prefix.
pkg/​workflow/​compiler_experiments_test.go Expect local experiment artifact prefixes.
pkg/​workflow/​agentic_output_test.go Update mention-token fallback expectations.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

func (c *Compiler) generateSetupStepForJob(jobName string, data *WorkflowData, setupActionRef string, destination string, enableArtifactClient bool, traceID string, parentSpanID string, artifactClientCondition string) []string {
steps := c.generateSetupStepWithArtifactClientCondition(data, setupActionRef, destination, enableArtifactClient, traceID, parentSpanID, artifactClientCondition)
if data != nil && hasWorkflowCallTrigger(data.On) && jobName != "activation" && jobName != "pre_activation" {
steps = append(steps, generateArtifactPrefixStep()...)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The GHES path now uses retry-stable prefixes, while non-GHES jobs continue to consume the producer’s prefix output. I added a regression test for attempts 1 and 2. Fixed in d024eb1.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/workflow/compiler_yaml_step_generation.go:224): Computing a fresh prefix in every downstream job breaks partial reruns of workflow_call workflows. actions/setup/sh/compute_artifact_prefix.sh includes GITHUB_RUN_ATTEMPT in the hash. If activation succeeds on attempt 1 and a failed agent or detection job reruns on attempt 2 without activation, its download now requests an attempt-2 artifact that was never uploaded. The same mismatch affects downstream jobs consuming retained agent artifacts. Resolve download names from the producer's attempt or artifact metadata without relying on maskable cross-job outputs, or use retry-stable names wi... - Avoid GHES masking of cross-job workflow outputs #66678 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: d2cf978
Sous-chef work: 3dfe952b08a0003a5d25cd3bcab40bb1043f74f02c5af115bf5f24b947fab7c8
Sous-chef state: a82fbb912e4a19dbdeb6e8fd0b469c135807e94e4bdda09d1d55e6c7691d2f5f

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 3.24 AIC · ⌖ 12.7 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 7, 2026 22:50
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
…put-masking

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

@copilot enable this mode when ghes: true

Copilot AI and others added 3 commits October 7, 2026 23:15
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
…put-masking

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Copilot AI requested a review from gh-aw-bot October 7, 2026 23:36
Copilot AI and others added 2 commits October 7, 2026 23:42
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@copilot enable this mode when ghes: true

The downstream artifact-prefix and repository-resolution behavior is now enabled only for ghes: true; non-GHES workflows retain producer outputs. Fixed in d024eb1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cross-Job Output Masking

4 participants