Repository navigation
Disable uv Actions caching and isolate sandbox runtime paths - #66958
SivaKesava1 with Copilot wants to merge 8 commits into
Conversation
Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.
|
|
✅ PR Code Quality Reviewer completed the code quality review.
|
|
🧠 Matt Pocock Skills Reviewer is reviewing this pull request using Matt Pocock's engineering skills... |
|
✅ Ponytail Reviewer completed successfully! Lean already. Ship.
|
Comment MemoryPeek at saved memory (pr-code-quality-reviewer)Note This comment is managed by comment memory.Expand the saved memory block to view or edit the persistent context for this thread.
|
There was a problem hiding this comment.
Request changes
The new uv hardening is headed in the right direction, but the validation path still still relies on the old substring-based runtime-step deduper, so we can silently drop unrelated uses: steps that merely contain astral-sh/setup-uv in the action name.
Blocking theme
The PR tightens repo matching for host-only env detection, but validateRuntimeSetupCaches still deduplicates through DeduplicateRuntimeSetupStepsFromCustomSteps, which matches on strings.Contains. That means an impostor action such as other/astral-sh/setup-uv@... can disappear before validation and from the compiled workflow whenever uv is otherwise detected. This is a compiler correctness regression, not just a warning-quality issue.
🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 58 AIC · ⌖ 5.62 AIC · ⊞ 19.8K
Comment /review to run again
There was a problem hiding this comment.
🟡 Changes recommended
Secret-expression detection and nested agent-job step discovery leave gaps in the intended security protections.
2 open findings
What changed in this PR
Updates gh-aw’s compiler to address #66779 by separating uv’s sandbox storage from host paths and disabling shared Actions caching.
Changes:
- Disable generated uv caching and validate preserved custom setup steps.
- Exclude host-only uv paths and locally git-ignore Cloud Hypervisor tool state.
- Add regression coverage, document behavior, and regenerate workflow locks.
| File | Description |
|---|---|
| pkg/workflow/runtime_setup_test.go | Tests cache defaults and deduplication. |
| pkg/workflow/runtime_setup_integration_test.go | Covers topologies, overrides, and validation. |
| pkg/workflow/runtime_definitions.go | Defines uv cache and host-path defaults. |
| pkg/workflow/runtime_deduplication.go | Prevents deduplicated cache overrides. |
| pkg/workflow/runtime_cache_validation.go | Validates custom uv caching. |
| pkg/workflow/runtime_cache_validation_test.go | Tests cache validation policies. |
| pkg/workflow/compiler_validators.go | Registers runtime cache validation. |
| pkg/workflow/cloud_hypervisor_test.go | Tests local tool-state exclusions. |
| pkg/workflow/awf_env.go | Collects host-only environment exclusions. |
| pkg/workflow/awf_env_test.go | Tests exclusions and override precedence. |
| pkg/workflow/awf_command_builder.go | Locally excludes .awf-home/ from Git. |
| docs/src/content/docs/reference/frontmatter.md | Documents cache and sandbox behavior. |
| .github/workflows/weekly-issue-summary.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/stale-repo-identifier.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/smoke-work-queue.lock.yml | Adds local tool-state exclusion. |
| .github/workflows/python-data-charts.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/prompt-clustering-analysis.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/portfolio-analyst.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/org-health-report.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/github-mcp-structural-analysis.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/detection-analysis-report.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-spending-forecast.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-security-observability.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-repo-chronicle.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-performance-summary.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-news.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-mcp-concurrency-analysis.lock.yml | Adds local tool-state exclusion. |
| .github/workflows/daily-issues-report.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-fact.lock.yml | Adds local tool-state exclusion. |
| .github/workflows/daily-experiment-report.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-code-metrics.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/daily-caveman-optimizer.lock.yml | Adds local tool-state exclusion. |
| .github/workflows/daily-awf-spec-compiler-surfacing.lock.yml | Adds local tool-state exclusion. |
| .github/workflows/daily-agentrx-trace-optimizer.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/copilot-session-insights.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/copilot-pr-nlp-analysis.lock.yml | Disables uv caching; excludes host paths. |
| .github/workflows/copilot-centralization-optimizer.lock.yml | Adds local tool-state exclusion. |
| .github/workflows/audit-workflows.lock.yml | Applies cache, path, and tool-state protections. |
| .github/workflows/api-consumption-report.lock.yml | Disables uv caching; excludes host paths. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
🏗️ Design Decision Gate — ADR RequiredThis PR makes significant changes to core business logic (763 new lines across 📄 Draft ADR committed:
🔍 Evidence used
📋 What to do next
Once an ADR is linked in the PR body, this gate will re-run and verify the implementation matches the decision. ❓ Why ADRs Matter
ADRs create a searchable, permanent record of why the codebase looks the way it does. Future contributors (and your future self) will thank you. 📋 Michael Nygard ADR Format ReferenceAn ADR must contain these four sections to be considered complete:
All ADRs are stored in
|
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: ccd3c89
|
…permission-issue Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot /pr-finisher Verified at
|
…permission-issue Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>
Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>
Merged latest main with
Finisher pass pushed |
|
Ready for review. Sandbox-verified at |
|
Per @pelikhan's request to split this into smaller PRs, it's superseded by:
The |

setup-uv exports host-only directories that uv cannot write inside the AWF sandbox. Making those paths writable while retaining Actions caching would allow agent-written content to enter repository-wide caches.
Cache safety
enable-cache: false; prevent deduplication from overriding it.Sandbox paths
UV_CACHE_DIRandUV_PYTHON_INSTALL_DIRunless explicitly configured through workflow, engine, or sandbox environment settings.HOME, retaining the existing AWF version gate..awf-home/to keep tool state out of normal staging and patches.Coverage and documentation
Generated setup-uv configuration:
runtimes: uv: setup-uv'sUV_CACHE_DIRis unwritable inside the AWF sandbox, and agent jobs save a repo-wide setup-uv cache #66779