Skip to content

Add scoped GitHub Issues mirrors for the Git-backed work queue - #67025

Merged
pelikhan merged 11 commits into
mainfrom
pelikhan-work-queue-issues
Oct 9, 2026
Merged

pelikhan merged 11 commits into
mainfrom
pelikhan-work-queue-issues

Conversation

@pelikhan

@pelikhan pelikhan commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Why

Git-backed queue state is durable and authoritative, but difficult for humans to follow during execution and delivery. This adds GitHub Issues as a human-facing mirror of already-admitted Work without changing scheduling, Claim authority, or Result verification.

Approach

  • Add optional tools.work-queue.issues configuration with a default work label and optional pre-provisioned native organization single-select status field. No Project, Issue intake, global reconciliation, new job, or new trigger is introduced.
  • Extend the shared Go/JavaScript/TypeSpec contract with immutable, lossless backing_issue, checked IssueLink and IssueComment records, and installed projector rules. Scope every mutation to this run's checked admissions or original authenticated Claims, including workflow revision, principal, run, and attempt.
  • Require exact installed projectors[].backing_issues grants for pre-existing Issues at admission and independently for the actual projecting principal/workflow/revision. Projector-created mirrors use verified creation receipts and checked links. Repository access, agent payload, markers, and summary handles do not establish target ownership.
  • Project through the existing activation and conclusion hooks using fresh checked reads, expected-head GraphQL publication, durable receipt journals, and per-Work/Issue coordination. Preserve human text, unrelated labels/fields, and discussion. Closure requires a verified non-PR Result and trusted projectors[].completion_policy from Policy at Work admission; default keep-open and later policy expansion cannot grant closure retroactively.
  • Package delightful bodies, summaries, and Claim comments in actions/setup/md, always including generated-by attribution. Use withRetry for proven pre-execution creation rejections, never blind retries of ambiguous writes. Protected hook and App tokens request contents: write, issues: write, and actions: read; agents do not receive writer credentials.

Architecture decision: ADR-67025: Scoped GitHub Issues mirrors.

Compatibility and recovery

Upgrade every closed-schema version-3 reader and deployment before enabling the new records. Administrators provision native fields/options separately. Missing or unwritable fields leave the queue committed and synchronization explicitly pending. Unprovable native writes retain non-expiring coordination rather than risk duplicate creation or stale updates; only authorized hooks for the same Work/Claims may retry.

An interruption before sending and an accepted native write followed by loss of its receipt can leave identical durable state. Those targets can remain pending indefinitely; automatic safe fence recovery is not implemented, and merely running a later authorized hook cannot establish the missing creation provenance. No exactly-once recovery-liveness guarantee is claimed.

Mocked authenticated hook budgets cover coordination and receipt publication: 6 requests for 25 unchanged Issues, 9 for an existing Issue/new summary, and 15 for new Issue creation, bindings, and coordination. Ordinary checked queue read/publication takes 2 requests. Shared activation work and App token minting are additional; live mutation primary cost is not claimed.

Validation

  • npm run typecheck and npx vitest run work_queue --no-file-parallelism: 954 tests pass across 48 suites.
  • JavaScript shard 2/4 passes locally: 139 suites, 3,661 tests. It also succeeded in CI on 471bb38b15, as did shard 3/4.
  • The subsequent shard 4/4 failure was reproduced exactly: SAFE_OUTPUTS_FILES omitted two PR-added transitive dependencies. f4e254f5e9bac7547f4226f91ae283f26ac78752 adds work_queue_issue_contract.cjs and work_queue_checked_transport.cjs to the isolated runtime, retaining the original assertion and adding explicit coverage. All 15 deployment tests pass. The exact shard passes locally: 136 suites passed, 2 skipped; 4,231 tests passed, 26 skipped, using Bash 5 and canonical session-local runner/workspace paths.
  • Native Go grant/binding tests and Go/JavaScript policy/replay parity pass. The final publication gate includes impacted Go unit tests.
  • python3 specs/work-queue/generate_contract.py --check, pinned official TypeSpec 1.16.0 compilation/emission, and verify_official_contract.py: all 45 schemas match.
  • make build, make build-wasm, formatting, lint, and the final make agent-report-progress pass. All 333 existing workflows compile without lock drift. The packaging follow-up also passes typecheck, JavaScript lint, and its own final publication gate.

Coverage includes concurrent binding collisions, overlapping projectors, partial/malformed receipts, shared queues, original-worker native authentication and rerun refusal, indistinguishable interrupted Issue/comment creation, oversized mutation chunking, comment-only status changes, native-field no-ops, missing permissions, label repair, staged behavior, exact target grants, admission-time closure policy, packaged runtime dependency completeness, and mandatory footer rendering. No live Issue/organization-field writes or hosted workflow runs were performed.

Finisher and CI hand-off

The authority/review fixes are pushed as 471bb38b15d38261902d4e934050768f3529504a; all eight additional review threads were replied to and resolved. The deployment follow-up is pushed as f4e254f5e9bac7547f4226f91ae283f26ac78752; a final review read still finds zero unresolved threads. Current main was integrated without conflicts in the earlier pass, and regenerated documentation fixes the missing work-queue: true example reproduced from CI's synthetic merge without weakening the assertion.

CI did run on 471bb38b15; a re-trigger was not the blocker for that HEAD. Its lint-go-govulncheck failure still reports 11 inherited Go 1.26.8 standard-library vulnerabilities, fixed in Go 1.26.9. Dependency manifests and traced existing sources were unchanged by this feature; this remains an external toolchain blocker, not a suppressed check. Shard 4's PR-introduced packaging defect is fixed and locally reproduced green in the follow-up.

CI for the new f4e254f5e9 HEAD is unverified in this hand-off; no workflows were manually triggered, re-run, or watched. The PR is mergeable and non-draft, but human approval and successful CI are still required. It has not been merged.

Keep Git authoritative while projecting checked admissions and original Claims through protected activation and conclusion hooks. Add immutable bindings, scoped native-field and comment projection, conservative recovery, checked GraphQL transport, packaged message templates, and required token permissions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pelikhan
pelikhan marked this pull request as ready for review October 8, 2026 23:42
Copilot AI balanced review requested due to automatic review settings October 8, 2026 23:42
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Generated by Ponytail Reviewer for #67025

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ponytail review: one dead guard can be removed.

net: -1 lines possible.

Generated by ✂️ Ponytail Reviewer for #67025 · codex · gpt56 · 22.8 AIC · ⌖ 6.33 AIC · ⊞ 13.4K
Comment /ponytail to run again

Comment thread actions/setup/js/work_queue_issue_api.cjs
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🏗️ Design Decision Gate — ADR Required

This PR makes significant changes to core business logic (~1500 new lines across pkg/workqueue, pkg/workflow, and actions/setup/js) but does not have a linked Architecture Decision Record (ADR).

📄 Draft ADR committed: docs/adr/67025-mirror-work-queue-work-to-github-issues.md — review and complete it before merging.

🔒 This PR cannot merge until an ADR is linked in the PR body.

📋 What to do next
  1. Review the draft ADR committed to your branch — it was generated from the PR description and diff
  2. Complete the missing sections — confirm the deciders, add context the AI couldn't infer, and refine the alternatives you actually weighed (bidirectional Issue intake, a global reconciliation job, Projects v2)
  3. Commit the finalized ADR to docs/adr/ on your branch and flip Status from Draft once accepted
  4. Reference the ADR in this PR body by adding a line such as:

    ADR: ADR-67025: Mirror Git-backed Work Queue Work to Scoped GitHub Issues

Once an ADR is linked in the PR body, this gate will re-run and verify the implementation matches the decision.

🔍 Evidence used
  • No docs/adr/67025-*.md existed on the branch before this run; latest ADR on branch was 66998-native-go-agy-engine-and-authored-dry-run-feature-scope.md
  • PR body contains no ADR / "Architecture Decision" link or section
  • 62 changed files; business-logic additions exceed the 100-line default threshold (no .design-gate.yml override present)
❓ Why ADRs Matter

"AI made me procrastinate on key design decisions. Because refactoring was cheap, I could always say 'I'll deal with this later.' Deferring decisions corroded my ability to think clearly."

ADRs create a searchable, permanent record of why the codebase looks the way it does. Future contributors (and your future self) will thank you.

📋 Michael Nygard ADR Format Reference

An ADR must contain these four sections to be considered complete:

  • Context — What is the problem? What forces are at play?
  • Decision — What did you decide? Why?
  • Alternatives Considered — What else could have been done?
  • Consequences — What are the trade-offs (positive and negative)?

All ADRs are stored in docs/adr/ as Markdown files numbered by PR number.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · opus50 · 46 AIC · ⌖ 51.3 AIC · ⊞ 1.8K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES

The queue→Issue projector still has a blocking recovery hole: both Issue creation and comment creation can get stuck permanently after a local interruption because the journal is written before the native mutation is attempted. It also regresses rerun status from Running back to Assigned.

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 65.1 AIC · ⌖ 5.54 AIC · ⊞ 19.9K
Comment /review to run again

Comment thread actions/setup/js/work_queue_issues.cjs
Comment thread actions/setup/js/work_queue_issues.cjs
Comment thread actions/setup/js/work_queue_issues.cjs

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /codebase-design (architecture/seam review, per pr-triage fallback — /tdd coverage was already extensive and didn't surface actionable gaps) across the new Issue-mirroring subsystem (work_queue_issues.cjs, work_queue_issue_api.cjs, work_queue_issue_contract.cjs). No blocking correctness issues found; comments below are about interface clarity and reducing duplicated magic numbers/logic as this subsystem grows.

📋 Key Themes & Highlights

Key Themes

  • Deep-module boundary blur in main() (work_queue_issues.cjs): rate-limit pacing/instrumentation is inlined into the top-level orchestration function, making it harder to unit test in isolation.
  • Repeated magic numbers: the 25-target batch cap appears in 4+ places across two files with no single source of truth.
  • Dense invariant encodings: isRejectedIssueCreation and the comment-handle collision check in applyIssueBinding correctly implement subtle, load-bearing rules, but their current one-liner form makes the "why" hard to recover without re-deriving the invariant.

Positive Highlights

  • ✅ Comprehensive compatibility story: closed-schema versioning, explicit pending states instead of silent fallback, no blind retries of ambiguous native writes.
  • ✅ Strong test coverage for the trickiest concurrency/ambiguity paths (batch chunking at 50, rate-limited retry vs. ambiguous-timeout, partial malformed creation responses).
  • ✅ Documentation (docs/reference/work-queue.md) clearly explains the new issues config, authority model, and recovery semantics — no /grill-with-docs gaps found.

Note: the pre-fetched diff patch is capped at 3000 lines and was truncated partway through docs/src/content/docs/reference/frontmatter-full.md; the Go-side files (pkg/workflow/work_queue_issues.go, pkg/workqueue/issues.go, schema JSON) were not visible in the diff and were only spot-checked directly in the working tree, not reviewed in full.

@copilot please address the review comments above.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 114.1 AIC · ⌖ 13.8 AIC · ⊞ 10.1K
Comment /matt to run again

Comment thread actions/setup/js/work_queue_issue_api.cjs Outdated
Comment thread actions/setup/js/work_queue_issue_contract.cjs
Comment thread actions/setup/js/work_queue_issues.cjs Outdated
Comment thread actions/setup/js/work_queue_issue_api.cjs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Worker conclusion projection currently cannot authenticate, and projector policy validation is inconsistent across readers.

3 open findings
What changed in this PR

Adds GitHub Issues as an optional human-facing mirror for the Git-backed work queue while preserving Git as the authority.

Changes:

  • Extends queue contracts with projector rules, Issue links, and comment handles.
  • Adds activation/conclusion projection with scoped credentials and checked publication.
  • Adds templates, documentation, and extensive Go/JavaScript coverage.

Security review found no agent credential exposure, but identified worker conclusion authentication and cross-reader contract inconsistencies.

File Description
specs/​work-queue/​transactions.tsp Extends the queue contract.
specs/​work-queue/​README.md Documents contract compatibility.
pkg/​workqueue/​types.go Adds Go projector and Issue state types.
pkg/​workqueue/​schema/​WorkOperation.json Adds backing-Issue schema.
pkg/​workqueue/​schema/​SubmitParameters.json Supports backing Issues on submission.
pkg/​workqueue/​schema/​RequestParameters.json Adds projector operations and policy.
pkg/​workqueue/​schema/​QueueRequest.json Adds Issue-link requests.
pkg/​workqueue/​schema/​QueuePolicy.json Adds projector rules.
pkg/​workqueue/​schema/​QueueOperation.json Adds Issue operations.
pkg/​workqueue/​schema/​QueueCommit.json Extends commit records.
pkg/​workqueue/​schema/​ProjectorRule.json Defines projector authority.
pkg/​workqueue/​schema/​PolicyOperation.json Extends policy operations.
pkg/​workqueue/​schema/​OperationsParameters.json Adds Issue operation parameters.
pkg/​workqueue/​schema/​IssueLinkOperation.json Defines immutable Issue links.
pkg/​workqueue/​schema/​IssueCommentOperation.json Defines comment handles.
pkg/​workqueue/​schema/​DispatchOperation.json Allows projector actors.
pkg/​workqueue/​schema/​Actor.json Adds the projector role.
pkg/​workqueue/​request.go Authorizes projector requests.
pkg/​workqueue/​replay.go Replays Issue bindings.
pkg/​workqueue/​policy.go Validates projector permissions.
pkg/​workqueue/​issues.go Implements Go projection authority.
pkg/​workqueue/​issues_test.go Tests Go/JavaScript parity.
pkg/​workqueue/​graph.go Validates backing-Issue uniqueness.
pkg/​workqueue/​evidence.go Verifies backing-Issue identity.
pkg/​workflow/​work_queue_policy.go Integrates Issue configuration.
pkg/​workflow/​work_queue_issues.go Generates projection steps and tokens.
pkg/​workflow/​work_queue_issues_test.go Tests workflow compilation.
pkg/​workflow/​notify_comment.go Adds conclusion projection.
pkg/​workflow/​notify_comment_conclusion_helpers.go Ensures conclusion execution.
pkg/​workflow/​compiler_activation_permissions.go Grants activation permissions.
pkg/​workflow/​compiler_activation_outputs.go Adds activation projection.
pkg/​parser/​schemas/​main_workflow_schema.json Defines frontmatter configuration.
docs/​src/​content/​docs/​specs/​work-queue-specification.md Records implementation evidence.
docs/​src/​content/​docs/​reference/​work-queue.md Documents backing Issues.
docs/​src/​content/​docs/​reference/​frontmatter-full.md Documents new frontmatter fields.
docs/​src/​content/​docs/​guides/​deploy-work-queue.md Adds deployment guidance.
actions/​setup/​md/​work_queue_issue_summary.md Adds summary template.
actions/​setup/​md/​work_queue_issue_status.md Adds status template.
actions/​setup/​md/​work_queue_issue_claim.md Adds Claim template.
actions/​setup/​md/​work_queue_issue_body.md Adds Issue body template.
actions/​setup/​md/​work_queue_generated_footer.md Adds attribution template.
actions/​setup/​js/​write_work_queue_snapshot.cjs Projects during activation.
actions/​setup/​js/​work_queue_store.cjs Enables checked GraphQL transport.
actions/​setup/​js/​work_queue_replay.cjs Replays Issue records.
actions/​setup/​js/​work_queue_policy.cjs Validates projector policies.
actions/​setup/​js/​work_queue_mcp_server.cjs Accepts backing-Issue submissions.
actions/​setup/​js/​work_queue_issues.test.cjs Registers projector tests.
actions/​setup/​js/​work_queue_issues.cjs Implements Issue projection.
actions/​setup/​js/​work_queue_issues_checks.cjs Tests projector behavior.
actions/​setup/​js/​work_queue_issues_acceptance.test.cjs Registers acceptance tests.
actions/​setup/​js/​work_queue_issues_acceptance_checks.cjs Tests recovery and transport.
actions/​setup/​js/​work_queue_issue_messages.cjs Renders Issue content.
actions/​setup/​js/​work_queue_issue_journal.cjs Validates durable receipts.
actions/​setup/​js/​work_queue_issue_coordination.cjs Coordinates concurrent projection.
actions/​setup/​js/​work_queue_issue_contract.cjs Enforces Issue authority.
actions/​setup/​js/​work_queue_issue_api.cjs Implements native Issue operations.
actions/​setup/​js/​work_queue_intents.cjs Normalizes backing Issues.
actions/​setup/​js/​work_queue_graph.cjs Validates Issue-backed Work.
actions/​setup/​js/​work_queue_documentation.test.cjs Tests deployment examples.
actions/​setup/​js/​work_queue_dispatch.cjs Resolves backing-Issue identity.
actions/​setup/​js/​work_queue_checked_transport.cjs Adds checked GraphQL reads/writes.
.github/​aw/​work-queue.md Adds concise operator guidance.

🧠 Review effort: Balanced

Comment thread actions/setup/js/work_queue_issues.cjs Outdated
Comment thread actions/setup/js/work_queue_policy.cjs Outdated
Comment thread specs/work-queue/transactions.tsp
Authenticate worker conclusion projection with original dispatch provenance. Preserve conservative ambiguous-write recovery with regression coverage, verify oversized mutation chunking, and finalize the architecture decision record.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread actions/setup/js/work_queue_issues.cjs Outdated
pelikhan and others added 2 commits October 8, 2026 17:39
Require exact installed grants for existing Issues and trusted admission-time closure policy. Preserve native reader parity, clarify recovery and request pacing, and integrate main with regenerated schema documentation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copy the Issue contract and checked transport into the isolated safe-outputs runtime. Add explicit deployment coverage while retaining the transitive dependency assertion that caught the missing files in JavaScript shard 4.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot conduct a security review, DevOps review, and GitHub API usage review. Update the compiler thread specification.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@copilot conduct a security review, DevOps review, and GitHub API usage review. Update the compiler thread specification.

Security review found no exploitable issue. The DevOps review confirmed that rejecting permissions.pull === false can misclassify GitHub App installation-token access; removed that check and added a regression test. The API review found no mutation/authorization bypass in the null-safety paths. Updated the compiler review-thread spec with lookup, pagination, stale-node, staged-mode, and token-failure semantics. Changes pushed in b52d7aa.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 645a8e1
Sous-chef work:
Sous-chef state: f4d185ce8db224adbe141a919b44d8883bb0f0a59558bf262ac7d3e15018431b

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 5.01 AIC · ⌖ 7.7 AIC · ⊞ 1K · ◷
Comment /souschef to run again

…ssues

# Conflicts:
#	actions/setup/js/work_queue_store_checks.cjs

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes....

Merged current main with make merge-main in 80ed458, resolving the queue-store test conflict while retaining the broader upstream regression coverage. Condensed the operator instructions to 796 words and pushed 3c62ce1. All 12 review threads are already resolved. Local build, workflow recompilation, and the final change-scoped gate pass. I did not trigger CI; the new head has no reported status checks, and GitHub currently reports the PR as blocked pending the required human/CI gates.

Copilot AI requested a review from gh-aw-bot October 9, 2026 03:11
@pelikhan

pelikhan commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot update TLA+ specs and model.

Copilot AI and others added 2 commits October 9, 2026 03:20
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@copilot update TLA+ specs and model.

Added specs/work-queue/IssueProjection.tla with bounded authority and recovery checks for existing Issue grants, receipt-backed mirrors, original-Claim/projector authorization, admission-captured close policy, PR-open behavior, and ambiguous-creation fencing. Registered four positive configurations and three expected counterexamples in specs/work-queue/check.sh, and documented the model’s scope and limitations in specs/work-queue/README.md. All focused TLC cases and the final change-scoped gate pass. Pushed as 3a0e43b6.

@pelikhan
pelikhan merged commit ec3d142 into main Oct 9, 2026
47 checks passed
@pelikhan
pelikhan deleted the pelikhan-work-queue-issues branch October 9, 2026 04:18
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants