Repository navigation
Extending work queue protocol to support checkpoints and maintenance jobs - #67105
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
| const file = options.planFile || process.env.GH_AW_WORK_QUEUE_COMPACTION_PLAN_FILE; | ||
| if (!file) throw new Error("Missing work queue compaction plan path"); | ||
| const plan = readPlan(file); | ||
| const actor = options.actor || { role: "administrator", repository: `${owner}/${repo}`, principal: process.env.GITHUB_ACTOR_ID }; |
There was a problem hiding this comment.
Authenticated the apply path with authenticatePublisher, validate the trusted context, and derive the checkpoint actor from that verified context. Commit: f895d24.
|
@copilot update the dedication instead of adding a comment describing the feature. |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Updated the work-queue reference description to mention checkpoints and maintenance compaction, and removed the feature mention from the generated workflow header. Commit: |
| const plan = readPlan(file); | ||
| const actor = options.actor || { role: "administrator", repository: `${owner}/${repo}`, principal: process.env.GITHUB_ACTOR_ID }; |
There was a problem hiding this comment.
This is addressed in the current implementation: main authenticates the native run with administrator role, derives the actor from the trusted context, and validates any supplied actor against that context. The focused authentication regression test passes. This is present in 4899f05.
|
@copilot resolve the merge conflicts on this branch. |
There was a problem hiding this comment.
🟡 Changes recommended
Checkpoint restoration weakens ancestor authorization and introduces receipt, inspection, error-handling, and finite-chain reliability failures.
7 open findings
Restore creator provenance before authorizing compacted state · New Retry only explicitly retryable maintenance failures · New Use restored policy for compacted current-epoch receipts · New Prevent checkpoint verification depth from growing indefinitely · New Bound checkpoint verification depth across compactions · New Restore Work creator provenance for pending deliveries · New Preserve historical provenance for checkpoint inspection · New
What changed in this PR
Adds Git-backed work-queue checkpoints and scheduled maintenance compaction while preserving replay state and concurrency safety.
Changes:
- Defines checkpoint protocol models, schemas, replay, validation, and fixtures.
- Adds Go/JavaScript checkpoint compaction with Git-parent verification.
- Generates maintenance plan/apply jobs and expands race/conformance coverage.
| File | Description |
|---|---|
specs/work-queue/transactions.tsp |
Defines checkpoint protocol types. |
specs/work-queue/README.md |
Documents checkpoint behavior and verification. |
specs/work-queue/fixtures/checkpoint.json |
Adds shared conformance fixture. |
specs/work-queue/FairWorkQueue.tla |
Models checkpoint races and soundness. |
specs/work-queue/FairCheckpoint.cfg |
Configures checkpoint verification. |
specs/work-queue/CheckpointRaceWitness.cfg |
Configures race witness generation. |
pkg/workqueue/types.go |
Adds checkpoint and projection state types. |
pkg/workqueue/selection.go |
Clones added projection indexes. |
pkg/workqueue/schema/RequestParameters.json |
Extends generated request schema. |
pkg/workqueue/schema/QueueRequest.json |
Adds checkpoint requests. |
pkg/workqueue/schema/QueueOperation.json |
Adds checkpoint operations. |
pkg/workqueue/schema/QueueCommit.json |
Extends commit schema. |
pkg/workqueue/schema/OperationsParameters.json |
Extends operation parameters. |
pkg/workqueue/schema/CheckpointParameters.json |
Defines checkpoint parameter schema. |
pkg/workqueue/schema/CheckpointOperation.json |
Defines checkpoint operation schema. |
pkg/workqueue/request.go |
Authorizes administrator checkpoints. |
pkg/workqueue/replay.go |
Restores and extends checkpoints. |
pkg/workqueue/policy.go |
Initializes checkpoint indexes. |
pkg/workqueue/graph.go |
Indexes observations by identity. |
pkg/workqueue/compaction.go |
Replaces canonicalization with checkpoints. |
pkg/workqueue/compaction_test.go |
Tests checkpoint compaction and CAS behavior. |
pkg/workqueue/checkpoint.go |
Implements checkpoint creation and restoration. |
pkg/workqueue/checkpoint_test.go |
Tests checkpoint conformance. |
pkg/workqueue/branch.go |
Verifies checkpoint Git ancestry. |
pkg/workqueue/branch_test.go |
Extends Git commit mocks. |
pkg/workflow/maintenance_workflow.go |
Enables maintenance for work queues. |
pkg/workflow/maintenance_workflow_yaml.go |
Emits queue compaction jobs. |
pkg/workflow/maintenance_workflow_work_queue_compaction.go |
Generates plan/apply jobs. |
pkg/workflow/maintenance_workflow_work_queue_compaction_test.go |
Tests generated jobs. |
go.sum |
Removes obsolete dependency checksums. |
docs/src/content/docs/specs/work-queue-specification.md |
Updates checkpoint semantics. |
docs/src/content/docs/reference/work-queue.md |
Documents compact behavior. |
actions/setup/js/work_queue_store.cjs |
Adds checkpoint publication and verification. |
actions/setup/js/work_queue_store_checks.cjs |
Adds parent data to Git mocks. |
actions/setup/js/work_queue_replay.cjs |
Implements JavaScript checkpoint replay. |
actions/setup/js/work_queue_policy.cjs |
Authorizes checkpoint requests. |
actions/setup/js/work_queue_dispatch.cjs |
Handles compacted submissions. |
actions/setup/js/work_queue_control_receipts.cjs |
Handles compacted receipt parameters. |
actions/setup/js/work_queue_compaction.test.cjs |
Tests maintenance compaction. |
actions/setup/js/work_queue_compaction_plan.cjs |
Creates bound compaction plans. |
actions/setup/js/work_queue_compaction_apply.cjs |
Applies plans using CAS. |
actions/setup/js/work_queue_checkpoint.test.cjs |
Tests JavaScript conformance. |
.github/workflows/work-queue-stress.yml |
Separates checkpoint race testing. |
.github/workflows/agentics-maintenance.yml |
Adds generated compaction jobs. |
.github/scripts/work-queue-stress.test.cjs |
Exercises real-Git checkpoint races. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| state.requests.set(checkpoint.request.id, checkpoint); | ||
| state.transactions = [checkpoint]; |
There was a problem hiding this comment.
Checkpoint restore rebuilds workCreators from validated historical receipts, and effect authorization consults that provenance before checking parent scopes. The regression test confirms a widened child target is rejected after compaction. Fix and test are in 247c4e3.
| const status = error && typeof error === "object" && "status" in error ? error.status : undefined; | ||
| const conflict = status === 409 || (status === 422 && /not a fast.forward|reference update failed/i.test(error instanceof Error ? error.message : "")); | ||
| if (!conflict && status !== 408 && !(typeof status === "number" && status >= 500) && status !== undefined) throw error; |
There was a problem hiding this comment.
Updated the apply step to retry only the explicitly retryable GitHub/API status codes; non-retryable HTTP responses and local/runtime errors now fail immediately instead of returning a deferred success.
| if ( | ||
| prior.request.fingerprint !== request.fingerprint || | ||
| (prior.request.parameters !== null && canonical(prior.request.parameters) !== canonical(request.parameters)) || | ||
| canonical(prior.actor) !== canonical(actorFromContext(facts.context)) |
There was a problem hiding this comment.
Compacted current-epoch control receipts now use the restored/current policy when their pre-checkpoint Policy transaction is no longer in the live suffix. Added focused regression coverage.
| ) | ||
| throw invalid(); | ||
| if (previous.state.tip !== checkpoint.prior_tip || prepareCheckpoint(previous.transactions, parent, root.actor, root.at)[0].operations[0].state_sha256 !== checkpoint.state_sha256) throw invalid(); | ||
| if (previous.transactions[0]?.operations[0]?.kind === "Checkpoint") await verifyCheckpointGitHistory(options, parent, previous.transactions[0], depth + 1); |
There was a problem hiding this comment.
Checkpoint ancestry verification now walks history iteratively rather than recursing, and the regression suite covers chains beyond 64 checkpoint generations.
| expected.StateSHA256 != checkpoint.StateSHA256 { | ||
| return invalid() | ||
| } | ||
| return b.verifyCheckpointHistory(ctx, parent, previous, depth+1) |
There was a problem hiding this comment.
The checkpoint ancestry verifier now iterates through nested checkpoint generations without the former fixed recursion-depth limit; the long-chain regression coverage exercises more than 64 generations.
| Version: Version, ID: receipt.ID, Request: Request{ | ||
| ID: receipt.RequestID, Kind: receipt.Kind, | ||
| Fingerprint: receipt.Fingerprint, Parameters: parameters, | ||
| }, Actor: receipt.Actor, PolicyEpoch: receipt.PolicyEpoch, | ||
| At: receipt.At, Operations: receipt.Claims, |
There was a problem hiding this comment.
Checkpoint restore now rebuilds the immutable Work-creator index from validated historical receipts, and creator-dependent authorization resolves through that provenance after compaction.
| } | ||
| } | ||
| } | ||
| state.CheckpointReceipts = snapshot.Requests |
There was a problem hiding this comment.
Checkpointed inspection now resolves request history and transaction attribution across the checkpoint boundary, preserving the existing ExplainBeforeClaim/ExplainRequest inspection behavior.
…ueue-protocol # Conflicts: # actions/setup/js/work_queue_replay.cjs # actions/setup/js/work_queue_store.cjs # pkg/workqueue/policy.go # pkg/workqueue/schema/OperationsParameters.json # pkg/workqueue/schema/QueueCommit.json # pkg/workqueue/schema/QueueOperation.json # pkg/workqueue/schema/QueueRequest.json # pkg/workqueue/schema/RequestParameters.json # specs/work-queue/transactions.tsp Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Merged |
| const state = replayTransactionLog(contents); | ||
| const transactions = state.transactions; | ||
| if (transactions.some(transaction => transaction.actor.repository.toLowerCase() !== repository.full_name.toLowerCase())) throw queueError("actor_unauthorized", "queue log contains an actor from another repository"); | ||
| if (verify && transactions[0]?.operations[0]?.kind === "Checkpoint") await verifyCheckpointGitHistory(options, sha, transactions[0], depth); |
There was a problem hiding this comment.
The checked GraphQL reader now calls the shared Git-parent checkpoint verifier using the authoritative ledger head SHA from the GraphQL read, before returning the verified queue.
| const file = options.planFile || process.env.GH_AW_WORK_QUEUE_COMPACTION_PLAN_FILE; | ||
| if (!file) throw new Error("Missing work queue compaction plan path"); | ||
| const plan = readPlan(file); | ||
| const actor = options.actor || { role: "administrator", repository: `${owner}/${repo}`, principal: process.env.GITHUB_ACTOR_ID }; |
There was a problem hiding this comment.
This is addressed in the current implementation: main authenticates the native run with administrator role, derives the actor from the trusted context, and validates any supplied actor against that context. The focused authentication regression test passes. This is present in 4899f05.
|
@copilot address the following outstanding work in one pass:
|
…ueue-protocol Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot address the following outstanding work in one pass:
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 4899f05
|
| const { actorFromContext, validateTrustedContext } = require("./work_queue_policy.cjs"); | ||
| const { authenticatePublisher } = require("./work_queue_native.cjs"); | ||
|
|
||
| const MAX_ATTEMPTS = 3; |
There was a problem hiding this comment.
MAX_ATTEMPTS and PLAN_MAX_BYTES are already module-level constants, so I kept them there. The plan limit is now 16 * 1024 and has boundary coverage. Commit: 2e53ab9.
| const { authenticatePublisher } = require("./work_queue_native.cjs"); | ||
|
|
||
| const MAX_ATTEMPTS = 3; | ||
| const PLAN_MAX_BYTES = 4096; |
There was a problem hiding this comment.
Raised the maximum compaction plan size to 16 KiB and added a test for the exact limit and one byte over. Commit: 2e53ab9.
| if: ${{ steps.apply_0.outcome == 'failure' || steps.apply_1.outcome == 'failure' || steps.apply_2.outcome == 'failure' || steps.apply_3.outcome == 'failure' || steps.apply_4.outcome == 'failure' || steps.apply_5.outcome == 'failure' }} | ||
| run: exit 1 | ||
|
|
||
| work_queue_compaction_plan: |
There was a problem hiding this comment.
@copilot merge work queue compaction in a single job since all the JavaScript is trusted.
There was a problem hiding this comment.
Planning and application now run sequentially in one work_queue_compaction maintenance job; the artifact upload/download handoff is removed. The generated workflow and generator tests are updated. Commit: 2e53ab9.
…ueue-protocol Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot must handle missing work-queue branch |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Added planner regression coverage for a missing
Correction: the commit hash is |
| with: | ||
| destination: ${{ runner.temp }}/gh-aw/actions | ||
|
|
||
| - name: Plan existing work queue |
There was a problem hiding this comment.
@copilot unified steps into a single JavaScript step
There was a problem hiding this comment.
Planning and conditional application now run in a single actions/github-script step. Added a generator regression assertion and regenerated the maintenance workflow. Commit: 6eac2d4.
…ueue-protocol Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>


Pull request created by AI Agent