Skip to content

Extending work queue protocol to support checkpoints and maintenance jobs - #67105

Merged
pelikhan merged 17 commits into
mainfrom
copilot/extend-work-queue-protocol
Oct 9, 2026
Merged

pelikhan merged 17 commits into
mainfrom
copilot/extend-work-queue-protocol

Conversation

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Pull request created by AI Agent

Copilot AI and others added 2 commits October 9, 2026 02:39
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
const file = options.planFile || process.env.GH_AW_WORK_QUEUE_COMPACTION_PLAN_FILE;
if (!file) throw new Error("Missing work queue compaction plan path");
const plan = readPlan(file);
const actor = options.actor || { role: "administrator", repository: `${owner}/${repo}`, principal: process.env.GITHUB_ACTOR_ID };

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Authenticated the apply path with authenticatePublisher, validate the trusted context, and derive the checkpoint actor from that verified context. Commit: f895d24.

@pelikhan

pelikhan commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@copilot update the dedication instead of adding a comment describing the feature.

Copilot AI and others added 2 commits October 9, 2026 04:42
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@copilot update the dedication instead of adding a comment describing the feature.

Updated the work-queue reference description to mention checkpoints and maintenance compaction, and removed the feature mention from the generated workflow header. Commit: f3f4883c.

Copilot AI requested a review from pelikhan October 9, 2026 04:47
Comment on lines +44 to +45
const plan = readPlan(file);
const actor = options.actor || { role: "administrator", repository: `${owner}/${repo}`, principal: process.env.GITHUB_ACTOR_ID };

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is addressed in the current implementation: main authenticates the native run with administrator role, derives the actor from the trusted context, and validates any supplied actor against that context. The focused authentication regression test passes. This is present in 4899f05.

@pelikhan
pelikhan marked this pull request as ready for review October 9, 2026 05:59
Copilot AI balanced review requested due to automatic review settings October 9, 2026 05:59
@pelikhan

pelikhan commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts on this branch.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Checkpoint restoration weakens ancestor authorization and introduces receipt, inspection, error-handling, and finite-chain reliability failures.

7 open findings
What changed in this PR

Adds Git-backed work-queue checkpoints and scheduled maintenance compaction while preserving replay state and concurrency safety.

Changes:

  • Defines checkpoint protocol models, schemas, replay, validation, and fixtures.
  • Adds Go/JavaScript checkpoint compaction with Git-parent verification.
  • Generates maintenance plan/apply jobs and expands race/conformance coverage.
File Description
specs/​work-queue/​transactions.tsp Defines checkpoint protocol types.
specs/​work-queue/​README.md Documents checkpoint behavior and verification.
specs/​work-queue/​fixtures/​checkpoint.json Adds shared conformance fixture.
specs/​work-queue/​FairWorkQueue.tla Models checkpoint races and soundness.
specs/​work-queue/​FairCheckpoint.cfg Configures checkpoint verification.
specs/​work-queue/​CheckpointRaceWitness.cfg Configures race witness generation.
pkg/​workqueue/​types.go Adds checkpoint and projection state types.
pkg/​workqueue/​selection.go Clones added projection indexes.
pkg/​workqueue/​schema/​RequestParameters.json Extends generated request schema.
pkg/​workqueue/​schema/​QueueRequest.json Adds checkpoint requests.
pkg/​workqueue/​schema/​QueueOperation.json Adds checkpoint operations.
pkg/​workqueue/​schema/​QueueCommit.json Extends commit schema.
pkg/​workqueue/​schema/​OperationsParameters.json Extends operation parameters.
pkg/​workqueue/​schema/​CheckpointParameters.json Defines checkpoint parameter schema.
pkg/​workqueue/​schema/​CheckpointOperation.json Defines checkpoint operation schema.
pkg/​workqueue/​request.go Authorizes administrator checkpoints.
pkg/​workqueue/​replay.go Restores and extends checkpoints.
pkg/​workqueue/​policy.go Initializes checkpoint indexes.
pkg/​workqueue/​graph.go Indexes observations by identity.
pkg/​workqueue/​compaction.go Replaces canonicalization with checkpoints.
pkg/​workqueue/​compaction_test.go Tests checkpoint compaction and CAS behavior.
pkg/​workqueue/​checkpoint.go Implements checkpoint creation and restoration.
pkg/​workqueue/​checkpoint_test.go Tests checkpoint conformance.
pkg/​workqueue/​branch.go Verifies checkpoint Git ancestry.
pkg/​workqueue/​branch_test.go Extends Git commit mocks.
pkg/​workflow/​maintenance_workflow.go Enables maintenance for work queues.
pkg/​workflow/​maintenance_workflow_yaml.go Emits queue compaction jobs.
pkg/​workflow/​maintenance_workflow_work_queue_compaction.go Generates plan/apply jobs.
pkg/​workflow/​maintenance_workflow_work_queue_compaction_test.go Tests generated jobs.
go.sum Removes obsolete dependency checksums.
docs/​src/​content/​docs/​specs/​work-queue-specification.md Updates checkpoint semantics.
docs/​src/​content/​docs/​reference/​work-queue.md Documents compact behavior.
actions/​setup/​js/​work_queue_store.cjs Adds checkpoint publication and verification.
actions/​setup/​js/​work_queue_store_checks.cjs Adds parent data to Git mocks.
actions/​setup/​js/​work_queue_replay.cjs Implements JavaScript checkpoint replay.
actions/​setup/​js/​work_queue_policy.cjs Authorizes checkpoint requests.
actions/​setup/​js/​work_queue_dispatch.cjs Handles compacted submissions.
actions/​setup/​js/​work_queue_control_receipts.cjs Handles compacted receipt parameters.
actions/​setup/​js/​work_queue_compaction.test.cjs Tests maintenance compaction.
actions/​setup/​js/​work_queue_compaction_plan.cjs Creates bound compaction plans.
actions/​setup/​js/​work_queue_compaction_apply.cjs Applies plans using CAS.
actions/​setup/​js/​work_queue_checkpoint.test.cjs Tests JavaScript conformance.
.github/​workflows/​work-queue-stress.yml Separates checkpoint race testing.
.github/​workflows/​agentics-maintenance.yml Adds generated compaction jobs.
.github/​scripts/​work-queue-stress.test.cjs Exercises real-Git checkpoint races.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +819 to +820
state.requests.set(checkpoint.request.id, checkpoint);
state.transactions = [checkpoint];

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checkpoint restore rebuilds workCreators from validated historical receipts, and effect authorization consults that provenance before checking parent scopes. The regression test confirms a widened child target is rejected after compaction. Fix and test are in 247c4e3.

Comment on lines +77 to +79
const status = error && typeof error === "object" && "status" in error ? error.status : undefined;
const conflict = status === 409 || (status === 422 && /not a fast.forward|reference update failed/i.test(error instanceof Error ? error.message : ""));
if (!conflict && status !== 408 && !(typeof status === "number" && status >= 500) && status !== undefined) throw error;

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the apply step to retry only the explicitly retryable GitHub/API status codes; non-retryable HTTP responses and local/runtime errors now fail immediately instead of returning a deferred success.

Comment on lines +148 to +151
if (
prior.request.fingerprint !== request.fingerprint ||
(prior.request.parameters !== null && canonical(prior.request.parameters) !== canonical(request.parameters)) ||
canonical(prior.actor) !== canonical(actorFromContext(facts.context))

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Compacted current-epoch control receipts now use the restored/current policy when their pre-checkpoint Policy transaction is no longer in the live suffix. Added focused regression coverage.

Comment thread actions/setup/js/work_queue_store.cjs Outdated
)
throw invalid();
if (previous.state.tip !== checkpoint.prior_tip || prepareCheckpoint(previous.transactions, parent, root.actor, root.at)[0].operations[0].state_sha256 !== checkpoint.state_sha256) throw invalid();
if (previous.transactions[0]?.operations[0]?.kind === "Checkpoint") await verifyCheckpointGitHistory(options, parent, previous.transactions[0], depth + 1);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checkpoint ancestry verification now walks history iteratively rather than recursing, and the regression suite covers chains beyond 64 checkpoint generations.

Comment thread pkg/workqueue/branch.go Outdated
expected.StateSHA256 != checkpoint.StateSHA256 {
return invalid()
}
return b.verifyCheckpointHistory(ctx, parent, previous, depth+1)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The checkpoint ancestry verifier now iterates through nested checkpoint generations without the former fixed recursion-depth limit; the long-chain regression coverage exercises more than 64 generations.

Comment thread pkg/workqueue/checkpoint.go Outdated
Comment on lines +226 to +230
Version: Version, ID: receipt.ID, Request: Request{
ID: receipt.RequestID, Kind: receipt.Kind,
Fingerprint: receipt.Fingerprint, Parameters: parameters,
}, Actor: receipt.Actor, PolicyEpoch: receipt.PolicyEpoch,
At: receipt.At, Operations: receipt.Claims,

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checkpoint restore now rebuilds the immutable Work-creator index from validated historical receipts, and creator-dependent authorization resolves through that provenance after compaction.

}
}
}
state.CheckpointReceipts = snapshot.Requests

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checkpointed inspection now resolves request history and transaction attribution across the checkpoint boundary, preserving the existing ExplainBeforeClaim/ExplainRequest inspection behavior.

…ueue-protocol

# Conflicts:
#	actions/setup/js/work_queue_replay.cjs
#	actions/setup/js/work_queue_store.cjs
#	pkg/workqueue/policy.go
#	pkg/workqueue/schema/OperationsParameters.json
#	pkg/workqueue/schema/QueueCommit.json
#	pkg/workqueue/schema/QueueOperation.json
#	pkg/workqueue/schema/QueueRequest.json
#	pkg/workqueue/schema/RequestParameters.json
#	specs/work-queue/transactions.tsp

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve the merge conflicts on this branch.

Merged origin/main and resolved the conflicts in commit 3c585084a0.

Comment thread actions/setup/js/work_queue_store.cjs Outdated
const state = replayTransactionLog(contents);
const transactions = state.transactions;
if (transactions.some(transaction => transaction.actor.repository.toLowerCase() !== repository.full_name.toLowerCase())) throw queueError("actor_unauthorized", "queue log contains an actor from another repository");
if (verify && transactions[0]?.operations[0]?.kind === "Checkpoint") await verifyCheckpointGitHistory(options, sha, transactions[0], depth);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The checked GraphQL reader now calls the shared Git-parent checkpoint verifier using the authoritative ledger head SHA from the GraphQL read, before returning the verified queue.

const file = options.planFile || process.env.GH_AW_WORK_QUEUE_COMPACTION_PLAN_FILE;
if (!file) throw new Error("Missing work queue compaction plan path");
const plan = readPlan(file);
const actor = options.actor || { role: "administrator", repository: `${owner}/${repo}`, principal: process.env.GITHUB_ACTOR_ID };

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is addressed in the current implementation: main authenticates the native run with administrator role, derives the actor from the trusted context, and validates any supplied actor against that context. The focused authentication regression test passes. This is present in 4899f05.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): The checkpoint publisher here fabricates an administrator actor directly from process.env.GITHUB_ACTOR_ID and never calls authenticatePublisher/validateTrustedContext, unlike every other queue write path (e.g. compactWorkQueue in work_queue_store.cjs and work_queue_binding.cjs, which authenticate the run against the native GitHub run before claiming a role). As a result this job can publish a root Checkpoint commit — the operation that replaces the whole ledger prefix and is restricted to (c... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  3. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): This entry point writes a checkpoint commit to the queue branch using a self-asserted actor (<code)role: "administrator" with principal taken straight from process.env.GITHUB_ACTOR_ID), and never calls authenticatePublisher/validateTrustedContext. Every other queue mutation path (compactWorkQueue, publishWorkQueueRequest, dispatch/finish/reconciler) binds the actor to the real Actions run via authenticatePublisher, which verifies the triggering principal, workflow ref, run id and attempt. As writt... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  4. Review (actions/setup/js/work_queue_replay.cjs:835): After checkpoint restore, state.transactions no longer contains the Work-creation commits that validateEffectResourceAuthority searches in work_queue_resource_scope.cjs:126. For a worker-created child, creator becomes undefined, the ancestor walk exits, and a target allowed by the child but forbidden by its parent is accepted after compaction. Preserve immutable creator provenance in the restored state and make authorization consult it before enabling checkpoint compaction. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  5. Review (actions/setup/js/work_queue_compaction_apply.cjs:79): This condition treats every exception without a numeric status as retryable. Local failures such as TypeError, malformed API responses, or filesystem/runtime errors are swallowed, followed by retries and a misleading deferred success path instead of failing the maintenance job. Define the retryable set positively and rethrow everything else. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  6. Review (actions/setup/js/work_queue_control_receipts.cjs:151): The compacted-request handling added here is unreachable for pre-checkpoint controls: the policy lookup above searches only state.transactions, which contains the checkpoint and suffix, so it throws work_queue_policy_missing before this comparison even when the receipt's epoch is the current checkpoint policy. Fall back to the restored policy for compacted receipts in the current epoch. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  7. Review (actions/setup/js/work_queue_store.cjs:193): Every compaction performed after new suffix commits creates another checkpoint whose parent history begins with the previous checkpoint. This recursive verification therefore consumes one depth per maintenance cycle and permanently rejects the queue once the chain reaches 64 checkpoints. Since scheduled maintenance can create such checkpoints indefinitely, use a flattenable/verifiable chain or another non-lifetime-bound verification strategy. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  8. Review (pkg/workqueue/branch.go:210): Nested checkpoints increase depth on every compaction generation, so this recursion eventually reaches the hard limit and makes a valid active queue unreadable after roughly 64 maintenance compactions. The JavaScript verifier has the same behavior. Checkpoint verification needs flattening or another bounded strategy that does not impose a finite lifetime on the queue. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  9. Review (pkg/workqueue/checkpoint.go:230): These restored request commits omit both Work operations and causal Previous links. immutableWorkCreators (pkg/workqueue/resource_scope.go:175-207) therefore builds an empty creator map after a checkpoint, so AuthorizeEffect rejects valid pending deliveries with immutable Work creator is missing. Restore creator provenance or update that lookup to derive it from the receipt order and each Work position. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  10. Review (pkg/workqueue/checkpoint.go:276): Restoring receipts does not preserve the existing inspection contract. ExplainBeforeClaim and ExplainRequest search causalOrder(commits) for the original commit ID, but after compaction that slice contains only the checkpoint, while CheckpointReceipts is never consumed outside this file. Consequently every pre-checkpoint grant fails with "no original commit," and TraceQueue silently returns no historical events. Inspection must follow the checkpoint's authenticated parent history or consume sufficient retained provenance. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  11. Review (actions/setup/js/work_queue_store.cjs:162): Checkpoint roots are only authenticated against their real Git parent ledger on this path. readWorkQueueLog returns early for GH_AW_WORK_QUEUE_CHECKED_TRANSPORT === "graphql" (used in production by issue-backed queues via work_queue_issues.go) and readCheckedQueue never calls verifyCheckpointGitHistory. Under that transport a root Checkpoint commit is trusted purely on its self-consistent state_sha256 and self-declared administrator actor, so any principal that can write the work-queue... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  12. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): This apply step fabricates an administrator actor from environment variables instead of deriving it from an authenticated publisher context. Every other queue publisher (compactWorkQueue, dispatch, finish, reconciler) calls authenticatePublisher/validateTrustedContext, which binds the actor's role, principal, workflow and run to the actual GitHub Actions run; here role: "administrator" is asserted unconditionally and principal is taken from process.env.GITHUB_ACTOR_ID. Any caller of this module with the ... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 3c585084a0ff199adc42dc49d58e0d1e400bc284
Sous-chef work: 0e79774bb187361fb147b49f33400402671f246436c43549356c1df1f2fdff9d 1fcdbb33f69d4593de7270d872373eea2dfa996388912baf15cb1f4a9c9a83d2 452bde27f8bf7eb8438e6d062043fa98db46815fcd0629dbec8f91ec76be95ae 5d4fa35897646fa3f1cf33e182d58126447386c538faec52019e42d8abfd689b 5f6ca3c7631241b72cbfcacc8ae102a41dd29a9e66f078821f06d4402dd3cbc3 8f4cb202289223a8a1d7aca55f90043f9395db7e609c53a02f2321f1dc222bdd bdefbf0dee115612456057579f0f1b0f289595b6c95b54eb5db2c8c5ee13d163 c36eff3545d27b31c911ac6d23431f4dface8ece35e6f32f8f545df09bf9aaf5 c9fc3cc0eea278e021441d8bcb7ebd99f63e154868d7e9a491b5a66c818c9c10 cebffcbca25c6ac2249bce2a3f0485c08f7307985f3061ecaac78e6ea9a2d29a f3ec42dc0f594d842dd89a5036e3447eef3e8b83c3f7ea437af08e6e4a18b2e5
Sous-chef state: 5e4bd67385c759e14d8b5a7f616a46b7739bad6b9cee1623db155ea3c41b0f6c

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 6.95 AIC · ⌖ 7.08 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 9, 2026 07:21
…ueue-protocol

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): This entry point writes a checkpoint commit to the queue branch using a self-asserted actor (role: "administrator" with principal taken straight from process.env.GITHUB_ACTOR_ID), and never calls authenticatePublisher/validateTrustedContext. Every other queue mutation path (compactWorkQueue, publishWorkQueueRequest, dispatch/finish/reconciler) binds the actor to the real Actions run via authenticatePublisher, which verifies the triggering principal, workflow ref, run id and attempt. As writt... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  3. Review (actions/setup/js/work_queue_compaction_apply.cjs:79): This condition treats every exception without a numeric status as retryable. Local failures such as TypeError, malformed API responses, or filesystem/runtime errors are swallowed, followed by retries and a misleading deferred success path instead of failing the maintenance job. Define the retryable set positively and rethrow everything else. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  4. Review (actions/setup/js/work_queue_control_receipts.cjs:153): The compacted-request handling added here is unreachable for pre-checkpoint controls: the policy lookup above searches only state.transactions, which contains the checkpoint and suffix, so it throws work_queue_policy_missing before this comparison even when the receipt's epoch is the current checkpoint policy. Fall back to the restored policy for compacted receipts in the current epoch. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  5. Review (actions/setup/js/work_queue_store.cjs:188): Every compaction performed after new suffix commits creates another checkpoint whose parent history begins with the previous checkpoint. This recursive verification therefore consumes one depth per maintenance cycle and permanently rejects the queue once the chain reaches 64 checkpoints. Since scheduled maintenance can create such checkpoints indefinitely, use a flattenable/verifiable chain or another non-lifetime-bound verification strategy. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  6. Review (pkg/workqueue/branch.go:210): Nested checkpoints increase depth on every compaction generation, so this recursion eventually reaches the hard limit and makes a valid active queue unreadable after roughly 64 maintenance compactions. The JavaScript verifier has the same behavior. Checkpoint verification needs flattening or another bounded strategy that does not impose a finite lifetime on the queue. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  7. Review (pkg/workqueue/checkpoint.go:230): These restored request commits omit both Work operations and causal Previous links. immutableWorkCreators (pkg/workqueue/resource_scope.go:175-207) therefore builds an empty creator map after a checkpoint, so AuthorizeEffect rejects valid pending deliveries with immutable Work creator is missing. Restore creator provenance or update that lookup to derive it from the receipt order and each Work position. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  8. Review (pkg/workqueue/checkpoint.go:483): Restoring receipts does not preserve the existing inspection contract. ExplainBeforeClaim and ExplainRequest search causalOrder(commits) for the original commit ID, but after compaction that slice contains only the checkpoint, while CheckpointReceipts is never consumed outside this file. Consequently every pre-checkpoint grant fails with "no original commit," and TraceQueue silently returns no historical events. Inspection must follow the checkpoint's authenticated parent history or consume sufficient retained provenance. - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  9. Review (actions/setup/js/work_queue_store.cjs:162): Checkpoint roots are only authenticated against their real Git parent ledger on this path. readWorkQueueLog returns early for GH_AW_WORK_QUEUE_CHECKED_TRANSPORT === "graphql" (used in production by issue-backed queues via work_queue_issues.go) and readCheckedQueue never calls verifyCheckpointGitHistory. Under that transport a root Checkpoint commit is trusted purely on its self-consistent state_sha256 and self-declared administrator actor, so any principal that can write the work-queue... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  10. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): This apply step fabricates an administrator actor from environment variables instead of deriving it from an authenticated publisher context. Every other queue publisher (compactWorkQueue, dispatch, finish, reconciler) calls authenticatePublisher/validateTrustedContext, which binds the actor's role, principal, workflow and run to the actual GitHub Actions run; here role: "administrator" is asserted unconditionally and principal is taken from process.env.GITHUB_ACTOR_ID. Any caller of this module with the ... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  11. Review (actions/setup/js/work_queue_store.cjs:161): The new version-3 checkpoint lets a single fast-forward commit replace the entire ledger with a self-described state snapshot (policy, works, claims, dispatches, request receipts). The only thing binding that snapshot to real history is verifyCheckpointGitHistory, and it is invoked solely from this REST read path. The projector entry points in work_queue_issues.cjs still read the ledger through work_queue_checked_transport.readCheckedQueue, which performs no checkpoint ancestry/state_sha256 re-derivation, so a checkpoint root app... - Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)
  12. Review (actions/setup/js/work_queue_replay.cjs:1019): After a checkpoint restore, work.position.commit is a global history index (it indexes snapshot.requests / historicalTransactions), but state.transactions now contains only [checkpoint, ...post-checkpoint commits]. The PR updated some consumers for this (generateRequestOperations, validateEffectResourceAuthority), but the projection authority checks still index the live array directly: assertProjectionAuthority in work_queue_issue_contract.cjs (state.transactions[work.po... - https://github.com/github/gh-aw/pull/67105#discussion_r4229337727

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: c20b21f6319e09f7476a16b4f5ef06cacf54afee
Sous-chef work: 0c69b0857c2f2e5bc46d1b58a4d4362645cb78c32f636d4a9438b34156a3a5ca 0e79774bb187361fb147b49f33400402671f246436c43549356c1df1f2fdff9d 1fcdbb33f69d4593de7270d872373eea2dfa996388912baf15cb1f4a9c9a83d2 452bde27f8bf7eb8438e6d062043fa98db46815fcd0629dbec8f91ec76be95ae 5f6ca3c7631241b72cbfcacc8ae102a41dd29a9e66f078821f06d4402dd3cbc3 8f4cb202289223a8a1d7aca55f90043f9395db7e609c53a02f2321f1dc222bdd bdefbf0dee115612456057579f0f1b0f289595b6c95b54eb5db2c8c5ee13d163 c17c8c8bd35e3df22c2b146eb7b57cffd13a5e7fe593bd73fd9ee02f4890a3d9 c36eff3545d27b31c911ac6d23431f4dface8ece35e6f32f8f545df09bf9aaf5 c9fc3cc0eea278e021441d8bcb7ebd99f63e154868d7e9a491b5a66c818c9c10 cebffcbca25c6ac2249bce2a3f0485c08f7307985f3061ecaac78e6ea9a2d29a
Sous-chef state: 5e7365572a67f88359872c6e3ac05e7ce6cca2a9dcb8d4322079b9f9b7001c60

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 7.73 AIC · ⌖ 11.8 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.

  2. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): This entry point writes a checkpoint commit to the queue branch using a self-asserted actor (role: "administrator" with principal taken straight from process.env.GITHUB_ACTOR_ID), and never calls authenticatePublisher/validateTrustedContext. Every other queue mutation path (compactWorkQueue, publishWorkQueueRequest, dispatch/finish/reconciler) binds the actor to the real Actions run via authenticatePublisher, which verifies the triggering principal, workflow ref, run id and attempt. As written, any workflow/job able to invoke this script (or set GH_AW_WORK_QUEUE_COMPACTION_PLAN_FILE) can publish a root checkpoint commit attributed to an unverified administrator identity, bypassing the queue's role authentication model. Authenticate the caller with authenticatePublisher({..., role: "administrator"}) and derive the actor with actorFromContext/validateTrustedContext before compacting.


    General fix: require authenticated/validated publisher context before deriving the actor used for compaction, instead of defaulting to an unverified administrator built from environment variables.

    Best concrete fix in this file: replace the insecure fallback actor construction at line 45 with a required caller-provided authenticated actor (via options.actor) and fail closed if absent. This preserves existing behavior for trusted callers that already pass an authenticated actor (e.g., obtained by authenticatePublisher(..., role: "administrator") plus trusted-context checks in the caller), while removing the local insecure bypass path.

    Edits needed in actions/setup/js/work_queue_compaction_apply.cjs:

    • In main, replace:
      • const actor = options.actor || { ...principal from env... };
    • With:
      • const actor = options.actor;
      • an explicit validation guard that throws if actor is missing or malformed (role/principal/repository).
        No new imports or dependencies are required.

    See: Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)

  3. Review (actions/setup/js/work_queue_compaction_apply.cjs:45): This apply step fabricates an administrator actor from environment variables instead of deriving it from an authenticated publisher context. Every other queue publisher (compactWorkQueue, dispatch, finish, reconciler) calls authenticatePublisher/validateTrustedContext, which binds the actor's role, principal, workflow and run to the actual GitHub Actions run; here role: "administrator" is asserted unconditionally and principal is taken from process.env.GITHUB_ACTOR_ID. Any caller of this module with the queue write token can therefore mint administrator-signed checkpoints that replace the whole ledger prefix. Derive the actor via authenticatePublisher({ role: "administrator" }) and publish through the authenticated path.


    To fix this without changing intended functionality, stop fabricating the administrator actor from environment variables and instead require callers to provide an authenticated actor object (already produced upstream by the trusted authentication path). In this snippet, the safest change is to remove the insecure default and fail closed when options.actor is missing.

    Edit location: actions/setup/js/work_queue_compaction_apply.cjs, in main, around current line 45.

    What to change:

    • Replace:
      • const actor = options.actor || { role: "administrator", repository: ..., principal: ... };
    • With:
      • const actor = options.actor;
      • validation that actor exists and has expected shape/role (administrator) and target repository.
    • Keep all existing behavior for compaction/replay/publish unchanged; only tighten actor sourcing.

    This enforces authenticated-path usage while preserving existing logic when a valid actor is provided.

    See: Extending work queue protocol to support checkpoints and maintenance jobs #67105 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 4899f05
Sous-chef work: 1fcdbb33f69d4593de7270d872373eea2dfa996388912baf15cb1f4a9c9a83d2 c36eff3545d27b31c911ac6d23431f4dface8ece35e6f32f8f545df09bf9aaf5
Sous-chef state: f8981258078a95a285775b2f87c406e638f3b524ceabc2deb92a926e65f65f9b

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 5.25 AIC · ⌖ 10.5 AIC · ⊞ 1K · ◷
Comment /souschef to run again

const { actorFromContext, validateTrustedContext } = require("./work_queue_policy.cjs");
const { authenticatePublisher } = require("./work_queue_native.cjs");

const MAX_ATTEMPTS = 3;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot move to constants

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MAX_ATTEMPTS and PLAN_MAX_BYTES are already module-level constants, so I kept them there. The plan limit is now 16 * 1024 and has boundary coverage. Commit: 2e53ab9.

const { authenticatePublisher } = require("./work_queue_native.cjs");

const MAX_ATTEMPTS = 3;
const PLAN_MAX_BYTES = 4096;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot allow 16k

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Raised the maximum compaction plan size to 16 KiB and added a test for the exact limit and one byte over. Commit: 2e53ab9.

if: ${{ steps.apply_0.outcome == 'failure' || steps.apply_1.outcome == 'failure' || steps.apply_2.outcome == 'failure' || steps.apply_3.outcome == 'failure' || steps.apply_4.outcome == 'failure' || steps.apply_5.outcome == 'failure' }}
run: exit 1

work_queue_compaction_plan:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot merge work queue compaction in a single job since all the JavaScript is trusted.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Planning and application now run sequentially in one work_queue_compaction maintenance job; the artifact upload/download handoff is removed. The generated workflow and generator tests are updated. Commit: 2e53ab9.

…ueue-protocol

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@pelikhan

pelikhan commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@copilot must handle missing work-queue branch

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor Author

@copilot must handle missing work-queue branch

Added planner regression coverage for a missing work-queue branch. Planning returns skipped, sets plan_created=false, and creates no plan artifact; the six-test compaction suite passes. Commit: $(git rev-parse --short HEAD).

@copilot must handle missing work-queue branch

Correction: the commit hash is 26f2e19.

with:
destination: ${{ runner.temp }}/gh-aw/actions

- name: Plan existing work queue

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot unified steps into a single JavaScript step

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Planning and conditional application now run in a single actions/github-script step. Added a generator regression assertion and regenerated the maintenance workflow. Commit: 6eac2d4.

Copilot AI and others added 2 commits October 9, 2026 15:35
…ueue-protocol

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI requested a review from pelikhan October 9, 2026 15:49
@pelikhan
pelikhan merged commit 7dbebb0 into main Oct 9, 2026
3 checks passed
@pelikhan
pelikhan deleted the copilot/extend-work-queue-protocol branch October 9, 2026 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants