Skip to content

Preserve model routing attribution in audit and logs - #67114

Merged
pelikhan merged 7 commits into
mainfrom
copilot/fix-audit-logs-loss
Oct 9, 2026
Merged

pelikhan merged 7 commits into
mainfrom
copilot/fix-audit-logs-loss

Conversation

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Agent artifact flattening discarded final routing metadata, and unified sessions omitted workflow metadata and the harness outcome. As a result, audit and logs could report AWF’s selected endpoint instead of the endpoint and effort actually used by the harness.

  • Preserve agent metadata: Stage the agent artifact before flattening so nested files survive; publish the final aw_info.json for existing consumers and prefer it in usage artifacts.
  • Record unified-session attribution: Emit workflow.info and model_routing.outcome; document their routing fields and the existing firewall.model_routing fields in the specification and schema.
  • Use session data in audit and logs: Read model, status, applied effort, and effective/selected endpoints from the unified session, retaining aw_info.json and AWF routing logs as fallbacks. Invalidate cached summaries from the prior schema version.

Example session events:

{"type":"workflow.info","data":{"model":"claude-sonnet-5","requestedModel":"agent","modelRouting":{"effectiveEndpoint":"/v1/messages","selectedEndpoint":"/chat/completions"}}}
{"type":"model_routing.outcome","data":{"status":"selected","effectiveEndpoint":"/v1/messages","selectedEndpoint":"/chat/completions","appliedEffort":"medium"}}

Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>
@SivaKesava1
SivaKesava1 marked this pull request as ready for review October 9, 2026 05:54
Copilot AI balanced review requested due to automatic review settings October 9, 2026 05:54
Copilot AI changed the title [WIP] Fix loss of final aw_info.json and harness routing outcome in audit/logs Preserve model routing attribution in audit and logs Oct 9, 2026
Copilot AI requested a review from SivaKesava1 October 9, 2026 05:56
@SivaKesava1

Copy link
Copy Markdown
Collaborator

@copilot resolve merge conflicts

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Production outcome writers omit promised endpoints, audit comparisons discard them, and endpoint-distinct route ordering is unstable.

2 open findings
What changed in this PR

Preserves harness-selected model-routing attribution across artifact downloads, unified sessions, audit reports, and logs.

Changes:

  • Preserves final agent metadata while flattening artifacts.
  • Adds workflow and routing-outcome session events.
  • Consumes session attribution and updates schemas, cache versions, documentation, and tests.
File Description
schemas/​logs.schema.json Adds endpoint fields to logs schemas.
schemas/​logs-jsonl.schema.json Adds endpoints and bumps cache schema.
schemas/​audit.schema.json Exposes routing endpoints in audits.
pkg/​cli/​model_routing.go Merges session routing attribution.
pkg/​cli/​model_routing_test.go Tests session attribution.
pkg/​cli/​model_routing_session.go Parses routing session events.
pkg/​cli/​logs_report.go Reports endpoint attribution.
pkg/​cli/​logs_models.go Adds selected endpoint metadata.
pkg/​cli/​logs_flatten_test.go Tests nested artifact preservation.
pkg/​cli/​logs_download_flatten.go Safely stages and flattens agent artifacts.
pkg/​cli/​logs_cached_json.go Invalidates and updates cached attribution.
pkg/​cli/​logs_cached_json_test.go Updates cache-version tests.
pkg/​cli/​audit_report_render.go Renders effective and selected endpoints.
pkg/​cli/​audit_expanded.go Adds session metadata fallback.
docs/​src/​content/​docs/​specs/​unified-agent-session-specification.md Documents routing events and fields.
docs/​public/​schemas/​unified-session.schema.json Extends the public session schema.
actions/​setup/​sh/​collect_usage_artifact_files.sh Prefers final agent metadata.
actions/​setup/​sh/​collect_usage_artifact_files_test.sh Tests final metadata collection.
actions/​setup/​js/​unified_session.test.cjs Tests routing session collection.
actions/​setup/​js/​unified_session.cjs Emits workflow and routing events.
actions/​setup/​js/​unified_session_render.test.cjs Tests endpoint rendering.
actions/​setup/​js/​unified_session_render.cjs Renders routing events.
actions/​setup/​js/​unified_session_payload.test.cjs Tests workflow metadata normalization.
actions/​setup/​js/​unified_session_payload.cjs Normalizes routing payloads.
actions/​setup/​js/​types/​unified_session.d.ts Adds routing event types.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread actions/setup/js/unified_session.cjs
Comment thread pkg/cli/model_routing.go
…s-loss

# Conflicts:
#	pkg/cli/audit_report_render.go
#	pkg/cli/logs_report.go
#	pkg/cli/model_routing.go
#	pkg/cli/model_routing_test.go
#	schemas/logs.schema.json

Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve merge conflicts

Resolved the conflicts by merging main; merge commit ec02768 preserves both routing changes and the incoming endpoint summary updates.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (actions/setup/js/unified_session.cjs:441): The new event cannot contain the endpoint fields promised by T-UAS-070 in real runs. recordAWFModelRoutingOutcome currently drops endpoint and selected_endpoint, and the Claude, Codex, Copilot, and Pi harness calls do not pass them; a direct call with both fields serializes only status/model/effort. Consequently these fields are present only in this fabricated collector test, while production model_routing.outcome events omit them. Thread the resolved selection endpoints through each harness call and persist validated endpoint fields in the outcome writer. - Preserve model routing attribution in audit and logs #67114 (comment)
  3. Review (pkg/cli/model_routing.go:84): The new endpoint attribution is still discarded by audit comparisons. modelRoutingComparisonRoute copies only model, effort, mode, and router version into AuditComparisonRoute, and sameModelRoutingRoute checks only those fields. Thus an audit diff where the effective endpoint changes while the selected route stays the same reports no endpoint and leaves model_routing_changed false. Propagate both endpoints through the comparison type, schema, equality check, and tests. - Preserve model routing attribution in audit and logs #67114 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: ec02768
Sous-chef work: 326436fb72cf3401e1bfd76275f259c2e349f3d4a5d93581c6cf56aaddaea466 4fe44e53555163220d76652fcb5c0d4daf671288df9ff17a5db89a29d1b73595
Sous-chef state: 3ed79d793af37a636da7d1a9bb24510075454d4021e824f0fb494dae8df5cfc2

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 4.93 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>
@SivaKesava1

Copy link
Copy Markdown
Collaborator

Verified 514fc721 in our sandbox (routed workflows compiled at this head, default AWF v0.28.50):

Run aw_session.jsonl gh aw audit --json model_routing
37956765407 Claude t01 workflow.info (model: claude-sonnet-5, modelRouting with effective/selected endpoints) and model_routing.outcome (effectiveEndpoint: /v1/messages, selectedEndpoint: /chat/completions, appliedEffort: medium) status: selected, effective_endpoint: /v1/messages, selected_endpoint: /chat/completions, model_effort: medium
37956778256 pi t10 same events; claude-opus-5, appliedEffort: max effective_endpoint: /v1/messages, selected_endpoint: /chat/completions

The download fix also works on artifacts from before this PR. gh aw audit 37890995735 (a Claude run on main from before this change) now keeps both aw_info.json and agent/aw_info.json with routing, and shows effective_endpoint: /v1/messages. Before this PR, audit only saw the activation copy (model: agent, no routing).

@copilot /pr-finisher

…s-loss

Co-authored-by: SivaKesava1 <11771739+SivaKesava1@users.noreply.github.com>
@SivaKesava1

Copy link
Copy Markdown
Collaborator

Ready for review. Sandbox-verified at 514fc721 (fresh Claude and pi routed runs plus an older run: workflow.info and model_routing.outcome are in aw_session.jsonl, and audit shows effective and selected endpoints). The later commits only regenerate the log schemas and merge main. Both review threads are addressed and resolved. The current CI failures (lint-go-custom in pkg/workqueue/replay.go, verify-integration-build on an undefined parseMaintenanceJobs in a work-queue test, work_queue_*.test.cjs, and impacted-go-tests in unrelated CLI tests) come from work-queue changes on main, not from this PR.

@SivaKesava1
SivaKesava1 requested a review from pelikhan October 9, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

audit/logs: agent job's final aw_info.json and harness routing outcome are lost (deleted on download, absent from aw_session.jsonl)

5 participants