Skip to content

ci: give the fix agent Opus 4.8 (1M), more turns, and inspection tools - #239

Merged
allxsmith merged 1 commit into
mainfrom
claude/fix-agent-opus-allowlist
Jul 7, 2026
Merged

allxsmith merged 1 commit into
mainfrom
claude/fix-agent-opus-allowlist

Conversation

@allxsmith

@allxsmith allxsmith commented Jul 7, 2026 •

Copy link
Copy Markdown
Owner

What

Three changes to the fix job in claude-pr-loop.yml (only the agent that failed):

  1. Add read-only inspection utils to the allowlist: rg, grep, cat, sed, ls, head, tail, wc, find.
  2. Raise the turn cap --max-turns 80 → 120 (the implement agent already runs at 150).
  3. Switch the model --model claude-sonnet-5 → claude-opus-4-8[1m] (Opus 4.8, 1M context).

Why

The fix run on PR #238 died with error_max_turns: 80 turns, 42 permission denials, $3.82, and zero output — no refutations, no fixes, no summary comment. The agent thrashed on denied tool calls and never reached convergence; the loop then paused safely (ai-loop-paused).

Root cause is a task/allowance mismatch on the fix agent. Its job is heavy — verify each finding against code, edit, test, reply in threads, commit, push — but its allowlist carried no read-only inspection utilities, so every rg/cat/sed/ls/grep a verifying agent naturally reaches for was a denial. Compounded by a tight 80-turn cap and the weaker sonnet model.

This mirrors robobun's approach (scope tools to the task, use a stronger model, don't starve it on turns) for this heavy adversarial pass. The implement agent is unchanged — it works (it opened #238).

Scope

One claude_args block; three values changed. No prompt or logic changes.

Caveat

claude-opus-4-8[1m] requests the 1M-context beta. If it's not available on the subscription token path, the next fix run will surface it and we drop the [1m] suffix — the Opus model itself is the main win.

Validation

After merge: on PR #238 remove ai-loop-paused and re-add ai-loop to retry the fix pass on the same commit, and confirm the agent now posts refutations instead of thrashing.


Generated by Claude Code

Summary by CodeRabbit

  • Chores
    • Updated the automation workflow’s AI configuration to allow longer-running tasks and broader tool access.
    • Improved the workflow’s capability to handle more complex repository operations during automated runs.

The fix run on PR #238 died with error_max_turns: 80 turns, 42 permission
denials, $3.82, and zero output — no refutations, no fixes, no summary.
The agent thrashed on denied tool calls and never converged; the loop then
paused safely (ai-loop-paused).

Root cause is a task/allowance mismatch on the FIX agent specifically. Its
job is heavy — verify each finding against code, edit, test, reply in
threads, commit, push — but its allowlist carried no read-only inspection
utilities, so every rg/cat/sed/ls/grep a verifying agent reaches for was a
denial. Compounded by a tight 80-turn cap and the weaker sonnet model.

Mirror robobun's approach (scope tools to the task; stronger model; no tight
turn starvation) for this heavy pass:
- Add read-only inspection utils: rg, grep, cat, sed, ls, head, tail, wc,
  find — kills the denial source, all read-only.
- Raise the cap 80 -> 120 (the implement agent already runs at 150).
- Run the fixer on claude-opus-4-8[1m] instead of sonnet-5 — a stronger
  model wastes fewer turns on a multi-finding adversarial pass, and the
  deep reviewer already uses opus.

Implement agent is unchanged (it works — it opened #238).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NVR5yWevceZEFbTJmpviiM
@coderabbitai

coderabbitai Bot commented Jul 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 67c91385-4fdb-4d68-a685-d002f1f7beb3

📥 Commits

Reviewing files that changed from the base of the PR and between 46d4e6e and 8d2dc77.

📒 Files selected for processing (1)
  • .github/workflows/claude-pr-loop.yml

Walkthrough

This change updates the fix job's Claude invocation configuration in the CI workflow file, increasing the max-turns limit, switching the model, and expanding the allowedTools allowlist with additional shell/git commands.

Changes

Claude PR Loop Workflow Configuration

Layer / File(s) Summary
Fix job Claude invocation parameters
.github/workflows/claude-pr-loop.yml
--max-turns increased from 80 to 120, model switched from claude-sonnet-5 to claude-opus-4-8[1m], and --allowedTools allowlist expanded with additional Bash(git ...) and related commands.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

  • allxsmith/bestax#218: Modifies the same Claude workflow to increase --max-turns and expand --allowedTools similarly.
  • allxsmith/bestax#227: Modifies .github/workflows/claude-pr-loop.yml's fix job with similar --max-turns and --allowedTools changes.
  • allxsmith/bestax#228: Modifies the same "Run Claude (fix)" configuration in the same workflow file.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main workflow change: stronger model, more turns, and expanded inspection tools for the fix agent.
Description check ✅ Passed The description covers the change summary, rationale, scope, caveat, and validation, though the template sections for package selection and related issues are not fully filled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/fix-agent-opus-allowlist

Comment @coderabbitai help to get the list of available commands.

@allxsmith
allxsmith merged commit d90c804 into main Jul 7, 2026
9 of 10 checks passed
@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://9bb1711e.bestax.pages.dev

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 5.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

allxsmith added a commit that referenced this pull request Jul 7, 2026
…nt (#241)

Two hardening changes ahead of stress-testing the loop on a real bug:

1. Mirror the read-only inspection utilities (rg/grep/cat/sed/ls/head/tail/
   wc/find) that #239 added to the fix agent into the implement agent's
   allowlist. The implement agent has the same latent gap that thrashed the
   sonnet fixer (42 denials); it has coped on sonnet-5 + 150 turns + native
   Read/Grep tools, but a heavy issue could hit the same wall. Cheap
   insurance, all read-only.

2. Upload the action's execution-output.json as an artifact (if: always())
   from both the implement and fix jobs. That file carries the full
   turn-by-turn stream — every tool call AND every permission denial —
   whereas the Actions log only streams init + final result. When the sonnet
   fixer thrashed we could see '42 denials' but not WHICH tools; this makes
   the next failure diagnosable instead of guesswork. Reuses the repo's
   existing pinned actions/upload-artifact and never fails the job
   (if-no-files-found: ignore).

Models are deliberately left as-is: sonnet-5 implement, opus deep review,
opus fix — the heterogeneity decorrelates implementer and reviewer blind
spots.


Claude-Session: https://claude.ai/code/session_01NVR5yWevceZEFbTJmpviiM

Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants