Skip to content

ci: raise reply agent to 120 turns; allowlist benign read/print tools - #262

Merged
allxsmith merged 1 commit into
mainfrom
ci/reply-turns-and-benign-tools
Jul 9, 2026
Merged

allxsmith merged 1 commit into
mainfrom
ci/reply-turns-and-benign-tools

Conversation

@allxsmith

@allxsmith allxsmith commented Jul 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Two changes from the run-log audit in #261:

  1. bestaxbot-reply.yml: --max-turns 60 → 120. A feature-sized request (run 28991564529) burned all 60 turns mid-implementation — 24 Edit/2 Write calls across a dozen files — and the runner died with everything uncommitted and no reply posted, so the PR just looked silent. The reply agent was the only write-capable agent still at 60 (loop fix step: 120, implement: 150).

  2. Allowlist benign tools whose denials wasted turns (evidence in ci: reply agent turn-caps at 60 losing all work; benign tool denials waste turns #261):

    • Bash(awk:*), Bash(echo:*), Bash(printf:*) for all three write-capable agents — read-only slicing / pure stdout; echo/printf denials were failing whole compound commands as the unapproved segment. Output redirection remains separately sandbox-blocked.
    • Bash(gh issue view:*) for the loop's fix step — denied 4× in one run; it's already allowed in reply + implement.

Deliberately NOT added (per the #261 census): git apply and perl -i (Bash write paths that would bypass #260's Edit()/Write() protected-path deny rules), rm, the file-ops MCP commit tool (git-CLI steering stays), and the Bash static-analyzer refusals, which are safety behavior, not misconfiguration.

Fixes #261

Test plan

  • All three workflows parse as valid YAML (js-yaml)
  • Diff is 4 lines: one turn bump + three allowlist strings
  • Post-merge: re-request the remaining PR feat(bulma-ui): add Avatar, Avatars, and Badge components #257 review work from bestaxbot and confirm the run completes within budget, commits, and replies (or at minimum replies with what it deferred)

Summary by CodeRabbit

  • Chores
    • Improved automated workflow reliability and flexibility for issue and pull request assistance.
    • Extended the time available for one automation run, reducing the chance of premature stops.
    • Broadened permitted command support in automation, including additional shell and GitHub issue-related actions.

A feature-sized request to bestaxbot-reply (run 28991564529) burned all
60 turns mid-implementation and the runner died with everything
uncommitted and no reply posted - the only write-capable agent still at
60 turns (loop fix: 120, implement: 150). Raise it to 120.

Log census across three runs also shows benign denials wasting turns:
gh issue view (4x in one loop fix run - allowed everywhere but there),
awk (read-only slicing, same family as grep/sed/head), and echo/printf
failing whole compound commands as the unapproved segment. Allowlist
those; write-path denials (git apply, perl -i, rm, file-ops MCP) and
the static-analyzer refusals stay as-is by design.

Fixes #261
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 70e6e6ef-1377-4664-a560-88a50bcddec5

📥 Commits

Reviewing files that changed from the base of the PR and between 75f4566 and 743d49d.

📒 Files selected for processing (3)
  • .github/workflows/bestaxbot-reply.yml
  • .github/workflows/claude-implement.yml
  • .github/workflows/claude-pr-loop.yml

Walkthrough

Modifies three Claude GitHub Actions workflow files: increases --max-turns from 60 to 120 in bestaxbot-reply.yml, and adds new Bash tool permissions (awk, echo, printf, gh issue view) to the --allowedTools allowlists in claude-implement.yml and claude-pr-loop.yml.

Changes

Claude Workflow Configuration Tuning

Layer / File(s) Summary
Reply agent turn-cap increase
.github/workflows/bestaxbot-reply.yml
Increases --max-turns from 60 to 120 for the bestaxbot reply step, matching the fix step's turn cap.
Allowlist expansion for implement and fix agents
.github/workflows/claude-implement.yml, .github/workflows/claude-pr-loop.yml
Adds Bash(awk:*), Bash(echo:*), Bash(printf:*) to the implement agent's allowedTools, and adds Bash(gh issue view:*) to the pr-loop fix step's allowedTools.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related issues

Possibly related PRs

  • allxsmith/bestax#218: Both PRs modify claude-implement.yml's claude_args allowedTools allowlist and max-turns parameter.
  • allxsmith/bestax#227: Both PRs modify claude-pr-loop.yml's fix agent allowedTools allowlist.
  • allxsmith/bestax#245: Both PRs adjust a Claude workflow's --max-turns from 60 to 120.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning Key details are present, but the template sections for affected packages, type of change, checklist, and other required fields are mostly missing. Add the package selection, related-issue, type-of-change, checklist, screenshots/demos, and additional-context sections in the repo template format.
Linked Issues check ⚠️ Warning The PR covers #261's turn-cap bump and some allowlist updates, but it appears to miss the required benign-tool allowlist changes for the reply workflow. Add Bash(awk:*), Bash(echo:*), and Bash(printf:*) to the reply agent allowlist, then verify all three write-capable agents match #261.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed Title is concise and matches the main CI changes: raise reply turn limit and expand benign tool allowlists.
Out of Scope Changes check ✅ Passed All changes stay within the requested CI workflows and map to the issue objectives.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/reply-turns-and-benign-tools

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://e106a73d.bestax.pages.dev

@allxsmith
allxsmith merged commit e738ddb into main Jul 9, 2026
11 checks passed
@allxsmith
allxsmith deleted the ci/reply-turns-and-benign-tools branch July 9, 2026 05:16

Copy link
Copy Markdown
Owner Author

Closing out the CodeRabbit review: the ⚠️ Linked Issues check warning ("appears to miss the required benign-tool allowlist changes for the reply workflow") is a false positive. The merged diff added Bash(awk:*),Bash(echo:*),Bash(printf:*) to all three write-capable agents, including .github/workflows/bestaxbot-reply.yml — see the first hunk of e738ddb. The walkthrough summary only credited two of the three files, which is likely where the warning came from. Verified on main: all three workflows contain the additions. No fix needed.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: reply agent turn-caps at 60 losing all work; benign tool denials waste turns

1 participant