Fix Copilot CLI path for agentic workflows - #37447
Conversation
Regenerate all agentic workflows with gh-aw v0.86.2 so the installed Copilot CLI is staged and invoked from a portable runner-local path. Explicitly disable shell access in the issue labeler to satisfy the hardened integrity policy. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 74cff858-a5a6-486e-a1d3-1d516fc3bdaa
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.sh | bash -s -- 37447Or
iex "& { $(irm https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.ps1) } 37447" |
|
Azure Pipelines: 1 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Pull request overview
This PR updates the repo’s GitHub Agentic Workflows (gh-aw) generated artifacts to restore Copilot-based workflow execution on hosted runners by removing the hard-coded /usr/local/bin/copilot dependency and using a runner-local staged Copilot CLI path. It also tightens the agentic labeler workflow by explicitly disabling shell access.
Changes:
- Regenerated the Copilot-based agentic workflow lockfiles with gh-aw
v0.86.2(enginecopilot 1.0.79), including the PATH-based Copilot executable resolution fix. - Staged the installed Copilot CLI into
${{ runner.temp }}/gh-aw/bin/copilotand updated harness invocations to use that staged path (instead of/usr/local/bin/copilot). - Disabled bash tooling in the agentic labeler workflow (
tools: bash: false) to enforce “no shell” behavior undermin-integrity: none.
Reviewed changes
Copilot reviewed 16 out of 16 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/rerun-review-scanner.lock.yml | Regenerated lockfile; stages Copilot CLI in runner-local path and updates harness invocation. |
| .github/workflows/daily-repo-status.lock.yml | Regenerated lockfile; updates Copilot CLI path handling and related gh-aw runtime scaffolding. |
| .github/workflows/ci-status-main.lock.yml | Regenerated lockfile; updates Copilot CLI execution to use staged runner-local path. |
| .github/workflows/agentic-labeler.md | Disables bash tooling (bash: false) to explicitly prevent shell access in the labeler workflow. |
| .github/workflows/agentic-labeler.lock.yml | Regenerated lockfile reflecting labeler tool restrictions and updated Copilot CLI path usage. |
| .github/workflows/ci-status-fix.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/ci-status-fix-net11.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/ci-status-net11.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/leak-fixer.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/daily-leak-hunter.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/regression-corpus-scanner.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/copilot-review-tests.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/copilot-evaluate-tests.lock.yml | Regenerated lockfile with updated gh-aw compiler/runtime and staged Copilot CLI usage. |
| .github/workflows/aw-actions-update.lock.yml | Regenerated lockfile for the action-pin refresh workflow under updated gh-aw compiler/runtime. |
| .github/workflows/aw-version-update.lock.yml | Regenerated lockfile for the gh-aw upgrade detector under updated gh-aw compiler/runtime. |
| .github/aw/actions-lock.json | Updates pinned github/gh-aw-actions/setup version/sha to v0.86.2. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d00747b7-96f3-4e7a-8dfb-e3a48db04b2d
|
@copilot-pull-request-reviewer addressed the latest container-pin feedback in 2732c13 and verified the upgraded workflows compile cleanly. This is ready for re-review — thanks! |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 16 out of 16 changed files in this pull request and generated no new comments.
Suppressed comments (4)
.github/workflows/daily-repo-status.lock.yml:1211
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURSis set to "0" for the agent-failure handler, which effectively makes failure issues expire immediately (previously this was typically 168h). This behavior change isn’t called out in the PR description; please confirm it’s intentional for this workflow family (otherwise restore the prior expiry).
GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
GH_AW_WORKFLOW_ID: "daily-repo-status"
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0"
GH_AW_ENGINE_ID: "copilot"
.github/workflows/ci-status-main.lock.yml:1224
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURSis now "0" in the agent-failure handler, which changes failure-issue retention behavior (typically this was 168h). Since the PR description focuses on Copilot CLI path portability and labeler shell disablement, please confirm this retention change is intended (or revert it).
GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
GH_AW_WORKFLOW_ID: "ci-status-main"
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0"
GH_AW_ENGINE_ID: "copilot"
.github/workflows/rerun-review-scanner.lock.yml:1225
- The agent-failure handler sets
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0", which likely causes any created failure-tracker issue to expire immediately. Please confirm this is intentional and document it in the PR description (or restore the previous retention window).
GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
GH_AW_WORKFLOW_ID: "rerun-review-scanner"
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0"
GH_AW_ENGINE_ID: "copilot"
.github/workflows/agentic-labeler.lock.yml:1215
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURSis set to "0" for this workflow’s agent-failure handler. Even though the labeler suppresses issue creation via safe-outputs, this env var still represents a notable behavior change vs the previous 168h default—please confirm it’s intentional and align the PR description accordingly.
GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
GH_AW_WORKFLOW_ID: "agentic-labeler"
GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0"
GH_AW_ENGINE_ID: "copilot"
PureWeen
left a comment
There was a problem hiding this comment.
Adversarial review — no new actionable findings
Reviewed exact head 2732c1335e32e7ee80b9d65c3eadc3e42a71869e with three independent reviewers plus the MAUI workflow specialist.
Confirmed the v0.86.2 regenerated locks consistently stage and mount the PATH-installed Copilot executable across all affected agent and threat-detection jobs; no /usr/local/bin/copilot invocation remains. The labeler source/lock pair tightens its low-integrity boundary by disabling Bash while retaining checkout: false, read-only permissions, and the existing bounded area-* / platform/* safe-output allowlist. Action and container pins are coherent, and GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0" intentionally disables expiry rather than immediately expiring failure reports.
Existing container-pin feedback was verified as fixed at this head. This is a COMMENT-only review; it does not constitute an automated approval. Build Analysis remains in progress and maui-pr is path-filtered (neutral).
PureWeen
left a comment
There was a problem hiding this comment.
Expert review — see inline comments.
| # for the issue-creation step is correctly suppressed. | ||
|
|
||
| tools: | ||
| bash: false |
There was a problem hiding this comment.
[moderate] Cross-Component Consistency — bash: false correctly satisfies the v0.86.2 strict rule for min-integrity: none, and the compiled agent invocation drops to --allow-tool github --allow-tool safeoutputs --allow-tool write (agentic-labeler.lock.yml:827) with no shell tool. However the compiler still injects the MCP-CLI prompt into this workflow's prompt ({"file":"mcp_cli_tools_prompt.md"} in GH_AW_PROMPT_CONFIG, agentic-labeler.lock.yml:304) and still mounts ${RUNNER_TEMP}/gh-aw/mcp-cli/bin on PATH (line 827). That prompt text (gh-aw v0.86.2 actions/setup/md/mcp_cli_tools_prompt.md) instructs the agent: "Invoke them from bash" and "For safeoutputs ... always use the CLI commands above." Concrete failure scenario: on a real labeler run the agent follows that instruction, attempts a shell invocation it no longer has permission for, and can end the turn without emitting add_labels/noop — a silent no-label run rather than a hard failure (and this workflow deliberately disables failure-issue reporting, so it would not surface). safeoutputs is still reachable as an MCP tool, so this is recoverable, but please validate one live labeler run (issue opened → label applied) before merging, and consider reporting the prompt/capability mismatch upstream.
There was a problem hiding this comment.
Confirmed the prompt/capability mismatch in the v0.86.2 output: the generated prompt says safeoutputs must be invoked from Bash while strict min-integrity: none requires tools.bash: false. There is no safe local workaround without either weakening first-time-contributor coverage or violating strict mode, so I reported it upstream as github/gh-aw#53532. A true live run cannot safely validate this unmerged fork workflow on dotnet/maui, and the fork does not have the target repo PAT-pool environment; I’m leaving this thread open pending the upstream fix or post-merge live evidence.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d00747b7-96f3-4e7a-8dfb-e3a48db04b2d
|
@PureWeen completed the gh-aw v0.86.2 upgrade set in 9eea171 and strict-compiled all 14 workflows. I also confirmed and reported the no-Bash safeoutputs prompt mismatch as github/gh-aw#53532; that validation thread remains open. This is ready for re-review — thanks! |
Skill Validation Results
❌ Skill Validation Results —
|
PureWeen
left a comment
There was a problem hiding this comment.
Adversarial review — 2 actionable findings
.github/agents/agentic-workflows.md moves its 15 upstream gh-aw guidance URLs from the versioned v0.85.4 tag to mutable main (for example, line 45). The repo's compiler and generated locks are pinned to v0.86.2; a later upstream main change can therefore make this dispatcher load schema/prompt guidance that the installed compiler does not support, or make the same repository revision behave differently over time. Pin the URLs to v0.86.2 (or an immutable commit) and advance them together with future compiler upgrades.
ASCII Charts prompt/reference section, but the dispatch menu at .github/agents/agentic-workflows.md:30 still routes chart requests to the now-undefined asciicharts guide. A chart request no longer has a resolvable route within this dispatcher. Remove that menu entry or restore the reference section, pinned consistently with the other upstream guidance.
The regenerated locks consistently eliminate the hard-coded Copilot CLI path, use the v0.86.2 setup pin, and preserve the labeler's no-Bash tool boundary.
Methodology: 3 independent reviewers with adversarial consensus + repo domain specialist. The generated poutine:ignore removals were discarded: no active repository scanner consumes them. No test files changed; this configuration update relies on source/lock compilation validation. Prior review feedback was reconciled; no unresolved error-level issue applies at this pinned head.
This is a COMMENT-only review and not an automated approval.
Keep dispatcher prompts aligned with the repository's gh-aw v0.86.2 compiler pin and restore the ASCII Charts reference removed during template refresh. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d00747b7-96f3-4e7a-8dfb-e3a48db04b2d
|
@PureWeen addressed both findings in 6d34d8e. All 15 upstream dispatcher references now use the immutable v0.86.2 tag matching the repository compiler pin, and the ASCII Charts reference section is restored. gh-aw v0.86.2 strict validation compiled all 14 workflows with only the two existing warnings. Ready for re-review. |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 18 out of 18 changed files in this pull request and generated no new comments.
Suppressed comments (1)
.github/skills/agentic-workflows/SKILL.md:39
enclaves.mdis listed as an upstream gh-aw reference file, but it does not exist ingithub/gh-aw(including tagv0.86.2). This will cause the skill instructions to point agents at a missing file and slow down debugging/upgrades.
- `.github/aw/designer.md`
- `.github/aw/enclaves.md`
- `.github/aw/evals.md`
The gh-aw v0.86.2 guide set does not contain enclaves.md, so omit it from the dispatcher rather than directing agents to a 404. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d00747b7-96f3-4e7a-8dfb-e3a48db04b2d
|
Addressed the suppressed Copilot review finding in 8f91d43: removed the nonexistent gh-aw |
PureWeen
left a comment
There was a problem hiding this comment.
Adversarial review — no new actionable findings
Reviewed exact head 8f91d43d6dd1e932e22dc022077fcd11dc3c8ec5 with 3 independent reviewers and the MAUI domain specialist. The generated locks consistently stage the PATH-installed Copilot executable into the runner-local sandbox path, and no hard-coded /usr/local/bin/copilot harness invocation remains. The action/container pins, versioned upstream guidance, and source-to-lock metadata remain coherent.
The labeler preserves its intended security boundary: pull_request_target does not check out untrusted PR code, the agent remains read-only with bash: false, and writes are restricted to bounded, allowlisted label safe outputs. The generated GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "0" settings are compiler-driven v0.86.2 behavior for this repository configuration, not an immediate-expiry regression.
Test coverage: No test files changed; this generated workflow/configuration update has no independently identified test gap.
Prior review status: Earlier configuration findings were resolved before this exact head; no qualifying adversarial review existed for this commit.
Methodology: 3 independent reviewers with adversarial consensus + repo domain specialist.
This is a COMMENT-only review and not an automated approval.
Note
Are you waiting for the changes in this PR to be merged?
It would be very helpful if you could test the resulting artifacts from this PR and let us know in a comment if this change resolves your issue. Thank you!
Summary
/usr/local/bin/copilotmin-integrity: noneRoot cause
The failing runs install Copilot CLI successfully, but gh-aw v0.85.4 then invokes
/usr/local/bin/copilot. That path no longer exists on the hosted runner, so the engine exits withENOENTbefore producing output or making a model request. gh-aw v0.86.2 includes the upstream path-portability fix and resolves the installed executable fromPATH.The same generated path affected every Copilot workflow, including the labeler, whose failure reporting is intentionally disabled.
Regeneration also incorporates github/gh-aw#51425. Because this repository does not generate an
agentics-maintenance.ymlconsumer for the implicit action-failure expiry, all 14 lockfiles now setGH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURSto"0". In gh-aw v0.86.2, explicit0means expiration is disabled; it prevents unenforceable expiry markers and does not make failure issues expire immediately.Validation
gh aw compile --strict --validate --actionlint --no-emit/usr/local/bin/copilot"0"disabled-expiry sentinel consistentlyNo existing open MAUI PR addresses this gh-aw/Copilot path failure.
Fixes #37430
Fixes #37431
Fixes #37432
Fixes #37435
Fixes #37442