Skip to content

fix: bootstrap trusted canary driver - #2

Merged
myagentdojo merged 1 commit into
mainfrom
codex/bootstrap-trusted-canary-driver
Aug 10, 2026
Merged

myagentdojo merged 1 commit into
mainfrom
codex/bootstrap-trusted-canary-driver

Conversation

@myagentdojo

@myagentdojo myagentdojo commented Aug 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

Imports the reviewed first-consumer bootstrap fix from agent-plugin-template into the playground's trusted base. This leaves plugin.config.json unchanged with template: true, then lets the follow-on initialization PR qualify the playground's exact same-repository canary targets.

This is the bounded bootstrap step before PR #1. Its own hosted canary may remain red because the trusted base predates this exception and the playground credential cannot access the template's shared canary repositories.

Validation

  • bun test: 648 passed, 3 intentional skips, 0 failed
  • bun test scripts/ship-canary.test.ts --coverage: 44 passed, 0 failed
  • bun run build: passed
  • bun run release:validate: passed
  • bun run generate:check: current
  • Exact byte match with the reviewed files merged in agent-plugin-template#36

Related: myagentdojo/agent-plugin-template#36
Related: #1

Summary by CodeRabbit

  • Bug Fixes

    • Improved canary deployment validation to accept only trusted targets.
    • Added safeguards against redirected targets, repository mismatches, incorrect identities, incomplete configurations, and fork-based deployments.
    • Prevented retries and logging side effects for rejected target configurations.
  • Tests

    • Added coverage for valid bootstrap scenarios and invalid canary configurations.
    • Added workflow validation for pull request repository handling.

@myagentdojo
myagentdojo had a problem deploying to hosted-canary-qualification August 10, 2026 11:30 — with GitHub Actions Failure
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 31c9bab1-83ac-4c93-bd0c-e0b15486237f

📥 Commits

Reviewing files that changed from the base of the PR and between 8a5447b and 454ec62.

📒 Files selected for processing (3)
  • .github/workflows/hosted-canary.yml
  • scripts/ship-canary.test.ts
  • scripts/ship-canary.ts

📝 Walkthrough

Walkthrough

The canary flow now validates candidate targets against trusted configuration, supports protected template bootstrap, uses resolved targets during preflight, and passes the pull request head repository through the hosted workflow.

Changes

Trusted Canary Qualification

Layer / File(s) Summary
Candidate configuration and trusted target validation
scripts/ship-canary.ts, scripts/ship-canary.test.ts
Candidate loading preserves full metadata. Trusted target validation accepts exact matches and constrained protected bootstrap cases. Tests cover rejected configurations and side effects.
Preflight target and transport binding
scripts/ship-canary.ts
Preflight uses resolved targets for transport identity binding and target construction.
Workflow head repository propagation
.github/workflows/hosted-canary.yml, scripts/ship-canary.test.ts
The workflow exports CANARY_HEAD_REPOSITORY. Tests verify the environment variable wiring.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant HostedWorkflow
  participant Qualification
  participant CandidateConfigLoader
  participant TrustedCanaryTargets
  participant Transport
  HostedWorkflow->>Qualification: pass CANARY_HEAD_REPOSITORY
  Qualification->>CandidateConfigLoader: load candidate metadata
  CandidateConfigLoader-->>Qualification: template, repository, and canary configuration
  Qualification->>TrustedCanaryTargets: validate candidate targets
  TrustedCanaryTargets-->>Qualification: resolved targets or canary_target_mismatch
  Qualification->>Transport: bind identity and construct targets
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: fixing trusted canary bootstrap behavior in the canary driver.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/bootstrap-trusted-canary-driver

Comment @coderabbitai help to get the list of available commands.

@myagentdojo

Copy link
Copy Markdown
Owner Author

@codex review

@myagentdojo
myagentdojo merged commit 80a1c59 into main Aug 10, 2026
17 of 20 checks passed

This branch had an error being deployed

1 failed deployment
hosted-canary-qualification — 454ec620 Deployed Aug 10, 2026 by myagentdojo via Qualify immutable hosted candidates #4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants