Skip to content

[repo-assist] Fix new-contributor detection, firewall boilerplate, stale-issue triage & double-commenting - #50963

Closed
blozano-tt wants to merge 1 commit into
mainfrom
fix/repo-assist-triage-bugs
Closed

blozano-tt wants to merge 1 commit into
mainfrom
fix/repo-assist-triage-bugs

Conversation

@blozano-tt

@blozano-tt blozano-tt commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes four issues surfaced by a maintainer-requested grading review (Wilder) of repo-assist's first live run (Actions run 30053298328), which produced monthly issue #50956. All changes are confined to .github/workflows/repo-assist.md (the source) and its regenerated repo-assist.lock.yml. This branch is off current main and is independent of the unrelated open PR #50962.

Fixes

1. New-contributor detection was broken — 3/3 false positives (highest priority)

The run welcomed three established, prolific contributors as if they were newcomers:

The old Task 7 welcomed "first-time contributors" without ever verifying repo history, so it inferred "new" from local/thread context. Fix: Task 7 now requires an explicit history check before any welcome — a contributor qualifies only if they have zero merged PRs AND no prior issues/comments, verified via the GitHub search API:

  • is:pr is:merged author:<login> repo:tenstorrent/tt-metal → must be 0
  • is:issue author:<login> repo:tenstorrent/tt-metal → must be 0 (other than the item being triaged)
  • no prior PR/comment activity

If any check shows history, the welcome is skipped. "When in doubt, do not welcome."

2. Every public comment polluted with firewall boilerplate

Every comment carried a ⚠️ Firewall blocked 1 domain: awmgmcpg block. This is benign/cosmetic: awmgmcpg is gh-aw's own internal MCP Gateway sidecar hostname (image github/gh-aw-mcpg, container awmg-mcpg) being flagged by gh-aw's own firewall — not a real missing external dependency (matches known gh-aw behaviour).

The requested fix (adding awmgmcpg to network.allowed) is rejected by the gh-aw compiler (v0.82.14): a bare awmgmcpg is neither a valid ecosystem identifier nor a domain (no dot). The gateway's actual transport, host.docker.internal, is already in the defaults allowlist, so allowlisting changes nothing. Fix (fallback per the review's instruction): a documented NOTE in the frontmatter explains the situation, and a new "Never forward firewall boilerplate into comments" guideline instructs the agent to strip any such block from anything posted publicly. network stays defaults.

3. Commented on a 14-month-old stale [HELP] issue (#9364) and mislabeled it bug

Fix: Task 2 now restricts first-time comment+label triage to issues active in roughly the last 90 days; older stale issues are routed to the stale-nudge path or left alone rather than getting a cold first-time comment. Task 1 labeling guidance now says [HELP]/question/support issues must not default to bug unless a defect is actually confirmed.

4. Double-commenting the same issue in one run

Issues #50897 and #50955 each got both a triage comment and a separate welcome comment. Fix: Task 7 and the anti-spam guideline now require combining triage + welcome into a single comment when both apply to the same issue in the same run.

Verification

  • ✅ gh aw compile repo-assist succeeds with 0 errors, 0 warnings, pinned to the repo's existing compiler version v0.82.14 (no compiler-version drift — only the workflow's own frontmatter/body hashes changed in the lock file).
  • ✅ Only the two intended files are touched (an unrelated actions-lock.json cache-cleanup side-effect of recompiling was reverted).
  • ⚠️ Not yet verifiable without a live re-run: the new-contributor search-API check and the reduced comment noise can only be fully confirmed by triggering /repo-assist again after merge. This PR proves the workflow compiles cleanly and that the instructions are in place; it cannot prove runtime behaviour on its own.

🤖 Prepared with assistance from Claude Code, per a maintainer grading review.

CI Status

Auto-generated on every push. Badges update live. Click a badge to filter runs by this branch.

Address four findings from a maintainer-requested grading review (Wilder)
of repo-assist's first live run:

1. Tighten new-contributor detection (3/3 false positives in the run).
   Require zero merged PRs and no prior issues/comments, verified via the
   GitHub search API, before welcoming — not inferred from context.
2. Stop polluting comments with the benign `awmgmcpg` firewall boilerplate.
   The hostname cannot be added to network.allowed at compiler v0.82.14
   (rejected as invalid), so instruct the agent to strip the block instead;
   documented the reasoning in the frontmatter.
3. Restrict fresh comment+label triage to issues active in ~90 days and stop
   defaulting [HELP]/question issues to the `bug` label.
4. Combine triage + welcome into a single comment per issue per run.

Recompiled with gh aw (v0.82.14); no compiler-version drift.

Co-Authored-By: Claude <noreply@anthropic.com>

Co-Authored-By: BrAIn <brain@tenstorrent.com>
Copilot AI review requested due to automatic review settings July 23, 2026 23:54
@blozano-tt
blozano-tt requested review from a team as code owners July 23, 2026 23:54
@github-actions github-actions Bot added the fix Bug fix label Jul 23, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates Repo Assist triage behavior following its first live run.

Changes:

  • Adds contributor-history checks and combines welcome/triage comments.
  • Adds freshness and issue-labeling guidance.
  • Attempts to suppress internal firewall warnings from public output.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
.github/workflows/repo-assist.md Updates workflow instructions and safeguards.
.github/workflows/repo-assist.lock.yml Refreshes generated workflow hashes.

Comment on lines +46 to +48
# is therefore handled at the instruction level instead — see the "Never forward
# firewall boilerplate into comments" guideline below, which tells the agent to
# strip this internal notice from anything posted publicly.
Comment on lines +170 to +171
- **Prefer fresh issues for first-time comments+labels.** Restrict new comment+label triage to issues opened or updated in roughly the **last 90 days**. A first-time comment (and a fresh label) dropped out of the blue on a long-stale issue is usually unwelcome noise.
- **Do not open fresh triage on old stale issues.** For issues with no recent activity (older than ~90 days since last update), do **not** post a first-time comment or apply a first-time label. Route them instead toward the existing stale-nudge path (see Task 6 for the analogous PR handling), or simply leave them alone. When a stale issue clearly needs closing or a nudge, note it under Suggested Actions in Task 8 rather than commenting cold.
2. **Verify contributor history before welcoming — do not infer "new" from context.** A person qualifies as a genuinely new contributor **only if they have zero merged PRs AND no prior issues/comments** in this repository. Do not treat "first time we've seen them on this issue", "first comment in this thread", or "not in our memory" as sufficient — an established, prolific contributor can easily be someone we simply haven't interacted with yet. Confirm history explicitly via GitHub's search API before posting a welcome:
- `is:pr is:merged author:<login> repo:${{ github.repository }}` — must return **0** results (no merged PRs).
- `is:issue author:<login> repo:${{ github.repository }}` — must return **0** results other than the item currently being triaged (no prior issues authored).
- Also confirm they have no prior comment/PR activity in the repo (e.g. `is:pr author:<login> repo:${{ github.repository }}` returning 0, and no earlier comments).
@blozano-tt

Copy link
Copy Markdown
Contributor Author

Superseded by #50964, which combines this PR with #50962 into a single coherent repo-assist.md source and one clean gh aw compile of repo-assist.lock.yml.

Since the compiled lock is a deterministic function of the whole .md source (both frontmatter_hash and body_hash are recomputed each compile), this PR and #50962 could not be merged independently without one clobbering the other's lock regeneration. Per maintainer request, they are merged in #50964 so the workflow can be manually tested end-to-end against a single lock file.

All four triage fixes from this PR are carried over verbatim into #50964. Closing (not merging) in favor of #50964. Leaving the fix/repo-assist-triage-bugs branch in place for reference/history. 🤖

@blozano-tt blozano-tt closed this Jul 24, 2026
pull Bot pushed a commit to Stars1233/tt-metal that referenced this pull request Jul 24, 2026
…(supersedes tenstorrent#50962, tenstorrent#50963) [skip ci] (tenstorrent#50964)

## Summary

This PR **combines and supersedes** two open repo-assist PRs so there is
a **single coherent `repo-assist.md` source and one clean `gh aw
compile`** to test against:

- Supersedes tenstorrent#50962 — *DeepWiki MCP tool + cross-repo grounding
guidance*
- Supersedes tenstorrent#50963 — *4 triage-logic bug fixes from the first live run*

### Why combine them

`.github/workflows/repo-assist.lock.yml` is a deterministic function of
the **whole** `.github/workflows/repo-assist.md` source (both its
`frontmatter_hash` and `body_hash` are recomputed on every compile).
Each of the two PRs changed **both** hashes, so merging them
independently would have one PR's lock regeneration clobber the other's.
Per @wilder's request, they are merged here into one source file and
compiled **once** so the workflow can be manually tested end-to-end
against a single lock.

## What's included

### DeepWiki MCP tool + guidance (from tenstorrent#50962)
- Adds a read-only **DeepWiki** MCP server
(`https://mcp.deepwiki.com/mcp`) scoped to `read_wiki_structure`,
`read_wiki_contents`, `ask_question`. No new write permissions — purely
an additional read-only tool.
- New body section **"Using DeepWiki (cross-repo grounding)"**: use it
to orient across the sibling repos the runner can't easily clone
(`tt-metal`, `tt-umd`, `tt-kmd`, `tt-isa-documentation`), with a strict
**verify-before-asserting** discipline — anything load-bearing must be
confirmed against current code via `bash`/`gh`, never asserted from
DeepWiki alone.
- **Memory** guidance: cache **pointers, not frozen facts** — store
dated, re-derivable notes ("ask DeepWiki about X; last checked <date>")
rather than pasting DeepWiki answers that drift.

### Triage-logic fixes (from tenstorrent#50963)
1. **New-contributor welcome (Task 7)** now requires **verified** zero
merged PRs **and** zero prior issues/comments (via GitHub search) before
welcoming — no longer inferring "new" from local context/memory.
2. **Firewall boilerplate** — adds an instruction to strip the benign
`⚠️ Firewall blocked … awmgmcpg` block from public comments. `awmgmcpg`
is gh-aw's own internal MCP-gateway sidecar; it **cannot** be silenced
via `network.allowed` at this compiler version (confirmed dead end,
documented in a frontmatter NOTE), so it's handled at the instruction
level.
3. **Fresh-issue scoping (Task 1/2)** — first-time comment+label triage
is restricted to issues active in ~90 days, and `[HELP]`/question issues
no longer default to the `bug` label.
4. **Comment dedup (Task 7 + Anti-spam)** — when both a triage comment
(Task 2) and a welcome (Task 7) apply to the same issue in one run, they
are **combined into a single comment** instead of two.

## Compile / testing notes

- `repo-assist.lock.yml` was regenerated **once** with `gh aw compile`
on the combined source using **gh-aw v0.82.14** — the exact
`compiler_version` pinned in the base `main` lock's `gh-aw-metadata`.
Result: **0 errors, 0 warnings**, and a second compile is byte-identical
(deterministic). The lock diff reflects only real content changes
(DeepWiki added to the MCP gateway config + `GH_AW_ALLOWED_DOMAINS`,
updated `gh-aw-metadata` hashes). The `.lock.yml` is generated — please
don't hand-edit; regenerate via `gh aw compile repo-assist`.
- **Suggested manual test:** trigger `/repo-assist <a cross-repo
question>` (e.g. something about tt-umd device init) on a test issue.
One run then exercises **both** change-sets: the DeepWiki tool for
cross-repo grounding, and the fixed contributor-detection / labeling /
comment-dedup behavior.

Once this is verified and merged, tenstorrent#50962 and tenstorrent#50963 are being closed in
favor of it.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

### CI Status
_Auto-generated on every push. Badges update live. Click a badge to
filter runs by this branch._

-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/sanity-tests.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/runtime-sanity-tests.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/runtime-sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/blackhole-sanity-tests.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/blackhole-sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/tt-metal-l2-nightly.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/tt-metal-l2-nightly.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/all-model-tests.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/all-model-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-t3k.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-t3k.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)
-
[![](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-galaxy.yaml/badge.svg?branch=feat/repo-assist-deepwiki-and-triage-fixes)](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-galaxy.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes)

---------

Co-authored-by: Repo Assist <repo-assist@tenstorrent.com>
Co-authored-by: BrAIn <brain@tenstorrent.com>
Co-authored-by: Repo Assist (BrAIn) <repo-assist@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fix Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants