[repo-assist] Fix new-contributor detection, firewall boilerplate, stale-issue triage & double-commenting - #50963
blozano-tt wants to merge 1 commit into
Conversation
Address four findings from a maintainer-requested grading review (Wilder) of repo-assist's first live run: 1. Tighten new-contributor detection (3/3 false positives in the run). Require zero merged PRs and no prior issues/comments, verified via the GitHub search API, before welcoming — not inferred from context. 2. Stop polluting comments with the benign `awmgmcpg` firewall boilerplate. The hostname cannot be added to network.allowed at compiler v0.82.14 (rejected as invalid), so instruct the agent to strip the block instead; documented the reasoning in the frontmatter. 3. Restrict fresh comment+label triage to issues active in ~90 days and stop defaulting [HELP]/question issues to the `bug` label. 4. Combine triage + welcome into a single comment per issue per run. Recompiled with gh aw (v0.82.14); no compiler-version drift. Co-Authored-By: Claude <noreply@anthropic.com> Co-Authored-By: BrAIn <brain@tenstorrent.com>
There was a problem hiding this comment.
Pull request overview
Updates Repo Assist triage behavior following its first live run.
Changes:
- Adds contributor-history checks and combines welcome/triage comments.
- Adds freshness and issue-labeling guidance.
- Attempts to suppress internal firewall warnings from public output.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
.github/workflows/repo-assist.md |
Updates workflow instructions and safeguards. |
.github/workflows/repo-assist.lock.yml |
Refreshes generated workflow hashes. |
| # is therefore handled at the instruction level instead — see the "Never forward | ||
| # firewall boilerplate into comments" guideline below, which tells the agent to | ||
| # strip this internal notice from anything posted publicly. |
| - **Prefer fresh issues for first-time comments+labels.** Restrict new comment+label triage to issues opened or updated in roughly the **last 90 days**. A first-time comment (and a fresh label) dropped out of the blue on a long-stale issue is usually unwelcome noise. | ||
| - **Do not open fresh triage on old stale issues.** For issues with no recent activity (older than ~90 days since last update), do **not** post a first-time comment or apply a first-time label. Route them instead toward the existing stale-nudge path (see Task 6 for the analogous PR handling), or simply leave them alone. When a stale issue clearly needs closing or a nudge, note it under Suggested Actions in Task 8 rather than commenting cold. |
| 2. **Verify contributor history before welcoming — do not infer "new" from context.** A person qualifies as a genuinely new contributor **only if they have zero merged PRs AND no prior issues/comments** in this repository. Do not treat "first time we've seen them on this issue", "first comment in this thread", or "not in our memory" as sufficient — an established, prolific contributor can easily be someone we simply haven't interacted with yet. Confirm history explicitly via GitHub's search API before posting a welcome: | ||
| - `is:pr is:merged author:<login> repo:${{ github.repository }}` — must return **0** results (no merged PRs). | ||
| - `is:issue author:<login> repo:${{ github.repository }}` — must return **0** results other than the item currently being triaged (no prior issues authored). | ||
| - Also confirm they have no prior comment/PR activity in the repo (e.g. `is:pr author:<login> repo:${{ github.repository }}` returning 0, and no earlier comments). |
|
Superseded by #50964, which combines this PR with #50962 into a single coherent Since the compiled lock is a deterministic function of the whole All four triage fixes from this PR are carried over verbatim into #50964. Closing (not merging) in favor of #50964. Leaving the |
…(supersedes tenstorrent#50962, tenstorrent#50963) [skip ci] (tenstorrent#50964) ## Summary This PR **combines and supersedes** two open repo-assist PRs so there is a **single coherent `repo-assist.md` source and one clean `gh aw compile`** to test against: - Supersedes tenstorrent#50962 — *DeepWiki MCP tool + cross-repo grounding guidance* - Supersedes tenstorrent#50963 — *4 triage-logic bug fixes from the first live run* ### Why combine them `.github/workflows/repo-assist.lock.yml` is a deterministic function of the **whole** `.github/workflows/repo-assist.md` source (both its `frontmatter_hash` and `body_hash` are recomputed on every compile). Each of the two PRs changed **both** hashes, so merging them independently would have one PR's lock regeneration clobber the other's. Per @wilder's request, they are merged here into one source file and compiled **once** so the workflow can be manually tested end-to-end against a single lock. ## What's included ### DeepWiki MCP tool + guidance (from tenstorrent#50962) - Adds a read-only **DeepWiki** MCP server (`https://mcp.deepwiki.com/mcp`) scoped to `read_wiki_structure`, `read_wiki_contents`, `ask_question`. No new write permissions — purely an additional read-only tool. - New body section **"Using DeepWiki (cross-repo grounding)"**: use it to orient across the sibling repos the runner can't easily clone (`tt-metal`, `tt-umd`, `tt-kmd`, `tt-isa-documentation`), with a strict **verify-before-asserting** discipline — anything load-bearing must be confirmed against current code via `bash`/`gh`, never asserted from DeepWiki alone. - **Memory** guidance: cache **pointers, not frozen facts** — store dated, re-derivable notes ("ask DeepWiki about X; last checked <date>") rather than pasting DeepWiki answers that drift. ### Triage-logic fixes (from tenstorrent#50963) 1. **New-contributor welcome (Task 7)** now requires **verified** zero merged PRs **and** zero prior issues/comments (via GitHub search) before welcoming — no longer inferring "new" from local context/memory. 2. **Firewall boilerplate** — adds an instruction to strip the benign `⚠️ Firewall blocked … awmgmcpg` block from public comments. `awmgmcpg` is gh-aw's own internal MCP-gateway sidecar; it **cannot** be silenced via `network.allowed` at this compiler version (confirmed dead end, documented in a frontmatter NOTE), so it's handled at the instruction level. 3. **Fresh-issue scoping (Task 1/2)** — first-time comment+label triage is restricted to issues active in ~90 days, and `[HELP]`/question issues no longer default to the `bug` label. 4. **Comment dedup (Task 7 + Anti-spam)** — when both a triage comment (Task 2) and a welcome (Task 7) apply to the same issue in one run, they are **combined into a single comment** instead of two. ## Compile / testing notes - `repo-assist.lock.yml` was regenerated **once** with `gh aw compile` on the combined source using **gh-aw v0.82.14** — the exact `compiler_version` pinned in the base `main` lock's `gh-aw-metadata`. Result: **0 errors, 0 warnings**, and a second compile is byte-identical (deterministic). The lock diff reflects only real content changes (DeepWiki added to the MCP gateway config + `GH_AW_ALLOWED_DOMAINS`, updated `gh-aw-metadata` hashes). The `.lock.yml` is generated — please don't hand-edit; regenerate via `gh aw compile repo-assist`. - **Suggested manual test:** trigger `/repo-assist <a cross-repo question>` (e.g. something about tt-umd device init) on a test issue. One run then exercises **both** change-sets: the DeepWiki tool for cross-repo grounding, and the fixed contributor-detection / labeling / comment-dedup behavior. Once this is verified and merged, tenstorrent#50962 and tenstorrent#50963 are being closed in favor of it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) ### CI Status _Auto-generated on every push. Badges update live. Click a badge to filter runs by this branch._ - [](https://github.com/tenstorrent/tt-metal/actions/workflows/sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/runtime-sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/blackhole-sanity-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/tt-metal-l2-nightly.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/all-model-tests.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-t3k.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) - [](https://github.com/tenstorrent/tt-metal/actions/workflows/pipeline-select-galaxy.yaml?query=branch:feat/repo-assist-deepwiki-and-triage-fixes) --------- Co-authored-by: Repo Assist <repo-assist@tenstorrent.com> Co-authored-by: BrAIn <brain@tenstorrent.com> Co-authored-by: Repo Assist (BrAIn) <repo-assist@users.noreply.github.com>
Summary
Fixes four issues surfaced by a maintainer-requested grading review (Wilder) of
repo-assist's first live run (Actions run 30053298328), which produced monthly issue #50956. All changes are confined to.github/workflows/repo-assist.md(the source) and its regeneratedrepo-assist.lock.yml. This branch is off currentmainand is independent of the unrelated open PR #50962.Fixes
1. New-contributor detection was broken — 3/3 false positives (highest priority)
The run welcomed three established, prolific contributors as if they were newcomers:
skrsmanovicTT— 10 merged PRsRiddy21— 126 merged PRsThe old Task 7 welcomed "first-time contributors" without ever verifying repo history, so it inferred "new" from local/thread context. Fix: Task 7 now requires an explicit history check before any welcome — a contributor qualifies only if they have zero merged PRs AND no prior issues/comments, verified via the GitHub search API:
is:pr is:merged author:<login> repo:tenstorrent/tt-metal→ must be 0is:issue author:<login> repo:tenstorrent/tt-metal→ must be 0 (other than the item being triaged)If any check shows history, the welcome is skipped. "When in doubt, do not welcome."
2. Every public comment polluted with firewall boilerplate
Every comment carried a
⚠️ Firewall blocked 1 domain: awmgmcpgblock. This is benign/cosmetic:awmgmcpgis gh-aw's own internal MCP Gateway sidecar hostname (imagegithub/gh-aw-mcpg, containerawmg-mcpg) being flagged by gh-aw's own firewall — not a real missing external dependency (matches known gh-aw behaviour).The requested fix (adding
awmgmcpgtonetwork.allowed) is rejected by the gh-aw compiler (v0.82.14): a bareawmgmcpgis neither a valid ecosystem identifier nor a domain (no dot). The gateway's actual transport,host.docker.internal, is already in thedefaultsallowlist, so allowlisting changes nothing. Fix (fallback per the review's instruction): a documented NOTE in the frontmatter explains the situation, and a new "Never forward firewall boilerplate into comments" guideline instructs the agent to strip any such block from anything posted publicly.networkstaysdefaults.3. Commented on a 14-month-old stale
[HELP]issue (#9364) and mislabeled itbugFix: Task 2 now restricts first-time comment+label triage to issues active in roughly the last 90 days; older stale issues are routed to the stale-nudge path or left alone rather than getting a cold first-time comment. Task 1 labeling guidance now says
[HELP]/question/support issues must not default tobugunless a defect is actually confirmed.4. Double-commenting the same issue in one run
Issues #50897 and #50955 each got both a triage comment and a separate welcome comment. Fix: Task 7 and the anti-spam guideline now require combining triage + welcome into a single comment when both apply to the same issue in the same run.
Verification
gh aw compile repo-assistsucceeds with 0 errors, 0 warnings, pinned to the repo's existing compiler version v0.82.14 (no compiler-version drift — only the workflow's own frontmatter/body hashes changed in the lock file).actions-lock.jsoncache-cleanup side-effect of recompiling was reverted)./repo-assistagain after merge. This PR proves the workflow compiles cleanly and that the instructions are in place; it cannot prove runtime behaviour on its own.🤖 Prepared with assistance from Claude Code, per a maintainer grading review.
CI Status
Auto-generated on every push. Badges update live. Click a badge to filter runs by this branch.