Skip to content

feat(sandbox): add runtime-install field to control sbx/gVisor install step generation - #51413

Merged
pelikhan merged 8 commits into
mainfrom
copilot/add-field-to-sandbox-agent-runtime-install
Aug 8, 2026
Merged

pelikhan merged 8 commits into
mainfrom
copilot/add-field-to-sandbox-agent-runtime-install

Conversation

Copilot AI commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Adds sandbox.agent.runtime-install: bool (default true) so workflows can opt out of generating sbx/gVisor installation steps — useful when the runtime is pre-installed on the runner. The credential-refresh step is always emitted regardless, since it does not require sudo. Field is importable from shared agent workflows (false-wins merge semantics). Noop when no runtime is specified.

Also refactors all previously-inlined shell code into standalone scripts under actions/setup/sh/; scripts requiring sudo are prefixed sudo_.

New shell scripts

Script sudo
docker_sbx_kvm_check.sh No
docker_sbx_secrets_check.sh No
sudo_docker_sbx_install.sh Yes
docker_sbx_daemon.sh No
docker_sbx_preflight.sh No
docker_sbx_credential_refresh.sh No
sudo_gvisor_install.sh Yes

Usage

sandbox:
  agent:
    runtime: docker-sbx
    runtime-install: false   # skip install/daemon/preflight steps; credential-refresh still runs

Key changes

  • sandbox.go — RuntimeInstall *bool on AgentSandboxConfig; mergeImportedSandboxAgentRuntimeInstall() (false-wins across imports)
  • firewall.go — isRuntimeInstallEnabled(): returns true when runtime is unset (noop), false only when runtime is set and field is explicitly false
  • docker_sbx_install.go / copilot_engine_installation.go — step generators now call external scripts instead of inlining shell
  • codex_engine.go / nodejs.go — install steps gated on isRuntimeInstallEnabled(); credential-refresh remains ungated
  • import_field_extractor.go / import_processor.go — accumulator field + MergedSandboxAgentRuntimeInstall in ImportsResult

Generated by 👨‍🍳 PR Sous Chef · gpt54 · 13 AIC · ⌖ 6.35 AIC · ⊞ 8.5K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/31268056080> Generated by 👨‍🍳 PR Sous Chef · gpt54 · 4.6 AIC · ⌖ 5.27 AIC · ⊞ 8.5K · ◷

Comment /souschef to run again

Copilot AI and others added 3 commits August 8, 2026 15:47
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
…r sbx/gvisor steps

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title Add sandbox.agent.runtime-install field to control sbx/gvisor install step generation feat(sandbox): add runtime-install field to control sbx/gVisor install step generation Aug 8, 2026
Copilot AI requested a review from pelikhan August 8, 2026 16:03
@pelikhan
pelikhan marked this pull request as ready for review August 8, 2026 16:05
Copilot AI balanced review requested due to automatic review settings August 8, 2026 16:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds sandbox.agent.runtime-install to skip runtime setup when gVisor or docker-sbx is preinstalled, while retaining credential refresh.

Changes:

  • Adds runtime-install gating and import merge semantics.
  • Extracts inline runtime setup commands into shell scripts.
  • Updates runtime setup tests and script assertions.
Show a summary per file
File Description
pkg/workflow/sandbox.go Defines and merges runtime-install configuration.
pkg/workflow/nodejs.go Gates npm-engine runtime setup steps.
pkg/workflow/gvisor_test.go Tests gVisor script delegation.
pkg/workflow/firewall.go Adds the runtime-install helper.
pkg/workflow/docker_sbx_test.go Tests docker-sbx scripts and gating.
pkg/workflow/docker_sbx_install.go Delegates docker-sbx setup to scripts.
pkg/workflow/copilot_engine_installation.go Delegates gVisor installation to a script.
pkg/workflow/compiler_orchestrator_engine.go Applies imported runtime-install values.
pkg/workflow/codex_engine.go Gates Codex runtime setup steps.
pkg/parser/import_processor.go Exposes the merged import value.
pkg/parser/import_field_extractor.go Extracts runtime-install from imports.
eslint-factory/src/rules/require-invalid-date-check-before-compare.ts Applies formatting-only changes.
actions/setup/sh/sudo_gvisor_install.sh Installs and verifies gVisor.
actions/setup/sh/sudo_docker_sbx_install.sh Installs docker-sbx.
actions/setup/sh/docker_sbx_secrets_check.sh Validates Docker Hub credentials.
actions/setup/sh/docker_sbx_preflight.sh Runs the docker-sbx smoke test.
actions/setup/sh/docker_sbx_kvm_check.sh Checks KVM availability.
actions/setup/sh/docker_sbx_daemon.sh Configures and starts docker-sbx.
actions/setup/sh/docker_sbx_credential_refresh.sh Refreshes sbx credentials.

Review details

Tip

Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 19/19 changed files
  • Comments generated: 2
  • Review effort level: Balanced

Comment thread pkg/workflow/sandbox.go
ModelFallback *TemplatableBool `yaml:"model-fallback,omitempty"` // AWF API proxy model fallback enable/disable flag (optional)
TokenSteering *bool `yaml:"token-steering,omitempty"` // AWF API proxy token steering enable/disable flag (optional)
Targets map[string]*AgentAPIProxyTargetConfig `yaml:"targets,omitempty"` // Per-provider API proxy target overrides keyed by provider name (e.g. "openai", "anthropic")
RuntimeInstall *bool `yaml:"runtime-install,omitempty"` // Controls generation of runtime installation steps (gVisor/docker-sbx). Default: true. Noop when runtime is not set.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 0c37a5b. runtime-install is now accepted by pkg/parser/schemas/main_workflow_schema.json, extracted in extractAgentSandboxConfig, and covered by direct frontmatter regression tests in pkg/workflow/docker_sbx_test.go and pkg/workflow/frontmatter_extraction_security_test.go.

Comment thread pkg/workflow/nodejs.go
Comment on lines +154 to +159
if isRuntimeInstallEnabled(workflowData) {
steps = append(steps, generateDockerSbxKVMCheckStep())
steps = append(steps, generateDockerSbxSecretsCheckStep())
steps = append(steps, generateDockerSbxInstallStep())
steps = append(steps, generateDockerSbxAuthAndDaemonStep())
steps = append(steps, generateDockerSbxPreFlightStep())

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 0c37a5b. validateSandboxConfig now requires sandbox.agent.sudo: true for docker-sbx only when runtime installation remains enabled, and TestDockerSbxValidation_RuntimeInstallFalseAllowsPreinstalledRuntime plus the frontmatter compile regression cover the preinstalled-runtime path.

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.individual.githubcopilot.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.individual.githubcopilot.com"

See Network Configuration for more information.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

🧪 Test Quality Sentinel Report

Test Quality Score: 100/100 ✅ Excellent

Overview

This PR introduces comprehensive tests for the new runtime-install field, with a strategic refactoring that moves sandbox setup logic into dedicated shell scripts and validates them at both the Go layer and script layer.

Changes Summary

  • docker_sbx_test.go: +197 lines, -57 lines (net +140)
  • gvisor_test.go: +42 lines, -37 lines (net +5)
  • Implementation ratio: 0% (all tests are behavioral/design contracts)
  • Build tags: ✅ Present ((go/redacted):build !integration)
  • Mock libraries: ✅ None detected

Test Breakdown

New Test Functions (6 tests, 100% design quality)
Test Subtests Assertions Classification
TestDockerSbxShellScriptContent 6 36+ behavioral_contract, high_value
TestSudoDockerSbxInstallScriptRequiresSudo — 2 behavioral_contract, high_value
TestIsRuntimeInstallEnabled 6 12 design_test, high_value
TestDockerSbxRuntimeInstallFalseOmitsInstallSteps — 5 behavioral_contract, high_value
TestSudoGVisorInstallScriptContent — 11 behavioral_contract, high_value
Modified: TestGenerateDockerSbxInstallSteps 6 14 new design_test, maintained
Modified: TestGenerateGVisorInstallStep — 5 new design_test, maintained

Strengths:

  • ✅ All new tests verify behavioral contracts (file existence, step names, script references)
  • ✅ Edge cases covered: TestIsRuntimeInstallEnabled validates 6 scenarios (nil, no-runtime, nil-field, true, false with docker-sbx, false with gvisor)
  • ✅ No duplication: Each test has distinct purpose
  • ✅ File I/O integration: Tests verify actual shell scripts exist and contain expected key operations
  • ✅ Descriptive assertions: Every assert/require has a message explaining what failed
  • ✅ Script-driven contracts: Refactored tests shifted from inline implementation assertions to verifying step names and script references—this is intentional and improves maintainability since logic now lives in shell scripts
Test Inflation Analysis
File Test Lines Prod Lines (net) Assessment
docker_sbx_test.go +197 -85 (docker_sbx_install.go) ✅ Production simplified; tests validate both Go layer and shell scripts
gvisor_test.go +42 N/A (new scripts) ✅ Reasonable overhead for new script verification

Analysis: Apparent 2–2.3:1 ratio is not inflation. Production code was refactored and simplified (106 deleted from docker_sbx_install.go). New tests validate the actual implementation layer (shell scripts) that now contain the logic—this is healthy boundary testing.


Quality Score Details

Calculation:

Design Tests: 6/6 (100%) × 40 = 40
Edge Cases: 6/6 (100%) × 30 = 30
No Duplicates: 20 − 0 = 20
No Inflation: 10
───────────────────────────────
Total: 100/100

Thresholds:

  • ≥80 ✅ Excellent (this PR)
  • 60–79 ⚠️ Acceptable
  • 40–59 🔶 Needs improvement
  • <40 ❌ Poor

Key Quality Signals

Behavioral Coverage

  • ✅ Shell script existence validated (all 6 docker-sbx scripts + gVisor script)
  • ✅ Key operations verified in scripts (KVM checks, secret handling, daemon logic, sudo usage)
  • ✅ New isRuntimeInstallEnabled() helper covers all branches (nil, no-runtime, field variations)
  • ✅ Critical behavior: runtime-install: false omits 5 install steps (verified with negative assertions)

Design Rigor

  • ✅ Tests verify contracts, not implementations (step names, script references)
  • ✅ Both runtime types tested (docker-sbx, gvisor)
  • ✅ Error paths validated ("exit 1", missing files, missing secrets)
  • ✅ No mocking of core logic—only I/O against real files

Refactoring Quality

The modified tests (TestGenerateDockerSbxInstallSteps, TestGenerateGVisorInstallStep) were refactored to test the new interface:

  • Before: Verified inline implementation (specific shell commands)
  • After: Verify step names and script references (the actual contract)
  • Impact: More maintainable; logic is now in scripts, tests verify scripts are called

Hard Checks: All Passing ✅

  • ✅ No Go mock library usage (gomock, testify/mock, .EXPECT(), .On())
  • ✅ Required build tags present ((go/redacted):build !integration on line 1)
  • ✅ No forbidden mocking patterns
  • ✅ All assertions have descriptive failure messages
  • ✅ Proper require/assert usage (fatal on setup, soft on assertions)

Recommendation

✅ APPROVE — This is a high-quality test PR that comprehensively validates the new runtime-install feature while maintaining clean code structure and design principles. The shift to script-driven contracts improves long-term maintainability.

🧪 Test quality analysis by Test Quality Sentinel · haiku45 · 19.9 AIC · ⌖ 3.41 AIC · ⊞ 7.7K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Test Quality Sentinel: 100/100. All tests are behavioral contracts with comprehensive edge-case coverage. Zero implementation tests, no violations. Production code was simplified while test coverage expanded—healthy refactoring. The shift to script-driven contracts improves maintainability.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /tdd and /codebase-design — requesting changes on two test gaps and one potential logic bug in the false-wins merge.

📋 Key Themes & Highlights

Issues Found

  1. TestDockerSbxRuntimeInstallFalseOmitsInstallSteps missing positive assertion — the test verifies install steps are absent but does not assert that credential-refresh is still emitted. The PR stated guarantee ("credential-refresh always emitted") is untested.

  2. TestGenerateGVisorInstallStep lost supply-chain security assertions — moving logic to a script is correct, but the test no longer checks SHA-512 verification, uname -m, or sudo install. A TestGVisorInstallScriptContent analogous to TestDockerSbxShellScriptContent would restore that coverage.

  3. mergeImportedSandboxAgentRuntimeInstall may violate false-wins contract — an import with runtime-install: true can overwrite a main workflow that explicitly set runtime-install: false. See inline comment on sandbox.go:344.

Positive Highlights

  • Clean extraction of inlined shell into named scripts — greatly improves maintainability and testability
  • isRuntimeInstallEnabled is a well-scoped helper with comprehensive unit tests
  • Credential-refresh ungating is the right design: it does not require sudo and should always run
  • Import accumulator pattern is consistent with existing merge semantics in the codebase

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · sonnet46 · 53.6 AIC · ⌖ 7.22 AIC · ⊞ 7.1K
Comment /matt to run again

assert.NotContains(t, content, "sudo_docker_sbx_install.sh", "install step must be omitted when runtime-install: false")
assert.NotContains(t, content, "docker_sbx_daemon.sh", "daemon step must be omitted when runtime-install: false")
assert.NotContains(t, content, "docker-sbx pre-flight smoke test", "pre-flight must be omitted when runtime-install: false")
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/tdd] The test verifies that install steps are absent when runtime-install: false, but it does not assert that the credential-refresh step is still emitted — the core invariant this PR claims.

Without a positive assertion, a regression that accidentally drops the credential-refresh step would go undetected.

💡 Suggested addition
// Credential refresh must still be present.
assert.Contains(t, content, "docker_sbx_credential_refresh.sh",
    "credential refresh step must still be emitted when runtime-install: false")

Add this inside TestDockerSbxRuntimeInstallFalseOmitsInstallSteps after the existing NotContains block.

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 0c37a5b. I added an end-to-end compile regression in TestDockerSbxFrontmatterExtractionRuntimeInstallFalse that asserts Refresh sbx credentials is still emitted when runtime-install: false, and kept the install-step omission test focused on the gated install builder.

// Must detect architecture dynamically, not hardcode amd64/arm64.
assert.Contains(t, s, "uname -m", "must detect architecture via uname -m")
assert.NotContains(t, s, "amd64", "must NOT remap architecture to amd64")
assert.NotContains(t, s, "arm64", "must NOT remap architecture to arm64")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/tdd] The refactored TestGenerateGVisorInstallStep loses precise supply-chain assertions: SHA-512 verification, uname -m architecture detection, sudo install, and the official gVisor URL. The new test only checks that the script filename is referenced — it no longer guards against the script being modified to skip integrity checks.

Consider adding a TestGVisorInstallScriptContent (similar to TestDockerSbxShellScriptContent) that reads sudo_gvisor_install.sh and asserts sha512sum -c, uname -m, storage.googleapis.com/gvisor, and sudo install are present.

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 0c37a5b. pkg/workflow/gvisor_test.go now includes TestGVisorInstallScriptContent, which asserts sha512sum -c, uname -m, the official storage.googleapis.com/gvisor URL, and sudo install are present in sudo_gvisor_install.sh.

Comment thread pkg/workflow/sandbox.go

// isSandboxEnabled checks if the sandbox is enabled (either explicitly or auto-enabled)
// Returns true when:
// - sandbox.agent is explicitly set to awf

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/codebase-design] mergeImportedSandboxAgentRuntimeInstall applies false-wins semantics, but when the imported value is true and the main workflow has already explicitly set RuntimeInstall: &false, this line overwrites it:

if !*importedRuntimeInstall || sandboxConfig.Agent.RuntimeInstall == nil {
    sandboxConfig.Agent.RuntimeInstall = importedRuntimeInstall
}

If the main workflow sets runtime-install: false and an import sets runtime-install: true, the import wins — contradicting the false-wins contract described in the PR description and the comment above the function.

The condition should be: apply only when the imported value is false (never let an import make it true if already false).

💡 Suggested fix
// Only set from import when: import is false (always wins), or field is not yet set.
if !*importedRuntimeInstall {
    sandboxConfig.Agent.RuntimeInstall = importedRuntimeInstall
} else if sandboxConfig.Agent.RuntimeInstall == nil {
    sandboxConfig.Agent.RuntimeInstall = importedRuntimeInstall
}

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked in 0c37a5b. The merge logic already preserved false-wins semantics; I added TestMergeImportedSandboxAgentRuntimeInstall to lock that in, including the case where a main workflow’s explicit false must not be overwritten by an imported true.

… script extraction

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

ADR Required - Draft Committed

This PR adds 545 lines of new code in business-logic directories and no Architecture Decision Record (ADR) was found.

A draft ADR has been committed to this branch at:

docs/adr/51413-sandbox-agent-runtime-install-field-with-script-extraction.md

This PR cannot merge until the ADR is reviewed and its status updated from Draft to Accepted.

What to do next:

  1. Open docs/adr/51413-sandbox-agent-runtime-install-field-with-script-extraction.md on this branch.
  2. Review the auto-generated Context, Decision, Alternatives, and Consequences sections.
  3. Correct or expand any section marked [TODO: verify].
  4. Change Status: Draft to Status: Accepted (or Proposed if team sign-off is needed first).
  5. Commit the updated ADR on this branch - the gate will re-evaluate and approve once the status is set.

Why ADRs matter: ADRs create a permanent, searchable record of why a decision was made. Without one, future contributors have no way to understand the constraints that shaped the code, making changes riskier and context loss inevitable.

Required ADR sections (Michael Nygard template):

  • Context: The situation, problem, and non-negotiable constraints
  • Decision: What was decided and the primary reason
  • Alternatives Considered: At least 2 real alternatives and why each was rejected
  • Consequences: Expected positive and negative outcomes

Merge blocked until docs/adr/51413 status is Accepted (or Proposed).

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · sonnet46 · 72.1 AIC · ⌖ 25.8 AIC · ⊞ 8.8K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: feat(sandbox): add runtime-install field

One blocking issue found — schema validation will reject the new field.

The runtime-install field is correctly added to the Go struct (AgentSandboxConfig.RuntimeInstall *bool) and wired through the full stack (import accumulator → merge function → codex/nodejs engine). However, pkg/parser/schemas/main_workflow_schema.json is not updated, and the sandbox.agent object definition there has "additionalProperties": false. Any workflow that sets sandbox.agent.runtime-install: false will receive a schema validation error from the compiler before the feature ever executes.

Fix required: Add "runtime-install": { "type": "boolean", ... } to the sandbox.agent properties block in the schema file (around the existing runtime property definition, ~line 3523).

Other observations (non-blocking)
  • False-wins merge semantics: The "false wins" accumulation in mergeSandboxAgentRuntimeInstall is clearly documented and intentional — this is correct for a security-oriented field.
  • Shell script extraction: Moving inline bash from Go string slices into actions/setup/sh/*.sh scripts is a sound refactor — scripts are now independently testable and readable.
  • generateDockerSbxCredentialRefreshStep is always emitted even when runtime-install: false — the comment "always emitted" is consistent with the implementation in nodejs.go (it sits outside the isRuntimeInstallEnabled guard). This is the intended behaviour for pre-installed runtimes.
  • Import-level override precedence: mergeImportedSandboxAgentRuntimeInstall correctly lets the main workflow's explicit true resist being overridden by an import's true, while still being overridden by an import's false. Correct.
  • Tests are thorough and cover the new helper, the omission of steps, and the shell script contents.

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · sonnet46 · 79.1 AIC · ⌖ 7.48 AIC · ⊞ 5.5K

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Quick triage nudge for this PR.

Please address the latest blocking review feedback, update the ADR status if it is ready, refresh the branch if GitHub can do so cleanly, then run the pr-finisher skill and push follow-up fixes.

Open review context (newest first):

  • github-actions requested changes: schema validation will reject sandbox.agent.runtime-install unless pkg/parser/schemas/main_workflow_schema.json adds the new boolean property.
  • github-actions requested changes: restore/extend coverage for credential refresh and gVisor script assertions, and re-check the false-wins merge behavior noted in review.

Branch refresh was requested.

Run: https://github.com/github/gh-aw/actions/runs/31267317361

Generated by 👨‍🍳 PR Sous Chef · gpt54 · 13 AIC · ⌖ 6.35 AIC · ⊞ 8.5K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits August 8, 2026 16:45
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot Quick triage nudge for this PR.

Please address the latest blocking review feedback, update the ADR status if it is ready, refresh the branch if GitHub can do so cleanly, then run the pr-finisher skill and push follow-up fixes.

Open review context (newest first):

  • github-actions requested changes: schema validation will reject sandbox.agent.runtime-install unless pkg/parser/schemas/main_workflow_schema.json adds the new boolean property.
  • github-actions requested changes: restore/extend coverage for credential refresh and gVisor script assertions, and re-check the false-wins merge behavior noted in review.

Branch refresh was requested.

Run: https://github.com/github/gh-aw/actions/runs/31268056080

Generated by 👨‍🍳 PR Sous Chef · gpt54 · 4.6 AIC · ⌖ 5.27 AIC · ⊞ 8.5K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Quick triage nudge for this PR.

Please address the latest blocking review feedback, update the ADR status if it is ready, refresh the branch if GitHub can do so cleanly, then run the `pr-fin...

Addressed in 0c37a5b. I fixed the schema/frontmatter wiring, made docker-sbx sudo validation conditional on runtime installation being enabled, restored the missing credential-refresh and gVisor script coverage, added a false-wins merge regression test, and marked the ADR Accepted. The branch was not behind base, so no update-branch action was needed. Local make test and targeted workflow tests passed; make lint / BASE_REF=origin/main make agent-report-progress still hit pre-existing failures in pkg/parser/import_schema_validation_input_type_test.go (testifylint) and eslint-factory’s require-fs-io-try-catch tests. CI on this pushed head is still stale until a maintainer re-triggers it.

Copilot AI requested a review from gh-aw-bot August 8, 2026 17:02
@pelikhan
pelikhan merged commit d71cd18 into main Aug 8, 2026
28 of 30 checks passed
@pelikhan
pelikhan deleted the copilot/add-field-to-sandbox-agent-runtime-install branch August 8, 2026 17:16
Copilot stopped work on behalf of gh-aw-bot due to an error August 8, 2026 17:17
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.86.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants