You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[automated] Recurring CI failures could split across multiple memory records and GitHub issues. Repeated occurrences such as:
Process completed with exit code -1073741502 (0xC0000142)
could receive different proposed cause IDs, lose a historical issue association, or mutate duplicate issues before the canonical issue was updated safely.
Root cause: Agent-proposed IDs were treated as stable identities before comparison with historical records, while issue reconciliation and publication receipts were distributed across producer-specific workflow steps. Same-test records, aliases, trusted job evidence, labels, and occurrence history could therefore diverge across runs.
The fix: Resolve proposed causes deterministically against canonical IDs, transitive aliases, normalized test names, trusted retry patterns, explicit matchers, and trusted failed-job attribution before persistence. Compatible historical same-test records converge on the oldest canonical root, while fresh proposals reuse an existing family only when authoritative identity evidence supports it.
Trusted retry patterns and matchers can redirect the current proposal, but they rewrite an existing historical root only when the same trusted diagnostic signal also matches that root. This preserves intentional split-family convergence without allowing an unrelated proposed ID to absorb another issue family or inherit its aliases and issue URL.
Stored-alias proposals follow the same trusted resolution path. A redirect changes only the current occurrence unless the alias family shares the trusted diagnostic signature, and ambiguous trusted matches fail closed.
Trusted failed-job attribution now enforces non-empty, unique, positive job IDs at the shared validation boundary before any rerun side effect.
The shared tracking-issue.js planner/executor owns exact-marker lookup, oldest-canonical selection, post-create relisting, comment hydration, reopening, label repair, and optional duplicate closure. Canonical updates execute before duplicate comments or closes, and missing cause labels are repaired without reopening a closed receipt-only issue.
Cause publication preserves a bounded rolling occurrence section and consolidates valid rows from open and closed aliases before closing open duplicates. Malformed or conflicting open history suppresses duplicate reconciliation; malformed closed history is skipped with a warning so it cannot permanently block cleanup. Replay-only history consolidation does not reopen a closed canonical issue, while a genuinely new occurrence still does.
Publication receipts are bound to the selected canonical issue URL and resolved across canonical and transitive alias records. Replaying a trimmed occurrence remains idempotent without treating memory persistence before a failed issue mutation as successful publication.
Main-branch breakage titles and diagnostics are rendered from trusted run context. Agent-derived fields are rendered as literal Markdown, occurrence delimiters and rows are recognized only as complete standalone lines, and retry-pattern output matching uses trusted bounded job-log tails rather than agent-authored evidence.
Validation: 554 focused tests passed across AgenticWorkflowTests, AnalyzeCiFailureCauseIssuesTests, AnalyzeCiFailureCauseResolverTests, AnalyzeCiFailureWorkflowTests, AutoRerunTransientCiFailuresTests, and TrackingIssueTests. JavaScript syntax checks, focused formatting, git diff --check, and gh aw compile analyze-ci-failure --validate --actionlint --shellcheck also passed.
This combines output evidence from all jobs with jobNames.some(...), so a two-field job pattern can match across different jobs. For example, a cause spanning Windows and Linux is canonicalized by a { jobName: "windows", output: "LINUX_ONLY_TOKEN" } rule when only the Linux test contains that token. Job-level retry rules require both matchers to hold for the same job; build evidence per job and accept a rule only when one job satisfies all of its matchers, otherwise unrelated causes can be merged under one canonical ID.
Explain how canonical cause IDs and aliases unify repeated CI analyses, how
retry patterns provide stable mappings, and how occurrence receipts prevent
duplicate publication.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🟡 Changes recommended
Alias/test mismatches can merge unrelated flaky tests, normalization differs across validation boundaries, and an obsolete renderer remains checked in.
Get a fresh assessment by requesting another Copilot review.
Occurrence receipts were tracked only by workflow run ID. When canonical
issue selection changed across aliases, a receipt from the previous issue
could suppress the canonical update before duplicate reconciliation closed
the issue that still contained the occurrence.
Persist the selected issue URL with each receipt and honor the receipt only
for that issue. Legacy URL-less receipts and count-based inference remain
accepted when exactly one matching issue exists, while multi-issue
reconciliation always verifies the selected canonical body.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
Recurring CI failure reconciliation could split canonical histories when
a proposed flaky ID reused another test's alias, when stored aliases were
not indexed, or when JavaScript and jq normalized Unicode test names
differently. Existing canonical issues could also permanently lose their
cause-specific labels because labels were only applied during creation.
Validate named flaky families against stored test identity, resolve stored
aliases through their canonical records with fail-closed collision checks,
and align test-name folding with jq's ASCII semantics. Route supplemental
label repair through the shared tracking issue engine without reopening
closed receipt-only issues.
Regression coverage exercises mismatched aliases and roots, Unicode test
names, direct and retry-pattern alias reuse, ambiguous aliases, cross-type
collisions, label repair, and closed-issue behavior.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
Preserve canonical failure comments when run marker is on duplicate
.github/workflows/tracking-issue.js:469
When closeDuplicates is false (the default used by the existing recordRun callers), this now deduplicates against every planning match. If the run marker exists only on a noncanonical duplicate, the selected canonical receives no failure comment; when all matches are closed it is even reopened with no occurrence recorded there. Since duplicate reconciliation is disabled, there is also no link to the issue that contains the run. Preserve the old behavior by treating a marker on another issue as a reason to comment on the selected canonical.
The workflow split analysis publishing and PR commenting into separate
steps, but the contract test still searched for the old combined step
names. CI therefore failed before verifying the intended artifact wiring.
Assert the current publisher and comment step names while retaining all
existing environment and script checks.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
Canonical issue reconciliation rebuilt occurrence history from only the
selected issue before closing aliases. Distinct rows on an alias therefore
disappeared from the canonical view, including replays after the current
run already had a publication receipt.
Merge validated occurrence rows from open aliases into the canonical
update, deduplicate identical run rows, and retain deterministic ordering
and bounded totals. If alias history is malformed or conflicts, publish
the current occurrence but leave duplicates open.
Regression coverage includes new publication, receipt replay, malformed
history, and conflicting rows.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
Trusted retry patterns and matchers could redirect an agent proposal that
named an unrelated historical root, permanently aliasing separate issue
families. Closed aliases were also excluded from occurrence consolidation,
leaving canonical issue history incomplete.
Require the trusted identity signal to match the proposed historical root
before rewriting it. Import valid occurrence rows from closed aliases while
keeping replay-only closed canonicals closed and ignoring malformed closed
history without blocking open duplicate reconciliation.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
The shared validator now accepts duplicate job_ids (for example, [1, 1]), even though the rerun contract requires them to be unique and the replaced inline validator explicitly enforced that invariant. Because the rerun job calls this function directly on agent output, malformed attribution can now pass validation and reach the rerun side effect. Add a set-size check here.
The shared cause-attribution boundary accepted duplicate and non-positive
job IDs even though the workflow contract requires unique positive IDs.
That allowed malformed cause data to reach the rerun path after replacing
the workflow's inline validation.
Validate the complete job ID contract before attribution or rerun side
effects, and cover both the shared resolver and compiled rerun workflow.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
[automated] Fixed by restoring unique, positive job ID validation in the shared attribution boundary before rerun side effects. The direct resolver boundary and the compiled rerun workflow now both reject duplicate and non-positive IDs.
This skips trusted retry-pattern and explicit-matcher resolution whenever the agent proposes a stored alias. For example, if legacy-dns aliases dns-outage but the trusted job log matches the configured windows-init pattern, the same failure resolves to DNS when proposed as legacy-dns but to Windows when proposed as dns-outage. That lets an incorrect alias contaminate an unrelated historical family despite the trusted identity signal. Evaluate the trusted mechanisms for alias proposals too, then either redirect the current proposal or fail closed when the authoritative identities conflict.
Stored cause aliases bypassed trusted retry-pattern and explicit-matcher
resolution, so identical failure evidence could resolve to different cause
families depending on which alias the agent proposed.
Apply trusted current evidence consistently to alias proposals while keeping
unrelated alias families separate unless the same diagnostic signature
matches their stored history. Ambiguous trusted matches continue to fail
closed.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 68afc81c-eaf6-4e13-a0e8-9528d8824b0c
[automated] Fixed in 998e6ef by applying trusted retry-pattern and explicit-matcher resolution consistently to stored-alias proposals. Trusted evidence can redirect the current occurrence without transferring an unrelated alias family; compatible families still converge only when the same diagnostic signature matches stored history, and ambiguous trusted matches fail closed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[automated] Recurring CI failures could split across multiple memory records and GitHub issues. Repeated occurrences such as:
could receive different proposed cause IDs, lose a historical issue association, or mutate duplicate issues before the canonical issue was updated safely.
Root cause: Agent-proposed IDs were treated as stable identities before comparison with historical records, while issue reconciliation and publication receipts were distributed across producer-specific workflow steps. Same-test records, aliases, trusted job evidence, labels, and occurrence history could therefore diverge across runs.
The fix: Resolve proposed causes deterministically against canonical IDs, transitive aliases, normalized test names, trusted retry patterns, explicit matchers, and trusted failed-job attribution before persistence. Compatible historical same-test records converge on the oldest canonical root, while fresh proposals reuse an existing family only when authoritative identity evidence supports it.
Trusted retry patterns and matchers can redirect the current proposal, but they rewrite an existing historical root only when the same trusted diagnostic signal also matches that root. This preserves intentional split-family convergence without allowing an unrelated proposed ID to absorb another issue family or inherit its aliases and issue URL.
Stored-alias proposals follow the same trusted resolution path. A redirect changes only the current occurrence unless the alias family shares the trusted diagnostic signature, and ambiguous trusted matches fail closed.
Trusted failed-job attribution now enforces non-empty, unique, positive job IDs at the shared validation boundary before any rerun side effect.
The shared
tracking-issue.jsplanner/executor owns exact-marker lookup, oldest-canonical selection, post-create relisting, comment hydration, reopening, label repair, and optional duplicate closure. Canonical updates execute before duplicate comments or closes, and missing cause labels are repaired without reopening a closed receipt-only issue.Cause publication preserves a bounded rolling occurrence section and consolidates valid rows from open and closed aliases before closing open duplicates. Malformed or conflicting open history suppresses duplicate reconciliation; malformed closed history is skipped with a warning so it cannot permanently block cleanup. Replay-only history consolidation does not reopen a closed canonical issue, while a genuinely new occurrence still does.
Publication receipts are bound to the selected canonical issue URL and resolved across canonical and transitive alias records. Replaying a trimmed occurrence remains idempotent without treating memory persistence before a failed issue mutation as successful publication.
Main-branch breakage titles and diagnostics are rendered from trusted run context. Agent-derived fields are rendered as literal Markdown, occurrence delimiters and rows are recognized only as complete standalone lines, and retry-pattern output matching uses trusted bounded job-log tails rather than agent-authored evidence.
Validation: 554 focused tests passed across
AgenticWorkflowTests,AnalyzeCiFailureCauseIssuesTests,AnalyzeCiFailureCauseResolverTests,AnalyzeCiFailureWorkflowTests,AutoRerunTransientCiFailuresTests, andTrackingIssueTests. JavaScript syntax checks, focused formatting,git diff --check, andgh aw compile analyze-ci-failure --validate --actionlint --shellcheckalso passed.Fixes #19578