You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Automates Azure DevOps validation for the repository's generated CI-fix pull requests.
Adds strict same-repository gating for the automated fingerprint: github-actions[bot], ci-fix/** head, agentic-workflows label, and the correct title/base pairing for main and net11.0.
Uses trusted pull_request_target execution plus trusted-main workflow_run reconciliation for both fixer workflows, including cases where GitHub-token-created PR events are suppressed or approval-gated. Every configured PR event reconciles live eligible open PR heads rather than relying on stale webhook identities.
Refreshes nominated PRs individually and verifies each test-merge commit contains the refreshed source head as its second parent before queueing or deduplication. Missing, stale, or conflicting merge pairs produce explicit per-PR failures without blocking other verified heads; the overall run remains non-success when eligible work cannot be dispatched. Live eligibility and the head/merge pair are revalidated for each pipeline under the same partial-failure boundary as dedupe and queue operations.
Queues MAUI validation definitions 302 (maui-pr), 313 (maui-pr-uitests), and 314 (maui-pr-devicetests) with the verified PR merge ref/SHA, provider triggerInfo, and serialized system.pullRequest.* parameters matching observed normal Azure PR build payloads. The system parameters include the bare target branch used by pipeline conditions and the source head SHA. PR-head check association remains subject to live canary verification.
Adds per-pipeline/head-SHA deduplication, bounded retries, safe ambiguous-POST reconciliation, explicit partial-failure reporting, summaries, and build links. Nested PowerShell request timeouts enter reconciliation without repeating the POST; failed reconciliation preserves possible-acceptance uncertainty. Deduplication and both fixer instructions require the PR merge ref and exact source-head metadata when matching automatic builds.
Both fixer variants retain primary-pipeline whole-build validation for build-only fixes. When a build break originates in definition 313 or 314, merely observing its exact-head run is insufficient: all relevant originating platform build legs must be completed and successful before marking ready. Missing, unknown, pending, failed, or canceled relevant evidence stops readiness; unrelated test-leg flakes do not. Readiness audit comments identify the validated primary and originating pipeline/build evidence.
A shared seven-minute dispatch budget caps HTTP timeouts and backoff under the ten-minute job limit. Budget exhaustion, including during queue-time revalidation, preserves completed results and explicitly reports unprocessed work without implying those pipelines submitted a queue POST.
Never checks out or executes PR-controlled code; authentication uses the existing main-branch OIDC trust and no PAT.
Updates the CI-fixer descriptions, setup documentation, and compiled gh-aw lock files.
Validation
Completed locally:
73 focused Pester tests passed at d0cf55b, independently rerun, including offline full-script reconciliation, delayed-event regressions, behavioral queue-response coverage, shared-budget exhaustion, and accurate partial-result reporting across multiple PRs. Coverage includes nested timeout exceptions with real duplicate identity matching, outer/nested JSON contract assertions for main and net11.0, stale/malformed merge-parent rejection, refreshed eligibility revocation, actual entrypoint mixed/all-unverifiable failure routing, preservation of completed results after queue-time revalidation failures, and dedupe/fixer source-head contract alignment. The readiness additions assert prompt requirements in both sources; they do not simulate agent execution.
A local stalled-HTTP-server repro confirms actual PowerShell Invoke-RestMethod timeout exceptions are recognized as transient after the fix. No Azure request was made by this repro.
PowerShell parse validation passed.
actionlint passed for the new dispatcher workflow. Direct linting of the generated fixer locks reports the same six pre-existing findings before and after this readiness change; the gh-aw actionlint wrapper returned tooling exit 125, not a clean lint result.
Both gh-aw v0.86.2 strict compile/no-emit checks passed for the readiness follow-up, and both locks were regenerated with zero compiler warnings. This follow-up changes only their body hashes, not workflow configuration.
Dry-run payload validation passed for all three pipeline definitions.
git diff --check passed.
Rollout notes
Merging enables the automation. Only pipeline 302 OIDC queueing has live proof so far. Azure DevOps Basic access and Queue builds permission for all three definitions, plus exact PR-head check association, remain rollout/canary requirements and should be verified after merge. No live build was queued by this PR-creation or review-follow-up work.
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.
The reason will be displayed to describe this comment to others. Learn more.
GPT-only empirical adversarial review of 820c6531907b - needs changes.
One additional P1 defect is documented inline: the workflow_run reconciliation path crashes before it can queue any validation. I reproduced it using actual public GitHub open-PR JSON and a real completed main-branch fixer payload, replaying only the HTTP response boundary locally with a noncredential placeholder. The full script's workflow_run -DryRun invocation throws Unexpected base repository ''. at line 106, reached through lines 232 and 553. Explicitly enumerating the same response changes one System.Object[] item into three PR objects and lets the scan complete.
Produced the expected merge-ref, merge-SHA and source-head payloads for definitions 302, 313 and 314; no builds queued
Full workflow_run -DryRun path
Reproduced the inline defect
CI evidence: required maui-pr is skipping, and there are no PR builds for definitions 302/313/314. PowerShell Script Tests has three failures, but all three are stale GPT-5.6 model assertions in unchanged base-branch inputs; I reproduced those same three failures locally and verified the relevant files are identical between this PR's base and head. This is not a clean-CI or live-rollout claim: OIDC queue permissions for all three definitions and actual PR-head check association still need a live canary.
The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.
The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.
Require originating pipeline run to pass before advancing to T3
.github/workflows/ci-status-fix-net11.md:1220
This gate only checks that the originating UI/device pipeline build exists, then proceeds to T3 even if that matching run is still pending or has failed. A build-only fix for a 313/314 failure can therefore be marked ready without showing that the originating build break is fixed. Require the matching run’s relevant legs to be fully green before proceeding.
Require originating pipeline run to pass before advancing to T3
.github/workflows/ci-status-fix.md:1204
This gate only checks that the originating UI/device pipeline build exists, then proceeds to T3 even if that matching run is still pending or has failed. A build-only fix for a 313/314 failure can therefore be marked ready without showing that the originating build break is fixed. Require the matching run’s relevant legs to be fully green before proceeding.
The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.
@PureWeen — new AI review results are available based on commit d0cf55b.
🗂️ Review Sessions — click to expand 🚦 Gate — Test Before & After Fix
Gate Result: ⚠️ SKIPPED
No tests were detected in this PR.
Recommendation: Add tests to verify the fix using the write-tests-agent.
📋 Pre-Flight — Context & Validation
⚠️Pre-Flight did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🔬 Code Review — Deep Analysis
⚠️Code Review did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🛠️ Try-Fix — Analysis & Comparison
⚠️Try-Fix did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🏁 Report — Final Recommendation
⚠️Report / Final Recommendation did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🧭 Next Steps — review latest findings
No alternative fix was selected for this run. Review the session findings and CI results before merging.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Automates Azure DevOps validation for the repository's generated CI-fix pull requests.
github-actions[bot],ci-fix/**head,agentic-workflowslabel, and the correct title/base pairing formainandnet11.0.pull_request_targetexecution plus trusted-mainworkflow_runreconciliation for both fixer workflows, including cases where GitHub-token-created PR events are suppressed or approval-gated. Every configured PR event reconciles live eligible open PR heads rather than relying on stale webhook identities.maui-pr), 313 (maui-pr-uitests), and 314 (maui-pr-devicetests) with the verified PR merge ref/SHA, providertriggerInfo, and serializedsystem.pullRequest.*parameters matching observed normal Azure PR build payloads. The system parameters include the bare target branch used by pipeline conditions and the source head SHA. PR-head check association remains subject to live canary verification.Validation
Completed locally:
d0cf55b, independently rerun, including offline full-script reconciliation, delayed-event regressions, behavioral queue-response coverage, shared-budget exhaustion, and accurate partial-result reporting across multiple PRs. Coverage includes nested timeout exceptions with real duplicate identity matching, outer/nested JSON contract assertions for main and net11.0, stale/malformed merge-parent rejection, refreshed eligibility revocation, actual entrypoint mixed/all-unverifiable failure routing, preservation of completed results after queue-time revalidation failures, and dedupe/fixer source-head contract alignment. The readiness additions assert prompt requirements in both sources; they do not simulate agent execution.Invoke-RestMethodtimeout exceptions are recognized as transient after the fix. No Azure request was made by this repro.actionlintpassed for the new dispatcher workflow. Direct linting of the generated fixer locks reports the same six pre-existing findings before and after this readiness change; the gh-aw actionlint wrapper returned tooling exit 125, not a clean lint result.git diff --checkpassed.Rollout notes
Merging enables the automation. Only pipeline 302 OIDC queueing has live proof so far. Azure DevOps Basic access and Queue builds permission for all three definitions, plus exact PR-head check association, remain rollout/canary requirements and should be verified after merge. No live build was queued by this PR-creation or review-follow-up work.