You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Are you waiting for the changes in this PR to be merged?
It would be very helpful if you could test the resulting artifacts from this PR and let us know in a comment if this change resolves your issue. Thank you!
Description of Change
Fix a confirmed startup-deadline regression in the CI-fix Azure DevOps dispatcher introduced by #39147, and correct a separate, pre-existing producer prompt contradiction that blocks mandatory safe-output registration.
Production evidence:run 37477952193 spent approximately 533 seconds between starting the 420-second deadline and completing trusted checkout; run 37485076087 spent approximately 494 seconds. Both then failed with The variable cannot be validated because the value 0 is not a valid value for the DispatcherBudgetSeconds variable.
Root cause: The script parameter [ValidateRange(1, 540)][int]$DispatcherBudgetSeconds and top-level $script:DispatcherBudgetSeconds are the same validated PowerShell variable. Clamping valid caller input 420 against an already-expired absolute deadline assigns 0 to that variable, triggering validation before explicit budget-exhaustion reporting can run. Extracted helper tests did not exercise this entrypoint initialization.
Correction:
Store the clamped runtime allowance in the distinct EffectiveDispatcherBudgetSeconds variable and update remaining-budget helpers and their extracted-test state consistently. Caller budget 0 remains invalid.
Fail startup explicitly with [dispatcher-budget-exhausted] when preparation has consumed the deadline, before PR discovery, authentication, HTTP, or sleep. Write a failed preparation/deadline job summary and state No queue POST was attempted. This also fails rather than claiming successful no-work reconciliation when the deadline is expired.
Limit trusted checkout to the standalone /.github/scripts/Queue-CiFixAzdoValidation.ps1 using non-cone sparse checkout. The existing SHA-pinned checkout v7.0.1 supports exact patterns and automatically uses blob:none for sparse fetches. Preserve github.sha, fetch-depth: 1, and persist-credentials: false; never fetch or execute PR code.
Document preparation behavior and limitations. Keep the absolute pre-checkout 420-second deadline and ten-minute hard job timeout unchanged; do not restart or extend either allowance.
Validation: Baseline dispatcher suite: 73 passed. Before the script correction, the six new actual-entrypoint cases produced four expected expired-deadline failures with the original validation exception and two passing caller-validation/future-deadline cases. After correction, all 79 tests passed, including existing helper/queue regressions. Expired cases assert the preparation summary, explicit prefix, no-POST message, and zero HTTP/sleep calls; a native PowerShell process asserts nonzero exit. The valid future deadline still produces the three verified offline pipeline payloads.
Limits: The sparse-checkout assertion is a static configuration/trust regression, not a hosted checkout timing measurement. Production checkout performance remains unproven; checkout or PowerShell startup exceeding the ten-minute hard guard can still cancel the job before a summary is written. No live Azure queue requests, manual workflow dispatches/reruns, /azp requests, or credential/permission/model-policy changes were performed. There is still no successful eligible-PR Azure canary evidence here; this PR does not establish Azure permissions or exact-head check linkage for any of the three pipelines.
Related producer blocker (pre-existing, not introduced by #39147):main producer run 37464881821 and net11 producer run 37465231994 concluded success but emitted missing_tool / report_incomplete. The net11 diagnostic explicitly says mandatory expectation registration requires PowerShell but the run instructions exclude it. The main diagnostic likewise reports the prompt-specific no-pwsh restriction, alongside separate unavailable cited Azure timeline evidence. This is an upstream producer blocker: a compliant PR cannot reach dispatcher validation if required registration is prohibited by its own prompt.
Both producers already allow pwsh in tools.bash, and Hard Rule 11 requires Register-CiFixSafeOutputExpectation.ps1 or atomic validation/registration via Test-CiFixTransport.ps1. Their bottom Environment constraints sections nevertheless said no pwsh. The mirrored correction changes only that prose: explicitly identify pwsh availability for those deterministic helpers, retain no gh / no python and curl + jq API guidance, and reiterate existing fail-closed registration/transport requirements. No tool allowlists, network, permissions, credentials, trust, model policy, or output gates change.
Added two assertions in the existing registration test suite protecting both producer twins. Both failed on the old contradictory guidance and pass after correction. Regenerated both locks with retained gh-aw v0.86.2, without manual edits or compiler upgrade; only body_hash changes. Frontmatter and all generated lock runtime content remain identical.
/Users/shneuvil/.copilot/session-state/237fbb01-6532-4170-9f5e-6af14fa3a5e0/files/tools/gh-aw-0.86.2/darwin-arm64 compile ci-status-fix ci-status-fix-net11 --strict --no-emit --no-check-update
# Passed: 2 workflows, 0 warnings.
/Users/shneuvil/.copilot/session-state/237fbb01-6532-4170-9f5e-6af14fa3a5e0/files/tools/gh-aw-0.86.2/darwin-arm64 compile ci-status-fix ci-status-fix-net11 --strict --no-check-update
# Passed: 2 workflows, 0 warnings; emitted body-hash-only changes.
actionlint .github/workflows/ci-status-fix.lock.yml .github/workflows/ci-status-fix-net11.lock.yml
# Nonzero both before and after regeneration: identical six baseline diagnostics.# Each twin: concurrency.queue not recognized, ShellCheck SC2129 style, github.aw expression not recognized.# No new lint findings; baseline/after outputs compared byte-identical.
Producer limits: These are static prompt/configuration assertions and offline helper tests, not a hosted agent behavior evaluation. Removing the contradiction does not guarantee that an agent will register correctly, find a viable product fix, create a PR, or attach Azure checks. Separate cited-timeline failures and other producer blockers are not fixed here. No live workflow or network validation tests were run.
Issues Fixed
Follow-up to #39147 for the production startup regression evidenced by the two linked dispatcher runs, plus the separate pre-existing producer helper-guidance contradiction evidenced by the two producer runs. No separate tracking issue is closed by this PR.
Separate the validated caller budget from effective remaining time and report expired preparation deadlines before discovery or authentication. Sparse-check out only the trusted standalone dispatcher script without changing the absolute deadline or hard job timeout.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1e0cc90a-a521-4055-9e7a-9565cdaf5504
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.
The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.
Remove the prose contradiction that excludes an already allowed pwsh command required for deterministic safe-output registration and transport checks. Preserve tool and policy configuration, cover both producer prompts, and regenerate body hashes using gh-aw v0.86.2.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1e0cc90a-a521-4055-9e7a-9565cdaf5504
PureWeen
changed the title
CI-fix dispatcher: Handle deadline exhaustion during startup
CI-fix automation: Fix startup deadlines and producer helper guidance
Oct 6, 2026
The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.
With a CRLF checkout (for example, Windows with core.autocrlf=true), this assertion fails even when the workflow is correct. Get-Content -Raw preserves the \r after false, but .NET's multiline $ anchor matches before \n, not before \r\n. The repository's .gitattributes does not force workflow files to LF. Allow \r? before the final $, matching the preceding lines' handling of line endings.
Accept the optional carriage return before the final multiline anchor and exercise the trusted sparse-checkout assertion with both LF and CRLF input. Reproduces and addresses top-level Copilot review 5432776264 without changing runtime behavior.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1e0cc90a-a521-4055-9e7a-9565cdaf5504
The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.
@PureWeen — new AI review results are available based on commit ddc5d50.
🗂️ Review Sessions — click to expand 🚦 Gate — Test Before & After Fix
Gate Result: ⚠️ SKIPPED
No tests were detected in this PR.
Recommendation: Add tests to verify the fix using the write-tests-agent.
📋 Pre-Flight — Context & Validation
⚠️Pre-Flight did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🔬 Code Review — Deep Analysis
⚠️Code Review did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🛠️ Try-Fix — Analysis & Comparison
⚠️Try-Fix did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🏁 Report — Final Recommendation
⚠️Report / Final Recommendation did not produce output on this run.
The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.
Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.
🧭 Next Steps — review latest findings
No alternative fix was selected for this run. Review the session findings and CI results before merging.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note
Are you waiting for the changes in this PR to be merged?
It would be very helpful if you could test the resulting artifacts from this PR and let us know in a comment if this change resolves your issue. Thank you!
Description of Change
Fix a confirmed startup-deadline regression in the CI-fix Azure DevOps dispatcher introduced by #39147, and correct a separate, pre-existing producer prompt contradiction that blocks mandatory safe-output registration.
Production evidence: run 37477952193 spent approximately 533 seconds between starting the 420-second deadline and completing trusted checkout; run 37485076087 spent approximately 494 seconds. Both then failed with
The variable cannot be validated because the value 0 is not a valid value for the DispatcherBudgetSeconds variable.Root cause: The script parameter
[ValidateRange(1, 540)][int]$DispatcherBudgetSecondsand top-level$script:DispatcherBudgetSecondsare the same validated PowerShell variable. Clamping valid caller input420against an already-expired absolute deadline assigns0to that variable, triggering validation before explicit budget-exhaustion reporting can run. Extracted helper tests did not exercise this entrypoint initialization.Correction:
EffectiveDispatcherBudgetSecondsvariable and update remaining-budget helpers and their extracted-test state consistently. Caller budget0remains invalid.[dispatcher-budget-exhausted]when preparation has consumed the deadline, before PR discovery, authentication, HTTP, or sleep. Write a failed preparation/deadline job summary and stateNo queue POST was attempted.This also fails rather than claiming successful no-work reconciliation when the deadline is expired./.github/scripts/Queue-CiFixAzdoValidation.ps1using non-cone sparse checkout. The existing SHA-pinned checkout v7.0.1 supports exact patterns and automatically usesblob:nonefor sparse fetches. Preservegithub.sha,fetch-depth: 1, andpersist-credentials: false; never fetch or execute PR code.Validation: Baseline dispatcher suite: 73 passed. Before the script correction, the six new actual-entrypoint cases produced four expected expired-deadline failures with the original validation exception and two passing caller-validation/future-deadline cases. After correction, all 79 tests passed, including existing helper/queue regressions. Expired cases assert the preparation summary, explicit prefix, no-POST message, and zero HTTP/sleep calls; a native PowerShell process asserts nonzero exit. The valid future deadline still produces the three verified offline pipeline payloads.
Exact final commands and results:
Limits: The sparse-checkout assertion is a static configuration/trust regression, not a hosted checkout timing measurement. Production checkout performance remains unproven; checkout or PowerShell startup exceeding the ten-minute hard guard can still cancel the job before a summary is written. No live Azure queue requests, manual workflow dispatches/reruns,
/azprequests, or credential/permission/model-policy changes were performed. There is still no successful eligible-PR Azure canary evidence here; this PR does not establish Azure permissions or exact-head check linkage for any of the three pipelines.Related producer blocker (pre-existing, not introduced by #39147): main producer run 37464881821 and net11 producer run 37465231994 concluded success but emitted
missing_tool/report_incomplete. The net11 diagnostic explicitly says mandatory expectation registration requires PowerShell but the run instructions exclude it. The main diagnostic likewise reports the prompt-specificno-pwshrestriction, alongside separate unavailable cited Azure timeline evidence. This is an upstream producer blocker: a compliant PR cannot reach dispatcher validation if required registration is prohibited by its own prompt.Both producers already allow
pwshintools.bash, and Hard Rule 11 requiresRegister-CiFixSafeOutputExpectation.ps1or atomic validation/registration viaTest-CiFixTransport.ps1. Their bottom Environment constraints sections nevertheless saidno pwsh. The mirrored correction changes only that prose: explicitly identifypwshavailability for those deterministic helpers, retainno gh/no pythonandcurl+jqAPI guidance, and reiterate existing fail-closed registration/transport requirements. No tool allowlists, network, permissions, credentials, trust, model policy, or output gates change.Added two assertions in the existing registration test suite protecting both producer twins. Both failed on the old contradictory guidance and pass after correction. Regenerated both locks with retained gh-aw v0.86.2, without manual edits or compiler upgrade; only
body_hashchanges. Frontmatter and all generated lock runtime content remain identical.Additional exact validation commands and results:
Producer limits: These are static prompt/configuration assertions and offline helper tests, not a hosted agent behavior evaluation. Removing the contradiction does not guarantee that an agent will register correctly, find a viable product fix, create a PR, or attach Azure checks. Separate cited-timeline failures and other producer blockers are not fixed here. No live workflow or network validation tests were run.
Issues Fixed
Follow-up to #39147 for the production startup regression evidenced by the two linked dispatcher runs, plus the separate pre-existing producer helper-guidance contradiction evidenced by the two producer runs. No separate tracking issue is closed by this PR.