Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 22 additions & 9 deletions .github/workflows/drafter.lock.yml

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions .github/workflows/drafter.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ engine:
id: claude
imports:
- shared/network.md
# just and the gh-aw CLI, for recompiling lock files
- shared/workflow-tools.md
tools:
bash: ["*"]
github:
Expand Down Expand Up @@ -151,6 +153,8 @@ implementation.
lockfiles before opening the pull request: run `just setup && just
compile` (this recompiles *all* workflows, not just the one you touched —
every `.lock.yml` must stay in sync with its `.md` source).
`just` and the pinned gh-aw CLI are already installed; the sandbox
can't install them itself.
6. Check if the originating issue #${{ github.event.issue.number }} has the
`agent/workflow-edits-allowed` label by reading its labels. If it does,
you must propagate this label to the pull request so that subsequent
Expand Down
31 changes: 22 additions & 9 deletions .github/workflows/fix.lock.yml

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions .github/workflows/fix.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,8 @@ engine:
id: claude
imports:
- shared/network.md
# just and the gh-aw CLI, for recompiling lock files
- shared/workflow-tools.md
tools:
bash: ["*"]
github:
Expand Down Expand Up @@ -214,6 +216,8 @@ manually: this workflow removes `agent/fixme` itself via `remove-labels`
workflows, not just the one you touched — every `.lock.yml` must stay in
sync with its `.md` source). Include the resulting `.lock.yml` changes in
your commit.
`just` and the pinned gh-aw CLI are already installed; the sandbox
can't install them itself.
8. Push your fix as a new commit on the same branch via the
`push-to-pull-request-branch` safe-output. Do not open a new PR.

Expand Down
24 changes: 24 additions & 0 deletions .github/workflows/shared/workflow-tools.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
---
description: just and the gh-aw CLI for recompiling lock files, installed before the agent starts
# Tools the drafter and fix agents need to recompile lock files
# (`just setup && just compile`). They're installed on the runner before the
# agent starts because the agent can't install them from inside the AWF
# sandbox: it has no GitHub token for `gh extension install`, and
# api.github.com isn't on its network allowlist. AWF exposes the host's
# binaries and $HOME (where gh keeps extensions) to the agent, so no custom
# runner or container image is needed. See
# https://github.github.com/gh-aw/reference/sandbox/#host-binaries
#
# The gh-aw runtime installs the CLI at the version that compiled the lock
# file, which ci.yml keeps equal to .github/aw/gh-aw-version.
runtimes:
gh-aw: {}
# Custom steps run outside the sandbox, after checkout; see
# https://github.github.com/gh-aw/reference/steps-jobs/
steps:
- name: Install just

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks right but followup cut over to ubuntu-26.04 plus https://github.com/bootc-dev/actions/tree/main/bootc-ubuntu-setup

run: |
set -euo pipefail
sudo apt-get update -q
sudo apt-get install -y -q just
---
9 changes: 6 additions & 3 deletions justfile
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,16 @@ setup:
#!/usr/bin/env bash
set -euo pipefail
wanted="{{ gh_aw_version }}"
if gh extension list 2>/dev/null | grep -q 'github/gh-aw'; then
installed=$(gh aw version 2>&1 | awk '{print $NF}')
# Ask gh-aw itself: `gh extension list` needs gh to be logged in, and it
# isn't in the agent sandbox, where the CLI is pre-installed (see
# .github/workflows/shared/workflow-tools.md).
if version=$(gh aw version 2>&1); then
installed=$(awk '{print $NF}' <<<"$version")
if [ "$installed" = "$wanted" ]; then
echo "gh-aw $wanted already installed."
exit 0
fi
echo "gh-aw installed at ${installed:-unknown}, re-pinning to $wanted..."
echo "gh-aw installed at $installed, re-pinning to $wanted..."
gh extension remove gh-aw
fi
gh extension install github/gh-aw --pin "$wanted"
Expand Down