Skip to content

docs: add runner doctor failure mode D6 — Docker sbx microVM runtime#6262

Merged
lpcox merged 6 commits into
mainfrom
copilot/update-runner-doctor-failure-mode-d6
Jul 15, 2026
Merged

docs: add runner doctor failure mode D6 — Docker sbx microVM runtime#6262
lpcox merged 6 commits into
mainfrom
copilot/update-runner-doctor-failure-mode-d6

Conversation

Copilot AI commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Adds failure mode D6 to the runner doctor knowledge base, covering the --container-runtime sbx case introduced in #6101 where sbx CLI absence causes AWF to abort before the agent starts.

Changes

  • shared/self-hosted-failure-modes.md — Appends D6 row to Category D and a quick-lookup entry mapping Error: sbx is not available / spawn sbx ENOENT → D6
  • .github/agents/self-hosted-runner-doctor.md — Mirrors the same D6 row (condensed portable-agent variant) and quick-lookup entry; this file embeds the full catalog for portable agent use

self-hosted-runner-doctor.md requires no changes — it uses imports: shared/self-hosted-failure-modes.md and picks up D6 automatically.

Copilot AI changed the title [WIP] Update Runner Doctor failure mode D6 for Docker sbx microVM runtime docs: add runner doctor failure mode D6 — Docker sbx microVM runtime Jul 15, 2026
Copilot finished work on behalf of lpcox July 15, 2026 15:49
Copilot AI requested a review from lpcox July 15, 2026 15:49
@lpcox
lpcox marked this pull request as ready for review July 15, 2026 15:52
Copilot AI review requested due to automatic review settings July 15, 2026 15:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds runner-doctor guidance for diagnosing missing Docker sbx CLI failures.

Changes:

  • Adds D6 and a quick-lookup entry.
  • Mirrors the guidance in the portable agent catalog.
Show a summary per file
File Description
.github/workflows/shared/self-hosted-failure-modes.md Adds shared D6 diagnostics.
.github/agents/self-hosted-runner-doctor.md Mirrors D6 for portable use.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 2/2 changed files
  • Comments generated: 4
  • Review effort level: Medium

Comment thread .github/workflows/shared/self-hosted-failure-modes.md Outdated
Comment thread .github/workflows/shared/self-hosted-failure-modes.md Outdated
Comment thread .github/agents/self-hosted-runner-doctor.md Outdated
Comment thread .github/agents/self-hosted-runner-doctor.md Outdated
lpcox and others added 2 commits July 15, 2026 10:01
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

lpcox and others added 2 commits July 15, 2026 10:02
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation...

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Smoke Claude passed

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Contribution Check completed successfully!

PR #6262 follows the applicable CONTRIBUTING.md guidelines: it is a focused documentation/knowledge-base update, uses appropriate repository locations, includes a clear description with related issue references, and does not introduce new functionality requiring tests or additional documentation.

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Smoke Gemini completed. All facets verified. 💎

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

🔑 Smoke Copilot PAT PAT auth validated. All systems operational. ✅

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

🐳🔮 Smoke Docker Sbx Codex completed. Docker sbx + Codex smoke test passed. ✅

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

🐳🏗️ Smoke Docker Sbx Build Test completed. Docker sbx build test passed. ✅

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results

Test Status
GitHub MCP Connectivity
GitHub.com HTTP ⚠️ (template vars unresolved)
File Write/Read ⚠️ (template vars unresolved)

Overall: PARTIAL — MCP reachable; pre-step outputs were not substituted before agent invocation (workflow config issue). Author: @lpcox

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

Check Result
API Status ✅ PASS
GH Check ✅ PASS
File Status ✅ PASS

Overall Result: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Generated by Smoke Claude for #6262 · 35 AIC · ⊞ 3.3K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) ✅ PASS

Test Result
GitHub MCP connectivity
GitHub.com connectivity
File write/read
BYOK inference (agent → api-proxy → api.githubcopilot.com)

Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com

Overall: PASS@lpcox

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: API Proxy OpenTelemetry Tracing

Scenario Result Notes
Module Loading otel.js loads successfully; exports: startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled
Test Suite 39 passed, 0 failed (otel.test.js)
Env Var Forwarding api-proxy-env-config.test.ts confirms all 6 OTEL vars forwarded (GH_AW_OTLP_ENDPOINTS, OTEL_EXPORTER_OTLP_ENDPOINT, OTEL_EXPORTER_OTLP_HEADERS, GITHUB_AW_OTEL_TRACE_ID, GITHUB_AW_OTEL_PARENT_SPAN_ID, OTEL_SERVICE_NAME)
Token Tracker Integration onUsage callback exists in token-tracker-http.js (line 343) as OTEL hook point
OTEL Diagnostics No OTLP endpoint configured in this run; file-based fallback (/var/log/api-proxy/otel.jsonl) active — graceful degradation working

All 5 scenarios pass. OTEL tracing integration is fully operational.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions github-actions Bot mentioned this pull request Jul 15, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🦎 gVisor Smoke Test Results

  • 🦎 gVisor runtime: unconfirmed (runc detected, gVisor plumbing not yet wired)
  • ✅ GitHub.com connectivity: HTTP 200
  • ✅ Network isolation: example.com blocked (timeout)
  • ⚠️ Pre-step data: workflow template vars not expanded

Overall: PASS (best-effort)

@lpcox

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • example.com
  • host.docker.internal

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"
    - "host.docker.internal"

See Network Configuration for more information.

🦎 gVisor smoke test by Smoke gVisor
Add label test-gvisor to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot PAT Auth

Test Result
GitHub MCP connectivity
GitHub.com HTTP ⚠️ pre-step data unavailable
File write/read ⚠️ pre-step data unavailable

Overall: INDETERMINATE — template vars not substituted in prompt.

Auth mode: PAT (COPILOT_GITHUB_TOKEN) | Author: @lpcox

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

🔑 PAT report filed by Smoke Copilot PAT
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results

❌ Redis (PING): Network is unreachable
❌ PostgreSQL pg_isready: no response
❌ PostgreSQL SELECT 1: Network is unreachable

Overall: FAILhost.docker.internal (172.17.0.1) is unreachable. Service containers do not appear to be running or accessible.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: gVisor + Claude

🦎🟣 gVisor + Claude runtime: unconfirmed (kernel reports Linux 4.4.0, no gVisor signature)

  • ❌ gVisor runtime verification (no gVisor in /proc/version)
  • ✅ GitHub.com connectivity (HTTP 200)
  • ✅ File write/read test
  • ✅ Network isolation (example.com blocked)
  • ⚠️ GitHub MCP test (tool unavailable in this run)

Overall: FAIL (runtime unconfirmed)

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • example.com
  • host.docker.internal

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"
    - "host.docker.internal"

See Network Configuration for more information.

🦎🟣 gVisor + Claude smoke test by Smoke gVisor Claude
Add label test-gvisor-claude to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results (Gemini)

Overall Status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

💎 Faceted by Smoke Gemini
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results

Test Status
GitHub MCP connectivity ✅ (connected, results filtered by secrecy policy)
GitHub.com HTTP ⚠️ pre-step data unavailable (template vars unexpanded)
File write/read ⚠️ pre-step data unavailable (template vars unexpanded)

Overall: PARTIAL — MCP connectivity confirmed; pre-computed step outputs were not passed to agent (unexpanded ${{ }} expressions).

📰 BREAKING: Report filed by Smoke Docker Sbx
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Chroot Version Comparison Results

Runtime Host Version Chroot Version Match?
Python Python 3.12.13 Python 3.12.3 ❌ NO
Node.js v24.18.0 v22.23.1 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

⚠️ Not all tests passed — smoke-chroot label was not applied.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🦎🔮 gVisor + Codex runtime: unconfirmed
✅ file write/read verified
❌ GitHub.com connectivity (000)
❌ GitHub MCP PR-list check unavailable
✅ example.com blocked
Overall: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • 172.30.0.1

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "172.30.0.1"

See Network Configuration for more information.

🦎🔮 gVisor + Codex smoke test by Smoke gVisor Codex
Add label test-gvisor-codex to run again

@github-actions

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia 1/1 passed ✅ PASS
Bun hono 1/1 passed ✅ PASS
C++ fmt N/A ✅ PASS
C++ json N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world N/A ✅ PASS
.NET json-parse N/A ✅ PASS
Go color 1/1 passed ✅ PASS
Go env 1/1 passed ✅ PASS
Go uuid 1/1 passed ✅ PASS
Java gson 1/1 passed ✅ PASS
Java caffeine 1/1 passed ✅ PASS
Node.js clsx all passed ✅ PASS
Node.js execa all passed ✅ PASS
Node.js p-limit all passed ✅ PASS
Rust fd 1/1 passed ✅ PASS
Rust zoxide 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — ✅ PASS

Note (Java): The default ~/.m2 directory was root-owned (no sudo available), so Maven was run with -Dmaven.repo.local=/tmp/gh-aw/agent/m2-repo to use a writable local repository. All tests passed successfully.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "awmgmcpg"

See Network Configuration for more information.

Generated by Build Test Suite for #6262 · 34.3 AIC · ⊞ 6.9K ·
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🐳🟣 Docker sbx + Claude

  • ✅ GitHub MCP connectivity (list PRs)
  • ✅ GitHub.com reachable (HTTP 200)
  • ✅ File write/read
  • ❌ Network isolation — example.com (not allowlisted) returned HTTP 200 instead of being blocked

Overall: FAIL

🐳🟣 Docker sbx + Claude smoke test by Smoke Docker Sbx Claude
Add label test-docker-sbx-claude to run again

@github-actions

Copy link
Copy Markdown
Contributor

🐳🏗️ Docker Sbx Build Test Results

Test Status
GitHub.com connectivity
Node.js build (npm ci && npm run build)
Node.js tests (Jest subset)
Go build (color, uuid)
Go tests (color, uuid)
Network isolation

Overall: FAIL

🐳🏗️ Docker sbx build test by Smoke Docker Sbx Build Test
Add label test-docker-sbx-build to run again

@github-actions

Copy link
Copy Markdown
Contributor

🐳🔮 Docker sbx + Codex
✅ GitHub.com connectivity
✅ File write/read
❌ PR lookup / blocked-domain verification
Overall: FAIL

🐳🔮 Docker sbx + Codex smoke test by Smoke Docker Sbx Codex
Add label test-docker-sbx-codex to run again

@lpcox
lpcox merged commit afb6ad4 into main Jul 15, 2026
130 of 135 checks passed
@lpcox
lpcox deleted the copilot/update-runner-doctor-failure-mode-d6 branch July 15, 2026 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🩺 Runner Doctor Updatenew failure mode D6 — Docker sbx microVM runtime (--container-runtime sbx)

3 participants