[safe-output-health] Safe Output Health Monitor - Daily Report 2026-09-25 #63353
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-09-26T05:07:56.277Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive Summary
Daily safe-output health audit for 2026-09-25 (~24h window). Scope: safe_outputs job executions only (create_discussion, create_issue, add_comment, update_project, submit_pull_request_review, resolve_pull_request_review_thread, approve_workflow_run, etc.) — agent/detection/activation job failures are out of scope for this monitor.
Safe Output Job Statistics
Error Clusters
Cluster A — "No PR context" decline miscategorized as hard failure (2 of 3 failures, 66%)
submit_pull_request_review: "Target is "triggering" but not running in pull request context, skipping PR review" (3rd occurrence: 2026-08-29, 2026-08-31, 2026-09-25)resolve_pull_request_review_threadx8: "Cannot resolve review threads outside of a pull request context" (3rd occurrence: 2026-09-23 x2, 2026-09-25; root cause confirmed today via direct raw error text, previously only hypothesized as a stale-reference race)Both runs otherwise succeeded on their remaining 8-9 safe-output items — job-level "failure" despite high per-item success, reconfirming that per-item success counts alone don't guarantee job success.
Cluster B — Credential/permission bug, genuine and unresolved (1 of 3 failures, 33%)
update_projectx2: "Bad credentials - https://docs.github.com/rest" (4th occurrence over nearly a month: 2026-08-31, 2026-09-05, 2026-09-23, 2026-09-25)Root Cause Analysis
Cluster A: no-PR-context decline bug class (click to expand)
Two distinct safe-output tools —
submit_pull_request_review(target:triggering) andresolve_pull_request_review_thread— both fail with an E099 hard error when a workflow run is not itself PR-triggered (e.g. a scheduled smoke-test run). The tools correctly detect there is no PR to act on, but instead of soft-skipping the wayadd_commentalready does under the analogous "no context" condition, they surface the decline through the same hard-failure path used for genuine bugs.This was previously tracked as two separate, tool-specific investigations. As of today, the
resolve_pull_request_review_threadroot cause is directly confirmed (not just structurally inferred), and its error text and mechanism are functionally identical to the already-confirmedsubmit_pull_request_reviewcase. These are now treated as one shared bug class requiring a single fix in the shared no-context-detection path used by all PR-scoped safe-output tools.This is structurally similar to (but distinct from) an already-tracked sibling family: protected-files/allowed-files declines on
approve_workflow_runandpush_to_pull_request_branchbeing miscategorized as hard failures. Together, these two "policy decline miscategorized as failure" families likely account for the majority of all safe_outputs failures tracked across this audit's history since 2026-08-22.Cluster B: Smoke Project "Bad credentials" (click to expand)
update_projectfails with a GraphQL 401 "Bad credentials" error against the target GitHub Project board. This is distinct from the more common "Resource not accessible by personal access token" (scope-limited) errors seen elsewhere — "Bad credentials" suggests an invalid or missing token rather than an under-scoped one. All 4 occurrences to date have been on the Copilot engine; engine-specificity remains untested (no comparison run on a different engine has recurred yet) but the credential problem itself is no longer in doubt after 4 occurrences spanning nearly a month.Recommendations
Critical
Bug Fixes
submit_pull_request_review,resolve_pull_request_review_thread,dismiss_pull_request_review, and any other PR-scoped safe-output tool with the same precondition, in the shared context-detection code path (not patched per-tool). This single fix would have prevented 2 of today's 3 failures and at least 6 confirmed occurrences since 2026-08-29.approve_workflow_run/push_to_pull_request_branchas soft skips rather than hard failures.Process
safe-output-errors.jsonretrieval is a positive signal against the historical ~50% average — worth confirming over the next several audits before declaring the underlying reliability issue resolved.Work Item Plans
projectscope; compare against a non-Copilot-engine run if one becomes available to test engine-specificity.add_comment's existing behavior) instead of raising when no PR context is available; apply uniformly rather than tool-by-tool to prevent future recurrences in yet-untested tools.Historical Context & Trends
Metrics & KPIs
Next Steps
References:
All reactions