[safe-output-health] Safe Output Health Report - 2026-10-01 #64689
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-02T04:54:53.494Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
🏥 Safe Output Health Report - 2026-10-01
Executive Summary
Caveat on cadence: there is an 8-day gap since the last audit (2026-09-23 → 2026-10-01), so no day-over-day trend is available — only a comparison against that prior data point.
Safe Output Job Statistics
Error Clusters
Cluster 1 (NEW, DOMINANT):
set_issue_typesilently fails while every sibling item succeedsCount: 10 occurrences (91% of today's failures)
Affected workflows: Smoke Copilot, Smoke Copilot - AOAI (apikey), Smoke Copilot - AOAI (Entra) — all 3 engine variants of the Smoke Copilot family
Affected runs: 36745551409, 36745556440, 36745561562 (16:37Z, commit
bc0233b0), 36762114132, 36762134104 (18:56Z, commitf19087b6), 36795117785, 36797299158 (00:13–00:39Z, main branch, scheduled trigger, commit856e7fa3), 36812740323, 36812743202, 36812746071 (03:55Z, commite4da7f04)Sample evidence (run 36812746071, Smoke Copilot - AOAI (Entra)):
Root cause:
set_issue_typeis invoked by the agent in every single occurrence (visible inusage/activity/summary.json→gateway.tool_calls), but never produces an entry in the same file'ssafe_outputs.items/items_by_type, while every other configured safe-output type in the same batch (add_comment,create_issue,send_slack_message,add_labels,remove_labels,create_check_run,comment_memory) succeeds and shows a real URL/number. This reproduced identically across:copilot/fix-agentic-conversation-session-state, workflow_dispatch-triggered), andscheduletrigger (commit856e7fa3)This rules out a branch-specific or trigger-specific explanation — it is a genuine, reproducible code-level defect in the
set_issue_typesafe-output handler itself. It is also not consistently correlated with the separateclients2.google.comfirewall block noted in some of these runs (present in only ~4 of the 10 occurrences), so that network block is circumstantial, not causal.Impact: This is the single most consistent, 100%-reproducible signature in this monitor's entire history (10/10 checked occurrences share the exact shape) and is the direct cause of today's record-low success rate. No credential ambiguity, no policy-decline miscategorization, no "which item failed" evidence gap — just a clean, structural, repeatable bug.
Evidence gap: raw
safe-output-errors.json/ per-item error/stack-trace text was not retrievable this audit — anagenticworkflows auditcall withartifacts: ["all"]against run 36812746071 returned only the same structuredrun_summary.jsonshape, no raw console text. This is the same intermittent raw-log-retrieval gap flagged in several prior audits (tracked separately below).Cluster 2 (recurring, already tracked): Smoke Project
update_project/create_project_status_update— Bad credentialsupdate_project×6,create_project_status_update×1 — 100% of the run's 7 safe-output items failedsmoke-project-update-project-bad-credentialspattern (first seen 2026-08-31). The token used by the Copilot-engine "Smoke Project" workflow continues to be rejected for GraphQL project-management mutations againstgithub/projects/24068.Root Cause Analysis
Code/Logic Issues
The
set_issue_typecluster above is a genuine, high-confidence, actionable bug — not a false positive or policy decline like most of this monitor's historically-tracked clusters. It warrants immediate engineering attention.Permission/Credential Issues
Smoke Project's
update_project/create_project_status_update401 "Bad credentials" issue persists unresolved after 4 occurrences spanning a month (first seen 2026-08-31).Notable Absence
Zero occurrences today of the previously-dominant
PR Sous Chef/approve_workflow_runpattern (13+ prior occurrences across the monitor's history) — no evidence this was fixed, simply no PRs today triggered the relevant protected-files/fork-PR conditions.Observability Gap (carried forward)
Raw per-item error text (
safe-output-errors.json) was again not retrievable viaagenticworkflows audit/logswithartifacts: ["all"]— this is now a recurring, ~50%-of-audits limitation that forces root-causing via structural cross-referencing (tool-call vs. result-array diffing) rather than direct error messages. See the carried-forward recommendation below.Recommendations
Critical Issues (Immediate Action Required)
set_issue_typesilent failure in the safe_outputs handlerset_issue_typesafe-output tool is invoked but never returns/records a result, in 10/10 checked occurrences across 3 workflow variants, 4 distinct commits, bothworkflow_dispatchandscheduletriggers.set_issue_typeruntime handler (compiler-side config inpkg/workflow/set_issue_type.go; runtime execution happens in the safe-outputs processing script invoked during the "Process Safe Outputs" step). Check for an unhandled exception in the issue-type GraphQL mutation (e.g., referencing an issue type name/ID that doesn't resolve in this repo), a recent regression, or a permissions gap specific to that mutation. Also consider makingset_issue_typesoft-skip-on-failure (consistent with howadd_comment's no-context case already soft-skips) so one failing item doesn't flip an otherwise-healthy batch to a hard job failure.Bug Fixes Required
set_issue_typehandler — no result producedpkg/workflow/set_issue_type.go(compiler/config side) and its runtime safe-outputs processing counterpartsafe_outputs.items, with job-level "Process Safe Outputs" step concludingfailuresafe-output-errors.json; fix the underlying mutation/call so it succeeds or gracefully declinesProcess Improvements
agenticworkflows audit/logswithartifacts: ["all"]intermittently fails to retrievesafe-output-errors.json/raw console text even when the targeted run and job are correctly specified (recurred again today against run 36812746071).Work Item Plans
Work Item 1: Fix
set_issue_typesafe-output handler silent failureset_issue_typefails to produce a result in 100% of 10 occurrences today across 3 Smoke Copilot workflow variants, both on an in-development branch and on main, while every sibling safe-output item in the same batch succeeds. This is driving the safe_outputs job failure rate to a monitor-record low.set_issue_typeidentified (handler exception, GraphQL mutation failure, or permissions gap)set_issue_typeeither succeeds or fails with a clear, logged error insafe-output-errors.jsonset_issue_typefailure no longer hard-fails the whole safe_outputs job when sibling items succeed (soft-skip or isolated failure reporting)Work Item 2: Investigate Smoke Project "Bad credentials" (carried forward)
update_project/create_project_status_updatecontinue to fail with GraphQL 401 "Bad credentials" againstgithub/projects/24068for the Copilot-engine "Smoke Project" workflow.projectscope, or not passed through correctly for this engine/runtime combinationupdate_projectrun if one exists; check secret/token configuration for this workflowHistorical Context
Comparing against the last available data point (2026-09-23, since there is an 8-day audit gap):
Trends
set_issue_typesilent failure (brand new, 10 occurrences) — not a previously-tracked signature.add_labelspattern, PR Sous Chefresolve_pull_request_review_thread/dismiss_pull_request_reviewpattern, the long-dominant PR Sous Chefapprove_workflow_runpattern — none recurred today, though absence of PRs touching the relevant conditions is a more likely explanation than an actual fix for most of these.Metrics and KPIs
set_issue_typeand Smoke Project'supdate_project/create_project_status_updatesucceeded today (e.g.,add_comment,create_issue,send_slack_message,add_labels,remove_labels,create_check_run,comment_memoryall had 100% success in the runs examined)set_issue_type(0% success in every occurrence it was invoked today)Next Steps
set_issue_typehandler — this is the highest-confidence, highest-impact, most actionable finding in this monitor's history to dateset_issue_typerecurs at the same 100% rate or is fixedagenticworkflows audit/logsto improve future root-causing speedAll reactions