Repository navigation
[safe-output-health] 🏥 Safe Output Health Report - 2026-10-06 #66015
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-07T04:47:44.094Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive Summary
/tmp/gh-aw/aw-mcp/logs, 309 run directories, 156 with asafe_outputsjob)safe_outputsjobsafe_outputsis a single consolidated job per run in this repo's compiled workflows — there are no separate per-type jobs likecreate_discussion/add_comment)Safe Output Job Statistics
This repository compiles all safe-output handling into a single
safe_outputsjob per run (it internally dispatches to whichever tool types —create_issue,add_comment,ledger_append,set_issue_type, etc. — the agent requested), rather than one job per output type. The table below reflects that architecture.safe_outputsError Clusters
Cluster 1:
ledger_appendschema validation failure (NEW)safe_outputs→ "Process Safe Outputs" step (also cascades intopush_ledger_changes→ "Reconcile and push ledger changes")mainbranch){"key":"37372003041","ledger":"caveman-run-history","operation":"upsert", "value":{"date":"2026-10-05","files_optimized":0,"files_processed":5, "planned_outcome":"noop","record_type":"caveman_run","run_id":"37372003041"}, "type":"ledger_append"}ledger_appenditem carries fields (date,files_optimized,files_processed,planned_outcome,record_type,run_id) that don't match the safe-outputs ledger handler's built-in transaction field schema, so the handler manager rejects the whole transaction.push_ledger_changesjob (nothing valid to reconcile). Distinct from the 2026-10-04 "ledger-reconciliation-empty-transaction-bug" cluster, which was about empty transactions — this one is about invalid fields in a non-empty transaction.Cluster 2:
target: "triggering"hard-fails outside its expected context (ROOT CAUSE CONFIRMED, GENERALIZES A KNOWN UNRESOLVED ISSUE)safe_outputs→ "Process Safe Outputs" step"triggering"hard-fails the entiresafe_outputsjob when the triggering event lacks the context that type needs —set_issue_typeneeds an issue, but this run was triggered from a PR comment (no issue context). This is the identical error shape already confirmed on 2026-08-31 forsubmit_pull_request_review(which needs PR context and hard-fails on non-PR triggers). The semantically identical no-context condition foradd_commentis instead correctly treated as a soft skip. This confirms the bug lives in the shared "triggering" target-resolution layer, not in any one tool's handler.set_issue_typewas one of the 5 failed items there;add_commentandhaiku_printerin that same cluster remain unexplained).Root Cause Analysis
Validation Issues
ledger_append's built-in schema mismatch (Cluster 1) is a straightforward data-shape bug: the workflow emits fields the handler doesn't recognize as valid.Logic / Design Issues
The
"triggering"target-resolution hard-fail (Cluster 2) is a design inconsistency: the processor has two different failure modes for "the agent asked for something that doesn't apply in this run's context" — a soft skip (used byadd_comment) and a hard job-failing error (used bysubmit_pull_request_reviewand now confirmed forset_issue_type). The inconsistency, not the no-context condition itself, is the bug.Other Issues
3
safe_outputsjobs were marked cancelled this period (Daily Ambient Context Optimizer, Copilot PR Prompt Pattern Analysis, Daily Project Performance Summary Generator) — all 3 belong to overall-failed runs and were almost certainly cancelled as a downstream consequence of an upstream agent/detection job failure, not a safe-outputs-specific bug. Out of scope for this monitor (agent/detection failures are tracked by other workflows) but noted for completeness. 4 jobs were skipped, all in overall-succeeded runs with nothing to process — expected, benign behavior.Recommendations
Bug Fixes Required
Soft-skip
"triggering"targets outside their expected context, at the shared resolution layertarget: "triggering"(shared across tool handlers — exact file not retrievable from this audit's log bundle, but the fix point is the one place that resolves"triggering"to an issue/PR number before dispatch)set_issue_type, PR forsubmit_pull_request_review), the processor raises a job-failing error (E099/##[error]) instead of a soft skip."triggering"targets a soft skip/no-op for that single item, matchingadd_comment's existing correct behavior, across all tool types that supporttarget: "triggering".set_issue_type,submit_pull_request_reviewconfirmed;add_comment/create_pull_request_review_comment/haiku_printerfailures in the 2026-09-23 Smoke Copilot cluster remain unexplained and should be re-checked against this same pattern.Fix or allow-list Daily Caveman Optimizer's
ledger_appendfieldsledger_appendprompt/config) and/or the safe-outputs ledger handler's built-in transaction field schema{date, files_optimized, files_processed, planned_outcome, record_type, run_id}, none of which the handler's built-in schema accepts.safe_outputsandpush_ledger_changesjobs.Process Improvements
failure_kindfields.agenticworkflows logswith{"workflow_name": "<slug>", "start_date": ..., "end_date": ..., "artifacts": ["all"]}successfully retrievedsafe-output-errors.json(with exact error text and the rejected payload) for both failures. Continue using this exact invocation shape (slug-formworkflow_name, narrow date range,artifacts: ["all"]) as the default first move for any future failure investigation, before falling back to grader-inferred fields.Work Item Plans
Work Item 1: Soft-skip no-context
"triggering"targets in the safe-outputs processoradd_commentno-context handling to all tool types that accepttarget: "triggering", so a context mismatch (no issue / no PR) produces a soft skip for that one item instead of failing the wholesafe_outputsjob.set_issue_typewithtarget: "triggering"and no issue context produces a skipped/no-op result, not a job failuresubmit_pull_request_reviewwithtarget: "triggering"and no PR context produces a skipped/no-op result, not a job failure"triggering"and change its error path to a soft-skip path, reusing whatever mechanism already makesadd_commentbehave correctly.Work Item 2: Fix Daily Caveman Optimizer's
ledger_appendschema mismatchledger_appendfields with the ledger handler's built-in transaction schema (or extend the schema).ledger_appenditem passes handler validationpush_ledger_changes's "Reconcile and push ledger changes" step succeeds in the same runledger_appendprompt/config against the handler's accepted built-in field list; adjust whichever side is wrong.Historical Context
Trends
approve_workflow_runprotected-files decline,push_to_pull_request_branchallowed-files decline,submit_pull_request_reviewno-PR-context, and nowset_issue_typeno-issue-context), reinforcing that this is a systemic classification problem in the safe-outputs processor, not isolated per-tool bugs.approve_workflow_run, Design Decision Gate allowed-files decline, Smoke Issues jira/linear credentials, Smoke Projectupdate_projectbad credentials, Auto-Triage Issuesadd_labels, same-PR concurrency race) recurred in this window — all previously-flagged workflows ran clean today.Metrics and KPIs
safe_outputsjob per run in this repo's architectureledger_append(Daily Caveman Optimizer) andset_issue_type(Smoke Copilot), one failure eachNext Steps
"triggering"target no-context hard-fail (Work Item 1)ledger_appendschema mismatch (Work Item 2)add_commentandhaiku_printer's still-unexplained failures from the 2026-09-23 Smoke Copilot cluster against the newly-confirmed"triggering"pattern, in case they share the same root causeAll reactions