Skip to content

org-history: Omit unset bot and repositoryFilter from snapshots - #121

Draft
bootc-bot[bot] wants to merge 1 commit into
mainfrom
agent/org-history-omit-null-header-afb2f1e8bf2d2eb1
Draft

bootc-bot[bot] wants to merge 1 commit into
mainfrom
agent/org-history-omit-null-header-afb2f1e8bf2d2eb1

Conversation

@bootc-bot

@bootc-bot bootc-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Addresses #118 ("fix the generator to omit null if not present").

workflowRuns records already drop unset values in scripts/org-history.js (workflowRunRecord → sparseProperties, with a unit test and a README note). The one place the generator still wrote null for something missing was the snapshot header: bot: null and repositoryFilter: null whenever --bot / --repo was not passed.

This PR builds the header through sparseProperties() as well, using a small exported snapshotHeader() helper so it can be unit-tested without gh. Key order is unchanged when the options are set.

Not changed, on purpose:

  • coverage.aic.total stays an explicit null. There it means "not every eligible run has a known AIC value", and the CI snapshot-schema check asserts the key is present.
  • The committed history/2026-38.json / 2026-39.json still contain the old null fields. They were written by an older generator, and the history-immutability CI job makes weekly history append-only, so they are left as they are. Future weekly snapshots will be sparse.

Validation

  • node --test tests/*.test.js: 17/17 pass, including a new test covering header output with and without bot / repositoryFilter.
  • node --check scripts/org-history.js
  • The CI live-snapshot step passes --repo and --bot, so its repositoryFilter assertion still holds.

Assisted-by: AI
The change and unit test are LLM generated; they need human review.

🤖 Generated with [Claude Code]((claude.com/redacted)

Generated by Drafter for #118 · claude · opus55 · 114 AIC · ⌖ 32.8 AIC · ⊞ 4.3K · ◷

workflowRuns records already drop unavailable properties via
sparseProperties(), but the snapshot header still serialized
`bot: null` and `repositoryFilter: null` whenever --bot or --repo
was not passed. Build the header through sparseProperties() too so
absent options are omitted rather than written as null.

coverage.aic.total keeps its explicit null, since there it means
"not every eligible run has a known value" and CI asserts the key.

Closes: #118
Assisted-by: AI

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bootc-bot bootc-bot Bot added the agent/workflow-edits-allowed Pre-authorizes agent runs to edit protected files without the request_review gate label Sep 30, 2026
@bootc-bot bootc-bot Bot added agent/review-working The review agent is actively working on this PR and removed agent/review-working The review agent is actively working on this PR labels Sep 30, 2026
@cgwalters

cgwalters commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Okay it looks like I think a change in GH-AW to increase security broke the review agent? Do we need to tweak our permissions: here? Something with the token minting?

@cgwalters-bot take this p0 for triage/analysis

@cgwalters cgwalters added the agent/fixme Reviewer agent found issues that need fixing label Sep 30, 2026
@bootc-bot bootc-bot Bot added agent/fix-working The fix agent is actively working on this PR and removed agent/fixme Reviewer agent found issues that need fixing labels Sep 30, 2026
@bootc-bot

bootc-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

The fix agent was triggered by agent/fixme, but the PR has no reviews or inline review comments, so there was no feedback to act on. I removed agent/fixme and made no code changes (1 of 3 commits used; the iteration cap is not reached).

This fits the earlier comment about the review agent being broken. It seems to have applied the label without also posting its review body. Once the review agent is working again, re-run it so it posts actionable feedback. After that, re-applying agent/fixme will start a real fix attempt.

Generated by PR Fix Agent for #121 · claude · opus55 · 47.9 AIC · ⌖ 30.4 AIC · ⊞ 5.4K · ◷

@cgwalters-bot

Copy link
Copy Markdown
Contributor

Not a permissions: or token-minting problem. The review agent's run dies in "Checkout PR branch" with ERR_PERMISSION: Refusing PR checkout: actor 'bootc-bot[bot]' has 'none' permission (requires write or higher). gh-aw v0.89.22 (github/gh-aw#63011) dropped the bypass for sender.type == "Bot" in checkout_pr_branch.cjs, and #120 picked that up with the v0.90.1 bump. The check is now on the triggering actor's collaborator permission, and a GitHub App bot can't be a collaborator, so no secret or app-permission change fixes it. The fix agent will hit the same thing whenever the review agent applies agent/fixme (today's fix run passed only because you added the label).

Fix: cgwalters-forge#4 pins gh-aw back to v0.89.21 (the latest non-prerelease, which still has the bypass) and pins Claude Code to 2.1.285 so opus-5-5 keeps working. The lock files compile cleanly with no drift. The real fix belongs upstream: gh-aw should trust actors in the bots: allowlist for PR checkout. Do you want me to file that on github/gh-aw?

Generated-by: https://github.com/cgwalters/#llms

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent/workflow-edits-allowed Pre-authorizes agent runs to edit protected files without the request_review gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Let's fix the generator to omit null if not present

2 participants