diff --git a/.github/workflows/simplycubed.yml b/.github/workflows/simplycubed.yml index 2232239..b927388 100644 --- a/.github/workflows/simplycubed.yml +++ b/.github/workflows/simplycubed.yml @@ -54,7 +54,7 @@ on: type: string version: description: SimplyCubed CLI tag to install. - default: v0.1.8 + default: v0.1.9 required: false type: string secrets: diff --git a/CHANGELOG.md b/CHANGELOG.md index 88cbb0f..61fe48f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,46 @@ All notable changes are recorded here and summarized again in the matching GitHub release notes for each tag. +## v0.1.9 + +- **The GitHub Actions runtime does the work now.** Until this release the + issue-to-PR loop had never once produced a pull request from Actions, on this + repository or any other. The engine confines itself with a bundled bubblewrap, + bubblewrap builds its sandbox from an unprivileged user namespace, and Ubuntu + 24.04 forbids those by AppArmor policy, so the sandbox died at startup on + every run: + + ``` + bwrap: loopback: Failed RTM_NEWADDR: Operation not permitted + ``` + + Every command the engine tried then failed, including `pwd`, so it read + nothing and changed nothing while still exiting successfully. That is why this + presented for so long as an agent quietly declining to work rather than one + that had never been able to start. The workflow now enables the kernel feature + the sandbox is built from, which reads like a weakening and is the reverse: + with the restriction in place the engine was confined by nothing, because its + confinement never loaded. Measured on a runner in both directions, same + binary, only that setting changing. None of the engines' own "dangerous" flags + are set, here or anywhere. +- Comment commands answer on the thread instead of in a log nobody opens. + `@simplycubed-code help` produced the right text and printed it inside the + runner, so the person who asked saw silence. Worse, `address` on an issue ran + anyway and failed two layers down with a raw GraphQL error, because nothing + checked that a pull-request verb had been aimed at a pull request. The agent + now resolves which surface a comment arrived on, answers with the verb that + does apply, and stays green: someone using the wrong word is not a failure. A + comment that merely mentions the agent in passing still says nothing at all. +- `engine: claude` no longer demands Azure credentials it never uses. The + adapter was selectable and unusable, because the CLI required an Azure + endpoint and key whatever engine was chosen, and then wrote a Codex provider + config the Claude path never reads. Both are now conditional on the engine. + This is the local CLI path; the reusable workflow still installs only the + Codex CLI, which is tracked separately. +- The repository's own comment job installs the commit under test rather than + the last release, matching the two jobs beside it. It was the one path whose + regressions could not be caught before they shipped. + ## v0.1.8 - **The Actions runtime was dead in `v0.1.7` and is fixed here.** The comment diff --git a/README.md b/README.md index c50a548..255e062 100644 --- a/README.md +++ b/README.md @@ -4,7 +4,7 @@ An autonomous coding agent that lives inside your own GitHub. You file an issue, it opens a pull request, and a human decides whether to merge. -> Beta, at `v0.1.8`. Product overview: [simplycubed.com/code](https://simplycubed.com/code?utm_source=github&utm_medium=readme&utm_campaign=code). See [Status](#status). +> Beta, at `v0.1.9`. Product overview: [simplycubed.com/code](https://simplycubed.com/code?utm_source=github&utm_medium=readme&utm_campaign=code). See [Status](#status). ### Try it without letting it write anything @@ -115,7 +115,7 @@ Start with the adopter quickstart in [docs/setup.md](docs/setup.md). It covers t Install the pinned release you want to run: ```sh -go install github.com/simplycubed/code/cmd/simplycubed@v0.1.8 +go install github.com/simplycubed/code/cmd/simplycubed@v0.1.9 simplycubed version ``` @@ -210,7 +210,7 @@ The first engine adapter targets the Codex CLI running against Azure OpenAI. Tod ## Status -Beta, and honest about it. Two loops run end to end via the CLI on the Codex-on-Azure engine: issue to pull request, and fix-on-request (a human requests changes, the fixer addresses them and pushes back). `v0.1.8` is the latest release and you should still expect rough edges. +Beta, and honest about it. Two loops run end to end via the CLI on the Codex-on-Azure engine: issue to pull request, and fix-on-request (a human requests changes, the fixer addresses them and pushes back). `v0.1.9` is the latest release and you should still expect rough edges. Roadmap, roughly in order: diff --git a/STATUS.md b/STATUS.md index e0f9825..4ca2af7 100644 --- a/STATUS.md +++ b/STATUS.md @@ -30,16 +30,21 @@ The Actions runtime authenticates as the `simplycubed-code[bot]` GitHub App. Each job mints its own installation token scoped to one repository with `contents`, `issues`, and `pull-requests` permissions only. -`v0.1.8` is the current release. `go install -github.com/simplycubed/code/cmd/simplycubed@v0.1.8` works today. `v0.1.2` and `v0.1.4` are retracted in `go.mod` because those tags pointed at the wrong +`v0.1.9` is the current release. `go install +github.com/simplycubed/code/cmd/simplycubed@v0.1.9` works today. `v0.1.2` and `v0.1.4` are retracted in `go.mod` because those tags pointed at the wrong commits. -Do not use `v0.1.7`. Its copy of the reusable workflow has a duplicate `env:` -key, which GitHub refuses to load, so every run under it fails in about a second -without starting a job. `v0.1.8` is the fix. - -Both loops were dogfooded: the issue-to-PR loop produced the merged -dependency-upgrade PR on `charlesgreen/gsm`. +Upgrade from anything earlier. `v0.1.7` has a duplicate `env:` key in its copy +of the reusable workflow, which GitHub refuses to load, so every run under it +fails in about a second without starting a job. `v0.1.8` loads and runs, but its +engine sandbox cannot start on an Ubuntu 24.04 runner, so every Actions run +under it escalates without proposing anything. `v0.1.9` is the first release +whose Actions runtime can do work. + +Both loops are dogfooded here. The issue-to-PR loop, running in this +repository's own Actions, produced PR #102 against issue #95: the fix, the +tests, and the documentation for it, reviewed and merged by a human. That is the +first pull request the agent has opened from Actions. ## Layers (all green under `make check`) diff --git a/cmd/simplycubed/main.go b/cmd/simplycubed/main.go index 1d9c1fd..2f5f001 100644 --- a/cmd/simplycubed/main.go +++ b/cmd/simplycubed/main.go @@ -131,7 +131,7 @@ gate: ` const ( - latestKnownWorkflowTag = "v0.1.8" + latestKnownWorkflowTag = "v0.1.9" callerWorkflowTagToken = "__SIMPLYCUBED_TAG__" simplycubedAppLogin = "simplycubed-code[bot]" ) diff --git a/docs/setup.md b/docs/setup.md index ea51a83..07cab29 100644 --- a/docs/setup.md +++ b/docs/setup.md @@ -16,7 +16,7 @@ Prerequisites: 1. Install the CLI: ```sh -go install github.com/simplycubed/code/cmd/simplycubed@v0.1.8 +go install github.com/simplycubed/code/cmd/simplycubed@v0.1.9 simplycubed version ``` diff --git a/docs/templates/simplycubed-caller.yml b/docs/templates/simplycubed-caller.yml index 133f469..d5d54dd 100644 --- a/docs/templates/simplycubed-caller.yml +++ b/docs/templates/simplycubed-caller.yml @@ -11,7 +11,7 @@ on: jobs: run: if: ${{ github.event_name == 'issues' && github.event.label.name == 'sc:go' }} - uses: simplycubed/code/.github/workflows/simplycubed.yml@v0.1.8 + uses: simplycubed/code/.github/workflows/simplycubed.yml@v0.1.9 with: ref: ${{ github.event.issue.number }} github-app-client-id: ${{ vars.SIMPLYCUBED_GH_APP_CLIENT_ID }} @@ -27,7 +27,7 @@ jobs: if: >- github.event_name == 'pull_request_review' && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.review.author_association) - uses: simplycubed/code/.github/workflows/simplycubed.yml@v0.1.8 + uses: simplycubed/code/.github/workflows/simplycubed.yml@v0.1.9 with: ref: ${{ github.event.pull_request.number }} github-app-client-id: ${{ vars.SIMPLYCUBED_GH_APP_CLIENT_ID }} @@ -50,7 +50,7 @@ jobs: github.event.comment.user.type != 'Bot' && startsWith(github.event.comment.body, '@simplycubed-code') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association) - uses: simplycubed/code/.github/workflows/simplycubed.yml@v0.1.8 + uses: simplycubed/code/.github/workflows/simplycubed.yml@v0.1.9 with: ref: ${{ github.event.issue.number }} github-app-client-id: ${{ vars.SIMPLYCUBED_GH_APP_CLIENT_ID }}