From f436ca40352d2da2fe526f3c4744d0c3080eac77 Mon Sep 17 00:00:00 2001 From: navidpadid Date: Mon, 6 Apr 2026 04:21:59 +0000 Subject: [PATCH 1/3] now works only on pull request not by itself --- .github/workflows/update-docs-agent.lock.yml | 64 +++++++++++++------- .github/workflows/update-docs-agent.md | 9 ++- 2 files changed, 47 insertions(+), 26 deletions(-) diff --git a/.github/workflows/update-docs-agent.lock.yml b/.github/workflows/update-docs-agent.lock.yml index 4e6b2b6..6166993 100644 --- a/.github/workflows/update-docs-agent.lock.yml +++ b/.github/workflows/update-docs-agent.lock.yml @@ -21,18 +21,19 @@ # For more information: https://github.github.com/gh-aw/introduction/overview/ # # Keeps ProcLens documentation synchronized with kernel/userspace/release changes. -# Triggered on pushes to main/master and manual dispatch. It analyzes diffs in src/, +# Triggered on pull request closure targeting main and manual dispatch. It analyzes diffs in src/, # e2e/, Makefile, and .github/workflows, then updates matching documentation while # preserving the project's style and single-source-of-truth rules. # -# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"a5e013342eb873ea0ef55e50cb6e6d30b9d795803ee285314d8884e190a47ef1","compiler_version":"v0.65.4","strict":true,"agent_id":"copilot"} +# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"130f3edf91922bdab022f5a508c6d26412e693a942ef38a530f4c6c9eb7fbde4","compiler_version":"v0.65.4","strict":true,"agent_id":"copilot"} name: "Update ProcLens Docs" "on": - push: + pull_request: branches: - main - - master + types: + - closed workflow_dispatch: inputs: aw_context: @@ -44,23 +45,29 @@ name: "Update ProcLens Docs" permissions: {} concurrency: - group: "gh-aw-${{ github.workflow }}-${{ github.ref || github.run_id }}" + group: "gh-aw-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref || github.run_id }}" + cancel-in-progress: true run-name: "Update ProcLens Docs" jobs: activation: needs: pre_activation - if: needs.pre_activation.outputs.activated == 'true' + if: > + needs.pre_activation.outputs.activated == 'true' && ((github.actor != 'github-actions[bot]') && (github.event_name != 'pull_request' || + github.event.pull_request.head.repo.id == github.repository_id)) runs-on: ubuntu-slim permissions: contents: read outputs: + body: ${{ steps.sanitized.outputs.body }} comment_id: "" comment_repo: "" lockdown_check_failed: ${{ steps.generate_aw_info.outputs.lockdown_check_failed == 'true' }} model: ${{ steps.generate_aw_info.outputs.model }} secret_verification_result: ${{ steps.validate-secret.outputs.verification_result }} + text: ${{ steps.sanitized.outputs.text }} + title: ${{ steps.sanitized.outputs.title }} steps: - name: Setup Scripts uses: github/gh-aw-actions/setup@934698b44320d87a7a9196339f90293f10bd2247 # v0.65.4 @@ -126,6 +133,15 @@ jobs: setupGlobals(core, github, context, exec, io); const { main } = require('${{ runner.temp }}/gh-aw/actions/check_version_updates.cjs'); await main(); + - name: Compute current body text + id: sanitized + uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 + with: + script: | + const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs'); + setupGlobals(core, github, context, exec, io); + const { main } = require('${{ runner.temp }}/gh-aw/actions/compute_text.cjs'); + await main(); - name: Create prompt with built-in context env: GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt @@ -143,19 +159,19 @@ jobs: run: | bash ${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh { - cat << 'GH_AW_PROMPT_01a36bd4c91a0b9b_EOF' + cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' - GH_AW_PROMPT_01a36bd4c91a0b9b_EOF + GH_AW_PROMPT_963e1016abafa76b_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_01a36bd4c91a0b9b_EOF' + cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' Tools: create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_01a36bd4c91a0b9b_EOF + GH_AW_PROMPT_963e1016abafa76b_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_01a36bd4c91a0b9b_EOF' + cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' The following GitHub context information is available for this workflow: @@ -185,12 +201,12 @@ jobs: {{/if}} - GH_AW_PROMPT_01a36bd4c91a0b9b_EOF + GH_AW_PROMPT_963e1016abafa76b_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_01a36bd4c91a0b9b_EOF' + cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' {{#runtime-import .github/workflows/update-docs-agent.md}} - GH_AW_PROMPT_01a36bd4c91a0b9b_EOF + GH_AW_PROMPT_963e1016abafa76b_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 @@ -347,12 +363,12 @@ jobs: mkdir -p ${RUNNER_TEMP}/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/config.json << 'GH_AW_SAFE_OUTPUTS_CONFIG_7ee9e7f0a209b88c_EOF' + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/config.json << 'GH_AW_SAFE_OUTPUTS_CONFIG_9053720f59e75ce4_EOF' {"create_pull_request":{"draft":true,"labels":["automation","documentation"],"max":1,"max_patch_size":1024,"protected_files":["package.json","bun.lockb","bunfig.toml","deno.json","deno.jsonc","deno.lock","global.json","NuGet.Config","Directory.Packages.props","mix.exs","mix.lock","go.mod","go.sum","stack.yaml","stack.yaml.lock","pom.xml","build.gradle","build.gradle.kts","settings.gradle","settings.gradle.kts","gradle.properties","package-lock.json","yarn.lock","pnpm-lock.yaml","npm-shrinkwrap.json","requirements.txt","Pipfile","Pipfile.lock","pyproject.toml","setup.py","setup.cfg","Gemfile","Gemfile.lock","uv.lock","CODEOWNERS"],"protected_files_policy":"fallback-to-issue","protected_path_prefixes":[".github/",".agents/"]},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"}} - GH_AW_SAFE_OUTPUTS_CONFIG_7ee9e7f0a209b88c_EOF + GH_AW_SAFE_OUTPUTS_CONFIG_9053720f59e75ce4_EOF - name: Write Safe Outputs Tools run: | - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_0d4719e2fb879eb7_EOF' + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_6c356e029984db13_EOF' { "description_suffixes": { "create_pull_request": " CONSTRAINTS: Maximum 1 pull request(s) can be created. Labels [\"automation\" \"documentation\"] will be automatically added. PRs will be created as drafts." @@ -360,8 +376,8 @@ jobs: "repo_params": {}, "dynamic_tools": [] } - GH_AW_SAFE_OUTPUTS_TOOLS_META_0d4719e2fb879eb7_EOF - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/validation.json << 'GH_AW_SAFE_OUTPUTS_VALIDATION_2aaa4b186073f5e9_EOF' + GH_AW_SAFE_OUTPUTS_TOOLS_META_6c356e029984db13_EOF + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/validation.json << 'GH_AW_SAFE_OUTPUTS_VALIDATION_78b3c75c09840e5b_EOF' { "create_pull_request": { "defaultMax": 1, @@ -457,7 +473,7 @@ jobs: } } } - GH_AW_SAFE_OUTPUTS_VALIDATION_2aaa4b186073f5e9_EOF + GH_AW_SAFE_OUTPUTS_VALIDATION_78b3c75c09840e5b_EOF node ${RUNNER_TEMP}/gh-aw/actions/generate_safe_outputs_tools.cjs - name: Generate Safe Outputs MCP Server Config id: safe-outputs-config @@ -525,7 +541,7 @@ jobs: export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network host -v /var/run/docker.sock:/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e GH_AW_SAFE_OUTPUTS_PORT -e GH_AW_SAFE_OUTPUTS_API_KEY -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw ghcr.io/github/gh-aw-mcpg:v0.2.11' mkdir -p /home/runner/.copilot - cat << GH_AW_MCP_CONFIG_f5f0ca55f5cf7f7b_EOF | bash ${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.sh + cat << GH_AW_MCP_CONFIG_6db2d3b1c62d0be5_EOF | bash ${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.sh { "mcpServers": { "github": { @@ -566,7 +582,7 @@ jobs: "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}" } } - GH_AW_MCP_CONFIG_f5f0ca55f5cf7f7b_EOF + GH_AW_MCP_CONFIG_6db2d3b1c62d0be5_EOF - name: Download activation artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: @@ -954,7 +970,7 @@ jobs: uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 env: WORKFLOW_NAME: "Update ProcLens Docs" - WORKFLOW_DESCRIPTION: "Keeps ProcLens documentation synchronized with kernel/userspace/release changes.\nTriggered on pushes to main/master and manual dispatch. It analyzes diffs in src/,\ne2e/, Makefile, and .github/workflows, then updates matching documentation while\npreserving the project's style and single-source-of-truth rules." + WORKFLOW_DESCRIPTION: "Keeps ProcLens documentation synchronized with kernel/userspace/release changes.\nTriggered on pull request closure targeting main and manual dispatch. It analyzes diffs in src/,\ne2e/, Makefile, and .github/workflows, then updates matching documentation while\npreserving the project's style and single-source-of-truth rules." HAS_PATCH: ${{ needs.agent.outputs.has_patch }} with: script: | @@ -1022,6 +1038,8 @@ jobs: await main(); pre_activation: + if: > + (github.actor != 'github-actions[bot]') && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.id == github.repository_id) runs-on: ubuntu-slim outputs: activated: ${{ steps.check_membership.outputs.is_team_member == 'true' }} diff --git a/.github/workflows/update-docs-agent.md b/.github/workflows/update-docs-agent.md index df1f04b..5eb6d42 100644 --- a/.github/workflows/update-docs-agent.md +++ b/.github/workflows/update-docs-agent.md @@ -1,15 +1,18 @@ --- description: | Keeps ProcLens documentation synchronized with kernel/userspace/release changes. - Triggered on pushes to main/master and manual dispatch. It analyzes diffs in src/, + Triggered on pull request closure targeting main and manual dispatch. It analyzes diffs in src/, e2e/, Makefile, and .github/workflows, then updates matching documentation while preserving the project's style and single-source-of-truth rules. on: - push: - branches: [main, master] + pull_request: + branches: [main] + types: [closed] workflow_dispatch: +if: github.actor != 'github-actions[bot]' + permissions: read-all network: defaults From 60cd357a5d3f27c4d7a5836e8842d4b5af991a68 Mon Sep 17 00:00:00 2001 From: navidpadid Date: Mon, 6 Apr 2026 04:26:03 +0000 Subject: [PATCH 2/3] draft pr change to regular pr --- .github/workflows/update-docs-agent.lock.yml | 40 ++++++++++---------- .github/workflows/update-docs-agent.md | 6 +-- 2 files changed, 23 insertions(+), 23 deletions(-) diff --git a/.github/workflows/update-docs-agent.lock.yml b/.github/workflows/update-docs-agent.lock.yml index 6166993..0419aa3 100644 --- a/.github/workflows/update-docs-agent.lock.yml +++ b/.github/workflows/update-docs-agent.lock.yml @@ -25,7 +25,7 @@ # e2e/, Makefile, and .github/workflows, then updates matching documentation while # preserving the project's style and single-source-of-truth rules. # -# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"130f3edf91922bdab022f5a508c6d26412e693a942ef38a530f4c6c9eb7fbde4","compiler_version":"v0.65.4","strict":true,"agent_id":"copilot"} +# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"d7c22a35600664358894b276276c2e8248646c24ee6477dd61d4a4ebdf1b8d7c","compiler_version":"v0.65.4","strict":true,"agent_id":"copilot"} name: "Update ProcLens Docs" "on": @@ -159,19 +159,19 @@ jobs: run: | bash ${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh { - cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' + cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' - GH_AW_PROMPT_963e1016abafa76b_EOF + GH_AW_PROMPT_c1d3f941fb7ad28a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' + cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' Tools: create_pull_request, missing_tool, missing_data, noop - GH_AW_PROMPT_963e1016abafa76b_EOF + GH_AW_PROMPT_c1d3f941fb7ad28a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_create_pull_request.md" - cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' + cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' The following GitHub context information is available for this workflow: @@ -201,12 +201,12 @@ jobs: {{/if}} - GH_AW_PROMPT_963e1016abafa76b_EOF + GH_AW_PROMPT_c1d3f941fb7ad28a_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_963e1016abafa76b_EOF' + cat << 'GH_AW_PROMPT_c1d3f941fb7ad28a_EOF' {{#runtime-import .github/workflows/update-docs-agent.md}} - GH_AW_PROMPT_963e1016abafa76b_EOF + GH_AW_PROMPT_c1d3f941fb7ad28a_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8 @@ -363,21 +363,21 @@ jobs: mkdir -p ${RUNNER_TEMP}/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/safeoutputs mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/config.json << 'GH_AW_SAFE_OUTPUTS_CONFIG_9053720f59e75ce4_EOF' - {"create_pull_request":{"draft":true,"labels":["automation","documentation"],"max":1,"max_patch_size":1024,"protected_files":["package.json","bun.lockb","bunfig.toml","deno.json","deno.jsonc","deno.lock","global.json","NuGet.Config","Directory.Packages.props","mix.exs","mix.lock","go.mod","go.sum","stack.yaml","stack.yaml.lock","pom.xml","build.gradle","build.gradle.kts","settings.gradle","settings.gradle.kts","gradle.properties","package-lock.json","yarn.lock","pnpm-lock.yaml","npm-shrinkwrap.json","requirements.txt","Pipfile","Pipfile.lock","pyproject.toml","setup.py","setup.cfg","Gemfile","Gemfile.lock","uv.lock","CODEOWNERS"],"protected_files_policy":"fallback-to-issue","protected_path_prefixes":[".github/",".agents/"]},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"}} - GH_AW_SAFE_OUTPUTS_CONFIG_9053720f59e75ce4_EOF + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/config.json << 'GH_AW_SAFE_OUTPUTS_CONFIG_c5123daebf6c6de9_EOF' + {"create_pull_request":{"draft":false,"labels":["automation","documentation"],"max":1,"max_patch_size":1024,"protected_files":["package.json","bun.lockb","bunfig.toml","deno.json","deno.jsonc","deno.lock","global.json","NuGet.Config","Directory.Packages.props","mix.exs","mix.lock","go.mod","go.sum","stack.yaml","stack.yaml.lock","pom.xml","build.gradle","build.gradle.kts","settings.gradle","settings.gradle.kts","gradle.properties","package-lock.json","yarn.lock","pnpm-lock.yaml","npm-shrinkwrap.json","requirements.txt","Pipfile","Pipfile.lock","pyproject.toml","setup.py","setup.cfg","Gemfile","Gemfile.lock","uv.lock","CODEOWNERS"],"protected_files_policy":"fallback-to-issue","protected_path_prefixes":[".github/",".agents/"]},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"}} + GH_AW_SAFE_OUTPUTS_CONFIG_c5123daebf6c6de9_EOF - name: Write Safe Outputs Tools run: | - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_6c356e029984db13_EOF' + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_fcf08ae320930597_EOF' { "description_suffixes": { - "create_pull_request": " CONSTRAINTS: Maximum 1 pull request(s) can be created. Labels [\"automation\" \"documentation\"] will be automatically added. PRs will be created as drafts." + "create_pull_request": " CONSTRAINTS: Maximum 1 pull request(s) can be created. Labels [\"automation\" \"documentation\"] will be automatically added." }, "repo_params": {}, "dynamic_tools": [] } - GH_AW_SAFE_OUTPUTS_TOOLS_META_6c356e029984db13_EOF - cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/validation.json << 'GH_AW_SAFE_OUTPUTS_VALIDATION_78b3c75c09840e5b_EOF' + GH_AW_SAFE_OUTPUTS_TOOLS_META_fcf08ae320930597_EOF + cat > ${RUNNER_TEMP}/gh-aw/safeoutputs/validation.json << 'GH_AW_SAFE_OUTPUTS_VALIDATION_bb4240b2c6fd8e45_EOF' { "create_pull_request": { "defaultMax": 1, @@ -473,7 +473,7 @@ jobs: } } } - GH_AW_SAFE_OUTPUTS_VALIDATION_78b3c75c09840e5b_EOF + GH_AW_SAFE_OUTPUTS_VALIDATION_bb4240b2c6fd8e45_EOF node ${RUNNER_TEMP}/gh-aw/actions/generate_safe_outputs_tools.cjs - name: Generate Safe Outputs MCP Server Config id: safe-outputs-config @@ -541,7 +541,7 @@ jobs: export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network host -v /var/run/docker.sock:/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e GH_AW_SAFE_OUTPUTS_PORT -e GH_AW_SAFE_OUTPUTS_API_KEY -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw ghcr.io/github/gh-aw-mcpg:v0.2.11' mkdir -p /home/runner/.copilot - cat << GH_AW_MCP_CONFIG_6db2d3b1c62d0be5_EOF | bash ${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.sh + cat << GH_AW_MCP_CONFIG_79fbfcb06dda8f41_EOF | bash ${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.sh { "mcpServers": { "github": { @@ -582,7 +582,7 @@ jobs: "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}" } } - GH_AW_MCP_CONFIG_6db2d3b1c62d0be5_EOF + GH_AW_MCP_CONFIG_79fbfcb06dda8f41_EOF - name: Download activation artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: @@ -1153,7 +1153,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,github.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,telemetry.enterprise.githubcopilot.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_pull_request\":{\"draft\":true,\"labels\":[\"automation\",\"documentation\"],\"max\":1,\"max_patch_size\":1024,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"AGENTS.md\"],\"protected_files_policy\":\"fallback-to-issue\",\"protected_path_prefixes\":[\".github/\",\".agents/\"]},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_pull_request\":{\"draft\":false,\"labels\":[\"automation\",\"documentation\"],\"max\":1,\"max_patch_size\":1024,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"AGENTS.md\"],\"protected_files_policy\":\"fallback-to-issue\",\"protected_path_prefixes\":[\".github/\",\".agents/\"]},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"}}" GH_AW_CI_TRIGGER_TOKEN: ${{ secrets.GH_AW_CI_TRIGGER_TOKEN }} with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/update-docs-agent.md b/.github/workflows/update-docs-agent.md index 5eb6d42..0d85286 100644 --- a/.github/workflows/update-docs-agent.md +++ b/.github/workflows/update-docs-agent.md @@ -19,7 +19,7 @@ network: defaults safe-outputs: create-pull-request: - draft: true + draft: false protected-files: fallback-to-issue labels: [automation, documentation] @@ -41,7 +41,7 @@ Your name is ${{ github.workflow }}. You are an Autonomous Technical Writer and ### Mission Keep ProcLens docs aligned with code behavior for both kernel module and userspace CLI paths. -Treat documentation drift as a failing quality signal and fix it through focused draft pull requests. +Treat documentation drift as a failing quality signal and fix it through focused pull requests. ### Project-Specific Ground Truth @@ -105,7 +105,7 @@ Treat documentation drift as a failing quality signal and fix it through focused 5. Produce safe output -- Create a draft pull request with: +- Create a pull request with: - concise summary of detected code-to-doc mappings - list of modified docs and why each changed - explicit note if no doc update was needed From ac181fe6da698ea01f967ef5ef5ed2ce5275076c Mon Sep 17 00:00:00 2001 From: navidpadid Date: Mon, 6 Apr 2026 04:32:44 +0000 Subject: [PATCH 3/3] added documentation and updated the instruction file --- .devcontainer/Dockerfile | 1 + .github/copilot-instructions.md | 7 +++ README.md | 1 + docs/AGENTIC_WORKFLOW.md | 89 +++++++++++++++++++++++++++++++++ 4 files changed, 98 insertions(+) create mode 100644 docs/AGENTIC_WORKFLOW.md diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile index f684f3e..dff8177 100644 --- a/.devcontainer/Dockerfile +++ b/.devcontainer/Dockerfile @@ -13,6 +13,7 @@ RUN apt-get update && apt-get install -y \ linux-headers-generic \ kmod \ git \ + gh \ vim \ sudo \ curl \ diff --git a/.github/copilot-instructions.md b/.github/copilot-instructions.md index e8c40c6..0165ec1 100644 --- a/.github/copilot-instructions.md +++ b/.github/copilot-instructions.md @@ -40,6 +40,13 @@ per-process I/O statistics, ELF metadata, and thread information. - `docs/CODE_QUALITY.md`: quality tooling details - `docs/SCRIPTS.md`: QEMU workflow details - `docs/RELEASE.md`: release process and labels +- `docs/AGENTIC_WORKFLOW.md`: high-level docs-agent workflow guide + +### Agentic Workflow Source of Truth + +- Author workflow logic in `.github/workflows/update-docs-agent.md` +- Treat `.github/workflows/update-docs-agent.lock.yml` as generated output +- Recompile after edits with `gh aw compile update-docs-agent` ## Code Style and Standards diff --git a/README.md b/README.md index e42fcde..6b6d586 100644 --- a/README.md +++ b/README.md @@ -326,6 +326,7 @@ Code formatter that ensures consistent style: - [CODE_QUALITY.md](docs/CODE_QUALITY.md) - Static analysis, code formatting, best practices - [SCRIPTS.md](docs/SCRIPTS.md) - Detailed script documentation - [RELEASE.md](docs/RELEASE.md) - Version release process and guidelines +- [AGENTIC_WORKFLOW.md](docs/AGENTIC_WORKFLOW.md) - High-level guide for the docs agent workflow ## Contributing diff --git a/docs/AGENTIC_WORKFLOW.md b/docs/AGENTIC_WORKFLOW.md new file mode 100644 index 0000000..ea886d2 --- /dev/null +++ b/docs/AGENTIC_WORKFLOW.md @@ -0,0 +1,89 @@ +# Agentic Workflow Guide + +## Purpose (High-Level) + +ProcLens uses an agentic GitHub Actions workflow to keep documentation aligned with implementation changes. + +The workflow: +- Monitors repository changes when pull requests are closed into main +- Maps code/process changes to the correct docs files +- Opens a pull request with documentation updates when needed +- Skips self-trigger loops from github-actions bot + +This is intentionally high-level. Detailed behavior and policy live in the workflow source file: +- `.github/workflows/update-docs-agent.md` + +## Source of Truth + +Use this model: +- Author/edit workflow logic in `.github/workflows/update-docs-agent.md` +- Treat `.github/workflows/update-docs-agent.lock.yml` as generated output + +Do not hand-edit the lock file unless absolutely necessary for emergency triage. + +## How To Update The Workflow + +1. Edit the source workflow: + + `.github/workflows/update-docs-agent.md` + +2. Apply your policy/trigger/tooling changes (for example: triggers, safe outputs, PR behavior, guard conditions). + +3. Compile the workflow to regenerate the lock file. + +## How To Compile + +From repository root: + +```bash +gh aw compile update-docs-agent +``` + +This updates: +- `.github/workflows/update-docs-agent.lock.yml` + +Optional compile checks: + +```bash +gh aw compile update-docs-agent --validate +gh aw compile update-docs-agent --actionlint +``` + +## Testing and Verification + +### 1) Local Static Verification + +Run compile and inspect the generated lock file for expected trigger/guard/output behavior. + +Useful checks: + +```bash +gh aw compile update-docs-agent +git diff -- .github/workflows/update-docs-agent.md .github/workflows/update-docs-agent.lock.yml +``` + +### 2) Trigger Verification (GitHub) + +Validate expected event behavior in Actions: +- Automatic run on pull_request closed targeting main +- No automatic run on push +- No run when actor is github-actions[bot] + +A practical test sequence: +1. Open a test PR against main +2. Merge/close it +3. Confirm workflow execution in Actions +4. Confirm resulting documentation PR behavior and labels + +### 3) Safe Output Verification + +Ensure workflow output policy is still enforced: +- PR creation path is allowed +- Protected files/path prefixes remain respected +- Unexpected writes fall back to issue/no-op handling as configured + +## Maintenance Notes + +- Keep workflow description aligned with real trigger behavior. +- When changing workflow behavior, update this document if operational steps change. +- Prefer small policy changes and recompile immediately to avoid source/generated drift.