Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
280 changes: 98 additions & 182 deletions .agents/skills/apm-review-panel/SKILL.md

Large diffs are not rendered by default.

7 changes: 4 additions & 3 deletions .apm/architecture/owners/install-deployment.json
Original file line number Diff line number Diff line change
Expand Up @@ -73,11 +73,12 @@
},
{
"id": "bundle-native-layout-lowering",
"decision": "Bundle-native directory and filename lowering to APM primitive kinds and target deploy layout",
"owner": "bundle/plugin_layout.py (PLUGIN_LAYOUT, plugin_command_prompt_name) consumed by install/local_bundle_paths.py (_lower_to_target)",
"decision": "Bundle-native directory and filename lowering to APM primitive kinds, target deploy layout, and pack eligibility",
"owner": "bundle/plugin_layout.py (PLUGIN_LAYOUT, plugin_command_prompt_name) and integration/targets.py (TargetProfile) consumed by install/local_bundle_paths.py and bundle/lockfile_enrichment.py",
"selectors": [
"src/apm_cli/bundle/plugin_layout.py",
"src/apm_cli/install/local_bundle_paths.py"
"src/apm_cli/install/local_bundle_paths.py",
"src/apm_cli/bundle/lockfile_enrichment.py"
],
"guards": ["install-deployment-bundle-native-layout"]
},
Expand Down
14 changes: 9 additions & 5 deletions .github/workflows/pr-review-panel.lock.yml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

28 changes: 27 additions & 1 deletion .github/workflows/pr-review-panel.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,10 +87,36 @@ permissions:
imports:
- uses: shared/apm.md
with:
target: copilot
apm-version: '0.30.0'
# Temporary workaround: 0.30 installs Copilot skills under .agents,
# but sole-target copilot packing omits that tree. Keep the shared
# default unchanged; remove agent-skills after the pack fix ships.
target: copilot,agent-skills
packages:
- microsoft/apm#main

# Fail before inference if the trusted bundle lost the panel or its resources.
# This hook runs after shared/apm.md's restore and framework initialization.
# Only inspect file metadata here; never execute bundled scripts or fetch PR head.
pre-agent-steps:
- name: Verify restored review panel skill and resources
shell: bash
run: |
set -euo pipefail
cd "$GITHUB_WORKSPACE"
skill=.agents/skills/apm-review-panel
for resource in \
SKILL.md \
assets/panelist-return-schema.json \
assets/ceo-return-schema.json \
assets/recommendation-template.md
do
if [ ! -f "$skill/$resource" ] || [ ! -s "$skill/$resource" ]; then
echo "::error::Missing or empty required review panel file: $skill/$resource. Check the APM install/pack/restore bundle before retrying."
exit 1
fi
done

tools:
github:
toolsets: [default]
Expand Down
84 changes: 83 additions & 1 deletion .github/workflows/verify-shared-apm-matrix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: Verify shared/apm.md matrix secret-stripping fix

# Empirical proof for fixes in .github/workflows/shared/apm.md.
#
# Three job sets:
# Four job sets:
#
# A. prove-old-pattern-strips-output (regression sentinel)
# Replicates the pre-fix shape (PEM embedded in a job output). Asserts
Expand Down Expand Up @@ -34,6 +34,9 @@ name: Verify shared/apm.md matrix secret-stripping fix
# at runtime, so apm-action resolves '' || 'latest' and floats.
# (3) Drift guard (source of truth): the schema default's pack format
# must be detected by the pinned microsoft/apm-action ref.
# Retains the 0.28.0 default multi-bundle proof and independently checks
# the review panel's 0.30.0 copilot,agent-skills override: real install,
# archive and clean restore must preserve each required resource's bytes.
#
# D. pack-format-consumer-compat (cross-repo drift guard)
# Proves the `apm pack --archive` default archive format (.zip) stays
Expand Down Expand Up @@ -539,6 +542,85 @@ jobs:
test -n "$(find "$RESTORE_ROOT" -type f -print -quit)"
echo "[+] APM 0.28 packed two explicit targets and restored both bundles."

c-apm-030-panel-compat:
name: C. APM 0.30 review panel skill roundtrip
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
steps:
# No checkout: installed and restored files cannot be confused with
# the repository's committed deployment tree. Match the production
# dependency and per-consumer override, not the shared 0.28.0 default.
- name: Pack real review panel with APM 0.30
id: pack-panel
uses: microsoft/apm-action@d723bb64ed70c135bbaf87d126b721dd2dae0439 # v1.10.0
with:
dependencies: |
- microsoft/apm#main
isolated: 'true'
pack: 'true'
archive: 'true'
target: copilot,agent-skills
apm-version: '0.30.0'
working-directory: ${{ runner.temp }}/apm-030-panel-pack

- name: Require a fresh panel restore destination
env:
RESTORE_ROOT: ${{ runner.temp }}/apm-030-panel-restore
run: |
set -euo pipefail
test ! -e "$RESTORE_ROOT"

- name: Restore review panel bundle with APM 0.30
uses: microsoft/apm-action@d723bb64ed70c135bbaf87d126b721dd2dae0439 # v1.10.0
with:
apm-version: '0.30.0'
bundle: ${{ steps.pack-panel.outputs.bundle-path }}
working-directory: ${{ runner.temp }}/apm-030-panel-restore

- name: Compare installed, archived, and restored panel bytes
shell: python
env:
PACK_ROOT: ${{ runner.temp }}/apm-030-panel-pack
BUNDLE: ${{ steps.pack-panel.outputs.bundle-path }}
RESTORE_ROOT: ${{ runner.temp }}/apm-030-panel-restore
run: |
import os
from pathlib import Path
from zipfile import ZipFile

# Read only the four required skill/resource files, not persona
# definitions. A nonempty .github tree alone missed this regression.
required = (
"SKILL.md",
"assets/panelist-return-schema.json",
"assets/ceo-return-schema.json",
"assets/recommendation-template.md",
)
skill = Path(".agents/skills/apm-review-panel")
with ZipFile(os.environ["BUNDLE"]) as archive:
names = archive.namelist()
markers = [
name for name in names
if name.count("/") == 1 and name.endswith("/apm.lock.yaml")
]
assert len(markers) == 1, "Expected one APM bundle wrapper"
wrapper = markers[0].split("/")[0]
for resource in required:
deployed = skill / resource
installed = Path(os.environ["PACK_ROOT"]) / deployed
restored = Path(os.environ["RESTORE_ROOT"]) / deployed
assert installed.is_file(), f"Not installed: {deployed}"
expected = installed.read_bytes()
assert expected, f"Empty installed resource: {deployed}"
member = f"{wrapper}/{deployed.as_posix()}"
assert names.count(member) == 1, f"Missing or duplicate archive entry: {deployed}"
assert archive.read(member) == expected, f"Archive bytes differ: {deployed}"
assert restored.is_file(), f"Not restored: {deployed}"
assert restored.read_bytes() == expected, f"Restored bytes differ: {deployed}"
print("[+] 4 review panel files survived install, pack, and restore byte-for-byte.")

# =====================================================================
# Job set D: apm pack archive-format <-> apm-action consumer detection.
# Outage shape: GH-AW Compatibility job 'apm pack produced no bundle'.
Expand Down
4 changes: 2 additions & 2 deletions apm.lock.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -254,7 +254,7 @@ dependencies:
- .agents/skills/apm-review-panel/evals/render_eval.py
- .agents/skills/apm-review-panel/evals/trigger-evals.json
deployed_file_hashes:
.agents/skills/apm-review-panel/SKILL.md: sha256:c9fee6c311b23b6ea72b06a424c8ba21c5d88bcc833e65259b7e0212aa73abbb
.agents/skills/apm-review-panel/SKILL.md: sha256:495c7d5b703b93e3046f341324e90806fe96ee44a93f92a2dea53bc684ed6b83
.agents/skills/apm-review-panel/apm.yml: sha256:80c403c4d3c59a91bb27b85650e21a466e9cd0cbc28e92bf0f3e53c6ea71cb2c
.agents/skills/apm-review-panel/assets/ceo-return-schema.json: sha256:d8707211968efb0471d083f880d5353d66a0eda84635e803a930f60c91837468
.agents/skills/apm-review-panel/assets/panelist-return-schema.json: sha256:e3cf2ae17e93dd934f2659ed77d2640ea9601fbe8698f63ba800edf046691f99
Expand Down Expand Up @@ -1945,7 +1945,7 @@ deployments:
owners:
- local:packages/apm-review-panel
active_owner: local:packages/apm-review-panel
content_hash: sha256:c9fee6c311b23b6ea72b06a424c8ba21c5d88bcc833e65259b7e0212aa73abbb
content_hash: sha256:495c7d5b703b93e3046f341324e90806fe96ee44a93f92a2dea53bc684ed6b83
- kind: project-relative
target: copilot
value: .agents/skills/apm-review-panel/apm.yml
Expand Down
10 changes: 10 additions & 0 deletions docs/src/content/docs/integrations/gh-aw.md
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,16 @@ imports:

Use a bare semver tag (e.g. `'0.28.0'`). Pass `'latest'` to opt into floating to the newest release; omit the input entirely to keep the workflow's pinned default.

:::caution[Temporary Copilot skill-bundle workaround]
APM 0.30.0 still omits `.agents/skills/` under `--format apm --target copilot`. Only target-filtered legacy APM packaging is affected, not target-agnostic plugin formats. The PR review panel temporarily sets `apm-version: '0.30.0'` and `target: 'copilot,agent-skills'`; the shared default remains 0.28.0.

Change the source workflow import, then run `gh aw compile` so the generated `.lock.yml` upgrades both pack and restore. Do not hand-edit generated locks or use `apm self-update`. Before agent launch, the workflow checks restored `.agents/skills/apm-review-panel/SKILL.md` and its three required assets.

After these changes merge into trusted `main`, maintainers must start a fresh `workflow_dispatch` for PR #2741 and verify an actual recommendation. Re-running an old run does not validate the new workflow.

The permanent fix is not yet published. Keep `agent-skills` until you pin a release containing that fix and recompile.
:::

Copies vendored before this change default to APM 0.21.0, the repository's current CLI line when that default was selected. If a copy's `apm-action pin:` line reads `v1.4.2`, its target input applies only to packing and does not reach the isolated install. To migrate:

1. Replace `.github/workflows/shared/apm.md` with the [canonical file](https://github.com/microsoft/apm/blob/main/.github/workflows/shared/apm.md). This also moves the default to the compatibility-tested 0.28.0.
Expand Down
Loading
Loading