Commit Graph

8 Commits

Author SHA1 Message Date
can1357 79faf94f26 feat(python/robomp): added the wontfix primary classification and comment-only triage path
- Added `wontfix` to primary classification handling by updating host-tool classification metadata and issue taxonomy prompts.
- Updated kickoff/follow-up/system prompt guidance to treat intentional-design reports as `wontfix`, with maintainer-intent signals stopping work and ending in a single explanatory comment.
- Added tests to verify `classify_issue` persists a `wontfix` classification and returns a no-PR, comment-only next step.
2026-07-15 00:09:00 +02:00
can1357 93f8548f6a security(git): hardened git operations by neutralizing malicious local config
- Constrained git configuration for smart-HTTP requests by explicitly overriding proxy, sslVerify, and credential helpers across all relevant path suffixes.
- Prevented potential credential capture by disabling repo-configured credential helpers that could otherwise execute malicious commands during authentication challenges.
- Hardened git operations against attacker-injected proxies by exhaustively blanking configuration keys for all identifiable git request endpoints.
- Excluded sslCAInfo/sslCAPath from overrides to prevent premature TLS negotiation failure while maintaining security via mandatory proxy neutralization.
2026-06-24 15:30:29 +02:00
can1357 c58f72d943 chore: update changelogs 2026-06-23 20:22:31 +02:00
can1357 c752aee69d security(python-robomp): implemented git remote validation and credential hardening
- Sanitized git subprocess environment variables to prevent leakage of parent authentication tokens.
- Enforced strict HTTPS protocol restrictions and source validation for all git repositories.
- Implemented secure remote URL handling to neutralize malicious push URLs and prevent credential exfiltration.
- Applied scoped token injection during git operations to restrict token exposure to intended targets.
2026-06-23 20:19:14 +02:00
roboomp a692ffeb31 fix(robomp): backfilled partial-clone blobs before worktree add
`SandboxManager.ensure_workspace` calls `fetch_base_ref` (then
`worktree add origin/<ref>`) and `fetch_pr_head` (then
`worktree add --detach FETCH_HEAD`). Both used to issue a plain
`git fetch origin <ref>`. On a `--filter=blob:none` pool the fetch
inherits `remote.origin.partialclonefilter` from the pool config and
brings the commit + tree but no blobs. The next `worktree add` runs
in a non-token subprocess, hits a missing blob, and tries a lazy
promisor fetch — which under `ProxyGitTransport` deployments has no
PAT in the orchestrator container and dies with

    fatal: could not read Username for 'https://github.com'
    fatal: could not fetch <sha> from promisor remote

`git_ops.fetch_ref` and `fetch_pr_head` now pass `--refetch
--no-filter` so the fetch (which already runs through the token-bearing
transport) eagerly materializes every blob reachable from the requested
ref. `--refetch` is required: without it git short-circuits on "we
already have this commit" and the lazy-fetch path stays primed.
`fetch_prune` (the periodic pool refresh) is untouched, so the
partial-clone disk savings are preserved on the steady-state path.
`remote.origin.partialclonefilter` is left intact in the pool config.

Fixes #1818
2026-06-04 05:39:46 +00:00
can1357 b503f7d86b feat(robomp): added incoming PR review feature with classify and submit
- Added `review_pr` task that checks out PR head in a detached worktree, classifies rank/type/area, and posts a batched GitHub review as `event=COMMENT`.
- Added four new host tools: `fetch_pr`, `classify_pr`, `pr_review_comment`, and `submit_pr_review`; review tools self-gate on `review_mode`, push/open-PR tools refuse when `review_mode` is set.
- Added sqlite staging table `pr_review_comments` with `stage_review_comment`, `list_staged_review_comments`, and `clear_staged_review_comments` DAOs.
- Routed `pull_request.opened/reopened/ready_for_review` to `review_pr` and extended `pull_request.closed` cleanup to any tracked PR regardless of author.
2026-06-02 08:23:09 +02:00
can1357 784ac0b6cf feat(python-robomp): added DirtyState and inspect_dirty_state in git_ops
- Added `DirtyState` and `inspect_dirty_state` in `git_ops` to report uncommitted, unpushed, and summary state.
- Updated `_drive_turn` to recheck completion each cycle and emit dirty-state reminders or exit when clean.
- Wired `dirty_state_reminder` into persona rendering with `uncommitted`, `unpushed`, and `summary` context.
- Added `dirty_state_reminder.md` guidance for fixing/restoring changes and pushing only after `bun run fix` completes.
- Added worker tests for dirty, clean, and persistent-dirty flows and prompt-count assertions.
2026-05-19 18:39:09 +09:00
can1357 ec20364322 chore: flatten robomp 2026-05-17 04:10:50 +02:00