Skip to content

Add expression quote-escaping test & implement server job timeouts an… - #6

Merged
Bnjoroge1 merged 16 commits into
mainfrom
autoresearch/session-20260628
Jul 1, 2026
Merged

Bnjoroge1 merged 16 commits into
mainfrom
autoresearch/session-20260628

Conversation

@Bnjoroge1

@Bnjoroge1 Bnjoroge1 commented Jul 1, 2026 •

Copy link
Copy Markdown
Collaborator

…d runner lease reaper


Summary by cubic

Adds a GitHub App webhook that triggers workflows on push/PR and reports per‑job status to GitHub Checks. Adds server‑side job timeouts and a lease reaper to auto‑cancel/fail stuck jobs, plus a one‑click App registration flow, tests, and docs.

  • New Features

    • Webhook receiver at /api/v1/github/webhooks with HMAC signature verification (requires AKSH_WEBHOOK_SECRET); loads workflows from AKSH_LOCAL_WORKSPACE or GitHub and triggers matching runs.
    • GitHub Checks: create/update per‑job check runs (queued → in_progress → completed); mock mode if AKSH_GITHUB_TOKEN is unset.
    • Background reaper: enforce job timeout (default 360m) and expire runner leases after 120s; enqueue cancellations or mark failed, and clean up sessions.
    • One‑click GitHub App Manifest flow at /api/v1/github/register and /api/v1/github/callback; docs at docs/github-app-webhook.md; tests for webhook flows, manifest conversion, reaper behavior, and escaped single quotes in expressions.
  • Bug Fixes

    • Paginate PR changed files retrieval to handle large pull requests.
    • Do not initialize last_renewed_at in the legacy non‑renewing next_message path to avoid false lease renewals.

Written for commit 745884b. Summary will update on new commits.

Review in cubic

@Bnjoroge1 Bnjoroge1 closed this Jul 1, 2026
@Bnjoroge1 Bnjoroge1 reopened this Jul 1, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

4 issues found across 7 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread crates/aksh-runner-server/src/lib.rs Outdated
Comment thread crates/aksh-runner-server/src/lib.rs
Comment thread crates/aksh-runner-server/src/github.rs
Comment thread docs/github-app-webhook.md Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 3 files (changes from recent commits).

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="crates/aksh-runner-server/src/github.rs">

<violation number="1" location="crates/aksh-runner-server/src/github.rs:467">
P1: Reject empty webhook secrets, not just missing ones. An empty `AKSH_WEBHOOK_SECRET` is treated as configured and allows signatures generated with a public empty key.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment on lines +467 to +470
let secret = shared.state.webhook_secret.as_ref().ok_or_else(|| {
warn!("Webhook secret not configured on server, rejecting request");
StatusCode::UNAUTHORIZED
})?;

@cubic-dev-ai cubic-dev-ai Bot Jul 1, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Reject empty webhook secrets, not just missing ones. An empty AKSH_WEBHOOK_SECRET is treated as configured and allows signatures generated with a public empty key.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At crates/aksh-runner-server/src/github.rs, line 467:

<comment>Reject empty webhook secrets, not just missing ones. An empty `AKSH_WEBHOOK_SECRET` is treated as configured and allows signatures generated with a public empty key.</comment>

<file context>
@@ -452,15 +464,18 @@ pub(crate) async fn handle_github_webhook(
-        if !verify_signature(secret, &body, sig_header) {
-            return Err(StatusCode::UNAUTHORIZED);
-        }
+    let secret = shared.state.webhook_secret.as_ref().ok_or_else(|| {
+        warn!("Webhook secret not configured on server, rejecting request");
+        StatusCode::UNAUTHORIZED
</file context>
Suggested change
let secret = shared.state.webhook_secret.as_ref().ok_or_else(|| {
warn!("Webhook secret not configured on server, rejecting request");
StatusCode::UNAUTHORIZED
})?;
let secret = shared
.state
.webhook_secret
.as_deref()
.filter(|secret| !secret.is_empty())
.ok_or_else(|| {
warn!("Webhook secret not configured on server, rejecting request");
StatusCode::UNAUTHORIZED
})?;
Fix with cubic

@Bnjoroge1
Bnjoroge1 merged commit c8959b7 into main Jul 1, 2026
2 of 3 checks passed
@Bnjoroge1
Bnjoroge1 deleted the autoresearch/session-20260628 branch July 1, 2026 15:17
Bnjoroge1 added a commit that referenced this pull request Aug 7, 2026
Add expression quote-escaping test & implement server job timeouts an…
Bnjoroge1 added a commit that referenced this pull request Aug 7, 2026
Add expression quote-escaping test & implement server job timeouts an…
Bnjoroge1 added a commit that referenced this pull request Aug 7, 2026
Add expression quote-escaping test & implement server job timeouts an…
Bnjoroge1 added a commit that referenced this pull request Aug 7, 2026
Add expression quote-escaping test & implement server job timeouts an…
Bnjoroge1 added a commit that referenced this pull request Aug 7, 2026
Add expression quote-escaping test & implement server job timeouts an…
Bnjoroge1 added a commit that referenced this pull request Oct 9, 2026
- fix #8: JSON validation - handle malformed JSON with 422
- fix #9: Cancel shim race condition handling
- fix #6: Check suite rerequest for multiple workflows on same SHA
- Add regression tests for security and JSON validation fixes
Bnjoroge1 added a commit that referenced this pull request Oct 9, 2026
- #9 cancel: 202 only when the locked cancel transitioned a live run;
  already-terminal and archived runs answer GitHub's 409 'Cannot cancel
  a workflow run that is completed.' Backend CancelOutcome gains
  run_cancelled so the REST shim reads the real transition result.
- #6 suite rerequest: rerun every terminal run whose checks reported at
  the suite's head_sha via check_run_report_coords (status_check_sha /
  effective sha), not just the newest run by checkout sha; skip suites
  of unregistered Apps when the payload names one.
- #8: malformed JSON / wrong JSON types → GitHub-shaped 422 regardless
  of Content-Type; empty and null bodies keep defaults.
- REST rerun shims pass the authenticated caller as triggering_actor.
- fix missing triggering_actor arg on dispatch.rs rerun calls.
- clippy -D warnings cleanups in test targets (toolchain 1.97).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant