Repository navigation
fix: /dotbot never ran — invalid permissions scope rejects dotbot-act.yml - #11
Merged
Merged
Conversation
`dotbot-act.yml` declared `permissions: workflows: write`. There is no such GITHUB_TOKEN scope, so GitHub rejects the whole workflow file: each push records a failed ".github/workflows/dotbot-act.yml" run with X This run likely failed because of a workflow file issue. and no jobs. All 28 recorded runs are failures of that kind, none of them ever started a job, and no `/dotbot` comment has ever triggered one — Act mode has been a no-op since the scope was introduced, which is also why the DOTBOT_ACT_MODEL wiring could not be exercised. - Drop the invalid scope. Editing `.github/workflows/*` needs a token carrying the PAT `workflow` scope, not a workflow-level permission (README corrected — consumers copying that example got a dead Act workflow). - Checkout token falls back to the workflow token so Act works with no PAT, documenting the trade-offs (no workflow re-trigger, no workflow-file edits). - Guard it: a test asserts every `permissions:` scope in .github/workflows is one GitHub knows, and CI runs actionlint (1.7.12.25), which reports the same thing locally before anyone pushes. Repro: `uvx --from actionlint-py==1.7.12.25 actionlint` .github/workflows/dotbot-act.yml:31:7: unknown permission scope "workflows"
Review feedback (both models): the scope check only walked job-level `permissions:`, so an invalid scope in a workflow's top-level block — which bricks the file just the same — would have passed. Check both levels via a shared helper, and cover the string shorthands (`read-all`/`write-all`) at either level. Verified the extended guard fails on a top-level `workflows: write` in ci.yml and passes once reverted.
|
dotbot code review:
Incremental change only extends permission-scope guard to top-level permissions with no logic errors. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · meta/muse-spark-1.3 · medium |
|
dotbot code review:
The incremental change addresses the prior top-level permissions gap cleanly via a shared Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · ~z-ai/glm-latest · medium |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
/dotbothas never worked in this repo, and the cause is one line:workflows: writeis not a valid permission scope, so GitHub rejects the whole workflow file. Every push records a failed run named after the file path with no jobs:All 28 recorded runs of this workflow are that failure. No
/dotbotcomment has ever triggered one, so Act mode has been a no-op since the scope was introduced — and theDOTBOT_ACT_MODELwiring from #7 could never be exercised.Caught by
uvx --from actionlint-py==1.7.12.25 actionlint:Fix
/dotbotedit.github/workflows/*) is a token concern: theGITHUB_TOKENused to push cannot update workflow files, and the escape hatch is a PAT with theworkflowscope — not a workflow-level permission.${{ secrets.REPO_ACCESS_TOKEN || github.token }}, so Act runs where no PAT exists (this repo has none). Documented trade-offs: pushes made with the workflow token don't trigger further workflow runs, and can't touch workflow files.workflows: write, so anyone copying it got a dead workflow; the "workflows: writeis required" note now explains the PAT scope instead.test_workflow_permissions_use_known_scopesasserts everypermissions:scope is one GitHub knows (verified: it fails on the old file, passes now), and CI runsactionlintso invalid workflows are reported before they are pushed.Verification
uvx --from actionlint-py==1.7.12.25 actionlint→ clean, exit 0uv run pytest -q→ 808 passed;pre-commit run --all-files(ruff, mypy) → Passed/dotbotprobe on a scratch PR to confirm Act starts and resolves the act model fromDOTBOT_ACT_MODEL(the org value is~deepseek/deepseek-flash-latest)