Uh oh!
There was an error while loading. Please reload this page.
Revert sbx to 10% of agentic workflows, set gvisor to 10% - #51294
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Uh oh!
There was an error while loading. Please reload this page.
✅ Design Decision Gate 🏗️ completed the design decision gate check. No ADR enforcement needed: PR does not have the 'implementation' label and has ≤100 new lines of code in business logic directories (0 additions detected in default business logic dirs).
|
✅ Test Quality Sentinel completed test quality analysis. No test files were added or modified in this PR. Test Quality Sentinel skipped.
|
✅ PR Code Quality Reviewer completed the code quality review. Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.individual.githubcopilot.com"See Network Configuration for more information.
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅
|
There was a problem hiding this comment.
Pull request overview
Rebalances agent sandbox runtimes across workflows: 28 use docker-sbx, 28 use gVisor, and 227 use the default runtime.
Changes:
- Reverts 80 workflows from
docker-sbxto the default runtime. - Assigns gVisor to 28 workflows.
- Regenerates affected compiled lock files.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/weekly-safe-outputs-spec-review.md | Restores default runtime. |
.github/workflows/weekly-issue-summary.md | Restores default runtime. |
.github/workflows/weekly-editors-health-check.md | Restores default runtime. |
.github/workflows/weekly-blog-post-writer.md | Restores default runtime. |
.github/workflows/smoke-workflow-call.md | Restores default runtime. |
.github/workflows/smoke-workflow-call-with-inputs.md | Restores default runtime. |
.github/workflows/smoke-test-tools.md | Restores default runtime. |
.github/workflows/smoke-temporary-id.md | Restores default runtime. |
.github/workflows/smoke-pydantic.md | Restores default runtime. |
.github/workflows/smoke-otel-backends.md | Restores default runtime. |
.github/workflows/smoke-opencode.md | Restores default runtime. |
.github/workflows/smoke-multi-pr.md | Restores default runtime. |
.github/workflows/smoke-kiro.md | Restores default runtime. |
.github/workflows/smoke-goose.md | Restores default runtime. |
.github/workflows/smoke-github-claude.md | Restores default runtime. |
.github/workflows/smoke-gemini.md | Restores default runtime. |
.github/workflows/smoke-cursor.md | Restores default runtime. |
.github/workflows/smoke-crush.md | Restores default runtime. |
.github/workflows/smoke-copilot.md | Restores default runtime. |
.github/workflows/smoke-copilot-sub-agents.md | Restores default runtime. |
.github/workflows/smoke-copilot-small.md | Restores default runtime. |
.github/workflows/smoke-copilot-sdk.md | Restores default runtime. |
.github/workflows/smoke-copilot-mai.md | Restores default runtime. |
.github/workflows/smoke-copilot-auto.md | Restores default runtime. |
.github/workflows/smoke-copilot-arm.md | Restores default runtime. |
.github/workflows/smoke-copilot-aoai-entra.md | Restores default runtime. |
.github/workflows/smoke-copilot-aoai-apikey.md | Restores default runtime. |
.github/workflows/smoke-codex.md | Restores default runtime. |
.github/workflows/smoke-claude-on-copilot.md | Restores default runtime. |
.github/workflows/smoke-ci.md | Restores default runtime. |
.github/workflows/smoke-checkout-pr-dispatch.md | Restores default runtime. |
.github/workflows/smoke-call-workflow.md | Restores default runtime. |
.github/workflows/smoke-aider.md | Restores default runtime. |
.github/workflows/smoke-agent-scoped-approved.md | Restores default runtime. |
.github/workflows/smoke-agent-public-none.md | Restores default runtime. |
.github/workflows/smoke-agent-public-approved.md | Restores default runtime. |
.github/workflows/smoke-agent-all-none.md | Restores default runtime. |
.github/workflows/smoke-agent-all-merged.md | Restores default runtime. |
.github/workflows/hourly-ci-cleaner.md | Restores default runtime. |
.github/workflows/daily-yamllint-fixer.md | Restores default runtime. |
.github/workflows/daily-workflow-updater.md | Restores default runtime. |
.github/workflows/daily-vulnhunter-scan.md | Restores default runtime. |
.github/workflows/daily-token-consumption-report.md | Restores default runtime. |
.github/workflows/daily-testify-uber-super-expert.md | Restores default runtime. |
.github/workflows/daily-team-evolution-insights.md | Restores default runtime. |
.github/workflows/daily-syntax-error-quality.md | Restores default runtime. |
.github/workflows/daily-spec-coverage-kiro.md | Restores default runtime. |
.github/workflows/daily-spdd-spec-planner.md | Restores default runtime. |
.github/workflows/daily-skill-optimizer.md | Restores default runtime. |
.github/workflows/daily-sentrux-report.md | Restores default runtime. |
.github/workflows/daily-security-red-team.md | Restores default runtime. |
.github/workflows/daily-security-observability.md | Restores default runtime. |
.github/workflows/daily-secrets-analysis.md | Restores default runtime. |
.github/workflows/daily-schema-audit-cursor.md | Restores default runtime. |
.github/workflows/daily-safeoutputs-git-simulator.md | Restores default runtime. |
.github/workflows/daily-safe-outputs-conformance.md | Restores default runtime. |
.github/workflows/daily-safe-output-optimizer.md | Restores default runtime. |
.github/workflows/daily-safe-output-integrator.md | Restores default runtime. |
.github/workflows/daily-repo-chronicle.md | Restores default runtime. |
.github/workflows/daily-rendering-scripts-verifier.md | Restores default runtime. |
.github/workflows/daily-reliability-review.md | Restores default runtime. |
.github/workflows/daily-regression-audit-kiro.md | Restores default runtime. |
.github/workflows/daily-pr-review-cursor.md | Restores default runtime. |
.github/workflows/daily-performance-summary.md | Restores default runtime. |
.github/workflows/daily-observability-report.md | Restores default runtime. |
.github/workflows/daily-news.md | Restores default runtime. |
.github/workflows/daily-multi-device-docs-tester.md | Restores default runtime. |
.github/workflows/daily-model-resolution.md | Restores default runtime. |
.github/workflows/daily-model-inventory.md | Restores default runtime. |
.github/workflows/daily-mcp-concurrency-analysis.md | Restores default runtime. |
.github/workflows/daily-max-ai-credits-test.md | Restores default runtime. |
.github/workflows/daily-malicious-code-scan.md | Restores default runtime. |
.github/workflows/daily-issues-report.md | Restores default runtime. |
.github/workflows/daily-hippo-learn.md | Restores default runtime. |
.github/workflows/daily-graft-intelligence.md | Restores default runtime. |
.github/workflows/daily-go-test-stubs-aider.md | Restores default runtime. |
.github/workflows/daily-github-docs-seo-optimizer.md | Restores default runtime. |
.github/workflows/daily-geo-optimizer.md | Restores default runtime. |
.github/workflows/daily-function-namer.md | Restores default runtime. |
.github/workflows/daily-formal-spec-verifier.md | Restores default runtime. |
.github/workflows/code-simplifier.md | Assigns gVisor. |
.github/workflows/code-simplifier.lock.yml | Compiles gVisor setup. |
.github/workflows/code-scanning-fixer.md | Assigns gVisor. |
.github/workflows/cloclo.md | Assigns gVisor. |
.github/workflows/cli-version-checker.md | Assigns gVisor. |
.github/workflows/cli-consistency-checker.md | Assigns gVisor. |
.github/workflows/cli-consistency-checker.lock.yml | Compiles gVisor setup. |
.github/workflows/claude-code-user-docs-review.md | Assigns gVisor. |
.github/workflows/ci-coach.md | Assigns gVisor. |
.github/workflows/ci-coach.lock.yml | Compiles gVisor setup. |
.github/workflows/chaos-pr-bundle-fuzzer.md | Assigns gVisor. |
.github/workflows/changeset.md | Assigns gVisor. |
.github/workflows/breaking-change-checker.md | Assigns gVisor. |
.github/workflows/bot-detection.md | Assigns gVisor. |
.github/workflows/bot-detection.lock.yml | Compiles gVisor setup. |
.github/workflows/blog-auditor.md | Assigns gVisor. |
.github/workflows/aw-failure-investigator.md | Assigns gVisor. |
.github/workflows/avenger.md | Assigns gVisor. |
.github/workflows/auto-triage-issues.md | Assigns gVisor. |
.github/workflows/audit-workflows.md | Assigns gVisor. |
.github/workflows/audit-workflows.lock.yml | Compiles gVisor setup. |
.github/workflows/artifacts-summary.md | Assigns gVisor. |
.github/workflows/archivx-agentic-workflows-analyzer.md | Assigns gVisor. |
.github/workflows/archivx-agentic-workflows-analyzer.lock.yml | Compiles gVisor setup. |
.github/workflows/architecture-guardian.md | Assigns gVisor. |
.github/workflows/architecture-guardian.lock.yml | Compiles gVisor setup. |
.github/workflows/archie.md | Assigns gVisor. |
.github/workflows/approach-validator.md | Assigns gVisor. |
.github/workflows/api-consumption-report.md | Assigns gVisor. |
.github/workflows/ai-moderator.md | Assigns gVisor. |
.github/workflows/agentic-token-trend-audit.md | Assigns gVisor. |
.github/workflows/agent-persona-explorer.md | Assigns gVisor. |
.github/workflows/agent-performance-analyzer.md | Assigns gVisor. |
.github/workflows/agent-performance-analyzer.lock.yml | Compiles gVisor setup. |
.github/workflows/ace-editor.md | Assigns gVisor. |
.github/workflows/ace-editor.lock.yml | Compiles gVisor setup. |
.github/workflows/ab-testing-advisor.md | Assigns gVisor. |
.github/workflows/ab-testing-advisor.lock.yml | Compiles gVisor setup. |
Review details
Tip
Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 84/216 changed files
- Comments generated: 1
- Review effort level: Balanced
| @@ -57,8 +57,7 @@ features: | |||
| sandbox: | |||
| agent: | |||
| id: awf | |||
| runtime: docker-sbx | |||
| sudo: true | |||
| sudo: false | |||
There was a problem hiding this comment.
The runtime distribution rebalance looks correct. All 28 gvisor-added workflows correctly use sudo: false, the sbx rollbacks properly restore default settings, and the lock files are recompiled consistently. No issues found.
🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · sonnet46 · 21.9 AIC · ⌖ 7.03 AIC · ⊞ 5.5K
There was a problem hiding this comment.
Skills-Based Review 🧠
Applied /codebase-design — one observation on the gVisor install step; no blocking issues.
📋 Key Themes & Highlights
Key Themes
- Supply-chain verification gap: SHA-512 checksums are fetched from the same GCS bucket as the binaries, so they provide integrity-in-transit but not authenticity. The
packages.cloud.google.comapt repository (already in the firewall allowlist) uses GPG-signed packages and would provide stronger guarantees. - gVisor version pinned (
20250707.0) — good practice. docker systemctl restartrationale documented — good inline comment explaining why reload is insufficient.
Positive Highlights
- ✅ Clear distribution table in the PR description
- ✅ All 283 lock files recompiled successfully
- ✅
sudo: falsecorrectly set for gVisor (no privilege escalation needed) - ✅
runsc --version+docker run --runtime=runsc hello-worldsanity check in every generated step
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · sonnet46 · 36 AIC · ⌖ 7.49 AIC · ⊞ 7.1K
Comment /matt to run again
🎉 This pull request is included in a new release. Release: |
Rebalances sandbox runtime distribution across the 283 agentic workflow files. Previously sbx had been rolled out broadly (~38%); this reverts it to ~10% and establishes gvisor at ~10%.
Runtime distribution changes
docker-sbxgvisorWhat changed
runtime: docker-sbx+sudo: truefrom 80 workflows, restoring them tosudo: falsewith no explicit runtimeruntime: gvisorto 28 workflows that previously had no runtime. Usessudo: false(gvisor runs cleanly in strict mode without sudo)