Skip to content

Queue team-memory updates through Java Pack - #1106

Merged
Changyong Gong (chagong) merged 2 commits into
mainfrom
chagong-project-explorer-queued-memory
Oct 10, 2026
Merged

Changyong Gong (chagong) merged 2 commits into
mainfrom
chagong-project-explorer-queued-memory

Conversation

@chagong

@chagong Changyong Gong (chagong) commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Replace the direct team-memory agent invocation in .github/workflows/team-memory-post-merge.yml with microsoft/IssueLens/.github/actions/queue-team-memory@a81d2d96167fc0e69ac631c2edc85f858e693289, targeting microsoft/vscode-java-pack, team-memory-coordinator.yml, and main explicitly.
  • Preserve the existing source opt-in and default-branch push trigger. Require the canonical source repository, push, matching workflow/head SHAs, and non-created/non-deleted/non-forced pushes. Pass exactly five string inputs: source_repository, source_run_id, source_run_attempt, push_before, and push_after.
  • Mint a dispatch installation token using actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 (v3.2.0), with client-id, restricted to Java Pack with Contents read and Actions write; the source GITHUB_TOKEN has no permissions. No source checkout, artifact, helper copy, Azure login, or agent invocation remains.
  • Remove the local manual direct-invocation path. This PR changes only the workflow; all public documentation additions have been removed per user direction. Issue triage, policies, extension behavior, and repository documentation are unchanged.

The coordinator owns shared queueing, source/run/range validation, IssueLens invocation, and final wiki-maintenance validation. push_before is an authorized reconciliation ancestor, not attested original-event provenance. Dispatch acceptance does not imply queue admission or maintenance completion; the shared dispatcher performs one bounded POST without retries and reports ambiguous outcomes explicitly.

For manual merged-PR maintenance, use Run workflow on Java Pack's team-memory-coordinator.yml with source_repository=microsoft/vscode-java-dependency and pull_request_number set to the merged PR. Leave automatic run/attempt and before/after inputs empty. There is no local direct-invocation bypass.

Rollout prerequisites — configure before merging with the source opt-in enabled

During initial preparation, the existing ISSUELENS_TEAM_MEMORY_ENABLED variable was present; its live value was not inspected or changed. Merging while it is true immediately switches the source caller to queue dispatch.

  • Source dispatch authentication: at initial preparation, the proposed repository variable ISSUELENS_DISPATCH_APP_CLIENT_ID and secret ISSUELENS_DISPATCH_APP_PRIVATE_KEY were absent from the read-only repository name listings. Provide a dedicated dispatch App installed only on microsoft/vscode-java-pack with Contents read and Actions write. Do not reuse the hosted IssueLens App credentials or central source-read credentials.
  • Central external-source authentication: the coordinating rollout investigation found Java Pack lacked ISSUELENS_SOURCE_READ_APP_CLIENT_ID and ISSUELENS_SOURCE_READ_APP_PRIVATE_KEY. Separately configure the central source-read App with Actions read, Contents read, and Pull requests read access to microsoft/vscode-java-dependency. The source's canonical name/ID is already allowlisted. A successful own-repository Java Pack run does not establish external-source readiness.
  • The Java Pack coordinator must remain enabled. This PR does not change any live settings, opt-ins, secrets, credentials, or receiver policy and does not enable or invoke workflows. These setup prerequisites remain in the PR description, not public repository documentation.

Validation

  • actionlint 1.7.12 .github/workflows/team-memory-post-merge.yml passed during the original workflow migration (release binary verified against published SHA-256 checksum).
  • Eleven focused offline contract tests passed against the actual pinned action schemas and dispatcher implementation during the original migration: trigger/opt-in, ordinary-push admission, unsafe/mismatched gate rejection, token permissions and scope, exact five-string payload, target-ref independence, mocked bounded single POST, explicit missing-credential failure, ambiguous-outcome/no-retry behavior, and unchanged integration surfaces.
  • The follow-up restores CONTRIBUTING.md to its exact pre-migration Git blob. The workflow Git blob is unchanged from the validated migration, YAML parsing and git diff --check passed, and self-review confirms the final changed-file set is only .github/workflows/team-memory-post-merge.yml.
  • No live token minting, dispatch, rerun, agent call, or wiki update was performed. External live readiness remains dependent on the rollout prerequisites above.

Replace the source agent invocation with the pinned standalone dispatcher and a scoped dispatch App token. Preserve the source opt-in and document source/central credential prerequisites and central manual maintenance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Restore CONTRIBUTING.md to its pre-migration content per user direction. Keep the workflow migration and safeguards unchanged; rollout prerequisites remain in the pull request description.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@chagong
Changyong Gong (chagong) merged commit 16eed35 into main Oct 10, 2026
33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants