fix(agent): run step scripts from outside the workspace so agents can't break the run
Stage the shared scripts into $RUNNER_TEMP and point $SCRIPTS there for every step, so an agent that commits/deletes the in-tree .agents-workflow checkout no longer destroys the scripts the post-agent steps run (issue #33). Scrub any in-tree .agents-workflow artifact before publishing, and add a failure-safe rescue step that opens a PR for pushed work when a run fails.
This commit is contained in:
@@ -98,6 +98,18 @@ if [ "$MODE" != "pr" ]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# Scrub the runtime scripts checkout (.agents-workflow) from the tree so it never lands in a
|
||||
# commit/PR and never confuses the git ops below (issue #33). The scripts we run live outside the
|
||||
# workspace ($SCRIPTS -> runner.temp), so removing this in-tree copy is always safe. Handle every
|
||||
# way an agent might have left it: untracked dir, tracked files, or a committed gitlink/submodule.
|
||||
if git ls-files --error-unmatch .agents-workflow >/dev/null 2>&1 || \
|
||||
[ -n "$(git ls-files .agents-workflow 2>/dev/null)" ]; then
|
||||
git rm -r --cached --quiet --ignore-unmatch .agents-workflow 2>/dev/null || true
|
||||
fi
|
||||
git config -f .gitmodules --remove-section submodule..agents-workflow 2>/dev/null || true
|
||||
[ -s .gitmodules ] || rm -f .gitmodules 2>/dev/null || true
|
||||
rm -rf .agents-workflow 2>/dev/null || true
|
||||
|
||||
# The agent may have committed on the starting branch AND/OR created extra
|
||||
# ai/issue-N-<slug> branches. Commit any leftover on the current branch, push it, then
|
||||
# open a PR for EVERY ai/issue-N* branch that has commits beyond main.
|
||||
|
||||
Reference in New Issue
Block a user