Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
55e00871f9 | ||
|
|
eeae1fdaaa | ||
|
|
7abbbb1b8d | ||
|
|
95bc254640 | ||
|
|
75a2493dee | ||
|
|
53ac2b7ba8 | ||
|
|
4b73d0b8e9 |
+47
-18
@@ -5,6 +5,10 @@ name: agent
|
||||
on:
|
||||
workflow_call:
|
||||
|
||||
# Pinned opencode version — used to install it and to key the CI cache below.
|
||||
env:
|
||||
OPENCODE_VERSION: "1.17.13"
|
||||
|
||||
jobs:
|
||||
|
||||
agent:
|
||||
@@ -44,17 +48,6 @@ jobs:
|
||||
# job must never hold the single runner slot for hours.
|
||||
timeout-minutes: 45
|
||||
steps:
|
||||
- name: Acknowledge with 👀
|
||||
env:
|
||||
GT: ${{ secrets.GITEA_TOKEN }}
|
||||
CID: ${{ github.event.comment.id }}
|
||||
NUM: ${{ github.event.issue.number }}
|
||||
run: |
|
||||
B="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}/issues"
|
||||
if [ -n "$CID" ]; then R="$B/comments/$CID/reactions"; else R="$B/$NUM/reactions"; fi
|
||||
curl -sS -X POST -H "Authorization: token $GT" -H "Content-Type: application/json" \
|
||||
"$R" -d '{"content":"eyes"}' -w '\nreact -> HTTP %{http_code}\n' || true
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
@@ -119,12 +112,44 @@ jobs:
|
||||
TOKEN_INTERN: ${{ secrets.TOKEN_INTERN }}
|
||||
run: bash "$SCRIPTS/route.sh"
|
||||
|
||||
- name: Acknowledge with 👀 (as the routed agent)
|
||||
if: steps.prep.outputs.mode != 'skip'
|
||||
env:
|
||||
SELF_TOKEN: ${{ steps.prep.outputs.name == 'pm' && secrets.TOKEN_PM || steps.prep.outputs.name == 'junior' && secrets.TOKEN_JUNIOR || steps.prep.outputs.name == 'senior' && secrets.TOKEN_SENIOR || steps.prep.outputs.name == 'lead' && secrets.TOKEN_LEAD || steps.prep.outputs.name == 'qa' && secrets.TOKEN_QA || steps.prep.outputs.name == 'ops' && secrets.TOKEN_OPS || steps.prep.outputs.name == 'intern' && secrets.TOKEN_INTERN || '' }}
|
||||
CID: ${{ github.event.comment.id }}
|
||||
NUM: ${{ github.event.issue.number }}
|
||||
run: |
|
||||
[ -n "$SELF_TOKEN" ] || { echo "no agent token — skipping 👀"; exit 0; }
|
||||
B="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}/issues"
|
||||
if [ -n "$CID" ]; then R="$B/comments/$CID/reactions"; else R="$B/$NUM/reactions"; fi
|
||||
curl -sS -X POST -H "Authorization: token $SELF_TOKEN" -H "Content-Type: application/json" \
|
||||
"$R" -d '{"content":"eyes"}' -w '\nreact -> HTTP %{http_code}\n' || true
|
||||
|
||||
- name: Cache opencode CLI
|
||||
if: steps.prep.outputs.mode != 'skip'
|
||||
continue-on-error: true # a cache backend hiccup must never fail an agent run
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: ~/.opencode
|
||||
key: opencode-${{ runner.os }}-${{ env.OPENCODE_VERSION }}
|
||||
|
||||
- name: Cache Playwright browsers + npm (browser agents only)
|
||||
if: steps.prep.outputs.mode != 'skip' && (steps.prep.outputs.name == 'senior' || steps.prep.outputs.name == 'lead' || steps.prep.outputs.name == 'qa')
|
||||
continue-on-error: true
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: |
|
||||
~/.cache/ms-playwright
|
||||
~/.npm
|
||||
key: playwright-npm-${{ runner.os }}-v1
|
||||
|
||||
- name: Install opencode + provider config (+ Playwright MCP for browser agents)
|
||||
if: steps.prep.outputs.mode != 'skip'
|
||||
env:
|
||||
SCRIPTS: ${{ runner.temp }}/agents-scripts
|
||||
OLLAMA_URL: ${{ secrets.OLLAMA_URL }}
|
||||
OLLAMA_CLOUD_API_KEY: ${{ secrets.OLLAMA_CLOUD_API_KEY }}
|
||||
XAI_API_KEY: ${{ secrets.XAI_API_KEY }}
|
||||
NAME: ${{ steps.prep.outputs.name }}
|
||||
SKILLS: ${{ steps.prep.outputs.skills }} # JSON array of skills this agent may load
|
||||
run: bash "$SCRIPTS/install-opencode.sh"
|
||||
@@ -188,6 +213,7 @@ jobs:
|
||||
env:
|
||||
SCRIPTS: ${{ runner.temp }}/agents-scripts
|
||||
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
XAI_API_KEY: ${{ secrets.XAI_API_KEY }}
|
||||
# SELF_TOKEN = the RUNNING agent's OWN token (TOKEN_PM for @pm, TOKEN_OPS for @ops, …).
|
||||
# Only this agent's token is placed in its process env, so no agent can act as another.
|
||||
# Powers the gitea-api / gitea-admin skills — each agent calls Gitea as itself. Every
|
||||
@@ -266,24 +292,27 @@ jobs:
|
||||
run: bash "$SCRIPTS/rescue-pr.sh" || true
|
||||
|
||||
- name: Mark done with 🚀 (remove 👀)
|
||||
if: steps.prep.outputs.mode != 'skip'
|
||||
env:
|
||||
GT: ${{ secrets.GITEA_TOKEN }}
|
||||
SELF_TOKEN: ${{ steps.prep.outputs.name == 'pm' && secrets.TOKEN_PM || steps.prep.outputs.name == 'junior' && secrets.TOKEN_JUNIOR || steps.prep.outputs.name == 'senior' && secrets.TOKEN_SENIOR || steps.prep.outputs.name == 'lead' && secrets.TOKEN_LEAD || steps.prep.outputs.name == 'qa' && secrets.TOKEN_QA || steps.prep.outputs.name == 'ops' && secrets.TOKEN_OPS || steps.prep.outputs.name == 'intern' && secrets.TOKEN_INTERN || '' }}
|
||||
CID: ${{ github.event.comment.id }}
|
||||
NUM: ${{ github.event.issue.number }}
|
||||
run: |
|
||||
[ -n "$SELF_TOKEN" ] || exit 0
|
||||
B="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}/issues"
|
||||
if [ -n "$CID" ]; then R="$B/comments/$CID/reactions"; else R="$B/$NUM/reactions"; fi
|
||||
curl -sS -X DELETE -H "Authorization: token $GT" -H "Content-Type: application/json" "$R" -d '{"content":"eyes"}' || true
|
||||
curl -sS -X POST -H "Authorization: token $GT" -H "Content-Type: application/json" "$R" -d '{"content":"rocket"}' -w '\nreact -> HTTP %{http_code}\n' || true
|
||||
curl -sS -X DELETE -H "Authorization: token $SELF_TOKEN" -H "Content-Type: application/json" "$R" -d '{"content":"eyes"}' || true
|
||||
curl -sS -X POST -H "Authorization: token $SELF_TOKEN" -H "Content-Type: application/json" "$R" -d '{"content":"rocket"}' -w '\nreact -> HTTP %{http_code}\n' || true
|
||||
|
||||
- name: Mark failed with 😕 (remove 👀)
|
||||
if: failure()
|
||||
if: failure() && steps.prep.outputs.mode != 'skip'
|
||||
env:
|
||||
GT: ${{ secrets.GITEA_TOKEN }}
|
||||
SELF_TOKEN: ${{ steps.prep.outputs.name == 'pm' && secrets.TOKEN_PM || steps.prep.outputs.name == 'junior' && secrets.TOKEN_JUNIOR || steps.prep.outputs.name == 'senior' && secrets.TOKEN_SENIOR || steps.prep.outputs.name == 'lead' && secrets.TOKEN_LEAD || steps.prep.outputs.name == 'qa' && secrets.TOKEN_QA || steps.prep.outputs.name == 'ops' && secrets.TOKEN_OPS || steps.prep.outputs.name == 'intern' && secrets.TOKEN_INTERN || '' }}
|
||||
CID: ${{ github.event.comment.id }}
|
||||
NUM: ${{ github.event.issue.number }}
|
||||
run: |
|
||||
[ -n "$SELF_TOKEN" ] || exit 0
|
||||
B="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}/issues"
|
||||
if [ -n "$CID" ]; then R="$B/comments/$CID/reactions"; else R="$B/$NUM/reactions"; fi
|
||||
curl -sS -X DELETE -H "Authorization: token $GT" -H "Content-Type: application/json" "$R" -d '{"content":"eyes"}' || true
|
||||
curl -sS -X POST -H "Authorization: token $GT" -H "Content-Type: application/json" "$R" -d '{"content":"confused"}' -w '\nreact -> HTTP %{http_code}\n' || true
|
||||
curl -sS -X DELETE -H "Authorization: token $SELF_TOKEN" -H "Content-Type: application/json" "$R" -d '{"content":"eyes"}' || true
|
||||
curl -sS -X POST -H "Authorization: token $SELF_TOKEN" -H "Content-Type: application/json" "$R" -d '{"content":"confused"}' -w '\nreact -> HTTP %{http_code}\n' || true
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
"desc": "Senior dev — complex, multi-file implementation (GLM-5.2 via Ollama Cloud, text-only)."
|
||||
},
|
||||
"lead": {
|
||||
"model": "anthropic/claude-opus-4-8",
|
||||
"model": "xai/grok-4.5",
|
||||
"vision": true,
|
||||
"mode": "pr",
|
||||
"skills": [
|
||||
|
||||
@@ -26,3 +26,9 @@ jq -rs '
|
||||
"### comment by \($who):\n\(.body | gsub("\\s*<!-- 🤖 agent reply — do not trigger -->"; ""))\n"' \
|
||||
/tmp/thread_pages.json > /tmp/thread.md 2>/dev/null || : > /tmp/thread.md
|
||||
echo "thread comments fetched: $(grep -c '^### comment by ' /tmp/thread.md 2>/dev/null || echo 0) (newest 100 kept)"
|
||||
|
||||
# Record the newest comment id on the thread BEFORE the agent runs. publish.sh compares against
|
||||
# it to detect an agent that self-posted its reply mid-run (via the gitea-api skill, despite the
|
||||
# prompt telling it not to) and skips the duplicate framework reply. Ids are monotonic — no dates.
|
||||
jq -rs '[ (add // [])[].id ] | max // 0' /tmp/thread_pages.json > /tmp/thread_max_cid 2>/dev/null || echo 0 > /tmp/thread_max_cid
|
||||
echo "pre-run newest comment id: $(cat /tmp/thread_max_cid)"
|
||||
|
||||
@@ -1,15 +1,22 @@
|
||||
#!/usr/bin/env bash
|
||||
# Install opencode + provider config (+ Playwright MCP for browser agents).
|
||||
#
|
||||
# Required env (provided by the workflow step): OLLAMA_URL OLLAMA_CLOUD_API_KEY NAME SKILLS
|
||||
# GITHUB_PATH HOME
|
||||
# Required env (provided by the workflow step): OLLAMA_URL OLLAMA_CLOUD_API_KEY XAI_API_KEY
|
||||
# NAME SKILLS GITHUB_PATH HOME
|
||||
set -eu
|
||||
|
||||
# PIN the opencode version: an unpinned `latest` means a breaking release (CLI flags, or the
|
||||
# --format json event schema that build-activity-log.sh parses) breaks every agent in every repo
|
||||
# at once. Bump deliberately by changing this default (or set OPENCODE_VERSION in the step env).
|
||||
OPENCODE_VERSION="${OPENCODE_VERSION:-1.17.13}"
|
||||
curl -fsSL https://opencode.ai/install | bash -s -- --version "$OPENCODE_VERSION"
|
||||
# Skip the download when a cache hit already restored the pinned binary (see the Cache
|
||||
# opencode CLI step in agent.yml). The installer always re-fetches otherwise.
|
||||
OC_BIN="$HOME/.opencode/bin/opencode"
|
||||
if [ -x "$OC_BIN" ] && "$OC_BIN" --version 2>/dev/null | grep -qF "$OPENCODE_VERSION"; then
|
||||
echo "opencode $OPENCODE_VERSION already present (cache hit) — skipping install"
|
||||
else
|
||||
curl -fsSL https://opencode.ai/install | bash -s -- --version "$OPENCODE_VERSION"
|
||||
fi
|
||||
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
|
||||
mkdir -p ~/.config/opencode
|
||||
# Playwright browser MCP only for agents that need to drive a web app
|
||||
@@ -35,15 +42,18 @@ PERM=$(jq -nc --argjson s "$SKILLS" '
|
||||
# The provider `models:` maps are DERIVED from agents.json (the single source of truth, shared with
|
||||
# route.sh) so every model an agent is routed to is always declared in the provider config.
|
||||
# `ollama-cloud/` prefix models go to the cloud provider; `ollama/` prefix models go to the local
|
||||
# provider. Built-in providers (e.g. `anthropic/claude-opus-4-8` for @lead) are not derived here.
|
||||
# provider. `xai/` prefix models go to the xAI provider (OpenAI-compatible, https://api.x.ai/v1).
|
||||
# Built-in providers (e.g. `anthropic/claude-opus-4-8` for @ops) are not derived here.
|
||||
# See issue #31.
|
||||
AGENTS_JSON="${SCRIPTS:-$(dirname -- "$0")}/agents.json"
|
||||
CLOUD_MODELS=$(jq -r '[.[] | .model | select(startswith("ollama-cloud/")) | sub("^ollama-cloud/";"")] | map({(.):{}}) | add // {}' "$AGENTS_JSON")
|
||||
LOCAL_MODELS=$(jq -r '[.[] | .model | select(startswith("ollama/")) | sub("^ollama/";"")] | map({(.):{}}) | add // {"ornith:35b":{}}' "$AGENTS_JSON")
|
||||
jq -n --argjson mcp "$MCP" --argjson perm "$PERM" --argjson cloud "$CLOUD_MODELS" --argjson local "$LOCAL_MODELS" --arg url "$OLLAMA_URL" --arg ckey "$OLLAMA_CLOUD_API_KEY" '{
|
||||
XAI_MODELS=$(jq -r '[.[] | .model | select(startswith("xai/")) | sub("^xai/";"")] | map({(.):{}}) | add // {}' "$AGENTS_JSON")
|
||||
jq -n --argjson mcp "$MCP" --argjson perm "$PERM" --argjson cloud "$CLOUD_MODELS" --argjson local "$LOCAL_MODELS" --argjson xai "$XAI_MODELS" --arg url "$OLLAMA_URL" --arg ckey "$OLLAMA_CLOUD_API_KEY" --arg xkey "$XAI_API_KEY" '{
|
||||
provider: {
|
||||
ollama: {npm:"@ai-sdk/openai-compatible", options:{baseURL:($url+"/v1")}, models:$local},
|
||||
"ollama-cloud": {npm:"@ai-sdk/openai-compatible", options:{baseURL:"https://ollama.com/v1", apiKey:$ckey}, models:$cloud}
|
||||
"ollama-cloud": {npm:"@ai-sdk/openai-compatible", options:{baseURL:"https://ollama.com/v1", apiKey:$ckey}, models:$cloud},
|
||||
xai: {npm:"@ai-sdk/openai-compatible", options:{baseURL:"https://api.x.ai/v1", apiKey:$xkey}, models:$xai}
|
||||
},
|
||||
permission: $perm,
|
||||
mcp: $mcp
|
||||
|
||||
@@ -195,7 +195,31 @@ if [ "$MODE" != "pr" ]; then
|
||||
done < /tmp/subtasks.txt
|
||||
subtext=$(printf '\n\n---\nCreated sub-issues%s (mention an agent on each when ready):%b' "${ms:+ under milestone **$ms**}" "$links")
|
||||
fi
|
||||
post "$(printf '%s%s%s' "$msg" "$subtext" "$activity")"
|
||||
# DEDUP GUARD (issue: @pm double-posts its report). Prompt-level "do not self-post" is ignored
|
||||
# by some models, so enforce it here: if the agent ALREADY posted a comment on this thread
|
||||
# during the run (any comment by $NAME newer than the pre-run newest id from fetch-thread.sh),
|
||||
# its self-post IS the reply — skip the duplicate framework comment. Markers (CLOSE_ISSUE,
|
||||
# DELEGATE, MERGE_PR, subtasks) were already processed above and are unaffected.
|
||||
# FAIL OPEN: if the pre-run marker is missing (fetch-thread hiccup), pre_cid=0 would make the
|
||||
# agent's comments from PREVIOUS runs count as self-posts and wrongly suppress the reply.
|
||||
# Without the marker, skip the guard and post normally.
|
||||
pre_cid=$(cat /tmp/thread_max_cid 2>/dev/null || echo "")
|
||||
selfposts=0
|
||||
if [ -n "$pre_cid" ]; then
|
||||
: > /tmp/all_comments.json
|
||||
for pg in $(seq 1 10); do
|
||||
cpg=$(curl -sS "${hdr[@]}" "$API/issues/$NUM/comments?limit=50&page=$pg" 2>/dev/null) || cpg='[]'
|
||||
cn=$(printf '%s' "$cpg" | jq 'if type=="array" then length else 0 end' 2>/dev/null || echo 0)
|
||||
[ "${cn:-0}" -gt 0 ] && printf '%s\n' "$cpg" >> /tmp/all_comments.json
|
||||
[ "${cn:-0}" -lt 50 ] && break
|
||||
done
|
||||
selfposts=$(jq -rs --arg n "$NAME" --argjson c "${pre_cid:-0}" '[ (add // [])[] | select(.user.login==$n) | select(.id > $c) ] | length' /tmp/all_comments.json 2>/dev/null || echo 0)
|
||||
fi
|
||||
if [ "${selfposts:-0}" -gt 0 ]; then
|
||||
echo "agent @$NAME already posted ${selfposts} comment(s) on #$NUM during this run — skipping duplicate framework reply"
|
||||
else
|
||||
post "$(printf '%s%s%s' "$msg" "$subtext" "$activity")"
|
||||
fi
|
||||
|
||||
# --- @pm autopilot merge: @pm is the ONLY agent that merges, and ONLY under the autopilot label ---
|
||||
# (@qa never merges — it approves and hands back here.) Merge with the PAT (TTOK), not the built-in
|
||||
|
||||
@@ -149,6 +149,12 @@ ${LEARN}
|
||||
shown by Gitea. Do NOT begin your reply with your own name, an '@${NAME}' header, or a '🤖/🔨 @you'
|
||||
line; just write the content directly.
|
||||
|
||||
Do NOT use the gitea-api skill to post your reply, report, or any comment on THIS thread
|
||||
yourself. The automation already posts your reply exactly once — self-posting it too is what
|
||||
creates the duplicate comments you must avoid. On this thread, use gitea-api only to READ, or to
|
||||
take an explicit action you were asked for (add/remove a label, close the issue, merge the PR).
|
||||
Your report or answer IS your reply text — write it as your reply; do not post it via the API.
|
||||
|
||||
TEAM ROSTER (who does what — hand off if a task isn't yours):
|
||||
${ROSTER}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user