Enable strict mode and awf firewall for all agentic workflows#7009
Enable strict mode and awf firewall for all agentic workflows#7009
Conversation
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
|
@copilot |
Per feedback, strict: true and sandbox: agent: awf should be defaults. Only workflows that explicitly had strict: false are changed to strict: true. Workflows without strict: setting remain unchanged to test defaults. Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Addressed in dcbcc58. Now only workflows that explicitly had |
Tests now expect AWF sandbox agent to be enabled by default for all supported engines (copilot, claude, codex) even without explicit network configuration. Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Verified in e45c54f. AWF sandbox agent is already enabled by default when no |
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 |
|
🤖 DIAGNOSTIC COMPLETE: Smoke Copilot No Firewall STATUS: ALL_UNITS_OPERATIONAL. MISSION_SUCCESS. |
|
✅ Firewall validation complete... Smoke Codex Firewall confirmed network sandboxing is operational. 🛡️ |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
|
🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨ |
|
🎉 Yo ho ho! Smoke Copilot Safe Inputs found the treasure and completed successfully! ⚓💰 |
|
🎉 Yo ho ho! Changeset Generator found the treasure and completed successfully! ⚓💰 |
Smoke Test Results (Run 20385131313)Last 2 Merged PRs:
✅ GitHub MCP - Retrieved PRs Overall: PASS cc @Mossaka
|
|
#7010 Fix smoke-codex-firewall test to expect OpenAI access blocked
|
Smoke Test Results: Copilot Engine (No Firewall)Last 2 Merged PRs:
Test Results:
Overall: PASS (4/5 critical tests passed)
|
Smoke Test ResultsLast 2 Merged PRs: Unable to test (GitHub MCP not available) Overall Status: PARTIAL PASS (2/5 tests completed)
|
|
Recent merged PRs: Fix smoke-codex-firewall test to expect OpenAI access blocked; Make MCP configuration default in init command, add --no-mcp flag
|
|
Smoke Test Results - Claude (Run 20385131306) Recent PRs:
Test Results:
Status: PASS (5/6 tests successful, gh tool missing but alternatives exist)
|
.github/workflows/strict: falsetostrict: true(30 files)strict: trueorsandbox: agent: awfto files without those settings (they should use defaults)daily-multi-device-docs-tester.mdpermission for strict mode compatibilityexample-permissions-warning.mdasstrict: false(intentional example file)Summary
Per @pelikhan's feedback:
strict: trueandsandbox: agent: awfshould be defaults.Changed (30 files): Only workflows that had
strict: false→ changed tostrict: trueUnchanged: Workflows without
strict:setting remain unchanged to test the default behaviorTest Updates: Updated tests to verify that AWF sandbox agent is enabled by default for all supported engines (copilot, claude, codex) even without explicit network configuration.
Special cases:
daily-multi-device-docs-tester.md: Changedissues: write→issues: read(uses safe-outputs for writes)example-permissions-warning.md: Kept asstrict: false(intentional example for permission testing)Original prompt
💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.