[aw] Smoke Verify Release NVX Assets reported incomplete result
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
Research direction
Read .github/workflows/smoke-verify-release-nvx-assets.md and the agentic-workflows guidance in .github/skills/agentic-workflows/SKILL.md, then inspect run 36050996755. Reproduce the release-asset download path and determine why the workflow cannot obtain raw files in its sandbox. Done means the workflow downloads the required assets, verifies their checksums and attestation, and reports a pass or fail rather than an infrastructure-only incomplete result.
Written by the indexing model from the issue text.
Description
Workflow Failure
Workflow: Smoke Verify Release NVX Assets
Branch: main
Run: https://github.com/github/gh-aw-firewall/actions/runs/36050996755
[!WARNING]
Task Could Not Be Completed: The agent reported that the task could not be performed due to an infrastructure or tool failure.
Reasons:
-
Sandbox network policy blocks binary asset downloads needed to verify release v0.28.25's NVX assets. gh release download produces no files (silent no-op) and gh api with Accept: application/octet-stream still returns JSON metadata instead of raw bytes (proxied via localhost:18443/api/v3), while direct requests to github.com/CDN download URLs are denied by the firewall ("Permission denied and could not request permission from user").
Confirmed via gh CLI only (no other network tools used), per task instructions:
gh release view --repo github/gh-aw-firewall --json tagName -q .tagNameresolved tag v0.28.25 (no release-event context was provided to this run, so latest was used per workflow-dispatch fallback).- Confirmed via
gh api repos/github/gh-aw-firewall/releases/tags/v0.28.25that all three required assets exist in the release: nvx-test-x86_64.tar.gz (id 586077866, size 137576921), nvx-test-x86_64.manifest.json (id 586077863, size 979), nvx-test-x86_64.manifest.sigstore.jsonl (id 586077890, size 10718). gh release download v0.28.25 --repo github/gh-aw-firewall --pattern '...' --dir <tmpdir> --clobberexits 0 but writes zero files.gh api -H "Accept: application/octet-stream" repos/github/gh-aw-firewall/releases/assets/<id>returns HTTP 200 with Content-Type: application/json (the metadata JSON, not raw binary content) even though a valid release asset ID was targeted — this indicates the CLI/proxy used in this sandbox does not follow the asset-download redirect to the binary blob.- Attempts to reach the browser_download_url (github.com/.../releases/download/...) directly via curl were denied by the sandbox firewall ("Permission denied and could not request permission from user"), as expected/by design — this environment restricts egress to api.github.com only.
Net effect: I could not extract the tarball, read the manifest.json, compute sha256sums, or run gh attestation verify (step 4 requires the local manifest.json and .sigstore.jsonl files, neither of which could be fetched with real byte content). No pass/fail verdict on the NVX asset fix (PR #8965) could be produced this run because the required raw files never reached the sandbox — this is an infrastructure/tool limitation, not a finding about the release itself.
Suggested follow-up: run this workflow in the correct environment where gh release download has network egress to GitHub's release CDN, or extend the workflow's firewall allowlist to include the domains used for GitHub release asset downloads.
This is a structured incompletion signal (report_incomplete), not a real task outcome. Any other safe outputs emitted alongside this signal (e.g., comments) describe the failure state, not a completed review or action.
Action Required
Assign this issue to an agent to debug and fix the issue.
Debug with any coding agent
Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):
Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md
The failed workflow run is at https://github.com/github/gh-aw-firewall/actions/runs/36050996755
Manually invoke the agent
Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.
- Start your agent
- Load the
agentic-workflowsskill from.github/skills/agentic-workflows/SKILL.mdor https://github.com/github/gh-aw/blob/main/.github/skills/agentic-workflows/SKILL.md - Type
debug the agentic workflow smoke-verify-release-nvx-assets failure in https://github.com/github/gh-aw-firewall/actions/runs/36050996755
[!TIP]
Stop reporting this workflow as a failure
To stop a workflow from creating failure issues, set
report-failure-as-issue: falsein its frontmatter:safe-outputs: report-failure-as-issue: false
Generated from Smoke Verify Release NVX Assets · copilot · 70.7 AIC · ◷
- expires on Oct 1, 2026, 8:04 PM UTC
- Dominant language
- TypeScript
- Stars
- 147
- Forks
- 71
- Avg merge
- 5h 38m
- Merged PRs (30d)
- 285
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/gh-aw-firewall
-
agentic-workflows automated dependencies
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/gh-aw-firewall#3837 ·
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 4/5 3-5 days Newbie friendliness 35/100
github/gh-aw-firewall#9277 ·
Maintainers usually reply within 1 day
-
[Duplicate Code] Extract repeated CloudHypervisorManager setup in manager-cleanup testsPossibly taken @lpcox claimed this today. Opencode-quality refactoring
github/gh-aw-firewall#9274 · 1 reaction · 2 assignees ·
Maintainers usually reply within 1 day
-
[Duplicate Code] Extract shared compose fixture in capability-filter testsPossibly taken @lpcox claimed this today. Opencode-quality refactoring
github/gh-aw-firewall#9273 · 1 reaction · 2 assignees ·
Maintainers usually reply within 1 day
-
Optimizer: detect redundant tool calls and suggest --max-num-tool-calls valuesPossibly taken @lpcox claimed this today. Open
github/gh-aw-firewall#9269 · 1 reaction · 2 assignees ·
Maintainers usually reply within 1 day
All issues in github/gh-aw-firewall
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
callstackincubator/rozenite#518 ·
Maintainers usually reply within 1 day
-
Area/Workflow Priority/Blocker Type/Bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
wso2/product-integrator#2622 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
area:bash bug has repro platform:macos
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
anthropics/claude-code#98644 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
allure-framework/allure-js#1603 ·
Maintainers usually reply within 1 day