Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[aw] Smoke Verify Release NVX Assets reported incomplete result

Closed
#8,972 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
github-actions
Domain
ci-cd, devops

Research direction

Read .github/workflows/smoke-verify-release-nvx-assets.md and the agentic-workflows guidance in .github/skills/agentic-workflows/SKILL.md, then inspect run 36050996755. Reproduce the release-asset download path and determine why the workflow cannot obtain raw files in its sandbox. Done means the workflow downloads the required assets, verifies their checksums and attestation, and reports a pass or fail rather than an infrastructure-only incomplete result.

Written by the indexing model from the issue text.

Description

agentic-workflows
Workflow Failure

Workflow: Smoke Verify Release NVX Assets
Branch: main
Run: https://github.com/github/gh-aw-firewall/actions/runs/36050996755

[!WARNING]
Task Could Not Be Completed: The agent reported that the task could not be performed due to an infrastructure or tool failure.

Reasons:

  • Sandbox network policy blocks binary asset downloads needed to verify release v0.28.25's NVX assets. gh release download produces no files (silent no-op) and gh api with Accept: application/octet-stream still returns JSON metadata instead of raw bytes (proxied via localhost:18443/api/v3), while direct requests to github.com/CDN download URLs are denied by the firewall ("Permission denied and could not request permission from user").

    Confirmed via gh CLI only (no other network tools used), per task instructions:

  1. gh release view --repo github/gh-aw-firewall --json tagName -q .tagName resolved tag v0.28.25 (no release-event context was provided to this run, so latest was used per workflow-dispatch fallback).
  2. Confirmed via gh api repos/github/gh-aw-firewall/releases/tags/v0.28.25 that all three required assets exist in the release: nvx-test-x86_64.tar.gz (id 586077866, size 137576921), nvx-test-x86_64.manifest.json (id 586077863, size 979), nvx-test-x86_64.manifest.sigstore.jsonl (id 586077890, size 10718).
  3. gh release download v0.28.25 --repo github/gh-aw-firewall --pattern '...' --dir <tmpdir> --clobber exits 0 but writes zero files.
  4. gh api -H "Accept: application/octet-stream" repos/github/gh-aw-firewall/releases/assets/<id> returns HTTP 200 with Content-Type: application/json (the metadata JSON, not raw binary content) even though a valid release asset ID was targeted — this indicates the CLI/proxy used in this sandbox does not follow the asset-download redirect to the binary blob.
  5. Attempts to reach the browser_download_url (github.com/.../releases/download/...) directly via curl were denied by the sandbox firewall ("Permission denied and could not request permission from user"), as expected/by design — this environment restricts egress to api.github.com only.

Net effect: I could not extract the tarball, read the manifest.json, compute sha256sums, or run gh attestation verify (step 4 requires the local manifest.json and .sigstore.jsonl files, neither of which could be fetched with real byte content). No pass/fail verdict on the NVX asset fix (PR #8965) could be produced this run because the required raw files never reached the sandbox — this is an infrastructure/tool limitation, not a finding about the release itself.

Suggested follow-up: run this workflow in the correct environment where gh release download has network egress to GitHub's release CDN, or extend the workflow's firewall allowlist to include the domains used for GitHub release asset downloads.

This is a structured incompletion signal (report_incomplete), not a real task outcome. Any other safe outputs emitted alongside this signal (e.g., comments) describe the failure state, not a completed review or action.

Action Required

Assign this issue to an agent to debug and fix the issue.

Debug with any coding agent

Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):

Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md

The failed workflow run is at https://github.com/github/gh-aw-firewall/actions/runs/36050996755
Manually invoke the agent

Debug this workflow failure using your favorite Agent CLI and the agentic-workflows prompt.

[!TIP]

Stop reporting this workflow as a failure

To stop a workflow from creating failure issues, set report-failure-as-issue: false in its frontmatter:

safe-outputs:
  report-failure-as-issue: false

Generated from Smoke Verify Release NVX Assets · copilot · 70.7 AIC · ◷

  • expires on Oct 1, 2026, 8:04 PM UTC
Dominant language
TypeScript
Stars
147
Forks
71
Avg merge
5h 38m
Merged PRs (30d)
285

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/gh-aw-firewall

All issues in github/gh-aw-firewall

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.