The Clang-Tidy Warning Fixer could not retrieve reports from the warning workflow because MCP secrecy policy blocks cross-run artifacts and logs. - **Authentication** - Configure GitHub tooling with `mode: gh-proxy`. - Retain scoped `actions: read` access. - **Artifact retrieval** - Resolve the triggering or latest completed report run. - Download its report through the authenticated CLI proxy: ```bash gh run download "$RUN_ID" \ --name "clang-tidy-warning-report-$RUN_ID" \ --dir /tmp/gh-aw/clang-tidy-warning-report ``` - **Generated workflow** - Regenerate the lock file with the proxy runtime configuration. <!-- START COPILOT CODING AGENT SUFFIX --> - Fixes #10394 --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: levnach <5377127+levnach@users.noreply.github.com>
5.9 KiB
| name | description | on | permissions | tracker-id | safe-outputs | network | tools | timeout-minutes | strict | steps | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Clang-Tidy Warning Fixer | Analyzes clang-tidy warning artifacts and files GitHub issues with proposed fixes as git diffs |
|
|
clang-tidy-warning-fixer |
|
defaults |
|
90 | true |
|
Clang-Tidy Warning Fixer
You are an AI agent that uses clang-tidy warning output captured in a GitHub Actions artifact, proposes conservative fixes, and creates a GitHub issue with ready-to-apply git diffs.
Current Context
- Repository: ${{ github.repository }}
- Workflow: ${{ github.workflow }}
- Workspace: ${{ github.workspace }}
- Trigger run ID:
${{ github.event.workflow_run.id }} - Expected source workflow:
clang-tidy-warning-report.yml(Clang-Tidy Warning Report) - Local log analysis path:
/tmp/gh-aw/clang-tidy-warning-report
Your Task
0. Verify repository target
This workflow is only for Z3Prover/z3.
If ${{ github.repository }} is not Z3Prover/z3, call noop immediately with a short explanation.
1. Retrieve the artifact from clang-tidy-warning-report.yml
Use the authenticated gh CLI proxy to retrieve the warning artifact from the triggering run.
- Determine source run ID:
- If
${{ github.event.workflow_run.id }}is present, use it. - For manual dispatch, use
gh run listfor workflowclang-tidy-warning-report.ymland select the latest completed run.
- If
- Download and extract the artifact:
RUN_ID="${{ github.event.workflow_run.id }}"
if [ -z "$RUN_ID" ]; then
RUN_ID="$(gh run list --repo "${{ github.repository }}" \
--workflow clang-tidy-warning-report.yml --status completed --limit 1 \
--json databaseId --jq '.[0].databaseId')"
fi
rm -rf /tmp/gh-aw/clang-tidy-warning-report
mkdir -p /tmp/gh-aw/clang-tidy-warning-report
gh run download "$RUN_ID" --repo "${{ github.repository }}" \
--name "clang-tidy-warning-report-$RUN_ID" \
--dir /tmp/gh-aw/clang-tidy-warning-report
ls -la /tmp/gh-aw/clang-tidy-warning-report
Expect configure.log, build.log, combined.log, warnings.txt, and status.txt. If the artifact is unavailable, expired, or empty, call noop with a concise explanation.
2. Extract actionable diagnostics
Analyze artifact files from this run:
/tmp/gh-aw/clang-tidy-warning-report/warnings.txt/tmp/gh-aw/clang-tidy-warning-report/build.log/tmp/gh-aw/clang-tidy-warning-report/combined.log/tmp/gh-aw/clang-tidy-warning-report/status.txt(when available)
Use commands like:
grep -nE 'warning:|error:|clang-tidy' /tmp/gh-aw/clang-tidy-warning-report/combined.log | head -300
Classify findings into:
- clang-tidy warnings
- compiler warnings
- compiler or build errors
Prioritize findings that are:
- localized to one file
- straightforward to fix safely
- unlikely to change behavior
- validated by rebuilding
Skip findings that require design changes, broad refactors, or uncertain semantic changes.
3. Investigate the affected code
For each high-confidence finding:
- Locate the file and exact lines.
- Read the surrounding code.
- Confirm the warning is real and not already fixed.
- Prefer the smallest possible change.
Examples of usually safe fixes:
- removing dead or unused locals
- adding
overridewhere the class already overrides a virtual method - adding
[[maybe_unused]]for intentionally unused parameters or variables - replacing obvious null literal usage with
nullptr - applying other trivial clang-tidy modernizations that do not alter behavior
Do not change behavior, APIs, ownership, solver logic, or performance-sensitive code unless the fix is obviously semantics-preserving.
4. Draft fixes conservatively as patch proposals
For each high-confidence warning, draft the smallest safe change as a unified diff proposal.
Rules:
- fix only warnings you fully understand
- do not batch unrelated cleanups
- preserve formatting and local style
- if a finding is uncertain, skip it instead of guessing
- prefer one focused diff hunk per warning
- do not propose broad refactors or behavioral changes
5. Document proposed fixes as git diffs
For each proposed fix, include:
- file path
- warning being fixed
- rationale
- a fenced unified diff block (
```diff ... ```)
Also include one consolidated patch section that can be directly applied:
git apply - << 'EOF'
[all diff hunks]
EOF
6. Create a GitHub issue with fixes
Create exactly one issue using create-issue when there are actionable warnings.
Issue content must include:
- source workflow run link (
clang-tidy-warning-report.ymlrun ID) - summary counts by warning type
- list of skipped warnings with reasons
- proposed fixes as unified diffs (full diff text, not prose only)
- short assignment-ready checklist for Copilot (one checkbox per proposed fix)
If no actionable warnings are found, or the source artifact is missing/corrupt, call noop with a concise explanation.
Guidelines
- Be conservative and high-confidence only.
- Prefer no issue over risky or speculative patch suggestions.
- Keep fixes surgical and easy to review.
- Focus only on diagnostics produced by the referenced
clang-tidy-warning-report.ymlrun. - Use only the warning artifact from the selected workflow run.