Repository navigation
Add dispatch tasks for Infigraph runtime integration - #659
Conversation
Co-authored-by: wryenmeek <6856065+wryenmeek@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 89f1827e64
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "tests/analysis/test_infigraph.py" | ||
| ], | ||
| "risk": "low", | ||
| "prompt": "Implement a reproducible Infigraph runtime wrapper in `scripts/analysis/infigraph.py`.\n\n### Diagnosis\nThe knowledgebase currently lacks a wrapper to invoke the Infigraph CLI. There is no code path in `scripts/analysis` (or elsewhere) that handles Infigraph metadata resolution, startup checks, or capability analysis. As a result, the integration cannot determine if the required analysis capabilities are available or execute them reproducibly.\n\n### Proposed Implementation\nIntroduce a new module `scripts/analysis/infigraph.py` that provides:\n1. `InfigraphRelease`: A dataclass for reproducible metadata (version, checksum, resolution date).\n2. `InfigraphStatus`: An Enum defining `analysis_complete`, `analysis_unavailable`, and `analysis_failed`.\n3. `InfigraphRuntime`: A class that verifies the executable exists, runs capability checks to distinguish between unavailable, unsupported, or ready to analyze, and executes analysis commands with timeout handling and actionable failure reasons.\n\n```python\n# scripts/analysis/infigraph.py\nimport subprocess\nimport json\nimport enum\nfrom dataclasses import dataclass\nfrom typing import Optional, Dict, Any\n\nclass InfigraphStatus(enum.Enum):\n ANALYSIS_COMPLETE = \"analysis_complete\"\n ANALYSIS_UNAVAILABLE = \"analysis_unavailable\"\n ANALYSIS_FAILED = \"analysis_failed\"\n\n@dataclass\nclass InfigraphRelease:\n version: str\n checksum: str\n resolved_at: str\n\nclass InfigraphRuntime:\n def __init__(self, executable_path: str, release: InfigraphRelease):\n self.executable_path = executable_path\n self.release = release\n\n def check_capabilities(self) -> InfigraphStatus:\n try:\n result = subprocess.run(\n [self.executable_path, \"--capabilities\"],\n capture_output=True,\n text=True,\n timeout=5\n )\n if result.returncode != 0:\n return InfigraphStatus.ANALYSIS_UNAVAILABLE\n return InfigraphStatus.ANALYSIS_COMPLETE\n except FileNotFoundError:\n return InfigraphStatus.ANALYSIS_UNAVAILABLE\n except subprocess.TimeoutExpired:\n return InfigraphStatus.ANALYSIS_FAILED\n except Exception:\n return InfigraphStatus.ANALYSIS_FAILED\n\n def analyze(self, target_path: str) -> Dict[str, Any]:\n try:\n result = subprocess.run(\n [self.executable_path, \"analyze\", target_path],\n capture_output=True,\n text=True,\n timeout=30\n )\n if result.returncode != 0:\n return {\"status\": InfigraphStatus.ANALYSIS_FAILED.value, \"reason\": \"Command failed\"}\n return {\"status\": InfigraphStatus.ANALYSIS_COMPLETE.value, \"data\": json.loads(result.stdout)}\n except FileNotFoundError:\n return {\"status\": InfigraphStatus.ANALYSIS_UNAVAILABLE.value, \"reason\": \"Executable not found\"}\n except subprocess.TimeoutExpired:\n return {\"status\": InfigraphStatus.ANALYSIS_FAILED.value, \"reason\": \"Timeout\"}\n except json.JSONDecodeError:\n return {\"status\": InfigraphStatus.ANALYSIS_FAILED.value, \"reason\": \"Malformed output\"}\n```\n\n### Test Scenarios\nCreate `tests/analysis/test_infigraph.py` using a fake executable (e.g., via a temporary python script) to cover:\n1. Successful capability discovery (`analysis_complete`).\n2. Representative installation failure (executable not found).\n3. Capability failure (executable unsupported).\n4. Command failure (executable returns non-zero code).\n5. Command timeout (`analysis_failed`).\n6. Malformed JSON output (`analysis_failed`).\n\n### Requirements & Constraints\n- Do NOT introduce cross-repository graph storage or MCP integration.\n- `scripts/analysis/infigraph.py` provides the runtime contract.\n- `tests/analysis/test_infigraph.py` fully tests the capabilities using a fake executable.\n- The codebase enforces the normalized statuses.\n\n### File Boundary Rule\nYou may ONLY modify the files listed above. If a test file outside your boundary fails, you must make your source changes backward-compatible so the existing test passes unmodified. Do NOT rename, move, or delete any files outside your boundary." |
There was a problem hiding this comment.
Allow the task to update the write-surface matrix
The dispatched agent is explicitly restricted to the new module and test, but adding this executable requires updating AGENTS.md: the existing scripts/analysis/** row permits only host-local Copilot telemetry, while this wrapper executes Infigraph against a caller-supplied target. Following the boundary rule therefore produces a governance-invalid PR; include the matrix update in the task's owned files and prompt.
AGENTS.md reference: AGENTS.md:L84-L88
Useful? React with 👍 / 👎.
| "tests/analysis/test_infigraph.py" | ||
| ], | ||
| "risk": "low", | ||
| "prompt": "Implement a reproducible Infigraph runtime wrapper in `scripts/analysis/infigraph.py`.\n\n### Diagnosis\nThe knowledgebase currently lacks a wrapper to invoke the Infigraph CLI. There is no code path in `scripts/analysis` (or elsewhere) that handles Infigraph metadata resolution, startup checks, or capability analysis. As a result, the integration cannot determine if the required analysis capabilities are available or execute them reproducibly.\n\n### Proposed Implementation\nIntroduce a new module `scripts/analysis/infigraph.py` that provides:\n1. `InfigraphRelease`: A dataclass for reproducible metadata (version, checksum, resolution date).\n2. `InfigraphStatus`: An Enum defining `analysis_complete`, `analysis_unavailable`, and `analysis_failed`.\n3. `InfigraphRuntime`: A class that verifies the executable exists, runs capability checks to distinguish between unavailable, unsupported, or ready to analyze, and executes analysis commands with timeout handling and actionable failure reasons.\n\n```python\n# scripts/analysis/infigraph.py\nimport subprocess\nimport json\nimport enum\nfrom dataclasses import dataclass\nfrom typing import Optional, Dict, Any\n\nclass InfigraphStatus(enum.Enum):\n ANALYSIS_COMPLETE = \"analysis_complete\"\n ANALYSIS_UNAVAILABLE = \"analysis_unavailable\"\n ANALYSIS_FAILED = \"analysis_failed\"\n\n@dataclass\nclass InfigraphRelease:\n version: str\n checksum: str\n resolved_at: str\n\nclass InfigraphRuntime:\n def __init__(self, executable_path: str, release: InfigraphRelease):\n self.executable_path = executable_path\n self.release = release\n\n def check_capabilities(self) -> InfigraphStatus:\n try:\n result = subprocess.run(\n [self.executable_path, \"--capabilities\"],\n capture_output=True,\n text=True,\n timeout=5\n )\n if result.returncode != 0:\n return InfigraphStatus.ANALYSIS_UNAVAILABLE\n return InfigraphStatus.ANALYSIS_COMPLETE\n except FileNotFoundError:\n return InfigraphStatus.ANALYSIS_UNAVAILABLE\n except subprocess.TimeoutExpired:\n return InfigraphStatus.ANALYSIS_FAILED\n except Exception:\n return InfigraphStatus.ANALYSIS_FAILED\n\n def analyze(self, target_path: str) -> Dict[str, Any]:\n try:\n result = subprocess.run(\n [self.executable_path, \"analyze\", target_path],\n capture_output=True,\n text=True,\n timeout=30\n )\n if result.returncode != 0:\n return {\"status\": InfigraphStatus.ANALYSIS_FAILED.value, \"reason\": \"Command failed\"}\n return {\"status\": InfigraphStatus.ANALYSIS_COMPLETE.value, \"data\": json.loads(result.stdout)}\n except FileNotFoundError:\n return {\"status\": InfigraphStatus.ANALYSIS_UNAVAILABLE.value, \"reason\": \"Executable not found\"}\n except subprocess.TimeoutExpired:\n return {\"status\": InfigraphStatus.ANALYSIS_FAILED.value, \"reason\": \"Timeout\"}\n except json.JSONDecodeError:\n return {\"status\": InfigraphStatus.ANALYSIS_FAILED.value, \"reason\": \"Malformed output\"}\n```\n\n### Test Scenarios\nCreate `tests/analysis/test_infigraph.py` using a fake executable (e.g., via a temporary python script) to cover:\n1. Successful capability discovery (`analysis_complete`).\n2. Representative installation failure (executable not found).\n3. Capability failure (executable unsupported).\n4. Command failure (executable returns non-zero code).\n5. Command timeout (`analysis_failed`).\n6. Malformed JSON output (`analysis_failed`).\n\n### Requirements & Constraints\n- Do NOT introduce cross-repository graph storage or MCP integration.\n- `scripts/analysis/infigraph.py` provides the runtime contract.\n- `tests/analysis/test_infigraph.py` fully tests the capabilities using a fake executable.\n- The codebase enforces the normalized statuses.\n\n### File Boundary Rule\nYou may ONLY modify the files listed above. If a test file outside your boundary fails, you must make your source changes backward-compatible so the existing test passes unmodified. Do NOT rename, move, or delete any files outside your boundary." |
There was a problem hiding this comment.
Validate the pinned release before reporting readiness
When an incompatible or tampered Infigraph executable exits --capabilities with status 0, this proposed implementation reports ANALYSIS_COMPLETE without parsing its output or checking any required capability, version, or checksum; analyze() also bypasses the capability check entirely. Consequently the dispatched implementation cannot provide the promised reproducible runtime contract and may accept results from the wrong tool release, so the prompt should require validation of the supplied release metadata and capabilities before analysis.
Useful? React with 👍 / 👎.
Added .fleet/2026_09_24 tasks for #597 to add Infigraph runtime module and capabilities.
PR created automatically by Jules for task 2626585914012331458 started by @wryenmeek