⚒️ Generated with [Fabro](https://fabro.sh)
This commit is contained in:
Fabro 2026-03-15 15:01:29 -04:00
parent 7a5a4528ca
commit cf10ad1ac8
3 changed files with 51 additions and 0 deletions

34
graph.fabro Normal file
View file

@ -0,0 +1,34 @@
digraph ImplementAndSimplify {
graph [
goal="Implement and simplify",
model_stylesheet="
* { backend: api; model: claude-opus-4-6;}
"
]
rankdir=LR
start [shape=Mdiamond, label="Start"]
exit [shape=Msquare, label="Exit"]
toolchain [label="Toolchain", shape=parallelogram, script="command -v cargo >/dev/null || { curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && sudo ln -sf $HOME/.cargo/bin/* /usr/local/bin/; }; cargo --version 2>&1", max_retries=0]
preflight_compile [label="Preflight Compile", shape=parallelogram, script="cargo check 2>&1", max_retries=0]
preflight_lint [label="Preflight Lint", shape=parallelogram, script="cargo clippy -- -D warnings 2>&1", max_retries=0]
fix_lints [label="Fix Lints", prompt="The preflight lint step failed. Read the build output from context and fix all clippy lint warnings.", max_visits=3]
implement [label="Implement", prompt="Read the plan file referenced in the goal and implement every step. Make all the code changes described in the plan."]
simplify [label="Simplify", prompt="@prompts/simplify.md"]
verify [label="Verify", shape=parallelogram, script="cargo clippy -- -D warnings 2>&1 && cargo test 2>&1", goal_gate=true, retry_target="fixup"]
fixup [label="Fixup", prompt="The verify step failed. Read the build output from context and fix all clippy lint warnings and test failures.", max_visits=3]
start -> toolchain
toolchain -> preflight_compile [condition="outcome=success"]
toolchain -> exit
preflight_compile -> preflight_lint [condition="outcome=success"]
preflight_compile -> exit
preflight_lint -> implement [condition="outcome=success"]
preflight_lint -> fix_lints
fix_lints -> preflight_lint
implement -> simplify -> verify
verify -> exit [condition="outcome=success"]
verify -> fixup
fixup -> verify
}

12
manifest.json Normal file
View file

@ -0,0 +1,12 @@
{
"run_id": "01KKSDZQ2AHTFP2GQAQQW25MNP",
"workflow_name": "ImplementAndSimplify",
"goal": "# Plan: Inject GitHub App IAT into Sandbox as GITHUB_TOKEN\n\n## Context\n\nWorkflow authors need `gh` CLI (and other GitHub-authenticated tools) to work inside sandboxes. Like GitHub Actions, we'll mint a short-lived Installation Access Token (IAT) from our GitHub App with user-declared permissions and inject it as `GITHUB_TOKEN`.\n\n## Target UX\n\n**workflow.toml:**\n```toml\n[github]\npermissions = { contents = \"write\", pull_requests = \"read\", issues = \"write\" }\n```\n\n**fabro.toml (project-wide defaults):**\n```toml\n[github]\npermissions = { contents = \"read\" }\n```\n\nWorkflow-level `[github]` replaces project-level (not merged) — same as `[pull_request]`.\n\n## Decisions\n\n- **Token refresh:** Deferred. Mint once at startup for V1.\n- **Preflight check:** Yes — mint during preflight to validate credentials/permissions.\n- **Approach:** Red/green TDD.\n\n## Changes\n\n### 1. `run_config.rs` — Add `GitHubConfig` struct + wire through config\n\n- New struct:\n ```rust\n #[derive(Clone, Debug, Default, Deserialize, PartialEq, Serialize)]\n pub struct GitHubConfig {\n pub permissions: HashMap<String, String>,\n }\n ```\n- Add `pub github: Option<GitHubConfig>` to `WorkflowRunConfig` and `RunDefaults`\n- In `apply_defaults()`: `if self.github.is_none() { self.github = defaults.github.clone(); }`\n- In `merge_overlay()`: `if overlay.github.is_some() { self.github = overlay.github; }`\n\n### 2. `project_config.rs` — Add `github` to `ProjectConfig`\n\n- Add `pub github: Option<GitHubConfig>` field\n- Add to `into_run_defaults()`: `github: self.github`\n- Import `GitHubConfig` from run_config\n\n### 3. `fabro-github/src/lib.rs` — Make `create_installation_access_token_with_permissions` pub\n\n- Change `async fn` → `pub async fn` (line 114)\n\n### 4. `run.rs` — Mint token and inject into sandbox env\n\n- Add `mint_github_token()` helper\n- After building `sandbox_env`, check `run_cfg.github.permissions`, mint + insert `GITHUB_TOKEN`\n- Add preflight check that mints a token to validate\n\n### 5. Tests (red/green TDD)\n\n- `run_config.rs`: parse `[github]`, `apply_defaults` fallthrough, `merge_overlay`\n- `project_config.rs`: parse `[github]` in fabro.toml, `into_run_defaults`\n\n## Files\n\n1. `lib/crates/fabro-workflows/src/cli/run_config.rs`\n2. `lib/crates/fabro-workflows/src/cli/project_config.rs`\n3. `lib/crates/fabro-github/src/lib.rs`\n4. `lib/crates/fabro-workflows/src/cli/run.rs`\n",
"start_time": "2026-03-15T19:01:29.060954Z",
"node_count": 10,
"edge_count": 13,
"run_branch": "fabro/run/01KKSDZQ2AHTFP2GQAQQW25MNP",
"base_sha": "891a6db29bf35007d664b08e511dc52fc62fa879",
"base_branch": "main",
"workflow_slug": "implement"
}

5
sandbox.json Normal file
View file

@ -0,0 +1,5 @@
{
"provider": "daytona",
"working_directory": "/home/daytona/workspace",
"identifier": "fabro-01KKSDZQ2AHTFP2GQAQQW25MNP"
}