You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reported symptoms: 0% coverage for both AWF Firewall and MCP Gateway across all 18 sampled runs
Issues Identified:
parse: true is not a valid parameter for the logs MCP tool — causes the tool call to fail with Unknown parameter 'parse'
The artifacts array was ["usage", "agent", "detection"] — missing firewall (needed for access.log) and mcp (needed for gateway.jsonl / rpc-messages.jsonl)
Because the artifact sets for firewall and MCP were never requested, those log files were never downloaded, so the analysis correctly reported 0% coverage — but the root cause was the missing artifact types, not an actual infrastructure problem.
The push was rejected because GitHub Actions does not have workflows permission to push these changes, and is never allowed to make such changes, or other authorization being used does not have this permission.
Create the pull request manually
# Download the patch from the workflow run
gh run download 28761720561 -n agent -D /tmp/agent-28761720561
# Create a new branch
git checkout -b q/fix-observability-artifact-downloads-fc3e2df5b18ae4ad main
# Apply the patch (--3way handles cross-repo patches)
git am --3way /tmp/agent-28761720561/aw-q-fix-observability-artifact-downloads.patch
# Push the branch and create the pull request
git push origin q/fix-observability-artifact-downloads-fc3e2df5b18ae4ad
gh pr create --title '[q] fix(observability): add firewall and mcp artifacts, remove invalid parse param' --base main --head q/fix-observability-artifact-downloads-fc3e2df5b18ae4ad --repo github/gh-aw
🎩 Equipped by Q · 51.3 AIC · ⌖ 8.64 AIC · ⊞ 8K · ◷ Comment /q to run again
Q Workflow Optimization Report
Issues Found (from live data)
daily-observability-report
parse: trueis not a valid parameter for thelogsMCP tool — causes the tool call to fail withUnknown parameter 'parse'artifactsarray was["usage", "agent", "detection"]— missingfirewall(needed foraccess.log) andmcp(needed forgateway.jsonl/rpc-messages.jsonl)Because the artifact sets for firewall and MCP were never requested, those log files were never downloaded, so the analysis correctly reported 0% coverage — but the root cause was the missing artifact types, not an actual infrastructure problem.
Changes Made
daily-observability-report (
.github/workflows/daily-observability-report.md)Both
logscall examples (broad fetch + targeted follow-up) updated:parse: trueparameter"firewall"artifact set → downloadsaccess.logfor firewall-enabled runs"mcp"artifact set → downloadsgateway.jsonlandrpc-messages.jsonlfor MCP-enabled runsExpected Improvements
access.logwill now be downloaded for firewall-enabled runs → firewall coverage > 0%gateway.jsonl/rpc-messages.jsonlwill now be downloaded for MCP-enabled runs → MCP gateway coverage > 0%parseparameter removed → logs calls will no longer fail on parameter validationValidation
All modified workflows compiled successfully:
daily-observability-reportNote:
.lock.ymlfile will be regenerated automatically after merge.References
all, activation, agent, detection, experiment, firewall, github-api, mcp, usageWarning
Protected Files — Push Permission Denied
This was originally intended as a pull request, but the patch modifies protected files. A human must create the pull request manually.
Protected files
The push was rejected because GitHub Actions does not have
workflowspermission to push these changes, and is never allowed to make such changes, or other authorization being used does not have this permission.Create the pull request manually