Skip to content

Pin Copilot CLI default back to 1.0.83 to fix instant HTTP 400 regression in 1.0.85 - #62421

Merged
pelikhan merged 3 commits into
mainfrom
copilot/fix-http-400-on-first-request
Sep 21, 2026
Merged

pelikhan merged 3 commits into
mainfrom
copilot/fix-http-400-on-first-request

Conversation

Copilot AI commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Copilot CLI 1.0.85 returns an instant HTTP 400 "Bad Request" on the very first /responses request for some workflow shapes, failing agent runs before any tokens are consumed. Diffing compiled workflows between the last known-good release and the broken one showed the Copilot CLI version bump (1.0.80 → 1.0.85) as the only relevant change, so this reverts the default/compatible version to 1.0.83 pending an upstream fix.

Version pin revert

  • pkg/constants/version_constants.go: DefaultCopilotVersion reverted from 1.0.85 to 1.0.83, with a comment noting the regression and the issue link.
  • .github/aw/compat.json: agent-compat-v1 copilot row max-agent capped at 1.0.83 so the compat-matrix resolution path (used by already-pinned workflows) also avoids 1.0.85.
  • actions/setup/sh/install_copilot_cli.sh: baked-in DEFAULT_COPILOT_VERSION fallback synced to match via scripts/sync-compat.sh.

Tests & changelog

  • pkg/constants/version_constants_test.go updated to expect 1.0.83.
  • Added a changeset documenting the regression and the revert.

Generated workflows

  • Recompiled all workflow .lock.yml files; the only diffs are 1.0.85 → 1.0.83 version strings in the baked-in engine metadata.

…n 1.0.85

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix instant HTTP 400 on first request in Copilot CLI Pin Copilot CLI default back to 1.0.83 to fix instant HTTP 400 regression in 1.0.85 Sep 21, 2026
Copilot AI requested a review from pelikhan September 21, 2026 18:24
@pelikhan

Copy link
Copy Markdown
Collaborator

/smoke-copilot

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts in this pull request

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this issue comment. Sources say the story is developing...

…on-first-request

# Conflicts:
#	.github/workflows/daily-testify-uber-super-expert.lock.yml

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve the merge conflicts in this pull request

Merged origin/main into this branch in 7da039d.

The only conflict was .github/workflows/daily-testify-uber-super-expert.lock.yml, where main had changed the workflow's frontmatter while this branch changed the baked-in engine version. Since lock files are generated, I took main's source and re-ran make recompile, so the resulting lock file carries main's frontmatter hash with "copilot":"1.0.83".

Verified afterwards: no .lock.yml still references 1.0.85, all 299 workflows compile, and make agent-report-progress reports lock files in sync with their markdown sources.

@github-actions

Copy link
Copy Markdown
Contributor

🔧 Smoke Test: Copilot Engine — PR #62421

PR: Pin Copilot CLI default back to 1.0.83 to fix instant HTTP 400 regression in 1.0.85

✅ github tool | ✅ mcpscripts-gh | ✅ serena | ✅ playwright-cli | ✅ web-fetch | ✅ file+bash | ✅ discussion comment | ✅ build | ✅ artifact upload | ✅ discussion create | ✅ workflow dispatch | ✅ PR review tools | ✅ comment memory | ❌ sub-agent (infra pricing error) | ✅ check run | ✅ LSP function count

Overall: PASS (1 non-blocking infra failure)

cc @pelikhan @Copilot

Warning

Firewall blocked 7 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • update.googleapis.com
  • www.google.com
  • www.gstatic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "update.googleapis.com"
    - "www.google.com"
    - "www.gstatic.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · copilot · auto · 56.7 AIC · ⌖ 3.21 AIC · ⊞ 9.9K · ◷
Comment /smoke-copilot to run again
Add label smoke to run again

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Tests run in the dark
Copilot checks every line
Green light, all is well

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 7 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • update.googleapis.com
  • www.google.com
  • www.gstatic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "update.googleapis.com"
    - "www.google.com"
    - "www.gstatic.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · copilot · auto · 56.7 AIC · ⌖ 3.21 AIC · ⊞ 9.9K · ◷
Comment /smoke-copilot to run again
Add label smoke to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test: automated review submission test (COMMENT event, no approval).

Warning

Firewall blocked 7 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • update.googleapis.com
  • www.google.com
  • www.gstatic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "update.googleapis.com"
    - "www.google.com"
    - "www.gstatic.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · copilot · auto · 56.7 AIC · ⌖ 3.21 AIC · ⊞ 9.9K
Comment /smoke-copilot to run again
Add label smoke to run again

// instant HTTP 400 ("Bad Request") on the very first /responses request for some
// workflow shapes (see github/gh-aw#62363). Do not bump past 1.0.83 until that
// regression is confirmed fixed upstream.
const DefaultCopilotVersion Version = "1.0.83"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test: verifying inline review comment tooling. Confirms DefaultCopilotVersion revert to 1.0.83.

@github-actions

Copy link
Copy Markdown
Contributor

✅ This PR looks great! The Copilot SWE agent has made a focused fix for the HTTP 400 regression introduced in Copilot CLI 1.0.85. The version revert is well-documented, tests have been updated, and all related workflow lock files have been recompiled. Ready for review.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by ✅ Contribution Check · copilot · auto · 50.1 AIC · ⌖ 13.5 AIC · ⊞ 9.2K · ◷

@pelikhan
pelikhan marked this pull request as ready for review September 21, 2026 21:02
Copilot AI balanced review requested due to automatic review settings September 21, 2026 21:02
@pelikhan
pelikhan merged commit 211e201 into main Sep 21, 2026
20 checks passed
@pelikhan
pelikhan deleted the copilot/fix-http-400-on-first-request branch September 21, 2026 21:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The compatibility row remains open to automated version bumps, allowing the quarantined release to be reintroduced.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Pins Copilot CLI to 1.0.83 to avoid the reported 1.0.85 HTTP 400 regression.

Changes:

  • Downgrades the default, installer fallback, and compatibility maximum.
  • Updates tests and adds a patch changeset.
  • Regenerates affected workflow lock metadata.
File Description
pkg/​constants/​version_constants.go Pins Copilot CLI to 1.0.83.
pkg/​constants/​version_constants_test.go Updates the expected version.
actions/​setup/​sh/​install_copilot_cli.sh Updates the installer fallback.
.github/​aw/​compat.json Caps compatibility at 1.0.83.
.changeset/​patch-revert-copilot-cli-1.0.85-http400.md Documents the rollback.
.github/​workflows/​workflow-skill-extractor.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​weekly-editors-health-check.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​visual-regression-checker.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​uk-ai-operational-resilience.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​ubuntu-image-analyzer.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​squad.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​squad-plan.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​squad-game-planner.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-workflow-call.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-multi-pr.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-issues.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-copilot-small.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-copilot-sdk.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-copilot-mai.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-copilot-auto.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​smoke-checkout-pr-dispatch.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​security-compliance.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​pr-nitpick-reviewer.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​pr-description-caveman.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​objective-impact-report.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​mergefest.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​layout-spec-maintainer.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​firewall.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-trajectory-grader-implementer.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-team-status.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-spec-coverage-kiro.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-schema-audit-cursor.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-regression-audit-kiro.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-pr-review-cursor.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-model-resolution.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-malicious-code-scan.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-github-docs-seo-optimizer.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​daily-byok-ollama-test.lock.yml Regenerates Copilot version metadata.
.github/​workflows/​agent-persona-explorer.lock.yml Updates the detection-engine version metadata.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/aw/compat.json
Comment on lines +37 to 38
"max-agent": "1.0.83",
"open": true
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.20

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Copilot CLI 1.0.85 (gh-aw v0.89.17) returns instant HTTP 400 on first request, breaking agent runs

3 participants