flagon-io/g1t

public

Git for AI scale: a forge for thousands of agents working on the same code at once.

g1t/services/work/src/plans.rs

695 lines27,053 bytesCodeBlame
//! Planning: an outcome someone wrote, turned by an agent into issues and
//! the order they have to land in.
//!
//! This service keeps the plan. The runner starts the sandbox in which an
//! agent reads the repository and writes it, and the sandbox reports back
//! with the plan's one-time token. A person then reads the proposal and
//! applies it, which opens the issues. Issues that depend on others are
//! held back and handed to a g1t agent when what they depend on has
//! merged, so that each starts from the result of the last.

use std::collections::HashMap;

use g1t_contracts::access::Capability;
use g1t_contracts::events::IssueEvent;
use g1t_contracts::repos::{GetByIdArgs, Repo, RepoPath};
use g1t_contracts::time::rfc3339;
use g1t_contracts::work::*;
use g1t_contracts::{FailureCode, Outcome, User, new_id};
use g1t_kit::now_ms;
use serde::Deserialize;
use sha2::{Digest, Sha256};
use worker::Result;
use worker::wasm_bindgen::JsValue;

use crate::rows::user;
use crate::{MAX_TITLE_CHARS, Work, valid_title};

const MAX_BRIEF_CHARS: usize = 8_000;
const MAX_PLANNED_ISSUES: usize = 12;
const MAX_BODY_CHARS: usize = 20_000;
const PLAN_PAGE: u32 = 20;
/// Planning that has not reported back in this long has failed.
const PLANNING_MINUTES: u64 = 20;
/// How many g1t agents make changes in one repository at once. The rest of
/// a plan waits its turn, which also keeps a large plan from flooding the
/// sandboxes that checks and reviews need.
const MAX_AGENTS_AT_WORK: usize = 6;

#[derive(Deserialize)]
struct PlanRow {
    id: String,
    repo_id: String,
    brief: String,
    status: PlanStatus,
    summary: Option<String>,
    issues: String,
    error: Option<String>,
    token_hash: String,
    author_id: String,
    author_name: String,
    created_at: String,
    finished_at: Option<String>,
}

impl From<PlanRow> for Plan {
    fn from(row: PlanRow) -> Self {
        // A sandbox that never reported is not still planning.
        let oldest = rfc3339(now_ms().saturating_sub(PLANNING_MINUTES * 60 * 1000));
        let abandoned = row.status == PlanStatus::Planning && row.created_at < oldest;
        Plan {
            id: row.id,
            repo_id: row.repo_id,
            brief: row.brief,
            status: if abandoned {
                PlanStatus::Failed
            } else {
                row.status
            },
            summary: row.summary.unwrap_or_default(),
            issues: serde_json::from_str(&row.issues).unwrap_or_default(),
            error: row
                .error
                .or_else(|| abandoned.then(|| "The planner did not report back.".to_owned())),
            author: user(row.author_id, row.author_name),
            created_at: row.created_at,
            finished_at: row.finished_at,
            progress: Vec::new(),
            exchanges: Vec::new(),
        }
    }
}

#[derive(Deserialize)]
struct LatestPull {
    number: u32,
    agent: String,
    status: String,
    stage: Option<String>,
    stage_detail: Option<String>,
}

/// An issue waiting for a g1t agent, as selected.
#[derive(Deserialize)]
struct QueuedRow {
    repo_id: String,
    number: u32,
    queued_by: String,
}

fn hash(token: &str) -> String {
    hex::encode(Sha256::digest(token.as_bytes()))
}

/// Tidies what an agent proposed into something that can be opened as it
/// is: bounded, with titles that are valid and dependencies that point only
/// at earlier issues.
pub(crate) fn tidy(proposed: Vec<PlannedIssue>) -> Vec<PlannedIssue> {
    let mut issues: Vec<PlannedIssue> = Vec::new();
    for issue in proposed.into_iter().take(MAX_PLANNED_ISSUES) {
        // Nothing is dropped, so that the positions later issues depend on
        // stay what the agent meant.
        let title = match valid_title(&issue.title) {
            Ok(title) => title.to_owned(),
            Err(_) => match issue.title.trim() {
                "" => "Untitled change".to_owned(),
                long => long.chars().take(MAX_TITLE_CHARS).collect(),
            },
        };
        let position = issues.len() as u32 + 1;
        let mut depends_on: Vec<u32> = issue
            .depends_on
            .into_iter()
            .filter(|earlier| (1..position).contains(earlier))
            .collect();
        depends_on.sort_unstable();
        depends_on.dedup();
        issues.push(PlannedIssue {
            title,
            body: issue.body.trim().chars().take(MAX_BODY_CHARS).collect(),
            labels: normalize_labels(&issue.labels).unwrap_or_default(),
            checks: issue
                .checks
                .into_iter()
                .map(|check| check.trim().to_owned())
                .filter(|check| !check.is_empty())
                .take(10)
                .collect(),
            files: issue.files.into_iter().take(40).collect(),
            depends_on,
            number: None,
        });
    }
    issues
}

impl Work {
    async fn plan_row(&self, id: &str) -> Result<Option<PlanRow>> {
        self.db
            .prepare("SELECT * FROM plans WHERE id = ?")
            .bind(&[id.into()])?
            .first::<PlanRow>(None)
            .await
    }

    /// Records an outcome to plan for, and returns what a sandbox needs to
    /// plan it. Needs the Write role: a plan becomes issues and agents at
    /// work, which the workspace pays for.
    pub(crate) async fn start_plan(&self, a: StartPlanArgs) -> Result<Outcome<PlanJob>> {
        let repo = match self.repo(&a.repo, &Some(a.actor.clone())).await? {
            Outcome::Ok(repo) => repo,
            Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
        };
        if let Outcome::Fail(failure) = crate::retired::writable(&repo) {
            return Ok(Outcome::Fail(failure));
        }
        if let Some(refused) = may_plan(&a.actor, &repo) {
            return Ok(refused);
        }
        let brief: String = a.brief.trim().chars().take(MAX_BRIEF_CHARS).collect();
        if brief.is_empty() {
            return Ok(Outcome::fail(
                FailureCode::Invalid,
                "Say what you want to be true when the work is done.",
            ));
        }
        let now = now_ms();
        let id = new_id("pln", now);
        let mut bytes = [0u8; 32];
        getrandom::getrandom(&mut bytes).expect("no source of randomness");
        let token = hex::encode(bytes);
        self.db
            .prepare(
                "INSERT INTO plans
                   (id, repo_id, brief, token_hash, author_id, author_name, created_at)
                 VALUES (?, ?, ?, ?, ?, ?, ?)",
            )
            .bind(&[
                id.as_str().into(),
                repo.id.as_str().into(),
                brief.as_str().into(),
                hash(&token).into(),
                a.actor.id.as_str().into(),
                a.actor.username.as_str().into(),
                rfc3339(now).into(),
            ])?
            .run()
            .await?;
        Ok(Outcome::Ok(PlanJob {
            plan_id: id,
            token,
            brief,
            repo: RepoPath {
                namespace: repo.namespace,
                name: repo.name,
            },
        }))
    }

    /// Records the plan a sandbox's agent wrote, or why it could not write
    /// one. The plan's token is the only credential.
    pub(crate) async fn report_plan(&self, a: ReportPlanArgs) -> Result<Outcome<bool>> {
        let row = self
            .plan_row(&a.plan_id)
            .await?
            .filter(|row| row.token_hash == hash(&a.token));
        let Some(row) = row else {
            return Ok(Outcome::fail(FailureCode::NotFound, "Plan not found."));
        };
        if row.status != PlanStatus::Planning {
            return Ok(Outcome::fail(
                FailureCode::Conflict,
                "This plan has already been reported.",
            ));
        }
        let issues = tidy(a.issues);
        let error = a.error.or_else(|| {
            issues
                .is_empty()
                .then(|| "The planner proposed no issues.".to_owned())
        });
        self.db
            .prepare(
                "UPDATE plans SET status = ?, summary = ?, issues = ?, error = ?, finished_at = ?
                 WHERE id = ? AND status = 'planning'",
            )
            .bind(&[
                if error.is_some() { "failed" } else { "ready" }.into(),
                a.summary.trim().into(),
                serde_json::to_string(&issues)?.into(),
                error.as_deref().map_or(JsValue::NULL, JsValue::from),
                rfc3339(now_ms()).into(),
                row.id.into(),
            ])?
            .run()
            .await?;
        Ok(Outcome::Ok(true))
    }

    pub(crate) async fn get_plan(&self, a: PlanArgs) -> Result<Outcome<Plan>> {
        let repo = match self.repo(&a.repo, &a.viewer).await? {
            Outcome::Ok(repo) => repo,
            Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
        };
        // The repos service found it for the viewer, so they can read it,
        // and whoever can read a repository can read its plans.
        Ok(
            match self
                .plan_row(&a.id)
                .await?
                .filter(|row| row.repo_id == repo.id)
            {
                Some(row) => {
                    let mut plan: Plan = row.into();
                    if plan.status == PlanStatus::Applied {
                        plan.progress = self.progress(&repo.id, &plan).await?;
                        let numbers: Vec<u32> = plan
                            .progress
                            .iter()
                            .flat_map(|item| std::iter::once(item.number).chain(item.pull))
                            .collect();
                        plan.exchanges = self.exchanges(&repo.id, &numbers).await?;
                    }
                    Outcome::Ok(plan)
                }
                None => Outcome::fail(FailureCode::NotFound, "Plan not found."),
            },
        )
    }

    /// Where each issue an applied plan opened stands now, all at once.
    async fn progress(&self, repo_id: &str, plan: &Plan) -> Result<Vec<IssueProgress>> {
        let numbers: Vec<u32> = plan.issues.iter().filter_map(|issue| issue.number).collect();
        let issues = futures_util::future::try_join_all(
            numbers.iter().map(|number| self.issue(repo_id, *number)),
        )
        .await?;
        let pulls = futures_util::future::try_join_all(numbers.iter().map(|number| async move {
            self.db
                .prepare(
                    "SELECT number, agent, status, stage, stage_detail FROM pulls
                     WHERE repo_id = ? AND issue_number = ? AND status != 'closed'
                     ORDER BY number DESC LIMIT 1",
                )
                .bind(&[repo_id.into(), (*number).into()])?
                .first::<LatestPull>(None)
                .await
        }))
        .await?;
        let open: std::collections::HashSet<u32> = issues
            .iter()
            .flatten()
            .filter(|issue| issue.state == State::Open)
            .map(|issue| issue.number)
            .collect();
        Ok(issues
            .into_iter()
            .zip(pulls)
            .filter_map(|(issue, pull)| {
                let issue = issue?;
                let blocked_by: Vec<u32> = issue
                    .blocked_by
                    .iter()
                    .copied()
                    .filter(|number| open.contains(number))
                    .collect();
                let (state, detail) = if issue.state == State::Closed {
                    match (issue.reason, issue.resolved_by) {
                        (Some(IssueReason::Completed), Some(by)) => {
                            ("landed".to_owned(), format!("Landed with #{by}."))
                        }
                        _ => ("closed".to_owned(), "Closed without landing.".to_owned()),
                    }
                } else if let Some(pull) = pull.as_ref().filter(|pull| pull.status != "merged") {
                    (
                        pull.stage.clone().unwrap_or_else(|| {
                            if pull.status == "draft" { "working" } else { "ready" }.to_owned()
                        }),
                        pull.stage_detail.clone().unwrap_or_default(),
                    )
                } else if !blocked_by.is_empty() {
                    let named: Vec<String> = blocked_by.iter().map(|n| format!("#{n}")).collect();
                    ("blocked".to_owned(), format!("Waiting for {} to land.", named.join(", ")))
                } else if issue.queued {
                    ("waiting".to_owned(), "Waiting for an agent to be free.".to_owned())
                } else {
                    ("open".to_owned(), "Nobody is working on it.".to_owned())
                };
                Some(IssueProgress {
                    number: issue.number,
                    title: issue.title,
                    state,
                    detail,
                    blocked_by,
                    pull: pull.as_ref().map(|pull| pull.number),
                    agent: pull.map(|pull| pull.agent).or(issue.agent),
                })
            })
            .collect())
    }

    pub(crate) async fn list_plans(&self, a: ViewArgs) -> Result<Outcome<Vec<Plan>>> {
        let repo = match self.repo(&a.repo, &a.viewer).await? {
            Outcome::Ok(repo) => repo,
            Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
        };
        // Found for the viewer: they can read it, and so its plans.
        let rows = self
            .db
            .prepare("SELECT * FROM plans WHERE repo_id = ? ORDER BY id DESC LIMIT ?")
            .bind(&[repo.id.into(), PLAN_PAGE.into()])?
            .all()
            .await?
            .results::<PlanRow>()?;
        Ok(Outcome::Ok(rows.into_iter().map(Plan::from).collect()))
    }

    /// Opens a plan's issues. Each depends on the issues the plan said it
    /// does, by their new numbers. With `assign`, every one is queued for a
    /// g1t agent: those that depend on nothing are ready at once, and the
    /// rest as what they depend on merges.
    pub(crate) async fn apply_plan(&self, a: ApplyPlanArgs) -> Result<Outcome<Plan>> {
        let repo = match self.repo(&a.repo, &Some(a.actor.clone())).await? {
            Outcome::Ok(repo) => repo,
            Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
        };
        if let Outcome::Fail(failure) = crate::retired::writable(&repo) {
            return Ok(Outcome::Fail(failure));
        }
        if let Some(refused) = may_plan(&a.actor, &repo) {
            return Ok(refused);
        }
        let Some(row) = self
            .plan_row(&a.id)
            .await?
            .filter(|row| row.repo_id == repo.id)
        else {
            return Ok(Outcome::fail(FailureCode::NotFound, "Plan not found."));
        };
        // Only whoever flips it from ready to applied opens the issues.
        let claimed = self
            .db
            .prepare(
                "UPDATE plans SET status = 'applied' WHERE id = ? AND status = 'ready'
                 RETURNING id AS value",
            )
            .bind(&[row.id.as_str().into()])?
            .first::<crate::rows::ValueRow>(None)
            .await?;
        if claimed.is_none() {
            return Ok(Outcome::fail(
                FailureCode::Conflict,
                "This plan is not waiting to be applied.",
            ));
        }

        let mut plan: Plan = row.into();
        // What the person kept, in the plan's order. A dependency on an
        // issue they dropped is dropped with it.
        let kept: Vec<usize> = match &a.keep {
            Some(positions) => (0..plan.issues.len())
                .filter(|index| positions.contains(&(*index as u32 + 1)))
                .collect(),
            None => (0..plan.issues.len()).collect(),
        };
        let queued_by = a
            .assign
            .then(|| serde_json::to_string(&a.actor))
            .transpose()?;
        let mut numbers: Vec<Option<u32>> = vec![None; plan.issues.len()];
        for index in kept {
            let planned = &plan.issues[index];
            let blocked_by: Vec<u32> = planned
                .depends_on
                .iter()
                .filter_map(|position| numbers.get(*position as usize - 1).copied().flatten())
                .collect();
            let number = self.next_number(&repo.id).await?;
            let now = now_ms();
            let timestamp = rfc3339(now);
            let issue_id = new_id("iss", now);
            self.db
                .prepare(
                    "INSERT INTO issues
                       (id, repo_id, number, title, body, labels, checks, blocked_by, queued_by,
                        author_id, author_name, created_at, updated_at)
                     VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)",
                )
                .bind(&[
                    issue_id.as_str().into(),
                    repo.id.as_str().into(),
                    number.into(),
                    planned.title.as_str().into(),
                    planned.body.as_str().into(),
                    serde_json::to_string(&planned.labels)?.into(),
                    serde_json::to_string(&planned.checks)?.into(),
                    serde_json::to_string(&blocked_by)?.into(),
                    queued_by.as_deref().map_or(JsValue::NULL, JsValue::from),
                    a.actor.id.as_str().into(),
                    a.actor.username.as_str().into(),
                    timestamp.as_str().into(),
                    timestamp.as_str().into(),
                ])?
                .run()
                .await?;
            if a.assign {
                self.note(
                    &repo.id,
                    number,
                    (&a.actor.id, &a.actor.username),
                    &if blocked_by.is_empty() {
                        "queued this for g1t-agent".to_owned()
                    } else {
                        format!(
                            "queued this for g1t-agent, to start once {} {} merged",
                            blocked_by
                                .iter()
                                .map(|number| format!("#{number}"))
                                .collect::<Vec<_>>()
                                .join(", "),
                            if blocked_by.len() == 1 { "has" } else { "have" }
                        )
                    },
                )
                .await?;
            }
            self.publish(
                "issue.opened",
                &repo.id,
                &a.actor,
                IssueEvent {
                    issue_id,
                    repo_id: repo.id.clone(),
                    number,
                    title: Some(planned.title.clone()),
                    ..IssueEvent::default()
                },
            )
            .await?;
            numbers[index] = Some(number);
        }
        for (issue, number) in plan.issues.iter_mut().zip(&numbers) {
            issue.number = *number;
        }
        self.db
            .prepare("UPDATE plans SET issues = ? WHERE id = ?")
            .bind(&[
                serde_json::to_string(&plan.issues)?.into(),
                plan.id.as_str().into(),
            ])?
            .run()
            .await?;
        plan.status = PlanStatus::Applied;
        Ok(Outcome::Ok(plan))
    }

    /// Queues an issue for a g1t agent, which needs the Write role, or
    /// takes it out of the queue, as whoever may change the issue.
    pub(crate) async fn queue_issue(&self, a: QueueIssueArgs) -> Result<Outcome<bool>> {
        let issue = match self.manageable_issue(&a.actor, &a.repo, a.number).await? {
            Outcome::Ok(issue) => issue,
            Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
        };
        if a.queued {
            let repo = match self.repo(&a.repo, &Some(a.actor.clone())).await? {
                Outcome::Ok(repo) => repo,
                Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
            };
            if let Outcome::Fail(failure) = crate::allowed(Some(&a.actor), &repo, Capability::Run) {
                return Ok(Outcome::Fail(failure));
            }
        }
        let queued_by = a
            .queued
            .then(|| serde_json::to_string(&a.actor))
            .transpose()?;
        self.db
            .prepare("UPDATE issues SET queued_by = ? WHERE id = ?")
            .bind(&[
                queued_by.as_deref().map_or(JsValue::NULL, JsValue::from),
                issue.id.as_str().into(),
            ])?
            .run()
            .await?;
        Ok(Outcome::Ok(true))
    }

    /// Takes the issues that are waiting for a g1t agent and can be given
    /// one now: open, queued, with nobody working on them, and with
    /// everything they depend on closed. Oldest first, in one repository or
    /// in all, and no more than leaves each repository with
    /// `MAX_AGENTS_AT_WORK` agents making changes at once.
    ///
    /// Taking an issue takes it out of the queue, in one statement, so two
    /// callers cannot both start an agent on it. A caller that then cannot
    /// start one puts it back with `queue_issue`.
    pub(crate) async fn ready_issues(&self, a: ReadyIssuesArgs) -> Result<Vec<ReadyIssue>> {
        let rows = self
            .db
            .prepare(
                "SELECT repo_id, number, queued_by FROM issues
                 WHERE state = 'open' AND queued_by IS NOT NULL
                   AND (?1 IS NULL OR repo_id = ?1)
                   AND NOT EXISTS (
                     SELECT 1 FROM pulls
                     WHERE pulls.issue_id = issues.id AND pulls.status IN ('draft', 'open'))
                   AND NOT EXISTS (
                     SELECT 1 FROM json_each(issues.blocked_by) AS blocker
                     JOIN issues AS earlier
                       ON earlier.repo_id = issues.repo_id AND earlier.number = blocker.value
                     WHERE earlier.state = 'open')
                 ORDER BY number LIMIT 50",
            )
            .bind(&[a.repo_id.map_or(JsValue::NULL, JsValue::from)])?
            .all()
            .await?
            .results::<QueuedRow>()?;
        let mut ready = Vec::new();
        let mut room: HashMap<String, usize> = HashMap::new();
        for row in rows {
            let Ok(actor) = serde_json::from_str::<User>(&row.queued_by) else {
                continue;
            };
            // How many more agents this repository has room for.
            if !room.contains_key(&row.repo_id) {
                // An archived or deleted repository's issues stay queued,
                // untaken, for when it is writable again.
                if !self.repo_active(&row.repo_id).await? {
                    room.insert(row.repo_id.clone(), 0);
                    continue;
                }
                let working = self
                    .db
                    .prepare(
                        "SELECT count(*) AS n FROM pulls
                         WHERE repo_id = ? AND managed = 1 AND status = 'draft'",
                    )
                    .bind(&[row.repo_id.as_str().into()])?
                    .first::<crate::rows::NumberRow>(None)
                    .await?
                    .map_or(0, |row| row.n as usize);
                room.insert(
                    row.repo_id.clone(),
                    MAX_AGENTS_AT_WORK.saturating_sub(working),
                );
            }
            let left = room.get_mut(&row.repo_id).expect("just inserted");
            if *left == 0 {
                continue;
            }
            let taken = self
                .db
                .prepare(
                    "UPDATE issues SET queued_by = NULL
                     WHERE repo_id = ? AND number = ? AND queued_by IS NOT NULL
                     RETURNING id AS value",
                )
                .bind(&[row.repo_id.as_str().into(), row.number.into()])?
                .first::<crate::rows::ValueRow>(None)
                .await?;
            if taken.is_none() {
                continue;
            }
            *left -= 1;
            // Whoever queued it could see the repository then; where it is
            // now is asked as them.
            let repo: Outcome<Repo> = g1t_kit::call(
                &self.repos,
                "get_by_id",
                &GetByIdArgs {
                    id: row.repo_id.clone(),
                    viewer: Some(actor.clone()),
                },
            )
            .await?;
            if let Outcome::Ok(repo) = repo {
                ready.push(ReadyIssue {
                    repo: RepoPath {
                        namespace: repo.namespace,
                        name: repo.name,
                    },
                    number: row.number,
                    actor,
                });
            }
        }
        Ok(ready)
    }
}

/// Refuses whoever may not plan work in `repo`: the Write role, verified.
fn may_plan<T>(actor: &User, repo: &Repo) -> Option<Outcome<T>> {
    if !actor.verified {
        return Some(Outcome::fail(FailureCode::Forbidden, crate::UNVERIFIED));
    }
    match crate::allowed(Some(actor), repo, Capability::Run) {
        Outcome::Ok(()) => None,
        Outcome::Fail(failure) => Some(Outcome::Fail(failure)),
    }
}

#[cfg(test)]
mod tests {
    use super::*;

    fn proposed(title: &str, depends_on: &[u32]) -> PlannedIssue {
        PlannedIssue {
            title: title.to_owned(),
            body: "  What to do.  ".to_owned(),
            labels: vec!["Feature".to_owned()],
            checks: vec![" cargo test ".to_owned(), String::new()],
            files: vec!["src/lib.rs".to_owned()],
            depends_on: depends_on.to_vec(),
            number: None,
        }
    }

    #[test]
    fn a_proposal_is_trimmed_and_normalised() {
        let issues = tidy(vec![proposed("  Add a flag  ", &[])]);
        assert_eq!(issues[0].title, "Add a flag");
        assert_eq!(issues[0].body, "What to do.");
        assert_eq!(issues[0].labels, ["feature"]);
        assert_eq!(issues[0].checks, ["cargo test"]);
    }

    #[test]
    fn an_issue_can_only_depend_on_earlier_ones() {
        let issues = tidy(vec![
            proposed("First", &[2]),
            proposed("Second", &[1, 1, 2, 9]),
            proposed("Third", &[2, 1]),
        ]);
        assert!(issues[0].depends_on.is_empty());
        assert_eq!(issues[1].depends_on, [1]);
        assert_eq!(issues[2].depends_on, [1, 2]);
    }

    #[test]
    fn a_plan_is_bounded() {
        let many = (0..30)
            .map(|i| proposed(&format!("Issue {i}"), &[]))
            .collect();
        assert_eq!(tidy(many).len(), MAX_PLANNED_ISSUES);
    }
}