Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Issues and pull requests replace intents and attempts | 1 | //! Runs a coding agent on one pull request and reports back to g1t. |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 2 | //! |
| Issues and pull requests replace intents and attempts | 3 | //! This is the program a hosted sandbox starts. It clones the pull |
| 4 | //! request's fork, runs the agent harness headless, streams what the agent | |
| 5 | //! does into the pull request's session as it happens, pushes the result | |
| 6 | //! and marks the pull request ready for review. It talks to g1t only through the public API and git, exactly | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 7 | //! as an agent on someone's own machine would. |
| 8 | //! | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 9 | //! `MODE` selects another job instead: `checks` runs acceptance checks, |
| 10 | //! `update` brings a pull request up to date with its target branch, | |
| 11 | //! `review` has an agent review one, and `revise` sends the author back to | |
| 12 | //! address what the checks or a review found, `plan` turns an outcome | |
| Agents and memory, checks and conflicts, profiles, slug renames, custom domains | 13 | //! into issues, `queue` builds and checks a state of the merge queue, |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 14 | //! `mergecheck` finds out whether a pull request merges cleanly, |
| Merge branch 'worktree-agent-ac5b181a013e54348' | 15 | //! `actions` runs one job of a GitHub Actions workflow, `backup` cuts a |
| 16 | //! repository's nightly backup bundle, and `bump` makes a | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 17 | //! security update: one package raised in its lockfiles, pushed as g1t. |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 18 | //! See the modules of those names. |
| Acceptance checks in sandboxes, line comments and review verdicts | 19 | //! |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 20 | //! Configuration comes from the environment: |
| 21 | //! | |
| 22 | //! - `G1T_API`, `G1T_TOKEN`, `G1T_USER`: where and who to report as. | |
| Issues and pull requests replace intents and attempts | 23 | //! - `G1T_REPO`, `PULL_NUMBER`, `GIT_REMOTE`: the pull request and its fork. |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 24 | //! - `PROMPT`: what the agent is asked to do. |
| 25 | //! - `COMMIT_MESSAGE`: used if the agent leaves changes uncommitted. | |
| 26 | //! - `ANTHROPIC_API_KEY`: read by the harness itself. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 27 | //! |
| 28 | //! Every mode runs with the mining watch in `abuse`: a sandbox that looks | |
| 29 | //! like it is mining stops itself and exits with `abuse::EXIT_CODE`. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 30 | //! |
| 31 | //! Given a command instead (`register`, `run`, `service`, `remove`, | |
| 32 | //! `update`, `version`), it is a self-hosted runner on someone's own | |
| 33 | //! machine, which runs work in these modes: see `selfhosted`. | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 34 | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 35 | mod abuse; |
| GitHub Actions on g1t, part two: running workflows | 36 | mod actions; |
| Merge branch 'worktree-agent-ac5b181a013e54348' | 37 | mod backup; |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 38 | mod bump; |
| Acceptance checks in sandboxes, line comments and review verdicts | 39 | mod checks; |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 40 | mod clone; |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 41 | mod confidence; |
| Deployments: a preview for every pull request, production on g1t.page | 42 | mod deploy; |
| Merge branch 'main' into actions-toolkit-oidc-artifacts | 43 | mod docker; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 44 | mod guard; |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 45 | mod harness; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 46 | mod learned; |
| Agents and memory, checks and conflicts, profiles, slug renames, custom domains | 47 | mod mergecheck; |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 48 | mod plan; |
| Agents and memory, checks and conflicts, profiles, slug renames, custom domains | 49 | mod progress; |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 50 | mod queue; |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 51 | mod reply; |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 52 | mod report; |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 53 | mod review; |
| 54 | mod revise; | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 55 | mod selfhosted; |
| Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request | 56 | mod steer; |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 57 | mod update; |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 58 | |
| 59 | use std::path::Path; | |
| 60 | use std::process::Command; | |
| 61 | ||
| 62 | use anyhow::{Context, Result, bail}; | |
| 63 | use base64::Engine; | |
| 64 | use base64::engine::general_purpose::STANDARD; | |
| 65 | ||
| 66 | use report::{Entry, Reporter}; | |
| 67 | ||
| Acceptance checks in sandboxes, line comments and review verdicts | 68 | pub(crate) const WORKDIR: &str = "/work/repo"; |
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 69 | /// The name and address on every commit g1t makes here, whether its agent |
| 70 | /// or g1t itself: `g1t_contracts::system::{USERNAME, EMAIL}`. | |
| 71 | pub(crate) const AUTHOR_NAME: &str = "g1t"; | |
| 72 | pub(crate) const AUTHOR_EMAIL: &str = "g1t@users.noreply.g1t.sh"; | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 73 | |
| Acceptance checks in sandboxes, line comments and review verdicts | 74 | pub(crate) fn env(name: &str) -> Result<String> { |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 75 | std::env::var(name).with_context(|| format!("{name} is not set")) |
| 76 | } | |
| 77 | ||
| 78 | /// Runs git and returns its trimmed output, failing on a non-zero exit. | |
| Acceptance checks in sandboxes, line comments and review verdicts | 79 | pub(crate) fn git(dir: &Path, args: &[&str]) -> Result<String> { |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 80 | let output = Command::new("git") |
| 81 | .current_dir(dir) | |
| 82 | .args(args) | |
| 83 | .output() | |
| 84 | .context("could not run git")?; | |
| 85 | if !output.status.success() { | |
| 86 | bail!( | |
| 87 | "git {} failed: {}", | |
| 88 | args.first().unwrap_or(&""), | |
| 89 | String::from_utf8_lossy(&output.stderr).trim() | |
| 90 | ); | |
| 91 | } | |
| 92 | Ok(String::from_utf8_lossy(&output.stdout).trim().to_owned()) | |
| 93 | } | |
| 94 | ||
| 95 | /// A git option that authenticates one command. The credential is passed | |
| 96 | /// per command and never written to the clone's config or its remote URL, | |
| 97 | /// where the agent would find it. | |
| Acceptance checks in sandboxes, line comments and review verdicts | 98 | pub(crate) fn auth_option(user: &str, token: &str) -> String { |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 99 | let credentials = STANDARD.encode(format!("{user}:{token}")); |
| 100 | format!("http.extraHeader=Authorization: Basic {credentials}") | |
| 101 | } | |
| 102 | ||
| Agents as a team: lifecycle, merge queue, billing and a new shell | 103 | /// Clones the fork, runs the agent on `PROMPT`, commits and pushes what it |
| 104 | /// did, and returns its closing summary. | |
| 105 | pub(crate) fn run(reporter: &mut Reporter) -> Result<String> { | |
| 106 | let mut prompt = env("PROMPT")?; | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 107 | let remote = env("GIT_REMOTE")?; |
| 108 | let auth = auth_option(&env("G1T_USER")?, &env("G1T_TOKEN")?); | |
| 109 | let workdir = Path::new(WORKDIR); | |
| 110 | ||
| Merge branch 'model-routing' | 111 | // Which model, and why: the router's one line names both. |
| 112 | let reason = std::env::var("AGENT_MODEL_REASON").unwrap_or_default(); | |
| 113 | if !reason.trim().is_empty() { | |
| 114 | reporter.record(Entry::new("note", reason.trim())); | |
| 115 | } else if let Ok(model) = std::env::var("AGENT_MODEL_NAME") { | |
| Show the model behind each choice; toolchains in the sandbox | 116 | reporter.record(Entry::new("note", &format!("Running on {model}."))); |
| 117 | } | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 118 | reporter.record(Entry::new("prompt", &prompt)); |
| 119 | reporter.flush(); | |
| 120 | ||
| 121 | std::fs::create_dir_all("/work")?; | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 122 | clone::clone(Path::new("/work"), &auth, &[], &remote, WORKDIR).context("could not clone the pull request's fork")?; |
| g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent | 123 | git(workdir, &["config", "user.name", crate::AUTHOR_NAME])?; |
| 124 | git(workdir, &["config", "user.email", crate::AUTHOR_EMAIL])?; | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 125 | let branch = git(workdir, &["rev-parse", "--abbrev-ref", "HEAD"])?; |
| 126 | let start = git(workdir, &["rev-parse", "HEAD"]).unwrap_or_default(); | |
| 127 | ||
| Agents as a team: lifecycle, merge queue, billing and a new shell | 128 | // Sent back to work that is already open: start from where the branch it |
| 129 | // will land on is now, so what passes here passes there too. | |
| 130 | if let (Ok(upstream), Ok(upstream_branch)) = (env("UPSTREAM_REMOTE"), env("UPSTREAM_BRANCH")) { | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 131 | clone::fetch(workdir, &auth, &upstream, &upstream_branch).context("could not fetch the branch this will land on")?; |
| 132 | // Shallow: deep enough to tell whether it is behind, and to merge. | |
| 133 | clone::share_history(workdir, &auth, &[("origin", branch.as_str()), (upstream.as_str(), upstream_branch.as_str())], "HEAD", "FETCH_HEAD")?; | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 134 | let behind = Command::new("git") |
| 135 | .current_dir(workdir) | |
| 136 | .args(["merge-base", "--is-ancestor", "FETCH_HEAD", "HEAD"]) | |
| 137 | .status() | |
| 138 | .is_ok_and(|status| !status.success()); | |
| 139 | if behind { | |
| 140 | let message = format!("Catch up with {upstream_branch}"); | |
| 141 | let merged = Command::new("git") | |
| 142 | .current_dir(workdir) | |
| 143 | .args(["merge", "--quiet", "--no-edit", "-m", &message, "FETCH_HEAD"]) | |
| 144 | .status() | |
| 145 | .is_ok_and(|status| status.success()); | |
| 146 | if merged { | |
| 147 | reporter.record(Entry::new( | |
| 148 | "note", | |
| 149 | &format!("Merged in the latest {upstream_branch} before starting."), | |
| 150 | )); | |
| 151 | } else { | |
| 152 | let files = git(workdir, &["diff", "--name-only", "--diff-filter=U"])?; | |
| 153 | let files: Vec<&str> = files.lines().collect(); | |
| 154 | reporter.record(Entry::new( | |
| 155 | "note", | |
| 156 | &format!( | |
| 157 | "Merged in the latest {upstream_branch} before starting; {} conflict.", | |
| 158 | files.join(", ") | |
| 159 | ), | |
| 160 | )); | |
| 161 | prompt.push_str(&format!( | |
| 162 | "\n\nBefore you started, the latest {upstream_branch} was merged into this branch, and these files conflict: {}. Resolve the conflicts first, keeping what both sides meant, then address the points above. Leave no conflict markers.", | |
| 163 | files.join(", ") | |
| 164 | )); | |
| 165 | } | |
| 166 | reporter.flush(); | |
| 167 | } | |
| 168 | } | |
| 169 | ||
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 170 | // The agent is asked what it learned, which goes to memory, and how sure |
| 171 | // it is of its change, which g1t weighs with what it observes. Neither | |
| 172 | // stays in the summary. | |
| 173 | let asked = confidence::ask(&learned::ask(&prompt)); | |
| 174 | let summary = confidence::finish(learned::finish(harness::run_claude(workdir, &asked, reporter)?)); | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 175 | |
| 176 | // Commit whatever the agent left in the working tree. | |
| 177 | if !git(workdir, &["status", "--porcelain"])?.is_empty() { | |
| 178 | let message = std::env::var("COMMIT_MESSAGE").unwrap_or_else(|_| "Agent changes".into()); | |
| 179 | git(workdir, &["add", "--all"])?; | |
| 180 | git(workdir, &["commit", "--quiet", "--message", &message])?; | |
| 181 | } | |
| 182 | let head = git(workdir, &["rev-parse", "HEAD"])?; | |
| 183 | if head == start { | |
| Agents asked while not at work are woken to answer | 184 | // An agent woken to answer usually only answers. |
| 185 | if std::env::var("MODE").as_deref() == Ok("answer") { | |
| 186 | return Ok(summary); | |
| 187 | } | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 188 | bail!("the agent finished without changing anything"); |
| 189 | } | |
| 190 | git( | |
| 191 | workdir, | |
| 192 | &[ | |
| 193 | "-c", | |
| 194 | &auth, | |
| 195 | "push", | |
| 196 | "--quiet", | |
| 197 | "origin", | |
| 198 | &format!("HEAD:{branch}"), | |
| 199 | ], | |
| 200 | ) | |
| Issues and pull requests replace intents and attempts | 201 | .context("could not push the pull request's commits")?; |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 202 | reporter.record(Entry::new( |
| 203 | "note", | |
| Issues and pull requests replace intents and attempts | 204 | &format!("Pushed {}.", &head[..head.len().min(12)]), |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 205 | )); |
| 206 | Ok(summary) | |
| 207 | } | |
| 208 | ||
| 209 | fn main() { | |
| Merge branch 'main' into actions-toolkit-oidc-artifacts | 210 | // The runc the job's Docker Engine starts containers with (docker/oci.rs). |
| 211 | if docker::oci::invoked_as_runc() { | |
| 212 | docker::oci::main(); | |
| 213 | } | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 214 | // A self-hosted runner's commands; the modes below are what it, and |
| 215 | // g1t's sandboxes, run work with. | |
| 216 | let args: Vec<String> = std::env::args().skip(1).collect(); | |
| 217 | if selfhosted::is_command(&args) { | |
| 218 | std::process::exit(selfhosted::main(args)); | |
| 219 | } | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 220 | // A guarded sandbox's HTTPS is re-signed on its way out: trust that |
| 221 | // before anything is fetched. The guard hook runs before every tool | |
| 222 | // call, so it skips this. | |
| 223 | if std::env::var("MODE").as_deref() == Ok("guard") { | |
| 224 | std::process::exit(guard::hook_main()); | |
| 225 | } | |
| 226 | guard::trust_egress_ca(); | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 227 | // Watches for mining for as long as the sandbox runs (abuse.rs). Not in |
| 228 | // the hooks the harness runs after every tool call. | |
| 229 | if std::env::var("MODE").as_deref() != Ok("steer") { | |
| 230 | abuse::watch(); | |
| 231 | } | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 232 | // The same image does the other jobs a sandbox is started for. |
| 233 | match std::env::var("MODE").as_deref() { | |
| GitHub Actions on g1t, part two: running workflows | 234 | Ok("actions") => std::process::exit(actions::main()), |
| Merge branch 'worktree-agent-ac5b181a013e54348' | 235 | Ok("backup") => std::process::exit(backup::main()), |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 236 | Ok("bump") => std::process::exit(bump::main()), |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 237 | Ok("checks") => std::process::exit(checks::main()), |
| Deployments: a preview for every pull request, production on g1t.page | 238 | Ok("deploy") => std::process::exit(deploy::main()), |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 239 | Ok("update") => std::process::exit(update::main()), |
| 240 | Ok("review") => std::process::exit(review::main()), | |
| 241 | Ok("revise") => std::process::exit(revise::main()), | |
| Agents asked while not at work are woken to answer | 242 | Ok("answer") => std::process::exit(revise::answer()), |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 243 | Ok("plan") => std::process::exit(plan::main()), |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 244 | Ok("reply") => std::process::exit(reply::main()), |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 245 | Ok("queue") => std::process::exit(queue::main()), |
| Agents and memory, checks and conflicts, profiles, slug renames, custom domains | 246 | Ok("mergecheck") => std::process::exit(mergecheck::main()), |
| Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request | 247 | Ok("steer") => std::process::exit(steer::main()), |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 248 | _ => {} |
| Acceptance checks in sandboxes, line comments and review verdicts | 249 | } |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 250 | let mut reporter = match Reporter::from_env() { |
| 251 | Ok(reporter) => reporter, | |
| 252 | Err(error) => { | |
| 253 | eprintln!("g1t-runner: {error:#}"); | |
| 254 | std::process::exit(2); | |
| 255 | } | |
| 256 | }; | |
| 257 | match run(&mut reporter) { | |
| 258 | Ok(summary) => { | |
| 259 | reporter.flush(); | |
| Issues and pull requests replace intents and attempts | 260 | if let Err(error) = reporter.ready(&summary) { |
| 261 | eprintln!("g1t-runner: could not mark the pull request ready: {error:#}"); | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 262 | std::process::exit(1); |
| 263 | } | |
| 264 | } | |
| 265 | Err(error) => { | |
| 266 | eprintln!("g1t-runner: {error:#}"); | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 267 | // Stopped at a cap: like a person's stop, the pull request is |
| 268 | // left open for a person, not closed. | |
| 269 | if guard::is_halt(&error) { | |
| 270 | reporter.record(Entry::new("note", &format!("g1t stopped the agent: {error:#}."))); | |
| 271 | reporter.flush(); | |
| 272 | std::process::exit(1); | |
| 273 | } | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 274 | reporter.record(Entry::new("note", &format!("The run failed: {error:#}"))); |
| 275 | reporter.flush(); | |
| Issues and pull requests replace intents and attempts | 276 | let _ = reporter.close(); |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 277 | std::process::exit(1); |
| 278 | } | |
| 279 | } | |
| 280 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.