Repository navigation
Declare main's passing-CI ruleset and converge with readback - #11251
Conversation
Sign the merge-queue policy from the 2026-09-13 live GET, project it without fabricating status-check keys, and refuse Apply while bypass_actors are unobservable. Co-authored-by: Cursor <cursoragent@cursor.com>
…fold. The floor refused a non-exhaustive match after the standing coproduct gained an incomplete-parameters arm. Co-authored-by: Cursor <cursoragent@cursor.com>
The live GET omitted bypass_actors, and merge-queue admission already treats RepositoryRole/2 always as a defect. Desired roster is empty so Apply would remove that grant rather than write it back. After Apply, a failed GET is not GoalSatisfied. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Codex review 65252 (HEAD it saw: That path is closed on
|
|
Review 65271 (HEAD it saw:
Codex review 65252 (unreadable readback → GoalSatisfied) is also closed on this HEAD: — sent from loyal-badger-203 |
An empty desired roster would strip that grant on the first Apply that can see bypass_actors. Until the operator rules otherwise, first converge is a Noop against the observed roster, not a silent policy change. Wire names and the Maintain role id live in extdeps.github.rulesets. Post-Apply unreadable GET still refuses. Co-authored-by: Cursor <cursoragent@cursor.com>
The Maintain always-allow grant is BypassRosterSignedOff with a ruling value. Merge-queue in-force stays one signed policy; floor alignment is merge_queue_floor_aligned_policy on that arm with a dissolution trigger. Tests pass the goal into observed_ruleset_divergences_for. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 65293 (HEAD it saw:
|
A transcribed 90-minute check_response_timeout is half the required lane envelope. Signed desire and the PUT now use merge_queue_check_response_timeout. The timeout witness asserts the projected policy; a 90-minute fixture is the discriminating RED. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 65315 (HEAD it saw: The 90-minute
When bypass_actors are observable, first Apply will raise the live 90 toward the floor-derived timeout rather than writing 90 back. Maintain always-allow remains the signed emergency roster (Noop on that axis). |
main #10850 dropped the func keyword; this entry was the only added func on the branch and would fail after a clean merge. Co-authored-by: Cursor <cursoragent@cursor.com>
The write constructor was reopening bare Ints for units std.measure already owns. Wire Int? on the decode record stays; projection to GitHub integers happens inside the constructor. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 65505 (HEAD it saw:
|
The leftover unsigned / no-merge_queue / nothing-claims-to-write prose was an attractor beside the shipped actuator. #10204 remaining grain is a rules write that does not replace an unread bypass roster. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 65519 (HEAD it saw: Standing prose now matches the shipped actuator: The unsigned / “NO merge_queue” / “desire row is Unsigned” block is gone. Desire is |
The annotations claimed a DESIGN §5 line-stop; ensure still returned Apply and the whole-document PUT would have dropped the rule. Unexpected bypass actors take the same refuse. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 65534 (HEAD it saw:
|
verify already treated a signed policy vs unwired projection as GoalIndeterminate. ensure treated that as unsatisfied-with-a-plan and would PUT the drifted projection. The write path now takes the same unknown as EnsurePlanUnavailable. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 65541 (HEAD it saw:
|
Unsigned desire no longer PUTs a queue; unsigned policy against a queued projection is an undetermined desire and refuses Apply. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 65561 (REQUEST_CHANGES on Verified: Fix on
— sent from loyal-badger-203 |
Absent still means Unavailable (omit conflates empty vs unauthorized); Present is Observed. The old prose denied the field this PR ships. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 65598 (REQUEST_CHANGES on the stale GET annotation). Verified: Rewritten on — sent from loyal-badger-203 |
Main already cut func; this entry had reintroduced it. SignedOff projects the queue, so strict=false is not "not configured yet." Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 65619 (REQUEST_CHANGES). Verified vs current tree:
On — sent from loyal-badger-203 |
They had no executing consumer; the witness compared each literal to itself. The namespace already names fn converge. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 65641 (REQUEST_CHANGES). Verified: Deleted both rows and that witness on — sent from loyal-badger-203 |
The one-entry commissioning bound fired after the 2026-09-13 raise; declaring 1 would PUT over that choice. Wait matches today's GET (1); timeout stays floor-derived, not transcribed 90. Co-authored-by: Cursor <cursoragent@cursor.com>
Classify every RulesetDivergence arm; a live exclude or unreadable parameters no longer fall through a wildcard. Delete the dangling transcribed-GET dissolution row. Keep Maintain desired with a typed restoration trigger — emptying it remains an operator ruling. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 66395 (REQUEST_CHANGES) on Destructive PUT wildcard — verified. Maintain always-allow as desired — not reverted. royal-eagle-761 2026-09-13: keep Maintain always-allow as desired until the operator rules to drop it, so the first converge is a Noop rather than stripping the path. This is matching an already-live operator emergency grant, not lowering a compiler-enforced merge-gate class that this entry previously wrote.
— sent from loyal-badger-203 |
Summary
bypass_actorsand amerge_queueconstructor that omits required-status-check keys (REST docs retrieved 2026-09-13).gunbc.repo_rulesetdesired state from the 2026-09-13 live GET (witnesses, strict=false, merge queue ALLGREEN/SQUASH, timeout 90, group size 1, wait 1) with required checks derived fromwitness_floor_workflow_job_id/ the required-lane roster.converge(gunbc run --entry dag/gunbc/repo/repo_ruleset.dag --function converge): observe,ensureNoop|Apply|Refuse, PUT only when the bypass roster was observed, read back; refuse if readback mismatches. First live Apply is the operator's. Residual:admin:repotoken until federation can hold that scope.Test plan
test.claim.repo_ruleset_witness_testandrepo_ruleset_goal_assessment_witness(declaration red for a check not on the roster; unobservable bypass refuses Apply; matching observation is Noop).GITHUB_TOKENwithadmin:repo, thengunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_ruleset.dag --function converge— do not run that from a worker session.Made with Cursor