Multi-repo pipelines: coordinated PRs across repositories (#3393) - #3418
Merged
Conversation
james-in-a-box
Bot
force-pushed
the
egg/issue-3393/work
branch
from
July 2, 2026 00:26
2d7e6d2 to
f162bf2
Compare
This was referenced Jul 2, 2026
Grounded the issue's current-state claims against the live tree (create_worktree list-shape, per-repo credentials, repo-param PR creation, Slice schema gap, repos[0] collapse sites). Four grounding corrections flagged for the planner, acceptance criteria restated, HITL decision registered for v1 merge-sequencing gate semantics. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Take ownership of 3393-analysis-human.md: verified faithful against the refiner's 3393-analysis.md (v1, 107c930) and the contract task description; removed remaining jargon and added the per-repo work-branch/ umbrella-PR point. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…e NACK) Verified live: _spawn.py:452,464, commit_authorship_store.py:932-933, and routes/pipelines.py:732 (overseer_repo). Added plain-language sweep clause. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Correction #1 un-inverted: client method IS create_worktrees (plural, gateway_client/_worktree.py:13); singular create_worktree is the gateway-internal helper (worktree_manager/_create.py:115); repo_volumes is the live spawner param fed from WorktreeResult.worktrees — rewritten as a two-layer naming map. - repos[0] collapse sites enumerated as THREE (adds routes/pipelines.py:732 overseer_repo); sdlc_hitl.py:82 cleared as guarded. Verdict row 6, correction #4, AC-4 updated; human summary 'two spots' -> 'three spots'. - Per-repo conventions entailment added (design recommendation #5 + AC-7): slice agent cwd + CLAUDE.md/linters/check commands of the slice's repo. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tions - Hard-bit #1 now states the operator's decided model: automated draft-hold auto-readied on upstream merge; HITL only for beyond-merge-state waits (release/publish, version pinning) and genuine development blocks. - Added per-repo house-rules bullet (refiner v2 design rec #5 / AC-7). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Operator resolved HITL cq-1 (merge-sequencing gate) with a two-tier model: automated draft->ready on upstream PR merge for plain merge ordering; HITL-resolved holds for beyond-merge-state conditions (release/publish waits, version pinning, genuine development blocks). Added HITL Resolution section with planner-facing consequences; updated design recommendation #2, hard part #2, AC-6, and the human summary's hard-bit #1. No new HITL decisions induced. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Reverts 3393-analysis-human.md byte-exact to the simplifier's e88c16d rendering, restoring (1) the per-repo house-rules bullet (design rec #5 / AC-7 rendering) and (2) the simplifier's hard-bit #1, which keeps the cq-1 resolution's development-blocks element. Root cause: my v3 rebase conflict resolution used 'git checkout --theirs', which in a rebase selects the replayed (stale) commit, overwriting the simplifier's concurrent v3. 3393-analysis.md is deliberately untouched (reviewers: ACK-ready). BRC memory updated with the ownership rule. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Hard-bit #3: owner/repo re-key is decided; same-name rejection ruled out; prohibitive fan-out returns to the operator, never a silent fallback. - New 'Where decisions stand' section: all design questions settled and binding; only a new operator decision reopens them. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ngs as binding Design questions section retitled to OPERATOR RULINGS (binding, same standing as cq-1): lazy-per-repo work branches/context PRs, per-slice-repo test-gate/reviewer-diff scoping, primary-repo naming + per-repo status surfaces, and per-repo conventions all RATIFIED (substance unchanged, status upgraded from recommendation). New ruling #6: worktree map MUST be re-keyed by full owner/repo; reject-same-name-sets is forbidden; prohibitive fan-out at plan time is a new HITL, never a silent fallback. Consistency-only knock-ons: correction #2 advice sentence points to the ruling (facts unchanged), AC-2 drops the same-name-rejection alternative, AC-4 requires owner/repo keying. cq-1 fold-in and grounding facts untouched; human summary untouched (simplifier-owned). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…g bullet Operator ruling (4) is 'first in list unless explicitly flagged'; the bullet had stated the stricter first-in-list-only rule (reviewer_refine NACK). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…t, repos[0] de-collapse, per-repo PR routing, cq-1 merge gate Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
7 risks; verdict PROCEED_WITH_MITIGATIONS (MEDIUM-HIGH). Load-bearing: R1 Contract has no repo dimension (Slice.repo absent=>primary unresolvable), R2 EGG_PIPELINE_REPO is a hard-required overseer consumer (collapse != deletion), R3 cq-1 merge-poll terminal/failure states unspecified. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Renders task_planner v1 (d067323): fixed-order six-step chain, the two submission safety checks, the three collapse-site fixes with owner/repo re-keying, per-repo PR routing, the cq-1 two-tier hold, and per-repo gate scoping — with the N=1 no-behavior-change guarantee stated plainly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…k_analyst R1 NACK) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…r_plan R3 NACK) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Operator re-materialization of the cq-4 resolution (option 1). The original materialization (task-4-4) was lost when the phase restart re-synced the pipeline worktree contract from a stale origin copy; slice-4 consequently converged structural-only. slice-7 (dep: slice-6) carries the wiring so coordinated cross-repo PRs work end-to-end.
james-in-a-box
Bot
force-pushed
the
egg/issue-3393/work
branch
from
July 2, 2026 19:47
b2d5528 to
bb7d0ec
Compare
jwbron
approved these changes
Jul 2, 2026
jwbron
added a commit
that referenced
this pull request
Jul 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lets a single pipeline operate across an arbitrary number of repositories and open coordinated, cross-referencing PRs — one per slice, each in that slice's repo — with cross-repo ordering expressed through the existing slice-dependency mechanism. Replaces the manual hand-off that today carves the cross-repo half of a logically-single change out of the pipeline and gives it to an engineer.
The change is built on the ratified refine analysis's verified thesis: the single-repo assumption is concentrated, not pervasive. The gateway worktree list, per-repo credentials,
create_slice_pr(repo=...), and repo-agnostic push policy already exist; the concentrated gaps are the contract's missing repo dimension and therepos[0]collapse in the agent environment.Delivered as a single serialized six-slice chain (five slices edit orchestrator/routes/pipelines.py, so per #3046 they are ordered along one dependency chain):
Slice.repo+ a pure additive schemaVersion 1.3→1.4 stamp (Slice.repo stays None on legacy load), and orchestrator-layerPipeline.repos(RepoSpec) +primary_repo+ a runtimeresolve_slice_repowhere absent⇒primary is resolved; N=1 round-trips/behaves unchanged.submit_task/POST /api/v1/pipelinesaccept a list of {repo, base_branch}) with submission-time validation rejecting mixed-visibility and mixed-auth-mode sets.repos[0]collapse sites plus a full repo→worktree map exposed to the agent environment re-keyed by fullowner/repo(operator ruling Phase 4: CLI implementation #6), guarded by a ratchet test + grep sweep.slice.repoand a lazy-per-repo work branch + context PR (every repo with ≥1 slice; PRs cross-reference siblings).Out of v1 (deferred): mixed auth modes across repos, richer merge-sequencing machinery, and cross-repo atomic merge (impossible on GitHub — v1 ships an ordering hold, not atomicity).
Test Plan
Automated (per slice;
make testnarrows to reachable suites, thenmake test-allbefore phase exit;make lintgreen throughout):Slice.repo⇒ primary repo; legacy singletonPipeline.repo⇒ one-element list; JSON round-trip; N=1 back-compat unchanged.owner/repo; all three collapse sites gone; a ratchet test asserts norepos[0]collapse reintroduced (with the len(repos)==1-guarded sdlc_hitl.py:82 explicitly allowed).slice.repo; a repo with ≥1 slice gets a work branch + context PR, a slice-less submitted repo gets neither; sibling-PR cross-reference rendered.Regression baseline: single-repo (N=1) pipelines exhibit no behavior change; existing suites stay green.
Manual Steps
Pre-merge: none.
Post-merge: the schema migration (schemaVersion 1.3→1.4) applies lazily on contract load following the four existing precedents — no manual migration of persisted contracts is required; absent
Slice.reporesolves to the pipeline's primary repo on read. New multi-repo behavior takes effect for pipelines submitted after the orchestrator image is rebuilt/redeployed on the normal release cadence. File a follow-up issue for the deferred scope: mixed auth modes across repos and any richer first-class merge-sequencing machinery beyond the v1 hold.Pipeline context
issue-3393slice-1) — [issue-3393][slice-1/6] Repo dimension in the persisted contract... #3422slice-2) — [issue-3393][slice-2/6] List-shaped submission + uniform... #3423slice-3) — [issue-3393][slice-3/6] Stop the repos[0] collapse... #3424slice-4) — [issue-3393][slice-4/6] Slice-PR routing to slice.repo + lazy... #3429slice-5) — [issue-3393][slice-5/7] Cross-repo merge-sequencing hold (cq-1... #3430slice-6) — [issue-3393][slice-6/7] Per-repo test-gate + reviewer-diff scoping... #3437slice-7) — [issue-3393][slice-7/7] Secondary-repo worktree + branch... #3442Per-phase BRC transcripts:
refine,plan,implement-unattributed.