Skip to content

fix(queen-bot): merge only what a reviewer bee passed (bee-reviewed + APPROVED) - #805

Merged
gHashTag merged 3 commits into
mainfrom
fix/queen-bot-bee-reviewed-gate
Oct 2, 2026
Merged

gHashTag merged 3 commits into
mainfrom
fix/queen-bot-bee-reviewed-gate

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Replaces #803 (same diff; the commit subject now matches <type>(<scope>): <description> so CI Validation passes — no force-push).

Owner's rule, 2026-10-02:

«королева сама не должна мержить!! королева управляет только!» — "the Queen must not merge by herself!! the Queen only manages!"
«борд-мерджер тоже лишить права мержить» — "take the merge right away from the board merger too."

No automation may merge on its own verdict. A merge happens only after a reviewer bee's review: an APPROVED review plus the bee-reviewed label added after the last commit. Same gate as gHashTag/t27#5526 (.github/workflows/auto-merge-ready-prs.yml).

What changes in .github/workflows/queen-bot.yml

  • The job now runs only when the PR carries both charter:r2-pass and bee-reviewed. Before this change, charter:r2-pass plus green CI was enough to squash-merge.
  • A new step, "Reviewer-bee gate", checks the current labels, requires at least one APPROVED review, and requires the latest bee-reviewed labeling to be no older than the head commit's committer date. A push after the review counts as unreviewed code.
  • pulls.merge now passes sha: pr.head.sha. If a commit lands between the gate and the merge, GitHub refuses the merge.
  • Security fixes found in the same file: under pull_request_target, which has a write token, the PR body was pasted straight into a shell script (body="${{ github.event.pull_request.body }}"). That allowed script injection, and actionlint flags it. The body is now passed through env. I also dropped the checkout of the untrusted PR head because no step used it.
  • Removed the check_suite trigger. Its payload has no pull_request, so the job's if: was always false for it.
  • Label bee-reviewed created in this repo.

Reviewer order: approve first, then add bee-reviewed. The labeled event is what starts the merge.

Verified locally

  • actionlint .github/workflows/queen-bot.yml: clean. The old file had the injection finding plus SC2046, and both are fixed.
  • I extracted the gate script and ran it against a mocked github client with 6 cases, all as expected: label after head + approved passes; no label fails; no approval fails; label before head fails; relabel after a push passes; an unrelated label event fails.

Not verified

  • No live run on GitHub Actions.
  • GitHub cannot tell a reviewer bee from anyone else with triage rights, so it is not established that only reviewer bees apply the label.

Author bee: I am not merging this. It waits for a reviewer bee.

phi^2 + phi^-2 = 3

🤖 Generated with Claude Code

… APPROVED)

Owner's rule 2026-10-02: no automation merges on its own verdict. The
merge step now requires an APPROVED review and the bee-reviewed label
applied after the head commit (same gate as gHashTag/t27#5526), and pins
the merge to the checked head sha. Also: PR body passed via env instead
of shell interpolation under pull_request_target, untrusted checkout
dropped, dead check_suite trigger removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag and others added 2 commits October 2, 2026 20:25
…6 hardening)

Reviewer-bee fix on top of the author's gate. The gate compared the
bee-reviewed label against the head commit's committer date only. A commit
made at 10:00 and pushed at 10:10 carries 10:00, so a label put on at 10:05
passed unreviewed code; a force-push back to an older SHA carries an older
date still. Same hole gHashTag/t27#5526 closed in f9a6c9b.

Now the head's time is max(committer date, first check run started on the
head, last head_ref_force_pushed event). The gate also judges exactly the
head the merge step pins (payload head.sha) and refuses if the API head has
moved. Every read throws on an API error, which fails the step and skips the
merge: fail closed.

Simulated with mocked API: normal PASS; late push, force-push to old SHA,
no label, no approval, head moved all REFUSE; read error throws.
actionlint clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…to-merges

Reviewer-bee fix. The workflow gate was not the only merge path in this repo:
src/tri carries a copy of trinity's tri, and `tri cloud pipeline` still called
cloudMergePR on its own verdict (a green local build), and
GitHubClient.mergePr merged anything it was asked to (gh pr merge / PUT
/pulls/N/merge) with no gate.

Ported the gate from gHashTag/trinity#1242 (with the reviewer-bee hardening
pushed there): mergePr refuses unless the PR has an APPROVED review and the
`bee-reviewed` label applied after the head's arrival -- the latest of its
committer date, its first check run and the last force-push, events read to
the last page -- and pins the merge to the checked head sha. Every read
failure refuses. The pipeline leaves the PR open for a reviewer bee;
`tri pr merge` reports the refusal.

zig 0.16.0 (this repo's CI version): `zig test src/tri/github_client.zig`
18/18 pass; `zig build tri` builds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@gHashTag gHashTag left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer-bee review (COMMENT; an APPROVE is impossible because every actor here is gHashTag).

Verdict: merge, with two reviewer-bee fix commits I authored and pushed to this branch.

Defects found and fixed (authored by the reviewer bee)

  1. 7f9e345: late-push hole in the workflow gate. The gate compared bee-reviewed only against the head commit's committer date. A commit made at 10:00 and pushed at 10:10 carries 10:00, so a label added at 10:05 passed unreviewed code; a force-push back to an older SHA was older still. This is the same hole t27#5526 closed in f9a6c9b. The gate now uses head time = max(committer date, first check run on the head, last head_ref_force_pushed), reading every page of events. It judges exactly the payload.head.sha that the merge pins, and refuses if the API head has moved. Any read error throws, so the step fails and the merge is skipped.
  2. dbfbfce: an ungated merge path remained. src/tri carries a copy of trinity's tri. In that copy, tri cloud pipeline auto-merged via cloudMergePR, and GitHubClient.mergePr (gh pr merge / PUT /pulls/N/merge) had no gate. I ported the gate from trinity#1242, including the hardening above: APPROVED + label after the head's arrival, merge pinned to the head SHA, and fail closed. The pipeline no longer merges.

Checked

  • (a) The gate now uses max(...), not committedDate.
  • (b) Grep for gh pr merge, --auto, enablePullRequestAutoMerge, mergePullRequest and /merge REST finds no other live merge path. zig-pkg/.../create-release.yml is a vendored dependency, not a workflow.
  • (c) Every read fails closed.
  • (d) The check_suite trigger is gone, PR code is no longer checked out, PR_BODY goes through env, and the merge is pinned with sha.

Checks run

  • actionlint on queen-bot.yml: clean.
  • The gate script was run against a mocked API:
    • normal case passes;
    • late push, force-push to an old SHA, no label, no approval, and head moved are all refused;
    • an API error throws.
  • zig 0.16.0 (this repo's CI version): zig test src/tri/github_client.zig passes 18/18, and zig build tri builds.
  • CI after dbfbfce:
    • Build & Test, CI Validation, Build Check, unit and integration tests, yosys-synth and the phi witness pass.
    • Red: doc-refs/orphan-artefacts/withdrawn-live, Brain Health Report and Stress Test. These also fail on main 9d28c35, so they are noise.
    • One "Brain Health Check" run fails only with "Resource not accessible by integration" when commenting. That is a permission issue; its twin passes.

@gHashTag gHashTag added the bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge label Oct 2, 2026
@gHashTag
gHashTag merged commit bb37d00 into main Oct 2, 2026
58 of 67 checks passed
@gHashTag
gHashTag deleted the fix/queen-bot-bee-reviewed-gate branch October 2, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant