Repository navigation
fix(queen-bot): merge only what a reviewer bee passed (bee-reviewed + APPROVED) - #805
Merged
Merged
Conversation
… APPROVED) Owner's rule 2026-10-02: no automation merges on its own verdict. The merge step now requires an APPROVED review and the bee-reviewed label applied after the head commit (same gate as gHashTag/t27#5526), and pins the merge to the checked head sha. Also: PR body passed via env instead of shell interpolation under pull_request_target, untrusted checkout dropped, dead check_suite trigger removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…6 hardening) Reviewer-bee fix on top of the author's gate. The gate compared the bee-reviewed label against the head commit's committer date only. A commit made at 10:00 and pushed at 10:10 carries 10:00, so a label put on at 10:05 passed unreviewed code; a force-push back to an older SHA carries an older date still. Same hole gHashTag/t27#5526 closed in f9a6c9b. Now the head's time is max(committer date, first check run started on the head, last head_ref_force_pushed event). The gate also judges exactly the head the merge step pins (payload head.sha) and refuses if the API head has moved. Every read throws on an API error, which fails the step and skips the merge: fail closed. Simulated with mocked API: normal PASS; late push, force-push to old SHA, no label, no approval, head moved all REFUSE; read error throws. actionlint clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…to-merges Reviewer-bee fix. The workflow gate was not the only merge path in this repo: src/tri carries a copy of trinity's tri, and `tri cloud pipeline` still called cloudMergePR on its own verdict (a green local build), and GitHubClient.mergePr merged anything it was asked to (gh pr merge / PUT /pulls/N/merge) with no gate. Ported the gate from gHashTag/trinity#1242 (with the reviewer-bee hardening pushed there): mergePr refuses unless the PR has an APPROVED review and the `bee-reviewed` label applied after the head's arrival -- the latest of its committer date, its first check run and the last force-push, events read to the last page -- and pins the merge to the checked head sha. Every read failure refuses. The pipeline leaves the PR open for a reviewer bee; `tri pr merge` reports the refusal. zig 0.16.0 (this repo's CI version): `zig test src/tri/github_client.zig` 18/18 pass; `zig build tri` builds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag
commented
Oct 2, 2026
gHashTag
left a comment
Owner
Author
There was a problem hiding this comment.
Reviewer-bee review (COMMENT; an APPROVE is impossible because every actor here is gHashTag).
Verdict: merge, with two reviewer-bee fix commits I authored and pushed to this branch.
Defects found and fixed (authored by the reviewer bee)
- 7f9e345: late-push hole in the workflow gate. The gate compared
bee-reviewedonly against the head commit's committer date. A commit made at 10:00 and pushed at 10:10 carries 10:00, so a label added at 10:05 passed unreviewed code; a force-push back to an older SHA was older still. This is the same hole t27#5526 closed in f9a6c9b. The gate now uses head time = max(committer date, first check run on the head, lasthead_ref_force_pushed), reading every page of events. It judges exactly thepayload.head.shathat the merge pins, and refuses if the API head has moved. Any read error throws, so the step fails and the merge is skipped. - dbfbfce: an ungated merge path remained.
src/tricarries a copy of trinity's tri. In that copy,tri cloud pipelineauto-merged viacloudMergePR, andGitHubClient.mergePr(gh pr merge/PUT /pulls/N/merge) had no gate. I ported the gate from trinity#1242, including the hardening above: APPROVED + label after the head's arrival, merge pinned to the head SHA, and fail closed. The pipeline no longer merges.
Checked
- (a) The gate now uses max(...), not committedDate.
- (b) Grep for
gh pr merge,--auto,enablePullRequestAutoMerge,mergePullRequestand/mergeREST finds no other live merge path.zig-pkg/.../create-release.ymlis a vendored dependency, not a workflow. - (c) Every read fails closed.
- (d) The
check_suitetrigger is gone, PR code is no longer checked out,PR_BODYgoes through env, and the merge is pinned withsha.
Checks run
actionlinton queen-bot.yml: clean.- The gate script was run against a mocked API:
- normal case passes;
- late push, force-push to an old SHA, no label, no approval, and head moved are all refused;
- an API error throws.
- zig 0.16.0 (this repo's CI version):
zig test src/tri/github_client.zigpasses 18/18, andzig build tribuilds. - CI after dbfbfce:
- Build & Test, CI Validation, Build Check, unit and integration tests, yosys-synth and the phi witness pass.
- Red: doc-refs/orphan-artefacts/withdrawn-live, Brain Health Report and Stress Test. These also fail on main 9d28c35, so they are noise.
- One "Brain Health Check" run fails only with "Resource not accessible by integration" when commenting. That is a permission issue; its twin passes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces #803 (same diff; the commit subject now matches
<type>(<scope>): <description>so CI Validation passes — no force-push).Owner's rule, 2026-10-02:
No automation may merge on its own verdict. A merge happens only after a reviewer bee's review: an APPROVED review plus the
bee-reviewedlabel added after the last commit. Same gate as gHashTag/t27#5526 (.github/workflows/auto-merge-ready-prs.yml).What changes in
.github/workflows/queen-bot.ymlcharter:r2-passandbee-reviewed. Before this change,charter:r2-passplus green CI was enough to squash-merge.APPROVEDreview, and requires the latestbee-reviewedlabeling to be no older than the head commit's committer date. A push after the review counts as unreviewed code.pulls.mergenow passessha: pr.head.sha. If a commit lands between the gate and the merge, GitHub refuses the merge.pull_request_target, which has a write token, the PR body was pasted straight into a shell script (body="${{ github.event.pull_request.body }}"). That allowed script injection, and actionlint flags it. The body is now passed throughenv. I also dropped the checkout of the untrusted PR head because no step used it.check_suitetrigger. Its payload has nopull_request, so the job'sif:was always false for it.bee-reviewedcreated in this repo.Reviewer order: approve first, then add
bee-reviewed. Thelabeledevent is what starts the merge.Verified locally
actionlint .github/workflows/queen-bot.yml: clean. The old file had the injection finding plus SC2046, and both are fixed.githubclient with 6 cases, all as expected: label after head + approved passes; no label fails; no approval fails; label before head fails; relabel after a push passes; an unrelated label event fails.Not verified
Author bee: I am not merging this. It waits for a reviewer bee.
phi^2 + phi^-2 = 3
🤖 Generated with Claude Code