Skip to content

ci: the merge queue policy covers every organization of the fleet - #233

Merged
sylphx-desk-studio[bot] merged 2 commits into
mainfrom
fix/merge-queue-orgs
Oct 9, 2026
Merged

sylphx-desk-studio[bot] merged 2 commits into
mainfrom
fix/merge-queue-orgs

Conversation

@sylphx-desk-studio

Copy link
Copy Markdown
Contributor

What

policy/merge-queue.json listed one organization in orgs, SylphxAI, so the
policy's review.required_approving_review_count = 0 reached only SylphxAI
repository rulesets. The other three organizations kept the 1-approval
pull_request rule their repository rulesets carry, and a merge there is held
for an approval that the fast gate ci-ok already made unnecessary.

orgs now names the same four organizations as policy/optimistic-merge.json,
the one list of the fleet: SylphxAI, Cubeage, EpiowAI, OzyrixLtd.

Six repository rulesets drift under the shipped policy, all found with the tool
itself (scripts/apply_merge_queue.py, desk App, read-only dry run at
2026-10-07T19:5xZ, 60 rulesets read):

ruleset drift
Cubeage/.github ALLGREEN -> HEADGREEN, build 10 -> 5, merge 10 -> 20, approval 1 -> 0
EpiowAI/.github ALLGREEN -> HEADGREEN, build 10 -> 5, merge 10 -> 20
EpiowAI/brand same
EpiowAI/renovate-config same
OzyrixLtd/.github same
OzyrixLtd/renovate-config same

The queue parameters differ too, because merge_queue is a repository-level-only
rule: the organization rulesets carry none, so those repositories were never
converged on the queue policy either.

Only Cubeage/.github also carries pull_request; the other five rulesets hold
no pull_request rule at all, so their only change is the queue parameters.
Cubeage/big2-tycoon and EpiowAI/epiow already sit at approval 0 (the review
rollout of 2026-10-04 read every organization), so this change is the policy
catching up with them, not a new decision.

Hands-off repositories stay out of it: SylphxAI/bgca,
Cubeage/hk-mahjong-tycoon and SylphxAI/openclaw-sylphx are excluded through
policy/optimistic-merge.json, and the dry run reports them EXCLUDED, unchanged.

docs/merge-queue-settings.md records that the count reaches every organization
of the fleet and which repositories are excluded.

Why

A required approval on a repository whose gate is ci-ok checks nothing ci-ok
did not (owner standards: ONE CHECK), and it costs a bot approval or a human wait
on every merge. The policy is the one place the count is set, so the policy has
to name every organization that carries a ruleset.

How it was tested

  • python -m unittest discover -s tests: 912 tests, OK (the CI command of
    .github/workflows/project-control.yml).
  • tests/test_apply_merge_queue.py compares orgs with the audited
    policy/optimistic-merge.json list, and its fake GitHub now serves one
    organization per query as GitHub answers, so a run over a multi-organization
    orgs is exercised end to end (plan, apply, read-back, idempotent second run).
  • Read-only dry run over all four organizations with the desk App: 60 rulesets,
    drift 6 as tabled above, ok 52, excluded 2.

Applying the policy to the six drifted rulesets is a separate write step with the
rollout that owns the credential; this change ships the policy and the tool that
converges them.

policy/merge-queue.json listed only SylphxAI, so the required approving
review count of 0 reached one organization and the other three kept the
1 approval the review ruleset left on their repository rulesets: Cubeage/.github,
EpiowAI/.github, EpiowAI/brand, EpiowAI/renovate-config, OzyrixLtd/.github and
OzyrixLtd/renovate-config. A repository ruleset's pull_request rule is optional at
repository level but required at organization level, so it can hold a review with
no queue.

The list is now the same four organizations as policy/optimistic-merge.json, the
one fleet list its audit test pins; a test compares the two. The fake GitHub in
the tests serves one organization per query, as GitHub answers, so a run over the
list is exercised. docs/merge-queue-settings.md records the coverage and the
hands-off repositories that stay as they are.

Read with scripts/apply_merge_queue.py through the desk App: 60 rulesets, drift 6
(the six above), ok 52, excluded 2 (SylphxAI/bgca, SylphxAI/openclaw-sylphx).
tests: python -m unittest discover -s tests, 912 pass.

@sylphx-desk-studio sylphx-desk-studio Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. policy/merge-queue.json:6-8 expands the ruleset rollout to three more organizations, but scripts/apply_merge_queue.py only excludes hard-coded repository names. Check each repository delivery property before including it in the write plan, excluding sylphx_delivery=delivered and unreadable properties (the existing scripts/is-delivered.sh defines this contract). Otherwise --apply can rewrite a delivered customer repository ruleset without a customer request. Add regression coverage proving those repositories receive no PUT. This is required by the company rule excluding delivered repositories from ruleset rollouts.

@sylphx-desk-services sylphx-desk-services Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The policy now covers all four fleet organizations. Delivered and unreadable delivery properties are excluded before planning, and a forbidden property read stops before any write. The regression tests cover the exclusion and permitted-write paths; all required checks passed. No blocking findings. Follow-up: simulate subprocess.TimeoutExpired rather than RuntimeError in the timeout regression and handle that exception as an unreadable property.

@sylphx-desk-studio
sylphx-desk-studio Bot added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 3188b1c Oct 9, 2026
6 checks passed
@sylphx-desk-studio
sylphx-desk-studio Bot deleted the fix/merge-queue-orgs branch October 9, 2026 10:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant