Repository navigation
ci: the merge queue policy covers every organization of the fleet - #233
Merged
Merged
Conversation
policy/merge-queue.json listed only SylphxAI, so the required approving review count of 0 reached one organization and the other three kept the 1 approval the review ruleset left on their repository rulesets: Cubeage/.github, EpiowAI/.github, EpiowAI/brand, EpiowAI/renovate-config, OzyrixLtd/.github and OzyrixLtd/renovate-config. A repository ruleset's pull_request rule is optional at repository level but required at organization level, so it can hold a review with no queue. The list is now the same four organizations as policy/optimistic-merge.json, the one fleet list its audit test pins; a test compares the two. The fake GitHub in the tests serves one organization per query, as GitHub answers, so a run over the list is exercised. docs/merge-queue-settings.md records the coverage and the hands-off repositories that stay as they are. Read with scripts/apply_merge_queue.py through the desk App: 60 rulesets, drift 6 (the six above), ok 52, excluded 2 (SylphxAI/bgca, SylphxAI/openclaw-sylphx). tests: python -m unittest discover -s tests, 912 pass.
Contributor
Author
There was a problem hiding this comment.
- policy/merge-queue.json:6-8 expands the ruleset rollout to three more organizations, but scripts/apply_merge_queue.py only excludes hard-coded repository names. Check each repository delivery property before including it in the write plan, excluding sylphx_delivery=delivered and unreadable properties (the existing scripts/is-delivered.sh defines this contract). Otherwise --apply can rewrite a delivered customer repository ruleset without a customer request. Add regression coverage proving those repositories receive no PUT. This is required by the company rule excluding delivered repositories from ruleset rollouts.
Contributor
There was a problem hiding this comment.
The policy now covers all four fleet organizations. Delivered and unreadable delivery properties are excluded before planning, and a forbidden property read stops before any write. The regression tests cover the exclusion and permitted-write paths; all required checks passed. No blocking findings. Follow-up: simulate subprocess.TimeoutExpired rather than RuntimeError in the timeout regression and handle that exception as an unreadable property.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
policy/merge-queue.jsonlisted one organization inorgs,SylphxAI, so thepolicy's
review.required_approving_review_count = 0reached only SylphxAIrepository rulesets. The other three organizations kept the 1-approval
pull_requestrule their repository rulesets carry, and a merge there is heldfor an approval that the fast gate
ci-okalready made unnecessary.orgsnow names the same four organizations aspolicy/optimistic-merge.json,the one list of the fleet:
SylphxAI,Cubeage,EpiowAI,OzyrixLtd.Six repository rulesets drift under the shipped policy, all found with the tool
itself (
scripts/apply_merge_queue.py, desk App, read-only dry run at2026-10-07T19:5xZ, 60 rulesets read):
Cubeage/.githubEpiowAI/.githubEpiowAI/brandEpiowAI/renovate-configOzyrixLtd/.githubOzyrixLtd/renovate-configThe queue parameters differ too, because
merge_queueis a repository-level-onlyrule: the organization rulesets carry none, so those repositories were never
converged on the queue policy either.
Only
Cubeage/.githubalso carriespull_request; the other five rulesets holdno
pull_requestrule at all, so their only change is the queue parameters.Cubeage/big2-tycoonandEpiowAI/epiowalready sit at approval 0 (the reviewrollout of 2026-10-04 read every organization), so this change is the policy
catching up with them, not a new decision.
Hands-off repositories stay out of it:
SylphxAI/bgca,Cubeage/hk-mahjong-tycoonandSylphxAI/openclaw-sylphxare excluded throughpolicy/optimistic-merge.json, and the dry run reports them EXCLUDED, unchanged.docs/merge-queue-settings.mdrecords that the count reaches every organizationof the fleet and which repositories are excluded.
Why
A required approval on a repository whose gate is
ci-okchecks nothingci-okdid not (owner standards: ONE CHECK), and it costs a bot approval or a human wait
on every merge. The policy is the one place the count is set, so the policy has
to name every organization that carries a ruleset.
How it was tested
python -m unittest discover -s tests: 912 tests, OK (the CI command of.github/workflows/project-control.yml).tests/test_apply_merge_queue.pycomparesorgswith the auditedpolicy/optimistic-merge.jsonlist, and its fake GitHub now serves oneorganization per query as GitHub answers, so a run over a multi-organization
orgsis exercised end to end (plan, apply, read-back, idempotent second run).drift 6 as tabled above, ok 52, excluded 2.
Applying the policy to the six drifted rulesets is a separate write step with the
rollout that owns the credential; this change ships the policy and the tool that
converges them.