docs: require a published exact-head review for every self-merge - #4583
Conversation
`skills/loopx-pr-merge/SKILL.md` already states that a merge, approval, self-merge or admin-bypass decision requires review evidence for the exact head, and `pr-review --check-merge-readiness` already fails closed without it. The policy list an agent reads first did not say so, and four self-merged PRs (#4488, #4489, #4491, #4562) reached main with no review record at all. - Add the published-exact-head-review condition to the self-merge list, naming the `COMMENTED` review an author-owned PR uses because GitHub blocks formal self-approval, and naming the `check-merge-readiness` result it must have. - State in the 自合并 definition that a self-merge without that record is a process gap to repair, not a smaller form of review. - Make the merge skill's decision record unambiguous: publish it on the exact head rather than summarizing it in another channel. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Exact head: b52f439d1ea0c4b76ef844576c7e84f5efc4b1ff · policy revision 6 · pr-review --check-result 返回 approval_consistent: true。
动机
你指出"自合并的 PR 都需要自 review"。我按这条口径查了 GitHub:本账号合并的 64 个 PR 里有 4 个 reviews=0 —— #4488、#4489、#4491、#4562。它们都是自合并,且合并没有留下任何 review 记录。
更关键的是缺口在哪:skills/loopx-pr-merge/SKILL.md 已经写明"合并、批准、自合并或 admin 绕过都必须有 exact head 的 review 证据",loopx/capabilities/pr_review_queue/merge_readiness.py 也已经在没有有效 exact-head conclusion 时返回 current_head_review_missing_or_invalid。也就是说机器门禁存在,缺的是先读到的策略清单没有写这一条,所以自合并时容易只满足"CI 绿 + 读过 diff"就合并。
改动思路
不新增第二道门禁(那会与 check-merge-readiness 重复),而是把已经存在的义务写进 agent 最先读到的策略位置,并把"决定记在哪里"写死为 exact head 上的已发布 review。
具体改动
AGENTS.md:自合并条件清单新增一条——exact head 必须带已发布的 self-review,且loopx pr-review --check-merge-readiness NUMBER@HEAD_OID对该未变 head 返回 ready;并说明 GitHub 阻止作者正式自批准,因此 author-owned PR 的记录是带 approval conclusion 与英文 verdict 的COMMENTEDreview,"CI 绿 / 读过 diff / 合并本身"都不是这条记录。AGENTS.md:自合并定义补一句——自合并是"自己 review/refine → 把该 review 发布到 exact head → admin 绕过合并",缺这条记录的合并是流程缺口,要补发布该 merged commit 的 review 并修掉放它过去的规则。skills/loopx-pr-merge/SKILL.md:决策记录明确为"发布在 exact head 上的 review",而不是在别的渠道里做总结。
对主干的风险
纯策略文本,无运行时路径。两处显式区分了 guidance 与 machine-enforced:机器强制的一半是既有 check-merge-readiness,本次文本只是把它写清楚并加上记录格式的期望。风险是文本本身无法被机器证明——但这不是新增空头承诺,因为它指向的门禁已经在跑。
我的整体评价
这是把"流程缺口"落成"可读规则"的最小改动,没有为了显得严格而加第二套门禁。同时我已按此规则为那 4 个 PR 在各自 merged head 上补发了回顾性 review(含非阻断发现),并让本 PR 自己走一遍修正后的流程:capability review → exact-head 发布 → check-merge-readiness → 合并。
Approval conclusion (author-owned PR; GitHub blocks formal self-approval): APPROVE at b52f439d — delivery judgment problem_context = goal_achieved(缺 review 记录的实例已补、规则已成文;机器门禁本就存在,未新增第二套)。
English verdict: APPROVE — at b52f439d, the change states the self-merge condition that the review capability and check-merge-readiness already enforced but the policy list omitted, and it fixes where the decision record is published; the four review-less self-merges (#4488, #4489, #4491, #4562) are repaired with retrospective exact-head reviews that carry non-blocking findings, and this PR is itself reviewed and merged through the corrected flow.
|
Merge record: exact-head review published at |
Goal And Delivered Outcome
skills/loopx-pr-merge/SKILL.mdalready requires review evidence for the exact head, andpr-review --check-merge-readinessalready fails closed without it, but the self-merge condition list inAGENTS.mddid not state it. Four self-merged PRs authored by me reachedmainwith no review record at all: test(configure-goal): cover the pull-request review catalog entry #4488, docs: surface TypeScript core in README badges #4489, test(showcase): declare the typed dependency scope in the blocked-P0 rotation fixture #4491, test(install): expect the fixed install to keep repo-only skills in the checkout #4562 (reviews=0while the other 60 author-owned merges carry one).check-merge-readinessresult it must have, and the 自合并 definition says a self-merge without that record is a process gap to repair.mainate6427250a.Scope And Continuation
build_merge_readinessreturnscurrent_head_review_missing_or_invalidwithout a valid exact-head conclusion.check-merge-readiness.Validation
af1d2d2(branch head)staticpassedexamples/pr-review-command-smoke.pyreportspr-review-command-smoke ok; it asserts the merge-skill routing phrases and the repo-only delivery ofloopx-pr-merge.staticpassedexamples/docs-governance-smoke.pyreportsdocs-governance-smoke okfor the changedAGENTS.md.manualpassedloopx/capabilities/pr_review_queue/merge_readiness.py, which already returnscurrent_head_review_missing_or_invalidwhen the exact head has no valid conclusion, so the added policy names an existing gate rather than a new obligation.Frontend / Visual Evidence
Type of Change
LoopX Area
Technical Direction
Shared-authority RFC fixture impact
Boundary Checklist
.loopx/,.codex/goals/, and liveACTIVE_GOAL_STATE.md).none.Signed-off-bytrailer (git commit -s).