From b52f439d1ea0c4b76ef844576c7e84f5efc4b1ff Mon Sep 17 00:00:00 2001 From: huangruiteng <14976749+huangruiteng@users.noreply.github.com> Date: Thu, 17 Sep 2026 01:16:16 +0800 Subject: [PATCH] docs: require a published exact-head review for every self-merge MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `skills/loopx-pr-merge/SKILL.md` already states that a merge, approval, self-merge or admin-bypass decision requires review evidence for the exact head, and `pr-review --check-merge-readiness` already fails closed without it. The policy list an agent reads first did not say so, and four self-merged PRs (#4488, #4489, #4491, #4562) reached main with no review record at all. - Add the published-exact-head-review condition to the self-merge list, naming the `COMMENTED` review an author-owned PR uses because GitHub blocks formal self-approval, and naming the `check-merge-readiness` result it must have. - State in the 自合并 definition that a self-merge without that record is a process gap to repair, not a smaller form of review. - Make the merge skill's decision record unambiguous: publish it on the exact head rather than summarizing it in another channel. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com> --- AGENTS.md | 13 +++++++++++-- skills/loopx-pr-merge/SKILL.md | 7 ++++++- 2 files changed, 17 insertions(+), 3 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index cb6df8df3f..4262306093 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -100,12 +100,21 @@ adapters, smoke tests, public docs, or commit/push workflows, use the For small, low-risk PRs, maintainers may self-merge after validation when all of the following are true: -Here, "自合并" means: 自己 review/refine, then admin-bypass merge after the -required validation and authorization. +Here, "自合并" means: 自己 review/refine, publish that review on the exact head, +then admin-bypass merge after the required validation and authorization. A +self-merge whose head carries no published review is a process gap, not a +smaller form of review: repair it by publishing the exact-head review for the +merged commit and correcting the rule that let it through. - the PR only touches public docs, contributor metadata, or narrow cleanup; - the change is single-purpose and easy to review from the diff; - required checks or focused smokes have passed; +- the exact head carries a published self-review, and + `loopx pr-review --check-merge-readiness NUMBER@HEAD_OID` returned ready for + that unchanged head. GitHub blocks formal self-approval, so on an + author-owned PR the record is a `COMMENTED` review on the exact head that + states the approval conclusion and an English verdict; a green CI run, a diff + read, or the merge itself is not that record; - private state, raw benchmark evidence, credentials, local paths, and generated logs are excluded; - there is no runtime behavior, benchmark adapter, permission, destructive git, diff --git a/skills/loopx-pr-merge/SKILL.md b/skills/loopx-pr-merge/SKILL.md index 8951a0602e..2e427d098b 100644 --- a/skills/loopx-pr-merge/SKILL.md +++ b/skills/loopx-pr-merge/SKILL.md @@ -57,7 +57,12 @@ then reports separately authorized admin bypass, never permission to merge. 4. Decide: approve, self-merge with owner authorization, request changes, or hold for the maintainer path. Record the decision on the pull request with the changed surfaces, the checks that ran, failures and skips, manual holds, - and the reason that coverage is enough. + and the reason that coverage is enough. Record it as a published review on + the exact head, not as a summary in another channel: on an author-owned PR + GitHub blocks formal self-approval, so the record is the `COMMENTED` review + carrying the approval conclusion and the English verdict. A self-merge whose + head carries no such record is a process gap to repair, not an authorized + merge. 5. After the merge, sync the local default branch, leave unrelated dirty worktree state alone, and update LoopX todo or evidence when the work is tracked.