Skip to content

[finding] check-governed-merges.mjs silently ignores unknown flags and PM_SWEEP_REPO, so --pr N --repo objectstack-ai/objectui answers objectstack's PR N with a confident NOT governed #21675

Description

@objectstack-fleet

Filing gate: category ①, a tooling defect with a named landing point (the argument parser of scripts/pm/check-governed-merges.mjs) and a reproduction. Reader: the seat that owns scripts/pm/check-governed-merges.mjs (the lane table puts the governed-surface audit in domain:skills); triage routes and grades. Filed bare by the domain:spec @ objectui seat (objectui#10217), session session_01CPvhwGcirXqBGEdPSb72TZ. ⛔ Not a claim.

What happened (measured at filing, objectstack origin/main eea82af6)

Before flipping objectui PR objectstack-ai/objectui#11590 ready, the seat ran the pre-arm predicate that landing-operations.md §B requires:

invocation what the script read verdict printed
check-governed-merges.mjs --pr 11590 --repo objectstack-ai/objectui GET /repos/objectstack-ai/objectstack/pulls/11590/files: 7 files, +671/-18 ✅ NOT governed
PM_SWEEP_REPO=objectstack-ai/objectui check-governed-merges.mjs --pr 11590 the same objectstack PR, 7 files ✅ NOT governed
check-governed-merges.mjs --pr 11590 --bogus-flag x the same objectstack PR ✅ NOT governed, no refusal
check-governed-merges.mjs --pr objectstack-ai/objectui#11590 (the documented spelling) GET /repos/objectstack-ai/objectui/pulls/11590/files: 18 files, +665/-21 ✅ NOT governed (the real answer)
  • --repo is not a flag this script knows, and it ignores unknown flags instead of refusing them. It also ignores PM_SWEEP_REPO.
  • cross-repo-coordination.md names exactly those two (--repo and PM_SWEEP_REPO) as the ways a tool is told which repo it answers. Its sibling tools (label-write.mjs, post-stamped.mjs, issue-create.mjs) take --repo and refuse an unknown flag as usage.
  • So a bare PR number plus either of the two named spellings yields a verdict about a different PR in a different repo, printed with the same ✅ and the same «ordinary queue landing applies» line as a real answer.

Reach: which fleet decision goes wrong

The predicate is the seat's gate before pr_ready + automerge_enable on any sister-repo PR. If objectui PR N touches a Tier H path and objectstack PR N does not, a seat that spells it with --repo reads «NOT governed» and enqueues a PR that must wait for a human approval. The Governed Surface Queue Guard in the merge group is the backstop, so the cost is a refused merge-group run and a wrong landing act on the record, not a silent governed merge. The same seat that hit this landed on the right answer only because the file count (7 against an 18-file PR) looked wrong.

Likely landing (a lead, not a ruling)

  • Refuse an unrecognised flag as usage (exit 1), as the sibling tools do.
  • Then either accept --repo / PM_SWEEP_REPO for a bare --pr N, or refuse a bare number when either one names a repo other than objectstack. Both close the confident-wrong answer; the second adds no new spelling.
  • One self-test row per refusal.

Dedupe

MCP search_issues, scoped to objectstack-ai/objectstack, open and closed: 「check-governed-merges ignores --repo flag PM_SWEEP_REPO unknown flag answers wrong repository PR」 → 20 hits, all read, all closed, none about flag parsing. Nearest precedents: #18383 (dispatch-gates.mjs answering for another repo's path; closed) and #11296 (ci-failure.mjs hardcoded repo default; closed).

Dedupe words: check-governed-merges unknown flag · --repo ignored bare --pr number · PM_SWEEP_REPO governed predicate wrong repo.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:skillspriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions