Skip to content

docs: document the main branch protection model - #194

Merged
TMHSDigital merged 1 commit into
mainfrom
ci/document-main-protection
Sep 22, 2026
Merged

TMHSDigital merged 1 commit into
mainfrom
ci/document-main-protection

Conversation

@TMHSDigital

Copy link
Copy Markdown
Owner

What

main had no protection and no rulesets — the protection API returned 404 and every gate in this repo was advisory. It now carries the repository ruleset main-integrity (id 23797003, target ~DEFAULT_BRANCH, enforcement active, no bypass actors): deletion, non_fast_forward, required_linear_history.

This PR documents that model in CONTRIBUTING.md, next to the CI coverage section. Settings-only change otherwise; no code, no workflow edits.

What is enforced, proven by live run

Force-push to main, verbatim:

$ git push --force origin HEAD~1:main
remote: error: GH013: Repository rule violations found for refs/heads/main.
remote: Review all repository rules at https://github.com/TMHSDigital/Blender-Developer-Tools/rules?ref=refs%2Fheads%2Fmain
remote:
remote: - Cannot force-push to this branch
remote:
 ! [remote rejected] HEAD~1 -> main (push declined due to repository rule violations)
error: failed to push some refs to 'https://github.com/TMHSDigital/Blender-Developer-Tools.git'

Ruleset live, by API:

$ gh api repos/TMHSDigital/Blender-Developer-Tools/rules/branches/main
["deletion","non_fast_forward","required_linear_history"]

What could not be proven

  • The deletion rule. git push origin --delete main is refused, but by the default-branch guard, not by the ruleset: ! [remote rejected] main (refusing to delete the current branch: refs/heads/main). The rule is configured and verified present via the API; its refusal path is untestable on the default branch without renaming the default, which was not done.
  • The release path is inspection-only in this PR. docs: cuts no release, so no bump commit is pushed here. Part B carries fix: commits; its merge is the live test. By inspection: a fast-forward single-parent push violates none of the three rules, and a branch ruleset does not target tags, so the tag pushes, the GitHub release, and the gh workflow run pages.yml --ref main dispatch are all outside the ruleset's scope.

What is deliberately NOT enforced

Required status checks and a pull-request requirement. A red PR can still be merged. This is a structural limit of a user-owned repository, measured on a throwaway branch and written up in #192 with the full probe matrix and the GH006/GH013 error text.

Short version: a required-check rule blocks direct pushes for any actor without a bypass, release.yml pushes the bump commit to main as github-actions[bot], and GitHub rejects the GitHub Actions integration as a bypass actor outside an organization (422 "Actor GitHub Actions integration must be part of the ruleset source or owner organization"). A RepositoryRole:Write bypass covers the owner, never the bot — backwards, and it would re-open admin merges of red PRs.

The three rules that are active were chosen precisely because release.yml's push does not violate them.

Check enumeration behind the doc

Diffed a merged PR without needs-5.1 (#191, #190) against one with it (#185). The only difference is Blender 5.1 smoke. The doc records the seven unconditional checks as the required set to adopt if the constraint lifts, and names why Blender 5.1 smoke (label-gated), Auto-label by path (label-sync.yml has no reopened trigger), and Resolve smoke matrix (skipped on non-needs-5.1 label events) must stay out of it.

Probe branches protection-probe and chore/probe-workflow, and all probe rulesets, have been torn down.

Refs #192

🤖 Generated with Claude Code

`main` now carries the `main-integrity` ruleset: deletion, non-fast-forward,
and required-linear-history, with no bypass actors. Record what is enforced,
what is not, and why.

Required status checks and a PR requirement are deliberately absent. A
required-check rule blocks direct pushes for any actor without a bypass, and
`release.yml` pushes its bump commit to `main` as github-actions[bot]. On a
user-owned repository GitHub refuses the GitHub Actions integration as a
bypass actor, and a role-based bypass covers the owner rather than the bot.
Tracked in #192.

Also record the required-check set to adopt if that constraint lifts, and
why `Blender 5.1 smoke`, `Auto-label by path`, and `Resolve smoke matrix`
must stay out of it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: TMHSDigital <154358121+TMHSDigital@users.noreply.github.com>
@TMHSDigital
TMHSDigital merged commit 6440e83 into main Sep 22, 2026
11 checks passed
@TMHSDigital
TMHSDigital deleted the ci/document-main-protection branch September 22, 2026 00:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant