docs: document the main branch protection model - #194
Merged
Merged
Conversation
`main` now carries the `main-integrity` ruleset: deletion, non-fast-forward, and required-linear-history, with no bypass actors. Record what is enforced, what is not, and why. Required status checks and a PR requirement are deliberately absent. A required-check rule blocks direct pushes for any actor without a bypass, and `release.yml` pushes its bump commit to `main` as github-actions[bot]. On a user-owned repository GitHub refuses the GitHub Actions integration as a bypass actor, and a role-based bypass covers the owner rather than the bot. Tracked in #192. Also record the required-check set to adopt if that constraint lifts, and why `Blender 5.1 smoke`, `Auto-label by path`, and `Resolve smoke matrix` must stay out of it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: TMHSDigital <154358121+TMHSDigital@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
mainhad no protection and no rulesets — the protection API returned 404 and every gate in this repo was advisory. It now carries the repository rulesetmain-integrity(id23797003, target~DEFAULT_BRANCH, enforcementactive, no bypass actors):deletion,non_fast_forward,required_linear_history.This PR documents that model in
CONTRIBUTING.md, next to the CI coverage section. Settings-only change otherwise; no code, no workflow edits.What is enforced, proven by live run
Force-push to
main, verbatim:Ruleset live, by API:
What could not be proven
deletionrule.git push origin --delete mainis refused, but by the default-branch guard, not by the ruleset:! [remote rejected] main (refusing to delete the current branch: refs/heads/main). The rule is configured and verified present via the API; its refusal path is untestable on the default branch without renaming the default, which was not done.docs:cuts no release, so no bump commit is pushed here. Part B carriesfix:commits; its merge is the live test. By inspection: a fast-forward single-parent push violates none of the three rules, and a branch ruleset does not target tags, so the tag pushes, the GitHub release, and thegh workflow run pages.yml --ref maindispatch are all outside the ruleset's scope.What is deliberately NOT enforced
Required status checks and a pull-request requirement. A red PR can still be merged. This is a structural limit of a user-owned repository, measured on a throwaway branch and written up in #192 with the full probe matrix and the
GH006/GH013error text.Short version: a required-check rule blocks direct pushes for any actor without a bypass,
release.ymlpushes the bump commit tomainasgithub-actions[bot], and GitHub rejects the GitHub Actions integration as a bypass actor outside an organization (422 "Actor GitHub Actions integration must be part of the ruleset source or owner organization"). ARepositoryRole:Writebypass covers the owner, never the bot — backwards, and it would re-open admin merges of red PRs.The three rules that are active were chosen precisely because
release.yml's push does not violate them.Check enumeration behind the doc
Diffed a merged PR without
needs-5.1(#191, #190) against one with it (#185). The only difference isBlender 5.1 smoke. The doc records the seven unconditional checks as the required set to adopt if the constraint lifts, and names whyBlender 5.1 smoke(label-gated),Auto-label by path(label-sync.ymlhas noreopenedtrigger), andResolve smoke matrix(skipped on non-needs-5.1label events) must stay out of it.Probe branches
protection-probeandchore/probe-workflow, and all probe rulesets, have been torn down.Refs #192
🤖 Generated with Claude Code