-
Notifications
You must be signed in to change notification settings - Fork 61
ci: auto-queue PRs in Mergify once verify, Unfret and live-gate pass (#100) #107
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
92b2249
f65069f
91b0d5b
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| merge_queue: | ||
| max_parallel_checks: 1 | ||
|
|
||
| queue_rules: | ||
| - name: default | ||
| batch_size: 1 | ||
| checks_timeout: null | ||
| merge_method: merge | ||
| queue_conditions: | ||
| - -draft | ||
| - check-success=verify | ||
| - check-success=Unfret | ||
| - check-success=live-gate | ||
| merge_conditions: [] | ||
|
Comment on lines
+9
to
+14
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Operator adjudication: no change. With in-place checks, Mergify updates a behind branch; the new head must pass the queue conditions again, including fresh exact-head live-gate after operator re-testing. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Agreed. With There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. If
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Operator adjudication: no change. With in-place checks, Mergify updates a behind branch; the new head must pass the queue conditions again, including fresh exact-head live-gate after operator re-testing. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Understood. Given Mergify’s in-place update behavior, advancing Tip: You can customize Greptile's behavior for this repo with |
||
|
|
||
| merge_protections_settings: | ||
| auto_merge_conditions: | ||
| - base = main | ||
| # Workflow changes never auto-queue; the operator queues them by hand. | ||
| - -files~=^\.github/ | ||
|
|
||
| merge_protections: | ||
| - name: Queue ready pull requests | ||
| description: Automatically queue non-draft pull requests targeting main after verify, Unfret, and live-gate pass on the head. | ||
| if: | ||
| - base = main | ||
| success_conditions: | ||
| - -draft | ||
| - check-success=verify | ||
| - check-success=Unfret | ||
| - check-success=live-gate | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 Medium · Stale queue admission invalidates the exact-head live gate These admission conditions allow a PR whose branch is behind main to enter the serial in-place queue while all three checks pass on its old head. Mergify then merges main into the PR branch, creating a new head SHA without the operator-posted Now at Also affects:
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Operator adjudication: no change. This is the documented fails-loudly hold: an updated head lacks exact-head live-gate and leaves the queue; the operator re-tests that head and re-posts live-gate before it can proceed.
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Operator adjudication: no change. Mergify removes a PR from the queue when queue_conditions stop matching, including a new head without exact-head live-gate, so the queue does not stall. The operator re-tests the new head and re-posts live-gate. |
||
|
|
||
| commands_restrictions: | ||
| requeue: | ||
| conditions: | ||
| - sender-permission >= write | ||
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 Critical · Auto-queue gates accept spoofable check names
The queue conditions (L11-13) and merge-protection success conditions (L27-29) match
verify,Unfretandlive-gateby name only, with no source check.auto_merge_conditions(L18) admits any PR to main with no author or approval restriction. Scenario: a non-draft PR adds a workflow with jobs namedlive-gate/Unfret(and can edit the verify workflow). The PR could come from a fork whose Actions run, or from the builder bot. Those jobs post successful check-runs with the gated names on the PR head. Mergify then auto-queues the PR and, with emptymerge_conditions, merges it. The operator never posted live-gate and the real Unfret may never have passed. Before this diff, merges were manual. Branch protection that requires human approval would block this, but it is not visible here and may exist outside this diff. Also reported for this defect: - Unqualified check names allow gate spoofing (.mergify.yml:11-13): Mergify's barecheck-successform accepts a successful check with the matching name regardless of its producer. A pull request can publish trivially successful checks namedverify,Unfret, andlive-gate; these conditions then pass even if the trusted checks failed or never ran. The same unqualified names at lines 27-29 let the spoof satisfy merge protection too, allowing an untrusted PR to be auto-queued and merged without the mandated gates. - Authenticate the live-gate result's source (.mergify.yml:13): Mergify's unqualifiedcheck-successaccepts a matching check from any app, not just the operator's commit status. A fork contributor can add apull_requestActions job namedlive-gatethat simply succeeds; GitHub publishes that check even with a read-only token. For an up-to-date, non-draft PR whose genuineverifyandUnfretpass, this line and line 29 accept the workflow-produced result, allowing automatic merging without the operator's installed-candidate test required by AGENTS.md. Both gate conditions need to distinguish the trusted live-test result from PR-controlled check runs.Also affects:
- .mergify.yml:13
Withdrawn in the latest review.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Applied the operator-confirmed correction in f65069f: both queue_conditions and success_conditions now include
-files~=^\.github/, with a short explanatory comment. PRs touching.github/cannot auto-queue and require manual operator queueing. No other mechanism added.