Skip to content

bug: activate main-protection merge gate and prove a healthy post-merge observation #7408

Description

@ll7

*This was generated by AI during triage.

Maintainer-only rollout gap

The fail-closed workflow and caller-side authority are not effective until Robot SF's main-protection configuration requires them and a real merge-group observation proves the live behavior.

Current state:

  • main-protection ruleset ID 18917814 is active, but its pull-request rule has no required status checks, no merge-queue rule, and required_review_thread_resolution: false.
  • Current Robot SF main: 462032df2abc3e086655935288c806b9df8bda2b.
  • fix: fail closed on Robot SF gate evidence #7343 remains draft at exact head bd2c834e7c6f81bbc53f02d18289204bf22abf6e; companion orchestrator Add optional Three.js visualization alongside pygame #1645 remains draft at 5a0d6bf4b67c89efa34ae1f67bf0cb52df097d35.
  • The live protection checker currently reports passed: false, including merge_queue_rule_absent, gate_context_not_required, merge_queue_not_required, conversation_resolution_not_required, and zero_merge_group_runs.

Required order

  1. Merge the reviewed Robot SF workflow and orchestrator authority changes after fresh exact-head review.
  2. Verify the workflow is present on the effective Robot SF main and run a real source-head check.
  3. Apply the reviewed main-protection change requiring the exact merge-queue-gate status context, enable the native merge queue with ALLGREEN ("Only merge non-failing pull requests"), require conversation resolution, and leave bypass actors empty.
  4. Re-read the effective ruleset and run check_merge_queue_protection --check --repo ll7/robot_sf_ll7; it must return passed: true, no reasons, and merge_group_runs_total >= 1.
  5. Observe a real post-change merge-group audit with Merge Queue Gate / merge-queue-gate completed successfully for the exact synthetic head, gate_verdict_status=accepted, metadata_verdict_status=accepted, staleness_verdict=fresh, ci_overall=success, resolved threads, no requested reviewers, and passed=true.
  6. After a newly merged PR under the effective ruleset, run python3 scripts/fleet_invariants.py --json from a fresh source snapshot. The current merged_heads_have_accepted_gate_trailer key must be absent/healthy at an observation timestamp later than that merge. ok(historical), a dashboard snapshot, or code-merge evidence alone is insufficient.

Only after this sequence should the recurrence issue be considered prevented/closed. Historical merges remain forensic evidence and must not be backfilled. Related: #7343, ll7/codex-orchestrator#1645, and #7287.

schema: goal_autopilot_preparation.v1
repository: ll7/robot_sf_ll7
issue: 7408
source_body_sha256: cd2aa2546fa134bcf3e6f8a172c33f2a22745fbec48555c8851c57fe66a3be76
source_comments_sha256: 
audit_schema: open_issue_contract_audit.v1
audit_digest: 1c191411793929640684e0827d763f3a2009a8682ab98dcefa8c2ded3e54f4ea
audit_classification: blocked
next_action: resolve_named_blocker
authority: blocker_owner
execution_mode: blocker
preferred_worker: MaxRunner
expected_pr_runner_label: runner:max
implementation_admitted: False
state_ready_change_proposed: False
mutation_batch: open-issues-20260830-04

This packet is preparation evidence only. It never overrides live labels, exact claim state, branch state, typed dependencies, domain gates, compute authority, release authority, or scientific evidence rules.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triagepriority:0P0: correctness, safety, or CI-critical workruledAuthor ruling recorded; execution pending or completestate:blocked-external-inputBlocked on external data, asset, license, or human staging inputtype:maintenance

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions