Skip to content

fix(agent): close bad contributor PRs even on guarded paths - #1106

Merged
JSONbored merged 1 commit into
mainfrom
fix/close-bad-guarded-prs
Jun 23, 2026
Merged

fix(agent): close bad contributor PRs even on guarded paths#1106
JSONbored merged 1 commit into
mainfrom
fix/close-bad-guarded-prs

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Per spec — guarded + would-merge → hold; otherwise → closure. #1090 made guarded paths block auto-close too, so rejected contributor PRs touching crucial paths (e.g. #1098, touching src/review|services|signals) were held with a 'closing' comment but never closed. The guardrail must only block auto-MERGE/APPROVE of crucial paths, never the rejection of a bad PR (closing merges nothing → always safe). willClose no longer checks guardrailHit; owner PRs still never close; good-but-guarded still held. Full suite green (3492).

…(guard blocks merge, not rejection)

#1090 gated willClose on !guardrailHit, so a rejected CONTRIBUTOR PR touching a guarded path was HELD instead
of closed (e.g. gittensory #1098: rejected, touches src/review|services|signals → stayed open with a
'closing' message). That contradicts the spec: 'guarded + would-merge → hold; otherwise → closure.'

The hard-guardrail exists to stop auto-MERGING/APPROVING crucial-path changes without owner review (canMerge
+ approve still gate on !guardrailHit). It must NOT keep a rejected PR open — closing rejects bad changes and
merges nothing, so it is always safe. willClose no longer checks guardrailHit; owner/automation PRs are still
never closed (isContributor gates it); GOOD-but-guarded PRs still fall through to the owner (held).

Test flipped: a failing contributor PR on a guarded path now CLOSES.
@dosubot dosubot Bot added the size:S label Jun 23, 2026
@JSONbored
JSONbored merged commit a0b0ea7 into main Jun 23, 2026
12 checks passed
@JSONbored
JSONbored deleted the fix/close-bad-guarded-prs branch June 23, 2026 20:56
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jun 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.79%. Comparing base (9745a13) to head (9ea009f).
⚠️ Report is 1 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1106   +/-   ##
=======================================
  Coverage   94.79%   94.79%           
=======================================
  Files         153      153           
  Lines       18553    18553           
  Branches     6708     6708           
=======================================
  Hits        17587    17587           
  Misses        408      408           
  Partials      558      558           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

JSONbored added a commit that referenced this pull request Jun 23, 2026
…g (#hold-crucial-on-reject) (#1109)

Operator decision: a guarded/crucial PR (CI, the review engine, visual) must NEVER be auto-closed, even on a
reject verdict — a hallucinated reject (the #1528 near-miss: diff-only false-positives) must not auto-close a
good crucial PR. The owner verifies + closes/merges. The BULK (non-guarded) contributor PRs still auto-close
one-shot on a bad verdict / conflict; only the small crucial set is held. Restores the guardrail check on
willClose (reverts #1106's removal). Owner/automation PRs never close regardless.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant