Skip to content

source-control: migrate ten babysit repository-tooling keys from userConfig to the source-control.md cascade #4572

Description

@kyle-sexton

Summary

Migrate ten source-control babysit userConfig keys that describe a repository's tooling to the
layered .claude/source-control.md surface, with per-key trust binding and a deprecation window.
The ruling that splits the 17 babysit identity and topology keys into declare, migrate-now and
migrate-later sets is recorded in the ADR added by the linked pull request. This issue tracks only
the migrate-later set, which needs new resolution machinery.

Keys

babysit_merge_method, babysit_merge_block_labels, babysit_extra_dependency_manager_logins,
babysit_approval_downgrade_logins, babysit_skip_downgrade_logins,
babysit_review_trigger_phrase, babysit_review_bot_logins, babysit_review_settle_minutes,
babysit_review_gate_context, babysit_ci_gateway_context.

Out of scope, by the ruling: babysit_watched_owners, babysit_self_logins,
babysit_intended_write_identity, babysit_lane_logins, babysit_approver_bot_logins,
babysit_extra_bot_logins stay userConfig (a repo-writable value would widen authority).
branch_issue_pattern migrates in the linked pull request.

Design to settle

  1. Per-target-repo resolution. /source-control:babysit-prs is a fleet loop and substitutes
    ${user_config.*} once at skill load. Reading the launching checkout's file would apply one
    repo's values to every other repo's PRs. Resolve per target repository, per PR, per cycle, from
    that repository's tracked .claude/source-control.md on its default branch (gh api contents),
    never a working tree, following the babysit_loop_trusted_internal_bot_logins precedent in
    plugins/source-control/reference/config-resolution.md.
  2. Merge mode per key.
    • Hold and veto lists (babysit_merge_block_labels, babysit_extra_dependency_manager_logins,
      babysit_approval_downgrade_logins): add-only union across layers and the deprecated
      userConfig value, so no later layer can drop an entry. The surface has no union mode today
      (closed lists are taken whole), so this is a new, declared policy-floor merge mode.
    • babysit_review_bot_logins with babysit_review_settle_minutes: bound as one unit from one
      layer, so a per-key merge cannot take one half from each layer and leave the settle hold
      silently dormant. A lower layer may lengthen the settle window, never shorten it.
    • babysit_skip_downgrade_logins: decide whether it is a floor or a preference before choosing.
    • babysit_merge_method, babysit_review_trigger_phrase, babysit_review_gate_context,
      babysit_ci_gateway_context: plain per-key override.
  3. Deprecation window. The userConfig value stays a fallback (a union member for the hold
    lists) and emits one deprecation note when it is used. Remove it in a later minor release with a
    CHANGELOG Removed entry, no earlier than 90 days after the resolver ships.
  4. Tests. Resolver cases for each merge mode, the default-branch-only read, precedence against
    the deprecated fallback, and a fleet run over two repositories with different values.

Security

Any design that lets a repo-writable layer shorten a hold, drop a veto label, or replace a hold list
under plain per-key override loosens a merge-safety check. That needs the maintainer's explicit
decision before implementation. A security review is mandatory on the implementing pull request.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions