docs(w6d): smoke controller self-merge path #826

Merged
Iskra merged 3 commits from codex/issue-823-automerge-selfmerge-smoke into main 2026-06-26 10:37:01 +02:00
Collaborator

Canary status: not required — W6d safe-scope state/cycle self-merge smoke

Canary Context Pack

Product story

This is the follow-up to #825: prove that a boring safe-scope PR can pass Patchwarden and then be merged by the autonomous controller instead of by Piotr/manual merge.

What changed

Added one state-only W6d self-merge smoke note under state/cycle/.

Why it changed

Issue #823 acceptance still needs a PR that actually goes through the controller merge path after Patchwarden passes.

Files touched

  • state/cycle/W6d-controller-selfmerge-smoke-2026-06-25.md

Relevant context

  • #823 — Patchwarden unattended merge-safety loop.
  • #824 — readiness artifacts emit controller verdicts and exact-head merge actor guards.
  • #825 — first dogfood PR, manually merged by operator before self-merge could be tested.
  • docs/forgejo-agent-operations.md Autonomous Merge Readiness v0.

Runtime evidence

No runtime mutation. No deploy. No secrets. No branch protection, DNS, auth, ingress, routing, public exposure, or workflow change.

Known constraints

This PR should stay eligible for W6d automerge only while every changed file remains in the safe state/docs scope and Patchwarden exact-head evidence is green.

Explicit out-of-scope

No code changes, no policy expansion, no security-sensitive merge, no controller retry-loop implementation.

Requested decision

Expected readiness verdict after checks: ready_for_controller_merge. Expected final action: trusted automerge-pilot workflow approval/merge through its runner-local merge actor.

Merge blockers

  • Any file outside W6d safe scope.
  • Missing/stale exact-head Patchwarden/status evidence.
  • Any security-sensitive classification.

Verification

  • git diff --check → clean.
  • Changed path is only state/cycle/W6d-controller-selfmerge-smoke-2026-06-25.md.

Spec sources read

  • docs/forgejo-agent-operations.md — W6d/Patchwarden automerge contract.
  • state/cycle/W6d-autonomous-merge-pilot.md — W6d policy notes.
  • #823, #824, #825 — current goal and preceding attempts.

Refs #823

Canary status: not required — W6d safe-scope state/cycle self-merge smoke ## Canary Context Pack ### Product story This is the follow-up to #825: prove that a boring safe-scope PR can pass Patchwarden and then be merged by the autonomous controller instead of by Piotr/manual merge. ### What changed Added one state-only W6d self-merge smoke note under `state/cycle/`. ### Why it changed Issue #823 acceptance still needs a PR that actually goes through the controller merge path after Patchwarden passes. ### Files touched - `state/cycle/W6d-controller-selfmerge-smoke-2026-06-25.md` ### Relevant context - #823 — Patchwarden unattended merge-safety loop. - #824 — readiness artifacts emit controller verdicts and exact-head merge actor guards. - #825 — first dogfood PR, manually merged by operator before self-merge could be tested. - `docs/forgejo-agent-operations.md` Autonomous Merge Readiness v0. ### Runtime evidence No runtime mutation. No deploy. No secrets. No branch protection, DNS, auth, ingress, routing, public exposure, or workflow change. ### Known constraints This PR should stay eligible for W6d automerge only while every changed file remains in the safe state/docs scope and Patchwarden exact-head evidence is green. ### Explicit out-of-scope No code changes, no policy expansion, no security-sensitive merge, no controller retry-loop implementation. ### Requested decision Expected readiness verdict after checks: `ready_for_controller_merge`. Expected final action: trusted `automerge-pilot` workflow approval/merge through its runner-local merge actor. ### Merge blockers - Any file outside W6d safe scope. - Missing/stale exact-head Patchwarden/status evidence. - Any security-sensitive classification. ## Verification - `git diff --check` → clean. - Changed path is only `state/cycle/W6d-controller-selfmerge-smoke-2026-06-25.md`. ## Spec sources read - `docs/forgejo-agent-operations.md` — W6d/Patchwarden automerge contract. - `state/cycle/W6d-autonomous-merge-pilot.md` — W6d policy notes. - #823, #824, #825 — current goal and preceding attempts. Refs #823
docs(w6d): smoke controller self-merge path
All checks were successful
canary-required / collect-diff (pull_request) Successful in 4s
base-is-main / guard (pull_request) Successful in 1s
patchwarden-client-dry-run / collect-diff (pull_request) Successful in 4s
patchwarden-pr-sanity / collect-diff (pull_request) Successful in 3s
canary-required / canary (pull_request) Has been skipped
patchwarden-client-dry-run / dry-run (pull_request) Successful in 24s
patchwarden-pr-sanity / sanity (pull_request) Successful in 35s
aaa5771a53
First-time contributor

No Patchwarden findings to render.

No Patchwarden findings to render.
First-time contributor

Patchwarden PR sanity

Verdict: PASS WITH DEGRADED REVIEWER HEALTH - deterministic checks are clean, but this is not an approval signal.

Next step: Rerun PR sanity or inspect the degraded reviewer lane before unattended merge.

  • PR: 826
  • Commit: 6223226300e048cfa2c7796fd37ff43fb409b2d4
  • Status: eligible_sanity_clean
  • Reviewer health: degraded
  • Security-sensitive label: missing
  • Authority: Patchwarden policy signal; branch protection and automerge controller remain merge authority.
  • Model mix: glm-5.2:cloud, deepseek-v4-pro:cloud, kimi-k2.7:cloud

What I checked

  • Changed files: 1
  • Deterministic blocker scan: clean
  • Model reviewer lanes: 3
  • Comment contract: this comment is updated in place via a hidden Patchwarden marker.

Approval Handoff

  • State: not_ready_degraded_reviewer_health
  • Action: rerun PR sanity or inspect the degraded reviewer lane before any unattended approval.
  • Boundary: branch protection and the automerge controller remain merge authority.

Required Fixes

No deterministic blockers.

Reviewer Details

Model reviewer lanes

global-glm / glm-5.2:cloud

  • Status: ok
  • Verdict: OK
  • Findings: none

global-deepseek / deepseek-v4-pro:cloud

  • Status: ok
  • Verdict: OK
  • Findings: none

redteam / kimi-k2.7:cloud

  • Status: error
  • Verdict: -
  • Note: Ollama HTTP 404: {"error": "model 'kimi-k2.7:cloud' not found"}
  • Findings: none

Policy notes

  • Patchwarden PR sanity is the first merge-lane signal for this PR.
  • Models produce findings; Patchwarden/policy produces decisions.
  • Model findings alone do not fail the status check; they require human or agent disposition.
  • Formal approval is separate from this comment and requires clean reviewer health.
  • Automerge remains delegated to branch protection and the automerge pilot.
<!-- patchwarden-pr-sanity:pdurlej/platform:PR-826 --> <!-- patchwarden.pr_sanity.v1 status=eligible_sanity_clean model_health=degraded approval_handoff=not_ready_degraded_reviewer_health pr=826 sha=6223226300e048cfa2c7796fd37ff43fb409b2d4 --> # Patchwarden PR sanity **Verdict:** PASS WITH DEGRADED REVIEWER HEALTH - deterministic checks are clean, but this is not an approval signal. **Next step:** Rerun PR sanity or inspect the degraded reviewer lane before unattended merge. - PR: `826` - Commit: `6223226300e048cfa2c7796fd37ff43fb409b2d4` - Status: `eligible_sanity_clean` - Reviewer health: `degraded` - Security-sensitive label: `missing` - Authority: Patchwarden policy signal; branch protection and automerge controller remain merge authority. - Model mix: `glm-5.2:cloud`, `deepseek-v4-pro:cloud`, `kimi-k2.7:cloud` ## What I checked - Changed files: `1` - Deterministic blocker scan: `clean` - Model reviewer lanes: `3` - Comment contract: this comment is updated in place via a hidden Patchwarden marker. ## Approval Handoff - State: `not_ready_degraded_reviewer_health` - Action: rerun PR sanity or inspect the degraded reviewer lane before any unattended approval. - Boundary: branch protection and the automerge controller remain merge authority. ## Required Fixes No deterministic blockers. ## Reviewer Details <details> <summary>Model reviewer lanes</summary> ### `global-glm` / `glm-5.2:cloud` - Status: `ok` - Verdict: `OK` - Findings: none ### `global-deepseek` / `deepseek-v4-pro:cloud` - Status: `ok` - Verdict: `OK` - Findings: none ### `redteam` / `kimi-k2.7:cloud` - Status: `error` - Verdict: `-` - Note: Ollama HTTP 404: {"error": "model 'kimi-k2.7:cloud' not found"} - Findings: none </details> ## Policy notes - Patchwarden PR sanity is the first merge-lane signal for this PR. - Models produce findings; Patchwarden/policy produces decisions. - Model findings alone do not fail the status check; they require human or agent disposition. - Formal approval is separate from this comment and requires clean reviewer health. - Automerge remains delegated to branch protection and the automerge pilot.
Merge remote-tracking branch 'origin/main' into codex/issue-823-automerge-selfmerge-smoke
All checks were successful
canary-required / collect-diff (pull_request) Successful in 4s
canary-required / canary (pull_request) Has been skipped
base-is-main / guard (pull_request) Successful in 1s
patchwarden-client-dry-run / collect-diff (pull_request) Successful in 4s
patchwarden-pr-sanity / collect-diff (pull_request) Successful in 4s
patchwarden-client-dry-run / dry-run (pull_request) Successful in 57s
patchwarden-pr-sanity / sanity (pull_request) Successful in 1m22s
3b1d252a97
First-time contributor

No Patchwarden findings to render.

No Patchwarden findings to render.
Author
Collaborator

Status update from codex, 2026-06-25:

#826 was refreshed on top of #827 and rechecked at head 3b1d252a97f18934d7385fffb16aea4ab8272aa0.

Evidence from automerge-pilot run #5944:

  • Collect Forgejo facts: passed via token_env=GITHUB_TOKEN, proving #827 fixed the stale read-token blocker.
  • automerge_readiness.py: ready_for_controller_merge, ready=true.
  • Iskra Matrix approval: approved=true for PR #826 and exact head SHA.
  • Final merge actor: failed at /api/v1/user with HTTP 401 while loading PLATFORM_AUTOMERGE_BOT_TOKEN.

Interpretation: the remaining blocker is runner-local merge-bot credential validity, not PR readiness and not Patchwarden. I did not bypass this with codex/operator/GITHUB_TOKEN, because the W6d contract requires a separate non-cousin merge actor.

Next exact step: refresh/restore the runner-local PLATFORM_AUTOMERGE_BOT_TOKEN for the W6d merge-bot identity, then rerun automerge-pilot for #826 with execute_merge=true and confirm=AUTOMERGE_READY_W6D.

Status update from codex, 2026-06-25: #826 was refreshed on top of #827 and rechecked at head `3b1d252a97f18934d7385fffb16aea4ab8272aa0`. Evidence from `automerge-pilot` run #5944: - `Collect Forgejo facts`: passed via `token_env=GITHUB_TOKEN`, proving #827 fixed the stale read-token blocker. - `automerge_readiness.py`: `ready_for_controller_merge`, `ready=true`. - Iskra Matrix approval: `approved=true` for PR #826 and exact head SHA. - Final merge actor: failed at `/api/v1/user` with HTTP 401 while loading `PLATFORM_AUTOMERGE_BOT_TOKEN`. Interpretation: the remaining blocker is runner-local merge-bot credential validity, not PR readiness and not Patchwarden. I did not bypass this with codex/operator/GITHUB_TOKEN, because the W6d contract requires a separate non-cousin merge actor. Next exact step: refresh/restore the runner-local `PLATFORM_AUTOMERGE_BOT_TOKEN` for the W6d merge-bot identity, then rerun `automerge-pilot` for #826 with `execute_merge=true` and `confirm=AUTOMERGE_READY_W6D`.
First-time contributor

No Patchwarden findings to render.

No Patchwarden findings to render.
Merge remote-tracking branch 'origin/main' into codex/issue-823-automerge-selfmerge-smoke
All checks were successful
base-is-main / guard (pull_request) Successful in 1s
canary-required / collect-diff (pull_request) Successful in 4s
patchwarden-client-dry-run / collect-diff (pull_request) Successful in 4s
patchwarden-pr-sanity / collect-diff (pull_request) Successful in 4s
canary-required / canary (pull_request) Has been skipped
patchwarden-client-dry-run / dry-run (pull_request) Successful in 26s
patchwarden-pr-sanity / sanity (pull_request) Successful in 31s
6223226300
First-time contributor

No Patchwarden findings to render.

No Patchwarden findings to render.
Iskra approved these changes 2026-06-26 10:37:01 +02:00
Iskra left a comment

Approved by Iskra after W6d Matrix approval and deterministic readiness for the current PR head SHA.

Approved by Iskra after W6d Matrix approval and deterministic readiness for the current PR head SHA.
Iskra merged commit a1fa6c2101 into main 2026-06-26 10:37:01 +02:00
Iskra referenced this pull request from a commit 2026-06-26 10:37:03 +02:00
Sign in to join this conversation.
No reviewers
No labels
W6d-automerge-calibration
agent/claude-code
agent/codex
agent/hermes
agent/iskra
agent/ollama
agent/patchwarden
automerge-candidate
class/security-sensitive
cutover-gate
dependency/blocked
dependency/blocks-others
dependency/cross-repo
dependency/needs-confirmation
domain:agents
domain:ci
domain:docs
domain:forgejo
domain:infra
domain:memory
domain:runtime
domain:signal
domain:ux
flow/architecture
flow/blocked
flow/deployed
flow/done
flow/implementation
flow/intake
flow/maintained
flow/observed
flow/ready
flow/refining
flow/retired
flow/review
iterating
judge/codex-candidate
judge/hermes-candidate
judge/low-confidence
judge/needs-refinement
judge/operator-needed
judge/p0
judge/p1
judge/p2
judge/p3
judge/park
judge/patchwarden-candidate
judge/stale-priority
kind/adr
kind/bug
kind/chore
kind/feature
kind/infra
kind/ops
kind/refactor
kind/research
large-impact
merge/auto
merge/manual
merge/manual-dependency-conflict
merge/manual-failing-tests
merge/manual-merge-conflict
merge/manual-missing-review
merge/manual-operator-preference
merge/manual-red-zone
merge/manual-security-sensitive
merge/manual-unclear-scope
merge/manual-unknown
meta
mode:operator-only
mode:patchwarden-iskra-approved
mode:safe-auto
needs-operator-decision
needs-triage
not-ready
observed/erroring
observed/needs-followup
observed/pending
observed/retire-candidate
observed/unused
observed/used
operator-emotional
owner-attention
phase/02
phase/03
priority:p0
priority:p1
priority:p2
priority:p3
proposed
ready-for-agent
ready-for-operator
recovery
review:claude-reviewed
review:codex-reviewed
review:dziadek-reviewed
review:needs-human
risk/exposure
risk/process
risk/product
risk/runtime
safety:external-write
safety:no-prod-mutation
safety:prod-impact
safety:secret-touch
size/large
size/medium
size/small
size/tiny
size/unknown
source/adr
source/agent-generated
source/manual
source/operator-chat
source/voice-note
status:blocked
status:codex-ready
status:merged:pending-evidence
status:needs-evidence
status:operator-needed
status:parked
tier/full
tier/lite
tier/stacked
tier:0-platform-substrate
tier:1-iskra-value-layer
tier:2-tools-products-modules
type:bug
type:chore
type:docs
type:feat
type:policy
type:research
No milestone
No project
No assignees
4 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
pdurlej/platform!826
No description provided.