Skip to content

[finding] Governed Surface Queue Guard: the merge_group leg installs no dependencies, so the #11705 generated-surface lift NEVER applies at queue time — pure-regeneration PRs still need a human APPROVED review; the trade needs a ruling #12874

Description

@os-sales

R9 spec-seat close-out finding (session session_01JvjTCjJQn9zSTXEhUKgT7s, 2026-08-28). Recording only — unassigned. This is a decision-needing mismatch between two mechanisms that both claim to answer "is this diff governed": it should be graded toward a maintainer ruling, not silently fixed either way.

The mismatch, measured on PR #12718

Cost observed this shift

One code PR whose only governed-glob touch was a byte-identical regenerated index consumed: one queue kick, one standing-down comment, one review request, and one maintainer interaction — for a diff the register's own predicate calls not governed. Multiply by every future spec PR whose regeneration sweeps the skills index.

The question for the ruling (options, not a recommendation)

A. Accept the cost: human review stays the queue-time answer for anything under a governed glob; document it so seats park such PRs for review immediately instead of discovering the kick. (Status quo, now documented.)
B. Let the merge_group leg install the minimal dependency closure needed by the generators' --check twins so the #11705 lift works at queue time — pays queue latency for lift fidelity.
C. Precompute: a pull_request-leg artifact (byte-equality attestation signed by the run) that the merge_group leg can verify without deps.

Refs: #11705, #10277, #8161, #9495; PR #12718 (both kicks + the recovery); scripts/pm/check-governed-merges.mjs header.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions