Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 93 additions & 5 deletions scripts/pm/check-governed-merges.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -416,7 +416,10 @@
* verbatim and extend the audit to read the enqueue actor from the issue
* timeline (`added_to_merge_queue`) — never remap silently. A mainline commit
* whose subject names NO PR is listed as its own loud entry (a direct push to
* `main` is more anomalous than any PR merge, not less).
* `main` is more anomalous than any PR merge, not less). Such an entry has no
* pull request to query, so its attribution column reads NOT LOOKED UP, never
* "every channel failed" — the three-way column at `attributionCell` (#12645)
* carries that distinction and the reason it is not cosmetic.
*
* ### The attribution channel chain (#9619, measured on the PM container)
*
Expand DownExpand Up@@ -1430,6 +1433,58 @@ export function summariseAttributionFailures(entries) {

// ── rendering ───────────────────────────────────────────────────────────────

/**
* The attribution column, THREE ways (#12645) — because "nothing was found"
* and "nothing was looked at" are different facts, and this report keeps them
* apart everywhere else (#4690: an unaudited repo is not a clean repo, a
* window whose boundary is unproven is not an empty window).
*
* The column used to be picked on `entry.attribution` alone, so an entry with
* no attribution rendered "every channel failed; see the attribution note
* below" — and the ONE entry shape that can reach that branch without a single
* channel having been tried is the loudest line the sweep prints: a mainline
* commit whose subject names no PR (`main()` skips it: `if (entry.pr == null)
* continue` — there is no pull request to query). Measured 2026-08-27 on a
* constructed sweep, that line claimed every channel failed four lines under a
* printed `0 API lookup(s)`, and referred the reader to a note
* `summariseAttributionFailures` never produces for it (that function groups
* only entries carrying `attributionError`, and this one carries none). A
* false claim on the most anomalous entry in the list is exactly the line a
* reader learns to discount.
*
* 1. resolved — a channel answered; it names which one.
* 2. UNAVAILABLE — `attributionError` is present: channels WERE tried and
* all failed. ⚠️ This is the only branch that may point
* at the attribution note, because it is the only one
* `summariseAttributionFailures` writes a line for.
* 3. NOT LOOKED UP — no reading was attempted. The reason is READ off the
* entry, never assumed: absent PR number is the case
* `main()` produces, and an entry that has a PR number
* yet reached here gets the honest residual instead of
* being told it has no PR number — asserting an untried
* channel and asserting an absent PR number are the same
* defect wearing different words.
*
* ⛔ Report-only. This changes no judgment: `attributionFailed` (and with it
* the INCOMPLETE exit) is still set only by a real channel failure, and a
* PR-less entry is still its own loud entry — a direct push to `main` is more
* anomalous than any PR merge, not less. Pure, so `--self-test` asserts on the
* words.
*/
export function attributionCell(entry) {
if (entry.attribution) {
return (
`merged_by ${entry.attribution.mergedBy ?? '(none)'} @ ${entry.attribution.mergedAt ?? '(unknown)'} ` +
`(via ${entry.attributionChannel ?? 'unknown channel'})`
);
}
if (entry.attributionError) return `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
if (entry.pr == null) {
return `merged_by NOT LOOKED UP — no PR number in the subject, so there is no pull request to query (not a channel failure)`;
}
return `merged_by NOT LOOKED UP — no attribution reading was recorded for this entry (not a channel failure)`;
}

/**
* The window, in the words the operator reads — pure, and the half of route A
* the #12633 ruling names explicitly: the back-off has to be SAID, or a
Expand DownExpand Up@@ -1517,9 +1572,7 @@ export function renderReport({ window, repos, scanned, entries, lookups }) {

const lines = entries.map((e) => {
const surfaces = e.surfaces.map((s) => `${s.glob} ×${s.files.length}`).join(', ');
const who = e.attribution
? `merged_by ${e.attribution.mergedBy ?? '(none)'} @ ${e.attribution.mergedAt ?? '(unknown)'} (via ${e.attributionChannel ?? 'unknown channel'})`
: `merged_by UNAVAILABLE — every channel failed; see the attribution note below`;
const who = attributionCell(e);
const prName = e.pr != null ? `PR #${e.pr}` : '⚠️ NO PR NUMBER IN SUBJECT — direct push to main? investigate';
const files = e.surfaces.flatMap((s) => s.files.slice(0, 6)).slice(0, 8);
return ` • ${e.repoSlug ? `${e.repoSlug} ` : ''}${prName} — ${e.subject}\n commit ${e.sha.slice(0, 9)} @ ${e.date}; ${who}\n surfaces: ${surfaces}\n${files.map((f) => ` - ${f}`).join('\n')}`;
Expand DownExpand Up@@ -2196,6 +2249,41 @@ async function selfTest() {
assert('a-resolved-column-carries-the-account-is-not-a-principal-caveat', resolvedReport.includes('names an ACCOUNT, not a principal'), resolvedReport);
assert('the-caveat-is-absent-when-nothing-resolved', !unresolvedReport.includes('names an ACCOUNT, not a principal'));

// ── the attribution column's THIRD case (#12645) ──────────────────────────
// The two fixtures above are cases 1 and 2; the PR-less mainline entry —
// the loudest line the sweep prints — is case 3, and it used to render
// case 2's words with zero channels tried. All three are pinned as a set,
// because the defect was a two-way split covering three facts.
const notLookedUp = renderReport({ window: dateWindowFor('2026-08-13T00:00:00Z'), repos: allAudited, scanned: 3, entries: [noPr], lookups: 0 });
assert('a-pr-less-entry-is-NOT-LOOKED-UP-not-a-failed-lookup', notLookedUp.includes('merged_by NOT LOOKED UP') && !notLookedUp.includes('every channel failed'), notLookedUp);
assert('and-it-says-WHY-nothing-was-queried', notLookedUp.includes('no PR number in the subject') && notLookedUp.includes('not a channel failure'), notLookedUp);
// The dangling pointer half of the defect: it named a note that this very
// report never prints for it, because the note groups attributionError only.
assert('a-not-looked-up-entry-points-at-no-attribution-note', !notLookedUp.includes('attribution note below'), notLookedUp);
assert('and-the-report-prints-none-for-it', summariseAttributionFailures([noPr]).length === 0, JSON.stringify(summariseAttributionFailures([noPr])));
assert('the-note-pointer-belongs-to-the-every-channel-failed-case-alone', unresolvedReport.includes('attribution note below'), unresolvedReport);
// Report-only: the loud entry stays loud, and a case-3 column is still not
// a resolved one (no ACCOUNT-not-a-principal caveat, nothing to prompt on).
assert('the-third-case-does-not-soften-the-direct-push-warning', notLookedUp.includes('NO PR NUMBER IN SUBJECT — direct push to main? investigate'), notLookedUp);
assert('and-carries-no-resolved-column-caveat', !notLookedUp.includes('names an ACCOUNT, not a principal'));
// The cell function itself, all three classes plus the residual.
assert('cell-case-1-resolved-names-its-channel',
attributionCell({ attribution: { mergedBy: 'os-steve', mergedAt: '2026-08-18T09:00:00Z' }, attributionChannel: 'anonymous', pr: 5188 })
=== 'merged_by os-steve @ 2026-08-18T09:00:00Z (via anonymous)');
assert('cell-case-2-every-channel-failed-needs-an-attributionError',
attributionCell({ pr: 101, attributionError: 'anonymous REST: HTTP 403' }).startsWith('merged_by UNAVAILABLE — every channel failed'));
assert('cell-case-3-no-pr-number-is-nothing-to-query', attributionCell({ pr: null }).startsWith('merged_by NOT LOOKED UP — no PR number in the subject'));
// ⛔ An entry that HAS a PR number must never be told it has none: asserting
// an untried channel and asserting an absent PR number are the same defect.
const residual = attributionCell({ pr: 4242 });
assert('cell-residual-never-invents-a-missing-pr-number', residual.startsWith('merged_by NOT LOOKED UP') && !residual.includes('no PR number'), residual);
assert('and-the-residual-is-not-a-channel-failure-either', !residual.includes('every channel failed') && !residual.includes('attribution note below'), residual);
// An attributionError never outranks a real reading, and a resolved entry
// is never demoted by a stale PR-less shape.
assert('a-resolved-reading-outranks-a-stale-error',
attributionCell({ attribution: { mergedBy: 'x', mergedAt: 'y' }, attributionChannel: 'env-token', pr: null, attributionError: 'HTTP 401' })
=== 'merged_by x @ y (via env-token)');

// ── the --test pre-arm predicate (#9550) ──────────────────────────────────
const governedCase = testVerdict(['AGENTS.md']);
assert('--test-on-the-#9527-file-list-answers-GOVERNED', governedCase.governed === true && governedCase.hitPaths.join() === 'AGENTS.md', JSON.stringify(governedCase));
Expand DownExpand Up@@ -2505,7 +2593,7 @@ async function selfTest() {
for (const failure of failures) console.error(` • ${failure}`);
process.exit(1);
}
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
console.log(`✓ check-governed-merges --self-test: ${checked} assertions (the unified governed predicate + near misses, subject→PR spellings, window parsing, the #12633 landing window — the QS-7 regression pin in both directions, the topological close beyond the budget, the unproven-boundary EDGE, the listed-or-INCOMPLETE invariant over every fixture, the escalating floors, per-repo --since-ref resolution and its named fallback, and the window words — the replay fixtures, the four-repo resolution incl. absent/wrong-origin/relocated checkouts, the attribution channel chain + its proxy-transport re-arm plan and its one named fallback line, the three-way attribution column (resolved · every-channel-failed · NOT LOOKED UP, and the note pointer that belongs to the middle one alone), the --test pre-arm predicate, the generated-artifact provenance exception — the four ruled cases against the generator's own splice, byte-exactness, fail-closed inputs, the untouched mixed-diff rule, single-file-not-a-class, the #11084 generator co-edit fence in both directions, and its render words — the #11705 generator-owned rows inside skills/** (a genuine generated file passes, the same path hand-edited does not, a path no generator declares is hand-authored content, per-row fences, and the enumeration read from the real generator), the exit table, and the report wording pins).\n ${liveNote}`);
}

/** The exit code `--test` would return for a path list — pinned without spawning. */
Expand Down
Loading