The fleet roster names three review bots and triage — and neither identity that opens every PR. Who is in it, now that the roster also spends actions: write?
#435
AnalysisWhere this came from. @cndgrr surfaced it mid-build on #424, measured against this repository, and correctly declined to edit the roster: "a builder quietly adding itself to the list of identities allowed to spend Measurement 1 — the three confs are identical, and none of them names a builder. No Measurement 2 — the identities that open every PR are in none of it. The last twelve PRs here are What that costs the moment #424 lands. #424 D3's gate 1 measures the label's actor against A — a per-author row per live builder login. B — a dedicated C — leave it. Costs nothing, grants nothing, and is not absurd: triage is in One inconsistency the same edit should settle. What is not being asked. Nothing about repository permissions. Every option here leaves Why this is a discussion and not an issue. Nothing on the board is blocked, so there is nothing to flag: #424 is |
Replies: 4 comments
Cost re-measure — #424 landed 26 minutes ago, so this ask's
|
| repo | ci-rerun present |
rerun-owed in label set |
refusal live? |
|---|---|---|---|
ceremony |
yes — main at d956a11 |
yes, D4C5F9 |
yes, now |
crew |
no — pinned @0.6.2 |
no — 404 |
at its pin bump |
incubator |
no — pinned @0.7.3 |
no — 404 |
at its pin bump |
No tag carries #424: the newest is 0.7.3 and main is armed at 0.7.4-dev. The two consumers are not degraded and will not be until a cut and a pin bump each. I am not proposing a cut, and none is owed by this.
Understated: here, it is not hypothetical
The gate reads the actor of the labeled event against .github/labels.conf and returns REFUSE:actor at ci-rerun.sh:241, before it reads any evidence. Re-measured live at this write, all three confs are still byte-identical in the two fields it reads, and no panel[<login>]= row exists in any of them:
panel=claude-bot-andresmgsl codex-bot-andresmgsl kimi-bot-andresmgsl
triage-actors=dan-claude-bot
Two PRs are open here right now, authored by exactly the two logins in neither field — #438 (@cndgrr) and #436 (@andriujoseba). If either head goes red on an infrastructure failure and its author sets rerun-owed as LABELS.md instructs, the gate refuses the setter.
Which makes this a live disagreement on main, between two things that both shipped today
LABELS.md:102 ships "Set by the builder with its evidence". ci-rerun refuses that builder. Neither is wrong against its own issue — #423 named the setter, #424 built the roster gate — and the seam between them is precisely what this ask asks. It is worth saying plainly that this is now readable in the tree rather than predicted.
What inaction selects, which is new since the ask
Before the merge, the hard block held nothing behind it. It is no longer neutral. With no conf edit, the only identity that can set rerun-owed and be admitted is dan-claude-bot — so the fleet is operating under option C by default, unruled: the builder posts the evidence, triage sets the label, the gate admits, and ci-rerun reads the evidence from the PR author anyway, which it already does by design (:351-353). C therefore works today at zero file cost. Its price is a triage round-trip on every stall — which is a smaller version of the human round-trip #423 exists to remove — plus a LABELS.md correction, since the shipped row would name the wrong setter.
Recommendation unchanged — A. A per-author panel[<login>]= row enrols the bracketed login as fleet and sets that author's panel; written with the same three reviewers, it changes no required review set, needs no consumer schema change, and parses on every pin in the fleet today. What has changed is only that C is now the status quo rather than a third option, so choosing C is ratification rather than a change.
Default unchanged — none, hard block, and structurally: who these two identities are is a fact only you hold, and no elapsed time can make that default fire. Nothing here is a re-ask or a second venue — the answer belongs on this thread.
Cost re-measure — the degraded set is two of three repositories as of today, not one. The ask is unedited and still yoursBacklog-hygiene pass, What moved since my 2026-08-15
|
| repo | ci-rerun caller |
rerun-owed in label set |
builder login in FLEET |
refusal live? |
|---|---|---|---|---|
ceremony |
yes | yes, D4C5F9 |
no | yes (since 2026-08-15) |
incubator |
yes — .github/workflows/ci-rerun.yml on main |
yes, D4C5F9, byte-identical to the shipped row |
no | yes — as of today |
crew |
no — still pinned @0.6.2 |
no | — | not yet |
Measured at heavy-duty/incubator's own .github/labels.conf:
panel=claude-bot-andresmgsl codex-bot-andresmgsl kimi-bot-andresmgsl
triage-actors=dan-claude-bot
No panel[<login>]= row, so load_fleet at the pin builds a FLEET containing three review bots and triage and no builder login. Gate 1 of ci-rerun.sh measures the label's actor against exactly that list, so on that board a builder-set rerun-owed is refused by name, and the day-one servicing path is: the builder posts the 🔁 rerun owed at head <sha> evidence on its own PR, asks triage, triage applies the label, gate 1 admits triage-actors. One round trip per stalled head.
Why that changes the price rather than just the count
The second repository is the one the whole arc came from — incubator#212, the red head nobody in the fleet could rerun, twice in a day. The refusal is now live in the repository whose incident produced it, and the humans building there hit it on the next unrerunnable red rather than on the next pin bump. That is not an argument for any of A, B or C; it is the wait's cost, and it stopped being hypothetical today.
Nothing else moves. Stops — nothing is still true and re-measured: this board's only open issue is #423, post-merge on a wake condition this ruling does not gate, and no open issue anywhere declares this thread as a blocker. No needs-ruling mirror is owed on the board, which is why none is set. Options A, B, C and the recommendation of A are exactly as written; the decision is still yours, @danmt, and the hard-block default means it cannot be taken by anyone else, including me.
Ruled: A. Recorded as a decision, transcribed into four mints, and the flag comes down@danmt ruled A at The decisionEach governed repository's A's central claim is now measured rather than argued. I ran both shipped parsers over each repository's real conf, before and after the two lines, at each board's own pin —
So the review side does not move and the rerun side does, which is what A promised. The cost A was chosen with also stands unchanged: one field now carries two facts, and a later edit to a panel row is silently an edit to the rerun roster. What was written
Each carries the file content in its spec, so the builder transcribes a decision instead of choosing who is in the fleet. None of the four blocks another. #453 is A's one measured side effect. What A does not touch, restated so nothing is read into it
The one thing the ruling did not settle, which is not being droppedThe ask's analysis raised a second, independent disagreement in the same file pair: Flag stateThis ask carried no |
A is fine @dan-claude-bot