Skip to content

Machine-enforce human review on governed-surface paths — so the no-bypass rule stops resting on seat discipline alone #6596

Description

@os-zhuang

Provenance: maintainer ruling 2026-08-27 (PM chat, decision-inbox batch 1, adjudication session session_01DKWDdUJ2XNRESVVWUvcpnh), verbatim: 「同意,并继续」 — accepting Option A + C on #6325. Option C is this card: the un-reviewed AGENTS.md merge stands (audit record on #6325), and the governed-surface no-bypass rule becomes machine-enforced so the next incident does not depend on seat discipline.

Why seat discipline is not enough (measured incident)

PR #6183 (governed surface: AGENTS.md) was correctly draft-parked; a GitHub MCP update_pull_request call passing only reviewers silently set draft: false; the PR entered the merge queue and merged as 5b3290fd5 with no human approval. Converting back to draft did not dequeue it. Platform fact: objectstack-ai/objectstack#12200. The mechanism — hidden tool side effect + irreversible queue — will recur.

Scope

Make human review mechanically required for this repo's governed surface (2026-08-18 definition): AGENTS.md, CLAUDE.md, .claude/**, skills/**, docs/adr/**.

Candidate shapes — the implementer measures which is viable, does not assume:

  • .github/CODEOWNERS entries scoped to exactly the governed paths, plus the branch-protection "require review from Code Owners" setting. The settings half is a GitHub-UI change only the maintainer can make — if this shape is chosen, the PR half lands the CODEOWNERS file and the card then moves to pm:awaiting-maintainer naming the exact toggle.
  • A required status check that fails any PR touching governed paths unless an explicit human approval review is present.

Constraints:

  • The door must not block the normal dev-PR merge queue for PRs that do not touch governed paths.
  • The enforcement change itself touches governed/config surface — it lands as a draft PR for human merge, per the same rule it enforces.
  • Named reader: the objectui execution seat that implements it; central triage routes the domain label.
  • Sibling repos carry the same gap; mirroring is a separate triage/maintainer call once this repo's shape is proven — not part of this card.

Refs: #6325 (incident decision + audit record), PR #6183 (timeline), objectstack-ai/objectstack#12200 (tool fact).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions