Skip to content

verify-satisfied tells the agent to arm auto-merge when the base has no required contexts (would merge instantly) #121

Description

@hyperpolymath

What happens

squabble verify-satisfied tells the agent to arm auto-merge on a PR whose base branch has no required status checks. In the same verdict it warns that arming would merge the PR at once. AGENTS.md §5c item 5 forbids exactly that ("Never arm automerge on a repo with no required contexts — it merges instantly"). Such a PR can never reach exit 0 without breaking the rule, so the agent is stuck.

Where

crates/squabble-core/src/done.rs on feat/verify-satisfied (PR #119), section "5 + 6", around line 446:

None if facts.merge_state == "BLOCKED" || required_pending => {
    agent.push(Item::AutoMergeNotArmed { .. })
}

The arm is not guarded by "the base has at least one required context". The warning about this goes only into notes, so it does not affect the verdict.

Measured (2026-10-01, squabble 0.1.0 at ~/.local/bin/squabble)

PR mergeStateStatus required contexts agent_items
hyperpolymath/occupancy-types#4 BLOCKED (APPROVED, rollup SUCCESS) none auto_merge_not_armed
metadatastician/bowtie-workbench#7 BLOCKED none auto_merge_not_armed
metadatastician/sim-public-relations#31 BLOCKED none auto_merge_not_armed

In each case, notes[0] reads: "no required status checks on the base branch — automerge would merge on arming, before any review bot reports".

All three rulesets carry a code_scanning rule. None of the three heads has a CodeQL run. The BLOCKED state most likely comes from that rule. Squabble lists code_scanning in neither agent_items nor its "not evaluated" note.

Second, smaller defect: text rendering

When held_by_human is empty, the text renderer prints notes straight after the agent items and leaves out the notes: header. The warning then reads as a third agent instruction ("agent must act: … – no required status checks …"). On git-seo#25 the same notes appear under "held by a human" instead.

Acceptance criteria

  • When the base has no required contexts, verify-satisfied never emits AutoMergeNotArmed. A BLOCKED PR goes to held_by_human, with a kind that names the reason (e.g. blocked_without_required_contexts, carrying the effective rule types).
  • A code_scanning rule whose tool has produced no analysis on the head is reported, as an item or at least by name in the BLOCKED safety-net note. It is not left unmentioned.
  • The text output always prints the notes: header, so a note can never render as an agent or human item.
  • Regression tests: one fixture per case above, plus a positive control: a repo with a required context still gets AutoMergeNotArmed when BLOCKED.
  • Mutant check: dropping the new guard turns the no-required-context test red.

Found while running verify-satisfied across the 71 ORCID citation PRs.

🤖 Generated with Claude Code

https://claude.ai/code/session_01B2ARtAVppZ7x7mVY5u6nAz

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions