Skip to content

Keep nested doctor repairs opt-in for current-target runs - #298

Merged
NagyVikt merged 1 commit into
mainfrom
agent/codex/scope-gx-doctor-current-to-current-repo-2026-04-22-13-13
Apr 22, 2026
Merged

Keep nested doctor repairs opt-in for current-target runs#298
NagyVikt merged 1 commit into
mainfrom
agent/codex/scope-gx-doctor-current-to-current-repo-2026-04-22-13-13

Conversation

@NagyVikt

Copy link
Copy Markdown
Collaborator

Automated by gx branch finish (PR flow).

Recursive doctor now defaults to traversing nested repos, but targeted repair needs a short alias that stays on the selected repo. This wires --current through the existing single-repo path, updates the recursive hint text, adds a regression that keeps a nested repo broken during scoped runs, and backfills the matching OpenSpec change.

Constraint: Recursive doctor must stay the default behavior for parent repo repairs

Rejected: Add a shared --current traversal flag for setup and other commands | would widen CLI semantics beyond this doctor follow-up

Confidence: high

Scope-risk: narrow

Reversibility: clean

Directive: Keep --current doctor-only unless another command gets explicit OpenSpec coverage for the alias

Tested: node --check bin/multiagent-safety.js; node --test test/doctor.test.js; openspec validate doctor-current-single-repo-alias --type change --strict; openspec validate --specs

Not-tested: Manual run against a live nested repo outside the test harness
@NagyVikt
NagyVikt merged commit c14c63c into main Apr 22, 2026
@NagyVikt
NagyVikt deleted the agent/codex/scope-gx-doctor-current-to-current-repo-2026-04-22-13-13 branch April 22, 2026 11:39
NagyVikt added a commit that referenced this pull request Jul 9, 2026
* fix(branch): honor --gate-review in `gx branch finish`

`gx branch finish` passed its argv straight to agent-branch-finish.sh via
invokePackageAsset, bypassing src/finish/index.js where runReviewGate lives.
Two consequences: the script exits 1 on the unknown `--gate-review` argument,
and its --via-pr path merges the moment the PR opens (the unconditional
`gh pr merge` before the wait/auto fallbacks). So the documented default
workflow could never gate, and merged fail-open.

Split the gx-level gate flags out of the script's argv and run runReviewGate
before invoking the script. It throws on a dirty review, red CI, or a PR
GitHub will not merge, so the script -- and the merge -- never runs. Unrelated
flags (--auto-resolve, --no-preflight, ...) still reach the script untouched.

This is the gap that let lifted.sk-storefront PR #298 merge with its `review`
check skipped.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(branch): resolve the gated base the way the shell does

Code review caught a wrong-merge-target hazard. The gate resolved the base with
resolveBaseBranch, which only knows the explicit --base, the global config, and
the detected default. agent-branch-finish.sh instead honors the per-branch
branch.<name>.guardexBase when --base is omitted (agent-branch-finish.sh:504),
as does `gx finish` via resolveFinishBaseBranch.

With `branch.agent/x.guardexBase=dev` and no --base, the gate would open and
review a PR against main while the shell merged into dev — reviewing one base
and merging into another. Use resolveFinishBaseBranch so both agree.

Cover it, plus the inline --branch=/--base= form and the no-gate-flag
passthrough that every repo depends on. The suite's git stub now exposes
resolveFinishBaseBranch, so a regression to the old helper fails loudly.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: NagyVikt <nagy.viktordp@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant