You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Decision] permissions.deny: extend declared = enforced to the enqueue class — deny mcp__github__enable_pr_auto_merge too, or keep it hook-guarded only? #18282
Filed by the domain:skills execution PM seat, session session_01HZfg2AwVX191qCizp88gQr, at 2026-09-15T07:16Z, from the #18218 dev's assumption-(3) reading (report 5676241066; PR #18276). The decision is the maintainer's — the deny list is the maintainer-level lever — so the seat puts the question rather than guessing.
The reading
mcp__github__enable_pr_auto_merge is NOT in permissions.deny (15 entries after PR fix(settings,pm-dispatch): deny mcp__github__update_pull_request and route the ready flip through the CCR routes #18276). It is matched by the PreToolUse hook guard-governed-enqueue.sh (settings.json :82; hook header :5), which blocks only a governed PR's enqueue that lacks a pinned approval — a different mechanism from a deny, and one that lets a non-governed enqueue through MCP under the bound user account.
A (seat recommends) — deny mcp__github__enable_pr_auto_merge (and disable_pr_auto_merge, the same class) in lock 1; the hook stays as defence in depth; rest-channel :53 drops the 「备用 MCP 未拒」 clause. Four axes: the REST route already serves every real enqueue (实际业务需求); one write channel, no dialect (长远合理性); a tool the runtime refuses cannot be mis-called by a seat that mis-reads the hook's scope (防 AI 犯错); immediate, no staged window (创业阶段).
B — keep it hook-guarded only; the deny list stays a content-write roster; the prose keeps naming the exception.
Answer with 「A」 or 「B」 on this card; the seat then grades the executable half (A: one deny entry + one rest-channel line, rules layer, four-piece) as a Task in this lane. needs-user-decision · domain:skills · p3.
Filed by the
domain:skillsexecution PM seat, sessionsession_01HZfg2AwVX191qCizp88gQr, at 2026-09-15T07:16Z, from the #18218 dev's assumption-(3) reading (report 5676241066; PR #18276). The decision is the maintainer's — the deny list is the maintainer-level lever — so the seat puts the question rather than guessing.The reading
mcp__github__enable_pr_auto_mergeis NOT inpermissions.deny(15 entries after PR fix(settings,pm-dispatch): deny mcp__github__update_pull_request and route the ready flip through the CCR routes #18276). It is matched by the PreToolUse hookguard-governed-enqueue.sh(settings.json :82; hook header :5), which blocks only a governed PR's enqueue that lacks a pinned approval — a different mechanism from a deny, and one that lets a non-governed enqueue through MCP under the bound user account.PUT …/pulls/N/ccr/auto_merge, rest-channel :50); the write-identity rule (Lock 1 is inert in running sessions: the harness loads.claude/settings.jsonandos-dev.mdfrom the shared checkout at clone time — an MCP-created PR after both deny lists landed, and the charter's constant-claude[bot]lines are false #18205 → PR docs(pm,agents): write identity follows the channel, not the account — REST-only content writes, the ACCEPT refuses MCP writes, a stale shared checkout re-seats (#18205) #18216) makes an MCP enqueue a user-account write. rest-channel :53 after PR fix(settings,pm-dispatch): deny mcp__github__update_pull_request and route the ready flip through the CCR routes #18276 states the fact precisely: 「auto-merge 备用 MCP 未拒」.Options
mcp__github__enable_pr_auto_merge(anddisable_pr_auto_merge, the same class) in lock 1; the hook stays as defence in depth; rest-channel :53 drops the 「备用 MCP 未拒」 clause. Four axes: the REST route already serves every real enqueue (实际业务需求); one write channel, no dialect (长远合理性); a tool the runtime refuses cannot be mis-called by a seat that mis-reads the hook's scope (防 AI 犯错); immediate, no staged window (创业阶段).Answer with 「A」 or 「B」 on this card; the seat then grades the executable half (A: one deny entry + one rest-channel line, rules layer, four-piece) as a Task in this lane.
needs-user-decision·domain:skills· p3.Generated by Claude Code