Skip to content

feat(pr-management): let a project allow specific @-mentions everywhere - #1584

Merged
potiuk merged 3 commits into
perf/pr-mgmt-9-mentor-routing-prefirstfrom
perf/pr-mgmt-10-mention-allowlist
Oct 10, 2026
Merged

potiuk merged 3 commits into
perf/pr-mgmt-9-mentor-routing-prefirstfrom
perf/pr-mgmt-10-mention-allowlist

Conversation

@potiuk

@potiuk potiuk commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Every pr-management renderer keeps only the PR author's @-mention live and backtick-quotes every other handle, and the agent-guard mention guard refuses the rest. A project had no way to say "this bot / this team may be mentioned" short of a per-command override.
  • A new mention_allowlist key in pr-management-config.md names handles and teams that stay live. One shared helper honours it in every renderer (triage notes, stale-sweep comments, mentor comments, code-review bodies), and so does the guard on every surface it checks (comments, folded notes, reviews, gh api writes).
  • One call can add a handle with --allow-mention <login>, paired with MAGPIE_ALLOW_MENTIONS=1 on the posting command, so the exception is explicit in both places.

Top of the stack.

Security notes

  • The guard reads the allowlist, and the mentoring hand-off team, from .apache-magpie-overrides/ as GitHub serves it from the target repository's default branch, not from the local checkout, which the agent can edit, commit to, or swap for a scratch repository. Only a reviewed, merged change can widen what may be mentioned. This replaces the local committed-file check the hand-off exemption used in the bottom PR of the stack.
  • The target must be explicit and unambiguous: --repo and/or a PR or issue URL as the selector, all agreeing, or a plain repos/OWNER/REPO/… endpoint for gh api.
    • There is no fallback to the checkout's repository, which a cd or GH_REPO earlier on the line could redirect.
    • A URL in body text does not count.
    • Endpoints with ./.. segments, percent-encoding or {owner} placeholders are refused.
    • GraphQL writes get no allowlist.
  • The guard reads gh's arguments the way gh does, with each flag's arity for the comment, edit and review commands, so a flag's value (--body "-Racme/x @bob") is never taken for --repo or the selector; the attached -ROWNER/REPO form counts, and an unknown flag, combined short flags or an extra positional leave the target ambiguous.

Type of change

  • Tool change (agent-guard, tools/pr-management)
  • Skill and config-template docs

Test plan

  • prek run --all-files passes
  • agent-guard pytest: allowlist and hand-off cases, plus locally committed config ignored, another repository's config ignored, and every ambiguous-target spelling above
  • tools/pr-management pytest (tests/test_mentions.py)

Was generative AI tooling used to co-author this PR?
  • Yes — Claude Code (Opus 5). I reviewed the diff and the test results; commits carry Generated-by:.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv

@potiuk potiuk added family:pr-management pr-management-* skills family:setup setup-* skills family:tools tools/* capability:platform Framework / agent substrate skills (install, verify, doctor, override, status, setup bootstrap) labels Oct 10, 2026
@github-actions github-actions Bot added family:docs Docs, MISSION.md, READMEs capability:triage Sweep + classify + propose disposition capability:review Deep per-item code review or contributor mentoring substrate:analytics Tool substrate: read-only metrics / dashboards / renderers substrate:action-guard Tool substrate: deterministic pre-tool-use command guards labels Oct 10, 2026
@potiuk
potiuk added this pull request to stack #1586 October 10, 2026 09:23
@potiuk
potiuk force-pushed the perf/pr-mgmt-10-mention-allowlist branch 2 times, most recently from dcd8d02 to d9a6991 Compare October 10, 2026 10:18
Every pr-management renderer keeps only the PR author's @-mention live
and backtick-quotes every other handle, and the agent-guard `mention`
guard refuses the rest. There was no way for a project to say "this
bot / this team may be mentioned" short of a per-command override.

A new `mention_allowlist` key in `pr-management-config.md` names the
handles and teams that stay live, honoured by one shared helper in
every renderer — triage notes, stale-sweep comments, mentor comments
and code-review bodies — and by the guard on every surface it checks
(comments, folded notes, reviews, `gh api` writes). One call can add a
handle with `--allow-mention <login>`, paired with
`MAGPIE_ALLOW_MENTIONS=1` on the posting command so the exception is
explicit in both places.

The guard reads the allowlist, and the mentoring hand-off team, from
`.apache-magpie-overrides/` as GitHub serves it from the target
repository's default branch — not from the local checkout, which the
agent can edit, commit to, or swap for a scratch repository. Only a
reviewed, merged change can widen what may be mentioned. The target
must be explicit and unambiguous: `--repo` and/or a PR or issue URL as
the selector, all agreeing, or a plain `repos/OWNER/REPO/…` endpoint
for `gh api`; there is no fallback to the checkout's repository, a URL
in body text does not count, an endpoint with `.`/`..` segments,
percent-encoding or `{owner}` placeholders is refused, and GraphQL
writes get no allowlist. This replaces the local committed-file check
the hand-off exemption used.

Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv
…n target

gh accepts `-ROWNER/REPO` as well as `-R OWNER/REPO` and `--repo=`, and the
last value wins. The mention guard read only the separated and `=` forms,
so `gh pr comment 5 --repo acme/product -Rvictim/other` posted to
victim/other while the guard applied acme/product's allowlist. Every
spelling now counts, and two that disagree leave the target ambiguous,
so no allowlist applies.

Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv
…ntion target

The mention guard found the target repository by scanning tokens, so a
flag's value could pass for a repository: `gh pr comment 5 --body
"-Racme/product @bob"` made the guard apply acme/product's allowlist while
gh posted to the checkout's repository.

The arguments are now read the way gh reads them, with each flag's arity
for the comment, edit and review commands: a value is never taken for
`--repo` or the selector. A line the guard cannot read for certain — an
unknown flag, combined short flags, a second positional, or a second
`gh api` endpoint — names no target, so no allowlist applies.

Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01GTPsZ5aEE5bUVYqp47Dpvv
@potiuk
potiuk force-pushed the perf/pr-mgmt-10-mention-allowlist branch from d9a6991 to f3c0d0e Compare October 10, 2026 11:16
@potiuk
potiuk merged commit 6d5d82e into main Oct 10, 2026
25 checks passed
@potiuk
potiuk deleted the perf/pr-mgmt-10-mention-allowlist branch October 10, 2026 12:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

capability:platform Framework / agent substrate skills (install, verify, doctor, override, status, setup bootstrap) capability:review Deep per-item code review or contributor mentoring capability:triage Sweep + classify + propose disposition family:docs Docs, MISSION.md, READMEs family:pr-management pr-management-* skills family:setup setup-* skills family:tools tools/* substrate:action-guard Tool substrate: deterministic pre-tool-use command guards substrate:analytics Tool substrate: read-only metrics / dashboards / renderers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant