Skip to content

Run the merge head race through the real gateway and github-mcp-server - #242

Open
arpanghoshal wants to merge 4 commits into
mainfrom
github-mcp-merge-head-race
Open

arpanghoshal wants to merge 4 commits into
mainfrom
github-mcp-merge-head-race

Conversation

@arpanghoshal

Copy link
Copy Markdown
Member

A reader of github/github-mcp-server#3230 ran the PR-merge head race against Control.execute with a fake provider and asked which row changes through the gateway. research/github-merge-head-race/ answers that through the real stack: ctrlrun gateway → github-mcp-server 1.14.0 (http) → a fake GitHub REST API that keeps the merge endpoint's sha semantics. Eleven scenarios, three with no gateway as the control. Results are from ctrlrun[gateway]==0.12.2 off PyPI and match main at 1c02d1e.

What it found:

  • Without expectedHeadSha, an approved merge lands at a head nobody approved. The gateway has no precondition recheck (SPEC-v0.7 §6.4).
  • With it, GitHub refuses the stale merge. The SHA is part of the approval hash, so an agent that changes it gets a new approval request.
  • github-mcp-server reports a GitHub 409 and a dropped connection the same way (isError + text), so the gateway records both ambiguous.
  • mcp: {not_executed_on_error: true} is false for this server: it recorded failed for a merge that landed.
  • Requiring expectedHeadSha works only through the absent-argument fallback: Gateway: an absent argument is not a typo, so let a policy require one #239.
  • The gateway's pre-check refusals leave no receipt and no event: Gateway pre-check refusals leave no receipt and no event #240.

The second commit is the github-merge-agent recipe, extracted from CTRLRun/ctrlrun-docs by render_cookbook.py; its page is in the companion docs PR.

Tests: test_cookbook.py, test_examples.py, test_repository_signals.py and test_packaging.py pass (273). The full suite locally has 14 failures, none from this change: 12 in test_hop.py, fixed by #241, and 2 T221 connect-timeout tests that only fail on macOS 27, fixed on macos-27-full-backlog-rst. Merge #241 first, or this PR's CI goes red on the hop tests.

🤖 Generated with Claude Code

arpanghoshal and others added 2 commits October 6, 2026 06:06
A reader of github/github-mcp-server#3230 ran the PR-merge head race against
Control.execute with a fake provider and asked which row changes through the
gateway. This runs it through the real stack: ctrlrun gateway in front of
github-mcp-server 1.14.0 in http mode, in front of a fake GitHub REST API that
keeps the merge endpoint's sha semantics. Eleven scenarios, three of them with no
gateway as the control.

Through the gateway an approved merge without expectedHeadSha lands at a head
nobody approved, because the gateway has no precondition recheck. With it,
GitHub refuses the stale merge and the SHA is bound into the approval. The run
also records three gaps: a GitHub 409 and a lost reply are indistinguishable
to the gateway, not_executed_on_error is false for this server, and requiring
an argument only works through the absent-argument fallback. A fourth: the
gateway's pre-check refusals leave no receipt and no event.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Arpan Ghoshal <contact@arpanghoshal.com>
Written by ctrlrun-docs tools/docs_audit/render_cookbook.py from
docs/cookbook/github-merge-agent.mdx.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Arpan Ghoshal <contact@arpanghoshal.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 29 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 96045efa-2d6b-4a5b-8f58-f0faa8746782
📥 Commits

Reviewing files that changed from the base of the PR and between 1c02d1e and 4205fea.

📒 Files selected for processing (8)
  • examples/cookbook/github-merge-agent/ctrlrun.yaml
  • examples/cookbook/github-merge-agent/main.py
  • pyproject.toml
  • research/github-merge-head-race/README.md
  • research/github-merge-head-race/fake_github.py
  • research/github-merge-head-race/results/2026-10-05.json
  • research/github-merge-head-race/results/2026-10-05.md
  • research/github-merge-head-race/run.py
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread research/github-merge-head-race/run.py Fixed
arpanghoshal and others added 2 commits October 6, 2026 06:12
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Arpan Ghoshal <contact@arpanghoshal.com>
…erals

CodeQL reads an implicit string concatenation inside a list as a missing comma.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Arpan Ghoshal <contact@arpanghoshal.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants