The claim anchor for the PRs reroll-gate.sh opens (.github-private#933, under #913 step 1). Each rolled PR carries Claim-issue: bounded-systems/.github#<this>, and pr-claim / pr-claim is required org-wide, so this issue must be open and claimed while any rolled PR is unmerged. It is filed here, in a public repo, because pr-claim reads the named issue with the target repo's own token (.github#358).
What the rolled file is. gate.yml: one always-run job named gate that polls the head's other check runs and commit statuses until each has concluded, then reports green — red, stuck, or deadline-exceeded makes it red. No actions; checks: read and statuses: read only.
Why these repos need it. The conformance snapshot flags eight repos gate-absent: their CI runs, but nothing on the default branch requires it, so green decides nothing. None can simply join ci-green-standard: each runs at least one unfiltered PR-time check the standard's test lane does not cover (relay-live and pr-title in claude-box, flake / build in conformance-kit, wire-check in the three door daemons, the JSR publish dry-run in door-kit and ocap-provenance), which is the sentinel case docs/merge-gate.md rules out for auto-merge. An aggregating gate is the only shape that can be required without leaving a hole.
The seven (the eighth, conformance, is excluded by name and counted: it already produces a check run named gate, its cross-repo drift gate, which the template ignores by design — that job is renamed first): claude-box, conformance-kit, door-concierge, door-keeper, door-kit, door-scout, ocap-provenance.
Order after the roll. Each rolled PR's own gate run is the observation the staged rollout needs. Only once gate has reported on a real PR in all seven is org/rulesets/ci-green-gate.json applied through org-sync (Face ID) — applying it first would require a context nothing there produces yet and brick every PR in those repos.
Close when the rolled PRs have merged (or been deliberately declined, named here).
The claim anchor for the PRs
reroll-gate.shopens (.github-private#933, under #913 step 1). Each rolled PR carriesClaim-issue: bounded-systems/.github#<this>, andpr-claim / pr-claimis required org-wide, so this issue must be open and claimed while any rolled PR is unmerged. It is filed here, in a public repo, becausepr-claimreads the named issue with the target repo's own token (.github#358).What the rolled file is.
gate.yml: one always-run job namedgatethat polls the head's other check runs and commit statuses until each has concluded, then reports green — red, stuck, or deadline-exceeded makes it red. No actions;checks: readandstatuses: readonly.Why these repos need it. The conformance snapshot flags eight repos
gate-absent: their CI runs, but nothing on the default branch requires it, so green decides nothing. None can simply joinci-green-standard: each runs at least one unfiltered PR-time check the standard'stestlane does not cover (relay-liveandpr-titlein claude-box,flake / buildin conformance-kit,wire-checkin the three door daemons, the JSR publish dry-run in door-kit and ocap-provenance), which is the sentinel casedocs/merge-gate.mdrules out for auto-merge. An aggregating gate is the only shape that can be required without leaving a hole.The seven (the eighth,
conformance, is excluded by name and counted: it already produces a check run namedgate, its cross-repo drift gate, which the template ignores by design — that job is renamed first): claude-box, conformance-kit, door-concierge, door-keeper, door-kit, door-scout, ocap-provenance.Order after the roll. Each rolled PR's own
gaterun is the observation the staged rollout needs. Only oncegatehas reported on a real PR in all seven isorg/rulesets/ci-green-gate.jsonapplied through org-sync (Face ID) — applying it first would require a context nothing there produces yet and brick every PR in those repos.Close when the rolled PRs have merged (or been deliberately declined, named here).