fix(pr-triage): the mark-ready guard can be bypassed with a repeated or comma-separated --add-label
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 76/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- python
- Domain
- security, testing-qa, tooling
Research direction
Start with plugins/magpie-pr-management/skills/pr-triage/guards/mark_ready.py and the _opt_value() implementation in tools/agent-guard/src/agent_guard/init.py. Trace how dispatch() parses repeated and --flag=value arguments, then update the guard and run tools/agent-guard/tests/test_skill_guards.py. Done means repeated and comma-separated --add-label values containing the ready label are denied, while the existing fail-open cases remain unchanged.
Written by the indexing model from the issue text.
Description
What
plugins/magpie-pr-management/skills/pr-triage/guards/mark_ready.py enforces Golden rule 1b: never add the "ready for maintainer review" label while the PR head still has GitHub Actions runs awaiting approval. It decides whether a gh pr edit adds that label with:
label = ctx.opt("", "--add-label")
ctx.opt() is _opt_value() (tools/agent-guard/src/agent_guard/__init__.py:204-212), which returns the value of the first matching flag and stops. gh pr edit accepts --add-label more than once, and each value can be a comma-separated list, so two forms add the ready label without the guard looking at it. Using the same fake gh as test_mark_ready_pending_denied (two runs awaiting approval), through dispatch():
DENY gh pr edit 5 --repo o/r --add-label "ready for maintainer review"
ALLOW gh pr edit 5 --repo o/r --add-label triaged --add-label "ready for maintainer review"
ALLOW gh pr edit 5 --repo o/r --add-label "triaged,ready for maintainer review"
Why it matters
The guard is the deterministic check behind rule 1b. In the two forms above it does not see the ready label, so the rule is left to the skill's instructions alone. The guard's fail-open paths (no PR number, a failed gh lookup) are deliberate; this one is not.
#1246 fixed the neighbouring class, flag values mistaken for positionals. It did not cover repeated or comma-separated values.
Suggested fix
- Add a multi-value accessor next to
opt()on the guard context that returns every value of a flag, in both--flag valueand--flag=valueform. - In
mark_ready.py, split each--add-labelvalue on commas and deny when any of them equals the ready label (trimmed and case-insensitive, as today). - Add the two ALLOW cases above to
tools/agent-guard/tests/test_skill_guards.pyas DENY cases.
Found via
An architecture pass over how agent-guard parses gh argv; reproduced through dispatch() on main (37670575).
Related
- #1246: fix(agent-guard): consume gh flag values so guards cannot be bypassed by flag order.
command_kinds()(__init__.py:686-687) still classifies aghcall byargv[1], sogh -R o/r pr edit ...is kindgh:-R. No shipped guard triggers on agh:<group>kind today (they all declare["gh"]), so this is latent.gitalready goes throughgit_subcommand_index();gh_subcommand()could do the same job forgh.
- Dominant language
- Python
- Stars
- 108
- Forks
- 94
- Avg merge
- 9h 53m
- Merged PRs (30d)
- 343
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/magpie
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-2 days Newbie friendliness 64/100
Maintainers usually reply within 1 day
-
Explore Claude Code mods across the skill familiesPossibly taken @Kaap10 claimed this 2 days ago. Opencapability:platform enhancement family:issue family:pairing family:pr-management family:release-management family:security family:setup family:utilities
Difficulty 5/5 Over a week Newbie friendliness 35/100
apache/magpie#1497 · 3 comments ·
Maintainers usually reply within 1 day
-
feat(adapter/typed-decision-local): local model backend for contract:typed-decision (llama.cpp / Ollama / vLLM)Possibly taken @liwenjie200543 claimed this 1 day ago. Openenhancement family:tools
Difficulty 5/5 Over a week Newbie friendliness 42/100
apache/magpie#1431 · 1 comment ·
Maintainers usually reply within 1 day
-
feat(adapter/chat-discord): Discord adapter for contract:chatPossibly taken @onlyarnav claimed this 6 days ago. Opencapability:stats contract:chat enhancement family:ci family:contributor-growth family:docs family:setup family:tools substrate:analytics substrate:framework-dev
Difficulty 4/5 3-5 days Newbie friendliness 68/100
apache/magpie#1421 · 3 comments ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
SR_SECURITY_DESCRIPTOR.fromString drops the SACL when no DACL is presentPossibly taken @paul7436 claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
equinor/fmu-sumo-uploader#302 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
modelscope/evalscope#1821 ·
Maintainers usually reply within 1 day
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 testPossibly taken @yurnov claimed this today. Openneeds_triage
Difficulty 1/5 Under an hour Newbie friendliness 91/100
ansible-collections/kubernetes.core#1275 ·
Maintainers usually reply within 1 day