cctest: unify merge policy wording — recipe PRs are never agent-merged, both sides

Operator decision: no policy difference between cc-ci and recipe-maintainer. On
inspection ARM already agrees (recipe-upgrade-cron-all: 'PRs are reviewed and merged
manually by a human afterwards... never merges anything'; 'no human review in the
middle' = skip the mid-run plan confirmation only). Wrappers previously framed this
as a cc-ci override over ARM auto-merge flows — wrong reading; now stated as ONE
unified rule. /help conventions updated to match.
This commit is contained in:
autonomic-bot
2026-08-04 01:40:36 +00:00
parent 15e4e75681
commit be7f8bc850
32 changed files with 158 additions and 158 deletions
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+5 -5
View File
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+5 -5
View File
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+5 -5
View File
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+5 -5
View File
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+5 -5
View File
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+5 -5
View File
@@ -15,11 +15,11 @@ its shared swarm. Execute with the submodule as your working directory:
configured on this host (`settings.toml` from `settings.toml.example`, sandbox/test instances),
run `/cctest-intro` / `/cctest-setup-sandbox` first.
**Policy overrides (cc-ci-orchestrator conventions win):**
- Anything that would **merge a recipe PR or push a recipe main without review** requires
explicit operator opt-in per run — the cc-ci standing rule is recipe upgrade PRs are
operator-merged, and ARM skills that say otherwise (e.g. full-auto upgrade flows) do NOT
inherit blanket authorization here.
**Unified policy (same as cc-ci — no differences):**
- **Recipe PRs are NEVER merged by an agent.** Every flow ends at an open PR; the operator
reviews and merges. This is ARM's own rule too ("PRs are reviewed and merged manually by a
human afterwards — never pushes to upstream or merges anything"); ARM's "no human review in
the middle" wording refers only to skipping the mid-run plan confirmation, not to merging.
- Never touch cc-ci infrastructure (the CI server, its swarm, `/root/*` clones, the weekly
timers) from an ARM skill — cc-ci work goes through the cc-ci skills.
- The submodule is **pinned**: don't commit into it from here; upstream ARM changes arrive via
+3 -3
View File
@@ -61,9 +61,9 @@ sandbox: `/cctest-intro` (start here), `/cctest-recipe-overview`, `/cctest-recip
`/cctest-new-recipe-guide`, sandbox/instance management (`/cctest-setup-sandbox`,
`/cctest-t1cc-start|stop`), and more — enumerate with `ls .opencode/skills | grep ^cctest-`.
**Rule of thumb:** verifying/shipping against the CI pipeline → the cc-ci skills above;
exploratory or hands-on recipe development on a test instance → `/cctest-*`. cc-ci policy
overrides apply (auto-merge-style ARM flows need per-run operator opt-in; never touch cc-ci
infra from an ARM skill). After a submodule bump run `scripts/gen-cctest-skills.py`.
exploratory or hands-on recipe development on a test instance → `/cctest-*`. Policy is
unified: recipe PRs are never agent-merged on either side (operator reviews + merges), and
ARM skills never touch cc-ci infra. After a submodule bump run `scripts/gen-cctest-skills.py`.
## "What do you want to do?"