Skip to content

Champion merges blocked: branch-protection read returns 403 (Resource not accessible by integration) #166

Description

@loom-fleet-dispatch

Six Judge-approved, CI-green, mergeable PRs (#151, #152, #153, #161, #162, #164) cannot be merged. The merge-pr.sh required-check freshness guard reads classic branch protection, and the active loom-daemon credential gets HTTP 403 on this call:

gh api repos/2AMLogic/fasterhenry/branches/main/protection   ->  403 Resource not accessible by integration

The rules endpoint repos/.../rules/branches/main returns []. merge-pr.sh fails closed, so nothing merges and Champion cannot work around it. The same failure has been seen since at least 2026-10-06 (#159 freshness-lookup notice).

Needed from an operator: give the GitHub App/token used by loom-daemon for 2AMLogic read access to Administration (branch protection), or tell us if main has no required checks so the guard can treat the 403 as such. Not a work item for Builder.


Automated by Champion role

🤖 Generated with Claude Code

loom dashboard

Activity

  1. loom-fleet-dispatch commented on Oct 8, 2026

    @loom-fleet-dispatch
    ContributorAuthor

    Champion pass 2026-10-08: live GET repos/2AMLogic/fasterhenry/branches/main/protection/required_status_checks still returns HTTP 403 (Resource not accessible by integration). The approved merge queue remains blocked; no merge attempted and approval labels preserved. Existing operator holds on #159 and #160 remain; their CI checks pass, and #160 is conflicting. Updated the durable hold digest at #16. No Doctor-cycle-capped PRs found. Restore the active integration credential’s branch-protection read access so the freshness guard can establish merge eligibility.

    Automated by Champion role

  2. turian commented on Oct 8, 2026

    @turian
    Member

    Hold-queue pass: the choice this asks for was already made. On 2026-10-02 the operator ruled on 2AMLogic/klayout-tools#2553 to move required checks from classic branch protection to a ruleset, not to give the fleet Apps Administration: Read. The merge guard already reads rulesets.
    fasterhenry got classic protection on 2026-10-05 when #35 closed (7 required checks, non-strict, admins not enforced), and it has 0 rulesets. That is why the fleet gets a 403, and six loom:pr PRs (#151, #152, #153, #161, #162, #164) are still unmerged.
    Human step: a repo admin creates a ruleset on ~DEFAULT_BRANCH with the same 7 required checks (non-strict, block deletion and force-push, admin bypass as now), deletes the classic rule on main, and confirms the fleet App token reads it through GET /repos/2AMLogic/fasterhenry/rules/branches/main (operator, repo admin). Same steps as klayout-tools ruleset 24397320.

  3. loom-fleet-dispatch commented on Oct 10, 2026

    @loom-fleet-dispatch
    ContributorAuthor

    Curator dependency re-check: still blocked. The live branch-protection read continues to return 403 Resource not accessible by integration (verified 2026-10-10), so the merge-guard access premise has not cleared. Leaving loom:blocked in place.

    loom dashboard

  4. removed
    loom:curatingCurator is enhancing this issue. Applied by: Curator only (claim label).
    on Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    loom:blockedImplementation blocked, needs help or clarification

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions