Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
85 changes: 38 additions & 47 deletions docs/reports/REPORT_REPO_SETUP_PARITY_2026_09_26.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,17 +3,15 @@
**Date:** 2026-09-26
**Status:** living — update as the admin items are done
**Author:** Agent3
**Trigger:** Repo owner: *"verify review system/CI is setup like on agentmux .. there may need to be a webhook using
the github router so it also gets to discord. verify that all, report it to file"*, and *"also match the branch
protection and review requirements. see a5af/reagent, a5af/dev-tools, and a5af/shared-infrastructure for
reference"*.
**Compared against:** agentmuxai/agentmux, a5af/reagent, a5af/dev-tools, a5af/shared-infrastructure.
**Trigger:** Repo owner asked to verify that the review system and CI are set up like on agentmux, that
notifications reach Discord, and that branch protection and review requirements match agentmux and the
internal reference repos.
**Compared against:** agentmuxai/agentmux and the internal (private) reference repos.

## 0. Summary

- **Notifications already work.** The agentmuxai org webhook delivers muxcode events to github-router, which posts
them to the AgentMuxAI Discord `#github-firehose` and to muxbus (agents get ReAgent review notifications). No
webhook needs adding; a repo-level one would double-deliver.
- **Notifications already work.** Agents already get ReAgent's review notifications for muxcode. No webhook
needs adding.
- **ReAgent reviews muxcode**, but three of its checks fail on every PR because the default branch isn't `main`.
- **muxcode has no branch protection**, no required checks and no review requirement; agentmux requires the
`check` and `CI required` checks and one approval, and dismisses stale approvals.
Expand All @@ -26,38 +24,42 @@ reference"*.
Read-only. `gh-agent` (the agent's GitHub App) returned *Resource not accessible by integration* for branch
protection, webhooks, Actions permissions and secrets on every repo, and for org rulesets and hooks. What was
readable: `GET repos/<r>` (settings), `GET repos/<r>/branches/<b>` (protected, required checks, enforcement),
rulesets, workflow files, PR histories, and AWS CloudWatch logs for github-router and the muxbus consumer. Review
rulesets, workflow files and PR histories. Review
requirements are **inferred** from PR behaviour and marked as such.

## 2. Comparison

| | muxcode (before) | agentmux | reagent | dev-tools | shared-infrastructure |
|---|---|---|---|---|---|
| Default branch | `agent3/initial-implementation` | `main` | `main` | `main` | `main` |
| Default branch protected | **no** (`main` isn't either) | yes | yes | yes | yes |
| Required checks | none | **`check`, `CI required`** (GitHub Actions, app 15368; admins exempt) | none | none | none |
| One approval required (inferred) | no — #1 merged with changes requested | **yes**, high confidence (#3854 shows REVIEW_REQUIRED with only a comment; 20/20 sampled merges approved) | yes, high (#251, #262) | no (#388, #386 merged with changes requested) | no (#507, #506 merged on comment reviews) |
| Stale approvals dismissed on push (inferred) | — | **yes** (#3849, #3833) | yes (#257, #240) | not seen | not seen |
| Rulesets | none | none | none | none | "Copilot Auto-Review", disabled |
| Who approves | ReAgent | ReAgent | ReAgent | ReAgent | ReAgent |
| CI | `build` | `ci-pr.yml` with an aggregate **`CI required`**, doc gates, release checks | Test | CI | per-component tests |
| No-Co-Authored-By check | **missing** | yes (inline copy; job `check` is required) | reusable workflow | reusable workflow | hosts the reusable workflow |
| `.githooks/commit-msg` + `prepare` | **missing** | yes | yes | yes | yes |
| Squash commit title / message | **commit-or-PR title / commit messages** | PR title / blank | PR title / blank | PR title / blank | PR title / blank |
| Auto-merge | off | **on** | off | off | off |
| LICENSE / SECURITY.md | **no / no** (package.json said MIT) | Apache-2.0 / yes | — | — | — |
| CLAUDE.md | no | no (removed on purpose for a public repo, agentmux#3403) | yes | yes | yes |
| Codex review | manual `@codex review` | ReAgent triggers it; `codex-review-gate.yml` status (not required) | manual | manual | manual |
| | muxcode (before) | agentmux |
|---|---|---|
| Default branch | `agent3/initial-implementation` | `main` |
| Default branch protected | **no** (`main` isn't either) | yes |
| Required checks | none | **`check`, `CI required`** (GitHub Actions, app 15368; admins exempt) |
| One approval required (inferred) | no — #1 merged with changes requested | **yes**, high confidence (#3854 shows REVIEW_REQUIRED with only a comment; 20/20 sampled merges approved) |
| Stale approvals dismissed on push (inferred) | — | **yes** (#3849, #3833) |
| Rulesets | none | none |
| Who approves | ReAgent | ReAgent |
| CI | `build` | `ci-pr.yml` with an aggregate **`CI required`**, doc gates, release checks |
| No-Co-Authored-By check | **missing** | yes (inline copy; job `check` is required) |
| `.githooks/commit-msg` + `prepare` | **missing** | yes |
| Squash commit title / message | **commit-or-PR title / commit messages** | PR title / blank |
| Auto-merge | off | **on** |
| LICENSE / SECURITY.md | **no / no** (package.json said MIT) | Apache-2.0 / yes |
| CLAUDE.md | no | no (removed on purpose for a public repo, agentmux#3403) |
| Codex review | manual `@codex review` | ReAgent triggers it; `codex-review-gate.yml` status (not required) |

The internal reference repos were also compared. They all use `main`, protect it, are reviewed by ReAgent, run the
no-Co-Authored-By check and commit-msg hook, and squash with PR title / blank message. Their review requirements
vary; agentmux is the closest match for muxcode and is the model used below.

## 3. Fixed by the PR that adds this report

- `.github/workflows/no-coauthor-trailers.yml` — an exact copy of agentmux's (job `check`). It has to be a copy: a
public agentmuxai repo can't call the reusable workflow in private `a5af/shared-infrastructure`.
public repo can't call a reusable workflow that lives in a private repo.
- `.github/workflows/ci.yml` — an aggregate **`CI required`** job (`needs: build`, `if: always()`), the single
check branch protection requires, as on agentmux. `npm test` already runs (added in #35).
- `.githooks/commit-msg` (strips Co-Authored-By trailers; identical across the reference repos) and the same
`prepare` script as a5af/reagent, which points `core.hooksPath` at it in a clone and does nothing when the
package is installed from npm.
`prepare` script the reference repos use, which points `core.hooksPath` at it in a clone and does nothing when
the package is installed from npm.
- `LICENSE` (MIT, as `package.json` already declared), `SECURITY.md` (security@agentmux.ai, scoped to Mux Code),
`.github/dependabot.yml` (npm and GitHub Actions, weekly).

Expand All @@ -74,8 +76,8 @@ Do these in order; 3 depends on 1 and on the PR in §3 having run once.
`fatal: bad revision 'origin/main'`, so those checks silently skip on every PR.
2. **Squash settings:** Settings → General → Pull Requests → "Default commit message" for squash merges: **Pull
request title**, message **blank** (API: `squash_merge_commit_title=PR_TITLE`,
`squash_merge_commit_message=BLANK`). This was step 0 of shared-infrastructure's
`SPEC_COAUTHOR_TRAILER_SERVER_SIDE_CHECK_2026_09_20.md`, and muxcode was missed: its merges #2, #3, #34 and #35
`squash_merge_commit_message=BLANK`). This is the org-wide setting the other repos already use, and muxcode
was missed: its merges #2, #3, #34 and #35
carry `Co-authored-by:` trailers, and #34's commit lost its `Agent3@narko:` title prefix.
3. **Branch protection on `main`, matching agentmux** (`PUT repos/agentmuxai/muxcode/branches/main/protection`):
```json
Expand Down Expand Up @@ -106,25 +108,14 @@ Do these in order; 3 depends on 1 and on the PR in §3 having run once.

## 5. Elsewhere

- **ReAgent config** — add an `agentmuxai/muxcode` entry to `a5af/reagent` `config/repos.json` mirroring agentmux's
`codex: {enabled: true}` and `comment_reply` blocks (merge-regression analysis once `main` exists). muxcode runs on
ReAgent's defaults today.
- **Notifications (no change needed):** agentmuxai has one org webhook to `https://github-router.asaf.cc/webhook`
(shared-infrastructure `SPEC_DISCORD_GITHUB_FIREHOSE_2026_09_23.md` §3). The router publishes every event to SNS
(ReAgent and the muxbus github-consumer subscribe) and posts public agentmuxai repos to
`discord-webhook-firehose-agentmuxai`. Confirmed in `/aws/lambda/infrastructure-github-router-function`: muxcode
`pull_request`, `pull_request_review` and `issues` events posted to that sink; the review on muxcode#3 reached
`/aws/lambda/muxbus-github-consumer` at 06:23:30Z. The muxbus consumer's dedup notes (`handler.ts`) say
repo-level hooks on muxcode, cef and agentmux-mobile caused double notifications and were removed — **don't add
one back.**
- **Org-wide gap (not muxcode-specific):** the org hook delivers no `push`, `workflow_run` or `release` events for
any agentmuxai repo (none in three days of router logs), so Discord's CI-failed, push and release messages never
fire for agentmuxai.
- **ReAgent config** — add muxcode to ReAgent's repo configuration (kept in a private repo), mirroring agentmux's
entry (Codex and comment-reply enabled; merge-regression analysis once `main` exists). muxcode runs on ReAgent's
defaults today.
- **Notifications (no change needed):** muxcode's PR and review events already reach agents through the
organisation's existing notification setup. Don't add a repo-level webhook.
- **Release policy:** muxcode has no changesets, so ReAgent asks for a `package.json` bump on every code PR (as on
#35). That's being followed; adopting `.changesets/` like agentmux would move bumps into release PRs.

## 6. Side findings in the reference repos

- agentmux's `codex-review-gate.yml` says `Codex review` should be a required check; it isn't.
- The `check / check` co-author workflow isn't a required check on reagent, dev-tools or shared-infrastructure, and
shared-infrastructure doesn't run it on its own PRs.
Loading