# Remove "needs backport to 3.6" label

**URL:** <https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563>\
**Category:** Core Workflow\
**Created:** [December 18, 2018, 11:32pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563 "2018-12-18T23:32:33Z")\
**Posts on this page:** 15\
**Page:** 2

<div class="post-metadata">

**Author:** ![nad](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/nad/32/51_2.png) [@nad](https://discuss.python.org/u/nad)\
**Post date:** [January 10, 2019, 7:56pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/21 "2019-01-10T19:56:07Z")

</div>

@Mariatta, Yes, I am aware of that 🙂 However, in this case, the merger did not have any special privs, AFAICT.

---

<div class="post-metadata">

**Author:** ![Mariatta](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/mariatta/32/30581_2.png) [@Mariatta](https://discuss.python.org/u/Mariatta)\
**Post date:** [January 10, 2019, 8:00pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/22 "2019-01-10T20:00:09Z")

</div>

PR 11477 [https://github.com/python/cpython/pull/11477](https://github.com/python/cpython/pull/11477) was merged by @Senthil, who appears to have Admin access to python/cpython.

![51%20AM](https://us1.discourse-cdn.com/flex002/uploads/python1/original/1X/5399fbc285daad5db35ca4b92ca6a4cae0f48e0b.png)

---

<div class="post-metadata">

**Author:** ![nad](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/nad/32/51_2.png) [@nad](https://discuss.python.org/u/nad)\
**Post date:** [January 10, 2019, 8:08pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/23 "2019-01-10T20:08:25Z")

</div>

@Mariatta, oh, thanks! I was looking in the wrong place.

---

<div class="post-metadata">

**Author:** ![brettcannon](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/brettcannon/32/34895_2.png) [@brettcannon](https://discuss.python.org/u/brettcannon)\
**Post date:** [January 10, 2019, 8:27pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/24 "2019-01-10T20:27:47Z")

</div>

> [@Mariatta](#):
>
> Several people other than release managers, like myself, have admin access and can merge to protected branches. For myself I need this in order to see webhook deliveries for the bots.

Admin access probably needs to be cleaned up as it’s currently broader than RMs and those of us maintaining a webhook. Once 3.4 hits EOL in March I plan to talk it over with Ernest about a reasonable criteria for who gets admin access for security – and now branch access – reasons (and my guess it will simply tighten to those maintaining an active webhook or RMs 😄).

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [January 10, 2019, 9:25pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/25 "2019-01-10T21:25:12Z")

</div>

Does GitHub support different permissions for different group of people?

---

<div class="post-metadata">

**Author:** ![brettcannon](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/brettcannon/32/34895_2.png) [@brettcannon](https://discuss.python.org/u/brettcannon)\
**Post date:** [January 10, 2019, 9:26pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/26 "2019-01-10T21:26:33Z")

</div>

There’s read, write, and admin. They can be set at the individual or GitHub team level (e.g. `Python Core` has write access while `Release Managers` has admin access).

---

<div class="post-metadata">

**Author:** ![Senthil](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/senthil/32/18300_2.png) [@Senthil](https://discuss.python.org/u/Senthil)\
**Post date:** [January 11, 2019, 12:44am UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/27 "2019-01-11T00:44:05Z")

</div>

> [@Mariatta](#):
>
> PR 11477 [https://github.com/python/cpython/pull/11477](https://github.com/python/cpython/pull/11477) was merged by @Senthil, who appears to have Admin access to python/cpython.

I do. When we migrated from hg to git, I needed that access, it was left like that. I may not need it any longer, but I can ask again if I need it or we leave at status quo too, and I can use for helping others when required.

- PR11477 merging was a mistake, which has been corrected now by revert.

* * *

I hope the discussion on this topic: **Removal of “needs backport to 3.6”** can be separated from the above incident can be continued.

---

<div class="post-metadata">

**Author:** ![Senthil](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/senthil/32/18300_2.png) [@Senthil](https://discuss.python.org/u/Senthil)\
**Post date:** [January 11, 2019, 1:07am UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/28 "2019-01-11T01:07:05Z")

</div>

I read this discussion completely.

I’d go with Ned (RM for 3.6) having the authority on if we should remove “Needs backport to 3.6” label on not.

- Just we do not remove the selection of 3.6 in [bugs.python.org](http://bugs.python.org) it can be argued that we do not remove that label in [github.com/python/cpython](http://github.com/python/cpython) project too. (Side note: the issues themselves needs to be pruned for correct selection now that 3.6 is in security fix only mode).

- Now that the previously set labels are removed from PRs. Keeping the label itself seems harmless to me, and the label will help us if we really want to backport security fixes automatically PRs automatically. (Imagine doing the backport via the computer in your pocket standing in the trains, labels,github, ui etc are helpful here).

- There were 2 mistakes so far, and it can be corrected as we realize 3.6 is security fixes only. And current automation provided by miss-islington bot is actually very good IMO.

---

<div class="post-metadata">

**Author:** ![njs](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/njs/32/204_2.png) [@njs](https://discuss.python.org/u/njs)\
**Post date:** [January 11, 2019, 2:11am UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/29 "2019-01-11T02:11:53Z")

</div>

> [@Senthil](#):
>
> I didn’t know that if the bot was not auto merging on purpose and thought, it needed manual intervention.

Would it be helpful for the bot to somehow signal the issue, e.g. posting a comment saying “only release managers can backport to this branch”?

---

<div class="post-metadata">

**Author:** ![brettcannon](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/brettcannon/32/34895_2.png) [@brettcannon](https://discuss.python.org/u/brettcannon)\
**Post date:** [January 11, 2019, 6:31pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/30 "2019-01-11T18:31:54Z")

</div>

> [@njs](#):
>
> Would it be helpful for the bot to somehow signal the issue, e.g. posting a comment saying “only release managers can backport to this branch”?

I think fixing the permissions issue is the easier solution. That doesn’t require custom code and for security purposes we should do it anyway.

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [January 29, 2019, 2:29pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/31 "2019-01-29T14:29:06Z")

</div>

In following up here, new policies have been implemented that limit GitHub Organization Owners and python/cpython Repository Admins to help mitigate these kinds of things in the future.

You can view the initial policies here: [https://github.com/python/devguide/pull/448](https://github.com/python/devguide/pull/448).

Moving to least privilege model is a first step, we should further assess how to handle more granular situations as necessary.

---

<div class="post-metadata">

**Author:** ![dstufft](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/dstufft/32/23_2.png) [@dstufft](https://discuss.python.org/u/dstufft)\
**Post date:** [January 29, 2019, 2:32pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/32 "2019-01-29T14:32:15Z")

</div>

> [@brettcannon](#):
>
> I think fixing the permissions issue is the easier solution. That doesn’t require custom code and for security purposes we should do it anyway.

This is a bit delayed, but I think fixing permissions is something that _should_ be done regardless. Principle of least authority and all that.

However, I think we should _also_ have one of the bots active on backport branches and should have a status check that ensure the RM of that branch has signed off on the PR. This would be similar to the check for a news file, except it would check to see if the RM for that branch has approved the PR (or something similar).

Effectively, reducing the people who have owner on the permission narrows down the list of people who can possibly make a mistake, but it doesn’t prevent those mistakes from happening. Adding controls so that the RM has to approve PRs for security only branches _does_ prevent them (or well, makes it so it’s the RMs fault in that case 😉 ).

---

<div class="post-metadata">

**Author:** ![Mariatta](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/mariatta/32/30581_2.png) [@Mariatta](https://discuss.python.org/u/Mariatta)\
**Post date:** [January 29, 2019, 6:33pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/33 "2019-01-29T18:33:44Z")

</div>

> [@dstufft](#):
>
> However, I think we should _also_ have one of the bots active on backport branches and should have a status check that ensure the RM of that branch has signed off on the PR. This would be similar to the check for a news file, except it would check to see if the RM for that branch has approved the PR (or something similar).

I think we can add that in. If there is no rush in wanting this feature, I can see to it worked by a newcomer during Python US sprint. So essentially, we’ll add a “approved by RM” status check to the protected branches?

---

<div class="post-metadata">

**Author:** ![dstufft](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/dstufft/32/23_2.png) [@dstufft](https://discuss.python.org/u/dstufft)\
**Post date:** [January 29, 2019, 7:16pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/34 "2019-01-29T19:16:03Z")

</div>

> [@Mariatta](#):
>
> I think we can add that in. If there is no rush in wanting this feature, I can see to it worked by a newcomer during Python US sprint. So essentially, we’ll add a “approved by RM” status check to the protected branches?

Yea, I think an Approved By RM status check to protected branches would be ideal. I also don’t think there is any rush, the number of people who can merge now is small and if someone does accidentally do it, a revert can solve it in the interim.

---

<div class="post-metadata">

**Author:** ![nad](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/nad/32/51_2.png) [@nad](https://discuss.python.org/u/nad)\
**Post date:** [January 29, 2019, 9:26pm UTC](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563/35 "2019-01-29T21:26:05Z")

</div>

With the changes that @EWDurbin has announced, I don’t think any further action is needed. It should now be the case that only the RM for a security-only branch can merge things (or an admin) to the branch and, even so, I think there is little chance that something would slip by. A bot would be overkill at this point.

[Previous page](https://discuss.python.org/t/remove-needs-backport-to-3-6-label/563.md?page=1)
