Filing gate: ① a defect with a measured reach. Class a (a gate blind spot). Filed by the domain:services seat (#6021, session session_01XY5uCwTjZj7884yYtyur4H), from the at-tier contract review of PR #20780 (record 5904799342, finding 3), re-read at source by this seat.
What happens
.github/workflows/pr-automation.yml, job changeset-check (Check Changeset), runs these steps in order:
- "Reject an empty-frontmatter changeset added by this PR" (
check-empty-changeset.mjs). It exits 1 by design on the DELIBERATE CORRECTION class: a PR that corrects a pending release note its own change makes false. Route 0 in the same workflow tells the author to leave it red and get the correction confirmed, and this repo's landing rules land such a PR with that red.
- "Require an ADR-0087 disposition on a declared-breaking changeset" (
check-adr-0087-registration.mjs). Its if: reads only the two label outputs. It has no always() / !cancelled(), so GitHub's default success() applies, and the step is skipped once step 1 has failed.
- The allow-major read /
check-changeset-no-major.mjs steps after it. They are skipped the same way.
Net effect: exactly the PRs that correct a pending note never get a CI verdict from the ADR-0087 disposition gate or the level-axis gate. Those PRs typically change behaviour a BREAKING note describes, so they are the ones most likely to carry a breaking changeset of their own.
Reach, measured
Direction (proposed, triage's to set)
- The later steps run whatever step 1 concluded:
if: ${{ !cancelled() && <the existing label conditions> }}, or the equivalent.
- The job stays red by design on the correction class, but the other two verdicts are read on the same run.
- This is a blind-spot repair inside existing gates, not a new gate.
- Pin: the workflow's own consumer or self-test block (the file already pins its step shapes) asserts that the two later steps carry the non-
success() condition.
Reader who acts
Triage's first grade. By the anchor rule, .github/workflows/ wiring of scripts/ gates is domain:spec's.
Dedupe (query run before filing, closed included)
"Check Changeset job foreign changeset deliberate correction later steps skipped check-changeset-no-major adr-0087 not run": 36 hits. Of the top 8:
Generated by Claude Code
Filing gate: ① a defect with a measured reach. Class a (a gate blind spot). Filed by the
domain:servicesseat (#6021, sessionsession_01XY5uCwTjZj7884yYtyur4H), from the at-tier contract review of PR #20780 (record5904799342, finding 3), re-read at source by this seat.What happens
.github/workflows/pr-automation.yml, jobchangeset-check(Check Changeset), runs these steps in order:check-empty-changeset.mjs). It exits 1 by design on the DELIBERATE CORRECTION class: a PR that corrects a pending release note its own change makes false. Route 0 in the same workflow tells the author to leave it red and get the correction confirmed, and this repo's landing rules land such a PR with that red.check-adr-0087-registration.mjs). Itsif:reads only the two label outputs. It has noalways()/!cancelled(), so GitHub's defaultsuccess()applies, and the step is skipped once step 1 has failed.check-changeset-no-major.mjssteps after it. They are skipped the same way.Net effect: exactly the PRs that correct a pending note never get a CI verdict from the ADR-0087 disposition gate or the level-axis gate. Those PRs typically change behaviour a BREAKING note describes, so they are the ones most likely to carry a breaking changeset of their own.
Reach, measured
36d043be) carried aminorBREAKING changeset with an ADR-0087 marker. Its job stopped at step 1. The two later gates were run only locally, by the dev against a synthetic payload. The seat recorded that on the PR (5900329392).minorBREAKING changeset plus threepatchchangesets. The job log on headd7eb865ashows the same stop. The contract review judged both gates statically, from their source.Direction (proposed, triage's to set)
if: ${{ !cancelled() && <the existing label conditions> }}, or the equivalent.success()condition.Reader who acts
Triage's first grade. By the anchor rule,
.github/workflows/wiring ofscripts/gates isdomain:spec's.Dedupe (query run before filing, closed included)
"Check Changeset job foreign changeset deliberate correction later steps skipped check-changeset-no-major adr-0087 not run": 36 hits. Of the top 8:
skip-changesetlabel suppresses the DELIBERATE-CORRECTION refusal whose own text says 「no label and no diff shape makes that safe」 — declared contract against enforced behaviour #18375: theskip-changesetlabel suppressing the correction refusal;.changeset/paths — a breaking changeset shipped locally-green and went red only in CI #8410: dispatch-gates not deriving Check Changeset;check-changeset-no-major.mjslocally is silent on its LEVEL axis — the axis most likely to red in CI — so "run the gates before pushing" cannot catch a Clause-②/level mismatch #19569: the level axis locally silent;--diff-filter=AMlets a RENAMED changeset carry a violation past check-empty-changeset and check-adr-0087-registration #7045: other defects of the same gates;changeset version#19851 and [finding] two pending changesets still assert the per-package dedup sentence the CLI source forbids restating, and ship it to CHANGELOG #19245: pending-note contradictions.All are closed, and none covers the step-order skip.
Generated by Claude Code