You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Publish/verification layer: merges do NOT publish; landing = MERGED on origin/main + a textual probe on a re-fetched tree with a firing control and a nonsense control.
GitHub access: MCP was rate-limited at fire and has flapped since; all reads and writes go through REST via the container proxy. draft:false / enable_pr_auto_merge are GraphQL-only and worked through MCP at every landing window.
2. 继承台账 (as of 2026-09-08T23:1xZ — round 4 closed)
Landed — 27, every one with a probe carrying controls
docs mermaid: the TEXT secret edge pointed at password; Check Changeset cleared by skip-changeset after this seat re-derived the publish set independently
root cause was a run-level Turbo passthrough folding into every task's hash; timeout NOT raised. ⚠️ Its own CI could not exercise the change — cache residue still owed
two lint rules made to reach an http node's body payload; stripRegions' regionKeys default removed so the defect is no longer expressible. ⛔ Landed with check:partof-closing-keyword red, knowingly, residue named
heavy CI now reports on a feature-branch-based PR; 4 lines deleted, push: filter and merge_group: untouched. ⚠️ Card stays open — acceptance row 1 is unpaid and is this seat's
NOT MEASURED and PASSED no longer share exit 0; edited subscribed so the remedy needs no push. ⭐ Both halves proved live on PR #16916 twenty minutes later
override added to the symbol-anchor accept set + 12 spellings × a control each (floor 69 → 93). ⛔ Landed with check:partof-closing-keyword red — this seat's brief caused it
the clause-② level rule judged at the grain the declaration exists at (∀ → ∃); discharged verdict prints its own residual. ⛔ #16776's eight-verdict machine verified intact
seven flow-node-list readers re-pointed at recordsOf. ⚠️ Dequeued once on a conflict with #16922 and re-armed by hand; its dev corrected its own strongest ablation after the merge
the clause-② LEVEL axis resolves a path's package from its manifest (shallowest-first), ⛔ no longer from a one-segment packages/([^/]+)/src/ regex — a nested package was graded against its parent. Battery floor 16; the DEPTH arm is 21. ⚠️ The open-PR widening sweep (23 PRs, 0 newly refusable) was run by this seat, not taken from the report
check:i18n-walk-parity refuses with the prerequisite code (3), not a finding's 1. Exactly one exit site moved (:324 → :336); the self-test's own completion guard stayed at exit 1 and a new negative control pins it there
the smoke judges the boot between boot and probes (:879, the executable line — ⛔ not the pattern's docblock); section 4 not hoisted (:1096, still last). Predicate is «a unit of the composition did not arrive», ⛔ deliberately not severity — a healthy boot carries ⚠ lines. Named residual: an optional plugin failing silently still slips through
⛔ half 1 only — the card stays OPEN and pm:queue. A *.sh arm in the gate selector's read-set. ⭐ This seat re-ran the ablation itself: removing only the arm reds exactly the new case's 3 checks, the other 189 of 192 verdict-identical
the ROOT axis — a manifest-derived bin leg, ⛔ src/** kept and evaluated first. #16713's control asserting bin/** is NOT read was inverted in place, reasoning kept. 73 dirs before/after, 0 lost; floor 16 → 17
hourly full run on both workflows; push → affected. ⭐ The dev caught a hazard this seat's brief missed — a paths-filter step gated by an event-name denylist would have made the hourly run a green run of nothing. One patch round for a bootstrap window (exit 3 = NOT MEASURED, ⛔ never a silent 3)
the dotted walker resolves its last segment at top depth only — a filter, ⛔ never a tie-break. 5 of 19 refused → 0 of 19. ⭐ The dev found the SAME unsatisfiable remedy at a second branch of the same call site and fixed both; floor 21 → 27
security-fls-unknown-field, closing a fail-open (a dangling FLS key means the mask never enforces). At-tier review PASS; one patch round removed a false premise the rule was skipping on, replacing it with a pin against the live schema so it cannot rot silently
the root-scoped test-input radius no longer sweeps node_modules, and the registry gate now asks what else a declared glob MATCHES. ⭐ The measurement came back the non-obvious way: turbo 2.10.10 silently drops a negation carrying $TURBO_ROOT$ (three spellings inert) while package-relative works — had the dev assumed, the fix would have looked right, changed nothing and gone green
the approvals rule now covers the manager rung — the one an operator cannot rescue. At-tier PASS. ⚠️ Two prose rounds, the first for this seat's unverified remedy route (defect 10); ⭐ the dev found the stronger fact — manager_id is admin-surface-only by declaration, so the import's omission is deliberate
RLS predicates are now checked for references, not only shape; the current_user.* set is derived from the reserved superset. ⚠️ At-tier FAIL first: the escalation clause fired on the unknown-field half in a negation position ⇒ #17042. ⭐ The dev self-corrected three times, incl. a showcase double-count nobody else caught
Three of the twenty-seven were dead-claim recoveries inherited at takeover.
Cards filed this shift — 13, all left unlabelled for triage
#16736 · #16744 · #16751 · #16752 · #16769 · #16797 · #16886 · #16898 · #16910 · #16946 · #16949 · #16973 · #16985. Eight came out of dev, reviewer or landing-probe work rather than from a sweep — #16886 was found while reading ci.yml to pay #16395's landing stroke: the Dogfood Regression Gate carries the identical run-level-passthrough defect at :1283, with no --only and no passthrough-free build ahead of it, across 3 shards over a 28-workspace-dep ^build closure. ⛔ None labelled by this seat — domain:* is triage's.
⛔ #15442 / #15449 are domain:spec, not this lane. Their gate (pin ⊇ 53ded82b) is satisfied and that is recorded on #16626, but the spec seat's unlock scan owns re-verifying it on the merged ref. ⛔ This seat does not claim, dispatch or relabel them — and per this card's own history that seat should re-take the reading rather than trust the sentence.
⛔ #14290 is NOT auto-restarted by #16132 closing. Its Restart-when: is satisfied; the release is still a two-step read.
Decision box — 0 · Awaiting human merge — 0
Both empty. #13799 is the one open ask: pm:queue, carrying an unresolved A/B/C fork for the maintainer (a live 速讀 5556393251 asking for a letter, and a director ruling 5564370647 recording 「同意」 while calling the label a leftover and not mentioning that question). ⛔ This seat neither picked nor re-hung needs-user-decision.
Lane inventory — 128 open (re-derived 23:1xZ by page walk; ⛔ the search endpoint is refused by this container's proxy — repo-scoped labels= pages only. Control: a nonsense label reads 0 on the same walk)
pm:queue 68 (67 dispatchable) · pm:on-hold 25 · pm:blocked 11 · pm:awaiting-maintainer 10 · pm:dispatched 3 (this seat: 0 — all three are hotlong's, untouched since 2026-09-04/05) · pm:epic 2 · needs-user-decision0 · no pm-state 9. Parts sum to the whole: 68+25+11+10+3+2+9 = 128. finding45. Release board target:v18 = 2 (#9139, #15214), neither dispatchable ⇒ this lane blocks no RC.
⚠️ Bare cards fell 20 → 9 while pm:queue rose 66 → 68: triage is labelling the backlog, not draining it. Queue grew 33 → 67 dispatchable across this shift while 19 landed. That is a staffing reading for the maintainer, ⛔ not a backlog failure.
3. 热文件串行队
⚠️ Rebuilt 14:2xZ. Contention discipline behind every row: every open PR's changed-file list, paged to exhaustion (19 of 19 returned non-empty — the control fired), filtered for the exact paths below.
FREE (PR #16991 merged 01:06:57Z) → serial: #16454, #16494, #16717, #16886. ⚠️ The hottest file in the lane. ⚠️#16467's surface is wider than its title: narrowing push-on-main to the affected set breaks two unstated couplings — ci.yml:45-47's concurrency key is byte-identical for schedule and push (so the hourly run would be cancelled by the next merge) and select-shard-timings-run.mjs:265 hard-codes event=push (so the balancing dataset would regenerate from a partial run, green)
FREE (PR #16988 merged 00:39:15Z) — the checker moved four times today (#16776 verdicts, #16361 grain, #16713 depth), each landing proved the previous two intact → #16946 is open against the WHICH LEVEL prose in that same file, and #16973 against a PR that merged green through the blind axis
scripts/check-i18n-walk-parity.mjs
FREE (PR #16970 merged 21:58:46Z). ⚠️EXIT_PREREQUISITE_NOT_MET === 3 now means NOT MEASURED here — ⛔ a 3 is neither green nor red, and a reader that treats it as pass reintroduces #16776's defect one file over
FREE (PR #16976 merged 22:44:09Z) → open siblings #16630 (Server is ready on a degraded boot) and #16500 (the guidance half). ⚠️ The ORDER pin asserts gate → probes → section 4 by byte offset; a reorder reds it
FREE. ⚠️Three corpora register through this resolver, not two — check-system-context-census too; #16898 is open against a fourth that does not register
FREE (PR #16944 merged 18:41:07Z). ⚠️ A routing tension is open: triage's own rule says scripts/pm/** → domain:skills, yet #16822 was routed domain:devx — ⛔ triage's to settle
packages/lint/src/**
FREE (PRs #17034 and #17036 merged 05:11:12Z — different files, no collision; only #17036 touched index.ts) → ⭐ #16119's input plumbing ALREADY EXISTS — indexObjectGraph + resolveFieldPath cost one word in an existing import, measured by #16108's dev; ⛔ do not budget it as architecture. Then #16910 (the edges sibling — ⚠️ owes a NEW sweep arm), then #16108, #16119. ⚠️RESIDUAL_THROWS is now empty; a change that reintroduces a throw reds the sweep
FREE (PR #17035 merged 04:33:38Z). ⚠️#16593's scope CHANGED — note 5595460789: the derive-from repair is right in direction (declaration from walk) but blocked, measured — it cannot be static analysis, and a derived declaration reds check:pm-dispatch-gates on a watch-hint-inheritance question that is not this table's. ⛔ Tell whoever takes it to run that gate FIRST
scripts/pm/dispatch-gates.mjs
FREE. ⚠️#16769 is open against the selector's key sets, and its read-set moved once already inside two hours
scripts/ci/select-gate-families.sh
FREE (PR #16986 merged 00:14:59Z) — ⛔ half 1 only landed (the *.sh arm + a self-test that drives the window); the structural half (pin the selector's key sets to the gates' live read-sets) stays open and the card stays pm:queue
FREE; script-owned, ⛔ never hand-edited. #16797 open against the lockstep generator
AGENTS.md
FREE (PR #16573 merged 02:13:02Z) → #15410 (p2) is unblocked
.claude/skills/pm-dispatch/**
FREE; its waiter #14944 is pm:awaiting-maintainer, ⛔ not queue
content/docs/permissions/system-context.mdx
FREE, but ⚠️ will not stay free — re-check the holder before re-dispatch (#15927)
4. 说明
Platform readings — this shift's, each paid for with a wrong answer first
"The readers are exactly the N I ran" is NOT an acceptable narrowing justification. A dev skipped 40 gates claiming ten readers; the derivation over the same paths names 41 families / 49 commands. ⇒ The dispatch-gates derivation IS the reader list.
On a shallow clone git merge-base --is-ancestor returns exit 1 for MISSING HISTORY in the same shape as a true negative. Deepen until it answers. ⭐ The control-leg exit 0 is the only reading a shallow clone cannot fake — exit 0 means a path was found; missing history can only prevent an answer, never invent one. On an untrustworthy instrument, find the leg that can only false-negative.
⛔ Never post a landing stroke whose zero has no control beside it. This seat produced three false zeros from bad grep patterns this shift (a rule id that lives in its own file not the registry; a call site whose trailing as cast defeated the pattern; a != 'skip' count that mixed guards with prose). Every one would have read as a broken delivery. The control is the only reason none was reported as one.
A two-way local/network spawn classification is INCOMPLETE. A third class — ambient-by-design — must NOT be stripped: children whose subject is the merge or commit git is performing right now. Stripping them regresses silently with a green test.
A gate-mandated citation refresh inside packages/spec belongs to devx, not the spec seat — proved by restoring the base files under the new pin and watching check:objectui-pin-citations go exit 1. A bump that omits it cannot land green.
Clause-② enqueue bar is mechanical: diff touching packages/spec/src/** + a sub-tier dispatch ⇒ ⛔ no enqueue until an in-seat review at tier passes. It fired once here on a card whose content did not predict the spec face.
check-governed-merges.mjs audits only objectstack from this container — objectui/cloud/objectos/hotcrm have no checkout here and read UNAUDITED. ⛔ An unaudited repo is not a clean repo.
This checkout is SHALLOW; several tools need --deepen. ⛔ Never verify main from the shared checkout's working tree — probes go through git show origin/main:<path>.
⚠️When MCP is rate-limited, LANDING HAS NO FALLBACK — and this seat proved there is none, rather than assuming it.draft:false and enable_pr_auto_merge are GraphQL-only. Measured 2026-09-09T01:3xZ while landing PR fix(scripts): a dotted member path's last segment resolves at the region's top depth #17001: MCP returned «API rate limit already exceeded for user ID 6194462», and a direct GraphQL markPullRequestReadyForReview with this container's own token returned 403 — «This GraphQL query is not enabled for this session — only the pinned set of PR-review operations is served». ⭐ Note the two credentials are independent: this container's REST read 15000/15000 core, 10000/10000 graphql at the same moment MCP was exhausted, so ⛔ never infer MCP's quota from GET /rate_limit — that endpoint answers for the wrong token. ⇒ A green, reviewed PR simply waits; ⛔ do not improvise a path around it, and ⛔ do not report it as landed. Say it is flipped-pending and re-arm the timer.
Standing rules
Before EVERY dispatch read bash scripts/pm/os-verify-lock.sh --status; ⛔ never dispatch while arriving depth would be ≥2. Two live PRs never share a hot file. Governed surfaces (docs/adr/**, .claude/**, skills/**, AGENTS.md, CLAUDE.md) are ⛔ never flipped, armed or merged by this seat. Enqueue eligibility is every check green, ⛔ not the required subset; the only reliable enqueue probe is added_to_merge_queue in the PR's events. ⛔ #13503: no deletion before the maintainer's release line.
⭐ Attribution, corrected this shift: AGENTS.md governs — the harness-written Co-Authored-By trailer with its session link is the one exemption to the model-identifier ban. ⛔ Do not restate this as a blanket "no model identifiers in anything pushed"; that inherited sentence produced a wrong dispatch ruling twice before it was caught.
Dispatch-brief defects — kept so they are not reintroduced
⛔ Do not tell a dev to write an attribution footer (the platform appends its own) — and ⛔ do not tell it to strip the trailers either.
⛔ Do not tell a PM-dispatched dev to post its own Claim:.
⛔ Tell the dev the card relation goes in the PR BODY only — a commit message carries NO card trailer..claude/agents/os-dev.md says so 「卡片关系只在正文声明一次,commit ⛔ 不带卡片 trailer」, and scripts/check-partof-closing-keyword.mjs RULE 2 (:12-13) forbids every spelling — its self-test at :868 drives ['Fixes', 'Closes', 'Resolves', 'Part of', 'Refs'] as findings, so ⛔ Refs #N is not a safe substitute for Fixes #N. Once the branch is pushed ⛔ no action clears the red (a new commit joins the list; only a forbidden rewrite removes it), the queue edits nothing, and a closing trailer then sits in permanent history. Say it before the first commit or pay it forever. ⚠️This seat broke its own rule at R2: all three round-2 briefs told the dev to write Refs #N. ci: heavy CI never runs on a PR whose base is a feature branch — lint.yml / ci.ymlpull_request triggers are limited to branches: [main], so six required contexts report nothing on such PRs (item 3 of #16149) #16482's dev caught it, tested it (commitRelations() returned a finding), amended before pushing and flagged it; corrections were sent to the other two in flight. ⇒ A recorded defect is not a followed defect — re-read this list when writing the brief, not only when reviewing.
⛔ Do not add a trigger to a workflow without auditing every step condition written as a DENYLIST of event names.ci.yml's paths-filter step was if: github.event_name != 'merge_group' — an exclusion spelled as one event's name rather than as an allow-list of the events the action can actually resolve a diff for. Adding schedule: walks straight into it: the action runs with no resolvable base, every filter output comes back the literal 'false', and the || 'true' fallback ⛔ does not rescue an output that EXISTS and says false, because every downstream guard is != 'false'. ⇒ the hourly full run would have been a completely green run of nothing at all. ⭐ ci: push runs on main use the affected set; an hourly scheduled run keeps the full list and files a card on red (maintainer-directed) #16467's dev found this; this seat's brief missed it — and the brief had named two other hazards confidently enough to read as exhaustive. ⇒ ⛔ Never present a hazard list as complete; say how it was derived, so the dev knows to keep looking.
⛔ A change that creates a NEW run population leaves a bootstrap window in which that population is EMPTY — rule on it in the brief.ci: push runs on main use the affected set; an hourly scheduled run keeps the full list and files a card on red (maintainer-directed) #16467 repoints the shard-timings selector at event=schedule, but schedule: does not reach main until that PR merges, so the selector examined 0 candidates and refused (exit 1) on the PR itself, and would have stayed red for ≥1 hour after merge. ⚠️ Worse, its message blamed causes that had not occurred («censored, failed, or lost artifacts») — ⛔ a diagnosis naming a cause that did not happen is worse than none, it sends the next reader hunting a flake that does not exist. ⇒ Require the empty case to be distinguishable from the failed case: EXIT_PREREQUISITE_NOT_MET (3) for «the prerequisite has not happened yet» vs exit 1 for a finding — the idiom check:i18n-walk-parity exits 1 for PREREQUISITE NOT MET — the code a real finding uses #16558 landed the same night — and ⛔ require the 3 to be loud, because once the population should exist, an empty one is an alarm.
1. 当前 PM
session_012GKcPZbMoGq7WPzKLfRBTU(accountbaozhoutao) · seated 2026-09-08T01:23Z, round-open marker5577823514. Predecessorsession_01Vbw3RPgdtqesx4azk9SbW8died without a stand-down briefing (last output 2026-09-07T17:56Z); takeover confirmed by the maintainer in-session, conservative-confirmation path.trig_01LnAfFddrwzjCnaWsYno7o9). Batch cap3⇒ all three slots free. R5 landed five ([finding]judgeLevelcounts a package as "grown" only throughpackages/*/src/**, so a shippedbin/target is a published surface the changeset level axis cannot see #16692 · [finding] nothing pinsselect-gate-families's key sets to the gates' LIVE read-sets — the dispatch-gates self-test grew a.shcontent census the day the selector shipped, and the selector has no*.sharm #16769 half 1 · ci: push runs on main use the affected set; an hourly scheduled run keeps the full list and files a card on red (maintainer-directed) #16467 ·check-adr-0087-registration's dottedtype-surface-onlywalker cannot name a DIRECT member of an object literal whose name recurs in a nested literal —organizations.createis refused as AMBIGUOUS withorganizations.teams.create, and no deeper path exists for the direct one #16571 · lint: an object-qualified field-permission key naming a field the object does not declare is reported by nothing —security-fls-unqualified-keyonly catches the unqualified shape #16108); R6 landed three (spec's declared test-input radiuspackages/**/*.jsonsweeps vitest's ownnode_modules/.vite/vitest/*/results.json, so the task that hashes it (spec#test:repoafter #16466;spec#testbefore) can never replay from cache on a runner that ran any vitest before it #16555 ·approval-approvers-may-resolve-emptycoverspositionand notmanager— the rung whose column no product surface can write is the one the rule stays silent on #16748 · lint: an RLS predicate naming a non-existent field, or an un-pre-resolvedcurrent_user.*variable, is reported by nothing — both fail CLOSED at runtime #16119) and filed [finding] a gate whose diagnosis is exact but whose REMEDY cannot be carried out from the state it detected — two closed instances, and one gate that carried it at two branches #17037 and [finding] an RLS predicate naming an unknown column in a NEGATION position widens the policy to every row in the tenant instead of denying — the field-existence safety net is -only #17042. Cloud sessions created: none — every dispatch this shift wasmode:subagent..claude/skills/pm-dispatch/references/lanes/devx.md(pointer only).origin/main+ a textual probe on a re-fetched tree with a firing control and a nonsense control.draft:false/enable_pr_auto_mergeare GraphQL-only and worked through MCP at every landing window.2. 继承台账 (as of 2026-09-08T23:1xZ — round 4 closed)
Landed — 27, every one with a probe carrying controls
a472b07→53ded82b; Clause-② bar lifted by review, not by this seatTEXTsecret edge pointed atpassword;Check Changesetcleared byskip-changesetafter this seat re-derived the publish set independentlyhttpnode'sbodypayload;stripRegions'regionKeysdefault removed so the defect is no longer expressible. ⛔ Landed withcheck:partof-closing-keywordred, knowingly, residue namedpush:filter andmerge_group:untouched.NOT MEASUREDandPASSEDno longer share exit 0;editedsubscribed so the remedy needs no push. ⭐ Both halves proved live on PR #16916 twenty minutes lateroverrideadded to the symbol-anchor accept set + 12 spellings × a control each (floor 69 → 93). ⛔ Landed withcheck:partof-closing-keywordred — this seat's brief caused itdischargedverdict prints its own residual. ⛔ #16776's eight-verdict machine verified intactcheck-widening-tellsT2's two accidental variables removed on hunk-local evidence; self-test 131 → 150, nine ⛔-controls.:68's self-closing sentence replaced, twin includedrecordsOf.packages/([^/]+)/src/regex — a nested package was graded against its parent. Battery floor 16; the DEPTH arm is 21.check:i18n-walk-parityrefuses with the prerequisite code (3), not a finding's 1. Exactly one exit site moved (:324→:336); the self-test's own completion guard stayed at exit 1 and a new negative control pins it there:879, the executable line — ⛔ not the pattern's docblock); section 4 not hoisted (:1096, still last). Predicate is «a unit of the composition did not arrive», ⛔ deliberately not severity — a healthy boot carries⚠lines. Named residual: an optional plugin failing silently still slips throughpm:queue. A*.sharm in the gate selector's read-set. ⭐ This seat re-ran the ablation itself: removing only the arm reds exactly the new case's 3 checks, the other 189 of 192 verdict-identicalbinleg, ⛔src/**kept and evaluated first. #16713's control assertingbin/**is NOT read was inverted in place, reasoning kept. 73 dirs before/after, 0 lost; floor 16 → 17security-fls-unknown-field, closing a fail-open (a dangling FLS key means the mask never enforces). At-tier review PASS; one patch round removed a false premise the rule was skipping on, replacing it with a pin against the live schema so it cannot rot silentlynode_modules, and the registry gate now asks what else a declared glob MATCHES. ⭐ The measurement came back the non-obvious way: turbo 2.10.10 silently drops a negation carrying$TURBO_ROOT$(three spellings inert) while package-relative works — had the dev assumed, the fix would have looked right, changed nothing and gone greenmanagerrung — the one an operator cannot rescue. At-tier PASS.manager_idis admin-surface-only by declaration, so the import's omission is deliberatecurrent_user.*set is derived from the reserved superset.Three of the twenty-seven were dead-claim recoveries inherited at takeover.
Cards filed this shift — 13, all left unlabelled for triage
#16736 · #16744 · #16751 · #16752 · #16769 · #16797 · #16886 · #16898 · #16910 · #16946 · #16949 · #16973 · #16985. Eight came out of dev, reviewer or landing-probe work rather than from a sweep — #16886 was found while reading
ci.ymlto pay #16395's landing stroke: the Dogfood Regression Gate carries the identical run-level-passthrough defect at:1283, with no--onlyand no passthrough-free build ahead of it, across 3 shards over a 28-workspace-dep^buildclosure. ⛔ None labelled by this seat —domain:*is triage's.⛔ #15442 / #15449 are
domain:spec, not this lane. Their gate (pin ⊇53ded82b) is satisfied and that is recorded on #16626, but the spec seat's unlock scan owns re-verifying it on the merged ref. ⛔ This seat does not claim, dispatch or relabel them — and per this card's own history that seat should re-take the reading rather than trust the sentence.⛔ #14290 is NOT auto-restarted by #16132 closing. Its
Restart-when:is satisfied; the release is still a two-step read.Decision box — 0 · Awaiting human merge — 0
Both empty. #13799 is the one open ask:
pm:queue, carrying an unresolved A/B/C fork for the maintainer (a live 速讀5556393251asking for a letter, and a director ruling5564370647recording 「同意」 while calling the label a leftover and not mentioning that question). ⛔ This seat neither picked nor re-hungneeds-user-decision.Lane inventory — 128 open (re-derived 23:1xZ by page walk; ⛔ the search endpoint is refused by this container's proxy — repo-scoped
labels=pages only. Control: a nonsense label reads 0 on the same walk)pm:queue68 (67 dispatchable) ·pm:on-hold25 ·pm:blocked11 ·pm:awaiting-maintainer10 ·pm:dispatched3 (this seat: 0 — all three arehotlong's, untouched since 2026-09-04/05) ·pm:epic2 ·needs-user-decision0 · no pm-state 9. Parts sum to the whole: 68+25+11+10+3+2+9 = 128.finding45. Release boardtarget:v18= 2 (#9139, #15214), neither dispatchable ⇒ this lane blocks no RC.pm:queuerose 66 → 68: triage is labelling the backlog, not draining it. Queue grew 33 → 67 dispatchable across this shift while 19 landed. That is a staffing reading for the maintainer, ⛔ not a backlog failure.3. 热文件串行队
.github/workflows/ci.yml+lint.yml+scripts/ci/select-shard-packages.sh+select-shard-timings-run.mjsmainto the affected set breaks two unstated couplings —ci.yml:45-47's concurrency key is byte-identical forscheduleandpush(so the hourly run would be cancelled by the next merge) andselect-shard-timings-run.mjs:265hard-codesevent=push(so the balancing dataset would regenerate from a partial run, green).github/workflows/pr-automation.yml+scripts/check-changeset-no-major.mjsWHICH LEVELprose in that same file, and #16973 against a PR that merged green through the blind axisscripts/check-i18n-walk-parity.mjsEXIT_PREREQUISITE_NOT_MET === 3now means NOT MEASURED here — ⛔ a 3 is neither green nor red, and a reader that treats it as pass reintroduces #16776's defect one file overscripts/publish-smoke.sh+packages/spec/scripts/publish-smoke-boot-failure.test.tsServer is readyon a degraded boot) and #16500 (the guidance half).ORDERpin asserts gate → probes → section 4 by byte offset; a reorder reds itscripts/symbol-anchors.mjs+scripts/check-scripts-symbol-anchors.mjscheck-system-context-censustoo; #16898 is open against a fourth that does not registerscripts/pm/check-widening-tells.mjs+check-clause2-carriers.mjsscripts/pm/**→domain:skills, yet #16822 was routeddomain:devx— ⛔ triage's to settlepackages/lint/src/**index.ts) → ⭐ #16119's input plumbing ALREADY EXISTS —indexObjectGraph+resolveFieldPathcost one word in an existing import, measured by #16108's dev; ⛔ do not budget it as architecture. Then #16910 (theedgessibling —RESIDUAL_THROWSis now empty; a change that reintroduces a throw reds the sweepscripts/cross-package-test-inputs.mjs+turbo.json5595460789: the derive-from repair is right in direction (declaration from walk) but blocked, measured — it cannot be static analysis, and a derived declaration redscheck:pm-dispatch-gateson a watch-hint-inheritance question that is not this table's. ⛔ Tell whoever takes it to run that gate FIRSTscripts/pm/dispatch-gates.mjsscripts/ci/select-gate-families.sh*.sharm + a self-test that drives the window); the structural half (pin the selector's key sets to the gates' live read-sets) stays open and the card stayspm:queue.objectui-sha,sdui.manifest.json,scripts/sdui-manifest.record.json,packages/sdui-parser/objectui-lockstep.jsonAGENTS.md.claude/skills/pm-dispatch/**pm:awaiting-maintainer, ⛔ not queuecontent/docs/permissions/system-context.mdx4. 说明
Platform readings — this shift's, each paid for with a wrong answer first
dispatch-gatesderivation IS the reader list.git merge-base --is-ancestorreturns exit 1 for MISSING HISTORY in the same shape as a true negative. Deepen until it answers. ⭐ The control-leg exit 0 is the only reading a shallow clone cannot fake — exit 0 means a path was found; missing history can only prevent an answer, never invent one. On an untrustworthy instrument, find the leg that can only false-negative.where, which blocks the ruled #15442/#15449 filter converge #16626's unblock check--is-ancestor 53ded82b <new pin>holds reflexively once the pin is53ded82b. Name the load-bearing legs instead — here, that the pin is on objectuimain, plus a functional probe. ⭐ And add a negative control (--is-ancestor origin/main NEWPIN→ 1) to show exit 0 discriminates rather than always answering yes.ascast defeated the pattern; a!= 'skip'count that mixed guards with prose). Every one would have read as a broken delivery. The control is the only reason none was reported as one.'git'literal probe cannot see a git spawn inside ansh -ccommand string. Tier A of the #16624 class: themerge=os-regendriver and the pre-commit/pre-push gate build throwaway git repos with no environment of their own — the two files git itself invokes #16753's card counted 12 sites; there are 13. Same false-negative species the card itself documented forgit init, one level out — found by a behavioural battery, ⛔ not by reading.packages/specbelongs to devx, not the spec seat — proved by restoring the base files under the new pin and watchingcheck:objectui-pin-citationsgo exit 1. A bump that omits it cannot land green.packages/spec/src/**+ a sub-tier dispatch ⇒ ⛔ no enqueue until an in-seat review at tier passes. It fired once here on a card whose content did not predict the spec face.check-governed-merges.mjsaudits onlyobjectstackfrom this container —objectui/cloud/objectos/hotcrmhave no checkout here and readUNAUDITED. ⛔ An unaudited repo is not a clean repo.--deepen. ⛔ Never verifymainfrom the shared checkout's working tree — probes go throughgit show origin/main:<path>.draft:falseandenable_pr_auto_mergeare GraphQL-only. Measured 2026-09-09T01:3xZ while landing PR fix(scripts): a dotted member path's last segment resolves at the region's top depth #17001: MCP returned «API rate limit already exceeded for user ID 6194462», and a direct GraphQLmarkPullRequestReadyForReviewwith this container's own token returned 403 — «This GraphQL query is not enabled for this session — only the pinned set of PR-review operations is served». ⭐ Note the two credentials are independent: this container's REST read15000/15000 core, 10000/10000 graphqlat the same moment MCP was exhausted, so ⛔ never infer MCP's quota fromGET /rate_limit— that endpoint answers for the wrong token. ⇒ A green, reviewed PR simply waits; ⛔ do not improvise a path around it, and ⛔ do not report it as landed. Say it is flipped-pending and re-arm the timer.Standing rules
Before EVERY dispatch read
bash scripts/pm/os-verify-lock.sh --status; ⛔ never dispatch while arriving depth would be ≥2. Two live PRs never share a hot file. Governed surfaces (docs/adr/**,.claude/**,skills/**,AGENTS.md,CLAUDE.md) are ⛔ never flipped, armed or merged by this seat. Enqueue eligibility is every check green, ⛔ not the required subset; the only reliable enqueue probe isadded_to_merge_queuein the PR's events. ⛔ #13503: no deletion before the maintainer's release line.⭐ Attribution, corrected this shift: AGENTS.md governs — the harness-written
Co-Authored-Bytrailer with its session link is the one exemption to the model-identifier ban. ⛔ Do not restate this as a blanket "no model identifiers in anything pushed"; that inherited sentence produced a wrong dispatch ruling twice before it was caught.Dispatch-brief defects — kept so they are not reintroduced
Claim:.flow-double-brace-interp/flow-bare-dollar-refnever reach anhttpnode's request payload — the samestripRegionsunion that blinded the flow-template rules #16405's claim scoped to one file; the card body and triage both required the sibling repair too, so the dev breached and explained (correctly) rather than shipping a half fix..claude/agents/os-dev.mdsays so 「卡片关系只在正文声明一次,commit ⛔ 不带卡片 trailer」, andscripts/check-partof-closing-keyword.mjsRULE 2 (:12-13) forbids every spelling — its self-test at:868drives['Fixes', 'Closes', 'Resolves', 'Part of', 'Refs']as findings, so ⛔Refs #Nis not a safe substitute forFixes #N. Once the branch is pushed ⛔ no action clears the red (a new commit joins the list; only a forbidden rewrite removes it), the queue edits nothing, and a closing trailer then sits in permanent history. Say it before the first commit or pay it forever.Refs #N. ci: heavy CI never runs on a PR whose base is a feature branch —lint.yml/ci.ymlpull_requesttriggers are limited tobranches: [main], so six required contexts report nothing on such PRs (item 3 of #16149) #16482's dev caught it, tested it (commitRelations()returned a finding), amended before pushing and flagged it; corrections were sent to the other two in flight. ⇒ A recorded defect is not a followed defect — re-read this list when writing the brief, not only when reviewing.merge=os-regendriver and the pre-commit/pre-push gate build throwaway git repos with no environment of their own — the two files git itself invokes #16753's red leg, run literally, reproduces the incident it tests for. Fence the stand-in before dispatch.lint.yml/ci.ymlpull_requesttriggers are limited tobranches: [main], so six required contexts report nothing on such PRs (item 3 of #16149) #16482's Pin bullet offersci-cd-pipeline-doc.test; measured onorigin/main, 0 files match that name (control: 9 paths matchpipeline). The claim inherited it, so the surface excluded the one file the pin actually had to live in — and the dev had to breach to land the card. A path in a card is a hint, not a reading.ci.yml's paths-filter step wasif: github.event_name != 'merge_group'— an exclusion spelled as one event's name rather than as an allow-list of the events the action can actually resolve a diff for. Addingschedule:walks straight into it: the action runs with no resolvable base, every filter output comes back the literal'false', and the|| 'true'fallback ⛔ does not rescue an output that EXISTS and says false, because every downstream guard is!= 'false'. ⇒ the hourly full run would have been a completely green run of nothing at all. ⭐ ci: push runs on main use the affected set; an hourly scheduled run keeps the full list and files a card on red (maintainer-directed) #16467's dev found this; this seat's brief missed it — and the brief had named two other hazards confidently enough to read as exhaustive. ⇒ ⛔ Never present a hazard list as complete; say how it was derived, so the dev knows to keep looking.event=schedule, butschedule:does not reachmainuntil that PR merges, so the selector examined 0 candidates and refused (exit 1) on the PR itself, and would have stayed red for ≥1 hour after merge.EXIT_PREREQUISITE_NOT_MET(3) for «the prerequisite has not happened yet» vs exit 1 for a finding — the idiom check:i18n-walk-parity exits 1 for PREREQUISITE NOT MET — the code a real finding uses #16558 landed the same night — and ⛔ require the 3 to be loud, because once the population should exist, an empty one is an alarm.Clause-②:line in a claim is a MACHINE-READ TOKEN LINE. Never put an instruction on it. This seat wroteClause-②: ⚠️ **judge it yourself and declare it in the PR body.** …on lint: an object-qualified field-permission key naming a field the object does not declare is reported by nothing —security-fls-unqualified-keyonly catches the unqualified shape #16108's claim.check-clause2-carriers.mjs'sCLAUSE2_KEY_LINE(:521) matched the key and found neither fixed value ⇒ MALFORMED, row C2 red at exit 4, and the enqueue gate's content limb had nothing to read for the pair — on a PR whose diff is exactly the case that limb exists for. ⭐ lint: an object-qualified field-permission key naming a field the object does not declare is reported by nothing —security-fls-unqualified-keyonly catches the unqualified shape #16108's dev caught it and ⛔ correctly refused to fill the line in on this seat's behalf: the declaration IS the judgement, and a missing reading is ⛔ not a declaredno. ⇒ Put the token alone on its line (Clause-②: yes) and the instruction on the NEXT line — the parser accepts a value with reasoning appended (os lintnever surfaces ADR-0087 conversion notices — it normalizes with noonConversionNoticesink, the #3782 parity gapos buildwas in #12297,:536) but ⛔ never a value that is notyesorno..claude/skills/pm-dispatch/SKILL.md:808gives the line asClause-②: yes | noand:479says 恰这两种拼写. The template was right; the claim was wrong. ⇒ Before filing a card against a governed surface on a dev's reading, ⛔ open the file. A card blaming a correct file for a seat's own error is worse than no card.approval-approvers-may-resolve-emptycoverspositionand notmanager— the rung whose column no product surface can write is the one the rule stays silent on #16748's brief told the dev the rule's hint must prescribe «populatesys_user.manager_idvia SCIM / import / directory sync». This seat took that from the card and ⛔ never derived it. Measured by the at-tier reviewer:admin-import-users.tshas 0manager_idhits (control:phone_number= 8, so the grep discriminates) and its update field set excludes the column; SCIM declares the Enterprisemanagerattribute (scim.zod.ts:405) but nothing inpackages/pluginsorpackages/runtimeprojects it intosys_user.manager_id(control:SysScimGroup= 2). ⇒ Only the seed / system-context route has a demonstrated writer —isUserContextWriteissession.userId && !isSystem, so a system-context write passes the guard.⭐ This is [finding] a gate whose diagnosis is exact but whose REMEDY cannot be carried out from the state it detected — two closed instances, and one gate that carried it at two branches #17037's own defect class, met from the brief-writing side, and this seat filed [finding] a gate whose diagnosis is exact but whose REMEDY cannot be carried out from the state it detected — two closed instances, and one gate that carried it at two branches #17037 an hour before committing it: a remedy that names routes the reader cannot take.
Generated by Claude Code