Skip to content

[finding] A gate label removed by a SEAT is still undetectable — the whole-set-PUT gate cannot reach that surface #11881

Description

@os-steve

Filed unassigned, from the #10778 implementation (PR #11880). Recording two things that would otherwise be buried when #10778 closes: a falsified attribution, and a recommendation its reporter explicitly deferred to triage.

1. The Auto Label attribution on #10778 is falsified

#10778's dispatch escalated on a 2026-08-23 measurement reading that the Auto Label workflow's whole-set PUT erased needs:contract-review on PR #11470 — a "second perpetrator" after #10703's PR-size labeler. That comment measured the effect (a label disappeared) and said so in as many words; the mechanism was assumed. It does not survive checking:

⇒ No second workflow perpetrator exists. #10778's actual premise ("nothing mechanically bans the verb") was true and is now fixed by PR #11880.

2. The residual gap that PR #11880 does NOT close

The gate landed in #11880 sweeps .github/workflows/**, .github/actions/** and scripts/**. The erasing actor on #11470 was a seat, which is none of those. So the gate would not have prevented the loss that motivated the escalation, and cannot: seats write through the API at runtime, not through a file the repo can scan.

What that leaves standing is the second-order cost #10778 names, unchanged for seat-side writes:

while the verb is reachable, "the label is absent" stops meaning anything — absence has two causes (cleared after review, or erased) and read-back is the only detection there is.

⚠️ To be precise about what is and is not measured here: the 21:41:25Z removal was by a seat and was re-applied 13 minutes later, which is consistent with an accidental loss caught by read-back; the 22:40:21Z one is consistent with an ordinary post-review clear. This card does not claim a seat performed a whole-set write — only that a compensating gate label can leave a PR with no mechanism making that noisy, and that the actor is outside the new gate's reach.

3. The deferred recommendation, recorded before it is lost

os-sam raised this on #10778 and explicitly left it to triage/the maintainer rather than ruling on it (2026-08-23, original wording preserved):

⚠️ 推论,交给分诊/维护者判断而非本席裁定:一条能被静默抹除的补偿性控制,严格来说不是一条控制,而是一条约定。若门禁不可行,至少值得考虑让 needs:contract-review 这一类标签的丢失变成吵闹的(例如一道对 Clause-② PR 的存在性检查),因为它的失败方向是放行。

An existence check over Clause-② PRs is the shape suggested. Not evaluated here and not proposed as queued work — this is an observation card, and #10778 is closing.

Dedupe

Searched before filing. Semantic search returned 0 and was not trusted on that alone (#10778's own thread records a zero that was a query artifact); instead all 350 open issues were enumerated and body-scanned as a controlled population. Positive control: label matched 71 cards. whole-set / setLabels / PUT /issues matched exactly one — #10778. Nearest neighbours (#11188, #11773, #11681, #11503) read and are unrelated.

Refs: #10778 · PR #11880 · #10703 · PR #11470 · PR #10698


Generated by Claude Code

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions