Uh oh!
There was an error while loading. Please reload this page.
Make the additive label POST the prescribed write and permit it for dev agents - #11112
Conversation
…-dev.md The skip-changeset paragraph taught the whole-set read -> union -> write as what the label write IS. The additive POST endpoint is the mechanism: named executably (curl + Bearer token, measured working from an agent seat), with read-back after the bots settle kept as the closing step, a vanished label re-applied rather than read as your own error, and the whole-set union demoted to a declared fallback for a seat where the additive call is refused. The objectui half is unchanged. 392 -> 395 lines, ceiling 399. Fixes#10902 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MsbKEG4LtERSLaDrbehM3e
…ion set
The auto-mode permission classifier was measured blocking a dev agent's
additive POST /repos/{owner}/{repo}/issues/{n}/labels while permitting the
whole-set labels write - the inversion that pushes agents into the clobbering
shape. Direction A: pre-approve exactly the additive POST spelling that
os-dev.md now prescribes (objectstack + objectui twins), strictly narrower
than the whole-set write already permitted.
Fixes#10686
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsbKEG4LtERSLaDrbehM3eos-zhuang
commented
Aug 22, 2026
PM 验收 — ACCEPT(终态)复核:席位 session_01MsbKEG4LtERSLaDrbehM3e 全 diff 审毕(+12/−7 两文件,一员一提交各带 Fixes)。成员 1(os-dev.md):裁定的四点形状逐项落地——加法 POST 以可执行拼写写明并与 settings 允许项互钉(「别改写」)、读回保留且移到 bots 稳定后(消失读作被抹、重加非己错——#10686 实测警示折入)、整组并集降为申报式回退、objectui 半边逐字节未动;395/399 无抬升,id-lint 绿。成员 2(settings.json):两条 前提修正如实申报:#10686 的 classifier 拦截本席未复现(同拼写 200)——判定被实测为形状敏感且跨会话不可重复(证据卡 #11114,已按发现纪律立卡待定级)。这不削弱方向 A,反而是其最强论据:显式 allow 条目是唯一确定性通道。机制自证:本 PR 的 skip-changeset 即以文档中的加法 POST 施加,读回 bots 后双标完好零 unlabeled。 治理面终态: Generated by Claude Code |
Uh oh!
There was an error while loading. Please reload this page.
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 32594788700 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
…3 maintainer ruling The merge group for this PR went red on check-skill-line-ratchet: os-dev.md composes to 401 lines against main (which #11112 took to 395), and to 405 once the queued #11137 (395→399) lands ahead of it — each PR green alone, over the ceiling only in composition. Maintainer ruling, 2026-08-23, on this PR (option B of the three put to them, verbatim): 「B:提天花板 399→405」 — keep the +6-line cross-repo caveat and raise the ceiling, quoted in the PR body as the ratchet requires. Sized to exactly 405 so headroom returns to zero once both queued PRs land. Gate + 19-case self-test green at this commit. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MsbKEG4LtERSLaDrbehM3e
…e permission set The seat's GraphQL bucket is measured at the ceiling (~4965/5000 used in one hour) while REST core sits nearly empty (~50/15000). The MCP list/read family runs on GraphQL — `list_issues` returns Connection cursors, and a squeeze measurement moved graphql used by +7/+4 across MCP calls while core barely moved. Every read the loop repeats therefore spends the scarce bucket. Pre-approve the REST equivalents so the seat can take them without a prompt, spelled exactly like the additive label POST added by #11112 (method, host and path shape pinned; URL immediately after `-X`; the trailing `*` absorbs the Bearer header and any payload). Nine path shapes per repo, objectstack and objectui twins: issue list, issue get, issue comments, issue labels read, PR get, PR files, PR commits, commit check-runs, and the PR body PATCH. Plus `GET /rate_limit`, which is free and is what a quota check reads. Query-carrying paths get the wildcard against the path itself (`comments* *`) so one entry covers both the bare and the `?per_page=…&page=N` spellings without widening the path shape. No bare `curl *` entry is added. The routing-guidance prose is NOT in this PR: `platform-readings.md` is at 134/134 and SKILL.md at 682/682, both zero headroom, and no honest deletion was available — see the PR body. Fixes#11181 Co-Authored-By: Claude <noreply@anthropic.com>
…se a contradicted --repo assertion (objectstack-ai#11126) * fix(pm): make dispatch-gates name the repo it answers about, and refuse a contradicted --repo assertion The tool derives gate families from the tree it runs in and never said so. Handed a sister repo's paths it returned a confident, well-formed, exit-0 answer about the wrong repo, with no tell — and four of the five repos in scope hold no copy of the script at all, so every sister-repo dispatch was exposed to it. Every derivation now opens with a banner naming the repo and commit the answer came from, and `--repo <owner>/<name>` turns a caller's expectation into a checked assertion that refuses, naming both repos, on mismatch. Paths are repo-relative, so a path's home repo is never guessed: the banner is the unconditional tell and the assertion is the mechanical one. The no-path merge-base mode is untouched apart from the banner. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MsbKEG4LtERSLaDrbehM3e * chore(pm): raise the os-dev.md line ceiling 399→405 per the 2026-08-23 maintainer ruling The merge group for this PR went red on check-skill-line-ratchet: os-dev.md composes to 401 lines against main (which objectstack-ai#11112 took to 395), and to 405 once the queued objectstack-ai#11137 (395→399) lands ahead of it — each PR green alone, over the ceiling only in composition. Maintainer ruling, 2026-08-23, on this PR (option B of the three put to them, verbatim): 「B:提天花板 399→405」 — keep the +6-line cross-repo caveat and raise the ceiling, quoted in the PR body as the ratchet requires. Sized to exactly 405 so headroom returns to zero once both queued PRs land. Gate + 19-case self-test green at this commit. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MsbKEG4LtERSLaDrbehM3e --------- Co-authored-by: Claude <noreply@anthropic.com>
…e permission set (objectstack-ai#11186) The seat's GraphQL bucket is measured at the ceiling (~4965/5000 used in one hour) while REST core sits nearly empty (~50/15000). The MCP list/read family runs on GraphQL — `list_issues` returns Connection cursors, and a squeeze measurement moved graphql used by +7/+4 across MCP calls while core barely moved. Every read the loop repeats therefore spends the scarce bucket. Pre-approve the REST equivalents so the seat can take them without a prompt, spelled exactly like the additive label POST added by objectstack-ai#11112 (method, host and path shape pinned; URL immediately after `-X`; the trailing `*` absorbs the Bearer header and any payload). Nine path shapes per repo, objectstack and objectui twins: issue list, issue get, issue comments, issue labels read, PR get, PR files, PR commits, commit check-runs, and the PR body PATCH. Plus `GET /rate_limit`, which is free and is what a quota check reads. Query-carrying paths get the wildcard against the path itself (`comments* *`) so one entry covers both the bare and the `?per_page=…&page=N` spellings without widening the path shape. No bare `curl *` entry is added. The routing-guidance prose is NOT in this PR: `platform-readings.md` is at 134/134 and SKILL.md at 682/682, both zero headroom, and no honest deletion was available — see the PR body. Fixesobjectstack-ai#11181 Co-authored-by: Claude <noreply@anthropic.com>
Fixes#10902
Fixes#10686
One defect in two halves, one commit per member.
Member 1 —
.claude/agents/os-dev.md(commit 8c0a24c)The skip-changeset paragraph taught the whole-set read → union → write as what the label write is. Rewritten to the adjudicated four-point shape:
POST /repos/{owner}/{repo}/issues/{n}/labelsis THE mechanism, named executably — the exactcurlline withAuthorization: Bearer $GITHUB_TOKEN(measured working from an agent seat; "apply it additively" alone was demonstrably not actionable).Line budget: os-dev.md 392 → 395 lines, ceiling 399 (
check:pm-skill-ratchetverdict below). No ceiling raise. No issue numbers added (id-lint clean).Member 2 —
.claude/settings.json(commit f6d61c9)Direction A from the paired card: the auto-mode permission classifier was measured blocking a dev agent's additive label POST while permitting the whole-set
issue_writelabels array — the inversion that pushes agents into the clobbering shape. Twopermissions.allowentries pre-approve exactly the additive POST spelling that os-dev.md now prescribes, for this repo and the objectui twin (the same settings file governs sessions that touch both):Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectstack/issues/*/labels *)Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectui/issues/*/labels *)Strictly narrower than the whole-set write already permitted: the endpoint can only add. Documentation note:
settings.jsonis strict JSON and cannot carry comments, so the rationale lives here and in the os-dev.md paragraph the entries serve (the doc pins the exact spelling the rules match — URL directly after-X POST— and says not to rewrite it). Failure direction if the harness does not support the mid-pattern wildcard on the issue number: the rule is inert and the classifier keeps deciding, i.e. no wider than today. This does not address the labeler's own whole-set PUT — that half remains open: #10703 remains open (devx lane).Verified this session from a dev seat: the additive POST to this PR's own labels endpoint returned 200 and the read-back after the size-labeler settled shows the label intact (evidence in the report comment on the anchor card).
Gates (all at head f6d61c9, run after the final commit)
node scripts/pm/dispatch-gates.mjs(no hand-fed paths) derived 8 families; all green:check:pm-skill-ratchet— "✓ check-skill-line-ratchet: .claude/agents/os-dev.md is 395 lines (ceiling 399; headroom 4)."check:pm-skill-id-lint— "✓ check-skill-id-lint: 17 file(s) clean (pattern /#[0-9]{3,}/g)."check:doc-authoring— "✓ doc authoring guard: 389 files clean — no bare metadata literals."check:nul-bytes— "check-nul-bytes: OK (scanned 6426 text file(s) … no raw ASCII control bytes)."check:pm-governed-merges— "✓ check-governed-merges --self-test: 119 assertions …"check:agent-model-declared— "✓ check-agent-model-declared: 1 agent definition(s) under .claude/agents/ all declare a model"check:skill-frame-sync— "✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files"check:doc-formula-expressions— "✓ … 22 record-scoped formula example(s) across 416 files / 1447 TS blocks judged clean".claude/**only — no publishable package changes, so no changeset; skip-changeset label applied. Governed surface (Prime Directive #14): draft PR, human merge only.Generated by Claude Code
Generated by Claude Code