Uh oh!
There was an error while loading. Please reload this page.
Instruction-text alignment: five governed-protocol clauses restated to measured reality - #12657
Merged
Merged
Conversation
…iour The session-URL footer does NOT survive a PR-body edit: measured 2026-08-26 (three REST writes, per-write read-back), every PATCH normalises the session form DOWN to bare, and the bare footer then survives later edits verbatim — the inverse of both files' standing promise. Both os-dev.md's byte-discipline section and AGENTS.md's attribution-footer clause now state the measured behaviour and the practice: session id is create-only; durable attribution goes in body prose or a comment. Comment channel unchanged (not re-measured). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq
…action, stated in both protocol files os-dev.md rule 2 asserted a state (claimed, do not touch the assignee) that contradicted the repo CLAUDE.md claim-first rule; devs resolved the conflict differently on the same day, one claiming late and one leaving a dispatched card unassigned-while-claimed. Ruling: the PM owns the assignee — it is set in the dispatch atomic pair (SKILL.md claim step 1), so CLAUDE.md's claim-first is satisfied by the PM's claim before the dev arrives. Rule 2 now gives one action in every observed state: never write the field, and report an empty-on-arrival assignee in the summary as a PM-side half-state. SKILL.md's claim intro states the ownership from the PM side in the same words. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq
… against union(read, intended) A whole-set label write erases any label a concurrent actor lands between your read and your write; the loss is silent and the victim is usually a label you never meant to touch (measured live: a bot's label survived only because its write landed before the PUT was composed). A bare read-back cannot see this. Both the PM-side hard-step rule (SKILL.md) and the dev-side whole-set fallback (os-dev.md) now require the read-back to be compared against union(read set, intended change): any label in the union but absent from the read-back was stripped by your PUT — re-add it and report it. The comparison detects the loss; it does not prevent it, and the texts say so. Additive MCP label calls and credential export are platform surfaces, out of scope here. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq
…der the 120-byte budget Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq
…'s kind split The skill stated finding-labelling unconditionally while the role file splits it by kind — observational findings wear the label, concrete defects stay unlabelled for triage. The two are different triage inputs (the label routes the card), so every dispatch brief quoting the skill mislabelled concrete defects and inflated the ungraded-findings health count. The role file wins by the skill's own conflict rule; the skill line is rewritten in place to the same kind split, inside the line ratchet, no re-wrap funding. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq
…sing the claim A dev that dies mid-edit has, by construction, not committed: its entire output is uncommitted changes in the dispatch worktree, invisible to every GitHub-side reading the recovery procedure prescribes. Following the label steps to the letter discarded-by-omission that work (a live case held 113 changed lines across two instruction files, recovered only because a seat looked). The reclaim step now starts by checking the dispatch worktree: uncommitted changes are committed as WIP on the dispatch branch, pushed, the sha named in the recovery comment and marked INCOMPLETE AND UNREVIEWED, so the resuming dispatch diffs it rather than building on it unexamined. The line is paid inside the ratchet by the previous member's in-place shrink. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq
os-litant
marked this pull request as ready for review
August 27, 2026 04:05
Uh oh!
There was an error while loading. Please reload this page.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes#12553
Fixes#12520
Fixes#11960
Fixes#12455
Fixes#12627
Family dispatch: five cards aligning the governed instruction files (pm-dispatch SKILL.md, os-dev.md, AGENTS.md) with measured reality on the claim/label/recovery discipline face. One commit per member; every edit stays inside the zero-headroom ratchets (SKILL.md 1005/1005, os-dev.md 470/470, AGENTS.md 1158/1158; widest SKILL.md table row unchanged at 765/765). All landing sites were re-verified against the post-merge main (the protocol-hardening chain rewrote os-dev.md rule 2 and SKILL.md's claim passages this morning); edits reconcile with the merged text, not with the cards' pre-merge quotes.
Per-member deliverables and check criteria
Chain head — comparative label read-back (protocol-text half only).
SKILL.md's hard-step label rule and os-dev.md's whole-set fallback now require the read-back to be diffed against union(read set, intended change), re-adding and reporting any label the whole-set write stripped; both texts state that the comparison detects the loss and does not prevent it. Criterion: grep both files for the union-diff spelling —
union(现集, 目标增删)in SKILL.md,union(读集, 目标)in os-dev.md. Candidate shapes 1 and 2 on the card (an additive MCP label call; seat-credential export) are platform surfaces and are deliberately not touched here.Assignee ownership — the os-dev vs repo-CLAUDE.md contradiction.
Ruled to the PM side, matching the dispatch atomic pair as merged this morning: os-dev.md rule 2 now opens
assignee 归 PMand gives one deterministic action in every observed state — never write the field; an empty-on-arrival assignee is a PM-side half-state reported in the summary — and states that the repo CLAUDE.md claim-first rule is satisfied by the PM's claim before the dev arrives. SKILL.md's claim intro states the same ownership from the PM side (assignee 字段归 PM:原子对 step 1 设,dev 席恒不写它). Criterion: both files answer "who writes the assignee field" with the same owner, and the dev instruction no longer asserts a state the dev may not observe.Finding-label kind split.
The skill's report-contract line now carries the role file's split — observational findings wear
finding, concrete defects stay unlabelled for triage — instead of the unconditional labelling token. Criterion: SKILL.md no longer contains an unconditional finding-labelling instruction; the rewritten parenthetical names both kinds and defers to os-dev rule 3.Footer promise restated to the measured edit-path behaviour.
os-dev.md's byte-discipline section and AGENTS.md's attribution-footer clause now state the 2026-08-26 measurement (three REST writes, per-write read-back): create keeps the session-URL form; every PATCH edit normalises it DOWN to bare; the bare footer survives later edits verbatim. Both files state the practice: the footer's session id is create-only; durable attribution goes in body prose or a comment. The comment-channel paragraph is untouched (separate channel, not re-measured). Criterion: neither file still claims the session form survives the edit path.
Dead-claim recovery rescues the worktree first.
The stale-claim reclaim step now begins by checking the dispatch worktree: uncommitted changes are committed as WIP on the dispatch branch, pushed, the sha named in the recovery comment and marked INCOMPLETE AND UNREVIEWED, so the resuming dispatch diffs it rather than building on it unexamined. Criterion: the reclaim clause names the worktree rescue before the assignee release.
Cut-ledger (zero-headroom accounting)
Every file lands exactly at its ceiling; every added byte was paid inside the passages being edited. Cuts, each with its surviving home:
Verification (head aede3eb)
Derived union from
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack(change set: exactly the three files; 14 local families), all runs at head aede3eb through the shared verify lock:Governed surface: this PR stays draft for maintainer merge (instruction .md files). No changeset — nothing publishable changes; skip-changeset label applied per this repo's mechanism.
Out of scope, stated safely: the platform-surface candidate shapes on the chain head (additive MCP label endpoint, seat-credential export) are not addressed here. The AGENTS.md claim-first paragraph for standalone, non-dispatched agents remains as is: under the PM-owned assignee ruling it needs no change, since the PM's dispatch-time assign satisfies it before a dispatched dev arrives.
Generated by Claude Code