Uh oh!
There was an error while loading. Please reload this page.
docs(pm-dispatch): clause-② negative boundary + attach-time rule for needs:contract-review - #12897
Conversation
…needs:contract-review Executes points 1, 2 and 4 of the maintainer's 2026-08-28 ruling (adopted whole, live director session): a runtime permission/security behaviour change is NOT clause-② — it is the 安全/权限边界 manual-floor category; needs:contract-review attaches only when a reviewable contract increment exists, and forward pre-marking on queue/blocked cards is retired. Both files sit at zero ratchet headroom; every added line is paid by a same-file cut or pure re-flow of sloppy wraps, proven render-identical (CSS segment-break normalization) outside the two ruled insertions and five enumerated cuts. Cut ledger in the PR body. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016SG9S6V15MqeAgkehDcTwk
os-elon
commented
Aug 28, 2026
Auto-merge armed by the director seat (session The PR body above pledges draft-only + hand-merge; that text was written before the maintainer acted. What changed, in order:
Basis: the approve-gated queue path for governed surfaces (merged as Generated by Claude Code |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Fixes#12887
Governed protocol change — this PR touches
.claude/**and stays DRAFT for the maintainer's hand-merge (Prime Directive 14, 「人工合并即人工审核」). Never ready, never queued, never auto-merge, by any seat.Executes points 1, 2 and 4 of the maintainer's 2026-08-28 ruling (live director session, recorded on the card; adoption verbatim and untranslated):
Points 3 (no new label, no rename) and 5 (stock cleanup) were already executed by the director seat before this dispatch: all 18 pre-marked open carriers stripped with per-card provenance comments — migration state at dispatch time:
label:needs:contract-review is:open= 0. An open carrier of the label is from now on always a real pending review.What the text now says
SKILL.md, 条款② clause): a runtime permission/security behaviour change is NOT clause-② — it is the 安全/权限边界 manual-floor category, whose control is the ruling itself, not the review chain; clause-② is the published contract face only. Evidence note carried in place: two independent seats derived the same wrong reading from the old text (a third seat self-audited the same conflation on the card).SKILL.md, 条款②入队闸门 paragraph):needs:contract-reviewattaches only when a reviewable contract increment EXISTS (draft PR, or a report arriving first); forward pre-marking on queue/blocked cards is retired. The forward clause-② fact lives in the three existing mechanisms — the card's ruling/triage comments, the claim's mandatoryClause-②: yes|nodeclaration, anddispatch-gates --tieroutput.references/contract-review.md, 载体纪律): the same rule at the operational layer, superseding the triage "pre-hang on queue cards" practice; it points at the main file's gate paragraph for the three channels (the reference's own header already declares the main file as the principles home, so the text stays self-contained).Zero-headroom ratchet: net 0 per file, cut ledger
Ratchet verdict lines (
pnpm check:pm-skill-ratchet, run at 04c7536, exit 0):Mechanical proof over the whole payment: for both files, render-normalized OLD text (CSS segment-break transformation: a break between two East Asian wide characters renders as nothing, any other break as one space) plus the two ruled insertions and the five cuts below equals render-normalized NEW text byte-for-byte. So every other visible diff line is pure re-flow of sloppy wraps (orphan lines of 3–46 bytes), moving whitespace only. The literal spaces that appear inside re-flowed lines (e.g. before 才落) are pre-existing renders made visible — the self-concealing re-wrap mechanism documented in the ratchet script's header — not introduced spaces. New lines were wrapped with the ratchet script's own exported
wrapLine(the canonical wrapper the gate verifies).SKILL.md (adds: negative boundary +266 bytes, attach-time rule +292 bytes; paid entirely by re-flow, net 0 at 1005/1005):
references/contract-review.md (adds: the ⛔ 不预挂 bullet, +2 lines / 225 bytes; paid by five same-file cuts, net 0 at 48/48):
needs:contract-review)挂与清两向同此四步」; the reference's clause was a duplicate pointer.Gates (run in the worktree at 04c7536; every exit captured before any pipe)
pnpm check:pm-skill-ratchet— exit 0 (self-test pass); verdict lines quoted above.pnpm check:pm-skill-id-lint— exit 0: "✓ check-skill-id-lint: 23 file(s) clean (pattern /#[0-9]{3,}/g)." — the new lines carry the ruling date, no card ids.pnpm check:skill-frame-sync— exit 0: "✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files" (frame untouched).pnpm check:skill-frame-freshness— exit 0: "✓ check-skill-frame-freshness: the decision frame in this tree is current with origin/main (fetched just now)."pnpm check:pm-governed-prose— exit 0: "✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces (docs/adr/** · .claude/** · skills/** · AGENTS.md · CLAUDE.md) and claim no others."pnpm check:pm-governed-merges— exit 0 (self-test, 206 assertions).pnpm check:doc-authoring— exit 0: "✓ doc authoring guard: 392 files clean — no bare metadata literals."pnpm check:agent-test-spelling— exit 0: "✓ sweep is clean".pnpm --filter @objectstack/lint run check:doc-formula-expressions— exit 0: "✓ check:doc-formula-expressions: 22 record-scoped formula example(s) across 425 files / 1453 TS blocks judged clean" — after building@objectstack/formulaand@objectstack/lint(the first run refused with PREREQUISITE NOT MET, which per the gate's own text is NOT MEASURED, not a finding).node scripts/pm/check-governed-queue-guard.mjs --self-test— exit 0 (113 cases). The full guard is a CI-context gate: it reads the workflow event payload, and a bare local run correctly refuses ("could not read GITHUB_EVENT_PATH" — could-not-look must never exit 0 there). The PR's own CI run is the real judgment for that family.pnpm check:nul-bytes— exit 0: "check-nul-bytes: OK (scanned 7168 text file(s) … no raw ASCII control bytes)."Gate union derived by
node scripts/pm/dispatch-gates.mjswith no paths passed (change set derived from git: 2 paths vs merge base 93a554d): 9 matched families — all run — plus the dispatch-named frame-freshness and nul-bytes.No changeset: internal instruction text under
.claude/skills/**, nothing publishes —skip-changesetlabel applied (this repo's real mechanism).content/docs/releases/untouched. The previously pre-marked cards named in the card's triage self-audit are the director/triage seats' to re-walk under the now-written rule; out of scope here: #12597 (it remains exactly as the director seat left it).Generated by Claude Code
Generated by Claude Code