Skip to content

docs(pm-dispatch): pin the security-object enumeration's method and calibration case - #13108

Merged
os-zhuang merged 4 commits into
mainfrom
claude/issue-12813-enum-method-record
Aug 29, 2026
Merged

docs(pm-dispatch): pin the security-object enumeration's method and calibration case#13108
os-zhuang merged 4 commits into
mainfrom
claude/issue-12813-enum-method-record

Conversation

@os-litant

@os-litantos-litant commented Aug 29, 2026

Copy link
Copy Markdown
Collaborator

Fixes#12813

⚠️REWORK — and it does NOT balance. Residual deficit: 3 lines. Read the ratchet
section first; this PR asks for a ceiling decision, not for a green gate.

The standing security-object platform-object enumeration (triage-seat instruction ⑦)
appends its NUMBERS to the seat post but never its METHOD. The card measured the
consequence: the surface half reproduced, the reader half did not — the recorded watch
item (3 non-declaration read points) could not be re-derived from anything written down.
This PR records the method in prose, in the file that already carries the triage seat's
other standing round duties.

⛔ The seat post itself is untouched — it belongs to another seat.

Session: https://claude.ai/code/session_01MnijPVVDakqK2J335JoJtq (carried in prose because
a body edit downgrades the footer form).

What the rework changed

The first commit funded a 19-line section entirely by re-wrapping 16 paragraphs with
zero content removed
. That is banned, by the ratchet's own row in the PM SKILL.md
(maintainer 2026-08-17, verbatim):

⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以
删减付账;密度优化仅随净减内容的 PR 顺带

Line count stayed flat while content volume rose — exactly the shape the rule forbids. The
whitespace-only / wrapLine-canonical proof the first body offered addressed fidelity,
which was never the objection; the objection is governance.

Three changes since:

  1. All 16 re-wraps reverted. Outside the five cut regions and the new section, this
    file is byte-identical to origin/main — verified by diff, not asserted.
  2. Section compressed 19 → 10 lines, hitting the stated target, while keeping all four
    pinned items, the calibration case, and the load-bearing .claude pathspec exclusion.
  3. Payment is real deletion only, 8 lines, each with its surviving home named.

The section as landed (10 lines)

Placeholders are spelled as words here because GitHub's body sanitizer eats short
angle-bracket fragments, including inside backticks: read BASELINE_REF, TWO_PLUGINS,
KEY and DECLARING_OBJECT_FILE for the file's 基线ref, 两插件, and
声明该列的 *.object.ts.

## security-object 无判决枚举(座位贴常设 ⑦)的方法与校准

  • 表面半边(⛔ 不比总数):git diff BASELINE_REF origin/main -- 'TWO_PLUGINS/src/objects/*.object.ts'
    grep -E "^[+-] [a-z_][a-z0-9_]*: Field\.";零命中 = 成员级同一,必记基线 ref(2026-08-26 b000ab59)。
  • 读者半边:git grep -I -n -w "KEY" -- . ':(exclude)DECLARING_OBJECT_FILE' ':(exclude).claude'(⛔
    缺后者会命中本节),逐命中行计一次:① *.generated.ts 不是读者;② packages/spec 契约声
    读点;③ 裸字面量 key: 拼写
  • 正对照恒先跑:sys_share_link.email_allowlist = 3(2026-08-26 记;漏 ① 得 7,多减 ② 得 2)——
    跑不出 3 即仪器坏了,⛔ 记下任何零之前停;⛔ 无对照的零记「没读到」不记 0(name 这类
    列名到处匹配,未校准的仪器平凡地回 0)。

All four requested items are there: ① member-level diff, not two totals agreeing (now
carried in the bullet's own label, which is what let it wrap in two lines); ② the three
classification answers, stated as THE rule; ③ the watch item as the calibration case, with
both wrong answers compressed into the parenthetical; ④ a zero without a positive control
is 「没读到」, not 0.

The .claude exclusion is not decoration: this file now names the calibration key, so
without it the next run's positive control reads 4 and this PR would have manufactured the
exact failure it repairs.

Cut ledger — real deletion, surviving home named per cut

atbefore → afterdeletedsurviving home
L691 → 0the seat-post back-pointer lineseat-post-protocol.md L32-33 states the same relationship from its own side, verbatim
L93-997 → 6the re-quoted 2026-08-20 ruling + the director-seat parentheticalSKILL.md L352-353 (same quote, same date, verbatim); SKILL.md L944 (director seat = manual summons, contract-review chain). The section heading already carries the date.
L133-1342 → 1the restated mechanical flagscripts/pm/check-half-states.mjs header — the H-numbered flag list this very line already declares authoritative
L224-2285 → 3the three re-quoted partition NAMESSKILL.md L633-634 quotes all three verbatim and delegates only the per-partition dev obligations here (「细则见 runbook」), which are kept
L269-2713 → 0the 已发布包/changeset conditional clause (whole bullet)review-checklist.md L21-24 carries the rationale verbatim; os-dev.md rule 4 + DoD carry the obligation. SKILL.md's conditional-clause index (L662-664) names three conditional clauses and not this one, so nothing points here.

Total recovered: 8 lines.

Every cut was re-derived against the post-13106 tree. PR 13106's three hunks on this
file cover roughly L105-119, L242-248 and L259-268 (with context); none of my five regions
falls inside them, so no cut 13106 already spends is claimed here and the two diffs should
merge without touching each other. The two cuts abandoned for that reason are worth naming:
the 云卡 item-4 subscribe_pr_activity duplicate (2 lines) is blocked because SKILL.md
L678 pins the count as 「云卡四课全文见 runbook」, so removing item 4 would need an edit to
the serially-occupied SKILL.md; and the 落卡分析模板 pointer bullet (2 lines) sits inside
13106's hunk context.

Ratchet — the deficit, stated plainly

fileceilingbeforeafterbalance
.claude/skills/pm-dispatch/references/dispatch-runbook.md274274277section +11 (10 + separator) · cuts −8 · deficit 3

check:pm-skill-ratchet is RED by construction. Its own verdict line:

✗ check-skill-line-ratchet: .claude/skills/pm-dispatch/references/dispatch-runbook.md is 277
lines; the ratchet ceiling is 274. ... Raising a ceiling requires a maintainer ruling
quoted in the PR.

3 is a measured floor, not a stopping point picked for convenience, and the measurement
is reproducible: the two recipes are single unbreakable code atoms of 75 and 46 bytes, so
bullet 1 cannot drop below 2 lines while carrying both (checked down to a 176-byte stripped
variant), and bullets 2 and 3 already land on their own minimum line counts at 286 and 290
bytes. Below 10 lines the only things left to remove are a whole recipe, or the
parentheticals that say WHY each rule is what it is — and a rule recorded without its
reasoning being re-derived wrong is the exact failure this card documents.

Offered as the evidence for a ceiling decision (274 → the measured need, which a maintainer
may wish to size to cover PR 13098's bullet in the same ruling).

Measured, not asserted: the set of over-120-byte lines went 18 → 17, with 0 introduced.

Evidence: both recorded recipes were run, as recorded

Reader half, the recipe exactly as landed:

$ git grep -I -n -w "email_allowlist" -- . \
':(exclude)packages/plugins/plugin-sharing/src/objects/sys-share-link.object.ts' \
':(exclude).claude'
packages/plugins/plugin-sharing/src/share-link-service.ts:504: email_allowlist:
packages/plugins/plugin-sharing/src/share-link-service.ts:599: const allow = row.email_allowlist ?? [];
packages/plugins/plugin-sharing/src/translations/en.objects.generated.ts:242: email_allowlist: {
packages/plugins/plugin-sharing/src/translations/es-ES.objects.generated.ts:242: email_allowlist: {
packages/plugins/plugin-sharing/src/translations/ja-JP.objects.generated.ts:242: email_allowlist: {
packages/plugins/plugin-sharing/src/translations/zh-CN.objects.generated.ts:242: email_allowlist: {
packages/spec/src/contracts/share-link-service.ts:61: email_allowlist?: string[] | null;
7 hits · after rule ① (drop the 4 *.generated.ts) = 3 the recorded value
· if ② were also dropped = 2 the card's reading

⇒ The positive control passes under the pinned rules; the card's two candidate numbers are
exactly the ① -omitted and ② -over-applied answers.

Surface half, the recipe exactly as landed:

$ git diff b000ab59 origin/main -- \
'packages/plugins/plugin-security/src/objects/*.object.ts' \
'packages/plugins/plugin-sharing/src/objects/*.object.ts' \
| grep -E "^[+-] [a-z_][a-z0-9_]*: Field\."
(no output — 0 column-declaration lines added or removed)
$ git diff --stat b000ab59 origin/main -- (same pathspecs)
.../src/objects/sys-permission-set.object.ts | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)

⇒ One object file changed, and not in its column declarations: member-level identity,
proven by diff. b000ab59 resolves (docs(glossary): …, 2026-08-26).

Gates

Union re-derived with node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack
and re-run at git rev-parse --short HEAD = 55f24d1, each redirected to a file
before capturing $?. Verdicts are the gates' own printed lines.

gateexitits own verdict line
check:pm-skill-ratchet1✗ … dispatch-runbook.md is 277 lines; the ratchet ceiling is 274. — the deficit above
check:pm-skill-id-lint0✓ check-skill-id-lint: 23 file(s) clean (pattern /#[0-9]{3,}/g).
check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
check:doc-authoring0✓ doc authoring guard: 392 files clean — no bare metadata literals.
check:agent-test-spelling0✓ check-agent-test-spelling: 0 violations — 398 file(s) · 4575 bare -- token(s) …
check:pm-governed-merges0live: the real generator declared 9 output(s) and certified this tree
check:doc-formula-expressions0✓ check:doc-formula-expressions: 22 record-scoped formula example(s) across 425 files / 1453 TS blocks judged clean
check:nul-bytes0check-nul-bytes: OK (scanned 7281 text file(s) … no raw ASCII control bytes).

check:doc-formula-expressions first answered PREREQUISITE NOT MET (@objectstack/formula
and @objectstack/lint unbuilt in the recreated worktree). That is not a red gate — nothing
was measured. Both were built through the shared verify lock
(scripts/pm/os-verify-lock.sh, VERDICT command-exit 0), after which it ran green.

check:pm-skill-ratchet is the one true red, and it is the deliverable of this rework
rather than a defect to hide.

Changeset

None. The diff is .claude/ only — no published package, nothing user-visible.
skip-changeset is on the PR (read-union-write plus a compare read-back at PR-open).

Not claimed

  • ⛔ Not claimed that the 2026-08-26 reading was wrong — the evidence shows it reproduces
    under the rules now written down; what was missing was the writing down.
  • ⛔ Not claimed that any zero-reader key exists or does not.
  • ⛔ Not claimed that this PR balances. It does not, by 3 lines, and says so.

…alibration case
The standing security-object platform-object enumeration appends its NUMBERS to
the seat post but never its METHOD, so the duty does not reproduce across seats:
the recorded watch item could not be re-derived from anything written down.
Record, in the triage-seat runbook where the other standing round duties live:
- the surface half as a member-level diff against the recorded baseline ref
(column-declaration lines), which is strictly stronger than comparing two
totals and cheaper;
- the reader-half classification rules the count depends on: generated bundles
are not readers, a packages/spec contract declaration IS a read point, and the
bare key: literal spelling counts per matching line;
- the watch item as the CALIBRATION case, so a run that cannot reproduce it
knows its instrument is wrong BEFORE it records a zero;
- a zero without a positive control is recorded as NOT MEASURED, never as 0.
Ratchet net-0: the 19 added lines are paid for by canonically re-wrapping 16
paragraphs in the same file (whitespace only, zero content removed, no new
over-120-byte line; three pre-existing over-length lines are resolved).
The recorded recipe excludes the .claude instruction surface, so this file
naming the calibration key does not perturb the next run's count.
… not re-wrapping
REWORK. The previous commit funded a 19-line section entirely by re-wrapping 16
paragraphs with zero content removed. That is banned: SKILL.md's ratchet row
(maintainer 2026-08-17) reads 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是
内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」.
Line count stayed flat while content volume rose, which is exactly the shape the
rule forbids.
- Every one of the 16 re-wraps is reverted: outside the five cut regions and the
new section, this file is byte-identical to origin/main.
- The section is compressed 19 -> 11 lines (three bullets, each at its own
120-byte minimum) while keeping all four pinned items, the calibration case
and the load-bearing .claude pathspec exclusion.
- Payment is now REAL DELETION with a surviving home named per cut (8 lines):
the seat-post back-pointer (home: seat-post-protocol.md); the re-quoted
2026-08-20 ruling plus the director-seat parenthetical (home: SKILL.md, same
quote and date); the restated mechanical flag (home: the half-states gate
script header this line already declares authoritative); the re-quoted three
partition names (home: SKILL.md, which delegates only the per-partition dev
obligations here); and the 已发布包/changeset conditional clause, whose
rationale is verbatim in review-checklist.md and whose obligation is in
os-dev.md.
Cuts were re-derived against the post-13106 tree and avoid its hunks, so none of
the cuts it already spends are claimed here.
RESIDUAL DEFICIT: 4 lines (274 -> 278). check:pm-skill-ratchet is RED by
construction and this number is the evidence for the ceiling decision; per the
rework instruction no further re-wrapping was used to close it.
…rget
Bullet 1's 「⛔ 不比总数」 point moves into its label, which lets the whole
bullet wrap in 2 lines instead of 3 without dropping the baseline-ref rule or
its 2026-08-26 provenance. Section 11 -> 10 lines, residual deficit 4 -> 3.
10 is the structural floor, not a stopping point chosen for convenience: the
two recipes are single unbreakable code atoms of 75 and 46 bytes, so bullet 1
cannot go below 2 lines while carrying both, and bullets 2 and 3 are already at
their own minimum line counts. Going lower means deleting a recipe or the
parentheticals that say why each rule is what it is.
RESIDUAL DEFICIT: 3 lines (274 -> 277).
Maintainer ruling 2026-08-29 (verbatim: 12813 tong yi, option A): one ruling covering the
merged end-state of the three stacked PRs on this file. Conflict resolved keeping both landed
intents; ceiling raised to the measured 278 with the ruling quoted in the gate's own comment.
Co-Authored-By: Claude <noreply@anthropic.com>
@os-litantClaude

Copy link
Copy Markdown
CollaboratorAuthor

天花板裁决落地(PM 亲笔,新 head fb4076155)。维护者裁决引用(棘轮抬限路径):2026-08-29 PM chat,原话「12813 同意」= 9️⃣ 选项 A —— references/dispatch-runbook.md 行天花板 274 → 278,一次裁定覆盖本文件三件叠置 PR 的合并终态。
执行内容:① 并 origin/main,冲突解法保双方落地意图(#13108 的压缩出处指针 + 已落地 #13098 的枚举完整性句,孤行并笔后文件恰 278 行);② check-skill-line-ratchet.mjs CEILINGS 274→278,裁决原话入门注释;③ 门全绿:ratchet「278 lines (ceiling 278)」+ self-test 111 过、id-lint 23 净、remedy-authority 165 扫过、derive 出的 17 族 union 全 0(两道先报 PREREQUISITE NOT MET 属未测,装依赖复跑绿)。
⚠️ 推送钉失了原批准——@os-zhuangfb4076155 上再批一次即自动入队,这是本班最后一件。


Generated by Claude Code

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-litant@os-zhuang@claude