You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Governed surface (.claude/**) — this PR stays DRAFT. Not flipped ready, not enqueued, no auto-merge armed, no review submitted. Landing is the maintainer's, by hand.
The defect, re-measured on current main
The reader half of standing duty ⑦ counts readers with git grep -I -n -w on the bare column name, and its only calibration case is sys_share_link.email_allowlist. I re-ran the pinned method over the whole population at base 889ec5b42:
Calibration control still holds: 7 raw hit lines − 4 *.generated.ts (rule ①) = 3. The instrument is calibrated as documented.
And that is the whole problem. Measured raw hit lines across all 121 keys:
statistic
raw hit lines
calibration case email_allowlist
7
population minimum
7 (the calibration case is the minimum)
median key
1366
maximum (name, 5419 files)
75985
The pinned control is not merely an easy key — it is the single easiest key in its own population. A calibration that passes there authorizes nothing about managed_by (891 lines / 154 files) or expires_at. The duty's no zero-reader keys output was therefore a false green over keys the instrument cannot discriminate on at all.
⭐ One in-passage correction the measurement forced, named here because an unnamed drive-by fix is unreviewable sprawl: the old text's own parenthetical read `name` 这类列名到处匹配,未校准的仪器平凡地回 0 — it names exactly the right key and states the wrong failure direction. name does not trivially return 0; it returns 75985. A generic name floods the count and can never return zero, which is precisely why the duty is blind to its own subject. Corrected in place, same passage, same defect class, no new file surface.
The repair
The honest applicability-domain route, with a derived criterion rather than a hand-listed key set:
Applicability domain. Only a key whose every hit line is adjudicated by rules ①②③ produces a reading. Everything else is recorded NOT MEASURED — explicitly neither0nor "has readers". The criterion is the method's own unit of work (a hand-read hit), so it re-derives itself per run and cannot rot: a key that becomes generic drops out automatically, one that becomes distinctive enters.
A negative control, run in the same round.managed_by must read as unadjudicable. This is the half the method never had: the positive control on the most distinctive key cannot fail for the reason the duty exists to fear, whereas a generic-name control that ever came back with a handful of hits would immediately expose a broken or over-excluding probe.
The output is always two halves — 已测 N (零读者 Z) · 未测 121-N — and 无零读者键 is banned outright, with the standing correction that ⑦'s historical greens are not evidence for that conclusion.
The family's transferable sentence lands here verbatim, in its extended form.
Why the two forbidden routes were not taken
⛔ More exclude paths. Adds none. The diff touches no path filter; the probe is byte-identical. Suppressing noise would just relocate the calibration to the next easy key, which is the same defect one step along.
⛔ Shrink 121 to 17 and declare 100%. No sample is narrowed and no coverage percentage is claimed. The reading is required to carry the unmeasured remainder in the same breath — that is what "输出恒两半" and the NOT MEASURED rule enforce. There is deliberately no fixed key list and no magic threshold constant in the text.
Route note (declaration-vs-use): I judged the strong form out of reach here and say so rather than fake it. Resolving "is this managed_by about this column or a homonym" needs real symbol resolution, not grep; nothing runnable per-seat in a few minutes does it, and a text pretending otherwise would be a second uncalibrated instrument. The domain statement is the deliverable the grading offers as the alternative, and it is the one that stays honest under its own failure.
Line budget
Word-compression inside the touched passage only. ⛔ No re-wrap-as-funding.
item
before
after
delta
dispatch-runbook.md lines
271
278
+7
ratchet ceiling
278
278
0
headroom
7
0
−7
widest line (bytes)
120
120
0
files changed
—
1
+10 / −3
Exactly the funded 7, ceiling untouched, no line over the file's 120-byte convention.
Gate verdicts
Derived from the actual diff with node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack (7 families). Union re-run at final head 0959367f1 on a clean tree; every exit captured before any pipe.
✓ check-agent-test-spelling: 0 violations — 413 file(s) · 5064 bare `--` token(s) · 1284 launcher-rooted run(s)
✓ doc authoring guard: 48 published skill files clean — no internal issue-id references.
✓ check:doc-formula-expressions: 22 record-scoped formula example(s) across 426 files / 1451 TS blocks judged clean
✓ check-governed-merges --self-test: 230 assertions
✓ check-skill-id-lint: 23 file(s) clean (pattern /#[0-9]{3,}/g).
✓ check-skill-line-ratchet: .claude/skills/pm-dispatch/references/dispatch-runbook.md is 278 lines (ceiling 278; headroom 0).
✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
check:doc-formula-expressions first returned PREREQUISITE NOT MET (@objectstack/formula, then @objectstack/lint, not built). Per the gate's own text — "Nothing was measured … It is NOT a finding" — that was read as NOT MEASURED, not as red; both packages were built and the gate then produced the green above.
Reverse verification
(a) Ratchet ablation past the real headroom. Prediction stated before running: RED. Fix committed first; mutation proven on disk (marker count 1, 278 → 279 lines, blob 7b18c579 → 31b25275); absolute paths in an EXIT INT TERM trap.
RATCHET EXIT UNDER MUTATION = 1
✗ check-skill-line-ratchet: …dispatch-runbook.md is 279 lines; the ratchet ceiling is 278.
Restore proven, not assumed — git checkout HEAD -- (never bare), then blob back to 7b18c579ec2bcaa28284d96d910107873932c7a6, git diff HEAD empty, marker count 0. This also confirms the headroom of 7 was a live ceiling rather than a phantom check.
(b) Anchored-grep acceptance, evaluated against both refs so it is reproducible (git show REF:path), CJK-joined so the wrapped verbatim sentence reassembles:
anchor
889ec5b42 (before)
0959367f1 (after)
transferable sentence (verbatim)
0
1
NOT MEASURED rule
0
1
applicability domain (适用域)
0
1
negative control (负对照)
0
1
ban on 无零读者键
0
1
file lines
271
278
Scope
One file, one passage. No changeset — instruction-surface only, no package publishes anything; skip-changeset applied. The surface half of the method (the canonical-diff leg that PR #13108 landed, measured good) is deliberately untouched. Not a duplicate of #12813: that card recorded the method as unwritten; this one records the written method's calibration as unable to authorize readings on generic names.
…ty domain
The pinned reader-count method is calibrated only on sys_share_link.email_allowlist,
which measures as the population MINIMUM (7 hit lines of 121 keys; median 1366, max
75985). A calibration that passes on the most distinctive key in its population cannot
authorize readings on generic column names, so the duty's 'no zero-reader keys' output
was a false green over 104 unmeasurable keys.
Adds an applicability-domain statement: only keys whose every hit line is adjudicated
produce a reading; all others are recorded NOT MEASURED (neither 0 nor 'has readers').
Adds a generic-name negative control that must read as unadjudicable, so the calibration
can now fail for the reason the duty exists to fear. Output is always two halves.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EXxTW8mvPBhoHxmyPZ63de
Standing down — superseded by maintainer ruling; closing this PR unmerged.
Maintainer ruling (2026-08-31, chat, verbatim): 「13580 B(荐」 — option B of the value review offered on this PR: retire duty ⑦'s reader half instead of documenting its limits. The maintainer had already disarmed auto-merge here personally; the ruling settles the direction.
The reader half of duty ⑦ (the 读者半边 and 正对照 bullets in dispatch-runbook.md) is RETIRED by a net-negative follow-up PR on a fresh branch, quoting the ruling. The surface half (canonical member-level diff, measured good) stays untouched.
My contract-review ACCEPT (comment on the source card, 02:23Z) is withdrawn as a landing verdict — its diff verification and budget arithmetic stand as evidence, but the value gate now in force supersedes it.
Branch claude/issue-13304-reader-count-domain is preserved as evidence (the measurements live in its history). No further pushes here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate
3 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes#13304
Governed surface (
.claude/**) — this PR stays DRAFT. Not flipped ready, not enqueued, no auto-merge armed, no review submitted. Landing is the maintainer's, by hand.The defect, re-measured on current
mainThe reader half of standing duty ⑦ counts readers with
git grep -I -n -won the bare column name, and its only calibration case issys_share_link.email_allowlist. I re-ran the pinned method over the whole population at base889ec5b42:*.generated.ts(rule ①) = 3. The instrument is calibrated as documented.email_allowlistname, 5419 files)The pinned control is not merely an easy key — it is the single easiest key in its own population. A calibration that passes there authorizes nothing about
managed_by(891 lines / 154 files) orexpires_at. The duty'sno zero-reader keysoutput was therefore a false green over keys the instrument cannot discriminate on at all.⭐ One in-passage correction the measurement forced, named here because an unnamed drive-by fix is unreviewable sprawl: the old text's own parenthetical read
`name` 这类列名到处匹配,未校准的仪器平凡地回 0— it names exactly the right key and states the wrong failure direction.namedoes not trivially return 0; it returns 75985. A generic name floods the count and can never return zero, which is precisely why the duty is blind to its own subject. Corrected in place, same passage, same defect class, no new file surface.The repair
The honest applicability-domain route, with a derived criterion rather than a hand-listed key set:
0nor "has readers". The criterion is the method's own unit of work (a hand-read hit), so it re-derives itself per run and cannot rot: a key that becomes generic drops out automatically, one that becomes distinctive enters.managed_bymust read as unadjudicable. This is the half the method never had: the positive control on the most distinctive key cannot fail for the reason the duty exists to fear, whereas a generic-name control that ever came back with a handful of hits would immediately expose a broken or over-excluding probe.已测 N (零读者 Z) · 未测 121-N— and无零读者键is banned outright, with the standing correction that ⑦'s historical greens are not evidence for that conclusion.Why the two forbidden routes were not taken
NOT MEASUREDrule enforce. There is deliberately no fixed key list and no magic threshold constant in the text.Route note (declaration-vs-use): I judged the strong form out of reach here and say so rather than fake it. Resolving "is this
managed_byabout this column or a homonym" needs real symbol resolution, not grep; nothing runnable per-seat in a few minutes does it, and a text pretending otherwise would be a second uncalibrated instrument. The domain statement is the deliverable the grading offers as the alternative, and it is the one that stays honest under its own failure.Line budget
Word-compression inside the touched passage only. ⛔ No re-wrap-as-funding.
dispatch-runbook.mdlinesExactly the funded 7, ceiling untouched, no line over the file's 120-byte convention.
Gate verdicts
Derived from the actual diff with
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack(7 families). Union re-run at final head0959367f1on a clean tree; every exit captured before any pipe.check:doc-formula-expressionsfirst returnedPREREQUISITE NOT MET(@objectstack/formula, then@objectstack/lint, not built). Per the gate's own text — "Nothing was measured … It is NOT a finding" — that was read as NOT MEASURED, not as red; both packages were built and the gate then produced the green above.Reverse verification
(a) Ratchet ablation past the real headroom. Prediction stated before running: RED. Fix committed first; mutation proven on disk (marker count 1, 278 → 279 lines, blob
7b18c579→31b25275); absolute paths in anEXIT INT TERMtrap.Restore proven, not assumed —
git checkout HEAD --(never bare), then blob back to7b18c579ec2bcaa28284d96d910107873932c7a6,git diff HEADempty, marker count 0. This also confirms the headroom of 7 was a live ceiling rather than a phantom check.(b) Anchored-grep acceptance, evaluated against both refs so it is reproducible (
git show REF:path), CJK-joined so the wrapped verbatim sentence reassembles:889ec5b42(before)0959367f1(after)NOT MEASUREDrule适用域)负对照)无零读者键Scope
One file, one passage. No changeset — instruction-surface only, no package publishes anything;
skip-changesetapplied. The surface half of the method (the canonical-diff leg that PR #13108 landed, measured good) is deliberately untouched. Not a duplicate of #12813: that card recorded the method as unwritten; this one records the written method's calibration as unable to authorize readings on generic names.Generated by Claude Code