docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals - #14125

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale
Sep 1, 2026
Merged

docs(agents): PD #14 — a generator-certified regeneration clears the queue with zero approvals#14125
os-zhuang merged 1 commit into
mainfrom
claude/issue-14067-pd14-regen-approval-stale

Conversation

@claude

@claudeclaudeBot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Fixes#14067

Prime Directive #14 told every seat to pre-request a pinned maintainer approval before
queueing even a pure regeneration, and justified it with a parenthetical that is no longer
true on main: the queue guard's merge_group leg now installs the generator toolchain,
so the byte-equality lift does evaluate at queue time. Left as written, the directive
kept sending seats to the maintainer for the exact approval the 2026-09-01 ruling removed.

Maintainer ruling this implements (2026-09-01, verbatim and untranslated):

纯生成的指针行(spec 源变更后再生成的 references/_index.md) 不需要我审核吧

The sentence, before and after

Before (AGENTS.md L304-306 at merge base 3795c5f5d, verbatim):

Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29).

After (AGENTS.md L304-306 at 244e3ae4f, verbatim):

Hand-authored governed content needs that approval; a PR whose only governed paths are register rows the queue leg regenerates byte-exact clears with zero approvals (2026-09-01) — an uncertified recompute, drift or a hand-authored sibling keeps it governed.

Nothing in it was invented. The criteria are the queue guard's own pinned case names —
with-the-toolchain-installed-a-PURE-REGENERATION-merge-group-CLEARS-with-zero-approvals-and-zero-api-calls,
plus the three shapes that still refuse: a-recompute-that-does-not-certify-still-REFUSES-the-same-merge-group-fail-closed
(no-toolchain and drift) and a-hand-authored-skills-file-beside-a-certified-regeneration-is-still-REFUSED.

The two facts that did not change are both still there, untouched by this diff:
a governed diff still lands only on an authorized approval pinned to the current head
(L301-304, GOVERNED_APPROVERS, commit_id = that sha), and no agent seat submits that
approval under any account (L306-308).

Premise verified on today's origin/main

Both halves checked first-hand at merge base 3795c5f5d, before writing:

  • AGENTS.md L304-306 still carried the stale parenthetical (quoted above, byte-exact).
  • .github/workflows/governed-surface-guard.yml now installs: Setup pnpm +
    pnpm install --frozen-lockfile, every toolchain step continue-on-error, and its own
    comment states the intent — "Both legs install." The guard header's ⭐ block says the same
    ("THE JOB INSTALLS DEPENDENCIES"), and the --self-test pins the wiring.
  • PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's line citation from the card (L304-305) is still accurate; the sentence had not
    materially moved since the card was written, so no re-scoping was needed.

Net zero, measured before writing

The ratchet pins AGENTS.md at 1162 with headroom 0, so the replacement had to reflow
inside the count. Measured with the gate's own wrapLine at MAX_LINE_BYTES = 120 before
any edit:

measurementvalue
PD #14 landing paragraph L296-312, lossless rewrap17 lines → 17 lines (headroom 0)
reflow region L304-312 (the tail from the edited sentence)9 lines → 9 lines (headroom 0)
replaced fragment194 B → 259 B (+65 B)
widest resulting line120 B (budget 120 B)
AGENTS.md total1162 → 1162 lines

The +65 B is absorbed entirely by the slack in the region's last line, which was 57 B.
The ceiling is not byte arithmetic — greedy wrapping breaks on words, so it was found by
measuring real candidate strings: a 257 B candidate spilled to a 10th line while the chosen
259 B one fits. Candidates at +67 B and above spill; the chosen wording is at the measured
maximum that keeps the count.

Gate verdict line, quoted:

✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
✓ check-skill-line-ratchet: AGENTS.md: widest table row is 1081 bytes (pin 1081; headroom 0).

Companion ledger comment: KEPT as history, with a dated supersession marker

scripts/pm/check-skill-line-ratchet.mjs L402-414 is the ledger entry for the 1158 → 1162
bump, and its parenthetical carried the same "installs no dependencies" phrasing.

Decision: keep the history, mark it superseded — do not update it to today's facts.
Rationale: that entry exists to record why +4 lines was priced, and the rider it prices
cost +2 precisely because the queue leg then installed nothing. Rewriting it to describe
today's mechanism would erase the reason the bump was justified, which is the one thing the
ledger is for. But a bare present-tense claim is exactly what this card is about, so leaving
it unmarked invites the next reader to take it as live. The parenthetical is now:

(the queue leg then installed nothing, so the byte-equality lift never evaluated; SUPERSEDED 2026-09-01/#14067)

Also net zero: 97 → 111 chars, absorbed by reflowing the same 7 comment lines (L405-411,
7 → 7) at the block's existing 82-column width (L402-403 were already 82). That script is
not itself ratcheted; net zero here is the correction carve-out's discipline, not a gate.

Sibling coherence

A queued sibling card (#14059) will add a machine-readable enqueue-precondition line to the
pm-dispatch landing checklist. The new wording therefore states both halves in one breath
— hand-authored governed content ⇒ pinned approval, generator-certified-only ⇒ zero approvals
— so a seat reading the two texts side by side cannot construct a conflict between "approval
must precede enqueue" and "this class needs none". Noted here deliberately without a closing
keyword; that card stays open on its own.

Gates

Head 244e3ae4f. Derived union re-run after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands
(exit 0; change set derived by the tool itself from the merge base 3795c5f5d, 2 paths).
21 commands, exit codes captured before any pipe:

gateexit
the 20 other derived commands (check:pm-governed-prose, check:pm-skill-ratchet, check:pm-governed-merges, check:pm-dispatch-gates, check:required-contexts, check:watch-hint-literal, check:entry-guard, check:parse-guard, check:docs-audit-scope, check:cli-command-ids, check:bash32-floor, check:agent-test-spelling, check:cross-package-test-inputs, check:pm-skill-id-lint, check:pnpm-filter-targets, check-ci-filter-parity, check-cross-package-test-inputs, check-required-contexts, check-shard-attestation, bare-root-worklist --self-test)0
node scripts/check-test-completeness.mjs3 — NOT MEASURED

check-test-completeness exit 3 is its documented PREREQUISITE NOT MET branch: it grades a
saved turbo run test log and the derived family names it with no argument. Its own text says
"⛔ It is not a red, and there is nothing here to fix." CI passes it a log; that path is
unreachable locally.

Named on the card, plus the ones this diff drags in, run separately (exit codes before pipes):

gateexitverdict line
node scripts/pm/check-skill-line-ratchet.mjs0✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0).
node scripts/pm/check-skill-line-ratchet.mjs --self-test0✓ check-skill-line-ratchet self-test: 111 cases pass.
pnpm check:pm-governed-prose0✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces … and claim no others.
node scripts/pm/check-governed-queue-guard.mjs --self-test0✓ check-governed-queue-guard self-test: 129 cases pass (…)
pnpm check:skill-frame-sync0✓ check-skill-frame-sync: 4 copies of the decision frame are structurally isomorphic across 3 files
pnpm check:nul-bytes0check-nul-bytes: OK (scanned 7715 text file(s) … no raw ASCII control bytes).
pnpm check:ratchet-remedy-authority0
node scripts/check-published-list-mirrors.mjs0OK: 1 published list mirror(s) match their constants line for line.
node scripts/check-skills-token-ratchet.mjs0✓ check-skills-token-ratchet: 38 authored bundle file(s) within their ceilings

The edited script's own test suite is its --self-test (there is no separate vitest file
naming it); it is in the table above at 111 cases. Its three in-repo importers
(check-published-list-mirrors, check-skills-token-ratchet, check:pm-dispatch-gates) were
run as well.

Changeset

Publishes nothing from any package — the diff is AGENTS.md plus a comment in
scripts/pm/. Carrying skip-changeset, applied additively and read back.

Landing

AGENTS.md is a governed surface, so this is draft-only: no merge, no queue, no
auto-merge, no ready-flip from this seat. Landing is the maintainer's, by hand, or through the
queue on an authorized approval pinned to head 244e3ae4f.

Generated by Claude Code


Generated by Claude Code

…queue with zero approvals
The queue guard's `merge_group` leg now installs the generator toolchain, so
the register's `verify` rows can actually recompute at queue time. PD #14's
parenthetical still told every seat the opposite ("the queue-time leg installs
no dependencies and never evaluates the byte-equality lift"), which reads as an
instruction to pre-request a pinned maintainer approval for a pure regeneration
that needs none.
Reflowed at net zero (1162/1162 lines, every line within the 120-byte budget).
Both unchanged facts stay: a hand-authored governed diff still needs an
authorized approval pinned to the current head, and no agent seat submits it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Msg17tAHJ3jVTYFgHydCm2
@claudeclaudeBot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 1, 2026
@claude
claudeBot requested review from hotlong and os-zhuangSeptember 1, 2026 06:08
@github-actionsgithub-actionsBot added size/s documentation Improvements or additions to documentation labels Sep 1, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review September 1, 2026 06:35
@os-zhuang
os-zhuang added this pull request to the merge queueSep 1, 2026
Merged via the queue into main with commit 0566dc6Sep 1, 2026
34 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-14067-pd14-regen-approval-stale branch September 1, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants

@os-zhuang@claude