agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility
Sep 2, 2026
Merged

agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract#14229
os-zhuang merged 3 commits into
mainfrom
claude/issue-12800-osdev-contract-visibility

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Fixes#12800
Fixes#13116

One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards: .claude/agents/os-dev.md only. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).

What changed

Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.

Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.

Rulings carried (verbatim, untranslated)

  • Maintainer 2026-08-17: 「⛔ re-wrap(折行合并)不得用作筹行 —— 棘轮治理的是内容体量,行数只是机读代理,新增以删减付账;密度优化仅随净减内容的 PR 顺带」
  • Maintainer 2026-08-29: 「筹行(为内容购买行数)⛔ vs 独立密度修复(无内容购买)允许」
  • Triage convergence (2026-08-31 re-grade, identical on both cards): 「⛔ 不要分两次改同一个受管文件 —— 那是两次人工合并、两次筹行」·「要往 dev 契约里加一句话,必须先从它里面删掉等量内容。」·「⛔ 抬 pin 是人工地板(门禁削弱含抬 ratchet ceiling)⇒ 删不出来就回分诊,由维护者裁。」·「⛔ .claude/**受管面 ⇒ 人工合并,PR 不进自动队列。」

Must-answer 1 — the deleted lines, and why no third same-shape card

All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).

  1. Model-pin comment, 6 lines to 2. The resolution order, the batched-death incident and both traps live fuller and verbatim in the header of scripts/check-agent-model-declared.mjs — the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.
  2. Stash mechanism and replacement spellings, 3 lines to 1. They live verbatim in CLAUDE.md — which the harness injects into every session's context, a mechanical read, not a voluntary one — and in AGENTS.md, the binding first read named by os-dev.md's own preamble. The operative ban (never git stash) stays in os-dev.md.
  3. Footer measurement detail, 4 lines to 2. The 2026-08-26 three-write read-back measurement lives verbatim (plus the comment-append half os-dev.md never carried) in AGENTS.md's attribution-footer clause — the single home os-dev.md's own sanitizer section already declares (「一条规则一个家」). The operative conclusions stay in os-dev.md: session form is create-only; durable attribution goes in prose or a comment; no re-append loop.

None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).

Must-answer 2 — no rules moved to a new file

No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".

Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees

The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point; check:* gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.

Script-side precondition, measured (triage had recorded it NOT MEASURED)

The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep: scripts/pm/os-verify-lock.sh prints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.

Line budget, measured with the gate itself

  • origin/main before: 469/469, headroom 0 — the re-grade's 466 figure was stale; measured with check:pm-skill-ratchet, not recalled.
  • This PR's head (b5caded): gate verdicts ".claude/agents/os-dev.md is 469 lines (ceiling 469; headroom 0)" and "widest table row is 0 bytes (pin 0; headroom 0)". Net 0 lines; whole file 469 before, 469 after; scripts/pm/check-skill-line-ratchet.mjs is not in the diff.

Gates — run at b5caded, after the final commit

Union derived by node scripts/pm/dispatch-gates.mjs with no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:

  • check:pm-skill-ratchet — "469 lines (ceiling 469; headroom 0)" · "widest table row is 0 bytes (pin 0; headroom 0)"
  • check:pm-skill-id-lint — "23 file(s) clean (pattern …)"
  • check:skill-frame-sync — "4 copies of the decision frame are structurally isomorphic across 3 files"
  • check:agent-model-declared — "1 agent definition(s) under .claude/agents/ all declare a model"
  • check:agent-test-spelling — "0 violations — 429 file(s) … 9 separator(s) JUDGED"
  • check:nul-bytes — green (self-test 75 assertions)
  • check:doc-authoring — green (16 batteries, 198 cases)
  • check:pm-governed-merges — green (self-test 243 assertions)
  • check:doc-formula-expressions — green after building @objectstack/formula and @objectstack/lint through the shared verify lock; the first two attempts exited 3 PREREQUISITE NOT MET and are recorded as not-measured runs, not failures
  • governed-queue-guard — self-test green (129 cases); the live leg reads a CI event payload and is NOT MEASURED locally by design

Governed surface

.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence. skip-changeset applies (diff is .claude/** only; nothing publishes).

Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).

Generated by Claude Code


Generated by Claude Code

…antee list
Rule 1's entry-point list named four guarantees and no non-guarantee, one
line above rule 6's wall-clock absolute — so every reader completed the
list into exclusivity the lock never promised. Add the missing clause: the
lock does NOT guarantee an idle machine; it only excludes work routed
through this entry point, and check:* gate runs, installs and dev servers
never take that path, so wall-clock absolutes measured under a hold are
shared-box readings. The script itself has stated this boundary on every
acquisition and in its VERDICT line since the disclosure change landed;
the clause points there rather than re-explaining. Rule 6 is untouched —
its sentence is literally true; the list is where the belief formed.
Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin
comment to a pointer: its resolution order, batch-death incident and both
traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's
header, which is the surface that goes red when the pin is touched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath
The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs
paying line ratchets hit it independently in one hour, each doing exactly
what its dispatch said and reaching for the cheapest visible line source.
Add the rule to the contract the dev actually reads, stating BOTH sides so
the next dev neither funds with re-wrap nor refuses a legitimate
densification repair: additions are paid only by deleting content
(maintainer 2026-08-17), while independent densification that buys no
content is an allowed repair (maintainer 2026-08-29); the boundary
question is whether the re-wrap bought lines for new content. Raising the
ceiling stays the maintainer's floor; when nothing can be deleted, the
answer is a blocked report, not a raise.
Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to
their canonical homes: the stash mechanism + replacement spellings live in
CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26
footer measurement lives in AGENTS.md's attribution-footer clause, which
this file's own sanitizer section already names as the single home. The
operative conclusions (never stash; session footer is create-only) stay.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
@os-zhuang
os-zhuang marked this pull request as ready for review September 2, 2026 01:19
@os-zhuang
os-zhuang added this pull request to the merge queueSep 2, 2026
Merged via the queue into main with commit 909a441Sep 2, 2026
29 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12800-osdev-contract-visibility branch September 2, 2026 01:43
os-litant pushed a commit that referenced this pull request Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline
The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on
origin/main: (1) resource rule 1 now states the lock's non-guarantee —
it does not promise an idle machine, only excludes work routed through it,
so wall-clock readings under a hold are shared-box readings; (2) a size
ratchet is paid only by deleting content — a re-wrap is not payment, a
densification that adds nothing is a repair, a ceiling is raised only by
the maintainer, nothing left to delete means "blocked". Additions +108
tokens, funded in the same package: three dispatch-prompt non-negotiables
that restated the template's binding-file paragraph, the "When to STOP"
rule and rule 4 verbatim; the template's top-paragraph restatement of the
final-message rule; the sanitizer trap's HTML-comment clause (stated at
the report block); and rule 4's published-only rationale sentence about
disk exhaustion, which the oracle does not carry. Package 11,556 ->
11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at
the landed counts: entry 9,708, rules/dev-template.md 1,838.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/sskip-changesetPR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants

@os-justin@os-zhuang@claude