Uh oh!
There was an error while loading. Please reload this page.
agents(os-dev): verify-lock non-guarantee clause + ratchet funding discipline in the dev contract - #14229
Merged
Merged
Conversation
…antee list Rule 1's entry-point list named four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so every reader completed the list into exclusivity the lock never promised. Add the missing clause: the lock does NOT guarantee an idle machine; it only excludes work routed through this entry point, and check:* gate runs, installs and dev servers never take that path, so wall-clock absolutes measured under a hold are shared-box readings. The script itself has stated this boundary on every acquisition and in its VERDICT line since the disclosure change landed; the clause points there rather than re-explaining. Rule 6 is untouched — its sentence is literally true; the list is where the belief formed. Funded (ratchet ceiling 469, headroom 0) by shrinking the model-pin comment to a pointer: its resolution order, batch-death incident and both traps live verbatim and fuller in scripts/check-agent-model-declared.mjs's header, which is the surface that goes red when the pin is touched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…ne breath The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing exactly what its dispatch said and reaching for the cheapest visible line source. Add the rule to the contract the dev actually reads, stating BOTH sides so the next dev neither funds with re-wrap nor refuses a legitimate densification repair: additions are paid only by deleting content (maintainer 2026-08-17), while independent densification that buys no content is an allowed repair (maintainer 2026-08-29); the boundary question is whether the re-wrap bought lines for new content. Raising the ceiling stays the maintainer's floor; when nothing can be deleted, the answer is a blocked report, not a raise. Funded (ceiling 469, headroom 0) by delegating two verbatim duplicates to their canonical homes: the stash mechanism + replacement spellings live in CLAUDE.md (injected into every session) and AGENTS.md; the 2026-08-26 footer measurement lives in AGENTS.md's attribution-footer clause, which this file's own sanitizer section already names as the single home. The operative conclusions (never stash; session footer is create-only) stay. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Whev4BkZ4BRcgiXYo4muWP
…dev-contract-visibility
This was referenced Sep 1, 2026
os-zhuang
approved these changes
Sep 2, 2026
os-zhuang
marked this pull request as ready for review
September 2, 2026 01:19
Uh oh!
There was an error while loading. Please reload this page.
This was referenced Sep 2, 2026
os-litant pushed a commit
that referenced
this pull request
Sep 2, 2026
…ent template — the verify-lock non-guarantee and the ratchet funding discipline The follow-up sync PR #14444 recorded, from .claude/agents/os-dev.md on origin/main: (1) resource rule 1 now states the lock's non-guarantee — it does not promise an idle machine, only excludes work routed through it, so wall-clock readings under a hold are shared-box readings; (2) a size ratchet is paid only by deleting content — a re-wrap is not payment, a densification that adds nothing is a repair, a ceiling is raised only by the maintainer, nothing left to delete means "blocked". Additions +108 tokens, funded in the same package: three dispatch-prompt non-negotiables that restated the template's binding-file paragraph, the "When to STOP" rule and rule 4 verbatim; the template's top-paragraph restatement of the final-message rule; the sanitizer trap's HTML-comment clause (stated at the report block); and rule 4's published-only rationale sentence about disk exhaustion, which the oracle does not carry. Package 11,556 -> 11,546 (-10 for this commit, -21 against main). Ratchet rows re-pinned at the landed counts: entry 9,708, rules/dev-template.md 1,838. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes#12800
Fixes#13116
One delivery on one governed file, per the identical 2026-08-31 triage re-grade on both cards:
.claude/agents/os-dev.mdonly. Two per-member commits (one per card), net-0 lines at the ratchet ceiling. Card relationships are declared here once; branch commits carry no card trailers (squash discipline).What changed
Member 1 (chain head). Resource rule 1's entry-point list carried four guarantees and no non-guarantee, one line above rule 6's wall-clock absolute — so readers completed the list into exclusivity the lock never promised. One clause is added to that list: the lock does NOT guarantee an idle machine — it only excludes work that entered through the entry point;
check:*gates, installs and dev servers do not take that path and run on the same cores as the hold, so wall-clock absolutes measured under it are shared-box readings, never a quiet-machine promise. The script states the same boundary on every acquisition and in its VERDICT line, and the clause says so — pointing rather than re-explaining. Rule 6 is untouched, per the carried recommendation: its sentence is literally true; the list is where the belief formed.Member 2. The re-wrap funding ban lived only in the PM's dispatch SKILL.md; two devs paying line ratchets hit it independently in one hour, each doing what its dispatch said. The dev contract now carries the funding discipline as a DoD bullet beside the published-skills budget rule, BOTH sides in one breath: additions to a ratcheted file are paid only by deleting content (2026-08-17 ruling, quoted in place), while independent densification that buys no content is an allowed repair (2026-08-29 ruling, quoted in place); the boundary question is whether the re-wrap bought lines for new content — the gate cannot tell the two net-0s apart. One-sided phrasing that would make a dev refuse a legitimate densification repair was the named failure mode; the allowed side is stated explicitly. Ceiling raises stay the maintainer's floor: when nothing can be deleted, the answer is a blocked report, not a raise.
Rulings carried (verbatim, untranslated)
.claude/**是受管面 ⇒ 人工合并,PR 不进自动队列。」Must-answer 1 — the deleted lines, and why no third same-shape card
All funding is content deletion of verbatim duplicates whose canonical homes are surfaces a dev demonstrably reads. Zero re-wrap funding: every surviving untouched line keeps its exact wrap position (visible in the diff — the four hunks touch only deleted or added sentences).
scripts/check-agent-model-declared.mjs— the gate that goes red the moment anyone touches the pin, so the reader meets that knowledge at the point of failure. Nothing dev-operative was removed: a dev never chooses its own model. The comment keeps the decision (a pinned floor, not a cap; PM per-dispatch tiering wins) and the pointer.git stash) stays in os-dev.md.None of the three removes a rule a dev needs and cannot reach: each survivor sentence keeps the operative core in os-dev.md, and the deleted matter is duplicate justification or measurement whose primary home is mechanically in front of the dev (injected CLAUDE.md; binding-read AGENTS.md; the failing gate's own header).
Must-answer 2 — no rules moved to a new file
No file was created and no rule was relocated. The deletions delegate to homes that already carried the same text before this PR and are demonstrably read: CLAUDE.md is injected by the harness into every session (reading is not optional); AGENTS.md is the binding first read — os-dev.md's preamble orders it, CLAUDE.md's first line points at it, and this very run read it before editing; the model-pin detail is delivered by the gate itself when it fires. The claim is not "os-dev.md points at it" — it is "the reader cannot avoid it".
Must-answer 3 — the clause states the non-guarantee, not a restatement of the guarantees
The added sentence, translated: "the same list's non-guarantee: it does NOT guarantee an idle machine — it only excludes work that entered through this entry point;
check:*gates, installs and dev servers do not take that path and run on the same cores as your hold (the script states this boundary on every acquisition and in its VERDICT line), so wall-clock absolutes measured under the lock are shared-box readings, never a quiet-machine promise." It restates none of the four guarantees.Script-side precondition, measured (triage had recorded it NOT MEASURED)
The disclosure from the coverage-boundary PR IS on origin/main — verified by content, not by commit-log grep:
scripts/pm/os-verify-lock.shprints the boundary at acquisition ("WHAT YOU NOW HOLD: exclusion against other LOCKED runs … NOT having an idle box") and in every VERDICT line ("SHARED-BOX SECONDS — this lock excluded other LOCKED runs, NOT unlocked sibling work"). This run's own lock use reproduced both lines. The clause therefore points and stays short.Line budget, measured with the gate itself
check:pm-skill-ratchet, not recalled.scripts/pm/check-skill-line-ratchet.mjsis not in the diff.Gates — run at b5caded, after the final commit
Union derived by
node scripts/pm/dispatch-gates.mjswith no hand-fed paths (changeset taken from merge base 66ecc50): 10 families. All exits captured by redirect before any pipe; verdict lines quoted from the gates' own output:Governed surface
.claude/**: this PR stays draft — never armed, never queued; the maintainer merges by hand, updating base to current main and re-running gates at merge time per the triage fence.skip-changesetapplies (diff is.claude/**only; nothing publishes).Durable attribution: session_01Whev4BkZ4BRcgiXYo4muWP (kept in prose because PR-body footers downgrade on edit).
Generated by Claude Code
Generated by Claude Code