Filed by the domain:skills execution PM seat, session session_01HZfg2AwVX191qCizp88gQr, at 2026-09-16T02:11Z, from its own readings this shift.
Measured (comment authors read back through GET /issues/comments/{id}, same session, same tool scripts/pm/post-stamped.mjs, same REST proxy)
| comment |
written |
user.login |
user.type |
performed_via_github_app |
| 5687342171 (landing record #18324) |
2026-09-15T20:04:43Z |
claude[bot] |
Bot |
claude |
| 5690836932 (ruling-C provenance PR #18315) |
2026-09-16T01:53:43Z |
os-zhuang |
User |
claude |
| 5690861787 / 5690953559 / 5690957832 |
01:57Z – 02:10Z |
os-zhuang |
User |
claude |
GET /user on the same credential reads os-zhuang / User at both instants (it did at seating, 02:03Z the day before, when the writes read back claude[bot]).
- No seat action sits between the two readings: no re-attach, no token change the seat can see; the flip happened while the seat was idle between 20:04Z and 01:53Z. ⇒ the proxy now injects a user-to-server token (the App acting on behalf of
os-zhuang) where it injected the installation token before; performed_via_github_app reads claude in both classes, so it is NOT a discriminator (already on the register); user.login + user.type on a read-back IS.
- Consequence measured on the live board: the seat's four ruling-C provenances of 01:53–01:57Z carry the SAME account as the approving reviews they cite (os-zhuang, 5217668792 / 5217673315 / 5217676382 / 5217679727). The session line inside each record is the attribution; the red line (the seat writes no approving review) held — the review endpoint was never called — but a reader of
merged_by / comment authors alone cannot tell the seat from the approver any more.
What is asked (⛔ not asserted — the seat grades)
One or two rows in references/platform-readings.md (write side): the proxy's token class can change between two writes of one session with no seat action; the class is read on every write's read-back (user.login + user.type), never carried forward from the round-open marker; a change is recorded on the seat post at the next refresh with both instants. Optionally one line in the seat-post protocol: the round-open marker's identity reading is dated, not standing. References tier (in-seat contract-tier review). Fold candidate with #18320 (same file); the ceiling is 466 with 463 in use.
Grading (lane finding self-triage; class (c), a platform fact change measured with a control): p3 · Task · pm:queue · domain:skills.
查重词
write identity flipped mid-shift · installation token to user-to-server · claude[bot] os-zhuang read-back · performed_via_github_app not a discriminator · token class re-read every write
Generated by Claude Code
Filed by the
domain:skillsexecution PM seat, sessionsession_01HZfg2AwVX191qCizp88gQr, at 2026-09-16T02:11Z, from its own readings this shift.Measured (comment authors read back through
GET /issues/comments/{id}, same session, same toolscripts/pm/post-stamped.mjs, same REST proxy)user.loginuser.typeperformed_via_github_appclaude[bot]claudeos-zhuangclaudeos-zhuangclaudeGET /useron the same credential readsos-zhuang/Userat both instants (it did at seating, 02:03Z the day before, when the writes read backclaude[bot]).os-zhuang) where it injected the installation token before;performed_via_github_appreadsclaudein both classes, so it is NOT a discriminator (already on the register);user.login+user.typeon a read-back IS.merged_by/ comment authors alone cannot tell the seat from the approver any more.What is asked (⛔ not asserted — the seat grades)
One or two rows in
references/platform-readings.md(write side): the proxy's token class can change between two writes of one session with no seat action; the class is read on every write's read-back (user.login+user.type), never carried forward from the round-open marker; a change is recorded on the seat post at the next refresh with both instants. Optionally one line in the seat-post protocol: the round-open marker's identity reading is dated, not standing. References tier (in-seat contract-tier review). Fold candidate with #18320 (same file); the ceiling is 466 with 463 in use.Grading (lane
findingself-triage; class (c), a platform fact change measured with a control): p3 · Task ·pm:queue·domain:skills.查重词
write identity flipped mid-shift·installation token to user-to-server·claude[bot] os-zhuang read-back·performed_via_github_app not a discriminator·token class re-read every writeGenerated by Claude Code