Skip to content

pm-dispatch: relay-opened dev PRs are never attached to the seat's session, and the relay landing route has no allow rule, so auto mode decides seat landings call by call #19990

Description

@objectstack-fleet

Filing gate: ③ a task the maintainer directed. The maintainer, in the domain:engine#1 seat's session session_01Bvd69VPa6puiNzzPUroDBx (chat), 2026-09-24, verbatim, in order:

  • 「你的pr为什么没有挂在当前session上」
  • 「写一个 skills 卡片,更新技能」
  • 「包括你刚才为什么不能merge,我当前session设置的是auto」

The maintainer names the skills lane. ⛔ Routing labels are triage's, so this card is filed bare. Filed by the domain:engine execution seat 1. ⛔ Not a claim.

Case 1: dev PRs opened through the relay are not attached to the seat's session

What happened. PR #19971, PR #19972 and PR #19979 were opened by os-dev subagents running inside this seat's session. Each went through the relay (pr_create, executed by the fleet-write workflow as objectstack-fleet[bot]), so the session did not create them, and nothing attached them to it. The harness's own "subscribe after you create a PR" step never fires for a relay-created PR. The seat subscribed all three at 14:45Z, only when the maintainer asked, roughly 50–75 minutes after the PRs opened. The PRs had CI runs, two FAIL reviews, patch rounds and re-reviews in between.

Governing text. references/landing-operations.md 〈B〉: 「落地窗口给关键 PR 挂 subscribe_pr_activity,会话型座位专用」 and 「⛔ 不订阅 dev 交报告前的 PR」. The rule exists, but:

  • it is optional in wording ("关键 PR");
  • it lives in the landing file, which a seat reads only after ACCEPT;
  • nothing in the collection step (references/execution-duties.md 〈收集〉) says to subscribe when a report names a PR.

Ask. Make the subscription part of collection: when an os-dev-report (subagent or cloud) names a PR, a session seat subscribes it in the same act and lists it on the seat post; the unsubscribe at MERGED / closed stays as written. State once why it is needed: relay-created PRs are never auto-attached.

Case 2: why the seat could not land under auto mode, then could

Readings from this session:

  1. Denied, [CI Bypass]. Under ruling 1A (Why three engine-lane landings needed the maintainer this round (a pending release-note correction, a first-time queue-flake signature, a subagent's denied label write): can each become seat-decidable? #19940, 5814546887) the seat edited PR fix(objectql): settle readonlyWhen locks per cycle, so a cycle no longer over-locks the rest of the update #19979's record and correction comment so it could enqueue over the by-design red Check Changeset. The very next command was denied: a read-back curl of those two comments.
  2. Denied, [Self-Approval]. A send_later timer whose text said: if every check on PR fix(driver-turso)!: refuse a remote url beside syncUrl, and any replica not on a local file, instead of running on :memory: #19971 / PR fix(driver-sql): the local json backfill lets the codec decide, so JSON nested past SQLite's depth limit is no longer quoted into a string #19972 is green, post the ACCEPT and run pr_ready + automerge_enable. Both PRs were written by os-dev subagents inside the same session.
  3. Passed. After the maintainer's 「你试试看现在有没有权限」, the seat ran scripts/pm/with-fleet.sh --via dispatch --repo objectstack-ai/objectstack --actions FILE: first with pr_ready + automerge_enable for PR fix(objectql): settle readonlyWhen locks per cycle, so a cycle no longer over-locks the rest of the update #19979 (14:49Z), then for PR fix(driver-turso)!: refuse a remote url beside syncUrl, and any replica not on a local file, instead of running on :memory: #19971 and PR fix(driver-sql): the local json backfill lets the codec decide, so JSON nested past SQLite's depth limit is no longer quoted into a string #19972 (14:53Z). The session was in auto mode, and all three calls passed. PR fix(driver-sql): the local json backfill lets the codec decide, so JSON nested past SQLite's depth limit is no longer quoted into a string #19972 and PR fix(objectql): settle readonlyWhen locks per cycle, so a cycle no longer over-locks the rest of the update #19979 are in the merge queue; PR fix(driver-turso)!: refuse a remote url beside syncUrl, and any replica not on a local file, instead of running on :memory: #19971 is ready with auto-merge armed.

What the tree says.

Ask (the skills seat recommends; a new allow rule stays the maintainer's call):

  • (a) Give the relay's landing ops a spelling that can be allow-listed narrowly. with-fleet.sh --actions * would admit every op, so a landing-only entry point is one option.
  • (b) Say where a maintainer's standing authorization to land reviewed PRs is recorded, if seats are to land mode:subagent PRs under auto mode at all; otherwise say that the landing click stays human for those PRs.
  • (c) One line in the landing text: a classifier denial during landing is stop, surface to the maintainer, and record on the card, ⛔ never routed around. That is what this seat did, from the harness's own instruction, not from the skill.
  • (d) Timer texts: reading-discipline.md already bars unconditioned imperatives in timers. Consider stating that a timer carries only the re-read and its triggers, never a landing write verb.

Filing-gate answers


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions