You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
pm-dispatch: the allow-listed ccr ready flip was denied [Auto-Mode Bypass] in a session whose checkout carried the allow rows from its first HEAD — and since #19997 a denied ccr call leaves a session seat no landing route #20048
Filing gate: ③ a task the maintainer directed. The maintainer, in the domain:cli execution seat's session session_01TnPAC1UsTGfHPXVUCL6iLn (chat), 2026-09-24, verbatim:
这条命令在 .claude/settings.json 的放行清单里,但 auto 模式的权限分类器还是拒了,拒因是 [Auto-Mode Bypass]。」
(One client UI notice, which the paste carried mid-sentence, is omitted from the quote. It is not the maintainer's words.)
The maintainer names the skills lane. ⛔ Routing labels are triage's, so this card is filed bare. Filed by the domain:cli execution seat #6024. ⛔ Not a claim.
Acting reader: the domain:skills seat, which owns .claude/skills/pm-dispatch/references/landing-operations.md §B. The permission choice in the last section is the maintainer's. .claude/settings.json is governed.
Command.curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectstack/pulls/20022/ccr/ready_for_review -d '{}', issued once, standalone, on 2026-09-24 at about 20:30Z.
The PR was a clean landing on every reading the seat owns. It was ACCEPTed (5821336143). CI on head ca79edd2 read 33 success plus 2 rostered skips, with 0 pending and 0 failed. check-governed-merges --pr 20022 said NOT governed (483 lines). There was no os-regen path and no Clause-② limb.
Why this is now a skills problem, not only a classifier reading
Since #19997 (cc4ee775), references/landing-operations.md §B reads:
:51 「绿即转 ready + 挂 auto-merge,只走 settings.json allow 行的 ccr 两命令」 (ready and auto-merge go only through the two allow-listed ccr commands);
:54 「落地中遭分类器拒 ⇒ 停手、报维护者、卡上记命令与拒因;⛔ 不换拼法或改走中继绕过」 (a denial during landing: stop, report, record; never respell or switch to the relay).
Read together, a session whose classifier denies the ccr pair has no landing route at all. Every accepted PR in that session then waits for a human. #19997's own "Measured risk that stays open" named this case as unmeasured; this is the negative reading.
Cost, measured. PR #20022 has been ACCEPTed and green since about 20:28Z and was still draft at 23:07Z. The lane runs serial by the maintainer's standing order (5815600379 on #6024), so no next card can be dispatched until a human lands it.
The skills seat, once the maintainer answers. Make §B name exactly one landing route that a session seat takes after a denied ccr call, or state plainly that there is none and a human lands. The current pair of lines implies the second without saying it, and the stop rule reads as though a fallback exists elsewhere.
Record the reading where the skill keeps classifier readings (references/platform-readings.md, beside :435, the content-based [Self-Approval] reading): the allow-listed ccr ready flip was denied [Auto-Mode Bypass] in a session whose checkout carried the allow rows from its first HEAD.
The skills PR answers item 2 in §B's own lines and does not add a gate. If it adds or changes a settings.json row, that part is governed and lands by the maintainer's hand.
Filing gate: ③ a task the maintainer directed. The maintainer, in the
domain:cliexecution seat's sessionsession_01TnPAC1UsTGfHPXVUCL6iLn(chat), 2026-09-24, verbatim:(One client UI notice, which the paste carried mid-sentence, is omitted from the quote. It is not the maintainer's words.)
The maintainer names the skills lane. ⛔ Routing labels are triage's, so this card is filed bare. Filed by the
domain:cliexecution seat #6024. ⛔ Not a claim.domain:skillsseat, which owns.claude/skills/pm-dispatch/references/landing-operations.md§B. The permission choice in the last section is the maintainer's..claude/settings.jsonis governed.PUT …/ccr/auto_mergefrom one turn: 4 allowed / 4 denied under three reasons; and a hooks landing rotates every seat off shift before it can flip ready #18469, [finding] the committed.claude/settings.jsonallow-lists every REST write the seat makes except the two landing calls (ccr/ready_for_review,ccr/auto_merge) — so landing falls to the non-deterministic auto-mode classifier and seven green PRs waited for a human #19014, Seat batch closure needs a named script and a matching allow rule — the runtime's write classifier refuses the three-step close (comment · label · PATCH) non-deterministically, and the two existing allow rules do not match how seats invoke the tools #19469, pm-dispatch: relay-opened dev PRs are never attached to the seat's session, and the relay landing route has no allow rule, so auto mode decides seat landings call by call #19990. 0 are open. Why this is not a duplicate:PUT …/ccr/auto_mergefrom one turn: 4 allowed / 4 denied under three reasons; and a hooks landing rotates every seat off shift before it can flip ready #18469's closing comment rules: 「之后如果分类器再拒掉某条具体命令,按那条命令另开一张新卡」 (if the classifier denies a specific command again, open a new card for that command). This is that card..claude/settings.jsonallow-lists every REST write the seat makes except the two landing calls (ccr/ready_for_review,ccr/auto_merge) — so landing falls to the non-deterministic auto-mode classifier and seven green PRs waited for a human #19014 explained its own post-landing denial by the session's permission set predating the rows. That explanation is measured below and does not apply here.The reading
curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectstack/pulls/20022/ccr/ready_for_review -d '{}', issued once, standalone, on 2026-09-24 at about 20:30Z.[Auto-Mode Bypass]. The record is on [finding] a THIRD package-install door — marketplace install-local — parses nothing at all: 0 ManifestSchema, 0 safeParse across 1,912 lines, so an id MANIFEST_ID_PATTERN refuses installs cleanly there #19576 as5821758726..claude/settings.json:61:Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectstack/pulls/*/ccr/ready_for_review *). It landed in67624b78(chore(claude): allow-list the two landing REST calls in settings.json #19047) on 2026-09-18.2c1011b0(reflog, 2026-09-24T12:43Z), andgit show 2c1011b0:.claude/settings.jsoncarries both rows at :61–:62. ⇒ [finding] the committed.claude/settings.jsonallow-lists every REST write the seat makes except the two landing calls (ccr/ready_for_review,ccr/auto_merge) — so landing falls to the non-deterministic auto-mode classifier and seven green PRs waited for a human #19014's explanation ("its permission set predated the rules") does not fit. What remains is pm-dispatch: subscribe relay-opened PRs at collection; seats land through the allow-listed ccr pair; a landing denial stops and surfaces #19997's other unmeasured explanation: the classifier judges content over an allow row. That this session loaded the file is not proven here, only that the file had the rows.5821336143). CI on headca79edd2read 33 success plus 2 rostered skips, with 0 pending and 0 failed.check-governed-merges --pr 20022said NOT governed (483 lines). There was noos-regenpath and no Clause-② limb.scripts/pm/with-fleet.sh --via dispatch, opspr_ready+automerge_enable) readied and armed PRs fix(runtime): a seed dataset declared once registers once on an additive multi-package artifact #19981, fix(cli): mount the always-on package-registry capability at its spec-declared provider (#19387) #19983 and fix(runtime): the resume door checks WHO is resuming — the run's starter, or the sys_automation_run read grant (#19987) #20005 under auto mode without a single denial. The timeline actor isobjectstack-fleet[bot]. All three came beforecc4ee775reached this seat's checkout. (PR feat(mcp): resume_run completes a paused screen flow — the caller's own run, behind run_action's gates #19985 was readied by hand by the maintainer.)PUT …/ccr/auto_mergefrom one turn: 4 allowed / 4 denied under three reasons; and a hooks landing rotates every seat off shift before it can flip ready #18469. It measured 8 byte-identicalPUT …/ccr/auto_mergecalls from one turn: 4 allowed and 4 denied, one of them[Auto-Mode Bypass]. An allow row narrows the classifier's room; this reading says it does not close it.Why this is now a skills problem, not only a classifier reading
Since #19997 (
cc4ee775),references/landing-operations.md§B reads:settings.jsonallow 行的 ccr 两命令」 (ready and auto-merge go only through the two allow-listed ccr commands);Read together, a session whose classifier denies the ccr pair has no landing route at all. Every accepted PR in that session then waits for a human. #19997's own "Measured risk that stays open" named this case as unmeasured; this is the negative reading.
Cost, measured. PR #20022 has been ACCEPTed and green since about 20:28Z and was still draft at 23:07Z. The lane runs serial by the maintainer's standing order (
5815600379on #6024), so no next card can be dispatched until a human lands it.What this card asks
scripts/pm/」, or landings go through the relay with a new allow row. This reading is an input to that choice: in this session the allow-listed ccr route was denied, and the non-allow-listed relay route passed three times.references/platform-readings.md, beside :435, the content-based[Self-Approval]reading): the allow-listed ccr ready flip was denied[Auto-Mode Bypass]in a session whose checkout carried the allow rows from its first HEAD.Acceptance notes
settings.jsonrow, that part is governed and lands by the maintainer's hand.