docs(pm-skills): a dev container creates a remote branch it cannot delete — probe on the branch the dev keeps - #18808
Conversation
…, so probe on the branch the dev keeps Claude-Session: https://claude.ai/code/session_01Gqi43smmqjJ5sUrhfoPeKu Co-authored-by: Claude <noreply@anthropic.com>
Contract reviewServed-tier: Review of record on the PR thread (the queue guard's merge_group leg reads this thread and, since PR #18738, the card thread too). In-seat review of PR #18808 (#18774) by the dispatching ① Derived judgments
② Semver levelNone — no package is touched; ③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
Fixes #18774
Clause-②: noTwo files, both fact layer, both held at their ceilings:
.claude/skills/pm-dispatch/references/platform-readings.md466 / 466 and
.claude/skills/pm-dispatch/references/dispatch-runbook.md241 / 241 — net line change 0 ineach, three rows added and three retired in the first, one added and one retired in the second, every added row ≤ 120 B.
No ceiling raised, no ruling spent.
skip-changeset—.claude/**is shipped by no package'sfiles[], so nothingpublished moves.
The defect
A dispatched dev's container creates a remote branch and cannot delete one on either channel, so any instruction
that says "probe before you write anything" manufactures a permanent artefact: the dev reads "before writing anything" as
"not on your working branch", pushes a throwaway, and then cannot remove it. The leftover is not inert — a
claude/issue-NNNN-*head is exactly what the AGENTS.md claim pre-check greps for, so a stray branch answers "alreadyclaimed" for a card nobody is working. That failure direction is the silent one: a live card read as claimed, with no red
signal anywhere. This PR does not touch the capability (proxy policy is not this repo's to decide) and does not touch the
pre-check text at AGENTS.md :459–:463 (rules layer, another serial). It records the capability where branch and ref facts
live, and moves the instruction so the probe lands on the branch the dev is keeping anyway.
The capability, re-derived on this branch — ⛔ not taken from the card
Both attempts were made against this PR's own working branch, the one that stays either way.⚠️ No branch was created
in order to fail to delete it — that is the card's whole point.
Channel ① — git, 2026-09-17T21:47Z
Channel ② — REST, 2026-09-17T21:47Z
And the ref survived both, read back immediately after:
⇒ the card's premise holds for this container, on a third branch and in a third session. One correction to the tree's
existing wording, which the rows below carry: the old row said 「容器发不出分支删除 refspec」 — the container does
send it. The RPC is made and answered 403; nothing is held back locally. Same outcome, different mechanism, and the
mechanism is what tells a reader not to go looking for a local git config to fix.
The census — the seat's, cited; and my re-take
Handed down by the
domain:skillsseat, 2026-09-17T21:45Z (⛔ not retyped as mine):git ls-remote --heads origin 'refs/heads/claude/issue-*'answered 291 heads; against the newest 1200 PRs (back to 2026-09-05) — 26 with anopen PR, 8 with a closed / merged PR whose branch was never deleted, 257 with no PR in that window.
My re-take, 2026-09-17T21:48Z — one
ls-remote, zero writes:⇒ the population did not move in those three minutes. The two named strays are both present:
f22c63215matches the sha the card names. ⛔ I did not re-take the 26 / 8 / 257 split — that is the seat's reading,used as an existing fact, and only the head count was re-checked for increment.
①
platform-readings.md— the rowsThey land in the
## 读数陷阱block at:374–:379, whose subject is already refs: the row above them is thezero-commit probe-branch reading, the row below is the two-read criterion and then the ⛔ against reading a
ls-remote | grep issue-hit as a claim. ⇒ the capability, its consequence and the claim reading now sit on thecriterion they qualify, instead of one being 57 rows away in the same section.
Added — three rows, verbatim, with byte counts
:374is amended in place, no line bought, to carry the corrected mechanism and the replication count:Paid — three rows
:375(pre-edit) — the git-channel row, spelling the failure as 「send-pack: unexpected disconnect,三次退避全败,同会话普通 push 正常」 with a placeholder branch token:374now states positively. Per this corpus's own 行文纪律 — 「原话仅限操作性判据;⛔ 实测叙事不进操作文本」:375, which names both channels and keeps the operational ⛔:376(pre-edit) — 「⇒ 测量型派发留下的探针分支永久堆在 origin 上。」:376, same 「⇒」 position, same accumulation clause, plus the maintainer-only disposition:431(pre-edit) — 「分支删除被拒有第二形态:代理回 403,与既有 send-pack 断连同处置 ⇒ 不可删,⛔ 不重试。」:375:375⛔ No re-wrap was used as currency: nothing here is two wrapped halves of one sentence pushed together to free a line.
Each retirement drops content — an attempt narrative, a dangling consequence, a duplicate discovered twice.
②
dispatch-runbook.md— the rowAdded — one row, 119 B, last in
## 派发词构造细则(:236), directly under the measurement-first row, because ameasurement-first dispatch is the shape that produced the artefact on
origintoday:Paid —
:201(pre-edit), 59 BWhy the tree no longer needs it as a separate line: it is the rationale half of the row above it.
:200alreadycarries the operational rule — 「派发那刻现取、随派发词下发的两份读数,判据同一:PM 已有的读数下发一次」 — and the
prohibition it spells is stated operationally twice more in the same block: at
:201(post-edit) 「⛔ 不让 dev 枚举全 farm」 for the gate-list reading, and at
:204(post-edit) 「当既有事实用,只复核其后的增量,⛔ 不重跑」 for thededupe reading, which is also where the dev-side half of the contract is pointed at. Its cost clause is held by
:203(post-edit) 「② 去重或看板读数取一次(查询式加时间戳)整批共用」. No rule leaves the corpus.Reserved rows — verified by content on my head
Every change in this diff is at
:374or below, so nothing above:374moved by a single byte or a single line.:10–:12([finding] the harness auto-mode classifier denies the protocol's landing command non-deterministically — 8 byte-identicalPUT …/ccr/auto_mergefrom one turn: 4 allowed / 4 denied under three reasons; and a hooks landing rotates every seat off shift before it can flip ready #18469 PR-A) — byte-identical, and 362 lines above the first hunk.:29— byte-identical: 「零 legacy status 的仓恒答空集默认值pending+total_count: 0,⛔ 非门禁读数,门禁读 check-runs。」/pulls/18666/filesat 2026-09-17T21:52Z: its only hunk on this file is@@ -209,7 +209,7 @@, one changed line, thetotal_countrow. Onmainand on my head the numbers are the same:the changed line is
:212, the hunk's context window:209–:215. Every byte in:209–:215is unchanged, sodocs(pm-dispatch): name the repository each cited instrument answers for #18666 still applies cleanly.
:432([finding] the harness auto-mode classifier denies the protocol's landing command non-deterministically — 8 byte-identicalPUT …/ccr/auto_mergefrom one turn: 4 allowed / 4 denied under three reasons; and a hooks landing rotates every seat off shift before it can flip ready #18469 PR-A) — 「harness 按内容拒写:同会话派发 PR 上 PASS 拒为[Self-Approval]」 is still at:432on myhead: the insertion at
:378and the retirement at:431cancel across it.:431, which is adifferent row — the same off-by-one PR docs(pm-skills): a repo with zero legacy statuses reads the combined-status endpoint as an empty-set default #18775's body diagnosed, and the reason I checked the content rather than
the number before touching anything.
is still the only open PR touching this file.
higher in
## 读数陷阱. My rows are at:374–:379, the container-restart / probe-branch neighbourhood. No overlap.Ratchet before / after, and the diff
node scripts/pm/check-skill-line-ratchet.mjs— exit 0 both times:main9846f2763cde12f71b8aplatform-readings.mddispatch-runbook.mdWidest-table-row pins are 0 for both files (neither carries a markdown table) and are unchanged.
Five for five: 4 rows rewritten or inserted against 4 retired or replaced on
platform-readings.md(3 added + 1 amendedin place vs. 3 retired + 1 amended in place), 1 added against 1 retired on
dispatch-runbook.md.⏹️ For the MAINTAINER — the stray branches, and the one hand that can remove them
Both are on
originright now and no account in this loop can delete them — the dev container and the triage seatboth 403 on both channels. The two commands, to be run by a hand with delete rights:
claude/issue-18734-workflow-scope-probe—f22c63215c6935552f9761d1ec2bd59556c7b656, one commit ahead ofmain, noPR. This is the branch the card names; it is what makes
ls-remote --heads origin | grep issue-18734answer twobranches for one card.
claude/issue-18545-formula-can-function—d5e64d8d9dae7b58bb7fa4aabccd95247b1fb9de, no PR.⛔ This PR's own branch,
claude/issue-18774-probe-branch-undeletable, is not on that list — it is live work and itcarries this PR.
Gates
Derived from the worktree with
node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack(no hand-fed path list; change set 2 paths vs merge base
9846f2763, three-dot). All 18 run, exit code captured withredirect-then-
$?, never across a pipe:node scripts/check-closing-keyword-parity.mjsnode scripts/check-closing-keyword-parity.mjs --self-testnode scripts/check-comment-mask-corpus.mjsnode scripts/pm/check-governed-queue-guard.mjs --self-testnode scripts/pm/check-harness-current.mjs --self-testpnpm --filter @objectstack/lint run check:doc-formula-expressionspnpm check:agent-test-spellingpnpm check:doc-authoringpnpm check:driver-memory-censuspnpm check:nul-bytespnpm check:pm-governed-mergespnpm check:pm-half-statespnpm check:pm-skill-id-lintpnpm check:pm-skill-ratchetpnpm check:refd-timer-probepnpm check:required-contextspnpm check:skill-frame-syncpnpm check:watch-hint-literalcheck:doc-formula-expressionsanswered exit 3 — PREREQUISITE NOT MET on its first run (「@objectstack/lint — aworkspace package that is not built」), which is not a finding and not a measurement. The gate names its own fix; it
was run:
pnpm exec turbo run build --filter=@objectstack/formula --filter=@objectstack/lint --concurrency=2throughscripts/pm/os-verify-lock.sh(VERDICT command-exit 0 · held the lock 144s · waited 0s), after which the gate answeredexit 0. The 0 above is the second run.
Reconciliation, exit codes recorded per family:
Repo-wide
pnpm lint(eslint . --no-inline-config) — exit 0, run whole, not narrowed.Control-character self-scan over both edited files, beyond
check:nul-bytes:grep -naP '[\x00-\x08\x0b\x0c\x0e-\x1f\x7f]'on both paths — zero matches (grep exit 1).⛔ Not run here and not claimed: the 53 artifact-roster families, the 11 wide-population families, the 14
pending-changeset families and the CI-measured-only families the derivation prints under their own headings — CI owns
those.
Generated by Claude Code