Skip to content

governed: tier the register — Tier H stays human/approved, Tier S (.claude/**) lands on a contract-tier review of record - #19144

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-19133-governed-tiers
Sep 18, 2026
Merged

os-zhuang merged 3 commits into
mainfrom
claude/issue-19133-governed-tiers

Conversation

@os-elon-musk

Copy link
Copy Markdown
Collaborator

Fixes #19133
Clause-②: no

Tiers the governed register. Membership does not move (every row still governs what it did; one hit still forks the whole PR; --test still exits 3 on every row). What moves is the LANDING each row waits for, carried as tier on the register row and derived per PR by one function that both scripts read.

  • Tier H(人合): docs/adr/** · docs/NORTH-STAR.md · skills/** · AGENTS.md · CLAUDE.md — the maintainer's hand, or an authorized APPROVED review by GOVERNED_APPROVERS and then the owning seat lands it. Unchanged.
  • Tier S(席内达档复核落地): the whole .claude/** tree (skills, agents, hooks, settings) — the owning seat lands it through the queue once the PR thread or its card carries a ## Contract review record for the PR's current head with Served-tier: CONTRACT_REVIEW_TIER and **VERDICT: PASS**, check-clause2-carriers.mjs --pair N reads 0 and every check is green. Exactly the fact-layer path, generalised to the tier; the post-merge audit and the director's 职责四 are the compensating control.

Ruling (verbatim, chat 2026-09-18): 「同意改规则。」 on the seat's proposal quoted in the card body, then the amendment 「我觉得这些我也没必要确认:.claude/settings.json、.claude/hooks/**」 — applied as the amendment comment on the card says (Tier H shrinks to the four surfaces; the whole .claude/** tree is Tier S; published skills/** unchanged).

维护者速读(草稿)

改了什么:受管面登记表分成两档。Tier H(法):AGENTS.mdCLAUDE.mddocs/adr/**docs/NORTH-STAR.md、发布的 skills/**,照旧等你的手或授权批准。Tier S:整棵 .claude/**(skills、agents、hooks、settings),席内 CONTRACT_REVIEW_TIER 复核 PASS 记录在案、--pair 读 0、全绿,即由席位走队列落地;事后由受管合并审计抽查。队列守卫按登记表的档位放行或拒绝;--test 判词打印档位与该档的落地条件;AGENTS.md 第 14 条与 SKILL.md/契约复核/核心条款同步改写。

为什么改:你在聊天里说「一直让我点很浪费时间」并「同意改规则」。舰队自己的仪器由舰队按达档复核落地,你只需要确认真正的法。

风险与代价(含回滚):代价是 AI 可以在没有人闸的情况下改自己的操作规则(含 .claude/settings.json 权限集本身——修正评论已点名:自动模式分类器今天仍拒绝 AI 写它,实际写手仍是你的手,本次只免掉那一次批准点击)。补偿控制三件:PR 线程上的达档复核记录、落地后的受管合并审计(Tier S 无 PASS 记录即审计发现)、北极星「仪器为车队服务」评分。回滚:一个 PR,把六行登记表的 tier: GOVERNED_TIER_S 改回 GOVERNED_TIER_H,队列守卫即回到全人合;不需要回滚任何数据。

席位意见:(留空,由席位定稿)

你要做的:本 PR 含 AGENTS.md,属 Tier H——这是 Tier S 这一类的最后一次点击。审阅后给一个 APPROVED review(os-zhuanghotlong),认领席落地。

Register — before / after

id glob before after
adr docs/adr/** governed, human merge / authorized approval Tier H
north-star docs/NORTH-STAR.md (not on the register) Tier H — new exact row; the file itself arrives with #19131's branch (25 lines, docs/NORTH-STAR.md); the predicate is path-only so landing order does not matter
claude-tree .claude/** governed; only .claude/skills/pm-dispatch/references/ landed on a record (REFERENCES_TIER_PREFIX in the queue guard) Tier S — the whole tree; the prefix constant is deleted
skills-catalog skills/** governed, human merge / authorized approval Tier H (unchanged; the seat did not propose moving it)
agents-md AGENTS.md governed Tier H
claude-md CLAUDE.md governed Tier H

Order pin: adr,claude-tree,skills-catalog,agents-md,claude-mdadr,north-star,claude-tree,skills-catalog,agents-md,claude-md. #18489's branch (claude/issue-18489-north-star-enforcement) carried no commits when this was written (its tip is the then-origin/main, 14a762f9f), so line identity with its row could not be measured; whichever lands second merges origin/main first, as the card says.

Exit codes: no new exit constant. Both tiers exit 3 on --test / --pr / --branch (pinned: exit-3-is-SHARED-by-both-tiers…). Every reader of that status asks "may a seat arm this on green alone?" and the answer is no for both; the tier is a second fact and travels in the verdict line and in --json ("tier": "H" | "S" | null), never in the status, so no $? reader learns a new number. Tier H keeps its wording word for word (⛔ GOVERNED — a human merge is the review record for this PR) plus one ⚖️ landing tier: H(人合) line; Tier S prints its own block naming the record-on-thread landing. The NOT-governed exit and wording are untouched.

Self-test floors — before / after (raised or re-keyed, never lowered)

scripts/pm/check-governed-merges.mjs (351 assertions now):

  • the governed predicate: the 2026-08-18 unified list, exactly 8 → 9 (all-five-surfaces-declared-in-order re-keyed to all-six-…; north-star-exact added; three North Star near-misses added to the near-miss list)
  • the dispatch-gates declaration (#9979) 8 → 9 (every-exact-root-row-declares-a-watch-hint re-keyed to separator-less exact rows; a-non-root-exact-row-carries-its-own-separator-and-declares-no-hint added)
  • new battery ⚖️ the two landing tiers (#19133, ruled 2026-09-18) floor 19; SELF_TEST_BATTERY_FLOOR 25 → 26
  • two head-line byte pins re-keyed (5 surfaces, repo-agnostic)(6 surfaces, repo-agnostic)

scripts/pm/check-governed-queue-guard.mjs (261 cases now; 21 batteries unchanged):

  • ⭐ #18020: the references tier — a review of record, not an approval 40 → renamed ⭐ #18020 → #19133 Tier S: a review of record, not an approval 43 (the end-to-end pass for a .claude/agents/os-dev.md + .claude/settings.json PR on a valid record, and its lit control — the same PR with NO record is REFUSED)
  • the pull_request leg is an EARLY WARNING and never reddens 3 → 5 (the warning names Tier S and the record it waits for; names Tier H and the approval)
  • the replay fixtures: the three incidents this guard descends from 9 → 11 (the two .claude/** replays are Tier S today: judged on an ABSENT record they refuse unapproved as before; with NO record reading they refuse unreadable — never clear)
  • the prefix pin ⛔ the-tier-prefix-keeps-its-trailing-slash… re-keyed to ⛔ this-file-spells-NO-tier-prefix-Tier-S-is-the-register-rows-that-carry-S…

scripts/pm/check-governed-prose.mjs: floors unchanged (28 cases); PROSE_SURFACES[0].start anchor moved with the paragraph's first sentence. scripts/pm/check-clause2-carriers.mjs: +1 control (the cross-tool pin's fixture path is Tier S under the register), 942 cases.

Readers of the merges script (PM assumption 3 — every reader, and what changed)

  • scripts/pm/check-governed-queue-guard.mjs — the only ROUTER. Imports GOVERNED_TIER_H/S and governedTierFor from the register at module scope (the register was never mirrored there; the mirrors its docstring names are CONTRACT_REVIEW_LABEL and REVIEW_OF_RECORD_LOCATION, forced by the cycle with check-half-states.mjs). merge_group passes a Tier S PR on the record-of-record predicate, refuses a Tier H PR without an authorized approval as today; pull_request names the tier and what it waits for. TIER_RULES/TIER_REFERENCES/REFERENCES_TIER_PREFIX are gone; TIER_H/TIER_S re-export the register's values; governedTierFor is re-exported, not copied.
  • scripts/pm/check-clause2-carriers.mjs — its self-test built a fixture path from REFERENCES_TIER_PREFIX; re-keyed to a Tier S path literal with a register control. Not a router.
  • scripts/pm/check-governed-prose.mjs — reads the SET of globs; set-based, tiers are attributes (PM assumption 2 confirmed); header note added; not extended to parse tiers.
  • scripts/pm/dispatch-gates.mjs — reads the merges SOURCE for path literals (extractWatchHints), never its exit codes; docs/NORTH-STAR.md is a path literal so a North Star card now derives this gate. No meaning change for Tier H.
  • scripts/pm/check-half-states.mjs — H43/H48 load governedPathsIn and GOVERNED_APPROVERS (membership only; tier-agnostic). Unchanged.
  • scripts/pm/ci-failure.mjs (proxyRearmPlan), scripts/check-skills-token-ratchet.mjs (generatedExceptionFor) — untouched exports.
  • scripts/invoked-as.mjs, scripts/pm/check-skill-line-ratchet.mjs, .github/workflows/lint.yml — comments citing "exit 3 = GOVERNED"; still true for both tiers.
  • .github/workflows/governed-surface-guard.yml — invocation only; not edited.
  • Seat prose reading the printed verdict (landing-operations.md :26, state-machine.md :9, lanes/skills.md :18) — the line now names the tier.

Reader tests, one per tier

  • A seat holding a PASS record on a .claude/agents/os-dev.md PR: --test .claude/agents/os-dev.md prints ⛔ GOVERNED — Tier S(席内达档复核落地): …, exit 3, --json says "tier": "S". The seat runs the three landing checks (record on the current head, --pair 0, every check green), flips ready and arms auto-merge; the merge_group guard reads the record (stands) and prints ✅ CLEARED — … Tier S … satisfied 1 of them; the post-merge audit lists the landing. Without the record the same guard prints ⛔ REFUSED with remedy 3 (post the record on the CURRENT head and re-queue).
  • A seat holding a PASS record on an AGENTS.md PR: --test AGENTS.md prints ⛔ GOVERNED — a human merge is the review record … ⚖️ landing tier: H(人合), exit 3, "tier": "H". The record changes nothing: the seat leaves the PR at the four-piece terminal (draft, request review from both authorized accounts, the 速读 comment, the round report line). Enqueued anyway, the merge_group guard refuses unapproved — the record key is never even read for a Tier H entry; only a GOVERNED_APPROVERS APPROVED review lifts, then the owning seat lands.

Ceilings per file (all at headroom 0, every touched line within the 120-byte cap)

Gates (derived with node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack at d3bb7e0c3; every command run, exit captured redirect-then-$?; --ran reconciliation below)

Every derived command ran green (exit 0) at head d3bb7e0c3, one detached run's exit code pending (below). Highlights, verdict lines as printed:

  • pnpm check:pm-governed-merges :: exit 0 — ✓ check-governed-merges --self-test: 351 assertions …
  • node scripts/pm/check-governed-queue-guard.mjs --self-test :: exit 0 — ✓ check-governed-queue-guard self-test: 261 cases pass …
  • pnpm check:pm-governed-prose :: exit 0 — ✓ check-governed-prose: 2 instruction surface(s) name all 6 registered governed surfaces (docs/adr/** · docs/NORTH-STAR.md · .claude/** · skills/** · AGENTS.md · CLAUDE.md) and claim no others.
  • pnpm check:pm-skill-ratchet :: exit 0 — AGENTS.md 1099 / 1099, SKILL.md 812 / 812, contract-review.md 60 / 60, core-rules.md 151 / 151 (all headroom 0)
  • pnpm check:pm-skill-id-lint :: exit 0 — 27 file(s) clean · pnpm check:skill-frame-sync :: exit 0 · pnpm check:nul-bytes :: exit 0 (8965 files)
  • pnpm check:pm-clause2-carriers :: exit 0 — 942 cases · pnpm check:pm-half-states :: exit 0 — 5043 cases
  • pnpm --filter @objectstack/lint run check:doc-formula-expressions :: exit 0 — after bash scripts/pm/os-verify-lock.sh -c "pnpm --workspace-concurrency=2 --filter '@objectstack/lint...' build" (VERDICT command-exit 0 · held the lock 131s · waited 0s)
  • the remaining 40 derived scripts/check-* / pnpm check:* families :: exit 0 each (full COMMAND :: exit CODE record in the report comment on skills(governed): narrow the human-merge floor to the law — Tier H stays human/approved (AGENTS.md · CLAUDE.md · docs/adr/** · docs/NORTH-STAR.md · .claude/settings.json · .claude/hooks/**); Tier S (.claude/skills/** · .claude/agents/**) lands on the seat's CONTRACT_REVIEW_TIER PASS + post-merge audit #19133)
  • pnpm check:pm-dispatch-gates — exceeds the foreground cap, run detached: verdict lines read ✓ check:pm-dispatch-gates --self-test: the exit contract holds in all three directions. and ✓ dispatch-gates self-test: 1849 cases pass. (654.7 s); the detached start captured no exit code, so a second detached run with exit capture is in flight and its :: exit CODE line lands in the report comment.

--ran reconciliation (node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran RECORD): 50 derived, 49 run, 0 NOT-MEASURED, 1 UNRUN — the one UNRUN is pnpm check:pm-dispatch-gates above, pending its captured exit; the 50/50 reading follows in the report comment.

Acceptance commands from the card: --test .claude/skills/pm-dispatch/SKILL.md prints ⛔ GOVERNED — Tier S(席内达档复核落地): … (exit 3); --test AGENTS.md and --test docs/NORTH-STAR.md print ⛔ GOVERNED — a human merge is the review record … ⚖️ landing tier: H(人合) (exit 3); --test .claude/settings.json .claude/hooks/guard-main-checkout.sh prints Tier S (exit 3); --test scripts/pm/check-governed-merges.mjs prints ✅ NOT governed (exit 0); --test --json .claude/agents/os-dev.md carries "tier": "S".

Not run locally, CI-owned: pnpm lint (repo-wide eslint) and the artifact-roster / wide-population families the reconciliation names as outside this link.

Acceptance notes


Generated by Claude Code

os-dev and others added 2 commits September 18, 2026 22:44
… S (.claude/**) lands on a contract-tier review of record

WIP: register + queue guard + prose + AGENTS.md PD #14 + SKILL.md/contract-review/core-rules twins.

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
…ENT record, six-surface head pins, core-rules line under the byte cap

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF

Copy link
Copy Markdown
Collaborator Author

维护者速读(终稿)· skills 席 · 2026-09-18T23:17Z

这个 PR 做什么:把受管面登记表分成两档,按您 2026-09-18 的裁决「同意改规则。」和补充「我觉得这些我也没必要确认:.claude/settings.json、.claude/hooks/**」。Tier H(法,还是要您的手或一个授权 approve):AGENTS.mdCLAUDE.mddocs/adr/**docs/NORTH-STAR.md、发布的 skills/**。Tier S(席内达档复核落地):整个 .claude/**(skills、agents、hooks、settings)——席位出一份契约档 PASS 复核记录、--pair 为 0、检查全绿,就自己走队列落地,不用您点。成员资格没变:每条路径还是受管、一条命中仍整 PR 分叉;变的只是每条等什么落地。登记表每行带 tier,判定函数只有一处(check-governed-merges.mjs),队列守卫直接引用,没有第二份表。

一个您已接受、我再说一次的风险:.claude/settings.json 是权限集本身,归 Tier S 后由席位自己的复核记录落地,没有您的点击。兜底是合并后审计(每次 Tier S 合并都列出它的记录,没记录就是发现)和总监席的抽查。

顺序:它排在 #19142(北极星写进规则层)之后——两个 PR 都往登记表加 docs/NORTH-STAR.md 那一行、都改 PD #14 那一段。#19142 合了以后这个 PR 再合一次 main 解冲突,我在新 head 上重出记录再落地;您的 approve 给一次就够(裁决 C)。

它落地后我马上做的:#18903 · #19021 · #19033 · #19038 · #19039 五个 Tier S 草稿 PR 已有 PASS 记录,直接落地,不再让您点。遗留:os-dev.md 两行和 landing-operations.md 两行还写着旧的「事实层 = references/」,已立 #19146(p3)在它之后修。

验收:ACCEPT 在 #19133;记录 5737334942;门禁全绿(棘轮 812 / 60 / 151 / 1099 不变、id-lint、governed-prose 6/6、clause2 942、队列守卫自测 261、六条 --test 分档读数全对);CI 21 成功 · 11 跳过 · 2 在跑、0 红(2026-09-18T23:16Z);Fixes #19133Clause-②: no

请您做的一件事:先 approve #19142,再 approve 这个(os-zhuang 或 hotlong 任一);落地都由我做。


Generated by Claude Code

@os-zhuang
os-zhuang marked this pull request as ready for review September 18, 2026 23:34
…the north-star row keeps main's position with its tier; PD #14 keeps the tiered paragraph

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
@os-zhuang
os-zhuang merged commit 1047fe1 into main Sep 18, 2026
30 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-19133-governed-tiers branch September 18, 2026 23:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/l skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants