docs(agents): split the ruleset bullet, and date the governed guard's enrolment as a required context (objectui#9520) - #10984
Conversation
…equired checks readable (objectui#9520) The AGENTS.md ruleset bullet said both halves of its parenthetical -- who may bypass, and the required-checks list -- cannot be read from the repository. Re-measured: the bypass-actors roster is not returned to a seat's token (the ruleset answers with current_user_can_bypass and no bypass_actors key; a ruleset id that does not exist answers 404), while the required-checks list is read by scripts/check-required-check-set.mjs, which the scheduled patrol runs. The bullet now keeps its unreadable claim on the bypass half only and points the required-checks half at the live reader, naming the package script as the offline self-test it is. No membership is written down. The gate's inventory docblock and its pin are brought into line: the carrier objectui#9502 left standing is recorded as split, and the LEFT_STANDING control is renamed SPLIT_CARRIER with its comments re-described. The detector and every assertion are unchanged. Claude-Session: https://claude.ai/code/session_01EBx9rvB7dufCz4at53x35U Co-authored-by: Claude <noreply@anthropic.com>
|
changeset-claim-re-read
|
Claude-Session: https://claude.ai/code/session_01EBx9rvB7dufCz4at53x35U Co-authored-by: Claude <noreply@anthropic.com>
…-- say so as dated history (objectui#9520) The governed-surface paragraph still said the Governed Surface Queue Guard is not a required context and that its merge_group refusal only reports. Re-measured: GET /rules/branches/main lists the context among main's required checks (a branch no ruleset targets answers []), the committed 2026-09-14 reading did not, the ruleset was last edited on 2026-09-27 three minutes before objectui#6596 closed completed, and the workflow's merge_group job carries exactly that check name. Only the clauses the enrolment made false are rewritten: the opening summary, the "not yet required" warning (now dated history pointing at node scripts/check-required-check-set.mjs for current membership), the "likewise blocks nothing" comparison, and the "nothing will stop you" consequence (the queue now stops an unapproved governed PR; approval itself and ruleset bypass still rest on the rule). The advisory pull_request leg, green-is-not-ungoverned, the label-not-path criterion and exit 6 / exit 7 are kept. It also says the blocking is derived from configuration: every merge_group run since the enrolment passed, so no refusal has been observed yet. Claude-Session: https://claude.ai/code/session_01EBx9rvB7dufCz4at53x35U Co-authored-by: Claude <noreply@anthropic.com>
|
Standing down on one red check. It is not this PR's.
Generated by Claude Code |
Contract reviewServed-tier: Rendered at 2026-09-28T13:51Z. Inputs read: card #9520 (body and all five comments, including REWORK 5870779809 and both ① Derived judgmentsAccept set and public surface: no change implied by the diff. The three files are root Ruleset bullet (
Governed-surface paragraph (
Still-true warnings lost: none. Dropped, each because the enrolment made it false or stale: 「别读成一道拦得住的门」, 「 Membership restated as a standing fact: no. The bullet writes no membership; the paragraph writes one name's enrolment as dated history with the reader named for the present. Other
House rules on the diff: no cross-file Check-runs on the head (their conclusions, not re-run): 39 check-runs. First read 2026-09-28T13:39Z with ten still in progress; converged by 2026-09-28T13:45Z: 35 ② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
维护者速读(终稿)席位 改了什么:根
另外同步了 为什么改:按原文行事的 agent 会以为 required 清单无从核实、只能靠推断,或者以为挂 风险与代价(含回滚):只改说明文字与注释,不改任何门禁判定或 ruleset。唯一的「推断」处已写明是按配置推出、尚未实际观察到拦截。回滚:revert 这个 squash commit。 席位意见:建议批准。有三点请知悉:
你要做的:读一下 Generated by Claude Code |
…eset-readable-half Claude-Session: https://claude.ai/code/session_01EBx9rvB7dufCz4at53x35U Co-authored-by: Claude <noreply@anthropic.com>
Fixes #9520
Clause-②: no —
AGENTS.mdis an agent-facing convention, not a published contract, accept set or public surface维护者速读(草稿)
改了什么
根
AGENTS.md两处,都是「ruleset 设置变了、文字没跟上」的同一类问题:node scripts/check-required-check-set.mjs,清单本身照旧不抄进来。scripts/check-required-check-set.mjs的文档块和它的测试里「这条被刻意留着没修」的描述同步改成「finding(ci): FOUR places in the tree tell authors the four shard jobs are NOT required checks — all were true when written and are FALSE today, and acting on any one blocks every pull request in the repository #9502 留下、docs(agents): AGENTS.md:338 says the ruleset is 从仓内读不到 — measured HALF TRUE, and false on therequired checks 清单half it names alongside bypass actors #9520 拆开」,没有逻辑或断言改动。Governed Surface Queue Guard还不是 required context,拒绝只报告、不拦队列,「没有任何东西会替你拦下」。实测它已进了 required 集合(2026-09-27,objectui#6596 当天关闭),所以只改了这几处被这次登记变假的句子:改成有日期的历史,现状指向读取脚本,并写明「拦得住」是按配置推出的、登记后还没观察到一次真正的拒绝。仍然成立的警告一句没动:PR 上的绿不等于不受管、判据读 label 不读路径、exit 6 / exit 7。为什么改
两处都是照着做就会出错的受管文字。第一处让 agent 以为 required 清单无从核实,只能凭推断。第二处让 agent 以为受管 PR 进了队列也不会被拦,而现在队列会拦,只是「批准是不是人按的」依然没人替你拦。另外实测发现,卡片建议的指针
pnpm check:required-check-set是离线自测、不读线上,新句子点明了这一点。风险与代价(含回滚)
只改说明文字和注释,不改任何行为、门禁判定或 ruleset;
WATCHED_CONTEXTS与scripts/dependabot-merge-gate.mjs按指示未动。风险在于措辞是否准确,每一句都附了可复测的读数与对照(见下文)。回滚:revert 这个 squash commit,文件一起回到原样,测试前后都是绿的。席位意见
你要做的
审阅
AGENTS.md的两段新措辞:ruleset 那一条,和受管面那一段里以「本仓的机械兜底只有一件」开头、以「第五条禁令的效力」收尾的几句。同意就留一条 approve;按受管面规则,之后由认领席落地。What changed
AGENTS.md, ruleset bullet (round 1)node scripts/check-required-check-set.mjs, namingpnpm check:required-check-setas the offline self-test it is. No membership is written.AGENTS.md, governed-surface paragraph (round 2)scripts/check-required-check-set.mjs(round 1)scripts/__tests__/check-required-check-set.test.ts(round 1)LEFT_STANDINGis renamedSPLIT_CARRIER, and comments, the Leg 2 message and one test title are re-described. Every assertion and theCANNOT_READdetector are unchanged in logic.Round 1: the ruleset bullet (measured on
09d44d0d6b, accepted by the seat unchanged)GET /repos/objectstack-ai/objectui/rulesets/11776024answers 200 with nobypass_actorskey andcurrent_user_can_bypass: never, which says "can I", never "who can". CONTROL:GET …/rulesets/99999999answers 404.git grep -E 'bypass_actors|current_user_can_bypass'hits only the docblock lines this PR adds, so nothing re-derives it.GET …/rules/branches/mainanswers 200 with the required contexts. CONTROL: a branch no ruleset targets answers200 []. The tree's reader exits 0, and the patrol's scheduled runs all succeed.pnpm check:required-check-setis--self-test(offline), not a reader, which is why the bullet points at the bare script.AGENTS.mdstays out ofREPAIREDand remains Leg 2's real-content control, because 「从仓内读不到」 now sits only where it is true. Proof A (AGENTS.mdadded toREPAIRED) gave exactly 1 red,AGENTS.md makes no "cannot be read" claim; passing it would need a paraphrase that weakens the detector. Proof B (the phrase removed from the bypass half) gave exactly 1 red, the CONTROL case. Both were one-shot runs through../objectstack'sscripts/ablation-replace.mjs, restore proven by blob hash; Proof A's first attempt was a no-op (the anchor was contained in its replacement) and was re-run.Round 2: the governed-surface paragraph (measured 2026-09-28 13:28Z, each with its control)
Clauses rewritten, because the enrolment made them false:
merge_groupblocks the merge queue (since 2026-09-27, see below) andpull_requestonly warns.node scripts/check-required-check-set.mjs, with ⛔ do not copy its answer. It also says this is derived from configuration and not observed (see the last measurement).Kept word for word, still true: the
pull_requestleg is advisory and exits 0 on purpose, green is not the same as not governed, the approval criterion and its accepted cost, the second criterion reads the label and no path (exit 6, exit 7),pull_requestdoes not read labels, and the closing "not a complete list" warning.Measurements behind the rewritten clauses:
GET /repos/objectstack-ai/objectui/rules/branches/mainanswers 200 with rule typesdeletion · non_fast_forward · merge_queue · pull_request · required_status_checks. The required list containsGoverned Surface Queue Guardwithintegration_id15368 (GitHub Actions). CONTROL: the near-miss nameGoverned Surface Queue Guardxis absent;GET …/rules/branches/zzz-no-such-branch-9520-r2answers200 [].scripts/__tests__/fixtures/required-check-set/live-2026-09-14.json, holds 9 contexts, none of them this one.GET …/rulesets/11776024givesupdated_at2026-09-27T03:09:16Z (served as 11:09:16+08:00), enforcementactive.GET …/issues/6596reads closed / completed at 2026-09-27T03:12:42Z. CONTROL:GET …/issues/9520reads open..github/workflows/governed-surface-guard.ymlat HEAD has triggerspull_requestandmerge_group, and its one job'sname:is exactlyGoverned Surface Queue Guard, the context the ruleset requires. CONTROL: ascheduletrigger reads absent.scripts/check-governed-queue-guard.mjshasEXIT_REFUSED_CARRIER = 6andEXIT_REFUSED_CARRIER_UNREADABLE = 7, andneeds:contract-reviewis present, so the kept exit 6 / exit 7 text is still true.CODEOWNERSamong tracked files (CONTROL:.github/workflows/ci.ymlis found by the same listing), and.claude/hooks/holds only the main-checkout, shared-stash and tree-enum guards.GET /actions/workflows/governed-surface-guard.yml/runs?event=merge_group, created on or after 2026-09-27T03:09Z, givestotal_count165. Both pages were read (100 + 65 = 165 distinct), allcompleted/success, earliest 2026-09-27T03:24:52Z. The check runs on every merge group since the edit, and no refusal has been observed, so "blocks the queue" rests on the configuration, and the new text says so. (The patrol's job logs, which would pin the day more tightly, are served from a blob host this container's egress refuses.)AGENTS.md. The round-1 docblock and test descriptions ("stays on the bypass-actors half alone") stay true.Gates (round 2, all on
cdb89afa4a, exit captured before any pipe)check-required-check-set,check-installed-spec-pin-claims,check-shell-escape-residue,check-doc-links,dollar-dialect-alias-census,ci-cd-pipeline-doc):Test Files 6 passed (6),Tests 345 passed (345), lockVERDICT command-exit 0. TheAGENTS.mdreader ledger (node scripts/markdown-test-inputs.mjs --list) was re-derived after the merge and is unchanged.pnpm check:required-check-set: exit 0, "32 cases pass".pnpm check:control-bytes: exit 0.pnpm check:new-line-citations: exit 0, 0 new citations.pnpm check:shell-escape-residue: exit 0.pnpm check:installed-pin-claims: exit 0.pnpm check:test-path-roots: exit 0.node scripts/check-doc-links.mjs: exit 0, "Links are valid across 17 scan roots."node scripts/check-changeset-presence.mjs: exit 0, "no changeset is owed" (3 files, 0 published source).pnpm lint:root: exit 0, with 0 errors and 34 warnings, none in the changed files.node scripts/check-governed-queue-guard.mjs --test AGENTS.md: exit 3, "⛔ GOVERNED — 1 of 1 path(s)" (expected; this PR stays a draft).Branch history:
09d44d0d6b(round 1), a merge ofmainat42687baf20(no conflict, none of these files), thencdb89afa4a(round 2). No force-push.Acceptance notes
content/docs/guide/ci-cd-pipeline.md("Until it is flipped, the queue leg reports without stopping anything") and the header ofscripts/check-governed-queue-guard.mjs("Until the live required set carries the same name, this guard REPORTS…"). Neither yet says the flip happened.WATCHED_CONTEXTSinscripts/check-required-check-set.mjsdoes not listGoverned Surface Queue Guard, so the daily patrol reports DRIFTED (by design, exit 0). Left alone on purpose: that list moves by a ruling-cited change of its own.content/docs/guide/ci-cd-pipeline.md's sentence that the gate's docblock inventories "the one deliberately left alone and why" stays true, because the docblock keeps that history.Drafted in session
https://claude.ai/code/session_01EBx9rvB7dufCz4at53x35U.Generated by Claude Code