Skip to content

[PM seat] domain:spec-tooling — 🟢 os-help #6018

Description

@claude

This card is the single authoritative registration for the domain:spec-tooling seat (program card #5163). Index = label:pm:seat; entry point #4604.

Single-writer rule: only the incumbent seat PM edits this body; takeover = edit body + one audit comment. Before taking over: re-fetch the body, audit-comment timestamps arbitrate (first wins), read back after writing.


Current PM

  • GitHub account: os-help⚠️ shared with other active sessions; the account does not identify the seat, the session ID in the claim comment does.
  • Session: session_01KJATVrh6V2ysutYUJigh3B · Took over 2026-08-10T01:2xZ from session_01AZgRyPVwi1jLb1mNNuUQ9o.

⛔ READ FIRST — the skill you just loaded may be STALE (standing condition)

/pm-dispatch loads SKILL.md from the shared checkout (/home/user/objectstack), whose HEAD is set by whatever agent touched it last. Measured stale four separate times today (09:5x, 14:51, 15:5x, 17:0x) — at one point 5 commits / +283−219 behind, and three of those commits changed rules this seat was actively using. Nothing warns you.

git -C /home/user/objectstack log --oneline HEAD..origin/main -- .claude/skills/pm-dispatch/SKILL.md

Non-empty ⇒ read git show origin/main:.claude/skills/pm-dispatch/SKILL.md. Same for references/compile-surfaces.md / references/incidents.md.

Protocol refresh (current as of 2026-08-10 ~17:0xZ)

Ledger (18:0xZ)

Merged: 15 · In flight: 0 · In queue: 0 · Held for decision: 1 · Rework: 0 · Empty dispatch: 0 · Premise falsified: 1

Issue PR State
#7057target:v17 #7173 ✅ MERGED
#7122 #7183 ✅ MERGED — landed lib/dist-freshness.ts
#7088 #7184 ✅ MERGED
#6763 #7180 ✅ MERGED
#7076 #7191 ✅ MERGED
#6635 (record) #7190 ✅ MERGED — Part of, did NOT close the card
#7159 #7228 ✅ MERGED
#6940 #7238 ✅ MERGED
#7217 #7267 ✅ MERGED — visibility-predicate-over-budget
#6957 (adr-anchors half) #7301 ✅ MERGED 123b6c6bf
#7170 #7354 ✅ MERGED 7900527df
#7244 #7376 ✅ MERGED f0ac3e471
#7181 #7421 ✅ MERGED — dist precondition in 3 gates; 2 of 3 PM assumptions falsified
#7442 #7458 ✅ MERGED 45cd354ec — gate table's 4th column; first cloud card
#7220 #7479 ✅ MERGED 333769d86views[] visibility family → runtime-publish, whole family in one edit
#7303 HELD — ruling not executable as written
#6957 (registry half) pm:blocked on #7297 (domain:spec) — ⛔ stays OPEN

Lane pm:queue unassigned: 0 — live at 17:0xZ. ⚠️ Refilled six times this shift. ⛔ Never report from cache.

⚠️ #7217 and #7220 are the same family#7217 added visibility-predicate-over-budget at ~04:xxZ; #7220 (17:5xZ) then had to move six ids, not the four its body names. A card filed against a rule family goes stale the moment that family gains a member. Re-count the family at dispatch time.

⚠️ Open for the maintainer

  1. [finding] content/docs/references/contracts/ 是一个只剩 meta.json 的空目录,build-docs.ts 已不再产出它 #7303 — the ruling's premise does not hold and its action cannot land as written. Ruled "residue — delete" because "build-docs.ts's category table has no contracts entry". Measured: no category table exists (:127 = fs.readdirSync); content/docs/references/** is merge=os-regen (declared generated output); category-title.ts:75 declares the category and resolveCategoryTitles throws on a title with no directory. A delete-only PR reds check:docs; gen:docs restores it byte-for-byte. A = guard the meta.json emit on pages.length > 0 (mirroring build-docs.ts:849) — the delete then happens at the generator, permanently. B = leave the generator, fix the quick-reference row's now-false prose. Premises carry per-line re-check commands on the card (refreshed 15:5xZ); one drifted — packages/spec/src/contracts/ went 82 → 84 files, which strengthens B slightly. Claimed + assigned so no other seat spends a dev on it.
  2. [finding] #6148 的门禁只判 diff,v17 列车已有的 227 条 breaking changeset 从未被比对过 —— 抽样已见 2 条疑似同形漏登记 #6350 — ADR-0087 criterion (A / B recommended / C), denominator 61.
  3. [finding] Gate idea: flag a retired symbol whose retirement issue number appears in SOME but not ALL of its mentions within one file — the partial-update signal that found #6630 mechanically #6635 — recommendation A (close not planned).
  4. Veto windows open: feat(lint): check:doc-formula-expressions reads spec TSDoc @example strings (#6763) #7180's ruling-stretch; refactor(tooling): shard the ADR-anchor registry one file per anchor #7301's no-aggregate deviation.

⚠️ Report to #6015 — a grade whose stated basis is falsified

#7181 was graded observation-class because "all three are check-only — none writes a tracked artifact". False: check-dual-source-exports.ts --update rewrites the tracked baseline, so on a stale dist it launders a wrong ratchet exactly as #7122 did. Fix landed, so re-grading is moot; the point is the reasoning must not be inherited by the next card of this family without checking for an --update-shaped path. ⛔ Reported, not re-graded.

Findings produced this session (unassigned; grading is #6015's)

#7170 (fixed as #7354) · #7181 (unblocked + merged) · #7175 (transferred → PR #7235) · #7297 (transferred) · #7330 (fixed elsewhere) · #7373 (CEL defaultValue stores a raw Date) · #7412 (check-half-states.mjs live sweep unusable in a PM container) · #7465 (gate section ↔ cli.mdx disagree in 3 places).

Scope

Protocol toolchain / gates / generators + docs (#5163). Surface: scripts/**, packages/spec/scripts/**, packages/spec/docs/**, packages/lint/**, content/docs/** (⛔ never content/docs/releases/). ⛔ Never packages/spec/src/**/*.zod.ts or the strictness-ledger counts artifact. ⚠️ The runtime gate's dispatch side is packages/metadata* — another seat's; this lane owns the registry declaration in packages/lint (#7220 measured that declaring is sufficient, so no transfer was needed). devx boundary = #5469.

Operational facts

Standing disciplines

㉔ per-path history before EVERY dispatch · ㉕ disclose scope expansion · ㉖ report after push · ㉗ re-dispatch briefs measure THAT card's residue · ㉙ verify landing by content on a fresh ref · ㉚ a comment contradicting its PR body is a residual defect · ㉛ label provenance guesses as guesses · ㉜ a scanner must prove it can see before any zero is believed · ㉝ premise checks read origin/main · ㉞ never undraft on a webhook alone · ㉟ a positive control must be word-boundary exact · ㊱ a primitive you recommend must be measured against THIS consumer · ㊲ keep PM guesses out of the ruling block · ㊳ resolving a blocker is not dispatching the card · ㊴ "queue drained" has a shelf life of minutes · ㊵ name the obvious wrong fix and the dev builds the test for it · ㊶ line anchors go stale — anchor on text.

㊷ — a card can supply the fix and still never have measured it. Make the fix's own probe the accept bar (#7244).

㊸ — before dispatching ANY "delete this residue" card, establish WHO WRITES THE FILE. grep os-regen .gitattributes + run the generator. #7303 went four honest readings deep on one wrongly-scoped grep. Correct grep output from the wrong file reads exactly like proof.

㊹ — never wait on a background timer for CI; poll and report. Also protocol (#6644 L2).

㊺ — pm:blocked without a body Blocked-by: is a card parked with no exit. Unlock scan has two criteria: ① has the line ⇒ check upstream, then re-verify the file face on the merged ref; ② has none ⇒ that is itself the anomaly. ⚠️ And check the upstream rather than trusting a cached line#7220's blocker #4717 had closed six hours before anything said so; the standby criterion that said "re-verify rather than trust" is what turned a quiet standby into round 10.

㊻ — a card's SEVERITY GRADE rests on premises as falsifiable as its defect claim. When a grade is argued, put its load-bearing premise into the dispatch as a PM 机制假设 (#7181).

㊼ — a comment sitting next to the code is not a reading of the code, and the ones inside the file you are auditing are the most dangerous. #7442: runtime-gate.ts's own header comment listed a rule among those running on a flow snapshot; that rule never reads stack.flows — probed, zero errors. #7220 produced two more instances in one hour: my own grep returned runtimeTypes: ['permission_set'/'sharing_rule'] that live inside surfaceReason prose strings (\' escaping the only tell), and the dev found validateVisibilityPredicates carrying RUNTIME_NEEDS_FULL_SNAPSHOT — a reason describing nothing true about it, "the reason a rule got when nobody measured". ⇒ In a registry of self-describing entries, the descriptions are the least trustworthy field.

㊽ (new) — a card filed against a rule FAMILY goes stale the moment the family gains a member. #7220's body names four views[] visibility-predicate rules; by dispatch time the family was six ids across two registry entriesvisibility-predicate-over-budget had been added by this same lane (#7217) hours earlier. The dev counted them rather than trusting the body, and flagged why the sixth carried no partial-enforcement risk. ⇒ For any "move/retire/audit this family" card, re-enumerate the family at dispatch time and put the count in the brief; a family card that moves N−1 members is the exact defect such cards exist to prevent.

Environment

Fresh container. In-flight zero at 18:0xZ (wave-close point). Standby cadence. ⛔ Every other entry in list_triggers belongs to another seat.

Metadata

Metadata

Assignees

Labels

pm:seatPM seat registry issue - single-writer body, index = this label

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions