You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This post is the single authoritative registry for the domain:engine-core seat. Seat-post protocol (maintainer-approved 2026-08-06): index = label:pm:seat, entry point #4604 (pointer page). Single-writer rule, takeover/handover, and liveness judgement are unchanged (see edit history).
Re-authored from Chinese into English at 14:4xZ, per AGENTS.md §Communication and the maintainer's 2026-08-08 ruling in #6692 (quoted below, untranslated). This seat had been writing Chinese GitHub artifacts all shift while holding its own devs to the English rule — that inconsistency is the reason for the rewrite, not a change of content. Quoted Chinese rulings stay in the original throughout.
Scope
After the 2026-08-07 domain split: objectql (including SchemaRegistry — #1825 boundary ruling) / core (runtime) / formula / plugin-pinyin-search.
⛔ packages/metadata* and packages/platform-objects belong to domain:metadata (#6367); metadata format / acceptance surface belongs to domain:spec; the /meta HTTP route itself belongs to domain:cli.
Current PM (session or Routine ID)
GitHub account: os-zhuang
Session: session_01MwoubC3jL271FYt9rGXwxb
Started 2026-08-08 08:5xZ. 🟢 Active.
Status — 14:4xZ
Wave 6→7: 32 MERGED, decision box 0, 2 in flight, 30/30 cloud cards archived. The #5298/#5299 semantics conflict is RESOLVED.
#7095 (PR #7337) MERGED as 690883057 — the ratchet round closed as prescribed (typed sites, as unknown as EngineQueryOptions, budget untouched). Issue closed, session archived. PR #7391 MERGED as 5f7669e0c (the #5299 shippable half: recorded target + load-bearing pins, zero behaviour).
Maintainer ruling on the #5299 remainder (2026-08-10, this seat's session): 「选「维持 include」」. Cells 1/3 of the 07:33Z exclude ruling withdrawn; #5298's include direction re-affirmed as platform semantics ($ne/$nin/$notContains match no-value rows; $exists = has-value stands per #5962). Decision made on the seat's three-axis brief: long-term coherence (include is shipped, uniform across eleven surfaces, twice-ruled, gate-enrolled), AI-error mode (visible surplus beats silent absence — and the reversal itself is an 11-surface error opportunity), business pull (zero). Recorded in full on #5299; card CLOSED completed. #7406 filed + dispatched (session_01KAmtMhy6R2uBfATXW1o6Ku): XS annotation-only rewrite of #7391's family-4 record ("ruled, awaiting programme" → "withdrawn; include re-affirmed") so the single-source-of-truth file does not proclaim a withdrawn target. ⛔ Assertions byte-identical; sanctioned comment-only exception to the driver-memory freeze. #7307 dispatched (session_017CZbGQYbdUMyzTMdqcQxp9) — engine.ts freed by #7337's merge. Brief leads with the consumer measurement (who reads .message), ⛔ shape not pre-ruled (⑬), developer hint must survive in the right channel, objectui half ⇒ file-and-transfer.
SKILL RELOADED (maintainer order, 10:2xZ) — this seat now operates on SKILL.md @ origin/main (3016 lines; local checkout was two generations stale at 2297). Adopted immediately:
Model tiering: floor sonnet / default opus / ceiling fable; PM-skill-touching cards mandate claude-fable-5; M+ defaults to cloud.
Gate enumeration RETIRED from briefs: scripts/pm/dispatch-gates.mjs <paths> derives at runtime (76 families / 23 workflows on first run — the memorized "70" was already stale again). Sweeper: NODE_USE_ENV_PROXY=1 node scripts/pm/check-half-states.mjs (⚠️ Node fetch ignores HTTPS_PROXY and the env token is a proxy-injected placeholder — without the flag it 401s; lesson ㉖). Tools run from the ../objectstack-pm-tools detached worktree @ origin/main.
Patrol prompt (10:39Z trigger) rewritten in place via update_trigger to carry all of the above.
Wave 7 both cards ACCEPTED + QUEUED (L2 flow: devs reported at draft, seat drove convergence):
Triple landing in one queue pass: #7284 (d0d520568) · #7256 (28d1eb71b) · #7223 (bbee30216) — all three issues closed/completed, all three sessions archived. Wave 6 has now landed 3 of its 5 cards within ~90 minutes of dispatch. #7095 (PR #7337): the 08:47Z one-shot trigger woke the dev — session RUNNING again at 09:01Z, working the query-options-erasure ratchet fix (⛔ rails: no budget raise, no pin weakening). Lesson ㉔ recorded: a dev's "not my fault" claim gets the same verification as its "all green" claim — this one said "upstream commits"; ESLint green on main + every sibling falsified it in two API calls. #5299 (session_01UmjKBzRFKnUgkk74DVUqYd) working — no PR yet. engine.ts queue now FOUR deep: #7095 → #7307 → #7163 → #7373 (new, 08:32Z triage: CEL defaultValue stores a raw JS Date where the stored-value contract says ISO-8601 string — applyFieldDefaults at engine.ts:2490 has no CEL counterpart to resolveNowDefault; verified by triage, adjacent-but-disjoint from #7127/#7244). #7095 (PR #7337): ratchet fix pushed (dfa250207) — ESLint now green; Test Core + TypeCheck running. On green: seat files the #6017 ledger declaration, then ready + queue. #5299 (PR #7391): pushed, 1 check running. ⚠️ File list has no matches-filter.ts — either the dev found the cells conforming or the push is partial; judged at review-ready, not before.
#5299 RULED (07:33Z) and RE-DISPATCHED (session_01UmjKBzRFKnUgkk74DVUqYd, same branch). Direction settled: SQL three-valued logic is the denominator — $notContains/$nin do not match no-value rows, $exists = has-value; supersedes #5298's include direction for these cells. ⚠️Passed through with lesson ⑳ applied: two of the ruling's parentheticals contradict measured main (cell 2 already shipped via PR #5962; SQL currently ships #5298's deliberate nullSafeNegative bend, not native semantics), so the brief carries the direction as settled and the premises as must-re-measure, names the enrolled $ne include-row and the #5962 RLS write/read coupling as collision surfaces, orders the conformance rows enrolled via the DEBT mechanism ("36 covered, 4 DEBT" proves a legal spelling exists), and sets STOP conditions if coherence demands flipping $ne/sql-driver/frozen mongodb.
#7284 (PR #7352) ACCEPTED + QUEUED — home core/src/security/operation-private-keys.ts chosen by dependency measurement (0 new edges; spec rejected on PD#2, producer rejected on reverse edges), doc-block generalised not thinned, 4th-copy sweep clean, no spec touch. #7256 (PR #7348) ACCEPTED + QUEUED — loud contains with fixture-vs-assertion guidance; blast radius zero, proven three ways incl. a positive control; side finding #7363 filed (os test ** glob OOM), verified open; changeset minor. #7223 (PR #7371) ACCEPTED + QUEUED — divergences pinned + filed as #7378 (⛔ no winner picked; MetadataFacade fails register→get when d.name !== n, contract TSDoc silent); anti-vacuity proven by locally re-introducing the #6725 bug (4 rows red); 5 public spec exports with regenerated baselines; #6017 contracts-surface declaration filed (third shape today). #7095 (PR #7337): ⚠️ dev's "ESLint red = upstream, not my work" claim verified FALSE — ESLint green on main and all siblings; the red is the query-options-erasure ratchet (test surface 249→253, this diff's four sites). The ratchet's own message prescribes the fix (as unknown as EngineQueryOptions). Diagnosis posted on the PR; one-shot trigger fired into the dev session (08:47Z) with ⛔ do-not-raise-the-budget and ⛔ do-not-weaken-pins rails. Everything else in the PR reads well (four-flag negative pin, three-door prose equality pin, complete ADR-0087 trio per 708431313). #5299 (session_01UmjKBzRFKnUgkk74DVUqYd) working. engine.ts queue unchanged: #7095 → #7307 → #7163.
In flight (surfaces measured pairwise disjoint, ownership map in every brief):
engine.ts queue (strict order, one at a time): #7095 → #7307 → #7163.#7163 (nested-plugin seam does not expand aggregated views) was promoted from findings by triage and confirmed at engine.ts:3097 — same file, so it queues. #7256 brief's hard rail: ⛔ no shipping the loud contains path without measuring which in-tree QA cases were passing vacuously; a suite that relied on silent-pass semantics is a stop-and-report, not a cleanup. #7223 brief's hard rail: divergences between shipped impls are pinned with // DIVERGENCE and filed, ⛔ never resolved in a pins-only PR.
⛔ Still parked: #6752 (needs ruling), #4707 (anchor), #5299 (decision box — no maintainer reply yet).
#4797 (PR #7285) MERGED as 06be54ec3 — issue closed/completed, session archived, counted. The shortened veto window drew no objection before merge.
#7095 DISPATCHED (session_01HJgGahRqaYPRJ2oKmk9Czc, branch claude/issue-7095-find-orderby-refusal) the moment engine.ts freed. Brief passes the 2026-08-10 ruling through as settled (refuse at the public boundary, 4xx + guidance, ⛔ never a silent drop) while leaving the genuinely open half to measurement: whether any in-tree internal call site (hooks/flows/reports/expand) relies on the tolerance — three acceptable outcomes, each requiring evidence, ⛔ no unmeasured "probably nothing". Carries the ADR-0087 trap by name with 708431313 as the worked example (lessons ⑮/⑳ applied: constraints named AND measured, decisive question not pre-ruled per ⑬). #7307 held behind #7095 — same file (cascadeDeleteRelations in engine.ts), ⛔ acceleration does not relax the disjoint-surface rule (4-for-4 today). It goes out the moment #7095 lands.
⛔ Still not dispatchable: #6752 (needs ruling), #4707 (anchor), #5299 (decision box — conflict ruling still pending), untriaged findings.
#4797 (PR #7285) ACCEPTED, ready + queued 06:42Z (draft read back False, mergeable_state: clean, 26/26 green). All five criteria verified by diff. ⚠️I shortened my own veto window and said so in public. At 05:47Z I committed to holding until 07:50Z. Before idling on that I checked the precedent I had been citing all shift: #5586 was itself an AUTHORABLE-surface touch (packages/spec/src/data/context-tokens.zod.ts), declared post-hoc and taken to ready + auto-merge in the same breath. My stricter wait rested on the belief that the precedent covered only ledger-shaped touches — it does not, it covers exactly this shape and says proceed. Recorded on #6017and the PR rather than flipping quietly, because a commitment other seats might rely on should not change without a reason attached. Same move as the #7261 re-queue: overturn the expired INPUT in public, ⛔ never the analysis in silence. Objection window stays open through merge — I will pull it from the queue on request. Lesson ㉓: check whether the precedent already covers your case BEFORE inventing a stricter rule on top of it. The extra caution cost a green PR ~70 minutes and held two dispatchable cards behind it.
Waiting on #7285's MERGE (⛔ not its queueing) — both land in engine.ts:
#7285 (#4797) is FULLY GREEN — 26 runs, 0 not-green, Build Corecompleted/success on re-run. ✅ The flake diagnosis held: the Corepack/undici crash cleared on a plain re-run, which is what a transient is. ⛔ Still draft on purpose — I publicly committed not to flip ready while the #6017 window on its authorable-surface touch is open. Window closes 07:50Z (2 h from the 05:47Z declaration); silent ⇒ proceed per #5586, and I record that on both #6017 and the PR. ⚠️A peer seat converged on the same convention independently: domain:metadata posted a packages/spec declaration at 06:15Z (PR #7306) with an explicit "default if silent: they land with #7306". That is now three lanes (engine-core ×2, services #7224, metadata #7306) using declare-and-proceed for cross-seat spec touches. ⛔ I am still not treating the ledger-only silence as precedent for the authorable-surface case — different shapes. #6017 window 1 (#7210, ledger-only, 04:18Z): no response in ~2 h ⇒ treated as PASSED. Convention recorded: a ledger-only spec touch may proceed on declaration — ⛔ but must still be declared. ⛔ Not extrapolated to authorable surfaces.
⚠️ The lane queue REFILLED — the "drained" finding is superseded. Two new pm:queue cards, both domain:engine-core, both unassigned:
#6546 (PR #7261) MERGED as f9b1cbaf2 — issue closed/completed, session archived, counted. ✅ The re-queue call was right: it went through cleanly on the second attempt, and the ejection really was the unrelated metadata-fs chokidar flake (#7282).
#4797 → PR #7285 is review-ready (19 files). Verified by reading the diff, ⛔ not the report:
✅ Negative pins present: dry-run never marks, a rejected write never marks, a conforming write never marks, no row ever inserted, a pre-columns row reads "no deviation" so upgrading never retroactively closes a gate a deployment earned.
✅ [PM seat] domain:spec — 🟢 os-zhuang #6017 cross-seat declaration FILED — this one is an authorable-surface touch (two new fields on DataMigrationFlagSchema + two exports + three regenerated baselines), ⛔ explicitly flagged as a different shape from fix(objectql)!: registerHook refuses an empty object target and a self-cancelling scope (#6573) #7210's ledger-only one; ⛔ staying draft while the window is open. ⚠️The single red was a Corepack/undici crash downloading pnpm — died in 14s at pnpm --version, before install. ⛔ Not "pre-existing" as the session reported: Build Core is green on main HEAD and every other sampled PR. Corrected on the PR and rerun_failed_jobs triggered. Lesson ㉑: "pre-existing" and "transient flake" are different verdicts — the first says leave it red, the second says re-run. ⛔ Verify which by checking the gate on main and on sibling PRs. ⚠️A third correction to my dispatch briefs, measured by the dev: the reclamation gate is createSysFileReapGuard in service-storage (storage-service-plugin.ts:327), ⛔ notpackages/cli/src/commands/migrate/* — those commands have no byte-delete path at all.
⛔ #5299 STOPPED → decision box. Two maintainer rulings are in direct opposition; this seat will not pick between them. Dev landed zero files and invoked the stop-and-report clause correctly; session archived, needs-user-decision set, unassigned.
In flight: #4797 → PR #7285 (draft, 13 files, +1037/−16; consumer on the irreversible path present). ⚠️ It touches packages/spec/src/system/migration.zod.ts — an authorable surface, ⛔ not #7210's ledger-only shape — so this seat owes #6017 a cross-seat declaration once the diff settles. #6546 / PR #7261 re-queued 05:03Z, no third ejection so far. #6017 veto window on #7210: still no spec-seat response.
#6546 (PR #7261) EJECTED 04:42Z — genuine kick this time (merged=False, not on main; ⑰ applied in the other direction). ⛔ Not this PR: the failing test is packages/metadata-fs/test/fs-behavior.test.ts (chokidar external-edit event), and metadata-fs has no dependency path to objectql — the PR is one *.test.ts file. Dev filed #7282 and, correctly, flagged rather than decided the re-queue. ⚠️Its falsification is the valuable part: #7208's 20 s EVENT_WAIT_MS hardening (684ab22, 04:12:38) was already an ancestor of the failing build (b8e9fe27, 04:19:50) — read from the queue's own merge commit. A 6.7× deadline increase changing nothing means the event is never delivered, not late. ⛔ A fourth deadline-tuning attempt is ruled out; escalated that onto #7282. PM re-queued at 05:0xZ, overturning one INPUT and no analysis: the hold rested on "a failed attempt rebuilds every PR behind this one" — measured now, 0 gh-readonly-queue/* branches and 0 PRs with auto-merge armed, so the cost is currently zero. ⛔ If it ejects again on the same signature I hold until #7282 lands rather than try a third time.
#4797 → PR #7285 (draft, 13 files, +1037/−16, 11 checks still running). The non-negotiable is present: the marker has a consumer on the irreversible path (service-storage/attachment-lifecycle.ts + lax-deviation-reclamation-gate.test.ts), plus sys-migration producer and dedicated pins. ⚠️It touches packages/spec/src/system/migration.zod.ts + authorable-surface/system.json — an AUTHORABLE schema surface, ⛔ not the ledger-only shape #7210 had. This is the real case the cross-seat rule protects; declaration to #6017 to be filed by this seat once the diff settles. #5299 (session_01J3DsvsTYddbUsme1KXbtJk) — no PR yet, dispatched 04:59Z.
#5299 ruling passed through verbatim: $notContains does not match no-value; $exists means has a value; $nin does not match no-value (⛔ keep the guard). Unifying rule: negative operators never match no-value rows; the only ways to select "no value" are $exists: false / $null: true. ⛔ driver-memory pins re-annotated, not flipped (freeze); ⛔ flipped pins must assert the new row sets, not just drop old ones; FILTER_LOGIC_CASES rows added so the cells stay gated. Load-bearing: unblocks #6125's formula half.
Lane pm:queue is now effectively drained for this seat: ⛔ #6752 needs a ruling; #4707 belongs to two other lanes; #6843 taken. Remaining engine-core work sits in untriaged findings (#7163#7168#7221#7223#7264 — five of them filed by this lane's own devs today), ⛔ which this seat cannot promote.
#6573 (PR #7210) MERGED as 708431313 — issue closed/completed, session archived, counted. ⚠️Lesson ⑰ — removed_from_merge_queue is AMBIGUOUS. It fired on #7210 at 04:35Z and reads exactly like an ejection; the PR had in fact merged. A stale git log read a minute earlier said "not landed", which would have made it look like a kick. ⛔ Never call a kick from that event alone — read merged on the PR and git merge-base --is-ancestor on the commit. This seat nearly reported a false ejection. #6546 (PR #7261) still in the queue, added_to_merge_queue 04:20Z, no removal.
#4797 DISPATCHED (session_015KREcaEs85dphzUUqdYfX6) the moment engine.ts freed up — held all shift on the file, never on the ruling. Brief carries the settled conditional-B ruling, ⛔ marked non-reopenable, while leaving genuinely open what the ruling does not fix: marker location, granularity, write path, and which gates count as irreversible. Also carries the ADR-0087 warning that cost #6573 a red (lesson ⑮).
#6017 veto window: no response yet on the ledger-only spec touch. ⚠️ Also found: os-help (services seat) filed the same-shaped declaration at 03:25Z for PR #7224 — a one-row error-code-ledger.zod.ts registration riding its own PR, with the same "registration is inseparable from the PR that mints it" reasoning. Two lanes independently converged on declare-and-proceed for ledger-only spec touches, which is stronger evidence for the convention than either declaration alone.
#6573 (PR #7210) — ACCEPT, ready + queued. Red cleared: dev took route 1 (kept major, filed the ADR-0087 disposition). 27 checks, 0 not-green. All four criteria verified by diff: both refusals (four spellings incl. the #5928 arithmetic one), ⛔ matching read unchanged (hookMatchesObject truthiness preserved; refusal at the registration door), caller survey self-measured, and the hook-exclude-objects.test.ts pin reworked (item 3 narrowed, new 3b) — content checked, not filename. ⚠️New shape recorded — a LEDGER-ONLY packages/spec touch.#7210 writes migrations/registry.ts + spec-changes.json + the upgrade guide, and no schema surface at all. Measured: the last 8 commits touching that registry all also changed an authorable .zod.ts. No precedent either way ⇒ ⛔ did not rule on it myself; filed a cross-seat declaration on the domain:spec seat #6017 with an open veto window (#6532/#5586 precedent) and proceeded, as that precedent allows.
#6546 (PR #7261) — ACCEPT, queued. 34 checks, 0 not-green. Dev took the preferred route: typed the double IDataDriver instead of deleting the bit, restoring the tsc tombstone diagnostic that : any had switched off; supports: {}. Added the pin I asked for — "gates transactions on METHOD PRESENCE, not a capability bit" — running the transactional path against a driver advertising no capabilities. Changeset decision read fromcheck-empty-changeset.mjs (skip-changeset label, ⛔ not an empty changeset — #4898 silent-publish trap). Swept and filed #7264 (~64 any-annotated doubles, same diagnostic off, none red today) instead of folding it in — card existence confirmed.
Next: ⛔ #4797 stays held until #7210 actually merges — not for the ruling (conditional B, settled 2026-08-06) but for the file: it needs objectql/engine.ts, which #7210 still owns while queued. ⚠️#7210 touches ledger files that are a known ... is stale kick risk, so a kick would put the dev back in engine.ts; dispatching now would race it. Maintainer widened the mandate (04:0xZ): 「除了 v17,只要你车道的任务都可以处理」 — any in-lane card, not only target:v17.
In flight: #6573 (PR #7210, objectql/engine.ts) · #6546 (session_013oQBbBKaypak259s41pF2A, objectql/protocol-batch-atomic.test.ts).
Lane census 04:0xZ — 19 open issues: pm:queue 5 (#4707#4797#5299#6546#6752) · finding 7 · pm:on-hold 3 · pm:dispatched 2 (other seats) · other 2. Four of the seven findings were filed by this lane's own devs today (#7163#7168#7221#7223) — all awaiting triage, ⛔ not this seat's to promote.
#4797 is READY and QUEUED BEHIND #6573 — not blocked on a ruling. It carries a maintainer-approved conditional B (2026-08-06) and a triage designation (not a split) naming this seat sole claimant: a lax-switch write records a deviation marker, and that marker must gate irreversible paths (the ADR-0104 field-file reclamation gate, which today reads only verified_at); reversible behaviour continues; a real os migrate --apply clears it. ⛔ Unconditional B (marker with no consumer) was explicitly rejected as "C plus a dead field"; ⛔ A rejected (makes the escape hatch one-way). Size M, pin tests required. Why it is not dispatched yet: OS_ALLOW_LAX_* and the adr-0104-file-references gate both live in packages/objectql/src/engine.ts — the file #6573 is editing. Measured, not assumed (3 hits). The disjoint-surface rule caught it; it goes out the moment #6573 lands.
⚠️#5299 needs care before dispatch: it spans driver-memory (frozen under #5499) and formula. ⚠️#4707 spans three packages — dispatch when concurrency is low. ⛔ #6752 still needs a ruling.
#6725 (PR #7211) and #6678 (PR #7203) both merged 03:30:57Z; sessions archived; issues closed/completed. #6573 (PR #7210) still open — one red: Check Changeset fails "Require an ADR-0087 disposition on a declared-breaking changeset" (the changeset declares major). ESLint + TypeCheck green. Dev poked with the diagnosis (its status wrongly said the PR had merged). ⛔ Two routes given, neither pre-ruled; ⛔ told not to weaken a refusal or downgrade the bump merely to pass a gate.
⚠️Seat gap, recorded: the #6573 brief asked for a changeset on a public-API refusal and never named ADR-0087. Same shape as the gate-enumeration gap — confident about what it names, silent about what it omits. Lesson ⑮: a brief that requires a changeset for a breaking change must name the ADR-0087 disposition requirement.
All three verified live on main, all three issues closed/completed, all three sessions archived. #7049 was this lane's first target:v17 card of the shift and it arrived through triage's routing channel — the case for refusing to cherry-pick other lanes' boards, made by outcome.
#7073 was NOT taken by this seat — it is now pm:dispatched to os-help. It had been held pending #7098 (shared file); another seat claimed it first. ⛔ Do not claim it.
v17 supply after wave 4: 0 (target:v17 ∩ domain:engine-core, counterprobes engine-core 22 / v17 8). #6843's ride-along trigger did not fire — #6725 touches objectql/metadata-facade.test.ts, not metadata/metadata-service.test.ts; it stays held and becomes standalone-eligible once this queue drains.
#6966 / PR #7101 — MERGED 20:28:20Z as fc3a36af3. Verified live on main: hook.zod.ts:486 (dispatch), :795 (HookDispatch), both consumers (rule-hooks.ts ×3, file-reference-lifecycle.ts ×4), the export-origins entry, branch deleted. Both sessions archived (session_01EcLMsZRoR3daV3QzPXgwxK original dev — died at 16:20Z; session_01JPn1LbHwrvKXC1twtS6XvF requeue fix).
Two non-standard things happened and both are precedent:
Accepted via the direct-verification path. The dev pushed a green head and then stalled — both counters frozen across three patrols. The seat read the diff itself against all six criteria rather than strand finished work, and filed the missing cross-seat declaration to domain:spec ([PM seat] domain:spec — 🟢 os-zhuang #6017) on the dev's behalf, marked as such. ⛔ No code written for it.
batch:2 is safe here only because the two surfaces are disjoint — that was the selection criterion, not a coincidence. If either card grows into the other's files, it stops and reports rather than racing.
Pre-dispatch re-reads changed both cards' scope (full reasoning in each card's claim comment):
Maintainer asked to prioritise v17 three times (03:2xZ, 14:0xZ, 14:3xZ). Measured three times: label:target:v17 label:domain:engine-core = 0.
Repo-wide there are 12 open target:v17 cards, all in other lanes: domain:cli ×3 (#7033#7023#6599), repo:objectui ×4 (#6955#6275#5175#5149), repo:cloud ×2 (#6954#5852), domain:devx (#7005), domain:metadata (#6190), domain:spec (#4914). Most already assigned or queued by their own seats.
Standing ruling (maintainer 03:2xZ) remains in force: stay in this lane — ⛔ do not take over seat #6025, ⛔ do not cherry-pick v17 cards from other lanes. v17 work enters this lane only via triage labelling. #6832 is the proof the channel works: filed here, graded target:v17 by triage at 03:29Z, shipped 07:38Z.
Referred to triage for grading without lobbying: #6966 (drift introduced by #5574, which shipped under target:v17 in PR #6697) — flagged honestly as materially weaker than #6832, since the card's own measurement shows no user-visible failure today.
⏭️ Next up
#6573 / #6546 / #6725 / #4707. ⛔ #6752 needs a ruling before it can be dispatched ("需定夺是否一并退休"), so it is not queue-ready. #6843 — hold with a falsifiable trigger: rides along with any card touching packages/metadata/src/metadata-service.test.ts (disposition 1 pre-approved, 2/3 rejected); if nothing touches it before this lane's queue drains, promote it standalone as XS.
#7097 / #6679 acceptance record (16:05:16Z, merge commit 29b94ed2a; session archived): 25 check-runs, 0 not green; 3 files, all packages/formula; the UNSOUND_OVERLOAD_RE scope guard held. This card's grading was wrong and the implementation proved it — the filing marked the impact "appears nil" while explicitly flagging one direction as unmeasured; triage graded it not-target:v17 on that basis and this seat forwarded that framing into the dispatch brief. Measuring it for the fix found the case: when hydration lets the expression short-circuit around the throwing call, the spurious retry succeeds and returns a value where the fault was the right answer. Referred back to triage for target:v17 re-grading.
#6972 / #6832 acceptance record (07:38:34Z, merge commit 55011afa3): all eight step-7 criteria passed; grounds in the ACCEPT comment on #6832. The dev chose shape (b) "derive from schema" and excluded (a) by measurement — HookSchema.safeParse refuses four shapes the binder binds today (unknown key, unknown event name, wrong type, alias retries), so (a) would turn "binds and runs" into "fails to bind": blast radius larger than the defect. It also pinned "explicit 0 still wins" (the ??/|| trap) unprompted, and resolved the schema lazily because lazySchema exists precisely to avoid that allocation.
Handover still open: #6916 (domain:drivers) — driver-memory collisions can only ever land as silent duplicates; the only real fix sits inside the #5499 freeze; the engine-side alternative was measured and rejected, noted so nobody re-proposes it. #6916 is also the third piece of the #5495 closeout question.
Toolchain: npx turbo run build --filter='!@objectstack/docs' --concurrency=2; single test npx vitest run <file>; type-check-debt needs a full build first; CI ratchet uses the +N difference method.
Merge queue: auto_merge reading empty is the normal entry signature, not a failure. Confirm membership two ways — the added_to_merge_queue timeline event and a gh-readonly-queue/* branch.
⚠️/search/issues is BLOCKED for this session ("sessions are bound to their configured repositories") and its error body has no total_count, so a naive d.get('total_count') reads None — which looks exactly like a zero result. Lesson ⑫ in miniature, caught live at 22:5xZ. Use the repo-scoped endpoint, where labels= is AND, and always run a counterprobe:
Measured 22:5xZ with both counterprobes green (domain:engine-core alone 21, target:v17 alone 9): the intersection is 0 — this lane's v17 supply, fourth measurement. (The MCP search_issues tool does work; only the raw REST search path is blocked.)
Green means job conclusion completed: success (ESLint / TypeScript Type Check). ⛔ in_progress is not green; the aggregate status is not authoritative. If MCP pagination returns empty, fall back to REST curl .../commits/$sha/check-runs?per_page=100 and filter per job.
Closing action: PR MERGED or card voided ⇒ archive_session + unsubscribe immediately. Merge is confirmed against origin/main, not the webhook.
Wave-closeout protocol (maintainer ruling 03:5xZ, SKILL(pm-dispatch): 八条单班实测教训 —— 派发令模板、跨包落点、云卡归档、拆分卡标签继承 #6902 lesson ⑨): in-flight reaches zero ⇒ flush the seat post to current value ⇒ signal "ready to /compact" ⇒ dispatch the next card only after compaction. One full loop completed (04:5xZ closeout → 06:3xZ redispatch). Superseded for wave 3 by the maintainer's "继续派发" instruction, which raised concurrency to batch:2.
Measured lessons this shift (nine, full text on SKILL(pm-dispatch): 八条单班实测教训 —— 派发令模板、跨包落点、云卡归档、拆分卡标签继承 #6902): ① open the PR before waiting on CI (survived two quota stoppages with zero loss) ② write the expected landing surface + cross-package disposition into the card ③ closing on someone's behalf always cites its source ④ enumerate CI gates live — and ⛔ the command this seat used for that was defective all shift. grep -oE 'pnpm check:[a-z0-9:-]+' matches only the bare form and silently skips every pnpm --filter <pkg> check:*. All 9 skipped gates are @objectstack/spec (export-origins, authorable-surface, generated, spec-changes, docs, react-blocks, skill-docs, skill-refs, upgrade-guide) — so a spec-touching card was briefed with the spec gate family missing, and check:export-origins is what ejected PR fix(spec,objectql,sharing,storage): state per-row vs record dispatch on the hook contract (#6966) #7101 from the merge queue. ⛔ Every 42/44/48/52 figure recorded earlier is void. Correct command and values:
64 unique check:* in lint.yml, 70 across all workflow files ⑤ four disciplines for parallel work in one file (three cards, zero conflicts) — extended in wave 3 to pair cards by disjoint surface when running batch:2 ⑥ label PM assumptions "must be measured, falsification welcome" (three times, three payoffs — #6832's was the strongest) ⑦ archive the cloud card the moment its PR merges ⑧ a split card inherits its parent's release label (#6806 / #5495) ⑨ close out the wave, then compact ⑩ when a filer marks an "impact nil" grade as unmeasured in one direction, the dispatch brief must carry it as an OPEN QUESTION, never repeat it as a finding — #6679: the dev measured a wrong value while under a brief telling it not to inflate the card, which is what a correct response to that instruction looks like. ⑪ a site the card calls "comments only, no behaviour" is briefed as TO BE VERIFIED, not as settled — #6966: site 3 was in fact a user-visible failure on an access-control surface (every bulk write to a ruled object revoking all its rule grants), and the dev is who falsified it. ⑫ a live-enumeration rule is only as good as its command — state the command, and re-check it against the file it reads; a systematically blind grep is worse than no rule, because it yields a confident wrong number everyone downstream trusts (see ④).
This post is the single authoritative registry for the
domain:engine-coreseat. Seat-post protocol (maintainer-approved 2026-08-06): index =label:pm:seat, entry point #4604 (pointer page). Single-writer rule, takeover/handover, and liveness judgement are unchanged (see edit history).Scope
After the 2026-08-07 domain split: objectql (including SchemaRegistry — #1825 boundary ruling) / core (runtime) / formula / plugin-pinyin-search.
⛔
packages/metadata*andpackages/platform-objectsbelong todomain:metadata(#6367); metadata format / acceptance surface belongs todomain:spec; the/metaHTTP route itself belongs todomain:cli.Current PM (session or Routine ID)
os-zhuangsession_01MwoubC3jL271FYt9rGXwxbStatus — 14:4xZ
Wave 6→7: 32 MERGED, decision box 0, 2 in flight, 30/30 cloud cards archived. The #5298/#5299 semantics conflict is RESOLVED.
#7095 (PR #7337) MERGED as
690883057— the ratchet round closed as prescribed (typed sites,as unknown as EngineQueryOptions, budget untouched). Issue closed, session archived.PR #7391 MERGED as
5f7669e0c(the #5299 shippable half: recorded target + load-bearing pins, zero behaviour).Maintainer ruling on the #5299 remainder (2026-08-10, this seat's session): 「选「维持 include」」. Cells 1/3 of the 07:33Z exclude ruling withdrawn; #5298's include direction re-affirmed as platform semantics (
$ne/$nin/$notContainsmatch no-value rows;$exists= has-value stands per #5962). Decision made on the seat's three-axis brief: long-term coherence (include is shipped, uniform across eleven surfaces, twice-ruled, gate-enrolled), AI-error mode (visible surplus beats silent absence — and the reversal itself is an 11-surface error opportunity), business pull (zero). Recorded in full on #5299; card CLOSEDcompleted.#7406 filed + dispatched (
session_01KAmtMhy6R2uBfATXW1o6Ku): XS annotation-only rewrite of #7391's family-4 record ("ruled, awaiting programme" → "withdrawn; include re-affirmed") so the single-source-of-truth file does not proclaim a withdrawn target. ⛔ Assertions byte-identical; sanctioned comment-only exception to the driver-memory freeze.#7307 dispatched (
session_017CZbGQYbdUMyzTMdqcQxp9) —engine.tsfreed by #7337's merge. Brief leads with the consumer measurement (who reads.message), ⛔ shape not pre-ruled (⑬), developer hint must survive in the right channel, objectui half ⇒ file-and-transfer.engine.tsqueue advances: #7307 (live) → #7163 → #7373.SKILL RELOADED (maintainer order, 10:2xZ) — this seat now operates on SKILL.md @
origin/main(3016 lines; local checkout was two generations stale at 2297). Adopted immediately:engine.find()still drops aformulaORDER BY silently — decide whether the engine refuses or keeps its internal-caller tolerance #7095's red-CI review_ready report.pm:queue → pm:dispatched+ the fixed five-lineClaim:block (H2 reads the literal marker).claude-fable-5; M+ defaults to cloud.scripts/pm/dispatch-gates.mjs <paths>derives at runtime (76 families / 23 workflows on first run — the memorized "70" was already stale again). Sweeper:NODE_USE_ENV_PROXY=1 node scripts/pm/check-half-states.mjs(proxy-injectedplaceholder — without the flag it 401s; lesson ㉖). Tools run from the../objectstack-pm-toolsdetached worktree @ origin/main.update_triggerto carry all of the above.Wave 7 both cards ACCEPTED + QUEUED (L2 flow: devs reported at draft, seat drove convergence):
.message(Console toast, verbatim, no code branch). Shape: two sentences, one wire code — localized label-based usermessage+developerMessagecarrying the old sentence byte-for-byte in the developer channel. New spec catalogoperation-message.ts(errors.<key>), argued againstvalidation.field.*. ⛔ No objectui card needed (producer-side fix, Console is pass-through). Changesetminor×3; no error-code-ledger touch; [PM seat] domain:spec — 🟢 os-zhuang #6017 declared.expecteddiff line is prose);skip-changeset; [PM seat] domain:spec — 🟢 os-zhuang #6017 declared.Wave 7 CLOSED OUT: 34 MERGED, 32/32 cloud cards archived. DELETE_RESTRICTED (409) message is shown verbatim to end users: English-only, leaks API names, and contains developer-facing advice #7307 →
2ef18070e, Rewrite the family-4 record in filter-logic-conformance.ts: the 2026-08-10 exclude ruling was withdrawn — include re-affirmed #7406 →98132788c, both issuesclosed/completed, sessions archived.[finding] the nested-plugin seam does not expand an aggregated
viewscontainer — a nested plugin's per-view items never reach the registry, sogetViewsByObject()/GET /meta/view?object=answer with the container alone #7163 DISPATCHED (session_01BPVc5WY75PkeXoA5NFiEEk, wave 8) — first brief fully on the new protocol: five-line claim block,pm:dispatchedmigration in the same write, gate list pasted fromdispatch-gates.mjsoutput (5 local families + 25 undetermined), L2 report-at-draft instruction embedded.[finding] the nested-plugin seam does not expand an aggregated
viewscontainer — a nested plugin's per-view items never reach the registry, sogetViewsByObject()/GET /meta/view?object=answer with the container alone #7163 (PR fix(objectql): expand an aggregatedviewscontainer from the nested-plugin seam too (#7163) #7452) ACCEPTED + QUEUED — direction measured four ways (ADR-0017 §3.2, sibling loader agrees + "so the two loaders cannot drift" inline comment, ~51 shipping stacks vs zero in-tree nestedviews), and the fix removed the CLASS: both seams now share oneregisterMetadataCollectionsbody, extending ObjectQL's two collection-registration copies diverge: jobs / emailTemplates / tools / skills register from a manifest but NOT from a nested plugin — a package shipping them via a nested plugin registers nothing, stamps no ADR-0010 provenance #7049's list-sharing logic to the loop body.Adopt PR #7328 (objectui#3569 showcase datetime fixture): one push + merge — everything else is done and verified #7358 SEAT-EXECUTED (S-grade mechanical adoption per the objectui handoff): prepared i18n entry applied (
94161354b), pushed, auto-merge armed on PR test(showcase): 给内嵌网格子对象补 datetime 永久夹具 (objectui#3569 配套) #7328. Notes: the comment's diff block was markdown-mangled (applied by anchored replacement, byte-faithful);--deepen(lesson ㉘ candidate); local i18n gate needs a built CLI, CI is the arbiter (entry was double reverse-verified by the filing seat).Wave 8 landings: 36 MERGED, 33/33 cloud cards archived. [finding] the nested-plugin seam does not expand an aggregated
viewscontainer — a nested plugin's per-view items never reach the registry, sogetViewsByObject()/GET /meta/view?object=answer with the container alone #7163 →edbf8733c(issue closed, session archived) · Adopt PR #7328 (objectui#3569 showcase datetime fixture): one push + merge — everything else is done and verified #7358 →ec0f871fd(PR predates the card so no auto-close; closedcompletedmanually — the seat-executed adoption ran exactly as the handoff predicted: skip-changeset cleared, i18n gate green in CI, queue carried it).A CEL
defaultValuestores a rawDateintodatetime/datefields — the stored-value contract says ISO-8601 string, and theNOW()token normalizes but the CEL branch does not #7373 DISPATCHED (session_012tjfhdVGuYU9KH7SNbor56) — last card of the knownengine.tsqueue. Remedy ⛔ not pre-ruled (normalize-at-seam vs tighten-contract); brief demands the in-tree CEL-default census + per-driverDatebehaviour table first, points at today's bug(objectql): 扫描得来的 ADR-0104 证书在 lax 开关下会变陈旧 —— 数据回退了,闸却还开着 #4797 lax-shapes machinery as context (a defaults path silently bypassing the strict write path is part of the argument), and flags ADR-0053's calendar-day/UTC-midnight day-shift fork as file-don't-fold if deep.A CEL
defaultValuestores a rawDateintodatetime/datefields — the stored-value contract says ISO-8601 string, and theNOW()token normalizes but the CEL branch does not #7373 (PR fix(objectql): a CELdefaultValuestores the declared type's contract shape, not a rawDate(#7373) #7469) ACCEPTED + QUEUED — census: exactly 2 in-tree CELdefaultValuesites; per-driver table: sql/mongo byte-identical (already canonicalize), memory was the visible defect; remedy = theNOW()token's own per-type table shared by both branches; refusal rejected with evidence that corrects my brief (validateRecordacceptsDatefrom any caller — no strict path was being bypassed); ADR-0053 day-shift closed and pinned (LA-day case); pins assert againstvalueSchemaForitself and on TYPE (theJSON.stringifyillusion that hid the bug is named).ObjectQL.delete's single-id cascade is not transactional — a refusal mid-cascade leaves earlier children deleted while the response says the delete failed #7413 ASSESSED: implementation-shaped, ⛔ not decision-box — the transactionless-driver fork is already mechanized (
engine.transaction:require:truefails closed per [spec] engine.transaction 契约收紧:opts.requirefail-closed、跨驱动拒绝、owned-vs-joined 信号(#4619 的契约半边,维护者已批 P2) #5696/ADR-0119 D4; default degrades + warns once per fix(objectql): engine.transaction hardening — silent degrade, default-driver-only, and no owned-vs-joined signal (ADR-0118 D1 caveats) #4619; ambient joining handles the recursive re-entry). Assessment posted on the card. Dispatches the moment fix(objectql): a CELdefaultValuestores the declared type's contract shape, not a rawDate(#7373) #7469 merges (engine.tsserial); stop-conditions set for the two genuinely open residues (require-vs-degrade consequences census; hook-inside-transaction semantics).Triple landing in one queue pass: #7284 (
⚠️ File list has no
d0d520568) · #7256 (28d1eb71b) · #7223 (bbee30216) — all three issuesclosed/completed, all three sessions archived. Wave 6 has now landed 3 of its 5 cards within ~90 minutes of dispatch.#7095 (PR #7337): the 08:47Z one-shot trigger woke the dev — session RUNNING again at 09:01Z, working the
query-options-erasureratchet fix (⛔ rails: no budget raise, no pin weakening). Lesson ㉔ recorded: a dev's "not my fault" claim gets the same verification as its "all green" claim — this one said "upstream commits"; ESLint green onmain+ every sibling falsified it in two API calls.#5299 (
session_01UmjKBzRFKnUgkk74DVUqYd) working — no PR yet.engine.tsqueue now FOUR deep: #7095 → #7307 → #7163 → #7373 (new, 08:32Z triage: CELdefaultValuestores a raw JSDatewhere the stored-value contract says ISO-8601 string —applyFieldDefaultsatengine.ts:2490has no CEL counterpart toresolveNowDefault; verified by triage, adjacent-but-disjoint from #7127/#7244).#7095 (PR #7337): ratchet fix pushed (
dfa250207) — ESLint now green; Test Core + TypeCheck running. On green: seat files the #6017 ledger declaration, then ready + queue.#5299 (PR #7391): pushed, 1 check running.
matches-filter.ts— either the dev found the cells conforming or the push is partial; judged at review-ready, not before.#5299 RULED (07:33Z) and RE-DISPATCHED (⚠️ Passed through with lesson ⑳ applied: two of the ruling's parentheticals contradict measured
session_01UmjKBzRFKnUgkk74DVUqYd, same branch). Direction settled: SQL three-valued logic is the denominator —$notContains/$nindo not match no-value rows,$exists= has-value; supersedes #5298's include direction for these cells.main(cell 2 already shipped via PR #5962; SQL currently ships #5298's deliberatenullSafeNegativebend, not native semantics), so the brief carries the direction as settled and the premises as must-re-measure, names the enrolled$neinclude-row and the #5962 RLS write/read coupling as collision surfaces, orders the conformance rows enrolled via the DEBT mechanism ("36 covered, 4 DEBT" proves a legal spelling exists), and sets STOP conditions if coherence demands flipping$ne/sql-driver/frozen mongodb.#7284 (PR #7352) ACCEPTED + QUEUED — home⚠️ dev's "ESLint red = upstream, not my work" claim verified FALSE — ESLint green on
core/src/security/operation-private-keys.tschosen by dependency measurement (0 new edges; spec rejected on PD#2, producer rejected on reverse edges), doc-block generalised not thinned, 4th-copy sweep clean, no spec touch.#7256 (PR #7348) ACCEPTED + QUEUED — loud
containswith fixture-vs-assertion guidance; blast radius zero, proven three ways incl. a positive control; side finding #7363 filed (os test**glob OOM), verified open; changesetminor.#7223 (PR #7371) ACCEPTED + QUEUED — divergences pinned + filed as #7378 (⛔ no winner picked;
MetadataFacadefailsregister→getwhend.name !== n, contract TSDoc silent); anti-vacuity proven by locally re-introducing the #6725 bug (4 rows red); 5 public spec exports with regenerated baselines; #6017 contracts-surface declaration filed (third shape today).#7095 (PR #7337):
mainand all siblings; the red is thequery-options-erasureratchet (test surface 249→253, this diff's four sites). The ratchet's own message prescribes the fix (as unknown as EngineQueryOptions). Diagnosis posted on the PR; one-shot trigger fired into the dev session (08:47Z) with ⛔ do-not-raise-the-budget and ⛔ do-not-weaken-pins rails. Everything else in the PR reads well (four-flag negative pin, three-door prose equality pin, complete ADR-0087 trio per708431313).#5299 (
session_01UmjKBzRFKnUgkk74DVUqYd) working.engine.tsqueue unchanged: #7095 → #7307 → #7163.In flight (surfaces measured pairwise disjoint, ownership map in every brief):
session_01HJgGahRqaYPRJ2oKmk9Czcobjectql/engine.ts, PR #7337 (draft, CI running)session_017AD2nx7MRuje3kLqoLBHPMwithoutOperationPrivateKeysfiles + shared home (⛔ home may not land in an owned file)session_01EdBxv9i73dqkDD2QcnvNzdcore/src/qa/runner.tssession_0193R6tMZqgrdFrCSnaogFc4spec/src/contracts/**+ metadata impl tests (engine.tsqueue (strict order, one at a time): #7095 → #7307 → #7163. #7163 (nested-plugin seam does not expand aggregatedviews) was promoted from findings by triage and confirmed atengine.ts:3097— same file, so it queues.#7256 brief's hard rail: ⛔ no shipping the loud
containspath without measuring which in-tree QA cases were passing vacuously; a suite that relied on silent-pass semantics is a stop-and-report, not a cleanup.#7223 brief's hard rail: divergences between shipped impls are pinned with
// DIVERGENCEand filed, ⛔ never resolved in a pins-only PR.⛔ Still parked: #6752 (needs ruling), #4707 (anchor), #5299 (decision box — no maintainer reply yet).
#4797 (PR #7285) MERGED as
06be54ec3— issueclosed/completed, session archived, counted. The shortened veto window drew no objection before merge.#7095 DISPATCHED (
session_01HJgGahRqaYPRJ2oKmk9Czc, branchclaude/issue-7095-find-orderby-refusal) the momentengine.tsfreed. Brief passes the 2026-08-10 ruling through as settled (refuse at the public boundary, 4xx + guidance, ⛔ never a silent drop) while leaving the genuinely open half to measurement: whether any in-tree internal call site (hooks/flows/reports/expand) relies on the tolerance — three acceptable outcomes, each requiring evidence, ⛔ no unmeasured "probably nothing". Carries the ADR-0087 trap by name with708431313as the worked example (lessons ⑮/⑳ applied: constraints named AND measured, decisive question not pre-ruled per ⑬).#7307 held behind #7095 — same file (
cascadeDeleteRelationsinengine.ts), ⛔ acceleration does not relax the disjoint-surface rule (4-for-4 today). It goes out the moment #7095 lands.⛔ Still not dispatchable: #6752 (needs ruling), #4707 (anchor), #5299 (decision box — conflict ruling still pending), untriaged findings.
#4797 (PR #7285) ACCEPTED, ready + queued 06:42Z (
⚠️ I shortened my own veto window and said so in public. At 05:47Z I committed to holding until 07:50Z. Before idling on that I checked the precedent I had been citing all shift: #5586 was itself an AUTHORABLE-surface touch (
draftread backFalse,mergeable_state: clean, 26/26 green). All five criteria verified by diff.packages/spec/src/data/context-tokens.zod.ts), declared post-hoc and taken to ready + auto-merge in the same breath. My stricter wait rested on the belief that the precedent covered only ledger-shaped touches — it does not, it covers exactly this shape and says proceed. Recorded on #6017 and the PR rather than flipping quietly, because a commitment other seats might rely on should not change without a reason attached. Same move as the #7261 re-queue: overturn the expired INPUT in public, ⛔ never the analysis in silence. Objection window stays open through merge — I will pull it from the queue on request.Lesson ㉓: check whether the precedent already covers your case BEFORE inventing a stricter rule on top of it. The extra caution cost a green PR ~70 minutes and held two dispatchable cards behind it.
Waiting on #7285's MERGE (⛔ not its queueing) — both land in
engine.ts:engine.find()still drops aformulaORDER BY silently — decide whether the engine refuses or keeps its internal-caller tolerance #7095 first — ruled 2026-08-10:engine.find()refuses at the public boundary (4xx + guidance prose, ⛔ never a silent drop); internal-caller tolerance survives only if a measured call site relies on it, behind a pinned internal path. Site:planFormulaProjection(engine.ts:620).DELETE_RESTRICTED409 copy shown verbatim to end users (English-only, leaks machine names, hands a business user a developer instruction). Site:cascadeDeleteRelations. Transport is fine (statusset) — ⛔ purely user-facing copy.⛔ They also collide with each other, so one at a time,
engine.find()still drops aformulaORDER BY silently — decide whether the engine refuses or keeps its internal-caller tolerance #7095 first.#7285 (#4797) is FULLY GREEN — 26 runs, 0 not-green,
⚠️ A peer seat converged on the same convention independently:
Build Corecompleted/successon re-run. ✅ The flake diagnosis held: the Corepack/undici crash cleared on a plain re-run, which is what a transient is. ⛔ Still draft on purpose — I publicly committed not to flip ready while the #6017 window on its authorable-surface touch is open. Window closes 07:50Z (2 h from the 05:47Z declaration); silent ⇒ proceed per #5586, and I record that on both #6017 and the PR.domain:metadataposted apackages/specdeclaration at 06:15Z (PR #7306) with an explicit "default if silent: they land with #7306". That is now three lanes (engine-core ×2, services #7224, metadata #7306) using declare-and-proceed for cross-seat spec touches. ⛔ I am still not treating the ledger-only silence as precedent for the authorable-surface case — different shapes.#6017 window 1 (#7210, ledger-only, 04:18Z): no response in ~2 h ⇒ treated as PASSED. Convention recorded: a ledger-only spec touch may proceed on declaration — ⛔ but must still be declared. ⛔ Not extrapolated to authorable surfaces.
pm:queuecards, bothdomain:engine-core, both unassigned:DELETE_RESTRICTED409 copy is shown verbatim to end users: English-only, leaks machine names, hands a business user a developer instruction. SurfacecascadeDeleteRelations.engine.find()still drops aformulaORDER BY silently — decide whether the engine refuses or keeps its internal-caller tolerance #7095 — ruled 2026-08-10:engine.find()must refuse at the public boundary (4xx + guidance prose, ⛔ never a silent drop); the internal-caller tolerance survives only behind a pinned internal path if a measured call site relies on it.⛔ Neither dispatched yet, and the reason is the file, not the cards: both land in
packages/objectql/src/engine.ts— DELETE_RESTRICTED (409) message is shown verbatim to end users: English-only, leaks API names, and contains developer-facing advice #7307'scascadeDeleteRelations(2 hits) andengine.find()still drops aformulaORDER BY silently — decide whether the engine refuses or keeps its internal-caller tolerance #7095's ruled site atplanFormulaProjection(engine.ts:620) — which fix(objectql): a lax-admitted value withdraws the irreversible half of an ADR-0104 certificate (#4797) #7285 still owns while it sits at ready. Third time today the disjoint-surface rule has held something back, and it has been right each time. Both go out the moment fix(objectql): a lax-admitted value withdraws the irreversible half of an ADR-0104 certificate (#4797) #7285 merges.#6546 (PR #7261) MERGED as
f9b1cbaf2— issueclosed/completed, session archived, counted. ✅ The re-queue call was right: it went through cleanly on the second attempt, and the ejection really was the unrelatedmetadata-fschokidar flake (#7282).#4797 → PR #7285 is review-ready (19 files). Verified by reading the diff, ⛔ not the report:
storage-service-plugin.tsnow feeds thesys_filereap guard'sisCollectionOpenfrommayActIrreversiblyinstead ofisDataMigrationVerified— the one gate that deletes bytes. Recoverable consumers (strict enforcement D1 非媒体类型的按部署扫描门禁 + D2 动作参数 17.0 默认严格 —— 证据来源与载体已定于 ADR-0104 2026-07-30 附录(修订版) #3438, tombstoning ADR-0104 D3 wave 2 — file-as-reference:独占所有权模型 + 到开启回收的分步序列(PR-5b 门禁改由 #3617 承载) #3459 PR-5b) deliberately keep the old predicate. That asymmetry is the ruling.sys_migrationcolumns per migration id (⛔ not thedetailsJSON, which each run overwrites wholesale). Producer reuses bug(objectql): ADR-0104「空库即已迁移」自证写在首启 seed 之前 —— 部署证明了一个它同一次启动就违反的契约,第二次pnpm dev起永久 10 条 ERROR #4769's admit-path sink, once per id per process, never awaited, never inserts — pinned: five lax writes ⇒ one update.DataMigrationFlagSchema+ two exports + three regenerated baselines), ⛔ explicitly flagged as a different shape from fix(objectql)!:registerHookrefuses an emptyobjecttarget and a self-cancelling scope (#6573) #7210's ledger-only one; ⛔ staying draft while the window is open.pnpm --version, before install. ⛔ Not "pre-existing" as the session reported:Build Coreis green onmainHEAD and every other sampled PR. Corrected on the PR andrerun_failed_jobstriggered. Lesson ㉑: "pre-existing" and "transient flake" are different verdicts — the first says leave it red, the second says re-run. ⛔ Verify which by checking the gate onmainand on sibling PRs.createSysFileReapGuardinservice-storage(storage-service-plugin.ts:327), ⛔ notpackages/cli/src/commands/migrate/*— those commands have no byte-delete path at all.⛔ #5299 STOPPED → decision box. Two maintainer rulings are in direct opposition; this seat will not pick between them. Dev landed zero files and invoked the stop-and-report clause correctly; session archived,
needs-user-decisionset, unassigned.$ne/$nin/$notContains:driver-sql 排除 NULL 行,driver-memory / formula 返回它们(#5146 只裁定了$not) #5298 (2026-08-06, shipped across PRs fix(driver-sql):$not取反前先把操作数编译成全域谓词,NULL 行不再被静默排除 (#5146) #5296→fix(drivers,analytics,formula): $ne / $nin / $notContains 在 $not 之外也 NULL-safe (#5298) #5962→fix(analytics): $ne / $nin / $notContains 在 Cube 面保留无值行 (#5298 第二批) (#5977) #6004→feat(driver-turso): remote 模式补 canonical 时间列 backfill 通道(分批、可恢复、完成标记) (#5770) #6006→fix(driver-turso): remote 模式对齐 NULL-safe 语义 —— $not/$ne/$nin/$notContains 四算子 + $exists 拒收闸 (#5903) #6047, closed 08-07):$ne/$nin/$notContainsINCLUDE no-value rows — and its ruling comment says it covers this card's three cells.$notContains(null 值)、$exists(键在值为 null)、$nin(缺键) #5299 (2026-08-07 17:00): the same operators must NOT match no-value rows.I re-verified the dev's three load-bearing claims myself on
89470f7, ⛔ not on trust — all three hold:$existsalready readsactual != null(cell 2 shipped, PR fix(drivers,analytics,formula): $ne / $nin / $notContains 在 $not 之外也 NULL-safe (#5298) #5962);filter-logic-conformance.tsalready enrols "$nereturns the rows with no value" →['2','3','4']; and [finding]undefined比较数在仓内有五种读法 —— #6050 只在 driver-sql/turso 落了拒收,formula 读作「键缺失」、read-scope-sql 编成= NULL、driver-memory 读作 null #6125 closed at 16:38:47Z, 22 minutes BEFORE the 17:00:50Z ruling.⛔ The ruled
FILTER_LOGIC_CASESrows are not executable: they would sit three lines from the enrolled$nerow asserting the opposite for the same family and go red on all five drivers — the "a gate must not report a known red" rule 非否定路径上的$ne/$nin/$notContains:driver-sql 排除 NULL 行,driver-memory / formula 返回它们(#5146 只裁定了$not) #5298 ② was explicit about. And the ruling's "SQL can never deliver it" premise is false on current main (read-scope-sql.ts:815,col IS NULL OR col NOT LIKE ?, measured at zero index regression).undefined比较数在仓内有五种读法 —— #6050 只在 driver-sql/turso 落了拒收,formula 读作「键缺失」、read-scope-sql 编成= NULL、driver-memory 读作 null #6125 — it was already closed; I carried that from a 15:18Z comment without re-checking. (2) I passed all three ruling constraints through verbatim and confidently, one of which cannot be executed. Lesson ⑳: passing a ruling through faithfully is right; passing it through UNMEASURED is how a stale premise reaches a dev as an order.In flight: #4797 → PR #7285 (draft, 13 files, +1037/−16; consumer on the irreversible path present).⚠️ It touches
packages/spec/src/system/migration.zod.ts— an authorable surface, ⛔ not #7210's ledger-only shape — so this seat owes #6017 a cross-seat declaration once the diff settles.#6546 / PR #7261 re-queued 05:03Z, no third ejection so far. #6017 veto window on #7210: still no spec-seat response.
#6546 (PR #7261) EJECTED 04:42Z — genuine kick this time (
⚠️ Its falsification is the valuable part: #7208's 20 s
merged=False, not on main; ⑰ applied in the other direction). ⛔ Not this PR: the failing test ispackages/metadata-fs/test/fs-behavior.test.ts(chokidar external-edit event), andmetadata-fshas no dependency path toobjectql— the PR is one*.test.tsfile. Dev filed #7282 and, correctly, flagged rather than decided the re-queue.EVENT_WAIT_MShardening (684ab22, 04:12:38) was already an ancestor of the failing build (b8e9fe27, 04:19:50) — read from the queue's own merge commit. A 6.7× deadline increase changing nothing means the event is never delivered, not late. ⛔ A fourth deadline-tuning attempt is ruled out; escalated that onto #7282.PM re-queued at 05:0xZ, overturning one INPUT and no analysis: the hold rested on "a failed attempt rebuilds every PR behind this one" — measured now, 0
gh-readonly-queue/*branches and 0 PRs with auto-merge armed, so the cost is currently zero. ⛔ If it ejects again on the same signature I hold until #7282 lands rather than try a third time.#4797 → PR #7285 (draft, 13 files, +1037/−16, 11 checks still running). The non-negotiable is present: the marker has a consumer on the irreversible path (
⚠️ It touches
service-storage/attachment-lifecycle.ts+lax-deviation-reclamation-gate.test.ts), plussys-migrationproducer and dedicated pins.packages/spec/src/system/migration.zod.ts+authorable-surface/system.json— an AUTHORABLE schema surface, ⛔ not the ledger-only shape #7210 had. This is the real case the cross-seat rule protects; declaration to #6017 to be filed by this seat once the diff settles.#5299 (
session_01J3DsvsTYddbUsme1KXbtJk) — no PR yet, dispatched 04:59Z.In flight: #4797 (
session_015KREcaEs85dphzUUqdYfX6) · #5299 (session_01J3DsvsTYddbUsme1KXbtJk,packages/formula) — surfaces measured disjoint.get('object', …)#6843 — ⛔ alreadyclosedandpm:dispatchedtoos-help. Not a candidate at all.isSystem: truehas at least three distinct, undocumented side effects across three packages — each one has cost an app-side bug #4707 — ⛔ anchor card only. The 2026-08-06 maintainer ruling split its executable work into docs: one authoritative table of every behaviour keyed offisSystem(demand 1 of #4707, maintainer-ruled 2026-08-06) #6782 (domain:devx, the authoritativeisSystembehaviour table) and plugin-sharing: INFO line when isSystem writes cover an active sharing rule but materialise zero grants (demand 3 of #4707, maintainer-ruled 2026-08-06) #6783 (domain:identity, the one-INFO-line sharing fix); demand 2 was ruled do NOT split the flag, and that verdict is written into docs: one authoritative table of every behaviour keyed offisSystem(demand 1 of #4707, maintainer-ruled 2026-08-06) #6782 as table content.isSystem: truehas at least three distinct, undocumented side effects across three packages — each one has cost an app-side bug #4707 closes when both land. Nothing here for engine-core.$notContains(null 值)、$exists(键在值为 null)、$nin(缺键) #5299 — ✅ dispatched, and I nearly held it wrongly. Its body points atdriver-memory/memory-matcher.ts(inside the [裁决] driver-memory / driver-mongodb 投入冻结 —— 维护者 2026-08-05 口径(跨单锚点) #5499 freeze) and carries a stale path (packages/plugins/…). The 2026-08-07 ruling moved the landing site topackages/formulaand explicitly says keep driver-memory's guard — which is also why triage relabeled itdomain:drivers→domain:engine-core. ⛔ Reading a card body without its ruling gets the lane assignment backwards.#5299 ruling passed through verbatim:
$notContainsdoes not match no-value;$existsmeans has a value;$nindoes not match no-value (⛔ keep the guard). Unifying rule: negative operators never match no-value rows; the only ways to select "no value" are$exists: false/$null: true. ⛔ driver-memory pins re-annotated, not flipped (freeze); ⛔ flipped pins must assert the new row sets, not just drop old ones;FILTER_LOGIC_CASESrows added so the cells stay gated. Load-bearing: unblocks #6125's formula half.Lane
pm:queueis now effectively drained for this seat: ⛔ #6752 needs a ruling; #4707 belongs to two other lanes; #6843 taken. Remaining engine-core work sits in untriaged findings (#7163 #7168 #7221 #7223 #7264 — five of them filed by this lane's own devs today), ⛔ which this seat cannot promote.#6573 (PR #7210) MERGED as
⚠️ Lesson ⑰ —
708431313— issueclosed/completed, session archived, counted.removed_from_merge_queueis AMBIGUOUS. It fired on #7210 at 04:35Z and reads exactly like an ejection; the PR had in fact merged. A stalegit logread a minute earlier said "not landed", which would have made it look like a kick. ⛔ Never call a kick from that event alone — readmergedon the PR andgit merge-base --is-ancestoron the commit. This seat nearly reported a false ejection.#6546 (PR #7261) still in the queue,
added_to_merge_queue04:20Z, no removal.#4797 DISPATCHED (
session_015KREcaEs85dphzUUqdYfX6) the momentengine.tsfreed up — held all shift on the file, never on the ruling. Brief carries the settled conditional-B ruling, ⛔ marked non-reopenable, while leaving genuinely open what the ruling does not fix: marker location, granularity, write path, and which gates count as irreversible. Also carries the ADR-0087 warning that cost #6573 a red (lesson ⑮).#6017 veto window: no response yet on the ledger-only spec touch.⚠️ Also found:
os-help(services seat) filed the same-shaped declaration at 03:25Z for PR #7224 — a one-rowerror-code-ledger.zod.tsregistration riding its own PR, with the same "registration is inseparable from the PR that mints it" reasoning. Two lanes independently converged on declare-and-proceed for ledger-only spec touches, which is stronger evidence for the convention than either declaration alone.#6573 (PR #7210) — ACCEPT, ready + queued. Red cleared: dev took route 1 (kept
⚠️ New shape recorded — a LEDGER-ONLY
major, filed the ADR-0087 disposition). 27 checks, 0 not-green. All four criteria verified by diff: both refusals (four spellings incl. the #5928 arithmetic one), ⛔ matching read unchanged (hookMatchesObjecttruthiness preserved; refusal at the registration door), caller survey self-measured, and thehook-exclude-objects.test.tspin reworked (item 3 narrowed, new 3b) — content checked, not filename.packages/spectouch. #7210 writesmigrations/registry.ts+spec-changes.json+ the upgrade guide, and no schema surface at all. Measured: the last 8 commits touching that registry all also changed an authorable.zod.ts. No precedent either way ⇒ ⛔ did not rule on it myself; filed a cross-seat declaration on thedomain:specseat #6017 with an open veto window (#6532/#5586 precedent) and proceeded, as that precedent allows.#6546 (PR #7261) — ACCEPT, queued. 34 checks, 0 not-green. Dev took the preferred route: typed the double
IDataDriverinstead of deleting the bit, restoring thetsctombstone diagnostic that: anyhad switched off;supports: {}. Added the pin I asked for — "gates transactions on METHOD PRESENCE, not a capability bit" — running the transactional path against a driver advertising no capabilities. Changeset decision read fromcheck-empty-changeset.mjs(skip-changesetlabel, ⛔ not an empty changeset — #4898 silent-publish trap). Swept and filed #7264 (~64any-annotated doubles, same diagnostic off, none red today) instead of folding it in — card existence confirmed.Next: ⛔ #4797 stays held until #7210 actually merges — not for the ruling (conditional B, settled 2026-08-06) but for the file: it needs⚠️ #7210 touches ledger files that are a known
objectql/engine.ts, which #7210 still owns while queued.... is stalekick risk, so a kick would put the dev back inengine.ts; dispatching now would race it. Maintainer widened the mandate (04:0xZ): 「除了 v17,只要你车道的任务都可以处理」 — any in-lane card, not onlytarget:v17.In flight: #6573 (PR #7210,
objectql/engine.ts) · #6546 (session_013oQBbBKaypak259s41pF2A,objectql/protocol-batch-atomic.test.ts).Lane census 04:0xZ — 19 open issues:
pm:queue5 (#4707 #4797 #5299 #6546 #6752) ·finding7 ·pm:on-hold3 ·pm:dispatched2 (other seats) · other 2. Four of the seven findings were filed by this lane's own devs today (#7163 #7168 #7221 #7223) — all awaiting triage, ⛔ not this seat's to promote.#4797 is READY and QUEUED BEHIND #6573 — not blocked on a ruling. It carries a maintainer-approved conditional B (2026-08-06) and a triage designation (not a split) naming this seat sole claimant: a lax-switch write records a deviation marker, and that marker must gate irreversible paths (the ADR-0104 field-file reclamation gate, which today reads only
verified_at); reversible behaviour continues; a realos migrate --applyclears it. ⛔ Unconditional B (marker with no consumer) was explicitly rejected as "C plus a dead field"; ⛔ A rejected (makes the escape hatch one-way). Size M, pin tests required.Why it is not dispatched yet:
OS_ALLOW_LAX_*and theadr-0104-file-referencesgate both live inpackages/objectql/src/engine.ts— the file #6573 is editing. Measured, not assumed (3 hits). The disjoint-surface rule caught it; it goes out the moment #6573 lands.driver-memory(frozen under #5499) andformula.#6725 (PR #7211) and #6678 (PR #7203) both merged 03:30:57Z; sessions archived; issues
closed/completed.#6573 (PR #7210) still open — one red:
Check Changesetfails "Require an ADR-0087 disposition on a declared-breaking changeset" (the changeset declaresmajor). ESLint + TypeCheck green. Dev poked with the diagnosis (its status wrongly said the PR had merged). ⛔ Two routes given, neither pre-ruled; ⛔ told not to weaken a refusal or downgrade the bump merely to pass a gate.🔵 In flight (surfaces disjoint by construction)
session_011rfAjYFr66Mjnz89gD5CL5objectql/engine.ts—registerHooksession_0141cZum72My2vskaQSoQ1tZobjectql/metadata-facade.tssession_01KbH3tZeQe1R4U8Z64eAF1mformula/parse-cel-to-ast.test.ts✅ Wave 4 landed — three for three
target:v17bf42e76aaedb4af0995d24f4b94All three verified live on
main, all three issuesclosed/completed, all three sessions archived. #7049 was this lane's firsttarget:v17card of the shift and it arrived through triage's routing channel — the case for refusing to cherry-pick other lanes' boards, made by outcome.#7073 was NOT taken by this seat — it is now
pm:dispatchedtoos-help. It had been held pending #7098 (shared file); another seat claimed it first. ⛔ Do not claim it.v17 supply after wave 4: 0 (
target:v17∩domain:engine-core, counterprobes engine-core 22 / v17 8). #6843's ride-along trigger did not fire — #6725 touchesobjectql/metadata-facade.test.ts, notmetadata/metadata-service.test.ts; it stays held and becomes standalone-eligible once this queue drains.✅ Wave 3 closed — #6966 landed
#6966 / PR #7101 — MERGED 20:28:20Z as
fc3a36af3. Verified live onmain:hook.zod.ts:486(dispatch),:795(HookDispatch), both consumers (rule-hooks.ts×3,file-reference-lifecycle.ts×4), theexport-originsentry, branch deleted. Both sessions archived (session_01EcLMsZRoR3daV3QzPXgwxKoriginal dev — died at 16:20Z;session_01JPn1LbHwrvKXC1twtS6XvFrequeue fix).Two non-standard things happened and both are precedent:
domain:spec([PM seat] domain:spec — 🟢 os-zhuang #6017) on the dev's behalf, marked as such. ⛔ No code written for it.check:export-origins— a baseline (test(spec): export-surface pins compare a build-time baseline instead of running tsc (#4796) #7090, 16:06Z) that landed after this branch was cut, colliding with this PR's new spec exports. Not a defect in the work. A narrow fix session merged main + regenerated; the seat verified the feature was byte-identical and the regeneration added exactly one line (which also rules out the spec 同名双源:两个MetadataWatchEvent形状不同、分挂两个子路径入口,其中 kernel 版零消费方(ADR-0049 enforce-or-remove) #4411 dual-source trap), then re-queued. Re-queueing is the lane PM's call, not the queue steward's — the steward correctly stopped at diagnosis.batch:2is safe here only because the two surfaces are disjoint — that was the selection criterion, not a coincidence. If either card grows into the other's files, it stops and reports rather than racing.Pre-dispatch re-reads changed both cards' scope (full reasoning in each card's claim comment):
before*dispatch bindsinput.idon every context, silently changing the semantics of every "no id ⇒ skip, this is a bulk write" hook guard #6966 — triage said site 2 (plugin-audit) was governed by "plugin-audit captureBefore still fetches its own pre-image — retire the second read once the engine binds ctx.previous before every before* dispatch #6656's pending ruling". plugin-audit captureBefore still fetches its own pre-image — retire the second read once the engine binds ctx.previous before every before* dispatch #6656 closedcompletedat 08:02:02Z, and its landing already retired that guard:audit-writers.ts:658now reads "⛔ RETIRED … Do not reintroduce it". So the card is two sites, not three, and re-adding a guard there would reverse a landed ruling. Bonus: that same retirement docblock already surveys the exact dispatch seam this card must mark, with anchors re-measured on97b079896(:1825per-row bind,:1746after-phase bind).isNumericOverloadErroris the last author-text read left in cel-engine.ts — it arms the ADR-0032 §1c hydration retry off/no such overload/i, and our ownmatches()binding can put that phrase in a native error #6679 — anchors stale for the third time (:797at filing →:1048at triage → current:1046). Scope guard restated with anchors:UNSOUND_OVERLOAD_RE(:632, consumed:767) is a different mechanism and is ⛔ out of scope; conflating the two would silently widen the card.🎯 v17 — measured, not assumed
Maintainer asked to prioritise v17 three times (03:2xZ, 14:0xZ, 14:3xZ). Measured three times:
label:target:v17 label:domain:engine-core= 0.Repo-wide there are 12 open
target:v17cards, all in other lanes:domain:cli×3 (#7033 #7023 #6599),repo:objectui×4 (#6955 #6275 #5175 #5149),repo:cloud×2 (#6954 #5852),domain:devx(#7005),domain:metadata(#6190),domain:spec(#4914). Most already assigned or queued by their own seats.Standing ruling (maintainer 03:2xZ) remains in force: stay in this lane — ⛔ do not take over seat #6025, ⛔ do not cherry-pick v17 cards from other lanes. v17 work enters this lane only via triage labelling. #6832 is the proof the channel works: filed here, graded
target:v17by triage at 03:29Z, shipped 07:38Z.Referred to triage for grading without lobbying: #6966 (drift introduced by #5574, which shipped under
target:v17in PR #6697) — flagged honestly as materially weaker than #6832, since the card's own measurement shows no user-visible failure today.⏭️ Next up
#6573 / #6546 / #6725 / #4707. ⛔ #6752 needs a ruling before it can be dispatched ("需定夺是否一并退休"), so it is not queue-ready.
#6843 — hold with a falsifiable trigger: rides along with any card touching
packages/metadata/src/metadata-service.test.ts(disposition 1 pre-approved, 2/3 rejected); if nothing touches it before this lane's queue drains, promote it standalone as XS.🏆 Shift tally (since 08:46Z)
19 MERGED: #6658 (#5896, predecessor), #6670 (#4840), #6672 (#5282), #6677 (#6223), #6680 (#5586), #6671 (#1825), #6697 (#5574+#5846, XL,
target:v17), #6766 (#6132), #6786 (#5543,target:v17), #6788 (#6457,target:v17), #6791 (#4776), #6794 (#5929), #6812 (#6810), #6818 (#6808), #6454 (confirmation), #6907 (#6806,target:v17inherited from #5495), #6972 (#6832,target:v17), #7097 (#6679), #7101 (#6966).#7097 / #6679 acceptance record (16:05:16Z, merge commit
29b94ed2a; session archived): 25 check-runs, 0 not green; 3 files, allpackages/formula; theUNSOUND_OVERLOAD_REscope guard held. This card's grading was wrong and the implementation proved it — the filing marked the impact "appears nil" while explicitly flagging one direction as unmeasured; triage graded it not-target:v17on that basis and this seat forwarded that framing into the dispatch brief. Measuring it for the fix found the case: when hydration lets the expression short-circuit around the throwing call, the spurious retry succeeds and returns a value where the fault was the right answer. Referred back to triage fortarget:v17re-grading.#6972 / #6832 acceptance record (07:38:34Z, merge commit
55011afa3): all eight step-7 criteria passed; grounds in the ACCEPT comment on #6832. The dev chose shape (b) "derive from schema" and excluded (a) by measurement —HookSchema.safeParserefuses four shapes the binder binds today (unknown key, unknown event name, wrong type, aliasretries), so (a) would turn "binds and runs" into "fails to bind": blast radius larger than the defect. It also pinned "explicit0still wins" (the??/||trap) unprompted, and resolved the schema lazily becauselazySchemaexists precisely to avoid that allocation.Handover still open: #6916 (
domain:drivers) — driver-memory collisions can only ever land as silent duplicates; the only real fix sits inside the #5499 freeze; the engine-side alternative was measured and rejected, noted so nobody re-proposes it. #6916 is also the third piece of the #5495 closeout question.📋 Other ledger
completed08:02Z (was blocking #5574's per-rowbefore*dispatch bindsinput.idon every context, silently changing the semantics of every "no id ⇒ skip, this is a bulk write" hook guard #6966's site 2); 决策:自增号「计数器反解」规则是否作为 renderAutonumber 的逆进 packages/spec(PR #6553 的 open question,维护者裁) #6560 (option B approved, spec lane executing); #4649 的「记录对已声明字段全量」只落在两个接缝上 —— 另外三处求值仍是稀疏绑定 #4953 anchor retained.rls-predicate-unparseablewith SQL-vs-CEL prose — off-label for a bounds overrun #6778 dispatched and closedcompletedbydomain:spec-tooling; Registry heal restores the metadata-map view but never re-registers a packaged contributor definition an overlay save replaced #6853 graded and routed todomain:metadata, queued there. Neither is this seat's any more. First measurable return on the "file it on the spot, never smuggle it into the current PR" discipline: one shipped, one queued in the right lane, and neither polluted its origin PR's diff.docs/adr/**PR #6741, another seat in flight): once it lands,docs/adr/**PRs get review-only + ready, ⛔ never PM-queued.Operating notes (still in force)
AGENTS.md§Communication — GitHub artifacts (issue/PR titles, bodies, comments) in English; conversation with the maintainer in Chinese. Maintainer ruling 2026-08-08 (AGENTS.md §Communication and the os-dev template still mandate Chinese for PR/issue prose, while the dispatch seat enforces the 2026-08-06 English-on-GitHub policy — a dev agent is told both #6692), quoted in the original: 「issue 和 PR 必须用英文,在 claude code 中和我讨论可以用中文。」 Quoted Chinese rulings are never translated. This seat violated the rule for most of the shift — flagged by the identity seat on #5574's per-rowbefore*dispatch bindsinput.idon every context, silently changing the semantics of every "no id ⇒ skip, this is a bulk write" hook guard #6966 at 06:44Z, verified againstAGENTS.mdrather than taken on trust, corrected from the #5574's per-rowbefore*dispatch bindsinput.idon every context, silently changing the semantics of every "no id ⇒ skip, this is a bulk write" hook guard #6966 dispatch onward.npx turbo run build --filter='!@objectstack/docs' --concurrency=2; single testnpx vitest run <file>; type-check-debt needs a full build first; CI ratchet uses the +N difference method.auto_mergereading empty is the normal entry signature, not a failure. Confirm membership two ways — theadded_to_merge_queuetimeline event and agh-readonly-queue/*branch./search/issuesis BLOCKED for this session ("sessions are bound to their configured repositories") and its error body has nototal_count, so a naived.get('total_count')readsNone— which looks exactly like a zero result. Lesson ⑫ in miniature, caught live at 22:5xZ. Use the repo-scoped endpoint, wherelabels=is AND, and always run a counterprobe:Measured 22:5xZ with both counterprobes green (
domain:engine-corealone 21,target:v17alone 9): the intersection is 0 — this lane's v17 supply, fourth measurement. (The MCPsearch_issuestool does work; only the raw REST search path is blocked.)completed: success(ESLint / TypeScript Type Check). ⛔in_progressis not green; the aggregate status is not authoritative. If MCP pagination returns empty, fall back to RESTcurl .../commits/$sha/check-runs?per_page=100and filter per job.curlthe raw body before concluding a body is corrupted (fix(objectql): resync the engine fallback autonumber counter — adopt exempt writers' numbers, re-seed on collision (#6806) #6907: raw was intact; do not "fix" a dev's report).archive_session+ unsubscribe immediately. Merge is confirmed againstorigin/main, not the webhook./compact" ⇒ dispatch the next card only after compaction. One full loop completed (04:5xZ closeout → 06:3xZ redispatch). Superseded for wave 3 by the maintainer's "继续派发" instruction, which raised concurrency to batch:2.grep -oE 'pnpm check:[a-z0-9:-]+'matches only the bare form and silently skips everypnpm --filter <pkg> check:*. All 9 skipped gates are@objectstack/spec(export-origins,authorable-surface,generated,spec-changes,docs,react-blocks,skill-docs,skill-refs,upgrade-guide) — so a spec-touching card was briefed with the spec gate family missing, andcheck:export-originsis what ejected PR fix(spec,objectql,sharing,storage): state per-row vs record dispatch on the hook contract (#6966) #7101 from the merge queue. ⛔ Every 42/44/48/52 figure recorded earlier is void. Correct command and values:64 unique
check:*inlint.yml, 70 across all workflow files ⑤ four disciplines for parallel work in one file (three cards, zero conflicts) — extended in wave 3 to pair cards by disjoint surface when running batch:2 ⑥ label PM assumptions "must be measured, falsification welcome" (three times, three payoffs — #6832's was the strongest) ⑦ archive the cloud card the moment its PR merges ⑧ a split card inherits its parent's release label (#6806 / #5495) ⑨ close out the wave, then compact ⑩ when a filer marks an "impact nil" grade as unmeasured in one direction, the dispatch brief must carry it as an OPEN QUESTION, never repeat it as a finding — #6679: the dev measured a wrong value while under a brief telling it not to inflate the card, which is what a correct response to that instruction looks like. ⑪ a site the card calls "comments only, no behaviour" is briefed as TO BE VERIFIED, not as settled — #6966: site 3 was in fact a user-visible failure on an access-control surface (every bulk write to a ruled object revoking all its rule grants), and the dev is who falsified it. ⑫ a live-enumeration rule is only as good as its command — state the command, and re-check it against the file it reads; a systematically blind grep is worse than no rule, because it yields a confident wrong number everyone downstream trusts (see ④).Generated by Claude Code