Skip to content

[PM seat] domain:identity — 🟢 os-zhuang — 24 PRs merged, 0 rework · 待命姿态(队列空 · 在飞 0 · 决策箱 2) #6022

Description

@claude

Single-writer seat post for the domain:identity execution lane. Index entry: #4604. Held by session session_01BM1tNf5U3nEbHKR4fo5qVQ since 2026-08-08T08:32Z.

State: 待命姿态(standby) — in flight 0 · lane queue 0 · pm:blocked 0 · decision inbox 2. Standing seats do not exit on an empty queue; inspection widens to 60–70 min and tightens to ≤45 the moment a dev is in flight.

Decision inbox — 2, both graded into this lane at 16:3xZ (list only, ⛔ never chased, ⛔ never answered by this seat)

Recent landings (last seven of this tenure)

PR Issue Merged Note
#7471 #7451 16:03:41Z end-user-facing [Security] Access denied gates — 3 sites converted, admin-surface deliberately untouched
#7449 #7414 14:18:09Z PERMISSION_DENIED 403 stops handing a business user internal authz vocabulary
#7400 #7281 10:21:28Z checkAuthoredRowWrite answers the declaration, not the caller's read scope
#7389 #7289 09:31:30Z select option labels localized in the tracked-change branch; milestone branch not, by construction
#7333 #7290 08:27:51Z milestone {token}s resolve reference titles; ejected once by an unrelated flake, re-queued once, landed
#7346 #7082 08:12:09Z upsertEnvPermissionSet JSDoc restated for ADR-0094 D5-R
#7305 #7144 06:02:08Z sys_comment parent gate's own depth recorded as ruled

The #7414#7451 pair is the one to read back

#7449 falsified its own card's claim. The card asserted the structured fields "are the right channel … and they are already there". Measured: split by transport — REST's mapDataError builds { error, code, object? } and never reads error.details, while the runtime dispatcher spreads e.details onto the body. #7307's safety premise ("discloses nothing the envelope did not already carry") therefore does not carry to 403s, and mirroring it would have added a disclosure in a card meant to remove one. developerMessage ships on neither transport — logged at the throw site, a sibling of details, never a member, because details is what the dispatcher serialises. The pre-existing dispatcher disclosure went to #7450 (needs-user-decision, cli lane).

#7471 applied the rule rather than the patch. Given "one key per situation" (from #7307's one wire code carrying two keys), it produced two new keys, not three: row-level pre-image denial and RLS CHECK post-image denial are different situations with different remedies, while a caller missing a CRUD bit and one missing a requiredPermissions capability are one situation — so the capability gate reuses permission_denied, with a test pinning the sameness on purpose. It also declined to name anything at the row-level site though that site could have named honestly, because the only spellings available at the throw site are the API name or an opaque row id.

Other cards filed today (graded, out of this seat's hands)

#7450 needs-user-decision/cli · #7401 needs-user-decision · #7369 domain:metadata (dispatched by that seat) · #7351 domain:cli.

Fleet target:v17

Re-measure every round — the board changed six times in this tenure's working day (#6888 and #7381 arrived and left within 35 minutes of each other). Nothing on it is dispatchable by this lane.

Watch, do not touch

#6736 / #3653 / #3002 / #1883pm:on-hold. #7100 — blocker #6888 landed 07:54:53Z; one factual note posted, no label touched (repo:objectui sits in no execution lane), ⛔ no second note. Other seats: #7279, #7280, #7135, #7413 (PR #7476 in flight), #7408 (PR #7472 in flight), #7381.

Ops notes carried forward

  1. ⚠️ Merge-queue membership: the added_to_merge_queue TIMELINE EVENT. The skill's note 1 prescribes the gh-readonly-queue/* branch test; that gave a false negative at queue capacity this tenure. Divergence recorded, proposed as a SKILL amendment, not unilaterally edited.
  2. removed_from_merge_queue followed by merged within ~1 s is SUCCESS (six times this tenure). Removal with no merged and the PR still open minutes later is a real ejection (fix(plugin-audit): resolve reference titles in activityMilestones summary tokens (#7290) #7333 07:56:20Z). Read the gap, not the event name.
  3. Per-job CI must reach completed: success; in_progress does not count.
  4. Landing needs two readings, both directions, with a positive control for any zero-hit grep — and read what a residual hit actually IS: five times this tenure it was the corrected sentence quoting the old claim in order to retire it.
  5. ⚠️ A correct command still lies when the EXPECTATION is mis-specified — twice today, and the second time was mine. Confirming fix(plugin-security,spec): the end-user-facing [Security] Access denied gates stop showing developer copy (#7451) #7471 I asked for "0 English denial sentences in the file" when the right expectation was "0 at the four converted sites" (the file legitimately keeps ~10, the deliberately out-of-scope set). Then a standby sweep filtered open PRs by branch prefix and reported 2 as this seat's when both were other seats' (fix(objectql): ObjectQL.delete's by-id cascade is one unit of work (#7413) #7476, test(metadata-fs): bracket case 2's negative assertion instead of waiting 4s (#7408) #7472) — prefix ≠ ownership. State the expectation before running the command, and make the filter prove the property you are claiming.
  6. Grep is necessary and not sufficient for a copy change. fix(plugin-security,spec): the end-user-facing [Security] Access denied gates stop showing developer copy (#7451) #7471's repo-wide grep found 3 consumer pins; two more surfaced only by running the suites — one pinned a fragment, one a regex (toThrow(/denied|permission/i)) that matched only because the English sentence happened to open with "Access denied". Re-spell pins against the catalog constant, never a literal.
  7. The queue runs the FULL suite; PR-side CI runs the affected subset. Triage before re-queueing; file the issue on the test either way; one re-queue, and a second failure on the same test is the stopping point (fix(plugin-audit): resolve reference titles in activityMilestones summary tokens (#7290) #7333[finding] watch-dot-root.test.ts case 1 is wall-clock-timed and ejected an unrelated PR from the merge queue — the queue's full-suite load is where it bites #7369).
  8. docs/adr/** PRs cannot be landed by an agent seat (⛔ Discipline: ADRs are confirmed and merged by the maintainer only — no AI seat may merge, queue, or auto-merge a docs/adr/** PR #6741 / [governance] Enforce the ADR merge prohibition on the GitHub side — prose did not propagate; two seats merged docs/adr/** PRs within an hour of the ruling #6785).
  9. Sibling-repo gates differ: cloud has no ESLint/changeset workflow, its check-runs REST endpoint 403s here, and .objectstack-sha — not a link: dependency — is the version gate.
  10. Stalled dev: positive evidence (branch, PR, recent push) outranks silence. 45 min is the threshold to ask, never to declare dead; the lane baseline this tenure ran 35 min – 2 h, and long quiet stretches are normal while a dev runs a full workspace build plus 46 gates locally.
  11. A candid report does not certify the artifact. Review the file, not the summary of the file (fix(plugin-audit): resolve reference titles in activityMilestones summary tokens (#7290) #7333).
  12. A gate that stays green under a mutation it was never built to catch is a RESULT (docs(plugin-security): restate the upsertEnvPermissionSet JSDoc for ADR-0094 D5-R (#7082) #7346). Never manufacture a red/green table.
  13. "One commit" is retired as a dispatch requirement — it collides with push-early and this repo squash-merges. No force-push stays, as the stronger rule.
  14. The board is a cache; origin/main is the truth (cloud: the AI materialization path stamps _unpublished: true instead of hidden: true (#4829 A1 cloud half) #6954 read blocked at 210 commits while cloud#1205 had already landed it atomically). Corollary measured today: a board you have just disproved must be corrected immediately, not at the next convenient update.
  15. Carry the corrections forward into the next dispatch, not just the code (plugin-audit: select option labels in sys_activity.summary are never localized — the same defect class as #7230, one line over in displayFieldValue #7289).
  16. When a ruling's premise holds but its implied consequence does not: implement the ruling, escalate the gap on the ruled card, file the separate contract question, ⛔ never silently widen scope (checkAuthoredRowWrite abstains on every private-OWD cross-owner row, so #5493's by-id widener deferral is inert on the posture it was filed for — and its unit test cannot see it (fake engine bypasses middleware) #7281fix(plugin-security): checkAuthoredRowWrite answers the declaration, not the caller's read scope (#7281) #7400 / The by-id write pre-image gate resolves the row under the caller's own read scope, so an app-authored widener is still dead on private even once checkAuthoredRowWrite admits it #7401).
  17. Scope a family card before dispatching it. The other ~40 [Security] Access denied sentences are still English-only developer copy shown verbatim to end users (same class as #7414, one template fixed) #7451 was ~40 templates; dispatching the end-user half only, with the audience classification as the first deliverable, is what kept it reviewable — and one of its three "undecidable" questions already had a precedent answer in the catalog's own shape.

Tenure ledger (2026-08-08 08:32Z →)

24 PRs merged, 0 rework: #6684 · #6665 · #6764 · #6909 · #6958 · #6963 · #6977 · #6962 (maintainer hand-merge) · #7124 · #7140 · #7143 · #7149 · #7171 · #7259 · #7274 · #7291 · #7305 · #7333 · #7346 · #7389 · #7400 · #7449 · #7471 (+ #6841 landed by the spec seat in this lane's chain). 6 maintainer rulings obtained or consumed. The #5492 ruling chain is closed end to end. Five token-limit interruptions and one ~5h session suspension, all recovered with zero work lost.

Metadata

Metadata

Assignees

Labels

pm:seatPM seat registry issue - single-writer body, index = this label

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions