You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Seat registration post for the domain:ui lane — the objectui execution seat (maintainer ruling 2026-08-21, the three-way split of objectui cards into domain:devx / domain:spec / domain:ui).
Body is authoritative; title and assignee are derived views. Single writer: the sitting seat PM. Comments are audit only and never carry state — except that the read side takes body + comments newer than the body's last edit, so a comment posted after this edit is the current value until the next fold.
Versioned job description: objectstack:.claude/skills/pm-dispatch/references/lanes/ui.md (read this round at 7aae005).
Body current as of 2026-09-11T02:5xZ, read back after posting. R16 takeover fold. Round-open marker: 5628557417.
0. ⛔⛔ HANDOVER POINTERS — carry this section into every rewrite of this post
objectui#7089 and objectui#7233 are the two written handovers for THIS seat. They are documents to read, ⛔ not work to dispatch.
⚠️This section exists because the pointer was LOST.#7233's own body says it is "linked from the seat post #5560" — it was not: the link vanished across successive seat-post rewrites. #7233 warns about exactly this failure mode and then became its victim. ⇒ If you rewrite this body, this section survives.
Both carry pm:queue + priority:p1deliberately. The seat hung pm:retriage on both (objectui#7233 comment 5615838671, objectui#7089 comment 5615843493). ⛔ Neither is closed. Still awaiting the triage seat — unchanged at R16.
0a. ⛔⛔⛔ needs:contract-review — READ THIS BEFORE WRITING ANY CLAIM
⚠️ An R10 "governance escalation" arguing this label is underdetermined in this lane was wrong and is withdrawn. Retraction with sources: objectui#8568 comment 5625952236.
The contract, re-read at source this round at 7aae005:
where
what it says
objectstack/.claude/agents/os-dev.md
a Clause-②: yes claim ⇒ the DEV hangs the label on both carriers with the draft PR, and reports the --pair exit code
SKILL.md 〈入队与落地〉
a Clause-②: yesclaim hangs the card-side carrier in the same stroke — that half is the PM's
contract-review.md 复核归属
ownership is the dispatching seat's; for non-spec seats the clause-② review IS default-tier in-seat self-review plus the gates
contract-review.md 降档保险丝
the tier fuse binds only the spec seat and the skills seat — ⛔ not this lane
contract-review.md 清标即落地
PASS ⇒ the SEAT strips both carriers in one stroke, with a provenance comment citing the record id and the judged head
⭐ CORRECTED AT R16 — the charter moved on 2026-09-10T16:50Z and this rule changed. The previous body said "carriers stay hung when there is no PASS." The current text says 「FAIL 同 PASS 剥双载体」 — a FAIL also strips both carriers, leaving a handover comment on the card (citing the review, the independence pair, and what is owed) with card state and assignee unmoved.
⇒ the correct rule is: carriers hang only while NO review record exists. ⛔ Not "until PASS". The operational consequence for objectui#9078 is unchanged — it has no review of any kind — but the reason is narrower than the old wording.
⭐ ALSO NEW AT 7aae005 — the review record now has a REQUIRED SHAPE (同形). A conforming record carries: a ## Contract review heading · the reviewed head sha · items ①②③ (derived judgments / semver / boundary flags) · an independence pair · a PASS/FAIL verdict.
Implemented-by: the dev's claude/issue-N branch (a mode:subagent dev has no session of its own)
Reviewed-by: the reviewing seat's session id
Same session on both lines ⇒ report SELF-REVIEW, ⛔ not an independent review. The four exemplary trails this post used to cite (objectui#9072/#8728 · #9075/#8632 · #9080/#9020 · #9093/#8729) all predate the 同形 requirement — ⛔ do not copy their shape, copy 5628635238.
⭐ Exercised once under the new shape and it landed clean: objectui#9090 / card objectui#9053. Review 5628635238, provenance 5628648763, --pair 9090 exit 0.
⭐ Hang additively:POST .../issues/N/labelsadds; an issue_write update replaces the whole set.
⛔ Never tell a dev not to hang it. A standing contract outranks a PM's prose. ⚠️check-clause2-carriers.mjs lives in objectstack, and it defaults to the objectstack board. ⇒ PM_SWEEP_REPO=objectstack-ai/objectui node scripts/pm/check-clause2-carriers.mjs --pair N. Without it the script answers about the wrong repo and says so in a line easy to skim past. ⚠️PAIR-EXIT=$? after a pipe captures the pipe's exit code, not the script's — redirect to a file, then read it. ⚠️Disclosed by the predecessor and still owed: pre-landing check ② was not satisfied on that session's earlier clause-② landings, because the label was never hung. Nothing landed that the in-seat review had not passed. Whether to backfill is the maintainer's.
⛔ Do NOT clear it on objectui#8568 — provenance predates that session; it belongs to the maintainer or the director seat.
0b. ⛔⛔ HOW TO READ THE QUEUE
① THE CARD BODY'S FRAMING OF ITS DISPOSITION IS NOT ITS STATE. Measured SIX times.
Rulings land as comments; the body is never rewritten. #8568 · #8496 · #8778 · #8770 · #8958 · and at R16 #9053, whose stated blocker was discharged by a triage comment the body cannot know about.
② A TRUNCATED ENUMERATION READS LIKE A SHORT QUEUE.
list_issues on TWO labels returns the UNION and truncates silently. ⭐ Fix: single label, fieldsomitting body, perPage:100, then intersect locally. ⭐ Always cross-check against totalCount. ⚠️list_pull_requestsblows the context budget outright.
③ ⚠️ Do not over-correct. Verified genuinely unruled: #8824, #8817, #8885 Part 2, #8826 Q1/Q2, #8509.
④ ⭐⭐⭐ A TRIAGE RULING IS NOT SELF-SUFFICIENT — AND NEITHER IS ITS MEASUREMENT.
⑤ WRITE THE CLAIM COMMENT BEFORE LAUNCHING THE AGENT.
Claim: line plus a bare Clause-②: yes|no. Only bare yes/no parse; without it check-clause2-carriers reads exit 4. ⚠️ The declaration must survive a route the dev has not chosen yet. ⛔ Declaring no and revising on delivery is not available. ⇒ 「拿不准 ⇒ 按 yes」, and say in the claim why, so the in-seat review is not re-deriving the reason.
⑥ ⭐ TWO SEATS CAN GRADE THE SAME OPTION DIFFERENTLY — NOT THIS SEAT'S TO BREAK.
objectui#8631: triage says work-lane; a peer PM seat says ruling-versus-ruling and above the execution seat. Triage's "neutral unavailable affordance" IS the peer seat's option B, and the objection to B is not safety but that its copy "silently collapses two cards into one sentence". ⇒ ⛔ NOT dispatched; conflict at 5626536182, needs one maintainer sentence.
⑦ ⭐⭐⭐ §0b① APPLIES TO THIS SEAT'S OWN PRs, AND IT COST A DUPLICATE.
A PR body is frozen at PR-open time. When the seat's instruction is later withdrawn, the dev's faithful transcription of it stays in the body and reads like current state. On objectui#9075 that produced a duplicate PASS and a false claim about a dev who had done everything right (corrected at 5627159432).
⇒ ⛔ Before acting on any PR, read this post and the PR's COMMENTS first. The body is the oldest artefact on the page, not the newest.
1. 当前 PM
status
🟢 SEATEDsession_01UzHd6hDYatoDn17BuwKxnZ, GitHub identity os-tesla (id 327383522, measured with get_me, ⛔ not inherited), from the predecessor's explicit handover at 00:55Z
predecessor
session_01MPaVWWMuWeT5LgB1qoXjVB (os-steve), R1–R15, stood down on maintainer instruction
batch
3
posture
⛔ The R2 autonomous-dispatch grant (5617543680) is NOT inherited — it carries its own successor clause saying so verbatim. This seat runs the standing protocol, which independently gives 「可逆且有推荐默认的事项按否决窗口:声明即执行,异议再回滚」. Same latitude, from the charter rather than a spent session grant. Manual floor untouched: feature additions · ADRs · protocol/public-contract changes · breaking or hard-to-reverse acts · security/permission boundaries · gate weakening · cost/quota/fleet shape · new runtime third-party deps
charter
SKILL.md + core-rules + lane charter all at 7aae005 (2026-09-10T16:50:20Z). All three moved since the last marker ⇒ re-read in full. git diff HEAD origin/main -- .claude/skills/pm-dispatch/ empty
tier
lane default for BOTH build and review (maintainer ruling 5612097546; objectstack#17285). The seat's own default-tier review plus the gates is the review of record
⚠️scripts/pm/dispatch-gates.mjs has no objectui copy. Run against an objectui path it answers 「A card landing in another repo derives nothing here」 and 「no path-derived mandate」. ⇒ the tier is the seat's per-card judgement; quote that output in the claim rather than implying a mandate exists.
2. Ledger
Inherited from the predecessor: 34 PRs landed, R1–R14. ⛔ Not re-reviewed, ⛔ not re-listed — see the R15 handover body in this post's history and comment 5627651426. Its last two (objectui#9080 / card #9020 and objectui#9093 / card #8729) were left running unattended and both landed; verified at R16 on origin/main by squash subject (60500cb, 0b138da), ⛔ not by sha and ⛔ not by an ancestor test. Card #9020 was cleaned by the departing seat at 01:20Z; ⛔ no strip was owed.
⛔ columnIdentity is a SHARED helper (packages/core/src/utils/column-identity.ts, 20 importers including both held PRs' files). It is out of surface for every card above; a card that genuinely needs it is a different, wider card. ⚠️A successor obligation created by objectui#9090: the prose row in apps/console/src/__tests__/registry-inputs-spec-parity.test.ts saying a redacted accessorKey column is "kept AND rendered" loses its RENDERED half. No assertion moves, nothing reds. Whoever lands objectui#9058 owns that sentence. ⚠️Adjacency claims AGE inside a round ⇒ tell devs to re-derive; ⛔ never cite this section as fact.
✅ objectui#9090 / card objectui#9053 — REVIEWED AND QUEUED at R16
Ruling B implemented as briefed; ruling A was not implemented and no denied/empty state exists. The A/B fork was ruled B by the floor, not by preference: B restores an invariant with no user-visible change in any non-leaking case, while A adds a rendered state that does not exist today ⇒ a feature addition ⇒ manual floor. ⚠️ Flagged upward: a ruling on a security surface, and a reasonable maintainer might prefer A.
⭐ Its blocker is DISCHARGED, by re-routing rather than by an answer. The predecessor made objectui#9095 gate this PR. Triage closed #9095 as duplicate of objectui#8649 (5627847250) and ruled verbatim: 「⛔ Nothing here touches #9053's in-flight PR. Its repair stands; the declaration question is #8649's and always was.」 ⇒ the "which contract do redactFields / enforceFieldSecurity belong to" question is live and owned by objectui#8649 (domain:spec, p2 — ⛔ not this lane).
⭐ Review-side finding worth keeping: the repair's filterRedacted refuses on accessorKey || columnIdentity(c), byte-identical to the spelling the component renders through at eight sites, and the walk's key becomes the accessor. That identity match is what makes the repair real rather than cosmetic — verify it again if that file is ever refactored.
The stop the predecessor wrote did not fire (7328 files, lit control, zero legitimately-visible columns lost). ⚠️A different condition fired, which the fence failed to name: the repair turns : true into : false ⇒ an all-unresolvable column set yields an empty array; RelatedList gates on non-empty length ⇒ falls through to the schema-derived set, which redactFields never reached. ⭐ objectui#9090 closes that hole — hence the order. On landing: rebase onto it, and pick up the prose-row obligation in §3.
objectui#8434 requires an unresolved reference keep its raw value visible; a pin+docblock written while implementing objectui#2688 requires an unresolved created_by never show its raw opaque id.
⭐ Read #2688 at source rather than accepting the framing: it is a bug report, it locates its defect at schema bypass, and its expected-correct column asks for the resolved name, not an em-dash. ⇒ the opposition is a ruling versus a pin, not two rulings.
⛔ Still manual floor: no card has ruled what an audit footer shows when it cannot resolve. Option C (em-dash on the footer, affordance elsewhere) ruled out. Carriers stay hung because no review record of any kind exists — see the §0a correction; this is not the old "no PASS" rule.
⭐ Dev findings credited: "unresolvable" is one state with six causes and the renderer distinguishes zero; two tests left failing on purpose, because editing them would decide the fork by deleting one side's evidence.
⚠️ objectui#9063 — a standing pin INVERTED, ruled by the seat, flagged upward
Ruling a′ (5508048888) read directly: its budget is DOM elements per record ⇒ provider-independent; its text carves out no provider; its stated hazard is silent truncation and this adds the loud footnote it prescribes. ⇒ applying a′ is this lane's call; re-scoping it would not be. One isolated revertible hunk.
⚠️ objectui#9072 — a ruling premise FALSIFIED, and a regression shipped deliberately
Triage's ruling rested on the bar's rule being the repo's interpretation. It is LOCAL — percentDisplayValue in core is the declared SSOT and four other sites reach its boundary. ⇒ obeying the ruling moved stored values at or below -1 from -5% to -500%. Residue carried by objectui#9071, whose negative-value question is owed upward first.
⚠️ objectui#9085 — a residue objectui#9080 made DETERMINISTIC
buildDatasetDrillFilter (dataset-format.ts:547) writes a bare null for an empty drill bucket. With a second drill dimension or any dashboard filter, :554 merges them and the null key is already dropped ⇒ the drill already returned a superset on both routes. objectui#9080 removed the last accidental, configuration-dependent mitigation. ⭐ Not a new defect class — but now certain rather than intermittent, and it should be graded that way. Repair belongs at the producer; it moves 14 shape pins across plugin-dashboard and plugin-report.
⛔ objectui#8564 — RETURNED TO TRIAGE, no PR
pm:queue + pm:retriage, assignee cleared. Premise dead in both halves; full record 5626652690. ⚠️ Triage's 11-file count HOLDS; its "1 of 11 repaired" does NOT — 6 of the 9 DOM files are repaired. ⛔ Shared-helper route CONTRAINDICATED. ⇒ recommend close as superseded; closure is triage's.
⚠️#8883 HELD (URL grammar; serialise with #8882). ⛔ #8631 not dispatchable (§0b⑥).
⛔ Owed to the maintainer
item
what it needs
objectui#8672
⭐ NEW at R16 — A (wire dependsOn on lookup action params) or B (remove the residue)? Seat recommends B, four axes aligned, both arms manual floor. Full card 5628669335
objectui#9071
⭐ which authority the percent chip reads — and the -500% regression specifically
Half-state patrol — ⚠️ measured again at R16: UNAVAILABLE
half-state-patrol.yml:271 resolves the anchor from repository variable HALF_STATE_ANCHOR_ISSUE; :142 records that an unset variable is a SUPPORTED configuration delivering to the run summary only. Repository variables are outside an agent seat's API surface. Proxy reading taken this fire: of 7 open tracking cards, none is a patrol anchor. ⇒ record the leg UNAVAILABLE — NOT MEASURED, ⛔ never as passed. ⚠️ Re-measure every round; ⛔ do not inherit this line.
⚠️Unresolved config conflict, inherited: the session attribution template names a model in Co-Authored-By while the standing contract forbids any model identifier in a pushed artifact. The predecessor ruled the prohibition governs; this seat continues that. ⛔ Not reconciled at source.
⛔ Triage gaps found at R16, ⛔ not acted on
#8672 carries finding after a full dispatch and a merged PR (「定级即离标」) and has no priority:*. #9050 has no priority. Grading is triage's.
5. 说明 — lane facts
② Fixes auto-close does NOT strip pm:* or the assignee. THIRTY-ONE for thirty-one. ⇒ clean it explicitly, every time.
③ get_status returns only commit STATUSES, ⛔ never check runs. Read Lint and Type Check individually.
④ ⭐⭐⭐ VERIFICATION IS THE QUEUE-REF POSITIVE HIT, NEVER THE ECHO — see ㊹. ⛔ Never re-arm inside the lag window (29s–14min). ⭐ The ref name encodes the base, so queue order is readable from one ls-remote. ⭐ The ref disappearing while main advances is the landing signal — then verify by CONTENT.
⑦ A POSITIVE CONTROL PROVES THE INSTRUMENT WORKS — NOT THAT THE TREE IS CURRENT.
⑧ ⭐⭐ A LITERAL GREP CANNOT SEE A COMPUTED EMITTER, and a bare COUNT cannot tell code from prose. ⇒ print the line.
⑪ search_issues false zeros are SEAT-DEPENDENT. Devs correctly fall back to a bounded REST listing with a lit control and declare the channel switch.
⑫ A MEASUREMENT IS A CLAIM WITH A TIMESTAMP — a card body, its absence claims, and a triage comment's figures (§0b④).
⑭ AN ASSERTION THAT PASSES IS NOT ONE THAT WITNESSES.
⑰ A CARD'S OWN MEMBER LIST IS A CLAIM, NOT A CENSUS. objectui#9000's "four widgets" is three; objectui#8729's "one name site" is three.
㉑ A git grep PATHSPEC GLOB MATCHES THE WHOLE PATH, ⛔ NOT A DIRECTORY PREFIX.packages/*/src returns ZERO with no error; packages/*/src/** works.
㉕ "NOT THE SAME DEFECT, THE TYPE FORBIDS IT" CAN REST ON READING THE WRONG DECLARATION ⇒ undeclared is not unreachable.
㉗ TWO PRs CAN MOVE THE SAME SEMANTIC SURFACE AND AGREE IN EITHER LANDING ORDER ⇒ measure before spending a slot.
㉘ ⚠️ TIMER HYGIENE. ONE timer, "supersedes all earlier timers". ⚠️A SPENT ONE-SHOT ACCEPTS AN UPDATE SILENTLY AND NEVER FIRES.⚠️list_triggers blows the context budget — read it back with python3 over the saved tool-result file.
㉛ A GATE THAT CANNOT RUN IS NOT A GATE THAT PASSED.check:doc-snippets, check:doc-examples, check:readme-exports, check:sdui-registration-pins exit 2 without a full build. Same class: a missing script name (ERR_PNPM_NO_SCRIPT) is never a verdict, the shared verify lock's exit 99 = queue-timeout = NOT MEASURED, and a vitest run killed by SIGTERM exits 144.
㉜ ⚠️ the body-PATCH double-footer trap is CONDITIONAL, condition not isolated. Two MCP body patches on objectui#9075 read back one footer; objectui#9080's dev measured the opposite over REST. ⇒ the channel is implicated. ⛔ One clean observation is not a repeal, and ⛔ do not cite ㉜ as a reason to leave a false sentence in a body. ⚠️ The angle-bracket sanitizer is separate and still live: an opening bracket plus a letter is stripped from bodies, backticks do NOT protect it, comments are safe. Read back every body you post.
㉞ THE SEAT'S OWN ACCEPTANCE ORACLE CAN BE THE WRONG INSTRUMENT ⇒ measure which door the product actually uses.
㊲ ADDING A PARAMETER CAN CREATE A BUG IN A POINT-FREE CALLER.Array#map hands the callback the index; index 0 reads as absent.
㊳ AN EMPTY COLLECTION IN A FAILURE MESSAGE IS THE TELL FOR AN UN-AWAITED RENDER.
㊴ ⭐⭐⭐ A PR'S base.sha IS THE BASE BRANCH'S CURRENT TIP, ⛔ NOT ITS MERGE-BASE. Re-confirmed at R16 on objectui#9090: reported 16fc4cf2, real merge-base f1190b0. ⇒ use git merge-base.
㊵ ⭐⭐ git merge-tree --write-tree BASE HEAD IS A CONFLICT PROBE THAT TOUCHES NO WORKTREE. Exit 0 ⇒ no textual conflict.
㊶ ⭐⭐ VERIFY THE ONE CLAIM THAT WOULD CHANGE THE VERDICT, NOT THE WHOLE REPORT. ⭐ objectui#9090's whole verdict hung on "the filter refuses on the identity the component renders through" — checked at eight call sites before passing it.
㊷ ⭐⭐⭐ pnpm --filter 'PKG^...' IS DEPENDENCIES OF. DEPENDENTS IS pnpm --filter '...PKG' (leading dots).
㊸ ⭐⭐⭐ A HARD STOP CATCHES ONLY WHAT IT NAMES, AND THE INVERSE HAZARD IS THE ONE IT MISSES. ⇒ when fencing a narrowing change on a security surface, ask "what does the system do when this filter removes EVERYTHING?"
㊹ ⭐⭐⭐ enable_pr_auto_merge CAN RETURN ITS SUCCESS STRING AND DO NOTHING. The success string is not evidence — at R16 its echo again came back with a blank method: and a blank enabled-at. ⭐ Verify by queue ref; inside the lag window wait; past it re-arm exactly ONCE and say so.
㊺ ⭐⭐ A TEST FILE UNDER packages/*/src COUNTS AS PUBLISHED SOURCE for check-changeset-presence. The gate's own named exemption is an EMPTY-frontmatter changeset. ⇒ obey the gate, not the note.
㊻ ⭐⭐⭐ A STANDING CONTRACT OUTRANKS THIS SEAT'S PROSE, AND THE SEAT IS NOT EXEMPT FROM ITS OWN RULE. ⇒ ⛔ before escalating a rule as broken, read the rule's own document to the end.
㊽ ⭐⭐⭐ THE STATE CARRIER IS THIS POST AND THE COMMENTS, ⛔ NEVER A PR BODY — INCLUDING THIS SEAT'S OWN. ⇒ when a duplicate does happen, correct it by name on the same surface.
㊾ ⭐⭐⭐ git merge-base --is-ancestor IS THE WRONG INSTRUMENT FOR A SQUASH-MERGED PR. IT FALSE-NEGATIVES ON EVERY ONE. ⭐ Use the commit log (the squash carries the PR number), or the PR's own state/merged — then still verify by CONTENT.
㊿ ⭐⭐⭐ NEW at R16 — THIS CHECKOUT IS SHALLOW (50 commits), AND SHALLOWNESS ANSWERS bad object WITH A STRAIGHT FACE.git cat-file -t on a sha six days old said bad object; git fetch origin SHA --depth=1 made it present immediately. ⇒ ⛔ a "missing" object here is an artifact until you have tried to fetch it. Same class as ㉑ and ⑧: the tool answered confidently about a population it could not see.
(51) ⭐⭐⭐ NEW at R16 — git grep -l SYMBOL IS A SUBSTRING MATCH AND IT WILL HAND YOU THE WRONG FILE. Looking for normalizeVisible returned normalize-list-view.ts, which contains only normalizeVisibleWhen. The seat published that wrong location in a claim before catching it. ⇒ use git grep -nw for any symbol lookup, and when a symbol comes from a minified bundle (as objectui#9100's did) expect it to have no source spelling at all.
(52) ⭐⭐ NEW at R16 — CMD | tail MAKES $? THE EXIT CODE OF tail. A gate run whose verdict you capture after a pipe has no verdict. ⇒ redirect to a file, capture $? on the next line, then read the file.
Inherited lane facts — ⛔ none re-verified by this takeover
⭐⭐⭐ A scripted scroll is NOT a reachability measurement — drive page.mouse.wheel.
⭐⭐⭐ A PM landing and a dev's finalisation RACE, and the dev's write wins silently. ⇒ ⛔ do not touch a PR until its agent has returned.
⭐⭐⭐ Put YOUR OWN readings in the premise-verification gate (#7089 §6, #7233 §1).
⭐⭐ The governed surface is exactly five paths: docs/adr/** · .claude/** · skills/** · AGENTS.md · CLAUDE.md. Always --test AGENTS.md as the lit control.
⭐⭐ No gate parses a plaintext fence ⇒ acceptance must be render output.
⭐ A zero needs a lit control every time — and the control must be able to fail for the same reason the subject would. At R16 a branch-existence probe used a merged card as its control; its branch was deleted on merge, so the control was dead for an unrelated reason and the reading had to be retaken.
⭐ git grep -c counts LINES, not entries.
⭐ Landing verification is by CONTENT with a control proven to fire BEFORE the merge, ⛔ never by sha, ⛔ never by an ancestor test (㊾).
⭐ PREREQUISITE NOT MET = NOT MEASURED.
⭐ Line numbers in a card are stale by default — ⚠️ but only by default. ⇒ re-derive. At R16 a pre-measurement's DetailView gates at :1653/:1804 measured at :1691/:1842.
⭐ Live E2E (informational) is NO LONGER red-by-design. · A workflow RUN's conclusion can assert the opposite of its JOB's.
⭐ happy-dom / jsdom report clientWidth 0, but grid rows DO render. Use /opt/pw-browsers; ⛔ never playwright install. ⚠️Check-run pagination must keep ONE page size.
⭐ rerun_failed_jobs on the RUN id re-runs only the failed jobs. ⛔ never a strategy — and ⛔ never before checking ㊼. ⚠️issue_read with get_labels does NOT resolve a PR number — use pull_request_readget for a PR's labels. ⚠️ But issue_writedoes accept a PR number for a label write (used at R16 to clear objectui#9090's carrier). ㊼ ⭐⭐⭐ WHEN A NOT-THIS-PR FAILURE HAS A FIX ALREADY ON main, MERGE THE BASE IN. ⛔ DO NOT RE-RUN. objectui#9035 cost three PRs a cycle.
Tooling traps — ⛔ pnpm --filter PKG build --concurrency=2 dies; use pnpm --workspace-concurrency=2 --filter PKG build, flag BEFORE --filter · ⛔ pnpm --filter PKG exec vitest is refused by the #3378 guard (a false green) — run from the repo ROOT · ⭐ dependents is ...PKG (㊷) · ⛔ never --no-inline-config on eslint here · shared verify lock at /home/user/objectstack/scripts/pm/os-verify-lock.sh · ⛔ scripts/pm/dispatch-gates.mjs does NOT exist in objectui · ⭐ check-clause2-carriers.mjs lives in objectstack and defaults to the objectstack board (§0a) · ⚠️ this repo spells it check-control-bytes.mjs · ⚠️@objectstack/spec does not resolve from the primary checkout but does inside a worktree's node_modules · governed surfaces are enforced at merge_group and refuse rather than audit.
Platform traps — ⛔ the angle-bracket sanitizer eats issue and PR BODIES — spell placeholders as words · ⚠️ ㉜ the double-footer half is channel-conditional · ⭐ list_issues with two labels returns the UNION and truncates (§0b②); list_pull_requests blows the budget outright · get_job_logs returns only the TAIL · the closing-keyword parser ignores negation · skip-changeset is inert here · this repo forbids major, so a breaking change ships minor with the break spelled out · ⭐ cross-check any enumeration against totalCount.
⭐ The standing lesson
Every one of the predecessor's worst errors was caught by a dev, or by re-reading its own record — and R16 opened by catching two of its own inside twenty minutes (a substring grep that published a wrong file location, and a shallow-clone bad object read as a missing commit).
⇒ tell devs explicitly that PM claims are in scope for falsification, and that a clean stop on a falsified PM premise is a full success. Every brief carries a ZONE 2 block of the seat's own assumptions, named as the seat's.
Seat registration post for the
domain:uilane — the objectui execution seat (maintainer ruling 2026-08-21, the three-way split of objectui cards intodomain:devx/domain:spec/domain:ui).Body is authoritative; title and assignee are derived views. Single writer: the sitting seat PM. Comments are audit only and never carry state — except that the read side takes body + comments newer than the body's last edit, so a comment posted after this edit is the current value until the next fold.
Versioned job description:
objectstack:.claude/skills/pm-dispatch/references/lanes/ui.md(read this round at7aae005).Body current as of 2026-09-11T02:5xZ, read back after posting. R16 takeover fold. Round-open marker:
5628557417.0. ⛔⛔ HANDOVER POINTERS — carry this section into every rewrite of this post
objectui#7089 and objectui#7233 are the two written handovers for THIS seat. They are documents to read, ⛔ not work to dispatch.
Both carry
pm:queue+priority:p1deliberately. The seat hungpm:retriageon both (objectui#7233 comment 5615838671, objectui#7089 comment 5615843493). ⛔ Neither is closed. Still awaiting the triage seat — unchanged at R16.0a. ⛔⛔⛔
needs:contract-review— READ THIS BEFORE WRITING ANY CLAIM5625952236.The contract, re-read at source this round at
7aae005:objectstack/.claude/agents/os-dev.mdClause-②: yesclaim ⇒ the DEV hangs the label on both carriers with the draft PR, and reports the--pairexit codeClause-②: yesclaim hangs the card-side carrier in the same stroke — that half is the PM'scontract-review.md复核归属contract-review.md降档保险丝contract-review.md清标即落地⭐ CORRECTED AT R16 — the charter moved on 2026-09-10T16:50Z and this rule changed. The previous body said "carriers stay hung when there is no PASS." The current text says 「FAIL 同 PASS 剥双载体」 — a FAIL also strips both carriers, leaving a handover comment on the card (citing the review, the independence pair, and what is owed) with card state and assignee unmoved.
⇒ the correct rule is: carriers hang only while NO review record exists. ⛔ Not "until PASS". The operational consequence for objectui#9078 is unchanged — it has no review of any kind — but the reason is narrower than the old wording.
⭐ ALSO NEW AT
7aae005— the review record now has a REQUIRED SHAPE (同形). A conforming record carries: a## Contract reviewheading · the reviewed head sha · items ①②③ (derived judgments / semver / boundary flags) · an independence pair · a PASS/FAIL verdict.Same session on both lines ⇒ report SELF-REVIEW, ⛔ not an independent review. The four exemplary trails this post used to cite (objectui#9072/#8728 · #9075/#8632 · #9080/#9020 · #9093/#8729) all predate the 同形 requirement — ⛔ do not copy their shape, copy
5628635238.⭐ Exercised once under the new shape and it landed clean: objectui#9090 / card objectui#9053. Review
⚠️ ⚠️
⚠️ Disclosed by the predecessor and still owed: pre-landing check ② was not satisfied on that session's earlier clause-② landings, because the label was never hung. Nothing landed that the in-seat review had not passed. Whether to backfill is the maintainer's.
5628635238, provenance5628648763,--pair 9090exit 0.⭐ Hang additively:
POST .../issues/N/labelsadds; anissue_writeupdate replaces the whole set.⛔ Never tell a dev not to hang it. A standing contract outranks a PM's prose.
check-clause2-carriers.mjslives inobjectstack, and it defaults to the objectstack board. ⇒PM_SWEEP_REPO=objectstack-ai/objectui node scripts/pm/check-clause2-carriers.mjs --pair N. Without it the script answers about the wrong repo and says so in a line easy to skim past.PAIR-EXIT=$?after a pipe captures the pipe's exit code, not the script's — redirect to a file, then read it.⛔ Do NOT clear it on objectui#8568 — provenance predates that session; it belongs to the maintainer or the director seat.
0b. ⛔⛔ HOW TO READ THE QUEUE
① THE CARD BODY'S FRAMING OF ITS DISPOSITION IS NOT ITS STATE. Measured SIX times.
Rulings land as comments; the body is never rewritten. #8568 · #8496 · #8778 · #8770 · #8958 · and at R16 #9053, whose stated blocker was discharged by a triage comment the body cannot know about.
② A TRUNCATED ENUMERATION READS LIKE A SHORT QUEUE.
list_issueson TWO labels returns the UNION and truncates silently. ⭐ Fix: single label,fieldsomittingbody,perPage:100, then intersect locally. ⭐ Always cross-check againsttotalCount.list_pull_requestsblows the context budget outright.③⚠️ Do not over-correct. Verified genuinely unruled: #8824, #8817, #8885 Part 2, #8826 Q1/Q2, #8509.
④ ⭐⭐⭐ A TRIAGE RULING IS NOT SELF-SUFFICIENT — AND NEITHER IS ITS MEASUREMENT.
object-grid's private array-arm lowering interpolates missing keys into$orderby— aSortConfigwithorderomitted goes out asname undefined#8973 — triage's route was declined by the maintainer by name, unmentioned by triage ⇒ narrowed (5623522229).groupBybranch, so an authored{ field, dateGranularity }node is posted as an analytics DIMENSION object #8613 — triage's landing-site line names the path the card quotes as its contrast ⇒ overridden (5624381436).highlightFieldsbranch callsfilterFLSliterally while the heuristic walk inlines the identicalperms.checkFieldpredicate ⇒ FLS is re-applied on the derived path, so p2 and "push redaction down" both stand — now pinned as a test case rather than left in prose.properties.visibleloses its CEL envelope and is evaluated on the LEGACY JS engine —has()faults and the fail-soft default renders the banner on every row #9100 — the same discipline, applied at claim time (R16). Triage's card namednormalizeVisibleas the faulty normalizer. That is a minified bundle identifier with no source symbol; the real one istoPredicateInput, and the action path that works calls it too — so a shared normalizer cannot by itself be the discriminator. Correction posted before the dev started (5628606370).⑤ WRITE THE CLAIM COMMENT BEFORE LAUNCHING THE AGENT.
Claim:line plus a bareClause-②: yes|no. Only bareyes/noparse; without itcheck-clause2-carriersreads exit 4.noand revising on delivery is not available. ⇒ 「拿不准 ⇒ 按yes」, and say in the claim why, so the in-seat review is not re-deriving the reason.⑥ ⭐ TWO SEATS CAN GRADE THE SAME OPTION DIFFERENTLY — NOT THIS SEAT'S TO BREAK.
objectui#8631: triage says work-lane; a peer PM seat says ruling-versus-ruling and above the execution seat. Triage's "neutral unavailable affordance" IS the peer seat's option B, and the objection to B is not safety but that its copy "silently collapses two cards into one sentence". ⇒ ⛔ NOT dispatched; conflict at
5626536182, needs one maintainer sentence.⑦ ⭐⭐⭐ §0b① APPLIES TO THIS SEAT'S OWN PRs, AND IT COST A DUPLICATE.
A PR body is frozen at PR-open time. When the seat's instruction is later withdrawn, the dev's faithful transcription of it stays in the body and reads like current state. On objectui#9075 that produced a duplicate PASS and a false claim about a dev who had done everything right (corrected at
5627159432).⇒ ⛔ Before acting on any PR, read this post and the PR's COMMENTS first. The body is the oldest artefact on the page, not the newest.
1. 当前 PM
session_01UzHd6hDYatoDn17BuwKxnZ, GitHub identityos-tesla(id 327383522, measured withget_me, ⛔ not inherited), from the predecessor's explicit handover at 00:55Zsession_01MPaVWWMuWeT5LgB1qoXjVB(os-steve), R1–R15, stood down on maintainer instruction5617543680) is NOT inherited — it carries its own successor clause saying so verbatim. This seat runs the standing protocol, which independently gives 「可逆且有推荐默认的事项按否决窗口:声明即执行,异议再回滚」. Same latitude, from the charter rather than a spent session grant. Manual floor untouched: feature additions · ADRs · protocol/public-contract changes · breaking or hard-to-reverse acts · security/permission boundaries · gate weakening · cost/quota/fleet shape · new runtime third-party deps7aae005(2026-09-10T16:50:20Z). All three moved since the last marker ⇒ re-read in full.git diff HEAD origin/main -- .claude/skills/pm-dispatch/empty5612097546; objectstack#17285). The seat's own default-tier review plus the gates is the review of recordRestart-when:named the tier budget are half-discharged and not yet worked: #4795 #5521 #6033 #6170 #6262 #6349 #6497 #6795 #7175 #7192 #7206 #7299 #7561 #7650 #7659 #7682 #7946 #8024 #8086 #8151 #8220 #8268 #8285 #8292 #8294 #8303 #8310 #8320 #8355 #8442 #8576 #8897 #8900.scripts/pm/dispatch-gates.mjshas no objectui copy. Run against an objectui path it answers 「A card landing in another repo derives nothing here」 and 「no path-derived mandate」. ⇒ the tier is the seat's per-card judgement; quote that output in the claim rather than implying a mandate exists.2. Ledger
Inherited from the predecessor: 34 PRs landed, R1–R14. ⛔ Not re-reviewed, ⛔ not re-listed — see the R15 handover body in this post's history and comment
5627651426. Its last two (objectui#9080 / card #9020 and objectui#9093 / card #8729) were left running unattended and both landed; verified at R16 onorigin/mainby squash subject (60500cb,0b138da), ⛔ not by sha and ⛔ not by an ancestor test. Card #9020 was cleaned by the departing seat at 01:20Z; ⛔ no strip was owed.R16 (this session)
5628635238), both carriers cleared (5628648763),--pair0, ready, auto-merge SQUASH armed, QUEUED — refmain/pr-9090-d2f0c108…verified present, ⛔ not the echo stringClause-②: yesState repairs made this round, ⛔ no code:
dependsOnis gated PERMANENTLY —ActionParamDialogsupplies nodependentValuesto lookups, so nothing can ever lift the gate #8672 — waspm:dispatchedtoos-justinand silent ~38h. ⛔ Not a dead claim: itsPart ofPR objectui#8749 merged 2026-09-09, measurement complete, and nothing released the card. Two-day half-state. ⇒ assignee cleared, moved toneeds-user-decisionwith a four-axis block and a 维护者速读 (5628669335). Recommendation B (remove), four axes aligned; ⛔ both arms are manual floor so it is not auto-adjudicated.flattenedscope and advertises bare fields — declared-but-unbound once #5741 (Phase 2) retires the bare-field binding #7727 —pm:dispatchedtoos-justin, ~38h silent, no referencing PR and no remote branch (zero proved with a lit control after the first control turned out to be dead for an unrelated reason). ⛔ Not declared dead. Enquiry posted with a stated release window of 2026-09-11T14:00Z (5628677645).3. 热文件串行队
plugin-detail/src/RelatedList.tsx+renderers/record-related-list.tsxplugin-detail/src/renderers/record-details.tsxcore/src/evaluator/predicateInput.ts·app-shell/src/providers/ExpressionProvider.tsx·plugin-detail/src/renderers/record-alert.tsx⛔
⚠️ A successor obligation created by objectui#9090: the prose row in
⚠️ Adjacency claims AGE inside a round ⇒ tell devs to re-derive; ⛔ never cite this section as fact.
columnIdentityis a SHARED helper (packages/core/src/utils/column-identity.ts, 20 importers including both held PRs' files). It is out of surface for every card above; a card that genuinely needs it is a different, wider card.apps/console/src/__tests__/registry-inputs-spec-parity.test.tssaying a redactedaccessorKeycolumn is "kept AND rendered" loses its RENDERED half. No assertion moves, nothing reds. Whoever lands objectui#9058 owns that sentence.4. ⛔ Fences
Inherited binding fences — ⛔ not re-litigated
#8442 · #8426 · #8365⚠️ #7199 / #7559 are NOT #7234's defect · ⛔ #4695 · #3988 (escalated on #8773) · ⚠️ #6830 withdrawn, real work is #8488 · #8961
pm:retriage· #8348 · #7561 · #7650 · #6864 · #7740 · #7635 ·pm:blocked.✅ objectui#9090 / card objectui#9053 — REVIEWED AND QUEUED at R16
Ruling B implemented as briefed; ruling A was not implemented and no denied/empty state exists. The A/B fork was ruled B by the floor, not by preference: B restores an invariant with no user-visible change in any non-leaking case, while A adds a rendered state that does not exist today ⇒ a feature addition ⇒ manual floor.⚠️ Flagged upward: a ruling on a
securitysurface, and a reasonable maintainer might prefer A.⭐ Its blocker is DISCHARGED, by re-routing rather than by an answer. The predecessor made objectui#9095 gate this PR. Triage closed #9095 as
duplicateof objectui#8649 (5627847250) and ruled verbatim: 「⛔ Nothing here touches #9053's in-flight PR. Its repair stands; the declaration question is #8649's and always was.」 ⇒ the "which contract doredactFields/enforceFieldSecuritybelong to" question is live and owned by objectui#8649 (domain:spec, p2 — ⛔ not this lane).⭐ Review-side finding worth keeping: the repair's
filterRedactedrefuses onaccessorKey || columnIdentity(c), byte-identical to the spelling the component renders through at eight sites, and the walk'skeybecomes the accessor. That identity match is what makes the repair real rather than cosmetic — verify it again if that file is ever refactored.🛑🛑 objectui#8793 / PR objectui#9058 — HELD, unblocks when objectui#9090 lands
The stop the predecessor wrote did not fire (7328 files, lit control, zero legitimately-visible columns lost).⚠️ A different condition fired, which the fence failed to name: the repair turns
: trueinto: false⇒ an all-unresolvable column set yields an empty array;RelatedListgates on non-empty length ⇒ falls through to the schema-derived set, whichredactFieldsnever reached. ⭐ objectui#9090 closes that hole — hence the order. On landing: rebase onto it, and pick up the prose-row obligation in §3.🛑🛑 objectui#8695 / PR objectui#9078 — HELD,
pm:blocked, carriers deliberately STILL HUNGobjectui#8434 requires an unresolved reference keep its raw value visible; a pin+docblock written while implementing objectui#2688 requires an unresolved
created_bynever show its raw opaque id.⭐ Read #2688 at source rather than accepting the framing: it is a bug report, it locates its defect at schema bypass, and its expected-correct column asks for the resolved name, not an em-dash. ⇒ the opposition is a ruling versus a pin, not two rulings.
⛔ Still manual floor: no card has ruled what an audit footer shows when it cannot resolve. Option C (em-dash on the footer, affordance elsewhere) ruled out. Carriers stay hung because no review record of any kind exists — see the §0a correction; this is not the old "no PASS" rule.
⭐ Dev findings credited: "unresolvable" is one state with six causes and the renderer distinguishes zero; two tests left failing on purpose, because editing them would decide the fork by deleting one side's evidence.
Ruling a′ (
5508048888) read directly: its budget is DOM elements per record ⇒ provider-independent; its text carves out no provider; its stated hazard is silent truncation and this adds the loud footnote it prescribes. ⇒ applying a′ is this lane's call; re-scoping it would not be. One isolated revertible hunk.Triage's ruling rested on the bar's rule being the repo's interpretation. It is LOCAL —
percentDisplayValuein core is the declared SSOT and four other sites reach its boundary. ⇒ obeying the ruling moved stored values at or below -1 from-5%to-500%. Residue carried by objectui#9071, whose negative-value question is owed upward first.buildDatasetDrillFilter(dataset-format.ts:547) writes a barenullfor an empty drill bucket. With a second drill dimension or any dashboard filter,:554merges them and the null key is already dropped ⇒ the drill already returned a superset on both routes. objectui#9080 removed the last accidental, configuration-dependent mitigation. ⭐ Not a new defect class — but now certain rather than intermittent, and it should be graded that way. Repair belongs at the producer; it moves 14 shape pins acrossplugin-dashboardandplugin-report.⛔ objectui#8564 — RETURNED TO TRIAGE, no PR
pm:queue+pm:retriage, assignee cleared. Premise dead in both halves; full record5626652690.⛔ Owed to the maintainer
dependsOnon lookup action params) or B (remove the residue)? Seat recommends B, four axes aligned, both arms manual floor. Full card5628669335-500%regression specificallysecuritysurface.accessorKeyauthorable onrecord:related_list.columns?Half-state patrol —⚠️ measured again at R16: UNAVAILABLE
half-state-patrol.yml:271resolves the anchor from repository variableHALF_STATE_ANCHOR_ISSUE;:142records that an unset variable is a SUPPORTED configuration delivering to the run summary only. Repository variables are outside an agent seat's API surface. Proxy reading taken this fire: of 7 opentrackingcards, none is a patrol anchor. ⇒ record the leg UNAVAILABLE — NOT MEASURED, ⛔ never as passed.Co-Authored-Bywhile the standing contract forbids any model identifier in a pushed artifact. The predecessor ruled the prohibition governs; this seat continues that. ⛔ Not reconciled at source.⛔ Triage gaps found at R16, ⛔ not acted on
#8672 carries
findingafter a full dispatch and a merged PR (「定级即离标」) and has nopriority:*. #9050 has no priority. Grading is triage's.5. 说明 — lane facts
②
Fixesauto-close does NOT strippm:*or the assignee. THIRTY-ONE for thirty-one. ⇒ clean it explicitly, every time.③
get_statusreturns only commit STATUSES, ⛔ never check runs. ReadLintandType Checkindividually.④ ⭐⭐⭐ VERIFICATION IS THE QUEUE-REF POSITIVE HIT, NEVER THE ECHO — see ㊹. ⛔ Never re-arm inside the lag window (29s–14min). ⭐ The ref name encodes the base, so queue order is readable from one
ls-remote. ⭐ The ref disappearing whilemainadvances is the landing signal — then verify by CONTENT.⑦ A POSITIVE CONTROL PROVES THE INSTRUMENT WORKS — NOT THAT THE TREE IS CURRENT.
⑧ ⭐⭐ A LITERAL GREP CANNOT SEE A COMPUTED EMITTER, and a bare COUNT cannot tell code from prose. ⇒ print the line.
⑪
search_issuesfalse zeros are SEAT-DEPENDENT. Devs correctly fall back to a bounded REST listing with a lit control and declare the channel switch.⑫ A MEASUREMENT IS A CLAIM WITH A TIMESTAMP — a card body, its absence claims, and a triage comment's figures (§0b④).
⑭ AN ASSERTION THAT PASSES IS NOT ONE THAT WITNESSES.
⑰ A CARD'S OWN MEMBER LIST IS A CLAIM, NOT A CENSUS. objectui#9000's "four widgets" is three; objectui#8729's "one name site" is three.
㉑ A
git grepPATHSPEC GLOB MATCHES THE WHOLE PATH, ⛔ NOT A DIRECTORY PREFIX.packages/*/srcreturns ZERO with no error;packages/*/src/**works.㉕ "NOT THE SAME DEFECT, THE TYPE FORBIDS IT" CAN REST ON READING THE WRONG DECLARATION ⇒ undeclared is not unreachable.
㉗ TWO PRs CAN MOVE THE SAME SEMANTIC SURFACE AND AGREE IN EITHER LANDING ORDER ⇒ measure before spending a slot.
㉘⚠️ TIMER HYGIENE. ONE timer, "supersedes all earlier timers". ⚠️ A SPENT ONE-SHOT ACCEPTS AN UPDATE SILENTLY AND NEVER FIRES. ⚠️
list_triggersblows the context budget — read it back withpython3over the saved tool-result file.㉛ A GATE THAT CANNOT RUN IS NOT A GATE THAT PASSED.
check:doc-snippets,check:doc-examples,check:readme-exports,check:sdui-registration-pinsexit 2 without a full build. Same class: a missing script name (ERR_PNPM_NO_SCRIPT) is never a verdict, the shared verify lock's exit 99 = queue-timeout = NOT MEASURED, and a vitest run killed by SIGTERM exits 144.㉜⚠️ the body-PATCH double-footer trap is CONDITIONAL, condition not isolated. Two MCP body patches on objectui#9075 read back one footer; objectui#9080's dev measured the opposite over REST. ⇒ the channel is implicated. ⛔ One clean observation is not a repeal, and ⛔ do not cite ㉜ as a reason to leave a false sentence in a body. ⚠️ The angle-bracket sanitizer is separate and still live: an opening bracket plus a letter is stripped from bodies, backticks do NOT protect it, comments are safe. Read back every body you post.
㉞ THE SEAT'S OWN ACCEPTANCE ORACLE CAN BE THE WRONG INSTRUMENT ⇒ measure which door the product actually uses.
㊲ ADDING A PARAMETER CAN CREATE A BUG IN A POINT-FREE CALLER.
Array#maphands the callback the index; index0reads as absent.㊳ AN EMPTY COLLECTION IN A FAILURE MESSAGE IS THE TELL FOR AN UN-AWAITED RENDER.
㊴ ⭐⭐⭐ A PR'S
base.shaIS THE BASE BRANCH'S CURRENT TIP, ⛔ NOT ITS MERGE-BASE. Re-confirmed at R16 on objectui#9090: reported16fc4cf2, real merge-basef1190b0. ⇒ usegit merge-base.㊵ ⭐⭐
git merge-tree --write-tree BASE HEADIS A CONFLICT PROBE THAT TOUCHES NO WORKTREE. Exit 0 ⇒ no textual conflict.㊶ ⭐⭐ VERIFY THE ONE CLAIM THAT WOULD CHANGE THE VERDICT, NOT THE WHOLE REPORT. ⭐ objectui#9090's whole verdict hung on "the filter refuses on the identity the component renders through" — checked at eight call sites before passing it.
㊷ ⭐⭐⭐
pnpm --filter 'PKG^...'IS DEPENDENCIES OF. DEPENDENTS ISpnpm --filter '...PKG'(leading dots).㊸ ⭐⭐⭐ A HARD STOP CATCHES ONLY WHAT IT NAMES, AND THE INVERSE HAZARD IS THE ONE IT MISSES. ⇒ when fencing a narrowing change on a security surface, ask "what does the system do when this filter removes EVERYTHING?"
㊹ ⭐⭐⭐
enable_pr_auto_mergeCAN RETURN ITS SUCCESS STRING AND DO NOTHING. The success string is not evidence — at R16 its echo again came back with a blankmethod:and a blank enabled-at. ⭐ Verify by queue ref; inside the lag window wait; past it re-arm exactly ONCE and say so.㊺ ⭐⭐ A TEST FILE UNDER
packages/*/srcCOUNTS AS PUBLISHED SOURCE forcheck-changeset-presence. The gate's own named exemption is an EMPTY-frontmatter changeset. ⇒ obey the gate, not the note.㊻ ⭐⭐⭐ A STANDING CONTRACT OUTRANKS THIS SEAT'S PROSE, AND THE SEAT IS NOT EXEMPT FROM ITS OWN RULE. ⇒ ⛔ before escalating a rule as broken, read the rule's own document to the end.
㊽ ⭐⭐⭐ THE STATE CARRIER IS THIS POST AND THE COMMENTS, ⛔ NEVER A PR BODY — INCLUDING THIS SEAT'S OWN. ⇒ when a duplicate does happen, correct it by name on the same surface.
㊾ ⭐⭐⭐
git merge-base --is-ancestorIS THE WRONG INSTRUMENT FOR A SQUASH-MERGED PR. IT FALSE-NEGATIVES ON EVERY ONE. ⭐ Use the commit log (the squash carries the PR number), or the PR's ownstate/merged— then still verify by CONTENT.㊿ ⭐⭐⭐ NEW at R16 — THIS CHECKOUT IS SHALLOW (50 commits), AND SHALLOWNESS ANSWERS
bad objectWITH A STRAIGHT FACE.git cat-file -ton a sha six days old saidbad object;git fetch origin SHA --depth=1made it present immediately. ⇒ ⛔ a "missing" object here is an artifact until you have tried to fetch it. Same class as ㉑ and ⑧: the tool answered confidently about a population it could not see.(51) ⭐⭐⭐ NEW at R16 —
git grep -l SYMBOLIS A SUBSTRING MATCH AND IT WILL HAND YOU THE WRONG FILE. Looking fornormalizeVisiblereturnednormalize-list-view.ts, which contains onlynormalizeVisibleWhen. The seat published that wrong location in a claim before catching it. ⇒ usegit grep -nwfor any symbol lookup, and when a symbol comes from a minified bundle (as objectui#9100's did) expect it to have no source spelling at all.(52) ⭐⭐ NEW at R16 —
CMD | tailMAKES$?THE EXIT CODE OFtail. A gate run whose verdict you capture after a pipe has no verdict. ⇒ redirect to a file, capture$?on the next line, then read the file.Inherited lane facts — ⛔ none re-verified by this takeover
⭐⭐⭐ A scripted scroll is NOT a reachability measurement — drive⚠️ but only by default. ⇒ re-derive. At R16 a pre-measurement's
⚠️ Check-run pagination must keep ONE page size.
⚠️ ⚠️ But
page.mouse.wheel.⭐⭐⭐ A PM landing and a dev's finalisation RACE, and the dev's write wins silently. ⇒ ⛔ do not touch a PR until its agent has returned.
⭐⭐⭐ Put YOUR OWN readings in the premise-verification gate (#7089 §6, #7233 §1).
⭐⭐ The governed surface is exactly five paths:
docs/adr/**·.claude/**·skills/**·AGENTS.md·CLAUDE.md. Always--test AGENTS.mdas the lit control.⭐⭐ No gate parses a
plaintextfence ⇒ acceptance must be render output.⭐ A zero needs a lit control every time — and the control must be able to fail for the same reason the subject would. At R16 a branch-existence probe used a merged card as its control; its branch was deleted on merge, so the control was dead for an unrelated reason and the reading had to be retaken.
⭐
git grep -ccounts LINES, not entries.⭐ Landing verification is by CONTENT with a control proven to fire BEFORE the merge, ⛔ never by sha, ⛔ never by an ancestor test (㊾).
⭐ PREREQUISITE NOT MET = NOT MEASURED.
⭐ Line numbers in a card are stale by default —
DetailViewgates at:1653/:1804measured at:1691/:1842.⭐
Live E2E (informational)is NO LONGER red-by-design. · A workflow RUN's conclusion can assert the opposite of its JOB's.⭐ happy-dom / jsdom report
clientWidth0, but grid rows DO render. Use/opt/pw-browsers; ⛔ neverplaywright install.⭐
rerun_failed_jobson the RUN id re-runs only the failed jobs. ⛔ never a strategy — and ⛔ never before checking ㊼.issue_readwithget_labelsdoes NOT resolve a PR number — usepull_request_readgetfor a PR's labels.issue_writedoes accept a PR number for a label write (used at R16 to clear objectui#9090's carrier).㊼ ⭐⭐⭐ WHEN A NOT-THIS-PR FAILURE HAS A FIX ALREADY ON
main, MERGE THE BASE IN. ⛔ DO NOT RE-RUN. objectui#9035 cost three PRs a cycle.Tooling traps — ⛔⚠️ this repo spells it ⚠️
pnpm --filter PKG build --concurrency=2dies; usepnpm --workspace-concurrency=2 --filter PKG build, flag BEFORE--filter· ⛔pnpm --filter PKG exec vitestis refused by the #3378 guard (a false green) — run from the repo ROOT · ⭐ dependents is...PKG(㊷) · ⛔ never--no-inline-configon eslint here · shared verify lock at/home/user/objectstack/scripts/pm/os-verify-lock.sh· ⛔scripts/pm/dispatch-gates.mjsdoes NOT exist in objectui · ⭐check-clause2-carriers.mjslives inobjectstackand defaults to the objectstack board (§0a) ·check-control-bytes.mjs·@objectstack/specdoes not resolve from the primary checkout but does inside a worktree'snode_modules· governed surfaces are enforced atmerge_groupand refuse rather than audit.Platform traps — ⛔ the angle-bracket sanitizer eats issue and PR BODIES — spell placeholders as words ·⚠️ ㉜ the double-footer half is channel-conditional · ⭐
list_issueswith two labels returns the UNION and truncates (§0b②);list_pull_requestsblows the budget outright ·get_job_logsreturns only the TAIL · the closing-keyword parser ignores negation ·skip-changesetis inert here · this repo forbidsmajor, so a breaking change shipsminorwith the break spelled out · ⭐ cross-check any enumeration againsttotalCount.⭐ The standing lesson
Every one of the predecessor's worst errors was caught by a dev, or by re-reading its own record — and R16 opened by catching two of its own inside twenty minutes (a substring grep that published a wrong file location, and a shallow-clone
bad objectread as a missing commit).⇒ tell devs explicitly that PM claims are in scope for falsification, and that a clean stop on a falsified PM premise is a full success. Every brief carries a ZONE 2 block of the seat's own assumptions, named as the seat's.