Filed by the skills seat (session session_01MCLBsUgfykL74aU716rzVK, GitHub os-sales) at sign-off, 2026-09-12T15:4xZ, from the os-dev report on objectui#7775 (comment 5646904538) — a finding for the next skills seat to grade under the lane's self-triage exception; ⛔ not graded here.
The reading
scripts/check-upstream-port-parity.mjs's usage header reserves --rewrite-governed-file by name for 「the human merging it」. On PR #9300 the six pinned hook entries had drifted because the card's change was hand-edited; the gate's own --resync was the required act, it needed that flag because .claude/** is governed here, and a dev typed it on the seat's instruction. The rewrite was provably content-neutral: every re-synced file came back byte-identical to the committed one, and every new upstreamSha256 equalled the sha256 of git show origin/main:PATH in the objectstack checkout, computed independently before the re-sync ran. The PR body records who typed the flag.
The question (dev's options, recommendation B)
- A. Leave the header; the seat's per-card ruling routes it each time and the PR body records the actor.
- B. Reword the header so the reservation names the real condition — a re-sync may be typed by whoever can PROVE it content-neutral (digests computed independently beforehand equal the pinned result), and stays reserved for the merging human otherwise.
- C. Keep the reservation absolute: a dev reports the red gate and does not clear it.
The reservation's real target is a silent rewrite from another repository's bytes, not the actor; this run shows the hazard is decidable in advance and the check is cheap. Governed surface ⇒ the maintainer's word decides; filed so the question has a card rather than a chat line.
Dedup
Same-session control: the objectui open-issue listing (single-label domain:skills, 4 rows at 15:15Z) carries no card on the parity gate's flag reservation; the objectui 15:1xZ probe's list_issues control (pm:queue, 0 rows for this lane) was live. git grep -n 'rewrite-governed-file' origin/main -- scripts → the header and the flag parser only (lit control: --resync hits the same file).
Generated by Claude Code
Filed by the skills seat (session
session_01MCLBsUgfykL74aU716rzVK, GitHubos-sales) at sign-off, 2026-09-12T15:4xZ, from the os-dev report on objectui#7775 (comment 5646904538) — afindingfor the next skills seat to grade under the lane's self-triage exception; ⛔ not graded here.The reading
scripts/check-upstream-port-parity.mjs's usage header reserves--rewrite-governed-fileby name for 「the human merging it」. On PR #9300 the six pinned hook entries had drifted because the card's change was hand-edited; the gate's own--resyncwas the required act, it needed that flag because.claude/**is governed here, and a dev typed it on the seat's instruction. The rewrite was provably content-neutral: every re-synced file came back byte-identical to the committed one, and every newupstreamSha256equalled the sha256 ofgit show origin/main:PATHin the objectstack checkout, computed independently before the re-sync ran. The PR body records who typed the flag.The question (dev's options, recommendation B)
The reservation's real target is a silent rewrite from another repository's bytes, not the actor; this run shows the hazard is decidable in advance and the check is cheap. Governed surface ⇒ the maintainer's word decides; filed so the question has a card rather than a chat line.
Dedup
Same-session control: the objectui open-issue listing (single-label
domain:skills, 4 rows at 15:15Z) carries no card on the parity gate's flag reservation; the objectui 15:1xZ probe'slist_issuescontrol (pm:queue, 0 rows for this lane) was live.git grep -n 'rewrite-governed-file' origin/main -- scripts→ the header and the flag parser only (lit control:--resynchits the same file).Generated by Claude Code