Skip to content

Approve-gated queue for the governed surface: the queue guard passes a merge_group when an authorized human approval is pinned to the exact head — authorized set: os-zhuang, hotlong #12750

Description

@os-litant

Filed by the Director/skills seat (session session_01MnijPVVDakqK2J335JoJtq) executing two maintainer rulings from live PM chat, 2026-08-27.

Rulings (verbatim, untranslated)

The design (presented after the maintainer asked, verbatim: 「需要我人工审查的,如果我真的审查了,并且点了批准,也不能合并吗?还是要等我 bypass吗」): the Governed Surface Queue Guard changes from unconditionally red in merge_group context to green iff the PR carries an APPROVED review by an authorized account whose review.commit_id equals the PR's current head sha; otherwise red as today. PR-context behavior unchanged. The maintainer's workflow becomes review → Approve → done (the queue merges, restoring the merge-time re-validation the bypass path loses); the bypass direct merge stays as the fallback path.

The authorized-approver ruling, verbatim: 「os-zhuang hotlong 批准算数」.

Risk pinned into the record (presented before the ruling; the ruling stands)

os-zhuang is also operated by agent seats (triage sessions post as os-zhuang; measured on the board). With it in the authorized set, the technical control is normative for any agent holding os-zhuang credentials. Therefore this card ALSO lands the hard prohibition alongside the guard change: ⛔ an agent seat never submits an approving review on a governed-surface PR, under any account — same normative class as 「链永不合并受管面」, and the Director's governed-merge audit (duty 4) is the standing backstop: its attribution readings now cover the approver as well as the merger, and an agent-submitted governed approval is an incident (the #9495 regime).

The changes

  1. scripts/pm/check-governed-queue-guard.mjs: in merge_group context, resolve the PR from the payload, read its reviews, pass iff an APPROVED review by an account in GOVERNED_APPROVERS = ['os-zhuang', 'hotlong'] (constant single-source in this script, the CONTRACT_REVIEW_TIER pattern — protocol text references the constant, never copies the names) has commit_id == the PR head sha; stale approvals (older sha) never count. PR-context behavior byte-identical to today. Self-test rows for: pinned approval passes; stale-sha approval refuses; unauthorized-account approval refuses; no approval refuses; PR context unchanged.
  2. Protocol text (governed-landing clauses): the governed-surface landing rule gains the second legal path — 「授权人工批准钉 head ⇒ 队列放行」 alongside 「人工直合」; the agent-no-approve prohibition lands in the guardrails; provenance quotes carried by date. Single-source discipline: mechanics live at the guard script + one clause, other mentions point.

Non-goals (binding)

  • The governed surface definition, the draft-only delivery discipline, the four-piece, and the after-the-fact audit regime are untouched.
  • No new labels; no branch-protection settings change is assumed (the guard remains the enforcement point).
  • --test pre-arm predicate unchanged.

File surface

scripts/pm/check-governed-queue-guard.mjs (+ its self-test) + the governed-landing clause carriers (.claude/skills/pm-dispatch/SKILL.md and/or references/contract-review.md/landing-operations.md — locate the clause homes by grep; touch only where the clauses live). Zero-headroom ratchets on any .claude file touched — net 0, cut ledger.

Serial constraint

.claude/skills/pm-dispatch/SKILL.md and references/contract-review.md are held by open PR #12744 (#12706, awaiting the maintainer's merge). This card dispatches only after #12744 merges. The guard script is unheld.

Acceptance

  • Replay: a governed PR with os-zhuang's approval pinned to head enters the queue and merges; the same PR after a new push (stale approval) is dequeued red; an unauthorized approval is dequeued red; bypass direct merge still works.
  • Guard self-test green; ratchets hold on any touched .claude file; governed draft PR + human merge four-piece (this change is itself governed — it touches .claude/**).

Activity

  1. os-litant commented on Aug 27, 2026

    @os-litant
    CollaboratorAuthor

    Ruling increment. Maintainer, 2026-08-27, verbatim: 「需要批准的主动推送到这两个账户。」 — a governed PR reaching its ready-for-approval state is proactively pushed to the authorized approvers: the delivering seat requests review from both os-zhuang and hotlong (the review request is the push into their GitHub inboxes), not from one, and never waits to be discovered. This amends the four-piece's review-request step for governed deliveries; the protocol-text half of this card carries it (the clause references the same authorized-approver set as the guard constant). Applied immediately to the in-flight governed PR awaiting approval (#12744): hotlong added to its requested reviewers in this pass.


    Generated by Claude Code

  2. os-litant commented on Aug 27, 2026

    @os-litant
    CollaboratorAuthor

    Claim: skills-lane PM dispatch (ruling execution; filed rulings and claim by the same seat)
    Session: session_01MnijPVVDakqK2J335JoJtq
    Branch: claude/issue-12750-approve-gated-queue-guard
    Worktree: ../objectstack-12750 (dev-created from origin/main)
    Domain: skills
    File surface: scripts/pm/check-governed-queue-guard.mjs (+ its self-test) + the governed-landing clause carriers located by grep among .claude/skills/pm-dispatch/SKILL.md / references/contract-review.md / references/landing-operations.md — touch only where the clauses live. Zero-headroom ratchets on any .claude file touched — net 0, cut ledger with surviving homes.
    Container & model: mode:subagent, claude-fable-5 — live node scripts/pm/dispatch-gates.mjs --tier output for this surface (run this session): "Model tier — MANDATORY: claude-fable-5 … .claude/skills/pm-dispatch/SKILL.md ⇢ clause ① of the model-tiering ruling (narrowed to protocol semantics, 2026-08-20)". The guard-script half alone would be opus-eligible, but the card's protocol-text half sits on the clause-① surface and the two land as one governed PR. Clause-② content limb: no shipped product contract moves (internal CI guard + PM protocol text; the accept/reject change is on the repo's own merge pipeline, reviewed via the governed four-piece + human merge either way).
    Serial constraints cleared: PR #12744 (the prior holder of SKILL.md and contract-review.md) MERGED 2026-08-27T16:25Z (pull_request.closed outcome:merged on the subscribed PR; #12706 closed via Fixes and label-cleaned in the same pass). The guard script is unheld; no other open PR claims any of these files (single-writer check runs on the PR).
    Assignee set by this seat in the same stroke (assignee 归 PM under mode:subagent; the branch above is the dev claim's distinguishing identity).


    Generated by Claude Code

  3. self-assigned this
    on Aug 27, 2026
  4. os-litant commented on Aug 27, 2026

    @os-litant
    CollaboratorAuthor

    os-dev-report

    {
      "issue": 12750,
      "status": "done",
      "branch": "claude/issue-12750-approve-gated-queue-guard",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/12755",
      "premise_still_valid": true,
      "summary": "Guard: merge_group leg now passes a governed PR iff an APPROVED review by an account in GOVERNED_APPROVERS = ['os-zhuang','hotlong'] (frozen constant in scripts/pm/check-governed-queue-guard.mjs, single source; self-test pins the membership to the ruling) has commit_id equal to the PR's CURRENT head sha, read via a new makePullHeadReader on the same GITHUB_TOKEN channel the review read already uses (workflow untouched, pull-requests: read suffices). Stale/unauthorized/dismissed/superseded approvals refuse with exit 3 and actionable renders (stale names both shas); unreadable head or reviews stays exit 4, head-first so a failed head read never constructs the review request; PR-context behavior byte-identical including zero head reads. Protocol: SKILL.md four-piece piece 2 gains the second legal end (授权批准钉 head, quoted ruling, constant referenced not copied) with 人工直合 as fallback, piece 3 becomes the proactive dual review-push to both authorized accounts (quoted ruling; author-identity-422 fallback generalized), Guardrails land the agent-no-approve prohibition with the audit now reading approver as well as merger; contract-review.md 三样不变 mention aligned. Ratchets net 0 (SKILL.md 1005/1005 with row pin 765, contract-review.md 48/48), cut ledger with surviving homes in the PR body. Channel notes: repo-scoped REST measured 403 for this session (api.github.com blocked, gh absent) so writes + one targeted dedup search went MCP, declared; skip-changeset applied via MCP whole-set write and read back on the PR page (no pre-existing labels to preserve); card/comment reads went via the zero-quota web channel. PM half-state as dispatched: claim comment matched this branch, assignee pre-set.",
      "tests": "node scripts/pm/check-governed-queue-guard.mjs --self-test at b5fb6383a: EXIT=0 captured pre-pipe, verdict '113 cases pass' (base was 86; +27 rows: per-login pinned pass, membership pin, stale/no-commit_id/unauthorized/superseded/dismissed/none, sha case-insensitivity, unparsable-head fail-closed, end-to-end runGuard head-then-reviews, PR-leg zero-head-read byte-identity, unreadable-head exit-4 with reviews never constructed, head-reader unit rows, renders derived from the constant). pnpm check:pm-skill-ratchet: 'SKILL.md is 1005 lines (ceiling 1005; headroom 0)', 'widest table row is 765 bytes (pin 765)', 'contract-review.md is 48 lines (ceiling 48)', 'landing-operations.md is 80 lines (ceiling 80)'. check:pm-skill-id-lint '23 file(s) clean'; check:pm-governed-prose '2 instruction surface(s) name all 5 registered governed surfaces'; check:skill-frame-sync '4 copies structurally isomorphic'; check:skill-frame-freshness 'current with origin/main'. Derived union: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack, stderr line 1 'derived from the tree of objectstack-ai/objectstack at commit b5fb6383a'; all 17 matched families green in one os-verify-lock run ('os-verify-lock: VERDICT command-exit 0'), incl. doc-formula-expressions after building @objectstack/formula and @objectstack/lint cleared its PREREQUISITE NOT MET (not a red); convention families for the gate-script edit green: bare-root-worklist --self-test, check:pm-dispatch-gates ('dispatch-gates self-test: 719 cases pass'); check:nul-bytes OK 7093 files. STALE-TREE warning named only scripts/vercel-ignore-docs.* (outside this diff). No external test file pins the guard script (grepped; the --self-test IS its suite). NOT MEASURED, declared: the live merge_group half (real queue build + real token) is CI-only; no ablation was run (no dist-resolved subject; the guard is a dependency-free script whose self-test injects both readers).",
      "mcp_calls": "7 — create_pull_request, pull_request_read get (body read-back), issue_read get_labels (errored on a PR number, counted), issue_write labels whole-set, search_issues (dedup, control hit the card itself), issue_write create (finding #12756), add_issue_comment (this report)",
      "open_questions": [],
      "out_of_scope_findings": ["filed as #12756: AGENTS.md Prime Directive #14 still carries 'Reviewed + approved + fully green does not override this' and the unconditional never-enqueue wording — both contradicted by the 2026-08-27 approve-gated ruling; AGENTS.md was outside this card's dispatched surface, so the two instruction surfaces disagree until a follow-up amends the PD #14 editable prose (constraints inherited: governed + zero-headroom ratchet + pm-governed-prose region, constant referenced not restated)"]
    }

    Generated by Claude Code

  5. os-litant commented on Aug 27, 2026

    @os-litant
    CollaboratorAuthor

    ACCEPT — seat review done on the full diff (PR #12755, head b5fb6383a, 3 files; SKILL.md 1005/1005 and contract-review.md 48/48 net 0).

    • Guard predicate exactly as ruled: GOVERNED_APPROVERS = ['os-zhuang','hotlong'] frozen single-source with a self-test membership pin to the verbatim ruling; the merge_group leg passes iff a latest-decisive APPROVED review by a member has commit_id == the PR's CURRENT head (a reviewer's own later CHANGES_REQUESTED/DISMISSED supersedes; stale and unauthorized approvals refuse with actionable renders naming both shas / the never-counts account). Fail-closed everywhere: unparsable head pins nothing; unreadable head refuses exit 4 before the review request is even constructed (read order pinned by a trace test); unreadable reviews stay exit 4. PR leg byte-identical including zero head reads — pinned by test against the rendered output. Self-test 86 → 113, all quoted green.
    • Docblock history handled honestly: the earlier any-approval predicate is kept as the dated first layer with its own ruling quotes, the 2026-08-27 narrowing layered on top, and the attribution boundary respected — the guard stays keyed on the diff's paths and the review record, never the actor field.
    • Protocol text: the four-piece terminal gains the second legal end (授权批准钉 head ⇒ 队列放行, constant referenced never copied, stale-on-push stated); the review-push step becomes the proactive dual push to both authorized accounts with the author-identity-422 fallback correctly generalized (affected account → assign, the other still gets the request); the Guardrails land ⛔ agent 永不以任一账号对受管面 PR 提交批准 with the audit now reading the approver as well as the merger; contract-review.md's 三样不变 aligned (链永不入队亦不代批).
    • The out-of-scope finding is real and correctly handled: AGENTS.md PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14 still carries the unconditional never-enqueue wording — filed as its own card rather than widened into this PR; graded by this seat in the same pass (queue, dispatches after this PR merges so the amendment cites a landed predicate).

    Four-piece end state (same stroke): PR stays draft; review requested from both os-zhuang and hotlong (first application of the dual-push ruling); awaiting the maintainer — under the current text this one still lands by bypass direct merge; once merged, the approve-gated queue path applies from the NEXT governed PR onward. Fixes #12750 closes this card on merge.


    Generated by Claude Code

  6. os-litant commented on Aug 28, 2026

    @os-litant
    CollaboratorAuthor

    落地记录 (Director/skills seat, session session_01MnijPVVDakqK2J335JoJtq): PR #12755 merged 2026-08-28T06:51:46Z by os-zhuang — through the merge queue itself: the first governed PR to land via the approve-gated path it introduces. Self-bootstrap confirmed: the merge_group's speculative tree ran the NEW guard, which recognized the authorized APPROVED review pinned to head b5fb6383a and cleared. Both legal landing ends are now live on main. Labels cleaned to domain:skills; the serial successor card (AGENTS.md PD #14 amendment, filed from this PR's report) is dispatched in the same stroke.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions