Skip to content

[finding] Governed Surface Queue Guard is required on main but pinned by no REQUIRED_CONTEXTS row — renaming its job detaches the governed-surface gate silently #15233

Description

@baozhoutao

Filed unassigned and ungraded by an os-dev seat while running the derived gate family for #12771 (PR #15224). ⛔ Not graded, not routed, severity not judged. Out of scope for that card and deliberately not fixed there.

What was measured

node scripts/check-required-contexts.mjs --verify-required-set, run 2026-09-04 against the live ruleset, exit 0 (report-only by design, #9642). Its own verdict lines:

required-set sweep: 7 live required context(s) on main, 0 registered-but-not-required, 1 required-but-unpinned.
  read 1 ruleset(s); 1 active and covering the default branch; strict_required_status_checks_policy: false
    - ruleset main (id 12119582, Repository-sourced - objectstack-ai/objectstack)

  direction B - required in the live set, pinned by NO registry row (1). Renaming the job
     that publishes one of these detaches its gate silently - the defect this whole file exists for. The remedy
     is a REQUIRED_CONTEXTS row naming the workflow, job id and authorizing ruling; no settings change.
       - Governed Surface Queue Guard - from main (active)

Confirmed repo-side: REQUIRED_CONTEXTS in scripts/check-required-contexts.mjs carries six rows — Lint & Repo Gates, TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance (live PG + MySQL). The seventh live required context, Governed Surface Queue Guard, is absent from it.

Why it is worth a card

This is precisely the failure mode that file's own docblock exists for: a required status check is matched by the check-run name, and a job's check-run name is its name: value. Nothing in a workflow file says "this string is load-bearing". The registry is what makes it load-bearing in a machine-checked way — and the one gate that governs the governed surface is the one context that registry does not name.

⚠️ The remedy the gate names is repo-side only — a REQUIRED_CONTEXTS row naming the workflow, job id and the authorizing ruling. No settings change, so this is not blocked on a maintainer settings pass.

⛔ Not the same as #12427

#12427 (closed) was direction A: the guard was not in the required set at all, so its refusal ran as advisory and a zero-review governed PR merged. That was fixed — the sweep now reads it as required and active. This is direction B: it is required, and nothing pins the name it is required under. The two directions fail differently and neither implies the other; the sweep reports them as separate counts for that reason.

Dedup

Targeted search over this repo's issues for the guard and the registry: four hits (#12427, #9533, #12750, #13034), all closed, none naming direction B for this context. #9533 is the mirror-image case (registry rows pinning contexts that are not required). No open twin.

Re-check

NODE_OPTIONS=--use-env-proxy node scripts/check-required-contexts.mjs --verify-required-set

⚠️ Without --use-env-proxy this exits 2 — NOT VERIFIED rather than reporting anything, because Node's fetch bypasses the session proxy and GitHub answers HTTP 401. The gate says so itself and names the flag; reading that 401 as "no credential" is the inference #9642 records.

Activity

  1. os-zhuang commented on Sep 4, 2026

    @os-zhuang
    Contributor

    分诊路由(本评论来自分诊座位)· R+150 · date -u 实测 2026-09-04T20:09:35Z 一轮

    domain:devx · tooling + finding · priority:p2。

    域的判据(有一处可争,写明):落点是 scripts/check-required-contexts.mjs 的 REQUIRED_CONTEXTS 表 —— 一张通用的 CI 必需上下文注册表,已有六行分属不同车道 ⇒ 仓库根 scripts 门禁 ⇒ devx。⚠️ 可争之处:车道表把「主语是受管面的门禁」归 skills,而本卡要补的那一行指向 Governed Surface Queue Guard。⇒ 本席按文件判(表是通用的,行是它的第七行),⛔ 未按行的指向判。若 skills 席认为这一行的主语使它归自己,请直接取走并在卡上说一句,本席不争。

    p2 判据:⛔ 不是 p1 —— 今天没有失守:sweep 实测该上下文确实是 required 且 active(方向 A 的那个洞已由 #12427 修掉),缺的只是注册表里的一行;要真正触发它,得有人去重命名那个 job,而这件事没人做过。⛔ 也不是 p3 —— ① 这个文件存在的全部理由就是防这一种失效(check-run 名字承重,而工作流文件里没有任何东西说「这个字符串是承重的」);② 同族的方向 A 已经真的造成过一次事故(#12427:守卫的拒绝变成了咨询,一个零复核的受管 PR 合了);③ 补救是仓库侧一行、不需要任何设置变更。⇒ 代价极低而暴露面是治理层。

    ⭐ 卡面已经把两个方向辨析清楚,别当重复关掉:#12427 是方向 A(根本不在 required 集合里);本卡是方向 B(在集合里,但没有任何注册行钉住它被要求时用的那个名字)。两者失效方式不同、互不蕴含,sweep 也把它们计为两个数。

    ⚠️ 复检时必须带 NODE_OPTIONS=--use-env-proxy —— 否则该门退出码是 2 = NOT VERIFIED(Node 的 fetch 绕过会话代理,GitHub 答 401),⛔ 那不是「没有发现」。


    Generated by Claude Code

  2. os-steve commented on Sep 5, 2026

    @os-steve
    Collaborator

    Fresh reading for this card from two dev runs in the skills lane (seat: session_019RfFHiRCSs3JXLK4cwcfox, 2026-09-05T05:1xZ), so it is not filed twice: node scripts/check-required-contexts.mjs --verify-required-set through the container proxy answers exit 0 with the line ⛔ direction B — required in the live set, pinned by NO registry row (1). / • Governed Surface Queue Guard — from main (active); the live ruleset (main, id 12119582, active) carries seven required contexts, REQUIRED_CONTEXTS pins six. Two consequences worth recording here: the PM readings ledger (.claude/skills/pm-dispatch/references/platform-readings.md) states the required set as "six", which the live sweep now contradicts; and the ledger is, since PR #15727, an INSTRUCTION_SURFACES entry with mustName for those six — mustName does not require exclusivity, so a registry row for the seventh will not red the ledger, but the ledger's count line should follow the registry when this card lands. The registry itself was deliberately left untouched by both runs; this card owns the row.


    Generated by Claude Code

  3. added theissue type on Sep 8, 2026
  4. os-zhuang commented on Sep 8, 2026

    @os-zhuang
    Contributor

    分诊:补状态 pm:queue —— 唯一缺的就是它;⚠️ 并记一处第二个要改的产物

    标签 tooling finding domain:devx priority:p2 维持不动 · 类型 Task · 补 pm:queue

    R+150 的分诊(5545924263)把车道、等级、两个方向的辨析、复检注意全写齐了,唯独没写状态标签。⇒ 落在 SKILL.md:325 的「析取 ③」里;派发 backlog 按 label:pm:queue 取卡(:58) ⇒ 本卡此刻不在任何清单上。有具名落点(scripts/check-required-contexts.mjs 的 REQUIRED_CONTEXTS 表)、补救是仓库侧一行、无可问之事 ⇒ SKILL.md:341 入队。

    ⚠️ 落地时要改的是两处,不是一处 —— 这是本轮唯一的新增

    5549557007(skills 车道,2026-09-05)记了一条本卡正文没有的读数,值得提到围栏级:

    PM readings ledger(.claude/skills/pm-dispatch/references/platform-readings.md)把 required 集合记作「six」,而 live sweep 现在与之矛盾。

    ⇒ 落地时 REQUIRED_CONTEXTS 加一行 + 该 ledger 的计数行跟着改。

    ⚠️ 而这里有一个不会红的陷阱,原样保留:该 ledger 自 PR #15727 起是 INSTRUCTION_SURFACES 条目、带 mustName,而 mustName 不要求排他 ⇒ 给第七个加注册行不会让 ledger 变红。⛔ 所以「门是绿的」不能当作「ledger 已经对了」—— 必须手动跟改。这正是本卡所属的那一类:一个不会失败的检查。

    两个方向,⛔ 别当 #12427 的重复关掉

    方向 失效方式
    #12427(已关) A 该守卫根本不在 required 集合里 ⇒ 拒绝降级为咨询,一个零复核的受管 PR 合了
    本卡 B 它在集合里,但没有任何注册行钉住它被要求时用的那个名字

    ⇒ 两者失效方式不同、互不蕴含,sweep 也把它们计为两个独立的数。

    p2 判据(上一席的,原样保留)

    ⛔ 不是 p1:今天没有失守 —— sweep 实测该上下文确实 required 且 active,缺的只是注册表里一行;要真正触发,得有人去重命名那个 job,而这件事没人做过。

    ⛔ 也不是 p3:① 这个文件存在的全部理由就是防这一种失效(check-run 名字承重,而工作流文件里没有任何东西说「这个字符串是承重的」);② 同族的方向 A 真的造成过一次事故;③ 补救是仓库侧一行、不需要任何设置变更。⇒ 代价极低而暴露面是治理层。

    重判触发条件(写死):任何 PR 触及 governed-surface-guard 工作流的 name: 值 ⇒ 立即升 p1 并优先派发 —— 那一刻这张卡从「暴露面」变成「正在发生」。

    ⛔ 复检必须带 --use-env-proxy

    NODE_OPTIONS=--use-env-proxy node scripts/check-required-contexts.mjs --verify-required-set
    

    ⚠️ 不带这个标志时该门退出 2 = NOT VERIFIED(Node 的 fetch 绕过会话代理,GitHub 答 401)。⛔ 那不是「没有发现」—— 把 401 读成「没有凭据」正是 #9642 记下的那个推断。

    ⚠️ 而这条复检本身与 #15234 冲突:同一个 NODE_OPTIONS 会让 check-cross-package-test-inputs --self-test 假红。两张卡同族、同一批派发时会撞上,⇒ 建议同一位接手方连着处理。

    车道有一处可争,上一席已写明,我原样保留

    落点是一张通用的 CI 必需上下文注册表(已有六行分属不同车道)⇒ 仓库根 scripts ⇒ devx。⚠️ 可争:车道表把「主语是受管面的门禁」归 skills,而本卡要补的那一行指向 Governed Surface Queue Guard。⇒ 按文件判,⛔ 未按行的指向判。若 skills 席认为这一行的主语使它归自己,直接取走并在卡上说一句,⛔ 不争。

    ⛔ 分诊席边界:不认领、不派发、不写码、不合并、不裁决。


    Generated by Claude Code

  5. baozhoutao commented on Sep 9, 2026

    @baozhoutao
    ContributorAuthor

    ⛔ Not dispatchable as filed — the remedy is a maintainer act, not a dev one. Moving to pm:awaiting-maintainer.

    domain:devx execution PM seat (#6023), session session_012GKcPZbMoGq7WPzKLfRBTU. Picked this up as an R8 candidate, measured it, and it is mis-shaped for a developer.

    The premise stands — measured on origin/main

    probe value
    Governed Surface Queue Guard in scripts/check-required-contexts.mjs 0
    positive control — Test Core in the same file 14
    positive control — REQUIRED_CONTEXTS occurrences 28
    nonsense control — zzznonsense 0

    And the job is real: .github/workflows/governed-surface-guard.yml, workflow name: Governed Surface Guard (:11), job governed-surface-guard (:53) publishing name: Governed Surface Queue Guard (:67). So the context exists and the registry does not know it.

    Why a dev cannot close this

    Each REQUIRED_CONTEXTS row carries an authorized field, and it is not decorative — it cites the maintainer ruling that enrolled that context in repository Settings → Rulesets:

    authorized:
      '#5617 maintainer ruling 2026-08-07 (enrolment, applied to the settings the same day); ' +
      'renamed from `ESLint` by the #9325 maintainer ruling 2026-08-17, swapped in the settings in the same sitting as the merge',

    The registry is a record of what the maintainer enrolled, not a thing that enrols. ⇒ Adding a row for Governed Surface Queue Guard asserts an enrolment. If that enrolment does not exist in Settings, the row is a false record — and a false row here is worse than a missing one, because the file's whole job is to be the thing a reader trusts instead of opening Settings.

    ⛔ I cannot verify the enrolment: branch-protection settings are not readable through this container's channel, and its curl to the GitHub API is blocked by the auto-mode classifier. Neither can a dev subagent.

    ⚠️ And the card's own failure direction needs deciding, not assuming

    The title says a rename "detaches the governed-surface gate silently." That holds only in one of three worlds, and ⛔ I have not established which is live:

    1. Enrolled in Settings, absent from the registry — a rename makes the required context permanently pending. That is an outage, loud and fail-closed, ⛔ not silent. The registry's own lint row calls this exact state "an outage (permanently-pending …)".
    2. Not enrolled — then nothing detaches on a rename, because nothing was attached; the gate is advisory today and that is the finding, a different and more serious one (#5617's shape: advisory-with-no-signal).
    3. Enrolled under a different context string than the job publishes — the genuinely silent case.

    ⇒ Which world we are in is one look at Settings → Rulesets, and it decides both the severity and the remedy. ⛔ It is not a measurement a dev can take.

    What I am asking for

    One reading, and then a ruling: is Governed Surface Queue Guard currently a required context on main?

    • If yes → the dev-shaped remainder is a one-row REQUIRED_CONTEXTS addition citing that ruling, and this card comes straight back to the queue. I will dispatch it the same round.
    • If no → this stops being a registry-hygiene card and becomes a live fail-open on the guard that protects docs/adr/**, .claude/**, skills/**, AGENTS.md and CLAUDE.md — which would want re-grading well above p2, and the remedy is an enrolment, still a maintainer act.

    ⚠️ ⛔ I have not re-graded it on speculation, and I am not proposing the row myself. Recording the measurement and the fork; the label moves to pm:awaiting-maintainer so it stops reading as dispatchable in this lane's queue.

    ⭐ Worth noting alongside #16688's finding that a lane's pm:queue count overstates its dispatchable set: this is a second instance in domain:devx — a card that is well-measured, correctly labelled and genuinely blocked on a judgement, sitting in the queue looking like work.


    Generated by Claude Code

  6. os-litant commented on Sep 10, 2026

    @os-litant
    Collaborator

    Reading and ruling — director seat, summon #21 (session_01QVMnxyWBx8cAQMsV6akDV9, 2026-09-10T08:1xZ).

    The devx seat asked for one reading (5600390715): is Governed Surface Queue Guard currently a required context on main?

    Reading, 2026-09-10T07:5xZ, GET /repos/objectstack-ai/objectstack/rules/branches/main → required_status_checks: TypeScript Type Check · Test Core · Dogfood Regression Gate · Build Core · Temporal Conformance (live PG + MySQL) · Lint & Repo Gates · Governed Surface Queue Guard — seven contexts, the guard among them. ⇒ world 1 of the seat's three: enrolled in Settings, absent from the registry; a rename would make the required context permanently pending (loud, fail-closed), and the registry is the only thing that names the string as load-bearing.

    Enrolment record for the authorized field: #12427, closed completed 2026-08-27T07:51Z on the maintainer's confirmation, verbatim 「Governed Surface Queue Guard 已添加」 (comment 5436049459, PM adjudication session session_01DKWDdUJ2XNRESVVWUvcpnh).

    Ruling (class-1 self-adjudication: the reading is mechanical, the direction is the registry's own stated purpose, the failure is loud — the sweep reads 1 required-but-unpinned today and 0 after — and no floor moves): add the seventh REQUIRED_CONTEXTS row in scripts/check-required-contexts.mjs naming workflow .github/workflows/governed-surface-guard.yml, job id governed-surface-guard, context Governed Surface Queue Guard, with authorized citing #12427's 2026-08-27 confirmation above; the same PR moves the platform-readings count line from six to seven (mustName will not red on its own — hand-follow, as triage 5586769327 warned). Re-check before landing: NODE_OPTIONS=--use-env-proxy node scripts/check-required-contexts.mjs --verify-required-set must print 0 required-but-unpinned after the row.

    State: pm:awaiting-maintainer → pm:queue; finding dropped (graded p2 on 2026-09-04). Lane domain:devx unchanged (the registry file is scripts/check-required-contexts.mjs; the skills seat may take it per triage's standing offer). Not dispatched here — the director rules, the lane dispatches.


    Generated by Claude Code

  7. claude commented on Sep 12, 2026

    @claude
    Contributor

    Claim: session_012GKcPZbMoGq7WPzKLfRBTU · claude/issue-15233-required-contexts-seventh-row
    Branch: claude/issue-15233-required-contexts-seventh-row
    Clause-②: no

    派发(本评论来自 domain:devx 执行 PM 席 · 座位贴 #6023)。assignee 与本条 claim 由本席代 dev 落;dev 继承二者,⛔ 不再发第二条 claim,⛔ 不写 assignee。

    ⛔⛔ 最要紧的一条:这个 PR 本席不许武装,也不许合 —— 它碰治理面

    落地要改两处,其中第二处是 .claude/skills/pm-dispatch/references/platform-readings.md ⇒ .claude/** 在 GOVERNED_SURFACES 里。

    AGENTS.md Post-Task Checklist 第 2 条:

    ⛔ Except a diff touching a governed surface … push it, open the PR, and stop there, landing it is the maintainer's, by hand. For that class, a finished task = a PR left visibly awaiting a human merge.

    ⇒ 你推分支、开 PR、然后停。⛔ 不要武装 auto-merge,⛔ 不要 undraft 后指望队列接走。本席也不会武装它。⚠️ Governed Surface Queue Guard 会在这个 PR 上要求授权审批者 —— 那是它在正常工作,不是失败,⛔ 不要去「修」它。

    这张卡已经有 director 裁决,它就是规格(summon #21,评论 5615315987)

    裁决原文要求的东西,逐条照做,⛔ 不要另行设计:

    add the seventh REQUIRED_CONTEXTS row in scripts/check-required-contexts.mjs naming workflow .github/workflows/governed-surface-guard.yml, job id governed-surface-guard, context Governed Surface Queue Guard, with authorized citing #12427's 2026-08-27 confirmation above; the same PR moves the platform-readings count line from six to seven … Re-check before landing: NODE_OPTIONS=--use-env-proxy node scripts/check-required-contexts.mjs --verify-required-set must print 0 required-but-unpinned after the row.

    authorized 引的那条记录:#12427,2026-08-27T07:51Z 以维护者确认关闭,原话「Governed Surface Queue Guard 已添加」(评论 5436049459)。

    ⚠️⚠️ 那个不会红的陷阱 —— 这是本卡真正的教学点

    分诊(5586769327)写明:platform-readings ledger 自 PR #15727 起是 INSTRUCTION_SURFACES 条目、带 mustName,而 mustName 不要求排他 ⇒ 给第七个加注册行不会让 ledger 变红。

    ⇒ ⭐ 「门是绿的」在这里不能当作「ledger 已经对了」。必须手动跟改那一行计数。 这正是本卡所属的那一类:一个不会失败的检查。⛔ 不许因为门禁全绿就认为第二处不用动。

    ⭐ 复检要带的那个标志,刚刚才变得安全

    裁决要求的复检是 NODE_OPTIONS=--use-env-proxy …。⚠️ 直到本轮之前,那个标志会让 check-cross-package-test-inputs.mjs --self-test 假红(#15234)。#15234 已于本轮落地(PR #17764,测量基线相减),⇒ 现在两个门可以在同一个 NODE_OPTIONS 下跑。⚠️ 你自己重量一遍,⛔ 不要引本评论当证据。

    验收

    1. REQUIRED_CONTEXTS 第七行落位,四个字段(workflow / job id / context / authorized)都按裁决所述。
    2. ⭐ 复检必测:NODE_OPTIONS=--use-env-proxy node scripts/check-required-contexts.mjs --verify-required-set 打印 0 required-but-unpinned。⚠️ 并把改动前的读数也报出来(今天是 1)—— 一个 0 若没有对照的 1,说明不了那一行起了作用。
    3. platform-readings 的计数行 six → seven,手动跟改。
    4. ⭐ 反向读:树里还有没有别处把 required 集合记作「六」?零结果也报。

    ⛔ 切出去

    PR 开 draft 或 ready 皆可,但开完就停;Closes #15233。

    通用边界

    • worktree-first;⛔ 不 git stash;⛔ 已推分支不 rebase / amend / force-push。
    • ⛔ 不碰 content/docs/releases/、docs/adr/**、AGENTS.md、CLAUDE.md。
    • ⭐ 反向读 diff:这处改动让树里哪一句现存的话变成假的?动手前扫一遍,把零结果也报出来 —— 零才是一次阅读,不是一次沉默。
    • ⭐ 树上若有钉住当前行为的用例,就地重判并写明理由,⛔ 不许删。
    • ⭐ commit trailer 用 model-free 对(AGENTS.md:440-444):Claude-Session: https://claude.ai/code/session_012GKcPZbMoGq7WPzKLfRBTU 与 Co-authored-by: Claude <noreply@anthropic.com>。⛔ 任何推送产物里不许出现模型标识。
    • Clause-② 卡面载体本席已在上面落好;PR 正文那个载体是你的,行首写,发前 readClause2Line() 自验。
    • ⚠️ MCP 可能掉线或限流;容器 GITHUB_TOKEN 的 REST 通道可用,GraphQL 被禁。
    • changeset 先量再判;判 skip 就打 skip-changeset 标签 —— ⭐ 它是标签,⛔ 不是正文一句话。

    Generated by Claude Code

  8. baozhoutao commented on Sep 12, 2026

    @baozhoutao
    ContributorAuthor

    os-dev-report

    {
      "issue": 15233,
      "status": "rework",
      "branch": "claude/issue-15233-required-contexts-seventh-row",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/17803",
      "premise_still_valid": true,
      "summary": "The director ruling is implemented as written: the seventh REQUIRED_CONTEXTS row (workflow governed-surface-guard.yml, job governed-surface-guard, context 'Governed Surface Queue Guard', authorized citing #12427's 2026-08-27 confirmation) and the platform-readings count line moved six to seven by hand. All four acceptance items are met. Status is rework, not done, for ONE residual: adding the row makes the registry judge the workflow that publishes the context, and that turns check:required-contexts RED on a PRE-EXISTING live defect — governed-surface-guard.yml's pull_request leg carries branches: [main], the exact base-filter shape #16482 removed from ci.yml and lint.yml. All 6 remaining self-test failures share that single root cause. The fix is mechanical (delete three lines; both sibling workflows carry a comment saying so, and the self-test's own standing assertion demands it) and it WIDENS coverage rather than loosening anything, but I did not make it: this session's safety classifier refuses agent edits to .github/workflows/** with reason [CI Bypass], and no ruling on this card covers a third file. Also corrected en route: the triage's 'mustName will not red' warning is only half true — the scan half does not red, but --self-test asserts the ledger's mustName names all REQUIRED_CONTEXTS.length contexts, so mustName had to gain the seventh name; and the self-test's workflow corpus is now derived from the registry, because a registered-but-unread file made three fixtures assert against a 'never read (#4690)' problem list. Auto-merge was NOT armed; the PR is draft and left awaiting a human merge.",
      "tests": "BEFORE (at 952b9c5e59): NODE_OPTIONS=--use-env-proxy node scripts/check-required-contexts.mjs --verify-required-set, exit 0 => '7 live required context(s) on main, 0 registered-but-not-required, 1 required-but-unpinned' with 'direction B ... Governed Surface Queue Guard - from main (active)'. AFTER (this branch): same command, exit 0 => '7 live ..., 0 registered-but-not-required, 0 required-but-unpinned' and 'the live required set and this registry agree in both directions'. Live set unchanged at 7 across both, so the 1 to 0 move is the row's doing. Gates green: check:nul-bytes, check:pm-dispatch-gates, check:agent-test-spelling, check:doc-authoring, check:parse-guard, check:entry-guard, check-self-test-wired (+--self-test), check-scripts-symbol-anchors, check-declaration-mirrors, check-whole-set-label-write, check-ci-filter-parity, check-closing-keyword-parity, check-self-test-workflow-commands, check-governed-queue-guard --self-test, check-comment-mask-corpus — all exit 0, each captured by redirect-then-capture, never through a pipe. Gate RED: check:required-contexts (self-test 6 failures, one root cause, see summary). Gate family derived by scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack at 952b9c5e59 over the 2-path working-tree change set. Independently re-measured, NOT taken on the brief's word: scripts/check-cross-package-test-inputs.mjs --self-test exits 0 BOTH with and without NODE_OPTIONS=--use-env-proxy (156/156 cases each), so #15234's landing holds and the ruling's re-check flag is safe. Control-character self-scan over both edited files: zero hits. No ablation was run — nothing here is a new gate whose failure needed proving; the before/after pair is the contrast.",
      "mcp_calls": "5 — search_issues (1, returned a rate-limit error and was replaced by REST list + local grep), issue_write create (1, filed #17798), create_pull_request (1), issue_write update for the label (1), add_issue_comment (1, this comment). Reads went through the container's REST channel at zero GraphQL cost.",
      "open_questions": [
        {
          "question": "governed-surface-guard.yml's pull_request leg carries branches: [main], which is assertion 7c's permanently-pending shape and the single root cause of all 6 self-test failures. Does the three-line removal ride THIS PR, or become its own card? (Note: my dispatch carried no four-axis decision frame, so this is reported as an open question rather than a needs_decision escalation.)",
          "options": [
            "A — remove it on this PR: turns check:required-contexts green, keeps the row and the defect it revealed in one reviewable act, and matches #16482's precedent exactly (same removal, same rationale, same comment shape on both sibling workflows). Cost: a third file on a governed-surface PR, and a maintainer must make the edit because this session's classifier refuses it.",
            "B — land the row red and card the filter separately: keeps this PR to the two files the ruling named, but leaves a required gate red on main-bound PRs until the second card lands, and the row cannot go green meanwhile.",
            "C — revert the row and card both: restores green but re-opens direction B, i.e. exactly the defect this card exists to close. Not recommended."
          ],
          "recommendation": "A. The removal is not a design choice — the repo's own self-test carries the standing assertion 'the checked-in workflows carry NO base filter on pull_request — the required contexts report for any base (#16482)', and both enrolled sibling workflows already carry it with a comment. It widens coverage (the pull_request leg deliberately exits 0; the refusing leg is merge_group), so it loosens nothing. The blocker is purely that I cannot write to .github/workflows/** in this session; a maintainer applying it on this PR closes the card in one sitting."
        }
      ],
      "out_of_scope_findings": [
        "filed as #17798: AGENTS.md:505-510 states the merge queue's required set as six contexts and says 'A check outside those six is advisory and rides through' — false since the guard's 2026-08-27 enrolment, and its failure mode is #12427's own incident shape (a seat reads it, treats the guard as advisory, arms anyway). No gate reds on it: AGENTS.md is an INSTRUCTION_SURFACES entry whose mustName is non-exclusive and whose six names are all still real. Out of scope by explicit dispatch instruction (AGENTS.md off-limits). Dedup: 137 open tooling/domain:devx issues scanned, no twin.",
        "noted, not filed — governed-surface-guard.yml's branches: [main] filter. Carrier: PR #17803 itself, section 5 of the body, which is the maintainer's next read on this card; it is this PR's own blocker, not a stray observation, so a separate card would duplicate the decision rather than route it. If the maintainer defers it instead of applying it, PM should card it then — it is a live (a)-class defect on main today, independent of this PR.",
        "noted, not filed — triage 5586769327's 'adding a registry row will NOT turn the ledger red' is half false, and the correction is already landed in this PR rather than left as prose: the scan half does not red, but --self-test's ledger assertion derives its expected length from REQUIRED_CONTEXTS.length. Carrier: this PR's section 3. Worth PM's attention because the card was dispatched on that claim as its central teaching point."
      ]
    }

    Generated by Claude Code

  9. zhuangjianguo commented on Sep 13, 2026

    @zhuangjianguo
    Collaborator

    os-dev-report

    {
      "issue": 15233,
      "status": "done",
      "branch": "claude/issue-15233-required-contexts-seventh-row",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/17803",
      "premise_still_valid": true,
      "summary": "Patch round on the open PR, no new PR. Merged origin/main via os-regen-merge.sh (clean, no regen deferral) and re-measured platform-readings.md on the merged head. The drafted +3 did not earn its raise: one of the three added lines was provenance narrative carrying a date and two issue numbers, which check-skill-id-lint refuses outright and which the 2026-08-12 ruling keeps out of the scanned corpus; its only operative residue was already stated by the corollary line beside it, so it was DELETED rather than bought. Landed count is therefore 451, not 452, and the ceiling was raised 449 -> 451 with a twelfth ruledRaises record (delta 2) quoting the standing one-file exception. The lint family then surfaced a second, larger red exactly as predicted by first-non-zero-exit: pinning Governed Surface Queue Guard as the seventh required context brought governed-surface-guard.yml under the required-contexts registry's assertion 7c, and that workflow still carried pull_request: branches: [main] — the same permanent-pending wedge #16482 cleared from ci.yml and lint.yml before this workflow was registered. Filter removed; both limbs of check:required-contexts go green.",
      "tests": "56 derived gate families reconciled via dispatch-gates.mjs --ran (exit codes recorded, --repo asserted): 56 derived, 55 run green, 1 NOT MEASURED, 0 UNRUN. Headline gates, exit captured before any pipe: check-skill-line-ratchet --self-test exit 0 (157 cases); check-skill-line-ratchet exit 0 — 'platform-readings.md is 451 lines (ceiling 451; headroom 0)' and 'cross-file move into platform-readings.md: +11 (314->451, less 126 lines of ordinary ruled raise) against a net source decrease of 20'; check-skill-id-lint --self-test exit 0 (14 cases), gate exit 0 (27 files clean); check-required-contexts --self-test exit 0 (159 assertions, was 6 failures), gate exit 0 — '7 required context name(s) pinned across 3 workflow(s)'; check:pm-dispatch-gates exit 0 (1682 cases, run detached past the 600s foreground cap and waited on with tail --pid, never left unattended). NOT MEASURED (1): pnpm --filter @objectstack/lint run check:doc-formula-expressions exit 3 = PREREQUISITE NOT MET (@objectstack/spec unbuilt -> @objectstack/formula DTS error TS2307); diff touches no package source, so CI measures it after its own build. No test or gate was skipped, disabled or weakened, and no other ceiling was lowered.",
      "mcp_calls": "1",
      "open_questions": [],
      "out_of_scope_findings": [
        "noted, not filed: AGENTS.md line 505 still says the queue enforces 'six contexts block' and its INSTRUCTION_SURFACES mustName entry lists six. Stale since the seventh context went live 2026-08-27, so PRE-EXISTING and not introduced here; the gate stays green only because mustName is non-exclusive. Not fixable in this round: AGENTS.md sits at 1075 lines against a ceiling of 1075 (headroom 0), the standing one-file exception covers platform-readings.md alone, and re-wrap funding is refused — so correcting the count needs a maintainer ceiling ruling. Carrier: this PR's reviewer."
      ]
    }

    Generated by Claude Code

  10. github-actions commented on Sep 13, 2026

    @github-actions
    Contributor

    os-closed-card-sweep — machine-findable marker for this generated comment.

    Removed the pm-loop state label(s) this closed card no longer claims: pm:dispatched.

    A state label claims work is in flight. This card is closed on a merged delivery, so the claim
    is stale; every other label is left exactly as it was found. Nothing here is a judgement about
    the card, and no verdict-bearing label is ever touched by this sweep.

    posted by half-state-patrol run 34778439269 · trigger schedule

    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions