Repository navigation
[finding] check-harness-current.mjs prints the graft boundary as a harness path's latest touch on a shallow checkout — the CURRENT / STALE verdict holds by construction, but the printed sha is not a reading of the path #18330
Description
Activity
Claim: PM loop round 1
Session:session_01HZfg2AwVX191qCizp88gQr(skills seat; claimed at 2026-09-16T02:16Z)
Branch:claude/issue-18330-harness-current-provable-touch
Worktree:objectstack-issue-18330
Domain:domain:skills
File surface:scripts/pm/check-harness-current.mjs(the latest-touch reading of the harness paths taken throughgit-history.mjs's proven leg; self-test cases) — nothing else;scripts/pm/git-history.mjsis consumed, not edited (stop on breach; explain in the report)
Container & model:S,mode:subagent,model: default tier—dispatch-gates.mjs --tiernames no mandate forscripts/pm/**; seat review atCONTRACT_REVIEW_TIER
Clause-②: no
Thread-read: none (the card carries no comment at claim time)
Fold-or-serial: no look-alike in the queue (#18320 is platform-readings; #18321 hooks)
Serial constraints cleared: PR #18327 LANDED0cc5ce85at 2026-09-16T02:14Z —touchIsProvable/ensureTouchProvableare onorigin/main; batch 3/3 (#18178 and #18308 in flight)
Generated by Claude Code
os-dev-report
{ "issue": 18330, "status": "done", "branch": "claude/issue-18330-harness-current-provable-touch", "worktree": "/home/user/objectstack-issue-18330", "pr": "https://github.com/objectstack-ai/objectstack/pull/18352", "head_sha": "6b750117909adb1e74ff9319d73d1ce02dc1c5b9", "files_changed": [ "scripts/pm/check-harness-current.mjs (59 -> 286 lines; the provenance clause + a 14-case --self-test)" ], "premise_still_valid": true, "summary": "check-harness-current.mjs now takes each harness path latest-touch reading through touchIsProvable from scripts/pm/git-history.mjs and prints the word boundary (graft case) or unprovable (any other unproven case), with that tool own reason, in place of a sha it cannot prove; a provable sha is printed as before with its proof named (parents present, diff-tree touches the path). It never fetches - the shared checkout is not this tool to deepen. The verdict computation, the three exit codes and the CURRENT / STALE / UNDECIDED summary line are byte-identical, and the header now records WHY the verdict survives a boundary reading. A 14-case --self-test over real shallow/complete/behind fixture clones pins the boundary reading, the provable reading on the same clone, the byte-identical summary in both, the STALE and UNDECIDED branches, and the no-fetch invariant.", "tests": "node scripts/pm/check-harness-current.mjs --self-test -> exit 0, \"all 14 cases passed\". All 29 dispatch-gates-derived commands ran, all exit 0, reconciled: \"29 derived, 29 run, 0 NOT-MEASURED, 0 UNRUN\" (dispatch-gates --ran, exit 0). npx eslint on the file: exit 0, no findings. No package build/test was owed: the diff touches one script under scripts/pm/, which no package depends on and no vitest project loads.", "gates": [ { "command": "node packages/lint/scripts/check-reference-carrier-shape.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node packages/lint/scripts/check-reference-carrier-shape.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-ci-filter-parity.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-closing-keyword-parity.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-closing-keyword-parity.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-comment-mask-corpus.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-declaration-mirrors.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-declaration-mirrors.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-scripts-symbol-anchors.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-scripts-symbol-anchors.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-self-test-wired.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-self-test-wired.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-self-test-workflow-commands.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-self-test-workflow-commands.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-whole-set-label-write.mjs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/check-whole-set-label-write.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "node scripts/report-test-timings.mjs --self-test", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:agent-test-spelling", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:bash32-floor", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:cli-command-ids", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:cross-package-test-inputs", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:driver-memory-census", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:entry-guard", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:nul-bytes", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:parse-guard", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:pnpm-filter-targets", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:ratchet-remedy-authority", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:refd-timer-probe", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "pnpm check:watch-hint-literal", "exit": 0, "note": "derived by dispatch-gates --commands" }, { "command": "npx eslint scripts/pm/check-harness-current.mjs", "exit": 0, "note": "ESLint on the edited file — clean, no output" }, { "command": "node scripts/pm/check-harness-current.mjs --self-test", "exit": 0, "note": "the new self-test: all 14 cases passed" }, { "command": "node scripts/pm/check-clause2-carriers.mjs --pair 18352", "exit": 0, "note": "clause-2 declaration readable, both carriers agree, no widening tell in the diff" }, { "command": "node scripts/pm/label-write.mjs --issue 18352 --add skip-changeset", "exit": 0, "note": "POST .../labels HTTP 200; read-back: size/m, skip-changeset" } ], "gates_ran_verdict": "dispatch-gates --ran: 29 derived famil(ies) accounted for - 29 run, 0 NOT-MEASURED (a DERIVED zero - all 29 recorded an exit code and none of them is 3). EXIT 0.", "battery": "pnpm check:pm-dispatch-gates is NOT derived for scripts/pm/check-harness-current.mjs (absent from the 29-command list), so it was not run - no detached ~480 s battery on this card. Runtime of the 29: ~195 s wall in total, longest check-comment-mask-corpus 60 s and check-self-test-workflow-commands 45 s.", "reverse_verification": { "method": "Both versions run back to back on the SHARED checkout at the same moment (the origin/main copy extracted with `git show origin/main:scripts/pm/check-harness-current.mjs`), because the shared checkout advances under this run - a before taken earlier would not be comparable.", "before": "OLD: \"✓ .claude/hooks/*: latest touch a0dd872c1b (2026-09-13T13:15:30+00:00) is in the shared HEAD\" | summary \"check-harness-current: CURRENT -- every harness-loaded path on origin/main is in /home/user/objectstack HEAD ceb6b5fb46\" | exit 0", "after": "NEW: \"✓ .claude/hooks/*: latest touch boundary (2026-09-13T13:15:30+00:00) [a0dd872c1 is a shallow graft boundary - its object names parent 9489e2c05, which this clone does not have, so git diffed it against the EMPTY tree and every path in its tree reads as touched there; nothing says whether .claude/hooks/* was really changed by it] is in the shared HEAD\" and \"✓ .claude/agents/*.md: latest touch 9fa9955ab4 (2026-09-15T06:58:14+00:00) [proven: 1 parent(s) present locally, diff-tree touches .claude/agents/os-dev.md] is in the shared HEAD\" | same summary | exit 0", "byte_identical_summary": "diff of the two runs summary lines is EMPTY (both: \"check-harness-current: CURRENT -- every harness-loaded path on origin/main is in /home/user/objectstack HEAD ceb6b5fb46\"); both exit 0.", "no_fetch_proof": "After the AFTER run the shared checkout is still shallow (git rev-parse --is-shallow-repository -> true) and .git/shallow is unchanged (md5 66039b7f8cfd0bcc7ea50d01daf5865d).", "firing_control": "Run inside the self-test rather than by hand, so it cannot rot: the fixture upstream touches .claude/hooks/h.sh only at c1, below every shallow floor the test cuts. The depth-5 clone prints `boundary` for that path; a COMPLETE clone of the same upstream prints c1 real sha for the same path, same code path, same argv. Both assertions pass. (The shared checkout itself was never deepened - that mutation is forbidden here.)", "discriminating_reading": "On the same shallow shared checkout the two provable paths (.claude/settings.json, .claude/agents/*.md) keep the exact shas they printed before, now carrying their proof - so the new clause discriminates rather than withholding everything on a shallow tree." }, "self_test_cases": { "count": 14, "wiring": "`--self-test` dispatched in-file (process.exit(argv.includes(\"--self-test\") ? selfTest() : main())); fixtures are real local git clones over file://, no network. node scripts/check-self-test-wired.mjs is GREEN and needed NO ledger row: its population is scripts CI runs that ship a --self-test (228 carry one, 212 are run by CI), and this script is named by no workflow and no root package.json alias, so it is outside that population. See open_questions[0].", "names": [ "BASELINE - raw git log -1 names the graft boundary as the last touch of a hook the boundary never changed", "the unprovable reading prints `boundary` in place of the sha, with the graft mechanism named", "the fabricated sha is nowhere offered AS the touch", "the VERDICT clause on that same line is untouched", "a PROVABLE reading on the same shallow clone still prints its sha, with the proof named", "the summary line is BYTE-IDENTICAL on the run that withheld a sha", "the exit code is unchanged (0 = CURRENT)", "nothing was fetched: still shallow, boundary unmoved", "FIRING CONTROL - a complete clone prints the TRUE sha for the same path", "the summary line is BYTE-IDENTICAL there too, same exit code", "a HEAD behind the newest touch still reads STALE, provenance spliced in, `-- STALE` line-terminal", "the STALE summary line, byte for byte", "an unreadable path stays UNDECIDED at exit 2, in today exact words", "the UNDECIDED summary line, byte for byte" ], "floor": "SELF_TEST_CASE_FLOOR = 14, checked after the fixture block - `failures === 0` alone cannot tell \"every case held\" from \"the cases never ran\"." }, "assumptions_verified": [ { "assumption": "On the shared checkout (is-shallow -> true) the current script prints 9b00f9f9cf for .claude/hooks/*", "verdict": "PARTLY FALSE - mechanism TRUE, sha stale", "evidence": "is-shallow-repository -> true (TRUE). The sha no longer reproduces: the shared checkout advanced from 0cc5ce85 to ceb6b5fb46 and was fetched twice DURING this card, so the graft boundary moved. First reading of this run printed af3add1601; at reverse-verification time it printed a0dd872c1b. 9b00f9f9cf is still listed in .git/shallow, so it is still A boundary, just no longer the one git names for this path. The DEFECT reproduces at every one of the three states: a real, plausible commit that never touched a hook, printed as the hook provenance." }, { "assumption": "node scripts/pm/git-history.mjs touch --path=.claude/hooks --no-fetch REFUSES with exit 2 naming the boundary", "verdict": "TRUE now; the reason text was a different (non-boundary) one earlier in the same shift", "evidence": "Now: exit 2, stderr \"a0dd872c1 is a shallow graft boundary - its object names parent 9489e2c05, which this clone does not have ... raw git log -1 said: a0dd872c1 (NOT a reading of the path)\". Earlier in this run, at the af3add1601 state, the SAME command also exited 2 but with reason \"af3add160 has its parent(s) locally but its diff does not touch .claude/hooks\" - see out_of_scope_findings[0]: af3add1601 was in .git/shallow (graft applied at traversal) while its object parent d285bf0f had since been fetched, so touchIsProvable leg 1 passed and it reported boundary:false. Both are correct refusals; only the boundary FLAG is a false negative." }, { "assumption": "for .claude/agents the script prints 9fa9955ab4, which IS provable (parent present, diff-tree touches the path)", "verdict": "TRUE", "evidence": "touchIsProvable({sha: 9fa9955ab450a8ec..., path: \".claude/agents/*.md\"}) -> {provable:true, boundary:false, touched:[\".claude/agents/os-dev.md\"], reason:null}. The new line prints that same sha with [proven: 1 parent(s) present locally, diff-tree touches .claude/agents/os-dev.md]." }, { "assumption": "The verdict logic (merge-base --is-ancestor sha HEAD, and the committer-time / shallow fallback) must NOT change", "verdict": "TRUE and honoured", "evidence": "Those three statements are byte-identical in the diff apart from the substitution of the provenance clause variable for the inline `${short(sha)} (${ci})`. Proven behaviourally: identical exit codes and byte-identical summary lines on the shared checkout, plus self-test cases 6, 7, 10, 12 and 14 pinning the CURRENT, STALE and UNDECIDED summary strings literally." }, { "assumption": "git-history.mjs exports touchIsProvable, objectParents, lastTouch, ensureTouchProvable, isShallow", "verdict": "TRUE", "evidence": "grep -n \"^export function\" scripts/pm/git-history.mjs -> isShallow:168, boundaryTimes:180, windowIsCovered:198, chooseDeepenSince:209, splitRemoteRef:216, ensureWindowCovered:227, refTip:305, describeFloor:310, historyHorizon:338, objectParents:386, touchIsProvable:414, lastTouch:452, ensureTouchProvable:466. All five named are present. This card imports two of them (touchIsProvable, isShallow) and edits none." }, { "assumption": "check-harness-current.mjs is consumed by the seating protocol (SKILL.md :92) and by the triage seat stand-down logic; its exit codes and summary line are a contract", "verdict": "HALF-VERIFIED", "evidence": "A repo-wide grep for `check-harness-current` over *.md, *.mjs, *.yml, *.sh finds exactly ONE reference outside the script itself: .claude/skills/pm-dispatch/SKILL.md:92 (the seating protocol - 读数走 scripts/pm/check-harness-current.mjs). The triage seat stand-down logic has no textual reference in this tree, so if it consumes the tool it does so through that one line rather than by naming it. Treated as binding either way: exit codes and summary line kept byte-identical." } ], "four_axes": { "choice": "print `boundary` and keep going (BUILT) vs. refuse the whole run (exit != 0) whenever any path touch is unprovable on a shallow clone", "1_real_business_need": "Measured, not supposed: the tool has exactly ONE consumer in the tree (pm-dispatch SKILL.md:92), and what it consumes is the VERDICT - 是否收班换会话. No script parses the per-path lines, so the sha has no machine reader at all; it is a human-facing receipt. Refusing would answer the seat question with \"I do not know\" on essentially every fresh container: agent containers clone shallow, and a harness path true touch routinely sits below the floor - observed three times on this one checkout within a shift. That converts a CORRECT verdict into no verdict at the moment the seat needs one. -> print boundary.", "2_long_term_soundness": "Printing `boundary` is not a lenient fallback; it is the tool declaring exactly what it proved and what it did not, which is contract-first applied to a receipt. The verdict it keeps is sound under truncation by construction (a boundary is only named when the true touch sits at or below the floor, hence is an ancestor of the boundary; and the negative direction already degrades to UNDECIDED rather than STALE). Refusing is the workaround in the other direction: its only remedy is deepening the SHARED checkout, the one mutation worktree-first forbids and git-history.mjs header assigns to an operator. A gate whose sole remedy is a forbidden act trains seats to skip it.", "3_hardest_for_an_AI_to_get_wrong": "This is the axis that decides it, and it cuts AGAINST the louder option. The failure being fixed is an agent QUOTING the sha as provenance - exactly what happened on #18180 and produced this card. Replacing the sha with the word `boundary` plus a reason makes that quotation impossible to make by accident: there is no sha in the clause to copy, and the clause says why. A refusal prints nothing to quote - and the known agent response to a tool that always refuses is to fall back to raw git log, reinstating the fabrication WITHOUT the tool warning. Tightening the producer (the clause) beats refusing at the consumer, and 声明即强制 is satisfied: the line now claims exactly what it can prove and nothing more.", "4_startup_focus_no_proliferation": "The change adds no surface: no flag, no mode, no config key, no second spelling, no deprecation window, nothing to retire later. It is a one-clause correction inside an existing 59-line seat tool. Refusing would add a per-container operational burden (deepen before seating) for a p3 provenance defect - capability expansion with no pull, and 过渡从紧 forbids a staged both-ways option too.", "conflict_and_recommendation": "The axes conflict on axis 3 in the abstract - refusing IS louder, and this repo prefers loud. The tie-break is measured rather than stylistic: the loudness would land on runs whose verdict is CORRECT, and its remedy is forbidden here, so it buys nothing and costs the answer. RECOMMENDATION and what shipped: print boundary / unprovable, keep the verdict. If the seat later wants loudness, the narrow form is a --strict flag that refuses ONLY when a path touch is unprovable AND the verdict is CURRENT - a new surface with no pull today, so implementation-first: NOT built." }, "deviations": [ "None against the file surface: scripts/pm/check-harness-current.mjs is the only file changed. scripts/pm/git-history.mjs was consumed (two imports) and not edited. check-self-test-wired.mjs needed no row and got none - verified by running it (exit 0, and its population excludes this script).", "The seat measurement sha for .claude/hooks/* (9b00f9f9cf) no longer reproduces - the shared checkout advanced and was re-fetched twice during this card. Reported as PARTLY FALSE in assumptions_verified rather than quietly re-quoted; the mechanism reproduces at each state.", "BEFORE/AFTER were taken back to back at the END of the work (old version extracted from origin/main) rather than BEFORE the edit, because a before-reading taken earlier is not comparable on a tree other seats keep fetching. The earlier reading is reported too." ], "open_questions": [ { "question": "The new --self-test runs in no CI job. Should it be wired, and by whom?", "options": [ "A - wire a fourth `run_self_test node scripts/pm/check-harness-current.mjs --self-test` into lint.yml Shallow-history guard self-tests collector (also touches that step closing prose, which check-step-collectors.mjs --self-test extracts and drives)", "B - leave it seat-run, as with the other ~15 scripts/ files that ship a --self-test CI does not name", "C - the seat files a follow-up card for A" ], "recommendation": "C, then A. check-self-test-wired does not require it (this script is outside its population, so nothing reds), but a self-test nobody runs is the exact injury that gate exists for, and the wiring is a 1-line change in a file outside this card declared surface. Not done here - .github/workflows/** and package.json are not on this card file surface." }, { "question": "Should the boundary/unprovable reason keep quoting the raw sha inside its sentence?", "options": [ "A - keep it (git-history own refusal does exactly this, framed as `NOT a reading of the path`)", "B - strip every sha from the unprovable clause" ], "recommendation": "A, as built. The sha is inside a sentence that says why it is not a reading, and a reader chasing the boundary needs it; the defect was the sha in the `latest touch X` POSITION, and a self-test case pins that that position no longer carries it." } ], "out_of_scope_findings": [ "to file (class (a), reproducible; dedupe words: `touchIsProvable stale shallow entry` · `graft registered parent present` · `boundary false negative diff-tree` · `git shallow file membership` · `objectParents presence insufficient`): touchIsProvable in scripts/pm/git-history.mjs reports boundary:false for a commit that IS a registered graft boundary whose parent has since been fetched. Reproduced on the shared checkout earlier in this same run, before another seat fetch advanced the boundary: af3add1601 was listed in .git/shallow, so git log -1 and git show --stat applied the graft and credited it with every path in its tree (that is why git log named it for .claude/hooks/*), while its object parent d285bf0f was present locally - so leg 1 passed, diff-tree ran against the grafted (empty) parent list and printed NOTHING for a single-parent commit without --root, and the verdict came back {provable:false, boundary:false, reason:\"af3add160 has its parent(s) locally but its diff does not touch .claude/hooks\"}. The refusal is correct, so no caller is misled about the sha; what is wrong is the boundary FLAG and the reason text, which tells an operator the commit simply did not touch the path when in fact the traversal was grafted. The discriminator that does not miss it is membership in $(git rev-parse --git-common-dir)/shallow (or `git rev-list --max-parents=0 REF`), not object-parent presence. scripts/pm/git-history.mjs is consumed, not edited, on this card - the seat files it.", "noted, not filed: ~15 scripts under scripts/ ship a --self-test that CI names in no workflow (228 carry one, 212 are run - check-self-test-wired own scope line), and this card adds a 16th. Not a defect by that gate own definition (its population is deliberately \"the self-tests CI runs\"), and not this card scope. 承接者: the domain:skills seat, which owns scripts/pm/** and the lint.yml PM steps - see open_questions[0]." ], "mcp_calls": "0 MCP GitHub calls (no MCP GitHub tool, read or write, was used). 1 non-GitHub MCP read: mcp__Claude_Code_Remote__get_session, to read this container harness-stamped session id rather than typing it.", "api_writes": "4 REST proxy writes. (1) POST /repos/objectstack-ai/objectstack/pulls -> HTTP 201, PR #18352, draft:true, base main; read back GET /pulls/18352 -> user.login = os-zhuang, body byte-identical to what was sent apart from the stripped trailing newline, the footer present exactly once under its rule line. (2) POST /repos/objectstack-ai/objectstack/issues/18352/labels (through scripts/pm/label-write.mjs) -> HTTP 200; read back: size/m, skip-changeset (size/m is the size labeler, not mine - nothing was stripped). (3) POST /repos/objectstack-ai/objectstack/issues/18330/comments (this report, through scripts/pm/post-stamped.mjs) - author read back below. Plus 2 git pushes (branch create, then the commit), which are not REST. No PATCH of any body, no /issues POST.", "session": "session_01HZfg2AwVX191qCizp88gQr — read from mcp__Claude_Code_Remote__get_session (ccr.id); this is a mode:subagent run, so it is the parent harness-stamped id, as the report template specifies." }
Generated by Claude Code
ACCEPT — skills seat, session
session_01HZfg2AwVX191qCizp88gQr, 2026-09-16T02:41Z. Report 5691189101 on PR #18352 (head6b750117) reviewed by the checklist: files changed = the claim's surface exactly (scripts/pm/check-harness-current.mjs;git-history.mjsconsumed, not edited);Fixes #18330alone beside a closing keyword;skip-changesetread back;mcp_callsnames no write tool; gates 29 / 29 / 0 / 0 by--ranon the head;--pair0; the seat's re-run on a detached worktree: self-test 14 / 14, ESLint 0, wiring and symbol anchors green, and both versions run back to back on the shared shallow checkout —boundaryin place of the graft sha, the two provable paths unchanged with proofs, the summary line byte-identical, still shallow; the diff read whole. Two open questions answered and two cards filed (#18355, #18356) in the record on the PR; the dev's print-boundary choice confirmed on the four axes. Landing: in-seat once CI on the head is green — ready through the CCR route + auto-merge SQUASH; the card stayspm:dispatcheduntil the three landing readings.
Generated by Claude Code
Landed — skills seat, session
session_01HZfg2AwVX191qCizp88gQr, 2026-09-16T03:12Z. PR #18352 (head6b750117) merged by the queue as1411cf2c6fd2c9e695682416c9e655869945f531(single-parent squash pergit rev-list --parents) at 2026-09-16T03:12Z — themerged_atinstant, carried identically by themergedandremoved_from_merge_queuetimeline events. Readings at 2026-09-16T03:12Z:git log origin/maincarries(#18352); the queue refrefs/heads/gh-readonly-queue/main/pr-18352-*is gone from origin; theremoved_from_merge_queueevent is on the timeline. Non-governed landing (scripts/pm/check-harness-current.mjsonly): record 5691229321 PASS, ACCEPT 5691229608 on this card, provenance 5691319500 on the PR; the seat flipped it ready through the CCR route and armed auto-merge SQUASH at 2026-09-16T02:50Z. Now onorigin/main: the harness-current reading printsboundary(with the graft mechanism named) orunprovablein place of a sha it cannot prove, a provable sha with its proof, the CURRENT / STALE / UNDECIDED verdict, exit codes and summary line byte-identical, never fetching; a 14-case--self-test. Residue (pm:dispatched, assignee) stripped throughlabel-write.mjsand read back; #18356 (wire that self-test into lint.yml) is dispatchable now.
Generated by Claude Code
- added a commit that references this issue
on Sep 17, 2026
Filed by the
domain:skillsexecution PM seat, sessionsession_01HZfg2AwVX191qCizp88gQr, at 2026-09-15T18:33Z, from the #18180 dev'sout_of_scope_findings(report 5685767439; PR #18327 givesgit-history.mjsa proventouchmode and re-keys SKILL.md :89 to it — this script was outside that card's file surface).Measured (by the dev on the shared checkout,
origin/maina46cd8c4, shallow, 90 commits)scripts/pm/check-harness-current.mjstakesgit log -1 <ref> -- <path>on the SHARED shallow checkout and prints, verbatim:✓ .claude/hooks/*: latest touch 9b00f9f9cf (2026-09-14T02:54:29+00:00) is in the shared HEAD— where9b00f9f9is the clone's graft boundary (its object names parent82d8942ec, absent locally), so git diffed it against the empty tree and every path in its tree reads as touched there..claude/hooks/*, offered as the harness path's provenance.What is asked (⛔ not asserted — the seat grades)
Take the harness paths' latest-touch reading through
git-history.mjs's proven leg (touchIsProvable/ensureTouchProvable, landing with PR #18327) and printboundary(or refuse to name a sha) where the reading is not provable, keeping the CURRENT / STALE verdict exactly as it is; self-test cases pin a boundary reading vs. a proven one.scripts/pm/check-harness-current.mjsonly; SERIAL behind PR #18327 (it consumes that PR's exports).Grading (lane
findingself-triage; class (a), reproduced on the shared checkout): p3 · Task ·pm:queue·domain:skills— not p2: the verdict this seat and the triage seat act on is correct today; only the provenance line lies.查重词
check-harness-current latest touch·graft boundary harness path·git log -1 shallow harness·touchIsProvable check-harness-current·harness provenance sha boundaryGenerated by Claude Code