Skip to content

[finding] platform-readings: the REST proxy's write identity changed mid-shift with no seat action — content writes read back claude[bot] (installation) until 2026-09-15T20:04Z and os-zhuang / User via app claude (user-to-server) from 2026-09-16T01:53Z — the register has no row saying the token class is re-read, not assumed #18350

Description

@os-zhuang

Filed by the domain:skills execution PM seat, session session_01HZfg2AwVX191qCizp88gQr, at 2026-09-16T02:11Z, from its own readings this shift.

Measured (comment authors read back through GET /issues/comments/{id}, same session, same tool scripts/pm/post-stamped.mjs, same REST proxy)

comment written user.login user.type performed_via_github_app
5687342171 (landing record #18324) 2026-09-15T20:04:43Z claude[bot] Bot claude
5690836932 (ruling-C provenance PR #18315) 2026-09-16T01:53:43Z os-zhuang User claude
5690861787 / 5690953559 / 5690957832 01:57Z – 02:10Z os-zhuang User claude
  • GET /user on the same credential reads os-zhuang / User at both instants (it did at seating, 02:03Z the day before, when the writes read back claude[bot]).
  • No seat action sits between the two readings: no re-attach, no token change the seat can see; the flip happened while the seat was idle between 20:04Z and 01:53Z. ⇒ the proxy now injects a user-to-server token (the App acting on behalf of os-zhuang) where it injected the installation token before; performed_via_github_app reads claude in both classes, so it is NOT a discriminator (already on the register); user.login + user.type on a read-back IS.
  • Consequence measured on the live board: the seat's four ruling-C provenances of 01:53–01:57Z carry the SAME account as the approving reviews they cite (os-zhuang, 5217668792 / 5217673315 / 5217676382 / 5217679727). The session line inside each record is the attribution; the red line (the seat writes no approving review) held — the review endpoint was never called — but a reader of merged_by / comment authors alone cannot tell the seat from the approver any more.

What is asked (⛔ not asserted — the seat grades)

One or two rows in references/platform-readings.md (write side): the proxy's token class can change between two writes of one session with no seat action; the class is read on every write's read-back (user.login + user.type), never carried forward from the round-open marker; a change is recorded on the seat post at the next refresh with both instants. Optionally one line in the seat-post protocol: the round-open marker's identity reading is dated, not standing. References tier (in-seat contract-tier review). Fold candidate with #18320 (same file); the ceiling is 466 with 463 in use.

Grading (lane finding self-triage; class (c), a platform fact change measured with a control): p3 · Task · pm:queue · domain:skills.

查重词

write identity flipped mid-shift · installation token to user-to-server · claude[bot] os-zhuang read-back · performed_via_github_app not a discriminator · token class re-read every write


Generated by Claude Code

Activity

  1. added theissue type on Sep 16, 2026
  2. os-zhuang commented on Sep 16, 2026

    @os-zhuang
    ContributorAuthor

    Consequence measured — skills seat, session session_01HZfg2AwVX191qCizp88gQr, 2026-09-16T02:33Z. With the proxy writing as os-zhuang, the draft PRs this seat's devs open are AUTHORED by os-zhuang (PR #18351 read back user.login = os-zhuang), and GitHub then refuses to request a review from the author: POST /pulls/18351/requested_reviewers with ["os-zhuang","hotlong"] → 422 「Review cannot be requested from pull request author」; the same call with ["hotlong"] alone → 201. GitHub also does not let a PR's author submit an APPROVED review on it, so while this identity stands, os-zhuang cannot be the authorized approver of any governed PR this seat opens — only hotlong can, and ruling C depends on that approval. This turns the identity change from an audit concern into a throughput one: every rules-layer PR from this seat now waits on hotlong alone. Remedy stays the one in the card body: a dedicated low-privilege GitHub user behind seat sessions, or the App installation token (claude[bot]), which authored every seat PR before 20:04Z and was requestable / approvable by both approvers.


    Generated by Claude Code

  3. os-zhuang commented on Sep 16, 2026

    @os-zhuang
    ContributorAuthor

    Closed as a duplicate of #18334 (skills-lane self-triage): the triage seat measured the same write-identity flip first (2026-09-15T22:55Z, claude[bot] → os-sam on #6015), and this card's table is the second measurement of it on this seat's writes (claude[bot] at 2026-09-15T20:04Z → os-zhuang at 2026-09-16T01:53Z). Nothing here is dropped — the table, the GET /user reading, the maintainer's account of the mechanism and the reviewer-request consequence (422 on PR #18351) are carried onto #18334 in one comment, and #18334's grading names the three rows this card asked for (:129 / :130 re-keyed, one consequence row), folded with #18320 into one platform-readings PR. Skills seat, session session_01HZfg2AwVX191qCizp88gQr, 2026-09-16T03:19Z.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions