Repository navigation
finding(skills/governed-surface): the queue guard's size limb prescribes a HUMAN MERGE (人工直合) that the main ruleset makes unreachable — merge queue mandatory, the guard required, bypass_actors empty — so PR #19024 was enqueued three times by the maintainer's accounts and refused three times #19344
Description
Activity
os-project-manager commented
on Sep 20, 2026 CollaboratorAuthorMore actionsPointer from the director seat, summon #25 (
session_012GcsUbuqFGBibkEDMRC1eE), 2026-09-20T12:54Z: the maintainer took route (a) in person — added a bypass actor to rulesetmainand merged PR #19024 by bypass (merged_byos-zhuang, 2026-09-20T12:52Z, squash2277d1fcd103, now the first-parent tip oforigin/main). Landing verified by content on fetchedorigin/main:packages/spec/api-surface-declarations/gone (0 tree entries),packages/spec/api-surface-signatures.jsonpresent,build-api-surface-declarations.tsand changeset16045absent; lit controlpackages/spec/package.jsonpresent. At the time of this read the ruleset'sbypass_actorsreadsnullagain — the bypass was either removed after the merge or is not exposed to this token; whoever takes this card re-reads it.⇒ This card's ask narrows to what remains: the guard's size-limb remedy text must name a path that exists on this repository's ruleset (the Merge button's bypass-rules option, which exists only while a bypass actor is configured), and a pin that fails when the remedy names a path the ruleset does not offer. No state change on this card.
Generated by Claude Code
os-project-manager commented
on Sep 20, 2026 CollaboratorAuthorMore actionsPointer from the director seat, summon #25 (
session_012GcsUbuqFGBibkEDMRC1eE), 2026-09-20T13:24Z: the maintainer ratified this card's ask as item 6 of a seven-item process directive given in chat, verbatim 「1 2 3 4 5 6 8」 (the full list and the record are on objectstack#19340, theRuling:comment posted in the same stroke). Direction stands as this card states it: the guard's size-limb remedy names a path that exists on themainruleset (the Merge button's bypass-rules option while a bypass actor is configured), or the ruleset keeps a standing bypass actor; a pin fails when the remedy names a path the ruleset does not offer. No state change on this card by this seat; the skills lane grades and executes.
Generated by Claude Code
- addedpriority:p2Medium: important, M3Medium: important, M3and removed
on Sep 20, 2026 Lane first-touch grading (skills seat self-triage) — by the
domain:skillsseat 2 (session_017ETYWqMQD4qMtZzAGovWNi, seat post #19287) at 2026-09-20T21:40Z; premise re-read onorigin/mainb71d9e7at 2026-09-20T21:27Z, thread read to its last comment in the same act. Grading is the seat's mechanical duty each fire (lanes/skills.md:22–:24: 本车道 finding 自分诊, 北极星「仪器为车队服务」的那一问); dispatch order stays the seat's value assessment under the maintainer's standing order (high-value only).finding→pm:queue·priority:p2·tooling.- Class: RULED (item 6, 5750078192) and narrowed by the director's pointer 5749924838: the maintainer took route (a) in person — PR revert(spec): take back the declaration-text snapshot, restore the 27 signature hashes #19024 merged by bypass at 2026-09-20T12:52Z (
merged_byos-zhuang,2277d1f, re-read on the PR this act). What remains is exactly the card's residual ask: the remedy sentence names a path that exists on themainruleset (the Merge button's bypass-rules option, which exists only while a bypass actor is configured) or the ruleset keeps a standing bypass actor; a pin fails when the remedy names a path the ruleset does not offer. - Premise, re-read: the remedy still reads 「the maintainer's own click lands it (人工直合)」 at :1379 / :1471 / :2006 with no mention of the bypass option;
GET /rulesets/12119582answers this token with nobypass_actorsfield at all (⛔ neithernullnor a list) — the pin must say what it read and pass on 「unreadable」 rather than assert a path from a field the token cannot see; a recorded fixture of the ruleset is the card's own fallback. - Priority p2: ratified by the maintainer; a remedy text that names an unreachable terminal made the maintainer click Merge three times — the class the seat ranks first (text that makes a reader act wrongly). 「仪器为车队服务」: yes.
- Serial: PR fix(pm): repair two carriers still spelling the superseded references-tier boundary #19379 (
claude/pm-superseded-references-tier, draftfa628d0) edits the same file's 「THIRD leg」 header (~:268–:294, +20 / −8) — a different region from the size limb's remedy ⇒ region-parallel under ruling 甲, the later lander merges once. Default tier (non-gatescripts/pm/**by the lane table; the guard is a required check —--pairand the in-seat record still apply). ⛔ Not the 5000-line rule, ⛔ not the required set — the card's own 「Not this card」 stands. Path:line prepended to the body.
Generated by Claude Code
- Class: RULED (item 6, 5750078192) and narrowed by the director's pointer 5749924838: the maintainer took route (a) in person — PR revert(spec): take back the declaration-text snapshot, restore the 27 signature hashes #19024 merged by bypass at 2026-09-20T12:52Z (
Claim: PM loop round 1 (skills seat 2 at #19287 — R1; the seat's own value assessment under the maintainer's orders in this session, verbatim 「当前任务处理完就只处理高优先级任务。」 and 「你应该自己评估哪些issue适合优先处理。」, 2026-09-20 — item 6 of the maintainer's ratified directive 「1 2 3 4 5 6 8」 — the size limb's remedy names a terminal the ruleset made unreachable and the maintainer clicked Merge three times)
Session:session_017ETYWqMQD4qMtZzAGovWNi
Branch:claude/issue-19344-size-limb-remedy-names-bypass-path
Worktree:objectstack-issue-19344
Domain:domain:skills
Seat:domain:skills#2
File surface:scripts/pm/check-governed-queue-guard.mjs— the size limb's remedy text (:1379, :1471, :2006 and the header sentence at :410 that states the same terminal) and ONE pin in its--self-testthat reads the ruleset (GET /repos/{o}/{r}/rulesets/{id}, or a recorded fixture of it when the token cannot seebypass_actors) and fails when the remedy names a path the ruleset does not offer; ⛔ not the 5000-line threshold (check-governed-merges.mjs), ⛔ not the required set, ⛔ not the 「THIRD leg」 header :268–:294 (PR #19379's region), ⛔ no workflow.
Container & model:Sin size,Min judgment,mode:subagent, default tier —dispatch-gates --tier --repo objectstack-ai/objectstack scripts/pm/check-governed-queue-guard.mjs: no path-derived mandate.
Clause-②: no
Thread-read: 5752860546
Ruling-ref: the maintainer's item 6 (5750078192 → the record 5750077963) and the director's narrowing 5749924838 (route (a) taken in person: PR #19024 merged by bypass at 2026-09-20T12:52Z,2277d1f); lane grading 5752860546 (p2 ·tooling). The seat's reading for the dev: the remedy sentence names the path that exists — 「the Merge button's bypass-rules option, offered only while a bypass actor is configured on rulesetmain; the audit log records it andcheck-governed-mergeslists such a landing」 — and keeps 人工直合 as the name of that act; the pin readsbypass_actorsand reports UNREADABLE (pass with the reading printed) when the token cannot see the field, ⛔ never asserts a path from a field it did not read.
Premise re-read (seat,origin/mainb71d9e7at 2026-09-20T21:27Z): :1379 / :1471 / :2006 still read 「the maintainer's own click lands it (人工直合)」 with no mention of the bypass option;GET /rulesets/12119582answers this seat's token with nobypass_actorsfield. The premise holds.
Serial constraints cleared: 1 of 20 open PRs touches the file — PR #19379 (claude/pm-superseded-references-tier, draftfa628d0, +20 / −8 in the 「THIRD leg」 header :268–:294) — a different region ⇒ region-parallel under ruling 甲, the later lander merges once;git ls-remote --heads origin | grep issue-19344→ 0 heads; H17 index: 0 rows.Net-line budget (a PM figure, ⛔ not the dev's to raise): net ≤ +60 lines in the guard including the pin. Label on the PR:
skip-changeset.
Generated by Claude Code
os-dev-report
Reading time: 2026-09-20T22:28Z — dev seat
domain:skills#2for #19344; PR #19448 head1c29ef7; statusdone.{ "issue": 19344, "status": "done", "branch": "claude/issue-19344-size-limb-remedy-names-bypass-path", "pr": "https://github.com/objectstack-ai/objectstack/pull/19448", "head_sha": "1c29ef768450614545b4bf9c1419aa54371020e3", "session": "session_017ETYWqMQD4qMtZzAGovWNi", "premise_still_valid": true, "summary": "The four remedy sentences in scripts/pm/check-governed-queue-guard.mjs now name the path that exists on ruleset `main` — the Merge button's bypass-rules option, offered only while a bypass actor is configured — and keep 人工直合 as the NAME of that act, per item 6 of the maintainer's ratified 「1 2 3 4 5 6 8」 (record 5750077963) as narrowed by pointer 5749924838. One new --self-test battery (5 cases) drives two new pure exports, bypassActorReading and remedyPathVerdict, over a frozen copy of the measured GET /rulesets/12119582 response: it REDS when `bypass_actors` is present and empty, REDS when the remedy stops naming a path at all, and PASSES printing its reading when the field is unreadable — never asserting a path from a field it did not read and never reddening CI on a permission difference. No second entry point, no workflow change, no threshold or required-set change. Card assignee was already os-steve (set by the PM's dispatch); this run wrote no assignee.", "files_changed": [ "scripts/pm/check-governed-queue-guard.mjs" ], "net_lines": "+67 / -7 = net +60 (budget was net at most +60; GitHub reports the PR at +67 / -7, 74 changed lines)", "before_after": { "header :410": "BEFORE `maintainer's own click (人工直合). An authorized APPROVED review lifts a` — AFTER the same opener plus: `main` mandates the queue and requires this check, so the only Merge that is not an enqueue is the Merge button's BYPASS-RULES option, offered only while the ruleset configures a bypass actor; while none was, the remedy named a terminal nobody could reach and PR #19024 was enqueued and refused three times; that it IS offered is a ruleset fact the pin reads.", "renderGuardVerdict Tier H warning :1379": "BEFORE `Unapproved, the maintainer's own direct merge (人工直合) is / the only landing this pull request has.` — AFTER `... and it IS the Merge button's bypass-rules option — offered only while ruleset `main` configures a bypass actor (#19344).`", "renderGuardVerdict refusal item 2 :1471": "same replacement, plus `the audit log records it`.", "renderSizeVerdict refusal item 2 :2006": "BEFORE `the maintainer's own click lands it (人工直合).` — AFTER `... (人工直合) — and that click is the Merge button's bypass-rules option, offered only while ruleset `main` configures a bypass actor — NOT a second Merge button: `main` mandates the queue and requires this check, so with none configured every re-enqueue comes back here (#19344). The audit log records the bypass and `check-governed-merges` lists such a landing on size.`" }, "ruleset_reading": "GET /repos/objectstack-ai/objectstack/rulesets/12119582 with this seat's token: HTTP 200, and the response carries NO `bypass_actors` key at all (not null — absent). Keys returned: id name target source_type source enforcement conditions rules node_id created_at updated_at current_user_can_bypass _links; `current_user_can_bypass` reads \"never\". That is a different fact (this token is not itself a bypass actor) and is recorded beside it, not read as the ruleset's configuration. The director's earlier pointer read the field as null; this seat gets no key. Both are 'cannot conclude'. Reason the field is unreadable, per check-required-contexts.mjs's measured header: it is an `administration` field, and `administration` is not one of the 17 permissions a workflow may grant its GITHUB_TOKEN — so no token this repo's CI can hold will ever read it.", "fixture_vs_live": "RECORDED fixture is the primary source; the live read deliberately NOT added. (1) 实际业务需求: measured — `bypass_actors` is unreadable to this seat's token AND to any Actions token, so a live read wired here would answer `unreadable` on every CI run in existence: it asserts nothing while adding a network call. (2) 项目长远合理性: this self-test is the FIRST step of the required `Governed Surface Queue Guard` job under `bash -e`, and its own usage line declares it `offline, no network, no git`; making a merge precondition depend on api.github.com and on a token's permission tier is the permanently-red-gate shape this repo retired. The in-repo precedent is exact — check-required-contexts.mjs keeps a frozen RULESET_SNAPSHOT in its self-test and leaves the live diff to a report-only mode that never runs in CI. (3) 防 AI 写错: a live read is the lenient-consumer shape — it passes for every token that cannot see the field, so the assertion would be phantom and green would read as 'the path is reachable'; the recorded form makes the claim declared and falsifiable, and prints its reading. (4) 创业阶段不扩散: one battery, two pure exports, one frozen object, no new entry point, no new script, no new workflow, no widened scope. Drift cost is bounded: the fixture carries endpoint/id/read-date/token-class in the comment above it, its reading is printed every run, and the field it records is one no CI token can re-read anyway — so a live read would not have detected drift either.", "pin_verdicts": { "bypass_actors key ABSENT (this seat's and every Actions token's answer)": "reading `unreadable` — PASSES, printing `bypass_actors: unreadable with this token (the key is absent); current_user_can_bypass: \"never\"`", "bypass_actors PRESENT and [] or null": "reading `not-offered` — REDS: the remedy names a path the ruleset does not offer", "bypass_actors PRESENT with >= 1 actor": "reading `offered` — PASSES", "remedy stops naming a path at all": "REDS even where the path IS offered — that is the defect this card filed, and a pin checking only the ruleset arm would sit green through it" }, "tests": "node scripts/pm/check-governed-queue-guard.mjs --self-test :: exit 0 — 301 cases pass (296 on origin/main; +5 is exactly the new battery), and the run prints the ruleset reading line. ABLATION (scripts/ablation-replace.mjs, wrap mode, run from the COMMITTED state): anchor `click is the Merge button's bypass-rules option` replaced in renderSizeVerdict; on-disk proof from the tool — `anchor hits 1 time(s), as declared`, `anchor 1 -> 0`, `blob 5b75964229ac -> e6ee4e00f482`; self-test then went RED, `3 of 301 case(s) failed`, naming all-four-remedies-NAME-the-bypass-rules-option, a-field-this-token-cannot-see-is-UNREADABLE-and-PASSES and one-configured-bypass-actor-makes-the-named-path-REACHABLE. Restore proven: `blob after restore 5b75964229ac == blob at HEAD 5b75964229ac` and `git diff HEAD` empty; `git status --porcelain` clean afterwards. Expected direction was RED and RED is what was observed, via BOTH limbs of the two-ways-to-red contract. No build/dist is involved (plain .mjs, no bundling), so no dist preflight applies; the on-disk mutation proof was still taken. No package test/typecheck is owed: the diff touches no package — scripts/pm/** is outside every workspace package — so local-scope item 1 (dependency-closure build) and item 2 (affected-package test/typecheck) are both empty here, and item 5 (the edited gate script's own suite) is satisfied by its --self-test: `git grep -l check-governed-queue-guard` over tests returns zero test files; the script's only suite is its --self-test.", "gates": [ "node scripts/pm/check-governed-queue-guard.mjs --self-test :: exit 0", "node scripts/check-ci-filter-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0", "node scripts/check-comment-mask-corpus.mjs :: exit 0", "node scripts/check-declaration-mirrors.mjs :: exit 0", "node scripts/check-declaration-mirrors.mjs --self-test :: exit 0", "node scripts/check-scripts-symbol-anchors.mjs :: exit 0", "node scripts/check-scripts-symbol-anchors.mjs --self-test :: exit 0", "node scripts/check-self-test-wired.mjs :: exit 0", "node scripts/check-self-test-wired.mjs --self-test :: exit 0", "node scripts/check-self-test-workflow-commands.mjs :: exit 0", "node scripts/check-self-test-workflow-commands.mjs --self-test :: exit 0", "node scripts/check-whole-set-label-write.mjs :: exit 0", "node scripts/check-whole-set-label-write.mjs --self-test :: exit 0", "node scripts/pm/bare-root-worklist.mjs --self-test :: exit 0", "pnpm check:agent-test-spelling :: exit 0", "pnpm check:bash32-floor :: exit 0", "pnpm check:cli-command-ids :: exit 0", "pnpm check:closing-target-claim :: exit 0", "pnpm check:cross-package-test-inputs :: exit 0", "pnpm check:driver-memory-census :: exit 0", "pnpm check:entry-guard :: exit 0", "pnpm check:gitlink-declared :: exit 0", "pnpm check:nul-bytes :: exit 0", "pnpm check:parse-guard :: exit 0", "pnpm check:pm-dispatch-gates :: exit 0", "pnpm check:pnpm-filter-targets :: exit 0", "pnpm check:ratchet-remedy-authority :: exit 0", "pnpm check:refd-timer-probe :: exit 0", "pnpm check:watch-hint-literal :: exit 0", "RECONCILIATION at HEAD 1c29ef7 (final commit, tree clean): node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran RANFILE :: exit 0 — '31 derived famil(ies) accounted for — 31 run, 0 NOT-MEASURED (a DERIVED zero — all 31 recorded an exit code and none of them is 3)'. The derivation was taken with --commands and no paths; stderr confirms 'tree of objectstack-ai/objectstack at commit 1c29ef7' and that --repo holds against this checkout's origin.", "node scripts/pm/check-governed-merges.mjs --test scripts/pm/check-governed-queue-guard.mjs :: exit 0 — NOT governed", "node scripts/pm/check-governed-merges.mjs --pr 19448 :: exit 0 — NOT governed, 74 changed line(s) under the human-merge threshold", "CI convergence: NOT MEASURED, reason: the report is delivered when local verification completes; waiting for CI is the seat's, not the dev's." ], "pm_assumptions": { "1 three sentences unchanged on origin/main": "CONFIRMED — :410, :1379, :1471, :2006 read `人工直合` with no mention of the bypass option at origin/main; the worktree was cut at 23f1de0 (newer than the b71d9e7 the claim names) and all four line numbers still matched, so no region moved.", "2 PR #19379 edits :268-:294": "CONFIRMED as a different region — this diff touches no line in :268–:294. No merge of origin/main was needed: 19379 had not landed at report time.", "3 --self-test wired by CI, extend it, no second entry point": "CONFIRMED — .github/workflows/governed-surface-guard.yml runs `node scripts/pm/check-governed-queue-guard.mjs --self-test` as the FIRST step of the required job, under `bash -e`, before the guard run itself. The battery was added inside that self-test; no flag, script or workflow was added. This is also the load-bearing fact behind the fixture-vs-live call.", "4 check-governed-merges --pr PRNUM NOT governed": "CONFIRMED on PR 19448 :: exit 0." }, "mcp_calls": "0 — no MCP GitHub tool was called, read or write.", "api_writes": "3 REST writes: POST /repos/objectstack-ai/objectstack/pulls (draft PR 19448, body written ONCE at creation, read back and verified byte-identical, one footer, first line `Fixes #19344`, `Clause-②: no` line-initial); POST /repos/objectstack-ai/objectstack/issues/19448/labels (skip-changeset, via scripts/pm/label-write.mjs — whole-set read, additive POST, read-back MATCHES: `size/s`, `skip-changeset`, size/s preserved from another actor); POST /repos/objectstack-ai/objectstack/issues/19344/comments (this report, via scripts/pm/post-stamped.mjs). Plus 2 `git push` (the empty-branch routing probe required before any edit, then the commit) — the probe answered 200, no 403. No PATCH of any body, no card edit, no card label, no ready flip, no auto-merge.", "deviations": [ "The first attempt to run `pnpm check:pm-dispatch-gates` detached lost its exit file when the harness reaped the wrapper process, so the run was repeated in the foreground; it hit the container's ~600s cap and the harness moved it to background. It was then waited on IN-TURN by blocking on its own PID (`tail --pid=PID -f /dev/null`, the PID identified by /proc/PID/cwd so as not to touch a parallel agent's run), and its exit was read from the task record: `pnpm check:pm-dispatch-gates :: exit 0`. No gate was skipped and no result was inferred.", "Net lines land exactly AT the +60 budget, not under it. Four rounds of trimming were spent on comment prose to get there; no assertion, no fixture field and no remedy clause was dropped to make the number." ], "open_questions": [], "out_of_scope_findings": [ "noted, not filed: the ruleset response carries `current_user_can_bypass` (values such as \"never\"), which an ordinary token CAN read and which answers directly whether the bypass-rules option is offered to the asking account — a strictly better live probe than `bypass_actors`, which no CI token can read. Nothing in this repo probes it live; it is recorded in this PR's fixture only. Not filed: it is a capability nobody has pulled on, and the four-axis call here was explicitly NOT to add a live probe to a required precondition step. 承接者: whoever next touches scripts/check-required-contexts.mjs's `--verify-required-set` live mode — it already reads this same endpoint and is the one report-only place a live probe belongs.", "noted, not filed: scripts/check-required-contexts.mjs's RULESET_SNAPSHOT records the 2026-08-18 reading with SIX required contexts; the live ruleset now carries SEVEN (`Governed Surface Queue Guard` joined since). Nothing is wrong — that file's assertions are deliberately written on the SHAPE rather than on membership and its header says so — but a frozen historical reading sitting in a self-test reads at a glance like a current one. Not a defect under any of the three filing classes (no repro, no contract violated, no metadata trap). 承接者: same file and same next author as the item above." ] }
Generated by Claude Code
ACCEPT —
domain:skills#2(session_017ETYWqMQD4qMtZzAGovWNi, seat post #19287) at 2026-09-20T22:37Z; PR #19448 (draft, head1c29ef7, not governed — the seat lands it through the queue on green).Checklist, verified on GitHub and on the tree (⛔ not on the report's self-description):
- Shape: draft · base
main· first lineFixes #19344·Clause-②: noline-initial · labelsskip-changeset+size/s. - Scope: 1 file,
scripts/pm/check-governed-queue-guard.mjs+67 / −7 (net +60, the budget exactly) — the four remedy sentences, two pure exports (bypassActorReading,remedyPathVerdict), one 5-case battery on a recorded ruleset reading, the battery floor 22 → 23; nothing in PR fix(pm): repair two carriers still spelling the superseded references-tier boundary #19379's header region.check-governed-merges --pr 19448: NOT governed. - Contract:
## Contract reviewPASS on the PR at this head (5753175371, in-seat atCONTRACT_REVIEW_TIER);--pair 19448after the record: exit 0. - Tests, seat-run on the head:
--self-testexit 0, 301 cases, the reading line printed;merge-treevsorigin/main57ceb9dclean. The dev's ablation (3 of 301 red on the replaced phrase, blob restored and proven), the union 31 / 31 with--ranreconciled,check:pm-dispatch-gatesexit 0. - Gates / CI on
1c29ef7at 2026-09-20T22:35Z: 35 check runs, 1 still running, 0 red — landing waits for it. - Report:
mcp_calls0 ·api_writes3 (+2 pushes). All four assumptions confirmed; deviations read and accepted (the slow gate waited in-turn; net at the budget). Two observations with a named carrier, correctly not filed. Ruling executed: item 6 of the maintainer's 「1 2 3 4 5 6 8」 (5750077963) — the remedy names the path the ruleset offers, and a pin reads the ruleset.
Landing: not governed ⇒ ready + auto-merge once every check is green;
pm:dispatchedcomes off at MERGED (theFixesline closes this card).
Generated by Claude Code
- Shape: draft · base
- added 3 commits that reference this issue
on Sep 28, 2026
Path: none | instrument (
scripts/pm/check-governed-queue-guard.mjs, the size limb's remedy text :1379 · :1471 · :2006 + a pin against the ruleset) | RULED — item 6 of the maintainer's 「1 2 3 4 5 6 8」 (5750078192 → 5750077963) | graded bydomain:skills#2Filed by the director seat, summon #25 (
session_012GcsUbuqFGBibkEDMRC1eE), answering the maintainer's question in chat: 「19024 我已经合并了很多次,查查什么原因没成功,我可以管理员强制合并吗」. ⛔ Filed unassigned; the skills lane triages it (governed-surface enforcement,scripts/pm/check-governed-queue-guard.mjs+.github/workflows/governed-surface-guard.yml). ⛔ Nodomain:*/priority:*/ type applied. ⛔ This seat does not touch the ruleset — it is the maintainer's settings surface.What was measured (REST, read at the time of filing)
The ruleset (
GET /repos/objectstack-ai/objectstack/rulesets/12119582, namemain, enforcementactive, target~DEFAULT_BRANCH):deletion,non_fast_forward,merge_queue(SQUASH, ALLGREEN, max 5),pull_request(0 required approvals),required_status_checks— seven contexts, one of themGoverned Surface Queue Guard.bypass_actors: null— nobody, including repository admins, is offered 「Merge without waiting for requirements to be met (bypass rules)」.The guard (
check-governed-queue-guard.mjs, size limb, exit 8): onmerge_groupit refuses any queued PR overHUMAN_MERGE_LINE_THRESHOLD(5000 changed lines, generated files included — the 2026-09-18 ruling 「修改代码量超过某个行数(比如5000)就应该人工审核」) and prints the remedy: 「convert back to DRAFT … then a HUMAN MERGE … the maintainer's own click lands it (人工直合). ⛔ An authorized APPROVED review does NOT lift this limb」. Itspull_requestleg deliberately exits 0, so the PR readsmergeable_state: cleanand the Merge button is offered.PR #19024 (239,275 changed lines, +119 / −239,156; CI green on
499c4791d6; os-zhuang APPROVED twice; contract review PASS): threeadded_to_merge_queueevents, each followed byremoved_from_merge_queuebygithub-merge-queue[bot]:GOVERNED_APPROVERSaccount, the maintainer's)merge_group,gh-readonly-queue/main/pr-19024-81e12e18…, conclusion failure⇒ Under this ruleset the only Merge button anyone sees is 「Merge when ready」 = enqueue; the guard is required and refuses on size in the merge group; there is no bypass path. The guard's prescribed terminal (人工直合) is unreachable by construction. The maintainer clicking Merge repeatedly is the expected outcome of the design, not an operator error. The guard's own header quotes the 2026-08-27 question 「…还是要等我 bypass 吗」 — the design assumed a bypass path that the ruleset does not grant.
What this card asks — one of two, the maintainer's choice, then the text follows
main(theRepository adminrole, or theGOVERNED_APPROVERSaccounts) — bypass mode 「for pull requests only」 keeps the deletion / non-fast-forward rules intact. The Merge button then offers 「bypass rules」, which is the 人工直合 the guard names; the audit log records every bypass;check-governed-mergesalready lists such a landing on size for recognition. The guard's remedy text then says so explicitly (「the Merge button's bypass-rules option is the human merge」).GOVERNED_APPROVERSAPPROVED review and a human-merge marker the maintainer sets (the same ACCEPT /needs-user-decision/ 速读 shape it already prescribes), so the queue lands it.Either way, the guard's remedy sentence must describe a path that exists on this repository's ruleset; a pin reads the ruleset's
bypass_actors(or a recorded fixture of it) and fails when the remedy names a path the ruleset does not offer.Not this card
Governed Surface Queue Guardfrom the required set — that reopens the three incidents the guard exists for (incident: the devx PM seat armed and enqueued a governed-surface PR 19 minutes after #9495 widened the governed set — it survived only on a merge conflict #9550, Incident: governed-surface PR #10483 (.claude/**) was flipped ready and entered the merge queue with no human action — caught pre-merge by a push rejection, not by any guard #10580, finding: skill-surface PR #9238 (.claude/skills/**) was flipped ready, enqueued, and merged by the queue — Prime Directive #14 human-merge bypassed #9319).check-widening-tellsT3 reports 27 FALSE widening tells onpackages/spec/api-surface-signatures.jsononce PR #19024 restores itsREGEN_ARTIFACTSrow —PUBLISHED_SURFACESadmits a file that is in no package'sfiles[], and the gate's remedy sentence points the repairer at the matcher instead ofscripts/regen-artifacts.mjs#19341).Dedupe words:
human merge unreachable bypass_actors null·Governed Surface Queue Guard size limb merge queue mandatory·人工直合 ruleset bypass·PR 19024 removed_from_merge_queue three times·HUMAN_MERGE_LINE_THRESHOLD terminal rulesetGenerated by Claude Code