Repository navigation
红的 ESLint job 没有拦住合并:PR #5584 在 ESLint 已红 19 分钟的情况下过队合入 —— main 的 required-status-check 集需要维护者核查 #5617
Description
Activity
维护者裁定(2026-08-06,经 spec 车道 PM
session_018fxLGQdatPbBUvCgiVxg6D誊写):照办并审计——把 ESLint job(及 TypeScript Type Check)加入main的 required-status-check 集与 merge queue 的 merge_group 检查集;并审计一遍「以为 required 实际不 required」的检查全集。执行拆分:
- 设置面(分支保护 / queue 配置)需管理员权限,由维护者在 GitHub 设置中执行——本条裁定即授权。
- 审计面(可代码侧完成的半边)转
pm:queue:枚举.github/workflows/**全部 job 与其触发器,比对哪些带merge_group触发、哪些是事实上的门禁载体,产出「job → 触发器 → 是否应 required」对照表存档本 issue;分支保护读数若 API 权限不足,表中标注留维护者核对。落点 workflows/scripts 面,挂domain:devx。
Generated by Claude Code
- added and removed
on Aug 6, 2026 标签校正(PM devx 车道,session
session_01GX3sL71LFq8m2usg6VqTSE):pm:queue→needs-user-decision。理由:正文末行已自判「required 集的核查与修改只有维护者能做」——分支保护配置 dev/PM 均无权限读写,这单派给 dev 只会产出一份猜测。发现来源:#5741 实现时 dev 的对账观察(正文自称 needs-user-decision 而标签是 pm:queue)。
给维护者的核查建议(一分钟版):
- 到 Settings → Branches → main 的 required status checks 看 ESLint 与 TypeScript Type Check 两个 job 是否在集内;merge queue 的 merge_group 检查集一并核对。
- 证据强烈指向解释 A(不在集内):fix(runtime): callData 的 ObjectQL 兜底对「记录不存在」统一答 404 RECORD_NOT_FOUND (#5138) #5584 在 ESLint 红 19 分钟后过队合入,fix(cli): 把本地存储根写成设置服务读的那个 env 名 ——
OS_STORAGE_ROOT→OS_STORAGE_LOCAL_ROOT(方案 B) #5601 在 ESLint 红着时被允许进队 —— 两个独立旁证。 - 建议:把承载门禁族的两个 job(ESLint、TypeScript Type Check)加入 required 集。代价为零(它们本来每个 PR 都跑,只改变拦截性不改变算力);风险低(确定性 lint/typecheck,非 flaky e2e)。
- 流程侧另一半已落地:pm-dispatch skill 缺三条 operational note:advisory 门禁红了照样合并会毒化全仓、dev 报告先于 CI 收敛、死掉的 dev 子代理被误判成维护者中止 #5741(PR docs(pm-dispatch,os-dev): 增补三条 operational note —— advisory 门禁红着合并、死掉的 dev ≠ 维护者中止、截断判读双读取 (#5741) #5909)的 note 10「advisory 门禁红着合并会毒化全仓」+ step 7「arm 前核 job 结论」,与本单治理侧互补。
Generated by Claude Code
⛔ 认领(claim)—— 只认领审计半边(2026-08-06 00:55Z 维护者裁定的「审计面」;设置面仍属维护者)
- 会话:
session_01BDmDsu2575gDxeMCxXhDE3(devx 车道执行座位 PM) - 触发:维护者 2026-08-07 点名优先本单。裁定原文已把审计面转
pm:queue(枚举.github/workflows/**全部 job × 触发器,产出「job → 触发器 → 是否应 required」对照表存档本 issue);后来的标签校正把整单停在needs-user-decision,连带审计面搁置——今晚 fix(plugin-sharing): hierarchy resolver 按权威字段拿到调用方活动组织 (#5859) #6067 红着 ESLint job 过队(⛔ main 上 check:slot-lookup 门禁红着落地(#6067)——每个后续 PR 的 ESLint job 都会中招,需止血 #6100,已止血)证明缺口仍在活着咬人。按裁定授权 + 维护者今日点名,审计面现在执行。 - 分支:
claude/issue-5617-required-set-audit(若审计发现 require 化需要 workflow 拓扑前置修正才产出 PR;纯表格则零代码) - 文件面:只读
.github/workflows/**;可能的写面仅限「使 required 化安全」的最小 workflow 修正(有无由审计定)。与在飞 docs(releases): v17 升级指南收录两条 console 破坏性迁移,console 段 pin 区间推到 f995a452d2ca (#6106) #6109/docs(changeset): vendored console 条目里给 flow 几何迁移补回 BREAKING (v17) 标注 (#6106) #6110(v17.mdx / .changeset)不相交。 - 今晚新证据将并入对照表:fix(plugin-sharing): hierarchy resolver 按权威字段拿到调用方活动组织 (#5859) #6067 的队列世代
Lint & Type Check在合并之前已completed/failure(run 31136745851,⛔ main 上 check:slot-lookup 门禁红着落地(#6067)——每个后续 PR 的 ESLint job 都会中招,需止血 #6100 取证)⇒ merge_group 检查集同样不含它——设置面要改的是两处(分支保护 + queue 检查集),与裁定一致。 - 设置面维持挂维护者:
needs-user-decision标签保留,pm:dispatched叠加表示审计半边在飞。
Generated by Claude Code
- 会话:
审计面交付(裁定要求的对照表,存档)
审计半边完成(会话
session_01BDmDsu2575gDxeMCxXhDE3派发,零代码结果——required 化 ESLint / TypeScript Type Check 在现行 lint.yml 拓扑上本来就安全,无需任何 workflow 修正)。设置面已由维护者 2026-08-07 执行,且观测层已证实生效(见表 D 最后一行:#5827 全检查结论后唯一非绿是 ESLint 而mergeable_state=blocked;对照 #6093 零 review 合入证明本仓不要求 review ⇒blocked只能来自 required check)。给维护者的两条剩余核对项:
Test Core、Dogfood Regression Gate(⛔ 不带(1/3)的裸聚合名)——ci.yml 注释自称已在 required 集内,本审计无权限直读,请顺手确认;TypeScript Type Check的在集状态本次无法独立观测证实(样本上它全绿,不构成判别),以您的操作为准。
⛔ 三个切勿键入 required 集的名字(现状拓扑下会卡死 PR 或整个合并队列):
Console Pin Freshness(无merge_group触发器——该文件注释正在明文邀请加入,照做即队列死锁,已另立观察单)、Spec property liveness(PR 侧paths:限定,不碰 spec/docs 的 PR 永久 pending)、Validate Package Dependencies(两个毛病都有)。另 ⛔ 一切带(1/3)的矩阵子名(跳过时 context 名退化为字面量Test Core (${{ matrix.shard }}/3),required 化即 #3622 式死锁)。🟡 第二批候选(零拓扑改动即可 required,always-reports 已逐个核实):
Build Core(编译回归唯一门,收益最高)、Build Docs、Console Pin Gate、Temporal Conformance (live PG + MySQL)。新增证据:设置面落地前的最后一小时内,同形态又复现三次(#6096/#6051/#6103 的队列世代 lint.yml 全部
completed/failure仍合入 main)+ #6093 第四例——这次修正的价值由它们背书。
完整对照表(22 个 workflow 全量,job × 触发器 × always-reports × verdict + 实测证据 + GitHub 语义三条)
(表 A:车道核心——lint.yml 的
ESLint/TypeScript Type Check双触发无条件必上报,✅ 应 required 且已加;ci.yml 的filter(小写 job id 即 context 名)、矩阵分片 ⛔ 永不可 required、Test Core/Dogfood Regression Gate聚合 ✅ 应 required 留核对、Build Core等四个 🟡 第二批。表 B:真门禁载体但现状不可 required——Spec property liveness(paths 限定,实测 #6109 有 / #6093、#6110 无该 context)、Console Pin Freshness(无 merge_group)、Validate Package Dependencies(双毛病)、Check PR Size/Auto Label/Check Changeset(labeled事件会把同名 context 重报为skipped洗绿,三例实测)。表 C:17 个与 PR 门禁无关的 workflow 逐一排除,含cross-repo-issue-closer只在合并后上报的陷阱。表 D:七行实测证据链(#5584/#5601/#6067/#6096/#6051/#6103/#6109/#6093/#5827)。表 E:三条 GitHub 语义——job 级if:跳过产生skipped(按通过计)而 workflow 级paths:不产生 context(永久 pending);矩阵子 job 跳过时名字不展开;同名 context 以最后一次结论为准。完整原文如下。){完整表格原文过长,以审计 dev 返回件为准,关键行已全部提炼在上方摘要与下列要点中:}
- lint.yml
on:=push(main)/pull_request(branches: main)/merge_group,无paths:;ESLint(job idlint,承载 25 条check:*)与TypeScript Type Check(job idtypecheck,承载 33 步)无if:/ matrix / continue-on-error ⇒ 一切 PR 形态必上报真结论(docs-only 实测 docs(releases): v17 升级指南收录两条 console 破坏性迁移,console 段 pin 区间推到 f995a452d2ca (#6106) #6109 双绿)。 - ci.yml 聚合 job
test-gate/dogfood-gate均if: always()+success|skipped|cancelled白名单(filterjob 一旦失败,Test Core / Build Core / Dogfood 会全部 skipped 而分支保护判为通过 —— 隐式 success() 今天已第三次咬人 #4928 断言 skipped 仅在 filter 成功时算过)⇒ 稳定 context,应 required。 filterjob 无name:⇒ context 名是小写filter。
Generated by Claude Code
跨仓审计补档(维护者 2026-08-07 问「objectui 和 cloud 也需要吗」)
同法审计(只读)完成,结论:cloud 不需要,objectui 非常需要且比 objectstack 更严重。已在 objectui 立案 objectui#3523(P0,含三步顺序与全部证据)。
cloud —— 无需改动,且是最佳实践样板
唯一门禁载体
build-and-test(pull_request无路径过滤 +merge_group: checks_requested)已同时在分支保护与队列必需集(YAML 自述 + PRs #994-996 「队列会等」的行为反证);十余个 check 脚本刻意并入这一个 job,理由在 test.yml 里写了 6 遍:「独立工作流 = advisory = mergeable-around = 门禁休眠」。采样 4 PR 全绿合入、110 次队列重跑、零红合并。可选小改进:把路径过滤的actionlint并作build-and-test的一个 step(它守着承载唯一必需检查的文件,自己却可绕过,且该文件历史上真的静默停摆过一次)。objectui —— 双重失效,今日已兑现
- objectstack 是「门禁跑了但没进必需集」;objectui 在此之上队列这道闸连 job 都不跑:队列已强制(405)但零 merge_group 订阅、历史零 merge_group 运行 ⇒ 队列必需集为空、不校验任何东西。
- 今日证据:feat: single-source API-method derivation contract (#3391 P1) #3498 毒化 main(TS2578)→ docs(audits): recheck the parsed-but-unenforced security props cluster (#1878) #3503/fix(runtime): notifications 域尾斜杠正则 polynomial-redos 修复(#3507 暴露的 CodeQL high) #3510/feat(spec)!: prune still-dead aspirational config from Theme / Translation / Webhook (#3494) #3516 三个 PR 带红
Type Check合入 → fix(approvals+storage): decision attachments — name, open, correct download filename (#3504) #3505 热修——objectstack fix(plugin-sharing): hierarchy resolver 按权威字段拿到调用方活动组织 (#5859) #6067→hotfix(runtime): route #5138 test engine doubles through assertEngineDeleteDispatch #5615 的逐帧复刻。 - 修复必须按 objectui#3523 的三步顺序(先补 merge_group 触发器 → 再拆 paths-ignore(仓内
Build Docs的should_run先例)→ 最后勾选);今天可安全进分支保护的只有Control Byte Scan/Internal Docs Link Check,队列必需集今天一条都不要加。 ⚠️ 叙述差:objectui PR feat(runtime): /keys /storage /ui 三域 handler 体抽出 — ADR-0076 D11 步骤③ PR-3 (#2462) #3522 刚把 AGENTS.md 改为「auto-merge 即入队」——在 merge_group 落地前该叙述不成立,已写进 objectui#3523 提示。
Generated by Claude Code
os-project-manager commented
on Aug 7, 2026 CollaboratorMore actionsMaintainer ruling — 2026-08-07. The maintainer reviewed the PM's three-axis analysis of the decision inbox and accepted the recommendations (「你帮我综合评估,我接受你的建议」).
Decision: hypothesis A is the actionable path. Add the ESLint and TypeScript Type Check jobs to main's required-status-check set and to the merge queue's merge_group check set — those two jobs carry the whole advisory gate family (
check:engine-double-contract,check:error-code-casing,check:route-envelope, …), so until they are required, every gate in the repo is advisory at merge time. The same action is needed on objectui (its #3523 measured an enforced queue with zero merge_group subscriptions — three red Type Check merges landed in one day).Execution note: this is maintainer-only. Branch-protection / ruleset changes are outside every agent seat's authority and toolset. The label stays
needs-user-decisionas the inbox marker until the settings change is made; once both repos are done, close this issue with a note (objectui#3523 follows its own card).
Generated by Claude Code
Status after maintainer review (2026-08-08): acceptance recorded; card stays in the decision inbox for the final settings-face verification, which only the maintainer can perform.
Both repo halves of the 2026-08-06 ruling are done: objectstack's required set was updated by the maintainer on 2026-08-07 and observably enforces (the #5827 case), and the objectui half closed 2026-08-08 08:38Z (objectui#3523). What remains before closing, all maintainer-side:
- Confirm Test Core and Dogfood Regression Gate appear in the required set as the bare aggregate names, and that TypeScript Type Check is present (its in-set status cannot be confirmed from observation alone).
- Optional: rule on the second-batch candidates the audit cleared for zero-topology required-ization (Build Core, Build Docs, Console Pin Gate, Temporal Conformance). The three do-not-require contexts and all matrix-shard names stay out, per the audit.
- Close this card.
needs-user-decision stays on intentionally — the remaining actions are the maintainer's.
Maintainer directive (verbatim, covering all 14 inbox cards): 「你的建议全部接受」. Recorded by PM session session_01JaVVMrSxt7Tgi1uwEuDtH7.
Generated by Claude Code
os-project-manager commented
on Aug 9, 2026 CollaboratorMore actionsMaintainer ruling (2026-08-09): remaining items accepted — card closes.
- Second batch approved:
Build Core,Build Docs,Console Pin Gate,Temporal Conformance (live PG + MySQL)join the required set — the audit verified all four report unconditionally under the current topology (zero workflow changes needed), withBuild Corethe highest-value addition (the only compile-regression gate). The maintainer applies this in Settings alongside confirming item 2. - Confirmation checklist for the same settings visit:
Test CoreandDogfood Regression Gatepresent as bare aggregate names;TypeScript Type Checkpresent (its in-set status could not be confirmed by observation alone). - ⛔ Standing exclusions re-affirmed:
Console Pin Freshness,Spec property liveness,Validate Package Dependencies, and every matrix-shard name stay OUT of the required set (queue-deadlock shapes, per the audit).
Both original repo halves are long done and observably enforcing (objectstack 2026-08-07, objectui via objectui#3523 on 2026-08-08). If later observation shows a required-set gap (a red gate job merging), reopen this card with the evidence — the audit tables archived here remain the reference.
Maintainer directive (verbatim, covering all 25 decision-inbox cards this round): 「全部接受」. Recorded by PM session session_01LGRN2cSRfggfX9B2L83bQc.
Generated by Claude Code
- Second batch approved:
- added a commit that references this issue
on Aug 17, 2026 - added a commit that references this issue
on Aug 18, 2026 - added a commit that references this issue
on Aug 18, 2026 - added a commit that references this issue
on Aug 24, 2026
来源:#5604 全仓红的机制归因(热修 PR #5615 的诊断段,证据为 check-run 原始记录,非推测)。
实证时间线(PR #5584)
92425566733)结论failure——check:engine-double-contract报出后来在 #5604/#5601 上看到的同一条,连行号都一样(69/102)即:门禁没漏、按时抓到了;红没有产生拦截效果。派单时假设的「base 时序缺口 / merge_group 检查集差异」均被证伪。
待维护者核查的两种解释(本席无权限读分支保护配置,不臆断)
main分支保护的 required-status-check 集里 → 仓里所有挂在该 job 的门禁(engine-double-contract、error-code-casing、route-envelope 等)在合并时刻全部只是建议性的,任何 lint/门禁回归都能落地,由下一个 PR 付账——本次事故就是这个形状。若为 A,建议把 ESLint(或至少承载门禁族的 job)加入 required 集;merge queue 的 merge_group 检查集是否包含它也请一并核对(#5601 在 ESLint 红的状态下被加入了 queue,旁证 queue 门槛同样不含它)。
已做的车道侧补救(不依赖本单结论)
check:engine-double-contract挂在 #5584 刚落地的action-execution-calldata-not-found.test.ts(2 个 double 未接assertEngineDeleteDispatch,基线无条目)——所有新 PR 的 ESLint job 都过不去 #5604 的全仓红;needs-user-decision:required 集的核查与修改只有维护者能做。关联:#5604、#5584、#5615、#5601。