Skip to content

chore(claude): allow-list the two landing REST calls in settings.json - #19047

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-19014-settings-allow-landing-calls
Sep 18, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
claude/issue-19014-settings-allow-landing-calls

Conversation

@hotlong

@hotlong hotlong commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Fixes #19014

Clause-②: no

skip-changeset — .claude/settings.json is not published source of any released package and moves no published contract field, so this PR declares no release of its own.

What this lands

Two permissions.allow rules in .claude/settings.json, appended as the last entries of the array, in the spelling its existing rules use and matching the command spelling the seats type for the landing act:

Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectstack/pulls/*/ccr/ready_for_review *)
Bash(curl -sS -X PUT https://api.github.com/repos/objectstack-ai/objectstack/pulls/*/ccr/auto_merge *)

Nothing else in the file moves: permissions.allow 47 → 49, permissions.deny 17 → 17, key order unchanged, three insertions and one deletion (the anchor line gains its trailing comma).

Why

Every REST write a seat makes through curl was already allow-listed by shape — POST …/issues/*/labels, PATCH …/pulls/*, the reads — except the two calls the landing act is made of. No allow rule matched a POST or a PUT on …/pulls/* at all, so both fell through to the harness's auto-mode classifier, which #18469 measured as non-deterministic and which denied them repeatedly. The visible cost the card records: seven ACCEPTED, green, non-governed PRs sat in draft for hours until a human landed by hand what the rules say no human needs to look at.

⛔ What this is not

Not a widening of who may land. The act stays behind the seat's own pre-checks — record on head, --pair 0, checks green, the path face NOT governed, and the size face of #19012 — and behind Prime Directive #14 for any diff touching a governed surface. These two rules only stop the harness from second-guessing a call the repository has already decided is the seat's.

The structural pin the card asked about — measured, and there is none

The card asked for "the self-test / structural pin the settings file already has for its rule set, if one exists (measure: grep the tree for a test that reads permissions.allow)". Measured on this branch:

  • scripts/pm/check-settings-deny-roster.mjs pins permissions.deny equal to CONTENT_WRITE_TOOLS and states under its own "What is deliberately NOT asserted" heading that it does not assert that allow and deny agree. It reads the allow list only in one self-test fixture, to prove that a document with no deny key reads as absent rather than malformed.
  • A sweep of scripts/, .github/ and .claude/ for any other reader of permissions.allow returns none.

So no pin exists to extend, and the two added rules move no gate except JSON validity — which every reader of the file needs, and which is asserted below.

Gates

node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack .claude/settings.json on this branch derives 15 commands. All 15 ran; 15 pass.

One finding was printed and is not this diff's: check-agent-test-spelling flags a line in .claude/settings.local.json, a file that is untracked here and ignored by the global ignore file, so it exists on one workstation and never reaches CI. Nothing in this PR touches it.

JSON validity is asserted directly: the file parses, and the parsed document reports 49 allow members and 17 deny members with the two new rules last.

Landing

.claude/** is a governed surface (Prime Directive #14), so this PR is left in draft and awaits the maintainer's word. ⛔ No seat flips it ready, queues it, arms auto-merge on it, or approves it.


Generated by Claude Code

The repository's committed `.claude/settings.json` allow-listed every REST
write a seat makes through `curl` — labels, `PATCH .../pulls/*`, the reads —
except the two calls the landing act is made of. No `allow` rule matched a
`POST` or a `PUT` on `.../pulls/*` at all, so both fell through to the
harness's auto-mode classifier and were denied non-deterministically: green,
accepted, non-governed pull requests sat in draft for hours until a human
landed by hand what the rules say no human needs to look at.

Two rules, in the spelling the file's existing rules use:

    Bash(curl -sS -X POST .../objectstack/pulls/*/ccr/ready_for_review *)
    Bash(curl -sS -X PUT .../objectstack/pulls/*/ccr/auto_merge *)

Measured on this tree: `permissions.allow` 47 -> 49, `permissions.deny`
17 -> 17, key order unchanged, the file still parses.

⛔ Not a widening of who may land. The act stays behind the seat's own
pre-checks — record on head, `--pair` 0, checks green, the path face not
governed, the size face — and behind Prime Directive #14 for any diff that
touches a governed surface. These rules only stop the harness from
second-guessing a call the repository has already decided is the seat's.

No gate reads `permissions.allow`: `scripts/pm/check-settings-deny-roster.mjs`
pins `permissions.deny` against CONTENT_WRITE_TOOLS and states in its own
header that it does not assert that allow and deny agree; a sweep of
`scripts/`, `.github/` and `.claude/` finds no other reader. So the two added
rules move no gate except JSON validity.

Co-authored-by: Claude <noreply@anthropic.com>
@os-zhuang
os-zhuang marked this pull request as ready for review September 18, 2026 14:20
@os-zhuang
os-zhuang merged commit 67624b7 into main Sep 18, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-19014-settings-allow-landing-calls branch September 18, 2026 14:20
os-zhuang added a commit to objectstack-ai/objectui that referenced this pull request Sep 18, 2026
… (objectui#9862) (#9900)

Fixes #9862

## What this lands

Two `permissions.allow` rules in `.claude/settings.json`, appended as
the last entries of the array, in the spelling the framework
repository's rules use and matching the command spelling the seats type
for the landing act:

```text
Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectui/pulls/*/ccr/ready_for_review *)
Bash(curl -sS -X PUT https://api.github.com/repos/objectstack-ai/objectui/pulls/*/ccr/auto_merge *)
```

Nothing else in the file moves: `permissions.allow` 10 → 12,
`permissions.deny` 14 → 14, key order unchanged, three insertions and
one deletion (the anchor line gains its trailing comma).

## Why

Measured on the base of this branch: no `allow` rule matched a `POST` or
a `PUT` on `…/pulls/*`, and none named `ccr/`. So `POST
…/pulls/{n}/ccr/ready_for_review` and `PUT …/pulls/{n}/ccr/auto_merge`
fell through to the harness's auto-mode classifier, which
objectstack#18469 measured as non-deterministic on byte-identical calls,
and which denies them today. The cost is the one seat 3 recorded in
objectui#9800: ACCEPTED, green pull requests that no seat can land.

This is the twin of objectstack#19014; the framework-side pair is in
objectstack-ai/objectstack#19047.

## ⛔ What this is not

Not a widening of who may land. The act stays behind the seat's own
pre-checks — record on head, `--pair` 0, checks green, the path face not
governed — and behind the governed-surface rule for any diff that
touches one. These two rules only stop the harness from second-guessing
a call the repository has already decided is the seat's.

## Measurements

- **No gate reads either list.** A sweep of `scripts/` and `.github/`
for `permissions.allow` or `permissions.deny` returns no reader, so the
two added rules move no gate except JSON validity.
- **JSON validity, asserted directly.** The file parses, and the parsed
document reports 12 allow members and 14 deny members with the two new
rules last.
- **No changeset is owed, and that is measured rather than asserted.**
`node scripts/check-changeset-presence.mjs` on this branch: "1 file(s)
changed, 0 of them published source of a package the release covers, 0
of them a manifest whose published contract moved … so no changeset is
owed."

## Landing

`.claude/**` is a governed surface, so this pull request is left in
draft and awaits one authorized APPROVED review. ⛔ Until it appears no
seat flips it ready, joins the merge queue, arms auto-merge, or merges
it — and ⛔ no seat submits that approval itself, under any account.

---
_Generated by [Claude Code](https://claude.ai/code)_

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: os-zhuang <jack@objectstack.ai>
os-project-manager added a commit that referenced this pull request Sep 21, 2026
…ings.json

The objectui spellings of the two landing-endpoint allow rules that already
exist for objectstack since #19047. Written by the director seat itself under
the maintainer's explicit per-PR authorization, verbatim: 「19362 你可以直接开发,不派dev」
— the one charter exception to 「PM 永不写代码」 (a `.claude/` internal-tooling
PR with the authorization quoted; reviewed and merged by the maintainer, never
self-merged). Every dev-seat attempt to edit this file was refused by the
session classifier (Self-Modification, 4 refusals on 2 cards); `deny` is
untouched. The card relation is declared in the PR body.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012GcsUbuqFGBibkEDMRC1eE
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Sep 28, 2026
…ings.json (ruling objectstack-ai#204-4 A) (objectstack-ai#19484)

Fixes objectstack-ai#19362

Clause-②: no

## Ruling and authorization, verbatim

Batch objectstack-ai#204 item 4, letter A (maintainer 「204 同意」; record 5754492446 on
objectstack-ai#19362): the two landing endpoints are allow-listed by name for
objectui, as they already are for objectstack since objectstack-ai#19047. Written by
the director seat itself under the maintainer's explicit per-PR
authorization in chat (2026-09-21): 「19362 你可以直接开发,不派dev」 — the one
charter exception to 「PM 永不写代码」 (a `.claude/` internal-tooling PR with
the authorization quoted). Per that exception the PR is ⛔ not
self-reviewed and ⛔ not self-merged: the maintainer's own read and
hand-merge is the review (Tier S by the register, `.claude/**`).

## What lands

Two `permissions.allow` entries in `.claude/settings.json`, placed right
after their objectstack twins:

```
Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectui/pulls/*/ccr/ready_for_review *)
Bash(curl -sS -X PUT https://api.github.com/repos/objectstack-ai/objectui/pulls/*/ccr/auto_merge *)
```

`deny` is byte-identical; key order and formatting unchanged; the file
parses (55 allow entries, 2 matching `objectui/pulls/*/ccr`). Nothing
else changes: an APPROVED review stays forbidden for every seat account,
governed surfaces stay the maintainer's, the queue still runs every gate
— these two calls only take a reviewed non-governed objectui PR out of
draft and hand it to the queue.

## Why the seat wrote it

Two dev rounds (this card's and PR objectstack-ai#19479's) were refused by the session
permission classifier on every edit to this file (`[Self-Modification]`,
four refusals), so the dev lane is not a channel for it; the maintainer
authorized the seat to write the two lines directly. `Check Changeset`
needs `skip-changeset` (no package touched) — applied by the seat.

## Verification

`node -e 'JSON.parse(...)'` exit 0 · `node
scripts/pm/check-settings-deny-roster.mjs` exit 0 (17 content-write
tools declared = enforced, unchanged) · the diff is exactly +2 lines.

---
_Generated by [Claude
Code](https://claude.ai/code/session_012GcsUbuqFGBibkEDMRC1eE)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xs skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants