本贴是 domain:devx 座位的唯一权威登记。 座位贴协议(维护者 2026-08-06 批准):索引 = label:pm:seat,总入口 #4604 。
单写手规则 :只有在任座位 PM 编辑本贴正文;接管/移交 = 改正文 + 一条审计评论。空缺争用时:动手前重拉正文、审计评论时间戳先到先得、写后回读。活性判定(惰性,无心跳):超过 24h 无产出即可回收。
🟢 座位状态:在任
os-project-manager · session session_011RB4waLuNbdruCo6X9oobm · 接管 2026-08-15T15:10:33Z ,现值 2026-08-16T09:18:21Z (均 date -u 实读)。接管审计 5302843013。
⚠️ 本次接管不是惰性回收,⛔ 不得当回收先例引用 (依据是维护者明示指令,只对这一次成立)。⚠️ 归属判据恒为认领评论的 session ID ,不是 assignee。
并发上限 5 · 云卡片已获准 · 优先序:bug · v17 · 影响别人 (均维护者 2026-08-16)。
发布页作用域:只负责 v16 及以后 ,v14 及更早不管(维护者 2026-08-16)。
⛔ 平台注入的分支指令(claude/pm-dispatch-devx-d3pjau)不予采纳,派发契约优先。 把每卡工作灌进一条共享分支,与 Prime Directive #11 (每任务独立 worktree)正面冲突,理由完全相同:多 agent 并行会互相覆盖。#9050 的 dev 主动挂出该冲突并按契约做,本席确认。实证 :本席今日实测共享主 checkout 落后 origin/main 81 个提交 ,两个当日落地的门禁脚本在其工作树里根本不存在。
当前台账(2026-08-16T09:18:21Z )
dev 在跑 1 :#9034 · 队列 0 · 等人工合并 3 :#9057 (#9024 )· #9069 (#8531 -D)· #9079 (#9050 )
⛔ 三张均为 docs/adr/** 或 skills/**,不 merge / 不入队 / 不挂 auto-merge ;其 ADR maintainer approval 红是设计如此 (gate 读 PR review,座位无 token),已在 PR 上说明红因并声明不修。⚠️ 均已标 ready-for-review —— 「不 merge」≠「留在 draft」,草稿状态下人类按不了合并按钮。
被同文件锁压着 :#9058 (等 #9057 ,ADR-0076 同文件;人工闸口,可能压很久)
待分诊分级 :#9072 · #9075 · #9078 · #9080 · #9083 · #9084 · #9086 · #9089
本任期落地 42 张 —— 全部按 origin/main 内容 核,total_count 均恰为 1
**零 REWORK。**一次补丁轮(#7529 )。一次队列回归并修复(#8913 ,详见 pitfalls)。
本任期以「测量即记录」关闭 2 张
[finding] Proposal from #8711 half-2: a declaration-side ratchet (ADR-0049 class) — enumerate declared security keys, not primitives #8894 — 裁定「只测量不设门禁」,走分叉支 :枚举可机械化,读取判定不可 。判据是消融——移除真值键的全部真实读者后 oracle 仍打 5 分 ⇒ 它会在 sys_permission_set.active 整个失效期里保持绿色 ,4 漏 2 且漏的正是立卡依据的两个;动作散文半 40% 精确率并在 deactivate_capability 上反向 (那条恰是 sys_capability.active is read by nothing — the Deactivate action tells the admin grants stop resolving, and they do not #8535 专门改写来撤回假承诺的)。复核 5306352213。溢出的治理问题另立 [Decision] ADR-0049's declaration surface has two halves and only one is governed — platform-object row columns on security objects have no liveness ledger, and both #8894 ground-truth instances live there #9054 (needs-user-decision)。
Guard that named verification scripts actually exist in the filtered packages — a zero-match pnpm --filter run exits 0 and reads as a pass #8973 — ⭐ 前提被证伪而关闭 (not_planned)。正文被尖括号消毒器截断整任期,本席解围栏派它「重建规格或拒绝」,它拒绝了,并在拒绝中推翻了卡片的核心机制 :pnpm@10.31.0 下脚本缺失时 --filter 退出 1 不是 0 (九种拼法全测);finding(skills): a pnpm --filter run matching ZERO scripts exits 0 — a vacuous no-op reads as a pass in dev verification reports #8727 记的 exit-0 是那条命令带 | tail —— $? 是 tail 的 0,PIPESTATUS[0] 才是 1,正是 PR docs(agents): repo-conditional skip-changeset, vacuous-pass guard, publish-route preflight in the os-dev contract #8969 已在契约侧修掉的陷阱 。真正活着的空转通过是选择器匹配零个包 (No projects matched the filters,EXIT=0)。后继卡 A pnpm --filter selector that matches ZERO PACKAGES prints "No projects matched the filters" and exits 0 — the one vacuous pass that survives, successor to #8973's retired premise #9089 ,语料已在卡上枚举论证。复核 5306641295。
需先处置,⛔ 不可直接派
#7804's GlobalFilterSchema.object is unreachable in the Studio designer, and no console pin bump can fix it — the console vendors the PUBLISHED @objectstack/spec, which the key postdates #8134 — needs-user-decision。⭐ 实例半已随 v17 GA 在源头解决(npm pack @objectstack/spec@17.0.0 读 .d.ts,spec: GlobalFilterSchema needs an optional object — a dashboard global filter's field label (and its option labels) have no bundle key to resolve against #7804 的 object 键就在 field 与 label 之间 );objectui 21 处区间 ^17.0.0-rc.6 semver 上本就覆盖 17.0.0 ,钉死它的只有 lockfile ⇒ 链条三步缩成两步且无需改区间 ,交 v17 GA follow-through: objectui's lockfile still resolves @objectstack/spec@17.0.0-rc.6, so the console keeps vendoring a pre-GA spec and #7804's key stays unreachable #8893 。通用半原封不动,建议方向 1。分析 5306281629。
A controlled_by_parent object may declare its master reference without required, so the master-access guard is the only thing preventing an unreachable orphan detail row #8772 — ⚠️ 两份互相冲突的裁定 :08-15 裁方向 1 且说方向 2「没必要」;08-16 改判为方向 2 现在 + 方向 1 推 v18 + 方向 4 立刻 。**后者生效。**三片落三条车道,本席只占方向 1 且被闸在 v18 。⭐ 缺口:方向 4(guard 冻结注记,唯一带「立刻」、且是坡道期保护 A missing required master-detail parent still answers 422 MISSING_REQUIRED_FIELD with no fields[] and a [Security] message — while the same field, present-but-unresolvable, answers 400 VALIDATION_FAILED with fields[] (#7474 residual, 17.0.0 GA) #8688 的东西)归 domain:identity,而本卡按分诊原则无 domain:* ⇒ 没有任何车道的队列会返回它 。处置 5306343185。
The pre-repo ADR-0081 label survives in 37 more citations across three unrelated claims — same collision #8474 fixed for the active-org stamp only #8531 — 论断 D 已交付(docs(adr): anchor the multi-org entitlement to ADR-0105 D12 (#8531 claim D) #9069 ,等人工)。⚠️ 本席先前对 B/C 的路线判断已降级为「有条件」 :[finding] The repo never resolved whether the pre-repo ADR-0081 is cloud ADR-0081 — and ADR-0105 cites both spellings in one document #9072 显示 ADR-0105 同一份文档 里 :5 用带限定的 cloud ADR-0081、:334/:348 用不带限定的 —— 若是同一份记录,B/C 就不是幻影锚点而是欠限定的跨仓引用 ,一次机械 sweep 即可,不需要新立记录。判定需读 objectstack-ai/cloud,dev 与本席 add_repo 均无权限 ⇒ ⛔ 两边都不认定(在读不到的情况下断言两份记录相同,正是制造这 37 处缺陷的那个动作)。更正 5306495803。⚠️ 已实测:37 处里没有第四个论断 ;余 22 处分为 B(12)、C(7)、ADR-0093 内部 3 处刻意的历史引用(正确用法,⛔ sweep 不得扫掉) 。
v17 GA follow-through: objectui's lockfile still resolves @objectstack/spec@17.0.0-rc.6, so the console keeps vendoring a pre-GA spec and #7804's key stays unreachable #8893 — target:v17,仍锁。上游 objectui#4648 已裁定转 pm:queue,但适配卡 objectui#4649/authorable-surface 的 tombstone 门禁可被手编基线绕过 —— 删掉基线行就删掉了证据(#4638 / #4643 已两次这样过绿) #4650 与 pin bump PR objectui#4639 未落地。「阻塞源的标签变了」≠「阻塞解除了」。
[finding] ADR-0002's "already discarded in v3.4's ADR-0001" points at a document this repo never contained — the number it cites held an unrelated decision #7963 · #6162's anchor-body half never took: #5810's Routine prompt clause 6 still carries the pre-#6162 hint-comment-only wording #7276 — 落 docs/adr/** / 非 PR 形状。
本任期新立卡
#8893 · #8895 · #8896 · #8897 · #8900✅ · #8901 · #8903✅ · #8916 · #8917✅ · #8943✅ · #8946✅ · #8949 · #8967✅ · #8975 · #8982✅ · #8999 · #9054 · #9089
dev 派生 :#8959✅ · #8961✅ · #8965✅ · #8966 · #8975 · #8984 · #8995✅ · #9007✅ · #9014✅ · #9017 · #9018✅ · #9022 · #9034▶ · #9035✅ · #9046 · #9050⏳ · #9053✅ · #9055✅ · #9058 · #9064 · #9072 · #9075 · #9078 · #9080 · #9083 · #9084 · #9086
(✅ 已落地 · ⏳ 等人工 · ▶ dev 在跑)
⚠️ dev 自立卡是本任期后半段的主要补给源 —— 归属条款(⛔「测到了报给我我来立」不合法)一旦守住,流水线自己产出工作。当前限速器是分诊吞吐 ,不是并发。
范围
packages/lint · packages/sdui-parser(仅 lint 消费)· content/docs/** · apps/docs · scripts/(门禁类)· .github/workflows/(门禁接线)· .githooks/ · examples/** 测试基建面 · docker/README.md
热文件串行队
文件
状态
备注
content/docs/deployment/validating-metadata.mdx
#9034 在跑
⚠️ 今日被 #9033 、#9077 连改两次 ⇒ 锁保护并发写,保护不了行号引用
docs/adr/0076-*
#9057 等人工
#9058 排其后;人工闸口 ⇒ 压期不可预测
docs/adr/0105-* 等
#9069 等人工
论断 B/C ⛔ 不动
content/docs/{protocol/objectui/actions,ui/forms}.mdx · skills/objectstack-ui/SKILL.md
#9079 等人工
⚠️ forms.mdx 留着 2026-08-11 那条重定向 token 注记(属 objectui#4190),⛔ 别顺手删
lint.yml · 根 package.json
空(#9036 · #9065 已合)
✅ 新门禁接 ESLint job (判据:check-required-contexts.mjs 的 carries 字段)
apps/docs/redirects.mjs · docker/README.md
空(#9036 · #9065 已合)
✅ 两处历史盲区均已闭
content/docs/releases/**
空(#9039 · #9081 已合)
⛔ release-owned;两条通道 :完整性缺口需逐卡批准(#8917 ,⛔ 不构成先例);事实错误 可走专用 docs-only PR(#9035 走的这条)
packages/lint/src/{data-model-rules,validate-security-posture.test}.ts
⚠️ #8772 方向 1,闸在 v18
⛔ 在那之前不得改 severity、不得退 :434 的 pin
常设承诺
说明
接手指引 :/pm-dispatch devx → 读正文 → 读晚于正文最后编辑的评论 → 自己重扫车道标签 。
Key pitfalls(累积):
⛔⭐⭐⭐ 卡片正文冻结在立卡那一刻,而本仓刻意把 Blocked-by:、状态更正、维护者裁定放在评论里 ⇒ 只读正文,系统性地读到「决策之前的世界」。 实证 A type: 'form' action leaves the console shell for a bare /forms/:name page and ends on a generic "Thanks!" panel instead of the created record (observation) #7245 :本席读完正文判「三方向未定、不可派」,而维护者六天前就裁了 ,两个半边已落地,剩两行清理。⇒ 对任何超过一天的卡,正文是页面上最不当前的东西。
⛔⭐⭐⭐ 量具在共享 checkout 上会静默产生假警报,本席今日两次,两次都差点去指控刚核过是好的 PR。 ①dispatch-gates.mjs 读工作树不读 ref ,而共享主 checkout 落后 81 个提交 、新门禁脚本根本不存在 ⇒ 它诚实地报 96 族零命中,我差点据此立「盲区未闭」的假回归卡。②**FETCH_HEAD 也是共享的**,被另一 agent 的 fetch 在我两条命令之间冲掉,整个文件显示成新增,我差点判 docs(protocol): narrow realtime-protocol.mdx's "enforces this in CI" claim to what the tripwires check #9082 「没改到点子上」。⇒ 判据分两类且不可混用同一目录:读内容用 git show origin/main:;跑脚本必须在自己的 worktree;复核 diff 一律用具名 ref(git fetch origin <br>:refs/pmcheck/<n>),⛔ 不用 FETCH_HEAD。
⛔⭐⭐⭐ list_issues 多标签是 OR([finding] The GitHub MCP list_issues multi-label filter is OR (union), not AND — a two-label query returns every issue carrying either label #8942 ),而且会分页截断 —— 两个坑同日各踩一次。 我在被截断的 30 条里做交集,报出「队列见底」;真实 domain:devx 开放卡 36 张、带 pm:queue 的 13 张,6 张未见 。⇒ 单标签查询 + 客户端取交集 + perPage 给足;⛔ 永不把返回列表当车道队列。
⛔⭐⭐ PM 给 dev 的清单本任期错了四次,每次都靠「⛔ 自己重新推导」兜住 (packages/cli and packages/lint have no declared input radius for examples/**, so their four live-importing tests still never run on an examples-only PR #8946 平表 / check-cross-package-test-inputs --union-into re-walks the whole repo once per matching declaration #8900 声明数 / Three packages/cli tests read content/docs/deployment/*.mdx with a seed spelling check:cross-package-test-inputs does not recognise, so the reads are undeclared and the gate stays green #8995 路径数 / docs(deployment): the CLI reference has no entry for os package publish or os package install — the two commands that move an app onto a platform #8965 整份是另一命令的 flag)。⇒ 凡派发词给出实测值,必须同时给出「自己重测」的指令。
⛔⭐⭐ 量具默认编码了你对「东西长什么样」的假设 :MEASURED 全文计数 vs 条目内 · allowWrites 文件数 vs 真实声明 · IMPLICIT_FIELDS 正则漏类型标注 · 未加 scope 的键 · git diff --stat 会把路径缩写成 .../(我据此以为 fix(lint): a dashboard header modal action's target resolves against declared pages, only (#9013) #9077 开了新文件族) · grep -c 数的是行不是次 。⇒ 按位置查,不按次数查;显示层产物不是数据。
⛔⭐⭐ 门禁的自述必须为真,否则它守的是读者的错觉。 Guard that named verification scripts actually exist in the filtered packages — a zero-match pnpm --filter run exits 0 and reads as a pass #8973 实证:照标题建那道门禁,其理由(「pnpm 退出 0」)是假的 —— 一道理由为假的门禁比没有门禁更坏 ,因为下一个读者会相信它,以为某个风险已被覆盖。这是「绿 ≠ 门禁在看你关心的东西」的另一面,指向散文而非退出码。
⛔⭐⭐ 先例给的是「怎么想」,不是「怎么改」。 ①docs(deployment): self-hosting's OS_DATABASE_URL guidance omits mysql:// — the one page a production deployer reads never offers a now-supported target #9053 的 dev 用被改页面自己的惯例(每目标只写一个规范 scheme,从不列别名)否掉本席提的 mysql2://;②ADR-0076 D11 needs its ruled revision: the rest-server half is delineated-not-split, and the ADR still records it as an unmet obligation #9024 的 dev 拒绝把已退役 的 LOC 序列刷新进正在记录其退役的那一行;③⚠️ 计数在散文里 vs 在 transcript 里是两回事 —— 散文里的计数是作者断言,说不清可省略(docs(deployment): put widget-binding integrity on the runtime publish door #9005 / authorization.mdx tells customers "a declared-but-unenforced primitive fails the build" — measured, that holds only for a curated 15-probe table, and 43 of 50 matrix rows sit outside it #9028 );transcript 里的计数是对程序输出的复现,省掉就是伪造一段 CLI 永不打印的输出 (docs: the sample os validate transcript on validating-metadata.mdx prints a stale author-time rule count (38 shown, registry holds more) #9034 的派发分叉)。
⛔⭐ 「阻塞源的标签变了」≠「阻塞解除了」 (v17 GA follow-through: objectui's lockfile still resolves @objectstack/spec@17.0.0-rc.6, so the console keeps vendoring a pre-GA spec and #7804's key stays unreachable #8893 )。⇒ 解锁判据只能是 merged_at 或等价完成事实(validate-dashboard-action-refs 的 resolveActionTarget 仍接受 modal 裸对象名与 verb_object —— 其镜像依据(objectui DashboardView 运行时)已被 PR objectui#4782 删除,规则方向反转 #9013 即如此解锁)。
⛔⭐ 同文件锁保护并发写,保护不了行号引用 :docs(deployment): reconcile the four-doors table with AUTHORING_RULES #9033 落地解开 validate-dashboard-action-refs 的 resolveActionTarget 仍接受 modal 裸对象名与 verb_object —— 其镜像依据(objectui DashboardView 运行时)已被 PR objectui#4782 删除,规则方向反转 #9013 的锁,同时把它的目标行 83 → 95。⇒ 解锁那一刻正是行号最不可信的时刻。
⛔⭐ 合并提交标题可能不带卡号 (fix(devx): cap the docs-drift-check PR comment above 15 editable rows #9048 、docs(releases): correct the 16.0.0-rc.1 Console pin in v16.mdx to 69fa5d163a97 #9081 各一次)。⇒ 判据是 origin/main 上的内容 ,收官查 total_count 恰为 1。
⛔⭐ 「以为写成功」≠「观察到写成功」 :docs(adr): anchor the multi-org entitlement to ADR-0105 D12 (#8531 claim D) #9069 的 PR 正文写着 skip-changeset applied,而标签根本没打上,Check Changeset 转红。⇒ 写完必须读回 ;skipped 不清除同一必需上下文上更早的 failure,PM 侧补救只有 update_pull_request_branch,⛔ 永不 rerun_failed_jobs。
⛔⭐ 合并队列的 committer date ≠ 合并时刻 (chore(devx): lower @objectstack/lint TEST_DEBT to its measured 19 and re-tally its note (#8728) #8980 差 23 分钟)。⚠️ 全绿却未合并通常只是排在别人后面 (ci(docs): gate that docs image tags track packages/cli's version (#9018) #9065 实证),⛔ 不得据此动手。
⛔⭐ 同批次连带 ≠ flaky (docs(deployment): rewrite the section index around the two lifecycles and re-order meta.json (#8913) #8983 连带打红 test(engine-double-contract): pin the 29 baseline entries #8639 first-measured #8987 /test(lint): pin the four unprovisionedAnchors threading sites that the lint suite could not see #8989 )。⇒ 要问「同名测试在别处为何出现」。
⛔⭐ skip-changeset 反射有真例外 (fix(lint): three write rules ask anchor provenance before exempting a system column #8996 、validate-dashboard-action-refs 的 resolveActionTarget 仍接受 modal 裸对象名与 verb_object —— 其镜像依据(objectui DashboardView 运行时)已被 PR objectui#4782 删除,规则方向反转 #9013 )。⇒ 判据是 diff,不是习惯。
⛔⭐ 不要用一个错数字替换另一个错数字。 authorization.mdx tells customers "a declared-but-unenforced primitive fails the build" — measured, that holds only for a curated 15-probe table, and 43 of 50 matrix rows sit outside it #9028 最完整::257 的 ~18 查不出当初数的什么 ⇒ 省略而非替换 ,并给出查不出的原因(本地浅克隆 grafted,blame 假指),改走 API 沿真实历史回到 07-04,发现它在每个可达修订上都已对不上 且不匹配任何其他分组。
⛔⭐ 数字对不上时,先证明「是东西变了」还是「是方法不一致」。 ADR-0076 D11 needs its ruled revision: the rest-server half is delineated-not-split, and the ADR still records it as an unmet obligation #9024 把同一分类器拿回裁定当时的树重跑,逐字复现 6,008/5,400 ,再把差额归到 Extract rest-server.ts's error/fault-classification prologue — it is ADR-0112's concern, not the REST server's #8850 移走 1,296 行。⇒ 说不清就明说,说得清就证明给我看。
⛔⭐ 门禁跑绿 ≠ 门禁在看你关心的东西 ⇒ 唯一分辨方法是故意复现伤害 。⭐ 推论:被修干净的语料会让门禁失去唯一的活反例 —— fix(docs): three redirect destinations point at pages that do not exist #9015 修完三条死重定向后 ci(docs): nothing verifies apps/docs/redirects.mjs destinations resolve — the table can rot with CI fully green #9014 无法靠实跑自证(它交出真实 red→green + chain 肢首次对真实数据开火 + 48 条断言自检,干净表断言零发现 );Add a mechanical guard: docs image tags should track packages/cli's version #9018 同处境,加了 NO-OCCURRENCES 反空转肢(某个面读不出具体 pin 就判失败 ),⇒ 枚举不能悄悄退化成 no-op。
⛔⭐ 反向验证不是仪式,认真做会长出发现。 realtime-protocol.mdx says the authz conformance matrix "enforces this in CI" for per-recipient realtime authorization — the tripwires force classification, they cannot check the re-check exists #9055 两条腿:腿 1 证明该有的性质真会开火;腿 2 让 transport 接着、零授权,只手工把 tripwire key 追加进 experimental 行的 covers,15 passed 全绿 ⇒ 强制站点从来不是必需的(authz matrix: a wired realtime transport can be classified by the experimental row itself — the ledger never requires the enforcement site the tripwire note promises #9083 );外加 tripwire 只匹配 /realtime 字面量,对同页记载的 /ws 与 /api/v1/stream 根本不会开火 (authz matrix: the rest-server.ts realtime tripwire matches only a /realtime literal — it cannot fire for /ws or /api/v1/stream, the two transports the protocol page documents #9084 )。
⛔⭐ 消融覆盖率要诚实报 (finding: two IMPLICIT_FIELDS sets spread the blanket SYSTEM_FIELDS union with no provenance awareness — candidate sixth/seventh unprovisioned-anchor read sites #8663 :14 条新测试只有 4 条是消融证明的)。⚠️ 模板有字段不等于该填 —— Docs spell the internal form-action mount /console/forms/:name, but the same page's own example targets use /_console/ #9050 明说「散文/路径 sweep 无运行时行为可变异,填消融字段会是捏造」。
⛔⭐ 卡片自述的文件面/前提可以是假的 (本任期八例,最重的是 Guard that named verification scripts actually exist in the filtered packages — a zero-match pnpm --filter run exits 0 and reads as a pass #8973 的核心机制 被证伪、docs(releases): v16.mdx names af1b0db as the 16.0.0-rc.1 Console pin, but rc.1 ended at 69fa5d163a97 — two further pin moves, and objectui#2743 is documented nowhere #9035 的「17 处」与其自身枚举清单 15 条不一致)。「卡片说 X」是线索,不是发现。
⛔⭐ 一张卡列了 N 条原因而 PR 只修 M 条时,必须自己核剩下的为何不做并写在卡上 (registry-canary structurally cannot catch remote-template breakage — it scaffolds only blank and never runs npm run build; it was green over the #7644 defect #8678 )。
⛔⭐ get_status 不是门禁读数 (只聚合 Vercel);判据是 get_check_runs 的逐 job conclusion。
⛔⭐ 发版事件会整族地静默失效卡的前提 (v17 GA 翻掉 #7804's GlobalFilterSchema.object is unreachable in the Studio designer, and no console pin bump can fix it — the console vendors the PUBLISHED @objectstack/spec, which the key postdates #8134 的中心论断)。⚠️ 且可能让盲区更危险 :名实归位后,「同版本号下工作区已远超 tarball」这个唯一外显异味消失了。
⛔⭐ 问题问错层级,证据会「确认」一个假结论 ([finding] check-durability-degradation-log-level guards packages/** source but its lint.yml path filter lists only its own script — so no derivation can name it for a source change #8889 )。⛔⭐ 锚定行号要核所属函数/章节 (docs(deployment): put widget-binding integrity on the runtime publish door #9005 )。
⛔ 写 labels 用 read-then-union,⛔ 不盲写整集 (与 Auto Label 抢跑会冲掉 size/*)。
⛔ 先立卡、后引用 ;⛔ 裸 issue 号跨仓不唯一 。
⛔ 已发出的定时器文本会带着过期结论回来找你 ⇒ 每枪以「幂等,先重读」开头,只写判据不写结论 ;本任期三枪的清单在开火时均已整份过期。
⛔ 新进入 shrink-only 基线的条目是「首次测量」,不是「抬高的棘轮」 ;⛔ 不许给已消失的错误编造构成;⛔ 不许把归因编出来 。
⚠️ GitHub MCP 读回的 issue 正文可能被截断 (尖括号占位符被当 HTML 吞掉,[finding] GitHub MCP issue reads return HTML-escaped bodies, so any seat that appends a line by rewriting a card body may store ' literals into its code blocks #8813 )。⭐ 但「读不全的卡不能派」不是终局判决 —— 若规格的证据 存在于可读的一手来源,正确做法是把「重建规格」定为第一步并给它一个拒绝的出口 (Guard that named verification scripts actually exist in the filtered packages — a zero-match pnpm --filter run exits 0 and reads as a pass #8973 实证,而它正是靠那个出口证伪了前提)。⚠️ 「我拼出了一个说得通的规格」≠「我拼出了原来那个规格」。
⚠️ 凡写进记录的时刻必须来自 date -u 实读 。⚠️ AGENTS.md 正文不得带 issue 号 。
⚠️ 裁决字面可证伪,dev 证伪是好运行 —— 最有价值的一次是 ci(docs): nothing verifies apps/docs/redirects.mjs destinations resolve — the table can rot with CI fully green #9014 :卡片与分诊都推荐接进 TypeScript Type Check,dev 从仓库源码证伪(check-required-contexts.mjs 的 ESLint 条目 carries = 「the whole check:* gate family (25 steps)」)。该判据现已可引,后续门禁卡不必再各踩一遍 (Add a mechanical guard: docs image tags should track packages/cli's version #9018 直接沿用)。
⚠️ **复核只认成品,不认 PR 正文自述。**⚠️ 新 worktree 未 pnpm install 会产生 ERR_MODULE_NOT_FOUND 假红 (本任期三个 dev 各撞一次,均如实报出)。
⚠️ RECOGNISED_PATH_SPELLINGS 等公开常量印在失败文案并镜像进 AGENTS.md ⇒ 必须同批移动 (check:cross-package-test-inputs does not see a new URL(…, import.meta.url) seed, so an undeclared cross-package read passes green #8698 · Three packages/cli tests read content/docs/deployment/*.mdx with a seed spelling check:cross-package-test-inputs does not recognise, so the reads are undeclared and the gate stays green #8995 )。
迁移注记:「范围 / 常设承诺 / pitfalls」经 hotlong → os-zhuang → qq9340100 → os-zhuang → os-project-manager(本席)五任承接;台账与热文件队为本席 2026-08-16T09:18:21Z 现值。旧账留在 body revision 历史中。
本贴是
domain:devx座位的唯一权威登记。 座位贴协议(维护者 2026-08-06 批准):索引 =label:pm:seat,总入口 #4604。单写手规则:只有在任座位 PM 编辑本贴正文;接管/移交 = 改正文 + 一条审计评论。空缺争用时:动手前重拉正文、审计评论时间戳先到先得、写后回读。活性判定(惰性,无心跳):超过 24h 无产出即可回收。
🟢 座位状态:在任
os-project-manager · session
session_011RB4waLuNbdruCo6X9oobm· 接管 2026-08-15T15:10:33Z,现值 2026-08-16T09:18:21Z(均date -u实读)。接管审计5302843013。并发上限 5 · 云卡片已获准 · 优先序:bug · v17 · 影响别人(均维护者 2026-08-16)。
发布页作用域:只负责 v16 及以后,v14 及更早不管(维护者 2026-08-16)。
⛔ 平台注入的分支指令(
claude/pm-dispatch-devx-d3pjau)不予采纳,派发契约优先。 把每卡工作灌进一条共享分支,与 Prime Directive #11(每任务独立 worktree)正面冲突,理由完全相同:多 agent 并行会互相覆盖。#9050 的 dev 主动挂出该冲突并按契约做,本席确认。实证:本席今日实测共享主 checkout 落后origin/main81 个提交,两个当日落地的门禁脚本在其工作树里根本不存在。当前台账(2026-08-16T09:18:21Z)
dev 在跑 1:#9034 · 队列 0 · 等人工合并 3:#9057(#9024)· #9069(#8531-D)· #9079(#9050)⚠️ 均已标 ready-for-review —— 「不 merge」≠「留在 draft」,草稿状态下人类按不了合并按钮。
⛔ 三张均为
docs/adr/**或skills/**,不 merge / 不入队 / 不挂 auto-merge;其ADR maintainer approval红是设计如此(gate 读 PR review,座位无 token),已在 PR 上说明红因并声明不修。被同文件锁压着:#9058(等 #9057,ADR-0076 同文件;人工闸口,可能压很久)
待分诊分级:#9072 · #9075 · #9078 · #9080 · #9083 · #9084 · #9086 · #9089
本任期落地 42 张 —— 全部按
origin/main内容核,total_count均恰为 1check-durability-degradation-log-level.mjsRECOGNISED_PATH_SPELLINGS在门禁里index.mdx:22=(final release: 16.1.0)runtimeTypes: ['dashboard']·CONTEXT_STACK_KEYS含datasetsgrep -c 'is what would notice'→ 0SCOPE_FLOOR_MAJOR×8;0 处 releases 改动KNOWN_UNALIASED_TEST_IMPORTS在头部publish-and-preview.mdx223 行content/docs/upgrading.mdx+ 根meta.json14.8.0→ 0;锚点存活TEMPLATE_NAMESPACE×3;dist/objectstack.json断言DECLINED. Do not build it.在 ledger 里errors: 19;roster 改为「五个都已还清」[#8943]pin;源文件 blob 未变INVISIBLE_COUPLINGS = {}/docs/upgrading链接;NDJSON 三正则全绿*_UNPROVISIONED_ANCHOR导出escapingDirsMap 在循环外✓ᵈ;硬计数移除14.8.0→ 0,17.0.0×3os package publish×8 ·os package install×45xx标题与| 501 |行EXHIBIT STATUS段在;REPAIRED by #8895在;旧现在时断言 0✓ˢᵖᵉᵇᵒ与✓ᵈᵛᵒᵖᶠ各 1;无新硬计数check:docs-redirects条目 + lint.yml 步骤8ff9210标为 accept-set narrowingEDITABLE_ROW_CAP = 15;保留清单三项在;折叠 0 处~18 primitives省略而非替换check:docs-image-tag条目 + lint.yml;NO-OCCURRENCES反空转肢 ×11mysql://在OS_DATABASE_URL行;告诫从句与 #9052 逐字一致MODAL_VERB_RE→ 0;文档示例已改af1b0db→ 0;69fa5d163a97×5;区间修为#2701–#2743**零 REWORK。**一次补丁轮(#7529)。一次队列回归并修复(#8913,详见 pitfalls)。
本任期以「测量即记录」关闭 2 张
sys_permission_set.active整个失效期里保持绿色,4 漏 2 且漏的正是立卡依据的两个;动作散文半 40% 精确率并在deactivate_capability上反向(那条恰是sys_capability.activeis read by nothing — the Deactivate action tells the admin grants stop resolving, and they do not #8535 专门改写来撤回假承诺的)。复核5306352213。溢出的治理问题另立 [Decision] ADR-0049's declaration surface has two halves and only one is governed — platform-object row columns on security objects have no liveness ledger, and both #8894 ground-truth instances live there #9054(needs-user-decision)。pnpm --filterrun exits 0 and reads as a pass #8973 — ⭐ 前提被证伪而关闭(not_planned)。正文被尖括号消毒器截断整任期,本席解围栏派它「重建规格或拒绝」,它拒绝了,并在拒绝中推翻了卡片的核心机制:pnpm@10.31.0 下脚本缺失时--filter退出 1 不是 0(九种拼法全测);finding(skills): a pnpm --filter run matching ZERO scripts exits 0 — a vacuous no-op reads as a pass in dev verification reports #8727 记的 exit-0 是那条命令带| tail——$?是 tail 的 0,PIPESTATUS[0]才是 1,正是 PR docs(agents): repo-conditional skip-changeset, vacuous-pass guard, publish-route preflight in the os-dev contract #8969 已在契约侧修掉的陷阱。真正活着的空转通过是选择器匹配零个包(No projects matched the filters,EXIT=0)。后继卡 Apnpm --filterselector that matches ZERO PACKAGES prints "No projects matched the filters" and exits 0 — the one vacuous pass that survives, successor to #8973's retired premise #9089,语料已在卡上枚举论证。复核5306641295。需先处置,⛔ 不可直接派
GlobalFilterSchema.objectis unreachable in the Studio designer, and no console pin bump can fix it — the console vendors the PUBLISHED@objectstack/spec, which the key postdates #8134 —needs-user-decision。⭐ 实例半已随 v17 GA 在源头解决(npm pack @objectstack/spec@17.0.0读.d.ts,spec:GlobalFilterSchemaneeds an optionalobject— a dashboard global filter's field label (and its option labels) have no bundle key to resolve against #7804 的object键就在field与label之间);objectui 21 处区间^17.0.0-rc.6semver 上本就覆盖 17.0.0,钉死它的只有 lockfile ⇒ 链条三步缩成两步且无需改区间,交 v17 GA follow-through: objectui's lockfile still resolves@objectstack/spec@17.0.0-rc.6, so the console keeps vendoring a pre-GA spec and #7804's key stays unreachable #8893。通用半原封不动,建议方向 1。分析5306281629。controlled_by_parentobject may declare its master reference withoutrequired, so the master-access guard is the only thing preventing an unreachable orphan detail row #8772 —fields[]and a[Security]message — while the same field, present-but-unresolvable, answers 400 VALIDATION_FAILED withfields[](#7474 residual, 17.0.0 GA) #8688 的东西)归domain:identity,而本卡按分诊原则无domain:*⇒ 没有任何车道的队列会返回它。处置5306343185。ADR-0081label survives in 37 more citations across three unrelated claims — same collision #8474 fixed for the active-org stamp only #8531 — 论断 D 已交付(docs(adr): anchor the multi-org entitlement to ADR-0105 D12 (#8531 claim D) #9069,等人工)。ADR-0081iscloud ADR-0081— and ADR-0105 cites both spellings in one document #9072 显示 ADR-0105 同一份文档里:5用带限定的cloud ADR-0081、:334/:348用不带限定的 —— 若是同一份记录,B/C 就不是幻影锚点而是欠限定的跨仓引用,一次机械 sweep 即可,不需要新立记录。判定需读objectstack-ai/cloud,dev 与本席add_repo均无权限 ⇒ ⛔ 两边都不认定(在读不到的情况下断言两份记录相同,正是制造这 37 处缺陷的那个动作)。更正5306495803。@objectstack/spec@17.0.0-rc.6, so the console keeps vendoring a pre-GA spec and #7804's key stays unreachable #8893 —target:v17,仍锁。上游 objectui#4648 已裁定转pm:queue,但适配卡 objectui#4649/authorable-surface 的 tombstone 门禁可被手编基线绕过 —— 删掉基线行就删掉了证据(#4638 / #4643 已两次这样过绿) #4650 与 pin bump PR objectui#4639 未落地。「阻塞源的标签变了」≠「阻塞解除了」。docs/adr/**/ 非 PR 形状。本任期新立卡
#8893·#8895·#8896·#8897·#8900✅ ·#8901·#8903✅ ·#8916·#8917✅ ·#8943✅ ·#8946✅ ·#8949·#8967✅ ·#8975·#8982✅ ·#8999·#9054·#9089dev 派生:
#8959✅ ·#8961✅ ·#8965✅ ·#8966·#8975·#8984·#8995✅ ·#9007✅ ·#9014✅ ·#9017·#9018✅ ·#9022·#9034▶ ·#9035✅ ·#9046·#9050⏳ ·#9053✅ ·#9055✅ ·#9058·#9064·#9072·#9075·#9078·#9080·#9083·#9084·#9086(✅ 已落地 · ⏳ 等人工 · ▶ dev 在跑)
范围
packages/lint·packages/sdui-parser(仅 lint 消费)·content/docs/**·apps/docs·scripts/(门禁类)·.github/workflows/(门禁接线)·.githooks/·examples/**测试基建面 ·docker/README.mdscripts/下归本席 —— 判据是被改文件的路径。.claude/workflows/≠.claude/skills/(实证 docs: add upgrading.mdx stating both upgrade halves and linking the per-major checklists #8964)。domain:spec([PM seat] domain:spec-tooling — 🔀 merged into #6017 #6018)按 域标签词表有两个未入表条目:domain:spec-tooling(在用,文件面与 devx 完全重叠)与domain:ui(一例,与repo:objectui重复) #5469 切分(Complete the spec-lane merge: folddomain:spec-surface/domain:spec-toolinginto a singledomain:speclane in the SKILL.md domain table #9001/PR docs(pm-dispatch): complete the spec-lane merge — fold domain:spec-surface / domain:spec-tooling into a single domain:spec lane #9003 已合并 spec 两 lane)。domain:*判。 反向也成立:Docs spell the internal form-action mount/console/forms/:name, but the same page's own example targets use/_console/#9050 的一处落点在skills/([PM seat] skills — 🟢 os-warren (session_01AeA3nU1B5Q2pgxqxgUrexd) #7623 的面),卡仍是本席的,但由此产生的人工合并后果照单接受。热文件串行队
content/docs/deployment/validating-metadata.mdxdocs/adr/0076-*docs/adr/0105-*等content/docs/{protocol/objectui/actions,ui/forms}.mdx·skills/objectstack-ui/SKILL.mdforms.mdx留着 2026-08-11 那条重定向 token 注记(属 objectui#4190),⛔ 别顺手删lint.yml· 根package.jsonESLintjob(判据:check-required-contexts.mjs的carries字段)apps/docs/redirects.mjs·docker/README.mdcontent/docs/releases/**packages/lint/src/{data-model-rules,validate-security-posture.test}.ts:434的 pin常设承诺
docs/adr/**与.claude/skills/**/skills/**的 PR 不得 AI merge / 入队 / auto-merge(⛔ Discipline: ADRs are confirmed and merged by the maintainer only — no AI seat may merge, queue, or auto-merge adocs/adr/**PR #6741 / pm-dispatch SKILL: skills updates are ADR-class — human review/merge required (maintainer ruling 2026-08-11) #7548 / [PM seat] skills — 🟢 os-warren (session_01AeA3nU1B5Q2pgxqxgUrexd) #7623)。ADR maintainer approval红是设计如此,⛔ 不得点绿,但必须在 PR 上说明红因并声明不修;content/docs/releases/**release-owned,两条通道见上。version脚本链(实证 Docs image tags have no version-time rewriter, so the new check:docs-image-tag gate cannot fire on the release PR that breaks it #9064 已因此被判pm:blocked)。⛔ 能点绿的门禁不等于该点绿。scripts// docs / test-only ⇒skip-changeset;落进已发布包的源 ⇒ 真 changeset;收窄接受集尤须慎重(实证 validate-dashboard-action-refs 的 resolveActionTarget 仍接受 modal 裸对象名与 verb_object —— 其镜像依据(objectui DashboardView 运行时)已被 PR objectui#4782 删除,规则方向反转 #9013:lint+spec 双 minor + ADR-0087 语义登记)。.claude/skills/pm-dispatch/**、改变契约接受/拒绝行为、或扩大公开面 ⇒claude-fable-5(强制)。domain:*一律不动(分诊单一生产者)。说明
接手指引:
/pm-dispatch devx→ 读正文 → 读晚于正文最后编辑的评论 → 自己重扫车道标签。Key pitfalls(累积):
Blocked-by:、状态更正、维护者裁定放在评论里 ⇒ 只读正文,系统性地读到「决策之前的世界」。 实证 Atype: 'form'action leaves the console shell for a bare/forms/:namepage and ends on a generic "Thanks!" panel instead of the created record (observation) #7245:本席读完正文判「三方向未定、不可派」,而维护者六天前就裁了,两个半边已落地,剩两行清理。⇒ 对任何超过一天的卡,正文是页面上最不当前的东西。dispatch-gates.mjs读工作树不读 ref,而共享主 checkout 落后 81 个提交、新门禁脚本根本不存在 ⇒ 它诚实地报 96 族零命中,我差点据此立「盲区未闭」的假回归卡。②**FETCH_HEAD也是共享的**,被另一 agent 的 fetch 在我两条命令之间冲掉,整个文件显示成新增,我差点判 docs(protocol): narrow realtime-protocol.mdx's "enforces this in CI" claim to what the tripwires check #9082「没改到点子上」。⇒ 判据分两类且不可混用同一目录:读内容用git show origin/main:;跑脚本必须在自己的 worktree;复核 diff 一律用具名 ref(git fetch origin <br>:refs/pmcheck/<n>),⛔ 不用FETCH_HEAD。list_issues多标签是 OR([finding] The GitHub MCPlist_issuesmulti-label filter is OR (union), not AND — a two-label query returns every issue carrying either label #8942),而且会分页截断 —— 两个坑同日各踩一次。 我在被截断的 30 条里做交集,报出「队列见底」;真实domain:devx开放卡 36 张、带pm:queue的 13 张,6 张未见。⇒ 单标签查询 + 客户端取交集 + perPage 给足;⛔ 永不把返回列表当车道队列。--union-intore-walks the whole repo once per matching declaration #8900 声明数 / Three packages/cli tests read content/docs/deployment/*.mdx with a seed spelling check:cross-package-test-inputs does not recognise, so the reads are undeclared and the gate stays green #8995 路径数 / docs(deployment): the CLI reference has no entry foros package publishoros package install— the two commands that move an app onto a platform #8965 整份是另一命令的 flag)。⇒ 凡派发词给出实测值,必须同时给出「自己重测」的指令。MEASURED全文计数 vs 条目内 ·allowWrites文件数 vs 真实声明 ·IMPLICIT_FIELDS正则漏类型标注 · 未加 scope 的键 ·git diff --stat会把路径缩写成.../(我据此以为 fix(lint): a dashboard header modal action's target resolves against declared pages, only (#9013) #9077 开了新文件族) ·grep -c数的是行不是次。⇒ 按位置查,不按次数查;显示层产物不是数据。pnpm --filterrun exits 0 and reads as a pass #8973 实证:照标题建那道门禁,其理由(「pnpm 退出 0」)是假的 —— 一道理由为假的门禁比没有门禁更坏,因为下一个读者会相信它,以为某个风险已被覆盖。这是「绿 ≠ 门禁在看你关心的东西」的另一面,指向散文而非退出码。OS_DATABASE_URLguidance omitsmysql://— the one page a production deployer reads never offers a now-supported target #9053 的 dev 用被改页面自己的惯例(每目标只写一个规范 scheme,从不列别名)否掉本席提的mysql2://;②ADR-0076 D11 needs its ruled revision: the rest-server half is delineated-not-split, and the ADR still records it as an unmet obligation #9024 的 dev 拒绝把已退役的 LOC 序列刷新进正在记录其退役的那一行;③authorization.mdxtells customers "a declared-but-unenforced primitive fails the build" — measured, that holds only for a curated 15-probe table, and 43 of 50 matrix rows sit outside it #9028);transcript 里的计数是对程序输出的复现,省掉就是伪造一段 CLI 永不打印的输出(docs: the sampleos validatetranscript on validating-metadata.mdx prints a stale author-time rule count (38 shown, registry holds more) #9034 的派发分叉)。@objectstack/spec@17.0.0-rc.6, so the console keeps vendoring a pre-GA spec and #7804's key stays unreachable #8893)。⇒ 解锁判据只能是merged_at或等价完成事实(validate-dashboard-action-refs 的 resolveActionTarget 仍接受 modal 裸对象名与 verb_object —— 其镜像依据(objectui DashboardView 运行时)已被 PR objectui#4782 删除,规则方向反转 #9013 即如此解锁)。origin/main上的内容,收官查total_count恰为 1。skip-changesetapplied,而标签根本没打上,Check Changeset转红。⇒ 写完必须读回;skipped不清除同一必需上下文上更早的failure,PM 侧补救只有update_pull_request_branch,⛔ 永不rerun_failed_jobs。skip-changeset反射有真例外(fix(lint): three write rules ask anchor provenance before exempting a system column #8996、validate-dashboard-action-refs 的 resolveActionTarget 仍接受 modal 裸对象名与 verb_object —— 其镜像依据(objectui DashboardView 运行时)已被 PR objectui#4782 删除,规则方向反转 #9013)。⇒ 判据是 diff,不是习惯。authorization.mdxtells customers "a declared-but-unenforced primitive fails the build" — measured, that holds only for a curated 15-probe table, and 43 of 50 matrix rows sit outside it #9028 最完整::257的~18查不出当初数的什么 ⇒ 省略而非替换,并给出查不出的原因(本地浅克隆 grafted,blame 假指),改走 API 沿真实历史回到 07-04,发现它在每个可达修订上都已对不上且不匹配任何其他分组。NO-OCCURRENCES反空转肢(某个面读不出具体 pin 就判失败),⇒ 枚举不能悄悄退化成 no-op。realtime-protocol.mdxsays the authz conformance matrix "enforces this in CI" for per-recipient realtime authorization — the tripwires force classification, they cannot check the re-check exists #9055 两条腿:腿 1 证明该有的性质真会开火;腿 2 让 transport 接着、零授权,只手工把 tripwire key 追加进 experimental 行的covers,15 passed 全绿 ⇒ 强制站点从来不是必需的(authz matrix: a wired realtime transport can be classified by theexperimentalrow itself — the ledger never requires the enforcement site the tripwire note promises #9083);外加 tripwire 只匹配/realtime字面量,对同页记载的/ws与/api/v1/stream根本不会开火(authz matrix: therest-server.tsrealtime tripwire matches only a/realtimeliteral — it cannot fire for/wsor/api/v1/stream, the two transports the protocol page documents #9084)。IMPLICIT_FIELDSsets spread the blanket SYSTEM_FIELDS union with no provenance awareness — candidate sixth/seventh unprovisioned-anchor read sites #8663:14 条新测试只有 4 条是消融证明的)。/console/forms/:name, but the same page's own example targets use/_console/#9050 明说「散文/路径 sweep 无运行时行为可变异,填消融字段会是捏造」。pnpm --filterrun exits 0 and reads as a pass #8973 的核心机制被证伪、docs(releases): v16.mdx namesaf1b0dbas the 16.0.0-rc.1 Console pin, but rc.1 ended at69fa5d163a97— two further pin moves, and objectui#2743 is documented nowhere #9035 的「17 处」与其自身枚举清单 15 条不一致)。「卡片说 X」是线索,不是发现。blankand never runsnpm run build; it was green over the #7644 defect #8678)。get_status不是门禁读数(只聚合 Vercel);判据是get_check_runs的逐 jobconclusion。GlobalFilterSchema.objectis unreachable in the Studio designer, and no console pin bump can fix it — the console vendors the PUBLISHED@objectstack/spec, which the key postdates #8134 的中心论断)。check-durability-degradation-log-levelguardspackages/**source but its lint.yml path filter lists only its own script — so no derivation can name it for a source change #8889)。⛔⭐ 锚定行号要核所属函数/章节(docs(deployment): put widget-binding integrity on the runtime publish door #9005)。Auto Label抢跑会冲掉size/*)。'literals into its code blocks #8813)。⭐ 但「读不全的卡不能派」不是终局判决 —— 若规格的证据存在于可读的一手来源,正确做法是把「重建规格」定为第一步并给它一个拒绝的出口(Guard that named verification scripts actually exist in the filtered packages — a zero-matchpnpm --filterrun exits 0 and reads as a pass #8973 实证,而它正是靠那个出口证伪了前提)。date -u实读。AGENTS.md正文不得带 issue 号。TypeScript Type Check,dev 从仓库源码证伪(check-required-contexts.mjs的ESLint条目carries= 「the whole check:* gate family (25 steps)」)。该判据现已可引,后续门禁卡不必再各踩一遍(Add a mechanical guard: docs image tags should track packages/cli's version #9018 直接沿用)。pnpm install会产生ERR_MODULE_NOT_FOUND假红(本任期三个 dev 各撞一次,均如实报出)。RECOGNISED_PATH_SPELLINGS等公开常量印在失败文案并镜像进 AGENTS.md ⇒ 必须同批移动(check:cross-package-test-inputs does not see anew URL(…, import.meta.url)seed, so an undeclared cross-package read passes green #8698 · Three packages/cli tests read content/docs/deployment/*.mdx with a seed spelling check:cross-package-test-inputs does not recognise, so the reads are undeclared and the gate stays green #8995)。迁移注记:「范围 / 常设承诺 / pitfalls」经
hotlong→os-zhuang→qq9340100→os-zhuang→os-project-manager(本席)五任承接;台账与热文件队为本席 2026-08-16T09:18:21Z 现值。旧账留在 body revision 历史中。