Skip to content

docs(AGENTS): PD #14 approve-gated landing path — conditioned prohibitions, agent-never-approves, pure-regen proactive approval; ratchet ceiling 1158 to 1162 - #13059

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-12756-pd14-approve-gated-amend
Aug 29, 2026
Merged

docs(AGENTS): PD #14 approve-gated landing path — conditioned prohibitions, agent-never-approves, pure-regen proactive approval; ratchet ceiling 1158 to 1162#13059
os-zhuang merged 1 commit into
mainfrom
claude/issue-12756-pd14-approve-gated-amend

Conversation

@os-elon

@os-elon os-elon commented Aug 29, 2026

Copy link
Copy Markdown
Collaborator

Fixes #12756
Fixes #12896
Fixes #12874

Governed surface (AGENTS.md) — stays draft for the maintainer's pinned approval; the queue guard enforces the landing predicate at queue time.

What each ruling contributed

All three rulings are the 2026-08-29 maintainer batch #1 (verbatim, recorded on the cards: 「执行,批 #1 其他卡同意」), dispatch record session session_016SG9S6V15MqeAgkehDcTwk.

  1. First card (option A) — Prime Directive feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14's editable prose (paragraphs 1 and 3) replaced with the apply-ready draft held on the card, now ruled:
    • the superseded bolded sentence "Reviewed + approved + fully green does not override this." is removed;
    • the four ⛔ landing prohibitions are conditioned: "Those four lift only for an authorized approval pinned to the current head" — APPROVED, by an account in GOVERNED_APPROVERS (scripts/pm/check-governed-queue-guard.mjs), commit_id = the PR's exact head sha; any later push expires it. The approver set is referenced only as the constant, never as account names;
    • the maintainer's bypass direct merge (人工直合) stays named as the unpinned fallback;
    • no agent seat submits an approving review on a governed-surface PR, under any account — same paragraph, with the audit half in paragraph 3 ("the audit reads the approver as well as the merger; one he does not recognise, or any agent approval, is a seat violation");
    • paragraph 3's two now-false claims corrected: "only pre-merge barrier there is" dropped, "detection, not prevention" became "prevention and detection" — the queue guard's merge_group leg refuses an unpinned governed diff.
  2. Skills-section fold (AGENTS.md § Skills carries the same pre-approve-path wording as PD #14: "never queued, armed or flipped out of draft" is unconditional, and "Prime Directive #14 is the whole barrier" is stale since the queue guard #12896 — content verified against the card body before folding) — the § Skills closing rule, same file, the two enumeration rows: "never queued, armed or flipped out of draft" reconditioned to the PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14 pinned-approval path; "Prime Directive feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14 is the whole barrier" replaced by the guard's queue-time refusal. Per the card's binding note, "no per-PR check holds it" survives — true by design.
  3. Pure-regeneration line ([finding] Governed Surface Queue Guard: the merge_group leg installs no dependencies, so the #11705 generated-surface lift NEVER applies at queue time — pure-regeneration PRs still need a human APPROVED review; the trade needs a ruling #12874, option A) — one documentation line in the PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14 landing-path prose: "Even a pure-regeneration PR requests its pinned approval proactively, before queueing — the queue-time leg installs no dependencies and never evaluates the byte-equality lift (2026-08-29)." Placement: paragraph 1, immediately after the queue-path mechanics ("any later push expires it") and before the unpinned fallback. The guard header's filed-not-taken record stands unchanged.

Untouched, per the ruling's constraints: all three verbatim block-quoted rulings in the region, and the "Which surfaces" register paragraph pinned by check:pm-governed-prose.

Ceiling arithmetic — 1158 to 1162 (measured minimum)

The ruling authorizes raising to the measured minimum for this convoy. Measured with the gate's own exported wrapLine (canonical rewrap, byte-exact):

piece lines
PD #14 paragraph 1, held draft (after the card's seven-cut ledger) 12 to 15 (+3)
PD #14 paragraph 3, held draft 18 to 17 (−1)
pure-regeneration rider, in paragraph 1 +2
§ Skills closing-rule fold 2 to 2 (0)
total 1158 to 1162 (+4)

The rider's +2 is a floor, not a first draft: a probed 161-byte minimal variant still wraps to +2 (paragraph 1's total rewrap slack is 103 bytes, not recoverable by the greedy wrap), and every +1 variant drops ruled content — "pinned", "proactively", or the dependency-free reason. All three PD #14 paragraphs measure 0 lossless-rewrap headroom under wrapLine, and the card's seven-cut ledger was exhausted before any addition (recorded on the card). Headroom is 0 again by construction. The raise is recorded in the CEILINGS map with the ruling quoted verbatim and untranslated, the map's own convention.

Gates — red first, then green

Red-first, on the amended AGENTS.md before the raise (exit 1, captured by redirect-then-read, never through a pipe) — the gate demanding exactly the ruled remedy:

  • ✗ check-skill-line-ratchet: AGENTS.md is 1162 lines; the ratchet ceiling is 1158. ... Raising a ceiling requires a maintainer ruling quoted in the PR.

Green after the raise, on the final commit fdee46c3 (the full derived union — node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack, 17 matched families + 2 convention-triggered by the gate-script edit — every exit 0):

  • ✓ check-skill-line-ratchet: AGENTS.md is 1162 lines (ceiling 1162; headroom 0) — and the widest-row pin holds: 1081 bytes (pin 1081; headroom 0)
  • ✓ check-governed-prose: 2 instruction surface(s) name all 5 registered governed surfaces and claim no others
  • ✓ check-skill-id-lint: 23 file(s) clean
  • check:agent-test-spelling · check:bash32-floor · check:cli-command-ids · check:cross-package-test-inputs · check:docs-audit-scope · check:entry-guard · check:parse-guard · check:pm-governed-merges · check:pnpm-filter-targets · check:required-contexts · check:watch-hint-literal · check-ci-filter-parity · check-cross-package-test-inputs (node) · check-required-contexts (node) — all exit 0
  • convention-triggered by the gate-script edit: bare-root-worklist --self-test OK (none stale, none missing, none contradicted) · check:pm-dispatch-gates ✓ 834 cases pass
  • check:nul-bytes OK (7252 text files, no raw control bytes)

The ratchet gate's own self-test runs first inside pnpm check:pm-skill-ratchet and passes on the edited script.

No changeset: instruction text only, nothing publishes — skip-changeset label applied per the repo convention.


Generated by Claude Code

…e lift, agent-never-approves, pure-regen proactive approval; Skills closing rule reconditioned; AGENTS.md ratchet ceiling 1158 -> 1162 per the 2026-08-29 batch ruling

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016SG9S6V15MqeAgkehDcTwk
@os-zhuang
os-zhuang marked this pull request as ready for review August 29, 2026 02:27
@os-zhuang
os-zhuang added this pull request to the merge queue Aug 29, 2026
Merged via the queue into main with commit 269167f Aug 29, 2026
40 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-12756-pd14-approve-gated-amend branch August 29, 2026 02:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment