Skip to content

feat(pm): patrol row H64 — a seat- or dev-signed artefact authored by a user account - #18073

Merged
os-project-manager merged 4 commits into
mainfrom
claude/issue-18069-user-authored-seat-content-row
Sep 13, 2026
Merged

os-project-manager merged 4 commits into
mainfrom
claude/issue-18069-user-authored-seat-content-row

Conversation

@claude

@claude claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Fixes #18069

Lock 5 of the mechanism-layer plan. Maintainer, skills seat chat 2026-09-13T16:14Z, verbatim: 「机制层的五道锁 现在就派发处理」.

One REPORT-ONLY patrol row in scripts/pm/check-half-states.mjs (the whole file surface). H64 fires on an artefact that carries a seat/dev signature while GitHub records its author as a USER account rather than the App. A suspended user account hides everything it authored, so the artefact's text and its account field disagree about who wrote it and the record is held by an account the protocol does not control. ⛔ No new listing, ⛔ no label, ⛔ no write path, ⛔ no roster of seat accounts — the artefact is recognised structurally (H44's refusal, taken for H44's reason) and the author is read only as the defect.

Two of the card's five signature forms were measured and widened

form the card measured now
claim Claim: block with a Session: line comment 5652138683 — the card's own os-tesla fixture — carries no Session: line in its 35 CLAIM_COMMENT_MARKER alone, the marker H2/H33/H34/H37 already share
session id bare id in the first three lines PR #18051's only session token is line 45 of 45, in the attribution footer; the head window fires on 0 of 9 open PRs, the footer form on 4 head window stays narrow, the claude.ai/code/session_… footer is a SIXTH form; ⛔ the platform's own bare footer is not a signature

Two mechanisms the live measurement forced

  • A pin (H55's shape). 870 of 1075 signed texts on this board are user-authored. created_at before USER_AUTHORED_WRITE_SINCE (2026-09-13) is a CENSUS count and files no row — 816 of them, reaching back to 2026-08-05 — because "re-post it through the proxy" is not a remedy anyone performs 816 times.
  • A 10-row cap, newest first. renderMarkdown sorts by card number ASCENDING and the body trim eats the tail, so for this family the newest write — the one the lock exists to surface within the hour — is the first row removed. Changing that sort belongs to every family, so the family bounds itself instead; the clause prints the full judged count on every run.

user.type is the test, user.login is printed and never tested: the login form is a one-name roster wearing an equality sign and judges github-actions[bot] (2 open cards, 1 open PR here) as a user account.

Verification

Acceptance notes

  • Declared residuals, both stated in the row's banner and in the summary clause: a PULL-REQUEST comment thread is outside the corpus (H44's declared residual, restated), and an EDIT re-writes a body through the same channel without moving created_at.
  • Noted, not filed: the self-test's row-wrapper discipline covers the three-valued PREDICATES but nothing states it for three-valued HELPERS; this row's own ablation aborted 4042 cases at a bare seatSignature(...).kind before the wrappers went in. Carrier: the next row that exports a nullable helper.

skip-changeset: scripts/pm/** ships in no package's files[].


Generated by Claude Code

…account

Maintainer ruling, skills seat chat 2026-09-13T16:14Z, verbatim:
「机制层的五道锁 现在就派发处理」 — this row is lock 5.

Content written through the MCP GitHub tools is authored by a USER account;
content written through the REST proxy is authored by `claude[bot]`. A user
account that is suspended hides everything it authored, so a seat- or
dev-signed artefact under a user login is a half-state: the text says a seat
wrote it, the account field says a person did.

Report-only, zero requests: open card and PR bodies already in hand plus the
card threads H44/H56 read. No new listing, no label, no write path, and no
roster of seat accounts (H44's refusal, taken for H44's reason).

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
…ontrols

Offline rows only: #18045, objectui#9404, PR #18051 and comment 5652138683
fire; comment 5654046782 (the same claim shape authored `claude[bot]`) is the
clean control, and every fire has a control differing in exactly one feature.

Two of the filing card's five signature forms were measured against the
specimens it named and would not reach them: the os-tesla claim carries no
`Session:` line, and PR #18051's only session token sits in its attribution
footer on the last line. Both widenings are pinned as measurements.

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
…ile requires

The ablation found it: removing the footer signature form aborted all 4042
cases at the first `seatSignature(...).kind` instead of reddening the four
cases that own it. `seatSignature` and `artefactAuthor` are three-valued by
design, so a bare property read throws while `t()`'s arguments evaluate — the
hazard `selfTest`'s row-wrapper note already documents for the predicates.

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
@claude

claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author
  • Served-tier: 1352/1352 claude-fable-5-1 — harness model stamp counted over this seat's own transcript (non-sidechain assistant messages a model served; <synthetic> harness notices excluded) at 2026-09-13T17:24Z; get_session external_metadata.last_served_model read claude-fable-5-1 at 2026-09-13T17:24Z.

Contract review

Head: 5ec09514 (PR #18073, card #18069) — read at 2026-09-13T17:25Z by the skills seat at the contract-review tier. NOT GOVERNED, measured: scripts/pm/check-half-states.mjs only (+819; banner, predicate, sweep, band entry, count keys, summary clause, 127 cases) ⇒ in-seat review, then ready + auto-merge by this seat. Ruling of record: the maintainer's 「机制层的五道锁 现在就派发处理」 (2026-09-13T16:14Z), lock 5.

① derived judgments — one report-only row, H64, over a population the patrol already holds:

  1. Recognition is structural, the author is the defect: six signature forms (Claim: marker, os-dev-report marker, ## Contract review + Reviewed-by:, the Filed by the … seat/dev header, a bare session ID in the first three lines, the claude.ai/code/session_… attribution footer), then user.type !== 'Bot' — trusted over the login because github-actions[bot] is a Bot with a foreign login (measured: three artefacts on today's board where the two tests would diverge, none signed). No roster of accounts to exempt; authorized reviews and the maintainer's prose are outside by construction (never read / never signed).
  2. Two sub-premises of the card falsified by the live fixtures and corrected in the right direction: the os-tesla claim carries no Session: line, so the claim form is the marker alone (the one H2/H33/H34/H37 share); the dev-signed PR body carries its only session token in the footer (line 45 of 45), so the footer is the sixth form and the head window stays narrow. Both measured over all nine open PRs.
  3. Two mechanisms the card did not specify, both forced by measurement and declared: a 2026-09-13 pin (USER_AUTHORED_WRITE_SINCE) with an H55-shaped census for the 816 legacy writes — 870 of 1075 signed artefacts on this board are user-authored and a re-post remedy is not performed 816 times; and a 10-row newest-first cap, because renderMarkdown sorts rows by card number ascending and the body trim eats the tail, which would remove exactly the newest write lock 5 exists to surface. Consequence stated on the report: board-snapshot: once the open set completes, every run spends its whole budget on the closed history and never re-reads the live board — cards created or updated since 2026-09-10 are in no snapshot #18045 is inside the judged 54 and outside the rendered 10; the summary clause prints the judged count every run.
  4. Channel reading: performed_via_github_app.slug ⇒ MCP tool under the user's token; its absence on a payload that serves the field ⇒ a user PAT; the /pulls listing does not serve the field ⇒ UNREAD, printed as such — never inferred.
  5. Residuals declared: PR comment threads outside the corpus (H44's residual, restated); an edited body is judged at its first write. Report-only: no listing, no label, no write path.
  6. Live read-only run (the card's ask): 2073 texts, 1075 signed, 870 user-authored, 54 judged since the pin, 10 rows (PR docs(pm,agents): three rules-layer lines catch up with the charter rulings #18051 and nine newer artefacts), nothing authored claude[bot] named; the four card-named specimens fire against their live payloads and the same claim shape authored claude[bot] (5654046782) is silent.

Seat measurements on the head tree (git archive 5ec09514): check-half-states.mjs --self-test → 4042 cases pass, exit 0 (base 3915; +127). --pair 18073 → exit 0 at 2026-09-13T17:04Z. Checks on 5ec09514 at 2026-09-13T17:24Z: 37 runs, 0 red, 1 running (Lint & Repo Gates) — the queue's own gate holds the merge until it is green. Dev's two ablations (author test forced true → the four clean controls red; footer form deleted → 11 red incl. PR #18051) restored by blob hash; the first ablation's abort (a bare .kind on a three-valued helper) was fixed by routing readers through wrappers before it counted as a measurement.

② semver: scripts/pm/** publishes nothing; skip-changeset is right.

③ boundary flags: open_questions empty. Two 「noted, not filed」 items stand as notes: the row-wrapper convention for three-valued exported helpers (the next row's author), and the 816-artefact legacy census — whether a one-time re-post sweep is worth it is the maintainer's call, carried to chat with this review. Landing consequence: from the next patrol run, any seat or dev write that lands under a user account is named within the hour.

Implemented-by: claude/issue-18069-user-authored-seat-content-row
Reviewed-by: session_01DAcomhvR9kKizeYgg89Vo8

Verdict: PASS — lock 5 as ordered: the defect is now visible on the anchor the hour it happens, with the legacy counted rather than shouted.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/l skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Patrol row: a seat- or dev-signed issue, PR or comment authored by a user account instead of the App is a half-state (lock 5)

2 participants