feat(pm): patrol row H64 — a seat- or dev-signed artefact authored by a user account - #18073
Conversation
…account Maintainer ruling, skills seat chat 2026-09-13T16:14Z, verbatim: 「机制层的五道锁 现在就派发处理」 — this row is lock 5. Content written through the MCP GitHub tools is authored by a USER account; content written through the REST proxy is authored by `claude[bot]`. A user account that is suspended hides everything it authored, so a seat- or dev-signed artefact under a user login is a half-state: the text says a seat wrote it, the account field says a person did. Report-only, zero requests: open card and PR bodies already in hand plus the card threads H44/H56 read. No new listing, no label, no write path, and no roster of seat accounts (H44's refusal, taken for H44's reason). Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8 Co-authored-by: Claude <noreply@anthropic.com>
…ontrols Offline rows only: #18045, objectui#9404, PR #18051 and comment 5652138683 fire; comment 5654046782 (the same claim shape authored `claude[bot]`) is the clean control, and every fire has a control differing in exactly one feature. Two of the filing card's five signature forms were measured against the specimens it named and would not reach them: the os-tesla claim carries no `Session:` line, and PR #18051's only session token sits in its attribution footer on the last line. Both widenings are pinned as measurements. Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8 Co-authored-by: Claude <noreply@anthropic.com>
…ile requires The ablation found it: removing the footer signature form aborted all 4042 cases at the first `seatSignature(...).kind` instead of reddening the four cases that own it. `seatSignature` and `artefactAuthor` are three-valued by design, so a bare property read throws while `t()`'s arguments evaluate — the hazard `selfTest`'s row-wrapper note already documents for the predicates. Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8 Co-authored-by: Claude <noreply@anthropic.com>
…er-authored-seat-content-row
Contract reviewHead: ① derived judgments — one report-only row, H64, over a population the patrol already holds:
Seat measurements on the head tree ( ② semver: ③ boundary flags: Implemented-by: Verdict: PASS — lock 5 as ordered: the defect is now visible on the anchor the hour it happens, with the legacy counted rather than shouted. Generated by Claude Code |
Fixes #18069
Lock 5 of the mechanism-layer plan. Maintainer, skills seat chat 2026-09-13T16:14Z, verbatim: 「机制层的五道锁 现在就派发处理」.
One REPORT-ONLY patrol row in
scripts/pm/check-half-states.mjs(the whole file surface). H64 fires on an artefact that carries a seat/dev signature while GitHub records its author as a USER account rather than the App. A suspended user account hides everything it authored, so the artefact's text and its account field disagree about who wrote it and the record is held by an account the protocol does not control. ⛔ No new listing, ⛔ no label, ⛔ no write path, ⛔ no roster of seat accounts — the artefact is recognised structurally (H44's refusal, taken for H44's reason) and the author is read only as the defect.Two of the card's five signature forms were measured and widened
Claim:block with aSession:lineSession:line in its 35CLAIM_COMMENT_MARKERalone, the marker H2/H33/H34/H37 already shareclaude.ai/code/session_…footer is a SIXTH form; ⛔ the platform's own bare footer is not a signatureTwo mechanisms the live measurement forced
created_atbeforeUSER_AUTHORED_WRITE_SINCE(2026-09-13) is a CENSUS count and files no row — 816 of them, reaching back to 2026-08-05 — because "re-post it through the proxy" is not a remedy anyone performs 816 times.renderMarkdownsorts by card number ASCENDING and the body trim eats the tail, so for this family the newest write — the one the lock exists to surface within the hour — is the first row removed. Changing that sort belongs to every family, so the family bounds itself instead; the clause prints the full judged count on every run.user.typeis the test,user.loginis printed and never tested: the login form is a one-name roster wearing an equality sign and judgesgithub-actions[bot](2 open cards, 1 open PR here) as a user account.Verification
--self-test3915 → 4042 cases, green. Ablation, both legs restored byte-identical to the HEAD blob: removing the author test reddens 4 cases, removing the footer form reddens 11.claude[bot].session), PR docs(pm,agents): three rules-layer lines catch up with the charter rulings #18051 (footer), objectui#9404 (filer), comment 5652138683 (claim); comment 5654046782, the same claim shape authoredclaude[bot], is silent. board-snapshot: once the open set completes, every run spends its whole budget on the closed history and never re-reads the live board — cards created or updated since 2026-09-10 are in no snapshot #18045 is inside the judged 54 and outside the rendered 10: the cap, working.dispatch-gates.mjs --commands --repo objectstack-ai/objectstackrun in the foreground at this head, exit codes captured before any pipe. Full list and readings in theos-dev-reporton Patrol row: a seat- or dev-signed issue, PR or comment authored by a user account instead of the App is a half-state (lock 5) #18069.Acceptance notes
created_at.seatSignature(...).kindbefore the wrappers went in. Carrier: the next row that exports a nullable helper.skip-changeset:scripts/pm/**ships in no package'sfiles[].Generated by Claude Code