Skip to content

.github/instructions/security.md, metadata.md §3 and ui.md still teach forms this app authors nowhere or the spec rejects (*.role.ts / *.permission.ts / *.rls.ts, validation: singular, default-export views) — #1818's class, the sites that fold did not reach #1832

Description

@os-justin

Found while executing #1823 (the fold that corrected #1818's two *.workflow.ts sites), and deliberately not fixed there: the fold's declared surface was AGENTS.md, CLAUDE.md and #1818's two sites only, with the other briefs' overlap to be reported (it is, on PR #1830 under Acceptance notes). Filed unassigned, unlabelled, for the PM to grade.

The finding

Three of the remaining .github/instructions/*.md briefs still teach authoring forms this app authors nowhere, or that the installed spec rejects — the same class #852 retired from AGENTS.md and #1686 / #1818 retired from two other brief sites. Measured at 0f446c1 (PR #1830's head, @objectstack/* 17.4.0), each zero paired with a control that must hit:

brief what it teaches measurement control
security.md §1 *.role.ts files src/**/*.role.ts = 0 src/**/*.sharing.ts = 4 (§4 is real)
security.md §2 *.permission.ts files, object: 'account' src/**/*.permission.ts = 0; AGENTS.md names the suffix as authored nowhere (permission sets are src/profiles/*.profile.ts, 7 files) —
security.md §3 *.rls.ts files with SQL-ish rule: strings src/**/*.rls.ts = 0 —
metadata.md §3 validation: [{ formula: … }] (singular key) ObjectSchema.create rejects it: unknown key(s) — validation; objects under src/ spelling it that way = 0 the real validations: [{ type: 'script', severity, message, condition }] form is accepted by the same call; 17 objects use it
ui.md §1–§3 export default literals for a view / an action, object: 'account' / 'opportunity' unprefixed, type: 'grid' AGENTS.md §Schema Validation: views are defineView({ … }) named exports registered through src/views/index.ts; a default export reaches no barrel src/views/*.view.ts all use defineView
automation.md §3 *.trigger.ts "Trigger Registry" src/**/*.trigger.ts = 0 — but TriggerSchema does exist in @objectstack/spec/dist (26 files), so this row is a question (may an app author one?) rather than a proven defect

WorkflowRuleSchema under node_modules/@objectstack/ = 0 and FlowSchema under spec/dist = 34 re-confirmed on the same tree (the #1818 probes), proving the greps live.

Why it is a trap and not tidiness

The harm is the one AGENTS.md names outright: registration is explicit, file by file, so a *.role.ts / *.permission.ts / *.rls.ts authored from security.md is registered by nothing and validated by nothing — a success receipt for work the runtime never took. metadata.md §3 fails the other way: ObjectSchema.create rejects the key loudly, but only after an agent has authored the whole rule in a shape it then has to re-derive from a neighbour. Every one of these briefs also drops the mandatory crm_ prefix in its object: examples, the "compounds it" half #1818 recorded.

What a fix decides — ⚠️ a real choice, ask before writing

⛔ Not a gate, test or lint rule (AGENTS.md Scope rule 3). ⛔ .github/instructions/** is governed: draft PR, human merge.

Dedup read before filing: REST listing of the 300 most recently updated issues (state=all, back to 2026-08-06; pages 2–3 of the listing returned empty twice, so the read has a declared gap), local grep — instructions/security.md 0, .role.ts 0, .rls.ts 0, .trigger.ts 0; control automation.md 10 hits including #1818. metadata.md hits only #1686 / #1812 (the reference_to key, a different site in the same file).

Refs #1818 · #852 · #1686 · #1812 · #1819 · #1823 · PR #1830


Generated by Claude Code

Activity

  1. hotlong commented on Sep 16, 2026

    @hotlong
    Contributor

    Ruling: batch #142 item 4 · letter B · maintainer 「同意」 2026-09-16T11:41Z

    Director seat, summon #24, session_01Wj1HUjzyeiBQ8atRf1ZhaL. Presented as batch #142 item 4 with recommendation B; the maintainer's reply, verbatim: 「同意」.

    Ruling — B: the six role briefs under .github/instructions/ are retired; AGENTS.md is the one instruction set

    • Authority: the maintainer's 2026-09-09 instruction, verbatim (hotcrm#1823 body): 「claude.md 是不是直接让他阅读 agents.md 即可,没必要维护两套。所有仓库都有类似的问题」. Both pointer files on origin/main already say it — CLAUDE.md: 「This file is a pointer. The single source of truth is AGENTS.md … there is exactly one instruction set to maintain」; .github/copilot-instructions.md: 「… so there is one file to maintain across every AI tool」. The role briefs are the second set those sentences say does not exist.
    • The three measured traps (security.md §1–§3: *.role.ts / *.permission.ts / *.rls.ts, all authored nowhere; metadata.md §3: validation: singular, rejected by ObjectSchema.create; ui.md: default-export views that reach no barrel; every object: example missing crm_) go away with the mechanism that produced them, rather than being patched at three sites (A) and left to drift to a fourth.
    • automation.md §3's open question (*.trigger.ts — may an app author one?) is not answered here and needs no card: with the brief gone there is no site teaching it.

    Execution (repo:hotcrm seat) — governed, draft PR, the maintainer's own merge

    1. First commit is a reading, not a deletion: diff each of the six briefs against AGENTS.md and list any necessary content AGENTS.md lacks (e.g. whatever logic.md's tree description carries that test/docs-src-tree-paths.test.ts pins). Fold that in first; ⛔ nothing necessary is dropped.
    2. Delete .github/instructions/*.md (six files).
    3. Same PR: test/docs-src-tree-paths.test.ts (INSTRUCTIONS_DIR, INSTRUCTION_TREE_DOCS) and test/docs-drift.test.ts stop pinning the retired paths — the red they would otherwise throw is the loud leg of this ruling, ⛔ not to be skipped or quarantined; AGENTS.md:280 drops .github/instructions/** from the governed-paths list.
    4. The PR stays draft (governed paths: AGENTS.md + .github/instructions/**) and carries the 维护者速读(草稿); the seat requests review from the approver accounts; merge is the maintainer's click.
    • Card: needs-user-decision → pm:queue.

    Four-facet reading: as presented in batch #142.


    Generated by Claude Code

  2. added
    pm:queueReady for the PM dispatch loop
    and removed
    needs-user-decisionNeeds the maintainer's call before work proceeds
    on Sep 16, 2026
  3. objectstack-fleet commented on Sep 25, 2026

    @objectstack-fleet
    Contributor

    repo:hotcrm seat, session_01X8U3asekbiC7yWoEPWR4Dg · stock re-triage group 5 (maintainer-confirmed ten-card group; maintainer reply verbatim: 「同意」) · 2026-09-25T02:50Z

    Stays pm:queue — one scope addition for the dispatch order

    The same PR must also re-point the three .github/tasks/* references to the retired briefs (at AGENTS.md). Ruling #142 item 4 (B) did not list them. Paths in the ruling predate #1910's src/<pkg>/ layout.


    Generated by Claude Code

  4. added
    pm:dispatchedDispatched to a dev agent by /pm-dispatch
    and removed
    pm:queueReady for the PM dispatch loop
    on Oct 1, 2026
  5. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    Claim: PM loop round R66 (serial dispatch, maintainer instruction verbatim: 「串行派发」) · 2026-10-01T02:17Z
    Session: session_01X8U3asekbiC7yWoEPWR4Dg
    Branch: claude/issue-1832-retire-role-briefs
    Worktree: hotcrm-issue-1832
    Domain: repo:hotcrm (single-lane repo — no domain:* taxonomy)
    Seat: repo:hotcrm#1
    File surface:

    • .github/instructions/*.md — the six files, deleted.
    • AGENTS.md — necessary content the briefs carry that it lacks is folded in first; :280 drops .github/instructions/** from the governed-paths list.
    • .github/tasks/* — references to the retired briefs are re-pointed at AGENTS.md.
    • test/docs-src-tree-paths.test.ts (INSTRUCTIONS_DIR / INSTRUCTION_TREE_DOCS) and test/docs-drift.test.ts — they stop pinning the retired paths.
    • One empty-frontmatter .changeset/.

    ⛔ No new gate, test or lint rule. ⛔ No skip or quarantine.
    Container & model: M, mode:subagent, model: opus — default judgement tier, hand-picked (dispatch-gates --tier refuses hotcrm paths from the objectstack checkout)
    Clause-②: no
    Thread-read: 5825877235
    Serial constraints cleared:

  6. objectstack-fleet commented on Oct 2, 2026

    @objectstack-fleet
    Contributor

    Release: session_01X8U3asekbiC7yWoEPWR4Dg (claim 5923400916, assignee os-warren) · reason: the claiming session is unreachable. Its last output on this board was 5923825391 (2026-10-01T02:57Z), and get_session answers not found · destination: taken over below by the repo:hotcrm seat · 2026-10-02T21:42Z. Provenance: the maintainer's summons of this seat, verbatim /pm-dispatch hotcrm, in the chat of session_01ER8ntXZhYebyQ66aXWdjfT at 2026-10-02T21:13Z. The seat-taking record is on the seat post, 5961921626.

    Claim: PM loop round R69 (seat takeover of an in-flight card; review and landing window only, no new dev dispatch)
    Session: session_01ER8ntXZhYebyQ66aXWdjfT
    Account: hotlong (the seat's linked user as GET /user answers it; always the card's assignee)
    Branch: claude/issue-1832-retire-role-briefs
    Worktree: none (no new dev; the seat reviews the pushed head)
    Domain: repo:hotcrm (single-lane repo, no domain:* taxonomy)
    Seat: repo:hotcrm#1
    File surface: unchanged from 5923400916: .github/instructions/*.md (deleted), AGENTS.md, .github/tasks/*, .github/AGENT_GUIDE.md, test/docs-src-tree-paths.test.ts, test/docs-drift.test.ts, one .changeset/ file (stop on breach; explain in the report)
    Container & model: none, no dev is dispatched by this claim; dispatch-gates --tier --repo objectstack-ai/hotcrm answers "no path-derived mandate … the tier stays the PM's per-card judgment call"; the seat reviews at its default judgement tier
    Clause-②: no
    Thread-read: 5923400916
    Serial constraints cleared: no other open hotcrm PR touches AGENTS.md, .github/instructions/**, .github/tasks/** or the two test files (read via pulls/N/files: #1981, #1963, #1962, #1953, #1950, #1058); since the PR's base a228df19, origin/main touched none of the PR's files (only .changeset/ additions), and git merge-tree against 39ba05e2 is clean.

    Handover record


    Generated by Claude Code

  7. objectstack-fleet commented on Oct 2, 2026

    @objectstack-fleet
    Contributor

    ACCEPT: PR #1977 at 54c5bad3c4b2. The six role briefs are retired, and AGENTS.md is the one instruction set (ruling batch #142 item 4, B). repo:hotcrm seat, session_01ER8ntXZhYebyQ66aXWdjfT, 2026-10-02T21:44Z. ⚠️ Tier H (AGENTS.md), so the PR stays draft and the merge is the maintainer's click. Details are below the list.

    • Form: draft, base main. The first line is Fixes #1832, and it is the only closing keyword in the body.
    • Scope: 13 files, the claim's surface plus .github/AGENT_GUIDE.md. The dev declared that file under Acceptance notes, and it falls inside the dispatch's re-point clause. Nothing under content/docs/releases/, src/ or config.
    • Changeset: .changeset/retire-role-briefs.md has empty frontmatter. That is this lane's legal zero-release form.
    • CI: 9 of 9 check runs success on 54c5bad3, the PR's current head.sha, read at 2026-10-02T21:32Z. The seat did not re-run the dev's pnpm verify transcript.
    • Ruling conformance:
      1. The first commit, ffb40366, is the reading. It folds logic.md's two facts into AGENTS.md.
      2. The six briefs are deleted.
      3. AGENTS.md's governed-paths list drops .github/instructions/**.
      4. The .github/tasks/* references are re-pointed. This is the scope addition in 5825877235.
      5. In test/docs-src-tree-paths.test.ts, the removed .github/instructions/logic.md points its action example at packages/crm/src/ — a layout hotcrm does not have, and no gate covers that directory #1233 block guarded only .github/instructions/*.md. The rules that cover AGENTS.md (TREE_DOCS) are untouched. ⛔ Nothing is skipped or quarantined.
    • Spot readings of the folded claims, on origin/main 39ba05e2:
      • src/sales/objects/_hook-api.ts declares count: (q: HookCountQuery), HookQuery.top, and update: (doc: HookUpdateDoc, options: HookUpdateOptions).
      • test/action-sandbox.test.ts:889 iterates allHooks.
      • 'api.read' / 'api.write' appear at 10 sites under src/.
      • src/revenue/objects/quote.hook.ts:89 guards on ctx.user?.id.
    • Residual references: git grep '.github/instructions' on the PR head, excluding CHANGELOG.md, finds only the changeset and the test's one-line retirement note. Control: the same grep on origin/main finds 7 hits in 5 files.
    • Base drift: main moved from a228df19 to 39ba05e2 (17.5 → 17.6.0 upgrade, strict-validate cleanup, two docs PRs) and touched none of the PR's files. git merge-tree is clean, and the queue re-tests on merge_group.
    • Size: +25/−831 = 856 lines, under the 5,000-line threshold.
    • How this was accepted: the dispatching session's os-dev report never reached GitHub, because that session is gone. This is the direct-accept fallback, and all three conditions hold: the draft PR is green; the session is confirmed gone and has not pushed for 2 h or more; the report is absent. The PR body served as the report, checked against the tree.
    • Deviations: none beyond .github/AGENT_GUIDE.md, which the dev declared.

    Endgame (Tier H): needs-user-decision on the PR, the final 维护者速读 posted on the PR, and review requested from os-zhuang and hotlong. ⛔ The seat does not ready, enqueue or approve it. Once the maintainer merges it, the seat confirms #1832 closed and strips pm:dispatched.


    Generated by Claude Code

  8. objectstack-fleet commented on Oct 2, 2026

    @objectstack-fleet
    Contributor

    Correction to the takeover 5961945086. One of its stated reasons is not evidence, and the takeover stands without it. repo:hotcrm seat, session_01ER8ntXZhYebyQ66aXWdjfT, 2026-10-02T21:56Z.

    The Release line cited get_session answering not found for session_01X8U3asekbiC7yWoEPWR4Dg. That answer carries no information. Session handles are account-scoped, so a session another account created answers not found exactly as a session that never existed would (dispatch-runbook.md: 「该答案与从不存在不可区分,⛔ 永不读作死亡信号」). The open-round marker 5961921626 on the seat post carries the same misreading.

    What the takeover rests on is the board reading alone. The claiming session's last output was 5923825391 at 2026-10-01T02:57Z, about 42 h of silence on a card with an unreviewed PR. The takeover protocol takes over an unreachable claimant ⛔ without judging it dead. If that session is still alive and returns, its claim 5923400916 is the earlier one, and this seat hands the card back with everything read so far.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions