Skip to content

governed: tier the register — Tier H stays human/approved, Tier S (.claude/**) lands on a contract-tier review of record - #19144

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-19133-governed-tiers
Sep 18, 2026
Merged

os-zhuang merged 3 commits into
mainfrom
claude/issue-19133-governed-tiers

Conversation

@os-elon-musk

Copy link
Copy Markdown
Collaborator

Fixes #19133
Clause-②: no

Tiers the governed register. Membership does not move (every row still governs what it did; one hit still forks the whole PR; --test still exits 3 on every row). What moves is the LANDING each row waits for, carried as tier on the register row and derived per PR by one function that both scripts read.

  • Tier H(人合): docs/adr/** · docs/NORTH-STAR.md · skills/** · AGENTS.md · CLAUDE.md — the maintainer's hand, or an authorized APPROVED review by GOVERNED_APPROVERS and then the owning seat lands it. Unchanged.
  • Tier S(席内达档复核落地): the whole .claude/** tree (skills, agents, hooks, settings) — the owning seat lands it through the queue once the PR thread or its card carries a ## Contract review record for the PR's current head with Served-tier: CONTRACT_REVIEW_TIER and **VERDICT: PASS**, check-clause2-carriers.mjs --pair N reads 0 and every check is green. Exactly the fact-layer path, generalised to the tier; the post-merge audit and the director's 职责四 are the compensating control.

Ruling (verbatim, chat 2026-09-18): 「同意改规则。」 on the seat's proposal quoted in the card body, then the amendment 「我觉得这些我也没必要确认:.claude/settings.json、.claude/hooks/**」 — applied as the amendment comment on the card says (Tier H shrinks to the four surfaces; the whole .claude/** tree is Tier S; published skills/** unchanged).

维护者速读(草稿)

改了什么:受管面登记表分成两档。Tier H(法):AGENTS.md、CLAUDE.md、docs/adr/**、docs/NORTH-STAR.md、发布的 skills/**,照旧等你的手或授权批准。Tier S:整棵 .claude/**(skills、agents、hooks、settings),席内 CONTRACT_REVIEW_TIER 复核 PASS 记录在案、--pair 读 0、全绿,即由席位走队列落地;事后由受管合并审计抽查。队列守卫按登记表的档位放行或拒绝;--test 判词打印档位与该档的落地条件;AGENTS.md 第 14 条与 SKILL.md/契约复核/核心条款同步改写。

为什么改:你在聊天里说「一直让我点很浪费时间」并「同意改规则」。舰队自己的仪器由舰队按达档复核落地,你只需要确认真正的法。

风险与代价(含回滚):代价是 AI 可以在没有人闸的情况下改自己的操作规则(含 .claude/settings.json 权限集本身——修正评论已点名:自动模式分类器今天仍拒绝 AI 写它,实际写手仍是你的手,本次只免掉那一次批准点击)。补偿控制三件:PR 线程上的达档复核记录、落地后的受管合并审计(Tier S 无 PASS 记录即审计发现)、北极星「仪器为车队服务」评分。回滚:一个 PR,把六行登记表的 tier: GOVERNED_TIER_S 改回 GOVERNED_TIER_H,队列守卫即回到全人合;不需要回滚任何数据。

席位意见:(留空,由席位定稿)

你要做的:本 PR 含 AGENTS.md,属 Tier H——这是 Tier S 这一类的最后一次点击。审阅后给一个 APPROVED review(os-zhuang 或 hotlong),认领席落地。

Register — before / after

id glob before after
adr docs/adr/** governed, human merge / authorized approval Tier H
north-star docs/NORTH-STAR.md (not on the register) Tier H — new exact row; the file itself arrives with #19131's branch (25 lines, docs/NORTH-STAR.md); the predicate is path-only so landing order does not matter
claude-tree .claude/** governed; only .claude/skills/pm-dispatch/references/ landed on a record (REFERENCES_TIER_PREFIX in the queue guard) Tier S — the whole tree; the prefix constant is deleted
skills-catalog skills/** governed, human merge / authorized approval Tier H (unchanged; the seat did not propose moving it)
agents-md AGENTS.md governed Tier H
claude-md CLAUDE.md governed Tier H

Order pin: adr,claude-tree,skills-catalog,agents-md,claude-md → adr,north-star,claude-tree,skills-catalog,agents-md,claude-md. #18489's branch (claude/issue-18489-north-star-enforcement) carried no commits when this was written (its tip is the then-origin/main, 14a762f9f), so line identity with its row could not be measured; whichever lands second merges origin/main first, as the card says.

Exit codes: no new exit constant. Both tiers exit 3 on --test / --pr / --branch (pinned: exit-3-is-SHARED-by-both-tiers…). Every reader of that status asks "may a seat arm this on green alone?" and the answer is no for both; the tier is a second fact and travels in the verdict line and in --json ("tier": "H" | "S" | null), never in the status, so no $? reader learns a new number. Tier H keeps its wording word for word (⛔ GOVERNED — a human merge is the review record for this PR) plus one ⚖️ landing tier: H(人合) line; Tier S prints its own block naming the record-on-thread landing. The NOT-governed exit and wording are untouched.

Self-test floors — before / after (raised or re-keyed, never lowered)

scripts/pm/check-governed-merges.mjs (351 assertions now):

  • the governed predicate: the 2026-08-18 unified list, exactly 8 → 9 (all-five-surfaces-declared-in-order re-keyed to all-six-…; north-star-exact added; three North Star near-misses added to the near-miss list)
  • the dispatch-gates declaration (#9979) 8 → 9 (every-exact-root-row-declares-a-watch-hint re-keyed to separator-less exact rows; a-non-root-exact-row-carries-its-own-separator-and-declares-no-hint added)
  • new battery ⚖️ the two landing tiers (#19133, ruled 2026-09-18) floor 19; SELF_TEST_BATTERY_FLOOR 25 → 26
  • two head-line byte pins re-keyed (5 surfaces, repo-agnostic) → (6 surfaces, repo-agnostic)

scripts/pm/check-governed-queue-guard.mjs (261 cases now; 21 batteries unchanged):

  • ⭐ #18020: the references tier — a review of record, not an approval 40 → renamed ⭐ #18020 → #19133 Tier S: a review of record, not an approval 43 (the end-to-end pass for a .claude/agents/os-dev.md + .claude/settings.json PR on a valid record, and its lit control — the same PR with NO record is REFUSED)
  • the pull_request leg is an EARLY WARNING and never reddens 3 → 5 (the warning names Tier S and the record it waits for; names Tier H and the approval)
  • the replay fixtures: the three incidents this guard descends from 9 → 11 (the two .claude/** replays are Tier S today: judged on an ABSENT record they refuse unapproved as before; with NO record reading they refuse unreadable — never clear)
  • the prefix pin ⛔ the-tier-prefix-keeps-its-trailing-slash… re-keyed to ⛔ this-file-spells-NO-tier-prefix-Tier-S-is-the-register-rows-that-carry-S…

scripts/pm/check-governed-prose.mjs: floors unchanged (28 cases); PROSE_SURFACES[0].start anchor moved with the paragraph's first sentence. scripts/pm/check-clause2-carriers.mjs: +1 control (the cross-tool pin's fixture path is Tier S under the register), 942 cases.

Readers of the merges script (PM assumption 3 — every reader, and what changed)

  • scripts/pm/check-governed-queue-guard.mjs — the only ROUTER. Imports GOVERNED_TIER_H/S and governedTierFor from the register at module scope (the register was never mirrored there; the mirrors its docstring names are CONTRACT_REVIEW_LABEL and REVIEW_OF_RECORD_LOCATION, forced by the cycle with check-half-states.mjs). merge_group passes a Tier S PR on the record-of-record predicate, refuses a Tier H PR without an authorized approval as today; pull_request names the tier and what it waits for. TIER_RULES/TIER_REFERENCES/REFERENCES_TIER_PREFIX are gone; TIER_H/TIER_S re-export the register's values; governedTierFor is re-exported, not copied.
  • scripts/pm/check-clause2-carriers.mjs — its self-test built a fixture path from REFERENCES_TIER_PREFIX; re-keyed to a Tier S path literal with a register control. Not a router.
  • scripts/pm/check-governed-prose.mjs — reads the SET of globs; set-based, tiers are attributes (PM assumption 2 confirmed); header note added; not extended to parse tiers.
  • scripts/pm/dispatch-gates.mjs — reads the merges SOURCE for path literals (extractWatchHints), never its exit codes; docs/NORTH-STAR.md is a path literal so a North Star card now derives this gate. No meaning change for Tier H.
  • scripts/pm/check-half-states.mjs — H43/H48 load governedPathsIn and GOVERNED_APPROVERS (membership only; tier-agnostic). Unchanged.
  • scripts/pm/ci-failure.mjs (proxyRearmPlan), scripts/check-skills-token-ratchet.mjs (generatedExceptionFor) — untouched exports.
  • scripts/invoked-as.mjs, scripts/pm/check-skill-line-ratchet.mjs, .github/workflows/lint.yml — comments citing "exit 3 = GOVERNED"; still true for both tiers.
  • .github/workflows/governed-surface-guard.yml — invocation only; not edited.
  • Seat prose reading the printed verdict (landing-operations.md :26, state-machine.md :9, lanes/skills.md :18) — the line now names the tier.

Reader tests, one per tier

  • A seat holding a PASS record on a .claude/agents/os-dev.md PR: --test .claude/agents/os-dev.md prints ⛔ GOVERNED — Tier S(席内达档复核落地): …, exit 3, --json says "tier": "S". The seat runs the three landing checks (record on the current head, --pair 0, every check green), flips ready and arms auto-merge; the merge_group guard reads the record (stands) and prints ✅ CLEARED — … Tier S … satisfied 1 of them; the post-merge audit lists the landing. Without the record the same guard prints ⛔ REFUSED with remedy 3 (post the record on the CURRENT head and re-queue).
  • A seat holding a PASS record on an AGENTS.md PR: --test AGENTS.md prints ⛔ GOVERNED — a human merge is the review record … ⚖️ landing tier: H(人合), exit 3, "tier": "H". The record changes nothing: the seat leaves the PR at the four-piece terminal (draft, request review from both authorized accounts, the 速读 comment, the round report line). Enqueued anyway, the merge_group guard refuses unapproved — the record key is never even read for a Tier H entry; only a GOVERNED_APPROVERS APPROVED review lifts, then the owning seat lands.

Ceilings per file (all at headroom 0, every touched line within the 120-byte cap)

Gates (derived with node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack at d3bb7e0c3; every command run, exit captured redirect-then-$?; --ran reconciliation below)

Every derived command ran green (exit 0) at head d3bb7e0c3, one detached run's exit code pending (below). Highlights, verdict lines as printed:

  • pnpm check:pm-governed-merges :: exit 0 — ✓ check-governed-merges --self-test: 351 assertions …
  • node scripts/pm/check-governed-queue-guard.mjs --self-test :: exit 0 — ✓ check-governed-queue-guard self-test: 261 cases pass …
  • pnpm check:pm-governed-prose :: exit 0 — ✓ check-governed-prose: 2 instruction surface(s) name all 6 registered governed surfaces (docs/adr/** · docs/NORTH-STAR.md · .claude/** · skills/** · AGENTS.md · CLAUDE.md) and claim no others.
  • pnpm check:pm-skill-ratchet :: exit 0 — AGENTS.md 1099 / 1099, SKILL.md 812 / 812, contract-review.md 60 / 60, core-rules.md 151 / 151 (all headroom 0)
  • pnpm check:pm-skill-id-lint :: exit 0 — 27 file(s) clean · pnpm check:skill-frame-sync :: exit 0 · pnpm check:nul-bytes :: exit 0 (8965 files)
  • pnpm check:pm-clause2-carriers :: exit 0 — 942 cases · pnpm check:pm-half-states :: exit 0 — 5043 cases
  • pnpm --filter @objectstack/lint run check:doc-formula-expressions :: exit 0 — after bash scripts/pm/os-verify-lock.sh -c "pnpm --workspace-concurrency=2 --filter '@objectstack/lint...' build" (VERDICT command-exit 0 · held the lock 131s · waited 0s)
  • the remaining 40 derived scripts/check-* / pnpm check:* families :: exit 0 each (full COMMAND :: exit CODE record in the report comment on skills(governed): narrow the human-merge floor to the law — Tier H stays human/approved (AGENTS.md · CLAUDE.md · docs/adr/** · docs/NORTH-STAR.md · .claude/settings.json · .claude/hooks/**); Tier S (.claude/skills/** · .claude/agents/**) lands on the seat's CONTRACT_REVIEW_TIER PASS + post-merge audit #19133)
  • pnpm check:pm-dispatch-gates — exceeds the foreground cap, run detached: verdict lines read ✓ check:pm-dispatch-gates --self-test: the exit contract holds in all three directions. and ✓ dispatch-gates self-test: 1849 cases pass. (654.7 s); the detached start captured no exit code, so a second detached run with exit capture is in flight and its :: exit CODE line lands in the report comment.

--ran reconciliation (node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran RECORD): 50 derived, 49 run, 0 NOT-MEASURED, 1 UNRUN — the one UNRUN is pnpm check:pm-dispatch-gates above, pending its captured exit; the 50/50 reading follows in the report comment.

Acceptance commands from the card: --test .claude/skills/pm-dispatch/SKILL.md prints ⛔ GOVERNED — Tier S(席内达档复核落地): … (exit 3); --test AGENTS.md and --test docs/NORTH-STAR.md print ⛔ GOVERNED — a human merge is the review record … ⚖️ landing tier: H(人合) (exit 3); --test .claude/settings.json .claude/hooks/guard-main-checkout.sh prints Tier S (exit 3); --test scripts/pm/check-governed-merges.mjs prints ✅ NOT governed (exit 0); --test --json .claude/agents/os-dev.md carries "tier": "S".

Not run locally, CI-owned: pnpm lint (repo-wide eslint) and the artifact-roster / wide-population families the reconciliation names as outside this link.

Acceptance notes


Generated by Claude Code

os-dev and others added 2 commits September 18, 2026 22:44
… S (.claude/**) lands on a contract-tier review of record

WIP: register + queue guard + prose + AGENTS.md PD #14 + SKILL.md/contract-review/core-rules twins.

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
…ENT record, six-surface head pins, core-rules line under the byte cap

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF

Copy link
Copy Markdown
Collaborator Author

维护者速读(终稿)· skills 席 · 2026-09-18T23:17Z

这个 PR 做什么:把受管面登记表分成两档,按您 2026-09-18 的裁决「同意改规则。」和补充「我觉得这些我也没必要确认:.claude/settings.json、.claude/hooks/**」。Tier H(法,还是要您的手或一个授权 approve):AGENTS.md、CLAUDE.md、docs/adr/**、docs/NORTH-STAR.md、发布的 skills/**。Tier S(席内达档复核落地):整个 .claude/**(skills、agents、hooks、settings)——席位出一份契约档 PASS 复核记录、--pair 为 0、检查全绿,就自己走队列落地,不用您点。成员资格没变:每条路径还是受管、一条命中仍整 PR 分叉;变的只是每条等什么落地。登记表每行带 tier,判定函数只有一处(check-governed-merges.mjs),队列守卫直接引用,没有第二份表。

一个您已接受、我再说一次的风险:.claude/settings.json 是权限集本身,归 Tier S 后由席位自己的复核记录落地,没有您的点击。兜底是合并后审计(每次 Tier S 合并都列出它的记录,没记录就是发现)和总监席的抽查。

顺序:它排在 #19142(北极星写进规则层)之后——两个 PR 都往登记表加 docs/NORTH-STAR.md 那一行、都改 PD #14 那一段。#19142 合了以后这个 PR 再合一次 main 解冲突,我在新 head 上重出记录再落地;您的 approve 给一次就够(裁决 C)。

它落地后我马上做的:#18903 · #19021 · #19033 · #19038 · #19039 五个 Tier S 草稿 PR 已有 PASS 记录,直接落地,不再让您点。遗留:os-dev.md 两行和 landing-operations.md 两行还写着旧的「事实层 = references/」,已立 #19146(p3)在它之后修。

验收:ACCEPT 在 #19133;记录 5737334942;门禁全绿(棘轮 812 / 60 / 151 / 1099 不变、id-lint、governed-prose 6/6、clause2 942、队列守卫自测 261、六条 --test 分档读数全对);CI 21 成功 · 11 跳过 · 2 在跑、0 红(2026-09-18T23:16Z);Fixes #19133、Clause-②: no。

请您做的一件事:先 approve #19142,再 approve 这个(os-zhuang 或 hotlong 任一);落地都由我做。


Generated by Claude Code

@os-zhuang
os-zhuang marked this pull request as ready for review September 18, 2026 23:34
…the north-star row keeps main's position with its tier; PD #14 keeps the tiered paragraph

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
@os-zhuang
os-zhuang merged commit 1047fe1 into main Sep 18, 2026
30 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-19133-governed-tiers branch September 18, 2026 23:48
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Sep 28, 2026
…-tier boundary (objectstack-ai#19379)

Part of objectstack-ai#19146

Clause-②: no

Two carriers of the governed-tier rule still stated the 2026-09-13
boundary (Tier S / "fact layer" = only
`.claude/skills/pm-dispatch/references/**`) that objectstack-ai#19133 (2026-09-18)
superseded. objectstack-ai#19133's ruling, verbatim and untranslated: maintainer
「同意改规则。」 on the skills seat's proposal, plus the amendment that folded
`.claude/settings.json` and `.claude/hooks/**` in too: 「我觉得这些我也没必要确认」.
Tier S is now the whole `.claude/**` tree.

Current, correct source of truth (unchanged by this PR):
- `scripts/pm/check-governed-merges.mjs` register row `{ id:
'claude-tree', prefix: '.claude/', glob: '.claude/**', tier:
GOVERNED_TIER_S, … }`, pinned by self-test case
`skills-agents-and-the-fact-layer-are-Tier-S`.
- `.claude/skills/pm-dispatch/SKILL.md:625-626`: 「受管面两层:Tier H(规则层)=
`AGENTS.md`+`CLAUDE.md`+`docs/adr/**`+`docs/NORTH-STAR.md`+发布
`skills/**`。」「Tier S = `.claude/**` 全树;Tier H 四件套等人批;Tier S 经席内达档复核 PASS
在案后 ready → 入队。」

## What was stale

**`.claude/skills/pm-dispatch/references/landing-operations.md:27-28`**

Before:
```
- 受管路径全在本技能 `references/` 者事实层:席内达档复核过落地前检三条即转正式入队。
- 其余为规则层:四件套留 draft 等人批,⛔ 不翻正式不入队;获授权批准后认领席落地。
```

After:
```
- Tier S(`.claude/**` 全树)者:席内达档复核过落地前检三条即转正式入队。
- Tier H(其余受管面)者:四件套留 draft 等人批,⛔ 不翻正式不入队;获授权批准后认领席落地。
```

Line count and byte ceiling unchanged (69/69, both lines within the
120-byte cap — `check:pm-skill-ratchet` verified).

**`scripts/pm/check-governed-queue-guard.mjs`, the "THIRD leg" header
(~268-294)**

It reproduced the 2026-09-13 boundary and concluded: "Every other
governed path is the rules layer and keeps the predicate above
byte-for-byte" — false since objectstack-ai#19133, and self-contradicting the same
file's own later "the landing TIER" section, which already records that
`REFERENCES_TIER_PREFIX` "is gone".

Fix: the quoted 2026-09-13 ruling is kept, untranslated, as the ruling
that STARTED this leg (history is load-bearing — a reader who finds that
text must see why it no longer governs). A new paragraph marks it
SUPERSEDED by objectstack-ai#19133 (cited with date, reusing this same file's own
existing verbatim quote of the amendment for consistency) and points at
`governedTierFor` / the register / `node
scripts/pm/check-governed-merges.mjs --test <paths>` instead of a prefix
to remember. The concluding sentence now reads "Every governed path
outside Tier S is Tier H, the rules layer, and keeps the predicate above
byte-for-byte."

No behavior changed: `GOVERNED_SURFACES`, `governedTierFor`,
`landingTierOf`, every tier constant and every self-test assertion's
expected value are untouched — only the two stale prose passages.

## Verification before editing

- Read objectstack-ai#19133 on GitHub directly (the tracking card/comments):
maintainer ruling 「同意改规则。」 plus the amendment 「我觉得这些我也没必要确认」, landed by
PR objectstack-ai#19144 (merged `1047fe101`), matches this PR's premise exactly.
- Read the register row, its self-test case, and `SKILL.md:625-626` —
all current and correct, confirmed unedited.
- Read both stale passages in full context before editing.

## Tier verdict on this PR's final file list

```
node scripts/pm/check-governed-merges.mjs --test .claude/skills/pm-dispatch/references/landing-operations.md scripts/pm/check-governed-queue-guard.mjs
```
→ `GOVERNED — Tier S`, exit 3. `landing-operations.md` hits the
`.claude/**` register row; `check-governed-queue-guard.mjs` is not
itself a registered surface (1 of 2 paths governed). Per Prime Directive
objectstack-ai#14, this PR lands on the owning seat's Tier S contract-tier review of
record — no seat approves it, and no maintainer click is waited for.

## Gates run (exit code captured before any pipe)

- `node scripts/pm/check-governed-queue-guard.mjs --self-test` — exit 0
(296 cases pass)
- `node scripts/pm/check-governed-merges.mjs --self-test` — exit 0 (435
assertions)
- `pnpm check:pm-skill-ratchet` — exit 0 (landing-operations.md 69/69,
headroom 0, unchanged)
- `pnpm check:pm-skill-id-lint` — exit 0 (27 files clean)
- `pnpm check:pm-governed-prose` — exit 0 (names all 6 registered
surfaces)
- `pnpm check:nul-bytes` — exit 0
- `npx eslint scripts/pm/check-governed-queue-guard.mjs` — exit 0
- `node --check scripts/pm/check-governed-queue-guard.mjs` — exit 0

## Changeset

`skip-changeset` — no `packages/*` touched; neither `.claude/skills/**`
nor `scripts/pm/**` ships in any package's `files[]` (same as precedent
PRs objectstack-ai#19144 and objectstack-ai#19021).

## On the card

This PR is filed as **Part of objectstack-ai#19146**, not a new card: objectstack-ai#19146 ("skills:
re-key the three 事实层 = references/ spellings the Tier S ruling leaves
false") was already open, filed by the seat that landed PR objectstack-ai#19144, and
its item 2 is exactly `landing-operations.md:27-28`. Creating a new
duplicate card would have contradicted this repo's own
duplicate-avoidance practice, so none was created. objectstack-ai#19146's other items
— `.claude/agents/os-dev.md:286-287`, `check-half-states.mjs` H48 and
`check-half-states.mjs` H43 — are **not** touched by this PR and remain
open on that card; neither is `SKILL.md:608`'s own `事实层` wording (added
to objectstack-ai#19146 by its own addendum comment). H43 is the newest of them: it
had lived only in card comment 5750573385 and is enumerated on the card
body as item 4 by this rework. It is left here deliberately — H43 is
missing LOGIC in a non-governed instrument (a LAZY `governedTierFor`
load, because that row travels to sibling repos, plus one `pnpm
check:pm-half-states` self-test case), which is the same change class as
H48 and rides with it in ONE half-states PR rather than under a
docs-only Tier S record. The at-tier review of record (`5751616940`)
ruled this PR NOT incomplete for leaving it there. This PR additionally
fixes `scripts/pm/check-governed-queue-guard.mjs`'s self-contradiction,
which is not named in objectstack-ai#19146 at all.

## Note on the dispatching brief

The brief that generated this PR stated "this repair has no card yet."
That is not accurate: objectstack-ai#19146 already existed (filed 2026-09-18, still
open) covering part of this exact repair. Everything else in the brief —
the ruling text, the register row, the self-test name,
`SKILL.md:625-626`, and both stale passages — verified exactly as stated
on direct reading.

## Rework after the at-tier contract review (record `5751616940` — FAIL)

Head `fa628d0b36` → `71216fcff6`, one commit on the same branch (⛔ no
rebase, no amend, no force-push — the review record is anchored to this
branch's history). Both defects are TEXT: ⛔ no tier constant, no
`GOVERNED_SURFACES` row, no `governedTierFor`, no `landingTierOf` and no
self-test expected value moved. Self-test case counts are unchanged at
296 / 435.

**1. `landing-operations.md:27` — the PR-level ALL quantifier is
restored.**

The line shipped as 「- Tier S(`.claude/**` 全树)者:…」, which names the
SURFACE. Its own predecessor (「受管路径全在本技能 `references/` 者事实层」), this
repair's prescribed wording on the card, and the sibling
`contract-review.md:46` (「受管路径全在 Tier S 面(`.claude/**`)者」) all carry the
quantifier. Without it, lines 27 and 28 partition governed SURFACES
rather than pull requests — so a mixed diff (a `.claude/**` path plus
`AGENTS.md`, Tier H by the register's ALL-not-ANY rule) matched both
lines with no tiebreak on the page.

```diff
-- Tier S(`.claude/**` 全树)者:席内达档复核过落地前检三条即转正式入队。
+- 受管路径全在 `.claude/**` 者 Tier S:席内达档复核过落地前检三条即转正式入队。
```

Re-measured here, not taken on trust: 93 B → 105 B against the 120 B
cap, file 69/69 lines with headroom 0 (`check:pm-skill-ratchet` exit 0
names the file at 69/ceiling 69).

**2. `check-governed-queue-guard.mjs:4442-4443` — the `--self-test`
SUCCESS line is re-keyed.**

The docblock repair in the first commit left the one instance seats
actually read: the SUCCESS line printed on EVERY run (it is in the
review's own capture) still stated the superseded objectstack-ai#18020 population,
while the battery at `:3949-3950` asserts `⛔
the-old-references-boundary-is-GONE`. Landed 2026-09-13 in objectstack-ai#18036 and
untouched by objectstack-ai#19144 — present at merge-base and at the reviewed head,
reproduced here before the edit.

```diff
-      'the boundary a label reader cannot cross — and the objectstack-ai#18020 references TIER: a governed diff whose governed ' +
-      'paths all lie under the one ruled prefix lands on the skills seat\'s review of record instead of an ' +
+      'the boundary a label reader cannot cross — and the objectstack-ai#18020 references TIER, re-keyed to Tier S by objectstack-ai#19133: a ' +
+      'governed diff whose governed paths are ALL Tier S — the register\'s `.claude/**` row, asked through ' +
+      '`governedTierFor`, never a prefix repeated here — lands on the skills seat\'s review of record instead of an ' +
```

History stays (the `objectstack-ai#18020` naming), exactly as the docblock keeps its
quoted ruling; only the POPULATION is re-keyed. Proof it is gone from
the PRINTED output, not merely from the source: `--self-test` at the new
head prints `the one ruled prefix` 0 times and the re-keyed sentence
once.

### Still stating the superseded boundary — reported, ⛔ deliberately not
pulled in

The review lists these as live and OUT of this PR's scope, and this
rework leaves them exactly as it found them:
`.claude/agents/os-dev.md:286-287` (this card's item 1) and
`SKILL.md:608`'s 「⛔ 无事实层例外」 (a card addendum, vocabulary only — the rule
itself stays true). Naming-only uses of "the references tier" as this
leg's NAME (queue-guard `:268`, `:358`, `:442`, `:452`, `:646`, `:736`,
code comments `:1420` / `:1546` / `:2261` / `:2470` / `:2560`, and
`check-clause2-carriers.mjs:8635`) are an optional tidy and were left
alone: widening the diff of a docs-only record to sweep names is not
what the FAIL asked for.

### Tier verdict on the FINAL file list

```
node scripts/pm/check-governed-merges.mjs --test .claude/skills/pm-dispatch/references/landing-operations.md scripts/pm/check-governed-queue-guard.mjs
```

→ `⛔ GOVERNED — Tier S(席内达档复核落地)`, exit 3; 1 of 2 paths on the register
(`.claude/**` ×1 — `landing-operations.md`;
`scripts/pm/check-governed-queue-guard.mjs` is not a registered
surface). File list unchanged from the reviewed head, so the tier is
unchanged. Per Prime Directive objectstack-ai#14 this lands on the at-tier review of
record — ⛔ no seat approves it and no maintainer click is owed.

### Gates at the new head (exit code captured BEFORE any pipe)

The brief's minimum, plus every family `node
scripts/pm/dispatch-gates.mjs --commands` derives for this change set —
38 commands, 37 at exit 0:

- `check-governed-queue-guard.mjs --self-test` — exit 0, 296 cases
(unchanged)
- `check-governed-merges.mjs --self-test` — exit 0, 435 assertions
(unchanged)
- `check:pm-skill-ratchet` exit 0 (69/69, headroom 0) ·
`check:pm-skill-id-lint` exit 0 (27 clean) · `check:pm-governed-prose`
exit 0 (6/6 surfaces, 28 self-test cases) · `check:skill-frame-sync`
exit 0 · `check:nul-bytes` exit 0 (9053 files, no raw control bytes)
- `node --check` exit 0 · `npx eslint
scripts/pm/check-governed-queue-guard.mjs` exit 0 (1 file linted, 0
errors, 0 warnings, read from `--format json`)
- `check:pm-dispatch-gates`, `check:pm-governed-merges`,
`check:ratchet-remedy-authority`, `check:doc-authoring`,
`check:cross-package-test-inputs`, `check-declaration-mirrors`,
`check-scripts-symbol-anchors`, `check-self-test-wired`,
`check-self-test-workflow-commands`, `check-comment-mask-corpus` and the
rest of the derived list — all exit 0
- ⊘ NOT MEASURED — `pnpm --filter @objectstack/lint run
check:doc-formula-expressions` exit 3, PREREQUISITE NOT MET
(`@objectstack/formula` and `@objectstack/lint` unbuilt in this
worktree). Exit 3 is this repo's NOT-MEASURED code, ⛔ not a finding; the
family's population is docs formula expressions, disjoint from this
diff's two paths, and CI runs it against a built tree.

⚠️ `dispatch-gates.mjs` prints a STALE TREE warning: this branch is ≥55
commits behind `origin/main` and 15 files the derivation reads changed
across that range. The gate list above is therefore derived from this
branch's tree, which is what the review record is anchored to; ⛔ it was
not refreshed by a rebase. CI on the merge group derives from the merged
tree.

### ⚠️ `check-clause2-carriers.mjs --pair 19379` reads 2 (UNJUDGED) —
measured, and it is the BRANCH NAME

Reproduced at the new head: `PM_SWEEP_REPO=objectstack-ai/objectstack
node scripts/pm/check-clause2-carriers.mjs --pair 19379` → exit 2, 「the
card's NEWEST claim comment (5754245926) matches the claim marker but
its `Branch:` directive parses to ZERO branches」. The stored line 2
really is `` Branch: `claude/pm-superseded-references-tier` `` on a line
of its own, so the printed remedy — "name the branch on a `Branch:` line
of its OWN" — is already satisfied and cannot clear it.

The cause is not the regex named in the dispatching brief.
`BRANCH_TOKEN` (`check-clause2-carriers.mjs:3278`) reads the
`Implemented-by:` VALUE of a review record; it never sees a claim's
`Branch:` directive. That directive is read by the sibling
`check-half-states.mjs:5407` `claimedBranches`, through
`CLAIM_BRANCH_SHAPE` (`:5358`):

```
/claude\/issue-\d+-[A-Za-z0-9][A-Za-z0-9._-]*/g
```

which REQUIRES a literal `issue-` plus digits segment. Measured on the
real stored comment body and two controls:

| input | `claimedBranches()` |
| --- | --- |
| the live comment `5754245926`, as stored | `[]` |
| the same comment, branch swapped to
`claude/issue-19146-superseded-references-tier` |
`["claude/issue-19146-superseded-references-tier"]` |
| `Branch: `claude/issue-abc-slug`` (no digits) | `[]` |

Only the branch NAME differs across those rows, so the marker, the
backticks, the line position and the directive shape are all fine.
`claimGovernance` on that one-comment thread returns `governing: null`
with `malformed: { id: 5754245926 }` — which `cardDeclaration` turns
into `claim-branch-unparsed`, i.e. exit 2.

The narrow shape is DELIBERATE where it was written
(`CLAIM_BRANCH_SHAPE`'s own docblock: a `Branch:` line naming some other
shape "is deliberately left unmatched, which puts the card out of this
row's scope entirely" — under-reporting beats manufacturing findings out
of typos). The consequence in THIS reader is not out-of-scope, though:
Prime Directive objectstack-ai#14 makes `--pair` at 0 part of the Tier S landing
predicate, so a Tier S PR on a branch without an `issue-`digits segment
cannot satisfy it by any act of the claiming seat short of renaming the
branch — which would strand this review record. ⛔ Not repaired here:
`check-clause2-carriers.mjs` is ⛔ out of this PR's scope and the branch
is ⛔ not renamed. Reported for the seat.

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01AmH9bKvGoLjiY86Q4Z3og2

---
_Generated by [Claude
Code](https://claude.ai/code/session_01AmH9bKvGoLjiY86Q4Z3og2)_

---
_Generated by [Claude Code](https://claude.ai/code)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/l skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants