governed: tier the register — Tier H stays human/approved, Tier S (.claude/**) lands on a contract-tier review of record - #19144
Conversation
… S (.claude/**) lands on a contract-tier review of record WIP: register + queue guard + prose + AGENTS.md PD #14 + SKILL.md/contract-review/core-rules twins. Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
…ENT record, six-surface head pins, core-rules line under the byte cap Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
维护者速读(终稿)· skills 席 · 2026-09-18T23:17Z这个 PR 做什么:把受管面登记表分成两档,按您 2026-09-18 的裁决「同意改规则。」和补充「我觉得这些我也没必要确认:.claude/settings.json、.claude/hooks/**」。Tier H(法,还是要您的手或一个授权 approve): 一个您已接受、我再说一次的风险: 顺序:它排在 #19142(北极星写进规则层)之后——两个 PR 都往登记表加 它落地后我马上做的:#18903 · #19021 · #19033 · #19038 · #19039 五个 Tier S 草稿 PR 已有 PASS 记录,直接落地,不再让您点。遗留:os-dev.md 两行和 landing-operations.md 两行还写着旧的「事实层 = references/」,已立 #19146(p3)在它之后修。 验收:ACCEPT 在 #19133;记录 5737334942;门禁全绿(棘轮 812 / 60 / 151 / 1099 不变、id-lint、governed-prose 6/6、clause2 942、队列守卫自测 261、六条 请您做的一件事:先 approve #19142,再 approve 这个(os-zhuang 或 hotlong 任一);落地都由我做。 Generated by Claude Code |
…the north-star row keeps main's position with its tier; PD #14 keeps the tiered paragraph Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BTeBejoPUvRHN8WdAJC6oF
…-tier boundary (objectstack-ai#19379) Part of objectstack-ai#19146 Clause-②: no Two carriers of the governed-tier rule still stated the 2026-09-13 boundary (Tier S / "fact layer" = only `.claude/skills/pm-dispatch/references/**`) that objectstack-ai#19133 (2026-09-18) superseded. objectstack-ai#19133's ruling, verbatim and untranslated: maintainer 「同意改规则。」 on the skills seat's proposal, plus the amendment that folded `.claude/settings.json` and `.claude/hooks/**` in too: 「我觉得这些我也没必要确认」. Tier S is now the whole `.claude/**` tree. Current, correct source of truth (unchanged by this PR): - `scripts/pm/check-governed-merges.mjs` register row `{ id: 'claude-tree', prefix: '.claude/', glob: '.claude/**', tier: GOVERNED_TIER_S, … }`, pinned by self-test case `skills-agents-and-the-fact-layer-are-Tier-S`. - `.claude/skills/pm-dispatch/SKILL.md:625-626`: 「受管面两层:Tier H(规则层)= `AGENTS.md`+`CLAUDE.md`+`docs/adr/**`+`docs/NORTH-STAR.md`+发布 `skills/**`。」「Tier S = `.claude/**` 全树;Tier H 四件套等人批;Tier S 经席内达档复核 PASS 在案后 ready → 入队。」 ## What was stale **`.claude/skills/pm-dispatch/references/landing-operations.md:27-28`** Before: ``` - 受管路径全在本技能 `references/` 者事实层:席内达档复核过落地前检三条即转正式入队。 - 其余为规则层:四件套留 draft 等人批,⛔ 不翻正式不入队;获授权批准后认领席落地。 ``` After: ``` - Tier S(`.claude/**` 全树)者:席内达档复核过落地前检三条即转正式入队。 - Tier H(其余受管面)者:四件套留 draft 等人批,⛔ 不翻正式不入队;获授权批准后认领席落地。 ``` Line count and byte ceiling unchanged (69/69, both lines within the 120-byte cap — `check:pm-skill-ratchet` verified). **`scripts/pm/check-governed-queue-guard.mjs`, the "THIRD leg" header (~268-294)** It reproduced the 2026-09-13 boundary and concluded: "Every other governed path is the rules layer and keeps the predicate above byte-for-byte" — false since objectstack-ai#19133, and self-contradicting the same file's own later "the landing TIER" section, which already records that `REFERENCES_TIER_PREFIX` "is gone". Fix: the quoted 2026-09-13 ruling is kept, untranslated, as the ruling that STARTED this leg (history is load-bearing — a reader who finds that text must see why it no longer governs). A new paragraph marks it SUPERSEDED by objectstack-ai#19133 (cited with date, reusing this same file's own existing verbatim quote of the amendment for consistency) and points at `governedTierFor` / the register / `node scripts/pm/check-governed-merges.mjs --test <paths>` instead of a prefix to remember. The concluding sentence now reads "Every governed path outside Tier S is Tier H, the rules layer, and keeps the predicate above byte-for-byte." No behavior changed: `GOVERNED_SURFACES`, `governedTierFor`, `landingTierOf`, every tier constant and every self-test assertion's expected value are untouched — only the two stale prose passages. ## Verification before editing - Read objectstack-ai#19133 on GitHub directly (the tracking card/comments): maintainer ruling 「同意改规则。」 plus the amendment 「我觉得这些我也没必要确认」, landed by PR objectstack-ai#19144 (merged `1047fe101`), matches this PR's premise exactly. - Read the register row, its self-test case, and `SKILL.md:625-626` — all current and correct, confirmed unedited. - Read both stale passages in full context before editing. ## Tier verdict on this PR's final file list ``` node scripts/pm/check-governed-merges.mjs --test .claude/skills/pm-dispatch/references/landing-operations.md scripts/pm/check-governed-queue-guard.mjs ``` → `GOVERNED — Tier S`, exit 3. `landing-operations.md` hits the `.claude/**` register row; `check-governed-queue-guard.mjs` is not itself a registered surface (1 of 2 paths governed). Per Prime Directive objectstack-ai#14, this PR lands on the owning seat's Tier S contract-tier review of record — no seat approves it, and no maintainer click is waited for. ## Gates run (exit code captured before any pipe) - `node scripts/pm/check-governed-queue-guard.mjs --self-test` — exit 0 (296 cases pass) - `node scripts/pm/check-governed-merges.mjs --self-test` — exit 0 (435 assertions) - `pnpm check:pm-skill-ratchet` — exit 0 (landing-operations.md 69/69, headroom 0, unchanged) - `pnpm check:pm-skill-id-lint` — exit 0 (27 files clean) - `pnpm check:pm-governed-prose` — exit 0 (names all 6 registered surfaces) - `pnpm check:nul-bytes` — exit 0 - `npx eslint scripts/pm/check-governed-queue-guard.mjs` — exit 0 - `node --check scripts/pm/check-governed-queue-guard.mjs` — exit 0 ## Changeset `skip-changeset` — no `packages/*` touched; neither `.claude/skills/**` nor `scripts/pm/**` ships in any package's `files[]` (same as precedent PRs objectstack-ai#19144 and objectstack-ai#19021). ## On the card This PR is filed as **Part of objectstack-ai#19146**, not a new card: objectstack-ai#19146 ("skills: re-key the three 事实层 = references/ spellings the Tier S ruling leaves false") was already open, filed by the seat that landed PR objectstack-ai#19144, and its item 2 is exactly `landing-operations.md:27-28`. Creating a new duplicate card would have contradicted this repo's own duplicate-avoidance practice, so none was created. objectstack-ai#19146's other items — `.claude/agents/os-dev.md:286-287`, `check-half-states.mjs` H48 and `check-half-states.mjs` H43 — are **not** touched by this PR and remain open on that card; neither is `SKILL.md:608`'s own `事实层` wording (added to objectstack-ai#19146 by its own addendum comment). H43 is the newest of them: it had lived only in card comment 5750573385 and is enumerated on the card body as item 4 by this rework. It is left here deliberately — H43 is missing LOGIC in a non-governed instrument (a LAZY `governedTierFor` load, because that row travels to sibling repos, plus one `pnpm check:pm-half-states` self-test case), which is the same change class as H48 and rides with it in ONE half-states PR rather than under a docs-only Tier S record. The at-tier review of record (`5751616940`) ruled this PR NOT incomplete for leaving it there. This PR additionally fixes `scripts/pm/check-governed-queue-guard.mjs`'s self-contradiction, which is not named in objectstack-ai#19146 at all. ## Note on the dispatching brief The brief that generated this PR stated "this repair has no card yet." That is not accurate: objectstack-ai#19146 already existed (filed 2026-09-18, still open) covering part of this exact repair. Everything else in the brief — the ruling text, the register row, the self-test name, `SKILL.md:625-626`, and both stale passages — verified exactly as stated on direct reading. ## Rework after the at-tier contract review (record `5751616940` — FAIL) Head `fa628d0b36` → `71216fcff6`, one commit on the same branch (⛔ no rebase, no amend, no force-push — the review record is anchored to this branch's history). Both defects are TEXT: ⛔ no tier constant, no `GOVERNED_SURFACES` row, no `governedTierFor`, no `landingTierOf` and no self-test expected value moved. Self-test case counts are unchanged at 296 / 435. **1. `landing-operations.md:27` — the PR-level ALL quantifier is restored.** The line shipped as 「- Tier S(`.claude/**` 全树)者:…」, which names the SURFACE. Its own predecessor (「受管路径全在本技能 `references/` 者事实层」), this repair's prescribed wording on the card, and the sibling `contract-review.md:46` (「受管路径全在 Tier S 面(`.claude/**`)者」) all carry the quantifier. Without it, lines 27 and 28 partition governed SURFACES rather than pull requests — so a mixed diff (a `.claude/**` path plus `AGENTS.md`, Tier H by the register's ALL-not-ANY rule) matched both lines with no tiebreak on the page. ```diff -- Tier S(`.claude/**` 全树)者:席内达档复核过落地前检三条即转正式入队。 +- 受管路径全在 `.claude/**` 者 Tier S:席内达档复核过落地前检三条即转正式入队。 ``` Re-measured here, not taken on trust: 93 B → 105 B against the 120 B cap, file 69/69 lines with headroom 0 (`check:pm-skill-ratchet` exit 0 names the file at 69/ceiling 69). **2. `check-governed-queue-guard.mjs:4442-4443` — the `--self-test` SUCCESS line is re-keyed.** The docblock repair in the first commit left the one instance seats actually read: the SUCCESS line printed on EVERY run (it is in the review's own capture) still stated the superseded objectstack-ai#18020 population, while the battery at `:3949-3950` asserts `⛔ the-old-references-boundary-is-GONE`. Landed 2026-09-13 in objectstack-ai#18036 and untouched by objectstack-ai#19144 — present at merge-base and at the reviewed head, reproduced here before the edit. ```diff - 'the boundary a label reader cannot cross — and the objectstack-ai#18020 references TIER: a governed diff whose governed ' + - 'paths all lie under the one ruled prefix lands on the skills seat\'s review of record instead of an ' + + 'the boundary a label reader cannot cross — and the objectstack-ai#18020 references TIER, re-keyed to Tier S by objectstack-ai#19133: a ' + + 'governed diff whose governed paths are ALL Tier S — the register\'s `.claude/**` row, asked through ' + + '`governedTierFor`, never a prefix repeated here — lands on the skills seat\'s review of record instead of an ' + ``` History stays (the `objectstack-ai#18020` naming), exactly as the docblock keeps its quoted ruling; only the POPULATION is re-keyed. Proof it is gone from the PRINTED output, not merely from the source: `--self-test` at the new head prints `the one ruled prefix` 0 times and the re-keyed sentence once. ### Still stating the superseded boundary — reported, ⛔ deliberately not pulled in The review lists these as live and OUT of this PR's scope, and this rework leaves them exactly as it found them: `.claude/agents/os-dev.md:286-287` (this card's item 1) and `SKILL.md:608`'s 「⛔ 无事实层例外」 (a card addendum, vocabulary only — the rule itself stays true). Naming-only uses of "the references tier" as this leg's NAME (queue-guard `:268`, `:358`, `:442`, `:452`, `:646`, `:736`, code comments `:1420` / `:1546` / `:2261` / `:2470` / `:2560`, and `check-clause2-carriers.mjs:8635`) are an optional tidy and were left alone: widening the diff of a docs-only record to sweep names is not what the FAIL asked for. ### Tier verdict on the FINAL file list ``` node scripts/pm/check-governed-merges.mjs --test .claude/skills/pm-dispatch/references/landing-operations.md scripts/pm/check-governed-queue-guard.mjs ``` → `⛔ GOVERNED — Tier S(席内达档复核落地)`, exit 3; 1 of 2 paths on the register (`.claude/**` ×1 — `landing-operations.md`; `scripts/pm/check-governed-queue-guard.mjs` is not a registered surface). File list unchanged from the reviewed head, so the tier is unchanged. Per Prime Directive objectstack-ai#14 this lands on the at-tier review of record — ⛔ no seat approves it and no maintainer click is owed. ### Gates at the new head (exit code captured BEFORE any pipe) The brief's minimum, plus every family `node scripts/pm/dispatch-gates.mjs --commands` derives for this change set — 38 commands, 37 at exit 0: - `check-governed-queue-guard.mjs --self-test` — exit 0, 296 cases (unchanged) - `check-governed-merges.mjs --self-test` — exit 0, 435 assertions (unchanged) - `check:pm-skill-ratchet` exit 0 (69/69, headroom 0) · `check:pm-skill-id-lint` exit 0 (27 clean) · `check:pm-governed-prose` exit 0 (6/6 surfaces, 28 self-test cases) · `check:skill-frame-sync` exit 0 · `check:nul-bytes` exit 0 (9053 files, no raw control bytes) - `node --check` exit 0 · `npx eslint scripts/pm/check-governed-queue-guard.mjs` exit 0 (1 file linted, 0 errors, 0 warnings, read from `--format json`) - `check:pm-dispatch-gates`, `check:pm-governed-merges`, `check:ratchet-remedy-authority`, `check:doc-authoring`, `check:cross-package-test-inputs`, `check-declaration-mirrors`, `check-scripts-symbol-anchors`, `check-self-test-wired`, `check-self-test-workflow-commands`, `check-comment-mask-corpus` and the rest of the derived list — all exit 0 - ⊘ NOT MEASURED — `pnpm --filter @objectstack/lint run check:doc-formula-expressions` exit 3, PREREQUISITE NOT MET (`@objectstack/formula` and `@objectstack/lint` unbuilt in this worktree). Exit 3 is this repo's NOT-MEASURED code, ⛔ not a finding; the family's population is docs formula expressions, disjoint from this diff's two paths, and CI runs it against a built tree.⚠️ `dispatch-gates.mjs` prints a STALE TREE warning: this branch is ≥55 commits behind `origin/main` and 15 files the derivation reads changed across that range. The gate list above is therefore derived from this branch's tree, which is what the review record is anchored to; ⛔ it was not refreshed by a rebase. CI on the merge group derives from the merged tree. ###⚠️ `check-clause2-carriers.mjs --pair 19379` reads 2 (UNJUDGED) — measured, and it is the BRANCH NAME Reproduced at the new head: `PM_SWEEP_REPO=objectstack-ai/objectstack node scripts/pm/check-clause2-carriers.mjs --pair 19379` → exit 2, 「the card's NEWEST claim comment (5754245926) matches the claim marker but its `Branch:` directive parses to ZERO branches」. The stored line 2 really is `` Branch: `claude/pm-superseded-references-tier` `` on a line of its own, so the printed remedy — "name the branch on a `Branch:` line of its OWN" — is already satisfied and cannot clear it. The cause is not the regex named in the dispatching brief. `BRANCH_TOKEN` (`check-clause2-carriers.mjs:3278`) reads the `Implemented-by:` VALUE of a review record; it never sees a claim's `Branch:` directive. That directive is read by the sibling `check-half-states.mjs:5407` `claimedBranches`, through `CLAIM_BRANCH_SHAPE` (`:5358`): ``` /claude\/issue-\d+-[A-Za-z0-9][A-Za-z0-9._-]*/g ``` which REQUIRES a literal `issue-` plus digits segment. Measured on the real stored comment body and two controls: | input | `claimedBranches()` | | --- | --- | | the live comment `5754245926`, as stored | `[]` | | the same comment, branch swapped to `claude/issue-19146-superseded-references-tier` | `["claude/issue-19146-superseded-references-tier"]` | | `Branch: `claude/issue-abc-slug`` (no digits) | `[]` | Only the branch NAME differs across those rows, so the marker, the backticks, the line position and the directive shape are all fine. `claimGovernance` on that one-comment thread returns `governing: null` with `malformed: { id: 5754245926 }` — which `cardDeclaration` turns into `claim-branch-unparsed`, i.e. exit 2. The narrow shape is DELIBERATE where it was written (`CLAIM_BRANCH_SHAPE`'s own docblock: a `Branch:` line naming some other shape "is deliberately left unmatched, which puts the card out of this row's scope entirely" — under-reporting beats manufacturing findings out of typos). The consequence in THIS reader is not out-of-scope, though: Prime Directive objectstack-ai#14 makes `--pair` at 0 part of the Tier S landing predicate, so a Tier S PR on a branch without an `issue-`digits segment cannot satisfy it by any act of the claiming seat short of renaming the branch — which would strand this review record. ⛔ Not repaired here: `check-clause2-carriers.mjs` is ⛔ out of this PR's scope and the branch is ⛔ not renamed. Reported for the seat. --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01AmH9bKvGoLjiY86Q4Z3og2 --- _Generated by [Claude Code](https://claude.ai/code/session_01AmH9bKvGoLjiY86Q4Z3og2)_ --- _Generated by [Claude Code](https://claude.ai/code)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Fixes #19133
Clause-②: no
Tiers the governed register. Membership does not move (every row still governs what it did; one hit still forks the whole PR;
--teststill exits 3 on every row). What moves is the LANDING each row waits for, carried astieron the register row and derived per PR by one function that both scripts read.docs/adr/**·docs/NORTH-STAR.md·skills/**·AGENTS.md·CLAUDE.md— the maintainer's hand, or an authorized APPROVED review byGOVERNED_APPROVERSand then the owning seat lands it. Unchanged..claude/**tree (skills, agents, hooks, settings) — the owning seat lands it through the queue once the PR thread or its card carries a## Contract reviewrecord for the PR's current head withServed-tier: CONTRACT_REVIEW_TIERand**VERDICT: PASS**,check-clause2-carriers.mjs --pair Nreads 0 and every check is green. Exactly the fact-layer path, generalised to the tier; the post-merge audit and the director's 职责四 are the compensating control.Ruling (verbatim, chat 2026-09-18): 「同意改规则。」 on the seat's proposal quoted in the card body, then the amendment 「我觉得这些我也没必要确认:.claude/settings.json、.claude/hooks/**」 — applied as the amendment comment on the card says (Tier H shrinks to the four surfaces; the whole
.claude/**tree is Tier S; publishedskills/**unchanged).维护者速读(草稿)
改了什么:受管面登记表分成两档。Tier H(法):
AGENTS.md、CLAUDE.md、docs/adr/**、docs/NORTH-STAR.md、发布的skills/**,照旧等你的手或授权批准。Tier S:整棵.claude/**(skills、agents、hooks、settings),席内CONTRACT_REVIEW_TIER复核 PASS 记录在案、--pair读 0、全绿,即由席位走队列落地;事后由受管合并审计抽查。队列守卫按登记表的档位放行或拒绝;--test判词打印档位与该档的落地条件;AGENTS.md 第 14 条与 SKILL.md/契约复核/核心条款同步改写。为什么改:你在聊天里说「一直让我点很浪费时间」并「同意改规则」。舰队自己的仪器由舰队按达档复核落地,你只需要确认真正的法。
风险与代价(含回滚):代价是 AI 可以在没有人闸的情况下改自己的操作规则(含
.claude/settings.json权限集本身——修正评论已点名:自动模式分类器今天仍拒绝 AI 写它,实际写手仍是你的手,本次只免掉那一次批准点击)。补偿控制三件:PR 线程上的达档复核记录、落地后的受管合并审计(Tier S 无 PASS 记录即审计发现)、北极星「仪器为车队服务」评分。回滚:一个 PR,把六行登记表的tier: GOVERNED_TIER_S改回GOVERNED_TIER_H,队列守卫即回到全人合;不需要回滚任何数据。席位意见:(留空,由席位定稿)
你要做的:本 PR 含 AGENTS.md,属 Tier H——这是 Tier S 这一类的最后一次点击。审阅后给一个 APPROVED review(
os-zhuang或hotlong),认领席落地。Register — before / after
adrdocs/adr/**north-stardocs/NORTH-STAR.mdexactrow; the file itself arrives with #19131's branch (25 lines,docs/NORTH-STAR.md); the predicate is path-only so landing order does not matterclaude-tree.claude/**.claude/skills/pm-dispatch/references/landed on a record (REFERENCES_TIER_PREFIXin the queue guard)skills-catalogskills/**agents-mdAGENTS.mdclaude-mdCLAUDE.mdOrder pin:
adr,claude-tree,skills-catalog,agents-md,claude-md→adr,north-star,claude-tree,skills-catalog,agents-md,claude-md. #18489's branch (claude/issue-18489-north-star-enforcement) carried no commits when this was written (its tip is the then-origin/main,14a762f9f), so line identity with its row could not be measured; whichever lands second mergesorigin/mainfirst, as the card says.Exit codes: no new exit constant. Both tiers exit 3 on
--test/--pr/--branch(pinned:exit-3-is-SHARED-by-both-tiers…). Every reader of that status asks "may a seat arm this on green alone?" and the answer is no for both; the tier is a second fact and travels in the verdict line and in--json("tier": "H" | "S" | null), never in the status, so no$?reader learns a new number. Tier H keeps its wording word for word (⛔ GOVERNED — a human merge is the review record for this PR) plus one⚖️ landing tier: H(人合)line; Tier S prints its own block naming the record-on-thread landing. The NOT-governed exit and wording are untouched.Self-test floors — before / after (raised or re-keyed, never lowered)
scripts/pm/check-governed-merges.mjs(351 assertions now):the governed predicate: the 2026-08-18 unified list, exactly8 → 9 (all-five-surfaces-declared-in-orderre-keyed toall-six-…;north-star-exactadded; three North Star near-misses added to the near-miss list)the dispatch-gates declaration (#9979)8 → 9 (every-exact-root-row-declares-a-watch-hintre-keyed to separator-less exact rows;a-non-root-exact-row-carries-its-own-separator-and-declares-no-hintadded)⚖️ the two landing tiers (#19133, ruled 2026-09-18)floor 19;SELF_TEST_BATTERY_FLOOR25 → 26(5 surfaces, repo-agnostic)→(6 surfaces, repo-agnostic)scripts/pm/check-governed-queue-guard.mjs(261 cases now; 21 batteries unchanged):⭐ #18020: the references tier — a review of record, not an approval40 → renamed⭐ #18020 → #19133 Tier S: a review of record, not an approval43 (the end-to-end pass for a.claude/agents/os-dev.md+.claude/settings.jsonPR on a valid record, and its lit control — the same PR with NO record is REFUSED)the pull_request leg is an EARLY WARNING and never reddens3 → 5 (the warning names Tier S and the record it waits for; names Tier H and the approval)the replay fixtures: the three incidents this guard descends from9 → 11 (the two.claude/**replays are Tier S today: judged on an ABSENT record they refuseunapprovedas before; with NO record reading they refuseunreadable— never clear)⛔ the-tier-prefix-keeps-its-trailing-slash…re-keyed to⛔ this-file-spells-NO-tier-prefix-Tier-S-is-the-register-rows-that-carry-S…scripts/pm/check-governed-prose.mjs: floors unchanged (28 cases);PROSE_SURFACES[0].startanchor moved with the paragraph's first sentence.scripts/pm/check-clause2-carriers.mjs: +1 control (the cross-tool pin's fixture path is Tier S under the register), 942 cases.Readers of the merges script (PM assumption 3 — every reader, and what changed)
scripts/pm/check-governed-queue-guard.mjs— the only ROUTER. ImportsGOVERNED_TIER_H/SandgovernedTierForfrom the register at module scope (the register was never mirrored there; the mirrors its docstring names areCONTRACT_REVIEW_LABELandREVIEW_OF_RECORD_LOCATION, forced by the cycle withcheck-half-states.mjs).merge_grouppasses a Tier S PR on the record-of-record predicate, refuses a Tier H PR without an authorized approval as today;pull_requestnames the tier and what it waits for.TIER_RULES/TIER_REFERENCES/REFERENCES_TIER_PREFIXare gone;TIER_H/TIER_Sre-export the register's values;governedTierForis re-exported, not copied.scripts/pm/check-clause2-carriers.mjs— its self-test built a fixture path fromREFERENCES_TIER_PREFIX; re-keyed to a Tier S path literal with a register control. Not a router.scripts/pm/check-governed-prose.mjs— reads the SET ofglobs; set-based, tiers are attributes (PM assumption 2 confirmed); header note added; not extended to parse tiers.scripts/pm/dispatch-gates.mjs— reads the merges SOURCE for path literals (extractWatchHints), never its exit codes;docs/NORTH-STAR.mdis a path literal so a North Star card now derives this gate. No meaning change for Tier H.scripts/pm/check-half-states.mjs— H43/H48 loadgovernedPathsInandGOVERNED_APPROVERS(membership only; tier-agnostic). Unchanged.scripts/pm/ci-failure.mjs(proxyRearmPlan),scripts/check-skills-token-ratchet.mjs(generatedExceptionFor) — untouched exports.scripts/invoked-as.mjs,scripts/pm/check-skill-line-ratchet.mjs,.github/workflows/lint.yml— comments citing "exit 3 = GOVERNED"; still true for both tiers..github/workflows/governed-surface-guard.yml— invocation only; not edited.landing-operations.md:26,state-machine.md:9,lanes/skills.md:18) — the line now names the tier.Reader tests, one per tier
.claude/agents/os-dev.mdPR:--test .claude/agents/os-dev.mdprints⛔ GOVERNED — Tier S(席内达档复核落地): …, exit 3,--jsonsays"tier": "S". The seat runs the three landing checks (record on the current head,--pair0, every check green), flips ready and arms auto-merge; themerge_groupguard reads the record (stands) and prints✅ CLEARED — … Tier S … satisfied 1 of them; the post-merge audit lists the landing. Without the record the same guard prints⛔ REFUSEDwith remedy 3 (post the record on the CURRENT head and re-queue).AGENTS.mdPR:--test AGENTS.mdprints⛔ GOVERNED — a human merge is the review record … ⚖️ landing tier: H(人合), exit 3,"tier": "H". The record changes nothing: the seat leaves the PR at the four-piece terminal (draft, request review from both authorized accounts, the 速读 comment, the round report line). Enqueued anyway, themerge_groupguard refusesunapproved— the record key is never even read for a Tier H entry; only aGOVERNED_APPROVERSAPPROVED review lifts, then the owning seat lands.Ceilings per file (all at headroom 0, every touched line within the 120-byte cap)
AGENTS.md1099 / 1099 — PD feat: Comprehensive CRM example demonstrating all ObjectStack protocol features #14 rewritten in place (34 lines → 34 lines); two dependent lines outside the named hunk re-keyed because the ruling made them false: :800 (skills/Tier H,.claude/skills/Tier S) and :1062–:1063 (landing waits for its tier's record). Same file, same ceiling, disjoint from docs(AGENTS): §7 names the third class of PR that never lands on green alone — over 5,000 changed lines #19042 (:495–:500) and skills(pm-dispatch): ADR-0136 D2 becomes the triage protocol —Journey:line, journey bands, cross-lane product-first order, journeys feed the queue #18489 (top pointer)..claude/skills/pm-dispatch/SKILL.md812 / 812 — :624–:625 re-keyed (Tier H(规则层) list incl.docs/NORTH-STAR.md; Tier S =.claude/**); :26–:27 and :607 keep their words (规则层 = Tier H)..claude/skills/pm-dispatch/references/contract-review.md60 / 60 — :46 re-keyed..claude/skills/pm-dispatch/references/core-rules.md151 / 151 — :122 twin re-keyed identically.CLAUDE.mduntouched.Gates (derived with
node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackatd3bb7e0c3; every command run, exit captured redirect-then-$?;--ranreconciliation below)Every derived command ran green (exit 0) at head
d3bb7e0c3, one detached run's exit code pending (below). Highlights, verdict lines as printed:pnpm check:pm-governed-merges:: exit 0 —✓ check-governed-merges --self-test: 351 assertions …node scripts/pm/check-governed-queue-guard.mjs --self-test:: exit 0 —✓ check-governed-queue-guard self-test: 261 cases pass …pnpm check:pm-governed-prose:: exit 0 —✓ check-governed-prose: 2 instruction surface(s) name all 6 registered governed surfaces (docs/adr/** · docs/NORTH-STAR.md · .claude/** · skills/** · AGENTS.md · CLAUDE.md) and claim no others.pnpm check:pm-skill-ratchet:: exit 0 — AGENTS.md 1099 / 1099, SKILL.md 812 / 812, contract-review.md 60 / 60, core-rules.md 151 / 151 (all headroom 0)pnpm check:pm-skill-id-lint:: exit 0 — 27 file(s) clean ·pnpm check:skill-frame-sync:: exit 0 ·pnpm check:nul-bytes:: exit 0 (8965 files)pnpm check:pm-clause2-carriers:: exit 0 — 942 cases ·pnpm check:pm-half-states:: exit 0 — 5043 casespnpm --filter @objectstack/lint run check:doc-formula-expressions:: exit 0 — afterbash scripts/pm/os-verify-lock.sh -c "pnpm --workspace-concurrency=2 --filter '@objectstack/lint...' build"(VERDICT command-exit 0 · held the lock 131s · waited 0s)scripts/check-*/pnpm check:*families :: exit 0 each (fullCOMMAND :: exit CODErecord in the report comment on skills(governed): narrow the human-merge floor to the law — Tier H stays human/approved (AGENTS.md · CLAUDE.md · docs/adr/** · docs/NORTH-STAR.md · .claude/settings.json · .claude/hooks/**); Tier S (.claude/skills/** · .claude/agents/**) lands on the seat's CONTRACT_REVIEW_TIER PASS + post-merge audit #19133)pnpm check:pm-dispatch-gates— exceeds the foreground cap, run detached: verdict lines read✓ check:pm-dispatch-gates --self-test: the exit contract holds in all three directions.and✓ dispatch-gates self-test: 1849 cases pass.(654.7 s); the detached start captured no exit code, so a second detached run with exit capture is in flight and its:: exit CODEline lands in the report comment.--ranreconciliation (node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran RECORD):50 derived, 49 run, 0 NOT-MEASURED, 1 UNRUN— the one UNRUN ispnpm check:pm-dispatch-gatesabove, pending its captured exit; the 50/50 reading follows in the report comment.Acceptance commands from the card:
--test .claude/skills/pm-dispatch/SKILL.mdprints⛔ GOVERNED — Tier S(席内达档复核落地): …(exit 3);--test AGENTS.mdand--test docs/NORTH-STAR.mdprint⛔ GOVERNED — a human merge is the review record … ⚖️ landing tier: H(人合)(exit 3);--test .claude/settings.json .claude/hooks/guard-main-checkout.shprints Tier S (exit 3);--test scripts/pm/check-governed-merges.mjsprints✅ NOT governed(exit 0);--test --json .claude/agents/os-dev.mdcarries"tier": "S".Not run locally, CI-owned:
pnpm lint(repo-wide eslint) and the artifact-roster / wide-population families the reconciliation names as outside this link.Acceptance notes
entrySatisfied/entryUnreadable/guardVerdict/runGuardre-keyed fromTIER_REFERENCEStoTIER_Swithout touching the record predicate..claude/agents/os-dev.md:286–:287 still spell the 事实层 =references/split (「受管路径全在 … references/ 者为事实层 … 余为规则层」/「规则层 PR 正文带 速读 … 事实层不欠」). After this lands AGENTS.md wins the conflict by its own header; the one-line re-key is Tier S work for the skills seat — 承接者: skills seat (a follow-up card; dedupe words: os-dev.md 事实层 规则层 Tier S 速读)..claude/skills/pm-dispatch/references/landing-operations.md:27–:28 say the same (事实层 =references/); :26 is HELD by PR feat(pm): a PR over 5,000 changed lines lands only by a human merge — size predicate in check-governed-merges --test, the same reading in dispatch-gates, one rule line in SKILL.md and landing-operations #19033 and :27–:28 abut it, so not touched here — 承接者: PR feat(pm): a PR over 5,000 changed lines lands only by a human merge — size predicate in check-governed-merges --test, the same reading in dispatch-gates, one rule line in SKILL.md and landing-operations #19033's follow-up or the skills seat.check-half-states.mjsH48 expects a## 维护者速读on every accepted governed PR; for Tier S PRs that brief has no reader now. Report-only patrol row, not a router — 承接者: skills seat.unreadable).Journey:line, journey bands, cross-lane product-first order, journeys feed the queue #18489 remains open; docs:docs/NORTH-STAR.md— the maintainer's North Star, verbatim (finalized in chat 2026-09-18) #19131 remains open.Generated by Claude Code