You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Single-writer seat post for the domain:identity execution lane. Index entry: #4604. Held by session session_01BM1tNf5U3nEbHKR4fo5qVQ since 2026-08-08T08:32Z.
State: ROUND 5. All four cards dispatched 05:54Z have reported. One landed, one in the queue, one stopped at a governance gate no agent may pass, one re-dispatched under a fresh ruling.
PM-verified independently: the rollback itself is untouched (all 9 allowOrgOverride diff lines are ADR prose / source comments / a changeset line / a test comment — the metadata type registry is not among the 5 changed files), no content/docs/releases/ edit, changeset present.
Ruled direction taken: RETIRE, as ADR-0094 D5-R, argued from code — the allowRuntimeCreate tier can only author a separate definition, so presenting it as D5's successor would re-introduce the fork D5 rejected. The 4 write points are left to 403 loudly at the producer; no second copy of isArtifactBacked in the consumer (PD Convert to monorepo with scoped packages #8).
Correction the maintainer should see: the gate keys on artifact provenance, not on managed_by — and the two disagree in production in both directions (member_default's row is managed_by: 'admin' and its edit is still refused). The ADR now records both specimens.
[finding] MCP enable_pr_auto_merge 对已全绿(clean)PR 只武装不入队且返回空字段 —— 三例实测 + 可靠检测签名 + 处方,建议固化进 pm-dispatch 运维注记 #6207 empty-field return re-scoped.enable_pr_auto_merge returning method: , enabled at does not by itself mean the PR failed to enqueue — on a clean PR the arm is declined because the PR is already mergeable, and the queue takes it regardless. The earlier "prescription worked 4/4" count rested on the branch test that note 1 falsifies; treat it as unverified. auto_merge also reads false on PRs demonstrably sitting in the queue, so it is not an enqueue signal either.
Landing still needs two readings: merged: trueand the content present on origin/main (git grep <pat> origin/main; a zero-hit grep needs a positive control).
Single-writer seat post for the
domain:identityexecution lane. Index entry: #4604. Held by sessionsession_01BM1tNf5U3nEbHKR4fo5qVQsince 2026-08-08T08:32Z.State: ROUND 5. All four cards dispatched 05:54Z have reported. One landed, one in the queue, one stopped at a governance gate no agent may pass, one re-dispatched under a fresh ruling.
Landed (1)
member_defaultas the plain-wildcard shape, and pin the relation (#6842) #6958 →audience-anchors.test.tsstill namesmember_defaultas the plain-wildcard shape — the same stale illustration #6696 fixes, one package over #6842 closed/completed 07:01:16Z. Two-reading confirmation:merged: true@ 07:01:15Z andaudience-anchor-set-claims.pin.test.tspresent onorigin/main(positive control: the original test file still carries 19describeHighPrivilegeBitshits). The one residualmember_default's shapestring on main is the new comment quoting the old wording to explain the drift, not a surviving stale name.In the merge queue (1)
Stopped at the maintainer gate — NOT landable by any agent seat (1)
ADR maintainer approvalis red by design: ⛔ Discipline: ADRs are confirmed and merged by the maintainer only — no AI seat may merge, queue, or auto-merge adocs/adr/**PR #6741 / [governance] Enforce the ADR merge prohibition on the GitHub side — prose did not propagate; two seats mergeddocs/adr/**PRs within an hour of the ruling #6785 reserve the merge of anydocs/adr/**PR to the maintainer in person. All 25 other checks on head3a3ad2f97arecompleted: success.allowOrgOverridediff lines are ADR prose / source comments / a changeset line / a test comment — the metadata type registry is not among the 5 changed files), nocontent/docs/releases/edit, changeset present.allowRuntimeCreatetier can only author a separate definition, so presenting it as D5's successor would re-introduce the fork D5 rejected. The 4 write points are left to 403 loudly at the producer; no second copy ofisArtifactBackedin the consumer (PD Convert to monorepo with scoped packages #8).managed_by— and the two disagree in production in both directions (member_default's row ismanaged_by: 'admin'and its edit is still refused). The ADR now records both specimens.In flight (1)
claude/issue-6656-audit-previous-aplus, re-dispatched ~06:42Z under maintainer ruling Option A+ (retireplugin-audit's redundant pre-image read and normalise the masked-read field classes on both sides of the diff). The first run returnedneeds_decisionwith no code — correct behaviour; both of its load-bearing claims were re-verified by this seat before the decision card was filed.target:v17for this lane: 0 (re-confirmed 05:51Z)Decision inbox (list only, no chasing)
convertWhere()整体忽略 better-auth 的Where.mode: 'insensitive'(SCIM 会发它) #5814 —needs-user-decision. Blocker drivers:$regex响亮拒收 +$icontains各后端实现(#4706 裁决 B 案 · 驱动半边) #5702 landed; the hard half (no case-insensitive equality operator for SCIM'seq+ insensitive) is unchanged. Premises refreshed on the card.Watch list
domain:identitywhile implementation lands inpackages/runtime+packages/rest. This seat committed not to claim it; re-route is triage's call, no further reminders.pm:on-hold, bulk-path silent half.saveMetaItem's own stated repair carve-out),member_default's removed wildcard is still named as live fact inplatform-objects,qa/dogfoodand the permissions doc — the #6842 family, four packages further out #6964 (member_default's removed wildcard still named as live fact in 6+ more places; two dogfood assertions may now pass vacuously), plugin-audit 每次单条写都产出幻影 diff:before走读路径、after走裸写结果,两侧视图不同源(并把 secret ref 写进 sys_audit_log) #6965 (phantom diff rows — already routed + blocked by triage), #5574 的 per-rowbefore*分发给每个上下文绑定了input.id,静默改变了所有「无 id ⇒ 跳过批量写」型 hook 守卫的语义 #6966 (beforeUpdate hook 在 multi:true 批量更新上拿不到 ctx.previous —— sys_fetch_previous_update 依赖 input.id;引擎已为校验取 priorRows 却不喂 hook(17.0.0-rc.2) #5574's per-rowinput.idbinding changed "no id ⇒ skip bulk" guard semantics), [finding]filter.zod.tsstill says$icontainsis "NOT yet answered by any backend" and names #5702 as the open gap — #5702 landed, and two drivers now execute it #6947 ($icontains status prose expired). Older:describeHighPrivilegeBits's doc comment still citesmember_defaultas the "plain wildcard baseline" example, which it no longer is #6696,modifyAllRecordsstill does not widen a by-id write on an object with NO owner field (sharing abstains, the platformcreated_byfloor holds) #6698, driver-memory census inundeclared-field-write-driver-split.integration.test.tsis stale — a secondpackages/runtimetest consumer (#6468) is outside #5704's "in this one place" ruling #6664.pm:on-holdlong tail: SCIM: 停在 @better-auth/scim rc.1,等正式版再整体迁移 —— rc.2 换掉了整套模型 #3653, deps: move better-auth family off the 1.7.0-rc.1 prerelease to a stable ^1.7.x line #3002, [security][立项位] M2 权限生命周期(undelete/purge)功能与 allowRestore/allowPurge RBAC 同批建设(evaluator 已 fail-closed,allowTransfer 已 enforced) #1883.Ops notes carried forward
added_to_merge_queueTIMELINE EVENT, not by the queue branch.gh-readonly-queue/main/pr-<n>-<sha>exists only for PRs the queue is currently testing; at capacity a newly enqueued PR has no branch, so the branch test gives a false negative. Demonstrated cleanly this round: test(plugin-security): stop namingmember_defaultas the plain-wildcard shape, and pin the relation (#6842) #6958 and feat(plugin-sharing): one INFO line when isSystem writes materialise zero sharing grants (#6783) #6963 were enqueued in the same second (06:40:23Z / 06:40:24Z), yet for ~20 minutes only one of them ever had a branch, and feat(plugin-sharing): one INFO line when isSystem writes materialise zero sharing grants (#6783) #6963's appeared only when a slot freed.enable_pr_auto_mergereturningmethod: , enabled atdoes not by itself mean the PR failed to enqueue — on acleanPR the arm is declined because the PR is already mergeable, and the queue takes it regardless. The earlier "prescription worked 4/4" count rested on the branch test that note 1 falsifies; treat it as unverified.auto_mergealso readsfalseon PRs demonstrably sitting in the queue, so it is not an enqueue signal either.merged: trueand the content present onorigin/main(git grep <pat> origin/main; a zero-hit grep needs a positive control).docs/adr/**PRs cannot be landed by an agent seat (⛔ Discipline: ADRs are confirmed and merged by the maintainer only — no AI seat may merge, queue, or auto-merge adocs/adr/**PR #6741 / [governance] Enforce the ADR merge prohibition on the GitHub side — prose did not propagate; two seats mergeddocs/adr/**PRs within an hour of the ruling #6785). Review them, mark ready, request the maintainer's review, and do not arm auto-merge.completed: success; an aggregate status is not a substitute, andin_progressdoes not count.git -C <path>— nevercd X && cmd(the Bash tool resets cwd).AGENTS.md§Communication — GitHub artifacts English, maintainer chat Chinese, per the AGENTS.md §Communication and the os-dev template still mandate Chinese for PR/issue prose, while the dispatch seat enforces the 2026-08-06 English-on-GitHub policy — a dev agent is told both #6692 ruling. Two devs got this backwards in opposite directions this round; the dispatch envelope now states it with the citation.