This post is the single authoritative registry for the domain:services seat (seat-post protocol; index label:pm:seat). Single writer: incumbent only. Read side: body + comments later than the body's last edit. ⛔ 班次叙事不进正文;本贴只载当前值 。
1. Current PM — 🟢 在任
在任 : session_01AUF1NoViznQK32gqpK8wS8 (GitHub os-sales ), 2026-09-02 ~01:05Z 起,维护者召唤 /pm-dispatch services;开轮标记 issuecomment-5502756535;R2 ~02:57Z … R14 ~18:10Z,R15 ~19:00Z,R16 ~21:40Z。
⚠️ 限流打断记录(现值,两次) :① 04:25–04:28Z 三个在飞 dev 被 5 小时用量上限终止(429),悬挂至 09:20Z 维护者确认「已重置,继续」,09:25Z 原 agent 续跑,全部交付。② 13:08–13:09Z 三个在飞 dev 再次被 429 终止(「session limit resets 14:20 UTC」),14:20Z 重置,维护者 ~14:2xZ 「继续,后续并发降到3」,14:22Z 原 agent 全部续跑并交付。若本会话再次被悬挂 :§2 表即现值,无半状态 —— 接班者先核 §2 在飞表各卡的分支远程产出与 PR,再核待落地 PR 是否 MERGED,再核卡上最新评论。
上一任 : session_016ZC5rNQj3WEet5HAmmAkMs(os-steve),2026-09-02 ~00:30Z 收班。
接手 : /pm-dispatch services,先读本贴。范围与常设承诺在 references/lanes/services.md。
红线:零 packages/spec;安全边界放宽 是维护者地板;⛔ 永不在代码 PR 里改 content/docs/releases/**。
席位会话档位:维护者 17:0xZ 起切 claude-opus-5(此前 claude-fable-5-1)。契约复审子代理仍显式传 fable 并逐轮从 transcript 验章 (本班十一次验章全 claude-fable-5-1);CONTRACT_REVIEW_TIER = 'claude-fable-5' 字面不等 —— 同族更高档,在案 finding finding(pm-dispatch): CONTRACT_REVIEW_TIER = 'claude-fable-5' no longer matches the served Fable tier claude-fable-5-1, so the in-seat review fuse reads a literal mismatch on every current Fable seat #14303 ;⛔ 不凭会话自述。
⛔ 并发上限 = 3 —— 维护者指示,覆盖文档默认值
2026-09-02 ~04:25Z 指示「后续并发降到3」,~14:2xZ 重申 。⇒ 同时在飞的 dev 上限 3 (计数 = 正在运行的 dev 子代理,含补丁轮 ;已交付待复审/待落地/队列中的卡不占位)。priority:p0 插队可超上限。现在飞 3,满载。
⚠️ 本席 20:3x–21:1xZ 一度到 4,是本班的一处执行错误 :交付会释放槽位,而补丁轮又把它占回去 ,开第二轮补丁时没重数。处置按既有原则(上限下调时不中断在飞、只不补位)同样适用于自己的超发:不打断在飞、不加新的、自然降回 3 。已在 14528#issuecomment-5516294194 公开声明。
⏳ 待派队列(槽位一空按此顺序,⛔ 不跳)
PR fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 的合并轮 (20:56Z 已公开声明为第一顺位)
PR fix(sharing): stamp organization_id on every sys_record_share write, backfill the stranded rows, admit the object to the tenancy ledger (#14484) #14726 的补丁轮 1 (复审 FAIL,见 §2)
✅ 契约复审:本班十一场已裁(七 PASS · 一 FAIL→delta PASS · 一 DECISION→裁 A 后视作 PASS · 两场 FAIL 待补丁轮 )
PASS:#13926 /#14322 · #13805 /#14347 · #14157 /#14352 · #13648 /#14388 · #14360 /#14540 (R2 delta)· #12775 /#14571 · #14033 /#14580 (R1 + delta)。DECISION → A :#13533 /#14528 。FAIL(补丁轮中/待派) :#14333 /#14712 (转录 62/62 fable)· #14484 /#14726 (转录 90/90 fable)。全部只喂卡 + 裁决 + PR 本体,逐字采纳,双载体同笔清标,check-clause2-carriers --pair 机读 exit 0 后落地。delta 复审 = 续用原隔离复审子代理 。
⭐ 条款②的机械地板(#14047 ):新导出符号 / 发布载荷新键 ⇒ 恒 yes;新增公开 API 的 changeset = minor(#13897 )。PM 收集时自己跑 git diff -U0 origin/main... | grep export + barrel 成员核一遍,⛔ 不信申报 。只有包内消费者的新导出 ⇒ 要求放进非 barrel 模块 ,changeset 降 patch(#14360 实例)。breaking runtime change 的 changeset 按 #13857 形 = minor + BREAKING 横幅 + ADR-0087 处置标记 (#14033 实例)。
🔴 os-elon 内容被屏蔽 — §4 item 24 · #13634
2. Ledger — 现值 2026-09-02 ~21:40Z
在飞 dev — 3 (满载)
卡
PR
档位
状态
#14333
#14712
opus
补丁轮 1 。复审 FAIL 逐字采纳于 14712#issuecomment-5515933381。验收判据机械:复审自跑的两条消融必须变红 —— (C) 删 InMemorySuspendedRunStore.claimSuspension 的 nodeId/correlation 比较、(C2) 删 ObjectStore 那侧的 multi: true;今天两者都留下 49/49 全绿。外加 §5 note 2/3/4(均为本 PR 自写文字)。⛔ 设计不重开。双载体挂着
#14530
#14718
opus
补丁轮 1 。裁决三件已达成(5000 行 10 658 ms/5000 写 → 448 ms/2 写;cap 分支实测挂上;P2 为假时测了两个世界)。补丁 = 谓词写入分页 ,使超过 MAX_BULK_PER_ROW_HOOK_ROWS 的对象仍被全部认领(21 000 行现认领 0,旧代码认领 10 000)。⚠️ 21:15Z check-tenant-audit-census 红:objectName 变 undecidable + 自测 5/19 失败 —— 已令其不得直接 --write 交差
#14373
—
sonnet
分诊裁 disposition 3 only。⚠️ 20:33Z 曾静默挂起(等一条不会到达的 Monitor 通知),已幂等续跑。21:13Z 分支仍停在基线 sha
待补丁(已交付,复审 FAIL,等槽位)
卡
PR
阻塞项
#14484
#14726
p1 security,维护者裁 A。复审 FAIL(90/90 fable),裁决全文 + 席位处置在 14726#issuecomment-5516612945。BLOCKING:recordOrganization 把「读取失败」与「记录无组织」都返回 null,直接授权路径遂把调用者会话的组织 盖上权限边界列 —— 行非 NULL ⇒ 回填修不了、对记录所属组织不可见而对兄弟组织可见、唯一痕迹是一条文本为假 的 warn;文件自己的文档注释已写明它缺的那条性质。§5 note 1/2/3 同轮,note 5 要跑门禁确认新增裸读被接受
待落地 — 1
PR
卡
现状
#14528
#13533
⚠️ 20:56:07Z 被以 MERGE_CONFLICT 踢出队列 ,冲突路径只有 content/docs/permissions/system-context.mdx,已用 git merge-tree(真做了文本合并并报 CONFLICT (content))与 GitHub 双读数确认为真冲突。⛔ 不会自动重排,冲突不自愈 ⇒ 需一轮 dev 合并轮(第一顺位)。此前双载体已清并回读,--pair 14528 exit 0
本班落地 — 17
#14228 · #14322 · #14334 · #14347 · #14352 · #14388 · #14383 (#12981 b9)· #14400 · #14532 (#14348 )· #14540 (#14360 )· #14567 (#14379 )· #14571 (#12775 )· #14580 (#14033 )· #14618 (#13918 )· #14624 (#14522 )· #14650 (#14332 )· #14687 (#14491 ,20:21Z,941952c15) 。全部卡已关或已按其形态转态、pm:dispatched 已摘读回。
决策箱 / 等维护者(只列不催)
Webhook fan-out matches subscriptions by object name only — on a walled deployment one organization's record events reach another organization's webhook endpoints #13566 两问(p0 泄露) :① 是否需要缓解先行;② 已发布版本是否受影响/披露。
决策卡:A deployment that seeds a people directory and no credentials is locked out for good: bootstrap-status and the audience bootstrap bypass both count HUMANS, not LOGINS #14349 (荐 C)· [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 (荐 A)。本车道另有 needs-user-decision 存量:[Decision] The share-link route probe re-opens the existence oracle that share-link-service deliberately closed — a switched-off link with a password still answers 401 #14637 · [finding] service-job scheduler leader election excludes for the DURATION OF THE FIRE, not for the deadline — the lease is released in finally, so replica clock skew larger than the handler's runtime defeats it #14619 · [finding] A schedule (cron) flow has no dispatch-claim ledger while a time_relative flow does — a re-run of a digest re-notifies #14501 。
pm:awaiting-maintainer:Seam (enterprise organizations package): its ensureDefaultOrganization wiring still triggers on grant inserts, which never fire on a fresh walled rig — adopt the exported isDefaultOrganizationBootstrapTrigger #13689 。跨席:spec: name the terminally-failed run state on AutomationResult.status — contract half of #13937 (shape 4 ruling) #14384 · Reading request for the hotcrm seat: does any objectstack-ai/hotcrm writer set sys_activity.environment_id? (#13433 cannot proceed without it) #14362 。
pm:retriage:service-automation: the two operator run-lifecycle verbs (cancelRun, restoreConsumedSuspension) have no door — no REST route, no CLI command, and not on IAutomationService #13953 · The durability log-level gate cannot see the catch { return null; } seeder family — 15 files outside #12923's five, and neither widening path is cheap #12981 · [finding] After #12892 step 2 an artifact boot with an engine still holds a THIRD, un-parsed copy of permissions / capabilities / sharingRules in the ObjectQL SchemaRegistry (AppPlugin.init → manifest.register), and the plugin-security / plugin-sharing seeders read that copy FIRST #14491 (测量已落地,卡转 pm:queue+pm:retriage、assignee 已释放;等分诊按实测数字改判 + 路由方向题)。
可派(全序;⛔ 现满载,且待派队列有两项在前)
try_catch whose catch region itself fails still discards the whole step record — the third returned-failure path, left unfolded by #14184 #14222 / [finding] service-automation: the subflow up-bubble path always logs "child run … is gone — continuing without child output" even when the engine-built signal carries the child's output #14392 / automation: create_record collapses the engine's DUPLICATE_RECORD envelope to a string, so a flow's try_catch / fault edge still cannot tell "already there" from "the store is down" #14419 (engine.ts 家族,在 fix(service-automation): a conditional advance claim on SuspendedRunStore, so two replicas cannot both advance one run #14712 落地后一次一张 ;automation: create_record collapses the engine's DUPLICATE_RECORD envelope to a string, so a flow's try_catch / fault edge still cannot tell "already there" from "the store is down" #14419 的 NodeResult 新字段属公开面扩大 ⇒ 条款② 预期 yes)
A deployment with human rows and zero sys_account rows boots silently into an unrecoverable state — say so loudly at kernel:ready #14353 (Bug p2)—— 实测 PR feat(plugin-auth): auth mail follows the caller's Accept-Language, deployment default second #14600 持 auth-manager.ts / auth-plugin.ts 的 kernel:ready 区(:784-788),同区 ⇒ 等其合并。auth 邮件(验证/重置)不按用户语言选模板:中文界面注册收到英文主题与正文 #14319 非本席
[finding] app-showcase's job sweep still normalizes { records } off an engine find() the contract types as an array #14460 · examples/app-crm: two comments reference a Discount Approval flow the app does not contain #14516 · finding: getPolicy()'s disabled-branch redactFields read has no reader once publicSharing.enabled is held at redemption (#14033) #14581 · changeset share-link-enabled-at-redemption.md says the refusal "will burst the log once" — the warn is per-hit and unlatched, so it continues with traffic #14668 · [finding] plugin-auth SCIM harnesses register no OAuth objects, so every sign-in logs a Better Auth ERROR (back-channel logout planning failed … no such table: sys_oauth_access_token) #14615 · [finding] plugin-approvals after #12775: the tenant-admin reverse check never asserts the lock release #14602 · [finding] plugin-auth SCIM lifecycle after #14360: DELETE of the last administrator is unpinned, last-admin-guard.ts header describes SCIM DELETE as a row delete, the timed-ban face rides a 1.5 s real-clock window #14555 (p3)
[Decision] Workflow resume ordering: a thrown node today leaves the run terminally unresumable — which of three shapes, given that the current order buys exactly-once across a crash? #13937 (等 spec: name the terminally-failed run state on AutomationResult.status — contract half of #13937 (shape 4 ruling) #14384 )· claimSeedOwnership claims nothing at all on an object with more than 10k rows under one unowned predicate, because MAX_BULK_PER_ROW_HOOK_ROWS refuses the whole write #14719 (claimSeedOwnership writes up to 20k single-id system updates in a loop, so per-record sharing materialisation cannot batch them #14530 的溢出卡,分页测出结果后由席位定去留)
3. Hot-file serial queue
区域
持有
释放后
plugin-sharing:rule-hooks.ts · sharing-plugin.ts · bu-tree-recompute.ts
PR #14528 (冲突,待合并轮)
释放即空
plugin-sharing:sharing-service.ts
PR #14726 (#14484 )
—
plugin-sharing:sharing-rule-service.ts
PR #14726 与 PR #14572 共用,区域不相交(实测) —— #14726 在 origin/main 行号 1014 / 1267 / 1284 / 1340 / 1357;#14572 在 136 / 1085 / 1118 / 1123(+49)。最近一对相距 71 行
—
objectql:tenancy/platform-object-tenancy.ts(跨域一行,裁决明令同 diff)
PR #14726
—
plugin-security:claim-seed-ownership.ts
PR #14718 (#14530 )
—
services/service-automation/src/engine.ts · suspended-run-store.ts · index.ts
PR #14712 (#14333 )
#14222 / #14392 / #14419 (一次一张)
plugin-auth:auth-manager.ts · auth-plugin.ts
PR #14600 (非本席) 持 auth-plugin.ts 784–788 ;#14373 走区域切分 ,其区在 auth-manager.ts 2070 / 3810 / 3912-3914 / 4233 / 4238 / 4251 与 auth-plugin.ts 1874
#14353
⚠️ scripts/engine-double-contract.pinned.json —— 三方争用
PR #14726 · PR #14528 · PR #14572
生成账本,⛔ 不手改:先合并再用门禁 --write 重生成
⚠️ content/docs/permissions/system-context.mdx
五个 open PR + #14600
merge driver 只认 pnpm gen:system-context-census(item 47/55);⚠️ os-regen-merge.sh 对 MIXED 冲突误报,见 #14671
⚠️ File-level, ⛔ never package-level。本班扫过 11 次;全量 31 分支扫是可行的 (item 60),但只覆盖你问到的路径 (item 64)。
4. Standing corrections
Items 1–15 stand. 16–20 只存活为摘要 (原文在 os-elon 所著、现不可达的评论里):16 安静的座位贴 ≠ 安静的座位 · 17「等别人」清单会无声腐烂 · 18 卡可以指名一个不存在的 API 而仍正确 · 19 单一所有权会在缺陷被评估前把它围起来 · 20 关掉的卡会永远挂着在飞标签。
mutex 协议两态、班次三态 ⇒ 需维护者仲裁。[finding] A seat post can go stale for a whole shift and nothing detects it — the staleness has a one-query signature, and prose in the seat post has now failed to prevent it twice running #13493
继承来的围栏是关于代码的断言 —— 重测它。
动手前先清掉卡的必验项 ⇒ 对树核,⛔ 永不对卡核。
🔴 记录持久性受限于承载卡的作者账户。Dangling-reference patrol: nothing detects an issue reference that fails to RESOLVE (as distinct from closed) — measured 6+ times, and a card's author is unreadable once it is unreachable #13634
issue_read 的 comments 不是可读评论数;分页读。
🔴 来自「回答不了该问题的命令」的零不是零,是 NOT MEASURED。⛔ 没有反向对照的零不是证据。
共享主检出不是 origin/main ⇒ 判据在 origin/main 的 worktree 里跑。⛔ 永不 git stash。
🔴 修正 26 管「某物不存在」的任何断言。「死在第 N 步」推不出「没做过第 M 步」。
check:i18n 与 check:skill-examples 用 exit 1 报「前置未满足」⇒ 读 verdict 行,永不读裸退出码。
跨陈旧基线的 git diff origin/main..HEAD 会把后来合入的文件显示成删除 ⇒ 用 git diff ..HEAD。
🔴 updated_at 晚于你上次读评论的时间 = 有你没读过的东西。
改动集变化后必须重推导门族。
⛔ 开轮标记不是坐席。 坐席 = 正文 §1/§2 + 标题 + assignee 三者同笔改成在任现值。
上一班简报里的「在飞 0」只管子代理,不管标签 ⇒ 接班按卡逐张核 pm:dispatched。
串行判断要对着围栏读 (git diff --name-only),不对着包名读;同文件不同区域可区域分割 ,前提是两边的 hunk 行号都写进本表。
issue_read get_labels 对 PR 号报错 ⇒ PR 侧标签用 pull_request_read get;issue_write 对 PR 号写 labels 可用(整体替换,先读现集)。
多 ref 一次 git fetch 后 FETCH_HEAD 不可靠 ⇒ 一律显式 sha。
🔴 标签 read-modify-write 的「read」必须紧贴「write」 。
get_check_runs 列表落后于 job API 且分页只给前几条 ⇒ 久挂的 job 用 job id 直读。
🔴 「已挂 auto-merge / 已入队」不是状态,MERGED 才是。 最便宜的权威读数是 git log origin/main --oneline | grep '(#PR)'。
[Decision] 标题 + pm:queue = 已裁、同笔转队的常态 ⇒ 读最新裁决评论定状态。
触 packages/spec 的已裁卡先切 contract-first ([Decision] Workflow resume ordering: a thrown node today leaves the run terminally unresumable — which of three shapes, given that the current order buys exactly-once across a crash? #13937 → spec: name the terminally-failed run state on AutomationResult.status — contract half of #13937 (shape 4 ruling) #14384 )。
⚠️ dispatch-gates 不为「移动了被锚定行」的改动推导 check-system-context-census ⇒ 派发令要求 dev 显式跑该门禁。
⚠️ 巡查在 PASS 后 head 移动时重挂 needs:contract-review ⇒ 补丁轮后落地前再读双载体一次。
⚠️ 维护者的并发指示随时改,以最新一条为准并写进 §1 ;上限下调时不中断在飞,只不补位。
🔴 子代理被用量上限(429)终止 ≠ 死认领,⛔ 不重派。 SendMessage 原 agent 续跑(幂等续跑令);dev 的 worktree 可能已被它自己清掉 —— 续跑令写明「不存在则从远程分支重建」。
⚠️ system-context.mdx 是本车道自己的冲突磁铁 :merge driver 只认 pnpm gen:system-context-census 重生成。
🔴 隔离复审 FAIL/DECISION 的处置 = 裁决逐字贴卡 + 补丁轮令只引用裁决、不改写;§5 非阻塞项由席位逐条定处置并写在裁决评论尾部 。
⚠️ 复审子代理的 DECISION 不是「PR 失败」 :零阻塞项 + 一个裁决未覆盖的处置问题 ⇒ 卡挂 needs-user-decision + 四棱块 + 轮报呈递;PR 停 draft、载体不清。
⚠️ 复审 §5 的非阻塞项落地后成组立一张 finding ,⛔ 不逐项立卡。但「改的是本 PR 自己新写的文字」的那几条要进补丁轮 —— 修自己的新文字不是扩面(fix(service-automation): a conditional advance claim on SuspendedRunStore, so two replicas cannot both advance one run #14712 note 2/3/4、fix(sharing): stamp organization_id on every sys_record_share write, backfill the stranded rows, admit the object to the tenancy ledger (#14484) #14726 note 1/2/3 实例)。
⚠️ 多批次卡的剩余批次派前重核锚定规则 ;落点不在本车道包 ⇒ pm:retriage + 异议评论。
⚠️ send_later 投递可迟到且不保证 ⇒ 每个轮次边界重挂一枪新的;PR 事件订阅只补充唤醒,⛔ 不替代探针。枪里的判断会过期 —— 21:08Z 那枪写着「等自动重排」,而 fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 二十分钟前已因冲突出队;⇒ 每枪先写「幂等,重读状态」,并在下一枪显式纠正上一枪的错误假设。
⚠️ 合并队列的位置与进度可读 :actions_list list_workflow_runs 过滤 event=merge_group,队列分支名形如 gh-readonly-queue/main/pr-NUMBER-MAINSHA。
⚠️ 认领可与 dev 启动分离,前提是认领评论写明启动闸门 ;槽位按运行中 dev 计。
⚠️ 本地 git merge-tree 对 census 页的「driver 拒绝」≠ GitHub 侧冲突 ;但若它真做了文本合并并报 CONFLICT (content) ,那就是真冲突,与 GitHub 的 MERGE_CONFLICT 互为佐证(fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 实例)。
⚠️ dev 报告里的 open question 若属 PM 判断范围 ⇒ 席位当场答在卡上 ,⛔ 不上交维护者;安全放宽类才上交。答案是「不做」时也要点名触发条件 ,否则它会以另一种形式回来(finding: every sys_record_share grant row lands organization_id NULL — SharingService writes under a bare system context and the row literal never carries the column #14484 的 spec 投射问题实例:答 A,触发条件 = measure: census the dependents of the SQL driver's orWhereNull tenant-wall carve-out before deciding its future (NULL org_id rows are globally visible on shared-DB walled deployments) #13564 的第一个租户面读者)。
⚠️ 「测量卡」的派发令必须把「⛔ 停在测量」写成硬约束并复述分诊原话 ;dev 若认为「一行就能修」,该念头正是裁决禁止其执行的东西 —— 写进 open_questions。
⚠️ 两个提交可有逐字相同的树 :核 git rev-parse <a>^{tree} 与 <b>^{tree} 相等 + git diff --stat 为空即可让读数对新 head 成立。
🔴 正文里的四棱块 + pm:queue = 已裁,不是待裁 (item 41 的近亲,更隐蔽):立卡人写的 os-decision-facets 块会自带「⛔ 席位不代裁」「推荐 A」这类看起来像现行状态 的句子,而裁决可能早已给出并同笔转队。判据永远是「最新裁决评论 + 当前标签」 (finding: every sys_record_share grant row lands organization_id NULL — SharingService writes under a bare system context and the row literal never carries the column #14484 实例)。
⚠️ 完整的 31 分支围栏扫描是可行的,超时不是它的固有属性 :先一次 git fetch 全部分支名再逐个 git diff --name-only。「零」成立需要三个 读数同时在场:解析到的 ref 数 = open PR 数、阳性对照非零、目标路径零命中。
🔴 merge_group 上你这张 PR 的批次 completed success ≠ 它合并了。 整批一起过才合并,同批任一 PR 失败即重组。fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 的批次 18:53Z 与 19:27Z 两次全绿都没合并 ;入队到 MERGED 因此从 25–65 分钟拉长到 90 分钟以上。
🔴 队列 flake 的处置姿态 :① 先按包与 diff 证明「不是本 PR 的」;② ⛔ 仓库有自动重排时不要手动重排 —— 手动一次要替队列里每张 PR 付一次全量重建,换一次抛硬币(test(runtime): measure which declaration copy the security/sharing seeders consume on an artifact boot with an engine #14687 正是在同一个未改动 head 上靠自动重排合并的);③ 站定说明写在 PR 上一次,⛔ 不重复;④ 锚卡若未定级,走紧急直接分诊通道升级,不要干等 (Queue-flake anchor: test/run-dev-unbuilt-workspace.e2e.test.ts #14706 因此被裁为 Queue-flake anchor: test/run-dev-unbuilt-workspace.e2e.test.ts #14648 的重复,fix 早在 domain:cli 手上)。⑤ 签名稳定不等于可以省掉核对 :当改动的代码正好在失败测试可能触及的路径上(如 claim-seed-ownership 之于 CLI 的 boot e2e),必须读 FAIL 原文。
⚠️ dev 可以静默死在一条不会到达的通知上 (它挂起去等一个 Monitor,而自己这侧已无在跑的后台子任务)。与 429 不同,没有任何信号 ;唯一线索是完成通知里那句「stops with no live background children」。续跑令要它自己去测那个它在等的状态 ,而不是继续等。
🔴 围栏 grep 只覆盖你问到的路径,而卡的文件面会长大。 认领时按四个具名模式扫,scripts/ 不在其中 ⇒ 漏掉了 engine-double-contract.pinned.json 的三方争用;而它是卡长出 backfill 模块 → 新引擎双 → 账本行之后才出现的。⇒ dev 交付后按实际 diff 重扫一次围栏 ,不要只信认领时的那次。
⚠️ 必需检查 TypeScript Type Check 在其 lane 被 cancelled 时报的是 failure 。一次被新推送取代的运行,会以一个红的必需检查出现在 PR 上,读起来与真类型错误一模一样 ⇒ 读 lane 的 OS_NEEDS 结论(cancelled vs failure)再判。
5. Notes
Round reports to the maintainer go in chat(中文);this post carries only current values. 本席定时器:send_later 一枪在案,每个轮次边界重挂(item 52)。全部 dev / 复审为进程内子代理,无 CCR 会话需归档。
⚠️ 主检出陈旧 ⇒ 门禁/派发脚本一律在 scratchpad/os-main-ro(detached worktree,每次派前 git fetch origin main)里跑。
⭐ #12981 的真实账本是仪器 :scripts/measure-durability-swallow-family.mjs。
⚠️ #13398 的维护者裁决管一整类 (PR #13592 issuecomment-5473600172):通过已发布 sink 形状上报的站点不得抬到 error。
⚠️ GitHub API 用户配额 曾耗尽。⛔ 撞上时不轮询、不循环重试,退避等待。
⚠️ list_issues 多标签过滤是 OR ⇒ 单标签整车道读全,本地求交。
⚠️ objectstack-ai/hotcrm 对本会话不可达 ⇒ 需要 hotcrm 读数的卡走 #14362 型缝卡。
This post is the single authoritative registry for the
domain:servicesseat (seat-post protocol; indexlabel:pm:seat). Single writer: incumbent only. Read side: body + comments later than the body's last edit. ⛔ 班次叙事不进正文;本贴只载当前值。1. Current PM — 🟢 在任
session_01AUF1NoViznQK32gqpK8wS8(GitHubos-sales), 2026-09-02 ~01:05Z 起,维护者召唤/pm-dispatch services;开轮标记issuecomment-5502756535;R2 ~02:57Z … R14 ~18:10Z,R15 ~19:00Z,R16 ~21:40Z。session_016ZC5rNQj3WEet5HAmmAkMs(os-steve),2026-09-02 ~00:30Z 收班。/pm-dispatch services,先读本贴。范围与常设承诺在references/lanes/services.md。packages/spec;安全边界放宽是维护者地板;⛔ 永不在代码 PR 里改content/docs/releases/**。claude-opus-5(此前claude-fable-5-1)。契约复审子代理仍显式传fable并逐轮从 transcript 验章(本班十一次验章全claude-fable-5-1);CONTRACT_REVIEW_TIER = 'claude-fable-5'字面不等 —— 同族更高档,在案 finding finding(pm-dispatch):CONTRACT_REVIEW_TIER = 'claude-fable-5'no longer matches the served Fable tierclaude-fable-5-1, so the in-seat review fuse reads a literal mismatch on every current Fable seat #14303;⛔ 不凭会话自述。⛔ 并发上限 = 3 —— 维护者指示,覆盖文档默认值
2026-09-02 ~04:25Z 指示「后续并发降到3」,~14:2xZ 重申。⇒ 同时在飞的 dev 上限 3(计数 = 正在运行的 dev 子代理,含补丁轮;已交付待复审/待落地/队列中的卡不占位)。
priority:p0插队可超上限。现在飞 3,满载。⏳ 待派队列(槽位一空按此顺序,⛔ 不跳)
✅ 契约复审:本班十一场已裁(七 PASS · 一 FAIL→delta PASS · 一 DECISION→裁 A 后视作 PASS · 两场 FAIL 待补丁轮)
PASS:#13926/#14322 · #13805/#14347 · #14157/#14352 · #13648/#14388 · #14360/#14540(R2 delta)· #12775/#14571 · #14033/#14580(R1 + delta)。DECISION → A:#13533/#14528。FAIL(补丁轮中/待派):#14333/#14712(转录 62/62 fable)· #14484/#14726(转录 90/90 fable)。全部只喂卡 + 裁决 + PR 本体,逐字采纳,双载体同笔清标,
check-clause2-carriers --pair机读 exit 0 后落地。delta 复审 = 续用原隔离复审子代理。⭐ 条款②的机械地板(#14047):新导出符号 / 发布载荷新键 ⇒ 恒
yes;新增公开 API 的 changeset =minor(#13897)。PM 收集时自己跑git diff -U0 origin/main... | grep export+ barrel 成员核一遍,⛔ 不信申报。只有包内消费者的新导出 ⇒ 要求放进非 barrel 模块,changeset 降patch(#14360 实例)。breaking runtime change 的 changeset 按 #13857 形 =minor+ BREAKING 横幅 + ADR-0087 处置标记(#14033 实例)。🔴
os-elon内容被屏蔽 — §4 item 24 · #136342. Ledger — 现值 2026-09-02 ~21:40Z
在飞 dev — 3(满载)
InMemorySuspendedRunStore.claimSuspension的nodeId/correlation比较、(C2) 删ObjectStore那侧的multi: true;今天两者都留下 49/49 全绿。外加 §5 note 2/3/4(均为本 PR 自写文字)。⛔ 设计不重开。双载体挂着MAX_BULK_PER_ROW_HOOK_ROWS的对象仍被全部认领(21 000 行现认领 0,旧代码认领 10 000)。check-tenant-audit-census红:objectName变undecidable+ 自测 5/19 失败 —— 已令其不得直接--write交差待补丁(已交付,复审 FAIL,等槽位)
recordOrganization把「读取失败」与「记录无组织」都返回null,直接授权路径遂把调用者会话的组织盖上权限边界列 —— 行非 NULL ⇒ 回填修不了、对记录所属组织不可见而对兄弟组织可见、唯一痕迹是一条文本为假的 warn;文件自己的文档注释已写明它缺的那条性质。§5 note 1/2/3 同轮,note 5 要跑门禁确认新增裸读被接受待落地 — 1
MERGE_CONFLICT踢出队列,冲突路径只有content/docs/permissions/system-context.mdx,已用git merge-tree(真做了文本合并并报CONFLICT (content))与 GitHub 双读数确认为真冲突。⛔ 不会自动重排,冲突不自愈 ⇒ 需一轮 dev 合并轮(第一顺位)。此前双载体已清并回读,--pair 14528exit 0本班落地 — 17
#14228 · #14322 · #14334 · #14347 · #14352 · #14388 · #14383(#12981 b9)· #14400 · #14532(#14348)· #14540(#14360)· #14567(#14379)· #14571(#12775)· #14580(#14033)· #14618(#13918)· #14624(#14522)· #14650(#14332)· #14687(#14491,20:21Z,
941952c15)。全部卡已关或已按其形态转态、pm:dispatched已摘读回。决策箱 / 等维护者(只列不催)
needs-user-decision存量:[Decision] The share-link route probe re-opens the existence oracle thatshare-link-servicedeliberately closed — a switched-off link with a password still answers 401 #14637 · [finding] service-job scheduler leader election excludes for the DURATION OF THE FIRE, not for the deadline — the lease is released infinally, so replica clock skew larger than the handler's runtime defeats it #14619 · [finding] Aschedule(cron) flow has no dispatch-claim ledger while atime_relativeflow does — a re-run of a digest re-notifies #14501。pm:awaiting-maintainer:Seam (enterprise organizations package): itsensureDefaultOrganizationwiring still triggers on grant inserts, which never fire on a fresh walled rig — adopt the exportedisDefaultOrganizationBootstrapTrigger#13689。跨席:spec: name the terminally-failed run state onAutomationResult.status— contract half of #13937 (shape 4 ruling) #14384 · Reading request for the hotcrm seat: does any objectstack-ai/hotcrm writer setsys_activity.environment_id? (#13433 cannot proceed without it) #14362。pm:retriage:service-automation: the two operator run-lifecycle verbs (cancelRun, restoreConsumedSuspension) have no door — no REST route, no CLI command, and not on IAutomationService #13953 · The durability log-level gate cannot see thecatch { return null; }seeder family — 15 files outside #12923's five, and neither widening path is cheap #12981 · [finding] After #12892 step 2 an artifact boot with an engine still holds a THIRD, un-parsed copy ofpermissions/capabilities/sharingRulesin the ObjectQL SchemaRegistry (AppPlugin.init→manifest.register), and the plugin-security / plugin-sharing seeders read that copy FIRST #14491(测量已落地,卡转pm:queue+pm:retriage、assignee 已释放;等分诊按实测数字改判 + 路由方向题)。可派(全序;⛔ 现满载,且待派队列有两项在前)
try_catchwhosecatchregion itself fails still discards the whole step record — the third returned-failure path, left unfolded by #14184 #14222 / [finding] service-automation: the subflow up-bubble path always logs "child run … is gone — continuing without child output" even when the engine-built signal carries the child's output #14392 / automation:create_recordcollapses the engine'sDUPLICATE_RECORDenvelope to a string, so a flow'stry_catch/faultedge still cannot tell "already there" from "the store is down" #14419(engine.ts家族,在 fix(service-automation): a conditional advance claim on SuspendedRunStore, so two replicas cannot both advance one run #14712 落地后一次一张;automation:create_recordcollapses the engine'sDUPLICATE_RECORDenvelope to a string, so a flow'stry_catch/faultedge still cannot tell "already there" from "the store is down" #14419 的NodeResult新字段属公开面扩大 ⇒ 条款② 预期 yes)sys_accountrows boots silently into an unrecoverable state — say so loudly atkernel:ready#14353(Bug p2)—— 实测 PR feat(plugin-auth): auth mail follows the caller's Accept-Language, deployment default second #14600 持auth-manager.ts/auth-plugin.ts的kernel:ready区(:784-788),同区 ⇒ 等其合并。auth 邮件(验证/重置)不按用户语言选模板:中文界面注册收到英文主题与正文 #14319 非本席{ records }off an enginefind()the contract types as an array #14460 · examples/app-crm: two comments reference a Discount Approval flow the app does not contain #14516 · finding:getPolicy()'s disabled-branchredactFieldsread has no reader oncepublicSharing.enabledis held at redemption (#14033) #14581 · changesetshare-link-enabled-at-redemption.mdsays the refusal "will burst the log once" — the warn is per-hit and unlatched, so it continues with traffic #14668 · [finding] plugin-auth SCIM harnesses register no OAuth objects, so every sign-in logs a Better Auth ERROR (back-channel logout planning failed … no such table: sys_oauth_access_token) #14615 · [finding] plugin-approvals after #12775: the tenant-admin reverse check never asserts the lock release #14602 · [finding] plugin-auth SCIM lifecycle after #14360: DELETE of the last administrator is unpinned,last-admin-guard.tsheader describes SCIM DELETE as a row delete, the timed-ban face rides a 1.5 s real-clock window #14555(p3)AutomationResult.status— contract half of #13937 (shape 4 ruling) #14384)· claimSeedOwnership claims nothing at all on an object with more than 10k rows under one unowned predicate, because MAX_BULK_PER_ROW_HOOK_ROWS refuses the whole write #14719(claimSeedOwnership writes up to 20k single-id system updates in a loop, so per-record sharing materialisation cannot batch them #14530 的溢出卡,分页测出结果后由席位定去留)维护者直派(非本席):#14318 · #14163 · #14514 · #14600(#14319)。另 #14547 / PR #14572 属他席(
session_01VR2khJ3Me96btawVsfG6jb),与 #14726 同属租户归属家族,文件面区域不相交(见 §3)。停放:#11973 · #13433(#14362)· #14328 · #13909(#13937→#14384)· #13807 · #14181
pm:blocked;H26:#11286←#7497 · #11975←#13515 · #11978←#11975/#11670;#13542pm:on-hold。本班立的 finding:dev 立 #14373(已派)· #14374 · #14392 · #14522(已落地)· #14530(已派)· #14570 · #14573 · #14581 · #14582 · #14615 · #14619 · #14671 · #14719;席立 #14555 · #14590 · #14637。
3. Hot-file serial queue
plugin-sharing:rule-hooks.ts·sharing-plugin.ts·bu-tree-recompute.tsplugin-sharing:sharing-service.tsplugin-sharing:sharing-rule-service.tsobjectql:tenancy/platform-object-tenancy.ts(跨域一行,裁决明令同 diff)plugin-security:claim-seed-ownership.tsservices/service-automation/src/engine.ts·suspended-run-store.ts·index.tsplugin-auth:auth-manager.ts·auth-plugin.tsauth-plugin.ts784–788;#14373 走区域切分,其区在auth-manager.ts2070 / 3810 / 3912-3914 / 4233 / 4238 / 4251 与auth-plugin.ts1874scripts/engine-double-contract.pinned.json—— 三方争用--write重生成content/docs/permissions/system-context.mdxpnpm gen:system-context-census(item 47/55);os-regen-merge.sh对 MIXED 冲突误报,见 #146714. Standing corrections
Items 1–15 stand. 16–20 只存活为摘要(原文在
os-elon所著、现不可达的评论里):16 安静的座位贴 ≠ 安静的座位 · 17「等别人」清单会无声腐烂 · 18 卡可以指名一个不存在的 API 而仍正确 · 19 单一所有权会在缺陷被评估前把它围起来 · 20 关掉的卡会永远挂着在飞标签。issue_read的comments不是可读评论数;分页读。origin/main⇒ 判据在origin/main的 worktree 里跑。⛔ 永不git stash。check:i18n与check:skill-examples用 exit 1 报「前置未满足」⇒ 读 verdict 行,永不读裸退出码。git diff origin/main..HEAD会把后来合入的文件显示成删除 ⇒ 用git diff ..HEAD。updated_at晚于你上次读评论的时间 = 有你没读过的东西。pm:dispatched。git diff --name-only),不对着包名读;同文件不同区域可区域分割,前提是两边的 hunk 行号都写进本表。issue_read get_labels对 PR 号报错 ⇒ PR 侧标签用pull_request_read get;issue_write对 PR 号写 labels 可用(整体替换,先读现集)。git fetch后FETCH_HEAD不可靠 ⇒ 一律显式 sha。get_check_runs列表落后于 job API 且分页只给前几条 ⇒ 久挂的 job 用 job id 直读。git log origin/main --oneline | grep '(#PR)'。[Decision]标题 +pm:queue= 已裁、同笔转队的常态 ⇒ 读最新裁决评论定状态。packages/spec的已裁卡先切 contract-first([Decision] Workflow resume ordering: a thrown node today leaves the run terminally unresumable — which of three shapes, given that the current order buys exactly-once across a crash? #13937 → spec: name the terminally-failed run state onAutomationResult.status— contract half of #13937 (shape 4 ruling) #14384)。dispatch-gates不为「移动了被锚定行」的改动推导check-system-context-census⇒ 派发令要求 dev 显式跑该门禁。needs:contract-review⇒ 补丁轮后落地前再读双载体一次。SendMessage原 agent 续跑(幂等续跑令);dev 的 worktree 可能已被它自己清掉 —— 续跑令写明「不存在则从远程分支重建」。system-context.mdx是本车道自己的冲突磁铁:merge driver 只认pnpm gen:system-context-census重生成。needs-user-decision+ 四棱块 + 轮报呈递;PR 停 draft、载体不清。pm:retriage+ 异议评论。send_later投递可迟到且不保证 ⇒ 每个轮次边界重挂一枪新的;PR 事件订阅只补充唤醒,⛔ 不替代探针。枪里的判断会过期 —— 21:08Z 那枪写着「等自动重排」,而 fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 二十分钟前已因冲突出队;⇒ 每枪先写「幂等,重读状态」,并在下一枪显式纠正上一枪的错误假设。actions_list list_workflow_runs过滤event=merge_group,队列分支名形如gh-readonly-queue/main/pr-NUMBER-MAINSHA。git merge-tree对 census 页的「driver 拒绝」≠ GitHub 侧冲突;但若它真做了文本合并并报CONFLICT (content),那就是真冲突,与 GitHub 的MERGE_CONFLICT互为佐证(fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 实例)。open_questions。git rev-parse <a>^{tree}与<b>^{tree}相等 +git diff --stat为空即可让读数对新 head 成立。pm:queue= 已裁,不是待裁(item 41 的近亲,更隐蔽):立卡人写的os-decision-facets块会自带「⛔ 席位不代裁」「推荐 A」这类看起来像现行状态的句子,而裁决可能早已给出并同笔转队。判据永远是「最新裁决评论 + 当前标签」(finding: every sys_record_share grant row lands organization_id NULL — SharingService writes under a bare system context and the row literal never carries the column #14484 实例)。git fetch全部分支名再逐个git diff --name-only。「零」成立需要三个读数同时在场:解析到的 ref 数 = open PR 数、阳性对照非零、目标路径零命中。merge_group上你这张 PR 的批次completed success≠ 它合并了。 整批一起过才合并,同批任一 PR 失败即重组。fix(plugin-sharing): let system writes materialize sharing rules — drop the isSystem skips in bindRuleHooks (#13533) #14528 的批次 18:53Z 与 19:27Z 两次全绿都没合并;入队到 MERGED 因此从 25–65 分钟拉长到 90 分钟以上。domain:cli手上)。⑤ 签名稳定不等于可以省掉核对:当改动的代码正好在失败测试可能触及的路径上(如claim-seed-ownership之于 CLI 的 boot e2e),必须读 FAIL 原文。scripts/不在其中 ⇒ 漏掉了engine-double-contract.pinned.json的三方争用;而它是卡长出 backfill 模块 → 新引擎双 → 账本行之后才出现的。⇒ dev 交付后按实际 diff 重扫一次围栏,不要只信认领时的那次。TypeScript Type Check在其 lane 被cancelled时报的是failure。一次被新推送取代的运行,会以一个红的必需检查出现在 PR 上,读起来与真类型错误一模一样 ⇒ 读 lane 的OS_NEEDS结论(cancelledvsfailure)再判。5. Notes
Round reports to the maintainer go in chat(中文);this post carries only current values. 本席定时器:
send_later一枪在案,每个轮次边界重挂(item 52)。全部 dev / 复审为进程内子代理,无 CCR 会话需归档。scratchpad/os-main-ro(detached worktree,每次派前git fetch origin main)里跑。⭐ #12981 的真实账本是仪器:
scripts/measure-durability-swallow-family.mjs。issuecomment-5473600172):通过已发布 sink 形状上报的站点不得抬到error。list_issues多标签过滤是 OR ⇒ 单标签整车道读全,本地求交。objectstack-ai/hotcrm对本会话不可达 ⇒ 需要 hotcrm 读数的卡走 #14362 型缝卡。