Skip to content

[PM seat] domain:engine — 🟢 session_01F3jdziLbAPGeceVNmSox5L · R6 · 1 in flight · 4 landed today · 4 awaiting maintainer #6367

Description

@hotlong

⚠️ This post is the RECORD of state, not the state. Every round, re-read the labels. Never read the counts here as current.

📌 Job description is versioned at .claude/skills/pm-dispatch/references/lanes/engine.md. ⛔ Not hand-copied per term.


1. Current PM

🟢 session session_01F3jdziLbAPGeceVNmSox5L · seated 2026-08-30T10:26Z via /pm-dispatch engine (maintainer summon).
Predecessor: session_01LZbWd2jNV1FErXTPSS4Dry, whose last act was 08:05:33Z on #13216: 「⛔ 本席位本轮不派(已收工)」. ⚠️ No shift-close brief was ever posted to this seat post — the newest seat-post comment is 2026-08-29T05:11:37Z and it declares 2 in flight. Seated on the summon-as-arbitration rule after conservative confirmation.

Round-mutex: CLEAR. Marker 5468137587. Reads 3 and 4 (newest lane-dispatch Claim: = 6h00m; newest closed-card claim = 6h49m) both exceed one round.

The read that nearly stood this seat down was wrong, and the correction is the load-bearing part. #13216 showed updated_at 37 seconds before fire — on its face a lane pm:dispatched card being written now. The writer was os-elon posting a contract-review verdict, which the protocol explicitly excludes: 「评审链/总监席落在车道卡上的笔迹是跨席作业不算占席」. ⇒ updated_at names a TIME, never an ACTOR. Any mutex read that turns on "who is working here" must resolve the author.

Clock: re-measured, not inherited. §6's ~3h41m-slow container is NOT this one — date -u 10:25:46Z against the newest GitHub-stamped object 10:25:09Z, agreement ~37s. ⛔ Timestamps still come from GitHub objects; the calibration only says the two agree today.

2. Ledger — this term

Card Disposition
#13195 🟢 Dispatched (opus). $exists cell measurement — ⛔ measurement only, mongo direction forked to the decision box, packages/spec/** fenced. Unblocked because #13166 landed; the previous seat had withheld it solely as a moving target.
#13324 🟢 Dispatched (opus). isMissingTableError never checks WHICH table. Direction ruled by this seat (restore-the-invariant; option 3 refused), option 1-vs-2 left to the dev on measurement.
#13178 🟢 Dispatched (opus). tenant-audit census only — triage's scope carried verbatim, ⛔ no fix, no gate, no behaviour change.
#13166 🔁 pm:retriage hung. Backend fix landed (PR #13356, verified by content: noValueSatisfiesNegation = 5 in memory-matcher.ts). Only enrolment remains, and it lives in packages/spec/src/** ⇒ spec lane. The predecessor requested the re-route in prose only, so the card kept advertising a pickable pm:queue + domain:engine. I picked it as top candidate and only the full comment re-read stopped the dispatch.
#13203 Not dispatchable. Predecessor measured the stated mechanism does not reproduce at current main; branch 1 is impossible (knex expresses neither WHERE nor COALESCE), branch 2 is a contract widening. Blocked ~22h on an unanswered question to @hotlong. ⛔ Not re-litigated this round.
#13340 Held serial behind #13195 — measured collision on memory-driver.ts.

3. Gates and landings

PR #13372 (#13216, direction 1) — contract review PASS (5468126465); os-zhuang APPROVED pinned to head 90042c379 at 10:31:30Z; enqueued (gh-readonly-queue/main/pr-13372-64f7b0d8…, control 7 queue refs). Nothing owed by this seat.

My error, recorded: I flipped #13372 to draft and back (~10:38Z → ~10:41Z, note 5468196764). I matched draft: false to §6's silent-undraft trap without reading the reviews first. The pattern fit; the binding did not — the pin-approval landed before the undraft, so the undraft was authorized and belonged to the review chain. Net state unchanged, approval intact, not ejected from the queue.
A governed PR reading ready is not itself evidence of a violation. Read the reviews before the draft bit — the release path and the violation path produce an identical draft: false.

Direction 3 of #13216 (index published pages in the command palette) still owes a dispatch, Part of #13216. It is a second contract-review surface (searchAll sweeps object RECORDS; surfacing pages is a new hit kind on the published /api/v1/search shape) — ⛔ do not fold it into anything.

4. Work at risk

None held by this seat. PM writes no files.

5. Hot-file serial queue

packages/drivers/driver-memory/src/memory-driver.ts

#13195 holds it (in flight). #13340 queued behind it — measured, not assumed: bulkCreate and the live mingo/$exists path are both in this file.
fold-or-serial answered: SERIAL, not folded. Gate ① fails (different defect shapes — batch atomicity vs filter semantics) and gate ③ fails for the neighbouring finding #13357, which is ungraded. #13166's own triage fence 3 forbids folding $exists in.

packages/drivers/driver-sql/src/sql-driver.ts

🚨 Still no CI gate behind this queuecheck-single-claim-paths.mjs declares only .objectui-sha. Two green PRs on this file are still a collision; the criterion is this seat's to enforce.
#13324 holds the write lock (its option may edit the isMissingTableError call site). #13178 is READ-ONLY here by dispatch — its deliverable is a census and its fences forbid writing source. That is what let both go out in one batch.

Measured clean this round

All 16 open PRs cross-checked by file surface. PR #13268 (the neighbouring #5499-prose sweep) verified to touch only .github/workflows/, docs/adr/ and scripts/ — ⛔ nothing under packages/drivers/**, so it does not contend with #13195.

6. Readings that must never be taken on faith

  • updated_at names a time, never an actor (§1). Resolve the author before concluding anyone is working somewhere.
  • A governed PR reading ready is not a violation on its own (§3). Reviews first, then the draft bit.
  • Timestamps come from the GitHub object, never container date — and re-measure the clock rather than inheriting a verdict about it either way.
  • 🚨 This checkout is SHALLOW. PR heads with no merge base make git diff origin/main...pr/N answer an empty diff, exit 0, no warning. Measure through the API.
  • A zero-hit is not a reading until a positive control fires⚠️ and pick the control term with care: mine failed this round (filter-logic-conformance simply does not occur inside its own file), which proves nothing about the probe. A control that does not fire invalidates the control, not the question.
  • Verify landings by content on origin/main, ⛔ not the API's merged field.
  • A CI diagnosis is measured on the run object and its job logs. Wedged runs may refuse both cancel (409) and re-run (403); the remedy is a new head SHA, ⛔ never an empty commit or close/reopen.
  • Enqueue bar is EVERY check green, not the required subset.
  • 🚨 list_issues' labels array is OR, not AND — passing two labels returned a queue inflated ~30×. Intersect locally, and page until hasNextPage is false. updated_at can lag comments.
  • Undraft works only through the MCP tool; raw REST returns 200 and does nothing. ⚠️ update_pull_request sends the draft bit whether or not you pass it — always pass it explicitly and read it back.
  • The sanitizer eats HTML-comment markers and truncates from the first tag-shaped token. ⛔ Never read a missing os-dev-report marker as "report not delivered" — read the TAIL.
  • ⚠️ A card's premise can be retired by a landing after it was filed — and its pm:* label will not notice. driver-memory's reference matcher still answers $notContains / $nin the pre-ruling way on a no-value row — the #5499 freeze that excused it dissolved 2026-08-11, so the divergence is now unexcused and untracked #13166 this round: fix landed, card still advertising pm:queue to the wrong lane.
  • ⚠️ A tracking anchor's body is never the reading — its comments are. state: open carries no information about whether it still binds ([裁决] driver-memory / driver-mongodb 投入冻结 —— 维护者 2026-08-05 口径(跨单锚点) #5499's dissolved freeze, six recorded sightings).
  • ⚠️ list_pull_requests and get_files overflow the tool token cap on this repo. They save to a file — slice it with python3, ⛔ don't retry the call.
  • GOVERNED_APPROVERS is read from the constant, scripts/pm/check-governed-queue-guard.mjs — currently ['os-zhuang', 'hotlong']. ⛔ Never copy the names into protocol text.

7. The standing rule

A premise carries the same burden as a claim in a review: measured on the current ref, with the command that measured it, or marked unverified. Reading the code is not measuring it. This applies unchanged to commit messages, CI diagnoses, labels, clocks, and to who is writing where. An absence claim needs its own measurement.

⭐ The predecessor's through-line, which this seat confirmed twice in one hour and therefore promotes to the top: each failure attached a real mechanism to the wrong subject. Every part of the sentence checks out except the binding. Both of my own slips this round were that exact shape — the round-mutex read (§1) and the governed-draft read (§3) — and in both cases the mechanism I invoked was genuinely real and genuinely mine to enforce. ⇒ Verify the binding, not just the mechanism.

Corollaries, each paid for:

8. Standing parameters

  • Concurrency 3; priority:p0 may take it to 4 — maintainer 2026-08-22.
  • Dispatch-to-PR baseline: median ~50 min, range 42–105. 45 min is the probe threshold, ⛔ never the death threshold.
  • CONTRACT_REVIEW_TIER = 'claude-fable-5' (scripts/pm/dispatch-gates.mjs). ⚠️ Fable quota measured at zero on 2026-08-29 (HTTP 429 on two dispatches); exit is the standing exemption — fable unavailable ⇒ opus, never lower, recorded with its reason in the claim comment. ⛔ Execution and contract-review share that one quota, so a clause-② card parked on review is waiting on a tier that may not exist.
  • dispatch-gates.mjs --tier is a FLOOR, never a clearance. Clause ② is not reachable from paths — it is judged from card CONTENT.
  • ⚠️ The derived gate family is not the whole farm: Lint & Repo Gates runs gates the derivation never names ([finding] dispatch-gates does not derive check-reference-carrier-shape, which CI runs unconditionally — a fresh instance of a class already closed three times #13333; PR fix(lint): narrow data-model rules to the canonical reference, and measure the two readers that stay tolerant #13322 lost a CI cycle to it).
  • Governed surfaces (docs/adr/**, .claude/**, skills/**, AGENTS.md, CLAUDE.md) — two release paths only: maintainer hand-merge, or an authorized approval pinned to the exact head. ⛔ Never flip ready, enqueue or auto-merge on your own judgment; ⛔ never approve one from an agent seat.

Seat protocol. Read boundary = this body plus comments newer than its last edit. Per-card state lives on the cards; write-side refresh at round boundaries.

Metadata

Metadata

Assignees

Labels

domain:enginepm:seatPM seat registry issue - single-writer body, index = this label

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions