fix(scripts/pm): the read-back names the collapse OVER the strip instead of calling the write lost - #19456
Conversation
…ead of calling the write lost `post-stamped --body` exited 4 "WRITTEN BUT NOT STORED ... the write did NOT land" on writes that landed whole: 13 in one shift, every one with the content intact on a fresh read. The sent body carried both a trailing newline of its own and a blank line above the footer rule, so three newlines went out before the rule; the platform stripped the newline and collapsed the run back to the block's own two. `footerReAnchoring`'s collapse arm refused that pair as an unmeasured cell -- it required `strippedNewlines === 0` -- and the tool told the seat thirteen landed writes were lost, which invites the one response that duplicates a body: a re-post. The cell is measured now, so the arm reads the TRIMMED body and ONE arm covers the collapse alone and the collapse over the strip. Everything else holds: the head is still compared literally against a candidate BUILT from the sent bytes, so a content byte lost or changed, a chewed footer, a whitespace truncation in the content and a footer RELOCATED to another position all still exit 4 -- pinned as controls, the relocation one because a multiset compare is exactly what this verdict must never become. Claude-Session: https://claude.ai/code/session_017ETYWqMQD4qMtZzAGovWNi Co-authored-by: Claude <noreply@anthropic.com>
Contract reviewServed-tier: ① Derived judgments
② Semver levelNone — nothing published; ③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
… closure, and the allow rules that let seats run it (ruling 「B(治本)」) (objectstack-ai#19479) Fixes objectstack-ai#19469 Clause-②: no ## The ruling this lands under, verbatim 「B(治本):给具名脚本加一条 Bash 允许规则进 .claude/settings.json(受管面,走 PR 您合),此后席位的批量关闭不再靠分类器掷硬币。分诊席的 objectstack-ai#19292 加了 4 条规则但没覆盖这个形状。你负责派发」 A second ruled source touches the same file: batch objectstack-ai#204 item 4, letter A (「204 同意」, recorded on objectstack-ai#19362) authorises the objectui spellings of the two landing-endpoint allow rules. Those two entries are **not in this diff** — see *Scope addition, refused mid-round* below. objectstack-ai#19362 is not addressed here and remains open. ## The measured defect Two seats, one wall, one day. A 90-card closing sweep spelled as a bash loop over `post-stamped.mjs` → `label-write.mjs` → `PATCH /issues/{n}` was refused by the session runtime's write classifier before any request. The second seat took the same order (objectstack-ai#19458, execution log 5753693136): 90 of 90 cards passed its live gate, 77 were actionable, **one** closed, and then a batch script, an inline three-card loop and a *single* `post-stamped --comment=19243` were each refused — the identical command shape that had just succeeded twice. It stopped rather than grind a coin-flip channel across 76 three-step acts, because a comment that lands without its label write is a half-state on the board. Why the existing rules did not cover it: the two seat-write rules carry `--use-env-proxy` **inside the prefix**, and seats invoke `node scripts/pm/post-stamped.mjs …` (the tool re-execs itself with that flag), usually behind a `cd … &&` compound. An allow rule is a prefix match against the command *as typed*, so neither matched and every call fell to the classifier. No rule named a batch shape at all. ## What lands **1. `scripts/pm/close-cards.mjs`** — the three-step closure (comment · label · close) as one named command, ⛔ no new gate. Per card, re-read live first, then SKIP and log on: not open · has an assignee · carries `pm:retriage` · pm-state is not *exactly* the expected label (default `pm:queue`; no state, another state and two states all skip) · an open PR references it (`--skip-pr-referenced`, default on). Otherwise: post the comment, remove the state label, close with the `state_reason` — and read the close back, because a 200 whose body does not say `closed`, or that records another reason, is not the close that was asked for. Stamping and the four-step label write are **reused, never re-implemented**: post-stamped's write path is module-private (`writeArtefact`/`main`), so it is driven as a child process with its documented flags (`--repo=`, `--comment=N`, `--file=`, `--json`) and its exit code read before any pipe; its exported pure half (`renderBody`, `claimKeyedLineRefusals`) runs the comment pre-flight **once**, before card one, rather than ninety times. The label step calls label-write's exported `runLabelWrite` in-process with options built by label-write's own `parseOptions`. The pm-state vocabulary is imported from `check-half-states.mjs`. A card whose comment landed and whose label write or close did not is a HALF-WRITE: the run **stops at that card** and exits 4 naming it and exactly which of the three writes landed. It does not continue and it does not retry — continuing turns one half-state into a page of them. Exits: `0` every non-skipped card landed all three writes · `2` usage · `3` PREREQUISITE NOT MET · `4` HALF-WRITE, the card is named · `5` the platform refused a write. **Which PR reading** — `GET /repos/{o}/{r}/issues/{n}/timeline`, `cross-referenced` events whose `source.issue` carries a `pull_request` and whose `state` is `open`. That endpoint is the one `references/rest-channel.md` already declares reachable for cross-references. ⛔ Not `/search/issues` (the egress proxy refuses `/search/*` by design, so the default skip would be unavailable on exactly the seats this tool is for) and ⛔ not a `closed_by_pull_requests`-style signal, which answers "which PR would close this" — narrower than "an open PR references it", and it would pass a card an open PR merely mentions. **2. `.claude/settings.json`** — four `permissions.allow` entries: `Bash(node scripts/pm/close-cards.mjs *)`, `Bash(node --use-env-proxy scripts/pm/close-cards.mjs *)`, and the no-flag spellings of the two existing seat-write rules, `Bash(node scripts/pm/post-stamped.mjs *)` and `Bash(node scripts/pm/label-write.mjs *)`. `deny` is untouched; key order and formatting unchanged. **3. Usage** — in the script header, with the reason: invoke it **from the repo root with nothing in front of `node`**, no `cd … &&` compound, because the rule matches the command as typed. `references/rest-channel.md` gets **no** line: `pnpm check:pm-skill-ratchet` reports that file at 82 lines against a ceiling of 82 — headroom 0 — so the header carries it alone, exactly as the card's item 3 provides for. **Minimal registration**, stated as the card asks: `check:pm-close-cards` in the root `package.json` and one step in `lint.yml`, beside the identical pair for post-stamped and label-write. Without it the new self-test would ship unrun by CI, which is the state `check:self-test-wired` exists to prevent — it now counts 220 scripts and this one is in the population. ## A defect this found in its own first reading The first dry run over the 90 cards exposed a truncation in the script's own timeline read. Measured: of those 90 cards, **objectstack-ai#13799 carries more than 100 timeline events**, so a single `?per_page=100` request returned a truncated history at HTTP 200 with nothing saying so — and a cross-reference on page 2 reads exactly like no cross-reference at all, i.e. the open-PR skip answering "no" for a card that has one. Fixed in the second commit: `readTimeline` walks by **page number** until a short page (the spelling `references/rest-channel.md` prescribes, cursor exhaustion having been measured on this platform to stop early), and a card still returning full pages at the 30-page cap **stops the run** rather than deciding on what it managed to read. The fake board pages for real, so the truncation case is driven rather than modelled. ## Verification **`--self-test`** — `node scripts/pm/close-cards.mjs --self-test`, exit 0: `OK close-cards self-test: 102 cases pass across 11 batteries — offline, no network, no token.` Battery roster, per-battery floor and the verdict handshake all copied from the landed shape in `label-write.mjs`. **Three ablations, each with the mutation proved on disk and the restore proved byte-identical** (`scripts/ablation-replace.mjs`, blob `a04f59d49673` before and after every leg, `git diff HEAD` empty): | leg | mutation | reading | |---|---|---| | A — a rule | delete the `pm:retriage` skip | blob `a04f59d49673` → `f455f723528c`; self-test RED, 1 of 102, naming that case | | B — the handshake | `return 0` before the verdict | blob → `44141e535b3c`; dispatch refuses, exit 1, "selfTest() returned without reaching its verdict" | | C — the floor | delete one assertion | blob → `d0d6a6169a2b`; RED with 0 case failures and 1 floor problem, naming the battery that fell 8 → 7 | **`--dry-run` over objectstack-ai#19458's 90 numbers** (a READ; it wrote nothing, on any card), re-run at `901b26ea` after the pagination fix: ``` close-cards: DRY RUN — nothing will be written. objectstack-ai/objectstack · 90 card(s) · reason `not_planned` · expect-state `pm:queue` · open-PR skip ON objectstack-ai#19408 SKIP an open PR references it (objectstack-ai#19445) objectstack-ai#19325 SKIP not open (state closed/not_planned) objectstack-ai#19146 SKIP has an assignee (`os-steve`) — somebody owns it objectstack-ai#19240 SKIP an open PR references it (objectstack-ai#19335) close-cards: DRY RUN — nothing was written. 90 read · 86 actionable · 4 skipped ``` **86 actionable / 4 skipped**, against the card's 77/13 read at 00:01Z. The card provides for the move; the move is measured rather than assumed. Probing every cross-referenced PR on the 86: **11 of those cards had their referencing PR close after 2026-09-21T00:00Z** — objectstack-ai#19440, objectstack-ai#19404, objectstack-ai#19396, objectstack-ai#19395, objectstack-ai#19390, objectstack-ai#19343, objectstack-ai#19336, objectstack-ai#19319, objectstack-ai#19309, objectstack-ai#19179 and objectstack-ai#18375, ten of them on PR objectstack-ai#19456 alone, closed 00:34:28Z. Of the remaining two, objectstack-ai#19325 is the one card the triage seat closed before it stopped, and objectstack-ai#19146 has since gained an assignee. The matrices agree; the board moved. **Gates** — derived with `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` against the diff (68 commands, the list identical before and after the second commit), each exit code captured before any pipe. Green includes `check:pm-settings-deny-roster`, `check:pm-widening-tells` (and the real diff judged with `--declaration no --diff`: no tell, "no declared surface covers it (4)"), `check:pm-skill-ratchet`, `check:self-test-wired`, `check:self-test-workflow-commands`, `check:pm-dispatch-gates`, `check:nul-bytes` and `check:pm-close-cards`. **`pnpm lint` (`eslint . --no-inline-config`) is green over the whole repo at exit 0 — no narrowing, so no narrowing to justify.** Six derived families answer **PREREQUISITE NOT MET — a built tree is required** and are NOT MEASURED locally: `check:dts-closure`, `check:dual-build-cjs-loads`, `check:lean-entry-closure`, `check:sourcemap-no-sources-content`, `check:type-check-debt` and the lint package's `check:doc-formula-expressions`. Each reads `dist/`; this diff contains no package source and produces no `dist/` byte, so it cannot move any of them, and CI runs them on a built tree. ⛔ Recorded as not measured, not as green. ## Scope addition, refused mid-round A mid-round scope addition asked for two further `permissions.allow` entries — the objectui spellings of the two landing-endpoint rules that already exist for objectstack (`.../objectui/pulls/*/ccr/ready_for_review` and `.../objectui/pulls/*/ccr/auto_merge`), placed after their objectstack twins. **They are not in this diff.** Both attempts to write them were refused by this session's own permission classifier with reason `[Self-Modification]` — once through a scripted edit, once through the editor tool — and a third route was not attempted. The working tree is clean and nothing partial landed. This is the same classifier, on the same file, that had permitted the four entries above earlier in the same round: a third observation of the non-determinism this card was filed for, now on a file surface rather than a write channel. A seat with a channel adds those two lines, or the maintainer adds them at merge. ## Tier and landing **Tier S by the register** (`GOVERNED_SURFACES` in `scripts/pm/check-governed-merges.mjs`): the diff touches `.claude/**`. Per the maintainer's directive above (「受管面,走 PR 您合」) **the maintainer merges this by hand**. ⛔ This PR is not flipped to ready, not queued, and auto-merge is not armed. `Check Changeset` wants `skip-changeset`: no released package is touched. The four paths are `.claude/settings.json`, `scripts/pm/close-cards.mjs`, `.github/workflows/lint.yml` and the root `package.json` (private, `@objectstack/spec-monorepo`, a `scripts` entry only) — every one of them on the non-publishing fast track. The label is the seat's to apply. ## Acceptance notes Noted, not filed: - `references/rest-channel.md` has **headroom 0** (82 lines, ceiling 82), and so does every other ceilinged file in that ratchet. The channel table therefore cannot gain a row for this script without a ruled raise or an equal deletion. Carrier: the next PR that raises that ceiling. Observation, not a defect. - `--dry-run` buys one card read per card and a timeline walk only for a card that would otherwise be acted on. A future batch larger than this one may want a `--json` summary for the completion comment; nothing needs it today. Carrier: none. ## 维护者速读(草稿) **改了什么** — 新增一个具名脚本 `scripts/pm/close-cards.mjs`,把「评论 · 摘标签 · 关卡」这三步合成一条可被允许规则整条命中的命令;并在 `.claude/settings.json` 的 `permissions.allow` 里加了 4 条规则(这个脚本两种拼写,加上两个既有工具的无 flag 拼写)。`deny` 一个字没动。 **为什么改** — 批量关卡以前是 shell 循环,每一步都由会话的写分类器逐条判,判得不稳:同一条命令刚成功两次就被拒,90 张卡关到第 1 张就停了。停是对的——评论落了标签没落就是半状态——但代价是这批清理走不动。一条具名脚本 = 一条前缀,分类器不再掷硬币。 **风险与代价(含回滚)** — 风险最集中的一点是「半写」:脚本在第一张半写的卡上立刻停,退出码 4,并点名是哪张卡、哪几步落了,⛔ 不继续、⛔ 不重试。回滚代价为零:删掉这个文件和那 4 行规则即回到今天,没有任何其它代码读它。另一项要请您留意的是,允许规则本身是放宽面——它放宽的是「跑本仓自己的三个 PM 脚本」,不是任何网络写端点。本轮还有 2 条 objectui 的规则被会话分类器当场拒写(见上节),不在这个 diff 里。 **席位意见** — (留空,待席位复审填写) **你要做的** — 读一眼那 4 行允许规则是不是您想给的面,然后手工合。⛔ 本 PR 不翻 ready、不入队、不挂 auto-merge。合完之后,这批 90 张卡的关闭由分诊席跑一次 `--dry-run` 再跑一次实关,日志回贴 objectstack-ai#19458。 --- _Generated by [Claude Code](https://claude.ai/code/session_012GcsUbuqFGBibkEDMRC1eE)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Fixes #19312
Clause-②: no
post-stamped --bodyanswered exit 4 —WRITTEN BUT NOT STORED … the write did NOT land— on thirteen writes that had landed whole. The response a false NOT-STORED invites is the one that duplicates a card body: a re-post.What was measured
Thirteen
--bodywrites in one shift exited 4 on the same one-line difference: 7 of 11 at 2026-09-20T21:40Z (#19343 · #19360 · #19390 · #19392 · #19395 · #19396 · #19404) and 6 more at 22:31Z (#19179 · #19221 · #19309 · #19336 · #19439 · #19440). The body sent\n\n\n---before its trailing footer rule and the platform stored\n\n---, content byte-identical on a freshGET.Reproduced offline on this branch's base (57ceb9d), with the stored tails read back from the cards themselves:
H+\n+ blockH+ blockfooter-blank-collapsed, exit 0H+\n+ block +\nH+ blockmutated, exit 4footer-blank-collapsed, exit 0H+ block +\nH+\n+ blockfooter-re-anchored, exit 0H+\n\n+ block +\nH+ blockmutated, exit 4The failing row is the shape a seat post's
--bodywrite actually sends: the file ends in a newline and its last paragraph stands a blank line above the rule, so three newlines go out before the rule and one after the block. The platform strips the trailing newline and collapses the run back to the block's own two. Two acts, both already declared on their own; the classifier had no arm for the pair.The one predicate that decided it
footerReAnchoring's collapse arm requiredstrippedNewlines === 0and readsentText. It now reads the trimmed body, so ONE arm covers the collapse alone and the collapse over the strip:Still an exact
===against a candidate BUILT from the sent bytes, and the head is still compared literally. ⛔ No multiset compare, ⛔ nothing position-insensitive, ⛔ no pattern, ⛔ no length test.The DECLARED set, before and after
Only one row moved, and it moved by naming a cell that is now measured rather than by widening a comparison.
footer-blank-collapsed: the stored body is that body with the blank line immediately before the footer block's rule collapsed — one newline of the block's own separator gone, and no content byte touched. The arm refused the pair in prose too: a sent body that carried trailing newlines AND came back collapsed is a cell nobody has measured, and an unmeasured cell is not one this tool forgives.identical,trailing-newline-stripped,footer-appended,footer-re-anchored,mutatedare untouched, and no class was added: the vocabulary is still six words.The rendered line had to move with it, because it said the one byte short is that separator newline about a body that is now two short. It names the second byte when there is one:
COLLAPSED, over 1 stripped trailing newline(s), so the byte(s) short are that separator newline and the newline(s) the platform does not keep, and every CONTENT byte sent IS stored.The three pinned fixtures
removed_from_merge_queuefires on a SUCCESSFUL merge too — 3 of 5 on this board today were merges, so the event is not a failure signal #19343 · 3585, [finding] thespec-property-retirementplaybook prescribes amajorchangeset that a live per-PR gate refuses — copy the checklist line verbatim and the PR reddens #19360 · 2892, [finding] a job log refused over REST is still readable through the MCP read tool — a seat mis-read one blocked channel as no channel and mis-diagnosed a queue ejection #19404 · 4623): classifiesfooter-blank-collapsedwithstrippedNewlines: 1, lands, exit 0.firstDifferingBytepinned at 0.Plus the pin this change had to rewrite rather than delete: the case that asserted
footerReAnchoring(sent + newline, collapsed) === nullpinned exactly the branch being removed, so it now asserts the measured shape and its recordedstrippedNewlines. Every other exit-4 control in both footer batteries is untouched and still green — a byte lost before the rule, a byte changed, a chewed footer, a rewritten link, a truncation ending in the block, a newline from nowhere, both separator newlines gone, and the whitespace-only truncation in the CONTENT (row 4 of the table above).The relocation decision, on the four axes
The card's original claim was a pure RELOCATION of the footer — sent and stored differing by position while the multisets are identical — and suggested a multiset compare. That shape stays exit 4, pinned as fixture 3.
no workarounds: a positional exemption with no reading behind it is tolerance, not a contract.identicalfor a body the platform rewrote in 482 places — the one case read-back exists to catch #19350 worse: that card is the read-back going SILENT on a body the platform rewrote in 482 places, and a rewrite that happens to preserve the byte multiset would pass a multiset compare. Strictness on the loud side must not be bought with silence on the quiet one.The boundary this change holds
#19350 (closed) is the OPPOSITE direction of the same comparison and the reason widening is refused. The only newly forgiven shape here is
stored === (sent minus its own trailing newlines, with the footer block's leading blank line collapsed). Any content rewrite — including a 482-place one — makes that===fail, so nothing in this change moves the read-back toward silence. The boundary is re-stated in prose in the classifier docblock; #19350 is not addressed here.Verification
node scripts/pm/post-stamped.mjs --self-test:: exit 0 — 544 cases across 18 batteries, up 14.strippedNewlines === 0 &&— throughscripts/ablation-replace.mjs, anchor hit 1 time, blob46734b107fcdtob24615b0ab9aon disk — turns the self-test red in exactly the expected direction: 9 of 544 cases fail, all of them the new ones, 0 floor problems. Restore leg verified against HEAD's blob, not an exit code:blob == HEAD (46734b107fcd)andgit diff HEADempty.node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack, no paths): 30 families, each run with its exit captured BEFORE any pipe. Reconciled with--ran: 30 derived, 30 run, 0 UNRUN.GOVERNED_SURFACESregister inscripts/pm/check-governed-merges.mjscarriesdocs/adr/,.claude/,skills/,AGENTS.md,CLAUDE.mdanddocs/NORTH-STAR.md—scripts/pm/**is on none of them. The--pairreading is in the report on the card.Acceptance notes
.claude/skills/pm-dispatch/references/platform-readings.md:360 records the tool's pre-fix behaviour as a fact — 「送全块即触发该归一 ⇒post-stamped的body档把这点空白判mutated,净零字节良性告警。」 — and is stale once this lands. That file is a governed fact table and outside this card's declared file surface; carrier: thedomain:skillsseat, alongside this PR. Line :359 (「平台在尾部---前后正反两向归一空行」) is unaffected and is in fact the reading this change acts on.\n\n\n---reaches the platform because the body FILE carries the extra blank line, not because the tool adds one. Whether the seat's body composition should normalise its own tail before the write is a separate question from whether the read-back should name what the platform does with it; noted, not filed — this PR changes only the instrument's reading.Generated by Claude Code