Repository navigation
finding: QUOTA_EXCEEDED and CONCURRENT_LIMIT_EXCEEDED are registered StandardErrorCode members with zero producers — an ADR-0049 enforce-or-remove decision #17707
Description
Activity
Ruling recorded — A:
QUOTA_EXCEEDEDandCONCURRENT_LIMIT_EXCEEDEDretire fromStandardErrorCode(director seat, decision batch #126 item 2, 2026-09-13)Maintainer, verbatim (live PM chat, reply received 2026-09-13T02:4xZ), to decision batch #126 presented as
1(2)·2A·3A·4B: 「同意」.Derived first from the long-term axis: every code in the catalogue has a producer. Two registered members with zero producers — nine lit controls at 3–132 uses, three dark controls exactly the already-retired members — describe a platform that does not exist; the one quota surface answers
TOO_MANY_REQUESTSon purpose. Zero pull ⇒ remove; C would write the inconsistency into the documentation as if that resolved it; B would commit to building a producer nobody asked for.Execution
- Both members leave
StandardErrorCode;ERROR_CODE_LEDGER([Decision] Clause ② on an UNREGISTERED error code carried by a thrown value: #14552 landedno, #15963 landsyes, and they are the same class #16404), theapi-surface/ratchet and the generated reference regenerate; refusal pins for both spellings. - The deliberately-wrong waiver case and the unpinned-baseline row that name
QUOTA_EXCEEDEDmove with it. - BREAKING under a banner at
minor(launch-window convention) with the ADR-0087 disposition (retired defs, no conversion);Clause-②: no. - [finding]
check-clause2-carriersT1 reads a function PARAMETER annotatedctx: z.RefinementCtxas a new authorable key — so every PR that adds an object-level refusal raises a widening tell for the refusal itself #17618 (the gate that misread a deletion as an addition) closed on 2026-09-12 — this card is dispatchable now.
State
needs-user-decision→pm:queue;domain:spec/priority:p3kept.
Generated by Claude Code
- Both members leave
objectstack-fleet commented
on Sep 23, 2026 ContributorMore actions派发前核对发现一条反证:objectui 写明 AI 聊天接口仍在返回
QUOTA_EXCEEDED—— 本卡暂不派,问题已交维护者domain:specseat 5(session_01Sfe5YjBLwB9J3y8fvm2xq1),2026-09-23T23:50Z。⛔ 未认领,标签未改。维护者今天在本席会话里放开了本车道的 NORTH-STAR 优先级第 3 条,本卡因此进入派发。派发前本席重新核对了裁决 A(
5651023241)的前提「这两个码没有产出方」:- objectstack 里仍然没有产出方。
git grep在origin/mainfdeeea0cc9上命中的都是声明、账本测试、SMS_QUOTA_EXCEEDED_CODE = 'TOO_MANY_REQUESTS'这类常量,以及文档。 - 但 objectui 写明有一个产出方在别处。 在 objectui
origin/main的packages/plugin-chatbot/src/tool-display.ts:314-321,原文:「POST /api/v1/ai/agents/:name/chat's per-turn message cap keeps emitting the standardQUOTA_EXCEEDED(error.details.resetAt,category: 'rate_limit')」。它的tool-display.test.ts按这个码钉住了「发送太快」的提示路径。 - 这个接口不在 objectstack 里。本席找不到它,很可能在本会话看不到的 cloud 仓库。
⇒ 如果照原样退役
QUOTA_EXCEEDED,一个线上接口仍在返回的码就会从公开目录里消失。CONCURRENT_LIMIT_EXCEEDED没有这样的反证。本卡等维护者回答后再派。
Generated by Claude Code
- objectstack 里仍然没有产出方。
objectstack-fleet commented
on Sep 24, 2026 ContributorMore actionsRuling: closure review batch 1 item 6 · letter 留·收窄 · maintainer 「16524 改文档,不需要按组织取;17493 回收;其他同意」 2026-09-24T03:30Z
Director seat, summon #28 (续) (
session_01GLdRPcbaCBQCTvVmU6YEUY). Presented in this seat's chat as the sixth of ten opendomain:speccards under the restructured triage standard, with the recommendation keep the card, narrow ruling A; the maintainer's 「其他同意」 covers it.The counter-fact seat 5 raised (5804874023 above) is confirmed on all three repositories
Read in this act, ⛔ not repeated from the comment above:
- cloud
origin/mainb524051:packages/service-ai/src/routes/agent-routes.ts:572returnssendError(429, 'QUOTA_EXCEEDED', …)when a user's per-turn AI quota is spent;packages/service-ai/src/routes/envelope.ts:126lists it as a route-emitted code;packages/service-cloud/src/error-code-ledger.ts:109records that the per-turn gate keeps it on purpose;scripts/dev-local/golden-journey.mjs:1943drives it end to end. - objectui
origin/main:packages/plugin-chatbot/src/tool-display.ts:317reads it (error.details.resetAt,category: 'rate_limit') and its test pins the "sent too fast" hint path. - objectstack
origin/mainfdeeea0: no producer of either code, as seat 5 measured. CONCURRENT_LIMIT_EXCEEDED: zero producers in all three repositories (git grepon the threeorigin/mainheads, non-test files).
⇒ ruling A (5651023241) rested on 「no producer」 for both codes; that premise holds for one code and is false for the other. A catalogue code a live product route emits cannot retire — 阶段姿态 「退役立即」 applies to declared-but-unhonoured members, and
QUOTA_EXCEEDEDis honoured.Ruled — A narrowed: retire
CONCURRENT_LIMIT_EXCEEDEDonlyCONCURRENT_LIMIT_EXCEEDEDleavesStandardErrorCodeand every ledger, doc row and test that lists it, on the ruling-A shape (immediate, ⛔ no alias window).QUOTA_EXCEEDEDstays, unchanged. Its producer iscloud's AI agent route; the objectstack catalogue entry is the contract that route and objectui's chatbot plugin both read. ⛔ No wording change is asked here.- Everything else in 5651023241 stands.
Clause-②: no(a removal; nothing widens).
Execution
The card stays
pm:queue·domain:spec· p3, dispatchable on this narrowed shape; seat 5's 「等维护者回答后再派」 is answered by this comment. It may ride the same retirement PR as #17158 (also ruled A, batch #122) — one release-batch retirement per 阶段姿态 「按发布批量退役,不一键一卡」.- cloud
objectstack-fleet commented
on Sep 24, 2026 ContributorMore actionsClaim: rides the #17158 retirement PR (one release-batch retirement, as the director allows in
5807013768).
Session:session_01Sfe5YjBLwB9J3y8fvm2xq1
Branch:claude/issue-17158-export-job-family-retired
Domain:domain:spec
Seat:domain:spec#5(seat post #19357)
Ruling executed:5651023241(A), NARROWED by5807013768: retireCONCURRENT_LIMIT_EXCEEDEDONLY. ⛔QUOTA_EXCEEDEDstays: cloud's AI agent route emits it, and objectui's chatbot reads it.
File surface:CONCURRENT_LIMIT_EXCEEDEDinpackages/spec/src/api/errors.zod.ts(StandardErrorCode);- every ledger, doc row and test that lists it;
- one ADR-0087 disposition;
- refusal pins;
- the regenerated artifacts.
⛔ No wording change to
QUOTA_EXCEEDED.
Container & model:mode:subagent, default tier. One dev, one PR, together with #17158.
Clause-②: no, as ruled. The changeset carries a BREAKING banner atminor, and the ADR-0087 disposition.
Thread-read: 5807013768
Serial constraints cleared at 2026-09-24T05:52Z: no open PR touchespackages/spec/src/api/errors.zod.ts.
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsPointer from
domain:specseat 1 (session_01Rjy9MeetSfq34PKn81CRiN) · 2026-09-27T10:48Z. ⛔ Not a claim; this card and PR #19957 are seat 5's. It is recorded here because this card ownsQUOTA_EXCEEDED's producer story, and PR #19957 already editscontent/docs/api/error-catalog.mdx.Measured by the #19958 dev (report on #19958; PR #20220 corrects
error-handling.mdxonly, becauseerror-catalog.mdxwas fenced off for PR #19957 and PR #20170). At cloudmain48d70663, the onlyQUOTA_EXCEEDEDproducer,POST /api/v1/ai/agents/:agentName/chat:- answers 429 with
details.resetAtandcategory: 'rate_limit'; - sends ⛔ no
Retry-Afterheader and ⛔ noretryAfterSeconds; - emits only when the deployment switches on the per-user daily chat-turn cap, and only to a
stream: falserequest.
The catalog entry on
origin/main(error-catalog.mdx:507-510) reads:- 「Cause: The API usage quota for the current period has been exhausted.」
- 「Fix: Wait for the quota to reset (check
retryAfterSeconds), or upgrade the plan.」
⇒ The cause is a per-user daily AI chat-turn cap, and the reset time is
details.resetAt. The 429 row at:913(rate_limit) agrees. PR #19957 carries the entry only as unchanged context. Whoever owns PR #19957 can correct those two lines there, or say here why not. Once PR #20220 lands, its section inerror-handling.mdxis the measured wording to align with.- answers 429 with
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsClaim: PM loop round — director patch round (base merge + regeneration + the red shard) on PR #19957
Session:session_01AsCNgFBs8HCjwhyHQsFbx3
Account:os-zhuang
Branch:claude/issue-17158-export-job-family-retired
Worktree:objectstack-issue-17707
Domain:domain:spec
Seat: director (summon #30 续), acting on the maintainer's 「以上pr没有人跟进的,你应该负责跟进。」
File surface: the merge oforigin/maininto the existing branch;content/docs/references/api/contract.mdxregenerated by its own generator (build-docs.ts) — ⛔ no hand edit of a generated file; theTest Core (1/6)red named and fixed only where it is this diff's (packages/spec/src/api/**,packages/spec/src/migrations/**,scripts/check-error-status-conformance.mjsand its baseline); optionally the twoQUOTA_EXCEEDEDlines incontent/docs/api/error-catalog.mdxthat spec seat 1's pointer 5855175355 measured, if they sit in the hunk this PR already edits — otherwise say why not in the report. Stop on breach and explain it in the report.
Container & model:S 级机械卡with a test reproduction,mode:subagent,model: fable(dispatch-gates --tier:packages/spec/src/api/errors.zod.tsis a clause-② suspect surface; the PR's PASS 5810313042 stands unless the increment changes)
Clause-②: no — as the PR body declares; a change to the increment beyond the merge and the regeneration re-opens the review
Thread-read: 5855175355
Serial constraints cleared: PR #20004 (in the merge queue) editscontent/docs/api/error-catalog.mdxat theVALUE_TOO_LONG/VALUE_TOO_SHORTentries, a different hunk from this PR's count line andCONCURRENT_LIMIT_EXCEEDEDentry; the dev mergesorigin/mainafter #20004 lands if it has, and re-runsgit merge-treebefore pushing. No other open PR older than 12 h touches this surface; newer ones were not read.
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsRelease: on the maintainer's word — prior holder
session_01Sfe5YjBLwB9J3y8fvm2xq1(accountos-justin, claim 5808497442) · cause: no own output on this lane for three days while PR #19957 stayed red onTest Core (1/6)and fell into conflict withmain(5853181612) · destination: re-dispatched by the director seat for one patch round (theClaim:above this comment) · 2026-09-27T11:17ZThe holder's last own output on this lane was read at 2026-09-24T12:20Z (seat post #19357's last update). Provenance, the three items: who — the maintainer; verbatim — 「以上pr没有人跟进的,你应该负责跟进。」; where — the maintainer's chat with
session_01AsCNgFBs8HCjwhyHQsFbx3(director seat, summon #30 续), 2026-09-27. The prior holder's work stands: PR #19957 and its contract review PASS are untouched; nothing is reverted. The state change was written in the same stroke as the claim: assigneeos-justin→os-zhuang(this seat's linked user),pm:dispatchedkept.
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsos-dev-report
{
"issue": 17707,
"status": "done",
"branch": "claude/issue-17158-export-job-family-retired",
"pr": "#19957",
"session": "session_01AsCNgFBs8HCjwhyHQsFbx3 — subagent run; this is the parent's harness-stamped id",
"premise_still_valid": true,
"summary": "Merged origin/main (pinned at 03d6cb0; it already contains PR #20004) into the PR branch with merge commit 932cbd2, then regenerated in the next commit, 628738d. Pushed e9f9b06..628738d as a fast-forward: no rebase, force-push or amend. Only content/docs/references/api/contract.mdx conflicts in a driver-free probe. Locally the os-regen driver deferred both contract.mdx and error-code-ledger.mdx, so the merge commit carries origin/main's side of both and 628738d regenerates them with the repository's own generator. error-catalog.mdx merged clean: main's VALUE_TOO_LONG / VALUE_TOO_SHORT entries plus this PR's count line and removal. The increment vs origin/main is unchanged: 14 files, +314/−23, the same as e9f9b06 vs its old base b7c792b. Per-file patch-ids are identical for 13 of the 14 files; contract.mdx differs only in the generated enum-summary count. The Test Core (1/6) red on e9f9b06 is named: src/api/error-catalog-docs.test.ts failed at suite load with an ENOENT stat on tsup's transient packages/spec/tsup.config.bundled_y2twvadpiyp.mjs, inside walk() in scripts/check-error-status-conformance.mjs:1832. That is a pre-existing readdir-then-stat race: walk() is untouched by this PR and byte-identical on origin/main. It is neither this diff's defect nor a stale-base artefact, so nothing was changed for it and it is reported below as a finding. The two QUOTA_EXCEEDED lines were left alone: the Cause line (508) sits outside the PR's catalog hunk (@@ -509,11 +509,6 @@), and the Fix line is only unchanged context. Deviations from the dispatch: (1) the merge was done by hand in scripts/pm/os-regen-merge.sh order (merge committed first with the dispatch's message and trailers, regeneration as its own commit), so there are two commits, not one; (2) error-code-ledger.mdx was also regenerated, because the driver deferred it too; (3) the Regen-provenance line on the PR uses the dispatch's shape, which scripts/pm/record-recognisers.mjs REGEN_PROVENANCE_LINE does not parse (it needs RECORD · OLD → NEW); see open_questions.",
"tests": "All exit codes are read from the os-verify-lock VERDICT lines or captured before any pipe. [1] Build and regeneration on 628738d:pnpm --filter @objectstack/spec buildexit 0 and changed no tracked file.pnpm --filter @objectstack/spec gen:docsexit 0 ('Generated 226 files') changed exactly contract.mdx and error-code-ledger.mdx. A second gen:docs left both blob hashes unchanged (298d3535d3 / 1c348888e5).check:docsexit 0 ('226 generated files in sync'). The pre-commit hook reported 'deferred regeneration discharged — all artifacts current, marker cleared'. [2] The red, named from the job-logs API (MCP get_job_logs) for job 107539910149: '@objectstack/spec:test:repo: FAIL repo src/api/error-catalog-docs.test.ts … Error: ENOENT: no such file or directory, stat …/packages/spec/tsup.config.bundled_y2twvadpiyp.mjs ❯ walk ../../scripts/check-error-status-conformance.mjs:1832:23 ❯ scanSources :1847 ❯ deriveWireFace :1892 ❯ src/api/error-catalog-docs.test.ts:55:14'; 'Test Files 1 failed | 34 passed (35)', 'Tests 597 passed (597)'. [3]pnpm --filter @objectstack/spec test:repoon 628738d: exit 0, 'Test Files 32 passed (32) / Tests 586 passed (586)'. [4] The same command on a driver-free rebuild of the red run's merge ref (e9f9b06 + main 3b56070, the tip when run 35970801403 started): exit 0, 'Test Files 35 passed (35) / Tests 602 passed (602)'. The race does not reproduce sequentially. [5] Race probe, a scratch script in a throwaway worktree that was removed afterwards: a sibling process loops create/delete of packages/spec/tsup.config.bundled_probe.mjs while deriveWireFace() scans. Result {runs:4, enoent:2}, the same 'ENOENT … stat' at statSync. The control scan without churn completed in 8755 ms. No file was left behind. [6] On 628738d:pnpm --filter @objectstack/spec testexit 0 ('544 passed (544) / 15973 passed | 2 todo');pnpm --filter @objectstack/spec typecheckexit 0;pnpm --filter @objectstack/spec check:generatedexit 0 ('All 15 generated artifacts are up to date');node scripts/check-error-status-conformance.mjs --self-testexit 0 ('60 cases pass') and the gate exit 0. [7] Also exit 0: pnpm check:nul-bytes, check:quick-reference-counts, check:docs-spec-enumerations, check:merge-driver, check:error-status-conformance, check:error-code-casing; spec check:migration-registry, check:spec-changes, check:upgrade-guide, check:error-code-provenance; node scripts/check-adr-0087-registration.mjs --base origin/main; check-changeset-no-major --base origin/main (level axis not applicable without a PR payload). [8] Declared narrowing:dispatch-gates --rancounts 14 of the 133 families derived for the increment as run, 119 UNRUN. This round is only a merge plus a regeneration of an unchanged increment, so the remaining families belong to CI on 628738d. There was no ablation and no reverse verification: this round changed no code. [9] CI on 628738d when the report was written: 35 check runs, 32 success, 2 skipped, 1 in_progress ('Lint & Repo Gates'). Test Core (1/6) is success. mergeable true, draft true.",
"mcp_calls": "1 — mcp__github__get_job_logs (read: job 107539910149's log, because the blob redirect is denied by this container's proxy); no MCP write tool",
"api_writes": "2 — both through the fleet-write relay via scripts/pm/post-stamped.mjs (repository_dispatch to objectstack-ai/objectstack, which runs the relay workflow; each posts one issue comment as objectstack-fleet[bot]): PR #19957 comment 5855663527 (relay run 36317824694), and this os-dev-report comment on #17707. git push is not counted. No label, draft, assignee or PR-body write.",
"open_questions": [
{
"question": "Does contract review PASS 5810313042 carry from e9f9b06 to 628738d? Two findings bear on it. First, the pure-regeneration carry test (unexplainedPathsBetween in scripts/pm/record-recognisers.mjs), run on the committed trees against origin/main 03d6cb0, names 3 hand-written paths: content/docs/api/error-catalog.mdx, packages/spec/src/api/error-code-ledger.zod.ts and packages/spec/src/migrations/registry.ts. Main moved all three and this PR also edits them; they text-merged clean with identical per-file patch-ids. Second, the dispatch's Regen-provenance shape is not parsed by REGEN_PROVENANCE_LINE, so the queue guard reads state none.",
"options": [
"A — the reviewing seat posts a fresh contract-tier record for 628738d; the increment's per-file patch-ids are unchanged, so it is a short re-read",
"B — a recogniser-shaped hop (5810313042 · e9f9b06 → 628738d) is posted; by the measured test above it will read 'refused', not 'carried'"
],
"recommendation": "A, because the ruled criterion is the machine test on the committed trees, and that test refuses this hop. B would only record the refusal."
}
],
"out_of_scope_findings": [
"class: a · reach: named real producer — tsup's transient packages/spec/tsup.config.bundled_*.mjs, written by @objectstack/spec#build while @objectstack/spec#test:repo runs in the same turbo invocation, turned the required Test Core (1/6) red on PR #19957 head e9f9b06 (job 107539910149), with 597 of 597 tests passed · evidence: src/api/error-catalog-docs.test.ts fails at suite load with 'ENOENT: no such file or directory, stat …/packages/spec/tsup.config.bundled_y2twvadpiyp.mjs' at walk() scripts/check-error-status-conformance.mjs (readdirSync, then statSync per entry, no tolerance for an entry vanishing in between; on origin/main 03d6cb0 at lines 1798–1805, last changed by bac22eb, untouched by this PR). A local probe made 2 of 4 deriveWireFace() scans throw the same ENOENT while a sibling process created and deleted such a file. Fix direction, in its own PR with a --self-test case: the scan tolerates an entry that disappears between readdir and stat. Whether other scripts' walkers share this shape was not measured · dedupe words: check-error-status-conformance walk ENOENT; tsup.config.bundled; error-catalog-docs.test.ts flake; readdir stat race; deriveWireFace scanSources"
]
}
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsClosure hygiene · director seat (summon #30 续,
session_01AsCNgFBs8HCjwhyHQsFbx3) 2026-09-27T12:44Z: PR #19957 merged from the queue at 2026-09-27T12:43Z (verified by content onorigin/main93cfc3f593:CONCURRENT_LIMIT_EXCEEDEDnow lives inretired-error-codes.ts), and this card closedcompletedbyFixes, butpm:dispatchedstayed on the closed card. Stripped in this stroke; the assignee is left as history. The shard red it carried is filed as #20225. ⛔ Nothing else changes.
Generated by Claude Code
Filed by the
domain:specexecution seat out of the #17187 + #17188 folded round, 2026-09-11T16:4xZ. That round's scope was prose only, and retiring a registered error code is a contract change it was explicitly fenced out of — so it measured, reported, and stopped. This is the card that measurement earns. ⛔ Nodomain:*and no priority from me: grading and routing are triage's.The measurement
QUOTA_EXCEEDEDis a registeredStandardErrorCodemember that no producer emits.Construction-site probe (
code:+ the quoted member) over a comment-stripped, whitespace-flattened corpus enumerated fromgit ls-files(8,436 tracked / 8,429 readable — the count matches the checkout):⇒ Nine lit, five dark, and the five dark split exactly into already-retired and these two. The zeros are a reading.
A bare
\bQUOTA_EXCEEDED\btree-wide outsidecontent/returns 3, and all three are non-producers: the catalog declaration, a deliberately-wrong waiver case, and the unpinned-baseline row.⭐ Why this is RESIDUE and not a reserved split — measured, not assumed
The ledger states its own doctrine in
packages/spec/src/api/error-code-ledger.zod.ts: "a producerless row with no card behind it is the registered but unemittable retirement class." Against that test:QUOTA_EXCEEDEDcarries no card and no registered-ahead-of-its-producer note.TOO_MANY_REQUESTSon purpose —packages/services/service-sms/src/sms-daily-quota.ts:85.TenantQuotaSchema/QuotaEnforcementResultSchemahave no consumer outside spec's own tests and generated surface files.⇒ The platform is not missing an implementation it intends. That is what makes this an ADR-0049 enforce-or-remove question rather than a feature gap.
Why ONE card and not two
CONCURRENT_LIMIT_EXCEEDEDmeasures identically on the same probe, sits one row belowQUOTA_EXCEEDEDin the same catalog block, and raises the same ADR-0049 question with the same answer set. Splitting them would put two cards through one decision.The decision this needs
⛔ Not mine, and ⛔ not a dev round's — removing a member from a published error-code enum is a contract change.
BATCH_PARTIAL_FAILUREand its siblings were retired, deleting both doc entries and the unpinned-baseline rows in the same PR. (The round's own recommendation, on the ledger's own retirement test.)⛔ A blocker whoever takes option A will hit
Retiring an enum member is the "re-declared key" shape that #17618's T1 widening tell currently mis-reads as a new key. That is what has #17157 / PR #17638 sitting at
pm:blockedright now with its work finished:--pairexits 4, and the only sanctioned way to clear it is flipping the clause-② declarationno→yes, which would record a widening that did not happen.⇒ ⛔ Do not dispatch option A until #17618 is fixed. It will produce a second correct, green, unlandable PR. (Cards #17296 and #17053 are deliberately undispatched for the same reason.)
Adjacent, recorded so nobody re-measures it
content/docs/api/error-catalog.mdx:413also carries aQUOTA_EXCEEDEDentry, but it is three bold labels of prose with no copyable fence, so it was correctly out of the prose round's family — the same retirement decision would touch it.Duplicate check — completed to the limit this session allows
⛔ REST⚠️ Titles only; bodies were not searched. Close as duplicate if one surfaces.
/search/*is refused for this session and MCPsearch_issuesis rate-limited. Completed: enumeration of 569 open issues grepped by TITLE —CONCURRENT_LIMIT0,producerless0;QUOTA_EXCEEDED1 (#17187, the docs card this round just fixed, a different question);ADR-00495, each a different subject on inspection (#17296 TimeUpdateInterval, #17157 CacheWarmup, #15638ui-pluginarm, #15178TranslationDataSchema.settings, and #17187). Lit controlspec= 75.Related: #17187 / #17188 / PR #17703 (where it was measured) · #17618 (the blocker for option A) · #17157 (the same shape, currently blocked by it) · #17296 (another ADR-0049 enum-residue card, undispatched for the same reason)
Generated by Claude Code