You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This post is the single authoritative registry for the domain:services seat (seat-post protocol; index label:pm:seat). Single writer: the incumbent only. Read side: this body plus every comment newer than the body's last edit. ⛔ Shift narrative does not belong in the body — this post carries current values only.
Body set to vacant at stand-down, by session_01XY5uCwTjZj7884yYtyur4H at 2026-10-01T18:27Z. §4 and §5 carry forward unchanged; §1–§3 are current values.
1. Current PM — ⏳ vacant
Last incumbent:session_01XY5uCwTjZj7884yYtyur4H (GitHub login os-justin), stood down on the maintainer's order 「当前任务处理完,合并后就下班」 (notice 5932495429). The final brief is the newest comment on this post.
To re-seat:/pm-dispatch services in a fresh session that carries the repo in its sources at creation (§4, first fact), then read this post first. The successor creates its own wake Routine; the last incumbent's (trig_014Y3GkVQuyfN3uUnUYqfZwb) is deleted.
Write identity: the fleet relay (objectstack-fleet[bot], route dispatch) via scripts/pm/* on latest main. ⛔ No user-token writes.
2. Ledger — current values at stand-down
In flight from this seat: none. No pm:dispatched card of this lane is assigned to this seat, no open PR of this seat remains, no dev agent is running, and no worktree is left.
Landed on 2026-10-01 (each completed, state label and assignee cleared, landing comment on the card):
None held by this seat. Seat 2's holds are on its own post (#21118).
Lessons carried into every order:
⭐ Selection follows the full order at every pick, read fresh. Open P0/P1 are re-read each time. A claimed-but-unbuilt card ranks by its own priority, never by being claimed. If a higher card appears while a lower claim is being written, the lower claim is rolled back.
4. Standing facts measured in this lane — ⛔ re-measure before relying, but do not re-discover
🔴 The agent roster is fixed at SESSION CREATION. A seat spawned without a repo source can attach the repo mid-session and gain its skills, but ⛔ never its agents — measured twice by session_018avjADnTGyuCcmmLWBxaNr with a register_repo_root in between. ⇒ a successor must carry the repo in session_context.sourcesat creation, and must confirm os-dev before claiming. ⚠️ The roster listing is only the declared surface; the confirming reading is an accepted Agent call.
CI must be read latest-run-per-check-name. A head carries several runs of one name and an earlier failure can be superseded by a later skipped/success. Already in platform-readings.md:301.
mergeable_state: blocked right after a ready-flip is a transient — ⛔ do not diagnose it at the one-minute mark.
⭐ The footer behaviour of a body write depends on the CHANNEL, not the surface. An earlier incumbent measured that an issue-body and a PR-body PATCH re-append the _Generated by_ footer. This session measured the opposite on the fleet relay's issue_patch op: the body is stored VERBATIM. That covers this post's body refreshes (zero footers sent, zero stored) and PR fix(service-analytics): judge each read scope with the engine's own admission before composing it #20232's body (zero sent, zero stored; the session-URL footer then sent once, one stored). ⇒ Send the footer you want stored, and read back after every write, as AGENTS.md says.
⭐ post-stamped now enforces the stamp contract (main f415bcf1): a body carrying {{NOW}} REFUSES any other bare YYYY-MM-DDThh:mmZ stamp. Write a quoted instant as {{WAS:…}}.
⭐ A comment POST normalises whitespace: the stored body can differ from what was sent by an inserted newline before a trailing ---. ⇒ a read-back equality check on fragile comments should compare fragments, not byte-identity, or it will cry wolf.
The REST /search/* path is refused in this container (sessions are bound to their repositories). Run dedupe searches through the MCP search_issues READ tool. ⛔ It is never a write channel.
ccr/auto_merge echoes merge_method back wrongly ⇒ ⛔ that field cannot tell queue landing from direct merge. The real criterion is the timeline's added_to_merge_queue; the landing criterion is delivery on origin/main, ⛔ never the PR-closed event.
A closing keyword does NOT clean the board. Auto-closed cards keep their pm:* state label and assignee ⇒ clear both on reading the merge event, with a note (⛔ never a silent assignee drop — the H47 shape).
⭐ Auto-merge can sit un-queued. PR docs(service-job): re-anchor the dead tracker citation to the commit that decided it #20866 stayed ready, green and clean with auto-merge enabled for 17 minutes and no added_to_merge_queue, while a PR readied later was queued within two minutes. One relay automerge_disable + automerge_enable pair queued it at once. It re-runs no CI, so it is not a kick.
⭐ The contract-review tier can run out mid-shift. Measured on PR docs(service-automation): re-anchor the dead tracker citations to the commits and ADR that decided them #20816: the at-tier review subagent stopped with a weekly-limit 429 before writing anything, and the landing waited. At the maintainer's 「Try again」 the retry was served and passed. ⇒ A failed review is re-launched, never replaced by a record at a lower tier; the landing waits for a record served at the tier.
⭐ Whole-machine restarts come under parallel heavy dev work (about 21:45Z, 22:05Z and 22:38Z on 2026-09-30, and about 11:35Z on 2026-10-01 with two devs under the lock). Each lost the in-flight runs before they reported, though their pushed branches survived. The cause is not measured (the VM exposes no cgroup memory). ⇒ Every order now puts every build, test run, typecheck and gate run under scripts/pm/os-verify-lock.sh, with a 3 GB heap, turbo --concurrency=1 and vitest --maxWorkers=2, and keeps a checkpoint log. Since then, three agents in parallel have run without a restart.
check-expected-skips.mjs / check-half-states.mjs will not run without pnpm install ⇒ their exit is NOT MEASURED, ⛔ never read as a clean board.
The dev writes a PR body once at POST /pulls and ⛔ never PATCHes it ⇒ on a patch round the body goes stale; the dev hands the markdown over in its report and the seat appends it, marked as the seat's append.
⭐ git-history.mjs touch REFUSES rather than guessing, and that refusal is load-bearing. On a shallow clone the floor is diffed against the empty tree, so raw git log -1 -- <path> answers at exit 0 with a real, plausible, WRONG sha. Measured this seating on references/lanes/services.md; the true value came only after unshallowing to 14358 commits.
⭐ Token grep answers 「does this string appear」, which is ⛔ not the question when the question is 「is it declared / exported / executed」. Prose describing a thing is indistinguishable from the thing. A positive control only licenses a zero when it sits on the same subject as that zero (same file, same corpus, same spelling convention). ⭐ Live example carried on-card at [finding] service-messaging: sms-channel declares no isAvailable() — fan-out can suppress email on an absent transport but never sms (#17732's unfinished half) #18567: a bare grep finds isAvailable in sms-channel.ts and reads as the premise being falsified — the hit is docblock prose about the email channel, and a declaration-shaped query returns the real members and no isAvailable.
Platform facts measured by the last incumbents (session_01Evb5jFDZGKQE9KG4jbMfMF and its predecessor)
⚠️gh is ABSENT in this container — REST goes through curl or python urllib.
⚠️ node's fetch does ⛔ not read HTTPS_PROXY here; scripts/pm/* re-exec themselves with --use-env-proxy and say so on stderr.
Publication layer for this repo (registration duty): a merge to main here does ⛔ not deploy or publish ⇒ this lane's landing criterion is MERGED — except that a fix whose consumer is another repo is judged on installability, ⛔ not on merge.
⛔ cloud, objectui, hotcrm are NOT reachable from this session (GitHub scope: objectstack-ai/objectstack). Consumer-side readings on cards filed from those lanes are accepted as declared and ⛔ are not re-verifiable here.
This session's reading: REST reachable, /rate_limit core 15000/15000, repo-scoped read 200. gh is absent; node_modules is absent in the shared checkout. The relay selector answers dispatch (workflow on main, Actions state active).
This post is the single authoritative registry for the
domain:servicesseat (seat-post protocol; indexlabel:pm:seat). Single writer: the incumbent only. Read side: this body plus every comment newer than the body's last edit. ⛔ Shift narrative does not belong in the body — this post carries current values only.Body set to vacant at stand-down, by
session_01XY5uCwTjZj7884yYtyur4Hat 2026-10-01T18:27Z. §4 and §5 carry forward unchanged; §1–§3 are current values.1. Current PM — ⏳ vacant
session_01XY5uCwTjZj7884yYtyur4H(GitHub loginos-justin), stood down on the maintainer's order 「当前任务处理完,合并后就下班」 (notice5932495429). The final brief is the newest comment on this post.os-bill) runs this lane's queue meanwhile./pm-dispatch servicesin a fresh session that carries the repo in its sources at creation (§4, first fact), then read this post first. The successor creates its own wake Routine; the last incumbent's (trig_014Y3GkVQuyfN3uUnUYqfZwb) is deleted.objectstack-fleet[bot], routedispatch) viascripts/pm/*on latestmain. ⛔ No user-token writes.2. Ledger — current values at stand-down
pm:dispatchedcard of this lane is assigned to this seat, no open PR of this seat remains, no dev agent is running, and no worktree is left.completed, state label and assignee cleared, landing comment on the card):$notover a multi-valued lookup ($contains) is refused 400, because the NULL-safe guard reaches driver-sql as$ne: nullon a JSON column, where the engine answers the rows #20918: PR fix(service-analytics): the ObjectQL strategy hands the engine its null tests as $null, so a $not over a multi-valued lookup gets the engine's rows (#20918) #21036 (5dbeb7d7).numberas a string (count: "2"), where SQLite answers 2 — the class #20335 closed at the engine door #20889: PR fix(core,driver-sql,service-analytics): the analytics native-SQL path answers measures declared number as numbers (#20889) #21040 (d1633f3a).maskingRule's describe and the result masker mask it — which one a public door serves is not measured #20995: PR fix(plugin-security)!: a caller who resolves no permission set is served a masked field masked and may not query on it #21051 (a9d36d51).9b81314c).mappingwhoseconnectorSourcenames a rest/openapi connector and writes through the import runner's upsert-by-match-key #20919: PR feat(service-automation,core,types): the connector sync executor pulls a mapping's connectorSource through the import runner, moved beside bulkWrite #21084 (8368f1c0).39ab2940).$contains/$notContainson a declared multi-valued or JSON-stored field still answer SUBSTRING on five faces, the analytics RLS read scope among them (u1admits a row storingu10) #20987: PR fix(service-analytics)!: the analytics read scope and the native where answer $contains on a JSON-stored field by membership (#20987) #21117 (58a77dbd).bafb8c94).cb45469e), landed ahead of PR fix(service-analytics): refuse a caller-named non-column member at the analytics query door in every tier (#21156) #21173 on the maintainer's 「先合并 fix(service-analytics)!: the analytics native-SQL path declines an object an engine middleware is registered for, so its read gates apply #21170」.objectstack-ai/cloud#2485's grant is handed to therepo:cloudseat (5935008711on [PM seat] repo:cloud#1 — 🟢 hotlong · session_01Wxo1xhh2bU66T73q23jzE4 · R44 #6026).097ef802).1ecb871b). It is the family close-out for the activity text, the ledger snapshots and the approval snapshot.security), ruled E (5933054144): the zero-set deny baseline alone, level M. TheRelease:note is5934091842, and seat 2 now holds it.pm:queue: Queue-flake anchor: src/__tests__/caller-content-admission-door.test.ts #21200 and Queue-flake anchor: src/__tests__/field-read-admission-gate.test.ts #21201 (p1); [Decision] #20822 F7: retiring formula's whole-day copy — the RLS write check judges the raw post-image, so deleting the copy refuses writes the same policy's read shows #21109, automation: a host's per-kernel scheduled-work refusal is reported with the deployment sentence —SCHEDULED_WORK_DISABLED_REASONtells a free-plan tenant to setOS_AUTOMATION_SCHEDULED_WORK_ENABLED=true(the #19834 seam has no reason slot) #21110 and analytics: a config cube min / max whose sql is a relationship path is neither judged by the aggregate field-type table nor presented by its declared type on the native face (#21044's family, the dotted half) #21129 (p2).pm:blocked: [finding] The delegated-admin gate resolves an EMPTY subtree on a stockobjectstack devboot — seeded business units are organization-less while every session carries an active organization, so every in-scope delegated write is refused #21057; plugin-sharing: after the #15030 revert, 17.x still cannot reach a NULL-org-seeded business unit from an org-stamped rule — and #14547, its only tracker, is closed #15086; feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196, refactor(plugin-security,platform-objects,spec): retire the catalog seeders, the per-organization catalog machinery and the four catalog objects; Setup creation is an environment write undersingleand refused under a wall (ADR-0131 D2/D3/D5/D13) #15204, refactor(plugin-email): templates resolve the registry; the seed and the provenance stamp retire; organization-level editing is closed (ADR-0131 D6/D10) #15205 and feat(spec,services): deployment-level state has no organization column — settings global rung, plumbing objects, the audit ledger, #12699 made total (ADR-0131 D7) #15207 (the v18 line).pm:on-hold: finding(service-automation,lint): the resume door evaluates a screen field'svisibleWhenover the run's variables, wider than the declared scope (the screen's own field names), and nothing refuses an undeclared name at authoring #20178, Authenticated data requests issue ~20 DB queries in ~17 sequential legs — per-request auth/session/localization/metadata resolution has no cross-request caching, costing ~1.5s/request on remote Postgres #10757, automation: config.organization '*' fans a packaged scheduled flow out once per installing organization under isolated tenancy (the recorded end state of #20619 ruling A) #20645, [security][立项位] M2 权限生命周期(undelete/purge)功能与 allowRestore/allowPurge RBAC 同批建设(evaluator 已 fail-closed,allowTransfer 已 enforced) #1883, [v18] retire the{var}template dialect in flow assignment slots: refuse at registration with per-spelling remedies (the C half of #11182 ruling D, on the v18 train) #19939, Design: does approver routing imply record read visibility? (#7345 model half) #7497, service: inbound mail + calendar sync (open-core scope) —plugin-emailis outbound-only, so email-to-record is impossible in any app #8998 and 权限设置应该可以配置实效性,权限在一个时间段之内生效 #9272.domain:servicespackages carry tracker numbers (168 messages in 17 packages, 263 ledgered ids): this lane's share of the #20513 A/A burn-down #20751 and security(plugin-security): a non-system caller who resolves no permission set is admitted to every object and read with no row scope; an empty set list grants by absence instead of answering the deny baseline #21079.5937829437): F11 (the ledger guard's column list is not pinned to its redaction's strip), F6 (the clause walk in three packages) and F12.SqlDriver's replacedprotectedhelpers, for the release note.IStorageService.list(prefix)means two different things on the two shipped adapters (local: one level, directories as files; S3: recursive, silently capped at 1000) #5266 carrydomain:servicesand nopm:*state.3. Hot-file serial queue
None held by this seat. Seat 2's holds are on its own post (#21118).
Check Changesetred on the old head (PR fix(rest): the public lookup picker searches and sorts by the first display field the caller may query #21136,5929612459).main. If both steps are clean, ask the maintainer whether to land first: PR fix(service-analytics)!: the analytics native-SQL path declines an object an engine middleware is registered for, so its read gates apply #21170 waited about two hours behind PR fix(service-analytics): refuse a caller-named non-column member at the analytics query door in every tier (#21156) #21173 for a clean merge.needs:contract-reviewis retired; ⛔ no order names it. Name the ⛔-marked roster families in every order. Grep for the#N-wordand#A/#Bspellings the census cannot see (check-issue-citations closeout (extractor spellings):CITATION_RErefuses a hyphen after the digits, so a dead#N-wordcitation (#13398-class) is invisible to the diff gate and to the census #20636).4. Standing facts measured in this lane — ⛔ re-measure before relying, but do not re-discover
session_018avjADnTGyuCcmmLWBxaNrwith aregister_repo_rootin between. ⇒ a successor must carry the repo insession_context.sourcesat creation, and must confirmos-devbefore claiming.Agentcall.failurecan be superseded by a laterskipped/success. Already inplatform-readings.md:301.mergeable_state: blockedright after a ready-flip is a transient — ⛔ do not diagnose it at the one-minute mark.PATCHre-append the_Generated by_footer. This session measured the opposite on the fleet relay'sissue_patchop: the body is stored VERBATIM. That covers this post's body refreshes (zero footers sent, zero stored) and PR fix(service-analytics): judge each read scope with the engine's own admission before composing it #20232's body (zero sent, zero stored; the session-URL footer then sent once, one stored). ⇒ Send the footer you want stored, and read back after every write, as AGENTS.md says.post-stampednow enforces the stamp contract (mainf415bcf1): a body carrying{{NOW}}REFUSES any other bareYYYY-MM-DDThh:mmZstamp. Write a quoted instant as{{WAS:…}}.POSTnormalises whitespace: the stored body can differ from what was sent by an inserted newline before a trailing---. ⇒ a read-back equality check on fragile comments should compare fragments, not byte-identity, or it will cry wolf./search/*path is refused in this container (sessions are bound to their repositories). Run dedupe searches through the MCPsearch_issuesREAD tool. ⛔ It is never a write channel.ccr/auto_mergeechoesmerge_methodback wrongly ⇒ ⛔ that field cannot tell queue landing from direct merge. The real criterion is the timeline'sadded_to_merge_queue; the landing criterion is delivery onorigin/main, ⛔ never the PR-closed event.pm:*state label and assignee ⇒ clear both on reading the merge event, with a note (⛔ never a silent assignee drop — the H47 shape).cleanwith auto-merge enabled for 17 minutes and noadded_to_merge_queue, while a PR readied later was queued within two minutes. One relayautomerge_disable+automerge_enablepair queued it at once. It re-runs no CI, so it is not a kick.where/ preview door, the read scope) and the memory cube face's door, with the F5 / F11 output vocabulary #20810 (PR feat(service-analytics,driver-memory): the shared filter lowering at the analytics seams and the cube face's new door (#5930 step 3) #20857), a queue merge of a PR whose body openedFixes #Nleft the card open, with noclosedevent. Both of those PRs had their body re-written through the relay'sissue_patch. That is not the cause: security(analytics): the native-SQL strategy answers a query naming a field the caller has no field-level read permission for, where the engine and the ObjectQL strategy refuse 403 #20917 (PR fix(service-analytics)!: one field-level read gate at the analytics door, before either strategy (#20917) #20931) closed on its own although its body was also re-written that way. The cause is unmeasured. ⇒ After everyFixeslanding, read the card's state; if it is still open, close itcompletedthrough the relay'sissue_patch, and say so in the landing comment.objectstack-ai/cloud. When triage asks this seat for a cloud follow-up card, the seat hands it to therepo:cloudseat on that seat's post ([PM seat] repo:cloud#1 — 🟢 hotlong · session_01Wxo1xhh2bU66T73q23jzE4 · R44 #6026), in the landing act. The hand-off carries the declaration line and the unlock condition (the release is installable). ⛔ It is not a claim. First done for plugin-auth:no_sign_in_account_at_bootstill fires at ERROR on hosted kernels whose platform-SSO button is hidden (the owner signs in through the cloud handoff, which the gate cannot see) #20861 (5915469225).domain:services): the cube read and the analytics read scope answer{ relation: { field: value } }as the engine seam now serves it — as the caller, capped, one answer on every face #20887's round-0 report (5916988260) put a door, a field path and the returned rows for an open gap on a public comment. The seat redacted it in place through the relay'scomment_edit; the edit history still holds it, and its purge is raised with the maintainer. ⇒ Read every report and PR body for disclosure before anything else. Orders for security cards now say: push nothing until the fix sits on the red pins.scripts/pm/os-verify-lock.sh, with a 3 GB heap, turbo--concurrency=1and vitest--maxWorkers=2, and keeps a checkpoint log. Since then, three agents in parallel have run without a restart.issue-createcan report UNVERIFIED although the issue exists. Measured twice (analytics: on the ObjectQL strategy a$notover a multi-valued lookup ($contains) is refused 400, because the NULL-safe guard reaches driver-sql as$ne: nullon a JSON column, where the engine answers the rows #20918, security(plugin-security): the engine's field guard does not judge a cross-field comparand that names a field the caller may not read, so a comparison against a hidden field is served instead of refused 403 #20932): the relay run succeeded, the read-back found no issue, and the board showed it with the exact title and body. ⇒ Read the board; ⛔ never retry blind.check-expected-skips.mjs/check-half-states.mjswill not run withoutpnpm install⇒ their exit is NOT MEASURED, ⛔ never read as a clean board.POST /pullsand ⛔ never PATCHes it ⇒ on a patch round the body goes stale; the dev hands the markdown over in its report and the seat appends it, marked as the seat's append.git-history.mjs touchREFUSES rather than guessing, and that refusal is load-bearing. On a shallow clone the floor is diffed against the empty tree, so rawgit log -1 -- <path>answers at exit 0 with a real, plausible, WRONG sha. Measured this seating onreferences/lanes/services.md; the true value came only after unshallowing to 14358 commits.sms-channeldeclares noisAvailable()— fan-out can suppressemailon an absent transport but neversms(#17732's unfinished half) #18567: a bare grep findsisAvailableinsms-channel.tsand reads as the premise being falsified — the hit is docblock prose about the email channel, and a declaration-shaped query returns the real members and noisAvailable.Platform facts measured by the last incumbents (
session_01Evb5jFDZGKQE9KG4jbMfMFand its predecessor)REST reachable:
/rate_limitcore 15000/15000, repo-scoped read leg 200 ⇒ session gate open. Write identityhuangyiirene.ghis ABSENT in this container — REST goes throughcurlor pythonurllib.fetchdoes ⛔ not readHTTPS_PROXYhere;scripts/pm/*re-exec themselves with--use-env-proxyand say so on stderr.Publication layer for this repo (registration duty): a merge to
mainhere does ⛔ not deploy or publish ⇒ this lane's landing criterion is MERGED — except that a fix whose consumer is another repo is judged on installability, ⛔ not on merge.⛔
cloud,objectui,hotcrmare NOT reachable from this session (GitHub scope:objectstack-ai/objectstack). Consumer-side readings on cards filed from those lanes are accepted as declared and ⛔ are not re-verifiable here.This session's reading: REST reachable,
/rate_limitcore 15000/15000, repo-scoped read 200.ghis absent;node_modulesis absent in the shared checkout. The relay selector answersdispatch(workflow onmain, Actions stateactive).5. Notes
issuecomment-5724940310names the gate by number, rejects option B as 「waits on a line the maintainer has not opened」, and the maintainer agreed 「其他同意」 — and that ruling's own Execution block routes the card topm:queue. ⇒ per-card maintainer authorisation, ⛔ not a seat overriding a gate. The reasoning is recorded on-card atissuecomment-5740746890.H525 of 50 rows,H193 of 12,H263 of 17, with 36 families partly omitted. ⛔ The absence of a row naming this lane is not a clean board.