Filed by the domain:skills execution PM seat, session session_01HZfg2AwVX191qCizp88gQr, at 2026-09-16T04:27Z, from the #18321 dev's out_of_scope_findings (report 5691990182 on #18321; PR #18365), measured by that dev and read by the seat.
Reading
.claude/hooks/guard-governed-enqueue.sh's fail-open 「no checkout of the target repo is available to recompute its provenance on」 (warn + allow, after the governed predicate answered exit 3 with an exception row) is pinned by NO case in guard-governed-enqueue.selftest.sh, in any environment. The case whose comment used to claim it (「an exception-row path in a repo this container cannot resolve」) never reaches it: with nothing resolved the register is invoked WITHOUT --root, answers about THIS tree, where skills/objectstack-data/references/_index.md is byte-exact against its own generator and therefore LIFTED (exit 0), so the hook leaves at the cleared-predicate exit 0 several branches above the fail-open, with EMPTY stderr. PR #18365 corrected that stale comment and made the case hermetic; it did not add coverage of the branch (a new fixture is a new verification surface — outside that card).
The branch IS reachable: node scripts/pm/check-governed-merges.mjs --test skills/zz-no-such-skill/references/_index.md returns exit 3 with exceptions of length 1 (the generator 「does not write」 that path — it is not among the 9 declared outputs). That path shape, with OS_GOVERNED_ENQUEUE_SIBLING_ROOT (PR #18365) pointed at an empty directory, takes the fail-open and prints the warning.
What is asked
One hermetic case in the selftest that reaches the fail-open (the path shape above + the injected empty root), asserting allow AND the warning text (the dev's phantom-check lesson: a text assertion must be shown to go red under a firing control — e.g. the same payload with the sibling resolved). .claude/hooks/guard-governed-enqueue.selftest.sh only (the hook unchanged unless the case reveals a defect — report, do not widen); rules layer (.claude/hooks/**) ⇒ draft PR, four-piece + an authorized APPROVED; ⛔ never armed by the seat.
Grading (lane self-triage; class (a), an unpinned branch): p3 · Task · pm:queue · domain:skills. SERIAL behind PR #18365 (the injection it uses). Fold candidate with the .git-slug card filed beside it (same two files; the second lander merges origin/main otherwise).
查重词
guard-governed-enqueue fail-open · no checkout available branch · target_root exception_rows · unpinned branch selftest · phantom check
Generated by Claude Code
Filed by the
domain:skillsexecution PM seat, sessionsession_01HZfg2AwVX191qCizp88gQr, at 2026-09-16T04:27Z, from the #18321 dev'sout_of_scope_findings(report 5691990182 on #18321; PR #18365), measured by that dev and read by the seat.Reading
.claude/hooks/guard-governed-enqueue.sh's fail-open 「no checkout of the target repo is available to recompute its provenance on」 (warn + allow, after the governed predicate answered exit 3 with an exception row) is pinned by NO case inguard-governed-enqueue.selftest.sh, in any environment. The case whose comment used to claim it (「an exception-row path in a repo this container cannot resolve」) never reaches it: with nothing resolved the register is invoked WITHOUT--root, answers about THIS tree, whereskills/objectstack-data/references/_index.mdis byte-exact against its own generator and therefore LIFTED (exit 0), so the hook leaves at the cleared-predicateexit 0several branches above the fail-open, with EMPTY stderr. PR #18365 corrected that stale comment and made the case hermetic; it did not add coverage of the branch (a new fixture is a new verification surface — outside that card).The branch IS reachable:
node scripts/pm/check-governed-merges.mjs --test skills/zz-no-such-skill/references/_index.mdreturns exit 3 withexceptionsof length 1 (the generator 「does not write」 that path — it is not among the 9 declared outputs). That path shape, withOS_GOVERNED_ENQUEUE_SIBLING_ROOT(PR #18365) pointed at an empty directory, takes the fail-open and prints the warning.What is asked
One hermetic case in the selftest that reaches the fail-open (the path shape above + the injected empty root), asserting
allowAND the warning text (the dev's phantom-check lesson: a text assertion must be shown to go red under a firing control — e.g. the same payload with the sibling resolved)..claude/hooks/guard-governed-enqueue.selftest.shonly (the hook unchanged unless the case reveals a defect — report, do not widen); rules layer (.claude/hooks/**) ⇒ draft PR, four-piece + an authorized APPROVED; ⛔ never armed by the seat.Grading (lane self-triage; class (a), an unpinned branch): p3 · Task ·
pm:queue·domain:skills. SERIAL behind PR #18365 (the injection it uses). Fold candidate with the.git-slug card filed beside it (same two files; the second lander mergesorigin/mainotherwise).查重词
guard-governed-enqueue fail-open·no checkout available branch·target_root exception_rows·unpinned branch selftest·phantom checkGenerated by Claude Code