Skip to content

docs(pm,agents,settings): write-identity locks 1–4 — deny MCP content writes, REST-only dev writes with api_writes, batch default 2, user-account roles - #18072

Merged
os-project-manager merged 8 commits into
mainfrom
claude/issue-18068-write-identity-locks
Sep 13, 2026
Merged

os-project-manager merged 8 commits into
mainfrom
claude/issue-18068-write-identity-locks

Conversation

@claude

@claude claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

Fixes #18068

Dev session session_01DAcomhvR9kKizeYgg89Vo8 on branch claude/issue-18068-write-identity-locks (worktree objectstack-issue-18068), off origin/main 6d64785, merged e248c4d before opening (no incoming commit touched these files). One commit per lock; each quotes its ruling.

Rulings (verbatim, untranslated)

  • Maintainer, skills seat chat, 2026-09-13T16:14Z: 「机制层的五道锁 现在就派发处理」 — the whole card.
  • Maintainer to the services seat, 2026-09-13: 「当前任务处理完,后续并发降到2」 — lock 3.
  • Triage ruling ③: 「立卡者不查重,只在卡面附 3–5 个查重词」 — why os-dev.md :51–:58 were stale (lock 2's payment).
  • Standing exception, pm-dispatch SKILL.md: 「唯一例外:platform-readings.md 增量抬上限到落地行数,免决策卡,记 ruledRaises 引常设裁决。条件:席位验收评论逐条核实、去重计数(候选/落地/已有/拒收)、一事一行、不计重排」 — the +2 on platform-readings.

What landed

  1. Lock 1 .claude/settings.json: permissions.deny with the 14 content-writing mcp__github__* tools the card lists; allow and hooks untouched; JSON.parse passes. Docs reading (code.claude.com/docs/en/permissions and /settings): rules evaluate deny, then ask, then allow; a deny at any scope beats an allow at any scope; mcp__server__tool is the per-tool spelling; the shared .claude/settings.json is read in cloud sessions and deny needs no workspace trust — lock 1 is ENFORCED, and a denied tool is removed from the roster. Recorded as two 文档载明未实测 lines in references/platform-readings.md (references tier, declared): 451 → 453, THIRTEENTH ruledRaises record; candidates 2 / landed 2 / already present 0 / refused 0, one matter per line.
  2. Lock 2 .claude/agents/os-dev.md 403/403: :51–:58 replaced by the REST-proxy write rule (curl + environment GITHUB_TOKEN, authored claude[bot]), the four-write budget, ⛔ no MCP GitHub write tool and no board enumeration, payload-or-single-card reads, findings reported for the seat to file, zero writes outside the budget (no PR-body PATCH), the rest-channel pointer (kept), and api_writes + mcp_calls in the report; the report template gains "api_writes". In place, net 0: the control-word rule now sits under rule 6; resource rule 6 routes late results to the report; the label-write fallback no longer prescribes an MCP issue_write; the out_of_scope_findings example no longer shows a dev-filed card number.
  3. Lock 3 SKILL.md :60 「默认 3」 → 「默认 2」; ceiling 5 unchanged; core-rules :11 states no default, so nothing mirrored.
  4. Lock 4 SKILL.md 〈全体座位的不变量〉 +2 lines (account roles; REST-proxy content and approver never seats), paid in the section (state and resume lines merged; the four Chinese channels named inline, dropping two parentheticals restated in 复核 and 升级与决策); the 〈认领〉 shared-identity line now reads 「身份只认正文 session ID,⛔ 不认作者字段」. core-rules 〈全体座位的不变量〉 one mirror line, paid by folding the three language lines into two. 812/812 (widest row 342 B), 151/151, frame :733–:754 md5 3327d02c56f8a0eca88569dad2270f32 unchanged.

Executable criterion, BASE 6d64785 → HEAD 7e1aeca

grep -c mcp__github__issue_write .claude/settings.json 0 → 1 (inside deny); SKILL.md 「默认 2」 0 → 1 and 「默认 3」 1 → 0; os-dev.md api_writes 0 → 2 (rule + template), search_issues 1 → 0; SKILL.md 「批准账号」 / 「永不跑席位」 0 → 1, core-rules 「批准账号」 0 → 1. Lit controls unchanged: 「每个方案必须沿四条固定评估轴分析」 1 → 1, 「一座位一车道双射」 1 → 1 in both files, os-dev.md mcp_calls 2 → 2.

Gates

node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack at 88e0610: 42 families, every one exit 0 in the foreground with the code captured before any pipe; --ran: 42 derived, 42 run, 0 NOT-MEASURED, 0 UNRUN. check:doc-formula-expressions first answered exit 3 (PREREQUISITE NOT MET, lint/formula unbuilt) — built under the verify lock (187 s held) and re-run: exit 0. Rule ⑤ for the ratchet-script edit: its --self-test (inside check:pm-skill-ratchet), check:ratchet-remedy-authority, scripts/check-published-list-mirrors.mjs and scripts/check-skills-token-ratchet.mjs all exit 0. Re-run at 7e1aeca after the merge: pm-skill-ratchet, pm-skill-id-lint, skill-frame-sync, pm-governed-prose, nul-bytes, agent-model-declared exit 0. Every added prose line ≤ 120 B (the one longer added line is inside the report's JSON fence, structurally exempt); SKILL.md over-120 baseline 23 → 23; control-character scan empty. skip-changeset: nothing published moves (.claude/**, scripts/pm/** only).

Deviations, declared

  • Lock 4 is two SKILL.md lines, not one: the card's four clauses do not fit one 120-byte line; both are paid inside the section.
  • Lock 2 edits four lines outside :51–:58 (rule 6 premise line, resource rule 6, the label fallback, the report template), each net 0, each of which would otherwise contradict the budget.
  • The card's budget has no PR-body PATCH; the rule says so explicitly and routes late gate results to the report comment. Allowing a body refresh would be one clause on that line, the seat's call.
  • PR docs(pm,agents): three rules-layer lines catch up with the charter rulings #18051 (open draft) edits os-dev.md :50, adjacent to this diff's :51 — whichever lands second takes a one-hunk merge; its SKILL.md :106/:113 lines do not overlap.

Acceptance notes

  • noted, not filed (承接者: the skills seat reviewing this PR): mcp__github__update_pull_request_branch writes merge commits, and request_copilot_review writes a review request, yet neither is on the card's list, so both stay allowed.
  • noted, not filed (承接者: the skills seat): SKILL.md :778 still reads 「只列三类立卡与 noted, not filed」; under lock 2 the dev lists findings to file and the seat files them.

维护者速读(草稿)

改了什么:四道机制锁。① 仓库的 Claude 设置里禁掉所有"以用户账号写内容"的 MCP GitHub 工具(建 issue、开 PR、评论、审查、推文件、合并等 14 个),状态类与只读工具照旧;② 开发 agent 对 GitHub 的写只走 REST 代理(署名 claude[bot]),预算固定四笔,报告新增 api_writes 供席位核对;③ 并发默认 3 → 2,天花板 5 不变;④ 写明用户账号只做三件事(assignee、授权批准、维护者亲手),批准账号永不跑席位,内容身份只认正文里的 session ID。
为什么改:今天的封号事故证明,用 MCP 工具写的内容署在关联用户名下,用户一被停,内容整批消失;走 REST 代理的内容署在 App 名下不受影响。并发只是放大器,身份才是被封的对象。
风险与代价(含回滚):deny 名单在会话启动时读入,已开的会话不受影响;席位仍可用 update_pull_request 等状态工具翻 ready、挂 auto-merge。回滚 = revert 本 PR 的任一 commit(每锁一个 commit,互不依赖)。platform-readings 上限 +2 走常设例外,不另开决策卡。
席位意见:(留空,由席位定稿)
你要做的:一个动作 —— 在本 PR 上给出授权批准;受管面,席位按裁决 C 落地。


Generated by Claude Code

…rite lands through the REST proxy (lock 1)

Maintainer, skills seat chat, 2026-09-13T16:14Z, verbatim and untranslated:
「机制层的五道锁 现在就派发处理」

Lock 1 of the write-identity locks: `.claude/settings.json` gains
`permissions.deny` naming the fourteen MCP GitHub tools that create
content or history (issue_write, create_pull_request, add_issue_comment,
add_comment_to_pending_review, add_reply_to_pull_request_comment,
pull_request_review_write, push_files, create_or_update_file,
delete_file, create_branch, sub_issue_write, merge_pull_request,
create_repository, fork_repository). Content written through those tools
is authored by the claude.ai account's linked GitHub USER and vanishes
with a user suspension; the REST proxy authors as `claude[bot]`. State
tools stay allowed (update_pull_request, since REST cannot un-draft;
enable/disable_pr_auto_merge; actions_run_trigger; resolve/unresolve
review thread; subscribe/unsubscribe) and so does every read tool. The
`allow` list and the hooks are untouched; `node -e 'JSON.parse(...)'`
passes.

Docs reading (code.claude.com/docs/en/permissions and /settings): rules
are evaluated deny, then ask, then allow; a deny at any scope blocks an
allow at any other scope; `mcp__server__tool` is the per-tool rule
spelling; the repository's shared `.claude/settings.json` is read in
cloud sessions, and deny rules apply without workspace trust.

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
… four-write budget, and reports `api_writes` (lock 2)

Maintainer, skills seat chat, 2026-09-13T16:14Z, verbatim and untranslated:
「机制层的五道锁 现在就派发处理」
Triage ruling ③ (the reason the dedupe-channel lines were stale):
「立卡者不查重,只在卡面附 3–5 个查重词」

Lock 2 of the write-identity locks, in `.claude/agents/os-dev.md`, net 0
lines (403/403), every added prose line within the 120-byte cap:

- The eight dedupe-channel lines under rule 3 (probe-then-choose, the
  403 ⇒ MCP `search_issues` fallback, the no-wide-scan line, the
  payload-tier description and the "MCP is for writes + that one dedupe"
  line) are replaced by seven lines: every GitHub write goes through the
  REST proxy (`curl` with the environment `GITHUB_TOKEN`), authored by
  the App's `claude[bot]`; the budget is `git push` + one `POST /pulls`
  (draft) + `POST /issues/{n}/labels` + the `os-dev-report` comment; no
  MCP GitHub write tool (user-account authorship, hidden on suspension);
  no board enumeration and no wide search; card and thread reads go
  through the payload tier or a single-card REST read; three-class
  findings go into the report with dedupe words for the seat to file;
  zero writes outside the budget (no `PATCH` of the PR body); the
  rest-channel table pointer is kept; the report records `api_writes`
  (count + endpoints) beside `mcp_calls`.
- The control-word rule that lived among the dedupe lines is kept as a
  premise-check rule under rule 6 (folded into the line it belongs to).
- Resource rule 6's tail now routes late verification results into the
  report instead of a body PATCH, so it agrees with the budget.
- The label-write fallback that instructed an MCP `issue_write` on a
  refused REST label POST now says: stop and report `blocked` naming the
  endpoint and status; never switch to an MCP write; still read back.
- The report template gains `"api_writes"` after `"mcp_calls"`, and the
  `out_of_scope_findings` example no longer shows a filed card number,
  since under the budget the dev files none.

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
Maintainer to the services seat, 2026-09-13, verbatim and untranslated:
「当前任务处理完,后续并发降到2」

Lock 3 of the write-identity locks: the `batch:<n>` row of the
`/pm-dispatch` argument table reads 「默认 `2`」 instead of 「默认 `3`」;
the maintainer ceiling `5` is unchanged, the seat-post protocol line is
unchanged. `core-rules.md` :11 states the parallelism rule without a
default, so no mirrored line moves. 812/812, one table row edited in
place (widest row 342 B untouched).

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
…tten as `claude[bot]` and identified by session ID (lock 4)

Maintainer, skills seat chat, 2026-09-13T16:14Z, verbatim and untranslated:
「机制层的五道锁 现在就派发处理」

Lock 4 of the write-identity locks. `SKILL.md` 〈全体座位的不变量〉 gains
two lines, paid inside the same section (812/812, every added line
within the 120-byte cap, frame block :733–:754 md5
3327d02c56f8a0eca88569dad2270f32 unchanged):

- 「用户账号仅三用:assignee、授权批准、维护者亲手;⛔ 席位与 dev 永不以用户账号写内容。」
- 「内容恒经 REST 代理(`claude[bot]`);批准账号永不跑席位、不作席位 claude.ai 的关联用户。」

Paid by density, deletions named: the state line absorbs 「循环必须能从
全新会话恢复」 (one line freed); the four Chinese channels are listed in
the English-only line as short names, dropping the two parentheticals
「(受管 PR 与决策卡)」 and 「(评论与四棱块)」, both stated in the 复核
and 升级与决策 sections (one line freed). The identity half — the body's
session ID, never the author field — lands in place on the shared-
identity line of 〈认领〉 (「身份只认正文 session ID,⛔ 不认作者字段」).

`core-rules.md` 〈全体座位的不变量〉 mirrors the rule in one line
(「用户账号仅三用:assignee、授权批准、维护者亲手;写恒经 REST 代理;批准账号
永不跑席位」), 151/151, paid by folding the three language lines into two
with no rule dropped (「一律」 kept, 「每个域恰好一个 PM」 → 「每域恰一 PM」).

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
…readings (+2 under the standing exception)

Maintainer, skills seat chat, 2026-09-13T16:14Z, verbatim and untranslated:
「机制层的五道锁 现在就派发处理」 — the card orders the deny-list reading
recorded in `references/platform-readings.md` when a row is owed.
The standing one-file exception, pm-dispatch SKILL.md, verbatim and
untranslated: 「唯一例外:`platform-readings.md` 增量抬上限到落地行数,免决策卡,
记 `ruledRaises` 引常设裁决。条件:席位验收评论逐条核实、去重计数(候选/落地/
已有/拒收)、一事一行、不计重排」

Two readings under 〈读数陷阱〉, beside the MCP invalid-session pair, both
from the Claude Code settings and permissions documentation and marked
文档载明未实测 in the file's own convention: the repository's shared
`.claude/settings.json` `permissions.deny` is read in a cloud session and
a deny at any scope is evaluated before every allow; a denied MCP tool is
removed from the tool roster entirely, so a tool's absence reads as the
deny working, never as a dead MCP server. Candidates 2 / landed 2 /
already present 0 / refused 0; 451 → 453, the THIRTEENTH `ruledRaises`
record (delta 2) citing the exception; `check:pm-skill-ratchet` green
(the cross-file move verdict is unchanged at +11 against a net source
decrease of 20).

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
@claude claude Bot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 13, 2026
@github-actions github-actions Bot added size/s documentation Improvements or additions to documentation labels Sep 13, 2026
…file's 120-byte line convention

The `out_of_scope_findings` example rewritten under lock 2 ran 141 bytes
against a file whose every line sat at or under 120 on the base; the
ratchet exempts fenced lines, so the gate stayed green while the file's
own convention regressed. Shortened to 107 bytes, same line count
(403/403), same meaning: the dev lists three-class findings to file with
dedupe words attached, and the seat files them.

Claude-Session: https://claude.ai/code/session_01DAcomhvR9kKizeYgg89Vo8
Co-authored-by: Claude <noreply@anthropic.com>
@claude

claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author
  • Served-tier: 1345/1345 claude-fable-5-1 — harness model stamp counted over this seat's own transcript (non-sidechain assistant messages a model served; <synthetic> harness notices excluded) at 2026-09-13T17:22Z; get_session external_metadata.last_served_model read claude-fable-5-1 at 2026-09-13T17:22Z.

Contract review

Head: a4dfd9d0 (PR #18072, card #18068) — read at 2026-09-13T17:23Z by the skills seat at the contract-review tier. GOVERNED rules layer, measured: .claude/settings.json (+16), .claude/agents/os-dev.md (11 lines, 403/403), .claude/skills/pm-dispatch/SKILL.md (6 lines, 812/812), references/core-rules.md (3 lines, 151/151), references/platform-readings.md (+2, 451 → 453 under the standing exception), scripts/pm/check-skill-line-ratchet.mjs (the ceiling row + a ruledRaises record) ⇒ four-piece: this record + 速读终稿 below, ACCEPT on #18068, needs-user-decision on this PR, reviews requested from os-zhuang and hotlong; ⛔ draft until an authorized approval exists, then ruling C landing by this seat. Built at claude-fable-5-1 by the tiering mandate; reviewed at the same tier. Ruling of record: the maintainer's 「机制层的五道锁 现在就派发处理」 (2026-09-13T16:14Z); lock 3 also carries 「当前任务处理完,后续并发降到2」.

① derived judgments — locks 1–4 of the write-identity plan, one commit each, every file at its ceiling and net 0:

  1. Lock 1, settings.json: permissions.deny names exactly the 14 content-writing MCP GitHub tools the card lists; the allow list (47 entries) and the hooks are untouched; the file parses. The Claude Code permissions documentation reads deny before allow at every scope, shared project settings are read in cloud sessions, and a bare-name deny removes the tool from the roster — recorded as two 文档载明未实测 lines in platform-readings (seat-verified against the diff: candidates 2 / landed 2 / already present 0 — the base's only neighbour, :280, speaks of permissions.allow — / refused 0; one fact per line; no reordering). Enforced by the runtime, not merely declared; the two update_pull_request_branch / request_copilot_review tools the dev notes stay allowed by the card's own list (state-shaped, not content) — accepted as noted.
  2. Lock 2, os-dev.md: the write channel is the REST proxy only, the budget is four writes (push, POST /pulls draft, POST /issues/{n}/labels, the report), ⛔ no MCP GitHub write tool, ⛔ no board enumeration, findings go to the report for the seat to file, and the report gains api_writes; paid by replacing the :51–:58 dedupe-channel lines that ruling ③ made stale, plus four net-0 touches outside them (each named in the report and each consistent with the rule: the label-write fallback no longer prescribes issue_write; the template example no longer shows a dev-filed card). The one line that ran 141 B on 7e1aecad is 106 B on this head; the file has zero lines over 120 again (base parity).
  3. Lock 3, SKILL.md :60: 「默认 3」 → 「默认 2」, ceiling 5 unchanged; core-rules.md :11 states no default, so no mirror was owed — measured, not assumed.
  4. Lock 4, SKILL.md 〈全体座位的不变量〉 + 〈认领〉 + core-rules.md: user accounts do three things only (assignee, authorized approval, the maintainer's hand); ⛔ seats and devs never write content as a user account; content goes through the REST proxy as claude[bot]; approver accounts never run a seat nor are a seat account's linked user; identity is the body's session ID, never the author field. Two lines instead of the card's one (the four clauses do not fit 120 B) — accepted; paid in the same section; the 〈认领〉 shared-identity line rewritten in place. core-rules.md mirrors the account-roles rule in one line. Widest row still 342 B (L244); frame block :733–:754 md5 3327d02c56f8a0eca88569dad2270f32 unchanged.
  5. The dev's open question is answered here: A — the four-write budget stands; a dev's late gate results go into its report comment, which the seat reads and verifies against api_writes; no fifth PATCH /pulls/{n} write.
  6. Boundary noted, not owed here: SKILL.md :778 「只列三类立卡与 noted, not filed」 now reads against lock 2's 「the dev lists findings to file and the seat files them」 — one-word residue for the next density pass on this file (this seat's), not this PR.

Seat measurements on the head tree (git archive a4dfd9d0): check-skill-line-ratchet ✓ on every touched file at headroom 0 (platform-readings 453/453 by the ruledRaises record); frame md5 equal; settings.json parses; check-governed-prose ✓; os-dev.md over-120 count 0, max 120. Executable criterion re-read on the diff: mcp__github__issue_write in settings.json 0 → 1 inside deny; 「默认 2」 0 → 1 / 「默认 3」 1 → 0; api_writes 0 → 2; 「批准账号」 0 → 1 in both SKILL.md and core-rules.md; controls unchanged. --pair 18072 → exit 0 at 2026-09-13T17:22Z. Checks on a4dfd9d0 at 2026-09-13T17:22Z: 29 runs, 0 red, 10 running — the landing check ③ reads them green before ruling C fires. The dev's 42-family derivation ran green at 88e0610f; the two later commits touch os-dev.md (one line) and merge origin/main.

② semver: .claude/** and scripts/pm/** publish nothing; skip-changeset is right.

③ boundary flags: open_questions — one, answered (A). Landing consequence: every seat and dev session in this repository loses the MCP GitHub content-writing tools; writes go through the REST proxy as claude[bot]; the batch default is 2; the objectui copy of settings.json and its AGENTS.md §9 line are objectui cards in this seat's next filing batch.

Implemented-by: claude/issue-18068-write-identity-locks
Reviewed-by: session_01DAcomhvR9kKizeYgg89Vo8

Verdict: PASS — the four locks land as rules a session cannot step around (the deny list) and rules a seat can be held to (the budget, the default, the account roles); awaiting an authorized approval.

维护者速读(终稿)

改了什么:四把锁。① 仓库 .claude/settings.json 加 deny 名单,禁掉 14 个会以用户身份写内容的 MCP GitHub 工具(建 issue、建 PR、发评论、审查、推文件、合并等);翻 ready、挂 auto-merge、重跑 CI 这些状态操作保留。② os-dev.md:dev 的 GitHub 写入只走 REST 代理(署名 claude[bot]),预算四笔(push、建 draft PR、贴标签、报告),不枚举板面,发现交席位立卡,报告新增 api_writes 计数。③ SKILL.md 里 batch 默认 3 改 2,天花板 5 不变。④ SKILL.md 和 core-rules 各加一条:用户账号只做 assignee、批准、你亲手三件事;席位和 dev 永不以用户身份写内容;批准账号不跑席位、不做席位账号的关联用户;身份看正文 session ID,不看作者栏。另外 platform-readings 记了两行文档读数(deny 在云会话里生效、被拒工具从工具表消失),按常设例外把该文件上限 451 抬到 453。
为什么改:今天 os-musk 被封,它用 MCP 建的 12 张卡全部隐藏;测得 MCP 写 = 用户署名,REST 代理写 = App 署名。这四把锁让「以用户身份写」在机制上不可达,并把并发和写量压到限额之下。
风险与代价(含回滚):纯配置与指令文本,无运行时影响;各文件行数不变、棘轮不动(platform-readings 的 +2 走常设例外并有记录)。回滚 = revert 对应 commit,四把锁彼此独立。deny 生效后,任何席位再想用 MCP 建卡会直接报工具不存在——这是预期,不是故障。
席位意见:通过。dev 问的一句(要不要给 dev 一次改自己 PR 正文的写)我定了 A:不给,晚到的结果写进报告。
你要做的:一次批准(os-zhuang 或 hotlong)。批准后我按裁决 C 落地,不再找你。
一句问:deny 名单落地后你自己的会话也不能再用 MCP 建 issue、发评论,只能走 REST 或网页——接受吗(是/否)?


Generated by Claude Code

@os-zhuang
os-zhuang marked this pull request as ready for review September 13, 2026 22:41
@os-zhuang
os-zhuang enabled auto-merge September 13, 2026 22:41
@os-zhuang
os-zhuang added this pull request to the merge queue Sep 13, 2026
@claude

claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Ruling C landing step — skills seat (session session_01DAcomhvR9kKizeYgg89Vo8), 2026-09-13T22:42Z. Authorized approval read: os-zhuang APPROVED on head a4dfd9d0 (review 5192548807, submitted 2026-09-13T22:41Z; not dismissed), who also flipped the PR ready and armed auto-merge. Seat readings at 2026-09-13T22:42Z: ① the contract review of record 5654849272 names this head a4dfd9d0 (unchanged since); ② check-clause2-carriers --pair 18072 exit 0; ③ 36 checks on a4dfd9d0, 0 red, 1 running — the enqueue follows its green; ④ needs-user-decision cleared in this pass and read back. PR #18051 is ahead of it in the queue on the same two files (different lines); the queue stacks this PR on top of that merge, and the seat re-reads and re-arms only if the queue ejects it. Landing record follows on #18068 once origin/main carries (#18072) — from that commit the MCP GitHub content-writing tools are denied in every session of this repository and batch defaults to 2.


Generated by Claude Code

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 13, 2026
…ite-identity-locks

# Conflicts:
#	.claude/agents/os-dev.md
@claude

claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author
  • Served-tier: 1450/1450 claude-fable-5-1 — harness model stamp counted over this seat's own transcript (non-sidechain assistant messages a model served; <synthetic> harness notices excluded) at 2026-09-13T23:03Z; get_session external_metadata.last_served_model read claude-fable-5-1 at 2026-09-13T23:03Z.

Contract review

Head: 3a3f5e0d (PR #18072, card #18068) — re-issued at 2026-09-13T23:04Z by the skills seat at the contract-review tier for the head that moved: the merge queue ejected a4dfd9d0 at 2026-09-13T23:00Z (MERGE_CONFLICT against PR #18051's landing 137eb00e), and the dev merged origin/main as a merge commit (no rebase, no amend; follow-up 5656804868). GOVERNED rules layer; the authorized approval (os-zhuang 5192548807 on a4dfd9d0, not dismissed) stands under ruling C for the seat's landing.

① derived judgments — the merge added no content of its own:

  1. The diff against origin/main is byte-for-byte the reviewed one: the same six files, +70 −21 (settings.json +16, os-dev.md 11 lines, SKILL.md 6, core-rules.md 3, platform-readings +2, the ratchet ceiling row + ruledRaises record). The record 5654849272's judgments 1–6 hold unchanged on this head.
  2. The one conflicted file resolved with both sides intact (.claude/agents/os-dev.md :50–:57): docs(pm,agents): three rules-layer lines catch up with the charter rulings #18051's landed line 立卡者不查重,只在卡面附 3–5 个查重词 at :50 (present, 1 hit) and lock 2's REST-only write rule, the four-write budget, the no-MCP line and api_writes right below it (present); SKILL.md carries both docs(pm,agents): three rules-layer lines catch up with the charter rulings #18051's 改路由(限未派发) rows and lock 3's 默认 2 plus lock 4's account-roles lines.
  3. Ceilings on the merged head, seat-measured on git archive 3a3f5e0d: SKILL.md 812/812 with the widest row 342 B and the frame block :733–:754 md5 3327d02c56f8a0eca88569dad2270f32; os-dev.md 403/403 with zero lines over 120 B; core-rules.md 151/151; platform-readings 453/453 by the ruledRaises record; settings.json parses; check-governed-prose ✓; check-skill-line-ratchet ✓ exit 0.

Seat measurements: --pair 18072 → exit 0 at 2026-09-13T23:03Z. Checks on 3a3f5e0d at 2026-09-13T23:03Z: 29 runs, 0 red, 7 running — the enqueue follows their green.

② semver: unchanged — nothing published; skip-changeset is right.

③ boundary flags: none new. Landing consequence unchanged: the MCP GitHub content-writing tools are denied in every session of this repository, batch defaults to 2, user accounts hold three roles only.

Implemented-by: claude/issue-18068-write-identity-locks
Reviewed-by: session_01DAcomhvR9kKizeYgg89Vo8

Verdict: PASS — the reviewed diff, now on a head that merges cleanly with origin/main; re-armed for the queue under the standing approval.


Generated by Claude Code

@claude

claude Bot commented Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

Ruling C re-landing step — skills seat (session session_01DAcomhvR9kKizeYgg89Vo8), 2026-09-13T23:05Z. After the queue ejection (2026-09-13T23:00Z, MERGE_CONFLICT against PR #18051's landing), the dev merged origin/main as a merge commit → head 3a3f5e0d (follow-up 5656804868). Seat readings at 2026-09-13T23:03Z: ① the contract review of record re-issued on this head (5656815610, PASS); ② check-clause2-carriers --pair 18072 exit 0; ③ 29 checks on 3a3f5e0d, 0 red, 7 running — the enqueue follows their green; ④ needs-user-decision already cleared (22:41Z) and still absent. Authorized approval: os-zhuang 5192548807 (not dismissed) stands. Auto-merge re-armed by this seat at 2026-09-13T23:04Z; ready was never lost. Landing record follows on #18068 once origin/main carries (#18072).


Generated by Claude Code

@os-project-manager
os-project-manager added this pull request to the merge queue Sep 13, 2026
Merged via the queue into main with commit 7ef05f9 Sep 13, 2026
32 checks passed
@os-project-manager
os-project-manager deleted the claude/issue-18068-write-identity-locks branch September 13, 2026 23:52
This was referenced Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/s skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants