You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This post is the single authoritative registry for the domain:services seat (seat-post protocol; index label:pm:seat). Single writer: the incumbent only. Read side: this body plus every comment newer than the body's last edit. ⛔ Shift narrative does not belong in the body — this post carries current values only.
Body refreshed after #20604 and #20628 landed and #20596 stage 4 was dispatched, by session_01XY5uCwTjZj7884yYtyur4H at 2026-09-29T13:22Z. §1 carries forward, §2–§3 are current values, and §4–§5 carry forward unchanged. No comment on this post is newer than the previous refresh.
1. Current PM — 🟢 os-justin
Incumbent:session_01XY5uCwTjZj7884yYtyur4H, GitHub login os-justin (get_me), seated at the maintainer's summons /pm-dispatch services.
Previous incumbent:session_017B6YKCGu8CTY2KBWgwaHAs (os-warren), signed off with brief 5882767934. Its open item with the maintainer stands: the os-litant Routine trig_01B4tX86W4G9qZzyrBbwvw9X is out of any seat's reach.
Write identity: the fleet relay (objectstack-fleet[bot], route dispatch) via scripts/pm/* on latest main. ⛔ No user-token writes.
Wake Routine:trig_014Y3GkVQuyfN3uUnUYqfZwb, a self-bound cron firing hourly at :57. send_later is only an accelerator.
Backend:mode:subagent. The seat runs at the default judgment tier, so contract reviews run as an isolated subagent at CONTRACT_REVIEW_TIER.
Harness:check-harness-current.mjs answered CURRENT at shared HEAD 1c761c0d71. Touches read at seating: SKILL.md 7b068877, references/**1b26b566, lanes/services.mdf151ef2c, os-dev.md7b068877.
2. Ledger — current values
Landed this incumbency (each closed completed with its state label and assignee cleared, or released as Part of):
4. Standing facts measured in this lane — ⛔ re-measure before relying, but do not re-discover
🔴 The agent roster is fixed at SESSION CREATION. A seat spawned without a repo source can attach the repo mid-session and gain its skills, but ⛔ never its agents — measured twice by session_018avjADnTGyuCcmmLWBxaNr with a register_repo_root in between. ⇒ a successor must carry the repo in session_context.sourcesat creation, and must confirm os-dev before claiming. ⚠️ The roster listing is only the declared surface; the confirming reading is an accepted Agent call.
CI must be read latest-run-per-check-name. A head carries several runs of one name and an earlier failure can be superseded by a later skipped/success. Already in platform-readings.md:301.
mergeable_state: blocked right after a ready-flip is a transient — ⛔ do not diagnose it at the one-minute mark.
⭐ The footer behaviour of a body write depends on the CHANNEL, not the surface. An earlier incumbent measured that an issue-body and a PR-body PATCH re-append the _Generated by_ footer. This session measured the opposite on the fleet relay's issue_patch op: the body is stored VERBATIM. That covers this post's body refreshes (zero footers sent, zero stored) and PR fix(service-analytics): judge each read scope with the engine's own admission before composing it #20232's body (zero sent, zero stored; the session-URL footer then sent once, one stored). ⇒ Send the footer you want stored, and read back after every write, as AGENTS.md says.
⭐ post-stamped now enforces the stamp contract (main f415bcf1): a body carrying {{NOW}} REFUSES any other bare YYYY-MM-DDThh:mmZ stamp. Write a quoted instant as {{WAS:…}}.
⭐ A comment POST normalises whitespace: the stored body can differ from what was sent by an inserted newline before a trailing ---. ⇒ a read-back equality check on fragile comments should compare fragments, not byte-identity, or it will cry wolf.
The REST /search/* path is refused in this container (sessions are bound to their repositories). Run dedupe searches through the MCP search_issues READ tool. ⛔ It is never a write channel.
ccr/auto_merge echoes merge_method back wrongly ⇒ ⛔ that field cannot tell queue landing from direct merge. The real criterion is the timeline's added_to_merge_queue; the landing criterion is delivery on origin/main, ⛔ never the PR-closed event.
A closing keyword does NOT clean the board. Auto-closed cards keep their pm:* state label and assignee ⇒ clear both on reading the merge event, with a note (⛔ never a silent assignee drop — the H47 shape).
check-expected-skips.mjs / check-half-states.mjs will not run without pnpm install ⇒ their exit is NOT MEASURED, ⛔ never read as a clean board.
The dev writes a PR body once at POST /pulls and ⛔ never PATCHes it ⇒ on a patch round the body goes stale; the dev hands the markdown over in its report and the seat appends it, marked as the seat's append.
⭐ git-history.mjs touch REFUSES rather than guessing, and that refusal is load-bearing. On a shallow clone the floor is diffed against the empty tree, so raw git log -1 -- <path> answers at exit 0 with a real, plausible, WRONG sha. Measured this seating on references/lanes/services.md; the true value came only after unshallowing to 14358 commits.
⭐ Token grep answers 「does this string appear」, which is ⛔ not the question when the question is 「is it declared / exported / executed」. Prose describing a thing is indistinguishable from the thing. A positive control only licenses a zero when it sits on the same subject as that zero (same file, same corpus, same spelling convention). ⭐ Live example carried on-card at [finding] service-messaging: sms-channel declares no isAvailable() — fan-out can suppress email on an absent transport but never sms (#17732's unfinished half) #18567: a bare grep finds isAvailable in sms-channel.ts and reads as the premise being falsified — the hit is docblock prose about the email channel, and a declaration-shaped query returns the real members and no isAvailable.
Platform facts measured by the last incumbents (session_01Evb5jFDZGKQE9KG4jbMfMF and its predecessor)
⚠️gh is ABSENT in this container — REST goes through curl or python urllib.
⚠️ node's fetch does ⛔ not read HTTPS_PROXY here; scripts/pm/* re-exec themselves with --use-env-proxy and say so on stderr.
Publication layer for this repo (registration duty): a merge to main here does ⛔ not deploy or publish ⇒ this lane's landing criterion is MERGED — except that a fix whose consumer is another repo is judged on installability, ⛔ not on merge.
⛔ cloud, objectui, hotcrm are NOT reachable from this session (GitHub scope: objectstack-ai/objectstack). Consumer-side readings on cards filed from those lanes are accepted as declared and ⛔ are not re-verifiable here.
This session's reading: REST reachable, /rate_limit core 15000/15000, repo-scoped read 200. gh is absent; node_modules is absent in the shared checkout. The relay selector answers dispatch (workflow on main, Actions state active).
This post is the single authoritative registry for the
domain:servicesseat (seat-post protocol; indexlabel:pm:seat). Single writer: the incumbent only. Read side: this body plus every comment newer than the body's last edit. ⛔ Shift narrative does not belong in the body — this post carries current values only.Body refreshed after #20604 and #20628 landed and #20596 stage 4 was dispatched, by
session_01XY5uCwTjZj7884yYtyur4Hat 2026-09-29T13:22Z. §1 carries forward, §2–§3 are current values, and §4–§5 carry forward unchanged. No comment on this post is newer than the previous refresh.1. Current PM — 🟢 os-justin
session_01XY5uCwTjZj7884yYtyur4H, GitHub loginos-justin(get_me), seated at the maintainer's summons/pm-dispatch services.5882767934was the newest event on this post, so the seat was taken at once. Mutex reading three found noClaim:on [security] a flow's inbound-hook secret (config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 or security: with no active organization, resolvePermissionSetsForContext reads the principal's position names as permission-set names organization-less, and sys_permission_set.name has no reserved-identity guard (NOT MEASURED; from PR #20540's review) #20555, the lane's onlypm:queuecards, and the lane has nopm:dispatchedcard. Reading four found only the released incumbency's session.session_017B6YKCGu8CTY2KBWgwaHAs(os-warren), signed off with brief5882767934. Its open item with the maintainer stands: theos-litantRoutinetrig_01B4tX86W4G9qZzyrBbwvw9Xis out of any seat's reach.objectstack-fleet[bot], routedispatch) viascripts/pm/*on latestmain. ⛔ No user-token writes.trig_014Y3GkVQuyfN3uUnUYqfZwb, a self-bound cron firing hourly at :57.send_lateris only an accelerator.mode:subagent. The seat runs at the default judgment tier, so contract reviews run as an isolated subagent atCONTRACT_REVIEW_TIER.check-harness-current.mjsanswered CURRENT at shared HEAD1c761c0d71. Touches read at seating: SKILL.md7b068877,references/**1b26b566,lanes/services.mdf151ef2c,os-dev.md7b068877.2. Ledger — current values
completedwith its state label and assignee cleared, or released asPart of):security): PR fix(plugin-security): an organization-less permission-set read resolves organization-less rows only #20584,6e3aa75e.security.explainreports a record visible under a row-levelusingthat compares two fields of different classes, whilefindrefuses the same read withINVALID_FILTER/ 400 #20431 (p2): PR fix(plugin-security): security/explain answers enforcement's refusal for a row-level policy comparing two fields of no shared comparison class #20598,7001918e.config.secreton the start node) is served in cleartext by the flow-definition read; after #20529 every armed hook carries one #20552 (p0security): PR fix(service-automation,metadata-protocol,metadata,runtime): withhold a flow's inbound-hook secret from every served definition, and keep it on a round trip (#20552) #20585,c96beb27.sys_comment.reactionsis described as "JSON array of emoji reaction objects", but its one reader and writer stores{ emoji: userIds[] }#20558 (p3): PR fix(plugin-audit): describe sys_comment reactions and mentions by the shape they store (#20558) #20605,ba4648da.security.explainshows a member removed from an organization that organization's grants, which enforcement refuses since PR #20540 (explain ≠ enforce, split from #20431) #20580 (p2): PR fix(plugin-security,core): security/explain resolves the user it explains through enforcement's organization-claim check (#20580) #20614,889139ce.security): PR fix(service-automation,metadata-protocol,runtime): withhold the remaining stored flow-credential positions at every depth, and answer a /meta list fault as itself (#20590) #20615,3f45b6cc.security.explainanswersallowed: trueunder a row-level policy comparing two fields of no shared class, whilefindrefuses it withINVALID_FILTER/ 400 #20604 (p2, the explain-versus-enforce closeout): PR fix(plugin-security,core): security/explain answers enforcement's refusal at the object level, and explains another user in their organization (#20604) #20629,cd901d7a.httpnode that setssigningSecretsends its request unsigned on the inline arm (and on the durable arm's no-outbox fallback), while the published contract promisesX-Objectstack-Signature#20628 (p1security, the inlinehttparm signs): PR fix(service-automation): sign the http node's inline request with the one scheme, and refuse a secret that did not resolve #20640,89801cd9.domain:servicespackages (629 sites, 112 numbers, 152 files): the ruling C+D stage for this lane (from #20556) #20596 stages 1–3: PR docs(service-messaging): re-anchor the dead tracker citations to the commits that decided them #20609422db788, PR docs(plugin-sharing): re-anchor the dead tracker citations to the commits that decided them #20626b80ab579, PR docs(plugin-auth): re-anchor the dead tracker citations to the commits that decided them #206344d04b6be.mode:subagent):domain:servicespackages (629 sites, 112 numbers, 152 files): the ruling C+D stage for this lane (from #20556) #20596 stage 4 (plugin-security, claim5890784382): a dev at the default tier.domain:services):security, positions 5–6: credentials in open maps and inurl):pm:queue+pm:retriage. Measured REACHED with in-repo exposure 0 (5890702006). Triage chooses the direction; the hotcrm count is not measured here.objectand objectui's DatasetWidget subscribes to nothing (objectui#11095's producer half) #20644 (p2, the producer half of objectui#11095):pm:blocked,Blocked-by: #20647(itspackages/spechalf, filed bare).5885196748.POST /api/v1/security/explainanswers a service refusal carryingINVALID_FILTER/ 400 as500 EXPLAIN_FAILED— the route's catch maps only PERMISSION_DENIED and OBJECT_NOT_FOUND #20603, plugin-security closeout (explain ≠ enforce): object-levelsecurity.explainanswersallowed: trueunder a row-level policy comparing two fields of no shared class, whilefindrefuses it withINVALID_FILTER/ 400 #20604, service-automation: a flowhttpnode that setssigningSecretsends its request unsigned on the inline arm (and on the durable arm's no-outbox fallback), while the published contract promisesX-Objectstack-Signature#20628, check-issue-citations closeout (extractor spellings):CITATION_RErefuses a hyphen after the digits, so a dead#N-wordcitation (#13398-class) is invisible to the diff gate and to the census #20636 and spec(contracts):AnalyticsResultdeclaresobject, the dataset answer's base object, present on every dataset answer (the spec half of #20644) #20647. Each passed the filing gate, with its reach and dedupe written on the card.isolatedtenancy — 17.5.0 requiresconfig.organizationbut offers no fan-out, so a marketplace app's scheduled flows cannot be armed for its tenants #20619 (needs-user-decision, packaged scheduled flows underisolated), from the HotCRM upgrade. It is not this seat's.5890884908).single; an unstamped write is derived there and refused everywhere else (ADR-0131 D3/D9/D11) #15195, feat(objectql,cli): inventory + migration — four fates per object, mirrors deleted only after the id→name rewrite is verified, per-table boot report (ADR-0131 D10) #15211.singleand refused under a wall (ADR-0131 D2/D3/D5/D13) #15204 → [gate] the v18 development line is not open — ADR-0131 execution cards are blocked on this card #15193, feat(objectql,plugin-auth): the Default Organization is load-bearing undersingle; an unstamped write is derived there and refused everywhere else (ADR-0131 D3/D9/D11) #15195, feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196.visibleWhenover the run's variables, wider than the declared scope (the screen's own field names), and nothing refuses an undeclared name at authoring #20178, [v18] retire the{var}template dialect in flow assignment slots: refuse at registration with per-spelling remedies (the C half of #11182 ruling D, on the v18 train) #19939, Authenticated data requests issue ~20 DB queries in ~17 sequential legs — per-request auth/session/localization/metadata resolution has no cross-request caching, costing ~1.5s/request on remote Postgres #10757, 权限设置应该可以配置实效性,权限在一个时间段之内生效 #9272, service: inbound mail + calendar sync (open-core scope) —plugin-emailis outbound-only, so email-to-record is impossible in any app #8998, Design: does approver routing imply record read visibility? (#7345 model half) #7497, [security][立项位] M2 权限生命周期(undelete/purge)功能与 allowRestore/allowPurge RBAC 同批建设(evaluator 已 fail-closed,allowTransfer 已 enforced) #1883.IStorageService.list(prefix)means two different things on the two shipped adapters (local: one level, directories as files; S3: recursive, silently capped at 1000) #5266 carrydomain:servicesand nopm:*state.3. Hot-file serial queue
plugin-security/srccomment proseservice-analytics/src/analytics-service.ts(the dataset answer'sobject)packages/spec)corethis incumbency: PR fix(plugin-security,core): security/explain resolves the user it explains through enforcement's organization-claim check (#20580) #20614 (5886089080), PR fix(plugin-security,core): security/explain answers enforcement's refusal at the object level, and explains another user in their organization (#20604) #20629 (5888695987) and PR fix(service-automation): sign the http node's inline request with the one scheme, and refuse a secret that did not resolve #20640 (5890504910). Formetadata-protocol/runtime: PR fix(service-automation,metadata-protocol,metadata,runtime): withhold a flow's inbound-hook secret from every served definition, and keep it on a round trip (#20552) #20585 and PR fix(service-automation,metadata-protocol,runtime): withhold the remaining stored flow-credential positions at every depth, and answer a /meta list fault as itself (#20590) #20615.dispatch-gateslists ⛔-marked roster families OUTSIDE its runnable commands. An order names them, and a report lists them separately. PR fix(plugin-security,core): security/explain answers enforcement's refusal at the object level, and explains another user in their organization (#20604) #20629's first head went red in CI on one that was never run.4. Standing facts measured in this lane — ⛔ re-measure before relying, but do not re-discover
session_018avjADnTGyuCcmmLWBxaNrwith aregister_repo_rootin between. ⇒ a successor must carry the repo insession_context.sourcesat creation, and must confirmos-devbefore claiming.Agentcall.failurecan be superseded by a laterskipped/success. Already inplatform-readings.md:301.mergeable_state: blockedright after a ready-flip is a transient — ⛔ do not diagnose it at the one-minute mark.PATCHre-append the_Generated by_footer. This session measured the opposite on the fleet relay'sissue_patchop: the body is stored VERBATIM. That covers this post's body refreshes (zero footers sent, zero stored) and PR fix(service-analytics): judge each read scope with the engine's own admission before composing it #20232's body (zero sent, zero stored; the session-URL footer then sent once, one stored). ⇒ Send the footer you want stored, and read back after every write, as AGENTS.md says.post-stampednow enforces the stamp contract (mainf415bcf1): a body carrying{{NOW}}REFUSES any other bareYYYY-MM-DDThh:mmZstamp. Write a quoted instant as{{WAS:…}}.POSTnormalises whitespace: the stored body can differ from what was sent by an inserted newline before a trailing---. ⇒ a read-back equality check on fragile comments should compare fragments, not byte-identity, or it will cry wolf./search/*path is refused in this container (sessions are bound to their repositories). Run dedupe searches through the MCPsearch_issuesREAD tool. ⛔ It is never a write channel.ccr/auto_mergeechoesmerge_methodback wrongly ⇒ ⛔ that field cannot tell queue landing from direct merge. The real criterion is the timeline'sadded_to_merge_queue; the landing criterion is delivery onorigin/main, ⛔ never the PR-closed event.pm:*state label and assignee ⇒ clear both on reading the merge event, with a note (⛔ never a silent assignee drop — the H47 shape).check-expected-skips.mjs/check-half-states.mjswill not run withoutpnpm install⇒ their exit is NOT MEASURED, ⛔ never read as a clean board.POST /pullsand ⛔ never PATCHes it ⇒ on a patch round the body goes stale; the dev hands the markdown over in its report and the seat appends it, marked as the seat's append.git-history.mjs touchREFUSES rather than guessing, and that refusal is load-bearing. On a shallow clone the floor is diffed against the empty tree, so rawgit log -1 -- <path>answers at exit 0 with a real, plausible, WRONG sha. Measured this seating onreferences/lanes/services.md; the true value came only after unshallowing to 14358 commits.sms-channeldeclares noisAvailable()— fan-out can suppressemailon an absent transport but neversms(#17732's unfinished half) #18567: a bare grep findsisAvailableinsms-channel.tsand reads as the premise being falsified — the hit is docblock prose about the email channel, and a declaration-shaped query returns the real members and noisAvailable.Platform facts measured by the last incumbents (
session_01Evb5jFDZGKQE9KG4jbMfMFand its predecessor)REST reachable:
/rate_limitcore 15000/15000, repo-scoped read leg 200 ⇒ session gate open. Write identityhuangyiirene.ghis ABSENT in this container — REST goes throughcurlor pythonurllib.fetchdoes ⛔ not readHTTPS_PROXYhere;scripts/pm/*re-exec themselves with--use-env-proxyand say so on stderr.Publication layer for this repo (registration duty): a merge to
mainhere does ⛔ not deploy or publish ⇒ this lane's landing criterion is MERGED — except that a fix whose consumer is another repo is judged on installability, ⛔ not on merge.⛔
cloud,objectui,hotcrmare NOT reachable from this session (GitHub scope:objectstack-ai/objectstack). Consumer-side readings on cards filed from those lanes are accepted as declared and ⛔ are not re-verifiable here.This session's reading: REST reachable,
/rate_limitcore 15000/15000, repo-scoped read 200.ghis absent;node_modulesis absent in the shared checkout. The relay selector answersdispatch(workflow onmain, Actions stateactive).5. Notes
issuecomment-5724940310names the gate by number, rejects option B as 「waits on a line the maintainer has not opened」, and the maintainer agreed 「其他同意」 — and that ruling's own Execution block routes the card topm:queue. ⇒ per-card maintainer authorisation, ⛔ not a seat overriding a gate. The reasoning is recorded on-card atissuecomment-5740746890.H525 of 50 rows,H193 of 12,H263 of 17, with 36 families partly omitted. ⛔ The absence of a row naming this lane is not a clean board.