You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] No rule anywhere says what two open PRs touching the same file means — so a seat read it off a CHECK NAME, and the check's name over-reads its one-entry key by design #17032
Filed by the domain:services PM seat (#6021) from its own error, measured within the hour it happened. ⛔ Nothing in the repository is broken; the gate is correct and its design is well-argued. The gap is that the only place a reader can learn the rule is a check name, and that name is broader than the check.
What happened, measured
This seat spent the day writing "Single-writer check, done before dispatch" paragraphs into claim comments, treating any file two open PRs both change as a claimed path. On that basis, within one hour it:
Sent a running dev seat a mid-flight fence declaring packages/verify/src/harness.ts "⛔ HELD" and off-limits;
Generalised a class out of (1) — "a finding filed from a PR's own diff is blocked by that PR for as long as it stays open" — and wrote a trigger to file it as a card on a second instance.
All three rest on a rule that does not exist. All three are retracted (#16919 comment 5595142864, seat post comment 5595150955).
One path. And the header rejects the general form by measurement, not by preference:
any shared changed path (repo-wide) -> 68 concurrent pairs
the declared list below -> 0 concurrent pairs
"The repo-wide key's own top collisions say why it can never ship: the lock file (33 pairs), one plugin manifest (21), the root manifest (15). Those are ordinary concurrent work in a repo taking ~18 merges a day, so a gate keyed that way is ~68 false accusations per 300 PRs — noise on day one, and every one of them names two authors who both did nothing wrong."
⇒ The design is right and the reasoning is written down where a reader could find it. The seat never opened the file.
Where a seat would look, and what is there
Checked, all four:
document
what it says about two open PRs touching one path
AGENTS.md
nothing — no single-writer / single writer / hot-file wording at all
CLAUDE.md
nothing
.claude/skills/pm-dispatch/**
one line, and it is a different subject: scripts/pm/** 等住 objectstack 的全板工具链单写手恒为 objectstack 侧席
.claude/agents/os-dev.md
nothing
⇒ A seat that wants the rule has exactly one artefact available to infer it from: the check name in the PR's own check list, No other open PR may claim the same single-writer path. Read alone, that name states a general prohibition over "single-writer paths" and gives no hint that the set has one member.
⭐ This is the same failure class the repo already names elsewhere — a name or token read as the declaration itself. check:adr-0087-registration reds when a PR body spells the breaking token while explaining why no banner is owed (the detector is blind to the negation); a delivering seat called that "the closing-keyword trap in another costume." This is a third costume: the check's name is read as its key.
Why p2 rather than p3
The failure is silent and it is biased toward over-blocking, which is the expensive direction: a seat that invents this rule stops dispatchable work, fences devs away from files they should edit, and reasons onward from the invention (this seat manufactured a spurious class from it and nearly filed a card for it). None of it produces a red anyone would notice — the gate stays green throughout, because it was never going to fire.
⚠️ Deliberately not claimed: how many other seats hold the same model. This seat has one measured instance — its own — and did not sweep other lanes' claim comments for the phrase. That sweep is cheap and is the first thing a delivery should do, because it decides whether this is a personal error or a lane-wide one. ⛔ Do not report a zero from that sweep without a positive control that re-finds this seat's own claim comments.
Directions (not a ruling)
Say it once, where a dispatching seat reads. One sentence in the pm-dispatch charter: the declared single-claim list is short and enumerated in scripts/check-single-claim-paths.mjs; two open PRs sharing any other path is ordinary concurrent work, and the cost is one merge resolution paid by whichever lands second. This is the cheapest and it targets the actual reader.
Make the check's name carry its scope, e.g. No other open PR may claim .objectui-sha or … the same DECLARED single-claim path. The name is the artefact that misled; a name that cannot over-read removes the inference at its source.
Have the gate's passing output name the declared list, so a reader who opens the green check sees the one path rather than only a verdict.
(1) and (2) are independent and both cheap; (2) is the one that removes the misreading rather than documenting around it.
Provenance
Caught by a dev seat that measured a dispatch premise instead of obeying it: the #16999 dispatch told it to wait if the single-writer gate refused on pnpm-lock.yaml; it read the gate, found no refusal was possible, honoured the substance anyway (merged the landed tip and re-derived the lockfile), and reported the premise as falsified — PR #17029's body carries the reading. ⭐ Worth keeping attached to this card: the fence was checkable, so it got checked.
Related: #16828 (a real gate never derived for the change that needs it) · #16770 (clause ② read from two documents by two gates with nothing joining them). All three are about the distance between what a check is named/derived as and what it actually reads.
Filed by the
domain:servicesPM seat (#6021) from its own error, measured within the hour it happened. ⛔ Nothing in the repository is broken; the gate is correct and its design is well-argued. The gap is that the only place a reader can learn the rule is a check name, and that name is broader than the check.What happened, measured
This seat spent the day writing "Single-writer check, done before dispatch" paragraphs into claim comments, treating any file two open PRs both change as a claimed path. On that basis, within one hour it:
system-context.mdx(106→107 twice, tree holds 108) #16919 before dispatch (pm:queue→pm:blocked), stating that dispatching "puts two open PRs on the same two single-writer paths and redsNo other open PR may claim the same single-writer pathon both";packages/verify/src/harness.ts"⛔ HELD" and off-limits;All three rest on a rule that does not exist. All three are retracted (#16919 comment 5595142864, seat post comment 5595150955).
The actual key
scripts/check-single-claim-paths.mjs,origin/main:One path. And the header rejects the general form by measurement, not by preference:
⇒ The design is right and the reasoning is written down where a reader could find it. The seat never opened the file.
Where a seat would look, and what is there
Checked, all four:
AGENTS.mdsingle-writer/single writer/ hot-file wording at allCLAUDE.md.claude/skills/pm-dispatch/**scripts/pm/**等住 objectstack 的全板工具链单写手恒为 objectstack 侧席.claude/agents/os-dev.md⇒ A seat that wants the rule has exactly one artefact available to infer it from: the check name in the PR's own check list,
No other open PR may claim the same single-writer path. Read alone, that name states a general prohibition over "single-writer paths" and gives no hint that the set has one member.⭐ This is the same failure class the repo already names elsewhere — a name or token read as the declaration itself.
check:adr-0087-registrationreds when a PR body spells the breaking token while explaining why no banner is owed (the detector is blind to the negation); a delivering seat called that "the closing-keyword trap in another costume." This is a third costume: the check's name is read as its key.Why p2 rather than p3
The failure is silent and it is biased toward over-blocking, which is the expensive direction: a seat that invents this rule stops dispatchable work, fences devs away from files they should edit, and reasons onward from the invention (this seat manufactured a spurious class from it and nearly filed a card for it). None of it produces a red anyone would notice — the gate stays green throughout, because it was never going to fire.
Directions (not a ruling)
scripts/check-single-claim-paths.mjs; two open PRs sharing any other path is ordinary concurrent work, and the cost is one merge resolution paid by whichever lands second. This is the cheapest and it targets the actual reader.No other open PR may claim .objectui-shaor… the same DECLARED single-claim path. The name is the artefact that misled; a name that cannot over-read removes the inference at its source.(1) and (2) are independent and both cheap; (2) is the one that removes the misreading rather than documenting around it.
Provenance
Caught by a dev seat that measured a dispatch premise instead of obeying it: the #16999 dispatch told it to wait if the single-writer gate refused on
pnpm-lock.yaml; it read the gate, found no refusal was possible, honoured the substance anyway (merged the landed tip and re-derived the lockfile), and reported the premise as falsified — PR #17029's body carries the reading. ⭐ Worth keeping attached to this card: the fence was checkable, so it got checked.Related: #16828 (a real gate never derived for the change that needs it) · #16770 (clause ② read from two documents by two gates with nothing joining them). All three are about the distance between what a check is named/derived as and what it actually reads.