diff --git a/.claude/skills/pm-dispatch/SKILL.md b/.claude/skills/pm-dispatch/SKILL.md index 8d45bc4ebfb..7ee426d4a69 100644 --- a/.claude/skills/pm-dispatch/SKILL.md +++ b/.claude/skills/pm-dispatch/SKILL.md @@ -199,7 +199,7 @@ PM 的工作是循环:选卡 → 认领 → 派发 → 收集 → 复核 → 报 - 该账户改为把 PR assign 给它替代通知,另一账户照常请审;轮次报告点名说明走了兜底。 - 请审走免碰 draft 位的 REST 专用路,ready/draft 走中继 op;MCP 兜底已拒;端点见 rest-channel。 - ④ 轮次报告单列 awaiting a human merge。 -- 已入队才读到本条 ⇒ 转 draft 与 disable 都做;出队以阳性探针答,ref 缺席只旁证。 +- 已入队 ⇒ 转 draft 并 disable,即请维护者手动出队(席位无实测手段);出队以阳性探针答。 - skills 车道自有 PR:纯代码面如 `scripts/pm/` 由本席按达档自审(清单不减)后落地。 - 受管面两层:Tier S = `.claude/**` 全树,余皆 Tier H 等人批;S 经达档复核 PASS 后 ready → 入队。 - 路径面干净的才转 ready → 入队;队列是唯一被认可的落地路径,⛔ 永不队列外合并。 diff --git a/AGENTS.md b/AGENTS.md index c70e4d09e43..1d1eb1d83e0 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -282,9 +282,10 @@ localStorage / auth gotchas. governed-surface PR, under any account** — an authorized account is agent-operated too; "CI is green" carries no information about a governance change. - **Already armed or queued when you read this?** Convert it back to **draft** AND disable auto-merge — draft is - what removes queue membership, disabling alone drops only the arming — then confirm from the remote that it is in - neither the queue nor `origin/main`. **Draft is no barrier by itself — the barrier is this directive**, and a + **Already armed or queued when you read this?** Disable auto-merge AND convert it back to **draft**, which disarms + an unqueued PR; no seat act, those two included, is measured to dequeue one (`platform-readings.md`, queue + membership), so ask the maintainer at once to remove a queued PR by hand — then confirm from the remote that it is + in neither the queue nor `origin/main`. **Draft is no barrier by itself — the barrier is this directive**, and a spent approval or a standing record IS the review record, ⛔ not a relaxation. Behind it: the queue guard refuses a governed diff without its tier's record; CODEOWNERS routes review requests for `docs/adr/` only, so nothing summons the maintainer on the other Tier H surfaces; the post-merge audit (`scripts/pm/check-governed-merges.mjs`) lists @@ -425,8 +426,8 @@ write; never a token in a remote URL, a `git config` value on disk or a log line it.** Under one shared identity every other participant's write arrives unsigned: the PM flipping your draft to ready and arming auto-merge, a bot re-labelling, the platform rewriting your body. A rewritten body is evidence about the body and of nothing else — -⛔ never extend it to the draft flag, which flipped back destroys auto-merge and queue -membership at once (§7's draft-flip re-arm note), invisibly. Read the timeline event's +⛔ never extend it to the draft flag, which flipped back destroys an unqueued PR's +auto-merge at once (§7's draft-flip re-arm note), invisibly. Read the timeline event's actor, or ask; undo only once you know who set it and why. **Write the attribution footer in the form the surface keeps — blank line, rule, ONE footer line:** @@ -529,8 +530,8 @@ Even inside your own worktree, operate defensively: known-flaky signature, then re-arm once, never reflexively; **collateral eviction is silent** (triage comments only on `failure`, so an entry cancelled because something *ahead* failed gets nothing) — neither on `main` nor in the queue means dropped, re-arm; - **flipping back to draft drops auto-merge and queue membership at once**, and neither - returns by itself — ready *first*, arm *second*. One non-fix: **a stale red does not + **flipping back to draft drops an unqueued PR's auto-merge at once**, and it does not + return by itself — ready *first*, arm *second*. One non-fix: **a stale red does not clear by re-running** — `rerun_failed_jobs` reuses the original run's commit and merge ref, so a fix that landed on `main` since is invisible to it; only a new commit (`git merge origin/main`) helps. Whether a direct `gh pr merge` is refused here is