Repository navigation
fleet-write: no relay op for PUT /pulls/{n}/update-branch — the sanctioned base sync (rest-channel.md:49) runs as bare REST and authors the merge commit under the seat's personal account (PR #22002 head fab444b4) #22052
Description
Activity
objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsTriage grade under the maintainer's dispatch hold (「创建卡片,暂时不派发。」, quoted in the body):
domain:skills·priority:p1added.pm:on-holdstays, and so does the body'sRestart-when:line (the maintainer or the director lifts the hold).Triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-07T05:01Z. ⛔ Not a claim, ⛔ not a dispatch.- Why p1, as finding(pm tooling): label-write falls back to a direct write under the seat's personal login when an accepted relay dispatch shows no run within 90 s — the identity exchange #19774 forbade, on a second branch #21892 is: this is the third branch of the identity exchange fleet-write: a relay-liveness read that answers anything but 404 /
disabled_manuallymust refuse, never fall back to the personal identity; the read runs behind the proxy re-exec; a proxy 403 is not a rate limit #19774 forbade. A fleet write goes out under a seat's personal account, here the merge commit of the sanctioned base sync (rest-channel.md:49). It is the same invariant at the same priority. - Lane:
domain:skills, because the relay's op table (scripts/pm/fleet-write/ops.mjs) and the channel rule are that lane's. - For the restart: as a
toolingcard it names its guarded surface on its first line when it enterspm:queue: the fleet-identity invariant of every relay write (fleet-write: a relay-liveness read that answers anything but 404 /disabled_manuallymust refuse, never fall back to the personal identity; the read runs behind the proxy re-exec; a proxy 403 is not a rate limit #19774).
- Why p1, as finding(pm tooling): label-write falls back to a direct write under the seat's personal login when an accepted relay dispatch shows no run within 90 s — the identity exchange #19774 forbade, on a second branch #21892 is: this is the third branch of the identity exchange fleet-write: a relay-liveness read that answers anything but 404 /
- addedpriority:p1High: required for production / M2High: required for production / M2
on Oct 7, 2026 - added a commit that references this issue
on Oct 9, 2026 objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsMaintainer ruling recorded — the 2026-10-07 dispatch hold on this card is lifted. Provenance, three items: the maintainer (os-elon-musk); verbatim 「继续上班,22052 也派发。」 (read 2026-10-09T09:05Z) and 「skills 车道所有卡都可以派发」 (read 2026-10-09T09:10Z), after 「你可以派发」 (read 2026-10-09T00:11Z); said in this seat's session chat (
session_01JmWtcHfGbC4ncw4GFKWuRA). They answer theRestart-when:line of this card (the maintainer lifts the hold 「创建卡片,暂时不派发。」). Skills seat 1 (seat post #7623), 2026-10-09T09:17Z.State:
pm:on-hold→pm:dispatchedin this act with the claim that follows (the hold's double check: this lift is newer than the hold comment 6031281642 and no PR merged on this card since; thepm:queuehop is folded into the claim because the claim is written in the same act). The body's first line now names the surface the card guards, as the triage grade asked for the restart (triage-duties.md:34).objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsClaim: PM loop round 2
Session:session_01JmWtcHfGbC4ncw4GFKWuRA
Account:os-elon-musk(the seat's linked user asGET /useranswers it; always the card's assignee)
Branch:claude/issue-22052-relay-pr-update-branch-op
Worktree:objectstack-issue-22052
Domain:domain:skills
Seat:domain:skills#1
File surface:scripts/pm/fleet-write/ops.mjs(ONE new rowpr_update_branchin the PR-ops cluster, besidepr_request_reviewers/pr_ready:pullrequired,expected_head_sharequired and 40 hex),scripts/pm/fleet-write/validate.mjs(a short or missing sha refused before dispatch),scripts/pm/fleet-write/execute.mjsanddispatch.mjs(the requestPUT /repos/{repo}/pulls/{n}/update-branch; a 422 "base unchanged" read as a no-op, not a failure; read-back polls the PR head offexpected_head_sha, bounded about 60 s, prints the new head), the self-test rows those files carry,.github/workflows/fleet-write.ymlONLY if the minted token's permission set must widen for this endpoint (the mint step already mintsissues,pull-requestsandcontentswrite — the dev measures on one real PR),.claude/skills/pm-dispatch/references/rest-channel.md(lines 49–50 move to the relay spelling; bare REST ⛔ for this verb) and.claude/skills/pm-dispatch/references/landing-operations.md§C (names the op). ⛔scripts/pm/dispatch-gates.mjsis FROZEN (ruling 208 R6) — untouched. Both reference files sit at their line ceiling (82/82 and 101/101): a new line is paid by deleting a line the same file restates, ⛔ no re-wrap, ⛔ no ceiling raise; operative text carries no issue number. Shared with #22369 (in flight this round): the same fourfleet-write/*files in DIFFERENT regions — this card's row sits in the PR-ops cluster, #22369 appendsworkflow_dispatchaftertransfer; parallel authoring, serial landing: THIS PR lands first; #22369 mergesorigin/mainbehind it. Stop on breach; explain in the report.
Container & model:M,mode:subagent,model: CONTRACT_REVIEW_TIER(reason:dispatch-gates --tier --repo objectstack-ai/objectstackover this surface prints "no path-derived mandate: the surface hits none of the 3 declared glob(s)" — the tier is the seat's call, taken fromreferences/lanes/skills.md「pm-dispatch 根恒契约复审档」 and the p1 fleet-identity invariant this card restores in the write toolchain; the in-seat contract review is at tier)
Clause-②: no
Responsibility: the seat's write toolchain produces the risk (the sanctioned base sync has no relay op, sorest-channel.md:49blesses bare REST under the seat's login) | the platform path that already covers it: none —OS_FLEET_TRANSPORT=directis the only sanctioned personal-account route and this verb never passes through it | who reaches it: every seat syncing a parked Tier H PR under landing-operations §C (one measured, PR #22002 headfab444b4); used this week
Thread-read: 6078049491
Serial constraints cleared: no open PR touchesscripts/pm/fleet-write/**,.github/workflows/fleet-write.ymlor.claude/skills/pm-dispatch/**(15 open PRs' file lists read at 2026-10-09T09:10Z);scripts/pm/fleet-write/*last touched172be37d(2026-10-07) — no same-day churn; this round's siblings: #22053 (triage-duties.md,seat-lifecycle.md,SKILL.md,os-dev.md,label-write.mjsorclose-cards.mjs) is file-disjoint; #22369 shares the fourfleet-write/*files region-disjoint and lands behind this PR (above); verify lock free, queue empty; the lane's open P0/P1 = this card ⇒ taken first. Readings at 2026-10-09T09:10Z.
Guards: the fleet-identity invariant of every relay write — a seat's base sync (
PUT /repos/{owner}/{repo}/pulls/{n}/update-branch) leaves asobjectstack-fleet[bot], never under a personal account (the class #19774 closed).Filing gate: ① a reproducible defect in the seat's write toolchain, class (b), a tool contract with no fleet-identity route: the only sanctioned way to merge
maininto a PR head (rest-channel.md:49,PUT …/pulls/{n}/update-branch) is bare REST under the seat's session token, so the merge commit is authored by the seat's personal account — the identity exchange #19774 forbade, on a third branch (the first two: route selection, #19774 closed; the no-run fallback, #21892 open). Filed bydomain:skillsseat 2 (seat post #19287,session_0181E4ZeZmWyknawnauxD2CE) on the maintainer's instruction in this session, verbatim: 「创建卡片,暂时不派发。」 ⛔ Not a claim.Reader: triage first-touch →
domain:skills; when the hold lifts, the skills seat dispatches it to one os-dev (file surface under Positions).Dedupe: REST listings, closed included (
labels=toolingsince 2026-09-07: 417; every issue updated since 2026-10-01: 625;domain:skillssince 2026-09-23: 109; union 1,030) grepped forupdate-branch|update_branch|merge main into|base sync→ 0;personal login|identity exchange|fleet identity→ 1, #21892 (open; the no-run branch — a sibling, not this path).grep -rn update-branch scripts/pm/fleet-write/ops.mjs scripts/pm/fleet-write/dispatch.mjs .github/workflows/*.yml→ 0: the closed op table has no such request.Maintainer hold at filing, verbatim: 「创建卡片,暂时不派发。」 — filed, not dispatched; the skills seat takes none of the cards filed under this instruction until the hold lifts.
Restart-when: the maintainer or the director seat comments on this card lifting the dispatch hold
What is measured
domain:skills, Tier H) was parked behind PR fix(deps): take the fixes for sharp and shell-quote that turn main's OSV scan red #22016 under landing-operations §C. After fix(deps): take the fixes for sharp and shell-quote that turn main's OSV scan red #22016 merged, the seat ran the one sanctioned sync,PUT /repos/objectstack-ai/objectstack/pulls/22002/update-branchwith the fullexpected_head_sha, as bare REST throughgh api: HTTP 202 "Updating pull request branch."fab444b4b9935b3c8199f8480e6164ec2a4c49aais a merge commit (parents95c510eb…,289ff6d4…).git log -1 --format='%an / %ae / %cn / %ce' fab444b4readsSteve Jobs <steve@objectstack.ai>/GitHub <noreply@github.com>: the author is the seat's linked personal account, notobjectstack-fleet[bot].AGENTS.md:418: "Every GitHub write leaves throughscripts/pm/, asobjectstack-fleet[bot], behind the shared write …".scripts/pm/fleet-write/dispatch.mjsheader: "falling back would exchange the fleet identity for the seat's personal account without its say-so — the shape that put two seat accounts on the platform's abuse ledger in one day …OS_FLEET_TRANSPORT=directis the ONLY way to write as the personal account in a cloud container"..claude/skills/pm-dispatch/references/rest-channel.md:49-50blesses the bare route: 「✓origin/main合进 PR head:PUT .../pulls/{n}/update-branch,PM 席位、零文件写、真合并提交。」 — a ✓ written before the relay carried this verb; it now contradictsAGENTS.md:418.Positions
scripts/pm/fleet-write/ops.mjs— the closed op table (issue_patchabout:340;pr_ready/automerge_enablerows). No request buildspulls/{n}/update-branch.scripts/pm/fleet-write/dispatch.mjs—--actions-filevalidation and read-back for the new op.main(fleet-write.yml) — the token's permission set must cover what the endpoint needs (pull_requests: write, andcontents: writefor the merge commit; the dev measures)..claude/skills/pm-dispatch/references/rest-channel.md:49-50andlanding-operations.md§C — the spelling moves to the relay op; bare REST for this verb becomes ⛔.Done when
pr_update_branchwithpull(required) andexpected_head_sha(required, 40 hex; a short sha is refused before dispatch, not by the platform's 422) issuesPUT /repos/{repo}/pulls/{n}/update-branchasobjectstack-fleet[bot]; a 422 "base unchanged" is reported as a no-op, not a failure (rest-channel.md:50).expected_head_sha(bounded, about 60 s) and prints the new head; the merge commit's author is the fleet identity, measured on one real PR and quoted in the PR body.rest-channel.md:49-50is rewritten to the relay spelling (bare REST ⛔ for this verb);landing-operations.md§C names the op; the write-pace log records it like every other op.expected_head_sharefused; a 422 read as no-op.rest-channel.md:74③: update-branch on an enqueued PR answers "cannot update") — it stays a read, now through the op's reported status.grep -rn 'update-branch' .claude scripts/pmreturns the op, its tests and the ⛔ line only.Generated by Claude Code