From 8cdefa6c2462751d694dfec1858014f460ef5238 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 6 Oct 2026 14:32:50 +0000 Subject: [PATCH] docs(pm-skill): judge responsibility before dispatch, breaker on reopening security review Four rules land in the pm-dispatch protocol text, each paid in place against the line ratchet: the claim template gains a `Responsibility:` line (whose code / platform path / who reaches it), the escalation enumeration gains the document-not-defend exit and the no-heuristic-security-boundary exit, the REWORK/ESCALATE verdicts gain the three circuit-breaker conditions, the round report lists breaker hits per PR, triage asks the three questions at first touch, and the grading rules cap a highest-privilege-only, no-current-user finding at p3 regardless of the security label. Claude-Session: https://claude.ai/code/session_0181E4ZeZmWyknawnauxD2CE Co-authored-by: Claude --- .claude/skills/pm-dispatch/SKILL.md | 6 +++--- .claude/skills/pm-dispatch/references/execution-duties.md | 4 ++-- .claude/skills/pm-dispatch/references/filing-gate.md | 2 +- .claude/skills/pm-dispatch/references/seat-lifecycle.md | 2 +- .claude/skills/pm-dispatch/references/triage-duties.md | 2 +- 5 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.claude/skills/pm-dispatch/SKILL.md b/.claude/skills/pm-dispatch/SKILL.md index 793cccd3d9a..d3ebd520e2e 100644 --- a/.claude/skills/pm-dispatch/SKILL.md +++ b/.claude/skills/pm-dispatch/SKILL.md @@ -211,6 +211,8 @@ PM 的工作是循环:选卡 → 认领 → 派发 → 收集 → 复核 → 报 ## 升级与决策 - 只在至少一条成立时升级:选项在产品语义或公开契约形状上真实分歧且既有规范定不了。 +- 或责任三答齐指他人代码、已有正路、仅最高权限可达 ⇒ 只提文档或决策卡,⛔ 不派码。 +- 或修复以猜测(键名、值形状、模式表)定安全边界 ⇒ 决策卡先比对声明式方案。 - 或修复需破坏性/难回滚动作;其余归 PM 裁量:裁定、派发、维护者否决窗口而非许可门。 - 具名不升级类(立即行动):恢复不变量;技术任务间顺序与依赖;验证策略;说明书脱节。 - 四类记账事同属不升级类,恒以无产品可见行为变化为界:去重与卡片合并;台账与记账整理; @@ -279,7 +281,6 @@ PM 的工作是循环:选卡 → 认领 → 派发 → 收集 → 复核 → 报 - 终报 JSON 形状住 `.claude/agents/os-dev.md`,⛔ 不抄第二份;`needs_decision` 时 `open_questions` 非空。 - `premise_still_valid: false` + `pr: null` 是合法终报,当再分诊输入复核,永不当失败派发。 - `out_of_scope_findings` 每条 `class: a|b|c`+`reach:`+证据,或 `carrier:`(承接者);皆无 ⇒ Acceptance notes。 -- `reach:` 无实测 ⇒ ⛔ 不立卡,例外三种与定义见立卡门 ①;同轮报告互读,同族只开一张。 - dev 不立卡;ACCEPT 逐条一行 `filed #N`/`Acceptance notes`/`dropped — 因`;三类由席位立在修复仓。 - 席位读 PR `## Acceptance notes`,实属三类的经立卡门补立、归挂;门外已立卡关 not planned。 - 同族发现并入收口卡(一卡覆盖全族位置,带枚举钉子),⛔ 不开单点卡;无则第二次即开。 @@ -293,11 +294,9 @@ PM 的工作是循环:选卡 → 认领 → 派发 → 收集 → 复核 → 报 | `scripts/pm/check-half-states.mjs` | label/assignee/PR 半状态的 report-only 巡查(含已复核就绪却无人落地的孤儿 PR 检测) | | `scripts/pm/check-governed-merges.mjs` | governed 面合并清单的 report-only 审计(事后防线;本地枚举零 API,仅归因走查询) | | `scripts/pm/dispatch-gates.mjs` | 文件面 → 该跑的门禁族(派发令取数) | -| `scripts/pm/git-history.mjs` | 窗口化 commit 计数:回答或 REFUSE(浅 clone 对窗口化 `git log`/`rev-list` 以 exit 0 无警告答错);`historyHorizon()` 是只读谓词 | | `scripts/pm/os-regen-merge.sh` | 碰生成物 PR 的 merge 四步序(防静默吞并与锚点倒退) | | `scripts/pm/ensure-pm-labels.sh` | pm 标签词表的幂等一次性创建;退役车道刻意不在 ⛔ 不加回,对象清理以脚本头为权威 | | `check:skill-frame-sync` / `-freshness` | 四维决策框架唯一一份拷贝的同构与新鲜度 | -| `guard-main-checkout` / `guard-shared-stash` hooks | worktree-first 与 stash 禁令的机械面 | ## 模板与表 @@ -314,6 +313,7 @@ Seat: `domain:#` (the seat number this PM sits on; absent = seat 1) File surface: `<预期触碰的目录>` (stop on breach; explain in the report) Container & model: ``, `mode:subagent | mode:cloud`, `model: <档位词,引当次 --tier 输出;天花板拼 CONTRACT_REVIEW_TIER,同行引其 MANDATORY 路径行或 reason:;⛔ 不抄模型 id>` Clause-②: yes | no +Responsibility: `` (defect cards only, else `n/a — not a defect card`; the dispatch prompt's ruling section repeats the three answers) Thread-read: Serial constraints cleared: `<点名同文件/同包的前驱 PR 与在飞认领,及分诊点名的任意车道在飞兄弟卡中本卡 pin 断言其行为者;无则 none>` ``` diff --git a/.claude/skills/pm-dispatch/references/execution-duties.md b/.claude/skills/pm-dispatch/references/execution-duties.md index 6b40454a346..dc93d760671 100644 --- a/.claude/skills/pm-dispatch/references/execution-duties.md +++ b/.claude/skills/pm-dispatch/references/execution-duties.md @@ -68,7 +68,6 @@ - 公开面 = 包构建后的入口声明所达,⛔ 不只数入口的再导出清单。 - 所达 = 再导出名,加经其 props、参数与返回类型可达的每个类型。 - 语言包键已发布:包导出语言包及其派生类型(`TranslationKeys = typeof en`)即发布每个键。 -- `Clause-②: yes` 至少 `minor`:AGENTS.md Post-Task Checklist 第 3 条,本行在认领处复述。 - 席位读不定(席位不做构建)⇒ 认领写明,dev 在报告里于构建声明闭包上实测,实测定案。 - 档位引 `dispatch-gates --tier --repo 仓`⛔ 不凭记忆;天花板拼常量名并同行引据,⛔ 不抄模型 id - 末行 Serial constraints cleared 是落在评论里的读数,同包在飞单不点名等于没查。 @@ -180,4 +179,5 @@ - 判决 ACCEPT:issue 英文短评论,核对清单结论 + 抽查读数 + 偏差,链接 PR,⛔ 不复述其叙事。 - `mcp_calls` 点名写工具(`settings.json` deny 清单 + `update_pull_request`)⇒ 拒收,⛔ 不带注放行。 - 判决 REWORK:逐项反馈,同认领重派;补丁轮优先 SendMessage 续派原 dev;最多 2 轮,第三次升级。 -- 判决 ESCALATE:见 SKILL.md 〈升级与决策〉。 +- 判决 ESCALATE:见〈升级与决策〉;熔断任一命中亦判,PR 暂停,答复前 ⛔ 不派下一轮。 +- 熔断三条:独立安全复审连续 2 轮不过;diff 超首次复核规模 2 倍;上轮修复引入新 HIGH。 diff --git a/.claude/skills/pm-dispatch/references/filing-gate.md b/.claude/skills/pm-dispatch/references/filing-gate.md index 1bde29ca354..285c58fa37b 100644 --- a/.claude/skills/pm-dispatch/references/filing-gate.md +++ b/.claude/skills/pm-dispatch/references/filing-gate.md @@ -12,7 +12,6 @@ - ① 有具名落点或复现的产品缺陷,即 `pm:queue` 的定义;其内的 `finding` 限三类且带 `reach:`。 - `reach:` 二选一:公开入口(HTTP/界面/`os validate`/保存)实测一次错误结果;或具名真实生产者。 - 三种例外照立,要点首条「先测可达性」:可能泄露数据;发版固化的错误文字;维护者直派。 -- 判例:自注「未测量」的 (b) 卡 ⇒ 不立;`reach:` 记公开入口一次实测错误的 (b) 卡 ⇒ 立。 - ② 只有维护者能做的决定,落卡即带「维护者速读」与四棱块。 - ③ 维护者直派的任务,正文引其原话。 - ④ 协调节点:跨仓/跨层父单与它的逐层子单。 @@ -41,6 +40,7 @@ - 「仪器为车队服务」的四种答案 ⛔ 不压成两条;假红的标准代价形态是席位顺从它。 - 点名一次被假红占住的席位动作(具名那张卡),与点名一次派错/落不了同等成立。 - 沿链继承只给上界,界内哪格由失效形态定:墙齐平,税降一格;可重入队的 PR 是税。 +- 可达面定上界:`security` 标签不抬级;仅最高权限可达且无现用者至多 p3,可记录不修。 - 北极星第 4 条只认出货面(`skills/**`、产品文档),⛔ 不含 `.claude/**` 内部协议。 - 它认的是一句说错的话,⛔ 不是一句缺席的话;缺句按覆盖不足走北极星第 2 条。 diff --git a/.claude/skills/pm-dispatch/references/seat-lifecycle.md b/.claude/skills/pm-dispatch/references/seat-lifecycle.md index e62d17c1b4c..49a69a0bff5 100644 --- a/.claude/skills/pm-dispatch/references/seat-lifecycle.md +++ b/.claude/skills/pm-dispatch/references/seat-lifecycle.md @@ -65,7 +65,7 @@ ## 轮次报告与节奏 - 每轮向维护者打中文轮次报告(chat 通道):issue → 判决 → PR 链接 → 备注的表。 -- 报告加升级项、代裁清单(分诊)、awaiting a human merge 项。 +- 报告加升级项、代裁清单(分诊)、awaiting a human merge 项、逐 PR 熔断命中项(无则 none)。 - 报告含 `UNRECOGNISED` 行:对本轮门禁日志 grep `UNRECOGNISED` 逐行照录,`NOT APPLICABLE` 行也在内。 - 健康指标五个:可派发库存(open `pm:queue` 未认领及趋势);决策箱(待维护者数)。 - 决策箱指标还要点名带开放下游依赖的决策卡,从 `Blocked-by:` 反向索引现算。 diff --git a/.claude/skills/pm-dispatch/references/triage-duties.md b/.claude/skills/pm-dispatch/references/triage-duties.md index 184c4b56c5c..94f81fc9784 100644 --- a/.claude/skills/pm-dispatch/references/triage-duties.md +++ b/.claude/skills/pm-dispatch/references/triage-duties.md @@ -71,7 +71,7 @@ - 同族发现并入收口卡,不开单点卡;在飞(assignee/open PR)永不并,`Blocked-by:` 不派;完工查过期。 - 执行席 ⛔ 不并卡,疑重复挂 `pm:retriage` 写明哪两张同文件同机制;同 assignee 者自关后卡。 - 生产者在哪是常设分诊问题:declared ≠ enforced 形状的卡先问谁在写这个字段。 -- 派发前按生产者的答案改卡的范围与域标签。 +- 首触答责任三问:谁的代码出险/有正路否/谁可达且有人用否;据答改卡范围、域与路由。 - 发现分诊轮:`finding` 恒 = 待首次定级、定级即离标;hold 重验只在 `Restart-when:` 命中时发生。 - closed 形态随每轮解锁扫描;可执行判据由分诊席每日一个低频子轮批量执行。 - `Restart-when:` 命中同 closed 命中待遇:回队前 ref 重验再回队。