Repository navigation
[Ruling A on #22649] @objectstack/skills: the published skills catalog ships as a versioned package in the fixed group — the build copies skills/** in and files lists only it; the compatibility line and metadata.version derive from the package version #22658
Description
Activity
- addedenhancementNew feature or requestNew feature or requestpriority:p2Medium: important, M3Medium: important, M3and removed
on Oct 10, 2026 objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsClaim: PM loop round 2
Session:session_01RdnZdPZH9ByduzPRWuH9tN
Account:marchtian(the seat's linked user asGET /useranswers it; always the card's assignee)
Branch:claude/issue-22658-skills-package
Worktree:objectstack-issue-22658
Domain:domain:skills
Seat:domain:skills#1
File surface: two PRs from one dev. PR 1 (not governed, lands through the queue; the branch above):packages/skills/**(new:package.json, the build/prepack copy step, a README, the gitignored publish tree),.changeset/config.json(thefixedgroup),.changeset/22658-*.md,pnpm-workspace.yamlonly if the new directory falls outside the workspace globs, and any publish gate that must learn the package through its own declared exemption or ledger path (check-published-list-mirrors,check:dual-build-cjs-loads,check:dts-closure,check:lean-entry-closure,check:sourcemap-no-sources-content, the type-check coverage ledger), ⛔ never by weakening a verdict. PR 2 (Tier H, the maintainer's word; branchclaude/issue-22658-compat-line-derived, worktreeobjectstack-issue-22658-compat):scripts/check-skill-compatibility-version.mjs,packages/spec/scripts/build-skill-docs.ts(or wherever the derived line is written), the tenskills/*/SKILL.mdfrontmatters (compatibility:andmetadata.version),skills/README.mdonly if its generated block changes. ⛔skills/**paths do not move; ⛔ no change to what any skill teaches (stop on breach; explain in the report)
Container & model:M — a new published package with a build-copied tree, then a small Tier H frontmatter PR,mode:subagent,model: CONTRACT_REVIEW_TIER—dispatch-gates --tier --repo objectstack-ai/objectstackatd817f1869prints "Model tier — MANDATORY: … skills/objectstack-data/SKILL.md ⇢ 'skills/**' — clause ① (2026-09-10 ruling, verbatim 「必须 fable的还包括对外发布的skills」)"
Clause-②: no
The new package carries catalog files, no JS entry: it adds no key, export or error code an author writes against; the frontmatter lines change their producer, not their meaning. The at-tier review judges the declaration on the diff.
Responsibility:n/a — not a defect card(the execution of ruling 6096124407 on #22649, letter A)
Thread-read: none
Serial constraints cleared:none— PR #22652 (queued) touchesskills/objectstack-automation/references/state-machines-and-approvals.md, not a frontmatter; PR #22654 (queued) touches.claude/**only; no open PR touchespackages/skills/**,.changeset/config.json, the compatibility gate orbuild-skill-docs.ts(open PRs' file lists read at 2026-10-10T09:49Z); #22659 and #22668 areBlocked-by:this card
Ruling-ref: 6096124407
Landing: PR 1 through the queue after this seat's at-tier contract review; PR 2 draft with the four-piece set until an authorized APPROVED review. File surface read atorigin/maind817f1869; claim written at 2026-10-10T10:04Z.objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22658, "status": "done", "branch": "claude/issue-22658-skills-package (PR 1) · claude/issue-22658-compat-line-derived (PR 2)", "pr": "https://github.com/objectstack-ai/objectstack/pull/22691 (PR 1, draft, not governed) · https://github.com/objectstack-ai/objectstack/pull/22692 (PR 2, draft, Tier H: skills/**)", "session": "session_01RdnZdPZH9ByduzPRWuH9tN", "premise_still_valid": true, "summary": "PR 1 (#22691, head 3372d78b1): new publishable package @objectstack/skills in the changeset fixed group (70 members); its build (packages/skills/scripts/sync-catalog.mjs, self-tested as the first leg of `build`) wipes dist/ and copies the repository root's skills/** into dist/skills/** byte for byte, --check at prepack refuses a stale tree, files lists dist + README + CHANGELOG, exports names only ./package.json (the @objectstack/console shape). Layout measured against skills@1.7.2: experimental_sync reads PKG/skills/NAME/SKILL.md or PKG/dist/skills/NAME/SKILL.md; dist/ chosen because it is canonical for check:published-files, gitignored, turbo's default output and skipped by the published-README gates' walk. Tarball + throwaway-project measurement: 68 entries (65 catalog files), `npx -y skills@latest experimental_sync --yes --agent claude-code` found 10 skills from @objectstack/skills, linked .agents/skills/NAME to node_modules/@objectstack/skills/dist/skills/NAME and .claude/skills/NAME to those, skills-lock.json records version 17.7.0 and skillPath dist/skills/NAME/SKILL.md. PR 2 (#22692, head 5567d606c): scripts/check-skill-compatibility-version.mjs now reconciles metadata.version against the fixed group's version (read off @objectstack/spec's manifest, the package every compatibility line cites; @objectstack/skills carries the same version by the fixed group) and gains a --fix leg that derives both the pins' majors and the stamp; the root `version` script runs --fix after `changeset version` (the sync-protocol-version / sync-template-versions precedent) so the Version Packages PR re-stamps the ten frontmatters; the ten SKILL.md files were regenerated by --fix (metadata.version 1.0/1.2/1.3/1.4/4.4 to 17.7.0; every compatibility pin already 17.x, byte-identical). Premise note: the mechanism assumption that the gate pinned against a hand-maintained constant was false — it already reconciled pins against the workspace manifests; the hand-kept surface was the frontmatter itself, which --fix now owns.", "tests": "PR 1 (worktree ../objectstack-issue-22658, base 243dd3c62): dispatch-gates --commands derived 140 families; --ran reconciliation: 140 derived, 140 run, 0 UNRUN. Exit codes captured per command before any pipe (summaries under scratchpad issue-22658/gates/*/summary.txt): all 0 except two exit-3 prerequisite refusals recorded NOT MEASURED — `node scripts/check-plugin-teardown-shape.mjs --self-test` (needs an unshallow clone) and, before the build, `pnpm check:docs-transcript-drift` (needs @objectstack/lint built; exit 0 after the build). Named gates: check:published-files 0 (70 publishable packages, 1 with a registered extra entry — spec), check:type-check-coverage 0 (EXEMPT row for @objectstack/skills), check:type-check-debt 0 (1 ledger entry re-measured, 26 errors, none above its record), check-ci-filter-parity 0 + --self-test 0 (131 assertions; live-tree pin moved 22 to 19 with the skills/** build input now covered by core), check-changeset-fixed 0 (70 public packages in sync), check:lockstep-package-count 0 after --fix (3 occurrences 69 to 70), spec check:llms-txt 0 after llms.txt 68 to 69 (was 1 before), check:published-readme-links 0 (102 published markdown files, 226 links), check:published-readme-exports 0, check:dts-closure 0 (`1 built package(s) declare no declaration entry point and owe none` on the package alone; 73-task tree swept green), check:dual-build-cjs-loads 0, check:sourcemap-no-sources-content 0, check:lean-entry-closure 0, check:skill-compatibility 0, check:skill-identifier-liveness 0, check:doc-authoring 0, check:nul-bytes 0, check:pm-governed-prose 0, check:pm-governed-merges 0, check:merge-driver 0, check-adr-0087-registration/check-changeset-no-major/check-empty-changeset --base origin/main 0 (+ self-tests 0), spec check:docs 0 (225 generated files in sync), spec check:skill-examples 0 (262 prose examples type-check), check:pm-dispatch-gates: `✓ dispatch-gates self-test (fast tier): 1825 cases pass; 6 slow section(s) deferred` (272.9s, detached, log read after exit). Build under the verify lock: `pnpm turbo run build --filter=!@objectstack/docs --concurrency=2` — `Tasks: 73 successful, 73 total`, `VERDICT command-exit 0 · held the lock 350s`; @objectstack/skills:build printed its 9 self-test cases and `65 file(s) across 10 skill(s) copied … read back byte-identical`. Package self-test standalone: 9 cases pass; build then --check: 65 files byte-identical; `diff -r skills packages/skills/dist/skills`: identical. pnpm pack: prepack ran --check, 68 entries. Turbo cache probe (restored, proven): one byte appended to skills/objectstack-data/SKILL.md gives `cache miss, executing aca937c23b400d14`; restored to HEAD (blob equal, `git diff HEAD` empty) gives `cache hit, replaying logs 47fea834c3a0ce5a`. pnpm changeset status: @objectstack/skills listed among the 70 fixed-group packages to be bumped, at the group's pending level (major, the v18 stock on main); the changeset carries @objectstack/skills minor + @objectstack/spec patch (llms.txt). Lint, narrowed and measured at 3372d78b1: eslint --format json over the 4 touched JS files — 4 files, 0 errors, 0 warnings; population = eslint.config.mjs judging `.`; invariance: no type-aware linting (the config's own note: no parserOptions.project, no typed rules), so no untouched file's verdict moves; the repo-wide run is CI's. PR 2 (worktree ../objectstack-issue-22658-compat, base 243dd3c62): derived 51 families; --ran: 51 derived, 51 run, 0 UNRUN, every exit 0 (check:merge-driver was 1 until the NOT_DRIVER_MANAGED row landed: `generator(s) with NO recorded merge disposition: version [@objectstack/spec-monorepo]`; 0 after: `all 43 generator(s) across 81 manifest(s) have a recorded disposition`). Named: check:skill-compatibility 0 (self-test: 22 check cases + 5 --fix derivation cases + 6 declaration cases; run: 10 files, 11 pins, 10 stamps equal @objectstack/spec 17.7.0), check-skills-token-ratchet 0 + --self-test 0 (data 6127 to 6128 of 6128, headroom 1 to 0; automation 5783 unchanged, headroom 2; platform 5830 to 5831, headroom 2; ui 3847 to 3848; upgrade 6184 to 6185; all within ceilings, none touched), spec check:skill-docs 0, check:skill-refs 0, check:skill-examples 0 (262), check:skill-identifier-liveness 0, check:skill-frame-sync 0, check:skill-frame-freshness 0, check:skill-top-level-keys 0, check:self-test-wired 0, check:ratchet-remedy-authority 0, check:doc-authoring 0, check:nul-bytes 0, check:corpus-claim-drift 0, check:role-word 0, check:pm-governed-prose 0, check:pm-governed-merges 0, dts-closure/dual-build/sourcemap/lean-entry 0 on a full build under the lock (`Tasks: 72 successful`, `VERDICT command-exit 0 · held the lock 463s`), check:pm-dispatch-gates fast tier `1825 cases pass; 6 slow section(s) deferred` (282.2s). Reverse verification on the live tree (skills/objectstack-query/SKILL.md, trap-restored through `git checkout HEAD --`): version line deleted gives exit 1 `cannot read metadata.version: frontmatter metadata: map has no version: key` + fix; stamp set to 4.4 gives exit 1 `declared: metadata.version \"4.4\"` / `actual: @objectstack/spec 17.7.0 (packages/spec/package.json)` / `fix: run … --fix`; --fix gives `1 of 10 SKILL.md file(s) rewritten` exit 0; restored blob 5e7ca0008a… equals HEAD, `git diff HEAD` empty, gate green again. Ten-file diff summary: 10 files, 10 insertions, 10 deletions — exactly ` version: \"17.7.0\"` replacing `\"1.0\"` ×1, `\"1.2\"` ×1, `\"1.3\"` ×4, `\"1.4\"` ×3, `\"4.4\"` ×1; skills/README.md generated block unchanged. Lint at 5567d606c: eslint --format json over scripts/check-skill-compatibility-version.mjs and scripts/regen-artifacts.mjs — 2 files, 0 errors, 0 warnings. CI on both PRs: in_progress (not awaited, per the dispatch).", "mcp_calls": "0 — no MCP GitHub tool was called; reads were single-card REST reads via gh api (issue 22658 + comments, 22649 + ruling comment 6096124407, 22659, 22668, the two PRs' read-back) and writes went through scripts/pm only", "api_writes": "6 REST writes in 5 fleet-write relay runs (objectstack-fleet[bot]), plus 6 git pushes (not REST): POST /repos/objectstack-ai/objectstack/pulls ×2 (pr_create, draft: #22691 run 38059227624, #22692 run 38059285908); POST /repos/…/issues/22691/assignees (label-write, run 38059339432); POST /repos/…/issues/22692/labels + POST /repos/…/issues/22692/assignees (one label-write run 38059390189: skip-changeset + marchtian); POST /repos/…/issues/22658/comments ×1 (this os-dev-report, post-stamped). git push: 2 empty-branch probes + 4 content pushes (c4b174153, 3372d78b1 on PR 1; 7f748bcf2, 5567d606c on PR 2 — WIP pushes before the minutes-long builds, per AGENTS.md).", "deviations": [ "Clause-②: the dispatch prompt said PR 1 `Clause-②: yes`; the claim comment 6096391379 and the card's Done-when both say `no`; os-dev.md says copy the claim's line, so both PR bodies carry `Clause-②: no`. check-changeset-no-major demands minor+ only under `yes`; `no` beside the `minor` changeset is consistent (gate exit 0 against origin/main). PM's call if `yes` was intended — a PR-body edit by the seat, not by this dev.", "PR 1 file surface beyond the declared list, each through the gate's own declared remedy: pnpm-lock.yaml (new importer `packages/skills: {}`, written by pnpm install); content/docs/protocol/backward-compatibility.mdx ×2 and scripts/publish-smoke-pack.mjs header (check:lockstep-package-count --fix, 69 to 70); packages/spec/llms.txt (check:llms-txt count 68 to 69, with an @objectstack/spec patch line in the changeset because the file ships); turbo.json (@objectstack/skills#build declares $TURBO_ROOT$/skills/** as an input — without it a skills/** edit is a cache hit replaying a stale copy, remote cache included); .github/workflows/ci.yml (core filter gains skills/**, required by check-ci-filter-parity for every build input); scripts/check-ci-filter-parity.mjs (its self-test pins the crosspkg-rollback count over the LIVE ci.yml by design; moved 22 to 19 with the two by-name assertions now asserting coverage through core, comment records why).", "PR 2 file surface beyond the declared list: root package.json (`version` script runs the --fix leg after `changeset version`, the sync-*.mjs precedent — without it main would sit red on check:skill-compatibility after every Version Packages merge); scripts/regen-artifacts.mjs (NOT_DRIVER_MANAGED row for skills/*/SKILL.md, gen: version — the --fix spelling makes the root version script a generator in git-merge-regen's population and the gate demanded a disposition). packages/spec/scripts/build-skill-docs.ts is untouched: it reads frontmatter and writes the README/mdx listings, never the frontmatter, so the real writer is the gate's --fix.", "PR 2 version source: the PM's assumption offered a sibling manifest or the new one and asked which exists on main — packages/skills/package.json does not exist at base 243dd3c62, packages/spec/package.json does. The derivation reads @objectstack/spec (the fixed group's anchor, cited by every compatibility line); @objectstack/skills carries the same version by the fixed group. So PR 2 is green on its own and safe in either landing order; reading the literal package manifest is a one-line constant change if the maintainer prefers it.", "PR 1's README states the ruling's end state (`npm create objectstack` and the docs read the catalog from this package); #22659 and #22668 make it true and are not addressed here — flagged in the PR body's acceptance notes.", "git push count: 6 (2 probes + 4 content/WIP pushes) against the budget of two (+ probes); AGENTS.md requires a WIP push before every minutes-long step (two full builds under the lock), so the extra pushes are that rule, listed here rather than hidden.", "NOT MEASURED (exit 3, prerequisite, neither reads this diff): check-plugin-teardown-shape --self-test (needs `git fetch --unshallow`); the 6 slow sections of check:pm-dispatch-gates (deferred by the fast tier to CI)." ], "files_changed": { "pr1": [ "packages/skills/package.json (new)", "packages/skills/scripts/sync-catalog.mjs (new)", "packages/skills/README.md (new)", "packages/skills/.gitignore (new)", ".changeset/config.json", ".changeset/22658-skills-package.md (new)", "scripts/check-type-check-coverage.mjs (EXEMPT row)", "scripts/check-ci-filter-parity.mjs (self-test live pin)", "turbo.json", ".github/workflows/ci.yml", "content/docs/protocol/backward-compatibility.mdx (lockstep --fix)", "scripts/publish-smoke-pack.mjs (lockstep --fix)", "packages/spec/llms.txt (check:llms-txt count)", "pnpm-lock.yaml" ], "pr2": [ "scripts/check-skill-compatibility-version.mjs", "scripts/regen-artifacts.mjs", "package.json (root `version` script)", "skills/objectstack-ai/SKILL.md", "skills/objectstack-api/SKILL.md", "skills/objectstack-automation/SKILL.md", "skills/objectstack-data/SKILL.md", "skills/objectstack-formula/SKILL.md", "skills/objectstack-i18n/SKILL.md", "skills/objectstack-platform/SKILL.md", "skills/objectstack-query/SKILL.md", "skills/objectstack-ui/SKILL.md", "skills/objectstack-upgrade/SKILL.md" ] }, "changeset_status": "pnpm changeset status (PR 1 tree): `Packages to be bumped: - major` lists all 70 fixed-group members including @objectstack/skills (line 66, beside @objectstack/spec) — the group's pending level is major from the v18 stock already on main; the new changeset itself declares @objectstack/skills minor and @objectstack/spec patch. PR 2 carries no changeset (skip-changeset applied and read back).", "pr2_ten_file_diff": "10 files changed, 10 insertions(+), 10 deletions(-): in each skills/NAME/SKILL.md exactly one line, ` version: \"X\"` to ` version: \"17.7.0\"` (X = 1.0 upgrade; 1.2 formula; 1.3 automation, i18n, platform, ui; 1.4 ai, api, query; 4.4 data). No compatibility: line moved (all already 17.x); no body text moved; skills/README.md unchanged.", "open_questions": [], "out_of_scope_findings": [ "carrier: none · noted, not filed — metadata.version is read by nothing: skills@1.7.2's parseSkillMd keeps the frontmatter `metadata` map but experimental_sync's lock records the npm package's own version (packageVersion), and no gate in this repository read the stamp before PR 2. The ruling still derives it; it is informational prose for a human reader of the installed SKILL.md.", "carrier: none · noted, not filed — two hand-count mechanisms restate the fixed group's size on two different populations: check:lockstep-package-count (3 prose occurrences, all public packages, 70) and spec check:llms-txt (the scoped @objectstack/* count in a published file, 69). Each is gated and each moved correctly here; an observation about shape, not a defect.", "carrier: none · noted, not filed — check-ci-filter-parity's self-test pins the crosspkg-rollback count over the LIVE ci.yml by design (its comment says so); every PR that adds a root to `core` pays one self-test edit. Observed, as designed." ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsClaim: PM loop round 2 — extension for the second branch of this card (the round-2 claim
6096391379names PR 1's branch on itsBranch:line and PR 2's only in prose; the closing-target guard reads the line)
Session:session_01RdnZdPZH9ByduzPRWuH9tN
Account:marchtian(the seat's linked user asGET /useranswers it; always the card's assignee)
Branch:claude/issue-22658-compat-line-derived
Worktree:objectstack-issue-22658-compat
Domain:domain:skills
Seat:domain:skills#1
File surface: PR 2 (Tier H,skills/**):scripts/check-skill-compatibility-version.mjs, the tenskills/*/SKILL.mdfrontmatters (one derived line each),scripts/regen-artifacts.mjs(the NOT_DRIVER_MANAGED row the merge-driver gate demanded), the rootpackage.jsonversionscript (the--fixleg afterchangeset version);packages/spec/scripts/build-skill-docs.tsuntouched (it never writes the frontmatter). PR 1's surface stays as the round-2 claim declares it, plus the gate-remedy files its body names.
Container & model:M,mode:subagent,model: CONTRACT_REVIEW_TIER—dispatch-gates --tier --repo objectstack-ai/objectstackover this PR's paths prints "Model tier — MANDATORY: claude-fable-5-1 (derived from the file surface, not recalled)."
Clause-②: no
Responsibility:n/a — not a defect card(the execution of ruling 6096124407 on #22649, letter A)
Thread-read: 6098502739
Serial constraints cleared:none— no open PR touchesskills/*/SKILL.mdfrontmatters, the compatibility gate or the rootversionscript (open PRs' file lists read at 2026-10-10T14:36Z); PR 1 (#22691) and PR 2 (#22692) are file-disjoint and land in either order.
Generated by Claude Code
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsACCEPT — PR #22692 (PR 2 of this card, head
5567d606c), Tier HSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-10T14:38Z · claim6096391379+ extension 6098607178 · report6098502739.Reviewed against GitHub per the review checklist, not against the report's narrative. PR 1 (#22691) is reviewed separately below once its patch round is in.
- Shape: draft, base
main, line 1Fixes #22658(the only closing keyword; PR 1 carriesPart of). 13 files: the gate script, the ten frontmatters (one derived line each), the regen row, the rootversionscript.skip-changesetholds (the stamp is derived; PR 1's changeset describes the catalog's versioning). PR assignee set by the dev's ownlabel-write(passed the classifier). - Done-when, read on the diff:
compatibility:majors andmetadata.versionderive from the workspace version (@objectstack/spec, the fixed group's anchor) through the gate's--fix; the ten frontmatters regenerated by it, exactly one line each, no body byte; the rootversionscript re-stamps after everychangeset version; the merge driver's disposition recorded. - Evidence: self-test 22 + 5 + 6 cases, floor 27; reverse verification on the live tree; 51 derived gate families exit 0 at
5567d606c; token ratchet within ceilings (objectstack-datanow at headroom 0 — carried on the seat post). - Deviations:
build-skill-docs.tsuntouched (it never writes the frontmatter — the dispatch's assumption corrected); rootpackage.jsonandregen-artifacts.mjsbeyond the claim, both gate-driven and named — accepted. The red closing-target claim guard is the seat's (the round-2 claim'sBranch:named PR 1's branch): fixed by the claim extension 6098607178 and the body edit that re-judges it. - Contract review:
## Contract reviewPASS on the PR, record 6098612738. Four-piece set: this ACCEPT · the record ·needs-user-decision+ 维护者速读(终稿) on the PR · review requested fromos-zhuangandhotlong. The PR waits draft for an authorized APPROVED review; then the seat lands it through the queue. - Out-of-scope findings: Acceptance notes —
metadata.versionis read by no tool today (the ruling still derives it); the two hand-count mechanisms (lockstep 70 / llms.txt 69) restate the group's size on two populations, each gated;check-ci-filter-paritypins the live rollback count by design. No card.
Generated by Claude Code
- Shape: draft, base
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22658, "patch_round": 1, "status": "done", "branch": "claude/issue-22658-skills-package", "pr": "https://github.com/objectstack-ai/objectstack/pull/22691", "head": "d10855bb8c4bd1e2d8c87f3987ae7ab0c1dfbb13", "session": "session_01RdnZdPZH9ByduzPRWuH9tN", "premise_still_valid": true, "summary": "Worktree recreated from the branch and origin/main (964699128) merged in (merge commit bf8d37964, clean, no regen-pending), then one content commit d10855bb8 on top. Item 1: the README paragraph claiming the scaffolder and the docs read the catalog from this package is deleted (both sentences; nothing put in its place); the install commands and the next-channel text stay. Item 2: the scaffold smoke's red is this package's `prepack` — `pnpm pack --json` prints pnpm's lifecycle banner and the script's line on stdout ahead of the JSON, and `scripts/publish-smoke-pack.mjs`'s packOne does `JSON.parse(stdout)`, so the smoke's step 1 (packing the publishable population) throws for @objectstack/skills; pnpm's own `> PKG@VERSION prepack …` banner is on stdout regardless of what the script prints, so any prepack on any publishable package would do it. The check moved from `prepack` to `prepublishOnly` (the @objectstack/console shape): `pnpm publish --dry-run` still runs it and prints `✓ … 65 file(s) under dist/skills are byte-identical`, while `pnpm pack` runs no lifecycle script, so both smokes pack the tree their own `pnpm run build` just produced. Reproduced before and after with the smoke's exact pack command and then end to end: `pnpm run build` (73 tasks) followed by `bash scripts/create-scaffold-smoke.sh` under the verify lock — `packed 70/70`, 70 overrides (@objectstack/skills pinned), `ok — 1 pinned package(s) resolved from tarballs, 0 registry leaks`, `os create scaffold smoke passed for: plugin`, SMOKE_EXIT=0.", "smoke_root_cause": "A `prepack` lifecycle script on a publishable package. `pnpm pack --json` writes the lifecycle banner (`> @objectstack/skills@17.7.0 prepack PATH`, `> node scripts/sync-catalog.mjs --check`) and the script's stdout BEFORE the JSON document, on stdout, with stderr empty (measured: 5823 bytes of stdout, 0 of stderr, `JSON.parse` fails with `Unexpected token '>'`). `scripts/publish-smoke-pack.mjs` packOne parses that stdout and throws, so `node scripts/publish-smoke-pack.mjs` exits 1 at the smoke's step 1 (`Packing publishable packages`). Candidate (b) and (c) are not reached: with the pack step green the manifest shape and the leak assertion both pass (`0 registry leaks`; the scaffolded plugin never depends on @objectstack/skills, which the overrides map pins anyway).", "smoke_reproduction": "Exact local command (the smoke's step 1 verbatim, before the fix, on the merged tree with the package built): `node scripts/publish-smoke-pack.mjs SCRATCH/tarballs-before` → exit 1, first error line: `Error: pnpm pack --json returned non-JSON for @objectstack/skills:` followed by `> @objectstack/skills@17.7.0 prepack /home/user/objectstack-issue-22658/packages/skills`. After the fix, the same command → exit 0, `packed 70/70`, `Wrote 70 override(s)`. End to end after the fix: `bash scripts/pm/os-verify-lock.sh -c 'pnpm run build; SMOKE_KEEP=1 bash scripts/create-scaffold-smoke.sh'` (detached, waited on with tail --pid) → BUILD_EXIT=0 (`Tasks: 73 successful, 73 total`), SMOKE_EXIT=0 (`templates: plugin`, `packed 70/70`, `ok — 1 pinned package(s) resolved from tarballs, 0 registry leaks`, `os create scaffold smoke passed for: plugin`). Unit proof of the release-time invariant: `pnpm publish --dry-run --no-git-checks` in packages/skills runs `prepublishOnly` and prints the ✓ line before the tarball listing.", "files_changed": [ "packages/skills/README.md (the consumer paragraph deleted; `prepack` sentence now reads prepublishOnly)", "packages/skills/package.json (scripts.prepack → scripts.prepublishOnly, same command)", "packages/skills/scripts/sync-catalog.mjs (header: why prepublishOnly and not prepack, with the measurement)", "merge commit bf8d37964 (origin/main 964699128 into the branch; no conflicts, no file of this PR's surface touched by the merge)" ], "tests": "On the merged tree at d10855bb8, exit codes captured before any pipe: pnpm check:published-files 0 (70 publishable packages, prepublishOnly is not a `files` entry); node scripts/check-published-list-mirrors.mjs 0 + --self-test 0 (no root alias exists for it; lint.yml runs the script directly); pnpm check:lockstep-package-count 0 (3 occurrences agree with 70); node scripts/check-ci-filter-parity.mjs 0 + --self-test 0 (131 assertions, the live pin at 19 holds after the merge); pnpm check:published-readme-links 0 (the README changed); pnpm check:nul-bytes 0; pnpm check:type-check-coverage 0; pnpm check:doc-authoring 0; node scripts/check-changeset-fixed.mjs 0 (70 public packages in sync); check-empty-changeset / check-changeset-no-major / check-adr-0087-registration --base origin/main 0; pnpm check:pm-governed-prose 0; pnpm check:merge-driver 0; spec check:llms-txt 0 (count 69 still true after the merge); the package's own `node scripts/sync-catalog.mjs --self-test` 0 (9 cases), build 0, --check 0 (65 files byte-identical); eslint on sync-catalog.mjs 0. dispatch-gates --commands on the merged diff derives the same 140 families as round 1; --ran over the union of round 1 and this round: 140 derived, 140 run, 0 UNRUN — the families named above were re-run on the merged tree, the rest carry their round-1 readings at 3372d78b1. Full build under the lock: `Tasks: 73 successful, 73 total`; the scaffold smoke end to end: SMOKE_EXIT=0. CI on the new head: in_progress (not awaited).", "mcp_calls": "0", "api_writes": "2 this round: 1 git push (d10855bb8, the one content push — made before the minutes-long build-plus-smoke as the WIP rule requires, and nothing changed after it, so it is also the final push) and 1 POST /repos/objectstack-ai/objectstack/issues/22658/comments (this report, through post-stamped via the relay). No PR body PATCH, no label write, nothing on #22692, no second claim.", "deviations": [ "Base: origin/main (964699128) was merged INTO the branch as merge commit bf8d37964 rather than fast-forwarded — a fast-forward was impossible (the branch already carried two commits main does not have), and AGENTS.md lands a moved main by merge, never by rewriting a pushed branch. The merge touched no file of this PR's surface and left no regen-pending debt; the fix commit d10855bb8 sits on top of it.", "The round asked for the full `bash scripts/create-scaffold-smoke.sh` reproduction after a build; done, but detached under the verify lock and waited on with `tail --pid` because build plus smoke exceeds the foreground cap; the root cause was first pinned by running the smoke's step-1 command alone (`node scripts/publish-smoke-pack.mjs`), which is the failing step verbatim.", "`pnpm check:published-list-mirrors` is not a root alias (pnpm answered command-not-found, exit 254, nothing ran); the script was run directly, both legs exit 0.", "`pnpm pack` alone no longer refuses a stale tree (only `pnpm publish` does, through prepublishOnly); the two smokes pack right after their own `pnpm run build`, so the tree they pack is the one that build wrote — stated in the script header rather than left implicit.", "Precision on the round's wording: prepack --check did NOT refuse on the runner — it passed (the ✓ line is in the captured stdout). What broke the smoke is pnpm writing its lifecycle banner and the script's output to stdout ahead of the pack JSON; prepublishOnly is right because pnpm pack runs no lifecycle script at all, while pnpm publish still runs it (measured with --dry-run)." ], "out_of_scope_findings": [ "class: a · reach: public door = `.github/workflows/os-create-smoke.yml` (and `scripts/publish-smoke.sh`, the release smoke) red at the pack step for ANY publishable package that declares a `prepack` script, wrong answer = `pnpm pack --json returned non-JSON for PKG` (reproduced on this branch at 3372d78b1 with the smoke's own command) · evidence: `scripts/publish-smoke-pack.mjs` packOne does `JSON.parse(stdout)` of `pnpm pack --json`, and pnpm writes the lifecycle banner to stdout ahead of the JSON regardless of the script's own output; today no package declares prepack (console uses prepublishOnly), so the trap is armed and unhit · dedupe words: publish-smoke-pack prepack non-JSON · pnpm pack --json lifecycle banner · create-scaffold-smoke pack step", "carrier: none · noted, not filed — the merge of origin/main brought no change under packages/skills, .changeset, turbo.json or ci.yml; the group count (70) and llms.txt count (69) still hold." ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsACCEPT — PR #22691 (PR 1 of this card, head
d10855bb8, after patch round 1), not governed → queueSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-10T17:46Z · claim6096391379· reports6098502739and 6100393030.Reviewed against GitHub per the review checklist, not against the report's narrative. The seat read the full diff at
3372d78b1, the fix commitd10855bb8and the base mergebf8d37964; the effective diff against the merge base is the 14 files below.- Shape: draft, base
main, line 1Part of #22658(no closing keyword; the card closes on PR 2). 14 files:packages/skills/(package.json, README,.gitignore,scripts/sync-catalog.mjswith its 9-case self-test), thefixedgroup entry and the changeset (@objectstack/skillsminor,@objectstack/specpatch forllms.txt), and the gate-remedy files each through its own declared path (check-type-check-coverageEXEMPT row;check-ci-filter-paritylive-pin self-test 22 → 19 with reasons;check:lockstep-package-count --fix69 → 70 in the two prose files;llms.txt68 → 69;turbo.json$TURBO_ROOT$/skills/**as the build input;ci.ymlcorefilter gainsskills/**, which the parity gate requires;pnpm-lock.yamlnew importer). No governed path (check-governed-merges: exit 0, no governed path among the 14). PR assignee set by the dev's ownlabel-write(passed the classifier). - Done-when, read on the diff and measured by the report: a versioned
@objectstack/skillsin the fixed group (70 members,pnpm changeset statuslists it at the group's pending level); the build wipesdist/and copiesskills/**byte for byte with read-back, refuses symlinks and an empty catalog;fileslistsdist+ README + CHANGELOG,exportsnames only./package.json;skills/**does not move, nothing a skill teaches changes; measured againstskills@1.7.2: a packed tarball of 68 entries installed into a throwaway project,experimental_syncfound 10 skills and linked them fromnode_modules/@objectstack/skills/dist/skills/NAME. - Patch round 1 (seat-ordered): (1) the README paragraph claiming
npm create objectstackand the docs already read this package — false until [Ruling A on #22649] create-objectstack installs the skills catalog from the installed @objectstack/skills package, not from GitHub main; the scaffolded project depends on it at the spec's version #22659/[Ruling A on #22649] docs: the skills install command reads the catalog from the installed @objectstack/skills package; the GitHub path is documented as the next (unreleased main) channel only #22668 land — deleted; (2) the scaffold smoke, green onmainand red on3372d78b1, root-caused:pnpm pack --jsonprints theprepacklifecycle banner on stdout ahead of the JSON andscripts/publish-smoke-pack.mjsparses that stdout, so aprepackon any publishable package reds both smokes at their pack step; the check moved toprepublishOnly(the@objectstack/consoleshape), which still refuses a stale or absent tree at publish time; the smokes pack the tree their own build just produced. Local smokeSMOKE_EXIT=0; CI ond10855bb8: CI_READING. - Clause-②: the claim and both PR bodies read
no; the dispatch prompt had saidyes. The seat's judgment at review: the package carries catalog files — no key, export or error code an author writes against — so the declarednostands as the record; theminorchangeset is right for a new published package either way. The dispatch'syeswas the seat's error, corrected by the claim. - Deviations accepted: the surface beyond the declared list, each gate-driven and named; the base merge
bf8d37964(a fast-forward was impossible once the branch carried commits; the effective diff is unchanged); six pushes (two probes, WIP pushes before minutes-long builds per AGENTS.md); NOT MEASUREDcheck-plugin-teardown-shape --self-test(needs an unshallow clone) and the six slow dispatch-gates sections (CI's). The worktree's detached smoke outlived the dev's first session; the resumed dev reads its log rather than re-running it. - Out-of-scope findings: Acceptance notes —
metadata.versionis read by no tool (PR 2 derives it anyway); the two hand-count mechanisms restate the group's size on two populations, each gated; the parity self-test pins the live rollback count by design. No card. - Landing (seat's, not governed):
check-expected-skips --pr 22691→ exit 0 (1 skipped check-run(s), every one in the roster); then relaypr_ready+automerge_enable; MERGED proof and the landing note follow on this card. [Ruling A on #22649] create-objectstack installs the skills catalog from the installed @objectstack/skills package, not from GitHub main; the scaffolded project depends on it at the spec's version #22659 and [Ruling A on #22649] docs: the skills install command reads the catalog from the installed @objectstack/skills package; the GitHub path is documented as the next (unreleased main) channel only #22668 unblock when the package is installable from a release, not at this merge (theBlocked-by:reading is the consumer-install one).
Generated by Claude Code
- Shape: draft, base
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsPR #22691 (PR 1): ACCEPTED, every check green, awaiting a human queue add — the relay's arm is refused on this pull
Skills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-10T18:01Z · ACCEPT6100420263.- State: head
d10855bb8,mergeable_stateclean, 36 success · 1 expected skip · 0 failed, not governed (check-governed-merges0 of 14 paths),check-expected-skipsexit 0, ready for review (flipped by the relay at 2026-10-10T17:47Z; a draft→ready round trip at 2026-10-10T17:59Z). - What refused:
automerge_enablethrough the fleet relay, three times — runs 38073172033 (pr_ready+ arm), 38073412183 (arm alone), 38073910401 (pr_draft+pr_ready+ arm) — each with the executor's exit 5 (a FAILED action on the platform's answer; the draft/ready legs landed every time, the arm never: noauto_merge_enabled, noadded_to_merge_queue). The row naming GitHub's answer is in the job log only, and this seat's egress policy denies the Actions log host, so the cause is NOT READ (filed as a relay finding, below). - What was measured around it: 25 arms through the same relay today succeeded, every one 1–12 s after its pull's ready flip (feat(objectql,service-storage): a refused sys_file reader sees a field-owned file's metadata by the download door's verdict (#22637) #22697 15:33Z and test(cli): drive the two new --json members and align the noise-budget scaffold with the workspace protocol (nightly tiers) #22699 16:30Z after the fleet-write change landed, so the relay code is not it); two pulls that also modify
.github/workflows/ci.yml(fix(ci): judge a partially attested cancelled matrix by each shard's recorded cancel cause (Test Core, Dogfood Regression Gate) #22685, fix(ci): judge a cancelled single-leg roster by its recorded cancel cause (Dogfood Regression Gate) #22666) armed and merged through it; this pull's arm fails in that same window. Nothing in the pull object stands out (mergeable: true, same-repo head, no requested reviewers,rebaseable: falsefrom the base merge in its branch). - The ask (one click, a maintainer): "Merge when ready" / add to the merge queue on feat(skills): publish the skills catalog as @objectstack/skills in the fixed group #22691. The seat's after-merge watcher posts the landing proof here once it merges; PR 2 (feat(skills): derive the compatibility majors and metadata.version from the workspace version #22692) is the one still needing an APPROVED review.
Generated by Claude Code
- State: head
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsCause read: the fleet token has no
workflowspermission, and #22691 changes.github/workflows/ci.yml— the arm is GitHub's refusal, not the relay'sSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-10T18:05Z · corrects the note above: the row was readable after all, through the MCP read tool (the reading #19404 recorded), not the REST log route the egress denies. No relay finding is filed.- The row (run 38073910401, action 3):
✗ automerge_enable: POST /graphql enablePullRequestAutoMerge -> GraphQL: Pull request refusing to allow a GitHub App to create or update workflow.github/workflows/ci.ymlwithoutworkflowspermission. The mint grantsissues,pull-requests,contents,metadata(the op table'sPERMISSIONS); no row spendsworkflows, and GitHub requires it to merge or enqueue a pull that changes a workflow file. Runs 38073172033 and 38073412183 are the same refusal. - Why two workflow-touching pulls still landed today (fix(ci): judge a partially attested cancelled matrix by each shard's recorded cancel cause (Test Core, Dogfood Regression Gate) #22685, fix(ci): judge a cancelled single-leg roster by its recorded cancel cause (Dogfood Regression Gate) #22666): their arms came 3 s after their ready flips, while mergeability was being recomputed, so GitHub accepted a deferred arm and enqueued them itself later; this pull's arm hit the refusal in all three timings. Timing is not a landing path.
- Standing reading for the lane: a pull that changes
.github/workflows/**is a human-queue item for the relay as minted — the seat ACCEPTs, posts the proof, and asks for one click. Whether the relay's arm row should spendworkflows: writeinstead is the maintainer's permission-boundary decision, filed as [Decision] fleet relay: should the auto-merge row spendworkflows: writeso seats can enqueue pulls that change.github/workflows/**, or stay a human-queue item? #22708. - The ask stands: a maintainer's "Merge when ready" on feat(skills): publish the skills catalog as @objectstack/skills in the fixed group #22691; the seat's watcher posts the landing proof here.
Generated by Claude Code
- The row (run 38073910401, action 3):
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22658, "patch_round": 2, "status": "done", "branch": "claude/issue-22658-skills-package", "pr": "https://github.com/objectstack-ai/objectstack/pull/22691", "head": "60b8d9a1f45a63aeb0ec2a597a8e602631edc6df", "merge_commit": "60b8d9a1f45a63aeb0ec2a597a8e602631edc6df (origin/main ed1de8c2d merged into the branch on top of d10855bb8; the head IS the merge commit — no other commit was made this round)", "session": "session_01RdnZdPZH9ByduzPRWuH9tN", "premise_still_valid": true, "summary": "Worktree recreated from the branch (d10855bb8) and origin/main (ed1de8c2d, 30 commits ahead of the previous base) merged in with a merge commit — never a rebase or force-push. git reported exactly one conflict, turbo.json (content): PR #22706 added the `@objectstack/spec#gen:migration-registry` task at the same spot where this branch had added `@objectstack/skills#build`, both right before `@objectstack/spec#build`. Resolved by keeping BOTH tasks in the file's existing order and shape — `@objectstack/skills#build` first (unchanged bytes), then main's `@objectstack/spec#gen:migration-registry` kept adjacent to `@objectstack/spec#build` exactly as main has it; turbo.json parses (55 tasks). `.github/workflows/ci.yml` and `pnpm-lock.yaml` auto-merged (this PR's `skills/**` core-filter entry and the `packages/skills: {}` importer both survive). The merge brought 12 `merge=os-regen` routed paths (ten content/docs/references pages, two packages/spec/liveness state-count files), all one-sided from main: the branch never edited any routed path since the merge base, the driver recorded nothing (no `os-regen-pending`), and `git diff --cached origin/main` on each is empty — so step 2 of `scripts/pm/os-regen-merge.sh` was already the merge's result and its regen sequence had nothing to discharge; the merge was committed plainly. `pnpm install --frozen-lockfile` 0 and a plain `pnpm install` 0 with `git diff pnpm-lock.yaml` empty: the lockfile did not move. One content push (60b8d9a1f), nothing else changed after it.", "conflict": "turbo.json, one hunk. HEAD side: `\"@objectstack/skills#build\": { \"dependsOn\": [\"^build\"], \"outputs\": [\"dist/**\"], \"inputs\": [\"$TURBO_DEFAULT$\", \"$TURBO_ROOT$/skills/**\"] }`; origin/main side: `\"@objectstack/spec#gen:migration-registry\": { \"dependsOn\": [], \"outputs\": [\"src/migrations/registry.ts\"], \"inputs\": [\"package.json\", \"scripts/build-migration-registry.ts\", \"src/migrations/registry.ts.template\", \"src/migrations/entries/**\"] }`. Resolved hunk, verbatim, between `@objectstack/docs#build` and `@objectstack/spec#build`:\n \"@objectstack/skills#build\": {\n \"dependsOn\": [\"^build\"],\n \"outputs\": [\"dist/**\"],\n \"inputs\": [\"$TURBO_DEFAULT$\", \"$TURBO_ROOT$/skills/**\"]\n },\n \"@objectstack/spec#gen:migration-registry\": {\n \"dependsOn\": [],\n \"outputs\": [\"src/migrations/registry.ts\"],\n \"inputs\": [\n \"package.json\",\n \"scripts/build-migration-registry.ts\",\n \"src/migrations/registry.ts.template\",\n \"src/migrations/entries/**\"\n ]\n },\nNo marker left (0 lines matching the three marker shapes); the file is byte-for-byte main's turbo.json plus this PR's one task.", "files_changed": [ "turbo.json (conflict resolved: both tasks kept, order docs#build, skills#build, spec#gen:migration-registry, spec#build)", "merge commit 60b8d9a1f (origin/main ed1de8c2d into the branch; .github/workflows/ci.yml and pnpm-lock.yaml auto-merged with this PR's entries intact; 12 os-regen routed paths taken from main one-sided)", "pnpm-lock.yaml: no movement (frozen install 0; plain install 0; diff empty)" ], "tests": "On the merged tree at 60b8d9a1f, exit codes captured before any pipe (summaries under scratchpad issue-22658/gates/P2*/summary.txt): node scripts/check-ci-filter-parity.mjs 0 (`OK: all 21 build input(s) turbo.json declares outside the packages … covered by core`) + --self-test 0; pnpm check:merge-driver 0; pnpm check:lockstep-package-count 0 (3 occurrences agree with 70); node scripts/check-published-list-mirrors.mjs 0 + --self-test 0; pnpm check:published-files 0; pnpm --filter @objectstack/skills build 0 (`✓ sync-catalog self-test: 9 cases pass.` then `65 file(s) across 10 skill(s) copied from skills/** into dist/skills and read back byte-identical`); node scripts/check-changeset-fixed.mjs 0; pnpm check:turbo-task-graph 0; pnpm check:nul-bytes 0; node scripts/check-dev-prereqs.mjs --self-test 0. `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` re-derived on the merged diff at 60b8d9a1f: 140 families, the same set as the earlier rounds; `--ran` over the union of every command run across rounds 1, patch 1 and patch 2: 140 derived, 140 run, 0 UNRUN. The gates named above were re-run on this head; the remaining families carry their earlier readings (3372d78b1 / d10855bb8), none of which read turbo.json, ci.yml or the lockfile beyond the ones re-run here. CI on 60b8d9a1f: in_progress, not awaited.", "mcp_calls": "0", "api_writes": "2 this round: 1 git push (60b8d9a1f — the one content push; it carries only the merge commit, and nothing changed after it, so it is also the final push) and 1 POST /repos/objectstack-ai/objectstack/issues/22658/comments (this report, through post-stamped via the relay). No PR body PATCH, no label write, nothing on #22692, no second claim.", "deviations": [ "`scripts/pm/os-regen-merge.sh` was not run, by its own scope: it is the sequence for a branch that TOUCHES os-regen-driven artifacts, and this branch edits none (measured: no routed path in `git diff MERGE_BASE..HEAD`); the routed paths the merge brought are one-sided from main, the driver deferred nothing, and each equals origin/main byte for byte in the merged index — the state the script's step 2 would have produced. Recorded here rather than run blind.", "No `--self-test` exists for the package build beyond the one it runs itself; `pnpm --filter @objectstack/skills build` is the self-test plus the copy, so that single command is the reading for both.", "The merge brought 30 commits, 27 more than the seat's `~22` estimate at the time of its message; the conflict set was exactly as reported (turbo.json only)." ], "out_of_scope_findings": [ "carrier: none · noted, not filed — the `@objectstack/skills#build` and `@objectstack/spec#gen:migration-registry` tasks both insert at the same line of turbo.json (immediately before `@objectstack/spec#build`), which is why any two PRs adding a per-package task there will conflict textually; a property of the file's layout, not a defect." ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsPR #22691 at
60b8d9a1f: conflict round landed clean; the one red check is main's, not this PR'sSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-11T00:47Z · patch round 2 report6103871301.- The merge: head
60b8d9a1fis the merge oforigin/mained1de8c2dintod10855bb8, one conflict (turbo.json: PR build(spec): the migration registry is generated at build and leaves git #22706'sgen:migration-registrytask and this PR'sskills#buildtask inserted at the same line) resolved keeping both in main's order; no conflict marker; the PR's diff againstmainis the same 14 files, +512/−16; the lockfile did not move (pnpm install --frozen-lockfile0).mergeable: true. The seat read the resolution on the branch. ACCEPT6100420263stands for this head. - The red: "Type Check · source gates" fails at its base-render step because the base
ed1de8c2d(main after PR build(spec): the migration registry is generated at build and leaves git #22706) no longer carries the generated migration registry in git and the render script's archive of the base cannot import it — the same failure awaits every PR from here, and the job is green onmain's own push. Not this PR's: nothing in its diff is on that path. The reading and the fix are on the spec seat's card [Decision] the migration registryregistry.tsis the last committed generated aggregate on the ADR-0087 D3 path: keep it and finish B′, or generate it at build #22554 (the follow-up PR build(spec): the migration registry is generated at build and leaves git #22706 owes). No re-run is spent: a re-run reproduces it until main carries the fix. - Landing stays a maintainer's queue add (the fleet token cannot arm a pull that changes
.github/workflows/ci.yml, [Decision] fleet relay: should the auto-merge row spendworkflows: writeso seats can enqueue pulls that change.github/workflows/**, or stay a human-queue item? #22708), once the fix lands onmainand this PR's checks re-run green — a merge ofmaininto the branch at that point is a dev's patch round if the fix does not reach the PR's test-merge by itself.
Generated by Claude Code
- The merge: head
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsPR #22691 at
60b8d9a1f, the second red check: "Scaffold outside the monorepo, install, build" fails at its pack step on@objectstack/spec— main's, not this PR's (PR #22706's newpreparescript meetspnpm pack --json's stdout; the trap #22705 described, now hit; green on this PR's pre-#22706 headd10855bb8). Reading on #22705 and #22554; no re-run spent. This PR waits for both main-side fixes, then a maintainer's queue add. — skills seat 1,session_01RdnZdPZH9ByduzPRWuH9tN, 2026-10-11T00:52Z.
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsThe smoke pack-parse breakage that reds PR #22691's scaffold smoke now has a live card: #22705 was closed by triage before the trap was hit, with a named re-entry; that re-entry is filed as #22752 (
Unblocks: #22658). The base-render breakage is #22744, whose fix PR #22750 is armed for the queue. Once both are onmain, this PR's checks re-run (amainmerge by the dev if the test-merge does not pick them up), then a maintainer's queue add. — skills seat 1,session_01RdnZdPZH9ByduzPRWuH9tN, 2026-10-11T01:38Z.
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsSuperseded by the corrected landing note below: this copy was posted with the seat's substitution placeholders unfilled (a shell quoting slip on the seat's side); the merge it records is PR #22692 as
bf515e724, read in full in the note that follows.
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsLanded (corrected copy; the one above carried unfilled placeholders) — PR #22692 (PR 2 of this card) MERGED as
bf515e724; the card closes on itSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-11T02:20Z · claim6096391379+ extension6098607178· ACCEPT6098628523· contract review6098612738(PASS, head5567d606c) · APPROVED review byos-zhuang(5481534826, on the reviewed head) at 2026-10-11T01:51Z, who also flipped it ready and armed the queue.- Proof:
merged: true; the merge commitbf515e724is an ancestor oforigin/main; the 13 files at the merge commit are byte-identical to the reviewed head5567d606c(12 of 13 md5-equal; the 13th,scripts/regen-artifacts.mjs, carries this PR's row verbatim beside PR build(spec): the migration registry is generated at build and leaves git #22706's own change to the same file, read on the squash commit's diff). Queue path: ready 2026-10-11T01:51Z →added_to_merge_queue2026-10-11T01:53Z → merged 2026-10-11T02:16Z. - Effect, from this merge on: the ten
skills/*/SKILL.mdfrontmatters carrymetadata.versionderived from the workspace version (17.7.0 today);scripts/check-skill-compatibility-version.mjs --fixis the one writer of that stamp and thecompatibility:majors; the rootversionscript re-stamps after everychangeset version, so the next Version Packages PR carries the ten lines (NOT MEASURED until then).skills/objectstack-data/SKILL.mdsits at its token ceiling (headroom 0). - Card: closed by the merge (
Fixes #22658);pm:dispatchedand the assignee stripped in this close-out. PR 1 (feat(skills): publish the skills catalog as @objectstack/skills in the fixed group #22691,Part of) is still open: ACCEPTED, waiting on the two main-side fixes (ci(spec): render-projection-diff's base archive lacks the generatedregistry.tssince #22706, so every merge-queue entry failsType Check · source gates#22744 / PR fix(spec): render-projection-diff generates a base's git-ignored migration registry #22750 and publish-smoke-pack parsespnpm pack --jsonstdout whole, so@objectstack/spec'sprepare(PR #22706) reds the scaffold and release smokes on every pull — re-entry of #22705, unblocks #22658 #22752) and then a maintainer's queue add — tracked on this card's thread and on the seat post.
Generated by Claude Code
- Proof:
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22658, "patch_round": 3, "status": "done", "branch": "claude/issue-22658-skills-package", "pr": "https://github.com/objectstack-ai/objectstack/pull/22691", "head": "61036dbbb43082dfc6d27d536e484059d70abf1b", "merge_commit": "61036dbbb43082dfc6d27d536e484059d70abf1b (parents 60b8d9a1f, the previous head, and bf515e724, origin/main; the head IS the merge commit — no other commit was made this round)", "session": "session_01RdnZdPZH9ByduzPRWuH9tN", "premise_still_valid": true, "summary": "Worktree recreated from the branch (60b8d9a1f) and origin/main (bf515e724, 6 commits ahead: #22692 — PR 2 of this card, the derived frontmatter lines — plus #22742, #22750 the base-render fix, #22740, #22735, #22723) merged in with a merge commit — never a rebase or force-push. The merge was clean: `Merge made by the 'ort' strategy`, no conflict, turbo.json untouched by the incoming side (the order docs#build, skills#build, spec#gen:migration-registry, spec#build stands as resolved in round 2; 55 tasks), this PR's `skills/**` core-filter entry in ci.yml and its `packages/skills: {}` lockfile importer intact. The merge brought 5 `merge=os-regen` routed paths (content/docs/references/api/package-api-assembled.mdx, identity/position.mdx, ui/page.mdx, packages/spec/authorable-surface/identity.json, packages/spec/liveness/state-counts/position.md), all one-sided from main: the branch edited no routed path since the merge base (ed1de8c2d), the driver recorded nothing (no os-regen-pending), and each equals origin/main byte for byte — so `scripts/pm/os-regen-merge.sh` had nothing to discharge and the merge was committed as git made it. `pnpm install --frozen-lockfile` 0; the lockfile did not move (diff empty, nothing to commit). One content push (61036dbbb); nothing changed after it. The package's own build on the merged tree copies the ten SKILL.md files as PR 2 left them on main (metadata.version 17.7.0) — 65 files byte-identical.", "conflicts": "none — `git merge origin/main` exited 0 with no CONFLICT line; turbo.json, .github/workflows/ci.yml and pnpm-lock.yaml were not on the incoming side at all.", "files_changed": [ "merge commit 61036dbbb (origin/main bf515e724 into the branch; 5 os-regen routed paths taken from main one-sided; no file of this PR's surface touched by the merge)", "pnpm-lock.yaml: no movement (frozen install 0; diff empty)" ], "tests": "On the merged tree at 61036dbbb, exit codes captured before any pipe (summaries under scratchpad issue-22658/gates/P3/summary.txt): node scripts/check-ci-filter-parity.mjs 0 (`OK: all 21 build input(s) turbo.json declares outside the packages … covered by core`) + --self-test 0; pnpm check:merge-driver 0 (`all 43 generator(s) across 82 manifest(s) have a recorded disposition`); pnpm check:lockstep-package-count 0; node scripts/check-published-list-mirrors.mjs 0 + --self-test 0; pnpm check:published-files 0; pnpm --filter @objectstack/skills build 0 (`✓ sync-catalog self-test: 9 cases pass.` then `65 file(s) across 10 skill(s) copied from skills/** into dist/skills and read back byte-identical`); node scripts/check-changeset-fixed.mjs 0; pnpm check:turbo-task-graph 0; pnpm check:nul-bytes 0; node scripts/check-dev-prereqs.mjs --self-test 0. `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` re-derived on the merged diff at 61036dbbb: 140 families, identical to the round-2 set (0 added, 0 dropped); `--ran` over the union of every command run across rounds 1, patch 1, patch 2 and patch 3: 140 derived, 140 run, 0 UNRUN. The gates named above were re-run on this head; the remaining families carry their earlier readings on this branch's own content, which the merge did not touch. CI on 61036dbbb: in_progress, not awaited.", "mcp_calls": "0", "api_writes": "2 this round: 1 git push (61036dbbb — the one content push; it carries only the merge commit, and nothing changed after it, so it is also the final push) and 1 POST /repos/objectstack-ai/objectstack/issues/22658/comments (this report, through post-stamped via the relay). No PR body PATCH, no label write, nothing on #22692, no second claim.", "deviations": [ "`scripts/pm/os-regen-merge.sh` was not run, by its own scope (the sequence for a branch that TOUCHES os-regen-driven artifacts; this branch edits none, measured against the merge base ed1de8c2d); the five routed paths the merge brought equal origin/main byte for byte and the driver deferred nothing — recorded rather than run blind, as in round 2.", "No `--self-test` exists for the package build beyond the one it runs itself; `pnpm --filter @objectstack/skills build` is the self-test plus the copy, so that single command is the reading for both.", "The gates re-run this round were run before the push rather than after, on the same tree the push carries (the merge commit was already made; `git status` clean before and after); nothing was committed between the runs and the push." ], "out_of_scope_findings": [ "carrier: none · noted, not filed — with #22692 on main, the ten SKILL.md files this package copies now carry metadata.version 17.7.0; the copy step reads whatever skills/** holds, so no change was needed here and none was made." ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsPR #22691 at
61036dbbb: patch round 3 is a clean merge ofmain; the required set is green, the one red is main's smoke — awaiting a human queue addSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-11T02:58Z · patch round 3 report6104578260.- The merge: head
61036dbbbis the merge oforigin/mainbf515e724(six commits past round 2's base: PR feat(skills): derive the compatibility majors and metadata.version from the workspace version #22692 — this card's PR 2 — PR fix(spec): render-projection-diff generates a base's git-ignored migration registry #22750 the base-render fix, and four others) into60b8d9a1f; no conflict; the lockfile did not move. The seat verified it against GitHub, not the report: the head's tree is identical togit merge-treeof its two parents, so the commit carries nothing beyond the merge, and the PR's diff againstmainis the same 14 files, +512/−16, as at ACCEPT6100420263. The ACCEPT stands for this head. - CI on this head: 37 check-runs at 02:57Z — 35 success, 1 expected skip (
Packed-tarball smoke (opt-in), in the roster;check-expected-skipsexit 0), 1 failure: "Scaffold outside the monorepo, install, build" (job 114368200225, read through the MCP log route), the same pack-parse breakage as on60b8d9a1f—pnpm pack --jsonon@objectstack/specwith PR build(spec): the migration registry is generated at build and leaves git #22706'spreparescript printing ahead of the JSON. Not this PR's (its diff adds nothing topackages/spec), not GitHub-required (mergeable_state: unstable= the required set passes), and not run by the merge queue (os-create-smoke.ymlhas nomerge_grouptrigger; its last scheduled run onmain, 2026-10-10 atd748ae80a, predates PR build(spec): the migration registry is generated at build and leaves git #22706). The fix is in flight on the devx lane: publish-smoke-pack parsespnpm pack --jsonstdout whole, so@objectstack/spec'sprepare(PR #22706) reds the scaffold and release smokes on every pull — re-entry of #22705, unblocks #22658 #22752 → PR fix(scripts): read the last JSON document on pnpm pack --json stdout #22753 (draft). No re-run spent: it reproduces until that lands. - Landing: this is the head for the maintainer's queue add ("Merge when ready"). The fleet token cannot arm a pull that changes
.github/workflows/ci.yml([Decision] fleet relay: should the auto-merge row spendworkflows: writeso seats can enqueue pulls that change.github/workflows/**, or stay a human-queue item? #22708; refused ×3 on this PR), so the seat does not re-try the relay's arm. After the merge the seat posts the landing record here; the card is already closed on PR 2's merge.
Generated by Claude Code
- The merge: head
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22658, "patch_round": 4, "status": "done", "branch": "claude/issue-22658-skills-package", "pr": "https://github.com/objectstack-ai/objectstack/pull/22691", "head": "061f1378ddd4d3ea34c5c7abaef1548c8da4beb1", "merge_commit": "061f1378ddd4d3ea34c5c7abaef1548c8da4beb1 (parents 61036dbbb43082dfc6d27d536e484059d70abf1b, the previous head, and 996aa86e0a2f21423b321250085479427a36758b, origin/main; the head IS the merge commit — no other commit was made this round)", "session": "session_01RdnZdPZH9ByduzPRWuH9tN", "premise_still_valid": true, "summary": "Worktree recreated from the branch (61036dbbb) and origin/main (996aa86e0, 12 commits ahead by `git rev-list --count`, among them c77a8feee — PR #22753, the pnpm pack --json parser fix for #22752) merged in with a merge commit — never a rebase or force-push. The merge was clean: `Merge made by the 'ort' strategy`, no CONFLICT line; `scripts/publish-smoke-pack.mjs` carries both sides — #22753's parser (the last JSON document on stdout) and this PR's header digit — and differs from main's copy by exactly that one line (`enumerates the same 70 names`); turbo.json (order docs#build, skills#build, spec#gen:migration-registry, spec#build; 55 tasks), this PR's `skills/**` core-filter entry in ci.yml and its `packages/skills: {}` lockfile importer all intact after the incoming side also touched those three files. The merge brought 5 `merge=os-regen` routed paths (content/docs/permissions/system-context.mdx, references/data/field.mdx, references/data/object.mdx, references/system/migration.mdx, references/ui/component.mdx), all one-sided from main: the branch edited no routed path since the merge base (bf515e724), the driver recorded nothing (no os-regen-pending), and each equals origin/main byte for byte — so `scripts/pm/os-regen-merge.sh` had nothing to discharge and the merge was committed as git made it, the same reading as rounds 2 and 3. `pnpm install --frozen-lockfile` 0; the lockfile did not move (diff empty, nothing to commit). The fixed packer's own self-test on this tree: `node scripts/publish-smoke-pack.mjs --self-test` 0, `SELF-TEST PASSED (10 cases)`, its last case `ok — packOne reads the document past a fake pnpm that prints a banner first` — the reading that the failure this PR's scaffold smoke showed in patch round 1 is closed on main. One content push (061f1378d); nothing changed after it.", "conflicts": "none — `git merge origin/main` exited 0 with no CONFLICT line. The two edits to scripts/publish-smoke-pack.mjs did not overlap (this PR: the header comment's count at line 36; #22753: the parser from line 45 on), and git merged them without a marker; `git diff origin/main -- scripts/publish-smoke-pack.mjs` is one hunk, 69 to 70 names.", "files_changed": [ "merge commit 061f1378d (origin/main 996aa86e0 into the branch; 5 os-regen routed paths taken from main one-sided; scripts/publish-smoke-pack.mjs, turbo.json, .github/workflows/ci.yml and pnpm-lock.yaml merged with this PR's entries intact)", "pnpm-lock.yaml: no movement (frozen install 0; diff empty)" ], "tests": "On the merged tree at 061f1378d, exit codes captured before any pipe (summaries under scratchpad issue-22658/gates/P4/summary.txt): node scripts/check-ci-filter-parity.mjs 0 (`OK: all 21 build input(s) turbo.json declares outside the packages … covered by core`) + --self-test 0; pnpm check:merge-driver 0 (`all 43 generator(s) across 82 manifest(s) have a recorded disposition`); pnpm check:lockstep-package-count 0; node scripts/check-published-list-mirrors.mjs 0 + --self-test 0; pnpm check:published-files 0; pnpm --filter @objectstack/skills build 0 (`✓ sync-catalog self-test: 9 cases pass.` then `65 file(s) across 10 skill(s) copied from skills/** into dist/skills and read back byte-identical`); node scripts/check-changeset-fixed.mjs 0; pnpm check:turbo-task-graph 0; pnpm check:nul-bytes 0; node scripts/check-dev-prereqs.mjs --self-test 0; node scripts/publish-smoke-pack.mjs --self-test 0 (`SELF-TEST PASSED (10 cases)`); pnpm check:publish-smoke-pin 0 (the root alias of that same self-test). `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` re-derived on the merged diff at 061f1378d: 140 families, identical to the round-3 set (0 added, 0 dropped — no family changed); `--ran` over the union of every command run across rounds 1, patch 1, 2, 3 and 4: 140 derived, 140 run, 0 UNRUN. The gates named above were re-run on this head; the remaining families carry their earlier readings on this branch's own content, which the merge did not touch. CI on 061f1378d: in_progress, not awaited.", "mcp_calls": "0", "api_writes": "2 this round: 1 git push (061f1378d — the one content push; it carries only the merge commit, and nothing changed after it, so it is also the final push) and 1 POST /repos/objectstack-ai/objectstack/issues/22658/comments (this report, through post-stamped via the relay). No PR body edit, no label write, nothing on #22692, no second claim.", "deviations": [ "`scripts/pm/os-regen-merge.sh` was not run, by its own scope (the sequence for a branch that TOUCHES os-regen-driven artifacts; this branch edits none, measured against the merge base bf515e724); the five routed paths the merge brought equal origin/main byte for byte and the driver deferred nothing — recorded rather than run blind, as in rounds 2 and 3.", "The incoming range counted 12 commits by `git rev-list --count 61036dbbb..origin/main` against the PM's 11; the listed commits are the ones the PM named (c77a8feee among them) plus the merge of #22765 at the tip. No conflict either way.", "The gates re-run this round were run before the push rather than after, on the same tree the push carries (the merge commit was already made; `git status` clean before and after); nothing was committed between the runs and the push." ], "out_of_scope_findings": [ "carrier: none · noted, not filed — the scaffold smoke's step-1 parse that reddened this PR in patch round 1 is now covered on main by #22753's self-test case (`packOne reads the document past a fake pnpm that prints a banner first`); this PR's own change there (the check at prepublishOnly rather than prepack) stays correct on its own terms and is not undone." ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsPR #22691 at
061f1378d: patch round 4 is a clean merge ofmaincarrying the smoke fix; every check green — ready for the maintainer's queue addSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-11T05:39Z · patch round 4 report6105696360.- The merge: head
061f1378dis the merge oforigin/main996aa86e0(eleven commits past round 3's base, among them PR fix(scripts): read the last JSON document on pnpm pack --json stdout #22753c77a8feee, the publish-smoke-pack parsespnpm pack --jsonstdout whole, so@objectstack/spec'sprepare(PR #22706) reds the scaffold and release smokes on every pull — re-entry of #22705, unblocks #22658 #22752 fix for the pack-parse smoke) into61036dbbb; no conflict (scripts/publish-smoke-pack.mjsis changed by both, in non-overlapping hunks); the lockfile did not move. Verified against GitHub, not the report: the head's tree is identical togit merge-treeof its two parents, and the PR's diff againstmainis the same 14 files, +512/−16, as at ACCEPT6100420263— the diff of the two diffs is empty apart from blob ids. The ACCEPT stands for this head. - CI on this head: 37 check-runs at 05:39Z — 36 success, 1 expected skip (
Packed-tarball smoke (opt-in), in the roster;check-expected-skipsexit 0), 0 failures; "Scaffold outside the monorepo, install, build" is green on this head, the first since PR build(spec): the migration registry is generated at build and leaves git #22706 — PR fix(scripts): read the last JSON document on pnpm pack --json stdout #22753's fix reached it through this merge.mergeable: true,mergeable_state: clean. No re-run was spent on any round. - Landing: this is the head for the maintainer's queue add ("Merge when ready"). The fleet token cannot arm a pull that changes
.github/workflows/ci.yml([Decision] fleet relay: should the auto-merge row spendworkflows: writeso seats can enqueue pulls that change.github/workflows/**, or stay a human-queue item? #22708, ruled A at6104822731; the widening PR is not landed yet, and this PR does not wait on it), so the seat does not re-try the relay's arm. After the merge the seat posts the landing record here; the card is already closed on PR 2's merge.
Generated by Claude Code
- The merge: head
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsLanded — PR #22691 (PR 1 of this card) MERGED as
165587ee64; both PRs of the card are now onmainSkills seat 1 ·
session_01RdnZdPZH9ByduzPRWuH9tN· 2026-10-11T06:39Z · claim6096391379· ACCEPT6100420263(headd10855bb8) · reports6098502739,6100393030,6103871301,6104578260,6105696360· PR 2's landing6104564080.- Proof:
merged: true; the merge commit165587ee64is an ancestor oforigin/main; the 14 files at the merge commit are byte-identical to the landed head061f1378d(14 of 14 files, md5-equal). Path: ready 2026-10-10T17:59Z (the relay's flip) →added_to_merge_queuebyos-zhuangat 2026-10-11T06:02Z (a human queue add: the fleet token cannot arm a pull that changes.github/workflows/ci.yml, [Decision] fleet relay: should the auto-merge row spendworkflows: writeso seats can enqueue pulls that change.github/workflows/**, or stay a human-queue item? #22708) → merged 2026-10-11T06:38Z. - The head the queue took:
061f1378d= the ACCEPTed content (d10855bb8) plus three merge-only patch rounds — round 2 (60b8d9a1f, mained1de8c2d, the oneturbo.jsonconflict resolved keeping both tasks, read by the seat in6103899539), round 3 (61036dbbb, mainbf515e724after PR fix(spec): render-projection-diff generates a base's git-ignored migration registry #22750 restored the base-render step, no conflict) and round 4 (061f1378d, main996aa86e0after PR fix(scripts): read the last JSON document on pnpm pack --json stdout #22753 fixed the pack-parse smoke, no conflict). The seat verified rounds 3 and 4 as clean merges: each head's tree equalsgit merge-treeof its two parents, so the commits carry nothing beyond the merge; the PR's diff againstmainstayed the same 14 files, +512/−16, through all three rounds (the diff of the two diffs is empty apart from blob ids). ACCEPT6100420263stands unchanged for the landed head. On this head every check was green before the queue add: 37 check-runs, 36 success, 1 expected skip,mergeable_state: clean(status comment6105913563). - Effect, from this merge on:
@objectstack/skillsexists in the workspace and the changesetfixedgroup (70 members); its build copiesskills/**intodist/skills/**byte for byte (65 files across the ten skills at this head, the frontmatters already carryingmetadata.version: 17.7.0from PR feat(skills): derive the compatibility majors and metadata.version from the workspace version #22692);skills/**is a build input (turbo.json) and in CI'scorefilter; the next Version Packages PR bumps it with the group and the next release publishes it. Nothing a skill teaches changed. - What this merge does NOT do: [Ruling A on #22649] create-objectstack installs the skills catalog from the installed @objectstack/skills package, not from GitHub main; the scaffolded project depends on it at the spec's version #22659 (
domain:cli) and [Ruling A on #22649] docs: the skills install command reads the catalog from the installed @objectstack/skills package; the GitHub path is documented as the next (unreleased main) channel only #22668 (domain:devx) staypm:blocked— their unlock reading is consumer-install (the package installable from a release), not this merge; the unlock scan returns them after the release that carries it. publish-smoke-pack parsespnpm pack --jsonstdout whole, so@objectstack/spec'sprepare(PR #22706) reds the scaffold and release smokes on every pull — re-entry of #22705, unblocks #22658 #22752 (thepack-runs-prepareparse breakage from PR build(spec): the migration registry is generated at build and leaves git #22706, re-entered from [finding] publish-smoke-pack parses the wholepnpm pack --jsonstdout, so any publishable package that declaresprepackreds both smokes at the pack step (armed, unhit) #22705) landed as PR fix(scripts): read the last JSON document on pnpm pack --json stdout #22753c77a8feeeon the devx lane before this merge; nothing of it is this PR's. - Card: already closed
completedat PR 2's merge (bf515e724,6104564080); this note completes the record. Nothing is left on the card.
Generated by Claude Code
- Proof:
Filing gate ③: a task the maintainer directed by ruling — #22649 letter A, maintainer 「22649 同意 A」, record 6096124407 (skills seat 1,
session_01RdnZdPZH9ByduzPRWuH9tN, said in this seat's session chat, 2026-10-10). Ruling-ref: 6096124407. This is the first of the three execution cards of that ruling (skills lane); the cli and devx cards areBlocked-by:this one. ⛔ Not a claim.Reader: the
domain:skillsseat dispatches it to one os-dev. Surface: a newpackages/skills(not governed);.changeset/config.json(thefixedgroup);scripts/check-skill-compatibility-version.mjsandpackages/spec/scripts/build-skill-docs.tswhere the derived line is produced or checked; the tenskills/*/SKILL.mdfrontmatters (governed Tier H, about two lines each). Two PRs are allowed and preferred: the package first (non-governed, through the queue), the frontmatter derivation second (Tier H, the maintainer's approval). ⛔skills/**paths do not move; ⛔ no change to what any skill teaches; ⛔ no new standalone gate (the maintainer named none).What the ruling decides (record 6096124407 on #22649)
The published catalog
skills/**ships today from the GitHub repository's default branch (npx skills add objectstack-ai/objectstack/skills …), so a project on@objectstack/spec17.7.0 reads skills that already teach v18 spellings (skills/objectstack-automation/SKILL.md:108onmain, PR #22475). The only binding is the hand-keptcompatibility: Requires @objectstack/spec 17.xline, reconciled to the workspace, not to the consumer. Ruled A: the catalog ships as a versioned package beside the spec, installed from the consumer'snode_modules; the GitHub path stays only as the documentednextchannel.Done when
packages/skills/package.json: name@objectstack/skills,private: false, added to.changeset/config.json'sfixedgroup so its version is always the spec's (17.7.0 today);fileslists only the copied catalog; abuildorprepackstep copies the repository'sskills/**(everySKILL.md,references/**,rules/**,evals/**,README.md) into the package's publish tree, which is gitignored; no second copy of a skill is committed; the published tree is proven equal toskills/**byte for byte by a self-test of the copy step or by an existing mirror gate (check-published-list-mirrorsif it fits), ⛔ not by a new standalone gate.npm packthe package, install it in a throwaway project, runnpx -y skills@latest experimental_sync; the reading (the skills it found, the directory it wrote) goes in the PR body. If the sync does not fit the layout, say so with the output — the cli card then copies the files itself.compatibility:line on every publishedSKILL.mdand eachmetadata.versionare derived from the package version (written bygen:skill-docs, or checked bycheck-skill-compatibility-version.mjsagainst the package's own major instead of the workspace spec's); no hand-kept version line remains inskills/**; the gate still reds on an absent line (its header's rule).skills/*/SKILL.mdkeeps its paths and stays green:check-skills-token-ratchet,check:skill-docs,check:skill-refs,check:skill-examples,check:skill-compatibility,check:skill-identifier-liveness,check:skill-frame-sync, andcheck-governed-merges's register row forskills/**.minorfor@objectstack/skills(a new published package),Clause-②: no(nothing a consumer writes changes). The package needs no JS entry; if a publish gate requires one (check:dual-build-cjs-loads,check:dts-closure), the PR shows the gate's own exemption path rather than a dummy entry.Workload (per the ruling): S + S; precedent for the frontmatter touch PR #22475 (one skill file, +17/−18); a new published package skeleton has no recent precedent in this repository — the PR says so.
Dedupe: REST listing
labels=domain:skills&state=all&since=2026-08-01(12 pages, 1,150 cards) grepped forversion|compat|bind|npx skills|skills add|catalog|release→ 0 cards on the catalog binding before #22649; this card is one third of #22649's execution; open titles grepped for@objectstack/skills→ 0. Dedupe words: skills package versioned catalog · @objectstack/skills · skills install from node_modules · compatibility line derived.Generated by Claude Code