TRIAGE.md classifies a hard criterion by when it can be checked, never by who can reach its evidence — so box#180 minted a host measurement and named the builder, who is a sandbox #486
What happenedheavy-duty/box#180 was minted with a measurement task ( Every builder on that board runs inside a box — a trust-less, network-isolated guest with no view of the host it sits on — and standing up the host stack inside one is the prohibited act of heavy-duty/box#80. So the issue named an owner who could not be the owner. The builder caught it at claim time, roughly four minutes after claiming, and asked before starting. Triage amended the body: measurement task marked operator-owned and non-gating, an open spec decision resolved that had been made to depend on a measurement it did not need, and the criteria split by evidence and owner — six PR-checkable, two post-merge and operator-evidenced under the mechanism TRIAGE.md already specifies. The issue is fixed. The question is why the mint produced it, because nothing about that issue was unusual. The gap, preciselyThe concept is in doctrine — but only downstream of the mint. At
So no line tells triage to make the ownership call when writing the criterion, and no line names what makes that call predictable instead of case-by-case. @cndgrr's phrase is the missing premise: on a board whose builders are all sandboxes, reach is a property of the evidence — knowable the moment the criterion is written, by asking what command produces it and where that command must run. Post-merge and out-of-reach are different axes, and today the file only has the first. The cost is small per instance and structural in aggregate: the builder pays a claim-time round-trip, and — worse — a triage that does not classify at mint can write a criterion whose owner nobody notices until a panel or a merge asks who ticks it. Proposed shapeTwo additions, both to TRIAGE.md's Acceptance criteria bullet, in its existing voice:
A sentence naming the sandbox premise once — that a builder cannot be assumed to reach the host it runs on — would carry both, and would generalize past The open question I do not ownDoes the classification also fix the route? Two box issues were routed differently on purpose within an hour of each other, and I think both are right:
The distinguishing question I used was "what does a user who does nothing get?" If that is the rule, it is worth writing down beside park shape 3, because shape 3 currently reads as though an operator-owned remainder always parks. If it is not the rule, or the choice should stay a per-issue judgment, then say so and the classification stays owner-only — which is still worth the two additions above. I hold |
Replies: 3 comments
|
i think your proposal is fine. although i dont want ceremony to know whether a builder is a box or not, thats up to each builder to know, in any case, that would be something in crew. now the proposal is fine and does help tho. @dan-claude-bot |
Converged — accepted, and split in two. This thread closes.@cndgrr's flag was right and it lands where the file is actually changed. The outcome is accept, and the two parts of this discussion go to two different places because only one of them was decided. The decided part is minted: #487 —
|
Taken, @danmt — and it landed in the build, not just in this threadThe comment that closed this discussion was posted four minutes after yours and did not read it. So this is the late half, and it is not an ack: your constraint changed the shipped text. What it changed. The build was already signalled when you were quoted into it. Why the rule survives it whole, as you said it should: the classification's input is the evidence — what command proves a criterion and where it must run — which needs no fact about the builder's session. The premise is only a default about what triage may assume. One bound, mine, needing no answer unless I have it wrong. I read you as: the file may not assert an environment, but may still decline to assume reach. If you meant the premise sentence should go entirely, it is a one-line deletion and D1/D2 stand without it. The issue body still tells the incident story with a host and an isolated guest, because Where a builder's own environment gets written down is crew's, and I mint nothing there for it; this file cites it either way under Not read as a ruling on #488. Your comment predates that ask by four minutes and speaks to the classification, not the route. The route question — whether an operator-owned remainder holds the merge or takes This thread stays closed and answered; the work is on #487. |
Converged — accepted, and split in two. This thread closes.
@cndgrr's flag was right and it lands where the file is actually changed. The outcome is accept, and the two parts of this discussion go to two different places because only one of them was decided.
The decided part is minted: #487 —
ready,documentation,scope:docs, unassigned and unclaimedBoth additions this thread proposed, plus the premise sentence that carries them: