The escalation contract — the ruling trigger, the comment shape, and the default ladder #72
Labels
No labels
attention
blocked
blocker:ci-red
blocker:conflict
blocker:drill-pending
blocker:unrequested
bug
claimed
documentation
enhancement
epic
merge-next
needs-ruling
needs-triage
offsite
post-merge
ready
release
scope:docs
scope:guards
scope:labels
scope:release-flow
stale
state:addressing
state:bots-reviewing
state:building
state:needs-human
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: heavy-duty/ceremony#72
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #50. Mints the doctrine half of the 2026-07-23 amendment as ruled by @danmt in #50 (14:24Z relay / 14:42Z confirm) — decisions D11–D14 in the epic body. Nothing here is open; the decisions are made and this issue implements their wording.
Context
needs-rulingshipped with the flag, the exclusion rule and the sweep invariants (#51, #52), but the doctrine describes the escalation as "one comment carrying the question, the options, and your recommendation" and stops there. Two things #16 taught are missing from it.The trigger is written too narrowly. REVIEWER.md L84-L93 and BUILDER.md L77-L86 both frame the flag as the exit from a panel disagreement. #16 stalled on neither ambiguity nor a review dispute: it stalled on which org owns a published package namespace, and on whether
paths-ignoremay skip docs in PR checks. Both are policy, neither had a dissenting reviewer, and the flag was correct for both.The comment has no shape, and shapelessness is what failed. #16's escalation was complete and correct, and the reply it drew was "I got lost in that wall of text." Analysis is not the deliverable; a decidable question is.
And nothing said what happens while the human is asleep. A flag with no exit path is a stall class with a label on it. @danmt's ruling supplies the ladder.
Spec
Four decisions, carried in full in #50's decision table (D11–D14) so a later reader does not reconstruct them from this issue. State them in the role files as follows; do not re-derive, re-open or re-word the reasoning.
D11 — the trigger is an unowned decision
The flag fires whenever the decision belongs to a human — org policy, published artifacts, secrets, prod, or any choice whose cost lands outside the PR — and not only when reviewers disagree. A panel deadlock stays one instance of it, not the definition. Reviewers still route through the builder (D3); one accountable flag-setter per artifact is unchanged.
D12 — the escalation comment has a fixed shape
At most five lines above the fold, everything else folded:
none — hard block.The four field labels (
Options:,Recommend:,Blocked:,Default:) are load-bearing strings — #73 greps for them. Write the template so the four lines are copy-pasteable verbatim.D13 — the ladder (@danmt's ruling)
A default is allowed only when the call is clear. The bar is affirmative: the flag-setter must be confident the decision is reversible — reversible meaning changeable inside the PR before merge — not merely unable to think of a reason it isn't. Unsure is not a tie, it is a block. Anything touching published artifacts, secrets, prod or org policy is a hard block by construction.
Default: <X> at <UTC>and proceeds on it when the deadline passes, saying out loud that it did. Anything with reasonable doubt carriesnone — hard blockand waits.The decision escalates from builder to triage rather than dissolving into nobody's hands, and the operator is notified throughout (the notification path is #74's).
D14 — where the rungs are anchored
The ladder's clock runs from the
labeledevent of the current flag episode, not from the last activity and not from theDefault:deadline. Consequences to state plainly:labeledevent.Default:says, hard blocks included.Default:governs only the 0–12h rung — whether the builder may act before the PR stage. A hard block never proceeds silently; at 24h it proceeds visibly, as a PR the human gates.needs-ruling.Tasks
needs-rulingparagraph (L74-L100) and its table row (L70) with D11's trigger and D13's ladder in summary; update theD1–D10citation toD1–D14. The canonical template lives in BUILDER.md — link it, do not duplicate it.#50 D11–D14where each decision is stated, so the epic stays the single source.Acceptance criteria
<details>fold; the other three files link to it.Options:,Recommend:,Blocked:,Default:— #73's mechanical check greps for these strings, so a rename here is a break there.D1–D10citation readsD1–D14.Test plan
test/run.shgreen — the doctrine files carry no executable behavior, buttest/self-ref.test.shand the docs mirror do read them.docs/VENDORED.txt: confirmactions/docs-sync/docs-sync.sh --checkbehaves — the mirror is content-addressed, so the edit must not need a manifest change, and must fail--checkin a consumer whose.ceremony/is stale. Demonstrate that failure once rather than assuming it.main. Ablob/mainlink in a doctrine file is a review failure.Dependencies
Part of #50. Blocks #73 (its grep targets are this issue's strings) and #74 (its rung descriptions cite this issue's wording).
I’m starting this build. I’ll implement the D11–D14 doctrine across the four governed files, verify the vendored-doc behavior (including a stale-consumer failure), run the full suite, and open a draft PR from a dedicated worktree.
claude-bot-andresmgsl referenced this issue2026-08-21 16:14:45 +00:00