From 92aeeeef2d4aa5f0b6e8c3248cadd1bd38bca978 Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Mon, 28 Sep 2026 08:27:03 -0500 Subject: [PATCH] docs(plans): brief, a queue row's owner can't be its reviewer (#1508) Filbert's n2 from the Piece D round 2 review, written as a queue brief. It is also the piece a fresh seat starts in Gate G. Co-Authored-By: Claude Opus 5.5 --- .../2026-09-28_queue-owner-not-reviewer.md | 58 +++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 docs/plans/2026-09-28_queue-owner-not-reviewer.md diff --git a/docs/plans/2026-09-28_queue-owner-not-reviewer.md b/docs/plans/2026-09-28_queue-owner-not-reviewer.md new file mode 100644 index 00000000..0c4e24bf --- /dev/null +++ b/docs/plans/2026-09-28_queue-owner-not-reviewer.md @@ -0,0 +1,58 @@ +# Queue: a row's owner can't be its reviewer + +Brief for one queue row under #1508. Written by Sage on 2026-09-28 from +Filbert's n2 in the Piece D round 2 review +(`agents/filbert/work/queue-d-review-r2-2026-09-27.md`). It is also the +piece a fresh seat starts in Gate G. + +## Refuse the owner as a reviewer at add, set reviewers and assign + +### Problem + +`queue set ID reviewers`, `queue add --reviewer` and `queue assign` accept +the row's owner as a reviewer. `review record` refuses the owner +(`packages/queue/src/queue.mjs`, the check near "only a listed reviewer +other than the owner"), but the approval check still waits for every listed +reviewer. So a row whose owner is on its reviewer list can't reach `done` +or `waiting-on-jason` until a privileged actor edits the list. The refusal +names the owner as a missing approval, which reads as a bug. Nothing is +unsafe today. It fails closed, but it can stall a row. The item is on +`docs/plans/DEFERRED.md` under "Queue: an owner listed as a reviewer blocks +the row". + +### Owner and reviewer + +- Owner: rocko. +- Reviewer: filbert, who found it. + +### Files owned + +- `packages/queue/src/queue.mjs` +- `packages/queue/tests/` (new or changed test files) +- `packages/queue/README.md` (one sentence on the rule) + +### What ships + +- `add` refuses a row whose `--owner` is also among its `--reviewer`s. +- `set ID reviewers` refuses a list that includes the row's owner. +- `assign ID SEAT` refuses a SEAT that is on the row's reviewer list. +- Each refusal exits 2, names the seat and the row, and writes nothing (no + log entry, no witness change). +- Do not fix it by dropping the owner from the required approvals. With + reviewers `[owner]` that list would be empty and the row would pass with + no review. +- Tests for each refusal and for the unchanged accept paths. + `node --test packages/queue/tests/` and `bash scripts/test-queue.sh` pass. + +### Out of scope + +Rows already in `queue.json`: none has its owner as a reviewer today, so no +migration. The other DEFERRED queue items (the queue-commit message when +HEAD moves, calendar checks on dates) stay separate. + +### Gate + +Filbert approves through the queue: the owner moves the row to in-review +with `--candidate`, and Filbert records an approval with `queue review +record`. Sage then commits the candidate, and the suites above must pass +on it.