docs(plans): brief, a queue row's owner can't be its reviewer (#1508)

Filbert's n2 from the Piece D round 2 review, written as a queue brief.
It is also the piece a fresh seat starts in Gate G.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-09-28 08:27:03 -05:00
co-authored by Claude Opus 5.5
parent 0d6658b57d
commit 92aeeeef2d
@@ -0,0 +1,58 @@
# Queue: a row's owner can't be its reviewer
Brief for one queue row under #1508. Written by Sage on 2026-09-28 from
Filbert's n2 in the Piece D round 2 review
(`agents/filbert/work/queue-d-review-r2-2026-09-27.md`). It is also the
piece a fresh seat starts in Gate G.
## Refuse the owner as a reviewer at add, set reviewers and assign
### Problem
`queue set ID reviewers`, `queue add --reviewer` and `queue assign` accept
the row's owner as a reviewer. `review record` refuses the owner
(`packages/queue/src/queue.mjs`, the check near "only a listed reviewer
other than the owner"), but the approval check still waits for every listed
reviewer. So a row whose owner is on its reviewer list can't reach `done`
or `waiting-on-jason` until a privileged actor edits the list. The refusal
names the owner as a missing approval, which reads as a bug. Nothing is
unsafe today. It fails closed, but it can stall a row. The item is on
`docs/plans/DEFERRED.md` under "Queue: an owner listed as a reviewer blocks
the row".
### Owner and reviewer
- Owner: rocko.
- Reviewer: filbert, who found it.
### Files owned
- `packages/queue/src/queue.mjs`
- `packages/queue/tests/` (new or changed test files)
- `packages/queue/README.md` (one sentence on the rule)
### What ships
- `add` refuses a row whose `--owner` is also among its `--reviewer`s.
- `set ID reviewers` refuses a list that includes the row's owner.
- `assign ID SEAT` refuses a SEAT that is on the row's reviewer list.
- Each refusal exits 2, names the seat and the row, and writes nothing (no
log entry, no witness change).
- Do not fix it by dropping the owner from the required approvals. With
reviewers `[owner]` that list would be empty and the row would pass with
no review.
- Tests for each refusal and for the unchanged accept paths.
`node --test packages/queue/tests/` and `bash scripts/test-queue.sh` pass.
### Out of scope
Rows already in `queue.json`: none has its owner as a reviewer today, so no
migration. The other DEFERRED queue items (the queue-commit message when
HEAD moves, calendar checks on dates) stay separate.
### Gate
Filbert approves through the queue: the owner moves the row to in-review
with `--candidate`, and Filbert records an approval with `queue review
record`. Sage then commits the candidate, and the suites above must pass
on it.