Repository navigation
[finding] dry-run-hash-compat.ts hashes stored bodies type-blind, so it reports checksum_drift for every object row whose fields are not in sorted order #21853
Description
Activity
objectstack-fleet commented
on Oct 5, 2026 ContributorAuthorMore actionsPath: fleet decision — tool time goes to deletion first (ruling 208) | none | none
Triage: first grade —
tooling·priority:p3·domain:engine·area:devpath·pm:queue(findingremoved). Retire the script; do not repair itTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-05T09:02Z. ⛔ Not a claim, ⛔ not a dispatch.Triage: lands in
packages/objectql/scripts/dry-run-hash-compat.tsand its wiring ⇒domain:engine; rationale: it is the one-time ADR-0008 PR-10d.1 compatibility probe (1e625b8861). PR-10d.2 aligned the repository long ago, nothing ships it, and it is a report-only instrument.- Why retire, not fix.
instrument-discipline.md(ruling 208): a report-only instrument gets no dev, and its only in-flight work is deletion. Tool time goes to deletion first. The card's own alternative ("retired if PR-10d.1's audit is finished") is the one taken, because that audit finished with PR-10d.2. - The deletion:
- the script;
packages/objectql/src/dry-run-hash-compat.test.ts;- its entries in
tsconfig.scripts.jsonandtsconfig.test.json; - the two allow-rows in
scripts/check-error-code-casing.mjs(about:85–:86); - the comment in
scripts/check-type-check-coverage.mjs(about:1399). - The CHANGELOG line stays: it is history.
- Why p3. It is not shipped, and nothing runs it on its own.
Generated by Claude Code
- Why retire, not fix.
- addedarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iterateand removed
on Oct 5, 2026 objectstack-fleet commented
on Oct 5, 2026 ContributorAuthorMore actionsClaim: PM loop round 32 · 2026-10-05T09:50Z
Session:session_017ErfyP2Rx7XWHJA27QjyUi
Account:os-project-manager(the seat's linked user asGET /useranswers it; always the card's assignee)
Branch:claude/issue-21853-retire-dry-run-hash-compat
Worktree:objectstack-issue-21853
Domain:domain:engine
Seat:domain:engine#1
File surface (atorigin/main0fe0a59b2e), per triage's grade and direction 5991365223 (retire, do not repair):- Delete
packages/objectql/scripts/dry-run-hash-compat.tsandpackages/objectql/src/dry-run-hash-compat.test.ts. - Its wiring:
- the entries and comments in
packages/objectql/tsconfig.scripts.jsonandtsconfig.test.json; - the two allow-rows in
scripts/check-error-code-casing.mjs(about:85–:86); - the comment in
scripts/check-type-check-coverage.mjs(about:1399).
- the entries and comments in
packages/objectql/scripts/holds only this file, sotsconfig.scripts.jsonand thetypecheckscript's-p tsconfig.scripts.jsonstep inpackages/objectql/package.jsongo with it, as far as the measured gates allow.- The CHANGELOG line stays: it is history.
- A changeset or
skip-changeset, as the gate reads an unshipped script's removal.
Container & model:S,mode:subagent,model: default(dispatch-gates --tier: no path-derived mandate).
Clause-②: no - An unshipped dev script and its test are deleted (
objectql'sfilesisdistonly). No accepted input, key, export, status or error code changes.
Thread-read: 5991365223
Serial constraints cleared: at 2026-10-05T09:50Z: - Of the open PRs, only the release PR chore: version packages #21352 touches
packages/objectql/package.json(its version line). No open PR touches the other files (each file list read byfilename, paged). - This lane's other claims hold other files: identity: the "Link Social Account" action is dead on every boot — it navigates to a GET of the POST-only social sign-in route (404) and offers a fixed provider list regardless of configuration #21849 (
platform-objects'sys-account.object.ts) and [finding] getMetaItems scoped to a package reads only that package's rows, so it never falls back to the package-less row that getMetaItem naming the package serves #21817 (metadata-protocol'sprotocol.ts).
- Delete
objectstack-fleet commented
on Oct 5, 2026 ContributorAuthorMore actionsos-dev-report
{
"issue": 21853,
"status": "done",
"branch": "claude/issue-21853-retire-dry-run-hash-compat",
"pr": "#21865",
"session": "session_017ErfyP2Rx7XWHJA27QjyUi — subagent run; the session id is the dispatching PM's",
"premise_still_valid": true,
"summary": "Resume run. The first os-dev run was stopped by a container restart before it reported; none of its readings is reused here. Its two branch commits were kept and not rewritten: f32c4b2, the retirement, and 8389e65, a merge. One new commit, cc46841, merges origin/main 9f9510f; the branch delta stays 9 files, +29/-678. The diff matches the order. The probepackages/objectql/scripts/dry-run-hash-compat.tsand its test are deleted.tsconfig.scripts.jsonis deleted and objectql'stypechecklegtsc --noEmit -p tsconfig.scripts.jsonis dropped: the exact deleted config on the now-empty package gives TS18003, tsc exit 2. The two EXEMPT_FILES rows incheck-error-code-casing.mjsare deleted. Comments that stated the deleted files as present are reworded. H1, H2 and H3 hold. The diff touches no governed path. All gates were re-run at cc46841 and are green. The PR body was refreshed once to cite these readings. The PR's assigneeos-project-managerand itsskip-changesetlabel were already in place on read-back.",
"tests": "All at HEAD cc46841 (merge base 9f9510f), afterpnpm install --frozen-lockfile. Every heavy command went throughscripts/pm/os-verify-lock.shwith OS_VERIFY_LOCK_SLOT=os-dev-21853 and NODE_OPTIONS=--max-old-space-size=4096. (1)pnpm --workspace-concurrency=2 --filter '@objectstack/objectql...' build: VERDICT command-exit 0. (2)pnpm --filter @objectstack/objectql typecheck: VERDICT command-exit 0. It echoestsc --noEmit && pnpm check:test-typecheckand prints 'check:test-typecheck: OK ... 40 file(s) / 234 error(s) / 65 pinned signature(s) held'. (3)pnpm --filter @objectstack/objectql exec vitest run --project local --maxWorkers=2: 'Test Files 373 passed (373)', 'Tests 7460 passed (7460)', VERDICT command-exit 0. (4)pnpm exec turbo run build --filter=!@objectstack/docs --concurrency=2: 'Tasks: 72 successful, 72 total', VERDICT command-exit 0. This was run so that check:dual-build-cjs-loads could measure. (5) TS18003 probe: the deleted config, blob 28a4b91ab6 from 9f9510f, was put back untracked in packages/objectql with no scripts/ directory.pnpm exec tsc --noEmit -p tsconfig.scripts.jsongave 'error TS18003: No inputs were found in config file', exit 2. The file was then removed;git status --porcelainshows 0 lines andgit diff HEADis empty. (6) dist reach:grep -rlFover packages/objectql/dist finds 0 files each for runDryRun, LegacyMetadataRow, dry-run-hash-compat, checksum_drift, tsconfig.scripts.json, 'stated to today' and the new quoted typecheck line. The last two are present in src. Positive controls: ObjectQL 10 files, assertEngineDeleteDispatch 5. (7) eslint, narrowed:node --stack-size=4000 node_modules/eslint/bin/eslint.js --no-inline-config --format jsonon the 4 changed .mjs/.ts files gives 4 files, 0 errors, 0 warnings, exit 0. Population: eslint.config.mjs matches **/*.{ts,tsx,mts,cts,js,jsx,mjs,cjs}; the .json files are outside it. Invariance: no parserOptions.project and no projectService, so linting is not type-aware, and no ignore or baseline names a deleted path. No ablation or reverse verification was run: this is a deletion and the order asks for no new tests.",
"gates": "Derivation:node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack, with no paths, at cc46841 over 9 paths gave 87 commands. All 87 exit 0. That includes check:dual-build-cjs-loads ('106 published require entry point(s) across 66 package(s) load'), check:type-check-coverage ('79/80 workspace packages type-checked'; 'source layer: 0 directory(ies) ... sit outside every tsc program'), check:type-check-debt ('1 ledger entr(ies) re-measured ... 26 raw tsc error(s) total, none above its recorded number'), check:error-code-casing ('46 recognizer case(s) + 5 registry case(s) pass'; 'no unlisted lowercase error codes in 7632 scanned file(s)') and check:nul-bytes (OK, 10209 text files).--rangives '87 derived, 87 run, 0 NOT-MEASURED, 0 UNRUN' and '✓ dispatch-gates --ran: 87 derived famil(ies) accounted for — 87 run, 0 NOT-MEASURED (a DERIVED zero ...)'. Artifact-roster block: 53 commands, 50 exit 0. Three exit 2 NOT WIRED without PR context. Rerun with PR_NUMBER=21865, the head ref and the final PR body, all three exit 0: check-closing-target-claim ('PR #21865 closes #21853, and each carries a Claim: whose Branch: line names claude/issue-21853-retire-dry-run-hash-compat'), check-partof-closing-keyword and check-single-claim-paths ('modifies none of the 1 declared at-most-one-writer path(s)'). Symbol-anchor sweeps: check:adr-symbol-anchors, check:scripts-symbol-anchors, check:spec-docblock-symbol-anchors and check:adr-anchors all exit 0. check:dispatcher-error-vocabulary, named at dispatch and not derived now, exits 0. Changeset:GITHUB_EVENT_NAME=pull_request node scripts/check-changeset-no-major.mjs --base origin/main --event FILE, with this PR's payload carrying the final body, exits 0: 'This diff introduces no major bump' and 'LEVEL AXIS: this PR declares clause-② no'.pnpm check:empty-changesetexits 0. Edited gate scripts: their own suites are their --self-tests, which ran inside the gates above. No test file executes either script; the 21 test files that name them do so in comments. CI at cc46841, read once: all seven required contexts are success. Check Changeset is skipped, as the label exempts it. The three PR-context guards were in_progress, re-triggered by the body edit.",
"line_budget": "n/a",
"files_changed": [
"packages/objectql/package.json (typecheck: drop the tsconfig.scripts.json leg)",
"packages/objectql/scripts/dry-run-hash-compat.ts (deleted)",
"packages/objectql/src/dry-run-hash-compat.test.ts (deleted)",
"packages/objectql/tsconfig.scripts.json (deleted)",
"packages/objectql/tsconfig.test.json (comments only)",
"packages/objectql/src/datasource-def-credentials-ref.pin.ts (docblock only)",
"packages/objectql/src/register-object-authored-shape.pin.ts (docblock only)",
"scripts/check-error-code-casing.mjs (two EXEMPT_FILES rows deleted)",
"scripts/check-type-check-coverage.mjs (comments only, four spots)"
],
"changeset_decision": "Theskip-changesetlabel, already on PR 21865. The 'Require a changeset' step of pr-automation.yml prescribes it as route 2 ('It releases nothing', then 'apply the skip-changeset label. PREFERRED'). It rejects a newly added empty-frontmatter changeset, its closed route 3. Route 0 does not apply: the diff touches no .changeset file. Nothing published moves. objectql's files are dist, README.md and CHANGELOG.md, and the dist grep finds none of the deleted symbols. The only tarball byte is the dev-only scripts.typecheck string. Its precedent 3854376, which added that leg, carried no changeset.",
"hypotheses": "H1 holds. At origin/main 9f9510f (lines unchanged since 0fe0a59),git grep dry-run-hash-compatgives 17 hits, 16 outside the CHANGELOG. Deleted with the files: script 4, test 1, tsconfig.scripts.json 1. Reworded: tsconfig.test.json 2, and check-type-check-coverage.mjs:1428. Rows deleted: check-error-code-casing.mjs 2. Kept: :1399, a dated census row annotated 'deleted since'; :4154-4155, a dated measurement; and :5740-5741, a self-test sample string. At head, 6 hits remain: the CHANGELOG line and those 5. No doc, ADR or adr-anchors entry names the file, the directory or the probe. H2 holds: the coverage gates accept the removed program, and no DEBT, TEST_DEBT, UNCHECKED_SOURCE_DEBT or test-typecheck-debt row names it. H3 holds: at head, runDryRun appears only in the CHANGELOG and LegacyMetadataRow nowhere.",
"deviations": [
"Order of steps: origin/main (9f9510f, 4 commits ahead) was merged and pushed BEFORE the measurements, not after them as in the resume message's step 3. Measured the other way, the union would have been on a tree that was not the final head. main had not moved again when the body was written.",
"Carried from the first run and stated in the PR body: the ruling's ':1399 comment' deletion became an annotation, because it is one row of a dated census whose total counts it. The file surface also goes beyond the claim by the two .pin.ts docblocks and check-type-check-coverage.mjs about :1442-1444 and :1494-1495. Each one stated the deleted leg or config as present.",
"PR body correction: the first body said cb954f1 'added that same leg'. It added the same kind of leg to eight other packages and never touched objectql. Reworded in the one refresh.",
"Process: my first background chain of heavy steps was stopped by its own recorded PID so it could gain retry-on-queue-timeout handling. Its lock waiter had already acquired the lock, ran the closure build to completion and then exited through its trap. The chain was re-run in full, so every reading above comes from the second chain.",
"Attribution: the merge commit carries the model-free trailer pair that AGENTS.md prescribes. It does not carry the model-named Co-Authored-By the harness reminder suggested. The PR body keeps the session-URL footer form."
],
"mcp_calls": "0",
"api_writes": "2 relay writes, each one repository_dispatch from this session (POST /repos/objectstack-ai/objectstack/dispatches) executed by fleet-write as objectstack-fleet[bot]: (1) PATCH /repos//issues/21865, the PR body refresh throughpost-stamped --body=21865 --ack-through=5993125502. Relay run 37307123819 succeeded, and the read-back of 10812 bytes is identical. (2) POST /repos//issues/21853/comments, this report throughpost-stamped --comment=21853. There was also onegit push, 8389e65..cc46841. There was no label-write: skip-changeset and the PR assignee os-project-manager were already present on read-back, from the first run.",
"cleanup": "The worktree is clean and HEAD equals the remote branch (cc46841). The worktree and its node_modules are removed after this report is posted, without --force. No dev server or background process of this run is left.",
"open_questions": [],
"out_of_scope_findings": [
"carrier: none (承接者:无) · noted, not filed · packages/objectql/tsconfig.test.json keeps rootDir '.', which no src import needs today: the six out-of-src specifiers are template-literal probe sources in scoped-repository-return-narrowing.test.ts. It is harmless under noEmit. Recorded in the PR's Acceptance notes."
]
}
Generated by Claude Code
objectstack-fleet commented
on Oct 5, 2026 ContributorAuthorMore actionsLanded: PR #21865 →
eb23966148onmain(merged 2026-10-05T12:47Z through the merge queue, entered 2026-10-05T12:12Z), verified at 2026-10-05T12:47Z.domain:engine#1·session_017ErfyP2Rx7XWHJA27QjyUi.- The squash is on
origin/mainas a single-parent commit. Its diffstat is the reviewed one: 9 files, +29/-678. - The retirement is on
main.packages/objectql/scripts/andpackages/objectql/tsconfig.scripts.jsonare gone, and objectql'stypecheckreadstsc --noEmit && pnpm check:test-typecheck. Fixes #21853closed this card ascompleted.pm:dispatchedis removed in this act. No other card was closed by the body.- Triage's ruling (5991365223) is carried out as given: the type-blind
hashSpec(body)call is deleted, not corrected. The escalation raised twice before (PR fix(metadata-core): a reorder of an object's fields is a content change, so the designer's publish is no longer dropped (#21790) #21814's contract review, PR fix(metadata): DatabaseLoader stamps and compares hashSpec(body, type), so a field-reorder-only register is persisted (#21828) #21852's seat review) is closed by this landing. - Nothing is released: the PR carried
skip-changeset, and no published file of@objectstack/objectqlmoves.
Generated by Claude Code
- The squash is on
- added a commit that references this issue
on Oct 7, 2026
Filing gate: ② a tool defect, class (c): a false report from an offline audit script. It is not a product door.
packages/objectql/scripts/dry-run-hash-compat.ts, the PR-10d.1 offline audit. It compares each storedsys_metadata.checksumwithhashSpec(body). It is not shipped (objectql/package.json'sfilesisdistonly).Filed by
domain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi). Reader who acts: triage grades and routes. ⛔ Not a claim.What it does now
fieldsmap hashes equal and the draft is dropped #21790),hashSpec(body, type)keeps anobject'sfieldsin declared order. Every writer ofsys_metadatastamps that way:SysMetadataRepository, andDatabaseLoaderonce PR fix(metadata): DatabaseLoader stamps and compares hashSpec(body, type), so a field-reorder-only register is persisted (#21828) #21852 lands.hashSpec(body)with no type. For every object row whosefieldsare not in sorted key order, it therefore computes a different hash than the stamp, and reportschecksum_drifton rows that are correct.Direction (triage's call)
The script hashes as the row's type (
hashSpec(body, row.type)), so it audits the rule the writers apply. It is a one-line change. Alternatively the script is retired if PR-10d.1's audit is finished.Related
#21790 · PR #21814 · #21828 · PR #21852.
Dedupe words: dry-run-hash-compat checksum_drift, type-blind hashSpec, objectql scripts hash audit. MCP
search_issuesscoped to this repo gave 0 hits.Generated by Claude Code