Repository navigation
docs(spec): re-anchor the dead tracker citations in packages/spec/src's test surface to the commits that decided them - #21700
Conversation
…'s test surface to the commits that decided them The test-surface stage of the dead-citation sweep. Every comment and docblock site in packages/spec/src/**/*.test.ts that cited a tracker number answering 404 now cites the commit on main that decided it (ruling C+D form C), reusing the anchor an earlier stage landed for the same number wherever one exists. Two census-dead sites are objectui numbers split from their qualifier; they are respelled so the qualifier joins the number. The two source comments tests read literally move with their readers: data/api-derivation.ts's marker now opens with the deciding commit 6968885 (read by data/api-derivation.test.ts), and identity/identity.zod.ts now opens its explanatory block with commit 2c86fe3 (read by identity/api-key-retirement.test.ts). Comment and docblock text only, plus those two readers. No test title, schema, type, export or behaviour change. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
…pped comments src/identity/identity.zod.ts ships verbatim through files[] (src/**/*.zod.ts), and the api-derivation.ts docblock is emitted with its declaration, so the rewritten text publishes. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift Check
What this run could not see
Coarse fallback — 138 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): |
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 37186683796 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
|
Queue build
GitHub rebuilt this PR's merge group on |
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 37187916146 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
… instead of a tracker number (stage 10) (objectstack-ai#21713) Part of objectstack-ai#20749 Clause-②: no Stage 10 of this card, and the first area of class (e): the test strings shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513. This stage takes the whole `automation/` directory. Its 105 test-title and test-message literals carried 110 tracker ids citing 55 records. Each id now either states what its record decided, in words (form D), or is dropped where the title already says it. Text only: no assertion, fixture value, test count or code comment changes. ## Census at the base (`7e0066af7a`, the claim's base) Instrument: stage 9's `census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`, byte-identical), plus one added classification pass. A literal counts as a test title when its folded message is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` / `.only` chains included. Everything else is an "other" string. Reference: the same instrument reads **1803 messages / 1919 ids in 425 files at `9b8c7f38d7`**, stage 9's reading exactly. Since then, objectstack-ai#21699 added 1 / 1 (`ui/component-props-unknown-members.pin.test.ts:143`) and objectstack-ai#21700 moved 3 / 3 (the two reader literals it re-anchored), which gives 1801 / 1917 at the base. | directory | files | titles msg / ids | other msg / ids | total msg / ids | excluded files | |:--|--:|--:|--:|--:|:--| | `data/` | 95 | 445 / 475 | 23 / 26 | 468 / 501 | | | `ui/` | 81 | 374 / 397 | 18 / 18 | 392 / 415 | `report.test.ts` 3 / 3 | | `api/` | 40 | 181 / 193 | 8 / 8 | 189 / 201 | | | `system/` | 34 | 128 / 138 | 26 / 27 | 154 / 165 | `job.test.ts` 4 / 4 | | (files directly in `src/`) | 30 | 117 / 119 | 1 / 1 | 118 / 120 | | | **`automation/`** (this PR) | 21 | 101 / 106 | 4 / 4 | **105 / 110** | | | `kernel/` | 36 | 92 / 96 | 10 / 10 | 102 / 106 | | | `shared/` | 21 | 73 / 81 | 12 / 14 | 85 / 95 | | | `contracts/` | 25 | 59 / 70 | 4 / 4 | 63 / 74 | | | `conversions/` | 9 | 34 / 34 | 0 | 34 / 34 | | | `security/` | 8 | 28 / 28 | 0 | 28 / 28 | | | `ai/` | 9 | 13 / 15 | 5 / 5 | 18 / 20 | | | `identity/` | 6 | 14 / 14 | 1 / 1 | 15 / 15 | | | `integration/` | 4 | 13 / 13 | 1 / 1 | 14 / 14 | | | `migrations/` | 2 | 9 / 12 | 0 | 9 / 12 | | | `marketplace/`, `meta-spelling/`, `studio/` | 5 | 7 / 7 | 0 | 7 / 7 | | | **total** | **426** | **1688 / 1798** | **113 / 119** | **1801 / 1917** | 7 / 7 | - **Excluded, in flight under this seat:** `system/job.test.ts` carries objectstack-ai#16292 (`:92`), objectstack-ai#14478 (`:471`), objectstack-ai#4667 (`:836`) and objectstack-ai#19184 (`:881`), and `ui/report.test.ts` carries objectstack-ai#20161 (`:233`), objectstack-ai#3916 (`:334`) and objectstack-ai#5013 (`:426`). All seven sit in titles. They wait for a later stage, after objectstack-ai#21703 and objectstack-ai#21702. - **Controls.** Lit, single line: `automation/approval.test.ts:135` reads one title with objectstack-ai#3508. Lit, multi-line: `api/discovery-environment-subset.pin.test.ts:63-66`, a `+` chain, reads as ONE message with its id on `:65`. Dark: the `// objectstack-ai#3508` comment at `automation/approval.test.ts:131` reads 0. Planted in a scratch copy of the head file: an id in a title reads 1 / 1, and an id in a comment reads 0. - **A wider pattern** (any `#` plus digits, so two-digit and six-digit numbers too) reads the same 105 / 110 in `automation/` at the base, and 0 / 0 at the head. - **At the head:** 1696 messages / 1807 ids in 405 files. `automation/` reads 0 / 0. Nothing else moved. ## How the area was chosen The directories are ranked by id count, and a stage takes whole directories up to about 100 ids. The four busiest each exceed that bound alone: `data/` (501), `ui/` (415), `api/` (201) and `system/` (165). The files directly in `src/` (120) are 20% over. `automation/` (110) is the busiest whole directory within about 10% of the bound, so it is this stage. The rule picked it before any card was read. Its 55 records (53 in this repository, 2 in objectui) were all readable in one pass. 54 answer 200. objectstack-ai#6362 answers 404, and its decision was read from its landing commit `b5404f496`. **Named for the next stages** (by directory, from the table): `data/` (about five stages, by subdirectory or file group; `data/driver/` alone is 52), `ui/` (about four), `api/` (two), `system/` (two), the files directly in `src/` (one), `kernel/` (one), `shared/` (one), `contracts/` with `conversions/` (one, 108), and `security/`, `ai/`, `identity/`, `integration/`, `migrations/`, `marketplace/`, `meta-spelling/` and `studio/` together (one, 96). The seven excluded ids join `system/` and `ui/` once their owners land. ## What each id became 38 literals (40 ids) now state a decision in words. 67 literals (70 ids) drop a citation the title already explains. Each record was read with its comments through REST, and where a record has no comments, from what landed. | record | ids | result | |:--|--:|:--| | objectstack-ai#3508 | 2 | `APPROVER_VALUE_BINDINGS`: "an approver value is picked from the records the engine resolves". `APPROVER_VALUE_SOURCES` (the follow-up): "where each picker finds its candidates, published on the wire". | | objectui#2955 | 1 | "for the decision dialog to render and enforce": both decision entry points collect the typed outputs, and `required` is enforced. | | objectstack-ai#3810 | 1 | "names the match-everything-write hazard": a filter emptied by interpolation matches every row, and the node is refused instead. The test pins the words `match-everything write`. | | objectstack-ai#4001 | 13 | "strict as of objectstack-ai#4001 批 9" becomes "an unknown key is refused, not stripped" (5 titles). Also "refused, not stripped", "an unknown key is refused, per shape" and "the unknown-key gate". Dropped from 5 titles that already read "unknown keys are rejected, not stripped". | | objectui#2670 | 1 | "so the flow designer renders it as a template": the designer's loop and region rendering reads this marker. | | objectstack-ai#4396 | 2 | "a function that writes says so; pure is the default", and "the authoring surface where a function declares its effect" (landed `eb4204b`). | | objectstack-ai#4697 | 2 | `defaultValue`: "a declared variable is bound on every path" (ruling A). Dropped once. | | objectstack-ai#3896 | 3 | "outputSchema retired: declared, never validated" (the audit close-out's reason, as `flow.zod.ts`'s tombstone records it). Dropped twice. | | objectstack-ai#4247 | 1 | "maxRetries — one default, and no zero-attempt “retry”" (landed `a648e96`). | | objectstack-ai#16134, objectstack-ai#15713 | 7 | "a region node reusing a top-level id is refused — one node-id space now spans every region" (ruling, batch 61). Dropped from 5 titles that state uniqueness. | | objectstack-ai#9205 | 5 | "template reference — notify content localized through an email template" (the ruled emailTemplates route). Three titles say "the template path" where they said "pre-objectstack-ai#9205". Dropped once. | | objectstack-ai#7086 | 1 | "severity — the closed info \| warning \| critical vocabulary" (the enum route). | | objectstack-ai#4415 | 3 | "FlowNodeSchema parses its own regions" (ruling 2026-08-07, direction 1). Dropped from 2 titles that already say it. | | objectstack-ai#4347 | 1 | "collectFlowGraphs — every region is walked, not only the top level" (landed `31e0be9`). | | objectstack-ai#4401 | 2 | "FLOW_REGION_SLOTS, the one declaration of where regions live" (landed `4bfd455`). Dropped once. | | objectstack-ai#4414 | 1 | "`condition` is pointed at the out-edges, NOT given the one-edit rename" (one working routing model, landed `5293114`). | | objectstack-ai#15429 | 1 | "taking every true branch must be declared" (ruling item 2: explicit `inclusive`). | | objectstack-ai#14149 | 3 | "every entry older than the value role" (ruling A: a value-role CEL slot on `assignment`). Dropped twice. | | objectstack-ai#19938 | 4 | "the CRUD `fields.*` value slots added exactly two rows". Dropped three times. | | objectstack-ai#15572 | 3 | "predicateSlotRefusal — a predicate slot holds bare CEL text", and "the other two doors refuse it". Dropped once. | | objectstack-ai#15662 | 1 | "structuralConditionRefusal — a structural condition is CEL text or an expression". | | objectstack-ai#15792, objectstack-ai#15807 | 4 | "REFUSES an `ast`-only envelope — admitted at first, refused once an evaluated slot required a `source`". Dropped from 2 titles that state the rule. | | objectstack-ai#17493 | 3 | Table row "a blank string — blanks are refused" (ruling A). Dropped twice. | | objectstack-ai#14945 | 4 | "EndConfigSchema — the `end` node contract: it may refuse the run with a message" (ruling 2′). Dropped three times. | | objectstack-ai#15617 | 4 | "`failed` is the fold INCLUDING what a delegating node rolled up from its child — it answers what the run caused" (ruling option 1). Dropped three times. | | dropped only | 36 | objectstack-ai#3196, objectstack-ai#3266, objectstack-ai#4158, objectstack-ai#4277, objectstack-ai#4343 (2), objectstack-ai#4389, objectstack-ai#4525, objectstack-ai#4738, objectstack-ai#4964 (2), objectstack-ai#6758, objectstack-ai#7085, objectstack-ai#9106, objectstack-ai#12278, objectstack-ai#14964, objectstack-ai#15430, objectstack-ai#15646 (3), objectstack-ai#16752, objectstack-ai#17306, objectstack-ai#17852, objectstack-ai#18102, objectstack-ai#18112 (2), objectstack-ai#18847, objectstack-ai#19151, objectstack-ai#19961 (4), objectstack-ai#20316 (2): each title already states the pinned decision. For objectstack-ai#4988 and objectstack-ai#6414, the two expect messages already say what was retired. | | objectstack-ai#6362 (404) | 1 | Dropped. The title "PRESERVES all seven envelope keys — measured, not assumed" carries the decision recorded in `b5404f496` (`webhook` was measured, and all seven keys survive). | ## Readers - **Test-name filters:** none. A tracked-tree search for `-t` and `--testNamePattern` finds only `packages/qa/dogfood/README.md:142` (`-t "owner-scoped"`), which is unrelated. - **Snapshots:** none. `automation/` has no `__snapshots__` and no `toMatchSnapshot`. - **Titles by substring:** every old title, plus a window around each id (250 needles), was searched across the tracked tree outside its own file. No gate, doc or script matches one. The hits are other files' own titles with the same words: `identity/`, `security/` and `automation/` siblings, a later stage's lot. There are also two code comments in `flow.zod.ts` and `flow-function.zod.ts`, which belong to the comment lane. - **Twin tables, not readers:** `packages/lint/src/validate-expressions.test.ts:4442/4445` and `packages/services/service-automation/src/decision-branch-expression-absent.test.ts:61/64` repeat the `flow-decision-branch-expression-absent` table's row names. Nothing compares them mechanically: the "same table" parity is prose in the headers, and it covers assertions, not names. They are outside this stage's surface (see Acceptance notes). ## Text-only proof A scratch tool (`textonly10.cjs`) compares base and head file by file on three legs: 1. **Skeleton:** the full AST, with string pieces masked. It must be identical. 2. **Comments:** every comment, byte-equal. 3. **Strings:** each string leaf that changed must sit in a test-call title position, or on one of the 4 declared lines (`flow-decision-branch-expression-absent.test.ts:63` and `:66`, table `name` values that feed `$name` titles; `sync-retirement.test.ts:120` and `:158`, expect messages). It must carry a tracker id before and no `#` plus digits after. - **Result:** 21 of 21 files SAME, 105 changed (101 title, 4 declared), on all three legs. - **Diff hunks:** exactly the 105 planned lines, with every file keeping its line count. - **Controls (10 of 10 as predicted, on scratch copies, each anchor hit once):** identifier rename DIFF; numeric literal DIFF; comment edit COMMENT DIFF; a non-title string with an id VIOLATION; a rewritten title given a new id VIOLATION; a title that was id-free at base edited VIOLATION; one title reverted to base SAME (104 changed); a declared string keeping an id VIOLATION; an undeclared expect message changed VIOLATION; a title re-split into a `+` chain DIFF. **Test counts:** the 21 files run at the base (in a separate base worktree) and at the head: 801 / 801 tests on both sides, with the same count and status sequence per file in 21 of 21. 560 full test names change, and each equals the base name with the planned replacements applied. ## Changeset: `skip-changeset` Measured, not assumed: - `npm pack --dry-run` of `@objectstack/spec` lists 2068 files, under `files[]` (`dist`, `src/**/*.zod.ts` and the rest). 0 of the 21 touched files are in it, and 0 `*.test.ts` at all. The control `src/automation/flow.zod.ts` is in it. - In `dist/`, three new phrases and three old ones each read in 0 files. The control `A predicate slot holds BARE CEL TEXT` reads in 2. So this PR publishes nothing, and no changeset is added. ## Verification (at `f3dc3fab03`) - `pnpm turbo run build` over all packages: 71 / 71. - `@objectstack/spec`: `vitest run --project local`, 612 files and 18185 passed, 1 todo. `typecheck` exit 0, including `check:test-typecheck`, whose program holds all 21 touched files. - **Gates:** `dispatch-gates --commands` derived 79 families, and all 79 exit 0. `--ran` reconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN. - **ESLint, a proven narrowing:** `--no-inline-config` over the 21 files, 0 errors and 0 warnings. The population comes from ESLint's own config: 21 configured, 0 ignored. No `parserOptions.project` or `projectService`, so no untouched file's verdict can move. - `check-governed-merges --test`: NOT governed, 210 changed lines. ## Acceptance notes - **Twin row names in other packages:** the lint and service-automation copies of the decision-branch table keep their `the objectstack-ai#19961 shape` and `the objectstack-ai#17493 control` row names, and their twin `describe` titles keep their ids. The lint copy is this card's own later share (the `packages/lint` test strings). The service-automation copy belongs to that package's lane. - **Code comments still carry ids** in these 21 files (for example `approval.test.ts:56`, `:69` and `:131`). They are the comment lane's, untouched here. - **`origin/main` moved** three commits past the base before this PR opened (objectstack-ai#21701, objectstack-ai#21707, objectstack-ai#21706). None touches `packages/spec`, so nothing was merged. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
… carries as the published spec (objectstack-ai#21709) (objectstack-ai#21717) Fixes objectstack-ai#21709 Clause-②: no ## What changes The `Console Pin Gate`'s probes no longer treat text that objectui's own source carries as evidence of either spec. A console bundle carries text from objectui's code as well as from the specs. objectui's component registry writes `inputs` descriptions that copy spec `.describe()` text, either verbatim or as a prefix it then extends. When the spec rewords one of those, the old text becomes published-only. objectui's literal still carries it, so a substring search found "the published spec" in a bundle built from this tree's spec. That is what has turned every merge-queue build red since objectstack-ai#21699 (`16d241a6af`): the object-gantt `markers` describe and objectui's `packages/plugin-gantt/src/index.tsx:190`. - `scripts/console-spec-probes.mjs`: `readHostSourceBlob(dir)` reads objectui's tracked code files at the pin (`git ls-files`; test files excluded; a quote's backslash normalised). `chooseProbes` now takes that blob as `hostBlob`, required. It is a TypeError without it. - **The rule (both legs):** a candidate that is in the bundle **and** carried by objectui's source is not evidence. It is counted (`counts.hostCarried`), never decides a verdict, and is never returned as a probe, so it is never stamped. A candidate **absent** from the bundle is still evidence, whoever else carries it. The rule excuses presence, never absence. - **One new refusal:** if every published-only candidate is in the bundle and objectui carries every one, the stale leg has no probe left. That is neither "no skew" nor "absent", so the assert exits **2** (inconclusive). The old code answered that same state exit 1, with a false accusation. It never passed. - `scripts/assert-console-spec-injection.mjs`: a new required `--objectui` flag (objectui's build tree, the git checkout at the pin). Its messages report host-carried text separately, so a pass no longer prints "all N published-only descriptions are absent" when one of them is in the bundle. - `scripts/build-console.sh` (**declared, and strictly needed by the route**): the single assert call site passes `--objectui "$BUILD_ROOT"`, the tree it just built. The only other way to find that tree is to reach two levels up from `--vendored`, which couples the assert to a path layout. A required flag means a forgotten call site fails loudly (exit 2). - `scripts/check-console-injection.mjs`: the replay logic is unchanged. It needs no objectui tree, because the build never stamps a host-carried probe. Its self-test gains battery 14, and batteries 12 and 13 now pass `--objectui`. - **Same-class fix on the fresh leg, declared:** the same rule applies to the injected-only witness. A witness that objectui writes itself is no proof of the injection. Before this change, a bundle that held objectui's literal and **no spec at all** passed; now it reads "neither spec appears" (exit 2). The four bounded-fix conditions all hold: same defect class, same function, a file nobody else has claimed, and the same gate family. It is pinned in battery 14. - The stamp shape is unchanged (`stampVersion` 1). The stamp now records the **filtered** choice, so a cache-hit replay agrees with the build. ## Reproduction (base `7e0066af7a`, the head of queue run `37187916146`) - **CI:** queue run `37187916146`, job `111393796807` ("Build the Console SPA at the pinned objectui SHA"). Its triage comment on objectstack-ai#21700 quotes `✗ Built console still carries the PUBLISHED @objectstack/spec.` I could not read the raw job log from this container: the log blob host answered 403. So the per-candidate figure comes from the local build below, at the same commit. - **Local, the real door:** `scripts/build-console.sh` at `7e0066af7a`, run under `os-verify-lock.sh`. It used objectui `ab1879721595`, and the vendored `@objectstack/spec` resolved to **17.6.0**. Lock held 559s. Result: exit 1, `(1 of 38 published-only descriptions), the first of them: "Extra vertical reference lines drawn like the Today marker ({ date, label?, color? })"`. - **Measured, not assumed:** over that real bundle (33.3 MB of JS), the published-only candidates present are exactly **1 of 38**, and it is the `markers` text. objectui's tracked non-test source carries it. The injected-only candidates present are 26 of 26, and none of those is host-carried. ## Route: (a), by measurement - **(b), whole-literal matching, would fix today's collision.** The `markers` text is not a whole literal in the real bundle. - **It leaves half the family open.** In the real bundle, **9** spec describes are whole literals inside objectui's own chunks, for example "Action IDs available for related records" in the `plugin-grid` chunk. Rewording any of those 9 would recreate this red under (b). - **At the pin, over the module's own file filter**, objectui's non-test code holds 18 literals equal to a spec describe and 18 more that begin with one. - **(a) covers both shapes.** It drops only text whose presence could not have been evidence anyway, and only when that text is in the bundle. - **Leak detectability (pin 2 on the real bundle):** I added the published 17.6.0 JS as a chunk to the real assets. The head assert exits 1 on `37 of 38`, detector "Actions to execute during transition". Replaying the good build's stamp beside those assets also exits 1. - **Cost:** the host blob is 32.3 MB and reads in about 0.3 s. ## Pins (battery 14, `node scripts/check-console-injection.mjs --self-test`) Base: 44 assertions. Head: 67. Every fixture runs the real assert script and replays its stamp through `evaluate()`. The mirrored texts sort **first**, so an unfiltered pick would choose them. 1. **Pin 1 passes:** the injected spec plus an objectui literal that begins with a published-only describe, plus a second literal equal to one (which exercises the quote-backslash normalisation). The stamp records `staleDetector` = a text objectui does not write. The replay passes. 2. **Pin 2 still fails:** a bundle carrying the published spec's own JS fails with exit 1 and names a detector objectui does not write. No stamp is written. objectui's **test** file quotes that detector, so this case also pins that tests are not read as source. 3. **Pin 3, the replay agrees:** the replay matches the assert on both bundles: 0 on bundle 1, and 1 ("carries the PUBLISHED") on bundle 2 with the good stamp beside it. Battery 14 also covers: - the all-host-carried stale leg (exit 2, "cannot judge"); - host-carried text absent from the bundle, which stays a valid detector (exit 0, stamped, replay 0); - the fresh-leg case (exit 2); - an objectui tree git cannot list (exit 2); - `chooseProbes` without `hostBlob` (TypeError). **Ablation.** Predicted first and saved, then run through `scripts/ablation-replace.mjs` in wrap mode. The mutation was `const hostCarried = new Set();`. On disk the anchor went 1 to 0 and the marker 0 to 1. The restore was proven: blob `903c3e80cce1` equals HEAD, and `git diff HEAD` is empty. - **Self-test:** exit 1, with **13 failures, exactly the predicted list**, all in battery 14 (pin 1 ×6, pin 2 detector wording ×2, pin 3 bundle-2 wording ×1, all-host-carried ×2, fresh leg ×2). No other battery failed. - **Pin 2's exit 1 held with and without the fix.** - **Synthetic bundles under ablation:** exit 1 `1 of 38` with the `markers` detector, and exit 1 `38 of 38`. - **Real bundle under ablation:** exit 1 `1 of 38` with the `markers` detector, and exit 1 `38 of 38` with the published chunk added. ## The real door on this head - **End to end:** `scripts/build-console.sh` on `93ea8e7d80` reused the built objectui tree, rebuilt the console at the pin, and ran the fixed assert. Exit **0**, with `37 of 38 published-only descriptions are absent; 1 ... ARE in the bundle, and objectui's own source at the pin carries each of them too`. Lock held 278s. The next CI steps then ran on that dist: `pnpm check:console-sha` exited 0, and `pnpm check:console-injection --require-stamp` exited 0 (self-test 67, replay passed). - **That build was before the last commit.** `93ea8e7d80` differs from the final head `0bcf6a0a95` only in a self-test fixture line in `check-console-injection.mjs`, and that self-test was re-run on `0bcf6a0a95`. - **PR side:** all four changed paths are in `ci.yml`'s `console` filter, so `Console Pin Gate` runs on this PR. Three of them (`build-console.sh`, the assert, the probes module) are in the dist cache key, so the key moves and the cache misses. The PR head therefore gets a full console build at the pin with this assert, and that is the CI reading of the real door. - **Queue:** once this merges, every queue build's `Console Pin Gate` runs this assert. `release.yml`'s key hashes `build-console.sh`, so its next run rebuilds through the new call site too. ## Gates (on `0bcf6a0a95`) - `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` derived 32 commands. All 32 exited 0. - `--ran` reconciliation: 32 derived, 32 run, 0 NOT MEASURED, 0 unrun, every one with a recorded exit code. That includes `pnpm check:console-injection`, `check:console-sha`, `check:ci-filter-parity` (+ self-test), `check:nul-bytes`, `check:entry-guard` and `check:pm-dispatch-gates` (1976 cases, run detached). - **eslint, narrowed:** `eslint.config.mjs` lints all three changed `.mjs` files, so none is ignored. `--format json` reported 3 files, 0 errors and 0 warnings. The config has no type-aware linting, so this diff cannot move any untouched file's verdict. `build-console.sh` is outside eslint's population. The full `pnpm lint` is left to CI. ## Changeset `skip-changeset`: nothing published changes. The diff is root `scripts/` only, and the root package is private and ships no `files`. I built the console dist (the one published package this build feeds) and grepped it: `readHostSourceBlob` / `hostCarried` have 0 hits, while the positive control, the `markers` literal, is found in 3 files. ## Acceptance notes - **Dead branch, not touched:** the assert's "published spec is gone, but nothing unique ... was found" branch is unreachable, both before and after this change. The "neither" branch and the stale exit cover every way into it. Carrier: none. - **Parity tests stay evidence:** objectui's `apps/console/src/__tests__/registry-inputs-spec-parity.test.ts` quotes 2 of the 38 published-only describes. Tests are excluded from the host source, so in a real leak those two still count as evidence. - **Same-tree pin:** the reproduction and the real-door runs used the same tree as the failing queue run, `7e0066af7a` (its `head_sha`). `origin/main` has since moved by four commits, and none of them touches this gate's inputs. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Part of #20234
Clause-②: no
What this stage does
The citation gate's census defers
packages/**/*.test.ts, so the dead tracker numbers inpackages/spec/src's test files were never in its count. This stage measured that surface and re-anchored every dead site in its comment and docblock text, in ruling C+D form C (triage5856637615): each line now cites the commit onmainthat decided what it describes, and says the decision in words. Wherever an earlier stage of this card, or a sibling lane, already landed an anchor for the same number, this stage reuses it.It also takes the two source comments that tests read literally, and moves each reader onto the new text:
src/data/api-derivation.ts:163: the[#6259]marker onDATA_ACTION_TO_API_OPERATIONbecomes[commit 6968885ef]and the sentence says what that commit did (it removed the producer-lessbatch: 'bulk'row and stopped the description callingbatcha runtime action). Its reader,src/data/api-derivation.test.ts:236, splits on the new marker.src/identity/identity.zod.ts:230:(#8715,becomes(commit 2c86fe3ea,; the maintainer-ruled DELETE and its date stay. Its reader,src/identity/api-key-retirement.test.ts:118, asserts the new opening phrase.packages/runtime/src/api-exposure.test.ts:152) readspackages/runtime/src/api-exposure.ts, not the spec file, so it is not a reader of this text and is untouched.Comment and docblock text only, plus those two readers. No test title, schema, type, export or behaviour change.
Census (base
7d0781482d, head0e92e882f4)Instrument: the gate's own
extractCitations(comment-prose projection) andnamesThisRepositoryover all 596packages/spec/src/**/*.test.tsfiles (no.test.tsx,.spec.tsor__tests__/files exist there), with string literals read through the sharedscanSourceliteral projection. Every distinct in-repo number was probed with RESTissues/N, redirects not followed, with lit controls #16862 #16847 #17698 and dead controls #16714 #16715 #16697 at the start, every 100 numbers and the end.87 is under the stage's 120-site bound, so this stage takes all of it. By area: package root 36,
shared/10,system/9,data/8,api/5,automation/5,integration/5,conversions/4,security/3,identity/2. The excluded files (migrations/**;automation/flow-slot-refusal-codes.test.ts;automation/flow-write-node-stored-metadata-target.test.ts) carry 0 dead sites, so the exclusions removed nothing.The three literal sites that left are exactly the two readers' literals. Every test title is untouched. No in-repo comment citation was added at head. The one live number that left the in-repo count is #6110, which now carries its
objectui#qualifier (below). A raw#Nscan of the comment projection agrees with the gate's extractor: its only extra hits are threeobjectui #11166sites that are objectui's.The gate's own census (
check-issue-citations.mjs --census --json, board enumerated, 196 pages, frontier #21684) reads 0 findings inpackages/spec/srcat head. The gate's extractor read 2 at base (api-derivation.ts:163#6259,identity.zod.ts:230#8715).Dead numbers left in string literals (not touched; #20749's class (e))
68 numbers at 147 sites, all test titles.
data/40,api/33,ui/21,kernel/18,contracts/10,shared/6,system/6,integration/5,(root)3,identity/3,conversions/2,automation/1. One of them is not a tracker number at all:#0000inshared/retired-key*.test.tsis a fixture placeholder.Anchors
18189983d7f713b662(the squash commit of PR #6072, ADR-0122 phase 1)53068c130(ADR-0122 phase 2)026101660(added this very pin file)f549a0d4a(the sweep commit, cited on the sweep's header line)6968885efe2798fab7(its diff wrote all five lines)b5404f496259459d8b(the squash commit of PR #6527)d127ff002c6b05c76a(wrote the prose-count check)42b05af892c86fe3ea24206416ad491625c12a29caa532306a765c35ad101bcd173125fbcccbe51bf735f5c709(the runtime and service-datasource lanes' anchor)e58ea8b38(stage 6's anchor for the same phrase)311433f6baa5994e17901355c3b9e0ba21a1fd289be45(the sibling files' spelling, "commit fd289be's strip")c45d8e6b4c5a9a437d(the squash commit of PR #14240, whose body names #14162 as the card it lands; it is the load path that judges eachpackages[]entry withArtifactPackageEntrySchema)c5a7448d5(its message names #14419 as the card it lands)35dffeace13c48c2a5279431e7ab3a63d32c23c72be3c(stage 1's "refuted in commit 23c72be")ecdfc941129dd1a6dd(it wrote this very pin line)86c505286(the service-analytics and core lanes' anchor)Every anchor is unique at nine hex digits, single-parent, and an ancestor of
main. That was read from a full, not shallow, treeless clone ofmainat the base. For 40 of the 49 (number, anchor, file) pairs, the anchor's own diff wrote a line naming the number into that file. Where it did not, the anchor's message or its PR body names the number.Two census-dead sites are not this repository's numbers. They are respelled so the gate reads their qualifier, following stage 5's precedent, and are not re-anchored. Both numbers answer 200 on objectui.
api/export-job-family-retirement.test.ts:24-25:objectui/PR #10264was split across a line break, so the census read dogfood: simulate a brand-new developer's first-run journey — README → create an app → skills-driven AI build → validate & test #10264 as bare. The line break now falls beforeobjectui PR #10264.shared/editability-boundary.test.ts:391-392:(objectui#6010 / #6110 / #6111)becomes(objectui#6010 / objectui#6110 / objectui#6111), the spellingui/view.zod.tsanddata/field.zod.tsalready use for the same pair.Proof that only text moved
maskComments, whitespace collapsed) run over all 36 files, base vs head. 34 files are IDENTICAL on both instruments. The other two differ only in the declared reader literals:api-derivation.test.tsin 2 string tokens ('[#6259]'and its assertion message), andapi-key-retirement.test.tsin 1 ('are NOT declared here (#8715').VERDICT text-only (36 files), exit 0.Reverse verification of the two readers (each leg through
scripts/ablation-replace.mjs, restore proven againstHEAD)api-derivation.ts:[commit 6968885ef]back to[#6259][commit 6968885ef]removal note vanished from the TSDoc", 1 failed, 31 passedapi-derivation.test.ts: the reader back tosplit('[#6259]')identity.zod.ts: back toare NOT declared here (#8715toContain('are NOT declared here (commit 2c86fe3ea'), 1 failed, 2 passedapi-key-retirement.test.ts: the reader back to(#8715Each leg's mutation landed (anchor 1 → 0, blob changed), and each restore read blob == HEAD with an empty
git diff HEAD. Both files are green atHEAD(32/32, 3/3), and the tree is clean afterwards.Generated artifacts and the changeset
pnpm --filter @objectstack/spec build, the rewrittenDATA_ACTION_TO_API_OPERATIONdocblock is indist/data/index.d.tsandindex.d.mts. The positive control, the same docblock's unchanged first sentence, is in the same two files, and the old[#6259]marker is in 0distfiles.identity.zod.tsblock comment is in nodistfile, and neither is the control sentence from the same block. Butfiles[]shipssrc/**/*.zod.tsverbatim, so the new text publishes.@objectstack/specpatch changeset (.changeset/spec-test-surface-dead-citation-anchors.md, with theClause-②: noline), andskip-changesetdoes not apply. Test files do not ship.check:generated: all 15 generated artifacts are up to date, with nothing regenerated.check:docsis green, so no reference page renders either comment.Verification
pnpm --filter @objectstack/spec build, thencheck:generated: exit 0.pnpm --filter @objectstack/spec exec vitest run --project local --maxWorkers=2: 610 files passed, 18,113 tests passed, 1 todo.repo-project files (export-job-family-retirement,rest-api-config-dead-keys-retirement) are green in the 34-file run.pnpm --filter @objectstack/spec typecheck: exit 0 (check:test-typecheckOK: 52 files, 246 errors, 135 pinned signatures held).dispatch-gates --commandsat0e92e882f4derives 85 families.--ranreports 85 accounted, 84 run (all exit 0), 1 NOT MEASURED and 0 unrun.check:dual-build-cjs-loads, which exits 3 (PREREQUISITE NOT MET) without a full monorepo build. It is a declared narrowing: the diff is comment-only inpackages/spec, and spec's 19 require entries from the gate's own--listall load at head (a missing-entry control throws). CI runs the full gate.eslint --no-inline-config --format jsonover the 36 touched files gives 36 files, 0 errors and 0 warnings.isPathIgnoredis false for all 36, read from eslint's own config.eslint.config.mjsenables no type-aware linting (noparserOptions.project), so a comment edit cannot move any untouched file's verdict. The repo-widepnpm lintis CI's.0e92e882f4.origin/mainwas re-fetched before opening this PR (83e2feeb46, 5 commits past the base). None of those commits touchespackages/specor any file here, andgit merge-treeonto it exits 0, so no merge was taken.Acceptance notes
retiredFromLoadPath: truedoes not keep a conversion off any load path — three runtime seams replay every retired entry withincludeRetired: true, andapply.tssays onlymigrate metadoes #16864 cites29dd1a6dd, the commit that wrote this exact pin line; stage 8 took ADR-0087's 2026-09-13 addendum for a different sentence about the three data-at-rest seams. [spec] View-Management 五方法(listViews/getView/createView/updateView/deleteView)是零实现零路由的声明面 —— 已导致 #5948 把它的响应 schema 误当成线上路由的契约 #6239's row in the-7receipt table now readsviews, and the sweep commitf549a0d4ais cited on the sweep's header line beside the live#6486.packages/spec/srcthere are no dead comment or docblock citations left: the gate census reads 0 and the test-surface census reads 0. What remains are the 68 dead numbers in 147 test-title literals listed above. This stage's dispatch assigns those to runtime strings in thedomain:specpackages carry tracker numbers (spec175 andlint83 messages): this lane's share of the #20513 A/A burn-down #20749's class (e), so this PR saysPart ofand leaves the card open for that call.docs/audits/2026-07-unknown-key-strictness-ledger.md:676(element:record_picker的sort/limit扁平简写:renderer 兑现、schema 未声明(#5775 实施中新测出,A 表之外的第 7 处) #6276) has no carrier.Generated by Claude Code