Skip to content

feat(spec)!: PROTOCOL_VERSION 17 → 18 in an ordinary PR — regenerated spec-changes.json and upgrade guide, ^18 handshakes, pre-mode lockstep exception (#22085 Q1 → B) - #22215

Merged
objectstack-fleet[bot] merged 42 commits into
mainfrom
claude/issue-22130-protocol-18
Oct 9, 2026
Merged

objectstack-fleet[bot] merged 42 commits into
mainfrom
claude/issue-22130-protocol-18

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #22130
Clause-②: yes (narrowing: the handshake refuses a manifest pinned to protocol 17 ('^17', '^17.x.y', '17.x'), while the exported PROTOCOL_VERSION moves to '18.0.0' and a '^18' manifest is admitted)

Executes #22085 Q1 → B (ruling record 6049734955, the maintainer's 「22082 22085 同意」): the protocol major moves in an ordinary pull request that runs the full CI, not in the version pass.

  • PROTOCOL_VERSION reads '18.0.0'.
  • The two generated documents are regenerated by their own tooling: spec-changes.json, and the 17 → 18 section of the protocol upgrade guide.
  • Every in-repo handshake that means "the current protocol" reads ^18.
  • The lockstep gets one narrow exception, routed by ruling record 6056808625 (letter E, maintainer 「同意」):
    • the local lockstep test recognises only the exception's shape;
    • scripts/check-changeset-no-major.mjs judges the evidence: Changesets pre mode AND a pending major for @objectstack/spec.

Status. os-zhuang approved this PR on c96d8e9446 (an authorized APPROVED review, Tier H); the owning seat lands it after the re-sync rounds below and a delta at-tier contract review. PR #22084 (pre mode plus the major marker) merged as a87d8be299 and is merged into this branch, so the pre-mode condition is live.

Size: 8,611 changed lines against the merge base e148ca9842 (+7,854 / −757, 52 files). 7,819 of them are the two generated documents. That is over the human-merge line (3,000 since #22490; AGENTS.md §7 class (c)), so this PR lands like a Tier H surface: an authorized approval and then the owning seat, or a human merge.

First measurements (answered before the edit, on ef1fcb26a2)

M1 — which packages/cli fixtures declare ^17 on purpose. Only packages/cli/src/utils/protocol-version-gap.test.ts:68.

  • That file's advisory judges a range against an explicit installed '17.2.0', never against PROTOCOL_VERSION. ^17 there is the "the range covers the install" control.
  • packages/cli/CHANGELOG.md is release-owned history.
  • The other 19 files (33 sites) are manifest fixtures standing for a valid current app, and none of them asserts on the range. They read ^18.

M2 — may #5082's 17 → 18 conversions (PR #22103) take effect before ADR-0131 C8? The bump does not change when any conversion applies, and no step-18 entry assumes C8. No fork.

  • applyConversions and the stored-row seam walk every conversion with no PROTOCOL_MAJOR filter.
  • The artifact door keys its conversion window on the declared floor against the installed spec package version.
  • os migrate meta already ends at 18: CHAIN_TERMINUS_MAJOR = Math.max(PROTOCOL_MAJOR, ...MIGRATION_MAJORS).
  • declared-index-unique-scope rewrites bare true to 'global', which is the same physical index. 'organization' is NULL-safe through COALESCE (ADR-0120 D3).
  • The step-18 entries that cite ADR-0131 cite D7 or D8 and describe the pre-C8 shape (rows with no organization are still answered). None assumes organization_id is NOT NULL.

What changes

Directory Files ^17 before ^17 after ^18 after
content/docs 3 3 0 3
examples/app-crm 1 1 0 1
examples/app-multi-package 2 2 0 2
examples/app-showcase 1 1 0 1
examples/app-todo 1 1 0 1
packages/cli 21 35 0 35
packages/lint 2 2 0 2
packages/mcp 1 2 0 2
packages/metadata 1 2 0 2
packages/qa 4 4 0 4
Total 37 53 0 53

Why the evidence lives in check-changeset-no-major.mjs (H3 falsified; ruling E)

H3 put the exception inside protocol-version.test.ts, reading .changeset/pre.json. Measured, that cannot stand:

The maintainer ruled E. R's repo-project test and its six declaration edits are reverted. Each of these files now equals main at b460153912, measured:

  • vitest.repo-tests.json
  • cross-package-test-inputs.mjs
  • check-cross-package-test-inputs.mjs
  • turbo.json
  • ci.yml
  • check-ci-filter-parity.mjs
  • protocol-version-pre-mode.test.ts

scripts/pm/dispatch-gates.mjs, release.yml, cut-rc.yml and sync-protocol-version.mjs are untouched.

The gate's verdict, measured three ways:

Tree Verdict Exit
This branch (protocol 18, @objectstack/spec@17.7.0, pre mode, the #22084 marker pending) ✓ Protocol lockstep: … the one exception, evidenced: pre mode (tag next) and a pending major for @objectstack/spec (.changeset/22080-v18-line-opens.md) 0
main 3513ac7781 with this gate copied in (an ordinary PR, no shape) ✓ Protocol lockstep: PROTOCOL_VERSION major 17, @objectstack/spec@17.7.0 — not one major ahead of a stable version, so there is no pre-mode exception to judge. 0
The same tree with the constant at 18 and the marker removed ⛔ … protocol lockstep refused … no pending changeset declares "@objectstack/spec": major. Either put the constant back in lockstep — PROTOCOL_VERSION = '17.0.0' … or open the next major line first … 1

Residuals, stated:

  • The Check Changeset step is skipped under the skip-changeset and allow-major labels.
  • Check Changeset is not one of the seven required contexts AGENTS.md §7 names.

Judgments: every handshake left at ^17, with its reason

Site Reason
packages/cli/src/utils/protocol-version-gap.test.ts:68 Paired with an explicit installed '17.2.0' (M1).
packages/cli/CHANGELOG.md:7788 Release-owned history.
content/docs/releases/v17/17-5.mdx, 17-6.mdx, 17-7.mdx Release-owned; each describes a 17.x release.
packages/create-objectstack/src/templates/blank/objectstack.config.ts:39 The version pass stamps it together with the template's @objectstack/* ranges (replay: engines.protocol → '^18' beside ^18.0.0). Moving it now would scaffold ^18 over ^17.0.0 dependencies. template-consistency.test.ts holds it equal to the scaffolder major.
packages/metadata/src/__fixtures__/forward-probe-17.4-built.artifact.json:11, hotcrm-17.1-built-bare-root-predicates.artifact.json:12, hotcrm-17.1-built-permissions.artifact.json:12 Frozen artifacts built by 17.x. Their floor is the subject, and the metadata plugin door runs no handshake.
packages/metadata/src/plugin-artifact-forward-conversion-retired-after.test.ts:194, plugin-artifact-forward-conversion.test.ts:221 The artifact's age is the subject.
packages/metadata-core/src/artifact-forward-conversion.test.ts:228, form-predicate-root-policy.test.ts:26,50 Age fixtures against an injected runtime version, or a repro shape. No handshake runs.
packages/runtime/src/app-plugin-artifact-forward-conversion.test.ts:81 The real incident's floor. Its readers run no handshake, and it is green at protocol 18.
packages/spec/src/kernel/manifest-unknown-keys.test.ts:53,278,282, manifest-permissions-string-list.test.ts:53 ManifestSchema shape samples; the schema never judges the major.
skills/objectstack-platform/SKILL.md:143, skills/objectstack-platform/evals/config-plugins-ops.json:7, skills/objectstack-upgrade/SKILL.md:91 Governed Tier H; the seat routes them.
.github/workflows/scaffold-e2e.yml:106 A comment.

Moved to >=17.1.0:

  • packages/runtime/src/standalone-stack-security-registrar.test.ts:49
  • standalone-stack-seeder-declaration-copy.test.ts:117

Both boot through the load seam, which refused ^17.1.0 at protocol 18. Their subject is the forward-conversion window, and that window opens on the floor. >=17.1.0 keeps the floor and admits 18.

Re-premised for protocol 18. This is not a handshake: it is a --from that meant the authoring major.

Site Before After
packages/cli/test/migrate-meta-default-range.test.ts (#17134) --from String(PROTOCOL_MAJOR), with the anti-vacuity line TERMINUS > PROTOCOL_MAJOR --from the rename step's toMajor − 1. The anti-vacuity line moved, word for word, to migrate-meta-default-range-window.test.ts, which holds the runtime major at that authoring major in-process.

Replay of the root version script (throwaway clone of bdee4d2da1)

A clone of the merged branch. pre.json and the major marker come from main, so no overlay was needed. release-rehearsal-clone.mjs --prepare answered FIT. Then pnpm install --frozen-lockfile and pnpm run version:

✓ PROTOCOL_VERSION already 18.0.0 — in lockstep with @objectstack/spec@18.0.0-next.0
✓ blank/objectstack.config.ts: engines.protocol → '^18'

release.yml's shape filter (SURFACES, stampedPaths(), syncedPaths(), the fixed pattern):

  • 361 moved paths, with UNEXPECTED empty.
  • protocol-version.ts not moved, so UNVALIDATED is empty.

Content gates on that tree:

Gate Result
vitest run --project local src/kernel/protocol-version.test.ts 3/3
check:spec-changes exit 0
check:upgrade-guide exit 0
check:template-manifests exit 0
pnpm --filter create-objectstack test 17 files, 254 tests
check-changeset-no-major.mjs exit 0; not one major ahead of a stable version (18 vs 18.0.0-next.0)

Control leg (round 1), the same overlay on ef1fcb26a2: ✓ PROTOCOL_VERSION 17.0.0 → 18.0.0, and protocol-version.ts is in the moved set. That is the UNVALIDATED refusal this PR removes.

Verification

Round 12, at 6ec484243e (report on #22130). The merge queue ejected 4ba5952ea1 in a group behind PR #22381, whose new fixture verify-host-root.test.ts:56 declared ^17 (triage 6081302430). main 8b713fad78 merged (3b97df5a7f, nothing of its own); the fixture moved to ^18 in its own commit (5159d64866), red before it and green after it. main e148ca9842 merged (462a24045b); #22447 had added two step-18 semantic entries, so both documents were regenerated in a separate commit (4d1a408a75: +28 and +6 lines), and the changeset's count tokens moved 327 → 329 in their own commit (6ec484243e). 138 derived gates run, 0 not measured. CI on 6ec484243e: 35 runs, 33 success, 2 expected skips.

Round 11, at 4ba5952ea1 (report 6080275052 on #22130). The merge queue ejected 5ef8ab6ac5 when PR #22315 landed first with a new step-18 semantic entry. main 3ca71b6e05 merged (a46840ee68, no path of its own per git diff-tree --cc); spec-changes.json (+14) and the upgrade guide (+4/−1) regenerated in a separate commit (b8a3e2a45c; 64 conversions, 327 semantic entries, aggregate 404 = the registry's 404); the changeset's two count tokens 326 → 327 in their own commit (4ba5952ea1). At-tier delta contract review PASS 6079895139. CI on 4ba5952ea1: 35 runs, 33 success, 2 expected skips.

Round 10, at 5ef8ab6ac5 (report 6077854211 on #22130; seat ACCEPT 6078284011). A pure regeneration: main bf492c8548 (#22412) merged (b50d5c3866), then spec-changes.json (+12/−12) and the upgrade guide (+6/−6) regenerated in a separate commit; every changed line is a rationale of the six step-18 entries #22412 reworded, and the counts stay 64 / 326. The at-tier PASS 6076766071 is carried by the Regen-provenance: line in PR comment 6077906555. CI on 5ef8ab6ac5: 35 runs, 33 success, 2 expected skips.

Patch round 1, at eb23db8a82 (report 6076558925 on #22130). main e02833c240 merged with os-regen-merge.sh (c80423bc16, committed before any generator ran); no step-18 entry arrived, check:spec-changes and check:upgrade-guide exited 0 on the merged tree, and both generators rewrite byte-identical (64 / 326). The specVersion prescription fix above. spec test 627 files / 18,757 passed and test:repo 54 files / 915; cli protocol-version-gap.test.ts 16 passed; the dogfood cold-boot file 4 passed. The 32 steps of Type Check · source gates exit 0, check:future-spec-major included; dispatch-gates: 138 derived, 138 run. CI on eb23db8a82: 35 runs, 33 success, 2 expected skips.

Round 9, at 4ff2827472 (report 6075705847; seat review 6075740377). The re-sync the handover named: main e75dceddd7 merged (e04231ab07), spec-changes.json and the upgrade guide regenerated after the merge commit (062e3545c8, 324 → 326 semantic entries), the changeset count updated, the two current-app fixtures main added moved to ^18, and PR #22416's one-file fix ported verbatim (02d07755d7; main now carries the identical blob, so it no longer shows in the diff). The merge-queue build of c96d8e9446 had failed check:spec-changes for exactly this staleness.

Round 8, at c96d8e9446. A merge of main b460153912 only, with os-regen-merge.sh (merge commit c96d8e9446). main touched no migration, conversion or kernel file and added no ^17 handshake since 41d0d4038c.

  • gen:spec-changes and gen:upgrade-guide both rewrote their files byte for byte: git diff HEAD is empty.
  • check:spec-changes, check:upgrade-guide, spec check:generated (15 artifacts), check:future-spec-major and check:adr-0087-registration --base origin/main exit 0. check-changeset-no-major --base origin/main --event exits 0 against this body.
  • The two Test Core timeouts on c78f55e352 are not this PR's. Both now exit 0:

Round 7, at c78f55e352. main 41d0d4038c was merged with os-regen-merge.sh (merge commit ecde207250, no regeneration in MERGE state). Then gen:spec-changes and gen:upgrade-guide were run (fed6cd402f), and the changeset now counts 324 semantic entries (c78f55e352).

  • Every step of lint.yml's Type Check · source gates job exits 0, run in order: 32 run steps. They include check:spec-changes, check:upgrade-guide, check:authorable-surface and check:future-spec-major (8 witnessed ledger entries; the new generated copies cite no @objectstack/spec major).
  • Spec check:generated (all 15 artifacts) exits 0.
  • check:adr-0087-registration --base origin/main, check:empty-changeset, check:changeset-gate-self-tests and check:nul-bytes exit 0. check-changeset-no-major --base origin/main --event exits 0 against this body.
  • dispatch-gates --commands derives the same 138 families; the merge adds none.
  • The full test task of every touched package, each exit 0:
    • @objectstack/spec: test 626 files, 18,740 tests passed, 1 todo; test:repo 54 files, 914 tests.
    • @objectstack/cli test (both projects): 366 files (269 unit + 97 integration), 4,877 tests passed, 2 skipped. typecheck exits 0.
    • @objectstack/runtime: test 340 files, 4,776 tests passed, 19 skipped; test:repo 3 files, 751 tests.
    • @objectstack/dogfood: 226 files passed, 1 skipped; 1,770 tests passed, 9 skipped.
    • @objectstack/lint 127 files, 5,843 tests. @objectstack/mcp 35 files, 390 tests. @objectstack/metadata 58 files, 870 tests.
    • example-crm 5 files, 45 tests. example-showcase 33 files, 408 tests. example-todo 7 files, 238 tests.

Round 6, at 99b16b2999. Test Core (1/6) was red on dd4ea171fb in @objectstack/cli's integration project: migrate-meta-default-range.test.ts, 4 tests. My earlier rounds ran --project unit only. Now:

  • pnpm --filter @objectstack/cli test (both projects) passes. 361 files (267 unit + 94 integration): 4,839 tests passed, 2 skipped, exit 0.
  • pnpm --filter @objectstack/cli typecheck exits 0. It includes check:test-typecheck over test/.
  • The full test task of every other touched package with more than one vitest project, each exit 0:
    • @objectstack/dogfood: 221 files passed, 1 skipped; 1,753 tests passed, 9 skipped.
    • @objectstack/runtime: test 336 files, 4,749 tests passed, 19 skipped; test:repo 3 files, 751 tests.
    • @objectstack/spec: test 625 files, 18,711 tests passed, 1 todo; test:repo 54 files, 914 tests.
    • lint, mcp, metadata, example-crm, example-showcase and example-todo have one project each. example-multi-package has no test script.
  • Two ablations, run from the committed state with scripts/ablation-replace.mjs. Each mutation was proven on disk, and each restore was proven by blob = HEAD and an empty git diff HEAD. Both subjects resolve to src/, so no build leg applies.
    • With the --to default reverted to PROTOCOL_MAJOR, exactly the window file's three default pins go red: expected 17 to be 18, expected [] to deeply equal [ …(5) ], and a missing Applied 5 mechanical change(s). The spawned file stays green under the same mutation, which measures that it cannot tell the defaults apart at protocol 18.
    • With the window mock neutralised (runtime major left at 18), the window guard and the anti-vacuity line go red: the registry carries a step past the runtime major: expected 18 to be greater than 18.

Round 5, at dd4ea171fb. Every step of lint.yml's Type Check · source gates job exits 0, run in the job's order: 32 run steps, from pnpm install --frozen-lockfile to check:llms-txt.

  • Before the two ledger entries, check:future-spec-major was red on three sites: docs/protocol-upgrade-guide.md:1039 and packages/spec/spec-changes.json:2340, :5880.
  • After them: self-test 29 cases, 10,167 files scanned, 8 witnessed ledger entries, every witness still matching.
  • readClause2Line reads the changeset as { value: yes, arm: narrowing }.
  • These exit 0 against this body: check-changeset-no-major --base origin/main --event, check:adr-0087-registration --base origin/main, check:empty-changeset and check:changeset-gate-self-tests.

All runs below happened after merging main (3513ac7781, then d1dbe70ebd), on a shared box, through the verify lock.

After the third merge (6729e107e8, which added one step-18 semantic entry), at 23e9e302d9, these all exit 0:

  • check:spec-changes, check:upgrade-guide and spec check:generated;
  • check-adr-0087-registration --base origin/main;
  • check-changeset-no-major --base origin/main --event, against this body;
  • the spec local tests under src/kernel src/migrations src/conversions (70 files, 1,853 tests);
  • package-union-readers.test.ts (7/7).

dispatch-gates --commands derives the same 137 families as at bdee4d2da1; the merge adds none.

Builds. The turbo closure of dogfood, cli, cloud-connection, the examples, create-objectstack and mcp: 65/65 tasks. Then lint/cli (59/59) and the seven dist-only packages (43/43). check:generated: all 15 artifacts up to date.

Tests

Package Scope Result
@objectstack/spec local, full 625 files, 18,661 tests
@objectstack/spec repo, full 53 files, 903 tests (in shards; build-schemas-check-mode.test.ts alone 88/88 in 909s)
@objectstack/spec after the second merge: src/kernel src/migrations src/conversions 71 files, 1,861 tests
@objectstack/spec typecheck exit 0
@objectstack/runtime local, full 335 files (3 shards: 112 + 112 + 111)
@objectstack/runtime repo 3 files, 751 tests
@objectstack/metadata-protocol full 221 files, 28,277 tests
@objectstack/metadata full 58
@objectstack/metadata-core full 18
@objectstack/cloud-connection full 41
@objectstack/lint full, after the second merge 127 files, 5,843 tests
create-objectstack full 17
@objectstack/cli --project unit 263 files (2 shards), 3,901 tests
@objectstack/cli touched .e2e files 2 files, 45 tests
@objectstack/dogfood touched files 6 files, 44 tests
example-crm full 5
example-todo full 7
example-showcase full 33
check-changeset-no-major.mjs --self-test — 378 assertions

Gates at bdee4d2da1:

Acceptance notes


Generated by Claude Code

claude added 8 commits October 8, 2026 03:33
…nd upgrade guide, ^18 handshakes, pre-mode lockstep exception

The protocol major moves in an ordinary pull request with full CI (ruling
record 6049734955, Q1 -> B). spec-changes.json and the 17 -> 18 section of
docs/protocol-upgrade-guide.md are regenerated by gen:spec-changes and
gen:upgrade-guide. Handshakes that mean the current protocol read ^18.

The lockstep's one exception (Changesets pre mode with a pending major for
@objectstack/spec) is judged in a new repo-project test that reads
.changeset/, declared on @objectstack/spec#test:repo; the local lockstep
recognises only the exception's shape and hands off to it.

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
…ADR-0087 disposition

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
… merging main; changeset names the 64th step-18 conversion

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
… floor, which the protocol 18 handshake admits

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
…spec's pre-mode lockstep check

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
… top-level directory turbo.json now declares

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
…* root (22 -> 23)

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 2 package(s): @objectstack/mcp, @objectstack/spec, touching 2 documentable anchor(s). ⚠️ 2 changed file(s) yielded no anchor (packages/mcp/README.md, packages/spec/spec-changes.json), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files.

3 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/getting-started/quick-reference.mdx (via ManifestSchema (symbol, a top-level const object))
  • content/docs/plugins/development.mdx (via ManifestSchema (symbol, a top-level const object))
  • content/docs/protocol/kernel/plugin-spec.mdx (via ManifestSchema (symbol, a top-level const object))

⛔ 4 release-owned page(s) also name something this change touched. These are read-only:

  • content/docs/releases/v12.mdx (via PROTOCOL_VERSION (symbol, a top-level const object))
  • content/docs/releases/v13.mdx (via PROTOCOL_VERSION (symbol, a top-level const object))
  • content/docs/releases/v14.mdx (via PROTOCOL_VERSION (symbol, a top-level const object))
  • content/docs/releases/v15.mdx (via ManifestSchema (symbol, a top-level const object))

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

What this run could not see
  • 2 changed file(s) yielded no anchor (packages/mcp/README.md, packages/spec/spec-changes.json) — pages documenting those are invisible to this run
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 144 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json e148ca984258c7c0d162eefd04b1f0f77c3fa9fd → packageMentionDocs.

Which tree this was computed on

This run read content/docs from faf473962ac6defe325d4c5ad2487aa1725185fb — the merge of head 6ec484243e3808af9680bb5b05822d768fb24cc0 into base e148ca984258c7c0d162eefd04b1f0f77c3fa9fd, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin faf473962ac6defe325d4c5ad2487aa1725185fb && git checkout faf473962ac6defe325d4c5ad2487aa1725185fb
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin e148ca984258c7c0d162eefd04b1f0f77c3fa9fd 6ec484243e3808af9680bb5b05822d768fb24cc0 && git checkout -B drift-repro e148ca984258c7c0d162eefd04b1f0f77c3fa9fd && git merge --no-ff 6ec484243e3808af9680bb5b05822d768fb24cc0

node scripts/docs-audit/affected-docs.mjs --json e148ca984258c7c0d162eefd04b1f0f77c3fa9fd

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs e148ca984258c7c0d162eefd04b1f0f77c3fa9fd → pass the list as
args.docs, on the commit named under Which tree this was computed on.

claude added 4 commits October 8, 2026 10:19
… merging main (step 18: 64 conversions, 319 semantic entries)

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
…ation edits, per ruling 6056808625 (E)

Each reverted file now equals origin/main at 3513ac7.

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
…evidence; the local lockstep test hands the shape to it (ruling 6056808625, E)

When PROTOCOL_VERSION's major is one ahead of @objectstack/spec's stable
version, the gate requires Changesets pre mode AND a pending major for the
spec package, read from source text with no build, and otherwise refuses
naming the remedy. Its own self-test battery covers both directions. The
changeset is regraded major now that pre mode is on main.

Claude-Session: https://claude.ai/code/session_01LAi5BVvQNiYzepSAcsoFLK
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Read at 2026-10-09T11:23Z · PR #22215 (open, non-draft, auto-merge off, mergeable_state blocked on a pending shard) at merge base 3ca71b6e05 · card #22130 · delta review (round 11, the re-sync after main took #22315) after the at-tier PASS 6076766071 at eb23db8a82 and its carry 6077906555 to 5ef8ab6ac5 · isolated, read-only, at tier.

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 4ba5952ea14d58cca61d279f864444aea767e646
Local-runs: none

Inputs: the card body and its 25 comments (the ruling 6056808625, the handover 6072775566, the claim 6074102194, the round-10 report 6077854211 and ACCEPT 6078284011; the round-11 dev report is NOT on the card at my read — the newest comment is 6078284011 at 09:33Z and the head's three commits are stamped 10:36Z to 10:42Z — so this head is judged from the committed trees alone, and the report, when it posts, is a claim to be read against this record, not an input to it); the PR body, its file list (51), its 16 comments and its one review; the three first-parent commits since 5ef8ab6ac5 (a46840ee68, the merge of main 3ca71b6e05; b8a3e2a45c, the regeneration; 4ba5952ea1, the changeset counts); the PR's net diff at each head — git diff e02833c240 eb23db8a82, git diff bf492c8548 5ef8ab6ac5 and git diff 3ca71b6e05 4ba5952ea1 (51 paths, +7,819 / −756, equal to the files API path for path) — compared path by path with index and hunk headers stripped; git diff-tree --cc of the merge; the two generated documents at the head parsed as JSON and as Markdown; the registries and the entries/semantic/18.*.ts tree at 3ca71b6e05, at the head and at today's main tip 587bd9699d; .changeset/pre.json, the #22084 marker, packages/spec/package.json, protocol-version.ts and .gitattributes at the head; scripts/check-adr-0087-registration.mjs and the two workflow files on main for the marker grammar and the job that runs it; the head's check-runs, read at 10:50Z and again at 11:20Z. Nothing was built, tested or re-run; every reading is git show / git diff / git diff-tree / git grep / git ls-tree / git rev-parse / a JSON parse / a gh api GET.

① Derived judgments

What this delta is, read off the trees. a46840ee68 merges main 3ca71b6e05 (six commits: #22440, #22315, #22396, #22436, #22442, #22439; 98 paths, +4,194 / −742 on the first-parent side). git diff-tree --cc of the merge is empty: no path differs from both parents, so the merge introduced nothing of its own. Against 5ef8ab6ac5 the merge commit leaves the three PR-side files byte-identical (spec-changes.json, the upgrade guide, the changeset) — main had touched none of them, and both documents are merge=os-regen (.gitattributes:165, :176). b8a3e2a45c then regenerates the two documents in its own commit after the merge (+18 / −1: spec-changes.json +14 in two hunks, per-major and aggregate; the guide +4 / −1, the 17 → 18 intro paragraph and one three-line entry), and 4ba5952ea1 edits the changeset alone. The post-merge PR-side change is exactly those two commits — git diff a46840ee68 4ba5952ea1 is the three files, +20 / −3.

Nothing else the PR owns moved. The net diff of the 48 paths outside those three is identical, line for line, at eb23db8a82 (the at-tier PASS head, against its base e02833c240), at 5ef8ab6ac5 (against bf492c8548) and at this head (against 3ca71b6e05): 1,409 +/- lines each, byte-equal; the path set is the same 51. So every judgment the record 6076766071 and its four predecessors made about those 48 — the handshake accept and refuse sets at every door, the specVersion prescription spelled from PROTOCOL_MAJOR, the lockstep exception's shape and the gate's third question, route R's revert, the os migrate meta --write claim, the two check:future-spec-major ledger entries, the #17134 re-premise and the window file, the two runtime fixtures at the greater-or-equal floor 17.1.0 — stands by identity, not by reuse, and against the at-tier head directly, not through the carry.

The regenerated documents equal the merged registries. What main added since bf492c8548 under packages/spec/src/migrations is one step-18 semantic entry, 18.flow-text-slot-single-brace-refused.ts (#22315, 2b61f2d9d6), registered in registry.ts by that same change, whose changeset at the merge base carries adr-0087: registered flow-text-slot-single-brace-refused under its own major grades. The regeneration adds exactly that entry: migrationId flow-text-slot-single-brace-refused, toMajor 18, present once in the 17 → 18 record and once in the aggregate; the 14 added JSON lines are its two seven-line objects, and the guide's added entry is the same id with its rationale and acceptance text; the intro-paragraph line carries its summary. Parsed at the head: the 17 → 18 record holds 64 conversionIds and 327 distinct migrationIds (no duplicate, every toMajor 18); the aggregate 16 → 18 holds 121 and 404, which are the two per-major records summed (57 + 64, 77 + 327). The 327 ids equal, as a set, the 327 entries/semantic/18.*.ts stems on main at the merge base 3ca71b6e05, at the head and at today's tip 587bd9699d (set difference empty both ways). The migrations registry blob (868d157c83) and the conversions registry blob (aa4b618125) are identical in all three trees, and the PR's diff touches neither directory. The guide's 17 → 18 Semantic section carries 327 entry bullets. The generators' own checks are the verdict: Type Check · source gates concludes success on this head (check:spec-changes, check:upgrade-guide, check:future-spec-major among its steps). Right.

The hand-edited changeset, line by line. git diff --word-diff of .changeset/22130-protocol-18.md from eb23db8a82 to this head is two tokens, 326 → 327, and nothing else: one in the adr-0087 marker comment's prose ("the step's 327 D3 semantic entries"), one in the bullet "64 mechanical conversions and 327 semantic entries. The aggregate record spans 16 → 18". Judged against the regenerated documents: 327 is the record's migrated count and the guide's bullet count; 64 is the record's converted count and the conversions registry's toMajor: 18 row count; the aggregate spans 16 → 18. The marker's already-registered list is unchanged — extracted strictly (the id text up to the first close paren, an ASCII paren, checked at the byte level), 64 ids, set-equal to the head's 64 step-18 conversionIds, order untouched, and every id pre-dates the merge base because the conversions registry did not move. The marker's prose claim — "each entry was registered by the change that made its break, under that change's own disposition; this diff adds, renames and removes none" — holds for the one entry this delta projects. Clause-② (line 8) is byte-identical to its state at eb23db8a82. Right.

No accept set moves. The two documents are projections of registries that already carried the entry; the changeset edit is prose in a release-owned input. No door, no schema, no export and no refusal string changed in this delta; the public surface of the PR is exactly the one 6076766071 judged.

Re-sync at my read: none owed. main is four commits past the merge base (#22456, #22441, #22448, #22457), 27 paths; none is one of the PR's 51, none is under packages/spec/src/{migrations,conversions,kernel}, packages/spec/scripts, or either generated document, and the added lines carry zero caret-17 protocol literals. The lockstep evidence is live at the head: .changeset/pre.json mode: pre, tag next; .changeset/22080-v18-line-opens.md pending with "@objectstack/spec": major; @objectstack/spec at 17.7.0; PROTOCOL_VERSION '18.0.0'.

② Semver level

Unchanged in grade and re-verified where the delta could touch it: major for @objectstack/spec under pre mode, patch for @objectstack/mcp, the **BREAKING** banner, feat(spec)!:. The disposition is one not-required (already-registered …) marker whose grammar fits the gate's parser (category, then ids up to the first close paren, then free prose), whose 64 ids equal the generated set, and whose count prose now says 327 = the record. Clause-②: yes (narrowing: …) — the PR body's line 2 and the changeset's line 8 are byte-identical (same SHA-1, 3300cfb220a1); the delta widens no accept set and narrows none. Gate verdicts on this head: Check Changeset concludes success — the job that runs check-changeset-no-major.mjs and the "Require an ADR-0087 disposition" step, neither skipped, since the PR carries no skip-changeset and no allow-major label — and Type Check · source gates concludes success. The Clause-②: line is right.

③ Boundary flags

Check-runs on this head at my reads (34 runs, newest per name, no reruns). At 10:50Z: 30 success, 2 skipped, 2 in progress (Lint & Repo Gates, Test Core (1/6)). At 11:20Z: 31 success, 2 skipped (Console Pin Gate, no .objectui-sha move; Packed-tarball smoke (opt-in)), 1 in progress — Test Core (1/6) — and the Test Core aggregate context has not reported yet. Six of the seven required contexts conclude success: Lint & Repo Gates, TypeScript Type Check, Dogfood Regression Gate (and its three shards), Build Core, Temporal Conformance (live PG + MySQL), Governed Surface Queue Guard; also Check Changeset, Check PR Size, the four Type Check · jobs, Build Docs, Dogfood Verify CLI, Spec property liveness, Flag docs affected by code changes, Check Documentation Links, Auto Label, the claim / single-writer / part-of guards, filter, and Test Core shards 2 to 6. Red — none. The pending shard is not judged green here: this record is the contract verdict on the diff; the landing waits for the seventh required context to conclude success (§7 class (c) with Prime Directive #14: the authorized approval on file, then the owning seat, on green), and the seat arms nothing before that.

Implemented-by: claude/issue-22130-protocol-18
Reviewed-by: session_01VZqqwTj2wsihZEbfT6yyYN

VERDICT: PASS

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

⛔ merge queue 构建失败 — 先分诊,再决定要不要重排

队列构建 37930835817 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集),
所以失败的测试可能在本 PR 没碰过的包里 —— 那不是重排能修的。每次盲目重排都会让排在后面的所有 PR 重建一轮。

分类:failure —— 按下面的日志分诊。

失败的 job(日志抽取,best effort):

  • Test Core (2/6) — 失败步骤: Run this shard's tests

    @objectstack/cli:test:  FAIL   integration  test/verify-host-root.test.ts > os verify anchors the app at its own directory, not the process cwd (#22301) > loads the app's own plugin from the app's dir
      ↳ 失败原因: @objectstack/cli:test: AssertionError: os verify failed from a foreign cwd:
    

↳ 失败原因 是判读的关键:超时(Test timed out in … / Hook timed out in …)多半是负载/时序,不是本 PR 的回归;
断言(AssertionError: …)才指向真实的行为改变。两者的 FAIL 行长得一模一样,只有这一行能区分。

⚠️ 断言这一侧有一类例外,判据是断言在测什么,不是它是不是 AssertionError。 断言的对象是产品行为(一个值、一个形状、一次拒收)⇒ 照上面读:真实的行为改变,去查,⛔ 不要重排掉;
断言的对象是这次实验自身的有效性前提(跑完的耗时、负载下的先后、任何只在时间预算内才成立的条件)⇒ 它跟超时是同一类,同样对负载敏感,重排一次是合法的判别手段。
识别是机械的:断言的消息或它比较的值本身点名了一段时长、一个时间戳、一个耗时计数。实测过的一对 —— AssertionError: SecurityPlugin.init() ran: expected false to be true 测的是产品行为(真回归);
AssertionError: this run took over a second, so second-precision stamps could have differed too: expected 1006 to be less than 1000 测的是实验前提:它守护的那条不变式当时是绿的,同一个 head 原样重排一次即成功。
穿着 AssertionError 外衣的时间测量,仍然是时间测量。(⛔ 这只改「怎么读一次红」,不改「哪些测试可以重排」——后者由别处管。)

跨 PR 相同签名(24h,按失败测试文件聚合):

  • test/verify-host-root.test.ts — 24h 窗口内只有本 PR 撞到过,暂不汇总(再有一个不同 PR 撞到就会自动开汇总 issue)。
  • ⚠️ 24h 评论账本没读完(超过 5 页仍未读到窗口尽头),所以上面的「不同 PR 数」是下界,不是全量。

历史信号:

  • ⚠️ 本 PR 过去 24h 已在队列失败 2 次(不含本次)。 内容未变而反复失败 ⇒ 高度怀疑 flaky 测试或与同组 PR 的语义冲突,重排不解决。
  • 过去 24h 队列共有 11 个失败构建(不含本次)。

分诊清单:

  1. 失败测试在本 PR 改动的包里 → 真回归,修 PR。
  2. 失败测试与本 PR 无关 → 看上面的「跨 PR 相同签名」;已有汇总 issue ⇒ flaky/环境问题实锤,去那张 issue 上谈,修好前重排只会再烧一轮全队列。
  3. 两者都不是 → 可能与同组 PR 语义冲突;等前面的 PR 落地或失败出队后再重排一次即可,不要连续重排。

Generated by Claude Code · merge-queue-triage workflow (#4859)

…nt protocol, ^18

#22381 (97610a5) added test/verify-host-root.test.ts with a current-app
fixture pinned to engines.protocol '^17'. Under PROTOCOL_VERSION 18.0.0 the
runtime handshake refuses that app, so `os verify` exits 1 before the pin's
subject (the app-dir anchoring) is ever reached. The fixture now declares
'^18', the same sweep rule this branch applies to every current-app fixture.

Claude-Session: https://claude.ai/code/session_01VZqqwTj2wsihZEbfT6yyYN
Co-authored-by: Claude <noreply@anthropic.com>
claude added 3 commits October 9, 2026 14:56
… merging main at e148ca9 (step 18: 64 conversions, 329 semantic entries)

main added two step-18 semantic entries since 8b713fa, both from #22447
(7895671): manage-org-presentation-retired and
meta-doors-organization-scope-retired. At protocol 18 both generators
project every step-18 entry, so both documents gain them. The conversion
ids are unchanged; the 16 -> 18 aggregate is 406, equal to the registry.

Claude-Session: https://claude.ai/code/session_01VZqqwTj2wsihZEbfT6yyYN
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Read at 2026-10-09T16:26Z · PR #22215 (open, non-draft, auto-merge off, mergeable_state clean) at merge base e148ca9842 · card #22130 · delta review (round 12, the re-sync after the merge queue ejected 4ba5952ea1 at verify-host-root.test.ts, triage 6081302430) after the at-tier PASS 6079895139 at 4ba5952ea1 · isolated, read-only, at tier.

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 6ec484243e3808af9680bb5b05822d768fb24cc0
Local-runs: none

Inputs: the card body and its 29 comments (the ruling 6056808625, the claim 6074102194, the round-11 ACCEPT 6080960782, the holder note 6081559243, the round-12 dev report 6084728061); the PR body as re-edited after that report (it now carries a Round 12 entry), its file list (52), its 18 comments and its one review; the five first-parent commits since 4ba5952ea1; the net diff git diff e148ca9842 6ec484243e (52 paths, +7,854 / −757, path for path and count for count equal to the files API) compared path by path, index and hunk headers stripped, with the round-11 net diff git diff 3ca71b6e05 4ba5952ea1; git diff-tree --cc of both merges; the two generated documents at the head parsed as JSON and as Markdown; the entries/semantic/18.*.ts tree and the two registries at 3ca71b6e05, e148ca9842, the head and today's main tip 2e10c9abe0; .changeset/pre.json, the #22084 marker, packages/spec/package.json and protocol-version.ts at the head; #22447's changeset at e148ca9842; HUMAN_MERGE_LINE_THRESHOLD and GOVERNED_SURFACES in scripts/pm/check-governed-merges.mjs and AGENTS.md §7 on main; the head's check-runs, read twice. Nothing was built, tested or re-run; every reading is git show / git diff / git diff-tree / git grep / git ls-tree / git merge-base / a JSON parse / a gh api GET.

① Derived judgments

What this delta is, read off the trees. Five first-parent commits. 3b97df5a7f merges main 8b713fad78 (14 first-parent commits past 3ca71b6e05, #22381 among them); 462a24045b merges main e148ca9842 (9 more, #22447 and #22490 among them). git diff-tree --cc of each merge prints only its own sha: neither introduced a line of its own. Between the merges 5159d64866 edits one file; after them 4d1a408a75 regenerates the two documents and 6ec484243e edits the changeset. Both merge targets are ancestors of today's main; the merge base is e148ca9842, equal to the PR's API base.

The hand-edited fixture, judged. packages/cli/test/verify-host-root.test.ts was ADDED by #22381 (97610a5339, +141, on main after the round-11 merge base). Its STACK.manifest is a current-app fixture: os verify is spawned on it, the boot runs the real load seam and the ADR-0087 D1 handshake, and nothing in the file asserts on the range text (^17 / ^18 occur at line 56 alone). So '^17' there is the same class as the 52 sites the PR already swept, and the queue's red — targets protocol ^17 (engines.protocol) but this runtime is protocol 18.0.0 — is the handshake doing what the Clause-② line declares. 5159d64866 is +1 / −1 on line 56, '^17' → '^18', and nothing else (word diff). Right. It is the ONLY added caret-17 protocol literal in main's delta 3ca71b6e05..e148ca9842 (one hit, that line), and main's one commit since the merge base (#22495, 2e10c9abe0) adds none and touches no packages/spec path. Per-file counts of caret / tilde / greater-or-equal 17 protocol literals over the tree (release pages excluded) are equal at 4ba5952ea1 and at this head; the intermediate merge 3b97df5a7f differs by exactly that one file. The path set grew 51 → 52 by exactly this file: comm -12 of main's delta paths with the PR's 52 is that one path, and nothing else main touched intersects the PR.

The regenerated documents equal the merged registries. What main added since 3ca71b6e05 under packages/spec/src/migrations is #22447 (7895671162): 18.manage-org-presentation-retired.ts, 18.meta-doors-organization-scope-retired.ts, and registry.ts +88 (the two entries, nothing else); its changeset at e148ca9842 carries adr-0087: registered manage-org-presentation-retired, meta-doors-organization-scope-retired. The conversions registry blob (aa4b618125) is identical at 3ca71b6e05, e148ca9842, the head and the tip; the migrations registry blob (ed7eda14f4) is identical at e148ca9842, the head and the tip. 4d1a408a75 is +34 / −0: spec-changes.json +28 in four hunks (each entry once in the 17 → 18 record, once in the aggregate), the guide +6 in two hunks (one three-line bullet per entry under Semantic). No conversionId was added. Parsed at the head: protocolVersion 18.0.0; the 17 → 18 record holds 64 converted (64 distinct, every toMajor 18) and 329 migrated (329 distinct migrationIds, every toMajor 18); the aggregate 16 → 18 holds 121 and 406, which are the per-major records summed (57 + 64, 77 + 329). The 329 ids equal, as a set, the 329 entries/semantic/18.*.ts stems at the head and at the main tip (set difference empty both ways). The guide's 17 → 18 section carries a 64-row mechanical table and 329 semantic bullets. The generators' own checks are the verdict: Type Check · source gates (check:spec-changes, check:upgrade-guide, check:future-spec-major among its steps) concludes success on this head. Right.

The hand-edited changeset, line by line. The word diff of .changeset/22130-protocol-18.md from 4ba5952ea1 is two tokens, 327 → 329: the adr-0087 marker's prose ("the step's 329 D3 semantic entries") and the bullet "64 mechanical conversions and 329 semantic entries". Both equal the regenerated record's migrated count and the guide's bullet count; 64 equals the converted count. The marker's already-registered list (the first match, ids up to the first close paren) is 64 ids, set-equal to the head's 64 step-18 conversionIds, unchanged since the merge base, and each id pre-dates the merge base because the conversions registry did not move. Clause-② (line 8) is byte-identical to its state at 4ba5952ea1 and at eb23db8a82. Right.

Nothing else the PR owns moved. Of the 52 paths, 48 have byte-identical +/− lines in the two net diffs (3ca71b6e05..4ba5952ea1 against e148ca9842..6ec484243e, headers stripped). The four that differ are exactly the four this delta names, compared as sorted multisets: the changeset 2 only-before / 2 only-after (the count tokens); the guide 0 / 6; spec-changes.json 0 / 28; verify-host-root.test.ts 0 / 2 (new to the set). So every judgment the at-tier records 6076766071 and 6079895139 made about the 48 — the accept and refuse sets at every door, the specVersion prescription from PROTOCOL_MAJOR, the lockstep exception's shape and the gate's third question, the #17134 re-premise and the window file, the two runtime fixtures at greater-or-equal 17.1.0 — stands by identity.

No accept set moves beyond what the PR already declared. The one new site is a fixture (a test input), not a door; the two documents project entries the registries already carried; the changeset edit is prose. No door, schema, export or refusal string changed in this delta. The public surface of the PR is the one 6076766071 judged. The lockstep evidence is live at the head: pre.json mode: pre, tag next; .changeset/22080-v18-line-opens.md pending with "@objectstack/spec": major; @objectstack/spec at 17.7.0; PROTOCOL_VERSION '18.0.0'.

Re-sync at my read: none owed. main is one commit past the merge base (#22495): 0 spec paths, 0 added caret-17 literals, 0 paths in common with the PR.

② Semver level

Unchanged in grade and re-verified where the delta could touch it: major for @objectstack/spec under pre mode, patch for @objectstack/mcp, the **BREAKING** banner, feat(spec)!:; no skip-changeset and no allow-major label (labels: documentation, ci/cd, size/xl, tests, tooling). The disposition is one not-required (already-registered …) marker whose 64 ids equal the generated set and whose count prose now says 329 = the record. Clause-②: yes (narrowing: …) — the PR body's line 2 (as re-edited after the dev report) and the changeset's line 8 are byte-identical (same SHA-1, 3300cfb220a1); the delta widens no accept set and narrows none beyond the declared arm (one more current-app fixture sits on the admitted side of the same door). Gate verdicts on this head: Check Changeset concludes success twice — the run on the push (113881328945) and the re-run the body edit fired (113913066996), neither skipped — and Type Check · source gates concludes success. The Clause-②: line is right.

③ Boundary flags

Dev flags (report 6084728061): open_questions empty; out_of_scope_findings empty; three deviations, each answered.

Check-runs on this head at my reads (42 runs across 35 names; seven names ran twice because the body edit after the dev report fired a second pull_request run on the same head). First read, newest per name: 30 success, 4 skipped, 1 in_progress (Check Changeset, its second run). Second read, six minutes later: 31 success, 4 skipped, 0 in progress, 0 red; across all 42 runs 38 success, 4 skipped. The seven required contexts conclude success: Lint & Repo Gates, TypeScript Type Check, Dogfood Regression Gate (and its three shards), Build Core, Temporal Conformance (live PG + MySQL), Governed Surface Queue Guard, Test Core (and its six shards, (2/6) included — the shard the queue failed on); also Check Changeset, the four Type Check · jobs, Build Docs, Dogfood Verify CLI, Spec property liveness, Flag docs affected by code changes, Check Documentation Links, the claim / single-writer / part-of guards, filter. Skipped: Console Pin Gate (no .objectui-sha move), Packed-tarball smoke (opt-in), and the second runs of Auto Label and Check PR Size (their first runs on this head, 113881487819 and 113881328312, conclude success; the re-run on the edit event skipped by its own condition). Red — none.

Implemented-by: claude/issue-22130-protocol-18
Reviewed-by: session_01VZqqwTj2wsihZEbfT6yyYN

VERDICT: PASS

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci/cd documentation Improvements or additions to documentation size/xl tests tooling

Projects

None yet

4 participants