Skip to content

Commit 03b19d9

Browse files
docs(spec): re-anchor the dead tracker citations in data/ to the commits that decided them (stage 3) (#20533)
Part of #20234 Clause-②: no ## What changed This is stage 3 of the staged sweep. It covers `packages/spec/src/data/**` and nothing else. It leaves out the files an open PR or an in-flight claim holds: `data-engine.zod.ts`, `data-engine.test.ts`, `hook.form.ts`, `analytics*.ts`, `cube-member-inner-name-retirement.test.ts`, `driver/turso.zod.ts` and `filter-subtree-provenance.ts`, as the claim names them. It also leaves out four files that open PRs started editing after the claim: `driver/turso.test.ts` (PR #20504, #20437's, opened 2026-09-28T20:08Z), `object.form.ts` (PR #20519, #20432's, 21:55Z), `object.zod.ts` (PR #20521, #20494's, 22:10Z) and `filter-logic-conformance.ts` (PR #20523, #20444's, 22:39Z). See Acceptance notes. Later stages cover the other areas, so this PR says `Part of`. Every comment or docblock site in scope that cited a tracker number answering 404 has been rewritten in ruling C+D's form C (comment 5749154545 on #19123). That is **163 sites on 161 lines in 44 files, covering 40 numbers**. Each rewritten line now cites the commit in `origin/main` history that decided what the line describes, and it says in its own words what that commit decided. No ADR or ruling-record file in `docs/adr/` or `scripts/adr-anchors/` records the decision behind any of the 43 dead numbers in scope. ADR-0104 names #12380 only as a reference, and ADR-0055 states the rule that #8772's ruling enforced, not the ruling itself. So every anchor is a commit: **38 distinct shas**. One number was dropped rather than anchored: #17286, a tracking card that recorded an axis as undecided, under which no commit landed. The sentence keeps its reason in words. Three comment sites in scope are left on purpose (see Acceptance notes). Two are the `[#6259]` marker in `api-derivation.ts:163`, which a test string reads, and the test comment that names that marker. The third is `field.zod.ts:370`, whose `#6111` is objectui's number. Only comments changed. Every source file keeps its line count (174 lines out, 174 in, over 45 files), so no line citation into these files moves. Thirteen of those 174 lines held no dead citation. Eleven are the other half of a sentence that had to be reflowed or rewritten. One is a table header (`value-roundtrip-conformance.ts:20`, 「card」 to 「card or commit」, because its row now holds a commit). One is `api-derivation.ts:164`, which now carries the `[#6259]` sentence's commit. No code token moves (see the guard below). The 41 string-literal sites that carry a dead number are tokens, so they are left as they were and listed below. **No citation number is added.** Every tracker number on an added line was already on the line it replaces. No PR number stands on an added line. Two more kinds of file change, both mechanical: - **One regenerated reference page.** Two of the rewritten docblock lines (`feed.zod.ts:15`, `:18`) project into `content/docs/references/data/feed.mdx`. `check:docs` proved that page stale, and `pnpm --filter @objectstack/spec check:generated --fix` regenerated only it. The diff is two lines, each the same substitution as its source line. No page a held file projects into (`analytics.mdx`, `data-engine.mdx`, `hook.mdx`, `driver-turso.mdx`) moved. - **A `patch` changeset** for `@objectstack/spec` (see Changeset below). ## Census: `data/`, before and after **Instrument.** This is the instrument of stages 1 and 2. It sends REST `GET /repos/objectstack-ai/objectstack/issues/N` without following redirects, for every distinct number cited in `packages/spec/src/data`. The population is: - the citation gate's own exported `CITATION_RE` and `NON_CITATION_HEADS`, kept when the qualifier is none, `objectstack`, `objectstack-ai/objectstack`, `framework`, `pre-` or `post-`; - widened here to the capitalised spellings of those qualifiers (`Pre-`, `POST-`, `Framework`: 7 sites, one of them dead), which stage 2's case-sensitive set did not read; - N of 100 or more, excluding `summon` heads. Each site is classified by the TypeScript parser as a line comment, a docblock, a block comment or a string. **Controls.** The lit controls were `#16862`, `#16847` and `#17698`. The dead controls were `#16714`, `#16715` and `#16697`. They were probed at the start, after every 100 numbers and at the end. They read 24 of 24 lit (200) and 24 of 24 dead (404) over 8 checkpoints in both runs. | reading | tree | numbers probed | 200 | 404 | 301 or other | dead sites, all of `data/` | in scope | excluded (held files) | in-scope lines | in-scope files | dead numbers in scope | |---|---|---|---|---|---|---|---|---|---|---|---| | before | base `9bf5e67af`, probed 2026-09-28T19:32Z to 19:36Z | 618 | 571 | 47 | 0 | **240** | 207 | 33 | 204 | 47 | 43 | | after | head `96fd49caa2`, probed 2026-09-28T23:19Z to 23:23Z | 600 | 571 | 29 | 0 | **77** | 44 | 33 | 43 | 16 | 21 | **Before, in scope, by class.** 92 non-test docblock sites and 13 non-test line comments. 16 test docblock sites and 45 test line comments. 39 test string sites. 2 non-test string sites. **After, in scope.** 41 string sites and 3 comment sites remain, all three deliberate. The head probe found no number newly dead since the base probe: the same 571 numbers answer 200. PR #20226's area table read `data` 239 at an earlier base; this census reads 240 at `9bf5e67af`. The 33 excluded sites sit in `object.zod.ts` (15), `analytics.zod.ts` (3), `analytics-strictness-batchd.test.ts` (2), `analytics-date-range-two-bound-window.test.ts` (1), `driver/turso.zod.ts` (2), `driver/turso.test.ts` (3), `filter-subtree-provenance.ts` (3), `filter-logic-conformance.ts` (3) and `object.form.ts` (1). `data-engine.*` and `hook.form.ts` carry none. ## Per-number table The counts are in-scope sites and files at the base. `rewritten / left` gives comment sites rewritten and sites left. Every anchor was read in its diff or message, not only in its subject: it is the commit that made the change the line now describes, and its own diff or message names the number it replaces. | number | sites / files | rewritten / left | anchor: what it decided | |---|---|---|---| | `#6111` (objectui) | 1/1 | 0/1 | objectui's number, left: see Acceptance notes | | `#6259` | 5/2 | 1/4 | `6968885ef`: retires the producer-less `batch: 'bulk'` row of `DATA_ACTION_TO_API_OPERATION` and the prose calling `batch` a runtime action. The marker and 2 test strings stay (see Acceptance notes) | | `#6345` | 18/5 | 17/1 | `e2798fab7`: one driver vocabulary; both boot hosts read the shared table; `mongo` to `mongodb`; turso a builtin; the fork-1 and fork-2 refusals | | `#6571` | 10/2 | 8/2 | `2f3e79351`: `$between` endpoints accept the ISO/clock strings the platform produces, as a bare string (rider ①) | | `#8495` | 9/2 | 6/3 | `4bfe1a539`: refuses `${…}` placeholders in memory `persistence.path` / `persistence.key` at publish | | `#8656` | 1/1 | 0/1 | a test title only | | `#8696` | 20/8 | 17/3 | `90a12fb18`, the card's mongodb arm: a bound secret rides beside an unmodified url as MongoClient `auth`. Its own pins carry the multi-host form `new URL()` cannot parse and the bound secret outranking `options.auth` | | `#8772` | 3/2 | 3/0 | `75b7c240a`: Direction 2 of the 2026-08-16 maintainer ruling. The builder forces `required: true` on a `master_detail` under `controlled_by_parent`, and raw parse stays tolerant. ADR-0055 stays cited beside it | | `#8778` | 1/1 | 1/0 | `7901b2dd2`: stamp-only `tenancy.organizationField`, declared by `sys_api_key` | | `#8794` | 2/1 | 2/0 | `1850ebbb0`: corrects the reuse-safety claim on the filter-subtree mark from the survey's measurement, and routes a mechanism change to a spec-seat ruling (stage 1's anchor too) | | `#8836` | 2/1 | 2/0 | `1850ebbb0`: the same commit, which pins the invariant (one line carries both numbers) | | `#8873` | 6/3 | 6/0 | `096106522`: a bound `credentialsRef` reaches the postgres server on the DSN branch. Its diff records that `pg` sends a password only when the server asks | | `#8874` | 1/1 | 1/0 | `d70428ae7`: a declared mysql `ssl` reaches `mysql2` as its own TLS options object, because `mysql2` rejects a bare boolean | | `#8876` | 9/5 | 6/3 | `d634e665b`: exports `urlUserinfoUsername`, and its diff states the asymmetry that a username is not credential material | | `#9040` | 20/6 | 14/6 | `24206416a`: refuses a credential in the mongo options passthrough at publish, and redacts the passthrough secret paths on read | | `#9041` | 22/2 | 17/5 | `d491625c1`: refuses a bound `credentialsRef` with a user-less mongo `config.url`, with the triage's fences | | `#10165` | 5/1 | 1/4 | `801296050`: `ttl.onlyWhen` with the canonical null predicate (maintainer ruling 2026-08-20, option A) | | `#10274` | 1/1 | 1/0 | `d1ba685ec`: re-measures the objectui pin citations and gates the class | | `#10329` | 6/2 | 6/0 | `15d58dbf1`: retires the import lookup transform's steering params (ADR-0049) | | `#10347` | 2/1 | 2/0 | `530c1df65`: the Archiver honours a declared `ttl` (maintainer ruling 2026-08-20) | | `#10527` | 2/1 | 1/1 | `5649efbf9`: refuses a diverging retention + ttl + archive triple at parse time | | `#11065` | 7/3 | 5/2 | `20950404c`: a boolean aggregand counts as 1 or 0 in `avg` and `sum`, the first face aligned. No commit message names the card; this is where the number first entered the tree | | `#11195` | 3/1 | 2/1 | `b37231883`: `UserActionsConfigSchema` adopts `group` / `hideFields` / `rowColor` | | `#11215` | 1/1 | 1/0 | `42a117b88`: documents `NoSQLIndexSchema.unique`'s deliberate scope-vocabulary omission | | `#11350` | 1/1 | 1/0 | `ece4dad31`: records the 2026-08-23 maintainer ruling on entry nameability (stage 1's anchor too) | | `#11408` | 2/1 | 1/1 | `f11fc61c5`: declares `editMode` (maintainer ruling 2026-08-24) | | `#11507` | 5/2 | 5/0 | `88b9d749a`: declares `sys_activity.type` an open, author-extensible vocabulary (maintainer ruling 2026-08-24, direction 4) | | `#11658` | 1/1 | 1/0 | `1a6a19c31`: opens `RecordActivityProps.types` to author-contributed kinds | | `#12380` | 4/2 | 4/0 | `4045b954d`: makes the SQLite `Field.json` codec injective; its message carries the measured boundary | | `#12868` | 1/1 | 0/1 | a test title only. Its comment site sits in `object.form.ts`, now held by PR #20519; its deciding commit is `c459da6bc` (see Acceptance notes) | | `#13156` | 1/1 | 1/0 | `fd289be45`: strips tracker ids from function-declaration-built refusal prose (the card's A half) | | `#13644` | 3/2 | 2/1 | `34ce8e7db`: declares `ctx.referentialFieldClear` on `HookContextSchema` | | `#14426` | 2/2 | 1/1 | `40a44b91b`: the undefined-comparand refusal prescribes the null predicate by its ruled spellings, position-safe | | `#14676` | 1/1 | 1/0 | `13c48c2a5`: retires `connector.errorMapping`; its test states the same assertion-set reasoning | | `#16126` | 2/2 | 2/0 | `859ded3ec`: refuses a whitespace-only `reference` on lookup / master_detail | | `#16685` | 4/2 | 4/0 | `ed7243d52`: accepts boolean / toggle for sum / avg / min / max (decision batch #80) | | `#16867` | 3/2 | 2/1 | `0ee32edef`: `notNull` / `not_null` prescribe `storage.notNull`, not `required` | | `#17014` | 3/2 | 2/1 | `80aef8032`: the one-day date-range presets prescribe a one-day window, and the table states its end-token convention | | `#17286` | 1/1 | 1/0 | dropped: a tracking card with no landing. The sentence now says the card is gone and to measure `driver-memory` for the open set | | `#17348` | 1/1 | 1/0 | `51efbf116`: pins the `driver-memory` temporal text-operator divergence by name in that driver's conformance suite | | `#17590` | 1/1 | 1/0 | `e04a0aff2`: `$contains` on a JSON column is a per-dialect membership test (director-seat ruling 2026-09-12) | | `#18012` | 8/3 | 7/1 | `176b03582`: `$between` requires two non-blank endpoints (decision batch #146 item 5, letter A) | | `#19377` | 6/2 | 6/0 | `a60c913de`: refuses a `{ $field }` reference as a `$between` endpoint at the runtime filter door | Every cited sha matches exactly one commit (`git rev-parse --disambiguate`, count 1), and every one is an ancestor of the base (`merge-base --is-ancestor`, exit 0). That is 38 distinct shas. Wordings to check, each true of its commit: - `datasource.zod.ts:352` names only the card's mongo arm (`90a12fb18`) for "the defect class … closed", because the paragraph is about mongo. The card's mysql arm (`72050cc47`) is not cited anywhere in this stage. - `datasource.zod.ts:354`: 「the triage's, as commit d491625 landed them」. `d491625c1`'s message lists the fences as "per triage". - `filter.zod.ts:1021-1025`: the `#17286` pointer becomes 「was measured on a tracking card … That card is gone: measure `driver-memory` for the open set, ⛔ not this text.」 The warning that this paragraph is not the authority is kept. ## The 41 string sites left as tokens - **Test titles and test-code strings (39 sites).** `driver/driver-credential-refusal.test.ts` 14, `object.test.ts` 6, `datasource-credential-redaction.test.ts` 3, `driver/driver-placeholder-refusal.test.ts` 3, `filter.test.ts` 3, `api-derivation.test.ts` 2 (the `split('[#6259]')` literal and its message), `field.test.ts` 2, and 1 each in `date-range-presets.test.ts`, `driver/postgres.test.ts`, `field-rows-option-description.test.ts`, `filter-comparand-type.test.ts`, `hook.test.ts` and `object-strictness-batch20.test.ts`. - **Non-test strings (2 sites).** `aggregation-conformance.ts:398` and `:407`, the `note` of two exported `AGGREGATION_CASES` rows (`#11065`, `#11151`). They ship as data. Their only readers are driver conformance suites, which print a `note` as the assertion message when a case fails, to a driver developer and never to a metadata author. So they are neither comments nor form D author-shown text. This is the same disposition stage 1 gave the two `why` strings and stage 2 the `PROVENANCE_WAIVERS` reason. No author-shown text in `data/` carries a dead number, so nothing here is #20233's form D. ## Mechanical guard: no code token moves The check compares leaf tokens with comments stripped, base `9bf5e67af` against head `96fd49caa2`. It uses the TypeScript parser's leaf tokens, so template literals are scanned in context, and it excludes JSDoc nodes. It ran over all 45 touched `.ts` files. - Real run: 140,379 base tokens, **0 files with a token change** (exit 0). - Comment-insertion control: 0 files changed, as expected (exit 0). - Positive control (a declaration inserted into `feed.zod.ts`): 1 file reads DIFFER (exit 1). - Positive control (one digit changed inside the `split('[#6259]')` string in `api-derivation.test.ts`): 1 file reads DIFFER (exit 1). ## Changeset This change ships bytes, so a `patch` changeset for `@objectstack/spec` is included. It says only that the provenance comments were re-anchored. Measured on the built package: 14 of the touched sources are `src/**/*.zod.ts`, which `files[]` ships verbatim. The rewritten docblocks also reach `dist`. `88b9d749a`, `e2798fab7` and `24206416a` each appear in 1 declaration file. `24206416a` appears in 20 bundled `.js` files and `2f3e79351` in 28. The positive control, a pre-existing `feed.zod.ts` docblock sentence, appears in `dist/data/index.d.ts`. ## Gates (head `96fd49caa2`) - **Citation judging pass, run as CI runs it:** `pnpm check:issue-citations && node scripts/check-issue-citations.mjs` exits 0. The self-test passes 73 cases in 7 batteries. The live run judged 11 citations across 25 files, and all 11 resolve. - **Doc authoring:** `pnpm check:doc-authoring` exits 0. - **Derived gates:** `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` at the final head derived 108 families, and all 108 exit 0. `--ran` reports 108 run, 0 NOT MEASURED, 0 unrun, and exits 0. (`check:i18n` was derived at the earlier heads from `object.form.ts`, and left the set when that file went back to base.) - At an earlier head, four gates first exited 3 (PREREQUISITE NOT MET) because the workspace was unbuilt: `check:doc-formula-expressions`, `check:doc-security-posture`, `check:skill-examples` and `check:docs-transcript-drift`. At the final head a full `turbo run build` of `./packages/*` ran first (71 tasks, exit 0, under the shared verify lock), and every gate exited 0 on its first run. - `check:generated` was run under the lock against that build: all 15 artifacts are up to date. - **Build, tests, typecheck and lint:** - `pnpm --filter @objectstack/spec build` exits 0. - `vitest run --maxWorkers=2 src/data` in `packages/spec` at the final head: 107 files and 3,517 tests pass (1 todo), covering every touched test file. - The 12 spec suites outside `src/data` that read `data/` source text pass at the final head: 12 files, 503 tests. These are `scripts/{file-description,root-index,skill-map-guards,strictness-ledger}.test.ts`, `src/api/api-entry-graph.pin.test.ts`, `src/contracts/scoped-context.test.ts`, `src/shared/{alias-integrity,evaluated-slot-population,retired-key-migrate-sentence}.test.ts`, `src/system/constants/platform-object-names.test.ts`, `src/type-alias-convention.pin.test.ts` and `src/ui/dashboard.test.ts`. - `pnpm --filter @objectstack/spec typecheck` at the final head exits 0, including `check:test-typecheck` (53 files, 251 errors, 138 pinned signatures held). - Lint, as a proven narrowing at the final head: `eslint --no-inline-config --format json` over the 45 touched `.ts` files gives 45 files, 0 errors and 0 warnings. All 45 are in eslint's own population (`isPathIgnored` is false for each). `eslint.config.mjs` never enables type-aware linting (no `parserOptions.project`, which its own line 328 states), so a comment edit here cannot move the verdict on any untouched file. The repo-wide `pnpm lint` is CI's run. ## Acceptance notes - **The `[#6259]` marker.** `api-derivation.test.ts:236` splits `DATA_ACTION_TO_API_OPERATION`'s TSDoc on the literal `[#6259]`, and a test string may not change here. So the marker line `api-derivation.ts:163` is byte-identical to the base, and the test comment at `:232` that names the marker stays too. The sentence's deciding commit sits on the next line instead: 「(both by commit 6968885)」. A first attempt wrote the commit onto the marker line itself. The diff-scoped `check-issue-citations` then read the kept `#6259` as an added citation and exited 1, so it was moved one line down (commit `b93f08f8d0`). - **objectui's `#6111`.** `field.zod.ts:370` reads 「objectui#6110 + #6111 (section)」. The qualifier covers only the first number, so the citation grammar reads `#6111` as this repository's (404 here). It is objectui's number: its introducing commit `f887e5249` writes `(objectui#6111)` in the same diff, and `objectstack-ai/objectui` answers REST 200 for #6111 to this session (and for #6110 and #10264). objectui has no `refs/pull/6111/head`, so it is an issue there, not a PR. The line is left unchanged. This is #20330's grammar family, the same as stage 2's `objectui PR #10264`, and it is noted there, not filed. - **Capitalised qualifiers.** `CITATION_RE` classes `Pre-#N`, `POST-#N` and `Framework#N` (7 sites in `data/`) as cross-repo and never judges them. This census read them as this repository's. One was dead and is rewritten here (`object.test.ts:223`, `POST-#10347`). This is the same #20330 family as stage 1's `pre-` / `post-` finding. - **Four files held after the claim.** Each joined the exclusions and went back to the base bytes (hypothesis 2 of the dispatch). Each PR's hunks were disjoint from this PR's lines, but the dispatch's rule is file-level. - `driver/turso.test.ts`: PR #20504 (#20437's) opened at 2026-09-28T20:08Z and edits it. Its two comment sites (`:4`, `:58`, both `#6345`) went back to blob `7fe99ebf9` in commit `86463ed0a1`. A no-driver `merge-tree` of that head with PR #20504's head `5dfa45e9f` exits 0. - `object.form.ts`: PR #20519 (#20432's) opened at 21:55Z and edits it. Its one comment site (`:256`, `#12868`, whose deciding commit is `c459da6bc`) went back to blob `60713e06f` in commit `3479600dda`. - `object.zod.ts`: PR #20521 (#20494's) opened at 22:10Z and edits one line at `:2123`. Its 15 comment sites (`#8772`, `#10165`, `#10347`, `#10527`, `#11195`, `#11408`, `#13608`) went back to blob `befde04ca` in commit `96fd49caa2`. Their deciding commits are `75b7c240a`, `801296050`, `530c1df65`, `5649efbf9`, `b37231883`, `f11fc61c5` and `fc9ba76a5`, all read for this stage. - `filter-logic-conformance.ts`: PR #20523 (#20444's) opened at 22:39Z. Its 3 comment sites (`#13195`) went back to blob `c9b32acba` in the same commit. Their deciding commit is `9dac1ae01`, with `PR #13529` as the link. - **What stays for later stages.** - The 33 dead sites in the held files listed above. The later stage can reuse the deciding commits named for them here. - The 41 string sites and the 3 deliberate comment sites above. - The `data/` numbers that also appear in `packages/spec/src/migrations/**`. Those are #20233's form D, or the migrations stage. - **The rung.** Several anchored changes also have ADR-0087 entries in `packages/spec/src/migrations`. Examples are `cbp-master-detail-required-forced` for #8772, `filter-between-blank-endpoint-refused` for #18012, the `datasource-*` entries for #9040, #9041 and #8873, and the `mapping-lookup-params-removed` conversion for #10329. This PR takes the commit rung, as stages 1 and 2 did, so it is precedent-consistent. The D3 id is the more durable in-repo record, if the ruling's first rung is later read to include those entries. - **The citation gate's reach.** It defers `packages/**/*.test.ts`, so 20 of the 45 touched `.ts` files never enter its judging population. The added-minus-removed count over the whole diff covers them: 0 numbers added. - **Base.** The branch is 22 commits behind `origin/main` (`1378ec7c0c`, read at 2026-09-29T00:18Z). Four of those commits touch `data/`, all in excluded files: #20475's `hook.form.ts`, #20487's `data-engine.*`, and, since this stage excluded them, PR #20521's `object.zod.ts` (`9e1689f8e2`) and #20444's `filter-logic-conformance.ts` (`fb386074f5`). None touches a file in this diff, and a no-driver `merge-tree` of the head onto `1378ec7c0c` exits 0. So there was no merge. The open-PR file lists were re-read at 00:18Z: 11 open PRs, none touching a file in this diff. --- _Generated by [Claude Code](https://claude.ai/code/session_014EJ1ED8X4MMrT18BhVx4tx)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent 6427e2c commit 03b19d9

47 files changed

Lines changed: 187 additions & 176 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
---
2+
'@objectstack/spec': patch
3+
---
4+
5+
Provenance comments in `data/` were re-anchored
6+
7+
Comment and docblock lines under `src/data` (all but the files other open work
8+
holds) that cited tracker numbers which no longer resolve on GitHub now cite
9+
the commit in this repository's history that decided the matter, and say in
10+
their own words what was decided. Comments only: no type, schema, export or
11+
runtime behaviour changes.

‎content/docs/references/data/feed.mdx‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,10 +15,10 @@ enums here configure the record activity component (`RecordActivityProps` in
1515
`FeedItemType` is not backend-free: it has no backend *import*, yet it is the
1616
TARGET of the map UI consumers apply to the `sys_activity.type` column — a
1717
backend *coupling* — and that column's vocabulary is OPEN and
18-
author-extensible (maintainer ruling 2026-08-24, #11507). `FeedItemType` is
18+
author-extensible (maintainer ruling 2026-08-24, commit 88b9d749a). `FeedItemType` is
1919
therefore the built-in guidance half of that map, never the value domain of
2020
an authoring surface: `RecordActivityProps.types` accepts contributed kinds
21-
beyond it (#11658), and consumers must map unknown `sys_activity.type` values
21+
beyond it (commit 1a6a19c31), and consumers must map unknown `sys_activity.type` values
2222
to a fallback rather than drop them. `SYS_ACTIVITY_BUILTIN_TYPES` below is
2323
the published built-in vocabulary of the `sys_activity.type` column,
2424
co-located with `FeedItemType` because UI consumers map one onto the other.

‎packages/spec/src/data/aggregate-field-type-compatibility.test.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
* conformance suite — every boolean case `AGGREGATION_CASES` requires a
1515
* backend to ANSWER (#11152) must be a pair this table accepts, so the two
1616
* tables in this package cannot contradict each other on the boolean axis
17-
* (#16685) — the cross-pin reaches exactly as far as the `flag` cases.
17+
* (commit ed7243d52) — the cross-pin reaches exactly as far as the `flag` cases.
1818
*/
1919

2020
import { describe, it, expect } from 'vitest';
@@ -140,7 +140,7 @@ describe('isAggregateCompatibleWithFieldType — the pairs the card is about', (
140140
// `AGGREGATION_ROWS.flag` is the boolean aggregand (declared `type:
141141
// 'boolean'` by every harness); each case over it is a pair #11152 pins
142142
// on six backends. A table refusing one of them would refuse a pair the
143-
// spec elsewhere REQUIRES an answer to (#16685).
143+
// spec elsewhere REQUIRES an answer to (commit ed7243d52).
144144
const booleanCases = AGGREGATION_CASES.filter((c) => c.field === 'flag');
145145
expect(sorted(new Set(booleanCases.map((c) => c.function)))).toEqual(sorted(AggregationFunction.options));
146146
for (const c of booleanCases) {

‎packages/spec/src/data/aggregate-field-type-compatibility.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* Aggregate × field-type compatibility — the ONE table saying which
55
* `AggregationFunction` may be applied to a field of which `FieldType`
66
* (#16353; director ruling, decision batch #59, 2026-09-06: "both legs, table
7-
* in spec"; the boolean rows by decision batch #80, 2026-09-08, #16685 — see
7+
* in spec"; the boolean rows by decision batch #80, 2026-09-08, commit ed7243d52 — see
88
* below). A `DatasetMeasure` pairs an `aggregate` with a `field`; this
99
* table is the contract both consumer legs execute — the compile-time refusal
1010
* in the dataset compiler (#16099) and the authoring-time lint rule — so the
@@ -65,11 +65,11 @@
6565
* aggregand to `int` on Postgres so that the one dialect storing a real
6666
* `boolean` column answers the same numbers (#11635). Batch #59's "every
6767
* other pair: refused" never named booleans — it was a blanket default —
68-
* and the director ruling of decision batch #80 (2026-09-08, #16685,
68+
* and the director ruling of decision batch #80 (2026-09-08, commit ed7243d52,
6969
* maintainer verbatim 「其他同意」, option A) holds that the specific ruling
7070
* #11152 stands over that default: the four rows carry both members and
7171
* nothing else moves. `avg(flag)` is the win-rate / SLA-violation-rate
72-
* shape (#11065) — the reason `AGGREGATION_CASES` exists — so a table that
72+
* shape (commit 20950404c) — the reason `AGGREGATION_CASES` exists — so a table that
7373
* refused it would refuse a pair every backend is REQUIRED to answer.
7474
* - **everything else** — the text family, option types, references, files,
7575
* structured JSON, `vector`, and the computed `formula` / `autonumber` — is

‎packages/spec/src/data/aggregation-conformance.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@
5959
* verbatim 「12745 A回,其他同意。」, superseding #11249's `false`/`true`)
6060
* pins that **booleans aggregate as numbers on every face, with no
6161
* per-aggregate exception** — `min(flag)`/`max(flag)` answer `0`/`1`, the
62-
* same numeric domain `sum`/`avg` already answer in (#11065). So a boolean
62+
* same numeric domain `sum`/`avg` already answer in (commit 20950404c). So a boolean
6363
* aggregand takes NO boolean read-presentation on any face, and
6464
* {@link AggregationExpectation.value} stays a `number` for every case.
6565
*
@@ -224,7 +224,7 @@ export interface AggregationRow {
224224
/**
225225
* [#11152] The non-null BOOLEAN aggregand — 3 true / 3 false, so `sum` and
226226
* `avg` cannot agree with a face that dropped the booleans (`0` / `null`,
227-
* the #11065/#11151 defect) or that counted rows instead of trues.
227+
* the commit 20950404c / #11151 defect) or that counted rows instead of trues.
228228
*
229229
* The distribution is the `FLAG_BY_ID` the #11635 suite landed, adopted here
230230
* verbatim so the two never disagree on grouped values: `west` holds
@@ -383,7 +383,7 @@ export const AGGREGATION_CASES: readonly AggregationCase[] = [
383383
// ── [#11152] the boolean aggregand: numbers on every face, by ruling ──────
384384
//
385385
// The whole vocabulary over `flag` (3 true / 3 false). Two rulings pin the
386-
// values: #11065 settled `sum`/`avg` (a boolean is an aggregand worth 1 or
386+
// values: commit 20950404c settled `sum`/`avg` (a boolean is an aggregand worth 1 or
387387
// 0 — driver-memory answered `0`/`null` while SQLite answered `2`/`0.4`,
388388
// found from an application because no conformance cell could see it), and
389389
// #11152 (maintainer 2026-08-28, superseding #11249's `false`/`true`)

‎packages/spec/src/data/api-derivation.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -203,7 +203,7 @@ describe('api-derivation (#3391)', () => {
203203
expect(DATA_ACTION_TO_API_OPERATION.bulk).toBe('bulk');
204204
});
205205

206-
// [#6259] `batch: 'bulk'` was a producer-less row: `callData` has had no
206+
// [commit 6968885ef] `batch: 'bulk'` was a producer-less row: `callData` has had no
207207
// `batch` arm since #5856, and REST gates `/batch` on the literal `'bulk'`.
208208
// Two pins, because the finding had two halves — the row AND the prose
209209
// that told readers `batch` was a live runtime action.

‎packages/spec/src/data/api-derivation.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -161,7 +161,7 @@ export const API_METHOD_DERIVATION: Record<LegacyApiMethod, DerivationRule> = {
161161
* `apiMethods`).
162162
*
163163
* [#6259] The `batch: 'bulk'` row was removed, and the line above no longer
164-
* calls `batch` a runtime `callData` action. It was the one entry with no
164+
* calls `batch` a runtime `callData` action (both by commit 6968885ef). It was the one entry with no
165165
* producer on either side: `callData` branches on a closed set that has not
166166
* contained `batch` since that arm was retired (#5856), and every REST caller
167167
* of `apiAccessDenialFromEnable` passes a canonical literal — including the

‎packages/spec/src/data/api-methods-batch-conformance.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,7 @@ const SINGLE_RECORD_WRITE_ONLY: Record<string, string> = {
9595
// `00d3f09c5` is the one that caught the previous record's OWN grid anchor as
9696
// wrong rather than merely shifted: `3790-3805` there is
9797
// `runBulkActionAggregate` and says nothing about selection. That is the
98-
// #10274 class, and the reason a citation refresh re-READS instead of moving
98+
// class commit d1ba685ec gates, and the reason a citation refresh re-READS instead of moving
9999
// numbers — arithmetic on a wrong anchor produces a fresh-looking span still
100100
// describing the wrong function. The second claim,
101101
// `hooks/useBulkExecutor.ts:298-303`, sits in a file that is byte-identical

‎packages/spec/src/data/datasource-credential-redaction.test.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -233,7 +233,7 @@ describe('write-door alignment: redactUrlPassword removes exactly what urlUserin
233233
// `urlUserinfoUsername` shares the password half's boundary parse by
234234
// construction; this pins the redactor to the same grammar from the other
235235
// side: stripping the password must never move or rewrite the username the
236-
// #8696 injection path will read off the redacted/stored row.
236+
// commit 90a12fb18's injection path will read off the redacted/stored row.
237237
for (const url of [...CARRYING, ...CREDENTIAL_FREE]) {
238238
expect(urlUserinfoUsername(redactUrlPassword(url)), url).toBe(urlUserinfoUsername(url));
239239
}
@@ -412,7 +412,7 @@ describe('passthrough secret redaction (#9040) — the nested spellings the key-
412412
keyVaultNamespace: 'encryption.__keyVault',
413413
kmsProviders: {
414414
// The identity halves the client also reads are NOT credential
415-
// material (#8876's asymmetry) and stay served.
415+
// material (commit d634e665b's asymmetry) and stay served.
416416
aws: { accessKeyId: 'AKIAFAKEFAKEFAKEFAKE' },
417417
azure: { tenantId: 'tenant-id', clientId: 'client-id' },
418418
gcp: { email: 'svc@example.iam.gserviceaccount.com' },

‎packages/spec/src/data/datasource-credential-redaction.ts‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -134,7 +134,7 @@ const STILL_WRITABLE_CREDENTIAL_KEYS: Record<string, readonly string[]> = {
134134

135135
/**
136136
* Secret-bearing paths inside a driver's passthrough `config` slot — the
137-
* FOURTH spelling of the stored credential (#9040).
137+
* FOURTH spelling of the stored credential (commit 24206416a).
138138
*
139139
* Since the nested-position finding this table is a RESIDUE, not the nested
140140
* judgment: the credential-name scrub runs at every object depth (see
@@ -150,16 +150,16 @@ const STILL_WRITABLE_CREDENTIAL_KEYS: Record<string, readonly string[]> = {
150150
* Only mongo declares a passthrough today (`options`, spread verbatim into
151151
* `MongoClientOptions`); postgres/mysql/turso/sqlite/memory have closed
152152
* strict-object contracts with no client-bound record slot (measured for
153-
* #9040 — memory's `initialData` is seed DATA, deliberately not judged here:
153+
* commit 24206416a — memory's `initialData` is seed DATA, deliberately not judged here:
154154
* redacting a seeded row's own `password` FIELD would corrupt data the driver
155155
* serves, which is not this module's question). Every path is measured against
156156
* `mongodb@7.5.0`, the client the driver spreads `options` into:
157157
*
158158
* - `options.auth.password` — resolved into `MongoCredentials`; the login
159159
* secret itself, and the one path the WRITE door also refuses
160-
* (`MONGO_OPTIONS_CREDENTIAL_PATHS` in `driver/common.zod.ts`; #8696
160+
* (`MONGO_OPTIONS_CREDENTIAL_PATHS` in `driver/common.zod.ts`; commit 90a12fb18
161161
* measured a bound secret outranking it at connect). `auth.username` is
162-
* deliberately not here — a username is not credential material (#8876).
162+
* deliberately not here — a username is not credential material (commit d634e665b).
163163
* - `options.proxyPassword` — SOCKS5 proxy password, honoured
164164
* (`c.options.proxyPassword`, measured).
165165
* - `options.tlsCertificateKeyFilePassword`, `options.key`,
@@ -189,7 +189,7 @@ const STILL_WRITABLE_CREDENTIAL_KEYS: Record<string, readonly string[]> = {
189189
* one slot is the login password, the proxyPassword posture — but never
190190
* SERVED. The same families' identity halves (`aws.accessKeyId`,
191191
* `azure.tenantId` / `clientId`, `gcp.email`) are read by the client too
192-
* but are not credential material (#8876's asymmetry), and the unmeasured
192+
* but are not credential material (commit d634e665b's asymmetry), and the unmeasured
193193
* neighbours (`kmip.endpoint`, `keyVaultNamespace`, `schemaMap`) mirror no
194194
* credential spelling — deliberately not here: entries land on this table
195195
* with a measurement quoted, never by name-shape.
@@ -218,7 +218,7 @@ const PASSTHROUGH_SECRET_PATHS: Readonly<Record<string, readonly (readonly strin
218218
* The nested config paths this module hides for `driver`, dotted-path-ready —
219219
* the passthrough sibling of {@link redactableConfigKeys}, exported so the
220220
* write-path inverse (`service-datasource`'s `restoreRedactedConfig`) mirrors
221-
* exactly the set the read path hides (#9040): a nested redaction the restore
221+
* exactly the set the read path hides (commit 24206416a): a nested redaction the restore
222222
* side did not mirror would turn an untouched "Save" on an affected legacy row
223223
* into silent credential deletion.
224224
*/
@@ -229,7 +229,7 @@ export function passthroughSecretPaths(driver: unknown): readonly (readonly stri
229229

230230
/**
231231
* The config-relative subset of {@link passthroughSecretPaths} the WRITE door
232-
* also refuses (#9040) — today `options.auth.password` on mongo, projected
232+
* also refuses (commit 24206416a) — today `options.auth.password` on mongo, projected
233233
* from the write door's own closed list (`MONGO_OPTIONS_CREDENTIAL_PATHS`) so
234234
* the two doors cannot drift. What the credential-migration planner consults:
235235
* a stored row carrying one of these holds a LIVE login credential the binder
@@ -492,7 +492,7 @@ export interface RedactedDatasourceConfig {
492492
* shapes inside a driver contract whose leaf is `z.never()`. None exist
493493
* today; the walk is what keeps "reading the schema is reading the
494494
* refusal list" true at depth the day one lands.
495-
* 4. The passthrough spellings (#9040, {@link passthroughSecretPaths}): the
495+
* 4. The passthrough spellings (commit 24206416a, {@link passthroughSecretPaths}): the
496496
* CLIENT-MEASURED secret names (`proxyPassword`, `key`, `passphrase`, …)
497497
* that mirror no top-level key, so neither the schema nor the name set can
498498
* derive them. The table is the residue for exactly that class — an entry

0 commit comments

Comments
 (0)