Skip to content

Commit 4bf4e7e

Browse files
docs(objectql): re-anchor the dead tracker citations to the commits and ADRs that decided them (stage 3 of #20595) (#21268)
Part of #20595 Clause-②: no ## What changed Stage 3 of the `domain:engine` lane of the dead-citation sweep: `packages/objectql/**`, comment and docblock prose only, per the claim (`5941871762`). Stages 1 and 2 (`packages/metadata-protocol`) landed as `a7d9768ec` and `d150c3039`; #20595 stays open for the next stage (`driver-sql`). Every comment or docblock site in the package that cited a tracker number answering 404 is rewritten in ruling C+D's form C (record `5749154545` on #19123): the ADR when one records the decision, otherwise the commit in this repository's history that made it. That is **279 sites on 275 lines in 67 files, covering 70 numbers**: - **136 census sites** (136 lines, 17 files under `src/`): the whole `allocated-but-absent` population of the gate's own census in this package at the base, the slash-joined `plugin.ts` `#10629` from the post-landing census (`5923084795`, now at `:1543`) included; - **1 site in `vitest.config.ts`** (`:61`, `#17853`): outside the census glob, inside the claimed surface; - **142 test-comment sites** (138 lines, 49 test files), which the census defers. They carry 51 numbers: the census itself reads 36 of them as dead elsewhere in the repository, and never judges the other 15 (they stand only in test files here), which the board and a single read each settle. **Anchors: 66 numbers by commit, 4 by ADR, 0 by words alone.** 45 numbers reuse the anchor another lane or stage already measured for them, 23 were measured here, and 2 are split between a reused and a measured commit (see the table). Two depart from another lane's anchor for a stated reason (`#10629`, `#10243`, under Wordings to check). Only comments changed. Every file keeps its line count (275 lines out, 275 in, plus the changeset), so no line citation into any of them moves. No code token moves (the guard below). **No citation number is added**: on every changed line, the numbers on the new text are a subset of those on the old, and the diff-scoped gate judged the 14 citations left on changed lines: 13 resolve and 1 is a declared cross-repo reference. **A `patch` changeset**: 54 of the 137 rewritten non-test lines are in the published `dist` (the `.d.ts` keeps JSDoc on exported members, and esbuild keeps some comments in the JS), and `dist` is not byte-identical with the base text (see Changeset). ## Census: `objectql`, before and after **Instrument (A1).** The gate's own `node scripts/check-issue-citations.mjs --census --json`, read-only and unchanged. The count is its `allocated-but-absent` findings under `packages/objectql/`. | reading | tree | board | whole-repo `allocated-but-absent` | sites | lines | files | numbers | |---|---|---|---|---|---|---|---| | before | base `4727fcb22`, run 22:38:04Z to 22:41:42Z | enumerated, 191 pages, frontier #21252, 19,073 records (newest number read before and after the run: #21252) | 592 | **136** | 136 | 17 | 50 | | after | `8d6465457`, run 23:19:32Z to 23:22:54Z | enumerated, 191 pages, frontier #21261, 19,082 records (newest before and after: #21261) | 456 | **0** | 0 | 0 | 0 | The whole-repo drop is 136, and the two finding sets differ by exactly the 136 rows of this package, removed; none was added. `resolves` (34,638), `resolves-as-pull-request` (2,095) and `cross-repo-unjudged` (1,144) did not move. The card's 135 was taken at `f11b5f20a2` with the older extractor; the base here reads 136, the difference being `plugin.ts` `#10629`. The same census at the first base `d150c3039` (before a fast-forward to `4727fcb22`, which touched no `objectql` file) read the identical 136 rows. The head's only later commit is a merge of `main` that touches no file under `packages/objectql` (`git diff 8d64654 1e08958 -- packages/objectql` is empty). **Supplementary instrument, the whole package.** The census reads neither test files nor strings nor files outside `src`. A second reading runs the gate's own exported `extractCitations` (whole-file and comment-prose projections) and `namesThisRepository` over every tracked file in the package (430 `.ts`, 6 `.json`, 2 `.md`, `LICENSE`), and classifies each citation with the gate's `classifyCitation` against one board enumerated by the gate's `enumerateBoard` (191 pages, frontier #21252, 19,073 records, 22:43:50Z). Every one of the 70 numbers in the population was then read on its own over the issues endpoint: **all 70 answer 404**, and the lit controls `#5286` and `#12624` answer 200. | reading | citations | dead | src comment | test comment | test string | changelog | |---|---|---|---|---|---|---| | before, `4727fcb22` | 9,338 | **388** | 137 | 142 | 43 | 66 | | after, head | 9,059 | **109** | 0 | 0 | 43 | 66 | `src comment` includes `vitest.config.ts`. The drop of 279 citations is exactly the rewritten sites, and the live counts did not move (non-test comment: 2,971 resolve, 80 as pull requests; test comment: 2,700 and 122). A third, raw reading (every `#` followed by 2 to 6 digits, whatever surrounds it) counts 9,504 before and 9,225 after: the same drop of 279. **Comment ids.** Six distinct comment-id citations stand on 11 lines in this package (`5237739551`, `5434929046`, `5791803339`, `5805782503`, `5865053231`, `5865693155`). Each was read over the issue-comments endpoint and each answers 200 (control `5941871762`, 200), so none is in the population. ## Per-number table `src` counts census sites (plus `vitest.config.ts` for `#17853`), `test` counts test-comment sites. Every sha below matches exactly one commit (`git rev-parse --disambiguate`, count 1) and is an ancestor of the base (`git merge-base --is-ancestor`, exit 0 for all 67 shas; the clone is not shallow, 15,432 commits at the base). The message or the diff of each one names the number it replaces, with one exception, `#10629`, explained under Wordings to check. Where a sentence credits a ruling, a measurement or a note to the number, the anchor's own message or diff carries it (checked per site; the ones that needed a reworded sentence are listed below). `source` says whether another lane or stage already used this anchor for this number (`reused`) or it was measured here (`measured`). | number | src | test | anchor | kind | source | what it decided | |---|---|---|---|---|---|---| | `#6037` | 2 | 1 | `18189983d` | commit | reused | validate-only data operation — DataProtocol.validateData | | `#6083` | 3 | 2 | `53068c130` | commit | reused | ADR-0122 phase 2 — flip bare names to parsed semantics | | `#6241` | 0 | 1 | `83a3b1f2e` | commit | reused | normalize the `:type` segment once per handler so the plural spelling cannot skip the §6.7 audience gate | | `#6300` | 5 | 4 | `74155c735` | commit | reused | IDataEngine.find/findOne accept the author state — engine fills SortNode.order's declared default | | `#6311` | 0 | 1 | `59b794f71` | commit | measured | narrow `HookContext.api` from `z.unknown()` to the minimal `IScopedContext` | | `#6478` | 0 | 1 | `474f131cf` | commit | reused | roll `flow`'s `allowOrgOverride` back to `false` per ADR-0005's original call, the write path refusing loudly | | `#6483` | 0 | 9 | `ee58392e1` | commit | reused | enforce the ADR-0005 whitelist: nine unratified `allowOrgOverride: true` flags rolled back to `false` (its message records the 2026-08-08 ruling) | | `#6573` | 5 | 6 | `708431313` | commit | measured | `registerHook` refuses an empty `object` target and a self-cancelling scope | | `#6723` | 0 | 4 | `8ad609c69` | commit | reused | declare what IMetadataService.getObject answers with | | `#6725` | 3 | 7 | `1507ba356` | commit | reused | MetadataFacade object writes now reach the map its reads use | | `#6745` | 0 | 4 | `7a5ef0008` | commit | reused | pin getObject(n) = get('object', n) across all three IMetadataService implementations | | `#8454` | 1 | 0 | `427344c26` | commit | measured | the object catalog loses to an explicitly-set scalar | | `#8460` | 7 | 0 | ADR-0029 D9.2a | ADR | reused | ADR-0029 D9.2a, the 2026-08-13 amendment: an extender's scalar yields to a diverged base (it names the number; executed as `01a7337fc`) | | `#8648` | 1 | 4 | `e5eeb499c` | commit | reused | pin the SEARCH-axis remedy agreement, and correct the three comments that claimed word-identity | | `#8672` | 6 | 4 | `ff08691e6` | commit | measured | a system-context insert resolves the install's organization, or is refused — the runtime producer of the autonumber fork | | `#8818` | 0 | 1 | `fd6bdf89f` | commit | reused | saveMetaItem's missing-item refusal declares 400 INVALID_REQUEST instead of answering 500 | | `#8823` | 10 | 4 | `4dfa369a9` | commit | measured | drop the caller value MySQL inlines in its duplicate-entry diagnostic | | `#9030` | 2 | 1 | `27a567dd8` | commit | measured | teach the internal-leak predicate MySQL's three error templates | | `#10062` | 2 | 0 | `fa5d137ab` | commit | reused | gate undeclared workspace imports in published src | | `#10091` | 1 | 0 | `da891e0ef` | commit | reused | gate sys_attachment beforeUpdate with the uploader-or-parent-editor rule | | `#10165` | 2 | 1 | `801296050` | commit | reused | lifecycle ttl.onlyWhen row filter with the canonical null predicate | | `#10194` | 0 | 3 | `2306a765c` | commit | reused | validate theme / analytics_cube at the /meta write door via UNREGISTERED_KIND_SCHEMAS | | `#10243` | 1 | 1 | ADR-0126 §7.2 | ADR | measured | ADR-0126 §7.2: the durable ledger row replaces the process-local `flowEnabled` map, retiring the env-wide toggle leak's mechanism (it names the number) | | `#10290` | 4 | 1 | `2570ab05c` | commit | measured | the primary key is never a `__search` companion source | | `#10347` | 5 | 3 | `530c1df65` | commit | reused | the Archiver honours a declared `ttl` instead of archiving by `created_at` age alone | | `#10485` | 0 | 2 | `35ad101bc` | commit | reused | retire the `themes` carrier key and ThemeSchema — `app.branding` is the one colour surface | | `#10527` | 1 | 0 | `5649efbf9` | commit | reused | refuse a diverging retention + ttl + archive lifecycle triple at parse time | | `#10528` | 4 | 1 | `7d483e1e5` | commit | measured | the Archiver resolves its window through P4 governance | | `#10629` | 1 | 2 | `199ec4712` | commit | measured | bind federated objects whatever the boot order, and report what could not be bound | | `#10643` | 1 | 0 | `5649efbf9` | commit | measured | refuse a diverging retention + ttl + archive lifecycle triple at parse time | | `#10729` | 1 | 1 | `10485009a` | commit | measured | log a contributed kind by its declared `id` | | `#11065` | 1 | 0 | `20950404c` | commit | reused | count a boolean aggregand as 1/0 in avg and sum | | `#11311` | 1 | 0 | `1272f0a6b` | commit | reused | promote resolveRecordOrganizationField to the shared platform-row resolver: approvals and automation runs stamp the subject record's organization | | `#11427` | 5 | 0 | `c3c72a4bc` | commit | reused | hydrate a tombstoned sys_file that still has a live holder | | `#11674` | 0 | 4 | `9a884c6e4` + `1cba33f16` | commit | reused | seed pass 2 writes back by the internal id captured at insert time, healing keyless datasets / warn at load time when a seed defers a required column, and document the ordering constraint at the four pointer-pair sites | | `#12194` | 0 | 2 | `311433f6b` | commit | reused | Declare the metadata item-name grammar in spec and refuse it loudly at the publish door | | `#13178` | 2 | 1 | `f087c376f` + `e49d98896` | commit | reused+measured | scope the sys_file / sys_upload_session update and delete doors to the acting organization / cut the tenant-audit control's scope by the object's tenancy, not the caller's flag | | `#13197` | 5 | 11 | `56c093c4d` | commit | reused | enforce field-level `unique` so a colliding write is refused, not landed | | `#13273` | 1 | 4 | `3a86a65e7` | commit | reused | pick the `find` failure log level from the cause — "the table is not provisioned yet" is not "the read failed" | | `#13644` | 3 | 2 | `34ce8e7db` | commit | reused | declare ctx.referentialFieldClear on HookContextSchema, populate every set_null cleanup write, and carry it across the QuickJS sandbox boundary | | `#13657` | 4 | 4 | `b003cf2e8` | commit | reused | Refuse an undeclared field a before-hook writes — the post-hook half of the declared-field door, one envelope on every driver | | `#14163` | 0 | 1 | ADR-0130 D3 + `1dcb995f2` | ADR | measured | ADR-0130 D3: the gate relaxation and the object-name uniqueness check are one change; `1dcb995f2` landed it, and its changeset names the number | | `#14345` | 0 | 1 | `e89fa9233` | commit | measured | declare aggregate? on IDataDriver with the signature the engine calls | | `#14390` | 6 | 1 | `9d7f7259f` | commit | reused | `update` answers a driver unique violation with the `DUPLICATE_RECORD` envelope, on every driver | | `#14399` | 3 | 8 | `3c1bbd2a8` | commit | measured | derive a view container's object through the shared helper, so the row's own `name` is LAST at every SOURCE registrar | | `#14422` | 0 | 1 | `dc7c226b9` | commit | reused | give the standalone-action owner-key ladder one spelling | | `#14423` | 11 | 2 | `a56baa2bd` | commit | reused | the action audit reads the store key and asks the plane by name, and listNames gains loadMany fault parity | | `#14472` | 1 | 1 | `00ff228fe` | commit | measured | decide the insert-side runtime-owned strip by hook-write provenance | | `#14474` | 1 | 3 | `df657d9df` | commit | reused | carry an ADR-0112 envelope on the install-time namespace conflict refusal | | `#14484` | 1 | 0 | `3f64fe6c6` | commit | reused | stamp organization_id on every sys_record_share write, backfill the stranded rows, admit the object to the tenancy ledger | | `#14535` | 0 | 1 | `1aba3159a` | commit | measured | declare the recorded-by fixture's lookup with the canonical `reference` key | | `#14666` | 1 | 6 | `d0ee598e6` | commit | measured | refuse a view container whose `name` disagrees with its derived object key | | `#14667` | 0 | 1 | `dc7c226b9` | commit | reused | give the standalone-action owner-key ladder one spelling | | `#14680` | 1 | 1 | `3bd9b3498` | commit | measured | a leaf `/view-container` subpath keeps objectql's lean ADR-0076 closure free of the manager, chokidar, glob and js-yaml | | `#14683` | 0 | 4 | `96326040f` | commit | reused | apply the allowOrgOverride read gate inside getMetaItems, so multi-type sweeps are scoped per type | | `#14723` | 1 | 0 | `65846bc46` | commit | reused | a batch/import ROW reports a unique-constraint refusal as `UNIQUE_VIOLATION`, the route's one wire spelling | | `#14770` | 0 | 6 | `d5cbb44f3` | commit | reused | gate `getMetaItem`'s overlay read on the metadata registry | | `#14878` | 0 | 2 | `29db3cd2a` | commit | reused | widen the deleted-member absence pin from one file to the tree | | `#14957` | 1 | 0 | `26144c204` | commit | measured | Derive and gate the platform-object tenancy census | | `#15041` | 2 | 1 | ADR-0104, 2026-09-05 addendum | ADR | reused | ADR-0104's 2026-09-05 addendum: the media column holds the bare `sys_file` id; its execution order puts the driver card at step 2 (it names the number) | | `#15094` | 1 | 0 | `901773b21` | commit | measured | check-react-page-adapter-contract names its class by shape, not by the records spelling, and re-anchors its citation | | `#16608` | 4 | 0 | `a016f08b8` | commit | reused | evaluate the insert-side RLS `check` on the row that will be stored, after `beforeInsert` | | `#16711` | 1 | 0 | `7862fb711` | commit | measured | object-definition parameters declare the keys they are read for, plus a gate that sees subclass overrides | | `#16729` | 1 | 0 | `0f38ab084` | commit | measured | an explicit tenancy opt-out survives a partial `syncSchema` re-registration | | `#16783` | 1 | 1 | `854639b31` | commit | reused | `findOne`, `update` and `delete` declare what they answer, and their hook seams are guarded | | `#16786` | 3 | 2 | `5c8f5af50` + `6059b29c0` | commit | measured+reused | `ObjectRepository` declares the `findOne` / `update` shapes it already published / declare IScopedObjectRepository.updateById's answer — the record or null, not any | | `#16805` | 2 | 0 | `a016f08b8` | commit | reused | evaluate the insert-side RLS `check` on the row that will be stored, after `beforeInsert` | | `#17195` | 1 | 0 | `d2c1d1980` | commit | reused | beforeUpdate receives the persist image; the caller submission moves to ctx.submitted | | `#17219` | 3 | 2 | `706ad0fcc` | commit | reused | name the withheld read-only key when a hook faults reaching through it | | `#17853` | 1 | 0 | `08f5f0e5a` | commit | reused | make a vitest filter that selects no test file say so | ## Wordings to check Most rewrites swap a tag in place (`[#N]` to `[commit SHA]`, `(#N)` to `(commit SHA)`, `#N's X` to `commit SHA's X`, `PR #N` to its squash commit), the form the landed stages use. These say more than the tag: - **`#10629`, three sites** (`plugin.ts:1543`, `skip-schema-sync-registers-object-metadata.test.ts:22`, `:153`): 「the same ruling #7737/#10629 made for federated objects」 became 「the same ruling #7737 made for federated objects (commit 199ec47)」. `199ec4712` is #7737's fix, and its message states the ruling the sites paraphrase: `OS_SKIP_SCHEMA_SYNC` is a DDL flag while the federated binding is DDL-free, and the binding is reconciled on `kernel:ready`. Its message and diff name #7737, **not #10629**: the only commit that names #10629 as its own (`13a6cb4ad`, the runtime lane's anchor for it) is an expected-log-noise capture, a different subject, and `a037f7cbd`, which wrote the 「#7737/#10629 ruling」 phrase, records nothing #10629 added. So the dead number is dropped and the live #7737 carries the citation, beside the commit that decided it. The same pair stands in `driver-sql` (`sql-driver.ts`), the next stage. - **`#10243`, two sites** (`action-activation.ts:185`, `action-activation.test.ts:23`): 「the #10243 mechanism ADR-0126 retires」 became 「the env-wide toggle leak's mechanism ADR-0126 §7.2 retires」. ADR-0126 §7.2 names that mechanism (the process-local `flowEnabled` map) and the number (「the #10243 leak's mechanism」), so ruling C's ADR rung applies; the dogfood lane anchored a similar sentence to `02b41232d`, the measurement commit. - **`#8672`, ten sites**: #8672 was an observation that no commit fixed. `ff08691e6` is the first in-repo record of its reasoning: its diff quotes 「an org-less row is defensible for `sys_permission_set`」 and names #8672 five times. So 「#8672's reasoning」 became 「commit ff08691's (recorded) reasoning」, and 「#8672 measured this primitive」 (`system-write-organization.test.ts:347`) became 「The card commit ff08691 cites measured this primitive」. `system-write-organization.test.ts:117` quotes what the file used to read, 「platform namespace ⇒ deliberately org-less (#8672)」; the quoted number is elided to 「(…)」 rather than re-spelled, so the quote stays true. - **`#13178`'s census figure** (`engine.ts:5450`, `tenancy-by-object-classification.test.ts:26`): 「#13178 census measured … 135 of 175」 became 「census cited in commit e49d988's message measured … 135 of 175」. That message carries the figure; see Acceptance notes for what `4ecafc78b` records about it. `platform-object-tenancy.ts:144` (the `sys_upload_session` update writer) takes `f087c376f`, the service-storage lane's anchor. - **`#15094`** (`find-hook-result-shape.ts:30`): 「the ~70 … normalizer limbs the #15094 census counted」 became 「… limbs a census counted (commit 901773b records its band)」. `901773b21` wrote the header of `scripts/check-react-page-adapter-contract.mjs`, which records that census (104 blocks at `ca46f8f12`) and a re-measure band; it does not restate 「~70」, so the sentence points at the band and claims nothing more. - **`#16805`** (`engine.ts:13014`, `:13218`): 「the contract review of PR #16805 measured」 became 「the contract review commit a016f08 records measured」. `a016f08b8` is that pull request's squash, and its message records the review's finding. - **`#16786`**: the `objectql` half (`engine.ts:18230`, `:18264`, two tests) takes `5c8f5af50`, the commit that declared `ObjectRepository`'s `findOne` / `update` shapes; `engine.ts:18272`'s 「stays open on #16786」 became 「(its spec half: commit 6059b29)」, the spec lane's anchor, since that half has landed. - **`#14163`** (`registry-ownership-refusal-envelope.test.ts:11`): `(ADR-0130 D3, commit 1dcb995)`. The cited thing is the install-time object-name check; ADR-0130 D3 decides it, and `1dcb995f2` landed it with a changeset naming #14163. - **`#8460`** (seven `registry.ts` sites): ADR-0029 D9.2a, the 2026-08-13 amendment, which names #8460; the dogfood and spec lanes used the same. `:2508`'s 「every shape #8460 measured」 became 「every shape the ADR-0029 D9.2a amendment records」. - **`#15041`** (`engine.ts:7164`, `:9860`, one test): 「the ruling on #15041 step 2」 became 「sequencing step 2 of ADR-0104's 2026-09-05 addendum」, the cli lane's spelling of the same record. - **`#6241`** (`metadata-service-roundtrip-conformance.test.ts:41`): 「the gate's header carries #3984/#5881/#6241」 became 「… carries #3984, #5881 and the third bypass, fixed in commit 83a3b1f」, because that header (`scripts/`, another lane's surface) still carries the number itself. - **Tense, where the anchor is past**: 「the phantom read #14770 removes」 became 「… commit d5cbb44 removed」 (`protocol-meta.test.ts:100`) and 「the resurrection #14683 closes」 became 「… commit 9632604 closed」 (`:169`), as stage 1 wrote it. `:181`'s backticked `` `#14770` `` became plain 「commit d5cbb44」; its message records the four raw-org callers the line says it measured. - **Card antecedents**: 「the whole subject of #14423」 became 「the whole subject of the card commit a56baa2 closed」 (`action-governance.ts:406`); 「the C4 cell #14423's ruling left open」 became 「the C4 cell commit a56baa2 left open」 (`plugin-governance-scoped-metadata.test.ts:5`; that commit pins C4 as 「a BOUNDARY, not a defect」); 「route 3 of #8648」 became 「route 3 of the card commit e5eeb49 fixed」 (`query-expression-conformance.test.ts:1070`, a line that commit wrote); 「filed #6573」 / 「#6573's ruling」 became 「filed the card commit 7084313 closed」 / 「The decision commit 7084313 records」 (`hook-exclude-objects.test.ts:501`, `:502`); 「(#11674, the card's "Second, NOT measured" question)」 became 「(the "Second, NOT measured" question on the card commit 9a884c6 fixed)」; 「measurement (#13644)」 became 「measurement (on the card commit 34ce8e7 closed)」. - **Other single rewrites**: 「and #6573 is why」 became 「and commit 7084313 says why」 (`engine.ts:2433`; its message gives the reason); 「question at this line (#10527), since decided」 became 「question at this line, since decided by that commit」 (`lifecycle-service.ts:1294`, where `:1293` now cites `5649efbf9`); 「#14680 is what they cost」 became 「the leak commit 3bd9b34 closed is what they cost」 (`core-boundary.ratchet.test.ts:52`); 「The #10165 acceptance criterion」 became 「The acceptance criterion behind commit 8012960」. - **Reference lists** (`metadata-service-getobject-equivalence.test.ts:51`, `metadata-service-roundtrip-conformance.test.ts:68`, `metadata-facade.test.ts:101`): the dead numbers became their commits, in the spec lane's 「commits SHA (what), …」 form; the live numbers in those lists stay, `PR #7211` beside its `1507ba356`. - No line was reflowed, so some are longer than their block's wrap (`eslint.config.mjs` declares no line-length rule, and a reflow would move neighbouring lines and every line citation into the file). ## Sites left - **In comments (src, test, `vitest.config.ts`): none.** - **String literals: 43 test-string sites, 25 numbers, 23 files** (describe and `it` titles, assertion arguments): `#14422` 4, `#13273` 3, `#13657` 3, `#17219` 3, `#11674` 3, `#6573` 3, `#14423` 2, `#10165` 2, `#14535` 2, `#10290` 2, `#8672` 2, and 14 more once each. Every one of the 25 is in this stage's population, so the table above holds an anchor for each. Non-test strings carry none. Strings are outside this stage's surface. - **Outside `src`:** the release-owned `CHANGELOG.md` names dead numbers on 66 sites (44 numbers); left. `test-typecheck-debt.json`, `tsconfig.test.json` and `tsconfig.scripts.json` cite only live numbers. ## Mechanical guard: no code token moves The guard (stage 2's) compares, base `4727fcb22` against the working tree, over all 67 touched files, with TypeScript 6.0.3: - **Reading 1**: the parser's leaf nodes, from a `forEachChild` walk. Comments are trivia there, and JSDoc is never visited. - **Reading 2**: the full token stream in parser context, from a `getChildren` walk, JSDoc nodes skipped. String, template and numeric literals are compared in full on both readings. Results: - Real run at the head: 298,707 base tokens, **0 files with a token change** (exit 0). - Comment control (「The defaulting」 to 「The DEFAULTING」 on `engine.ts:5`): 0 files changed (exit 0). - Positive control, an identifier (`ARCHIVE_BATCH_SIZE` to `ARCHIVE_BATCH_SIZEX`, `lifecycle-service.ts`): DIFFER on both readings (exit 1). - Positive control, a string literal (`'[value redacted]'` to `'[value redactedX]'`, `driver-fault-redaction.ts`): DIFFER on both readings (exit 1). - Positive control, a numeric literal (`ARCHIVE_MAX_BATCHES_PER_SWEEP = 20` to `21`): DIFFER on both readings (exit 1). Each mutation went through `scripts/ablation-replace.mjs` (wrap mode) under a shell trap that restores by absolute path from `HEAD`. Each landed (anchor 1 to 0, blob changed), and each restore was proven equal to its `HEAD` blob (`71f6c9268aeb`, `34b1dd7989b8`, `9594cdd593c8`), with `git diff HEAD` empty and a clean tree afterwards. ## Changeset: `patch` (`dist` measured) `files[]` is `dist`, `README.md` and `CHANGELOG.md`, and the package is not private. The dependency closure was built first (`turbo run build --filter='@objectstack/objectql^...'`, 13 tasks). Then the package's own `build` (tsup plus `check-dts-emitted`) ran three times in one script under the shared verify lock (VERDICT command-exit 0): - **Leg 1**, at `9d6a0a8d6`: 14 `dist` files hashed. Of the 137 rewritten non-test lines, 54 appear verbatim in `dist`: 25 from `engine.ts`, 7 from `action-governance.ts`, 5 from `platform-object-tenancy.ts`, and 17 from ten other files; in `index.d.ts` / `index.d.mts`, the shared `util-*.d.ts` chunk, and `index.js` / `index.mjs` / `core.js` / `core.mjs`. - **Leg 2**, the base text put back in the 18 non-test files (18 of 18 proven equal to their base blob): 10 of the 14 files differ from leg 1 (`core` and `index` in `.d.ts`, `.d.mts`, `.js`, `.mjs`, and the `util-*` chunk's two `.d` files). - **Leg 3**, after the proven restore (18 of 18 equal to their `HEAD` blob, `git diff HEAD` empty): all 14 files are byte-identical to leg 1, so the build is deterministic and the difference is the rewrite. So the rewrite ships, and `.changeset/20595-objectql-provenance-anchors.md` declares a `patch` for `@objectstack/objectql`, comment text only, with the claim's `Clause-②: no` line. ## Gates (head `1e0895870d`) - **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` at `1e0895870d` (68 paths against merge base `8dea55d31`; no stale-tree warning) derived 68 commands. All 68 ran, each exit code captured before any pipe: 68 exit 0. `--ran` reports 「68 derived, 68 run, 0 NOT-MEASURED, 0 UNRUN」 (a derived zero) and exits 0. A full `turbo run build` over `./packages/*` and `./packages/*/*` ran first under the verify lock (71 of 71 tasks, VERDICT command-exit 0), so no gate read an unbuilt workspace. - **Named in the dispatch:** `node scripts/check-issue-citations.mjs` exits 0 (「every citation this change adds resolves (or is a declared cross-repo reference)」, 14 judged across 17 files); `pnpm check:issue-citations` exits 0 (self-test); `pnpm check:doc-authoring` exits 0 (the sibling-package prose-id baseline holds, no growth); `pnpm check:nul-bytes` exits 0, and a raw scan of the 68 changed files for control bytes finds none. - **Tests and typecheck, under the verify lock, at `1e0895870d`:** `pnpm --filter @objectstack/objectql test`: 360 test files and 7,082 tests pass. `pnpm --filter @objectstack/objectql typecheck` exits 0; its `check:test-typecheck` step compiles all 361 tracked test files under `tsconfig.test.json` (`tsc --listFiles`), the ledger holding (40 files, 234 errors, 65 pinned signatures). - **Lint, as a proven narrowing:** eslint with inline config disabled, over the 67 touched `.ts` files plus `dist/index.js` as the control: 68 results, 0 errors and 1 warning, the control's ignore notice; none of the 67 is reported ignored. `eslint.config.mjs` never enables type-aware linting (its lines 327-328 say so), so a comment edit cannot move the verdict on an untouched file. The repo-wide `pnpm lint` is CI's run. ## Acceptance notes - **Base.** The branch was cut at `d150c3039`, fast-forwarded to `4727fcb22` before any edit (both census readings of this package agree), and merged with `main` once at `8dea55d31` before the gates; that merge touched no file under `packages/objectql` and neither `check-issue-citations.mjs` nor `dispatch-gates.mjs`. Tests, typecheck and gates ran on the merged head. - **The `135 of 175` figure.** `engine.ts:5450` and `tenancy-by-object-classification.test.ts:26` state that census figure as measured. `4ecafc78b`, which re-derived the tenant-audit census as an in-tree artifact after #13178 became unreachable, records that 「the 135/77% "silenced by the isSystem guard" figure has no surviving corroboration and is not reproduced」. This stage moves the citation to the commit whose message carries the figure and leaves the claim as written; whether those two sentences should say so is outside a citation sweep. - **A board enumeration came back short, at exit 0.** One run of the gate's own `enumerateBoard`, between two full ones, returned 91 pages, 9,000 records and frontier #9389, and raised nothing; the runs either side of it read 191 pages and frontier #21252. Its only guard is a zero-record check. This stage discarded that reading and re-enumerated; nothing above rests on it. Noted only. - **Wording only:** no line without a number was changed, except the lines whose antecedent was the number itself, listed above. --- _Generated by [Claude Code](https://claude.ai/code/session_017xfMoEjKUuSh2xYB8sCozp)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent b91e40b commit 4bf4e7e

68 files changed

Lines changed: 291 additions & 275 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
'@objectstack/objectql': patch
3+
---
4+
5+
Provenance comments in `@objectstack/objectql` cite the commits and ADRs that decided them, not tracker numbers that no longer resolve
6+
7+
Clause-②: no
8+
9+
Docblocks and comments across the package cited issue-tracker numbers that now answer 404 on GitHub.
10+
Each one now cites the commit in this repository's history that made the decision it describes, or the
11+
ADR that records it (ADR-0029 D9.2a, ADR-0104's 2026-09-05 addendum, ADR-0126 §7.2, ADR-0130 D3).
12+
Some of these docblocks sit on exported members, so the reworded text appears in the published
13+
`index.d.ts` / `index.d.mts`, `core.d.ts` / `core.d.mts` and the shared type chunk, and comments that
14+
esbuild keeps appear in the JavaScript output.
15+
16+
Comment only: no export, type, error code, status, message text or runtime behaviour changes.

‎packages/objectql/src/action-activation.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
// would switch off an entire installation's actions on its first boot.
2121
// 4. **The write is durable BEFORE it is local.** A store that throws must
2222
// leave the projection untouched, or the engine reports an activation state
23-
// the ledger does not carry — the #10243 shape with persistence bolted on,
23+
// the ledger does not carry — the env-wide toggle leak's shape with persistence bolted on,
2424
// which ADR-0126 §7.2 exists to remove.
2525
// 5. **Survives re-registration**, which is the in-process half of "survives a
2626
// restart": `resyncAuthoredActions` re-registers handlers on every

‎packages/objectql/src/action-activation.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -182,7 +182,7 @@ export class ObjectStoreActionActivationStore extends ObjectStoreMetadataActivat
182182
* written from exactly two places — {@link hydrate} (boot, from the ledger) and
183183
* {@link setActive} (which writes the durable row FIRST and updates the set only
184184
* after that write returns) — so it cannot drift into being an independent,
185-
* process-local off-switch, which is the #10243 mechanism ADR-0126 retires.
185+
* process-local off-switch, which is the env-wide toggle leak's mechanism ADR-0126 §7.2 retires.
186186
*
187187
* ⚠️ It is deliberately NOT re-read per `metadata:reloaded`: a reload
188188
* re-registers HANDLERS, and a re-registered handler must stay disabled. The

‎packages/objectql/src/action-governance-keyed-identity.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.
22

33
/**
4-
* #14423 — the audit and the router, defined on ONE identity and ONE set of
4+
* Commit a56baa2bd — the audit and the router, defined on ONE identity and ONE set of
55
* sources.
66
*
77
* ---------------------------------------------------------------------------

‎packages/objectql/src/action-governance.ts‎

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@
4545
* undeclared only when EVERY source the router resolves through answered
4646
* nothing for it.
4747
*
48-
* [#14423] EXISTENCE is settled now too, on both halves of the D5 bijection
48+
* [commit a56baa2bd] EXISTENCE is settled now too, on both halves of the D5 bijection
4949
* and in both of the ways the two sides could disagree:
5050
*
5151
* - IDENTITY — the metadata plane is read KEYED
@@ -264,7 +264,7 @@ export function reconcileActionRegistrations(
264264
/**
265265
* One declaration the engine can dispatch against.
266266
*
267-
* ## [#14423] `storeKey` — the identity a body is not required to carry
267+
* ## [commit a56baa2bd] `storeKey` — the identity a body is not required to carry
268268
*
269269
* `action` is the declaration BODY, exactly as its source hands it over.
270270
* `storeKey` is the key the metadata plane holds that body under, present
@@ -317,7 +317,7 @@ export interface GovernanceLogger {
317317
* with the object-embedded copy winning, mirroring the execution layer's
318318
* artifact-wins rule.
319319
*
320-
* ## [#14423] Two spellings for the metadata source, and why the keyed one wins
320+
* ## [commit a56baa2bd] Two spellings for the metadata source, and why the keyed one wins
321321
*
322322
* `loadStandaloneActionsKeyed` reads the plane under the identity the STORE
323323
* holds each row by (`MetadataManager.loadManyKeyed`); `loadStandaloneActions`
@@ -336,7 +336,7 @@ export interface GovernanceLogger {
336336
* So when the keyed source is present it REPLACES the unkeyed one — they read
337337
* the same population, and reading both would only re-admit the guess. The
338338
* unkeyed parameter stays for callers that have no keyed read to offer; it is
339-
* the pre-#14423 behaviour verbatim, nameless rows dropped and all.
339+
* the behaviour before commit a56baa2bd, verbatim, nameless rows dropped and all.
340340
*/
341341
export async function collectEngineActionDeclarations(
342342
objects: any[],
@@ -394,7 +394,7 @@ export async function collectEngineActionDeclarations(
394394

395395
/**
396396
* The router's BY-NAME rungs, applied to the handlers the declaration set did
397-
* not cover — `registry.getItem('action', <key>)` (rung 2) and, since #14423,
397+
* not cover — `registry.getItem('action', <key>)` (rung 2) and, since commit a56baa2bd,
398398
* `meta.loadDiagnosed('action', <key>)` / `meta.load(…)` (rung 3) — each
399399
* accepted on the router's own ownership test.
400400
*
@@ -403,7 +403,7 @@ export async function collectEngineActionDeclarations(
403403
* The router never enumerates either source: it asks for ONE name. Mirroring
404404
* it means asking for one name. And enumeration is not a substitute here even
405405
* where it exists — a plural read and a by-name read of the same plane can
406-
* disagree, which is the whole subject of #14423: one loader fault is
406+
* disagree, which is the whole subject of the card commit a56baa2bd closed: one loader fault is
407407
* swallowed by the plural read and served by the by-name read, so a handler
408408
* whose declaration lives on the faulted loader reads "undeclared" from the
409409
* enumeration alone. The keyed enumeration closes the IDENTITY half of that
@@ -474,7 +474,7 @@ function fingerprint(r: ReturnType<typeof reconcileActionRegistrations>): string
474474
* (`metadata:reloaded` re-runs this; a re-sync that changed nothing should
475475
* not repeat the same warning).
476476
*
477-
* ## [#14423] Both halves of the bijection read what the router reads
477+
* ## [commit a56baa2bd] Both halves of the bijection read what the router reads
478478
*
479479
* The two findings used to stand on different sources, which is how the audit
480480
* could contradict the router about whether a declaration exists:
@@ -522,7 +522,7 @@ export async function runActionGovernanceInventory(args: {
522522
*/
523523
loadStandaloneActions?: () => Promise<any[]>;
524524
/**
525-
* [#14423] The metadata plane's `action` rows KEYED by the store's own key
525+
* [commit a56baa2bd] The metadata plane's `action` rows KEYED by the store's own key
526526
* (`meta.loadManyKeyed('action')`). This is the source the declaration
527527
* half of the bijection is defined on, so that the audit and the router
528528
* share ONE identity — the store key (#14205) — instead of the audit
@@ -538,7 +538,7 @@ export async function runActionGovernanceInventory(args: {
538538
*/
539539
lookupRegistryAction?: (actionName: string) => unknown;
540540
/**
541-
* [#14423] The router's rung 3, injected the same way:
541+
* [commit a56baa2bd] The router's rung 3, injected the same way:
542542
* `meta.loadDiagnosed('action', name)?.data`, falling back to
543543
* `meta.load('action', name)` — the caller unwraps, so this returns the
544544
* declaration or nothing, exactly like {@link lookupRegistryAction}.

‎packages/objectql/src/action-owner-key-single-source.test.ts‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.
22

33
/**
4-
* This package spells the standalone-action owner-key ladder ONCE (#14422).
4+
* This package spells the standalone-action owner-key ladder ONCE (commit dc7c226b9).
55
*
66
* `ObjectQLPlugin` carried a private `actionObjectKey` that repeated
77
* {@link standaloneActionOwnerKey}'s three rungs, and the only thing holding
@@ -73,7 +73,7 @@ describe('standalone-action owner key — one spelling in @objectstack/objectql
7373
expect(plugin, 'plugin.ts is missing from the scan').toBeDefined();
7474
// The negative that used to live here — "plugin.ts does not name the
7575
// deleted member" — moved to the TREE-scoped section at the bottom of
76-
// this file (#14878). Its scope was the defect, not its subject. What
76+
// this file (commit 29db3cd2a). Its scope was the defect, not its subject. What
7777
// stays here is the positive half: the plugin still derives owner keys,
7878
// it just does it through the canonical helper now.
7979
expect(plugin!.text).toContain('standaloneActionOwnerKey(');
@@ -95,7 +95,7 @@ describe('standalone-action owner key — one spelling in @objectstack/objectql
9595
});
9696

9797
/**
98-
* ── [#14878] The absence assertion is TREE-scoped, not FILE-scoped ──────────
98+
* ── [commit 29db3cd2a] The absence assertion is TREE-scoped, not FILE-scoped ──────────
9999
*
100100
* The negative that used to sit in the plugin test above read `plugin.ts` and
101101
* nothing else, and THAT SCOPE was the defect. A pin written by the deleting PR
@@ -165,7 +165,7 @@ describe('standalone-action owner key — one spelling in @objectstack/objectql
165165
*/
166166

167167
/**
168-
* The member PR #14667 deleted from `ObjectQLPlugin`. Held as DATA: naming a
168+
* The member commit dc7c226b9 deleted from `ObjectQLPlugin`. Held as DATA: naming a
169169
* symbol in a string cannot resurrect it, and this file is excluded from its own
170170
* scan precisely so it may carry the name.
171171
*/

‎packages/objectql/src/adr0104-file-columns-moved-supply.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
/**
44
* [#15989] The kernel→driver supply seam for the ADR-0104 media arm, from the
5-
* ENGINE's side — the ruling on #15041 step 2, as amended by the director
5+
* ENGINE's side — sequencing step 2 of ADR-0104's 2026-09-05 addendum, as amended by the director
66
* ruling (decision batch #120 item 1).
77
*
88
* The driver has accepted `SqlDriverConfig.fileColumnsMoved` since PR #17403,

‎packages/objectql/src/core-boundary.ratchet.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@
4949
// What this file does NOT see, and what does (#15347)
5050
//
5151
// This is a SOURCE SCAN over two hard-coded names. Both limits are by
52-
// construction, and #14680 is what they cost: a heavyweight arriving through
52+
// construction, and the leak commit 3bd9b3498 closed is what they cost: a heavyweight arriving through
5353
// any other specifier is outside FORBIDDEN_PACKAGES, and a scan of this
5454
// package's own sources cannot follow one that arrives three packages deep —
5555
// which is how that one arrived, invisible to every gate for the whole time it

‎packages/objectql/src/driver-fault-redaction.test.ts‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,7 @@ describe('redactStatementFromMessage', () => {
106106
});
107107
});
108108

109-
// #8823 — the tail is kept because it names IDENTIFIERS, and on MySQL's
109+
// Commit 4dfa369a9 — the tail is kept because it names IDENTIFIERS, and on MySQL's
110110
// duplicate-entry family it does not: `ER_DUP_ENTRY` prints the conflicting
111111
// VALUE in the diagnostic itself. These cases pin both halves of the remedy —
112112
// the value goes, the index name stays — because a fix that blanked the tail
@@ -136,7 +136,7 @@ describe('#8823 — a caller value inlined in the diagnostic itself', () => {
136136
});
137137

138138
it('redacts a BARE diagnostic too — the shape that reaches us without a statement', () => {
139-
// Before #9030 the shared leak predicate did not recognise this phrasing,
139+
// Before commit 27a567dd8 the shared leak predicate did not recognise this phrasing,
140140
// so a bare `Duplicate entry …` was turned away at the door and kept its
141141
// value. That limb landed for a different reason; the two compose here.
142142
const out = redactStatementFromMessage(`Duplicate entry '${EMAIL}' for key 'crm_account.email'`);
@@ -284,7 +284,7 @@ describe('#9160 — the value-bearing families the live probe measured', () => {
284284
});
285285

286286
describe('postgres invalid_text_representation (22P02) / invalid_datetime_format (22007)', () => {
287-
// ⛔ The family the #8823 note was waiting for. Postgres' UNIQUE violation is
287+
// ⛔ The family the commit 4dfa369a9 note was waiting for. Postgres' UNIQUE violation is
288288
// saved only because its value sits on `error.detail`, which
289289
// `ObjectLogger.write` never serializes — "coincidence, not a defence". This
290290
// family puts the caller's value on `error.message`, which IS serialized, so
@@ -761,7 +761,7 @@ describe('#8682 half B — the write-path loggers', () => {
761761
}
762762

763763
/**
764-
* The one driver double in this file. #8823 needed a MySQL-shaped fault and
764+
* The one driver double in this file. Commit 4dfa369a9 needed a MySQL-shaped fault and
765765
* the shape is a PARAMETER rather than a second double — one fake engine per
766766
* file keeps the contract the double implements reviewable in one place.
767767
*/
@@ -864,7 +864,7 @@ describe('#8682 half B — the write-path loggers', () => {
864864
});
865865

866866
/**
867-
* [#8823] The same write path, with the fault MySQL raises instead — where
867+
* [commit 4dfa369a9] The same write path, with the fault MySQL raises instead — where
868868
* the caller's value is in the DIAGNOSTIC and not only in the statement, so
869869
* the statement cut alone never reached it.
870870
*/

‎packages/objectql/src/driver-fault-redaction.ts‎

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@
4444
* Nothing else about it moved: the same redacted `message`/`stack` reach the
4545
* same `error` key of the same meta bag (`ObjectQL.writeFailureLogMeta`).
4646
*
47-
* ## [#8823] …but "the tail names identifiers" is not true of every dialect
47+
* ## [commit 4dfa369a9] …but "the tail names identifiers" is not true of every dialect
4848
*
4949
* The paragraph above was written with a premise attached: that whatever the
5050
* database prints after the separator names IDENTIFIERS — a column, a table, a
@@ -60,7 +60,7 @@
6060
* ```
6161
*
6262
* Three keep an identifier; the second keeps a caller's value. Measured through
63-
* this function, not predicted — and re-measured byte-identical after #9030
63+
* this function, not predicted — and re-measured byte-identical after commit 27a567dd8
6464
* taught the shared leak predicate this phrasing, which moves the VERDICT but
6565
* not the cut.
6666
*
@@ -81,7 +81,7 @@
8181
*
8282
* ## [#9160] The list is now MEASURED, and there is a way to notice a gap
8383
*
84-
* #8823 left one entry and no instrument: nothing measured whether a diagnostic
84+
* Commit 4dfa369a9 left one entry and no instrument: nothing measured whether a diagnostic
8585
* a driver produced carried a value, so the next entry needed the same accident
8686
* that found the first. `sql-driver-diagnostic-value-probe.test.ts` is that
8787
* instrument. It plants a canary value, raises each candidate family against
@@ -108,7 +108,7 @@
108108
* ```
109109
*
110110
* ¹ on `error.message`. Both put the caller's row on `error.detail`, which
111-
* `ObjectLogger.write` does not serialize — the coincidence #8823 recorded, and
111+
* `ObjectLogger.write` does not serialize — the coincidence commit 4dfa369a9 recorded, and
112112
* it is still only a coincidence. **The three Postgres families marked VALUE put
113113
* the caller's value on `message`, the field that IS serialized**, so nothing
114114
* covers them but the entries below. That was the open question #9160 asked and
@@ -140,7 +140,7 @@
140140
* ```
141141
* pg 22P02/22007 value runs to end of message → head-anchored cut (below)
142142
* mysql 1292 value runs to end of message → head-anchored cut (below)
143-
* pg 22003 value "…" is out of range … → `tail`, the #8823 mechanism
143+
* pg 22003 value "…" is out of range … → `tail`, the commit 4dfa369a9 mechanism
144144
* ```
145145
*
146146
* `22003` was assumed unreachable on the reasoning that its value slot holds a
@@ -266,11 +266,11 @@ const STATEMENT_SEPARATOR = ' - ';
266266
/** What replaces a statement that carried nothing but values. */
267267
const REDACTED_STATEMENT = '[statement and bound values redacted]';
268268

269-
/** [#8823] What replaces one caller value inlined in the database's own diagnostic. */
269+
/** [commit 4dfa369a9] What replaces one caller value inlined in the database's own diagnostic. */
270270
const REDACTED_VALUE = '[value redacted]';
271271

272272
/**
273-
* [#8823] MySQL/MariaDB `ER_DUP_ENTRY` (1062), whole: the template's own head,
273+
* [commit 4dfa369a9] MySQL/MariaDB `ER_DUP_ENTRY` (1062), whole: the template's own head,
274274
* the conflicting VALUE, and the `for key <index>` tail that anchors it.
275275
*
276276
* `Duplicate entry '%-.192s' for key '%-.192s'` — the first slot is whatever the
@@ -295,7 +295,7 @@ const REDACTED_VALUE = '[value redacted]';
295295
const DUPLICATE_ENTRY = /(duplicate entry\s+)["'`][\s\S]*["'`](\s+for key\s+["'`][^"'`]+["'`])/gi;
296296

297297
/**
298-
* [#8823] The same template with its head already gone — what the statement cut
298+
* [commit 4dfa369a9] The same template with its head already gone — what the statement cut
299299
* leaves behind when the conflicting VALUE itself contained ` - `.
300300
*
301301
* Measured: `insert into … values ('2026 - Q3 plan') - Duplicate entry '2026 -
@@ -352,7 +352,7 @@ const MYSQL_INCORRECT_VALUE_TAIL = /'(\s+for column\s+'[^']*'\s+at row\s+\d+)/gi
352352
* invalid input syntax for type timestamp with time zone: "CANARY-notadate"
353353
* ```
354354
*
355-
* **This is the family the #8823 note was waiting for.** Postgres' unique
355+
* **This is the family the commit 4dfa369a9 note was waiting for.** Postgres' unique
356356
* violation is saved only because its value sits on `error.detail`, which
357357
* `ObjectLogger.write` does not serialize — recorded there as "coincidence, not
358358
* a defence". Here the value is on `error.message`, the field that IS
@@ -405,7 +405,7 @@ const PG_VALUE_OUT_OF_RANGE = /(value\s+)"[\s\S]*"(\s+is out of range for type [
405405
* logged: Q3" is out of range for type integer ← `Q3` is caller data
406406
* ```
407407
*
408-
* This family keeps its right anchor, so it takes the #8823 recovery and NOT a
408+
* This family keeps its right anchor, so it takes the commit 4dfa369a9 recovery and NOT a
409409
* `head`: everything before ` is out of range for type` is value residue by
410410
* construction and is dropped whole. ⛔ It must not be given a `head` — its
411411
* diagnostic continues past the value, which is exactly the shape the head
@@ -678,7 +678,7 @@ export function redactStatementFromMessage(message: string): string {
678678
if (!message || !looksLikeInternalErrorLeak(message)) return message;
679679
const cut = statementCut(message);
680680
// No statement to cut — but a dialect may still have inlined a value in the
681-
// diagnostic itself, and since #9030 taught the shared predicate this
681+
// diagnostic itself, and since commit 27a567dd8 taught the shared predicate this
682682
// phrasing, a BARE `Duplicate entry …` now reaches this line instead of
683683
// being turned away above.
684684
if (cut === -1) return redactDiagnosticValues(message);
@@ -716,7 +716,7 @@ function statementCut(message: string): number {
716716
}
717717

718718
/**
719-
* [#8823] Drop the caller values a dialect inlines into its OWN diagnostic,
719+
* [commit 4dfa369a9] Drop the caller values a dialect inlines into its OWN diagnostic,
720720
* keeping every identifier around them.
721721
*
722722
* Runs on the tail the statement cut already produced, never on the whole

0 commit comments

Comments
 (0)