@@ -5303,8 +5303,11 @@ const step18: MigrationStep = {
53035303 + 'tombstones on the SHARED shape, because that shape also feeds the `.strip()` wire '
53045304 + 'member, where a bare deletion would be a silent strip. The D2 conversion '
53055305 + '`view-item-owner-hidden-removed` strips them from the view item RECORD spelling only, '
5306- + 'as a lossless delete; a flattened overlay keeps its own `owner` / `hidden`, which are '
5307- + 'declared on a different door this retirement does not touch.',
5306+ + 'as a lossless delete, in both collections a record travels in — `views` (stack sources '
5307+ + 'and stored rows) and the assembled-manifest `viewItems` channel (package export, '
5308+ + 'environment artifacts), whose registration parse would otherwise refuse an artifact '
5309+ + 'assembled before this release; a flattened overlay keeps its own `owner` / `hidden`, '
5310+ + 'which are declared on a different door this retirement does not touch.',
53085311 conversionIds: [
53095312 'field-malformed-scale-precision-removed',
53105313 'record-chatter-position-vocabulary',
@@ -18258,6 +18261,56 @@ export const RETIRED_KEYS_BY_MAJOR: Readonly<Record<number, readonly string[]>>
1825818261 // carrying both — and the D2 conversion `chart-config-aria-removed` strips all
1825918262 // of them together with the dashboard site.
1826018263 'ui/ReportChart:aria',
18264+ // #20085 (ADR-0049 enforce-or-remove; triage direction 「retire both keys」).
18265+ // `ViewItem.hidden` promised to hide a view item from the switcher, and nothing
18266+ // ever read it: no writer and no reader of the view-item key in the framework,
18267+ // in objectui at its pin and at `main`, or in cloud, and both switcher read
18268+ // paths filter on `viewKind` + `object` only — `hidden: true` hid nothing.
18269+ // Tombstoned with `retiredKey()` on the shared `viewItemBaseShape()`, because
18270+ // that shape also feeds the `.strip()` wire member (`ui/ViewItemWire`,
18271+ // registered beside this row), where a bare deletion would strip in silence.
18272+ // The flattened-overlay members declare their own `hidden` on a different door,
18273+ // untouched. ⚠️ No gate below can JUDGE this row: `ui/ViewItem` is a
18274+ // discriminated union, whose emitted JSON Schema has no top-level
18275+ // `properties`, so `authorable-surface/` carries no `ui/ViewItem:*` line and
18276+ // check (b) never sees the tombstone — the row is declared, not checked.
18277+ // D2: `view-item-owner-hidden-removed`.
18278+ 'ui/ViewItem:hidden',
18279+ // #20085 (ADR-0049 enforce-or-remove; triage direction 「retire both keys」).
18280+ // `ViewItem.owner` named the user a `personal` view item belonged to, and
18281+ // nothing ever read it: no writer and no reader of the view-item key in the
18282+ // framework, in objectui at its pin and at `main`, or in cloud, and both
18283+ // switcher read paths filter on `viewKind` + `object` only — so a view marked
18284+ // as one user's was listed for everyone who can read the object. Per-user view
18285+ // scoping is a parked direction (ADR-0017, amended 2026-09-04). Tombstoned with
18286+ // `retiredKey()` on the shared `viewItemBaseShape()`, because that shape also
18287+ // feeds the `.strip()` wire member (`ui/ViewItemWire`, registered beside this
18288+ // row), where a bare deletion would strip in silence. ⚠️ No gate below can
18289+ // JUDGE this row: `ui/ViewItem` is a discriminated union, whose emitted JSON
18290+ // Schema has no top-level `properties`, so `authorable-surface/` carries no
18291+ // `ui/ViewItem:*` line and check (b) never sees the tombstone — the row is
18292+ // declared, not checked. D2: `view-item-owner-hidden-removed`.
18293+ 'ui/ViewItem:owner',
18294+ // #20085 — the wire carrier of `ui/ViewItem:hidden` (see that row for the
18295+ // measurement). `ViewItemWireSchema` is member 1 of the `view` union
18296+ // `saveMetaItem` validates; it is built from the same `viewItemBaseShape()`, so
18297+ // the one tombstone refuses the key there too instead of letting `.strip()`
18298+ // drop it in silence — registered under both def keys, the
18299+ // `integration/DeclarativeConnectorEntry:connectionTimeoutMs` precedent. Same
18300+ // blind spot as its sibling: a discriminated-union def emits no top-level
18301+ // `properties`, so no gate judges this row.
18302+ // D2: `view-item-owner-hidden-removed`.
18303+ 'ui/ViewItemWire:hidden',
18304+ // #20085 — the wire carrier of `ui/ViewItem:owner` (see that row for the
18305+ // measurement). `ViewItemWireSchema` is member 1 of the `view` union
18306+ // `saveMetaItem` validates; it is built from the same `viewItemBaseShape()`, so
18307+ // the one tombstone refuses the key there too instead of letting `.strip()`
18308+ // drop it in silence — registered under both def keys, the
18309+ // `integration/DeclarativeConnectorEntry:connectionTimeoutMs` precedent. Same
18310+ // blind spot as its sibling: a discriminated-union def emits no top-level
18311+ // `properties`, so no gate judges this row.
18312+ // D2: `view-item-owner-hidden-removed`.
18313+ 'ui/ViewItemWire:owner',
1826118314 // </os-generated retired-key:18>
1826218315 ],
1826318316};
0 commit comments