Repository navigation
[finding] Three files still tell authors check:cross-package-test-inputs recognises "exactly two seeds" — it recognises five, and the prose is load-bearing #10163
Copy link
Copy link
Labels
Description
Activity
Triage routing: the three files carrying the stale "exactly two seeds" prose sit on the
check:cross-package-test-inputstooling face ⇒domain:devx; keptfinding(load-bearing prose, but nothing breaks today — a mechanical 3-file correction when graded).
Generated by Claude Code
- added a commit that references this issue
on Aug 21, 2026 { "issue": 10163, "status": "done", "branch": "claude/issue-10163-cross-package-test-inputs-instructions", "pr": "https://github.com/objectstack-ai/objectstack/pull/10561", "premise_still_valid": true, "summary": "The card's premise held and under-counted in both directions. WHAT THE GATE DOES, established from its source (pathExpression + RECOGNISED_PATH_SPELLINGS) and its --self-test (60 cases green), never from the card or the three files, then confirmed by a probe calling its exported escapingBindings(): it resolves FOUR directory-naming seeds (dirname(fileURLToPath(import.meta.url)) incl. path./url. prefixed forms, __dirname, import.meta.dirname, dirname(import.meta.filename)), plus import.meta.url / import.meta.filename walked at hereDepth+1, plus new URL('<rel>', import.meta.url) bare or under fileURLToPath. Negative controls process.cwd(), a template-literal path and a bare relative literal are NOT resolved, so the probe can fail. 'Exactly two seeds' is wrong on every counting. CENSUS: the card counted three files; it is FOUR, and one of the three carried three stale claims, not one. Corrected (all pointing at RECOGNISED_PATH_SPELLINGS instead of restating a number, per triage direction A): (1) plugin-auth/managed-extension-fields.test.ts - the seed count; the 'ONLY escaping read the gate can see in plugin-auth' claim, false since #10161 gave the package a second visible escaping test; and 'the findUp walk from process.cwd() that rate-limit-storage-isolation.test.ts ... use', which that file stopped doing in #10161. (2) platform-objects/managed-api-method-affordance-sweep.test.ts - the same seed count. (3) scripts/check-type-check-coverage.mjs - the same claim in a TEST_DEBT note, the worst-placed instance. (4) NOT IN THE CARD: cli/src/commands/serve-multi-node-cap-advisory.pin.test.ts claimed the gate CANNOT follow a new URL() seed or a resolve() nested into the read - stale in the opposite direction. It follows both; what those spellings actually miss is the FLAT literal collector, which is now the reason the note gives for keeping the whole path in one literal. Comments and one note string only: stripping comments leaves the three .ts files byte-identical to origin/main, and the gate's own repoRelativeLiterals roster for each is unchanged, so no declaration and no turbo.json input moves. AGENTS.md was checked and needs NO change - its mirror already lists every spelling - so there is no governed wording to propose.", "tests": "Gate union re-derived with `node scripts/pm/dispatch-gates.mjs` (no path arguments, it read the change set itself: 4 paths vs merge base ceb33a9f1) and run on the FINAL commit c41a088b31. Each exit status captured before any pipe (cmd > file 2>&1; EXIT=$?), and each verdict below is the line the gate printed, not $?: check:cross-package-test-inputs EXIT=0 'All 60 self-test cases passed.' + 'OK: 12 package(s) read outside themselves, all declared, and turbo.json hashes every declared glob.'; check:pm-half-states EXIT=0 '715 cases pass'; check:slot-lookup EXIT=0 'ratchet holds: 107 unswept site(s), none new'; check:test-source-alias EXIT=0 '72 packages with tests scanned'; check:type-check-coverage EXIT=0 '64/77 workspace packages type-checked'; check:type-source-resolution EXIT=0 '76 packages ... scanned'; check:nul-bytes EXIT=0 '6178 text file(s) ... no raw ASCII control bytes'; check:i18n EXIT=0 '9 package(s) - all bundles in sync' (needed @objectstack/cli built first - done under scripts/pm/os-verify-lock.sh, VERDICT command-exit 0, held 389s, waited 267s); check:engine-double-contract EXIT=0 '329 (file, verb) row(s) held'; check:where-matcher EXIT=0 '0 silently-wrong and 0 unjudged matcher(s); none new'; check:query-options-erasure EXIT=0 '240 site(s) in 47 file(s) - at the ceiling'; check-affected-docs EXIT=0 '281 cases pass'. TWO DECLARED NARROWINGS. (a) check:type-check-debt --re-measure NOT run: it needs the whole workspace closure built and another agent was queued on the shared lock. It cannot move here - stripping comments from the three edited .ts files leaves them byte-identical to origin/main, and that instrument was proved in BOTH directions (appending one real statement to an untouched control file flips it to CODE CHANGED; removing it flips it back). The .mjs edit is one note: string, no errors: count. (b) scripts/pm/check-half-states.mjs full run exits 3 'PREREQUISITE NOT MET - the token in the environment is not a valid GitHub credential' - a container limitation, not a verdict on this diff; the --self-test form lint.yml invokes is green. MEASUREMENT OF THE GATE (independent of the card): probe at scratchpad issue-10163/probe-seeds.mjs calls the gate's exported escapingBindings() on 9 seed spellings + 3 negative controls - all 9 RECOGNISED, all 3 not seen. probe-cli-claim.mjs repeats it at the cli file's real coordinates: both spellings that file called unfollowable are FLAGGED, both negative controls are not. probe-flat.mjs measures the other half via the exported repoRelativeLiterals(): the current join(REPO_ROOT, <whole literal>) spelling IS collected, the two ascent-relative alternatives are NOT - which is what the corrected wording now says. TWO ABLATIONS, and NEITHER NEEDS A REBUILD - stated rather than assumed: this gate is a dependency-free SOURCE scan that reads the .ts files off disk (no dist, no bundler, no vitest alias), so a source edit is live on the next run; the dist/ preflight does not apply, and nothing was built for them. Each mutation was confirmed ON DISK by counting the removed and the injected string, never by an editor exit code. (1) plugin-auth/managed-extension-fields.test.ts, seed -> process.cwd(): on disk 'const HERE = __dirname;' 1 -> 0 and the injected spelling 0 -> 1; result GREEN, exit 0, --list-escapes silently drops the file while packages/**/*.object.ts stays declared and held by nothing. Restore confirmed on disk (mutation 0, original 1) and the gate re-run green. That falsifies the old prose's promised consequence and is filed as #10566. (2) platform-objects/managed-api-method-affordance-sweep.test.ts, same mutation, same on-disk confirmation: exit 1 naming '@objectstack/platform-objects declares a cross-package input radius, but no test in it reads outside the package any more' - so that file's stale-declaration consequence IS still real, and the corrected note now cites the measurement instead of asserting it. Restored, confirmed on disk, green. CENSUS + POSITIVE CONTROL: the expression grep -rIl 'cross-package-test-inputs|CROSS_PACKAGE_TEST_INPUTS' over tracked files (node_modules/dist/.turbo/.git excluded) returns 22 files and FINDS ALL THREE the card named - that is the positive control; no zero-hit is claimed anywhere without it. A second, gate-name-independent anchor (seed-prose near dirname/import.meta/escap/recognis/spelling) returns the same set plus AGENTS.md and the detector itself, adding no sixth file. A third pass for 'RECOGNISED_PATH_SPELLINGS' shows it is referenced ONLY inside the detector today - which is what these four corrections change. All 22 were read: 4 stale (fixed), 1 more stale inside scripts/check-cross-package-test-inputs.mjs itself (off-limits, filed as #10565), 17 checked accurate and deliberately untouched.", "open_questions": [], "out_of_scope_findings": [ "filed as #10565: the detector's OWN comments say 'the two seeds' four times (:660, :673, :679, :695); at :660 and :679 four directory seeds now sit below the phrase - this is the source the three external copies were made from. Not touched: scripts/check-cross-package-test-inputs.mjs is edited by open PR #10450.", "filed as #10566: verify() reports a stale declaration per PACKAGE, never per GLOB, so once a package has a second escaping test a declared glob can go held by nothing with the gate green - measured by ablation, with the single-escaping-test package as the positive control that the limb still fires. The fix is a change to the gate, so it belongs after PR #10450, not as a rider here." ] }
Generated by Claude Code
- added a commit that references this issue
on Aug 21, 2026 - added a commit that references this issue
on Aug 24, 2026 - added a commit that references this issue
on Sep 1, 2026
Observation-class finding, measured while implementing #10029 (PR #10161). No gate is red today. Filed unassigned, no
pm:queue.Measured
scripts/check-cross-package-test-inputs.mjsresolves seed expressions inpathExpression(). On2d3860df9it recognises five directory-seed spellings, not two:dirname(fileURLToPath(import.meta.url)):631__dirname:634import.meta.dirname:637dirname(import.meta.filename):638-640import.meta.url/import.meta.filename(the FILE, walked athereDepth + 1):653plus
new URL('<rel>', import.meta.url)as a seeded chain step (:661). The gate's ownRECOGNISED_PATH_SPELLINGS(:493-505) — printed in its failure text — lists all of them correctly. #8995 and #9763 widened the set after the "two seeds" wording was written.Three files outside the detector still tell the reader there are two:
packages/plugins/plugin-auth/src/managed-extension-fields.test.ts:306packages/platform-objects/src/managed-api-method-affordance-sweep.test.ts:104scripts/check-type-check-coverage.mjs:755— "…is one of the two seedscheck:cross-package-test-inputsrecognises…"Why it is worth recording rather than shrugging at
This is not idle prose. In both test files the sentence is the stated reason a specific seed may not be changed — it is what stops a future edit from making that package's declared radius invisible and reopening #7802's blind spot. A reader who checks the claim against the detector finds it false, and a reason that does not survive checking is a weak guard for a rule that matters. The
check-type-check-coverage.mjsinstance is worse-placed still: it is failure text an author reads at the moment they are choosing a seed, and it under-reports their options by three.The drift direction is benign — the prose is narrower than the detector, so following it is still correct — which is exactly why nothing has caught it. Both extensions (#8995, #9763) updated
RECOGNISED_PATH_SPELLINGS, which is the list the gate prints; neither swept for the count restated in prose elsewhere.Related, and NOT the same claim
managed-extension-fields.test.ts:306-311also says its walk is "the ONLY escaping read the gate can see in plugin-auth". PR #10161 makes that false by makingrate-limit-storage-isolation.test.tsvisible too:That file was deliberately left untouched by #10161 (it is a hot single surface, and its load-bearing half — that it alone holds the
packages/**/*.object.tsglob — stays true, since the rate-limit test holds only the two new consumer globs). Only the incidental "only" is now stale, so it belongs here with the rest of the sweep rather than as a rider on that PR.Directions (not a decision)
RECOGNISED_PATH_SPELLINGSas the single source rather than restating a number that drifts. Small, and removes the restatement that caused this.A is cheap and is what stops the next extension from producing a fourth stale copy.
Refs
#10029 / PR #10161 (where this was measured) · #8995 and #9763 (the extensions that widened the set) · #7802 (the blind spot the prose guards against)
Generated by Claude Code