Skip to content

The scope-less attribution corrected in #14803 already shipped: it is in the published 17.3.0 CHANGELOG of @objectstack/runtime and @objectstack/metadata-protocol #16122

Description

@claude

The sweep in #14803 corrected five platform-side comments that attributed the scope-less served row to examples/app-multi-package's module. While re-locating those sites on current origin/main, one of the five turned out not to be a comment at all, and not to be pending either.

Measured

.changeset/packages-read-door-writable-verdict.md — the site #14803 calls "pending, so it ships the false attribution into the release notes unless corrected first" — no longer exists. It was consumed by the version bump:

$ git log --oneline -- .changeset/packages-read-door-writable-verdict.md
8a1bad8b8 chore: version packages (#11336)     <- deleted it, 2026-09-04 10:20:24 +0000
63f3b4347 feat(packages): GET /packages and GET /packages/:id rows carry the server's own writable verdict (#14375) (#14430)

Its body is now release history in two published packages:

  • packages/runtime/CHANGELOG.md:1708, under the ## 17.3.0 heading
  • packages/metadata-protocol/CHANGELOG.md:957

and 17.3.0 is published: registry.npmjs.org/@objectstack/runtime reports dist-tags.latest = 17.3.0 and the version is present. Both packages ship CHANGELOG.md in their files[], so the text is inside the npm tarball an upgrading reader greps.

The sentence now carried by both published CHANGELOGs:

isWritablePackage reads engine.manifests FIRST, so a package booted from an artifact through registerApp is read-only whatever its scope says — and a scope-less type: module carried by a multi-package artifact lands there too.

The second clause is false, for the reason #14803 measured and #14597 fixed at the fixture: defineStack parses every packages[] entry through ManifestSchema, whose scope is .default('project'), so no package of a compiled artifact is ever scope-less. Re-measured on origin/main 9b459b791: ManifestSchema.parse of the orders body yields scope: "project", while SchemaRegistry.installPackage of the same unparsed body yields a record whose manifest keys are exactly the authored ones, with no scope key.

The decision this needs

The #14803 PR corrects every live source comment and adds a changeset stating the correction, so the retraction reaches the next release notes. It deliberately does not touch either CHANGELOG.md, because those are generated release history rather than authored prose, and rewriting them is not a call a code PR should make on its own. Two routes, and the maintainer picks:

Route B is the one that needs a ruling; route A is already in flight.

Notes


Generated by Claude Code

Activity

  1. os-zhuang commented on Sep 6, 2026

    @os-zhuang
    Contributor

    分诊 · domain:devx / documentation / priority:p3 / needs-user-decision

    分诊席位。⛔ 不认领、不派发、不写代码、不合并、不裁决 decision-box 卡 —— 本卡就是(路线 B 需要裁决,卡自陈,我同意)。origin/main @ 932acc3d,2026-09-06T03:18Z。

    三条读数复现

    断言 实测
    那个 changeset 文件已不存在 ✅ .changeset/packages-read-door-writable-verdict.md 在 origin/main 的树里 0 条目
    文本已进 runtime 的 17.3.0 ✅ packages/runtime/CHANGELOG.md:1708 — and a scope-less \type: module` carried by a multi-package artifact lands`
    文本已进 metadata-protocol 的 17.3.0 ✅ packages/metadata-protocol/CHANGELOG.md:957 — 同一句,逐字

    ⇒ 卡的核心事实成立:那句被 #14803 判定为假的话,已经不是待发布的 changeset,而是两个已发布包的 release history。

    车道 domain:devx

    路线 B 的落点是两个 CHANGELOG.md。⚠️ 它们分属两条车道(packages/runtime 在 domain:cli 行,packages/metadata-protocol 在 domain:engine 行),但交付物是发布记录的处置,不需要任何一侧的领域知识 ⇒ 归 domain:devx(工程/发布面)。⛔ 若裁 B 时执行席位认为该按包分派,打 pm:retriage,我重路由。

    ⚠️ 顺带一条本仓硬规矩,接卡人必须知道:⛔ 绝不在代码 PR 里改 content/docs/releases/。路线 B 若被裁中,必须是独立的 docs-only PR,⛔ 不能搭任何代码变更的车。(本卡改的是包内 CHANGELOG.md 而非 content/docs/releases/,但同一条精神适用:发布记录的改写自己走一趟。)

    四面框(给裁决者)

    要裁的只有一件事:已发布的 release history 能不能就地改写。 路线 A 已在飞(#14803 的 PR 修正所有活的源码注释,并用 changeset 把更正送进下一版的 release notes)。

    ① 长远合理性(≥50%)
    两种「诚实」互相冲突,这是本卡唯一的难点:

    • A 的诚实 = 发布记录忠实记录当时发布了什么(包括当时写错的话),更正出现在下一版条目里;
    • B 的诚实 = 读者 grep 到的那句话是对的。

    ⇒ 这是一条项目层面的档案政策,⛔ 不是一次文案修补。裁一次,以后同类照办。

    ② 实际业务拉动 —— 低,且卡自己说清了为什么
    ⭐ npm tarball 无论如何都保留旧文本。 17.3.0 已发布(dist-tags.latest = 17.3.0),B 只能改 repo 与 GitHub 视图。⇒ 一个从 npm 装包并 grep CHANGELOG.md 的升级者,在 B 之后仍然读到那句错话。这条把 B 的收益压得很低。

    ③ 防 AI 犯错
    一个 agent 读 CHANGELOG 学「scope-less type: module 会落进只读」,会据此写错的诊断。⚠️ 但同一个 agent 更可能读的是源码注释,而那五处 A 已经在修。⇒ 这条轴对 B 的支持弱于表面。

    ④ 创业阶段不扩散
    A = 零额外工作(已在飞)。B = 一个 docs-only PR + 一条以后要一直遵守的先例。

    ⚠️ 裁 B 的隐藏成本
    就地改写 17.3.0 条目后,repo 里的 CHANGELOG 与 npm tarball 里的不再一致。⇒ 任何比对两者的工具或人会看到差异,而这个差异本身没有记录。若裁 B,建议同时要求在被改的段落里留一行「corrected on , see #16122」——⛔ 否则是用一个静默的不一致换掉一个明说的错误。

    优先级 p3

    已发布记录里的一句错话,npm 侧无论如何不变,源码注释侧 A 已在修。⇒ 无人今天受损。p3。

    ⚠️ 去重口径

    卡诚实标了:370 条最近更新的 issue(开+关)grep changelog / release note / scope-less,只命中 #14803 自己;并声明「这是一个按时间的切片,不是全量 backlog」,且当时 MCP 搜索配额耗尽。
    ⇒ 本席位不把它升级为穷举(本轮反复出现的纪律:⛔ 不把别的席位的「非穷举」去重改写成「穷举」)。若有重复浮现,按重复关掉本卡。


    Generated by Claude Code

  2. os-zhuang commented on Sep 6, 2026

    @os-zhuang
    Contributor

    交叉标注:#16056 是同一个体裁问题的第二例,建议一次裁决两张

    分诊席位,2026-09-06T04:11Z。⛔ 不改本卡标签(domain:devx / documentation / needs-user-decision / p3 保持)。

    #16056 问的是:content/docs/releases/v17.mdx 的一句升级指引(「it also prints runtime 17.0.0 on a 17.3.0 install」)在 #15585 的 CLI 修复落地后失真,该改还是该留。它给的两读法与本卡同构:

    本卡 #16122 #16056
    载体 两个已发布包的 CHANGELOG.md(17.3.0 段) content/docs/releases/v17.mdx
    「留」的理由 发布记录忠实记录当时发布了什么 bullet 记录的是当时实测到什么(历史读法)
    「改」的理由 读者 grep 到的那句话应当是对的 它是读者今天落地页上的活指引(过期读法)

    ⇒ 两张共用同一条原则:发布说明到底是「档案」还是「指引」。 ⛔ 分开裁会得出不一致的答案——比如「CHANGELOG 是档案不改、releases 页是指引要改」,那需要明说这两者体裁不同,而今天没有任何地方这么说。

    ⚠️ 一处差异,裁决时值得注意:本卡的载体已随 npm tarball 发出(改了 repo 也改不了 tarball,收益因此受限);#16056 的载体只在站点上(改了就生效)。⇒ 同一条原则下,两者的收益不同,但该由同一条原则决定。

    已在 #16056 上做了对称标注。


    Generated by Claude Code

  3. os-zhuang commented on Sep 7, 2026

    @os-zhuang
    Contributor

    Ruling recorded — archive plus a dated in-place correction (director seat, decision batch #65, 2026-09-07; ruled together with #16056)

    Maintainer reply, verbatim: 「同意」 (all batch #65 recommendations adopted).

    General rule (same as recorded on #16056): published release text is never silently rewritten; a factual error gets a dated, referenced correction line appended in place, and the correction also rides the changeset into the next release (route A, already in flight via #14803's PR).

    This card. A docs-only PR appends one line under the ## 17.3.0 entry in both packages/runtime/CHANGELOG.md and packages/metadata-protocol/CHANGELOG.md: Correction (date): no package of a compiled artifact is scope-less — ManifestSchema defaults scope to project; the "scope-less type: module" clause above is withdrawn, see #14803 / #16122. The original sentence stays. This corrects the repository and GitHub view; the 17.3.0 npm tarball keeps the old text, and the correction line itself is the record of that difference (triage's caveat is thereby met — no silent inconsistency).

    Labels: needs-user-decision → pm:queue. Ledger on #12708 (batch #65).


    Generated by Claude Code

  4. claude commented on Sep 7, 2026

    @claude
    ContributorAuthor

    Claim: PM seat domain:devx @ objectstack (#6023), session session_01Vbw3RPgdtqesx4azk9SbW8, 2026-09-07T04:14Z — dispatching to an os-dev subagent on branch claude/issue-16122-changelog-correction-line.

    Clause-②: no

    Reason for no: the clause covers a card that changes a published contract's accept/reject behaviour or widens the public surface. This appends a dated correction line to two CHANGELOG.md files under an already-published ## 17.3.0 heading. No code, no schema, no gate, no accept/reject behaviour.

    Pre-dispatch premise checks at this claim (read on GitHub and origin/main, not on the card):

    • File surface free: none of the 33 open PRs touches packages/runtime/CHANGELOG.md or packages/metadata-protocol/CHANGELOG.md. The open Version Packages PR chore: version packages #15334 does not touch either file at its current head; when a release next runs it prepends a new entry above ## 17.3.0, which is not where this correction line goes. ⛔ This card is not a release action and the dev never touches chore: version packages #15334.
    • The ruling (5564448990, director seat, decision batch Add comprehensive test coverage for ObjectStack spec protocols - 100% coverage achieved #65) is the binding shape: append, do not rewrite. The original sentence stays exactly as published.
    • The card's measurements (the changeset file consumed by 8a1bad8b8, the two CHANGELOG line numbers, ManifestSchema's scope default of project) are the card's claims; the dev re-locates each on current origin/main before writing, because line numbers move.

    The assignee and this comment are the PM's write. The dev inherits both, posts no second claim, and never touches the assignee field.


    Generated by Claude Code

  5. baozhoutao commented on Sep 7, 2026

    @baozhoutao
    Contributor

    os-dev-report

    {
      "issue": 16122,
      "status": "done",
      "branch": "claude/issue-16122-changelog-correction-line",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/16493",
      "premise_still_valid": true,
      "summary": "Appended one dated correction sub-bullet under the existing #14375 entry in both packages/runtime/CHANGELOG.md (## 17.3.0, line 1719) and packages/metadata-protocol/CHANGELOG.md (## 17.3.0, line 970), nested alongside that entry's existing Why/Where/Additive sub-bullets to match the file's own markup. The original false sentence (\"...a scope-less `type: module` carried by a multi-package artifact lands there too\") was left byte-for-byte untouched -- appended-next-to, not rewritten. Verified both mechanism assumptions on origin/main before writing: (1) the false sentence is exactly where the card said, under ## 17.3.0 in both files, unchanged since the card was filed; (2) ManifestSchema.scope (packages/spec/src/kernel/manifest.zod.ts:319) is `z.enum([...]).default('project')`, and defineStack parses every packages[] entry through it, so the corrected fact holds. Also found that #14803's actual merge (commit 4b0508e1bd, PR #16123) already fixed the live source comment in packages/metadata-protocol/src/protocol.ts and shipped a changeset (.changeset/scope-less-booted-row-attribution.md) carrying the correction into the next release -- confirming the ruling's 'route A, already in flight' clause. No third file carries the same false clause (grepped the exact sentence fragment repo-wide: only the two ruled files matched).",
      "tests": "node scripts/check-nul-bytes.mjs: exit 0. node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack on final commit 14eeffb8ae derived 36 commands (29 path-matched + 7 whole-tree-declared) for the two changed CHANGELOG.md paths. Ran all 36 sequentially under scripts/pm/os-verify-lock.sh: 34/36 exit 0 (including pnpm check:doc-authoring, pnpm check:published-files, pnpm check:nul-bytes, check-comment-mask-adoption/-corpus, check-system-context-census, check-registry-log-declared, check-plugin-teardown-shape, check-keyed-text-bounds, check-undeclared-dep-imports, check-ci-filter-parity, check-closing-keyword-parity, check-reference-carrier-shape, docs-audit/check-affected-docs, docs-audit/check-drift-comment, and the check:cross-package-test-inputs/driver-memory-census/org-identifier/page-declaration-shape/refd-timer-probe/slot-lookup/test-source-alias/type-source-resolution/watch-hint-literal family). 2/36 (pnpm check:dts-closure, pnpm check:dual-build-cjs-loads) exit 3 PREREQUISITE NOT MET -- both read dist/ across the full 80-package workspace, not built for a docs-only two-line change; read as NOT MEASURED, not a failure -- identical precedented note on PR #15454 (the exact same shape of CHANGELOG-only correction PR) for check:dual-build-cjs-loads. Reconciliation: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran <36-command list> -> '36 derived, 36 run, 0 NOT-MEASURED, 0 UNRUN'. No pnpm test / pnpm typecheck run -- no source file touched, no package publishes. Changeset: none added; matches repo convention/precedent (PR #15454, labeled skip-changeset for the identical shape of already-published-CHANGELOG-only correction) -- leaving skip-changeset label application to the PM per this task's standing terms.",
      "mcp_calls": 5,
      "open_questions": [],
      "out_of_scope_findings": []
    }

    Generated by Claude Code

  6. claude commented on Sep 7, 2026

    @claude
    ContributorAuthor

    ACCEPT — PR #16493 (head 14eeffb8a, read 2026-09-07T04:28Z) — PM seat domain:devx @ objectstack (#6023), session session_01Vbw3RPgdtqesx4azk9SbW8. Reviewed against the three-dot diff origin/main...claude/issue-16122-changelog-correction-line (2 files, +6/−0), every changed line read; the dev's report is the increment I checked, not the evidence.

    • PR shape: draft, base main, first line Fixes #16122; full-body keyword scan reads that one binding and nothing else. One commit, size/xs, no model identifiers in title, body or diff.
    • Ruling implemented exactly (5564448990, director seat, decision batch Add comprehensive test coverage for ObjectStack spec protocols - 100% coverage achieved #65, maintainer 「同意」): the correction is appended, the published sentence is untouched — the diff has zero deletion lines in either file. In both files the new sub-bullet sits inside the same #14375 entry that carries the false clause, after its Why / Where / Additive siblings and matching their markup, and both are under ## 17.3.0 (verified: that heading is the last ## before the insertion point in each file). Wording carries all five parts the ruling named — the word Correction, the date, the corrected fact, the explicit withdrawal of the "scope-less type: module" clause, and the #14803 / #16122 references.
    • Premise re-verified by this seat, not taken from the card: packages/spec/src/kernel/manifest.zod.ts:319 reads scope: z.enum(['cloud', 'system', 'project']).default('project') — so the fact the correction asserts is true on origin/main. That mattered more than usual here: a correction line that is itself wrong is worse than the error it corrects.
    • Changeset: none, and skip-changeset applied by this seat just now (the label is the PM's write; the dev correctly left it alone and said so). Precedent named by the dev and checked: PR fix(spec): correct the offer-set claim in the icon-withdrawal CHANGELOG entry #15454, the same-shaped published-prose correction, merged with documentation + size/xs + skip-changeset and no changeset.
    • Governed: check-governed-merges.mjs --test on the final file list ⇒ NOT governed. Governed Surface Queue Guard green.
    • Scope discipline: content/docs/releases/** untouched, the Version Packages PR chore: version packages #15334 untouched, no third file edited (the dev checked and found none carrying the clause). The dev also noted Five platform-side comments still name the multi-package artifact as the source of the scope-less served row — it never was: defineStack materialises scope: 'project' #14803's live-source half already merged as PR docs(runtime,metadata-protocol): the scope-less booted row is a marketplace / offline import, not a multi-package artifact's module #16123 with its own changeset — that is route A, already in flight, exactly as the ruling describes.
    • Verification proportionality: two appended lines, so no heavy fleet run was owed and none was taken. dispatch-gates derived 36 commands, 34 exit 0 and 2 returned PREREQUISITE NOT MET (check:dts-closure, check:dual-build-cjs-loads — both need a workspace-wide dist/). Accepted as not owed for a docs-only diff, on the same precedent; ⛔ this is not a general waiver, and a code diff would owe both.

    Landing plan: flip point armed 04:55Z; flip ready when every row at 14eeffb8a reads completed/success on its own line (each Test Core (k/6), Lint & Repo Gates, each Type Check · row, each Dogfood Regression Gate (k/3), Dogfood Verify CLI, Build Core, Temporal Conformance, Check Changeset — the last should clear on the label, which that job reads live) → auto-merge → probe added_to_merge_queue. On MERGED → probe on origin/main: Correction (2026-09-07) = 1 in each of packages/runtime/CHANGELOG.md and packages/metadata-protocol/CHANGELOG.md; negative control: the published clause a scope-less \type: module` carried by a multi-package artifact landsstill = 1 in each (it must SURVIVE — this card appends, it does not delete); card closes byFixes, strip pm:dispatched`, clear assignee.


    Generated by Claude Code

  7. claude commented on Sep 7, 2026

    @claude
    ContributorAuthor

    LANDED — PR #16493 merged 2026-09-07T05:28:57Z (merge commit 8d0aede6c9f4b15a558205e6cfc097d2da397aac, head 14eeffb8a, Fixes #16122 closed the card). PM seat domain:devx @ objectstack (#6023), session session_01Vbw3RPgdtqesx4azk9SbW8, probe read 2026-09-07T05:42Z.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions