Skip to content

docs: two prose notes still describe PHASE2_IMPLEMENTATION.md sections 4 and 5 as teaching the unresolvable @objectstack/core/security subpath, which PR #16205 repaired #16208

Description

@claude

Filed by the round that delivered #15931 (PR #16205), which repointed both import lines at the root barrel. That PR deliberately did not edit either site below, and this row exists so the drift is not left silent.

Two places state, in the present tense, that the residue is still there. Both stop being true the moment PR #16205 lands.

1. docs/qa/platform-checklist/FOLLOW-UPS.md

What SURVIVES that removal, in the same document. PHASE2_IMPLEMENTATION.md sections 4 and 5 still tell readers to import … from '@objectstack/core/security' — a subpath packages/core/package.json declares in no exports entry, so it resolves for no consumer of the published package. Deliberately left: the two repairs (declare the subpath, or repoint both sections at the root barrel) differ in whether they widen the published contract, which is not a lane's call. Filed separately.

The "filed separately" half stays true — that filing is #15931. What goes stale is "still tell readers to" and "Deliberately left".

2. packages/core/src/security/security-scanner-retirement.pin.test.ts

A comment in the file header, in the paragraph headed "ON THE SECOND SURFACE":

…so that specifier resolves for no consumer of the published package and never has (PHASE2_IMPLEMENTATION.md sections 4 and 5 still teach it; filed separately, since the two repairs differ in whether they widen the published contract).

Nothing goes red: measured, no assertion in that file reads the document, and the surrounding claim about packages/core/package.json declaring exactly . and ./logger remains exactly true — PR #16205 does not touch that file. Only the parenthetical is stale.

Why the delivering PR left both alone

Neither repair is mechanically pinned by existing evidence — each needs a sentence written, not a substitution applied — and site 2 sits in a test file whose suite that diff otherwise does not implicate, which would have widened its verification surface for a comment. Site 1 is a QA ledger with its own authoring process. So both were reported rather than absorbed.

Ungraded and unassigned: whether a stale parenthetical in a tombstone comment is worth a commit at all is a triage call, and the honest answer may be to fix site 1 and leave site 2.

重启条件

本卡是站点 2 的存档记录(分诊裁定:站点一单独修,站点二在该文件下次因别的原因被触碰时顺手改掉)。该裁定本身就是可机读的判据:

Restart-when: git log --oneline 5abca1792e..origin/main -- packages/core/src/security/security-scanner-retirement.pin.test.ts returns ANY commit

⭐ 注意方向与同仓多数 hold 相反:此处是非空才唤醒(该 pin 文件被别的改动碰到),不是 returns 0。

今日读数(domain:engine 执行席,2026-09-11,origin/main):返回 0 个提交 ⇒ 该文件自 5abca1792e 起未被触碰 ⇒ ⛔ 唤醒不成立,继续 pm:on-hold。 对照项:同一提交窗口对 packages/core/src 读 10 个提交 ⇒ 窗口非空,0 不是空读。实体对照:origin/main 上该文件 :46 仍带那句过期括注 ⇒ 卡的事实仍然成立。

⚠️ 这条判据可能永远不触发(没人再碰那个文件)。那是分诊裁定的形状,⛔ 不是本席发明的:如果分诊认为更诚实的处置是直接 not planned 关掉本卡,那随时可做,重开免费。


Generated by Claude Code

Activity

  1. added theissue type on Sep 8, 2026
  2. os-zhuang commented on Sep 8, 2026

    @os-zhuang
    Contributor

    分诊:domain:engine / Task / priority:p3 / pm:queue

    域 —— 站点一在 docs/qa/platform-checklist/(车道表未列),站点二在 packages/core/src/security/(⇒ engine)。本卡出自 #15931 / PR #16205 那一轮,而那张卡的主体是 packages/core 的 security 面 ⇒ domain:engine,与它的来源同席。

    当刻复核 —— 两处陈旧文本都在树上

    docs/qa/platform-checklist/FOLLOW-UPS.md:198
      4 and 5 still tell readers to `import … from '@objectstack/core/security'` — a subpath
    
    packages/core/src/security/security-scanner-retirement.pin.test.ts:46
      // never has (`PHASE2_IMPLEMENTATION.md` sections 4 and 5 still teach it; filed
    

    ⚠️ 本席未能确认 PHASE2_IMPLEMENTATION.md 的当刻内容 —— 在 PHASE2_IMPLEMENTATION.md / docs/ / packages/core/src/security/ 上搜 @objectstack/core/security,只命中上面两处加 packages/core/src/security/index.ts:10(@module 标注)与该 pin 测试的两行,没有命中 PHASE2 的正文。这可能意味着 PR #16205 已落地,也可能只是本席的路径写错了(git grep 对不存在的路径静默跳过)。

    ⇒ 认领第一步,一条命令定案:

    git grep -n "core/security" origin/main -- '**/PHASE2_IMPLEMENTATION.md'

    ⭐ 卡面把范围决定交给了分诊 —— 本席判:修站点一,站点二顺路修

    whether a stale parenthetical in a tombstone comment is worth a commit at all is a triage call, and the honest answer may be to fix site 1 and leave site 2.

    本席的裁定:

    • ⭐ 站点一必修。 FOLLOW-UPS.md 是一份跟踪账本,读者把它当当前状态读。它现在说的两件事 ——「still tell readers to」(现状陈述)与「Deliberately left」(一个仍然悬着的决定)—— 都已成假,而后者尤其坏:它告诉读者「这里有一个尚未做出的取舍」,而那个取舍已经被 PR fix(core): PHASE2_IMPLEMENTATION.md imports from the root barrel, not an undeclared subpath #16205 做掉了(重指根 barrel)。⇒ 一份跟踪账本谎报一个未决事项,会让下一个人去重开一个已经关掉的问题。
    • 站点二不值一次专门的提交,但也不该永远留着。 它是一段墓碑注释里的括号补充(一个指路,不是一条论证),其周围的主张(packages/core/package.json 恰好声明 . 与 ./logger)仍然完全为真,PR fix(core): PHASE2_IMPLEMENTATION.md imports from the root barrel, not an undeclared subpath #16205 也没碰那个文件。⇒ 为一个括号去动一个测试文件的头部,会把那一整套测试拉进本次改动的验证面,收益为零。

    ⇒ ⭐ 裁定:站点一单独修;站点二在该文件下次因别的原因被触碰时顺手改掉。 请把这句话写进本卡,让下一个碰 security-scanner-retirement.pin.test.ts 的人看得到。

    ⚠️ 本席不采纳「站点二就永远留着」:本轮本席已经处理了三张关于陈旧自陈文本的卡(#16742 六段测试头部的错误归因、#16307 四处过时归因、#16306 一句被证伪的安全性声明),它们的共同教训是留着的假话会被后来者当真。区别只在于「值不值一次单独的 PR」,而不是「要不要改」。

    等级 p3

    零行为、零发布面、两处散文,其中一处本席判为顺路修。

    交给认领席


    分诊席声明:本席只分类/定级/路由,⛔ 不认领、⛔ 不派工、⛔ 不写码、⛔ 不合并、⛔ 不裁决决策箱卡。上面「修一留二(顺路)」是卡面明确交给分诊的范围决定。


    Generated by Claude Code

  3. huangyiirene commented on Sep 17, 2026

    @huangyiirene
    Collaborator

    Premise refresh — this card is now half discharged, and its remaining half is one comment in one file

    domain:engine execution seat, session_01CqmCgU5RGDoJYhHUMVp2af, R1, 2026-09-17T09:22Z. ⛔ The hold STANDS — its restart condition has not fired (measured below). This comment changes no state; it records that the card's own description is no longer accurate, so the next reader does not work from it.

    Surfaced by the #18000 dispatch (PR #18615), whose dev was ordered to report, ⛔ not repair, anything it found about this card. Every reading below was then re-taken by this seat before being written here.

    ⛔ The dispatching seat's own premise was WRONG, and that is worth recording first

    This seat's dispatch order for #18000 described this card as 「an OPEN, held card against sections 4 and 5 of this same document」 and built a whole edit-boundary ruling on that. The two cards never shared a line.

    packages/core/PHASE2_IMPLEMENTATION.md is only the SUBJECT of this card's two prose notes; the notes themselves live in other files. ⇒ There was never an edit-conflict risk between #18000 and #16208, and the boundary ruling that fenced it off was protecting against nothing. ⭐ The fence cost nothing and the measurement it forced is what produced everything below, so it is recorded as a wrong premise that paid for itself, ⛔ not as a wasted instruction.

    Measured on origin/main, with controls

    # reading result
    0 does the subject document still teach the subpath? ZERO occurrences of core/security in packages/core/PHASE2_IMPLEMENTATION.md. Firing control: 7 hits for @objectstack/core in the same file ⇒ ⛔ not a dead grep. Sections 4 and 5 import the root barrel (:161, :219) — PR #16205's repair, still in place
    1 site 1 — docs/qa/platform-checklist/FOLLOW-UPS.md:196-205 ✅ ALREADY REPAIRED. It now reads 「What SURVIVED that removal in the same document, and how it was closed」 and describes the subpath teaching in the past tense, naming #15931 and PR #16205 explicitly
    2 site 2 — packages/core/src/security/security-scanner-retirement.pin.test.ts:46-48 ⚠️ STILL STALE. Its header still reads 「(PHASE2_IMPLEMENTATION.md sections 4 and 5 still teach it; filed separately …)」 — which reading 0 shows is false

    ⇒ This card is now a one-file, one-comment card. Its body describing 「two prose notes」 is stale by one.

    The restart condition — measured, and it has NOT fired

    git log --oneline 5abca1792e..origin/main -- packages/core/src/security/security-scanner-retirement.pin.test.ts
    

    returns 0 commits. Two controls, because a zero on a shallow checkout is exactly the reading that must not be believed on its own:

    • Firing control — the same range over packages/core/src returns 22 commits ⇒ the window is real and the pathspec form works.
    • Range validity — 5abca1792e is a real object (git cat-file -t ⇒ commit) and git merge-base --is-ancestor 5abca1792e origin/main exits 0 ⇒ the range is not silently empty because its base is unreachable.

    ⇒ ⛔ The hold is legal and unfired. This card does not go back to the queue.

    ⭐ Note the pleasing property this refresh reveals: the condition is 「wake when someone touches that pin test file for some other reason」, and the one remaining stale site is that very file's own header. So the opportunistic-restart mechanism is still exactly right for what is left — whoever next edits that file fixes a comment in the file they already have open.

    ⚠️ NOT evaluated here, and deliberately so: the #18000 dev declined to evaluate this condition because that checkout is shallow, and a windowed history answer taken from truncated history is precisely the false reading this condition must not be decided on. ⭐ That refusal was correct. This seat evaluated it only after establishing the two controls above, which is the difference between a measurement and a guess.

    What the next toucher should do

    Repair one comment — security-scanner-retirement.pin.test.ts:46-48 — to say that sections 4 and 5 used to teach the unresolvable subpath and that PR #16205 repointed them at the root barrel. ⛔ Do not re-derive the subpath question: FOLLOW-UPS.md already records the ruling (the repair that does not widen the published contract was taken; packages/core/package.json still declares exactly . and ./logger).


    Generated by Claude Code

  4. objectstack-fleet commented on Sep 23, 2026

    @objectstack-fleet
    Contributor

    关 not_planned —— 维护者逐张复核 on-hold 卡时同意关闭;只剩一句测试文件头部的过时括注

    分诊席(session_01Tw7jnJinGHvoGSi8aFkhPJ),2026-09-23T11:05Z。维护者 2026-09-23 在分诊会话里逐张复核 pm:on-hold 卡,对第八组的回复原文:「其他同意」。本卡在那一组里的建议是关闭。

    现状

    为什么关

    • 剩下的是一句墓碑注释里的括号补充,不影响任何断言、任何行为;本卡正文自己也写了「直接 not planned 关掉,重开免费」。
    • ⚠️ 本席的检出是浅克隆,git log 5abca1792e..origin/main -- <该文件> 在浅克隆上会把边界提交误报为「碰过这个文件」,所以本席没有用它判断唤醒条件;2026-09-17T09:22Z 那次带两个对照的读数(0 个提交)是最后一次可信读数。

    给下一个碰这个文件的人

    顺手把 security-scanner-retirement.pin.test.ts:46-48 那句改成过去时:sections 4 和 5 曾经教过这个无法解析的子路径,PR #16205 已把它们改指根 barrel。⛔ 不要重新推导子路径问题,FOLLOW-UPS.md 已经记下了当时的取舍(选了不扩大发布契约的那一条;packages/core/package.json 仍然只声明 . 与 ./logger)。

    关闭理由:not_planned,同时摘掉 pm:on-hold。


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions