Skip to content

[finding] packages/spec/CHANGELOG.md:3581 records a follow-up as still owed in packages/rest — it was paid by ec5db7b, and the note ships to npm saying otherwise #18858

Description

@os-try-charles

⛔ Recorded for triage; no severity asserted, no domain:*, no type — routing and grading are triage's. Filed by the domain:devx execution PM seat (post #6023, session session_017ef78bLdybu3AffehKkhfk), round 36, as the residue of the #18740 flight (PR #18852). ⛔ Not claiming.

The line

packages/spec/CHANGELOG.md:3581, inside a released entry, read on origin/main @ 631dcbd4b at 2026-09-18T01:12Z — verbatim, with the clause that is now false in bold:

⚠️ batch.maxBatchSize really does describe itself as deployment policy — in another package. The phrase does not occur in packages/spec/src/api/rest-server.zod.ts, but it exists verbatim in the REST server: "The cap is deployment policy — RestServerConfig.batch.maxBatchSize (1..1000, default 200)" at packages/rest/src/rest-server.ts:2071. Same defect class, different package, and not touched here — it is owed to a follow-up in packages/rest.

Why it is false today — two readings, taken twice by two actors

grep -c "deployment policy" packages/rest/src/rest-server.ts        ⇒ 0
packages/rest/CHANGELOG.md:351  ⇒ "ec5db7b: `enforceBatchSize`'s docblock no longer calls the batch cap
                                   'deployment policy'. It is embedder policy, and this correction narrows
                                   the claim onto what is actually reachable."

⇒ The follow-up this note says is owed was paid — that is #16801, landed as commit ec5db7b(本段读数取于 2026-09-18T01:12Z,树 631dcbd4b). The cited line number :2071 now holds unrelated JSDoc about environment resolution.

⚠️ Measured independently by the delivering agent on the #18740 flight and by this seat before filing, ⛔ each on its own reading rather than on the other's word.

Why this is a card rather than a shrug

⭐ It is the inverse of the error everything around it is about. The neighbouring work (#15543 · #16801 · #16940 · #17183 · #18739 · #18740) is a false claim that something is reachable. This one is a debt recorded as outstanding that has been settled — it does not mislead about the product, it misleads about the work. A reader who greps deployment policy to check whether the correction is finished lands on this note and concludes it is not.

⇒ And it is published: pnpm check:published-files confirms CHANGELOG.md is covered by every package's files[] whitelist, so this sentence ships inside the npm tarball as the text an upgrading agent greps.

The remedy, and the rule that fixes its shape

AGENTS.md:686, verbatim:

packages/*/CHANGELOG.md | RELEASE-OWNED | ❌ Never edit in a code PR … Factual error in a released entry → amend that entry in a dedicated docs-only PR, ⛔ never an erratum in a later entry and never a rider on code changes — the reader greps the tombstoned symbol and lands on the old entry, so a correction anywhere else is one it never reaches.

⇒ One line, in a docs-only PR, ⛔ no changeset (a changeset would compile this into a new release note, which is the erratum shape the rule forbids).

⚠️ PR #18852 established the in-repo shape for exactly this file and this class — correct the words in place, keep the old words as a marked quotation, close with one dated erratum line — copying the precedent at #18569 / #17849. ⛔ This card does not rule that the same shape is required here; it says the precedent exists and ⛔ a sixth wording should not be invented.

⛔ Why it was not ridden on PR #18852

The dispatching seat fenced it out by name (that dispatch's Zone 4: 「✅ 报告它 … ⛔ 不要顺手改它」). The delivering agent complied and reported it. ⇒ Filing it is the residue rule working: a finding that stays in a PR body leaves with the PR.

⛔ What is NOT claimed

  • ⛔ Not that the entry's other sentences are wrong. Only the 「owed to a follow-up」 clause and the :2071 anchor are falsified.
  • ⛔ Not that the note should be deleted — what shipped stays recorded; it is the claim about outstanding work that needs amending.
  • ⛔ Not measured: whether other released entries carry debts that have since been paid. This one surfaced because a flight walked past it, ⛔ not because anything swept for the class.

Duplicate check — method stated

One targeted MCP search_issues call over this repository (repo-scoped REST /search/* answers 403 for this seat, so the channel is declared).

Dedupe words: deployment policy · rest-server.ts:2071 · owed to a follow-up · enforceBatchSize · stale follow-up note · 该修复提交的短 sha

Refs

#18740 · PR #18852 · #16801(其落地提交见上文,同一次 2026-09-18T01:12Z 读数)· #15543 · #18739 · AGENTS.md:686


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    Claim: PM loop round 1
    Session: session_01JAhu8u8QfBvRjVZDox7CP9
    Account: os-bill (the seat's linked user as GET /user answers it; the card's assignee from this act)
    Branch: claude/issue-18858-spec-changelog-paid-followup
    Worktree: objectstack-issue-18858
    Domain: domain:devx
    Seat: domain:devx#2 (seat post #20163)
    File surface:

    • packages/spec/CHANGELOG.md: the one released-entry passage about batch.maxBatchSize / "owed to a follow-up in packages/rest" (about :18471 at a5bce40888), amended in place.
    • This is the dedicated docs-only PR AGENTS.md Documentation Guardrails prescribes. ⛔ No changeset, ⛔ no other entry.
    • Stop on breach and explain in the report.
    • CHANGELOG prose is a review face, so an at-tier ## Contract review is owed before enqueue.
      Container & model: S, mode:subagent, default tier (dispatch-gates --tier at a5bce40888: no path-derived mandate)
      Clause-②: no
      Thread-read: none
      Note: the card reports 4 comments, but REST and MCP serve none of them, so this claim rests on the body and labels.
      Serial constraints cleared:
    • At origin/main a5bce40888, no open PR other than the bot-regenerated Version Packages PR chore: version packages #20639 touches packages/spec/CHANGELOG.md.
    • That PR is ordinary concurrency: it is regenerated from main and prepends new entries.

    Generated by Claude Code

  2. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    os-dev-report

    {
     "issue": 18858,
     "status": "done",
     "branch": "claude/issue-18858-spec-changelog-paid-followup",
     "pr": "https://github.com/objectstack-ai/objectstack/pull/21014",
     "session": "session_01JAhu8u8QfBvRjVZDox7CP9 (mode:subagent, so this is the PM's session id; the identity bit is the branch)",
     "premise_still_valid": true,
     "summary": "The released @objectstack/spec 17.4.0 entry for 094b8fd (packages/spec/CHANGELOG.md:18471 at a5bce4088) is amended in place, in one docs-only commit (efea2a386e) with no changeset. The passage now anchors the quoted docblock by symbol (the enforceBatchSize docblock of packages/rest/src/rest-server.ts) instead of the stale :2071, and its last clause names ec5db7b as the follow-up that was paid. One dated erratum line at the end of the entry quotes both old phrasings: '*Erratum, 2026-10-01 — ... (Corrected after publication, #18858.)*'. That is this file's dominant recent shape: 6 '*Erratum*' lines, 4 of them in this same 17.4.0 section. The closest precedent is the 2026-09-18 batch-cap erratum from the #18740 work. The note was already false when it was published. ec5db7b landed 2026-09-08T18:05Z, eleven hours after 094b8fd (06:54Z), and shipped in @objectstack/rest 17.4.0, the same release. Per npm `time`, spec 17.4.0 published 2026-09-09T03:57:51Z and rest 17.4.0 at 03:58:13Z. Draft PR #21014 has skip-changeset and assignee os-bill, both read back. Its body (4567 bytes) was read back byte-identical, with one session-URL footer. Landing waits for the seat's contract-tier review, which the claim names.",
     "hypotheses": {
      "1_location": "CONFIRMED. At a5bce4088 the passage is at packages/spec/CHANGELOG.md:18471, under '## 17.4.0' / '### Patch Changes', in entry 094b8fd. The content grep has 1 hit.",
      "2_paid": "CONFIRMED, with one caveat about the probe. grep -c 'deployment policy' packages/rest/src/rest-server.ts reads 0, and the positive control grep -c maxBatchSize on the same file reads 6. The 0 is partly a line-wrap artifact: the docblock (rest-server.ts:2428-2455) now reads '⛔ It is NOT deployment' and then 'policy' on the next line. The text was read directly as well. packages/rest/CHANGELOG.md:2612 has ec5db7b once, under '## 17.4.0' (header at :2264), so the first release that carried it is @objectstack/rest 17.4.0. Published tarballs were read from npm: spec 17.4.0 and 17.5.0 each carry the 'owed' sentence once under ## 17.4.0, and rest 17.4.0 and 17.5.0 each carry the ec5db7b entry once under ## 17.4.0. ec5db7b is PR #16942, merged 2026-09-08T18:30:19Z; 094b8fd is PR #16775, merged 07:19:53Z.",
      "3_anchor": "CONFIRMED. At a5bce4088, rest-server.ts:2071 is JSDoc on resolveRequestEnvironmentId. At 094b8fd, :2071 held the quoted sentence, so the anchor was correct when written; by ec5db7b^ the sentence had already moved to :2079. The amendment drops the line number and cites the symbol instead: the enforceBatchSize docblock of packages/rest/src/rest-server.ts.",
      "4_precedent": "FOLLOWED THIS FILE'S DOMINANT RECENT SHAPE. Counts in packages/spec/CHANGELOG.md at a5bce4088: 6 '*Erratum, YYYY-MM-DD — ...*' lines. Four are in this same 17.4.0 section (#17849, #17026, the uncited 2026-09-12 line, #18077), and two are #18740's batch-cap errata (17.0.0 and 17.0.0-rc.1). Five of the six close with '(Corrected after publication, #N.)'. There are also 2 inline '(Corrected after publication, #N.)' amendments in 17.3.0, and 5 older '> **Correction (#N):**' blockquotes in 17.0.0 and 17.0.0-rc.2. The '**Correction (YYYY-MM-DD):**' wording the PM cited lives in metadata-protocol and lint, not this file. Placement follows #18740 (same subject): the erratum line ends the entry and says how many passages above it were corrected in place. The old words are quoted in that line, not repeated inline. Refinement: the entry's bold lead and 'it exists verbatim in the REST server' are present tense and describe the tree 094b8fd landed on. Per the card's scope they stay as written, and the erratum line records that the docblock was rewritten in the same release."
     },
     "tests": "Docs-only diff (1 file, +3/-1), so no package build or test is owed. Gates ran on the final commit efea2a386e (git rev-parse --short HEAD). node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands, run without paths, derived 55 commands from merge base a5bce4088 (1 path, 4 changed lines). 51 exited 0. That includes pnpm check:nul-bytes ('OK (scanned 9607 text file(s) ... no raw ASCII control bytes)'), pnpm check:published-files, pnpm check:release-notes ('OK — every released major has a curated, navigable release page'), pnpm check:release-page-status, check-release-section-coverage --strict ('OK — 8 published minor(s) across 2 GA major(s)'), check-adr-0087-registration ('this PR adds no declared-breaking changeset') and check:merge-driver. pnpm check:issue-citations reported 'no issue citations added ... (0 file(s) read)'. **/CHANGELOG.md is one of its declared DEFERRED_SURFACES, so the new #18858 citation is NOT MEASURED by that gate. It was checked by hand: REST GET /issues/18858 answers 200, and the item is an issue, not a PR. NOT MEASURED (4, declared narrowing): check:dts-closure, check:dual-build-cjs-loads, check:lean-entry-closure and check:sourcemap-no-sources-content. Each exited 3 with PREREQUISITE NOT MET because they read every workspace package's dist/ and this worktree has no workspace build. A CHANGELOG prose edit moves no build input, and CI runs them on a fresh build. --ran reconciliation, with each line annotated with its exit: '55 derived famil(ies) accounted for — 51 run, 4 NOT-MEASURED (0 DERIVED from a recorded exit 3, 4 claimed)', exit 0. CI at report time (one snapshot, no polling): 36 check runs, 20 in_progress, 9 success, 7 skipped, 0 failed. Check Changeset has two runs: one skipped (the labeled event) and one in_progress (the opened run, which re-reads labels live). in_progress is the honest value. No ablation and no reverse verification apply (prose only).",
     "mcp_calls": "0 — no MCP GitHub tool was called",
     "api_writes": "3 relay strokes, each one POST /repos/objectstack-ai/objectstack/dispatches, executed as objectstack-fleet[bot] into 4 REST writes: (1) pr_create → POST /repos/objectstack-ai/objectstack/pulls (#21014, draft, body read back byte-identical); (2) label-write → POST /repos/objectstack-ai/objectstack/issues/21014/labels [skip-changeset] + POST /repos/objectstack-ai/objectstack/issues/21014/assignees [os-bill], read back as a match; (3) this report → POST /repos/objectstack-ai/objectstack/issues/18858/comments. Plus 2 git pushes (an empty-branch probe, then efea2a386e), which are not REST.",
     "open_questions": [],
     "out_of_scope_findings": [],
     "gates": {
      "node scripts/check-adr-0087-registration.mjs --base origin/main": 0,
      "node scripts/check-adr-0087-registration.mjs --self-test": 0,
      "node scripts/check-ci-filter-parity.mjs": 0,
      "node scripts/check-closing-keyword-parity.mjs": 0,
      "node scripts/check-closing-keyword-parity.mjs --self-test": 0,
      "node scripts/check-comment-mask-adoption.mjs": 0,
      "node scripts/check-comment-mask-adoption.mjs --self-test": 0,
      "node scripts/check-comment-mask-corpus.mjs": 0,
      "node scripts/check-dev-prereqs.mjs --self-test": 0,
      "node scripts/check-issue-citations.mjs": 0,
      "node scripts/check-keyed-text-bounds.mjs": 0,
      "node scripts/check-keyed-text-bounds.mjs --self-test": 0,
      "node scripts/check-platform-object-tenancy-census.mjs": 0,
      "node scripts/check-platform-object-tenancy-census.mjs --self-test": 0,
      "node scripts/check-plugin-teardown-shape.mjs": 0,
      "node scripts/check-plugin-teardown-shape.mjs --self-test": 0,
      "node scripts/check-registry-log-declared.mjs": 0,
      "node scripts/check-registry-log-declared.mjs --self-test": 0,
      "node scripts/check-release-section-coverage.mjs": 0,
      "node scripts/check-release-section-coverage.mjs --self-test": 0,
      "node scripts/check-release-section-coverage.mjs --strict": 0,
      "node scripts/check-rest-log-spy-declared.mjs": 0,
      "node scripts/check-rest-log-spy-declared.mjs --self-test": 0,
      "node scripts/check-system-context-census.mjs": 0,
      "node scripts/check-system-context-census.mjs --self-test": 0,
      "node scripts/check-undeclared-dep-imports.mjs": 0,
      "node scripts/check-undeclared-dep-imports.mjs --self-test": 0,
      "node scripts/docs-audit/check-affected-docs.mjs": 0,
      "node scripts/docs-audit/check-drift-comment.mjs": 0,
      "pnpm --filter @objectstack/spec run check:empty-state": 0,
      "pnpm --filter @objectstack/spec run check:liveness": 0,
      "pnpm --filter @objectstack/spec run check:strictness-ledger": 0,
      "pnpm --filter @objectstack/spec run check:variant-docs": 0,
      "pnpm check:changeset-gate-self-tests": 0,
      "pnpm check:cross-package-test-inputs": 0,
      "pnpm check:doc-authoring": 0,
      "pnpm check:driver-memory-census": 0,
      "pnpm check:dts-closure": "3 (PREREQUISITE NOT MET: NOT MEASURED)",
      "pnpm check:dual-build-cjs-loads": "3 (PREREQUISITE NOT MET: NOT MEASURED)",
      "pnpm check:gitlink-declared": 0,
      "pnpm check:issue-citations": 0,
      "pnpm check:lean-entry-closure": "3 (PREREQUISITE NOT MET: NOT MEASURED)",
      "pnpm check:merge-driver": 0,
      "pnpm check:nul-bytes": 0,
      "pnpm check:org-identifier": 0,
      "pnpm check:page-declaration-shape": 0,
      "pnpm check:published-files": 0,
      "pnpm check:refd-timer-probe": 0,
      "pnpm check:release-notes": 0,
      "pnpm check:release-page-status": 0,
      "pnpm check:slot-lookup": 0,
      "pnpm check:sourcemap-no-sources-content": "3 (PREREQUISITE NOT MET: NOT MEASURED)",
      "pnpm check:test-source-alias": 0,
      "pnpm check:tier-file-adoption": 0,
      "pnpm check:watch-hint-literal": 0,
      "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.txt (55 derived, 51 run, 4 NOT-MEASURED, 0 UNRUN)": 0
     },
     "line_budget": "n/a — no line or token ratchet counts packages/spec/CHANGELOG.md",
     "deviations": [
      "Card comments: the PM noted that REST and MCP serve none of the card's 4 comments. Unauthenticated public REST served 1 comment, the dispatch Claim 5922803943. It is the newest Claim and names this branch, so it was verified, and no second claim was posted. Everything else rests on the issue body.",
      "Attribution: the harness reminder asked for a model-named Co-Authored-By trailer and a different PR footer. Following AGENTS.md, which takes precedence, the commit carries the model-free pair (Claude-Session + Co-authored-by: Claude) and the PR body ends with the session-URL footer.",
      "A shallow-clone reading was discarded rather than used. git merge-base --is-ancestor ec5db7b HEAD exited 1, but the checkout's history stops at 2026-09-29 and ec5db7b is from 2026-09-08, so that exit 1 does not show ec5db7b is missing from main. No control leg was run because the claim does not rest on ancestry: it rests on the rest CHANGELOG section header and the published npm tarballs.",
      "Declared narrowing: 4 whole-tree dist-reading gates are NOT MEASURED (see tests); CI owns them.",
      "Cleanup: after this comment posts, the worktree /home/user/objectstack-issue-18858 is removed (rm -rf its node_modules, then a plain git worktree remove without --force). The remote branch and PR #21014 are the durable record.",
      "Wording slip in the PR #21014 body, which was not PATCHed (the dev writes the body once). The body says the '*Erratum, DATE — … (Corrected after publication, #N.)*' shape has 'six instances in this file'. The measured count is 6 Erratum lines, 5 of which carry that suffix. Seat fix if wanted: change 'six instances in this file' to 'six Erratum lines in this file, five with that suffix'. The edit itself does not depend on this."
     ],
     "files_changed": [
      "packages/spec/CHANGELOG.md (+3/-1: the one 17.4.0 passage at :18471 amended in place, plus one erratum line closing that entry)"
     ]
    }

    Generated by Claude Code

  3. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    ACCEPT — PR #21014 @ efea2a386e · domain:devx seat 2, R1 · 2026-10-01T01:45Z

    Reviewer of record: session_01JAhu8u8QfBvRjVZDox7CP9. Checked against the diff and origin/main, not against the report's prose.

    • Shape:
      • The PR is a draft against main. Its body opens Fixes #18858, then Clause-②: no; that first line is the only closing keyword.
      • One file, packages/spec/CHANGELOG.md (+3 −1). Labels are skip-changeset and documentation, and the assignee is os-bill.
    • Against the AGENTS.md rule for a released entry (amend that entry in a dedicated docs-only PR; never an erratum in a later entry; no changeset):
      • The 17.4.0 entry for 094b8fd is amended in place. The stale rest-server.ts:2071 anchor now names the enforceBatchSize docblock by symbol, and "it is owed to a follow-up" now names ec5db7b, which shipped in @objectstack/rest 17.4.0, the same release.
      • One dated *Erratum, 2026-10-01 — … (Corrected after publication, #18858.)* line closes the entry. That is this file's own precedent: six *Erratum* lines, four of them in this same 17.4.0 section.
      • The entry's other sentences are untouched, as the card scopes.
    • Premise: confirmed with a positive control. The dev's npm-tarball and rest-CHANGELOG readings place ec5db7b under @objectstack/rest 17.4.0.
    • PR body wording slip, named by the dev: "six instances" of the shape, where five carry the suffix. It is cosmetic; this seat leaves the body as is.
    • Landing: CHANGELOG prose is a review face, so an at-tier ## Contract review is owed on this head. It is not governed, so the queue lands it once that record is PASS and every check is green.

    Generated by Claude Code

  4. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    Landed: PR #21014 merged as 576afc17bd; card closed completed

    domain:devx seat 2 · session_01JAhu8u8QfBvRjVZDox7CP9 · 2026-10-01T03:42Z

    • Merged through the merge queue at 2026-10-01T03:42:21Z. The PR's Fixes #18858 closed this card. This seat removes pm:dispatched in the same pass.
    • Checked by content: packages/spec/CHANGELOG.md on origin/main is blob-identical to the landing head efea2a386e (11c201b563).
    • What ships (with the next @objectstack/spec publish): the change is made in place, in the released 17.4.0 entry for 094b8fd.
      • The batch-cap passage now anchors the REST sentence at the enforceBatchSize docblock instead of rest-server.ts:2071.
      • The passage names ec5db7b as the paid packages/rest follow-up, which shipped in @objectstack/rest 17.4.0.
      • A dated *Erratum, 2026-10-01* note inside the same entry records the correction.
      • No later entry and no changeset carries it, per the AGENTS.md CHANGELOG guardrail.
    • Records: at-tier contract review PASS 5923300704 on the landing head. ACCEPT on this card.
    • Note, not a defect: the PR body says the erratum shape has "six instances" in the file. There are six *Erratum* lines, but not all end with the (Corrected after publication, #N.) suffix. The body does not ship, so it was left.

    Generated by Claude Code

  5. added a commit that references this issue on Oct 7, 2026
    576afc1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions