Skip to content

docs(metadata): correct the retiredKey tombstone's minor version in the published 17.3.0 CHANGELOG entry - #17426

Merged
baozhoutao merged 1 commit into
mainfrom
claude/issue-16277-changelog-retirement-version
Sep 10, 2026
Merged

baozhoutao merged 1 commit into
mainfrom
claude/issue-16277-changelog-retirement-version

Conversation

@baozhoutao

Copy link
Copy Markdown
Contributor

Closes #16277

What

packages/metadata/CHANGELOG.md's ## 17.3.0 section (entry 54e2d36, #12772) described a measured pre-fix incident as:

... and spec 17.2.0's retiredKey tombstone refused the boot with no operator remedy ...

packages/spec/CHANGELOG.md files the allowRestore/allowPurge object-permission retirement (8af88dd, #12497, ADR-0049) under its own ## 17.3.0 section; its ## 17.2.0 section mentions neither key nor #12497 (grep count 0 over that section). The two changelogs disagreed on which minor version the tombstone shipped in.

Why

Triage located both entries by section-heading structure (spec's 17.3.0 heading precedes the entry, its 17.2.0 heading follows it) and showed the CHANGELOG evidence points at one reading, but drew a deliberate boundary: "CHANGELOG absence is not release absence" — it does not prove the code. The PM dispatch comment on #16277 ran the missing tag-level check:

  • @objectstack/cli@17.2.0: packages/spec/src/security/permission.zod.ts:157-158 declares allowRestore/allowPurge as live, ordinary z.boolean() fields — not retiredKey(). Zero files under packages/spec/src/migrations/entries/retired-keys/ match either name at that tag.
  • @objectstack/cli@17.3.0: packages/spec/src/migrations/entries/retired-keys/18.security__ObjectPermission__allowRestore.ts exists, headed #12497 — ADR-0049 enforce-or-remove.

I independently reconfirmed this on origin/main: git log --oneline --all -- 'packages/spec/src/migrations/entries/retired-keys/*allowRestore*' returns 8af88ddb0b feat(spec): retire the allowRestore / allowPurge object-permission bits (#12497, ADR-0049) (#12619) as the sole introducing commit, matching spec's ## 17.3.0 entry hash (8af88dd) exactly — no earlier commit touches that path.

⇒ The tombstone shipped with spec 17.3.0, not 17.2.0. The metadata entry's minor version is a slip.

The fix

Per the principle the filer, triage and the PM dispatch all converge on: cite the major version in prose, not the minor, unless the minor distinction itself carries information. It doesn't here — the incident is about the tombstone existing at all, not about which 17.x introduced it. The platform's own parse-time removal message already does this, and it is the one sentence both CHANGELOGs already agree on:

objects.OBJECT.allowRestore was removed in @objectstack/spec 17 (ADR-0049) ...

So spec 17.2.0's → spec 17's. One word, one line. The sentence no longer depends on a minor version that can be wrong.

Hard-stop condition: is hand-correcting a published CHANGELOG entry settled practice here?

Triage and the PM dispatch both flagged this as a hard stop — CHANGELOGs are changeset-generated, not hand-maintained, and this repo's discipline is release notes written centrally at release time. I searched git log on both CHANGELOG files for precedent before touching anything. It is settled practice, exercised repeatedly:

This PR follows the eabdd66f45/c3b6da4bca shape: a direct, minimal, in-place word substitution, no blockquote annotation, because nothing here needs to preserve a record of "what the released text used to claim" beyond what this PR description and its commit message already do — the change is a single version-number word, not a restated fact.

Out of scope (per the dispatch brief)

The issue's third measurement (ObjectPermissionSchema.safeParse: presence/truthiness asymmetry on allowRestore/allowPurge) is explicitly out of scope for this card. I re-ran it (pnpm --filter @objectstack/spec exec tsx against packages/spec/src/security/permission.zod.ts's ObjectPermissionSchema) and confirmed — with a more precise characterization than the original report (it's not a truthy/falsy split; only the literal false parses, everything else refuses, and no post-parse consumer guard can ever observe either key) — and filed it separately: #17425.

Verification

  • packages/metadata/CHANGELOG.md is the only file touched: git diff --stat → 1 file changed, 1 insertion(+), 1 deletion(-).
  • pnpm check:nul-bytes — pass (exit 0).
  • pnpm check:published-files — pass (exit 0); confirms CHANGELOG.md is a required-but-not-content-scanned package artifact.
  • pnpm check:doc-authoring — pass (exit 0); no internal issue-id introduced (spec 17's carries no #NNNN).
  • No test or gate parses packages/metadata/CHANGELOG.md content for correctness — the gates that name CHANGELOG.md (check-published-files.mjs, check-published-readme-exports.mjs) treat it as a required, opaque, packed artifact, never scan its prose. The gates that DO parse packages/spec/CHANGELOG.md prose for release tooling (check-release-notes.mjs, check-release-page-status.mjs, check-release-section-coverage.mjs, sync-release-index-currency.mjs) key on packages/spec/CHANGELOG.md specifically, not packages/metadata/CHANGELOG.md, and none of the four appear in this diff's derived gate set (node scripts/pm/dispatch-gates.mjs --commands).
  • No build/typecheck applicable: the diff touches no packages/*/src/**, so no package's dist/ is affected.
  • skip-changeset label applied — measured, not asserted: no published surface moves (prose-only CHANGELOG correction), matching the precedent PRs above, all of which shipped without a changeset.

Clause-②: no


🤖 Generated with Claude Code

https://claude.ai/code/session_012GKcPZbMoGq7WPzKLfRBTU


Generated by Claude Code

…he published 17.3.0 CHANGELOG entry (#16277)

packages/metadata/CHANGELOG.md's 17.3.0 section (54e2d36 / #12772) described a
measured pre-fix incident as "spec 17.2.0's `retiredKey` tombstone refused the
boot". packages/spec/CHANGELOG.md files the allowRestore/allowPurge retirement
(8af88dd, #12497, ADR-0049) under its own 17.3.0 section, and its 17.2.0
section mentions neither key nor #12497 (grep count 0). Triage located the
entry by section structure (17.3.0: line 3 vs 3343; 17.2.0: 7798-8854) to show
the two changelogs' evidence pointed at the same reading, but drew the line at
"CHANGELOG absence is not release absence" and left the tag-level check open.
The PM dispatch closed it: @objectstack/cli@17.2.0's
packages/spec/src/security/permission.zod.ts:157-158 declares allowRestore/
allowPurge as live ordinary boolean fields (not retiredKey), and zero tombstone
files under packages/spec/src/migrations/entries/retired-keys/ match either
name at that tag; the tombstone
(18.security__ObjectPermission__allowRestore.ts) first appears at
@objectstack/cli@17.3.0. The tombstone shipped with 17.3.0, not 17.2.0 — the
metadata entry's minor is a slip.

Repair follows the principle both the filer and triage converged on: cite the
MAJOR version in prose, not the minor, unless the minor distinction itself
carries information (it doesn't here — the incident is about the tombstone
existing at all, not about which 17.x introduced it). The platform's own
parse-time removal message already does this ("was removed in @objectstack/spec
17 (ADR-0049)"), which is the one sentence both changelogs already agree on.
"spec 17.2.0's `retiredKey` tombstone" becomes "spec 17's `retiredKey`
tombstone" — the sentence no longer depends on a minor version that can be
wrong.

Precedent for correcting published CHANGELOG text in place (as opposed to only
an erratum in a future release) is established practice in this repo:
eabdd66 ("correct three false sentences in the published 17.3.0 release
text"), c3b6da4 ("correct the offer-set claim in the icon-withdrawal
CHANGELOG entry"), 222be39 ("correct the withdrawn `os migrate meta` claim
in the published 17.0.0 app-area retirement entry"), and eb91eba. All are
docs-only, text-only, no changeset, no code, no test — the shape this PR
follows.

Text-only correction: one word changed on one line, no packages/*/src/**
touched, no accept/reject behaviour moves, no public surface widens.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012GKcPZbMoGq7WPzKLfRBTU
@baozhoutao baozhoutao added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 10, 2026 — with Claude
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

⚠️ 1 changed file(s) yielded no anchor (packages/metadata/CHANGELOG.md), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files. Nothing else in this diff resolved to a documentable surface (no symbol, route or SDK anchor derived from 1 changed package(s)).

What this run could not see
  • 1 changed file(s) yielded no anchor (packages/metadata/CHANGELOG.md) — pages documenting those are invisible to this run
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 15 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 92242041e738eec91b2ccd4e29c845682b53bb4a → packageMentionDocs.

@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 10, 2026
@baozhoutao
baozhoutao marked this pull request as ready for review September 10, 2026 13:45
@baozhoutao
baozhoutao added this pull request to the merge queue Sep 10, 2026
Merged via the queue into main with commit ba9f029 Sep 10, 2026
39 checks passed
@baozhoutao
baozhoutao deleted the claude/issue-16277-changelog-retirement-version branch September 10, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/xs skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants