Repository navigation
docs(metadata): correct the retiredKey tombstone's minor version in the published 17.3.0 CHANGELOG entry - #17426
Merged
Conversation
…he published 17.3.0 CHANGELOG entry (#16277) packages/metadata/CHANGELOG.md's 17.3.0 section (54e2d36 / #12772) described a measured pre-fix incident as "spec 17.2.0's `retiredKey` tombstone refused the boot". packages/spec/CHANGELOG.md files the allowRestore/allowPurge retirement (8af88dd, #12497, ADR-0049) under its own 17.3.0 section, and its 17.2.0 section mentions neither key nor #12497 (grep count 0). Triage located the entry by section structure (17.3.0: line 3 vs 3343; 17.2.0: 7798-8854) to show the two changelogs' evidence pointed at the same reading, but drew the line at "CHANGELOG absence is not release absence" and left the tag-level check open. The PM dispatch closed it: @objectstack/cli@17.2.0's packages/spec/src/security/permission.zod.ts:157-158 declares allowRestore/ allowPurge as live ordinary boolean fields (not retiredKey), and zero tombstone files under packages/spec/src/migrations/entries/retired-keys/ match either name at that tag; the tombstone (18.security__ObjectPermission__allowRestore.ts) first appears at @objectstack/cli@17.3.0. The tombstone shipped with 17.3.0, not 17.2.0 — the metadata entry's minor is a slip. Repair follows the principle both the filer and triage converged on: cite the MAJOR version in prose, not the minor, unless the minor distinction itself carries information (it doesn't here — the incident is about the tombstone existing at all, not about which 17.x introduced it). The platform's own parse-time removal message already does this ("was removed in @objectstack/spec 17 (ADR-0049)"), which is the one sentence both changelogs already agree on. "spec 17.2.0's `retiredKey` tombstone" becomes "spec 17's `retiredKey` tombstone" — the sentence no longer depends on a minor version that can be wrong. Precedent for correcting published CHANGELOG text in place (as opposed to only an erratum in a future release) is established practice in this repo: eabdd66 ("correct three false sentences in the published 17.3.0 release text"), c3b6da4 ("correct the offer-set claim in the icon-withdrawal CHANGELOG entry"), 222be39 ("correct the withdrawn `os migrate meta` claim in the published 17.0.0 app-area retirement entry"), and eb91eba. All are docs-only, text-only, no changeset, no code, no test — the shape this PR follows. Text-only correction: one word changed on one line, no packages/*/src/** touched, no accept/reject behaviour moves, no public surface widens. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012GKcPZbMoGq7WPzKLfRBTU
Contributor
📓 Docs Drift Check
What this run could not see
Coarse fallback — 15 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): |
baozhoutao
marked this pull request as ready for review
September 10, 2026 13:45
baozhoutao
enabled auto-merge
September 10, 2026 13:45
baozhoutao
deleted the
claude/issue-16277-changelog-retirement-version
branch
September 10, 2026 14:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #16277
What
packages/metadata/CHANGELOG.md's## 17.3.0section (entry54e2d36, #12772) described a measured pre-fix incident as:packages/spec/CHANGELOG.mdfiles theallowRestore/allowPurgeobject-permission retirement (8af88dd, #12497, ADR-0049) under its own## 17.3.0section; its## 17.2.0section mentions neither key nor#12497(grep count 0 over that section). The two changelogs disagreed on which minor version the tombstone shipped in.Why
Triage located both entries by section-heading structure (spec's 17.3.0 heading precedes the entry, its 17.2.0 heading follows it) and showed the CHANGELOG evidence points at one reading, but drew a deliberate boundary: "CHANGELOG absence is not release absence" — it does not prove the code. The PM dispatch comment on #16277 ran the missing tag-level check:
@objectstack/cli@17.2.0:packages/spec/src/security/permission.zod.ts:157-158declaresallowRestore/allowPurgeas live, ordinaryz.boolean()fields — notretiredKey(). Zero files underpackages/spec/src/migrations/entries/retired-keys/match either name at that tag.@objectstack/cli@17.3.0:packages/spec/src/migrations/entries/retired-keys/18.security__ObjectPermission__allowRestore.tsexists, headed#12497 — ADR-0049 enforce-or-remove.I independently reconfirmed this on
origin/main:git log --oneline --all -- 'packages/spec/src/migrations/entries/retired-keys/*allowRestore*'returns8af88ddb0b feat(spec): retire the allowRestore / allowPurge object-permission bits (#12497, ADR-0049) (#12619)as the sole introducing commit, matching spec's## 17.3.0entry hash (8af88dd) exactly — no earlier commit touches that path.⇒ The tombstone shipped with spec 17.3.0, not 17.2.0. The metadata entry's minor version is a slip.
The fix
Per the principle the filer, triage and the PM dispatch all converge on: cite the major version in prose, not the minor, unless the minor distinction itself carries information. It doesn't here — the incident is about the tombstone existing at all, not about which
17.xintroduced it. The platform's own parse-time removal message already does this, and it is the one sentence both CHANGELOGs already agree on:So
spec 17.2.0's→spec 17's. One word, one line. The sentence no longer depends on a minor version that can be wrong.Hard-stop condition: is hand-correcting a published CHANGELOG entry settled practice here?
Triage and the PM dispatch both flagged this as a hard stop — CHANGELOGs are changeset-generated, not hand-maintained, and this repo's discipline is release notes written centrally at release time. I searched
git logon both CHANGELOG files for precedent before touching anything. It is settled practice, exercised repeatedly:eabdd66f45— "correct three false sentences in the published 17.3.0 release text" (docs(changelog): correct three false sentences in the published 17.3.0 release text — the reversed depends_on justification and the ListView binding paragraph in both CHANGELOGs #16881) — direct in-place text replacement across two packages' CHANGELOGs, explicitly reasoned: "Released CHANGELOG text is treated as release-owned, so this is a dedicated docs-only PR riding on no code change."c3b6da4bca— "correct the offer-set claim in the icon-withdrawal CHANGELOG entry" (fix(spec): correct the offer-set claim in the icon-withdrawal CHANGELOG entry #15454) — same shape: "Text-only correction... no code, no test, no changeset."222be390bb— "correct the withdrawnos migrate metaclaim in the published 17.0.0 app-area retirement entry" (docs(spec): correct the withdrawnos migrate metaclaim in the published 17.0.0 app-area retirement entry #11644) — same shape, plus a> **Correction:**blockquote convention for cases where the surrounding sentence needs to record what the released artifact originally said.eb91ebacbc— an earlier instance of the same pattern ([spec] #4610/#4535-C3 Notification 退役的墓碑与 changelog 需事实更正:objectui 侧确有export … from消费者;FROM→TO 指引会引导编译失败的替换 #5781, [spec]packages/spec/CHANGELOG.md的 17.0.0-rc.2 段落仍带着「the server does not walkareas」—— GA 段落改对后同一文件会自相矛盾 #5809).This PR follows the
eabdd66f45/c3b6da4bcashape: a direct, minimal, in-place word substitution, no blockquote annotation, because nothing here needs to preserve a record of "what the released text used to claim" beyond what this PR description and its commit message already do — the change is a single version-number word, not a restated fact.Out of scope (per the dispatch brief)
The issue's third measurement (
ObjectPermissionSchema.safeParse: presence/truthiness asymmetry onallowRestore/allowPurge) is explicitly out of scope for this card. I re-ran it (pnpm --filter @objectstack/spec exec tsxagainstpackages/spec/src/security/permission.zod.ts'sObjectPermissionSchema) and confirmed — with a more precise characterization than the original report (it's not a truthy/falsy split; only the literalfalseparses, everything else refuses, and no post-parse consumer guard can ever observe either key) — and filed it separately: #17425.Verification
packages/metadata/CHANGELOG.mdis the only file touched:git diff --stat→1 file changed, 1 insertion(+), 1 deletion(-).pnpm check:nul-bytes— pass (exit 0).pnpm check:published-files— pass (exit 0); confirmsCHANGELOG.mdis a required-but-not-content-scanned package artifact.pnpm check:doc-authoring— pass (exit 0); no internal issue-id introduced (spec 17'scarries no#NNNN).packages/metadata/CHANGELOG.mdcontent for correctness — the gates that nameCHANGELOG.md(check-published-files.mjs,check-published-readme-exports.mjs) treat it as a required, opaque, packed artifact, never scan its prose. The gates that DO parsepackages/spec/CHANGELOG.mdprose for release tooling (check-release-notes.mjs,check-release-page-status.mjs,check-release-section-coverage.mjs,sync-release-index-currency.mjs) key onpackages/spec/CHANGELOG.mdspecifically, notpackages/metadata/CHANGELOG.md, and none of the four appear in this diff's derived gate set (node scripts/pm/dispatch-gates.mjs --commands).packages/*/src/**, so no package'sdist/is affected.skip-changesetlabel applied — measured, not asserted: no published surface moves (prose-only CHANGELOG correction), matching the precedent PRs above, all of which shipped without a changeset.Clause-②: no
🤖 Generated with Claude Code
https://claude.ai/code/session_012GKcPZbMoGq7WPzKLfRBTU
Generated by Claude Code