Skip to content

fix(scripts): the citation extractor reads hyphen-suffixed, slash-joined and URL-spelled citations, pinned in one spelling table - #20989

Merged
objectstack-fleet[bot] merged 2 commits into
mainfrom
claude/issue-20636-citation-extractor-closeout
Oct 1, 2026
Merged

objectstack-fleet[bot] merged 2 commits into
mainfrom
claude/issue-20636-citation-extractor-closeout

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #20636
Clause-②: no

The family closeout for the citation extractor in scripts/check-issue-citations.mjs: every spelling a seat measured as invisible to the diff gate and the census is now read, every exclusion keeps only the shapes it was measured protecting, and the self-test carries the one enumeration table the triage asked for (48 spellings, each "extracted as" or "not a citation, because"). Landing site: scripts/check-issue-citations.mjs only. scripts/check-doc-authoring.mjs is untouched; H2 below says why.

What changed

  • Hyphen after the number. The lookahead no longer refuses a -, so #13398-class, #5347-A and ui#6206-B read as citations of their number. It still refuses a word character, so a hex colour stays out.
  • Slash before the #. A / is now valid context before a bare #. It stays refused only before a qualifier candidate, so a URL path fragment such as https://example.com/docs/page#12 never reads page as prose. A / right after a digit is the exception, so #3076/objectui#2614 still reads its own qualifier.
  • Slash-joined continuation. In #A/#B, the second number takes the chain head's reading: bare after a bare or prose head, the head's repository after a qualified head, and an ordinal after an ordinal. Only a joined / continues a chain. objectui#1 / #2 and objectui#1 + #2 stay two separate readings.
  • URL spelling. https://github.com/OWNER/REPO/issues/N and .../pull/N are now citations, qualified by their own OWNER/REPO. That puts objectstack-ai/framework in this repository and makes every other repository's URL cross-repo, never a finding. Inside a markdown link [#N](URL), the citation counts once.
  • Head rows. I retired re-charter, clause and option (named in the thread), plus acceptance and the section mark (found by the same measurement). Each protects 0 sites repo-wide at two or more digits and hides board citations. The grammar's two-digit floor already keeps one-digit ordinals out. I added a ]( row, the narrower guard the hyphen exclusion leaves behind for markdown in-page heading anchors.
  • Self-test.
    • A new spellings battery (56 cases) reads the table row by row.
    • Every head row must excuse at least one table row, and every required spelling (the card's list plus the thread's) must be present.
    • The live-corpus battery gains three floors, one per new arm, each counting only a number spelled once on its line.
    • The roster floor rises from 6 to 9 batteries.
    • Total: 114 cases in 8 batteries became 173 in 9.
  • I edited the header in place and kept its line count, because scripts/pm/dispatch-gates.mjs's self-test pins scripts/check-issue-citations.mjs:204 local-env. The marker is still on line 204, and that pin passes (see Gates).

H1: what each exclusion protected and hid

Measured on 3693a1b50 over the declared surfaces. Every arm was judged against one enumerated board: 188 pages, frontier 20959, 2026-09-30T22:55Z. The instrument mirrors the gate's extractor and matched it file for file on all 2,640 files (0 mismatches).

exclusion hid (sites, dead) protected in the declared surfaces disposition
hyphen after the number 58, 1 dead (8 cross-repo) 0: no numeric range, slug or hex-like token. Repo-wide: in-page heading anchors, 16 lines in docs/design/** and skills/**, plus one range, docs/audits/...md, whose first number is a citation dropped; the ]( row keeps the anchor out
/ before the # 528, 10 dead: 523 #A/#B second numbers and 5 TOKEN/#N such as ADR-0049/#1888 0 paths and 0 URL fragments narrowed to the candidate arm; continuations read as their chain
head re-charter 0 left on this tree (the 26 dead re-charter #13135 were rewritten by PR #20750) 0; only the gate's own fixtures used it retired
head clause 0 in the surfaces; 4 in deferred test files, all board citations 0 retired
head option 1 (option #14088, live); 1 more under scripts/** 0 retired
head acceptance 1 (the silent acceptance #6132 closed, live) 0 at two or more digits retired (in-place, below)
head section mark 0 in the surfaces; 4 in test files (§6 #11176's decisions) 0 at two or more digits retired (in-place, below)
heads kept none measured hiding a citation directive 203 (max 13), PD 85 (max 13), batch 276 (69 distinct, 11 to 227), OQ 10, PKCS 1 kept

The 8 slash chains headed by another repository are not a case where the two populations cannot be told apart. The 5 on objectui's public board each name objectui's record, the issue and then the pull request that fixed it, read one by one against both boards:

  • objectui#2715/#2717
  • #2711/#2722
  • #2725/#2732
  • #2967/#2904
  • #4648/#4901

This repository's records with the same numbers are unrelated. The other 3 (cloud, hotcrm-heimao) are boards one credential cannot read, so they stay unjudged, as they were before.

H2: where the URL spelling belongs

The extractor. At 3693a1b50, 57 URL sites sit in the gate's projection: 56 in package comments and 1 link on a release page. 4 of them are dead. Only 2 URL sites in package sources are inside string literals, both internal note: strings in packages/runtime/src/route-ledger.ts.

check:doc-authoring asks a different question: may a runtime string carry a tracker reference at all? It reads string literals, skills and spec refusal messages. The two projections are disjoint, so adding the URL to the extractor double-counts nothing there. Inside the extractor, the one double-spelled site ([#15325](.../issues/15325) on v17/17-3.mdx) counts once. check-doc-authoring.mjs is not touched.

H3: open PRs' added lines

All 13 open PRs at 2026-09-30T23:2xZ: their heads were fetched into a private ref namespace (deleted afterwards). For each, the BASE extractor and this one were run over the lines it adds, against its merge base. Result: 85 added-line citations under both extractors, 0 newly extracted, 0 lost. No PR's verdict changes. Lines a PR does not add are never judged, which is unchanged and pinned in the diff-scope battery.

Census, before and after

The gate's own --census --json, once with the 3693a1b50 script and once with this one, over the same tree:

judged resolves resolves as PR cross-repo allocated-but-absent
before (frontier 20965) 37,152 33,403 1,985 1,024 740
after (frontier 20966) 37,796 33,917 2,083 1,041 755

That is 644 more judged sites and 15 more dead ones, with 0 findings lost. By arm: hyphen 1 dead, slash 10 dead, URL 4 dead.

Newly visible dead sites per lane. I rewrote none of them; they belong to the lane cards:

This census was run on the PR head's tree, not after landing. A re-run after landing reads the same corpus plus whatever main has gained by then.

In-place fixes beyond the three named rows

I retired the acceptance and section-mark rows here rather than filing them. All four conditions hold:

  1. They are the same defect class as option and clause: a head row hiding a board citation.
  2. The fix is mechanical, and the shape is pinned by the table.
  3. The file is this claim's own surface (NON_CITATION_HEADS).
  4. The same gate's self-test covers them, so no new verification surface is added.

Evidence: acceptance #6132 (live) in packages/formula/src/cel-pushdown-limits.ts:82, and the section-mark sites in deferred test files. Neither row has any two-or-more-digit ordinal anywhere in the repository.

Gates (final head 25d96fcc0)

I re-derived the list with node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack, which gave 32 commands. The same derivation on a throwaway tree at origin/main (05be35259) with this diff applied gave an identical list. I ran all 32, plus pnpm check:doc-authoring and the self-test, and every one exited 0. Reconciliation verdict line:

✓ dispatch-gates --ran: 32 derived famil(ies) accounted for — 32 run, 0 NOT-MEASURED (a DERIVED zero — all 32 recorded an exit code and none of them is 3).

Verdict lines worth quoting:

  • node scripts/check-issue-citations.mjs --self-test: ✅ ... every spelling enumerated ... (173 cases, 9 batteries). It also passes on origin/main 05be35259 with this diff applied.
  • node scripts/check-issue-citations.mjs (diff mode): ✅ check-issue-citations: no issue citations added against 3693a1b50 (0 file(s) read). The script lives in the deferred scripts/** surface.
  • pnpm check:pm-dispatch-gates: ✓ dispatch-gates self-test: 1976 cases pass. (1237.9s). Its pin scripts/check-issue-citations.mjs:204 local-env holds.
  • pnpm check:doc-authoring: ✓ doc authoring guard: ... hold the baseline — 549 pinned site(s).
  • pnpm check:nul-bytes: check-nul-bytes: OK (scanned 9582 text file(s) ...).
  • node scripts/check-scripts-symbol-anchors.mjs: ✅ ... 3706 anchors across 282 scripts resolve.

Ablations (one-shot, from committed 25d96fcc0, via scripts/ablation-replace.mjs)

Every leg was expected to go red, and every leg did. Each one restored to blob c732ce2e21c7 (equal to HEAD) with an empty git diff HEAD. No permanent ablation file is left.

mutation first red
hyphen refused again after the number the live corpus must yield a #N-word citation
/ refused again before the # the live corpus must yield a slash-joined #A/#B second number
URL arm disabled the live corpus must yield a URL-spelled citation
option head row restored spelling option #N in "the option #14088 gave" must read #14088; got nothing
continuation disabled spelling repo#A/#B ... must read objectstack-ai/objectui#2711, objectstack-ai/objectui#2722
]( row disabled a markdown link's in-page heading anchor is not a citation
link de-duplication disabled spelling [#N](URL) ... must read #15325

The first slash ablation, run before the floors were tightened, went red in the table but left the live-corpus continuation floor green. A line citing the same number twice let a plain citation stand in for the slash-joined one. Commit 25d96fcc0 makes each new floor count only a number spelled once on its line. The re-run above is red at that floor.

Acceptance notes

  • URL spelling in runtime strings. check:doc-authoring does not read it. At 3693a1b50 the population is 2 internal route-ledger note: strings (packages/runtime/src/route-ledger.ts:459, :465), and no author-facing door shows them. Noted, not filed; carrier: none.
  • Range second numbers. In a range such as #712-714, the second number carries no # and is not read. There is 1 site repo-wide, in docs/audits/**, outside the declared surfaces. Pinned in the table with its reason.
  • Dormant test-file citations. The 8 test-file citations the retired clause and section-mark rows hid are in the deferred test surface. They become visible only when that surface is swept.
  • Line-number pin. dispatch-gates.mjs pins this file's local-env marker by line number (:204), so any future header growth above it has to move that pin in the same PR.

No changeset: a root scripts/ file publishes nothing (the root package.json is private, and no package's files ships scripts/), so this PR takes skip-changeset.


Generated by Claude Code

…spelling, and pins them in one table

The extractor hid real citations behind exclusions wider than anything they
protected. Measured over the declared surfaces at 3693a1b against one
enumerated board:

- a hyphen after the number hid 58 `#N-word` sites and protected none; the one
  non-citation shape it covered repo-wide (a markdown in-page heading anchor)
  keeps a narrower `](` head row;
- a `/` before the `#` hid 528 sites (523 slash-joined second numbers); it
  stays only on the candidate arm, where it keeps URL path fragments out, and a
  slash-joined continuation reads as its chain (qualifier or ordinal);
- the `re-charter`, `acceptance`, `clause`, `option` and section-mark head rows
  each protected 0 sites repo-wide and hid board citations; retired;
- the URL spelling (`https://github.com/OWNER/REPO/issues/N`, `/pull/N`) is
  now a citation, qualified by its own OWNER/REPO, counted once inside a
  `[#N](URL)` link.

The self-test gains the one enumeration table (48 spellings, each "extracted
as" or "not a citation, because"), completeness rules over the head rows and
the required spellings, and three live-corpus floors for the new arms.

Claude-Session: https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU
Co-authored-by: Claude <noreply@anthropic.com>
…a number spelled once on its line

An ablation that restored the slash exclusion left the continuation floor
green: a line citing the same number twice let a plain citation stand in for
the slash-joined one. Each floor now counts only a row whose number appears
once in its line.

Claude-Session: https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added the size/m label Oct 1, 2026
@objectstack-fleet objectstack-fleet Bot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Oct 1, 2026
@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 1, 2026 00:54
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 1, 2026 00:54
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit a5bce40 Oct 1, 2026
38 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-20636-citation-extractor-closeout branch October 1, 2026 01:16
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…commits and ADR that decided them (objectstack-ai#21233)

Part of objectstack-ai#20595
Clause-②: no

## What changed

Stage 1 of the `domain:engine` lane of the dead-citation sweep:
`packages/metadata-protocol/**`, comment and docblock prose only, per
the claim (`5938223120`). The next stages (`objectql`, `driver-sql`,
`driver-memory`, then the rest) are separate claims, so objectstack-ai#20595 remains
open.

Every comment or docblock site in the package that cited a tracker
number answering 404 is rewritten in ruling C+D's form C (record
`5749154545` on objectstack-ai#19123): the ADR or ruling record when one exists,
otherwise the commit in this repository's history that made the decision
the sentence describes. That is **293 sites on 279 lines in 54 files,
covering 56 numbers**:

- **163 census sites** (155 lines, 8 files under `src/`): the whole
`allocated-but-absent` population of the gate's own census in this
package at the base;
- **1 site in `tsup.config.ts`** (`:15`, `objectstack-ai#11235`): same number, outside
the census glob but inside the claimed file surface;
- **129 test-comment sites** (123 lines, 45 test files), which the
census defers, found by the supplementary reading below. Each cites a
number the census itself reads as dead (41 of the 43 numbers are among
the census set; `objectstack-ai#10485` and `objectstack-ai#8600` are dead elsewhere in the
repository).

**Anchors: 55 numbers by commit sha, 1 by ADR (`objectstack-ai#13185`, ADR-0005's
design-principle-3 correction), 0 by words alone.** `objectstack-ai#11674` is split
across two commits, one per half of what it named (see the table). Two
`objectstack-ai#12176` sites (`protocol.item-name-grammar.test.ts:6`, `:12`) drop the
number without a new citation, because line `:4` of the same docblock
now cites the commit (`311433f6b`) that both sentences describe.

Only comments changed. Every file keeps its line count (280 lines out,
280 in, plus the changeset), so no line citation into any of them moves.
No code token moves (the guard below). **No citation number is added**:
every number on an added line already stood on its line, and 20 of those
23 are live by the census's own judgement. Of the 3 it never reads (they
stand only in test files), `objectstack-ai#11099` and `objectstack-ai#8390` answer as pull requests
and `objectstack-ai#14767` answers 404 (see Sites left).

**A `patch` changeset**: 52 of the rewritten non-test lines are in the
published `dist` (the `.d.ts` keeps JSDoc on exported members, and
esbuild keeps a few comments in the JS), and `dist` is not
byte-identical with the base text (see Changeset).

## Census: `metadata-protocol`, before and after

**Instrument (A1).** The gate's own `node
scripts/check-issue-citations.mjs --census --json`, read-only and
unchanged (it carries objectstack-ai#20989's wider extractor, merge `a5bce40888`, an
ancestor of the base). The count is its `allocated-but-absent` findings
under `packages/metadata-protocol/`.

| reading | tree | board | whole-repo `allocated-but-absent` | sites |
lines | files | numbers |
|---|---|---|---|---|---|---|---|
| before | base `e47355be5`, run ended 18:52:32Z | enumerated, 191
pages, frontier objectstack-ai#21227, 19,048 records | 755 | **163** | 155 | 8 | 54 |
| after | `06d41e512`, run 19:21:20Z to 19:25:08Z | enumerated, 191
pages, frontier objectstack-ai#21228, 19,049 records (newest number objectstack-ai#21228 read just
before and just after the run) | 592 | **0** | 0 | 0 | 0 |

The whole-repo drop is 163, and the two finding sets differ by exactly
the 163 rows of this package, removed; none was added. `resolves`
(34,516), `resolves-as-pull-request` (2,092) and `cross-repo-unjudged`
(1,139) did not move. The card's 162 was taken at `f11b5f20a2` with the
older extractor; the base here reads 163, which includes the
slash-joined `partial-index-probe.ts:395` `objectstack-ai#16657` that the post-landing
census (`5923084795`) named. The only commit after `06d41e512` adds the
changeset file, which is outside the census surface.

**Supplementary instrument, the whole package.** The census reads
neither test files nor strings nor files outside `src`. A second reading
runs the gate's own exported `extractCitations` (whole-file and
comment-prose projections) and `namesThisRepository` over every tracked
file in the package (235 `.ts`, 2 `.md`, 2 `.json`). A number is dead
when the before census reported it `allocated-but-absent`, and live when
the census's own scope extraction judged it and did not report it. The
82 numbers neither covers (they stand only in test files, strings or the
changelog) were each read on their own (issues endpoint, which also
answers pull requests): 27 issues, 38 pull requests, **17 answer 404**.
Controls: `objectstack-ai#10888`, `objectstack-ai#11674` and `objectstack-ai#16657` (the card's and the census's
named sites) answer 404, `objectstack-ai#5286` and `objectstack-ai#12624` answer 200.

| reading | citations | dead | src comment | test comment | test string
| changelog |
|---|---|---|---|---|---|---|
| before, `e47355be5` | 6,383 | **434** | 164 | 151 | 63 | 56 |
| after, head | 6,090 | **141** | 0 | 22 | 63 | 56 |

`src comment` here includes `tsup.config.ts`. Its before value is the
census's 163 plus that one site, which is the control on the second
instrument. The drop of 293 citations is exactly the rewritten sites. A
third, raw reading (every `#` followed by 2 to 6 digits, whatever
surrounds it) counts 6,479 before and 6,186 after: the same drop of 293.
The 22 test-comment sites left all carry numbers outside the census's
surface (see Sites left).

## Per-number table

`src` counts census sites (plus `tsup.config.ts` for `objectstack-ai#11235`), `test`
counts test-comment sites. Every sha below matches exactly one commit
(`git rev-parse --disambiguate`, count 1) and is an ancestor of the base
(`git merge-base --is-ancestor`, exit 0 for all 56; the clone was
unshallowed first, `--is-shallow-repository` false, 15,415 commits at
the base). Each one's message or diff names the number it replaces (diff
counts are the added lines naming it), and for every sentence that
credits a ruling, a measurement or a note to the number, the commit's
own message carries that ruling, measurement or note: `ee58392e1` (the
2026-08-08 three-part ruling), `c74aefe63` (ruling 2026-08-22, option
A), `65846bc46` (ruling A, 2026-09-03), `75e66fc8e` (Option B, diff raw
then redact), `96326040f` (the idempotence proof the direction-A ruling
was conditional on), `8744de9e9` (the second-rung ablation), `82cb6e849`
(the two faces left open), `376c70f98` (the measured `shims: true`
consequence). The one exception is `2a29caa53` (`objectstack-ai#9741`): its message
records the decision itself (`environmentId` recorded as
transport-level) but not the 2026-08-18 ruling, so that site keeps its
own date and now reads 「recorded 2026-08-18, landed as commit
2a29caa」. 37 of the 56 numbers were already re-anchored by other
lanes' stages, and for every one of them this stage uses a commit those
stages used (none differs; `objectstack-ai#11674` adds `9a884c6e4` beside their
`1cba33f16`, because 25 of its 32 sites here describe the write-back
half, which `git blame` puts in `9a884c6e4`). The other 19 had no prior
anchor and were measured here.

| number | src | test | anchor | kind | what it decided |
|---|---|---|---|---|---|
| `objectstack-ai#6037` | 1 | 1 | `18189983d` | commit | validate-only data operation
— DataProtocol.validateData |
| `objectstack-ai#6307` | 1 | 0 | `293476148` | commit | refuse a repeated `?version=`
on `GET`/`DELETE /packages/:id` instead of handing the array to
PackageService |
| `objectstack-ai#6478` | 1 | 4 | `474f131cf` | commit | rolls `flow`'s
`allowOrgOverride` back to `false` per ADR-0005's original call, the
write path refusing loudly |
| `objectstack-ai#6483` | 8 | 10 | `ee58392e1` | commit | enforces the ADR-0005
whitelist: nine unratified `allowOrgOverride: true` flags rolled back to
`false`; its message records the 2026-08-08 three-part maintainer ruling
it executes |
| `objectstack-ai#6608` | 4 | 2 | `ee58392e1` | commit | the same commit: `objectstack-ai#6608` was
the pull request whose squash it is |
| `objectstack-ai#8600` | 0 | 1 | `018d22cc3` | commit | require authored OWD at the
runtime object door; retire ADR-0094 R2 external-wider arm; declare
object in runtimeTypes |
| `objectstack-ai#8648` | 2 | 0 | `e5eeb499c` | commit | pin the SEARCH-axis remedy
agreement, and correct the three comments that claimed word-identity |
| `objectstack-ai#8671` | 1 | 2 | `75e66fc8e` | commit | stop the meta diff endpoint
serving credential values |
| `objectstack-ai#8818` | 1 | 1 | `fd6bdf89f` | commit | saveMetaItem's missing-item
refusal declares 400 INVALID_REQUEST instead of answering 500 |
| `objectstack-ai#9740` | 1 | 0 | `11b779e0f` | commit | declare
MetadataProtocol.getMetaItemLayered; drop the dead 'overlay' lockSource
arm |
| `objectstack-ai#9741` | 1 | 0 | `2a29caa53` | commit | declare previewDrafts/state
on meta-read requests; record environmentId as transport-level; retire
REST door casts |
| `objectstack-ai#9798` | 1 | 0 | `c7655d472` | commit | restore the objectstack-ai#4630 unscoped
multi-delete refusal on sys_comment through the wired engine |
| `objectstack-ai#9817` | 1 | 1 | `855591fe7` | commit | discriminate a failed
sys_organization probe from a genuinely empty one |
| `objectstack-ai#9934` | 13 | 2 | `79c46da90` | commit | producer-side user-facing
marking for hook refusal messages — userMessage channel |
| `objectstack-ai#9967` | 2 | 1 | `8f266f1cd` | commit | serve a sandboxed body's
declared HTTP status on /api/v1/data |
| `objectstack-ai#10063` | 5 | 1 | `9e04c3e35` | commit | let the publish door state
the package it is promoting |
| `objectstack-ai#10159` | 1 | 0 | `1ec36b730` | commit | refuse a settings write
issued before the engine is bound |
| `objectstack-ai#10340` | 3 | 4 | `26f3588fb` | commit | decide /meta org scope on
the folded type, not the raw URL spelling |
| `objectstack-ai#10350` | 5 | 3 | `490879ad0` | commit | declare `packageId` on
`publishMetaItem`'s request type, and correct three comments that say
the per-item door names no package |
| `objectstack-ai#10382` | 1 | 4 | `ee09d2119` | commit | derive each live-MySQL
suite's database from its own file, and enforce it repo-wide |
| `objectstack-ai#10485` | 0 | 10 | `35ad101bc` | commit | retire the `themes` carrier
key and ThemeSchema — `app.branding` is the one colour surface |
| `objectstack-ai#10788` | 1 | 1 | `3a7ec2d3b` | commit | a raw-SQL seam that cannot
answer is absent, not empty |
| `objectstack-ai#10789` | 6 | 1 | `38bc74ed1` | commit | a seam that cannot answer is
absent, not empty |
| `objectstack-ai#10842` | 1 | 3 | `f334d662e` | commit | watch(_, since) replays from
sys_metadata_history, and what a bare watch() owes is written down |
| `objectstack-ai#10886` | 3 | 10 | `809e61221` | commit | inventory the
DESTRUCTIVE_CHANGE 409's faces and pin the sole carrier |
| `objectstack-ai#10888` | 5 | 4 | `d806081dd` | commit | render the spec-validation
422 findings clause per write face |
| `objectstack-ai#10895` | 1 | 1 | `a79bd3561` | commit | Publish refusals: declare
failed[].issues + seedApplied.issues, then trim error to a headline |
| `objectstack-ai#11003` | 5 | 1 | `c74aefe63` | commit | thread packageId into both
resolveDraftOrgScopeForPublish probes |
| `objectstack-ai#11014` | 1 | 2 | `2d8b92ff1` | commit | the destructive gate's
reachable type set is `object` alone |
| `objectstack-ai#11015` | 6 | 9 | `82cb6e849` | commit | make the destructive-change
remedy clause face-aware — stop prescribing `?force=true` on the
duplicate door |
| `objectstack-ai#11021` | 3 | 1 | `7d81c889f` | commit | close() terminates watch
iterators instead of emitting a drain event |
| `objectstack-ai#11235` | 6 | 1 | `376c70f98` | commit | derive discovery `version`
instead of the hardcoded `'1.0'` literal |
| `objectstack-ai#11350` | 2 | 0 | `ece4dad31` | commit | re-export the three types
the root entry's own inferred types mention |
| `objectstack-ai#11674` | 20 | 12 | `9a884c6e4` + `1cba33f16` | commit | seed pass 2
writes back by the internal id captured at insert time, healing keyless
datasets / warn at load time when a seed defers a required column, and
document the ordering constraint at the four pointer-pair sites |
| `objectstack-ai#12144` | 1 | 0 | `3a04b0125` | commit | pin the shared identifier
schemas to the storage columns that bound them |
| `objectstack-ai#12176` | 2 | 3 | `311433f6b` | commit | Declare the metadata
item-name grammar in spec and refuse it loudly at the publish door |
| `objectstack-ai#12194` | 6 | 5 | `311433f6b` | commit | Declare the metadata
item-name grammar in spec and refuse it loudly at the publish door |
| `objectstack-ai#12195` | 1 | 0 | `7986d973f` | commit | Retire compound-name
metadata addressing — un-mount the three `:section` arities and unify
SDK URL spelling |
| `objectstack-ai#13185` | 1 | 1 | ADR-0005, design principle 3, its Correction note |
ADR | the field-level patch model retired and deleted whole under
ADR-0049 (executed as `9e0ba21a1`) |
| `objectstack-ai#13186` | 1 | 1 | `9e0ba21a1` | commit | Retire the paper
metadata-customization protocol with its full coupling set |
| `objectstack-ai#13259` | 1 | 1 | `2a75270b1` | commit | honour `hidden` on
getUiView's list priority pass |
| `objectstack-ai#13324` | 4 | 2 | `4cda78c9b` | commit | require a missing-table
error to name the table that was read |
| `objectstack-ai#14390` | 1 | 0 | `9d7f7259f` | commit | `update` answers a driver
unique violation with the `DUPLICATE_RECORD` envelope, on every driver |
| `objectstack-ai#14403` | 1 | 0 | `93d2d679b` | commit | pin the batch-row sink's
disclose/withhold log coherence |
| `objectstack-ai#14409` | 2 | 3 | `3ecb7dc1a` | commit | measure what each dialect
materialises for a datetime JS cannot hold |
| `objectstack-ai#14541` | 1 | 0 | `6d178a408` | commit | consult the bespoke
structured arms before the declared-status passthrough, so both error
doors answer one refusal with one body |
| `objectstack-ai#14683` | 6 | 5 | `96326040f` | commit | apply the allowOrgOverride
read gate inside getMetaItems, so multi-type sweeps are scoped per type
|
| `objectstack-ai#14723` | 3 | 1 | `65846bc46` | commit | a batch/import ROW reports a
unique-constraint refusal as `UNIQUE_VIOLATION`, the route's one wire
spelling |
| `objectstack-ai#14770` | 3 | 3 | `d5cbb44f3` | commit | gate `getMetaItem`'s overlay
read on the metadata registry |
| `objectstack-ai#14907` | 1 | 2 | `e1d4f9e3f` | commit | `getMetaItemLayered` gates
the org read, bound after the canonical fold |
| `objectstack-ai#14938` | 2 | 1 | `c383352cb` | commit | listDrafts emits the
ISO-8601 string updatedAt declares |
| `objectstack-ai#15068` | 1 | 0 | `8744de9e9` | commit | collapse the published-seed
read to the single env-wide read its gate produces |
| `objectstack-ai#16488` | 5 | 1 | `460d4b807` | commit | render a composite
externalId in seed diagnostics instead of its NUL-joined key |
| `objectstack-ai#16657` | 3 | 1 | `5a95b0e93` | commit | read the dialect text out of
`cause` for operator-facing records |
| `objectstack-ai#17167` | 4 | 5 | `dc709b2cf` | commit | the organization probe
records the operator channel as is, empty included |
| `objectstack-ai#19306` | 1 | 1 | `f9e16d856` | commit | a packaged permission set's
DELETE stops reporting a deletion it did not perform |

`objectstack-ai#13185`: the ADR rung is not empty there. ADR-0005's design principle 3
carries a dated Correction that records the 2026-08-29 retirement of the
field-level patch model, so ruling C's first rung applies.
`protocol.ts:8618` already names that record on the same line (「recorded
as a correction inside principle 3 itself」), so there the number is
dropped beside `commit 9e0ba21`.
`get-meta-item-org-read-gate.test.ts:40` now names it (「ADR-0005
principle 3's correction」). For the other 55 numbers, `git grep` over
`docs/adr` and `scripts/adr-anchors` finds no ADR or anchor that records
the decision a site describes. ADR-0094 D5-R and ADR-0086 mention the
`objectstack-ai#6483` rollback, but only as a pointer to it; the narrative and the
ruling are in `ee58392e1`'s message. So ruling C's commit rung applies.

## Wordings to check

Most rewrites swap a tag in place (`(#N)` to `(commit SHA)`, `[#N]` to
`[commit SHA]`, `#N's X` to `commit SHA's X`), the form the landed
stages use. These are the ones that say more than the tag:

- `protocol.ts:5697`: 「(objectstack-ai#9798 declared-but-unenforced, …」 became
「(commit c7655d4 restored a declared-but-unenforced refusal, …」. The
number named an instance of the class, and that commit is the one that
restored it.
- `protocol.ts:8590`: 「the resurrection objectstack-ai#14683 is about」 became 「the
resurrection commit 9632604 closed」.
- `protocol.ts:16640`: 「measured on the objectstack-ai#12176 census before this
landed」 became 「measured before this landed (the census commit 311433f
records)」. The census results are written into that commit's test-file
header.
- `migrations/seed-tenancy-backfill.ts:964`: 「Measured; recorded
separately as objectstack-ai#10159.」 became 「Measured; recorded separately, and
refused since commit 1ec36b7.」 That commit refuses the settings write
that answered "resolved" while persisting nothing.
- `discovery-version.ts:26`: 「considered and declined at objectstack-ai#11235 triage」
became 「considered and declined when the derivation landed (commit
376c70f)」. The triage discussion is not recorded in-repo. The commit
is where the package-local resolver was chosen, and its message records
why: the dependency direction forbids importing runtime's.
- `seed-loader-pointer-pair.test.ts:871`: 「— objectstack-ai#11674's B half, ruled by
triage…」 became 「— commit 1cba33f, the B half, ruled by triage…」.
- `protocol-publish-drafts-package-scope.test.ts:400` is the one changed
line that carried no number. 「option A (recorded on the issue)」 became
「option A (recorded in that commit's message)」, because the issue it
pointed at was the number removed on `:399`, and `c74aefe63`'s message
does record the ruling.
- `sys-metadata-repository.contract.test.ts:187` quotes a deleted line,
「`declaredDivergences: { resumableWatch: 'objectstack-ai#10842' }`」. The quoted value
is elided to 「…」 rather than re-spelled, so the quote stays true.
- `protocol.item-name-grammar.test.ts:6` and `:12`: the number is
dropped and nothing is substituted, since `:4` cites `311433f6b`.
- No line was reflowed, so many are longer than their block's wrap
(`eslint.config.mjs` declares no line-length rule, and reflowing would
move neighbouring lines and every line citation into the file).

## Sites left

- **In `src` comments and `tsup.config.ts`: none.**
- **Test comments: 22 sites carry 13 numbers that answer 404 and that
the census never reads** (they stand only in test files). By the
dispatch's rule they are not this stage's population, so they are
counted and not edited: `objectstack-ai#6287`, `objectstack-ai#10058`, `objectstack-ai#10064` (2), `objectstack-ai#10420`,
`objectstack-ai#10978` (2), `objectstack-ai#11017`, `objectstack-ai#13214`, `objectstack-ai#13244`, `objectstack-ai#13258`, `objectstack-ai#14389`, `objectstack-ai#14431`
(5), `objectstack-ai#14767`, `objectstack-ai#17621` (4). `objectstack-ai#14767` stands on a line this PR rewrote
(`get-meta-item-org-read-gate.test.ts:10`): it is the pull-request
number of `96326040f`'s squash, kept beside the new anchor as it stood.
- **String literals: 63 test-string sites** (describe and `it` titles,
assertion arguments) carry dead numbers: 56 with census-dead numbers
(`objectstack-ai#12194` 6, `objectstack-ai#10789` 5, `objectstack-ai#10886` 5, `objectstack-ai#11014` 4, `objectstack-ai#11674` 4, `objectstack-ai#16488` 4,
and 20 more numbers once to three times) and 7 with `objectstack-ai#17621`. Non-test
source strings carry none. Strings are outside this stage's file
surface.
- **Outside `src`:** the release-owned `CHANGELOG.md` names dead numbers
on 56 sites (45 census-dead, 11 among the 404 reads); left. `README.md`,
`package.json` and `tsconfig.json` name no number; `vitest.config.ts`'s
two are live.

## Mechanical guard: no code token moves

The guard compares, base `e47355be5` against the working tree, over all
54 touched `.ts` files:

- **Reading 1**: the TypeScript parser's leaf nodes, from a
`forEachChild` walk. Comments are trivia there, and JSDoc is never
visited.
- **Reading 2**: the full token stream in parser context, from a
`getChildren` walk. Punctuation and keywords are included and JSDoc
nodes are skipped. String, template and numeric literals are compared in
full on both readings.

Results:

- Real run at the head: 213,265 base tokens, **0 files with a token
change** on either reading (exit 0).
- Comment control (「The derived」 to 「The DERIVED」 on `protocol.ts:13`):
0 files changed (exit 0).
- Positive control, a code identifier (`postureEnforcesWall` to
`postureEnforcesWallX` in `protocol.ts`'s import): DIFFER in both
readings (exit 1).
- Positive control, a string literal (`'dashboard'` to `'dashboardX'` in
`sys-metadata-repository.contract.test.ts`): DIFFER in both readings
(exit 1).
- Positive control, a numeric literal (`BULK_BATCH_SIZE = 200` to `201`
in `seed-loader.ts`): DIFFER in both readings (exit 1).

Every mutation went through `scripts/ablation-replace.mjs` (wrap mode)
under a shell trap that restores by absolute path from `HEAD`. Each
landed: anchor count 1 to 0, blob changed. Each restore was proven equal
to its `HEAD` blob (`5be50ab59075`, `99ef73ef7562`, `41b999ca3ecc`),
with `git diff HEAD` empty and a clean tree afterwards.

## Changeset: `patch` (`dist` measured)

`files[]` is `dist`, `README.md` and `CHANGELOG.md`, and the package is
not private. The dependency closure was built first (`turbo run build
--filter='@objectstack/metadata-protocol^...'`, 12 tasks). Then the
package's own `build` (tsup plus `check-dts-emitted`) ran three times
under the shared verify lock:

- **Leg 1**, at the head: 24 `dist` files hashed. Of the 154 rewritten
non-test lines, 52 appear verbatim in `dist`: 36 from `protocol.ts`, 7
from `sys-metadata-repository.ts`, 5 from `seed-loader.ts` and 4 from
`migrations/seed-tenancy-backfill.ts`. Most are in `index.d.ts` /
`index.d.cts`; two from `seed-tenancy-backfill.ts` are in `index.js` /
`index.cjs`, where esbuild keeps a comment inside an expression.
- **Leg 2**, with the base text put back in the 8 non-test files (each
proven equal to its base blob): `index.d.ts`, `index.d.cts`, `index.js`
and `index.cjs` differ from leg 1, and so do the content-hashed chunk
names, including the seed-loader chunks.
- **Leg 3**, after the proven restore: all 24 files are byte-identical
to leg 1, so the build is deterministic and the difference is the
rewrite.

So the rewrite ships, and
`.changeset/20595-metadata-protocol-provenance-anchors.md` declares a
`patch` for `@objectstack/metadata-protocol`, comment text only, with
the claim's `Clause-②: no` line.

## Gates (head `3265b142f`)

- **Citation judging, as CI runs it:** `node
scripts/check-issue-citations.mjs` exits 0 (「every citation this change
adds resolves」, 19 citations judged across 8 files). `pnpm
check:issue-citations` exits 0 (self-test, 173 cases, 9 batteries).
- **Doc authoring:** `pnpm check:doc-authoring` exits 0 (17,085 spec
strings clean; the sibling-package prose-id baseline holds, no growth).
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` at `3265b142f` (change set
derived from git: 55 paths against merge base `e47355be5`) derived 62
commands. All 62 ran, each with its exit code captured before any pipe,
and all 62 exit 0. `--ran` reports 62 derived, 62 run, 0 NOT-MEASURED (a
derived zero), 0 unrun, and exits 0. A full `turbo run build` over
`./packages/*` and `./packages/*/*` ran first under the shared verify
lock (71 of 71 tasks), so no gate hit an unbuilt workspace.
- **Roster families the derivation lists outside its commands** whose
roster sits in a directory this diff touches: `node
scripts/check-changeset-fixed.mjs`, `pnpm check:authz-resolver` and
`pnpm check:error-code-casing`. Each exits 0.
- **Tests and typecheck, under the verify lock, at `3265b142f`:**
- `pnpm --filter @objectstack/metadata-protocol test`: 200 test files
pass and 3 skip (203); 2,973 tests pass and 19 skip.
- `pnpm --filter @objectstack/metadata-protocol typecheck` exits 0, and
`tsc --noEmit --listFiles` puts all 203 tracked test files in the
program (233 package files).
- **Lint, as a proven narrowing:** eslint with inline config disabled,
over the 54 touched `.ts` files plus `dist/index.js` as the control,
gives 55 results, 0 errors and 1 warning: the control's ignore notice.
Its `--format json` output reports none of the 54 ignored.
`eslint.config.mjs` never enables type-aware linting (its lines 327-328
say so), so a comment edit cannot move the verdict on any untouched
file. The repo-wide `pnpm lint` is CI's run.
- **Control bytes:** `pnpm check:nul-bytes` exits 0, and a raw scan of
the 55 changed files for control bytes finds none.

## Acceptance notes

- **Base.** The branch is on `main` at `e47355be5`. `main` has since
moved five commits (to `62b90d74f`), and `dispatch-gates` flags that as
a stale tree. None of the five touches a file in this diff,
`scripts/check-issue-citations.mjs` or `scripts/pm/dispatch-gates.mjs`.
One edits `protocol.meta-types-degenerate-derivation.test.ts` in this
package, adding a citation beside a live one. The one derivation input
that moved, `scripts/doc-authoring-prose-id.baseline.json`, lost 63
lines, none of them naming this package. No merge was taken; the merge
queue rebuilds on the merged generation.
- **The before census was not bracketed by newest-number reads.** It
enumerated 191 pages at frontier objectstack-ai#21227; the newest number read at
19:21:20Z, before the after run, was objectstack-ai#21228.
- **Comment ids are outside the grammar.** `comment 5299845282` stands
twice in this package (`protocol.ts:22793`,
`protocol.diff-credential-redaction.test.ts:19`) and names a comment on
the deleted `objectstack-ai#8671`, so it no longer resolves either. Neither instrument
reads it, and `75e66fc8e`, now cited beside it, carries the ruling's
text in its message. Left as it is.
- **Wording only:** 「the card」 / 「this card」 stands on 377 comment lines
in 105 files under this package. It carries no number, neither
instrument sees it, and this diff removes no antecedent except the one
repaired at `protocol-publish-drafts-package-scope.test.ts:400`.
- **A first guard reading was void.** The guard's first version read the
token stream with a bare scanner, which has no parser context. It loses
its place at template literals and reported 27 files changed; its
parser-context reading reported 0 on that same run. That bare-scanner
reading was replaced by the `forEachChild` walk above, and every figure
in the guard section is from the replacement.

---
_Generated by [Claude
Code](https://claude.ai/code/session_017xfMoEjKUuSh2xYB8sCozp)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants