Skip to content

fix(spec): datasource read redaction resolves a driver's identity the way its sibling helper does - #21963

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-21955-redaction-driver-identity
Oct 6, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-21955-redaction-driver-identity

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21955
Clause-②: no

What changed

The per-driver half of redactableConfigKeys in packages/spec/src/data/datasource-credential-redaction.ts now resolves a driver's identity through resolveDriverId. That is the resolver its sibling helper passthroughSecretPaths already uses, and the one the write door's contract lookup (getDriverConfigSchema) uses. There is no second identity resolver: the fix replaces one lookup line with the sibling's two-line shape.

  • Every spelling the write door judges against a builtin driver's contract is now redacted as that driver. The still-writable credential key is withheld on the datasource admin item read and on the metadata read under every accepted spelling, and redactedConfigKeys names it.
  • A crafted driver id now has a defined answer. It resolves to no builtin, so it answers as a driver the platform ships no contract for: the canonical credential spellings and the former aliases are withheld, and the read succeeds. It is never served and never throws.
  • No service-datasource source line moves. getDatasource(), restoreRedactedConfig and the credential migration all reach the fix through the spec export (measured below).

Measured reach, before the fix (BASE 76fec88b16, spec dist built from BASE)

A unit-level harness of service-datasource's DatasourceAdminService, with an in-memory record store, ran every spelling the alias table and the resolver's folding accept. The harness is scratch and is not committed.

  • Write door: every accepted spelling was accepted by DatasourceSchema.safeParse and by createDatasource, and was judged against the builtin contract (validateDriverConfig(...).known === true).
  • Admin item read (getDatasource, behind GET /api/v1/datasources/:name): for each accepted spelling other than the canonical one, the still-writable credential key came back in config and redactedConfigKeys was []. The canonical spelling withheld it.
  • Metadata read (the built-in datasource redactor, used by the /meta item and list reads): the same answer as the item read for every spelling.
  • Admin list read (listDatasources): it serves no config at all, by its contract (DatasourceSummary), so it carries no exposure for any spelling.
  • Crafted driver id: the write door accepted the row as an unknown plugin driver. Then getDatasource, the metadata redactor, restoreRedactedConfig and planCredentialMigration each threw an unhandled TypeError. So the item read failed, an edit with a config patch failed, and the migration planner failed. listDatasources was unaffected.

After the fix, the same harness reads every accepted spelling as withheld and named, and every crafted id as read without a throw.

Exposure stays admin-only: the datasource read doors require the admin capability.

Pins

  • packages/spec/src/data/datasource-credential-redaction.test.ts, a new block. Every spelling is derived from DRIVER_ID_ALIASES plus the resolver's own folding (as-is, upper, capitalised, padded), never listed by hand.
    • Premise: each accepted spelling resolves to its builtin and is judged by the write door against that contract.
    • Each accepted spelling answers its canonical driver's redactable set, byte-equal.
    • The still-writable credential key is withheld under each accepted spelling and named as withheld. It has a population floor, so a derivation that finds nothing fails.
    • Control: a canonical spelling withholds it exactly as before.
    • A crafted driver id answers as a driver with no shipped contract, with credentials withheld and no throw.
  • Lockstep in service-datasource (declared on [PM seat] domain:services — ⏳ vacant #6021):
    • datasource-config-redaction.test.ts: the admin item read withholds the key under each accepted spelling. An untouched Save restores the stored value under each accepted spelling, so redaction never turns a save into deletion. A crafted id is read with its credentials withheld, and an untouched Save keeps them.
    • datasource-credential-migration.test.ts: the planner reads the same list under each accepted spelling. A bindable row names the still-writable key as residue, byte-equal to the canonical spelling's plan. A row holding only that key is refused with it named.

Reverse verification (fix committed first, then reverted with scripts/ablation-replace.mjs, then restored)

  • Spec pin. The subject is imported relatively from src, so no build leg applies. Predicted three red, with the premise and the control staying green. Observed Tests 3 failed | 41 passed (44): the byte-equal set, the withheld key, and the crafted id. Restore proof: blob b543590328ef equals HEAD, and git diff HEAD is empty.
  • service-datasource pins. These resolve @objectstack/spec/data through dist, so each leg rebuilt spec.
    • Mutate leg: ablation-dist-preflight found the reverted line in 8 built files. Predicted five red. Observed Tests 5 failed | 61 passed (66).
    • Restore leg: rebuild, then --absent reported the marker absent from all 228 built files and the tree clean against HEAD. Then Tests 66 passed (66).

Clause-② (measured)

no. The fix narrows what the read path serves, not what @objectstack/spec accepts.

  • No schema file changed. DatasourceSchema.safeParse gave the same answer before and after for every spelling and every crafted id in the harness.
  • check:api-surface: public API surface + factory signatures unchanged.
  • check:authorable-surface and check:export-origins are green.

The changeset is @objectstack/spec patch. service-datasource takes none, because no source line in it moved.

Tests and gates (at HEAD cbea11408e)

  • pnpm --filter @objectstack/spec exec vitest run --project local --maxWorkers=2: Test Files 619 passed (619), Tests 18476 passed | 1 todo.
  • pnpm --filter @objectstack/service-datasource exec vitest run --maxWorkers=2: Test Files 41 passed (41), Tests 748 passed (748).
  • @objectstack/metadata-protocol, which reaches the datasource redactor: protocol.metadata-redaction.test.ts and stored-metadata-body-family.pin.test.ts gave Tests 56 passed (56).
  • pnpm --filter @objectstack/service-datasource typecheck and pnpm --filter @objectstack/spec typecheck (including check:test-typecheck) both exit 0. tsc --listFiles confirms that both edited service-datasource test files are in the program.
  • node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack: 87 derived, 86 run with exit 0, 1 NOT MEASURED, 0 unrun (--ran reconciliation).
    • NOT MEASURED: pnpm check:dual-build-cjs-loads, reason: PREREQUISITE NOT MET (exit 3). It reads every package's built dist/, and this worktree built only the closure it needed. Declared to CI.
  • Lint is a proven narrowing, not the repo-wide run.
    • ① The checked population is the four touched .ts files. Each resolves to a config under eslint --print-config, so none is ignored.
    • ② eslint --no-inline-config --format json linted 4 files with 0 errors and 0 warnings.
    • ③ Invariance: eslint.config.mjs enables no type-aware linting (zero project / projectService entries, and none in the resolved parserOptions). So this diff cannot move any untouched file's verdict.
    • The repo-wide pnpm lint stays CI's.
  • origin/main was re-fetched before this PR opened (80f9f7e6ba). Nothing that landed since BASE touches these files, so there was no merge.

Acceptance notes

  • STILL_WRITABLE_CREDENTIAL_KEYS and PASSTHROUGH_SECRET_PATHS are typed as string-keyed records. Typing them by the builtin id union would make a raw-string index a compile error, closing this defect class at tsc. That is not done here, to keep the fix to the sibling's shape. Carrier: the at-tier contract review of this PR.

Generated by Claude Code

claude added 3 commits October 6, 2026 06:16
… way its sibling helper does

The per-driver half of `redactableConfigKeys` now looks a driver up through
`resolveDriverId`, the resolver `passthroughSecretPaths` and the write door's
contract lookup already use. Every spelling the write door judges against a
builtin driver's contract is redacted as that driver, and a crafted driver id
answers as a driver with no shipped contract instead of throwing.

Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ
Co-authored-by: Claude <noreply@anthropic.com>
… credential migration hold under every accepted spelling of a builtin driver

Lockstep pins for the spec redaction fix: the item read withholds the
still-writable credential key under each accepted spelling, an untouched Save
restores the stored value, a crafted driver id is read with its credentials
withheld, and the migration planner reads the same list as under the canonical
spelling. No source line in this package moves.

Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added the size/m label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

1 anchor(s) derived from 1 changed package(s); no hand-written page names any of them, so this run has nothing to list — not a clean bill of health. This check sees only pages that NAME a derived anchor: one that documents this change in prose, or enumerates it in an authoring dialect, names none and stays invisible to it on every run.

What this run could not see
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 138 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 80f9f7e6ba5d2097a4cb32ca696908dcf9678102 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 9c12aae5c41bf6212c21662baad61cf30fc6a747 — the merge of head cbea11408e36bb46b64f71d04cd367a442ef4777 into base 80f9f7e6ba5d2097a4cb32ca696908dcf9678102, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 9c12aae5c41bf6212c21662baad61cf30fc6a747 && git checkout 9c12aae5c41bf6212c21662baad61cf30fc6a747
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 80f9f7e6ba5d2097a4cb32ca696908dcf9678102 cbea11408e36bb46b64f71d04cd367a442ef4777 && git checkout -B drift-repro 80f9f7e6ba5d2097a4cb32ca696908dcf9678102 && git merge --no-ff cbea11408e36bb46b64f71d04cd367a442ef4777

node scripts/docs-audit/affected-docs.mjs --json 80f9f7e6ba5d2097a4cb32ca696908dcf9678102

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

@github-actions github-actions Bot added documentation Improvements or additions to documentation protocol:data tests tooling labels Oct 6, 2026
@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 6, 2026 07:53
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 6, 2026 07:53
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit fb69825 Oct 6, 2026
37 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-21955-redaction-driver-identity branch October 6, 2026 08:24
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
… decision in words instead of a tracker number (stage 25) (objectstack-ai#21975)

Part of objectstack-ai#20749
Clause-②: no

Stage 25 of this card: the next area of class (e), the test strings
shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513.
This stage takes the second and last name-ordered `api/` group: the 13
id-bearing test files directly under `packages/spec/src/api/` from
`plugin-rest-api.handler-status-retirement.test.ts` to
`zod-issues-to-fields.test.ts`. Those files carried 89 messages and 95
tracker ids, citing 43 records. All 95 now either state what their
record decided, in words (form D), or are dropped where the title
already says it. No needle sits in this group. Text only: no assertion,
identifier, test count or code comment changes, and no file is renamed.
With this stage, `api/` carries no tracker id in a test string.

## Census at the base (`5a22eb5619`)

Instruments: `census10.cjs` (md5 `9d08602ab972b4b8643c90d64d40fa41`),
`census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`), `census-wide.cjs`
(md5 `c98410a19529c439adb0afbfb00026a2`) and `dirtable.cjs` (md5
`dda605c54745b4a60cc14c9a686e4eff`), byte-identical to the copies stages
10 to 24 used. A literal counts as a test title when its folded message
is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` /
`.only` chains included. Everything else is an "other" string.

The worktree was cut from `origin/main` at `5a22eb5619`, the claim's
base and stage 24's landing. Both instruments read **371 messages / 392
ids in 84 files**, the seat's reading and stage 24's head reading.

| directory | files | messages / ids | titles | other |
|:--|--:|--:|--:|--:|
| `system/` | 34 | 154 / 167 | 128 / 138 | 26 / 29 |
| (files directly in `src/`) | 30 | 118 / 120 | 117 / 119 | 1 / 1 |
| `api/` (this PR: all 13 files) | 13 | 89 / 95 | 86 / 92 | 3 / 3 |
| `ui/` | 5 | 7 / 7 | 0 | 7 / 7 |
| `ai/` | 1 | 2 / 2 | 0 | 2 / 2 |
| `contracts/` | 1 | 1 / 1 | 0 | 1 / 1 |
| **total** | **84** | **371 / 392** | **331 / 349** | **40 / 43** |

The group reads **89 messages / 95 ids in 13 files**, the seat's figures
file for file:

| file (under `api/`) | messages / ids | titles | other |
|:--|--:|--:|--:|
| `plugin-rest-api.handler-status-retirement.test.ts` | 4 / 4 | 3 / 3 |
1 / 1 |
| `plugin-rest-api.schema-refs.test.ts` | 2 / 2 | 2 / 2 | 0 |
| `plugin-rest-api.test.ts` | 2 / 2 | 2 / 2 | 0 |
| `protocol.test.ts` | 46 / 50 | 46 / 50 | 0 |
| `registry-retirement.test.ts` | 2 / 2 | 1 / 1 | 1 / 1 |
| `rest-api-config-dead-keys-retirement.test.ts` | 2 / 2 | 2 / 2 | 0 |
| `rest-server.test.ts` | 19 / 19 | 18 / 18 | 1 / 1 |
| `router.test.ts` | 1 / 1 | 1 / 1 | 0 |
| `sortability.test.ts` | 3 / 4 | 3 / 4 | 0 |
| `storage.test.ts` | 2 / 2 | 2 / 2 | 0 |
| `validate-data.test.ts` | 3 / 3 | 3 / 3 | 0 |
| `websocket.test.ts` | 1 / 1 | 1 / 1 | 0 |
| `zod-issues-to-fields.test.ts` | 2 / 3 | 2 / 3 | 0 |
| **13 files** | **89 / 95** | **86 / 92** | **3 / 3** |

Five more test files sit in the same name range and carry no id
(`query-adapter.test.ts`, `realtime-shared.test.ts`, `realtime.test.ts`,
`retired-error-codes.test.ts`, `versioning.test.ts`). The three "other"
strings are expect failure messages, rewritten and declared to the
text-only tool: `plugin-rest-api.handler-status-retirement.test.ts:179`
and `rest-server.test.ts:768` (template literals) and
`registry-retirement.test.ts:89` (one leaf of a `+` chain).

- **Controls.** Lit: `ui/notification.test.ts` (1 id) and
`system/book.test.ts` (2 ids), outside the group, read the same at the
base and at the head. Dark: `protocol.test.ts` reads 0 at the head while
65 of its lines still carry a number, every one of them a comment.
Planted in a scratch tree: an id put into a `storage.test.ts` title
reads 1 / 1 (`title:it`), and an id put into a `sortability.test.ts`
comment reads 0.
- **A wider pattern** (any `#` plus digits) reads the same as the gate
pattern in all 13 files at the base, and 0 in all 13 at the head.
- **At the head:** 282 messages / 297 ids in 71 files. The 13 files read
0 / 0, `api/` leaves the table, and no other file moved.

## How the area was chosen

`api/` has no subdirectory, so it is taken in name-ordered file groups
near the ~100-id bound, the rule stages 20 to 24 used. Stage 24's cut
named this group at 95 ids, and this census reads 95, so no re-cut was
needed. `protocol.test.ts` (50 ids) fits one PR and one text-only proof,
so it is not split.

**Named for the next stages** (cut from the head census, 282 / 297):
- **`system/`**, 167 ids in 34 files (one of them in
`system/constants/`), two stages:
- **first group:** `auth-config.test.ts` through
`metadata-form-declared-rows.pin.test.ts`, 18 files, 91 messages / 97
ids (`i18n-resolver.test.ts` alone 53 / 56);
- **second group:** `metadata-form-zod-reconciliation.test.ts` through
`worker.test.ts`, 16 files, 63 / 70. Its first file carries 17 "other"
strings, its ledger `why` entries.
- The files directly in `src/`, 120, one stage.
- The needles: the three docblock needles, the kept
`ui/component-props-unknown-members.pin.test.ts:322` and stage 22's two.
One stage, with an at-tier review. The four colour literals stay, as
stage 21 decided.

## What each id became

- **10 literals (11 ids)** now state a decision in words.
- **12 literals (16 ids)** get their subject back in words, where the
number stood for a thing.
- **67 literals (68 ids)** drop a number the title already explains.

Every cited record was fetched with all its comments through REST, and
its decision was read from its ruling, ACCEPT and landing comments: a
keyword digest of every record, and full reads wherever the new words
carry a decision. 43 records are cited: 36 answer 200 and 7 answer 404.
Two more were read for context: objectstack-ai#14478, whose ruling B objectstack-ai#15677 executes,
and PR objectstack-ai#11426, objectstack-ai#11006's landing. The seven that answer 404 were read
from what landed, through the commits endpoint (this checkout is
shallow), each commit found through the CHANGELOG entry or the commit
list of `protocol.test.ts`:
- **objectstack-ai#6037**, from `18189983dd` (objectstack-ai#6474): `DataProtocol.validateData` asks
the write path for its verdict and persists nothing, objectstack-ai#4633 ruling D;
- **objectstack-ai#6239**, from `f549a0d4ad` (objectstack-ai#6526): `ViewProtocol`'s five
viewId-addressed methods and ten schemas are retired;
- **objectstack-ai#6361**, from `90bbf25107` (objectstack-ai#6866): the notification-list `cursor`
is tombstoned on both halves (maintainer ruling 2026-08-07, option A);
- **objectstack-ai#9740**, from `11b779e0f9` (objectstack-ai#9773):
`MetadataProtocol.getMetaItemLayered` is declared, and the dead
`'overlay'` `lockSource` arm is dropped;
- **objectstack-ai#9741**, from `2a29caa532` (objectstack-ai#9804): `previewDrafts` / `state` are
declared where the implementation enforces them, and `environmentId` is
recorded as transport-level. Its changeset
(`packages/spec/CHANGELOG.md:31798`) names it "maintainer ruling
2026-08-18", and `cccbe51bf7` cites "the objectstack-ai#9741 ruling";
- **objectstack-ai#11006**, from `cccbe51bf7` (objectstack-ai#11426): `publishMetaItem` is declared
as an optional member with `PublishMetaItemRequest` (maintainer ruling
2026-08-22, option B);
- **objectstack-ai#14691**, from `b3a63d32c9` (objectstack-ai#14868): the ten inert
`RestServerConfig` keys the liveness ledger recorded as `dead` are
retired.

**The same-id titles stage 24 listed in this group:**
- **`[objectstack-ai#5672]` x2** (`protocol.test.ts:508`, `:526`): objectstack-ai#5672's maintainer
ruling A (`5199159328`): one closed capability vocabulary, emitted in
full by both discovery producers, with an absent capability `enabled:
false` rather than a missing key. `:508` now reads "strips a capability
key outside the closed vocabulary". The old verb was "rejects", but the
body pins the opposite: the parse stays green and the key does not
survive it. `:526` now reads "… (ruled: an absent capability is
`enabled: false`, not a missing key)".
- **`(objectstack-ai#12038)` x5** (`:2575` to `:2686`): these five "declares the …
body" describes are the describe-only transcriptions that the five-part
ruling's implementation plan names (`5434804846`). None of them pins a
lettered sub-ruling, so no letter is named; the title already says the
decision, and only the number goes.
- **`(objectstack-ai#12038 1C)`** (`:2710`): now "GetPublishedMetaItemResponseSchema
stays opaque (ruled: no shape frozen against the current type
registry)", ruling 1C's own reason. Its children pin the `unknown` body.
- **`(objectstack-ai#19543, door ③)`** (`:2726`): door ③ is the AI-conversation list,
which the schema name already names, and "declares the next-page signal"
is that door's spec half (letter A, re-derivation `5825819437`). Only
the number and the door label go.
- **`(objectstack-ai#15677)`** in `plugin-rest-api.test.ts:694` and
`websocket.test.ts:712`: now "… durations carry their unit in the key
name", objectstack-ai#14478's ruling B (`5518649320`, population ruling `5548763981`),
which objectstack-ai#15677 executes for `api/`. In `router.test.ts:565` the title
already shows the rename (`RouteDefinition.timeout → timeoutMs`), so
only the number goes.

**Stated in words:**

| record | literal (under `api/`) | now reads | the decision |
|:--|:--|:--|:--|
| objectstack-ai#14478 via objectstack-ai#15677 | `plugin-rest-api.test.ts:694`,
`websocket.test.ts:712` | "… durations carry their unit in the key name"
| Ruling B: a `z.number()` duration key carries its unit in its name;
the old spellings are `retiredKey()` tombstones. |
| objectstack-ai#5672 | `protocol.test.ts:508` | "strips a capability key outside the
closed vocabulary" | Ruling A (2026-08-06): one closed vocabulary. |
| objectstack-ai#5672 | `protocol.test.ts:526` | "rejects a capability map that is
missing part of the vocabulary (ruled: an absent capability is `enabled:
false`, not a missing key)" | Ruling A: both producers emit the whole
vocabulary. |
| objectstack-ai#9406 | `protocol.test.ts:1313` | "probes is opaque BY DECLARATION
(ruled: modeled only once a consumer needs a field): …" | Maintainer
ruling 2026-08-18 (`5322875103`): `probes` gets a deliberately opaque
passthrough, upgraded to a modeled schema only when a consumer needs a
field of it. |
| objectstack-ai#9343 | `protocol.test.ts:1383` | "PublishPackageDraftsResponseSchema
published[].advisories (ruled: advisory findings ride each published
element)" | Maintainer ruling 2026-08-17 (`5321046016`): `advisories`
rides each `published[]` element, with no parallel top-level map. |
| objectstack-ai#9741 | `protocol.test.ts:1739` | "environmentId stays OUT of the
meta-read request shape — transport-level by decision, not omission" |
The 2026-08-18 ruling, as landed in `2a29caa532`: `environmentId` is the
transport-level multi-kernel routing key. |
| objectstack-ai#12038 | `protocol.test.ts:2710` | "GetPublishedMetaItemResponseSchema
stays opaque (ruled: no shape frozen against the current type registry)"
| Ruling 1C (`5434804846`): a thin envelope with the body opaque, no
union frozen against today's type registry. |
| objectstack-ai#6037 | `validate-data.test.ts:25` | "ValidateDataRequest — asks the
write path for its verdict instead of predicting it" | What landed in
`18189983dd`: the dry run stops predicting the write's verdict and asks
for it. |
| objectstack-ai#6037 | `validate-data.test.ts:57` | "ValidateDataResponse — the
verdict the write path would reach, persisting nothing" | The same
commit: `validateData` reports the write path's verdict on candidate
rows and persists nothing. |

**Subject back in words** (12 literals):
- "zero holders after objectstack-ai#13823" becomes "zero holders after its
retirement", and "[objectstack-ai#13823] ADR-0087 registration" becomes "handlerStatus
retirement — ADR-0087 registration", the form of the repo's other
retirement registration describes (objectstack-ai#13823 ruled remove, `5494755488`);
- "the routes wired in objectstack-ai#3899" becomes "the routes wired to the
request-schema gate", the gate the file's header names;
- "(objectstack-ai#13155 — carries objectstack-ai#5745 to the third verb)" becomes "(carries the
declared = returned discipline to the third verb)", the discipline objectstack-ai#7294
and objectstack-ai#13155 name objectstack-ai#5745 for;
- "(objectstack-ai#4717 — objectstack-ai#4463 D3 on the response)" and "(objectstack-ai#9176 — objectstack-ai#4463 D3 on the
publish door)" become "(advisory findings ride the 2xx response)" and
"(advisory findings ride the 2xx on the publish door too)": objectstack-ai#4463's D3
sends gating findings to 422 and lets advisory findings ride the 2xx;
- "the objectstack-ai#9612-gate class" becomes "the package-closure publish-gate
class": objectstack-ai#9612's gate judges a publish against the written package's
closure;
- "objectstack-ai#10235 the objectstack-ai#7865 anchor category" becomes "the unprovisioned
injected-anchor category", the platform anchors injected into an
external object whose storage the platform does not provision (objectstack-ai#7865,
ruling B);
- the two "pre-objectstack-ai#3689" storage shapes become shapes "from before the
shared success envelope";
- "the objectstack-ai#4052 non-repeat" becomes "the non-repeat of the retired
`validateOnly` dry-run flag";
- "every objectstack-ai#8055-shaped fixture" becomes "every malformed-flow-body
fixture".

**Dropped where already stated** (67 literals, 68 ids). A number goes
only where the title already says its decision. Examples: the two
`[objectstack-ai#13823]` describes and the twelve `[objectstack-ai#14691]` / `(objectstack-ai#14691)` retirement
titles ("REJECTS `patterns` with the retirement prescription — …", "the
tombstones reject one key each, not the config — …"); `[objectstack-ai#11983]` x3,
`[objectstack-ai#4579]` x2, `[objectstack-ai#4939]`, `[objectstack-ai#6361]`, `[objectstack-ai#20294]` and `objectstack-ai#3899 —`; the
`objectstack-ai#10235` prefixes on "resolveObjectSortability — the closed category
set" and "wire validity — …"; the five "transport-level by the objectstack-ai#9741
ruling" titles, which now read "transport-level by ruling"; the
parenthesized `(objectstack-ai#5745 — …)`, `(objectstack-ai#7294 — …)`, `(objectstack-ai#9406 — …)`, `(objectstack-ai#10524 —
…)` x2, `(objectstack-ai#9726 — …)`, `(objectstack-ai#9741 — …)` and `(objectstack-ai#4717 — …)` pairs, which keep
their words; and the tails `(objectstack-ai#6239)`, `(objectstack-ai#4286)`, `(objectstack-ai#9740)`, `(objectstack-ai#11006)`
x2, `(objectstack-ai#11678)` x3, `(objectstack-ai#9426)`, `(objectstack-ai#12005)` x3, `(objectstack-ai#11679)` x2, `(objectstack-ai#12004)`
x2, `(objectstack-ai#3718)`, `(objectstack-ai#4572)`, `(objectstack-ai#4579)`, `(objectstack-ai#20294)`, `(objectstack-ai#8124/objectstack-ai#8055)`, the
five `(objectstack-ai#12038)` and the `(objectstack-ai#4738, …)` aside in one expect message. The
404 numbers among them (objectstack-ai#6239, objectstack-ai#6361, objectstack-ai#9740, objectstack-ai#9741, objectstack-ai#11006, objectstack-ai#14691) go
only where the title already states what landed.

**No file is renamed.**

## Readers

- **Needles:** none. The three declared strings are assertion failure
messages (the second argument of `expect`), none is an expected value,
and no title or message in the group is matched against a source
docblock or another file's text. The one self-read in the group,
`rest-api-config-dead-keys-retirement.test.ts:519`, reads its own file
for the id-free describe title "tree-scoped absence", which this PR does
not touch.
- **Test-name filters:** none. No tracked script, workflow or package
config passes `-t` / `--testNamePattern` to vitest; the one vitest `-t`
hit is a README example under `packages/qa/dogfood` filtering its own
fixture.
- **Snapshots:** none. No `__snapshots__` directory is tracked under
`packages/spec`, and none of the 13 files calls a snapshot matcher.
- **Projects:** `rest-api-config-dead-keys-retirement.test.ts` is in the
`repo` project (`packages/spec/vitest.repo-tests.json:31`); the other 12
run in `local`. The base-versus-head run below takes both projects.
- **By substring:** every old literal, its id-bearing fragment and a
window around each id (270 needles) was searched with `git grep` at the
base, across the tracked tree outside its own file. No gate, doc,
filter, snapshot, QA checklist entry or `scripts/check-*.mjs` self-test
reads one. The 6 hits are sibling test titles: the two `(objectstack-ai#15677)`
describes in this group hit each other (both rewritten here),
`client/src/client.test.ts:1134` shares "query.distinct (objectstack-ai#4286)", and
`metadata-protocol/src/protocol.validate-data.test.ts:102` shares "the
objectstack-ai#4052 non-repeat".

## Text-only proof

Stage 10's scratch tool (`textonly10.cjs`, md5
`d5e4801dbb4329ab1984da91e92fc47c`) compares base and head file by file
on three legs:
1. **Skeleton:** the full AST, with string pieces masked. It must be
identical.
2. **Comments:** every comment, byte-equal.
3. **Strings:** each changed string leaf must sit in a test-call title
position or on a declared line, must carry a tracker id before, and must
carry no `#` plus digits after. This stage declares the three
expect-message lines named above.

- **Result:** 13 of 13 files SAME on all three legs, with the per-file
counts predicted in writing before any edit.
- **Totals:** 89 changed string leaves in 89 literals: 86 titles and 3
declared. The diff's `+` and `-` lines are exactly the 89 planned lines
as multisets, and every file keeps its line count.
- **Controls (14 of 14 as predicted on the first run, on scratch copies,
each anchor hit once):** identifier rename DIFF; numeric literal DIFF;
comment edit COMMENT DIFF; a non-title string given an id VIOLATION; a
rewritten title given a new id VIOLATION; a title that was id-free at
base edited VIOLATION; one title reverted to base SAME; an `it.each` row
given an id VIOLATION; an undeclared expect message changed VIOLATION; a
title re-split into a `+` chain DIFF; a declared expect message reverted
to base SAME; a declared template expect message given a new id
VIOLATION; a declared `+`-chain leaf given a new id VIOLATION; a
template-literal title given a new id VIOLATION.
- **Templates and tables:** no `.each` title and no `$name` placeholder
changes. The two template literals change only their text after the
`${…}` span.

**Test counts:** the 13 files were run at the base, in a separate base
worktree, and at the head, with `--project local --project repo`. Both
sides read 509 tests in 13 files, all passed, with the same count and
status sequence per file in 13 of 13. 250 full test names change, and
each changed name equals the base name with the planned replacements
applied: 0 mismatches. No full name repeats on either side, and no head
name carries `#` plus digits (250 base names did). `router.test.ts:565`
writes its arrow as a `→` escape; the plan's anchor there starts after
the escape, so the comparison tool, which reads escapes literally, met
none, and vitest prints "RouteDefinition.timeout → timeoutMs …" on both
sides.

## Changeset: `skip-changeset`

Measured, not assumed:
- `npm pack --dry-run` of `@objectstack/spec` lists 2068 files. 0 of the
13 touched files are in it, and no `*.test.ts` at all. The controls
`src/api/protocol.zod.ts`, `src/api/rest-server.zod.ts` and
`dist/index.mjs` are in it.
- In the built `dist/`, two new phrases and an old one each read in 0
files. The control `Unrecognized key` reads in 42.

So this PR publishes nothing, and no changeset is added.

## Verification (at `c63eba0adf`)

- `pnpm turbo run build` over all packages: 71 / 71, through the shared
verify lock (`VERDICT command-exit 0`).
- `@objectstack/spec`:
  - `vitest run --project local`: 619 files, 18480 passed, 1 todo.
- `typecheck`: exit 0, including `check:test-typecheck` (52 files / 246
errors / 135 pinned signatures held). Its program holds all 13 group
files, counted by path with `tsc --listFilesOnly -p tsconfig.test.json`.
- `check:generated`: all 15 generated artifacts up to date, against the
`dist/` the build above wrote.
- **Gates:** `dispatch-gates --commands` derived 79 families: stage 24's
80 without `check:error-code-casing`, whose named sources this diff does
not touch. All 79 exit 0. `--ran` reconciles: 79 derived, 79 run, 0
NOT-MEASURED, 0 UNRUN, every family with its exit code recorded. The
same 79 derive from `origin/main` `230e4944b0` with this diff applied.
The five roster families marked as sharing a directory with this diff
(`check:meta-url-spelling`, `check:spec-changes`,
`check:authz-resolver`, `check:error-code-casing`,
`check:filter-alias-parity`) each exit 0.
- **ESLint, a proven narrowing:** `--no-inline-config` over the 13 files
reads 0 errors and 0 warnings. The population comes from ESLint's own
config: 13 configured, 0 ignored. No file sets `parserOptions.project`
or `projectService`, so no untouched file's verdict can move.
- `check-governed-merges --test`: NOT governed, 178 changed lines (+89 /
-89).
- A control-byte scan over the 13 changed files finds none.

## `main` since the base

Re-fetched just before this PR opened, `origin/main` was six commits
past the base (`c9761cd2fb`: objectstack-ai#21966, objectstack-ai#21951, objectstack-ai#21963, objectstack-ai#21969, objectstack-ai#21965,
objectstack-ai#21962). They touch 28 files, none of the 13 and none under
`packages/spec/src/api/`, so `main` was not merged. The two
`packages/spec/src` files they change
(`data/datasource-credential-redaction.ts` and its test) read 0 / 0 in
the census at `c9761cd2fb`: the one id they add is a code comment. `git
merge-tree` onto `c9761cd2fb` is clean, and none of the 4 open PRs
touches any of the 13 files.

## Acceptance notes

- **Same-id test titles in this card's later stages** go with those
stages: `system/book.test.ts:413` (`(objectstack-ai#12038)`).
- **Same-id test titles in other packages** stay: 97 lines in 15
packages (`runtime` 25, `objectql` 13, `lint` 12, `metadata-protocol`
12, `rest` 12, `client` 8, `metadata-core` 4, `qa/dogfood` 2,
`service-automation` 2, `service-storage` 2, and one each in
`examples/app-crm`, `examples/app-showcase`, `driver-sql`,
`plugin-sharing` and `types`), each package's share under the objectstack-ai#20513
lane children.
- **Code comments with live ids** remain in these files and their
sources, among them the `* objectstack-ai#3899 —` header in
`plugin-rest-api.schema-refs.test.ts`, the `* objectstack-ai#8124 —` header in
`zod-issues-to-fields.test.ts`, the `// [objectstack-ai#5672] This fixture used to
lead with …` comment above `protocol.test.ts:508`, and the `/** [objectstack-ai#20294]
… */` docblock in `rest-api-config-dead-keys-retirement.test.ts`. Code
comments are not this card's share.

---

_Generated by [Claude
Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation protocol:data size/m tests tooling

Projects

None yet

2 participants