Skip to content

feat(lint): ADR-0091 seed pair crosses the runtime publish gate (#8307) - #8390

Merged
hotlong merged 1 commit into
mainfrom
claude/issue-8307-seed-pair-runtime-types
Aug 13, 2026
Merged

hotlong merged 1 commit into
mainfrom
claude/issue-8307-seed-pair-runtime-types

Conversation

@hotlong

@hotlong hotlong commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Fixes #8307

Programme slice of #7891 (staging per #4001 pattern, #7220/PR #7479 precedent — the strictness-rollout direction is ruled, not re-decidable in this slice).

What changed

packages/lint/src/authoring-rules.ts — the validateSecurityPosture registry entry now declares surfaces: ['cli', 'runtime-publish'] with runtimeTypes: ['seed'] (previously CLI_ONLY with a surfaceReason). This puts the ADR-0091 seed pair — security-grant-expired-at-authoring, security-delegation-missing-reason — on the runtime metadata publish door (Studio, REST /meta, MCP/AI authors) for a seed write, per #7576's own staging note that this pair was the one slice ready to cross.

Why declaring it on the WHOLE registry entry is safe

This entry is the WHOLE validateSecurityPosture function (all 13 rule ids) — there is no per-rule-id split in authoring-rules.ts. runtime-gate.ts's baseline/candidate differential is what makes runtimeTypes: ['seed'] safe to declare here without leaking the other 11 rule ids' verdicts: a seed write's candidate stack carries objects IDENTICAL to the baseline (only data differs), so every finding this function derives from stack.objects / stack.permissions / stack.positions / stack.apps / stack.books is produced byte-identically in both passes and cancels in the diff. Only the ADR-0091 pair's stack.data[] reads can differ between the two passes. This is proven — not just asserted in a comment — by a new positive-control test: a seed write against a context object that WOULD trip security-owd-unset and security-role-word if the isolation failed, asserting zero leaked findings.

object / permission / book remain undeclared — that is #8310, still blocked (a strictness rollout on object, RUNTIME_NEEDS_FULL_SNAPSHOT on permission/book). security-role-word is deliberately not in this slice either (#7220 constraint — it judges six collections and wiring only the snapshot-safe two would split one rule id across the wall).

Re-measured, not inherited (hard constraint from the dispatch)

The dispatch required re-running the "trip-free on the shipped corpus" claim rather than trusting #7576/#8308's numbers. I grepped every defineSeed(...) call site across all four shipped stacks (showcase, CRM, todo, the blank create-objectstack template):

  • examples/app-showcase/src/data/seed/index.ts seeds Account, Contact, Project, Task, Category, BusinessUnit, Team, Product, ProjectMembership, FieldZoo, Invoice, InvoiceLine, ExpenseReport, ExpenseLine, Inquiry, Preference, Announcement.
  • examples/app-crm/src/data/index.ts seeds Account, Contact, Opportunity, Lead, Activity.
  • examples/app-todo/src/data/index.ts seeds Task.
  • packages/create-objectstack/src/templates/blank has no seed data at all.

None of the four apps authors a sys_user_position or sys_user_permission_set seed row — grep for valid_until, delegated_from, and either object name across all three source trees returns zero hits. Showcase's own approval demo (src/security/seed-approval-demo.ts) explicitly does this at runtime instead, precisely because "users can't be seeded (they sign up) and position assignments are runtime admin actions." So the ADR-0091 loop body (GRANT_SEED_OBJECTS.has(seedObject)) never executes for any of the four shipped apps — this is a structural zero for the current corpus, not a measured-and-hoped-stays-zero one. No STOP condition was hit.

Tests

packages/lint/src/validate-security-posture.runtime-surface.test.ts extended with the pin recording the crossing:

  • the whole registry entry now reports surfaces: ['cli', 'runtime-publish'] / runtimeTypes: ['seed'];
  • the pair is refused through the real runRuntimeAuthoringRules({ type: 'seed', ... }) (previously only the pre-crossing mirror could be asked);
  • a clean grant/delegation write earns zero errors/advisories at the real gate (positive control);
  • a seed write leaks no finding from the other 11 rule ids this entry carries, even against a context that would trip two of them over the whole stack (isolation proof);
  • object / permission / book / position / app still reach no rule (unaffected — [3 of #7891] Flip the registration: runtimeTypes gains object + permission/book — whole rule families cross the publish door #8310's residue).
pnpm --filter @objectstack/lint build   → exit 0
pnpm --filter @objectstack/lint test -- --maxWorkers=2
  Test Files  72 passed (72)
       Tests  1978 passed (1978)
pnpm --filter @objectstack/lint typecheck   → clean (tsc --noEmit)

Local gates (node scripts/pm/dispatch-gates.mjs <changed paths>)

Re-derived against the actual committed diff (git diff --name-only 2d8dba312 HEAD) — same file set as before commit, no drift:

  • check:spec-parsed-alias — OK
  • check:cross-package-test-inputs — OK (self-test + real run)
  • check:changeset-gate-self-tests (empty-changeset / adr-0087-registration / changeset-no-major self-tests) — OK
  • check:objectui-changeset, check:objectui-pin-fresh self-tests — OK
  • node scripts/check-changeset-no-major.mjs — "This diff introduces no major bump"
  • node scripts/check-adr-0087-registration.mjs — "this PR adds no declared-breaking changeset" (correct: this is additive enforcement, not a spec key removal/rename)
  • Convention-triggered (new test file): check:query-options-erasure — ratchet holds, no new unswept sites; check:type-check-coverage — unaffected, @objectstack/lint typechecks clean
  • check:nul-bytes — OK, no raw control bytes

check:api-surface is untouched, as expected — no packages/spec source in this diff.

Changeset

.changeset/security-posture-seed-pair-runtime-publish.md, "@objectstack/lint": minor — following the direct precedent of .changeset/visibility-predicate-family-runtime-publish.md (#7220's own family crossing the runtime-publish wall, also minor) rather than the dispatch prompt's default "patch unless conventions say otherwise": this is a real behavior change (a class of runtime writes that used to succeed will now be refused), and the established convention for "a rule crosses onto runtime-publish" in this repo is minor, not patch.

Scope note

File surface matches the dispatch exactly: the validateSecurityPosture registration in packages/lint, the runtime-surface pin extension, and the changeset. No object/permission/book wiring, no security-role-word. Did not touch #8273's (error-code-ledger + service-settings) or #8057's (objectql engine + kernel schema) files.


Generated by Claude Code

Register runtimeTypes: ['seed'] on the validateSecurityPosture registry
entry (packages/lint) so security-grant-expired-at-authoring and
security-delegation-missing-reason enforce at the runtime metadata write
door for a seed publish, per the #7891 programme's #4001-pattern staging.

Re-measured trip-free rather than inherited from #7576/#8308: none of the
four shipped stacks (showcase, CRM, todo, blank) author any seed row on
sys_user_position / sys_user_permission_set at all (grep across every
defineSeed() call site), so the ADR-0091 loop body never executes for the
current corpus -- structurally zero, not merely counted zero.

The other eleven rule ids this one registry entry also carries (object /
permission / book posture, security-role-word, ...) stay undeclared -- that
is #8310, still blocked on a strictness rollout and
RUNTIME_NEEDS_FULL_SNAPSHOT. Declaring runtimeTypes: ['seed'] on the WHOLE
entry rather than splitting it is safe because runtime-gate.ts's
baseline/candidate differential holds stack.objects identical across both
passes for a seed write, so every other-rule finding fires identically in
both passes and cancels in the diff -- proven in
validate-security-posture.runtime-surface.test.ts, including a positive
control (a trippy object context that WOULD leak if the isolation failed).

Extends validate-security-posture.runtime-surface.test.ts with the pin
recording the crossing (real runRuntimeAuthoringRules calls, not the
pre-crossing mirror) and a changeset.

Fixes #8307

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Euoy6wyfzgiWtgCg4s6JK2
@vercel

vercel Bot commented Aug 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectstack Ignored Ignored Aug 13, 2026 10:52am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/lint.

3 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/automation/hook-bodies.mdx (via @objectstack/lint)
  • content/docs/deployment/validating-metadata.mdx (via packages/lint)
  • content/docs/permissions/authorization.mdx (via @objectstack/lint)

⛔ 1 release-owned page(s) also reference the affected code. These are read-only:

  • content/docs/releases/v17.mdx (via @objectstack/lint)

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@github-actions github-actions Bot added documentation Improvements or additions to documentation tests tooling labels Aug 13, 2026
@hotlong
hotlong marked this pull request as ready for review August 13, 2026 11:19
@hotlong
hotlong added this pull request to the merge queue Aug 13, 2026
Merged via the queue into main with commit e41c1f2 Aug 13, 2026
26 checks passed
@hotlong
hotlong deleted the claude/issue-8307-seed-pair-runtime-types branch August 13, 2026 11:48
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Aug 17, 2026
… on validateSecurityPosture's reach (objectstack-ai#8547) (objectstack-ai#8866)

Two test comments justified the `package-author` carve-out with a claim about
where `validateSecurityPosture` is enforced, and that claim rotted twice.

`protocol.runtime-authoring-gate.test.ts` still said the rule is `CLI_ONLY` in
`AUTHORING_RULES`. The entry declares `surfaces: CLI_AND_RUNTIME` with
`runtimeTypes: ['seed', 'permission', 'book', 'object']` — false since PR objectstack-ai#8390,
and the `object` limb landed with PR objectstack-ai#8600.

`meta-object-owd-gate.test.ts` had already lost the words `CLI_ONLY` but still
concluded package authoring is "gated at build time instead", contradicting its
own file header and the sibling comment 214 lines above, both of which say the
rule now runs for `object` writes at that door.

Neither site is repaired by a word swap. The carve-out is intact and was never
the defect: both doors skip the `package-author` channel deliberately —
`assertRuntimeAuthoringRules` returns early on it at every call site and the
single `runAuthoringGate` call is guarded by the same check. The reason is
re-founded on that channel rather than on the rule's reach, which moves with
every objectstack-ai#7891 slice. Door order and ADR-0094's R1-stays / R2-retired outcome are
pointed at where they are already pinned rather than restated a second time,
and the surviving `isSystem` / `sys_*` exemption is recorded as fact with a
pointer to the open decision card.

Comment prose only: the diff touches `//` and ` *` lines exclusively. No
behaviour, assertion, pin or test-count change.


Claude-Session: https://claude.ai/code/session_01XeQRiAa7vYRVX5Fog7Zby8

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…commits and ADR that decided them (objectstack-ai#21233)

Part of objectstack-ai#20595
Clause-②: no

## What changed

Stage 1 of the `domain:engine` lane of the dead-citation sweep:
`packages/metadata-protocol/**`, comment and docblock prose only, per
the claim (`5938223120`). The next stages (`objectql`, `driver-sql`,
`driver-memory`, then the rest) are separate claims, so objectstack-ai#20595 remains
open.

Every comment or docblock site in the package that cited a tracker
number answering 404 is rewritten in ruling C+D's form C (record
`5749154545` on objectstack-ai#19123): the ADR or ruling record when one exists,
otherwise the commit in this repository's history that made the decision
the sentence describes. That is **293 sites on 279 lines in 54 files,
covering 56 numbers**:

- **163 census sites** (155 lines, 8 files under `src/`): the whole
`allocated-but-absent` population of the gate's own census in this
package at the base;
- **1 site in `tsup.config.ts`** (`:15`, `objectstack-ai#11235`): same number, outside
the census glob but inside the claimed file surface;
- **129 test-comment sites** (123 lines, 45 test files), which the
census defers, found by the supplementary reading below. Each cites a
number the census itself reads as dead (41 of the 43 numbers are among
the census set; `objectstack-ai#10485` and `objectstack-ai#8600` are dead elsewhere in the
repository).

**Anchors: 55 numbers by commit sha, 1 by ADR (`objectstack-ai#13185`, ADR-0005's
design-principle-3 correction), 0 by words alone.** `objectstack-ai#11674` is split
across two commits, one per half of what it named (see the table). Two
`objectstack-ai#12176` sites (`protocol.item-name-grammar.test.ts:6`, `:12`) drop the
number without a new citation, because line `:4` of the same docblock
now cites the commit (`311433f6b`) that both sentences describe.

Only comments changed. Every file keeps its line count (280 lines out,
280 in, plus the changeset), so no line citation into any of them moves.
No code token moves (the guard below). **No citation number is added**:
every number on an added line already stood on its line, and 20 of those
23 are live by the census's own judgement. Of the 3 it never reads (they
stand only in test files), `objectstack-ai#11099` and `objectstack-ai#8390` answer as pull requests
and `objectstack-ai#14767` answers 404 (see Sites left).

**A `patch` changeset**: 52 of the rewritten non-test lines are in the
published `dist` (the `.d.ts` keeps JSDoc on exported members, and
esbuild keeps a few comments in the JS), and `dist` is not
byte-identical with the base text (see Changeset).

## Census: `metadata-protocol`, before and after

**Instrument (A1).** The gate's own `node
scripts/check-issue-citations.mjs --census --json`, read-only and
unchanged (it carries objectstack-ai#20989's wider extractor, merge `a5bce40888`, an
ancestor of the base). The count is its `allocated-but-absent` findings
under `packages/metadata-protocol/`.

| reading | tree | board | whole-repo `allocated-but-absent` | sites |
lines | files | numbers |
|---|---|---|---|---|---|---|---|
| before | base `e47355be5`, run ended 18:52:32Z | enumerated, 191
pages, frontier objectstack-ai#21227, 19,048 records | 755 | **163** | 155 | 8 | 54 |
| after | `06d41e512`, run 19:21:20Z to 19:25:08Z | enumerated, 191
pages, frontier objectstack-ai#21228, 19,049 records (newest number objectstack-ai#21228 read just
before and just after the run) | 592 | **0** | 0 | 0 | 0 |

The whole-repo drop is 163, and the two finding sets differ by exactly
the 163 rows of this package, removed; none was added. `resolves`
(34,516), `resolves-as-pull-request` (2,092) and `cross-repo-unjudged`
(1,139) did not move. The card's 162 was taken at `f11b5f20a2` with the
older extractor; the base here reads 163, which includes the
slash-joined `partial-index-probe.ts:395` `objectstack-ai#16657` that the post-landing
census (`5923084795`) named. The only commit after `06d41e512` adds the
changeset file, which is outside the census surface.

**Supplementary instrument, the whole package.** The census reads
neither test files nor strings nor files outside `src`. A second reading
runs the gate's own exported `extractCitations` (whole-file and
comment-prose projections) and `namesThisRepository` over every tracked
file in the package (235 `.ts`, 2 `.md`, 2 `.json`). A number is dead
when the before census reported it `allocated-but-absent`, and live when
the census's own scope extraction judged it and did not report it. The
82 numbers neither covers (they stand only in test files, strings or the
changelog) were each read on their own (issues endpoint, which also
answers pull requests): 27 issues, 38 pull requests, **17 answer 404**.
Controls: `objectstack-ai#10888`, `objectstack-ai#11674` and `objectstack-ai#16657` (the card's and the census's
named sites) answer 404, `objectstack-ai#5286` and `objectstack-ai#12624` answer 200.

| reading | citations | dead | src comment | test comment | test string
| changelog |
|---|---|---|---|---|---|---|
| before, `e47355be5` | 6,383 | **434** | 164 | 151 | 63 | 56 |
| after, head | 6,090 | **141** | 0 | 22 | 63 | 56 |

`src comment` here includes `tsup.config.ts`. Its before value is the
census's 163 plus that one site, which is the control on the second
instrument. The drop of 293 citations is exactly the rewritten sites. A
third, raw reading (every `#` followed by 2 to 6 digits, whatever
surrounds it) counts 6,479 before and 6,186 after: the same drop of 293.
The 22 test-comment sites left all carry numbers outside the census's
surface (see Sites left).

## Per-number table

`src` counts census sites (plus `tsup.config.ts` for `objectstack-ai#11235`), `test`
counts test-comment sites. Every sha below matches exactly one commit
(`git rev-parse --disambiguate`, count 1) and is an ancestor of the base
(`git merge-base --is-ancestor`, exit 0 for all 56; the clone was
unshallowed first, `--is-shallow-repository` false, 15,415 commits at
the base). Each one's message or diff names the number it replaces (diff
counts are the added lines naming it), and for every sentence that
credits a ruling, a measurement or a note to the number, the commit's
own message carries that ruling, measurement or note: `ee58392e1` (the
2026-08-08 three-part ruling), `c74aefe63` (ruling 2026-08-22, option
A), `65846bc46` (ruling A, 2026-09-03), `75e66fc8e` (Option B, diff raw
then redact), `96326040f` (the idempotence proof the direction-A ruling
was conditional on), `8744de9e9` (the second-rung ablation), `82cb6e849`
(the two faces left open), `376c70f98` (the measured `shims: true`
consequence). The one exception is `2a29caa53` (`objectstack-ai#9741`): its message
records the decision itself (`environmentId` recorded as
transport-level) but not the 2026-08-18 ruling, so that site keeps its
own date and now reads 「recorded 2026-08-18, landed as commit
2a29caa」. 37 of the 56 numbers were already re-anchored by other
lanes' stages, and for every one of them this stage uses a commit those
stages used (none differs; `objectstack-ai#11674` adds `9a884c6e4` beside their
`1cba33f16`, because 25 of its 32 sites here describe the write-back
half, which `git blame` puts in `9a884c6e4`). The other 19 had no prior
anchor and were measured here.

| number | src | test | anchor | kind | what it decided |
|---|---|---|---|---|---|
| `objectstack-ai#6037` | 1 | 1 | `18189983d` | commit | validate-only data operation
— DataProtocol.validateData |
| `objectstack-ai#6307` | 1 | 0 | `293476148` | commit | refuse a repeated `?version=`
on `GET`/`DELETE /packages/:id` instead of handing the array to
PackageService |
| `objectstack-ai#6478` | 1 | 4 | `474f131cf` | commit | rolls `flow`'s
`allowOrgOverride` back to `false` per ADR-0005's original call, the
write path refusing loudly |
| `objectstack-ai#6483` | 8 | 10 | `ee58392e1` | commit | enforces the ADR-0005
whitelist: nine unratified `allowOrgOverride: true` flags rolled back to
`false`; its message records the 2026-08-08 three-part maintainer ruling
it executes |
| `objectstack-ai#6608` | 4 | 2 | `ee58392e1` | commit | the same commit: `objectstack-ai#6608` was
the pull request whose squash it is |
| `objectstack-ai#8600` | 0 | 1 | `018d22cc3` | commit | require authored OWD at the
runtime object door; retire ADR-0094 R2 external-wider arm; declare
object in runtimeTypes |
| `objectstack-ai#8648` | 2 | 0 | `e5eeb499c` | commit | pin the SEARCH-axis remedy
agreement, and correct the three comments that claimed word-identity |
| `objectstack-ai#8671` | 1 | 2 | `75e66fc8e` | commit | stop the meta diff endpoint
serving credential values |
| `objectstack-ai#8818` | 1 | 1 | `fd6bdf89f` | commit | saveMetaItem's missing-item
refusal declares 400 INVALID_REQUEST instead of answering 500 |
| `objectstack-ai#9740` | 1 | 0 | `11b779e0f` | commit | declare
MetadataProtocol.getMetaItemLayered; drop the dead 'overlay' lockSource
arm |
| `objectstack-ai#9741` | 1 | 0 | `2a29caa53` | commit | declare previewDrafts/state
on meta-read requests; record environmentId as transport-level; retire
REST door casts |
| `objectstack-ai#9798` | 1 | 0 | `c7655d472` | commit | restore the objectstack-ai#4630 unscoped
multi-delete refusal on sys_comment through the wired engine |
| `objectstack-ai#9817` | 1 | 1 | `855591fe7` | commit | discriminate a failed
sys_organization probe from a genuinely empty one |
| `objectstack-ai#9934` | 13 | 2 | `79c46da90` | commit | producer-side user-facing
marking for hook refusal messages — userMessage channel |
| `objectstack-ai#9967` | 2 | 1 | `8f266f1cd` | commit | serve a sandboxed body's
declared HTTP status on /api/v1/data |
| `objectstack-ai#10063` | 5 | 1 | `9e04c3e35` | commit | let the publish door state
the package it is promoting |
| `objectstack-ai#10159` | 1 | 0 | `1ec36b730` | commit | refuse a settings write
issued before the engine is bound |
| `objectstack-ai#10340` | 3 | 4 | `26f3588fb` | commit | decide /meta org scope on
the folded type, not the raw URL spelling |
| `objectstack-ai#10350` | 5 | 3 | `490879ad0` | commit | declare `packageId` on
`publishMetaItem`'s request type, and correct three comments that say
the per-item door names no package |
| `objectstack-ai#10382` | 1 | 4 | `ee09d2119` | commit | derive each live-MySQL
suite's database from its own file, and enforce it repo-wide |
| `objectstack-ai#10485` | 0 | 10 | `35ad101bc` | commit | retire the `themes` carrier
key and ThemeSchema — `app.branding` is the one colour surface |
| `objectstack-ai#10788` | 1 | 1 | `3a7ec2d3b` | commit | a raw-SQL seam that cannot
answer is absent, not empty |
| `objectstack-ai#10789` | 6 | 1 | `38bc74ed1` | commit | a seam that cannot answer is
absent, not empty |
| `objectstack-ai#10842` | 1 | 3 | `f334d662e` | commit | watch(_, since) replays from
sys_metadata_history, and what a bare watch() owes is written down |
| `objectstack-ai#10886` | 3 | 10 | `809e61221` | commit | inventory the
DESTRUCTIVE_CHANGE 409's faces and pin the sole carrier |
| `objectstack-ai#10888` | 5 | 4 | `d806081dd` | commit | render the spec-validation
422 findings clause per write face |
| `objectstack-ai#10895` | 1 | 1 | `a79bd3561` | commit | Publish refusals: declare
failed[].issues + seedApplied.issues, then trim error to a headline |
| `objectstack-ai#11003` | 5 | 1 | `c74aefe63` | commit | thread packageId into both
resolveDraftOrgScopeForPublish probes |
| `objectstack-ai#11014` | 1 | 2 | `2d8b92ff1` | commit | the destructive gate's
reachable type set is `object` alone |
| `objectstack-ai#11015` | 6 | 9 | `82cb6e849` | commit | make the destructive-change
remedy clause face-aware — stop prescribing `?force=true` on the
duplicate door |
| `objectstack-ai#11021` | 3 | 1 | `7d81c889f` | commit | close() terminates watch
iterators instead of emitting a drain event |
| `objectstack-ai#11235` | 6 | 1 | `376c70f98` | commit | derive discovery `version`
instead of the hardcoded `'1.0'` literal |
| `objectstack-ai#11350` | 2 | 0 | `ece4dad31` | commit | re-export the three types
the root entry's own inferred types mention |
| `objectstack-ai#11674` | 20 | 12 | `9a884c6e4` + `1cba33f16` | commit | seed pass 2
writes back by the internal id captured at insert time, healing keyless
datasets / warn at load time when a seed defers a required column, and
document the ordering constraint at the four pointer-pair sites |
| `objectstack-ai#12144` | 1 | 0 | `3a04b0125` | commit | pin the shared identifier
schemas to the storage columns that bound them |
| `objectstack-ai#12176` | 2 | 3 | `311433f6b` | commit | Declare the metadata
item-name grammar in spec and refuse it loudly at the publish door |
| `objectstack-ai#12194` | 6 | 5 | `311433f6b` | commit | Declare the metadata
item-name grammar in spec and refuse it loudly at the publish door |
| `objectstack-ai#12195` | 1 | 0 | `7986d973f` | commit | Retire compound-name
metadata addressing — un-mount the three `:section` arities and unify
SDK URL spelling |
| `objectstack-ai#13185` | 1 | 1 | ADR-0005, design principle 3, its Correction note |
ADR | the field-level patch model retired and deleted whole under
ADR-0049 (executed as `9e0ba21a1`) |
| `objectstack-ai#13186` | 1 | 1 | `9e0ba21a1` | commit | Retire the paper
metadata-customization protocol with its full coupling set |
| `objectstack-ai#13259` | 1 | 1 | `2a75270b1` | commit | honour `hidden` on
getUiView's list priority pass |
| `objectstack-ai#13324` | 4 | 2 | `4cda78c9b` | commit | require a missing-table
error to name the table that was read |
| `objectstack-ai#14390` | 1 | 0 | `9d7f7259f` | commit | `update` answers a driver
unique violation with the `DUPLICATE_RECORD` envelope, on every driver |
| `objectstack-ai#14403` | 1 | 0 | `93d2d679b` | commit | pin the batch-row sink's
disclose/withhold log coherence |
| `objectstack-ai#14409` | 2 | 3 | `3ecb7dc1a` | commit | measure what each dialect
materialises for a datetime JS cannot hold |
| `objectstack-ai#14541` | 1 | 0 | `6d178a408` | commit | consult the bespoke
structured arms before the declared-status passthrough, so both error
doors answer one refusal with one body |
| `objectstack-ai#14683` | 6 | 5 | `96326040f` | commit | apply the allowOrgOverride
read gate inside getMetaItems, so multi-type sweeps are scoped per type
|
| `objectstack-ai#14723` | 3 | 1 | `65846bc46` | commit | a batch/import ROW reports a
unique-constraint refusal as `UNIQUE_VIOLATION`, the route's one wire
spelling |
| `objectstack-ai#14770` | 3 | 3 | `d5cbb44f3` | commit | gate `getMetaItem`'s overlay
read on the metadata registry |
| `objectstack-ai#14907` | 1 | 2 | `e1d4f9e3f` | commit | `getMetaItemLayered` gates
the org read, bound after the canonical fold |
| `objectstack-ai#14938` | 2 | 1 | `c383352cb` | commit | listDrafts emits the
ISO-8601 string updatedAt declares |
| `objectstack-ai#15068` | 1 | 0 | `8744de9e9` | commit | collapse the published-seed
read to the single env-wide read its gate produces |
| `objectstack-ai#16488` | 5 | 1 | `460d4b807` | commit | render a composite
externalId in seed diagnostics instead of its NUL-joined key |
| `objectstack-ai#16657` | 3 | 1 | `5a95b0e93` | commit | read the dialect text out of
`cause` for operator-facing records |
| `objectstack-ai#17167` | 4 | 5 | `dc709b2cf` | commit | the organization probe
records the operator channel as is, empty included |
| `objectstack-ai#19306` | 1 | 1 | `f9e16d856` | commit | a packaged permission set's
DELETE stops reporting a deletion it did not perform |

`objectstack-ai#13185`: the ADR rung is not empty there. ADR-0005's design principle 3
carries a dated Correction that records the 2026-08-29 retirement of the
field-level patch model, so ruling C's first rung applies.
`protocol.ts:8618` already names that record on the same line (「recorded
as a correction inside principle 3 itself」), so there the number is
dropped beside `commit 9e0ba21`.
`get-meta-item-org-read-gate.test.ts:40` now names it (「ADR-0005
principle 3's correction」). For the other 55 numbers, `git grep` over
`docs/adr` and `scripts/adr-anchors` finds no ADR or anchor that records
the decision a site describes. ADR-0094 D5-R and ADR-0086 mention the
`objectstack-ai#6483` rollback, but only as a pointer to it; the narrative and the
ruling are in `ee58392e1`'s message. So ruling C's commit rung applies.

## Wordings to check

Most rewrites swap a tag in place (`(#N)` to `(commit SHA)`, `[#N]` to
`[commit SHA]`, `#N's X` to `commit SHA's X`), the form the landed
stages use. These are the ones that say more than the tag:

- `protocol.ts:5697`: 「(objectstack-ai#9798 declared-but-unenforced, …」 became
「(commit c7655d4 restored a declared-but-unenforced refusal, …」. The
number named an instance of the class, and that commit is the one that
restored it.
- `protocol.ts:8590`: 「the resurrection objectstack-ai#14683 is about」 became 「the
resurrection commit 9632604 closed」.
- `protocol.ts:16640`: 「measured on the objectstack-ai#12176 census before this
landed」 became 「measured before this landed (the census commit 311433f
records)」. The census results are written into that commit's test-file
header.
- `migrations/seed-tenancy-backfill.ts:964`: 「Measured; recorded
separately as objectstack-ai#10159.」 became 「Measured; recorded separately, and
refused since commit 1ec36b7.」 That commit refuses the settings write
that answered "resolved" while persisting nothing.
- `discovery-version.ts:26`: 「considered and declined at objectstack-ai#11235 triage」
became 「considered and declined when the derivation landed (commit
376c70f)」. The triage discussion is not recorded in-repo. The commit
is where the package-local resolver was chosen, and its message records
why: the dependency direction forbids importing runtime's.
- `seed-loader-pointer-pair.test.ts:871`: 「— objectstack-ai#11674's B half, ruled by
triage…」 became 「— commit 1cba33f, the B half, ruled by triage…」.
- `protocol-publish-drafts-package-scope.test.ts:400` is the one changed
line that carried no number. 「option A (recorded on the issue)」 became
「option A (recorded in that commit's message)」, because the issue it
pointed at was the number removed on `:399`, and `c74aefe63`'s message
does record the ruling.
- `sys-metadata-repository.contract.test.ts:187` quotes a deleted line,
「`declaredDivergences: { resumableWatch: 'objectstack-ai#10842' }`」. The quoted value
is elided to 「…」 rather than re-spelled, so the quote stays true.
- `protocol.item-name-grammar.test.ts:6` and `:12`: the number is
dropped and nothing is substituted, since `:4` cites `311433f6b`.
- No line was reflowed, so many are longer than their block's wrap
(`eslint.config.mjs` declares no line-length rule, and reflowing would
move neighbouring lines and every line citation into the file).

## Sites left

- **In `src` comments and `tsup.config.ts`: none.**
- **Test comments: 22 sites carry 13 numbers that answer 404 and that
the census never reads** (they stand only in test files). By the
dispatch's rule they are not this stage's population, so they are
counted and not edited: `objectstack-ai#6287`, `objectstack-ai#10058`, `objectstack-ai#10064` (2), `objectstack-ai#10420`,
`objectstack-ai#10978` (2), `objectstack-ai#11017`, `objectstack-ai#13214`, `objectstack-ai#13244`, `objectstack-ai#13258`, `objectstack-ai#14389`, `objectstack-ai#14431`
(5), `objectstack-ai#14767`, `objectstack-ai#17621` (4). `objectstack-ai#14767` stands on a line this PR rewrote
(`get-meta-item-org-read-gate.test.ts:10`): it is the pull-request
number of `96326040f`'s squash, kept beside the new anchor as it stood.
- **String literals: 63 test-string sites** (describe and `it` titles,
assertion arguments) carry dead numbers: 56 with census-dead numbers
(`objectstack-ai#12194` 6, `objectstack-ai#10789` 5, `objectstack-ai#10886` 5, `objectstack-ai#11014` 4, `objectstack-ai#11674` 4, `objectstack-ai#16488` 4,
and 20 more numbers once to three times) and 7 with `objectstack-ai#17621`. Non-test
source strings carry none. Strings are outside this stage's file
surface.
- **Outside `src`:** the release-owned `CHANGELOG.md` names dead numbers
on 56 sites (45 census-dead, 11 among the 404 reads); left. `README.md`,
`package.json` and `tsconfig.json` name no number; `vitest.config.ts`'s
two are live.

## Mechanical guard: no code token moves

The guard compares, base `e47355be5` against the working tree, over all
54 touched `.ts` files:

- **Reading 1**: the TypeScript parser's leaf nodes, from a
`forEachChild` walk. Comments are trivia there, and JSDoc is never
visited.
- **Reading 2**: the full token stream in parser context, from a
`getChildren` walk. Punctuation and keywords are included and JSDoc
nodes are skipped. String, template and numeric literals are compared in
full on both readings.

Results:

- Real run at the head: 213,265 base tokens, **0 files with a token
change** on either reading (exit 0).
- Comment control (「The derived」 to 「The DERIVED」 on `protocol.ts:13`):
0 files changed (exit 0).
- Positive control, a code identifier (`postureEnforcesWall` to
`postureEnforcesWallX` in `protocol.ts`'s import): DIFFER in both
readings (exit 1).
- Positive control, a string literal (`'dashboard'` to `'dashboardX'` in
`sys-metadata-repository.contract.test.ts`): DIFFER in both readings
(exit 1).
- Positive control, a numeric literal (`BULK_BATCH_SIZE = 200` to `201`
in `seed-loader.ts`): DIFFER in both readings (exit 1).

Every mutation went through `scripts/ablation-replace.mjs` (wrap mode)
under a shell trap that restores by absolute path from `HEAD`. Each
landed: anchor count 1 to 0, blob changed. Each restore was proven equal
to its `HEAD` blob (`5be50ab59075`, `99ef73ef7562`, `41b999ca3ecc`),
with `git diff HEAD` empty and a clean tree afterwards.

## Changeset: `patch` (`dist` measured)

`files[]` is `dist`, `README.md` and `CHANGELOG.md`, and the package is
not private. The dependency closure was built first (`turbo run build
--filter='@objectstack/metadata-protocol^...'`, 12 tasks). Then the
package's own `build` (tsup plus `check-dts-emitted`) ran three times
under the shared verify lock:

- **Leg 1**, at the head: 24 `dist` files hashed. Of the 154 rewritten
non-test lines, 52 appear verbatim in `dist`: 36 from `protocol.ts`, 7
from `sys-metadata-repository.ts`, 5 from `seed-loader.ts` and 4 from
`migrations/seed-tenancy-backfill.ts`. Most are in `index.d.ts` /
`index.d.cts`; two from `seed-tenancy-backfill.ts` are in `index.js` /
`index.cjs`, where esbuild keeps a comment inside an expression.
- **Leg 2**, with the base text put back in the 8 non-test files (each
proven equal to its base blob): `index.d.ts`, `index.d.cts`, `index.js`
and `index.cjs` differ from leg 1, and so do the content-hashed chunk
names, including the seed-loader chunks.
- **Leg 3**, after the proven restore: all 24 files are byte-identical
to leg 1, so the build is deterministic and the difference is the
rewrite.

So the rewrite ships, and
`.changeset/20595-metadata-protocol-provenance-anchors.md` declares a
`patch` for `@objectstack/metadata-protocol`, comment text only, with
the claim's `Clause-②: no` line.

## Gates (head `3265b142f`)

- **Citation judging, as CI runs it:** `node
scripts/check-issue-citations.mjs` exits 0 (「every citation this change
adds resolves」, 19 citations judged across 8 files). `pnpm
check:issue-citations` exits 0 (self-test, 173 cases, 9 batteries).
- **Doc authoring:** `pnpm check:doc-authoring` exits 0 (17,085 spec
strings clean; the sibling-package prose-id baseline holds, no growth).
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` at `3265b142f` (change set
derived from git: 55 paths against merge base `e47355be5`) derived 62
commands. All 62 ran, each with its exit code captured before any pipe,
and all 62 exit 0. `--ran` reports 62 derived, 62 run, 0 NOT-MEASURED (a
derived zero), 0 unrun, and exits 0. A full `turbo run build` over
`./packages/*` and `./packages/*/*` ran first under the shared verify
lock (71 of 71 tasks), so no gate hit an unbuilt workspace.
- **Roster families the derivation lists outside its commands** whose
roster sits in a directory this diff touches: `node
scripts/check-changeset-fixed.mjs`, `pnpm check:authz-resolver` and
`pnpm check:error-code-casing`. Each exits 0.
- **Tests and typecheck, under the verify lock, at `3265b142f`:**
- `pnpm --filter @objectstack/metadata-protocol test`: 200 test files
pass and 3 skip (203); 2,973 tests pass and 19 skip.
- `pnpm --filter @objectstack/metadata-protocol typecheck` exits 0, and
`tsc --noEmit --listFiles` puts all 203 tracked test files in the
program (233 package files).
- **Lint, as a proven narrowing:** eslint with inline config disabled,
over the 54 touched `.ts` files plus `dist/index.js` as the control,
gives 55 results, 0 errors and 1 warning: the control's ignore notice.
Its `--format json` output reports none of the 54 ignored.
`eslint.config.mjs` never enables type-aware linting (its lines 327-328
say so), so a comment edit cannot move the verdict on any untouched
file. The repo-wide `pnpm lint` is CI's run.
- **Control bytes:** `pnpm check:nul-bytes` exits 0, and a raw scan of
the 55 changed files for control bytes finds none.

## Acceptance notes

- **Base.** The branch is on `main` at `e47355be5`. `main` has since
moved five commits (to `62b90d74f`), and `dispatch-gates` flags that as
a stale tree. None of the five touches a file in this diff,
`scripts/check-issue-citations.mjs` or `scripts/pm/dispatch-gates.mjs`.
One edits `protocol.meta-types-degenerate-derivation.test.ts` in this
package, adding a citation beside a live one. The one derivation input
that moved, `scripts/doc-authoring-prose-id.baseline.json`, lost 63
lines, none of them naming this package. No merge was taken; the merge
queue rebuilds on the merged generation.
- **The before census was not bracketed by newest-number reads.** It
enumerated 191 pages at frontier objectstack-ai#21227; the newest number read at
19:21:20Z, before the after run, was objectstack-ai#21228.
- **Comment ids are outside the grammar.** `comment 5299845282` stands
twice in this package (`protocol.ts:22793`,
`protocol.diff-credential-redaction.test.ts:19`) and names a comment on
the deleted `objectstack-ai#8671`, so it no longer resolves either. Neither instrument
reads it, and `75e66fc8e`, now cited beside it, carries the ruling's
text in its message. Left as it is.
- **Wording only:** 「the card」 / 「this card」 stands on 377 comment lines
in 105 files under this package. It carries no number, neither
instrument sees it, and this diff removes no antecedent except the one
repaired at `protocol-publish-drafts-package-scope.test.ts:400`.
- **A first guard reading was void.** The guard's first version read the
token stream with a bare scanner, which has no parser context. It loses
its place at template literals and reported 27 files changed; its
parser-context reading reported 0 on that same run. That bare-scanner
reading was replaced by the `forEachChild` walk above, and every figure
in the guard section is from the replacement.

---
_Generated by [Claude
Code](https://claude.ai/code/session_017xfMoEjKUuSh2xYB8sCozp)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/m tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[0 of #7891] ADR-0091 seed pair crosses the publish door: runtimeTypes: ['seed'] — measured trip-free first slice

2 participants