Skip to content

Commit 48fa7a3

Browse files
docs(platform-objects): re-anchor the dead tracker citations to the commits and ADR that decided them (stage 7 of #20595) (#21477)
Part of #20595 Clause-②: no ## What changed Stage 7 of the `domain:engine` lane of the dead-citation sweep: `packages/platform-objects/**`, comment and docblock prose only, per the claim (`5961679986`). Stages 1 to 6 landed as `a7d9768ec`, `d150c3039`, `4bf4e7e70`, `13a24ece2`, `db0cf2231` and `85986144c`. #20595 stays open: the other half of this lane is the packages this stage does not touch (`core` 40, `metadata-core` 19, `drivers/driver-turso` 14, `drivers/driver-mongodb` 9, `formula` 4, `metadata-fs` 2 on the census after this stage, 88 in all), plus the test-string sites the card carries for a widened stage. Every comment or docblock site in the package that cited a tracker number answering 404 is rewritten in ruling C+D's form C (record `5749154545` on #19123): the ADR when one records the decision, otherwise the commit in this repository's history that made it. That is **42 sites on 42 lines in 28 files, covering 12 numbers**: - **27 census sites** (27 lines, 18 files under `src/`): the whole `allocated-but-absent` population of the gate's own census in this package at the base; - **3 sites outside the census glob, inside the claimed surface**: `scripts/i18n-extract.config.ts:17` (#11671) and `:283` (#11757), two `//` and docblock lines in the package's i18n extraction config, and `tsconfig.scripts.json:1` (#11351), a `//` line in a JSON-with-comments file. These follow stage 1's `tsup.config.ts`, stage 5's `tsconfig.typecheck.json` and stage 6's `tsup.config.ts` precedents; - **12 test-comment sites** (12 lines, 8 test files), which the census defers. They carry 8 numbers: 5 the census itself reads as dead in this package's `src` (#10165, #11374, #11513, #11671, #11757), 1 it reads as dead elsewhere (#8715, in `packages/spec`), and 2 it never judges on this tree because they stand only in test files (#12147, #19249), which a single read settles. No comment-id citation stands in the package (see Census). **Anchors: 11 numbers by commit, 1 by ADR, 0 by words alone.** 12 distinct shas. `#11374` is split by subject: `3954fb7df` (the identity columns' bounds, the route-A rule `platform-keyed-text-bounds.test.ts` once pinned, and the deliberately unbounded `sys_verification.value`, 15 sites) and `4805b5619` (`sys_import_job.created_by`, the route's last column, 1 site). 10 numbers reuse the anchor another lane or stage already used for them (for `#11374`, its 15-site half); 3 anchors were measured here: `cb954f170` (#11351), `74fb2f7a8` (#19249) and `4805b5619` (#11374's one-site half). 0 reused anchors were overridden. Only comments changed. Every file keeps its line count (42 lines out, 42 in, plus the changeset), so no line citation into any of them moves. No code token moves (the guard below). **No citation number is added**: on every changed line the numbers on the new text are a subset of those on the old (the only numbers on `+` lines are #3653, #11701, #12069 and #15989, each already on its line and each answering 200). **A `patch` changeset**: 26 of the 27 rewritten non-test lines are in the published `dist` (the `.d.ts` keeps JSDoc on exported members, and esbuild keeps the field comments inside the object literals), and `dist` is not byte-identical with the base text (see Changeset). ## H0: the package and its size The gate's own `node scripts/check-issue-citations.mjs --census --json` at base `7e7e64b13` (the before run below), `allocated-but-absent` per remaining `domain:engine` package: | package | before | after this stage | |---|---|---| | `core` | 40 | 40 | | `platform-objects` | **27** | **0** | | `metadata-core` | 19 | 19 | | `drivers/driver-turso` | 14 | 14 | | `drivers/driver-mongodb` | 9 | 9 | | `formula` | 4 | 4 | | `metadata-fs` | 2 | 2 | | `metadata-protocol`, `objectql`, `metadata`, `drivers/driver-sql`, `drivers/driver-memory`, `drivers/driver-sqlite-wasm`, `plugins/plugin-pinyin-search` | 0 each | 0 each | The lane total goes 115 to 88. `core` (40) is larger than `platform-objects`; the claim records the PM's stage-order call (two in-flight cards in this batch write `packages/core`), so this stage took `platform-objects`, which the re-measure finds non-empty. ## Census: `platform-objects`, before and after **Instrument (A1).** The gate's own `node scripts/check-issue-citations.mjs --census --json`, read-only and unchanged. The count is its `allocated-but-absent` findings under `packages/platform-objects/`. | reading | tree | board | whole-repo `allocated-but-absent` | sites | lines | files | numbers | |---|---|---|---|---|---|---|---| | before | base `7e7e64b13`, run 21:26:33Z to 21:30:05Z | enumerated, 193 pages, frontier #21468, 19,289 records (newest number read before and after the run: #21468) | 230 | **27** | 27 | 18 | 8 | | after | `e5d9a5d85`, run 21:43:18Z to 21:46:37Z | enumerated, 193 pages, frontier #21470, 19,291 records (newest before and after: #21470) | 203 | **0** | 0 | 0 | 0 | The whole-repo drop is 27, and the two finding sets differ by exactly the 27 rows of this package, removed; none was added. `resolves` (35,315), `resolves-as-pull-request` (2,381) and `cross-repo-unjudged` (1,229) did not move. The head's later commit is the changeset, outside the census surface. **Supplementary instrument, the whole package.** The census reads neither test files nor strings nor files outside `src`. A second reading runs the gate's own exported `extractCitations` (whole-file and comment-prose projections) over every tracked file in the package (158) and classifies each citation with the gate's `classifyCitation` against one board enumerated by the gate's `enumerateBoard` (193 pages, frontier #21468, 19,289 records, 21:31:03Z to 21:34:29Z), the same board for both readings. Every one of the 12 numbers in the population was then read on its own over the issues endpoint (21:35Z): **all 12 answer 404**; the lit controls `#5286` and `#12624` answer 200, and so do the four numbers that stay on changed lines (#3653, #11701, #12069, #15989). | reading | citations | dead | src comment | outside-glob comment | `tsconfig.scripts.json` | test comment | test string | src string | changelog | |---|---|---|---|---|---|---|---|---|---| | before, `7e7e64b13` | 1,410 | **69** | 27 | 2 | 1 | 12 | 5 | 1 | 21 | | after, `e5d9a5d85` | 1,368 | **27** | 0 | 0 | 0 | 0 | 5 | 1 | 21 | The citation count drops by exactly the 42 rewritten sites. The live counts did not move (src comment: 329 resolve, 10 as pull requests, 4 cross-repo; test comment: 273, 18 and 10). A third, raw reading (every `#` followed by 2 to 6 digits, whatever surrounds it) counts 1,418 before and 1,376 after: also a drop of 42. The one `src string` row is not a citation: it is the hex colour `'#475569'` at `src/apps/setup.app.ts:45`, which the grammar's six-digit ceiling admits and the classifier reads as never issued; the census blanks strings and never sees it. **Comment ids.** No comment-id citation stands in the package: every ten-digit run under `packages/platform-objects` (its `CHANGELOG.md` aside) is a translation source hash or a phone-number example inside a string, and an `issuecomment` / `discussion_r` grep finds no line (exit 1). The same ten-digit grep over `packages/metadata-protocol` finds 15 lines (control). ## Per-number table `census` counts census sites, `outside` the three sites outside the census glob, `test` the test-comment sites. Every sha matches exactly one commit (`git rev-parse --disambiguate`, count 1) and is an ancestor of the base `7e7e64b13` (`git merge-base --is-ancestor`, exit 0 for all 12; the clone was unshallowed first, see Acceptance notes). The `+` lines carry exactly these 12 nine-hex spans and no other. Each commit names the number it replaces: 6 in the message and the diff (`3954fb7df`, `4805b5619`, `d6e80b28b`, `2c86fe3ea`, `801296050`, `74fb2f7a8`), 6 in the diff alone (`09b4f4e4e` on 16 added lines, `4d25d22d4` 14, `cb954f170` 9, `945e91a13` 6, `5529a374e` 3, `e170b0ae5` 1); ADR-0104's addendum names #15041 in its Provenance paragraph. `git blame` at the base puts 29 of the 42 sites on their anchor; the other 13 were written by a commit that cites the number as an earlier decision (for example `dccbcec2e` citing #10165's null predicate, `428f9b24a` citing the #11513 posture as precedent, `945e91a13` moving #11374's rule out of a test file), and in each case the anchor is the commit that made the change the sentence credits to the number. `source` says whether another lane or stage already used this anchor for this number (`reused`) or it was measured here (`measured`). | number | census | outside | test | anchor | kind | source | what it decided | |---|---|---|---|---|---|---|---| | `#8676` | 1 | 0 | 0 | `d6e80b28b` | commit | reused (the dogfood lane, `cf684c98e`) | flag `sys_account.password` and `previous_password_hashes` internal | | `#8715` | 0 | 0 | 1 | `2c86fe3ea` | commit | reused (the spec lane, `a51920f5f`) | retire `ApiKeySchema`: `sys_api_key` has one declaration, the platform object | | `#10165` | 1 | 0 | 3 | `801296050` | commit | reused (stages 3 and 4; the plugin-auth lane) | `lifecycle.ttl.onlyWhen` with the canonical null predicate, and the two refines refusing it beside rotation and archive; its message records the maintainer's 2026-08-20 ruling (option A) | | `#11351` | 0 | 1 | 0 | `cb954f170` | commit | measured | put the packages' `scripts/` i18n-extract directories in a tsc program; it wrote this `tsconfig.scripts.json` | | `#11374` | 14 | 0 | 2 | `3954fb7df` (15 sites) | commit | reused (the plugin-audit lane, `4dfff176b`, for the same route-A sentence) | sourced `maxLength` bounds on the unbounded keyed identity columns (route A); its message records the 2026-08-24 ruling and that `sys_verification.value` stays deliberately unbounded; it created the package pin that carried route A's rule | | `#11374` | (1 of the 14) | | | `4805b5619` (1 site) | commit | measured | the route's last column, `sys_import_job.created_by` (「#11374 route A, last column」) | | `#11513` | 2 | 0 | 1 | `e170b0ae5` | commit | reused (the runtime lane, `a186aea99`) | lock package-declared permission sets at the save door and clone to customize; its message records the 2026-08-24 ruling, and its diff carries both the activate/deactivate row-state carve-out and 「an ordinary org-owned set with no upgrade linkage」 | | `#11671` | 5 | 1 | 1 | `09b4f4e4e` | commit | reused (the services lane's pointer `5914040746`; the cli lane) | record which source revision a generated translation leaf was filled from (the squash of PR #12557), correcting the false 「this hole cannot occur there」 note | | `#11757` | 2 | 1 | 2 | `4d25d22d4` | commit | reused (the plugin-auth lane, `4d04b6be3`) | retire the `sys_scim_provider` platform object | | `#12147` | 0 | 0 | 1 | `945e91a13` | commit | reused (the plugin-audit and plugin-security lanes, for the same heading) | the class-level keyed-text-bounds gate over every `*.object.ts`, superseding the per-package pins | | `#14817` | 1 | 0 | 0 | `5529a374e` | commit | reused (the cli lane, `4edb61449`) | put the three shipped platform record pages under an i18n gate; its message records that they author everything under `slots.*` as inline locale maps | | `#15041` | 1 | 0 | 0 | ADR-0104's 2026-09-05 addendum | ADR | reused (stages 3 and 4) | the media family's column holds the bare `sys_file` id; item 2 of its Sequencing is #15989, the card this sentence also names | | `#19249` | 0 | 0 | 1 | `74fb2f7a8` | commit | measured | declare the `sys_user` `set_user_manager` row action (「Part of #19249」); it wrote this test file | No ADR or ruling record decides any of the other 11 numbers: `git grep` over `docs/adr` and `scripts/adr-anchors` finds none of them except #11513, which ADR-0126 names only as precedent (「the landed #11513 posture」, the same dead number) rather than recording its ruling; `e170b0ae5`'s message records that ruling verbatim, so the commit is the anchor. ## Wordings to check Most rewrites swap a tag in place (`[#N]` to `[commit SHA]`, `(#N)` to `(commit SHA)`, `#N's X` to `commit SHA's X`, `in #N` / `before #N` to `in commit SHA` / `before commit SHA`). These say more than the tag: - **Where the number named the defect, not the change**: 「This note used to end with a claim that is FALSE, and #11671 is its counterexample」 became 「… and the defect commit 09b4f4e fixed is its counterexample」 (`source-hash.ts:87`); 「a different defect from #11374's」 became 「a different defect from the one commit 3954fb7 fixed」 (`platform-keyed-text-bounds.test.ts:82`). Stage 6's form. - **A measurement the commit acted on**: 「excluded from this module until #11671 measured that the hole it closes occurs here too」 became 「… until commit 09b4f4e acted on the measurement that the hole it closes occurs here too」 (`source-hash.ts:214`). The measurement itself is the module note's own reading on #11659, which stays where it is; the commit is what brought the generated sections into the module. - **Route A**: 「[#11374 route A]」 became 「[commit 4805b56, route A]」 (`sys-import-job.object.ts:95`), the plugin-audit and plugin-security lanes' spelling for the same tag. - **Slash pair**: 「[#11374/#11701]」 became 「[commit 3954fb7 and #11701]」 (`sys-verification.object.ts:107`). `3954fb7df`'s message is where `value` was left deliberately unbounded; #11701 is live and stays. - **Posture and carve-out** (`sys-metadata-activation.object.ts:27`, `:40`, `sys-metadata-activation.object.test.ts:63`): 「The #11513 deactivation carve-out」 became 「The deactivation carve-out of commit e170b0a」, and 「the landed #11513 posture」 became 「the landed posture of commit e170b0a」 (twice), stage 6's 「landed pin of commit」 form. - **The ruling on #15041**: 「(#15989, the ruling on #15041 step 2)」 became 「(#15989, step 2 of ADR-0104's 2026-09-05 addendum)」 (`migration-flag.ts:235`), stage 4's wording for the same step. - **A docblock title**: 「#19249 — the `set_user_manager` row action …」 became 「Commit 74fb2f7 — the `set_user_manager` row action …」 (`sys-user-set-manager-action.test.ts:4`), capitalised because it opens the block. - **Written the day before the retirement landed**: `sys-scim-connection-credential.object.ts:18` and `:19` read 「(which retires under #11757)」; `366f89576` wrote them on 2026-08-27 and `4d25d22d4` retired the object on 2026-08-28. Only `:19` carries the number, so only it changed: 「(which retires under commit 4d25d22)」. The commit did retire it, so the sentence credits it with nothing it did not do; the present tense on `:18` is left, because that line carries no number. - **Rule lines**: `sys-api-key-single-declaration.test.ts:7` and `sys-session-lifecycle.test.ts:58` are decorated section rules. The tag swap makes them 11 and 10 characters longer; the trailing dashes were not trimmed, so the change on each line is the citation alone. - No line was reflowed, so some are longer than their block's wrap (`eslint.config.mjs` declares no line-length rule, and a reflow would move neighbouring lines and every line citation into the file). No line without a number was changed. ## Sites left - **In comments (src, test, outside the glob): none.** - **String literals: 5 test-string sites, 3 numbers, 3 files** (`describe` and `it` titles, assertion arguments): `#8715` 2 (`sys-api-key-single-declaration.test.ts:23`, `:51`), `#19249` 2 (`sys-user-set-manager-action.test.ts:76`, `:141`), `#10165` 1 (`sys-session-lifecycle.test.ts:60`). Every one of the 3 is in this stage's table. Strings are outside this stage's surface. Non-test strings cite none (the hex colour above is not a citation). - **Files the claim excludes**: the ten `*.generated.ts` files carry no citation at all at the base, and `object-lifecycle-panel-echo-decisions.test.ts` carries 22, none dead, so nothing is carried from them. - **Outside `src`:** the release-owned `CHANGELOG.md` names dead numbers on 21 sites (16 numbers); left. `package.json`, `tsconfig.json`, `tsconfig.test.json`, `test-typecheck-debt.json` and `LICENSE` cite no dead number. ## Mechanical guard: no code token moves The guard (stages 2 to 6's) compares base `7e7e64b13` against the tree at `e5d9a5d85` over all 28 touched files, with TypeScript 6.0.3; `tsconfig.scripts.json` is parsed with `ts.parseJsonText`: - **Reading 1**: the parser's leaf nodes, from a `forEachChild` walk. Comments are trivia there, and JSDoc is never visited. A leaf that is not itself a token is re-scanned with trivia skipped. - **Reading 2**: the full token stream in parser context, from a `getChildren` walk, JSDoc nodes skipped. String, template and numeric literals are compared in full on both readings. Results: - Real run: 21,090 base tokens, **0 files with a token change** (exit 0). - Comment control (「Upstream hard cap」 to 「Upstream HARD cap」, `sys-device-code.object.ts`): 0 files changed (exit 0). - Positive control, an identifier (`HAND_AUTHORED_SECTIONS` to `HAND_AUTHORED_SECTIONSX`, `source-hash.ts`): DIFFER on both readings (exit 1). - Positive control, a string literal (`'Provider ID'` to `'Provider IDX'`, `sys-account.object.ts`): DIFFER on both readings (exit 1). - Positive control, a numeric literal (`maxLength: 64` to `65`, `sys-api-key.object.ts`): DIFFER on both readings (exit 1). - Positive control, a JSON value (`"rootDir": "."` to `"./"`, `tsconfig.scripts.json`): DIFFER on both readings (exit 1). Each mutation went through `scripts/ablation-replace.mjs` (wrap mode, anchor hit 1 to 0, blob changed) under a shell trap that restores by absolute path from `HEAD`. Each restore was proven equal to its `HEAD` blob (`e98db7d7591b`, `67b0e306ca60`, `e5196ab7b57c`, `e889bb45f2ef`, `288105dc3e6b`), with `git diff HEAD` empty and a clean tree afterwards. ## Changeset: `patch` (`dist` measured) `files[]` is `dist`, `README.md` and `CHANGELOG.md`, and the package is not private. In one script under the shared verify lock (VERDICT command-exit 0, held 243s), at `e5d9a5d85`: the workspace was built first (`turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2`, 71 of 71 tasks, 14 cached), then the package's own `build` (tsup plus `check-dts-emitted`) ran three times: - **Leg 1**, the head text: 66 `dist` files hashed. Of the 27 rewritten non-test lines, 26 appear verbatim in `dist`; the one that does not is `identity/index.ts:48`, a comment between two export statements. - **Leg 2**, the base text put back in the 18 non-test touched files (18 of 18 proven equal to their base blob): 18 of the 66 files differ from leg 1 (`index.js` / `.mjs`; `apps/index` `.d.ts` / `.d.mts` / `.js` / `.mjs`; `audit/index.js` / `.mjs`; `identity/index` `.d.ts` / `.d.mts` / `.js` / `.mjs`; `metadata-translations/index.d.ts` / `.d.mts`; `plugin.js` / `.mjs`; `system/index.d.ts` / `.d.mts`), and `scripts/ablation-dist-preflight.mjs` finds the base marker 「and #11671 is its」 in 2 built files (`apps/index.d.ts`, `apps/index.d.mts`; exit 0). - **Leg 3**, after the proven restore (18 of 18 equal to their `HEAD` blob, `git diff HEAD` empty, porcelain empty): all 66 files are byte-identical to leg 1, and the preflight's `--absent` reading exits 0 with a clean tree, so the build is deterministic and the difference is the rewrite. So the rewrite ships, and `.changeset/20595-platform-objects-provenance-anchors.md` declares a `patch` for `@objectstack/platform-objects`, comment text only, with the claim's `Clause-②: no` line. The changeset commit touches no file under `packages/platform-objects`. ## Gates (head `f45b9e60f`) - **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` at `f45b9e60f` (29 paths against merge base `7e7e64b13`, 100 changed lines) derived 63 commands. All 63 ran, each exit code captured before any pipe: 63 exit 0. `--ran` reports 「63 derived, 63 run, 0 NOT-MEASURED, 0 UNRUN」 (a derived zero) and exits 0. The PM's lead derivation (49 commands, tree `713b0fa7`) is a subset: the extra 14 come from the test and `tsconfig` paths (6) and the changeset (8). - **Named readings:** `node scripts/check-issue-citations.mjs` exits 0 (「every citation this change adds resolves (or is a declared cross-repo reference)」: 2 judged across 18 files, both resolve); `pnpm check:issue-citations` exits 0 (self-test, 173 cases, 9 batteries); `pnpm check:doc-authoring` exits 0 (the sibling-package prose-id baseline holds, no growth); `pnpm check:i18n` exits 0 (all bundles in sync); `pnpm check:nul-bytes` exits 0 (9,807 files, no raw control bytes), and a control-byte grep over the 29 changed files finds none (exit 1). - **Tests and typecheck, under the verify lock, at `f45b9e60f`** (VERDICT command-exit 0): `pnpm --filter @objectstack/platform-objects test`: 59 test files pass (59), 949 tests pass (949); `pnpm --filter @objectstack/platform-objects typecheck` (`tsc --noEmit`, `tsc --noEmit -p tsconfig.scripts.json`, then `check:test-typecheck`: 「1 file(s) / 3 error(s) / 2 pinned signature(s) held」) exits 0. `tsc --listFilesOnly` puts all 59 tracked test files in `tsconfig.test.json`'s program, the 18 changed non-test `src` files in `tsconfig.json`'s, and `scripts/i18n-extract.config.ts` in `tsconfig.scripts.json`'s. - **Lint, as a proven narrowing:** eslint with inline config disabled, over the 27 touched `.ts` files plus `dist/index.js` as the control: 28 results, 0 errors and 1 warning, the control's ignore notice; none of the 27 is reported ignored. `tsconfig.scripts.json` alone answers 「File ignored because no matching configuration was supplied」 (not an eslint target). `eslint.config.mjs` never enables type-aware linting (its lines 327 and 328 say so), so a comment edit cannot move the verdict on an untouched file. The repo-wide `pnpm lint` is CI's run. ## Acceptance notes - **Base.** The branch was cut at `7e7e64b13` and not merged with `main`: `main` has since moved two commits (`49524f690`, `packages/rest`; `aa4632235`, `packages/spec`), neither touching `packages/platform-objects`, `check-issue-citations.mjs` or `dispatch-gates.mjs`; the queue rebuilds the branch onto `main`. The net diff against `main` is the 28 rewritten files (+42/−42) and the changeset (+16). - **The clone was shallow** (1,077 commits reachable from the base). It was unshallowed (15,556 commits at the base) before any `blame`, `log -S` or ancestry reading, so every exit 0 above is on full history. - **The PM's reading of #11671** (6 lines in 4 files at `6210f887`) holds on this base: 5 census lines and the one test comment, with `source-hash.ts`'s third site now at `:570` (`:568` in the pointer). A seventh site, `scripts/i18n-extract.config.ts:17`, is outside the census glob and was in no earlier reading; it is in this stage's population. - **The same dead numbers outside this package**, each left to its own carrier: #11351 on the first line of eight other packages' `tsconfig.scripts.json` (`plugin-approvals`, `plugin-audit`, `plugin-security`, `plugin-sharing`, `plugin-webhooks`, `service-messaging`, `service-realtime`, `service-storage`), which the census does not read; `cb954f170` is their anchor too (`service-storage`'s line came later, from `ebb555091`). #8715 in `packages/spec/src/identity/identity.zod.ts:230` (the spec lane's population). #8715 also stands on two published release pages and #11757 on one; release pages are never edited. - **Wording only:** no line without a number was changed. --- _Generated by [Claude Code](https://claude.ai/code/session_01DDZNkDVwPQnevTFcYE47H3)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent cba4297 commit 48fa7a3

29 files changed

Lines changed: 58 additions & 42 deletions
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
'@objectstack/platform-objects': patch
3+
---
4+
5+
Provenance comments in `@objectstack/platform-objects` cite the commits that decided them, not tracker numbers that no longer resolve
6+
7+
Clause-②: no
8+
9+
Docblocks and comments across the package cited issue-tracker numbers that now answer 404 on GitHub.
10+
Each now cites the commit in this repository's history that made the decision it describes, except one
11+
that cites ADR-0104's 2026-09-05 addendum, the record of that ruling. Some of these docblocks sit on
12+
exported members, so the reworded text appears in the published declaration files (`apps`, `identity`,
13+
`metadata-translations` and `system` `index.d.ts` / `index.d.mts`), and the field comments esbuild keeps
14+
appear in the JavaScript output (`index`, `apps`, `audit`, `identity` and `plugin`, `.js` / `.mjs`).
15+
16+
Comment only: no export, type, error code, status, message text or runtime behaviour changes.

‎packages/platform-objects/scripts/i18n-extract.config.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
* --out=packages/platform-objects/src/apps/translations
1515
*
1616
* `--source-hashes` also emits `<locale>.source-hashes.generated.ts` — the
17-
* provenance companion from maintainer ruling #12069 Option A (#11671). Without
17+
* provenance companion from maintainer ruling #12069 Option A (commit 09b4f4e4e). Without
1818
* it, a leaf filled from the source and then left behind when the source was
1919
* revised is indistinguishable BY VALUE from a real translation, so it publishes
2020
* a superseded draft under a green `check:i18n` forever. This package opts in;
@@ -280,7 +280,7 @@ const config: ObjectStackDefinition = defineStack({
280280
SysSsoProvider,
281281
// Stable @better-auth/scim 1.7.x model set + the ObjectStack-owned
282282
// credential store (#3653). The rc.1-era SysScimProvider retired under
283-
// #11757.
283+
// commit 4d25d22d4.
284284
SysScimConnectionBinding,
285285
SysScimConnectionCredential,
286286
SysScimGroup,

‎packages/platform-objects/src/apps/translations/bundle-ownership.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ const OWNED_OBJECTS = new Set([
2727
// identity — external SSO provider (admin-facing, better-auth-managed)
2828
'sys_sso_provider',
2929
// identity — stable @better-auth/scim 1.7.x model set + the ObjectStack-owned
30-
// credential store (#3653; the rc.1-era sys_scim_provider retired under #11757)
30+
// credential store (#3653; the rc.1-era sys_scim_provider retired under commit 4d25d22d4)
3131
'sys_scim_connection_binding', 'sys_scim_connection_credential', 'sys_scim_group',
3232
'sys_scim_group_member', 'sys_scim_identity_tombstone', 'sys_scim_projection_grant',
3333
'sys_scim_subject', 'sys_scim_user',

‎packages/platform-objects/src/apps/translations/en.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -276,7 +276,7 @@ export const en: TranslationData = {
276276
// The platform's own record pages (`@objectstack/platform-objects/pages`,
277277
// contributed by plugin-auth and plugin-security). Their page-level `label`
278278
// is the only key the extractor reaches -- everything else on them is
279-
// authored as an inline locale map under `slots.*` (#14817). English
279+
// authored as an inline locale map under `slots.*` (commit 5529a374e). English
280280
// mirrors the literal in the page metadata, as above.
281281
sys_user_detail: { label: 'User' },
282282
sys_organization_detail: { label: 'Organization' },

‎packages/platform-objects/src/apps/translations/setup.translation.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ import { withSourceFallback } from './source-hash.js';
4646
*
4747
* A leaf with NO recorded hash is legacy-trusted and served verbatim.
4848
*
49-
* ## The generated half joined this seam in #11671
49+
* ## The generated half joined this seam in commit 09b4f4e4e
5050
*
5151
* The fourth argument is the GENERATED provenance table
5252
* (`<locale>.source-hashes.generated.ts`, written by `os i18n extract

‎packages/platform-objects/src/apps/translations/source-hash.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -232,7 +232,7 @@ describe('the shipped bundles', () => {
232232
});
233233

234234
// ───────────────────────────────────────────────────────────────────────────
235-
// The GENERATED half (#11671, maintainer ruling #12069 Option A)
235+
// The GENERATED half (commit 09b4f4e4e, maintainer ruling #12069 Option A)
236236
//
237237
// Same mechanism, different predicate: these leaves got their text by being
238238
// COPIED from the source, so the bytes are evidence and the record only says

‎packages/platform-objects/src/apps/translations/source-hash.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@
8484
*
8585
* ## Scope: BOTH halves — and the correction that put the generated half here
8686
*
87-
* This note used to end with a claim that is FALSE, and #11671 is its
87+
* This note used to end with a claim that is FALSE, and the defect commit 09b4f4e4e fixed is its
8888
* counterexample. It read:
8989
*
9090
* > `objects` and `metadataForms` are GENERATED (`*.generated.ts`) and are
@@ -211,7 +211,7 @@ export const HAND_AUTHORED_SECTIONS = ['apps', 'dashboards', 'pages'] as const;
211211
* judged by {@link findStaleFills}. Their recorded digests live in the
212212
* generated `<locale>.source-hashes.generated.ts`.
213213
*
214-
* These were excluded from this module until #11671 measured that the hole it
214+
* These were excluded from this module until commit 09b4f4e4e acted on the measurement that the hole it
215215
* closes occurs here too — see the module note for the claim that was wrong and
216216
* why it was wrong.
217217
*
@@ -567,7 +567,7 @@ function setDeep(target: Record<string, unknown>, path: string, value: string):
567567
* optional `filledFrom` judges the generated ones ({@link findStaleFills}), over
568568
* whatever sections `filledFrom` itself records.
569569
* Omitting `filledFrom` leaves the generated sections entirely legacy-trusted,
570-
* which is what every caller did before #11671 and is still the honest default
570+
* which is what every caller did before commit 09b4f4e4e and is still the honest default
571571
* for a bundle with no committed `<locale>.source-hashes.generated.ts`.
572572
*
573573
* The input is never mutated. Returns the same reference when nothing is stale,

‎packages/platform-objects/src/audit/sys-import-job.object.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -92,7 +92,7 @@ export const SysImportJob = ObjectSchema.create({
9292
// ── lifecycle timestamps ──
9393
started_at: Field.datetime({ label: 'Started At', required: false, group: 'State' }),
9494
completed_at: Field.datetime({ label: 'Completed At', required: false, group: 'State' }),
95-
// [#11374 route A] The value is `context.userId`, stamped by the rest-server
95+
// [commit 4805b5619, route A] The value is `context.userId`, stamped by the rest-server
9696
// import route (`String(context?.userId ?? context?.user?.id ?? '')` in
9797
// `rest-server.ts`) — i.e. a `sys_user.id`. The bound is derived by
9898
// referenced-column transitivity from three converging in-repo producers,

‎packages/platform-objects/src/identity/index.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ export { SysSsoProvider } from './sys-sso-provider.object.js';
4545
// ── SCIM 2.0 provisioning (@better-auth/scim) ──────────────────────
4646
// The stable 1.7.x model set (#3653) — seven library-managed tables plus the
4747
// ObjectStack-owned credential store the app-owned verifyBearerToken uses.
48-
// (The rc.1-era `SysScimProvider` connection row retired under #11757.)
48+
// (The rc.1-era `SysScimProvider` connection row retired under commit 4d25d22d4.)
4949
export { SysScimConnectionBinding } from './sys-scim-connection-binding.object.js';
5050
export { SysScimConnectionCredential } from './sys-scim-connection-credential.object.js';
5151
export { SysScimGroup } from './sys-scim-group.object.js';

‎packages/platform-objects/src/identity/sys-account.object.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@ export const SysAccount = ObjectSchema.create({
167167
provider_id: Field.text({
168168
label: 'Provider ID',
169169
required: true,
170-
// [#11374] Transitive bound: SSO-registered providers are the widest
170+
// [commit 3954fb7df] Transitive bound: SSO-registered providers are the widest
171171
// producer, and sys_sso_provider.provider_id declares maxLength: 255;
172172
// better-auth's built-in social providers are short fixed slugs.
173173
maxLength: 255,
@@ -177,7 +177,7 @@ export const SysAccount = ObjectSchema.create({
177177
account_id: Field.text({
178178
label: 'Provider Account ID',
179179
required: true,
180-
// [#11374] Bound from the identity-provider norms for the two federated
180+
// [commit 3954fb7df] Bound from the identity-provider norms for the two federated
181181
// shapes this column stores: an OIDC `sub` MUST NOT exceed 255 ASCII
182182
// chars (OIDC Core §2) and a SAML persistent/transient NameID MUST NOT
183183
// exceed 256 chars (SAML Core 2.0 §8.3.7/§8.3.8) — 256 is the wider of
@@ -276,7 +276,7 @@ export const SysAccount = ObjectSchema.create({
276276
required: false,
277277
}),
278278

279-
// [#8676] `internal: true` — never returned on the generic data path.
279+
// [commit d6e80b28b] `internal: true` — never returned on the generic data path.
280280
// Both columns below are one-way password hashes (ADR-0100's third
281281
// channel), and BOTH serialized on `/api/v1/data/sys_account` before this
282282
// flag: to an admin for every user's row, and to a member for their own

0 commit comments

Comments
 (0)