Commit a23be74
fix(dogfood, downstream-contract, plugin-dev): the qa fixtures, conformance ledgers and harness refusals state each decision in words instead of a tracker number (stage 5a) (#21250)
Part of #20752
Clause-②: no
**Stage 5a of the `domain:cli` lane under the maintainer's A / A ruling
(5902360492): every ledgered tracker number in the `packages/qa` strings
outside the authz conformance matrix, plus the `plugin-dev` test title
folded in from the dead-citation sweep.** The matrix file (76
occurrences) is stage 5b, which carries the closing keyword, so this PR
has none. Text only: no expected status, error `code`, verdict, route,
field, export or control flow moves.
## What this does
The dogfood harness refusals (`assertArmed`, the build stand-in, the
showcase security helper, the multi-org remedy), the expression and
search conformance ledgers' summary and enforcement cells, nine fixture
manifests and one permission-set label, and the downstream-contract
manifest sent the reader to a tracker number for the reason behind them.
In form D, as stages 1 to 4 applied it (PR #21172, PR #21188, PR #21219,
PR #21231), the number goes. Where the sentence already said what was
decided, only the citation goes. Where it leaned on the number, it now
says the decision in words.
All 26 ledgered occurrences in the claim's 16 files (claim
`5940325318`), at 25 string sites, plus the one `plugin-dev` `describe`
title the claim adds (not on the ledger). Every cited card was read
first. Three answer 404 or cannot be read here and were read through
their landing commits instead (below).
### Rewritten in words
| Where (head line) | Cited | The text now says | Decision read from |
|---|---|---|---|
| `dogfood/test/armed.ts:136-138` empty-declaration refusal | 8074 |
"...the exact defect class this helper exists to close, a fixture that
passes while the control it measures is not engaged." | card 8074 (an
org-less fixture cannot observe the gated write floor, so a real 403
records as a passing cell; direction 2: a helper that refuses) |
| `dogfood/test/armed.ts:162` DISARMED refusal | 8074 | the bracketed
tracker tag becomes `assertArmed():`, the same lead the
empty-declaration refusal already uses; the rest of the sentence already
said the assertions would pass without testing anything | card 8074 |
| `expression-conformance.ledger.ts:144` `sharing-condition` summary |
1887 | "(ADR-0058 D3: compiled from the authored CEL, a faithful
lowering rather than a divergent hand-written filter)" | card 1887 (the
spec condition was never compiled; enforce or remove) and ADR-0058 D3
(the CEL condition compiles to `criteria_json`, a faithful lowering of
the authored CEL) |
| `expression-conformance.ledger.ts:293` `settings-visibility`
enforcement | 7327 | "The spec DECLARES that same grammar
(`SettingsVisibilityInputSchema`) rather than CEL, so it is refused at
publish/parse too" | card 7327 (narrow the declaration to the grammar
the save-time evaluator implements, measured 1 against 93) |
| `expression-conformance.ledger.ts:303`
`cel-action-param-option-visible` summary | 5016 |
"(params[].options[].visibleWhen, the same per-option key a field's
option list declares)" | card 5016, maintainer ruling B (reuse the field
option vocabulary), landed as commit `f6609e6ae2`; `ui/action.zod.ts`
records the per-key outcome (`visibleWhen` opened) |
| `fixtures/attachments-fixture.ts:140` manifest | 2755 | "...exercising
the non-admin attachment permission matrix: ..." | card 2755 item 2
(dogfood the non-admin attachment permission matrix) |
| `fixtures/comments-fixture.ts:139` manifest | 4630 | "...exercising
the record-level comment permission matrix: ..." | card 4630
(`sys_comment` gains record-level authorization, mirroring attachments)
|
| `fixtures/label-scope-fixture.ts:55` manifest | 3602 | "Deal → vendor
lookup exercising the dimension-label read scope: a vendor the reader
cannot read is shown by raw id, never by name." | card 3602's first
residual (the per-record label read behind a grouped lookup carried no
read scope); the fixture's own header |
| `fixtures/rls-owner-fixture.ts:57` manifest | 1994 | "...exercising
the cross-owner by-id-write invariant: a caller that cannot read a
record must not be able to write it." | PR 1994 (a by-id write must pass
the row-level write filter); stage 4's wording of the same invariant in
`verify --rls` |
| `fixtures/rls-owner-fixture.ts:105` permission-set label | 1994 | `RLS
Fixture Member — owner-scoped reads only (no write policy: the
by-id-write hole shape)` | PR 1994; the fixture header (owner policy on
SELECT only, the hole class's authoring shape) |
| `dogfood/test/showcase-security.ts:66` refusal | 5491 | "...the CLI
wiring these fixtures model cannot be reproduced, and the platform
baseline alone grants a member no object access" | card 5491, maintainer
ruling of 2026-08-07 (the wildcard grant leaves `member_default`; the
baseline is explicit-allow) |
| `downstream-contract/src/stack.ts:19` manifest | 2035 | "Frozen
third-party consumer gating spec backward compatibility: a spec change
that needs this fixture edited to stay green is breaking." | landing
commit `92647c13aa` (the downstream-consumer contract, frozen: a spec
change that requires editing it is breaking), the work done under card
2035; the package README states the same contract |
### Citation only (the sentence already stated the decision)
- `dogfood/test/build-shaped-artifact.ts:192`, `:225`, `:265` (6293,
answers 404): the three refusals already say what a stand-in must do
instead of `JSON.stringify` (fix the walk, never the assertion; a
headless husk is what a plain stringify leaves; a function left in the
artifact would be dropped without a sound). Read from landing commit
`c39a911ae6` (fixtures get the real lowering, and the stand-in throws
naming what went missing).
- `dogfood/test/enterprise-organizations.ts:184` multi-org remedy
(4719): the twin of the `verify` harness remedy that stage 4 rewrote
citation-only. It already says the app's own declaration is what counts
and a transitive reach is not enough. Card 4719 (option 2: the host
declaration decides).
- `expression-conformance.ledger.ts:293` (7310): "Fail-closed since"
plus the card becomes "Fail-closed:"; the sentence goes on to say a
predicate outside the grammar refuses the save. PR 7310.
- `expression-conformance.ledger.ts:319` (objectui card 3067):
"selection-bar bulk action per-record eligibility
(bulkActionDefs[].visible)". This session has no read access to
`objectstack-ai/objectui` (403) and the dispatch forbids attaching it,
so the decision was read from this repository's record:
`ui/bulk-action.zod.ts`'s `visible` describe (evaluated once per
selected record; the button is offered when at least one passes) and the
row's own enforcement cell, both unchanged.
- `expression-conformance.ledger.ts:343`, `:350` (objectui card 2614):
the two summaries already say "per-record visibility" and "per-record
disabling" of the built-in row Edit/Delete. Read from this repository's
landing commit `627f225f2c` (`userActions.edit/delete` accept per-record
CEL predicates).
- `fixtures/email-template-materialization-fixture.ts:59` (4509) and
`fixtures/webhook-materialization-fixture.ts:55` (3461): each already
says the stack entries materialize into the rows the runtime reads;
`ADR-0054` stays.
- `fixtures/flow-durable-suspend-fixture.ts:101` (4470): already says
the flow suspends, persists and resumes after a cold boot.
- `fixtures/flow-function-effect-fixture.ts:69` (4396): already says the
declared effect reaches the run summary.
- `fixtures/flow-runas-fixture.ts:125` (1888): already says `flow.runAs`
identity is enforced.
- `dogfood/test/search-conformance.ledger.ts:49` (4254): already says a
name outside the set is a 400 at the REST ingress, not silently dropped.
- `plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts:121`
`describe` title (10036, answers 404; the fold site from the
dead-citation sweep, ACCEPT `5939681859`): the bracketed tag goes; the
title already says the warning must fire when `SecurityPlugin.start()`
bailed. Read from landing commit `7552e03375` (the warning probes the
published `security` service in `start()`).
## Text only, proven on the AST
A scratch script (not committed) parses each changed TypeScript file at
BASE `a7d9768ecd` and at `75e33f4c45` (the stage commit; the later merge
of `origin/main` touches none of these files), blanks every string value
and template span, and compares the remaining node sequence (kinds,
identifiers, numerals). Result: identical skeleton in all 17 files,
equal node and string-value counts per file, and 28 changed string
values, all prose: the 26 sites above plus two neighbouring literals of
the `armed.ts:136-138` refusal, re-wrapped so the message keeps its four
literals.
## The ledger
`node scripts/check-doc-authoring.mjs --census-ledger`, written to a
scratch file first so its no-growth check reads the committed baseline,
then installed:
| | occurrences | (file, id) pairs | files |
|---|--:|--:|--:|
| the 16 stage rows before | 26 | 21 | 16 |
| the 16 stage rows after | 0 | 0 | 0 |
| `authz-conformance.matrix.ts` (stage 5b) | 76 | 46 | 1 |
| whole ledger before (`a7d9768ecd`) | 385 | 272 | 103 |
| whole ledger after | 359 | 251 | 87 |
53 lines deleted, 0 added; every other row is byte-identical, the matrix
row included. After merging `origin/main` (`ef96c9ede7`) the recomputed
ledger is byte-identical to the committed one. `pnpm
check:doc-authoring`: before "325 pinned site(s) across 103 file(s) ...
no growth, no burn-down unrecorded", after "300 pinned site(s) across 87
file(s) ... no growth, no burn-down unrecorded".
## Pins
No test asserts any of the old strings: every rewritten fragment and
every cited number inside an assertion was searched across the
repository, with no hit outside the sites themselves. The two existing
pins that read rewritten messages, `armed.dogfood.test.ts` matching
`this fixture is DISARMED` and `arming declaration is EMPTY`, still
match, and pass. With nothing re-pointed there was no pin to ablate. The
`merge-queue-triage` job-log fixtures under `scripts/fixtures/` quote
the old `describe` title as recorded CI output; they are history and
stay as they are.
The run itself shows one rewritten string live: the multi-org skip line
in the dogfood run now prints "...being reachable as somebody else's
transitive dependency is not enough. Set
OS_TEST_MULTI_ORG_ENABLED=1...".
## What ships
Nothing. `@objectstack/dogfood` and `@objectstack/downstream-contract`
are `private: true`. `@objectstack/plugin-dev` publishes `dist`, and its
built `dist/` holds the new `describe` title 0 times; the control, the
warning's own `NOT enforced` text, is found in `dist/index.js`. So no
changeset, and the PR takes `skip-changeset`.
The downstream-contract fixture is frozen against spec-driven edits (its
README). This edit is prose in the manifest description, made for this
ruling and not to make a spec change pass.
## Verification (head `3efe6499b8`, after merging `origin/main`
`ef96c9ede7`)
Heavy runs went through `scripts/pm/os-verify-lock.sh` (slot
`issue-20752-s5a`); each verdict line reads `VERDICT command-exit 0`.
- Build: `pnpm turbo run build` over the dependency closures of
`@objectstack/dogfood`, `@objectstack/downstream-contract` and
`@objectstack/plugin-dev`, 63/63 tasks, before and after the merge.
- Tests, before and after the merge: `@objectstack/plugin-dev` 9 files /
86 tests passed (the renamed `describe` ran under the verbose reporter
with its 4 tests green); `@objectstack/downstream-contract` 3 / 31
passed; `@objectstack/dogfood`, every test file that imports a changed
module directly (46 files, run in two batches): 45 passed, 1 skipped
(`rls-multitenant`, which needs the enterprise organizations package
this repository does not ship), 388 tests passed, 3 skipped. The full
dogfood suite is CI's `Dogfood Regression Gate`.
- Typecheck: `@objectstack/dogfood` (`tsc --noEmit`; `--listFiles` shows
all 15 changed dogfood files in its program),
`@objectstack/downstream-contract`, and `@objectstack/plugin-dev` (`tsc
--noEmit` plus `check:test-typecheck`, which compiles the test layer:
OK).
- Gates: `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 67 commands; all 67 run
with exit codes recorded; `--ran` reconciliation: "67 derived famil(ies)
accounted for — 67 run, 0 NOT-MEASURED". `check:dual-build-cjs-loads`
first answered PREREQUISITE NOT MET (exit 3, no dist for unrelated
packages); after a full workspace build (72/72 tasks, 71 cached) it
passed, and that rerun is the recorded result.
- Lint: the full `pnpm lint` (`eslint . --no-inline-config`) at
`3efe6499b8`: exit 0, no findings.
## Acceptance notes
- `expression-conformance.ledger.ts:322` is a comment that says the bulk
row "reached the ledger in" one card "not" another, both spelled bare.
The second is objectui's card, and a bare number reads as this
repository's. It is a comment, not on the ledger, so it is untouched
here. Carrier: the dead-citation sweep.
- `packages/qa/downstream-contract/package.json`'s `description` and its
README still cite card 2035, and dogfood test titles and `it` names
still carry tracker numbers. None of these is on the ledger or the
claim. Carrier: the seat, when it stages what remains after 5b.
- Code comments in the 17 files still cite these cards. They are not on
the ledger, and the claim keeps them out of scope.
---
_Generated by [Claude
Code](https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB)_
Co-authored-by: Claude <noreply@anthropic.com>1 parent 4727fcb commit a23be74
18 files changed
Lines changed: 28 additions & 81 deletions
File tree
- packages
- plugins/plugin-dev/src
- qa
- dogfood/test
- fixtures
- downstream-contract/src
- scripts
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
121 | | - | |
| 121 | + | |
122 | 122 | | |
123 | 123 | | |
124 | 124 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
133 | 133 | | |
134 | 134 | | |
135 | 135 | | |
136 | | - | |
137 | | - | |
138 | | - | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
139 | 139 | | |
140 | 140 | | |
141 | 141 | | |
| |||
159 | 159 | | |
160 | 160 | | |
161 | 161 | | |
162 | | - | |
| 162 | + | |
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
189 | 189 | | |
190 | 190 | | |
191 | 191 | | |
192 | | - | |
| 192 | + | |
193 | 193 | | |
194 | 194 | | |
195 | 195 | | |
| |||
222 | 222 | | |
223 | 223 | | |
224 | 224 | | |
225 | | - | |
| 225 | + | |
226 | 226 | | |
227 | 227 | | |
228 | 228 | | |
| |||
262 | 262 | | |
263 | 263 | | |
264 | 264 | | |
265 | | - | |
| 265 | + | |
266 | 266 | | |
267 | 267 | | |
268 | 268 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
181 | 181 | | |
182 | 182 | | |
183 | 183 | | |
184 | | - | |
| 184 | + | |
185 | 185 | | |
186 | 186 | | |
187 | 187 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
141 | 141 | | |
142 | 142 | | |
143 | 143 | | |
144 | | - | |
| 144 | + | |
145 | 145 | | |
146 | 146 | | |
147 | 147 | | |
| |||
290 | 290 | | |
291 | 291 | | |
292 | 292 | | |
293 | | - | |
| 293 | + | |
294 | 294 | | |
295 | 295 | | |
296 | 296 | | |
| |||
300 | 300 | | |
301 | 301 | | |
302 | 302 | | |
303 | | - | |
| 303 | + | |
304 | 304 | | |
305 | 305 | | |
306 | 306 | | |
| |||
316 | 316 | | |
317 | 317 | | |
318 | 318 | | |
319 | | - | |
| 319 | + | |
320 | 320 | | |
321 | 321 | | |
322 | 322 | | |
| |||
340 | 340 | | |
341 | 341 | | |
342 | 342 | | |
343 | | - | |
| 343 | + | |
344 | 344 | | |
345 | 345 | | |
346 | 346 | | |
347 | 347 | | |
348 | 348 | | |
349 | 349 | | |
350 | | - | |
| 350 | + | |
351 | 351 | | |
352 | 352 | | |
353 | 353 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
137 | 137 | | |
138 | 138 | | |
139 | 139 | | |
140 | | - | |
| 140 | + | |
141 | 141 | | |
142 | 142 | | |
143 | 143 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
136 | 136 | | |
137 | 137 | | |
138 | 138 | | |
139 | | - | |
| 139 | + | |
140 | 140 | | |
141 | 141 | | |
142 | 142 | | |
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
| 59 | + | |
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
98 | 98 | | |
99 | 99 | | |
100 | 100 | | |
101 | | - | |
| 101 | + | |
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
69 | | - | |
| 69 | + | |
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
| |||
0 commit comments