Skip to content

Commit a387354

Browse files
fix(spec): the protocol 17 → 18 conversion summaries state each decision in words instead of a tracker number (stage 5) (#21568)
Part of #20749 Clause-②: no Stage 5 of the `domain:spec` lane's share of the runtime-string burn-down (ruling `5902360492`, form D): the rest of class (b), the protocol 17 → 18 conversion summaries in `packages/spec/src/conversions/registry.ts`. Every rewritten summary now states in words what the cited decision was, or drops a citation its sentence already explained. Text only. ## What changed - **35 ADR-0087 conversion summaries** (40 tracker ids, 34 distinct cards): every toMajor-18 summary that carried an id, from `field-malformed-scale-precision-removed` to `flow-decision-mode-inclusive-explicit`. A summary is what `os migrate meta --json` reports under `specChanges` (its chain already runs to protocol 18, `CHAIN_TERMINUS_MAJOR`), and it becomes the upgrade guide's "Change" column and the `to` text of `spec-changes.json`'s `converted[]` once protocol 18 ships, so an author upgrading metadata reads it. - One `@objectstack/spec` **patch** changeset, `Clause-②: no` (message text only). - **No generated file changes** (A2 below): no generator projects a toMajor-18 summary today. ## Census at the base (A1) Stage 4's instrument (`convtable.cjs`, byte-identical copy, md5 `9b7539067ffc38598172c692de637db5`) at base `e901c27449` (the worktree before any edit): 127 conversions, **35 summaries with ids, 40 id occurrences, 34 distinct cards** — stage 4's split unchanged. The toMajor-18 conversion that PR #21547 added carries no id. Under the ~60-card bar, so one stage. The stage-3 census re-run at the same base agrees (class b: 35 messages / 40 ids; nothing else in class b). | file:line (base) | id | conversion | |---|---|---| | `registry.ts:6551` | #8321 | `field-malformed-scale-precision-removed` | | `registry.ts:6659` | #8762 | `record-chatter-position-vocabulary` | | `registry.ts:6777` | #9198 | `element-input-target-variable-removed` | | `registry.ts:7024` | #9220 | `element-filter-removed` | | `registry.ts:7177` | #9249 | `element-form-removed` | | `registry.ts:7356` | #15178 | `translation-per-app-settings-removed` | | `registry.ts:7356` | #19620 | `translation-per-app-settings-removed` | | `registry.ts:7610` | #9249 | `translation-component-submit-label-removed` | | `registry.ts:7782` | #3951 | `field-column-lists-canonicalized` | | `registry.ts:7783` | #9227 | `field-column-lists-canonicalized` | | `registry.ts:7909` | #10414 | `metric-filters-removed` | | `registry.ts:8104` | #17296 | `cube-sub-day-granularities-removed` | | `registry.ts:8237` | #18612 | `cube-join-sql-and-relationship-removed` | | `registry.ts:8502` | #10054 | `record-highlights-field-icon-removed` | | `registry.ts:8759` | #11027 | `page-component-responsive-removed` | | `registry.ts:8860` | #11805 | `object-grid-default-sort-removed` | | `registry.ts:9047` | #21445 | `object-grid-resizable-columns-removed` | | `registry.ts:9250` | #17260 | `object-kanban-quick-add-removed` | | `registry.ts:9634` | #12497 | `permission-allow-restore-purge-removed` | | `registry.ts:9637` | #1883 | `permission-allow-restore-purge-removed` | | `registry.ts:9954` | #6837 | `field-reference-to-alias` | | `registry.ts:10372` | #14478 | `hook-timeout-to-timeout-ms` | | `registry.ts:10413` | #14478 | `job-timeout-to-timeout-ms` | | `registry.ts:11017` | #14478 | `api-endpoint-cache-ttl-to-cache-ttl-seconds` | | `registry.ts:11086` | #14478 | `dashboard-refresh-interval-to-refresh-interval-seconds` | | `registry.ts:11447` | #14478 | `memory-persistence-auto-save-interval-to-ms` | | `registry.ts:11671` | #14478 | `turso-config-timeout-to-timeout-ms` | | `registry.ts:11761` | #17063 | `view-page-mount-removed` | | `registry.ts:11866` | #17053 | `list-view-sort-string-clause-to-array` | | `registry.ts:11868` | #8221 | `list-view-sort-string-clause-to-array` | | `registry.ts:12366` | #19054 | `object-tenancy-organization-field-removed` | | `registry.ts:12476` | #20085 | `view-item-owner-hidden-removed` | | `registry.ts:12620` | #20230 | `view-overlay-owner-hidden-removed` | | `registry.ts:13214` | #17321 | `page-component-filter-record-to-rule-array` | | `registry.ts:13214` | #6206 | `page-component-filter-record-to-rule-array` | | `registry.ts:13463` | #20161 | `report-joined-chart-removed` | | `registry.ts:13728` | #20221 | `form-layout-inline-grid-to-vertical` | | `registry.ts:13884` | #19992 | `currency-config-precision-removed` | | `registry.ts:13988` | #20321 | `permission-rls-tags-removed` | | `registry.ts:14128` | #15429 | `flow-decision-mode-inclusive-explicit` | ## Projections (A2) Neither generator projects a toMajor-18 summary at this base. `build-spec-changes.ts` and `build-upgrade-guide.ts` both loop `major` from `MIGRATION_SUPPORT_FLOOR + 1` to `PROTOCOL_MAJOR`, which are 16 and 17 here (`PROTOCOL_VERSION = '17.0.0'`), so `spec-changes.json` carries one `perMajor` record (16 → 17) and the guide one "Protocol 16 → 17" table. `check:generated` reads all 15 artifacts up to date on this head with no regeneration, so no generated file is in the diff. Both projections will pick these summaries up when protocol 18 ships. ## Delivered: each site, the decision read, the new words (A3) Every cited card was read through REST with all its comments (30 objectstack cards, objectui#3951, #6206, #6837, #8221). The record column names the comment the decision was read from. Where a summary already said why, the citation is dropped and the sentence kept; where an `(#N, ADR-0049 — …)` opener cited both, the card number goes and the ADR stays, as stage 4 did. In the `cube-join-sql-and-relationship-removed` row, `ALIAS` stands for the angle-bracket placeholder in the source. | conversion (head line) | cited | decision as read (record) | summary now reads | |---|---|---|---| | `field-malformed-scale-precision-removed` (:6550) | #8321 | refuse a malformed scale/precision at the producer (z.number().int().min(0)); a stored malformed value takes the D2 strip so the row stays loadable; citation dropped, the sentence already said it (body + ACCEPT 5296942541) | malformed field 'scale'/'precision' declarations (non-integer or negative) are removed — they were silently unenforced; the schema now refuses them at authoring | | `record-chatter-position-vocabulary` (:6658) | #8762 | the row's vocabulary converges on the renderer's bottom/right/left: one vocabulary, no mapping layer; the three old spellings take a conversion (ruling 5299771841) | record:chatter / record:discussion 'position' respelled to the renderer's vocabulary — 'sidebar' → 'right', 'inline' → 'bottom', 'drawer' → 'right' (one vocabulary, the renderer's, rather than a mapping layer between two: the renderer compares only bottom/right/left, and the old set fell through every branch) | | `element-input-target-variable-removed` (:6778) | #9198 | ADR-0049 enforce-or-remove: verdict dead (a declarative hint with zero readers), retired with tombstones and a D2 conversion (ACCEPT 5311252358 (PR body verdict)) | text-input/record-picker component prop 'targetVariable' removed (retired under ADR-0049 enforce-or-remove as a declarative hint nothing read; the live binding resolves from the page variable whose `source` names the component id) | | `element-filter-removed` (:7025) | #9220 | dead at ELEMENT grain (no renderer anywhere; Studio excludes it from the palette), so the whole element retires under ADR-0049, not key by key (verdict 5312176877 + ACCEPT 5312709553) | the whole 'element:filter' element retired (ADR-0049 enforce-or-remove at element grain, not key by key — no renderer for it ever shipped in any repo, so every key was a capability claim nothing kept; list surfaces own their filtering via a view's userFilters / the list filter builder). All six props are stripped; the bare node the conversion leaves is refused by name at the parse, with the prescription to delete the component | | `element-form-removed` (:7179) | #9249 | dead at element grain, the #9220 precedent: the whole element retires; the palette already names object-form as the replacement (dev report 5384430470 (verdict re-taken in the PR body)) | the whole 'element:form' element retired (ADR-0049 enforce-or-remove at element grain, not key by key — no renderer for it ever shipped in any repo, so every key was a capability claim nothing kept; use the object-bound 'object-form' block instead — rendered and designer-publishable). All six props are stripped; the bare node the conversion leaves is refused by name at the parse, with the prescription to delete the component | | `translation-per-app-settings-removed` (:7358) | #15178, #19620 | #15178: the bundle type splits, the platform bundle keeps `settings`, a per-app bundle refuses it (settings is a platform key). #19620 ruling B: `settings` leaves the translation item too, because the file door and the item door are two authoring surfaces of one app metadata type and accept one shape (ruling 5653315643 (#15178); ruling 5770445203 (#19620)) | translation group 'settings' removed from both application-authored faces, the per-app bundle entry and the registered translation item: settings copy belongs to the platform, and the two authoring doors of one application translation type accept one shape. It is keyed by SettingsManifest.namespace and only platform code declares a manifest. A per-app bundle entry could only fill gaps the platform's own bundle left in the one merged served tree, and was overwritten wherever both defined the key; a stored item OVERRODE the platform copy, because the runtime-authored layer is read over the shipped bundles. Overrides now give way to the platform copy, gaps fall back to the manifest literal, and the group stays on the PLATFORM bundle, PlatformTranslationData | | `translation-component-submit-label-removed` (:7613) | #9249 | `element:form` retired whole because no renderer for it ever shipped (dead at element grain), which left `submitLabel` with no carrier (dev report 5384430470) | translation component-copy key 'submitLabel' removed (retired rather than re-anchored — its only declared carrier, 'element:form', retired whole because no renderer for it ever shipped, so the resolver no longer overlays it and a stored string was read by nothing; the live form surface's submit copy is 'object-form''s 'submitText', localized at its own authoring site, and re-anchoring the key there would only have added a second place to translate one word) | | `field-column-lists-canonicalized` (:7787) | objectui#3951, #9227 | objectui#3951: the published spec spelling `name` wins and the grid reader is fixed to read it. #9227: `inlineColumns` gets a strict name-keyed element schema (an unknown key is a named rejection at publish, not a blank cell); `relatedListColumns`, checked in the same pass, takes field-name strings (ruling 5236150020 (objectui#3951); ruling 5315735776 + ACCEPT 5317488979 (#9227)) | inline-grid column entries respelled 'field' → 'name' (the declared spelling wins, and the grid renderer now reads 'name' too) and related-list column objects folded to their child field-name string (both lists were z.any(), so a mis-keyed column published clean and rendered blank cells; inline columns now take a strict name-keyed shape and related-list columns plain field names, so a mis-keyed column is refused at publish) | | `metric-filters-removed` (:7916) | #10414 | the remove leg of enforce-or-remove: zero consumers (measured with a positive control) and a raw-SQL carrier; retire per the playbook; citation dropped, the sentence already said it (triage grading 5363699539) | cube metric key 'filters' removed (ADR-0049 — no strategy ever read it: the authored raw-SQL condition was parsed and dropped, and the query returned the unfiltered aggregate. Filter at query time with `where`, or use an ADR-0021 dataset measure's structured `filter`; a metric's own `sql` is a column reference) | | `cube-sub-day-granularities-removed` (:8111) | #17296 | each of second/minute/hour is residue and removed: no layer outside the enum names them and `queryDateGranularity` cannot advertise them; ADR-0049 prefers removal with no committed roadmap; citation dropped (dev report 5648182389 + landing 5648923185) | cube dimension granularities 'second' / 'minute' / 'hour' removed (ADR-0049 — no backend bucketed them and none could advertise them: `supports.queryDateGranularity` is a record over `DateGranularity`, which declares day, week, month, quarter, year. Offer the coarsest interval that still answers the question) | | `cube-join-sql-and-relationship-removed` (:8244) | #18612 | retire `sql` and `relationship` from CubeJoin: the join is derived from the FK relationship and no author-supplied ON clause executes; the addendum adds the D2 strip for persisted artifacts; citation dropped, the sentence already said it (ruling 5725370783 + addendum 5727426171) | cube join keys 'sql' and 'relationship' removed (ADR-0049 — neither was ever read: both strategies synthesise the ON clause as a foreign-key equality, so an authored join condition was REPLACED under a 200 and a declared cardinality changed no SQL. Keep `joins.ALIAS.name` alone; the record KEY is the foreign-key field on the base object) | | `record-highlights-field-icon-removed` (:8509) | #10054 | option A: measured dead (zero read points, not designer-publishable), so it retires under the ADR-0087 flow; citation dropped (ruling 5364978909) | record:highlights highlight-field key 'icon' removed (ADR-0049 — no render path: the highlight chip has no icon slot, the register hook carries field names only, and the Studio designer publishes the field list as plain strings, so an authored icon was accepted and drawn by nothing) | | `page-component-responsive-removed` (:8766) | #11027 | ruling B: retire `page.components[].responsive` (ADR-0049, wired into no renderer) and repair the texts that redirected authors to it (ruling 5380752244) | page component key 'responsive' removed (ADR-0049 enforce-or-remove — no renderer ever applied per-component breakpoint layout overrides, and the shared ResponsiveConfig shape leaves with its last carrier; use responsiveStyles (ADR-0065) for breakpoint behaviour that IS applied) | | `object-grid-default-sort-removed` (:8868) | #11805 | retire object-grid `defaultSort` (the strict route per the playbook), completing the objectui-side direction ruling at the producer (ruling 5404972152) | object-grid component prop 'defaultSort' removed (retired under ADR-0049 enforce-or-remove as the legacy single-sort second spelling of 'sort', read only when 'sort' was absent; the pair moves to sort: [{ field, order }], the array shape every read path honours) | | `object-grid-resizable-columns-removed` (:9055) | #21445 | `resizable` is canonical and `resizableColumns` retires now as a tombstone naming it: zero writers, so no window (immediate retirement) (triage direction 5958164933) | object-grid component prop 'resizableColumns' removed (the legacy second spelling of 'resizable', read only when 'resizable' was absent, retires at once so 'resizable' is the one spelling; the value moves to 'resizable' when that is absent, and is deleted when it is present) | | `object-kanban-quick-add-removed` (:9258) | #17260 | option B: `quickAdd` leaves `object-kanban` (accepted and dropped there); this repo carries the tombstone half (card body (the objectui ruling it executes, option B) + triage 5620331176) | object-kanban component prop 'quickAdd' removed (retired from the board under ADR-0049 enforce-or-remove — the affordance is gated on a host-supplied 'onQuickAdd' function no producer puts on an object-kanban node, so the key was accepted and dropped; delete the key — object-kanban offers no quick-add control) | | `permission-allow-restore-purge-removed` (:9643) | #12497, #1883 | option B: retire `allowRestore` / `allowPurge`, which gate operations that do not exist; #1883 stays open as the M2 anchor, where undelete/purge ship as feature + RBAC in one batch and the keys return with it (card body (#12497); ruling 5421209848 (#1883)) | object-permission keys 'allowRestore' and 'allowPurge' removed (ADR-0049 — the `restore`/`purge` operations they claimed to gate have never existed, so granting the bits delivered nothing; dispatched destructive lifecycle verbs stay denied fail-closed. The keys return with the M2 lifecycle initiative, which builds undelete and purge together with the permission bits that gate them) | | `field-reference-to-alias` (:9962) | objectui#6837 | ruling C: protocol normalisation belongs to the server and the frontend only executes the protocol; half 1 (this repo) guarantees the serve path carries only `reference`, half 2 deletes objectui's legacy fallback arms (ruling 5475017957 + half-1 pointer 5475055291) | field key 'reference_to' → 'reference' (the legacy objectql runtime dialect for a lookup/master_detail target; normalising to the protocol is the server's job and the renderer only executes the protocol, so stored rows must serve the canonical spelling before objectui deletes its `reference ?? reference_to` fallback arms) | | `hook-timeout-to-timeout-ms` (:10383) | #14478 | ruling B: a duration-shaped number key carries its unit in its name (or a unit-carrying value), every existing offender renamed under an ADR-0087 conversion, no grandfathered baseline (ruling 5518649320 + population ruling 5548763981) | hook key 'timeout' → 'timeoutMs' (a duration key carries its unit in its name, and this one's unit lived only in the description; the value, milliseconds, is unchanged) | | `job-timeout-to-timeout-ms` (:10424) | #14478 | as above (as above) | job key 'timeout' → 'timeoutMs' (a duration key carries its unit in its name, and this one's unit lived only in the description; the value, milliseconds, is unchanged) | | `api-endpoint-cache-ttl-to-cache-ttl-seconds` (:11028) | #14478 | as above (as above) | api endpoint key 'cacheTtl' → 'cacheTtlSeconds' (a duration key carries its unit in its name, and this one's unit lived only in the description; the value, seconds, is unchanged, and the key stays GET-only) | | `dashboard-refresh-interval-to-refresh-interval-seconds` (:11097) | #14478 | as above (as above) | dashboard key 'refreshInterval' → 'refreshIntervalSeconds' (a duration key carries its unit in its name, and this one's unit lived only in the description; the value, seconds, is unchanged) | | `memory-persistence-auto-save-interval-to-ms` (:11458) | #14478 | as above (as above) | memory datasource key 'config.persistence.autoSaveInterval' → 'autoSaveIntervalMs', on both the file and auto arms (a duration key carries its unit in its name, and this one's unit lived only in the description; the value, milliseconds, is unchanged) | | `turso-config-timeout-to-timeout-ms` (:11682) | #14478 | as above (as above) | turso datasource key 'config.timeout' → 'config.timeoutMs' (a duration key carries its unit in its name, and this one's unit lived only in the description and a .meta() title no parse reads; the value, milliseconds, is unchanged) | | `view-page-mount-removed` (:11772) | #17063 | the maintainer chose to retire (「撤」) over finishing the objectui render half or parking it: the `page` member and its mount leave the spec under enforce-or-remove (card body (the maintainer ruling it records)) | list-view type 'page' and its `pageName` binding removed (retired rather than finished: the delegating render half was never built, so a page view fell through to the grid branch and drew an empty table; ADR-0049 enforce-or-remove) | | `list-view-sort-string-clause-to-array` (:11877) | #17053, objectui#8221 | objectui#8221 option B: the legacy string `sort` is retired, one spelling platform-wide, the array. #17053: the spec slot that produces those documents stops accepting the string objectui now refuses (triage 5620223775 (#17053); ruling 5567944420 (objectui#8221)) | the bare string list-view `sort` clause becomes the `{ field, order }[]` array (one sort orthography platform-wide, the array: objectui already refuses the string, so the schema stops minting documents its own consumer refuses) | | `object-tenancy-organization-field-removed` (:12377) | #19054 | take `organizationField` off the authorable surface; its one real use stays a platform-internal fact; citation dropped, the sentence already said it (card body (the maintainer ruling it records)) | object `tenancy.organizationField` removed (ADR-0049 — the stamp-only column declaration was authorable by every application and declared exactly once in the whole protocol, on the platform's own credential table; the divergence moves to a platform-internal table in @objectstack/metadata-core and stops being a knob) | | `view-item-owner-hidden-removed` (:12487) | #20085 | retire both keys (ADR-0049 enforce-or-remove, zero pull) via the retirement playbook; citation dropped (triage direction 5826969296) | view item keys 'owner'/'hidden' removed (ADR-0049 — declared on the view item record and stored verbatim, read by nothing: no view switcher ever filtered on `hidden`, and no per-user scope ever read `owner`, so a view marked as one user's was listed for everyone) | | `view-overlay-owner-hidden-removed` (:12631) | #20230 | follow #20085's disposition for the same key pair on the overlay door: the same retirement (triage direction 5856621469) | flattened view overlay keys 'owner'/'hidden' removed (ADR-0049 — the view item's pair on the overlay door, retired the same way: declared, accepted by the write door and stored verbatim, read by nothing, so a `hidden: true` overlay hid no view and an `owner` scoped none) | | `page-component-filter-record-to-rule-array` (:13220) | objectui#6206, #17321 | objectui#6206 option B: one filter orthography platform-wide, the rule array. #17321 ruling B: a partial D2 conversion of what maps losslessly; combinator-carrying rows pass through untouched and are named as a TODO (flattening would silently change what a page selects) (ruling 5406409590 (objectui#6206); ruling 5644018752 (#17321)) | a record-form or single-level AST filter at a converged rule-array door becomes the `[{ field, operator, value }]` rule array wherever the mapping is lossless (flat keys → `equals` rules, `{ $op: v }` → the mapped operator, AST comparisons → one rule each); a filter carrying `$and` / `$or` / `$not` or any part with no lossless rule spelling is left exactly as stored — reported as a TODO, which `os migrate meta --stored` lists — and is not the form its door declares (one filter orthography platform-wide, the rule array; the migration converts only what maps losslessly and names the rest, because flattening a combinator would silently change what a page selects) | | `report-joined-chart-removed` (:13477) | #20161 | retire, not build block charts: the joined arm refuses a container chart, the block key goes, a non-joined report keeps its live chart; citation dropped (triage direction 5852548444) | a joined report's 'chart' removed from its blocks and refused on the container (ADR-0049 enforce-or-remove: the joined renderer draws each block as a table and never read either, so the chart parsed and nothing was plotted; a non-joined report keeps its live 'chart') | | `form-layout-inline-grid-to-vertical` (:13742) | #20221 | retire the `inline` / `grid` arms: multi-column already exists as `columns` and `inline` is not a record-form layout; citation dropped, the sentence already said it (triage direction 5855767378) | form 'layout' arms 'inline' and 'grid' rewritten to 'vertical' (ADR-0049 — no renderer ever gave either a behaviour of its own: every form presentation folded both to 'vertical'. Multi-column is 'columns', honoured under either layout, and is left untouched) | | `currency-config-precision-removed` (:13898) | #19992 | remove `currencyConfig.precision`: a currency's decimal places are the currency's, not a setting; citation dropped, the sentence already said it (triage 5817146460 (ruling 乙 on #19910 it executes)) | currency field key 'currencyConfig.precision' removed (ADR-0049 — no renderer or runtime ever read it: an amount's decimal places are its currency's ISO 4217 minor unit, derived from the currency itself. Its ISO 4217 contradiction check and the default `2` baked into parse output went with it; the field-level `precision` is a total digit count and is untouched) | | `permission-rls-tags-removed` (:14002) | #20321 | RETIRE by the maintainer's criterion (no mainstream platform has the capability); citation dropped, the sentence already said it (triage verdict 5860425529) | RLS-policy key 'tags' removed (ADR-0049 — nothing ever read a policy's tags and no mainstream platform tags a row-level policy; dropping it changes no access decision) | | `flow-decision-mode-inclusive-explicit` (:14141) | #15429 | align with mainstream engines: an edge-branched decision is exclusive (first match), and taking every true edge must be declared (`mode: 'inclusive'`); the migration writes it explicitly for existing nodes so authored behaviour is unchanged (ruling C narrows that promise to sources and artifacts) (ruling 5793803317; ruling C 5863827385) | edge-branched decision with two or more conditioned out-edges and no `mode`: `mode: 'inclusive'` written explicitly (the traversal became exclusive, first match in declaration order, as mainstream engines treat a decision, and taking every true edge must now be declared; the key keeps the every-true-edge behaviour those nodes had, and the author deletes it where the branches partition) | No site was left in place as unclear; `open_questions` is empty. ## Text only (A4) Stage 3's AST-skeleton plus string-text tool (`skeleton.cjs`, TypeScript 6.0.3; stage 4's copy with only its TypeScript load path changed to this worktree, md5 `3b10ec8a7e6284f19def54d35f001698` → `32b4630d7d0a532ee26239319269fe91`). Leg 1 compares an AST skeleton with every string's text masked (a `+` chain of string operands reads as one string, so re-wrapping is invisible); leg 2 compares the text of every string group, requiring each changed group to carry a tracker id before and none after, and every other group byte-identical. - `registry.ts`, base `e901c27449` vs the committed copy at `9c1d040145`: **1 of 1 SAME**, exit 0 — 62656 tokens both sides, 4955 string groups, 35 changed, every changed group carried an id before and carries none after; parse diagnostics 0/0. - Controls on scratch copies of the head file, each mutation counted on disk first (anchor hits 1, replacement present 1, anchor left 0): `renameFlowConfigAliases` renamed → DIFF exit 1; `!==` flipped to `===` → DIFF exit 1; one summary re-split into two `+` operands → SAME, 0 groups changed, exit 0; the `hook.timeout` surface string (never carried an id) changed → skeleton SAME, text leg VIOLATION, exit 1. No repo file was mutated for the controls. - The edits were applied by a script whose every anchor was asserted to hit exactly once, inside its own conversion's summary line span, and verified on disk after the write (36 anchors over 35 conversions). The conversion-table extractor reads 35 summaries changed, `toMajor` / `surface` / declaration unchanged on all 127, and 0 ids left in any summary. ## Pins and quotes (A6) No test asserts a summary, so no pin moves: nothing under `*.test.*` reads `.summary` off a conversion (the only summary reads are `spec-changes.ts` and `build-upgrade-guide.ts`), and every removed id-bearing fragment was searched across the repo. The hits are other files' own prose with their own citations (CHANGELOGs, `migrations/registry.ts` rationale, docblocks, `liveness/*.json` notes, test titles such as `permission.test.ts:278`, docs prose in `content/docs/permissions/*.mdx`), not quotes of a summary. `content/docs/**`: no quote of a changed summary. `skills/**`: none. ## Verification All builds and tests through `scripts/pm/os-verify-lock.sh` (slot `issue-20749-s5`), each `VERDICT command-exit 0`: - `pnpm --filter @objectstack/spec build`, then `check:generated` on the merged head `9a35e049e5`: "✓ All 15 generated artifacts are up to date". - The package `test` script (`vitest run --project local --maxWorkers=2`) on `9a35e049e5`: "Test Files 605 passed (605) / Tests 17904 passed | 1 todo (17905)". - `test:repo`: the 15 repo-project files that read the conversion registry, `spec-changes` or the guide, "Test Files 15 passed (15) / Tests 221 passed (221)". NOT MEASURED: `scripts/build-schemas-check-mode.test.ts` (88 cases at about 7 s each, over the foreground cap; it reads only conversion surfaces, which the proof shows unchanged) and the remaining repo-project files; reason: wall clock on a shared box. CI runs them. - `pnpm --filter @objectstack/spec run typecheck` on `9a35e049e5`: exit 0; "check:test-typecheck: OK — 52 file(s) / 246 error(s) / 135 pinned signature(s) held". - `pnpm turbo run build --concurrency=2 --filter=./packages/* --filter=./packages/*/*`: "Tasks: 71 successful, 71 total", for the gates that read built packages. - Gates: `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands` (no paths) at `9a35e049e5` derives 79 commands; each ran with its exit code written to disk before any pipe. Three first exited 3 (PREREQUISITE NOT MET: `check:doc-formula-expressions`, `check:dual-build-cjs-loads`, `check:lean-entry-closure` need built packages) and exit 0 after the build; the dist-reading gates were re-run after it too. `--ran`: "✓ dispatch-gates --ran: 79 derived famil(ies) accounted for — 79 run, 0 NOT-MEASURED". - `pnpm check:doc-authoring` (self-test and run): exit 0, "17323 customer-facing string(s) across 1250 spec sources clean"; the sibling-package ledger holds its baseline (`packages/spec` sits outside it, so no ledger change). `pnpm check:nul-bytes`: exit 0, "no raw ASCII control bytes". - Changeset gates with this body as the `--event` payload: `check-changeset-no-major.mjs --base origin/main --event` exit 0 ("✓ LEVEL AXIS: this PR declares clause-② `no`", declaration line `Clause-②: no`); `check-partof-closing-keyword.mjs` with `PR_BODY` exit 0 ("no Part-of/closing-keyword contradiction"); `check-adr-0087-registration.mjs --base origin/main` exit 0 ("adds no declared-breaking changeset (1 non-breaking changeset(s) seen)"); `check-empty-changeset.mjs --base origin/main` exit 0; `check-changeset-fixed.mjs` exit 0. - ESLint, a proven narrowing: `eslint --no-inline-config --format json` over the one changed TS file reads 1 file, 0 errors, 0 warnings; the population is read from ESLint's own config (`calculateConfigForFile` resolves it, `isPathIgnored` false); invariance: `eslint.config.mjs` enables no type-aware linting (`parserOptions.project` / `projectService` null for this file, its header at :327-328 says so), so a string-text edit cannot move an untouched file's verdict. Repo-wide `pnpm lint` is CI's. ## Acceptance notes - `origin/main` was merged once (`9a35e049e5`, five commits: #21539, #21473, #21554, #21556, #21557; spec moved only in `contracts/approval-service.ts` TSDoc); spec rebuilt, `check:generated`, the spec test project, typecheck and the gate union re-ran on the merged head. No os-regen deferral was recorded. - Hot file: no open PR touches `conversions/registry.ts`, `spec-changes.json` or the upgrade guide (all nine open PRs' file lists read just before opening this one). - Census after this PR (stage 3's instrument at `9a35e049e5`): non-test 160 → 125 messages, 358 → 318 ids; class (b) is empty. Left for the later stages: class (c) conformance-case notes 58 messages / 68 ids (the `#5322` selector and the `#8934` name pin move with their tests), class (f) internal registry rationale 17 / 33, the test strings 1804 / 1920 in 425 files; `migrations/registry.ts` 50 / 217 stays with #20234's stage 11. Word-form hits (an id spelled after "PR", "issue" and the like) stay 6, all outside this diff. - Excluded, untouched: `migrations/registry.ts`, comments anywhere, classes (c) and (f), test strings, the `.mjs` gate scripts. No gate is added or loosened. --- _Generated by [Claude Code](https://claude.ai/code/session_01YDt3PzwfrkuFzUBF89WPmM)_ Co-authored-by: Claude <noreply@anthropic.com>
1 parent e909aa0 commit a387354

2 files changed

Lines changed: 87 additions & 56 deletions

File tree

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
'@objectstack/spec': patch
3+
---
4+
5+
The protocol 17 → 18 conversion summaries no longer cite tracker numbers; each one states the decision behind it in words
6+
7+
Clause-②: no
8+
9+
A conversion's `summary` is the line an author reads when upgrading metadata: `os migrate meta --json` reports it under `specChanges` (its chain already runs to protocol 18), and it becomes the "Change" column of the upgrade guide's protocol 17 → 18 table and the `to` text of `spec-changes.json`'s `converted[]` records once protocol 18 ships. Thirty-five of the protocol-18 summaries pointed at an issue-tracker number for the reason behind a rewrite. The number goes; where the sentence did not already say what was decided, it now does. For example:
10+
11+
- The six duration-key renames (`hook.timeout` → `timeoutMs`, `apis[].cacheTtl` → `cacheTtlSeconds` and the rest) say the rule they follow: a duration key carries its unit in its name.
12+
- `translation-per-app-settings-removed` says why both application doors lose `settings`: settings copy belongs to the platform, and the bundle entry and the translation item are two doors of one type that accept one shape.
13+
- `flow-decision-mode-inclusive-explicit` says the decision node now follows mainstream engines (first match wins) and that taking every true edge must be declared.
14+
- `list-view-sort-string-clause-to-array` and `page-component-filter-record-to-rule-array` say what "one orthography platform-wide" means for each, and why combinator filters are named rather than flattened.
15+
16+
Text only: no conversion's id, surface, protocol step, transform or order changes, and no schema key, shape or default moves. A tool or test that matches the old summary text (for example a tracker-number suffix) needs the new spelling.

0 commit comments

Comments
 (0)