Repository navigation
Commit c205b6c
Part of #20595
Clause-②: no
## What changed
Stage 8 of the `domain:engine` lane of the dead-citation sweep:
`packages/core/**`, comment and docblock prose only, per the claim
(`5963404083`). Stages 1 to 7 landed as `a7d9768ec`, `d150c3039`,
`4bf4e7e70`, `13a24ece2`, `db0cf2231`, `85986144c` and `48fa7a381`.
#20595 stays open: the other half of this lane is the packages this
stage does not touch (`metadata-core` 19, `drivers/driver-turso` 14,
`drivers/driver-mongodb` 9, `formula` 4, `metadata-fs` 2 on the census
after this stage, 48 in all), plus the test-string sites the card
carries for a widened stage.
Every comment or docblock site in the package that cited a tracker
number answering 404, and the one comment-id citation that answers 404,
is rewritten in ruling C+D's form C (record `5749154545` on #19123), in
the form #20234 applies it to the spec tree: the ADR when one records
the decision, otherwise the commit in this repository's history that
made it, otherwise the fact in words. That is **81 sites on 80 lines in
34 files, covering 24 numbers and 1 comment id**:
- **40 census sites** (39 lines, 17 files under `src/`): the whole
`allocated-but-absent` population of the gate's own census in this
package at the base. `plugin-permission-enforcer.ts:119` carries two
numbers on one line;
- **6 sites outside the census glob, inside the claimed surface**:
`vitest.config.ts:21` (#17853, a `//` line), and five `//` lines in
three JSON-with-comments files, `tsconfig.examples.json:1`, `:2` and
`:22` (#14613, #14386 twice), `tsconfig.json:30` and
`tsconfig.test.json:1` (#14613). These follow stage 1's
`tsup.config.ts`, stage 5's `tsconfig.typecheck.json` and stage 7's
`tsconfig.scripts.json` precedents;
- **34 test-comment sites** (34 lines, 13 test files), which the census
defers. They carry 11 numbers: 6 the census itself reads as dead in this
package's `src` (#6216, #8734, #13279, #14919, #16721, #17147), 1 it
reads as dead elsewhere (#17590, at
`packages/spec/src/data/filter.zod.ts:1067`), and 4 it never judges on
this tree because they stand only in test files or outside the census
glob (#10978, #11330, #13179, #14613), which the board and a single read
each settle;
- **1 dead comment-id citation**:
`granted-permissions-not-enforced.pin.test.ts:9` named maintainer ruling
`5486840233`, a comment that answers 404 (see Census).
**Anchors: 22 numbers by commit, 1 by ADR, 1 by words, and the comment
id by ADR; 24 distinct shas.** Two numbers are split by subject:
`#14386` (`7cbe705b0` for the plugin-auth program's widening,
`c49007a7c` for the finding the sentence describes, see Wordings) and
`#17147` (`aaacf1d5c` for the pin and the seam, `65481183b` for the
pin's follow-up). `#11333` and `#17147` share one line. 19 numbers reuse
the anchor another lane or stage already used for them; measured here
are 5 commits (`fd289be45` for #13179, `cc00df2f7` for #14919,
`7cbe705b0` and `c49007a7c` for #14386, `65481183b` for #17147's
follow-up half) and 2 ADR anchors (ADR-0131's 2026-09-17 amendment for
#16682, ADR-0025 §3.7 for the comment id). The plugin-security lane's
`#16682` anchor (`9b9581b11`) was not taken: it is a different subject
(see the table). `#11331` takes words, as the spec lane gave it (see
Wordings).
Only comments changed. Every file keeps its line count (81 lines out, 81
in, plus the changeset), so no line citation into any of them moves. One
changed line carries no number (`plugin-artifact-integrity.ts:12`, see
Wordings). No code token moves (the guard below). **No citation number
is added**: on every changed line the numbers on the new text are a
subset of those on the old (the only numbers on `+` lines are #3984,
#5286, #5881, #6551, #10869, #11974, #16404 twice and #17978, each
already on its line and each answering 200).
**A `patch` changeset**: 21 of the 40 rewritten non-test lines are in
the published `dist` (the `.d.ts` keeps JSDoc on exported members, and
esbuild keeps some comments in the JS), and `dist` is not byte-identical
with the base text (see Changeset).
## H0: the package and its size
The gate's own `node scripts/check-issue-citations.mjs --census --json`
at base `fd96a8473` (the before run below), `allocated-but-absent` per
remaining `domain:engine` package:
| package | before | after this stage |
|---|---|---|
| `core` | **40** | **0** |
| `metadata-core` | 19 | 19 |
| `drivers/driver-turso` | 14 | 14 |
| `drivers/driver-mongodb` | 9 | 9 |
| `formula` | 4 | 4 |
| `metadata-fs` | 2 | 2 |
| `metadata-protocol`, `objectql`, `metadata`, `drivers/driver-sql`,
`drivers/driver-memory`, `drivers/driver-sqlite-wasm`,
`plugins/plugin-pinyin-search`, `platform-objects` | 0 each | 0 each |
The lane total goes 88 to 48. `core` is the largest remaining package
and reads 40, as at stage 7's census (`e5d9a5d85`), so the stage went
ahead.
## Census: `core`, before and after
**Instrument (A1).** The gate's own `node
scripts/check-issue-citations.mjs --census --json`, read-only and
unchanged. The count is its `allocated-but-absent` findings under
`packages/core/`.
| reading | tree | board | whole-repo `allocated-but-absent` | sites |
lines | files | numbers |
|---|---|---|---|---|---|---|---|
| before | base `fd96a8473`, run 00:07:44Z to 00:11:10Z | enumerated,
194 pages, frontier #21494, 19,315 records (newest number read before
and after the run: #21494) | 203 | **40** | 39 | 17 | 17 |
| after | `195aa6bdb`, run 00:27:00Z to 00:30:25Z | enumerated, 194
pages, frontier #21498, 19,319 records (newest #21495 before, #21498
after) | 163 | **0** | 0 | 0 | 0 |
The whole-repo drop is 40, and the two finding sets differ by exactly
the 40 rows of this package, removed; none was added. `resolves`
(35,428), `resolves-as-pull-request` (2,388) and `cross-repo-unjudged`
(1,243) did not move.
The head's later commits are the changeset, one merge of `main`, and one
comment line in `resolve-authz-context.ts` (the ADR re-anchor of `:925`,
which adds and removes no number). The census was run a third time at
the head `a4c483901` (00:50:57Z to 00:54:06Z, 194 pages, frontier
#21504, 19,325 records, newest #21504 before and after): whole-repo 163,
`core` 0, and its `allocated-but-absent` finding set is identical to the
after run's (0 removed, 0 added). Its `resolves` reads 35,441, 13 more
than above, from the merged `main` commits outside this package.
**Supplementary instrument, the whole package.** The census reads
neither test files nor strings nor files outside `src`. A second reading
runs the gate's own exported `extractCitations` (whole-file and
comment-prose projections) over every tracked file in the package (175)
and classifies each citation with the gate's `classifyCitation` against
one board enumerated by the gate's `enumerateBoard` (194 pages, frontier
#21494, 19,315 records, 00:11:24Z to 00:14:37Z), the same board for both
readings. Every one of the 24 numbers in the population was then read on
its own over the issues endpoint (00:19:57Z): **all 24 answer 404**; the
lit controls `#5286` and `#12624` answer 200, and so do the numbers that
stay on changed lines (#3984, #5881, #6551, #10869, #11974, #16404,
#17978).
| reading | citations | dead | src comment | test comment |
`vitest.config.ts` comment | other files (`tsconfig*.json` / rest) |
test string | changelog |
|---|---|---|---|---|---|---|---|---|
| before, `fd96a8473` | 2,048 | **125** | 40 | 34 | 1 | 5 / 2 | 22 | 21
|
| after, `195aa6bdb` | 1,968 | **45** | 0 | 0 | 0 | 0 / 2 | 22 | 21 |
The citation count drops by exactly the 80 rewritten tracker-number
sites (the 81st site is the comment id, which the citation grammar does
not read). The live counts did not move (src comment: 755 resolve, 19 as
pull requests, 3 cross-repo; test comment: 382, 12 and 4). A third, raw
reading (every `#` followed by 2 to 6 digits, whatever surrounds it)
counts 2,069 before and 1,989 after: also a drop of 80. The two `other
files` rows left are a JSON string and a markdown line (see Sites left).
**Comment ids.** Every ten-digit run under `packages/core` (its
`CHANGELOG.md` aside) was read. Three distinct comment ids are cited, on
four lines: `5257880748` (`auth-gate.test.ts:195`, inside a verbatim
quotation of a ruling) and `5394453215` (`platform-admin.ts:5`,
`resolve-authz-context.ts:1076`) answer 200; `5486840233`
(`granted-permissions-not-enforced.pin.test.ts:9`) answers 404 and is in
this stage's population; the control `5963404083` (the claim) answers
200. The other runs are decimals, epochs and fixtures in tests, and two
CI run ids in `kernel.ts:33` and `:34`, which are not citations of this
tracker. An `issuecomment` / `discussion_r` grep finds no line (exit 1).
After the rewrite, `5486840233` stands in 0 files under `packages/core`.
## Per-number table
`census` counts census sites, `outside` the six sites outside the census
glob, `test` the test-comment sites. Every sha matches exactly one
commit (`git rev-parse --disambiguate`, count 1) and is an ancestor of
the base `fd96a8473` (`git merge-base --is-ancestor`, exit 0 for all 24;
the clone is not shallow). The `+` lines carry exactly these 24 nine-hex
spans as new ones (the one other span on a `+` line, `abc4b83ce`, was
already on its line). Each commit names the number it replaces, in its
message, its diff or both, except `c49007a7c`, whose message names
`#10869` (see Wordings); each ADR anchor names its number or id in the
cited section. `git blame` at the base puts 52 of the 76 commit-anchored
lines on their anchor; the other 24 were written by a commit that cites
the number as an earlier decision (for example `07150b33a` citing
#16721's convergence, `baf974527` citing #16649's registration,
`82da264e1` citing #6216's closed field set), and in each case the
anchor is the commit that made the change the sentence credits to the
number. `source` says whether another lane or stage already used this
anchor for this number (`reused`) or it was measured here (`measured`).
| number | census | outside | test | anchor | kind | source | what it
decided |
|---|---|---|---|---|---|---|---|
| `#6206` | 2 | 0 | 0 | `8e13ca876` | commit | reused (the rest,
plugin-security and plugin-sharing lanes) | share-link enforcement takes
the whole authz envelope, so `accessible_org_ids` is no longer dropped |
| `#6216` | 8 | 0 | 8 | `f586f1a89` | commit | reused (the rest,
runtime, mcp, spec, plugin-hono-server and plugin-security lanes) | one
ExecutionContext assembler with two named anonymous entries; the frozen
parity pins and the closed entry field set. Its message does not record
the 2026-08-08 ruling, so the sites that name the ruling keep its date |
| `#6241` | 1 | 0 | 0 | `83a3b1f2e` | commit | reused (the rest lane) |
normalize the `:type` segment once per handler, closing the third
plural-spelling bypass of the audience gate |
| `#6725` | 1 | 0 | 0 | `1507ba356` | commit | reused (stage 3; the spec
lane) | `MetadataFacade` object writes reach the map its reads use |
| `#8734` | 2 | 0 | 1 | `f8eb73601` | commit | reused (the plugin-auth
lane) | bind the last-admin standing-key lists to the authz resolver's
measured read surface |
| `#10978` | 0 | 0 | 5 | `4c9780c7a` | commit | reused (stage 2; the
runtime lane) | authorization ObjectQL doubles enforce `limit`, by
presence |
| `#11330` | 0 | 0 | 2 | `a9ee98992` | commit | reused (the spec lane) |
the `manifest.runtime` trust-tier text states publish-gate-only
enforcement truthfully: the tier half of the same sentence |
| `#11331` | 2 | 0 | 0 | none | words | the spec lane's form
(`21ab410417`: 「The enforce leg is unbuilt.」) | it tracked the
unpack-time integrity re-verification leg, which was never built; no
commit or ADR decides it |
| `#11333` | 1 | 0 | 0 | `ea4d16420` | commit | reused (the runtime
lane) | option A phase 1 of that card, binding an artifact's granted
permissions at load (its diff says so); the site names the phase after
it |
| `#13179` | 0 | 0 | 2 | `fd289be45` | commit | measured | strip the
tracker ids from `HotReloadManager`'s author-facing refusal messages and
re-pin the twins (the 2026-08-29 family adjudication's member half); it
wrote both test lines |
| `#13279` | 7 | 0 | 2 | `6a180e42d` | commit | reused (stages 4 and 6;
the service-settings, plugin-hono-server and cloud-connection lanes) |
fail loud when a permission-store read fails; its message records the
2026-08-30 ruling verbatim |
| `#13324` | 1 | 0 | 0 | `4cda78c9b` | commit | reused (stages 1, 4 and
6; the types lane) | a missing-table error must name the table that was
read (`readObject`) |
| `#13644` | 1 | 0 | 0 | `34ce8e7db` | commit | reused (stage 3) |
declare `HookContext.referentialFieldClear` and populate it on every
set-null cleanup write |
| `#14192` | 1 | 0 | 0 | `4d0d9445a` | commit | reused (the cli and spec
lanes, for the same 「strictObject since」 sentence) | `ManifestSchema`
goes strict |
| `#14386` | 0 | 1 | 0 | `7cbe705b0` | commit | measured | put three
more package-root plugin manifests inside a tsc program; it widened
plugin-auth's `tsconfig.examples.json` |
| `#14386` | 0 | 1 | 0 | `c49007a7c` | commit | measured | declare
`plugin-hono-server` and put plugin-auth's published example in a tsc
program: the example that 「could not resolve, compile or run for anyone
who copied it」 |
| `#14613` | 0 | 3 | 2 | `81208086a` | commit | reused (the rest lane) |
`@objectstack/core` declares a `typecheck` script; the test and examples
layers enter the ratchet. It wrote all three `tsconfig` lines |
| `#14919` | 1 | 0 | 1 | `cc00df2f7` | commit | measured | retire
`PluginSecurityScanner` under ADR-0049; its message records the
2026-09-05 ruling |
| `#16649` | 2 | 0 | 0 | `613bfbd3d` | commit | reused (stage 4; the
runtime and spec lanes) | register the fourteen remaining `door: 'none'`
codes in `ERROR_CODE_LEDGER`, `PLUGIN_CONTRACT_VIOLATION` and
`SERVICE_NOT_REGISTERED` among them |
| `#16682` | 1 | 0 | 0 | ADR-0131's 2026-09-17 amendment | ADR |
measured (the plugin-security lane's `9b9581b11` is the `single`-posture
selection repair, a different subject) | the amendment's 「What the
ruling did NOT decide」 section quotes the 2026-09-08 ruling verbatim and
untranslated, the sentence this site quotes (「retiring the walled write
must not retire the `single` one」). `74832b68f`, which wrote the line,
quotes it too; the ADR comes first |
| `#16721` | 7 | 0 | 8 | `51ae73123` | commit | reused (the cli and
plugin-hono-server lanes) | `LiteKernel.use()` enforces the declared
plugin contract, converged with `ObjectKernel` (step 2). Its message
does not record the 2026-09-08 ruling, so the sites that name it keep
its date; step 1 was a measurement with no commit of its own |
| `#17124` | 1 | 0 | 0 | `86c505286` | commit | reused (the
service-analytics lane) | a `dateRange` array that is not a two-bound
window is refused once, instead of meaning three different things on
four faces |
| `#17147` | 1 | 0 | 1 | `aaacf1d5c` | commit | reused (the spec and
runtime lanes) | the install-time granted permission set is registered
at load and refuses nothing: say so, and pin the measurement. It created
the pin file |
| `#17147` | 0 | 0 | 1 | `65481183b` | commit | measured | the pin's
follow-up: sweep the retracted phrasing repo-wide instead of reading one
file. It wrote the line |
| `#17590` | 0 | 0 | 1 | `e04a0aff2` | commit | reused (stages 4 and 5;
this package's own `json-membership-sql.ts`) | compile `$contains` on a
JSON column as a per-dialect membership test, the construct that later
moved here |
| `#17853` | 0 | 1 | 0 | `08f5f0e5a` | commit | reused (stage 3; the
cli, rest, runtime, types and dogfood lanes, for the same line) | a
vitest filter that selects no test file says so |
| comment `5486840233` | 0 | 0 | 1 | ADR-0025 §3.7 | ADR | measured |
the ruling that fences per-plugin context construction to ADR-0025's
install-flow design work; §3.7 records that fence |
No ADR or ruling record decides any of the 22 commit-anchored numbers:
`git grep` over `docs/adr` and `scripts/adr-anchors` names only two of
the 24 numbers, `#16682` (ADR-0131, taken as that number's anchor) and
`#17147` (ADR-0025 §3.7, only as the tracker of the unbuilt seam).
## Wordings to check
Most rewrites swap a tag in place (`[#N]` to `[commit SHA]`, `(#N)` to
`(commit SHA)`, `since #N` to `since commit SHA`, `pre-#N X` to `X
before commit SHA`). These say more than the tag:
- **The sentence credits a finding to the wrong number**
(`tsconfig.examples.json:22`): 「That is the same shape #14386 found in
plugin-auth's example (a published example that could not resolve,
compile or run for anyone who copied it)」. That finding is
`c49007a7c`'s, word for word in its message (「the example could not
resolve, compile or run for anyone who copied it」, 「Part of #10869」),
and plugin-auth's own `tsconfig.examples.json` credits it to #10869;
`7cbe705b0` (#14386) widened that program to the package-root manifest.
So the line reads 「the same shape commit c49007a found」, the anchor
that does not name its number, as stage 3's `#10629` exception did. Line
2 of the same file pairs the program's origin and its widening, 「(#10869
/ commit 7cbe705)」, and keeps the live #10869.
- **By words, the spec lane's form** (`security/index.ts:41`,
`plugin-artifact-integrity.ts:12` and `:13`): `#11331` tracked the
unpack-time integrity re-verification leg, which was never built, and no
commit decides it (`b60f48b52` and `f89812e4d` kept the pointer; the cli
lane left its three sites for that reason). The spec lane's stage 1
(`21ab410417`) wrote 「Enforce leg tracked on #11331.」 as 「The enforce
leg is unbuilt.」. Here 「not by the cloud control plane (#11331)」 became
「(that leg is unbuilt)」, and 「(tracked on #11331, NOT discharged by this
module)」 became 「(that leg is unbuilt, and NOT discharged by this
module)」. That second sentence wraps, so line 12, which carries no
number, changed with line 13: 「(tracked on」 to 「(that leg is」. It is the
only line without a number that changed.
- **The two numbers on one line** (`plugin-permission-enforcer.ts:119`):
「the ADR-0025 materialize seam (#17147, Phase 1b of #11333)」 became
「(measured and recorded in commit aaacf1d; the phase after commit
ea4d164)」. The first half is the spec lane's wording for the same
seam; `ea4d16420`'s diff calls itself 「#11333 option A phase 1」.
- **A defect, not a change**: 「bypasses (#3984, #5881, #6241)」 became
「bypasses (#3984, #5881, the one commit 83a3b1f closed)」
(`metadata-service-contract.ts:44`); 「(silent loss, the #6725 family)」
became 「(silent loss, the same family as the defect commit 1507ba3
fixed)」 (`:68`, the parenthesis opening on `:67`); 「MEASURED on
`abc4b83ce` (#17124)」 became 「(the defect commit 86c5052 fixed)」
(`analytics-date-range-conformance.ts:124`). Stage 7's form.
- **Rulings the anchor's message does not record keep their date**: 「The
maintainer ruling of 2026-08-08 on #6216 (Option A)」 became 「The
maintainer ruling of 2026-08-08 (Option A, landed as commit f586f1a)」;
「(#16721, maintainer ruling 2026-09-08, option A)」 became 「(maintainer
ruling 2026-09-08, option A, landed as commit 51ae731)」; 「#16721,
maintainer ruling 2026-09-08, option A under …」 became 「commit 51ae731
landed maintainer ruling 2026-09-08, option A under …」
(`lite-kernel.ts:41`, line 42 unchanged); 「(#6216 Option A)」 became
「(commit f586f1a, the ruled Option A)」, the plugin-hono-server lane's
spelling.
- **The quoted ruling** (`resolve-authz-context.ts:925`): 「maintainer
2026-09-08 on #16682, verbatim: "The rest of Choice 4A …"」 became
「maintainer 2026-09-08, recorded in ADR-0131's 2026-09-17 amendment,
verbatim:」. The quotation is untouched, including its live `#11974`. The
first cut cited `74832b68f`; the ADR amendment that quotes the same
sentence was found before the PR opened and replaced it in its own
commit (`a4c483901`), ruling C's order.
- **Step 1 of #16721** was a measurement with no commit of its own:
「(#16721 step 1)」 became 「(step 1, before commit 51ae731)」
(`lite-kernel.ts:48`), and 「the wiring #16721 step 1 measured with」
became 「the wiring step 1 (before commit 51ae731) measured with」
(`plugin-contract-enforcement.test.ts:599`). 「The two inputs #16721 was
filed on」 became 「The two inputs behind commit 51ae731」 (`:472`). 「the
convergence #16721 / ruled for the other eight keys」 became 「the
convergence landed in commit 51ae731 as / ruled for the other eight
keys」 (`plugin-contract.ts:155`, line 156 unchanged).
- **`pre-#N`**: 「pre-#6216 assembly」, 「pre-#6216 transcriptions」,
「verbatim, pre-#6216」 (twice), 「Pre-#6216 these two」, 「The pre-#6216
dispatcher」 and 「the pre-#13279 `return []`」 became 「… before commit
f586f1a」 / 「… before commit 6a180e4」, stage 1's form.
- **The comment id**: 「fenced by maintainer ruling `5486840233`, which
assigns the per-plugin context to the ADR-0025 install-flow design
effort」 became 「fenced by the maintainer ruling ADR-0025 §3.7 records,
which assigns …」. §3.7's note (written by `c1078a559`) states that the
ruling assigns that construction to the ADR's install-flow design work
and forbids improvising it elsewhere; `aaacf1d5c`'s message carries the
same sentence.
- **The moved construct** (`json-membership-sql.test.ts:6`): 「moved here
from `driver-sql` (#17590)」 became 「moved here from `driver-sql`, where
commit e04a0af wrote it」, so the commit is not read as the move (which
is `58a77dbde`, under the live #20987 on line 4).
- **Follow-up and rule lines**: 「[#17147 follow-up]」 became 「[commit
6548118, the follow-up]」. `assemble-execution-context.test.ts:33`,
`security-scanner-retirement.pin.test.ts:8` and
`granted-permissions-not-enforced.pin.test.ts:4` are decorated rules;
their dashes were not trimmed, so the change on each line is the
citation alone.
- No line was reflowed, so some are longer than their block's wrap
(`eslint.config.mjs` declares no line-length rule, and a reflow would
move neighbouring lines and every line citation into the file).
## Sites left
- **In comments (src, test, outside the glob): none.**
- **String literals: 22 test-string sites, 8 numbers, 7 files**
(`describe` and `it` titles, assertion arguments): `#6216` 8
(`assemble-execution-context.test.ts`), `#13279` 7
(`authz-store-unavailable.test.ts`), `#17147` 2
(`granted-permissions-not-enforced.pin.test.ts:120`, `:140`), `#8734`,
`#10978`, `#13324`, `#14919` and `#16721` 1 each. Every one of the 8 is
in this stage's table. Strings are outside this stage's surface;
non-test strings cite none.
- **Outside comment prose**: `test-typecheck-debt.json:3` names #14613
inside the authored `_note` string (a JSON string value, not a comment);
`PHASE2_IMPLEMENTATION.md:282` names #14919 in markdown prose (not a
comment or docblock, and not in `files[]`). Both anchors are in this
stage's table (`81208086a`, `cc00df2f7`).
- **Outside `src`:** the release-owned `CHANGELOG.md` names dead numbers
on 21 sites; left.
## Mechanical guard: no code token moves
The guard (stages 2 to 7's) compares base `fd96a8473` against the tree
over all 34 touched files, with TypeScript 6.0.3; the three
`tsconfig*.json` files are parsed with `ts.parseJsonText`. It ran at
`195aa6bdb` with the controls below, and again at the head `a4c483901`:
- **Reading 1**: the parser's leaf nodes, from a `forEachChild` walk.
Comments are trivia there, and JSDoc is never visited. A leaf that is
not itself a token is re-scanned with trivia skipped.
- **Reading 2**: the full token stream in parser context, from a
`getChildren` walk, JSDoc nodes skipped. String, template and numeric
literals are compared in full on both readings.
Results:
- Real run: 50,680 base tokens, **0 files with a token change** (exit
0), at both trees.
- Comment control (「distinguish the two」 to 「DISTINGUISH the two」,
`resolve-authz-context.ts`): 0 files changed (exit 0).
- Positive control, an identifier (`PLUGIN_CONTRACT_VIOLATION_CODE` to
`…CODEX`, `plugin-contract.ts`): DIFFER on both readings (exit 1).
- Positive control, a string literal (`'SERVICE_NOT_REGISTERED'` to
`'SERVICE_NOT_REGISTEREDX'`, `service-not-registered.ts`): DIFFER on
both readings (exit 1).
- Positive control, a numeric literal (`'b'.repeat(24)` to `25`,
`api-key.test.ts`): DIFFER on both readings (exit 1).
- Positive control, a JSON value (`"noEmit": true` to `false`,
`tsconfig.test.json`): DIFFER on both readings (exit 1).
Each mutation went through `scripts/ablation-replace.mjs` (wrap mode,
anchor hit 1 to 0, blob changed) under a shell trap that restores by
absolute path from `HEAD`. Each restore was proven equal to its `HEAD`
blob (`ca0fbe39fd18`, `362e8a56a1b9`, `d36529c990a5`, `5ebcb9050807`,
`d51f5f214b09`), with `git diff HEAD` empty and a clean tree afterwards.
## Changeset: `patch` (`dist` measured)
`files[]` is `dist`, `README.md` and `CHANGELOG.md`, and the package is
not private. In one script under the shared verify lock (VERDICT
command-exit 0, held 355s), at `195aa6bdb`: the workspace was built
first (`turbo run build --filter='./packages/*'
--filter='./packages/*/*' --concurrency=2`, 71 of 71 tasks, 1 cached),
then the package's own `build` (tsup, `check-dts-emitted` and the
dev-prereqs stamp) ran three times:
- **Leg 1**, the head text: 14 `dist` files hashed. Of the 40 rewritten
non-test lines, 21 appear verbatim in `dist` (docblocks on exported
members in `index.d.ts` / `index.d.cts`; the `lite-kernel.ts`,
`plugin-loader.ts` and `plugin-permission-enforcer.ts` ones also in
`index.js` / `index.cjs`).
- **Leg 2**, the base text put back in the 17 non-test touched files (17
of 17 proven equal to their base blob): 6 of the 14 files differ from
leg 1 (`index.js`, `index.cjs`, `index.d.ts`, `index.d.cts`, and the two
build-input hash stamps), and `scripts/ablation-dist-preflight.mjs`
finds the base marker 「[#13279] This function used」 in 2 built files
(`index.d.ts`, `index.d.cts`; exit 0).
- **Leg 3**, after the proven restore (17 of 17 equal to their `HEAD`
blob, `git diff HEAD` empty, porcelain empty): all 14 files are
byte-identical to leg 1, and the preflight's `--absent` reading exits 0
with a clean tree, so the build is deterministic and the difference is
the rewrite.
So the rewrite ships, and `.changeset/20595-core-provenance-anchors.md`
declares a `patch` for `@objectstack/core`, comment text only, with the
claim's `Clause-②: no` line. The changeset commit touches no file under
`packages/core`. The one line `a4c483901` changed after the legs is a
`//` comment inside a function body: its text as built in leg 3 is in no
`dist` file (grep exit 1), while a docblock line of the same build is in
all four `index` files (`since commit 51ae731 it is ONE statement`,
the control), so that commit moves no shipped byte.
## Gates (head `a4c483901`)
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` at `a4c483901` (35 paths against
merge base `6f17d1d36`, 179 changed lines) derived 65 commands. All 65
ran, each exit code captured before any pipe: 65 exit 0. `--ran` reports
「65 derived, 65 run, 0 NOT-MEASURED, 0 UNRUN」 (a derived zero) and exits
0. The PM's lead derivation (55 commands, tree `6210f887`) is a subset:
the extra 10 are `check:authz-resolver` and
`check:dispatcher-error-vocabulary`, which this package's paths add, and
the 8 changeset families.
- **Roster families under touched directories**, run as well: `node
scripts/check-changeset-fixed.mjs`, `pnpm check:error-code-casing`,
`pnpm check:filter-alias-parity`, `pnpm check:tenant-chokepoint` and
`pnpm check:object-def-param-keys`: 5 exit 0.
- **Named readings:** `node scripts/check-issue-citations.mjs` exits 0
(「every citation this change adds resolves (or is a declared cross-repo
reference)」: 6 judged across 17 files, all 6 resolve; they are the live
numbers kept on changed lines); `pnpm check:issue-citations` exits 0
(self-test); `pnpm check:doc-authoring` exits 0 (the sibling-package
prose-id baseline holds, no growth); `pnpm check:nul-bytes` exits 0
(9,851 files, no raw control bytes), and a control-byte grep over the 35
changed files finds none (exit 1).
- **Tests and typecheck, under the verify lock, at `a4c483901`**
(VERDICT command-exit 0, held 64s): `pnpm --filter @objectstack/core
test` (vitest project `local`): 76 test files pass (76), 2,156 tests
pass (2,156); `pnpm --filter @objectstack/core exec vitest run --project
repo --maxWorkers=2` (the three repo-reading tests
`vitest.repo-tests.json` lists, two of them touched here): 3 files pass,
48 tests pass; `pnpm --filter @objectstack/core typecheck` (`tsc
--noEmit`, `tsc --noEmit -p tsconfig.examples.json`, then
`check:test-typecheck`: 「4 file(s) / 4 error(s) / 4 pinned signature(s)
held」) exits 0. The same three were green at `67ef07870`, before the
last commit. `tsc --listFilesOnly` puts all 79 tracked test files in
`tsconfig.test.json`'s program and the 17 changed non-test `src` files
in `tsconfig.json`'s.
- **Lint, as a proven narrowing, at `a4c483901`:** eslint with inline
config disabled, over the 31 touched `.ts` files plus `dist/index.js` as
the control: 32 results, 0 errors and 1 warning, the control's ignore
notice; none of the 31 is reported ignored. The three `tsconfig*.json`
files answer 「File ignored because no matching configuration was
supplied」 (not eslint targets). `eslint.config.mjs` never enables
type-aware linting (its lines 327 and 328 say so), so a comment edit
cannot move the verdict on an untouched file. The repo-wide `pnpm lint`
is CI's run.
## Acceptance notes
- **Base and merge.** The branch was cut at `fd96a8473` and merges
`main` once, pinned to `6f17d1d36` (merge `67ef07870`, no conflict). The
two commits it brought (`9ff74285f`, CI test-shard scripts; `6f17d1d36`,
`plugin-approvals`) touch neither `packages/core`,
`check-issue-citations.mjs` nor `dispatch-gates.mjs`; `plugin-approvals`
was rebuilt after the merge, before the tests and gates. The net diff
against `main` is the 34 rewritten files (+81/−81) and the changeset
(+17).
- **The census frontier moved during the after run** (newest #21495
before, #21498 after; the board's frontier is #21498). Nothing in this
package's reading depends on numbers above #21494, and the third run at
the head saw no movement.
- **The same dead numbers outside this package**, each left to its own
carrier: `scripts/check-meta-type-normalized.mjs` names #6241 in its
header and its failure text (outside the census surface, and a gate
script, which a citation stage does not edit);
`docs/adr/0025-plugin-package-distribution.md` §3.7 names #17147 and the
comment id `5486840233`, and ADR-0131's amendment names #16682 and its
comment `5587754690`, which also answers 404 (both governed, Tier H; the
amendment's quotation is what this stage anchors to, and it stays
legible whatever the links answer); `packages/cli` keeps its three
#11331 sites, which the cli lane left for want of a deciding commit, and
this stage's wording is there for whoever takes them; #17590 stands at
`packages/spec/src/data/filter.zod.ts:1067` in the spec lane's
population, where `e04a0aff2` is the anchor.
- **Wording only:** apart from `plugin-artifact-integrity.ts:12`, no
line without a number was changed.
---
_Generated by [Claude
Code](https://claude.ai/code/session_01DDZNkDVwPQnevTFcYE47H3)_
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 529d971 commit c205b6c
35 files changed
Lines changed: 101 additions & 81 deletions
File tree
- .changeset
- packages/core
- src
- security
- utils
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
92 | | - | |
| 92 | + | |
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
260 | 260 | | |
261 | 261 | | |
262 | 262 | | |
263 | | - | |
| 263 | + | |
264 | 264 | | |
265 | 265 | | |
266 | 266 | | |
| |||
385 | 385 | | |
386 | 386 | | |
387 | 387 | | |
388 | | - | |
| 388 | + | |
389 | 389 | | |
390 | 390 | | |
391 | 391 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
41 | | - | |
| 41 | + | |
42 | 42 | | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | | - | |
| 48 | + | |
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
| |||
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
72 | | - | |
| 72 | + | |
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
68 | | - | |
| 68 | + | |
69 | 69 | | |
70 | 70 | | |
71 | 71 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| |||
424 | 424 | | |
425 | 425 | | |
426 | 426 | | |
427 | | - | |
| 427 | + | |
428 | 428 | | |
429 | 429 | | |
430 | 430 | | |
| |||
469 | 469 | | |
470 | 470 | | |
471 | 471 | | |
472 | | - | |
| 472 | + | |
473 | 473 | | |
474 | 474 | | |
475 | 475 | | |
| |||
542 | 542 | | |
543 | 543 | | |
544 | 544 | | |
545 | | - | |
| 545 | + | |
546 | 546 | | |
547 | 547 | | |
548 | 548 | | |
| |||
567 | 567 | | |
568 | 568 | | |
569 | 569 | | |
570 | | - | |
| 570 | + | |
571 | 571 | | |
572 | 572 | | |
573 | 573 | | |
| |||
596 | 596 | | |
597 | 597 | | |
598 | 598 | | |
599 | | - | |
| 599 | + | |
600 | 600 | | |
601 | 601 | | |
602 | 602 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
10 | | - | |
| 10 | + | |
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| |||
113 | 113 | | |
114 | 114 | | |
115 | 115 | | |
116 | | - | |
| 116 | + | |
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
| |||
152 | 152 | | |
153 | 153 | | |
154 | 154 | | |
155 | | - | |
| 155 | + | |
156 | 156 | | |
157 | 157 | | |
158 | 158 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
418 | 418 | | |
419 | 419 | | |
420 | 420 | | |
421 | | - | |
| 421 | + | |
422 | 422 | | |
423 | 423 | | |
424 | 424 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
0 commit comments