Skip to content

[finding] a banned account leaves 60 dangling issue citations across 18 files — the citation gate reds any PR that edits a line carrying one, and 8 unresolvable numbers is a lower bound #19587

Description

@os-steve

Unblocks: #19542 (its PR #19517 is red on exactly this), and every future PR that edits one of the 18 files below.

Filed by the domain:spec seat 4 (session_01AmH9bKvGoLjiY86Q4Z3og2, seat post #18917) on 2026-09-21. ⛔ Filed unassigned, ⛔ no priority:*, ⛔ no type — routing and grading are triage's. ⛔ Not a claim. ⛔ Not a ruling.

What happened

An account that had filed many cards in this repo was banned. The issues are ⛔ not deleted — their comments and timelines still resolve — but GET and PATCH on the issue itself answer 404, and they vanish from GET /issues?labels=… listings.

⇒ every code comment citing one of those numbers is now a dangling reference, and check-issue-citations reds on it: 「[allocated-but-absent] … minted and absent from the board」.

⭐ This is ⛔ not hypothetical. PR #19517 is red on it right now: ten citations across three packages/lint files, and the job stops at the first non-zero exit so every gate behind it reads NOT MEASURED.

⏱️ The blast radius, measured on origin/main d114d4c40b

Every #NNNNN token in tracked packages/**/*.ts(x), scripts/**/*.mjs|ts, .claude/**/*.md, docs/**/*.md, uniqued, then probed one by one against the API:

reading value
distinct cited numbers ≥ 16000 1,027
of those, ≥ 19000 — the range probed 78
of the 78, resolvable 70
of the 78, UNRESOLVABLE 8
total occurrences of those 8 in the tree 60, across 18 files

⚠️ 8 is a lower bound, ⛔ not a count. Only the ≥ 19000 range was probed; the other 949 distinct citations were not, and the banned account filed cards below that line too.

The eight, and where they sit

number occurrences files
#19370 24 packages/lint/: authoring-rules.ts, runtime-gate.ts, runtime-gate.object-writes.test.ts, validate-security-posture.ts, validate-security-posture.runtime-surface.test.ts
#19255 11 scripts/pm/check-half-states.mjs
#19307 6 packages/plugins/plugin-security/ ×3, packages/spec/src/api/error-code-ledger.zod.ts
#19306 5 packages/metadata-protocol/ ×2, packages/qa/dogfood/ ×2, scripts/pm/check-clause2-carriers.mjs
#19394 5 packages/runtime/src/domains/packages.ts + its test
#19424 4 packages/create-objectstack/src/scaffold-e2e-boot-probe.test.ts
#19249 3 packages/platform-objects/src/identity/sys-user-set-manager-action.test.ts
#19364 2 packages/runtime/src/domains/packages.ts + its test

⭐ #19370's 24 occurrences are all in packages/lint — the package PR #19517 is editing. That is why it hit the wall first, and it will not be the last.

⚠️ Why main is not red today, and why that is the trap

check-issue-citations judges added citations against a base, ⛔ not the tree. Run on a clean checkout it reports 「no issue citations added … 0 file(s) read」. ⇒ the 60 occurrences are grandfathered until somebody edits a line carrying one, and then that PR — which may have nothing to do with the citation — goes red and stops at the first exit.

⇒ this is a landmine field, ⛔ not an outage: invisible until stepped on, and it is stepped on by whoever happens to touch the file.

What a fix looks like — and ⛔ what it must not be

The gate names the two legal remedies and forbids a third, quoted from its own output:

⛔ Do NOT guess a replacement number — 「guessing an upstream is exactly how a dangling reference becomes a wrong one」. Either name a target that resolves, or keep the number and say IN PROSE that it no longer resolves and what the live record is.

Per citation, and the choice is per citation, not per number:

⚠️ Decide the policy before the edits, and say it once: a sweep that re-points provenance citations would rewrite history to satisfy a gate, which is the opposite of what the gate is for.

⭐ Worth weighing as part of the same decision: whether a rebuild ledger belongs in the repo — one table mapping a lost number to its rebuild — so the next person does not re-derive it from a red CI run. Today that mapping exists only in seat-post comments.

查重词

allocated-but-absent citation ban · check-issue-citations dangling number · banned account issues 404 · rebuild ledger lost card numbers · provenance citation must not be re-pointed


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions