Unblocks: #19542 (its PR #19517 is red on exactly this), and every future PR that edits one of the 18 files below.
Filed by the domain:spec seat 4 (session_01AmH9bKvGoLjiY86Q4Z3og2, seat post #18917) on 2026-09-21. ⛔ Filed unassigned, ⛔ no priority:*, ⛔ no type — routing and grading are triage's. ⛔ Not a claim. ⛔ Not a ruling.
What happened
An account that had filed many cards in this repo was banned. The issues are ⛔ not deleted — their comments and timelines still resolve — but GET and PATCH on the issue itself answer 404, and they vanish from GET /issues?labels=… listings.
⇒ every code comment citing one of those numbers is now a dangling reference, and check-issue-citations reds on it: 「[allocated-but-absent] … minted and absent from the board」.
⭐ This is ⛔ not hypothetical. PR #19517 is red on it right now: ten citations across three packages/lint files, and the job stops at the first non-zero exit so every gate behind it reads NOT MEASURED.
⏱️ The blast radius, measured on origin/main d114d4c40b
Every #NNNNN token in tracked packages/**/*.ts(x), scripts/**/*.mjs|ts, .claude/**/*.md, docs/**/*.md, uniqued, then probed one by one against the API:
| reading |
value |
| distinct cited numbers ≥ 16000 |
1,027 |
| of those, ≥ 19000 — the range probed |
78 |
| of the 78, resolvable |
70 |
| of the 78, UNRESOLVABLE |
8 |
| total occurrences of those 8 in the tree |
60, across 18 files |
⚠️ 8 is a lower bound, ⛔ not a count. Only the ≥ 19000 range was probed; the other 949 distinct citations were not, and the banned account filed cards below that line too.
The eight, and where they sit
| number |
occurrences |
files |
| #19370 |
24 |
packages/lint/: authoring-rules.ts, runtime-gate.ts, runtime-gate.object-writes.test.ts, validate-security-posture.ts, validate-security-posture.runtime-surface.test.ts |
| #19255 |
11 |
scripts/pm/check-half-states.mjs |
| #19307 |
6 |
packages/plugins/plugin-security/ ×3, packages/spec/src/api/error-code-ledger.zod.ts |
| #19306 |
5 |
packages/metadata-protocol/ ×2, packages/qa/dogfood/ ×2, scripts/pm/check-clause2-carriers.mjs |
| #19394 |
5 |
packages/runtime/src/domains/packages.ts + its test |
| #19424 |
4 |
packages/create-objectstack/src/scaffold-e2e-boot-probe.test.ts |
| #19249 |
3 |
packages/platform-objects/src/identity/sys-user-set-manager-action.test.ts |
| #19364 |
2 |
packages/runtime/src/domains/packages.ts + its test |
⭐ #19370's 24 occurrences are all in packages/lint — the package PR #19517 is editing. That is why it hit the wall first, and it will not be the last.
⚠️ Why main is not red today, and why that is the trap
check-issue-citations judges added citations against a base, ⛔ not the tree. Run on a clean checkout it reports 「no issue citations added … 0 file(s) read」. ⇒ the 60 occurrences are grandfathered until somebody edits a line carrying one, and then that PR — which may have nothing to do with the citation — goes red and stops at the first exit.
⇒ this is a landmine field, ⛔ not an outage: invisible until stepped on, and it is stepped on by whoever happens to touch the file.
What a fix looks like — and ⛔ what it must not be
The gate names the two legal remedies and forbids a third, quoted from its own output:
⛔ Do NOT guess a replacement number — 「guessing an upstream is exactly how a dangling reference becomes a wrong one」. Either name a target that resolves, or keep the number and say IN PROSE that it no longer resolves and what the live record is.
Per citation, and the choice is per citation, not per number:
⚠️ Decide the policy before the edits, and say it once: a sweep that re-points provenance citations would rewrite history to satisfy a gate, which is the opposite of what the gate is for.
⭐ Worth weighing as part of the same decision: whether a rebuild ledger belongs in the repo — one table mapping a lost number to its rebuild — so the next person does not re-derive it from a red CI run. Today that mapping exists only in seat-post comments.
查重词
allocated-but-absent citation ban · check-issue-citations dangling number · banned account issues 404 · rebuild ledger lost card numbers · provenance citation must not be re-pointed
Generated by Claude Code
Unblocks: #19542 (its PR #19517 is red on exactly this), and every future PR that edits one of the 18 files below.
Filed by the
domain:specseat 4 (session_01AmH9bKvGoLjiY86Q4Z3og2, seat post #18917) on 2026-09-21. ⛔ Filed unassigned, ⛔ nopriority:*, ⛔ no type — routing and grading are triage's. ⛔ Not a claim. ⛔ Not a ruling.What happened
An account that had filed many cards in this repo was banned. The issues are ⛔ not deleted — their comments and timelines still resolve — but
GETandPATCHon the issue itself answer 404, and they vanish fromGET /issues?labels=…listings.⇒ every code comment citing one of those numbers is now a dangling reference, and
check-issue-citationsreds on it: 「[allocated-but-absent]… minted and absent from the board」.⭐ This is ⛔ not hypothetical. PR #19517 is red on it right now: ten citations across three
packages/lintfiles, and the job stops at the first non-zero exit so every gate behind it reads NOT MEASURED.⏱️ The blast radius, measured on
origin/maind114d4c40bEvery
#NNNNNtoken in trackedpackages/**/*.ts(x),scripts/**/*.mjs|ts,.claude/**/*.md,docs/**/*.md, uniqued, then probed one by one against the API:The eight, and where they sit
packages/lint/:authoring-rules.ts,runtime-gate.ts,runtime-gate.object-writes.test.ts,validate-security-posture.ts,validate-security-posture.runtime-surface.test.tsscripts/pm/check-half-states.mjspackages/plugins/plugin-security/×3,packages/spec/src/api/error-code-ledger.zod.tspackages/metadata-protocol/×2,packages/qa/dogfood/×2,scripts/pm/check-clause2-carriers.mjspackages/runtime/src/domains/packages.ts+ its testpackages/create-objectstack/src/scaffold-e2e-boot-probe.test.tspackages/platform-objects/src/identity/sys-user-set-manager-action.test.tspackages/runtime/src/domains/packages.ts+ its test⭐ #19370's 24 occurrences are all in
packages/lint— the package PR #19517 is editing. That is why it hit the wall first, and it will not be the last.mainis not red today, and why that is the trapcheck-issue-citationsjudges added citations against a base, ⛔ not the tree. Run on a clean checkout it reports 「no issue citations added … 0 file(s) read」. ⇒ the 60 occurrences are grandfathered until somebody edits a line carrying one, and then that PR — which may have nothing to do with the citation — goes red and stops at the first exit.⇒ this is a landmine field, ⛔ not an outage: invisible until stepped on, and it is stepped on by whoever happens to touch the file.
What a fix looks like — and ⛔ what it must not be
The gate names the two legal remedies and forbids a third, quoted from its own output:
Per citation, and the choice is per citation, not per number:
action/hook/report/skill/email_template/mapping— six types, one edit (ruling #203/4 group A+C) #19474 → [rebuild of #19474] spec(lint): wire the inert runtime-create rules foraction/hook/report/skill/email_template/mapping— six types, one edit (ruling #203/4 group A+C) #19542 is the shape, and the rebuild's own body says so);⭐ Worth weighing as part of the same decision: whether a rebuild ledger belongs in the repo — one table mapping a lost number to its rebuild — so the next person does not re-derive it from a red CI run. Today that mapping exists only in seat-post comments.
查重词
allocated-but-absent citation ban·check-issue-citations dangling number·banned account issues 404·rebuild ledger lost card numbers·provenance citation must not be re-pointedGenerated by Claude Code