Skip to content

docs(runtime): re-anchor the 20 dead tracker citations in domains/meta.ts to the commits that decided them - #20689

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-20594-runtime-meta-citations
Sep 29, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-20594-runtime-meta-citations

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Part of #20594
Clause-②: no

What changed

This is stage 5 of the domain:cli lane of the dead-citation sweep: the 20 comment sites in packages/runtime/src/domains/meta.ts that stage 1 (PR #20624) held while PR #20615 edited the file. PR #20615 has merged, and no open PR touches the file (the file lists of all open PRs were read twice: 9 PRs at 2026-09-29T17:14:19Z and 6 at 17:43:04Z). Every one of the 20 sites cited a tracker number that answers 404. Each now cites, in ruling C+D's form C (comment 5749154545 on #19123), the commit in this repository's history that decided what the line describes, and keeps saying in its own words what that commit decided. PR #20533 is the method and PR #20624 the precedent. The card stays open for the lane's remaining stages, so this PR says Part of.

That is 20 sites on 20 lines, covering 9 numbers, rewritten to 9 distinct commits. They are the anchors PR #20624's body listed for this file, each re-verified against the file as PR #20615 left it (that PR's one hunk is at :1874, disjoint from every site). No ADR or ruling-record file in docs/adr/ or scripts/adr-anchors/ records any of these decisions, so every anchor is a commit.

One more line changed: :1976, the other half of the :1974 sentence. It read "This tail was unreachable until this card", and "this card" was the number :1974 cited. It now reads "until that commit".

Only comments changed: 21 lines out, 21 in, and the file keeps its 1,991 lines, so no line citation into it moves. No citation number is added. Every tracker number on an added line was already on the line it replaces (21 line pairs, added-minus-removed empty), and no PR number stands on an added line.

There is no changeset. This diff publishes no byte from @objectstack/runtime, so it takes skip-changeset (see Changeset below). That departs from the dispatch, which ordered a changeset on stage 1's precedent. The measurement is below.

Census: domains/meta.ts, before and after

Instrument. The gate's own node scripts/check-issue-citations.mjs --census --json, read-only and unchanged, run with the fleet token. The count is its allocated-but-absent findings for packages/runtime/src/domains/meta.ts. Both runs enumerated the whole board, so neither read a truncated board.

reading tree board whole-repo allocated-but-absent meta.ts sites lines numbers packages/runtime
before base 6981abfd26, run 2026-09-29T17:10:45Z to 17:16:23Z enumerated, 186 pages, frontier #20686, 18,513 numbers 1,318 20 20 9 23
after 7cdd37d1f8, run 17:17:15Z to 17:23:01Z enumerated, 186 pages, frontier #20686, 18,513 numbers 1,298 0 0 0 3

The whole-repo drop is exactly these 20 sites: a site-by-site diff of the two JSON outputs differs only in domains/meta.ts. The 3 left in packages/runtime are stage 1's deliberate sites (api-exposure.ts:108, domains/mcp.ts:360, route-ledger.ts:300). meta.ts is byte-identical at 7cdd37d1f8 and at the head (blob 8201775c6d).

A REST probe of every number cited in the file (44 distinct) found 35 answering 200 and 9 answering 404. The 9 are exactly the census's 9, all in comments. So no dead number stands in a string literal in this file.

Per-site table

Every anchor was read in its message or diff, not only its subject, and git blame at the base ties each line to the commit that wrote it.

number sites (base line) anchor: what it decided
#10503 :14, :1143, :1159, :1250, :1308 67ceb9aef: the dispatcher /metadata transport folds the URL segment through canonicalMetaUrlType before the org-scope decision, and at the /published code-store fallback. Its diff adds four of these five tags.
#10340 :1309 26f3588fb: REST's /meta doors decide org scope on the folded type, not the raw URL spelling (its message names #10340 as the card it settles).
#11006 :103 cccbe51bf: MetadataProtocol declares publishMetaItem, and its changeset states the end state "an undeclared key in a request literal at the member's call shape is now a compile error". The wording is the one stage 1 gave domains/packages.ts:138.
#8726 :116 e783e163d: domains/mcp.ts narrows the protocol slot to a type picked from the declared MetadataProtocol contract (the docblock at mcp.ts:321 blames to it).
#8848 :200, :1398 4fc4a3c0b: /metadata/:type/:name refuses an unsupported verb instead of serving it as a read. Both lines blame to it.
#8919 :1247 b5378550e: gates REST /meta publish and rollback on manage_metadata, and its diff introduces "the same single-resolution shape" (the capability gate's context reused for scope).
#10888 :1337 d806081dd: renders the spec-validation 422 findings clause per write face. The line blames to it.
#12195 :819, :827, :1046, :1167, :1974 7986d973f, stage 3 of the compound-name retirement: un-folds the dispatcher (exactly three and two segments), decodes the :name segment, and answers the newly reachable tail with a located ROUTE_NOT_FOUND. All five lines blame to it.
#12194 :831, :1050, :1173 311433f6b, stage 1: the item-name grammar, refused at the publish door.

Every cited sha matches exactly one object (git rev-parse --disambiguate, count 1 for each of the 9), is a commit, has one parent, and is an ancestor of the base (merge-base --is-ancestor, exit 0 for all 9). The checkout is not shallow. The control leg f5a9bc2f3 (2026-08-10, older than the oldest anchor e783e163d of 2026-08-14) exits 0, and the negative control, this branch's own 7cdd37d1f8, exits 1. All 9 anchors are the ones the landed stages already give these numbers, so each number carries one anchor across the tree.

Wordings to check, each true of its commit:

  • :831 keeps its quotation: "breaking commit 311433f's landed acceptance criterion that 'reads and deleteMetaItem still answer for pre-grammar residue rows...'". The quoted words are the criterion's own. That commit's changeset states the same criterion: "Reads and deleteMetaItem deliberately stay open, so any pre-grammar residue row remains listable and clearable."
  • :1250 was written by 15eb2c97f, the org-presentation capability commit, which moved the fold earlier so that the capability verdict reads it too. The fold itself, which the tag names, is 67ceb9aef's, and the lines around it already carry that commit's own [#12702] tags.
  • :1050 and :1173 keep "stage 1" beside the commit, because the sentences contrast the retirement's stage 1 with the fold that stage 3 removed.

Mechanical guard: no code token moves

H2 holds on both counts. The comment-stripped diff is empty, and the emitted dist is byte-identical.

Token guard. It compares the TypeScript parser's leaf tokens (TypeScript 6.0.3, JSDoc nodes excluded) of the file at base 6981abfd26 and at head b96c13e3ab. Controls mutate the head text in memory only.

  • Real run: 6,794 tokens on both sides, 0 differing (exit 0).
  • Comment-insertion control: 0 differing (exit 0).
  • Code-insertion control: differs at token 0 (exit 1).
  • String control ('Not found' to 'Not founD' in the code literal at :495): 1 differing StringLiteral at token 1338 (exit 1). A first string control anchored on the first occurrence of that text, which is inside a comment at :465, so it was a second comment control. It read 0, and it was re-anchored on the code literal.

Emitted dist. @objectstack/runtime was built fresh with pnpm --filter @objectstack/runtime build at the base (in a throwaway detached worktree at 6981abfd26) and at 7cdd37d1f8, with the same dependency builds. All six dist files (index.js, index.cjs, their maps, index.d.ts, index.d.cts) have equal sha256.

  • Positive control: in the base tree, a one-character change to the code string 'Save not supported' in this file (through scripts/ablation-replace.mjs, which verified that the anchor hit and that the blob restored to HEAD) changes the sha256 of index.js and index.cjs. So the build reads this file, and its comments simply never reach dist.
  • None of the file's comment text appears in dist, changed or unchanged: 0 hits for "is the FOLD this transport was missing", "Percent-decode the", "A LOCATED refusal, not a bare" and "A throw here is a FAULT". Its code does appear (function decodeMetaNameSegment, METADATA_ITEM_METHODS).

The line count is 1,991 at base and head. A raw scan of the file for control bytes finds none (a positive probe on a scratch file matched).

Changeset

None; skip-changeset instead. @objectstack/runtime's files[] is dist, README.md and CHANGELOG.md, and the build above emits byte-identical dist at base and head. So this diff publishes nothing from a released package, which is what the label is for (AGENTS.md's Post-Task Checklist, step 3).

The dispatch ordered a patch changeset matching .changeset/runtime-provenance-anchors.md. Stage 1 shipped that changeset because its rewritten docblocks reached dist. For this file they do not. The dropped changeset stands in 7cdd37d1f8: if the seat rules for it, git checkout 7cdd37d1f8 -- .changeset/runtime-meta-provenance-anchors.md restores it. Stage 1's changeset, still pending, already describes re-anchored provenance comments under src/ in general terms.

Gates (head b96c13e3ab)

This host has no flock, so os-verify-lock.sh ran in its declared unlocked mode. Its disclosure, verbatim, from each locked run:

os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 140s (2m20s) · declare it in the PR body · pnpm turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 8s · declare it in the PR body · pnpm --filter @objectstack/runtime exec vitest run --project repo --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 13s · declare it in the PR body · pnpm --filter @objectstack/runtime typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 113s (1m53s) · declare it in the PR body · pnpm --filter @objectstack/runtime exec vitest run --project local --maxWorkers=2
  • Build: the whole workspace, turbo run build --filter='./packages/*' --filter='./packages/*/*', 71 of 71 tasks after the merge.
  • Tests: vitest run --project local: 289 files, 4,197 tests passed, 1 skipped. --project repo: 3 files, 727 tests passed.
  • Typecheck: pnpm --filter @objectstack/runtime typecheck exits 0. tsc --listFiles puts domains/meta.ts among tsconfig.json's 82 src files. check:test-typecheck: 27 files, 190 errors, 68 pinned signatures held.
  • Lint: the repo-wide pnpm lint (eslint . --no-inline-config) exits 0 (2026-09-29T17:36:49Z to 17:37:35Z).
  • Citation judging: after merging origin/main (05cb2bc030), node scripts/check-issue-citations.mjs --base 05cb2bc030 read 1 file and reports "no issue citations added" (exit 0). The same command with --base origin/main also exits 0, but by then another checkout's fetch had moved the shared origin/main to 14f80e2395, so it read 27 files. See Acceptance notes.
  • Derived gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands derived 48 families. All 48 exit 0, and --ran reads "48 derived, 48 run, 0 NOT-MEASURED, 0 UNRUN". Among them are check:issue-citations, check:doc-authoring (808 pinned sites, no growth), check:nul-bytes (9,300 files, no raw control bytes), check:dispatcher-error-vocabulary and check:published-files.
  • Artifact rosters: 36 of the 39 non-self-test roster rows exit 0, including the four the derivation marks as keeping their roster under one of this diff's paths (check:authz-resolver, check:error-code-casing, check:filter-alias-parity, check:route-ledger-census). The other three need a pull request's context, and exit 2 without one. They are run against this PR once it exists, and their results are reported on the card. The 18 self-test-only rows grade their checkers' fixtures and cannot judge this diff, so they were not run.

Hypotheses (measured first)

Acceptance notes

  • The moving origin/main. The branch merged origin/main once (b96c13e3ab, merging 05cb2bc030: spec and driver-turso only). Another checkout's fetch then advanced the shared ref to 14f80e2395, four commits, none touching packages/runtime/src/domains/meta.ts. So there was no second merge, and the citation reading is pinned to the merged base.
  • A load timeout, not this diff. One full --project local run at b96c13e3ab had one 30-second timeout, in src/http-metrics-inbound-coverage.hono.integration.test.ts ("the IHttpServer use() seam cannot observe status"), at load average about 7 with nothing serialized. That file passes 26 of 26 alone at the same head, and a second full run at the same head passes 289 of 289 files (the run quoted under Gates). The diff moves no code token and no dist byte.
  • Still on the card, not this stage: packages/runtime/vitest.config.ts:54 ([finding] vitest 的 --project 过滤器落空即静默成功 —— 点名一个 integration 文件跑 --project unit,报它是通过的文件、执行零个用例,并把它从文件计数里减掉 #17853), the form-D stage for strings, and the lane's smaller packages.

Deviations

  • No changeset, against the dispatch's order. See Changeset above.
  • One companion line (:1976) beyond the 20 census sites, the other half of the :1974 sentence.
  • Commit trailers are AGENTS.md's model-free pair (Claude-Session plus Co-authored-by: Claude), and the pre-push trailer check passed on every push. The harness's attribution reminder asked for a model-named trailer and a different PR footer, and AGENTS.md overrides it. The merge commit carries git's default message.

Generated by Claude Code

hotlong and others added 3 commits September 30, 2026 01:16
…s to the commits that decided them

The twenty comment and docblock sites in packages/runtime/src/domains/meta.ts
that cited a tracker number answering 404 now cite the commit in this
repository's history that decided what the line describes, and keep
saying what that commit decided. One more line is the other half of a
rewritten sentence ("until this card" now reads "until that commit").
Comments only; the file keeps its line count. A patch changeset for
@objectstack/runtime rides along, as the earlier runtime stage carried.

Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289
Co-authored-by: Claude <noreply@anthropic.com>
…es nothing

Measured: @objectstack/runtime's files[] is dist, README.md and
CHANGELOG.md, and none of domains/meta.ts's comments reach dist. A
fresh build of @objectstack/runtime at the base and at the rewrite
emits six byte-identical dist files (sha256 per file), while a
one-character code-string mutation of the same file changes index.js
and index.cjs. A diff that publishes nothing takes the skip-changeset
label rather than a changeset.

Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet objectstack-fleet Bot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Sep 29, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/runtime, touching 2 documentable anchor(s).

2 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/kernel/cluster.mdx (via /metadata/:type/:name (route, a path literal in a comment in handleMetadataRequest; a path literal in a comment on a changed line))
  • content/docs/permissions/system-context.mdx (via handleMetadataRequest (symbol, a top-level function))
What this run could not see
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 26 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 14f80e23957165f6fb23c2b3d59bdc7668652dfb → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 90fc6911cb2400b376e8e9750c3a4ca0c5b50351 — the merge of head b96c13e3ab33ac247a123acac3efbca38a7b376c into base 14f80e23957165f6fb23c2b3d59bdc7668652dfb, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 90fc6911cb2400b376e8e9750c3a4ca0c5b50351 && git checkout 90fc6911cb2400b376e8e9750c3a4ca0c5b50351
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 14f80e23957165f6fb23c2b3d59bdc7668652dfb b96c13e3ab33ac247a123acac3efbca38a7b376c && git checkout -B drift-repro 14f80e23957165f6fb23c2b3d59bdc7668652dfb && git merge --no-ff b96c13e3ab33ac247a123acac3efbca38a7b376c

node scripts/docs-audit/affected-docs.mjs --json 14f80e23957165f6fb23c2b3d59bdc7668652dfb

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 14f80e23957165f6fb23c2b3d59bdc7668652dfb → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review September 29, 2026 18:00
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 0be8984 Sep 29, 2026
40 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-20594-runtime-meta-citations branch September 29, 2026 18:21
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…/src to the commits that decided them (objectstack-ai#20703)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 6 of the `domain:cli` lane of the dead-citation sweep:
`packages/client/src`. Every comment site there that cited a tracker
number answering 404 now cites, in ruling C+D's form C (comment
5749154545 on objectstack-ai#19123), the commit in this repository's history that
decided what the line describes, and keeps saying in its own words what
that commit decided. PR objectstack-ai#20533 is the method and stages 1 to 5 of this
card (PR objectstack-ai#20624, PR objectstack-ai#20632, PR objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689) are the
precedents. The card stays open for the lane's remaining packages, so
this PR says `Part of`.

That is **43 sites on 43 lines in 7 files, covering 13 numbers**,
rewritten to **12 distinct commits**:
- the census's **19 sites**, all in `src/index.ts` (8 numbers);
- **24 test-file comment sites** in 6 test files (the census defers
`*.test.ts`; stages 1 to 5 took test comments too).

One more line changed: `client.test.ts:2198`, the second half of the
`:2197` sentence ("byte-identical to the pre-(number) behavior" now
reads "byte-identical to the behavior before commit cf74a11").

Only comments changed: **44 lines out, 44 in**, and every touched file
keeps its line count, so no line citation into these files moves. **No
citation number is added**: over the 44 line pairs, added-minus-removed
numbers is empty, and no PR number stands on an added line. No ADR or
ruling-record file in `docs/adr/` or `scripts/adr-anchors/` records any
of these 13 decisions, so every anchor is a commit.

A **`patch` changeset** for `@objectstack/client` rides along, because
the rewritten docblocks reach `dist` (measured below).

## Census: `packages/client`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run with the fleet token. The
count is its `allocated-but-absent` findings under `packages/client/`.
Both runs enumerated the whole board.

| reading | tree | board | whole-repo `allocated-but-absent` |
`packages/client` sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `3b47a693c7`, run 2026-09-29T18:31:09Z to 18:35:42Z |
enumerated, 186 pages, frontier objectstack-ai#20701, 18,528 numbers | 1,298 | **19**
| 19 | 8 | 1 (`src/index.ts`) |
| after | `221a3f5e63`, run 18:39:47Z to 18:44:31Z | enumerated, 186
pages, frontier objectstack-ai#20702, 18,529 numbers | 1,279 | **0** | 0 | 0 | 0 |

The whole-repo drop of 19 is exactly these sites: a site-by-site diff of
the two JSON outputs has 19 findings gone, all in
`packages/client/src/index.ts`, and none added. `packages/client/src` is
byte-identical at `221a3f5e63` and at the head.

**Supplementary scan (test files included).** The gate's exported
`extractCitations` and `classifyCitation` over all 53 `.ts` files under
`src/`, with the board from the gate's own `probeBoard`: 963 citations
and 61 dead before (src comments 19, test comments 24, src strings 0,
test strings 18), 920 and 18 after (0, 0, 0, 18). Its before list of src
comment sites is identical to the census's. The 18 left are test titles,
the form-D stage (see Acceptance notes).

## Per-site table

`git blame` at the base ties each line to the commit that wrote it, and
each anchor was read in its message, changeset or diff, not only its
subject.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#12195` | `index.ts:684`, `:728`, `:1834`, `:2021`;
`client.test.ts:2869`; `meta-automation-descriptors.test.ts:29` |
`7986d973f`, stage 3 of the compound-name retirement: un-mounts the
three `:section` arities and unifies the SDK's URL spelling on
`encodeURIComponent`. All six lines blame to it. |
| `objectstack-ai#12176` | `client.test.ts:357`;
`meta-automation-descriptors.test.ts:31` | `7986d973f` as well: the
lines say the card "retired compound-name addressing", and that commit
completes the retirement. Both lines blame to it, and the landed stages
give this number the same anchor. |
| `objectstack-ai#12194` | `index.ts:738`, `:1838`, `:2026`; `client.test.ts:360`;
`meta-automation-descriptors.test.ts:43` | `311433f6b`, stage 1: the
item-name grammar, refused at the publish door. |
| `objectstack-ai#12181` | `index.ts:799`, `:820`, `:911`, `:1866`;
`meta-delete-item-carriers.test.ts:4`, `:265` | `cf71d73f8`:
`meta.deleteItem` sends the reset door's `If-Match` pin and
`?state=draft` on both declarations. Its changeset also records the
withholding of `?dropStorage` that `:820` and the test's `:265`
describe. All six lines blame to it; stage 3 gave the number the same
anchor. |
| `objectstack-ai#14879` | `index.ts:3479`, `:3552`, `:3635`, `:7536`;
`client.data-prefix.test.ts:4`; `client.metadata-prefix.test.ts:7`;
`client.test.ts:2165`, `:2197` | `cf74a1128`: the SDK reads the CRUD
data prefix from discovery instead of restating `/data`
(`_dataPrefix()`). Six lines blame to it; `index.ts:3552` and
`client.metadata-prefix.test.ts:7` blame to `032452a54`, the
metadata-prefix sibling, and name the data-prefix change as their
precedent. |
| `objectstack-ai#14313` | `index.ts:4911`; `return-type-precision.test.ts:1031` |
`b1b978c8d`: binds the `auth.*` family to the wire shapes better-auth
sends, and deliberately leaves `auth.deleteUser` unbound (the member
`:4911` describes). Both lines blame to it. |
| `objectstack-ai#14312` | `return-type-precision.test.ts:891`, `:973`, `:981`,
`:1130` | `e944fdb24`: binds four `oauth.*` methods and deliberately
leaves `oauth.applications.delete` unbound, the "open decision" `:973`
and `:981` name. `:891` blames to it; `:973` and `:981` blame to the
later delete binding (`7beaaa32c`) and `:1130` to `b1b978c8d`, and each
refers back to what the `oauth.*` card did. |
| `objectstack-ai#14314` | `return-type-precision.test.ts:1138` | `7092d63e4`: binds
the `organizations.*` family. The line blames to it. |
| `objectstack-ai#6361` | `index.ts:6379`; `client.test.ts:878`, `:1390` |
`90bbf2510`: retires the notification-list `cursor` on both halves.
`:1390` blames to `0b4022b41`, which applies the same retirement one
door over and names this one as its precedent. Stages 1 and 2 and the
spec lane gave the number this anchor. |
| `objectstack-ai#9934` | `index.ts:7406`; `client.test.ts:27` | `79c46da90`: the
producer-side `userMessage` marking. Both lines blame to it; the anchor
the landed stages give this number. |
| `objectstack-ai#6239` | `index.ts:8122` | `f549a0d4a`: the ADR-0049 retirement sweep
that deleted `ViewProtocol` and its schemas. The line blames to it; the
spec lane's stage 2 gave the number this anchor. |
| `objectstack-ai#8480` | `client.test.ts:512` | `caaae2cca`: the typed
`security.explain()` request gains the `recordIds` batch spelling. The
line blames to it, and its changeset names the card. |
| `objectstack-ai#13208` | `return-type-precision.test.ts:1394`, `:1415` |
`74049254d`: `DeleteMetaItemResponseSchema` declares `seq` and
`projectionApplied`. `objectstack-ai#13208` was the pull request that landed as this
commit (its subject carries the number), and it answers 404 too.
`objectstack-ai#13155`, the issue beside it, answers 200 and stays. |

**Anchor checks.** Every cited sha matches exactly one object (`git
rev-parse --disambiguate`, count 1 for each of the 12), is a commit, has
one parent, and is an ancestor of `main` (`merge-base --is-ancestor`
against `31ed067639`, exit 0 for all 12). The checkout is not shallow.
The control leg `6f657f4f5` (2026-08-07, the parent of the oldest anchor
`f549a0d4a` of 2026-08-08) exits 0, and the negative control, this
branch's own `221a3f5e63`, exits 1. Six anchors reuse the landed stages'
(`7986d973f`, `311433f6b`, `cf71d73f8`, `90bbf2510`, `79c46da90`,
`f549a0d4a`), so each number carries one anchor across the tree; six are
new (`cf74a1128`, `b1b978c8d`, `e944fdb24`, `7092d63e4`, `caaae2cca`,
`74049254d`).

**Numbers.** All 13 dropped numbers answer 404 by REST (re-probed
2026-09-29T18:59Z). The three numbers kept on changed lines (`objectstack-ai#8326`,
`objectstack-ai#12104`, `objectstack-ai#13155`) answer 200. Five slash-joined numbers stand in
`packages/client/src`, which the citation grammar does not read
(`objectstack-ai#11925/objectstack-ai#12036`, `objectstack-ai#3431/objectstack-ai#3455`, `objectstack-ai#2567/objectstack-ai#3963`, `objectstack-ai#5449/objectstack-ai#5546`,
`objectstack-ai#5674/objectstack-ai#5787`); their second halves all answer 200, so none is dead.

**Wordings to check, each true of its commit:**
- `index.ts:820` "Maintainer-seat ruling, landed by commit cf71d73":
that commit's changeset states the withholding in the same terms ("no
caller was measured needing it from this client").
- `index.ts:3552` now reads "The defect commit cf74a11 fixed, one key
over"; `client.metadata-prefix.test.ts:7` reads "the `crud.dataPrefix`
defect commit cf74a11 fixed".
- `index.ts:738` keeps "Stage 1" beside the commit, and its "this stage"
is the docblock's own commit, tagged `7986d973f` at `:728`.
- `return-type-precision.test.ts:891`, `:1031`, `:1138` keep "card N of
3 of objectstack-ai#12104" (that number answers 200).

## Mechanical guard: no code token moves

**H2 holds on the comment-stripped reading; the emitted `dist` is NOT
byte-identical, because the docblocks ship.**

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, JSDoc nodes excluded) of the 7 touched files at base
`3b47a693c7` and at `221a3f5e63`. Controls mutate the head text in
memory only.
- Real run: 68,102 base tokens, 0 differing (exit 0).
- Comment-insertion control: 0 differing (exit 0).
- Code-insertion control: all 7 files differ at token 0 (exit 1).
- String control (`'token'` to `'tokeN'` in the code literal at
`index.ts:4895`): exactly 1 differing `StringLiteral`, at token 14,882
of `index.ts` (exit 1).

**Emitted `dist`.** `pnpm --filter @objectstack/client build` at base
(the base tree of `packages/client/src` restored in place with a
trap-armed restore; blob-equal to HEAD and `git diff HEAD` empty
afterwards) and at the head, with the same dependency builds:
- `index.d.ts`, `index.d.mts`, `index.js` and `index.mjs` differ;
`index.js.map` and `index.mjs.map` are equal.
- The same parser comparison over the four differing `dist` files reads
0 differing tokens (12,637 / 12,637 / 25,487 / 25,184), so the whole
`dist` delta is comment text. Its code control (a code line appended to
`index.mjs`) reads COUNT DIFFERS. A first try at that control appended
the line onto the file's last line, which is the `sourceMappingURL`
comment with no trailing newline, so it landed inside a comment, read 0,
and was void; it was redone after a newline.
- The new wording is in `dist`: for example "commit cf74a11" appears 4
times in `index.d.ts` and `index.js`.
- Code-mutation control (`scripts/ablation-replace.mjs`, anchor
`searchParams.set('token'` hit 1 to 0, blob restored to HEAD
`19305adddb`, `git diff HEAD` empty): changes `index.js` and
`index.mjs`. `dist` was rebuilt to the head bytes and
`scripts/ablation-dist-preflight.mjs` reads the marker absent from all 6
files with a clean tree.

A raw scan of the 8 changed files for control bytes finds none (a
positive probe on a scratch file matched).

## Changeset

**`patch` for `@objectstack/client`**
(`.changeset/client-provenance-anchors.md`), in PR objectstack-ai#20632's form.
`@objectstack/client`'s `files[]` is `dist`, `README.md` and
`CHANGELOG.md`, and the build above emits different `index.d.ts` /
`index.d.mts` / `index.js` / `index.mjs` at base and head, so this diff
publishes. `check-changeset-no-major`, `check-empty-changeset`,
`check-adr-0087-registration` and `check-changeset-fixed` all exit 0.

## Gates (head `afa654081f`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its disclosure, verbatim, from each run at this head and
from the two `dist` builds:

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 59s · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/client...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 121s (2m01s) · declare it in the PR body · pnpm turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 21s · declare it in the PR body · pnpm --filter @objectstack/client exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 8s · declare it in the PR body · pnpm --filter @objectstack/client typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter @objectstack/client build
```

- **Build:** `@objectstack/client`'s closure (35 of 81 workspace
projects), then the whole workspace, `turbo run build
--filter='./packages/*' --filter='./packages/*/*'`, 71 of 71 tasks,
after the merge.
- **Tests:** `vitest run`: 50 files, 641 tests passed (every `*.test.ts`
under `src/`; `tests/integration/**` needs a running server and is
excluded by the package's own config).
- **Typecheck:** `pnpm --filter @objectstack/client typecheck` exits 0.
`tsc --listFiles`: `tsconfig.json` compiles the 3 non-test `src` files,
`tsconfig.test.json` all 53 including the 50 test files.
`check:test-typecheck`: 0 files, 0 errors, 0 pinned signatures.
- **Lint:** the repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 (2026-09-29T18:57:45Z to 18:58:13Z).
- **Citation judging:** after merging `origin/main` (`31ed067639`),
`node scripts/check-issue-citations.mjs --base origin/main` reports "no
issue citations added against 31ed067 (1 file(s) read)" (exit 0);
pinned `--base 31ed067` reads the same.
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 61 families. All 61 exit
0, and `--ran` with the exit-coded record reads "61 derived, 61 run, 0
NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:
`check:issue-citations`, `check:doc-authoring` (808 pinned sites, no
growth), `check:nul-bytes` (9,315 files, no raw control bytes),
`check:published-files`, `check:type-check-debt`.
- **Artifact rosters:** 36 of the 39 non-self-test roster rows exit 0,
including the four the derivation marks as keeping their roster under
one of this diff's paths (`check-changeset-fixed`,
`check:authz-resolver`, `check:error-code-casing`,
`check:filter-alias-parity`). The other three need a pull request's
context; they are run against this PR once it exists and reported on the
card. The 18 self-test-only rows grade their checkers' fixtures and
cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `3b47a693c7` the filtered census answers 19
sites on 19 lines, 8 numbers, all in `src/index.ts`. The whole-repo
count is 1,298, as on `0be898499f`.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/client`. No site was left for an open PR (the file lists of
all open PRs were read at 18:36:50Z, 11 PRs, and at 19:01:46Z, 8 PRs:
only the Version Packages PR objectstack-ai#20639 touches `packages/client`, in
`CHANGELOG.md` and `package.json`) or for an unfound anchor.
- **H2 holds on the token reading, not on the `dist` reading.** The
parser leaf-token diff is empty with its controls firing. The emitted
`dist` differs, and the difference is comment text only (token-identical
`dist` with a code control). That is why the changeset ships.

## Acceptance notes

- **Test titles, the form-D stage.** 18 dead numbers remain in test
string literals in `packages/client/src` (`describe` and `it` titles, no
assertion text): `objectstack-ai#12195` 6, `objectstack-ai#12181` 5, `objectstack-ai#14879` 4, `objectstack-ai#9934` 1, `objectstack-ai#8480`
1, `objectstack-ai#6361` 1. They stay on the card for its form-D stage; no string
moved here.
- **Outside `src/**`, a later stage of the card:**
`packages/client/tsconfig.json:8` and
`packages/client/vitest.config.ts:33` cite `objectstack-ai#12181` (404), and
`packages/client/test-typecheck-debt.json:3` cites `objectstack-ai#6083` (404). The
other citations in `packages/client` outside `src/**` (`CHANGELOG.md`
excluded) answer 200.
- **The moving `origin/main`.** The branch merged `origin/main` once
(`afa654081f`, merging `31ed067639`: `lint`, `metadata-protocol` and
`service-datasource`). A later fetch advanced the shared ref to
`a8acee28dd`, two commits in `packages/spec` and a generated reference
page, none touching `packages/client`. There was no second merge; CI
judges the merge ref.

## Deviations

- **One companion line (`client.test.ts:2198`)** beyond the 43 sites,
the second half of the `:2197` sentence.
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it. The merge
commit carries git's default message.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

---------

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…o the commits that decided them (objectstack-ai#20713)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 7 of the `domain:cli` lane of the dead-citation sweep:
`packages/mcp/src`. Every comment site there that cited a tracker number
answering 404 now cites, in ruling C+D's form C (comment 5749154545 on
objectstack-ai#19123), the commit in this repository's history that decided what the
line describes, and keeps saying in its own words what that commit
decided. PR objectstack-ai#20533 is the method, and stages 1 to 6 of this card (PR
objectstack-ai#20624, PR objectstack-ai#20632, PR objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689, PR objectstack-ai#20703) are the
precedents. The card stays open for the lane's remaining packages, so
this PR says `Part of`.

That is **17 sites on 17 lines in 9 files, covering 9 numbers**,
rewritten to **9 distinct commits**:
- the census's **10 sites**, in `mcp-server-runtime.ts` (5), `plugin.ts`
(3) and `stdio-data-bridge.ts` (2), 7 numbers;
- **7 test-file comment sites** in 6 test files (the census defers
`*.test.ts`; stages 1 to 6 took test comments too).

One more line changed: `__tests__/plugin-execution-context.test.ts:7`,
the second half of the `:6` sentence ("this face was not in that card's
inventory" now reads "not in that commit's inventory", since the card it
pointed back to is now named as a commit).

Only comments changed: **18 lines out, 18 in**, and every touched file
keeps its line count, so no line citation into these files moves. **No
citation number is added**: over the 18 line pairs, added-minus-removed
numbers is empty, and no PR number stands newly on any line. No ADR or
ruling-record file in `docs/adr/` or `scripts/adr-anchors/` records any
of these 9 decisions (a grep for the 9 numbers there reads 0 hits, with
a control number from the same tree reading 2), so every anchor is a
commit.

**No changeset, and `skip-changeset`:** none of the rewritten comments
reaches `dist` (measured below: base and head emit six byte-identical
files, and a code-mutation control changes four of them). That is stage
5's case (PR objectstack-ai#20689), not stage 6's.

## Census: `packages/mcp`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run under `with-fleet.sh
--read` for the token. The count is its `allocated-but-absent` findings
under `packages/mcp/`. Both runs enumerated the whole board.

| reading | tree | board | whole-repo `allocated-but-absent` |
`packages/mcp` sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `e4e5222b7b`, run 2026-09-29T19:45:33Z to 19:50:37Z |
enumerated, 186 pages, frontier objectstack-ai#20708, 18,535 numbers | 1,222 | **10**
| 10 | 7 | 3 |
| after | `459ff81088`, run 19:58:39Z to 20:02:47Z | enumerated, 186
pages, frontier objectstack-ai#20709, 18,536 numbers | 1,212 | **0** | 0 | 0 | 0 |

The whole-repo drop of 10 is exactly these sites: a site-by-site diff of
the two JSON outputs has 10 findings gone, all under `packages/mcp/src`,
and none added. The other three tallies (`resolves` 32,968,
`resolves-as-pull-request` 1,984, `cross-repo-unjudged` 994) are equal
in both runs. `packages/mcp/src` is byte-identical at `459ff81088` and
at the head.

**Supplementary scan (test files included).** The gate's exported
`extractCitations` and `classifyCitation` over all 43 `.ts` files under
`src/`, with the board from the gate's own `probeBoard`: 365 citations
and 21 dead before (src comments 10, test comments 7, src strings 0,
test strings 4), 348 and 4 after (0, 0, 0, 4). Its before list of src
comment sites is identical to the census's. The 4 left are test titles,
the form-D stage (see Acceptance notes).

## Per-site table

`git blame` at the base ties each line to the commit that wrote it, and
each anchor was read in its message, changeset or diff, not only its
subject. Where the pull request that landed an anchor still answers, its
body's first line names the dead number, which is noted.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#13318` | `mcp-server-runtime.ts:272` | `3ec8646f1`: the bridged
tools' `readOnlyHint` / `destructiveHint` come from what the definition
declares, and a tool that declares nothing is served neither hint
(omit-when-unsourced). The line blames to `c39369d12`, the
`openWorldHint` sibling, whose changeset calls this the repair "that
preceded it". The PR that landed `3ec8646f1` answers 404 too. |
| `objectstack-ai#6724` | `mcp-server-runtime.ts:625`;
`mcp-server-runtime.metadata-outage.test.ts:289` | `4f3d2322e`: corrects
`diagnoseEmptyRead`'s falsified claim that `MetadataFacade.getObject`
differs from `get('object', n)`, in the TSDoc and in the outage test's
restatement of it. Both lines blame to it; PR objectstack-ai#6948, which landed it,
names objectstack-ai#6724. |
| `objectstack-ai#6745` | `mcp-server-runtime.ts:636` | `7a5ef0008`: adds
`metadata-service-getobject-equivalence.test.ts`, pinning `getObject(n)`
equal to `get('object', n)` across all three implementations. The line's
"PR objectstack-ai#6839 for objectstack-ai#6745" named this commit's PR (answers 200), which stays
beside the sha as a convenience link. The spec lane gave the number this
anchor. |
| `objectstack-ai#6723` | `mcp-server-runtime.ts:637`, `:652`;
`mcp-server-runtime.metadata-outage.test.ts:293` | `8ad609c69`: declares
on `IMetadataService.getObject` that it answers the same as
`get('object', name)`. `objectstack-ai#6723` was the pull request that landed as this
commit (its subject carries the number); `objectstack-ai#6505`, the issue beside it on
`:637`, answers 200 and stays. The spec lane gave the number this
anchor. |
| `objectstack-ai#17114` | `plugin.ts:8`, `:67`;
`stdio-tenancy-posture-api-key-matrix.test.ts:569` | `4af758d47`: the
last two admission doors, this one included, classify the tenancy
rejection through the shared `classifyAdmissionTenancyPosture`. All
three lines blame to it; PR objectstack-ai#17683 names objectstack-ai#17114, and stage 1 gave the
number this anchor. |
| `objectstack-ai#6216` | `plugin.ts:126`;
`__tests__/plugin-execution-context.test.ts:6` | `f586f1a89`: one
`ExecutionContext` assembler for the dispatcher, REST and share-link
sites. Both lines blame to `502dc6fe7`, which converged this stdio face
afterwards and names that convergence as its precedent. Its file list
touches no `packages/mcp` file, which is what `:7` ("not in that
commit's inventory") says. Stages 1 and 2 and the spec lane gave the
number this anchor. |
| `objectstack-ai#8422` | `stdio-data-bridge.ts:85`, `:394`;
`stdio-data-bridge.not-found.test.ts:4` | `4810dd628`: the stdio
bridge's by-id write seams throw the shared `recordNotFoundError`
envelope instead of a bare `Error`. All three lines blame to it; PR
objectstack-ai#8507 names objectstack-ai#8422. |
| `objectstack-ai#17568` | `mcp-record-id-key-mistake-refusal.test.ts:4` |
`9c9e6d08f`: pins that a missing-`recordId` refusal also names the `id`
the caller sent (test-only). The line blames to it; PR objectstack-ai#17650 names
objectstack-ai#17568. |
| `objectstack-ai#13486` | `mcp-tool-bridge-safety-annotations.test.ts:423` |
`6193e576d`: pins the bridge's two hand-copied safety name sets in the
direction the old pin could not see (the docblock's heading is that
commit's subject). The line blames to it; PR objectstack-ai#13888 names objectstack-ai#13486. |

**Anchor checks.** Every cited sha matches exactly one object (`git
rev-parse --disambiguate`, count 1 for each of the 9), is a commit, has
one parent, and is an ancestor of `main` (`merge-base --is-ancestor`
against `5757463712`, exit 0 for all 9). The checkout is not shallow.
The control leg `979ad9575` (2026-08-08, the parent of the oldest anchor
`8ad609c69` of 2026-08-08) exits 0, and the negative control, this
branch's own `459ff81088`, exits 1. Four anchors reuse the landed
stages' (`f586f1a89`, `4af758d47`, `7a5ef0008`, `8ad609c69`), so each
number carries one anchor across the tree; five are new (`3ec8646f1`,
`4f3d2322e`, `4810dd628`, `9c9e6d08f`, `6193e576d`).

**Numbers.** All 9 dropped numbers answer 404 by REST (re-probed
2026-09-29T19:54Z). The numbers kept on changed lines (`objectstack-ai#6839`, a pull
request; `objectstack-ai#6505`, `objectstack-ai#15348`, `objectstack-ai#16013`, `objectstack-ai#4435`, `objectstack-ai#5138`, `objectstack-ai#7867`) answer
200. Four slash-joined groups stand in `packages/mcp/src`, whose later
halves the citation grammar does not read (`objectstack-ai#4435/objectstack-ai#5138/objectstack-ai#7867` twice,
`objectstack-ai#5138/objectstack-ai#5581`, `objectstack-ai#7728/objectstack-ai#7823`); every half answers 200, so none is dead.

## Mechanical guard: no code token moves

**H2 holds on both readings: the parser leaf-token diff is empty, and
the emitted `dist` is byte-identical.**

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, JSDoc nodes excluded) of the 9 touched files at base
`e4e5222b7b` and at `459ff81088`. Controls mutate the head text in
memory only.
- Real run: 21,192 base tokens, 0 differing (exit 0).
- Comment-insertion control: 0 differing (exit 0).
- Code-insertion control: all 9 files differ at token 0 (exit 1).
- String control (the first character of the `'vitest'` import specifier
in `plugin-execution-context.test.ts` flipped): exactly 1 differing
`StringLiteral`, at token 15 of that file (exit 1).

**Emitted `dist`.** `pnpm --filter @objectstack/mcp build` at the head,
then at base (the base tree of `packages/mcp/src` restored in place
under a trap-armed restore; an on-disk probe read `objectstack-ai#13318` 1 and `commit
3ec8646` 0 before that build; afterwards every touched blob equals its
HEAD blob and `git diff HEAD` is empty), with the same dependency
builds:
- all six files (`index.cjs`, `index.cjs.map`, `index.d.cts`,
`index.d.ts`, `index.js`, `index.js.map`) are **byte-identical** by
sha256. The built files do carry docblocks (14 in `index.js`, 78 in
`index.d.ts`); none of the rewritten ones is on an emitted declaration.
- Code-mutation control (`scripts/ablation-replace.mjs`, anchor: the
sync leg's typed `ctx.getService` call on `'tenancy'` in `plugin.ts`,
hit 1 to 0, its argument renamed to a marker; blob restored to HEAD
`0a1aaa7955`, `git diff HEAD` empty):
`scripts/ablation-dist-preflight.mjs` found the marker in `index.cjs`
and `index.js`, and `index.cjs`, `index.js` and both `.map` files differ
from the head build. `dist` was then rebuilt, its six sha256 values
equal the first head build, and the preflight in `--absent` mode reads
the marker absent from all 6 files with a clean tree.

A raw scan of the 9 changed files for control bytes finds none (a
positive probe on a scratch file matched).

## Changeset

**None, and `skip-changeset`.** `@objectstack/mcp`'s `files[]` is
`dist`, `README.md` and `CHANGELOG.md`, and the build above emits
byte-identical `dist` at base and head, so this diff publishes nothing
from any released package. Stage 5 (PR objectstack-ai#20689) measured the same and
shipped the same; stage 6 (PR objectstack-ai#20703) measured the opposite and carried
a `patch`.

## Gates (head `7a0f15de62`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its disclosure, verbatim, from each run at this head and
from the four `dist` builds (at `459ff81088`, `packages/mcp/src`
byte-identical to this head):

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 25s · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/mcp...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 116s (1m56s) · declare it in the PR body · pnpm turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 10s · declare it in the PR body · pnpm --filter @objectstack/mcp exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 4s · declare it in the PR body · pnpm --filter @objectstack/mcp typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/mcp build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/mcp build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/mcp build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter @objectstack/mcp build
```

- **Build:** `@objectstack/mcp` with its closure (9 of 81 workspace
projects), then the whole workspace, `turbo run build
--filter='./packages/*' --filter='./packages/*/*'`, 71 of 71 tasks,
after the merge. The tree was clean after both.
- **Tests:** `vitest run`: 32 files, 344 tests passed (every `*.test.ts`
under `src/`), at the head and before the merge.
- **Typecheck:** `pnpm --filter @objectstack/mcp typecheck` exits 0.
`tsc --listFiles`: `tsconfig.json` compiles the 11 non-test `src` files,
`tsconfig.test.json` all 43 including the 32 test files.
`check:test-typecheck`: 6 files, 53 errors, 8 pinned signatures, held.
- **Lint:** the repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 at this head (2026-09-29T20:18:54Z to 20:19:23Z), and at
`459ff81088` before the merge.
- **Citation judging:** after merging `origin/main` (`9b384f63ae`),
`node scripts/check-issue-citations.mjs --base 9b384f6` judges 5
citations on the changed lines of 3 files (the kept numbers `objectstack-ai#15348`,
`objectstack-ai#16013`, `objectstack-ai#4435`, `objectstack-ai#6505`, and `objectstack-ai#6839` as a pull request) and exits 0:
every one resolves. Against `origin/main` after it moved to
`5757463712`, the same 5 citations, exit 0.
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 53 families. All 53 exit
0, and `--ran` with the exit-coded record reads "53 derived, 53 run, 0
NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:
`check:issue-citations`, `check:doc-authoring` (808 pinned sites, no
growth), `check:nul-bytes` (9,331 files, no raw control bytes),
`check:published-files`, `check:type-check-debt`.
- **Artifact rosters:** 36 of the 39 non-self-test roster rows exit 0,
including the three the derivation marks as keeping their roster under
one of this diff's paths (`check:authz-resolver`,
`check:error-code-casing`, `check:filter-alias-parity`). The other three
need a pull request's context; they are run against this PR once it
exists and reported on the card. The 18 self-test-only rows grade their
checkers' fixtures and cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `e4e5222b7b` the filtered census answers 10
sites on 10 lines, 7 numbers, in 3 files, as on the seat's `0be898499f`.
The whole-repo count is 1,222.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/mcp`. No site was left for an open PR (the file lists of all 8
open PRs were read at 20:08:05Z: only the Version Packages PR objectstack-ai#20639
touches `packages/mcp`, in `CHANGELOG.md` and `package.json`) or for an
unfound anchor.
- **H2 holds, on both readings.** The comment-stripped (parser-token)
diff of all 9 touched files is empty with its controls firing, and the
emitted `dist` is byte-identical at base and head with a code control
that changes it.

## Acceptance notes

- **Test titles, the form-D stage.** 4 dead numbers remain in test
string literals in `packages/mcp/src` (`describe` titles, no assertion
text): `objectstack-ai#17568` twice in `mcp-record-id-key-mistake-refusal.test.ts`
(`:151`, `:315`), `objectstack-ai#8422` in `stdio-data-bridge.not-found.test.ts:99`,
`objectstack-ai#17114` in `stdio-tenancy-posture-api-key-matrix.test.ts:592`. They
stay on the card for its form-D stage; no string moved here.
- **Outside `src/**`, a later stage of the card:**
`packages/mcp/vitest.config.ts:18` cites `objectstack-ai#8651` (404).
`packages/mcp/test-typecheck-debt.json:2` cites `objectstack-ai#13470` (404) inside
its `_comment` field, which the file itself says is generated by
`scripts/check-test-typecheck.mts`, so a fix there is at that producer,
in the `scripts/**` lane, not a hand edit. The other citations in
`packages/mcp` outside `src/**` (`CHANGELOG.md` excluded) answer 200.
- **Card-word residue, cited nowhere.** A few docblocks still say "this
card" or "the card" a paragraph away from the rewritten line (for
example `stdio-data-bridge.not-found.test.ts:19`,
`mcp-record-id-key-mistake-refusal.test.ts:19`,
`stdio-tenancy-posture-api-key-matrix.test.ts:580`, `:584`). They cite
no number, so they were left, as the landed stages left theirs; only the
one same-sentence companion (`plugin-execution-context.test.ts:7`) was
changed.
- **The moving `origin/main`.** The branch merged `origin/main` once
(`7a0f15de62`, merging `9b384f63ae`: `service-storage`,
`platform-objects` and `plugin-audit`, nothing in `packages/mcp`). A
later fetch advanced the shared ref to `5757463712`, one commit in
`platform-objects` translations. There was no second merge; CI judges
the merge ref.

## Deviations

- **One companion line (`plugin-execution-context.test.ts:7`)** beyond
the 17 sites, the second half of the `:6` sentence.
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it. The merge
commit carries git's default message.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…commits that decided them (objectstack-ai#20723)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 8 of the `domain:cli` lane of the dead-citation sweep:
`packages/qa`. `packages/qa` is a directory of five private workspace
packages, not one package, so the surface is `packages/qa/*/src/**`.
Every comment site there that cited a tracker number answering 404 now
cites, in ruling C+D's form C (comment 5749154545 on objectstack-ai#19123), the commit
in this repository's history that decided what the line describes. Each
line still says in its own words what that commit decided. PR objectstack-ai#20533 is
the method, and stages 1 to 7 of this card (PR objectstack-ai#20624, PR objectstack-ai#20632, PR
objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689, PR objectstack-ai#20703, PR objectstack-ai#20713) are the precedents.
The card stays open for the lane's remaining packages, so this PR says
`Part of`.

That is **12 sites on 12 lines in 5 files, covering 6 numbers**,
rewritten to **6 distinct commits**:
- the census's **8 sites**:
`downstream-contract/src/additional-domains.fixtures.ts` (2),
`http-conformance/src/adapter.ts` (4) and
`vitest-filter-preflight/src/index.ts` (2), 5 numbers;
- **4 test-file comment sites** in 2 test files under
`http-conformance/src/` (the census leaves `*.test.ts` out; stages 1 to
7 took test comments too).

Only comments changed: **12 lines out, 12 in**, and every touched file
keeps its line count, so no line citation into these files moves. **No
citation number is added.** Over the 12 line pairs, added-minus-removed
numbers is empty, and no PR number stands newly on any line. The two
numbers still on changed lines (`objectstack-ai#17978`, `objectstack-ai#14554`) were already on
them, and both answer 200.

**Two numbers have an ADR beside them, and both ADRs stay.**
- `objectstack-ai#6083`'s line already cited ADR-0122 phase 2. The ADR's own amendment
records phase 2, so the line now reads "ADR-0122 phase 2, commit
53068c1", the same pair spec stage 1 wrote in
`contracts/data-engine.ts`.
- `objectstack-ai#10485`'s line cites ADR-0049, the enforce-or-remove principle it was
retired under. No ADR records the theme retirement itself, so the commit
is the anchor, and the ADR stays beside it, as in the landed stages.

None of the other four numbers appears in `docs/adr/` or
`scripts/adr-anchors/`. The grep reads 0 hits for them. The control,
`objectstack-ai#5551`, reads 1 hit in ADR-0122.

**No changeset, and `skip-changeset`.** None of the three touched
packages publishes anything (see Changeset below).

## Census: `packages/qa`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run under `with-fleet.sh
--read` for the token. The count is its `allocated-but-absent` findings
under `packages/qa/`. Both runs enumerated the whole board.

| reading | tree | board | whole-repo `allocated-but-absent` |
`packages/qa` sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `679f95ec5c`, run 2026-09-29T21:05:44Z to 21:09:44Z |
enumerated, 186 pages, frontier objectstack-ai#20718, 18,545 numbers | 1,185 | **8** |
8 | 5 | 3 |
| after | `30aae6a3e6`, run 21:18:38Z to 21:22:42Z | enumerated, 186
pages, frontier objectstack-ai#20720, 18,547 numbers | 1,177 | **0** | 0 | 0 | 0 |

The whole-repo drop of 8 is exactly these sites. A site-by-site diff of
the two JSON outputs has 8 findings gone, all under `packages/qa/*/src`,
and none added. The other three tallies are equal in both runs:
`resolves` 32,982, `resolves-as-pull-request` 1,984 and
`cross-repo-unjudged` 995. `packages/qa/*/src` is byte-identical at
`30aae6a3e6` and at the head; the two later commits are merges of
`origin/main` that touch nothing in `packages/qa`.

**Supplementary scan (test files and everything outside `src/`
included).** The gate's exported `extractCitations` and
`classifyCitation` ran over all 221 tracked files under `packages/qa`
(`CHANGELOG.md` excluded), with the board from the gate's own
`probeBoard`. The totals are 1,678 citations and 139 dead before, and
1,666 and 127 after.
- Under `src/`, before: src comments 40 / 8 dead, test comments 42 / 4,
src strings 1 / 0, test strings 9 / 0.
- Under `src/`, after: src comments 32 / 0, test comments 38 / 0,
strings unchanged. Nothing dead is left under any `src/`, strings
included, so there is no form-D residue in this stage's surface.
- Its before list of src comment sites is identical to the census's.
- The 127 left are all outside `src/**` (see Acceptance notes).

## Per-site table

`git blame` at the base ties each line to the commit that wrote it. Each
anchor was read in its message, changeset or diff, not only its subject.
Where the pull request that landed an anchor still answers, its body's
first line names the dead number, and that is noted.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#6083` | `downstream-contract/src/additional-domains.fixtures.ts:11`
| `53068c130`, ADR-0122 phase 2: the bare type name becomes the AUTHOR
state (`z.input`) and the `XInput` synonyms retire. The same commit
moved these frozen fixtures' annotations onto the bare names without
touching a literal, which is what the paragraph says. The line blames to
it, and its subject carries the number. The PR that landed it answers
404, and spec stage 1 gave the number this anchor. |
| `objectstack-ai#10485` |
`downstream-contract/src/additional-domains.fixtures.ts:133` |
`35ad101bc`: retires the `themes` carrier key and `ThemeSchema` whole,
under ADR-0049, and drops `DcTheme` from these fixtures. The line blames
to it, and its subject carries the number. The spec, rest, runtime and
cli stages gave the number this anchor. |
| `objectstack-ai#6143` | `http-conformance/src/adapter.ts:32`, `:189`, `:257`,
`:346`; `http-conformance/src/fallback-seam.conformance.test.ts:4`,
`:27` | `12298c7d6`, which does two things: `NodeHttpServer` implements
the optional `setFallbackHandler` out of its own router, as a field
consulted in the route-miss branch, with the 405 answer extracted for
its second call site; and the cross-adapter suite asserts the contract's
four guarantees on both adapters. All six lines blame to it. PR objectstack-ai#6851,
which landed it, names objectstack-ai#6143 on its first line. |
| `objectstack-ai#6307` |
`http-conformance/src/query-multiplicity.conformance.test.ts:76`, `:296`
| `293476148`: refuses a repeated `?version=` on `GET` / `DELETE
/packages/:id`, and adds `package-routes-query-multiplicity.test.ts`.
Its changeset records the measured read: on `DELETE`, a repeated value
skipped the full-uninstall branch, and the call still reported success.
The lines blame to the later `68feaadd6` and `7cdbcbb30`, which cite
this earlier work by number. PR objectstack-ai#6895, which landed the anchor, names
objectstack-ai#6307 on its first line. The rest stage gave the number this anchor. |
| `objectstack-ai#17853` | `vitest-filter-preflight/src/index.ts:5` | `08f5f0e5a`: a
vitest file filter that selects nothing says so, even when the rest of
the run selects something. This is the first implementation, in
`packages/cli`. The line blames to `c667d8c80`, the shared port for all
eight project-declaring packages; its number is `objectstack-ai#17978`, which answers
200 and stays. PR objectstack-ai#17965, which landed the anchor, names objectstack-ai#17853 on its
first line. |
| `objectstack-ai#13504` | `vitest-filter-preflight/src/index.ts:273` | `44813ba57`:
splits `packages/cli`'s suite into the named `unit` and `integration`
tiers, decided on behaviour, with the partition pin. That is half of the
"tier walk" this sentence names, and its diff heads the new section with
this number. `objectstack-ai#14554`, the derived-population half, answers 200 and
stays. The only commit whose subject carries `objectstack-ai#13504` is `55519d503`,
the comment-only measurement half: PR objectstack-ai#13872 says it lands only that
half. So that commit is not the anchor for this sentence. The PR that
landed `44813ba57` answers 404. |

**Anchor checks.** Every cited sha matches exactly one object (`git
rev-parse --disambiguate`, count 1 for each of the 6). Each is a commit
with one parent, and each is an ancestor of `main` (`merge-base
--is-ancestor` against `cbaf04c1fd`, exit 0 for all 6). The checkout is
not shallow. The control leg `3cc8676e1` (2026-08-08, the parent of the
oldest anchor `53068c130` of 2026-08-08) exits 0, and the negative
control, this branch's own `06b8fbc2d3`, exits 1. Three anchors reuse
the landed stages' (`53068c130`, `35ad101bc`, `293476148`), so each
number carries one anchor across the tree. Three are new (`12298c7d6`,
`08f5f0e5a`, `44813ba57`).

**Numbers.** All 6 dropped numbers answer 404 by REST (probed
2026-09-29T21:16:49Z). The numbers kept on changed lines (`objectstack-ai#17978`,
`objectstack-ai#14554`) answer 200. No slash-joined citation group stands in
`packages/qa/*/src`.

## Mechanical guard: no code token moves

**H2 holds on the parser-token reading.** The emitted-`dist` reading
does not apply, because none of these packages has a build (see
Changeset below).

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, `getChildren` walked to the leaves, JSDoc nodes
excluded) of the 5 touched files at base `679f95ec5c` and at
`30aae6a3e6`. Controls mutate the head text in memory only.
- Real run: 7,917 base tokens, 0 differing (exit 0).
- Comment-insertion control: 0 differing (exit 0).
- Code-insertion control: all 5 files differ at token 0 (exit 1).
- String control (the first character of the `'vitest'` import specifier
in `fallback-seam.conformance.test.ts` flipped): exactly 1 differing
`StringLiteral`, at token 11 of that file (exit 1).

Every one of the 24 changed lines is a `//` or `*` comment line. A raw
scan of the 5 changed files for control bytes finds none (a positive
probe on a scratch file matched).

## Changeset

**None, and `skip-changeset`.** There is no `@objectstack/qa` package.
The three touched packages are `@objectstack/downstream-contract`,
`@objectstack/http-conformance` and
`@objectstack/vitest-filter-preflight`. Each is `"private": true`, has
no `build` script, no `files[]` and no `dist/`. `.changeset/config.json`
versions private packages but never tags or publishes them. This diff
therefore publishes nothing from any released package, so there is no
`dist` to compare and no code-mutation control to run. The measurement
is the packages' own manifests.

## Gates (head `06b8fbc2d3`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its disclosure, verbatim, from each run at this head, and
from the closure build at `527d5dca06` (the first merge; `packages/qa`
is byte-identical between the two):

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 77s (1m17s) · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/downstream-contract^...' --filter '@objectstack/http-conformance^...' --filter '@objectstack/vitest-filter-preflight^...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 11s · declare it in the PR body · pnpm turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter @objectstack/downstream-contract exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/downstream-contract typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 8s · declare it in the PR body · pnpm --filter @objectstack/http-conformance exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 4s · declare it in the PR body · pnpm --filter @objectstack/http-conformance typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 4s · declare it in the PR body · pnpm --filter @objectstack/vitest-filter-preflight exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 1s · declare it in the PR body · pnpm --filter @objectstack/vitest-filter-preflight typecheck
```

- **Build.** The three packages' dependency closure was built: 61 of 81
workspace projects, at `30aae6a3e6` and again at `527d5dca06`. Then the
whole workspace was built with `turbo run build --filter='./packages/*'
--filter='./packages/*/*'`: 71 of 71 tasks at this head, 66 of them
cache hits. The tree was clean after each build.
- **Tests (`vitest run`), at this head and at both earlier commits:**
  - `downstream-contract`: 3 files, 31 tests passed;
  - `http-conformance`: 8 files, 102 tests passed;
  - `vitest-filter-preflight`: 3 files, 111 tests passed.
  - These are every test file each package has.
- **Typecheck.** All three `typecheck` scripts exit 0;
`downstream-contract`'s is also one of CI's consumer-gate type-check
lanes. `http-conformance`'s `check:test-typecheck` holds: 3 files, 27
errors, 10 pinned signatures. `tsc --listFiles` shows every touched file
compiled:
  - `downstream-contract/tsconfig.json`: 11 files, 3 of them tests;
- `http-conformance/tsconfig.test.json`: 11 files, all 8 tests,
including both touched test files and `adapter.ts`;
  - `vitest-filter-preflight/tsconfig.json`: 6 files, 3 of them tests.
- **Lint.** The repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 at this head (2026-09-29T21:48:59Z to 21:49:26Z), and at
`527d5dca06` before the second merge.
- **Citation judging.** `node scripts/check-issue-citations.mjs --base
origin/main`, with `origin/main` at `cbaf04c1fd` and merged, judges 2
citations on the changed lines of 3 files (the kept `objectstack-ai#17978` and
`objectstack-ai#14554`). Both resolve, and the run exits 0. The pinned merged base of
the first merge (`--base 1ab9892`, at `527d5dca06`) gives the same 2
citations and also exits 0.
- **Derived gates.** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 53 families, identical at
`527d5dca06` and at this head. All 53 exit 0 at this head. `--ran` with
the exit-coded record reads "53 derived, 53 run, 0 NOT-MEASURED, 0
UNRUN" (a derived zero). Among them:
  - `check:issue-citations`;
  - `check:doc-authoring` (808 pinned sites, no growth);
  - `check:nul-bytes` (9,342 text files, no raw control bytes);
- `check:published-files`, `check:type-check-coverage` and
`check:type-check-debt`.
- **Artifact rosters.** 36 of the 39 non-self-test roster rows exit 0.
These include the three the derivation marks as keeping their roster
under one of this diff's paths (`check:authz-resolver`,
`check:error-code-casing`, `check:filter-alias-parity`). The other three
need a pull request's context; they are run against this PR once it
exists, and the results are reported on the card. The 18 self-test-only
rows grade their checkers' fixtures and cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `679f95ec5c` the filtered census answers 8 sites
on 8 lines, 5 numbers, in 3 files, as on the seat's `0be898499f`. The
whole-repo count is 1,185.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/qa`. No site was left for an open PR or for an unfound anchor.
The file lists of all 12 open PRs were read at 2026-09-29T21:13:53Z:
only the Version Packages PR objectstack-ai#20639 touches `packages/qa`, in
`CHANGELOG.md` and `package.json`.
- **H2 holds on the parser-token reading.** The comment-stripped
(parser-token) diff of all 5 touched files is empty, and its controls
fire. The `dist` reading is not available, because none of the packages
has a build.

## Acceptance notes

- **`packages/qa` outside `src/**`, a later stage of the card.** The
census surface is `packages/**/src/**`, and `packages/qa/dogfood` has no
`src/` at all. The supplementary scan counts 127 dead sites left in
`packages/qa` outside `src/**`:
- `dogfood/test/**` and `dogfood/vitest.config.ts`: 122 sites, 27
numbers, 28 files (94 comments, 28 strings);
- `downstream-contract/test/contract.test.ts:46` (`objectstack-ai#10485`, a comment);
- `vitest-filter-preflight/test/config-wiring-sweep.test.ts:6` and
`test/filter-preflight.test.ts:5` (`objectstack-ai#17853`, comments);
- `vitest-filter-preflight/package.json:6` (`objectstack-ai#17853`, in the package
`description`);
- `http-conformance/test-typecheck-debt.json:2` (`objectstack-ai#13470`, in the
generated `_comment`, whose producer is
`scripts/check-test-typecheck.mts`; that producer is objectstack-ai#20715's, and it is
never fixed by hand).

  None of them is in this stage's surface, and none moved.
- **ADR-0122's own status line and amendment heading** cite `objectstack-ai#6083`
(404). `docs/adr/**` is a governed surface and one of the gate's
deferred surfaces, so it is noted here, not touched.
- **Card-word residue, cited nowhere.**
`vitest-filter-preflight/src/index.ts:117` says "this card" about 150
lines from either rewritten line. It cites no number, so it was left, as
the landed stages left theirs.
- **The moving `origin/main`.** The branch merged `origin/main` twice.
The first merge (`527d5dca06`) took `1ab98926b0` (a spec retirement,
nothing in `packages/qa`). After it, the shared ref advanced to
`cbaf04c1fd`, the plugin-approvals re-anchor (PR objectstack-ai#20717). Against that
moved ref, `--base origin/main` then read the old plugin-approvals lines
as this branch's additions: it judged 31 citations and exited 2, because
the diff was two-dot. That run is not a measurement of this change. The
pinned base answered exit 0. The second merge (`06b8fbc2d3`) took
`cbaf04c1fd`, and every gate above was re-run on it. CI judges the merge
ref.

## Deviations

- **The dispatch's `packages/qa/src/**` and `@objectstack/qa`** do not
exist as spelled. The surface was read as `packages/qa/*/src/**`, the
census's own reading of `packages/**/src/**`. The changeset measurement
was taken per touched package.
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it. The two
merge commits carry git's default message.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…ges/cloud-connection/src to the commits that decided them (objectstack-ai#20735)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 9 of the `domain:cli` lane of the dead-citation sweep:
`packages/cloud-connection/src`. Every comment site there that cited a
tracker number answering 404 now cites, in ruling C+D's form C (comment
5749154545 on objectstack-ai#19123), the commit in this repository's history that
decided what the line describes, and keeps saying in its own words what
that commit decided. PR objectstack-ai#20533 is the method, and stages 1 to 8 of this
card (PR objectstack-ai#20624, PR objectstack-ai#20632, PR objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689, PR objectstack-ai#20703,
PR objectstack-ai#20713, PR objectstack-ai#20723) are the precedents. The card stays open for the
lane's remaining packages, so this PR says `Part of`.

That is **10 sites on 10 lines in 3 files, covering 3 numbers**,
rewritten to **3 distinct commits**:
- the census's **5 sites**, all in
`src/marketplace-install-local-plugin.ts` (3 numbers);
- **5 test-file comment sites** in 2 test files (the census defers
`*.test.ts`; stages 1 to 8 took test comments too).

Only comments changed: **10 lines out, 10 in**, and every touched file
keeps its line count (1,969 / 377 / 308), so no line citation into these
files moves. **No citation number is added**: over the 10 line pairs,
added-minus-removed numbers is empty, and no PR number stands on an
added line. No ADR or ruling-record file in `docs/adr/` or
`scripts/adr-anchors/` records any of these 3 decisions (a grep for the
3 numbers there reads 0 hits, with a control number from the same tree,
`objectstack-ai#7329`, reading 1), so every anchor is a commit.

A **`patch` changeset** for `@objectstack/cloud-connection` rides along,
because the rewritten docblocks reach `dist` (measured below). That is
stage 6's case (PR objectstack-ai#20703), not stages 5 and 7's.

## Census: `packages/cloud-connection`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run under `with-fleet.sh
--read` for the token. The count is its `allocated-but-absent` findings
under `packages/cloud-connection/`. Both runs enumerated the whole
board.

| reading | tree | board | whole-repo `allocated-but-absent` |
`packages/cloud-connection` sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `b291fcdae9`, run 2026-09-29T22:34:12Z to 22:38:18Z |
enumerated, 186 pages, frontier objectstack-ai#20731, 18,558 numbers | 1,153 | **5** |
5 | 3 | 1 |
| after | `4a1f38a4e6`, run 22:44:08Z to 22:47:58Z | enumerated, 186
pages, frontier objectstack-ai#20731, 18,558 numbers | 1,148 | **0** | 0 | 0 | 0 |

The whole-repo drop of 5 is exactly these sites: a site-by-site diff of
the two JSON outputs has 5 findings gone, all in
`packages/cloud-connection/src/marketplace-install-local-plugin.ts`, and
none added. The other three tallies (`resolves` 32,994,
`resolves-as-pull-request` 1,984, `cross-repo-unjudged` 995) are equal
in both runs. `packages/cloud-connection/src` is byte-identical at
`4a1f38a4e6` and at the head.

**Supplementary scan (test files included).** The gate's exported
`extractCitations` and `classifyCitation` over all 44 `.ts` files under
`src/`, with the board from the gate's own `probeBoard`: 301 citations
and 14 dead before (src comments 5, test comments 5, src strings 1, test
strings 3), 291 and 4 after (0, 0, 1, 3). Its before list of src comment
sites is identical to the census's. The 4 left are strings, the form-D
stage (see Acceptance notes).

## Per-site table

`git blame` at the base ties each line to the commit that wrote it, and
each anchor was read in its message, changeset or diff, not only its
subject.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#9011` | `marketplace-install-local-plugin.ts:35`, `:1001`, `:1821`;
`marketplace-install-local-capability-enumeration.test.ts:50`, `:303`;
`marketplace-install-local-list-posture.test.ts:4`, `:302` |
`01074e551`: the install-local listing requires an authenticated
principal (anonymous gets 401) and serves `installedBy` / `storageDir`
only to a `manage_metadata` holder, the maintainer's 2026-08-16 "Option
3" that `:1008` still names; it also extracts the one
`refuseUnauthenticated` 401 envelope that `:1821` describes. All seven
lines blame to it. The PR that landed it (PR objectstack-ai#9256, which answers 200)
names objectstack-ai#9011 on its first line. `list-posture.test.ts:302` now reads "The
wire shape before commit 01074e5" for "The pre-(number) wire shape". |
| `objectstack-ai#8919` | `marketplace-install-local-plugin.ts:98`;
`marketplace-install-local-capability-enumeration.test.ts:40` |
`b5378550e`: gates the `/meta` publish and rollback promotion verbs on
`manage_metadata` and adds
`meta-write-door-capability-enumeration.test.ts`, the enumeration pin
`:40` names as its precedent. Both lines blame to `e0695b582`, the
commit that gated the four mutating install-local doors for objectstack-ai#8976 (which
answers 200), whose message cites this gate as the precedent. Stages 2
and 5 gave the number this anchor. The PR that landed `b5378550e`
answers 404 too. |
| `objectstack-ai#13279` | `marketplace-install-local-plugin.ts:1813` | `6a180e42d`: a
failed permission-store read raises `AuthzStoreUnavailableError` instead
of resolving as an unauthenticated or capability-less principal, and
each fail-closed transport `catch` re-raises it. The line blames to it;
PR objectstack-ai#13475 names objectstack-ai#13279. Stages 1, 2 and 4 gave the number this anchor. |

**Anchor checks.** Every cited sha matches exactly one object (`git
rev-parse --disambiguate`, count 1 for each of the 3), is a commit, has
one parent, and is an ancestor of `main` (`merge-base --is-ancestor`
against `36d043be17`, exit 0 for all 3). The checkout is not shallow.
The control leg `818fcafda` (2026-08-16, the parent of the oldest anchor
`b5378550e` of 2026-08-16) exits 0, and the negative control, this
branch's own `16a88d69b2`, exits 1. Two anchors reuse the landed stages'
(`b5378550e`, `6a180e42d`), so each number carries one anchor across the
tree; one is new (`01074e551`).

**Numbers.** All 3 dropped numbers answer 404 by REST (probed
2026-09-29T22:40:35Z). The numbers kept near the changed lines (`objectstack-ai#8976`,
`objectstack-ai#15353`) answer 200. Three slash-joined groups stand in
`packages/cloud-connection/src`, whose later halves the citation grammar
does not read (`objectstack-ai#6603/objectstack-ai#7020`, `objectstack-ai#4127/objectstack-ai#4251` twice); every half answers
200, so none is dead.

## Mechanical guard: no code token moves

**H2 holds on the comment-stripped reading; the emitted `dist` is NOT
byte-identical, because the docblocks ship.**

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, JSDoc nodes excluded) of the 3 touched files at base
`b291fcdae9` and at `4a1f38a4e6`. Controls mutate the head text in
memory only.
- Real run: 12,349 base tokens (8,351 / 2,246 / 1,752), 0 differing
(exit 0 for each file).
- Comment-insertion control: 0 differing (exit 0).
- Code-insertion control: all 3 files differ (exit 1).
- String control (`'Authentication required.'` to `'Authentication
requireD.'` in `refuseUnauthenticated`): exactly 1 differing
`StringLiteral`, at token 7,973 of `marketplace-install-local-plugin.ts`
(exit 1).

**Emitted `dist`.** `pnpm --filter @objectstack/cloud-connection build`
at the head, then at base (the base tree of
`packages/cloud-connection/src` restored in place under a trap-armed
restore; an on-disk probe read `[objectstack-ai#13279]` 1 and `commit 6a180e4` 0
before that build; afterwards every touched blob equals its HEAD blob
and `git diff HEAD` is empty), with the same dependency builds:
- `index.cjs`, `index.js`, `index.d.ts` and `index.d.cts` differ;
`index.cjs.map` and `index.js.map` are equal.
- The same parser comparison over the four differing `dist` files reads
0 differing tokens (19,465 / 18,741 / 16,868 / 16,868), so the whole
`dist` delta is comment text. Its code control (a code line appended
after a newline) reads COUNT DIFFERS in each.
- The new wording is in `dist`: "commit 01074e5" appears 2 times in
`index.js` and `index.cjs` and 3 times in each declaration file, where
the base build carries `objectstack-ai#9011` in the same places.
- Code-mutation control (`scripts/ablation-replace.mjs`, anchor
`'Authentication required.'` hit 1 to 0, planted marker 0 to 1, blob
`2ef0f0ae8bac` to `77c3cef6324b`; `scripts/ablation-dist-preflight.mjs`
found the marker in `dist`): `index.cjs`, `index.js` and both `.map`
files differ from the head build. The blob was restored to HEAD
`2ef0f0ae8bac` with `git diff HEAD` empty, `dist` was rebuilt, its six
sha256 values equal the first head build, and the preflight in
`--absent` mode reads the marker absent from all 6 files with a clean
tree.

A raw scan of the 4 changed files for control bytes finds none (a
positive probe on a scratch file matched).

## Changeset

**`patch` for `@objectstack/cloud-connection`**
(`.changeset/cloud-connection-provenance-anchors.md`), in PR objectstack-ai#20632's
form. `@objectstack/cloud-connection`'s `files[]` is `dist`, `README.md`
and `CHANGELOG.md`, and the build above emits different `index.js` /
`index.cjs` / `index.d.ts` / `index.d.cts` at base and head, so this
diff publishes. `check-changeset-no-major`, `check-empty-changeset`,
`check-adr-0087-registration` and `check-changeset-fixed` all exit 0.

## Gates (head `16a88d69b2`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its disclosure, verbatim, from each run (the closure
build at `4a1f38a4e6`, whose `packages/cloud-connection` and dependency
closure are byte-identical to this head; the whole-workspace build, the
tests and the typecheck at this head; the three `dist` builds at
`4a1f38a4e6`, whose `packages/cloud-connection/src` is byte-identical to
this head):

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 59s · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/cloud-connection...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 118s (1m58s) · declare it in the PR body · pnpm turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 11s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 2 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm exec tsc --noEmit -p tsconfig.json --listFiles
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection build
```

- **Build:** `@objectstack/cloud-connection` with its closure (33 of 81
workspace projects), then the whole workspace, `turbo run build
--filter='./packages/*' --filter='./packages/*/*'`, 71 of 71 tasks,
after the merge. The tree was clean after both, and the package's six
`dist` files after the whole build equal the first head build by sha256.
- **Tests:** `vitest run`: 30 files, 397 tests passed (every `*.test.ts`
under `src/`), at this head and before the merge.
- **Typecheck:** `@objectstack/cloud-connection` has no `typecheck`
script; it is a `DEBT` entry in `scripts/check-type-check-coverage.mjs`
(13 errors: 11 TS2493, 2 config-tier). `tsc --noEmit -p tsconfig.json`
exits 2 with exactly those 13 (11 TS2493, 2 TS2550), all in three test
files this PR does not touch (`cloud-connection-plugin.test.ts` 4,
`connection-credential-store.test.ts` 7,
`marketplace-install-local-bundle.test.ts` 2). `--listFiles` compiles
all three touched files and all 30 test files. `check:type-check-debt`
and `check:type-check-coverage` exit 0, and the `dist` build's DTS step,
this package's type gate, succeeds.
- **Lint:** the repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 at this head (2026-09-29T23:01:12Z to 23:01:39Z).
- **Citation judging:** after merging `origin/main` (`36d043be17`),
`node scripts/check-issue-citations.mjs --base origin/main` reports "no
issue citations added against 36d043b (1 file(s) read)" (exit 0);
pinned `--base 36d043b` reads the same.
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 61 families. All 61 exit
0, and `--ran` with the exit-coded record reads "61 derived, 61 run, 0
NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:
`check:issue-citations`, `check:doc-authoring`, `check:nul-bytes`,
`check:published-files`, `check:type-check-debt`,
`check-adr-0087-registration`, `check-empty-changeset`.
- **Artifact rosters:** 36 of the 39 non-self-test roster rows exit 0,
including the four the derivation marks as keeping their roster under
one of this diff's paths (`check-changeset-fixed`,
`check:authz-resolver`, `check:error-code-casing`,
`check:filter-alias-parity`). The other three need a pull request's
context; they are run against this PR once it exists and reported on the
card. The 18 self-test-only rows grade their checkers' fixtures and
cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `b291fcdae9` the filtered census answers 5 sites
on 5 lines, 3 numbers, all in `src/marketplace-install-local-plugin.ts`,
as on the seat's `0be898499f`. The whole-repo count is 1,153.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/cloud-connection`. No site was left for an open PR (the file
lists of all 10 open PRs were read at 2026-09-29T22:41:18Z: only the
Version Packages PR objectstack-ai#20639 touches `packages/cloud-connection`, in
`CHANGELOG.md` and `package.json`) or for an unfound anchor.
- **H2 holds on the token reading, not on the `dist` reading.** The
parser leaf-token diff of all 3 touched files is empty with its controls
firing. The emitted `dist` differs, and the difference is comment text
only (token-identical `dist` with a code control). That is why the
changeset ships.

## Acceptance notes

- **Strings, the form-D stage.** 4 dead numbers remain in string
literals in `packages/cloud-connection/src`: `objectstack-ai#9011` in the three
`describe` titles of `marketplace-install-local-list-posture.test.ts`
(`:206`, `:247`, `:287`, no assertion text), and `objectstack-ai#9011` in the `note`
string of the `GET /api/v1/marketplace/install-local` row of
`cloud-connection-route-ledger.ts` (`:215`), a runtime string already
recorded in `scripts/doc-authoring-prose-id.baseline.json`. They stay on
the card for its form-D stage; no string moved here.
- **Outside `src/**`, a later stage of the card:**
`packages/cloud-connection/vitest.config.ts:64` cites `objectstack-ai#16917` (404).
The other citations in `packages/cloud-connection` outside `src/**`
(`CHANGELOG.md` excluded) answer 200: `README.md:108` (`objectstack-ai#10805`,
`objectstack-ai#12681`) and `vitest.config.ts` (`objectstack-ai#10374`, `objectstack-ai#11480`, `objectstack-ai#7668/objectstack-ai#7778`,
`objectstack-ai#7955`, `objectstack-ai#10374/objectstack-ai#13522`).
- **Card-word residue, cited nowhere.** A few docblocks still say "this
card's ruling" or "That ruling has since landed" a paragraph away from a
rewritten line
(`marketplace-install-local-capability-enumeration.test.ts:48`,
`marketplace-install-local-list-posture.test.ts:12`). They cite no
number, so they were left, as the landed stages left theirs.
- **The moving `origin/main`.** The branch merged `origin/main` once
(`16a88d69b2`, merging `36d043be17`: `service-automation` and two
changesets, nothing in `packages/cloud-connection` or its dependency
closure).

## Deviations

- **The first token-guard run was void.** It looped over the touched
files in a zsh shell, which does not word-split an unquoted variable, so
each invocation received all three paths as one argument and read
nothing; it was rerun under bash before any reading was used.
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it. The merge
commit carries git's default message.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

---------

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…kages/plugins/plugin-hono-server/src to the commits that decided them (objectstack-ai#20741)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 10 of the `domain:cli` lane of the dead-citation sweep:
`packages/plugins/plugin-hono-server/src`. Every comment site there that
cited a tracker number answering 404 now cites, in ruling C+D's form C
(comment 5749154545 on objectstack-ai#19123), the commit in this repository's history
that decided what the line describes, and keeps saying in its own words
what that commit decided. PR objectstack-ai#20533 is the method, and stages 1 to 9 of
this card (PR objectstack-ai#20624, PR objectstack-ai#20632, PR objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689, PR
objectstack-ai#20703, PR objectstack-ai#20713, PR objectstack-ai#20723, PR objectstack-ai#20735) are the precedents. The card
stays open for the lane's remaining packages, so this PR says `Part of`.

That is **24 sites on 24 lines in 5 files, covering 5 numbers**,
rewritten to **5 distinct commits**:
- the census's **5 sites**: `src/adapter.ts` 4,
`src/current-user-endpoints.ts` 1 (4 numbers);
- **19 test-file comment sites** in 3 test files (the census defers
`*.test.ts`; stages 1 to 9 took test comments too):
`ui-plugin-auto-discovery.pin.test.ts` 16,
`handler-throw-declared-envelope.test.ts` 2,
`current-user-endpoints-localization.test.ts` 1.

Only comments changed: **24 lines out, 24 in**, every one of them a site
(no companion line), and every touched file keeps its line count (1,660
/ 1,020 / 335 / 403 / 697), so no line citation into these files moves.
**No citation number is added**: over the 24 line pairs, the added
numbers are a subset of the removed ones (`objectstack-ai#16599` x2, `objectstack-ai#9864`,
`objectstack-ai#16334`, all answering 200, stay where they stood), and no PR number
stands on an added line. No ADR or ruling-record file in `docs/adr/` or
`scripts/adr-anchors/` records any of these 5 decisions (a grep for the
5 numbers there reads 0 hits; the control number `objectstack-ai#7329` reads 1 in the
same tree), so every anchor is a commit.

A **`patch` changeset** for `@objectstack/plugin-hono-server` rides
along, because one rewritten comment reaches `dist` (measured below).
That is stage 6's and stage 9's case (PR objectstack-ai#20703, PR objectstack-ai#20735), not stages
5 and 7's.

## Census: `packages/plugins/plugin-hono-server`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run under `with-fleet.sh
--read` for the token. The count is its `allocated-but-absent` findings
under `packages/plugins/plugin-hono-server/`. Both runs enumerated the
whole board.

| reading | tree | board | whole-repo `allocated-but-absent` | package
sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `f927864ea0`, run 2026-09-29T23:42:29Z to 23:46:56Z |
enumerated, 186 pages, frontier objectstack-ai#20735, 18,562 numbers | 1,105 | **5** |
5 | 4 | 2 |
| after | `91ce7e5e8f`, run 23:58:22Z to 2026-09-30T00:02:19Z |
enumerated, 186 pages, frontier objectstack-ai#20737, 18,564 numbers | 1,100 | **0** |
0 | 0 | 0 |

The whole-repo drop of 5 is exactly these sites: a site-by-site diff of
the two JSON outputs has 5 findings gone (`adapter.ts:225`, `:227`,
`:308`, `:349`; `current-user-endpoints.ts:448`) and none added. The
other three tallies (`resolves` 33,003, `resolves-as-pull-request`
1,984, `cross-repo-unjudged` 995) are equal in both runs.
`packages/plugins/plugin-hono-server` is byte-identical at `91ce7e5e8f`
and at the head.

**Supplementary scan (test files, strings and files outside `src/`
included).** The gate's exported `extractCitations` and
`classifyCitation` over all 41 tracked files of the package
(`CHANGELOG.md` excluded), comment-prose and whole-file projections,
with the board from the gate's own `probeBoard`: 347 citations and 32
dead before, 323 and 8 after. Under `src/`: comments 5 dead to 0, test
comments 19 to 0, strings 0 and test strings 2 unchanged. Its before
list of `src/` comment sites equals the census's. The 8 left are 2 test
strings and 6 sites outside `src/` (see Acceptance notes).

## Per-site table

`git blame` at the base ties each line to the commit that wrote it, and
each anchor was read in its message, changeset or diff, not only its
subject.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#13279` | `adapter.ts:225`, `:227`;
`handler-throw-declared-envelope.test.ts:84`;
`current-user-endpoints-localization.test.ts:90` | `6a180e42d`:
`tryFind` in `resolveAuthzContext` raises `AuthzStoreUnavailableError`
(503 `SERVICE_UNAVAILABLE`) when a permission-store read is issued and
throws, instead of answering it as an empty read, and each fail-closed
transport `catch` (`requireDatasourceAdmin` in `service-datasource`
among them) re-raises it: an unreadable store licenses no verdict, the
maintainer's 2026-08-30 ruling recorded in its message. The first three
lines blame to `cefe068702` (the declared-envelope rendering, PR objectstack-ai#17412)
and the fourth to `5f7fa1de0`; both wrote them citing this ruling. PR
objectstack-ai#13475 (200) names objectstack-ai#13279. Stages 1, 2, 4 and 9 gave the number this
anchor. |
| `objectstack-ai#9934` | `adapter.ts:308`;
`handler-throw-declared-envelope.test.ts:152` | `79c46da90`: the
producer-side user-facing marking for hook refusals, the `userMessage`
channel, a text field a producer sets at throw time and every classified
envelope carries. Both lines blame to `cefe068702`. The PR that landed
it (PR objectstack-ai#9992) answers 404 too. Stages 1, 2, 4 and 6 gave the number this
anchor. |
| `objectstack-ai#6307` | `adapter.ts:349` | `293476148`: refuse a repeated
`?version=` on `GET`/`DELETE /packages/:id` rather than pick one value,
through `readSingleQueryValue`, which it introduces. The line blames to
`7cdbcbb306` (surface repeated query parameters as arrays, PR objectstack-ai#7396),
which says it follows that direction. Stages 2 and 8 gave the number
this anchor. |
| `objectstack-ai#6216` | `current-user-endpoints.ts:448` | `f586f1a89`: one
`ExecutionContext` assembler with two named anonymous entries,
`assembleExecutionContext` the default, fail-closed one and
`assembleExecutionContextOrGuest` the explicit guest one, the
maintainer's 2026-08-08 Option A recorded in its docblock. The line
blames to `6615a024c3` (the current-user faces adopt the shared
assembler). Stages 1, 2 and 7 gave the number this anchor. |
| `objectstack-ai#16721` | `ui-plugin-auto-discovery.pin.test.ts:27`, `:37`, `:42`,
`:180`, `:211`, `:217`, `:360`, `:363`, `:495`, `:498`, `:594`, `:596`,
`:604`, `:608`, `:631`, `:646` | `51ae73123`: `LiteKernel.use()` runs
the same `assertPluginContract` as `ObjectKernel.use()` and refuses the
same plugin objects with the same envelope, the maintainer's 2026-09-08
option A (the kernels converge) recorded in its changeset. 15 lines
blame to it; `:180` blames to `3c48234b3`, which re-wrapped that
sentence and keeps its fact. Its `lite-kernel.ts` docblock records the
measurement taken before converging, which `:604` describes ("before
commit 51ae731"). `:363`, `:498` and `:631` said the `hono-plugin.ts`
question was "noted on" the dead number; that note is the text this
commit wrote into this file, so they now say "raised with" / "recorded
with" it. New anchor; no other package has re-anchored this number yet.
|

**Anchor checks.** Every cited sha matches exactly one object (`git
rev-parse --disambiguate`, count 1 for each of the 5), is a commit, has
one parent, and is an ancestor of `main` (`merge-base --is-ancestor`
against `f927864ea0`, exit 0 for all 5). The checkout is not shallow.
The control leg `2672f855fa` (2026-08-09, the parent of the oldest
anchor `293476148`) exits 0 against `origin/main`, and the negative
control, this branch's own head, exits 1. Four anchors reuse the landed
stages' (`6a180e42d`, `79c46da90`, `293476148`, `f586f1a89`), so each
number carries one anchor across the tree; one is new (`51ae73123`).

**Numbers.** All 5 dropped numbers answer 404 by REST (probed
2026-09-30T00:14:17Z). The numbers kept on or beside the changed lines
answer 200: `objectstack-ai#16599`, `objectstack-ai#9864`, `objectstack-ai#16334`, `objectstack-ai#16363`, `objectstack-ai#16049`, `objectstack-ai#6878`,
`objectstack-ai#3867`, `objectstack-ai#8086`, `objectstack-ai#16545`, `objectstack-ai#15999`, `objectstack-ai#5090`.
`packages/plugins/plugin-hono-server/src` has no slash-joined `#A/#B`
without spaces; the spaced pairs (`objectstack-ai#3867 / objectstack-ai#8086`, `objectstack-ai#2408 / objectstack-ai#3361`) are
read by the grammar and every half answers 200.

## Mechanical guard: no code token moves

**H2 holds on the parser-token reading; the emitted `dist` is NOT
byte-identical, because one rewritten `//` comment sits inside a
returned object literal and the bundler keeps it.**

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, `getChildren` walk, JSDoc nodes excluded) of the 5
touched files at base `f927864ea0` and at the head. Controls mutate the
head text in memory only.
- Real run: 15,054 base tokens (4,831 / 2,134 / 3,559 / 2,363 / 2,167),
0 differing, exit 0.
- Comment-insertion control: 0 differing, exit 0.
- Code-insertion control: all 5 files differ, exit 1.
- String control (the first character of the first import specifier
flipped in each file): exactly 1 differing `StringLiteral` per file,
exit 1.

All 48 changed lines (24 out, 24 in) are `//` or `*` comment lines.

**Emitted `dist`.** `pnpm --filter @objectstack/plugin-hono-server
build` at the head, then at base (the base blobs of the 5 touched files
restored in place under a trap-armed restore; an on-disk probe read
`objectstack-ai#9934` 1 and `commit 79c46da` 0 in `adapter.ts` before that build;
afterwards every touched blob equals its HEAD blob, `git diff HEAD` is
empty and the status is clean), with the same dependency builds:
- `index.js` and `index.mjs` differ, in one line each: the
`adapter.ts:308` comment, `refusal text (objectstack-ai#9934)` at base and `refusal
text (commit 79c46da)` at head. `index.d.ts`, `index.d.mts` and both
`.map` files are equal. No docblock of this diff reaches the declaration
files.
- The same parser comparison over the two differing files reads
identical tokens (10,818 in `index.js`, 10,521 in `index.mjs`), so the
whole `dist` delta is comment text. Its code control (a code line
appended) reads COUNT/TOKENS DIFFER in each.
- Code-mutation control (`scripts/ablation-replace.mjs`, wrap mode,
anchor `message: 'No response from handler' }` hit 1 to 0, planted
marker 0 to 1, blob `6a0c10f76282` to `d5223196afeb`;
`scripts/ablation-dist-preflight.mjs` found the marker in `index.js` and
`index.mjs`): `index.js`, `index.mjs` and both `.map` files differ from
the head build. The blob was restored to HEAD `6a0c10f76282` with `git
diff HEAD` empty, `dist` was rebuilt, its six sha256 values equal the
first head build, and the preflight in `--absent` mode reads the marker
absent from all 6 files with a clean tree.

A raw scan of the 6 changed files for ASCII control bytes finds none,
and `check:nul-bytes` exits 0.

## Changeset

**`patch` for `@objectstack/plugin-hono-server`**
(`.changeset/plugin-hono-server-provenance-anchors.md`), in PR objectstack-ai#20632's
form. The package's `files[]` is `dist`, `README.md` and `CHANGELOG.md`,
and the build above emits different `index.js` / `index.mjs` at base and
head, so this diff publishes. `check-changeset-no-major`,
`check-empty-changeset`, `check-adr-0087-registration` and
`check-changeset-fixed` all exit 0.

## Gates (head `03e5f4c0fd`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its official wording, verbatim (printed by every run; the
command line differs per run and is listed in the verdicts below):

> **Declared narrowing — verification ran UNLOCKED.**
`scripts/pm/os-verify-lock.sh`
> could not take the shared verify lock on this host: no usable `flock`.
The shared
> verify lock is declared Linux-only (`flock` is util-linux, and a stock
macOS does
> not ship it), so the command below was run directly, without the lock
—
> a declared narrowing, not a silent one. No serialization guarantee
held for this
> run, nor for any sibling agent in this container while it ran.

Its verdict line from each run (the closure build and the three `dist`
builds at `feaf0c9b73`, whose `packages/plugins/plugin-hono-server` is
byte-identical to this head; the first whole-workspace build, tests and
typecheck at `91ce7e5e8f`; the second whole-workspace build, tests and
typecheck at this head after the merge; the scratch-script paths
shortened to `SCRATCH`):

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 27s · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/plugin-hono-server...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · bash SCRATCH/base-build.sh SCRATCH
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · node scripts/ablation-replace.mjs --file packages/plugins/plugin-hono-server/src/adapter.ts --anchor "message: 'No response from handler' }" --replacement "message: 'No response from handler ABLMARK20594S10' }" -- bash SCRATCH/mut-inner.sh SCRATCH
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/plugin-hono-server build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 12s · declare it in the PR body · pnpm --filter @objectstack/plugin-hono-server exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 17s · declare it in the PR body · pnpm --filter @objectstack/plugin-hono-server typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 118s (1m58s) · declare it in the PR body · pnpm exec turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 118s (1m58s) · declare it in the PR body · pnpm exec turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 11s · declare it in the PR body · pnpm --filter @objectstack/plugin-hono-server exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 16s · declare it in the PR body · pnpm --filter @objectstack/plugin-hono-server typecheck
```

- **Build:** `@objectstack/plugin-hono-server` with its closure (7 of 81
workspace projects), then the whole workspace, `turbo run build
--filter='./packages/*' --filter='./packages/*/*' --concurrency=2`, 71
of 71 tasks, before and again after the merge. The tree was clean after
each, and the package's six `dist` files after each whole build equal
the first head build by sha256.
- **Tests:** `vitest run --maxWorkers=2`: 27 files, 324 tests passed
(every `*.test.ts` under `src/`), at this head and at `91ce7e5e8f`.
- **Typecheck:** `pnpm --filter @objectstack/plugin-hono-server
typecheck` exits 0 at this head and at `91ce7e5e8f` (`tsc --noEmit`,
`tsc --noEmit -p tsconfig.typecheck.json`, and `check:test-typecheck` OK
with 0 files / 0 errors / 0 pinned signatures). `--listFiles`:
`tsconfig.json` and `tsconfig.test.json` each compile 33 `src/` files
including all 27 tests and all 5 touched files.
- **Spec artifacts:** `origin/main` brought a `packages/spec` change, so
`pnpm --filter @objectstack/spec check:generated` ran after the rebuild:
"All 15 generated artifacts are up to date" (exit 0).
- **Lint:** the repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 at this head (2026-09-30T00:25:09Z to 00:25:36Z), and at
`91ce7e5e8f`.
- **Citation judging:** after merging `origin/main` (`fbec216e2d`),
`node scripts/check-issue-citations.mjs --base origin/main` reports "no
issue citations added against fbec216 (2 file(s) read)" (exit 0).
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 63 families, the same
list at `91ce7e5e8f` and at this head. All 63 exit 0 at this head in one
pass, and `--ran` with the exit-coded record reads "63 derived, 63 run,
0 NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:
`check:issue-citations`, `check:doc-authoring`, `check:nul-bytes`,
`check:published-files`, `check:dts-closure`,
`check:dual-build-cjs-loads`, `check:type-check-debt`,
`check-adr-0087-registration`, `check-empty-changeset`.
- **Artifact rosters:** 36 of the 39 non-self-test roster rows exit 0 at
this head, including the four the derivation marks as keeping their
roster under one of this diff's paths (`check-changeset-fixed`,
`check:authz-resolver`, `check:error-code-casing`,
`check:filter-alias-parity`). The other three need a pull request's
context; they are run against this PR once it exists and reported on the
card. The 18 self-test-only rows grade their checkers' fixtures and
cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `f927864ea0` the filtered census answers 5 sites
on 5 lines, 4 numbers, 2 files, as on the seat's `0be898499f`. The
whole-repo count is 1,105.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/plugins/plugin-hono-server`. No site was left for an open PR
(the file lists of all open PRs were read at 2026-09-29T23:48:36Z, 6
PRs, and again at 2026-09-30T00:15:14Z, 9 PRs: only the Version Packages
PR objectstack-ai#20639 touches the package, in `CHANGELOG.md` and `package.json`) or
for an unfound anchor.
- **H2 holds on the token reading, not on the `dist` reading.** The
parser leaf-token diff of all 5 touched files is empty with its controls
firing. The emitted `dist` differs in one comment line of `index.js` and
of `index.mjs`, token-identical with a code control. That is why the
changeset ships.

## Acceptance notes

- **Strings, the form-D stage.** One dead number remains in a string
literal in `packages/plugins/plugin-hono-server/src`: `objectstack-ai#16721` at the
end of the group-F `describe` title of
`ui-plugin-auto-discovery.pin.test.ts` (`:635`, a test title, no
assertion text). It stays on the card for its form-D stage; no string
moved here. The supplementary scan's second test-string hit, `:111`
(`'.os-pin{color:#123456}'`), is a CSS hex colour in a fixture, not a
citation: the whole-file projection reads it as a six-digit number,
while the census blanks strings and defers test files.
- **Outside `src/**`, a later stage of the card:**
`objectstack.config.ts:19` (`objectstack-ai#11332`) and `:26` (`objectstack-ai#10724`),
`tsconfig.test.json:3` and `:61` (`objectstack-ai#13176`),
`tsconfig.typecheck.json:12` (`objectstack-ai#11332` and `objectstack-ai#10724`; `objectstack-ai#4914` in the same
group answers 200). The other citations in the package outside `src/**`
(`CHANGELOG.md` excluded) answer 200: `tsconfig.test.json` (`objectstack-ai#14062`,
`objectstack-ai#5286`, `objectstack-ai#5449`, `objectstack-ai#12542`), `tsconfig.typecheck.json` (`objectstack-ai#13284`,
`objectstack-ai#5475`, `objectstack-ai#10756`), `vitest.config.ts` (`objectstack-ai#10374`, `objectstack-ai#9457`, `objectstack-ai#7378`;
`objectstack-ai#8129` resolves as a pull request). `README.md` carries none.
- **An open question now lives only in this file.** `hono-plugin.ts:521`
and `:523` still carry the `&& plugin.staticPath` conjunct and the
`plugin.slug || plugin.name.split('/').pop()` derivation that, since
`51ae73123`, neither published kernel's `use()` lets an input reach. The
pin file says so and leaves the call to `hono-plugin.ts`; the tracker
note it pointed at is gone, so this file's text (and commit
`3c48234b3`'s message) are the record. Unreachable defensive code, not a
defect: noted, not filed.
- **Card-word residue, cited nowhere.**
`handler-throw-declared-envelope.test.ts` still says "before this card"
(`:85`) and "the card" (`:19`, `:32`) around its rewritten lines. They
cite no dead number, so they were left, as the landed stages left
theirs.
- **The moving `origin/main`.** The branch merged `origin/main` once
(`03e5f4c0fd`, merging `fbec216e2d`: the ADR-0087 migration chain moves
to `@objectstack/spec/migrations`). `packages/spec` is in this package's
dependency closure, so the workspace was rebuilt and the package's
tests, typecheck and every gate above were rerun at the merge head;
nothing in `packages/plugins/plugin-hono-server` changed.

## Deviations

- **Three derived gates first read NOT MEASURED.**
`check:dual-build-cjs-loads`, `check:lean-entry-closure` and
`check:type-check-debt` exited 3 (PREREQUISITE NOT MET: built output
absent) in the first pass, before the whole-workspace build. Rerun after
it, each exits 0, and all 63 exit 0 in the single pass at this head.
- **The first `check:generated` run was void.** This host's global
`pnpm` is a v11 front end that rejects the `-s` each sub-gate passes, so
all 15 rows read "unexpected argument '-s'" (exit 1, nothing measured).
Rerun with the real pnpm 10.31 binary first on `PATH`, it reads all 15
up to date (exit 0).
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it. The merge
commit carries git's default message.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

---------

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…kages/create-objectstack/src to the commits that decided them (objectstack-ai#20748)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 11 of the `domain:cli` lane of the dead-citation sweep:
`packages/create-objectstack/src`. Every comment site there that cited a
tracker number answering 404 now cites, in ruling C+D's form C (comment
5749154545 on objectstack-ai#19123), the commit in this repository's history that
decided what the line describes, and keeps saying in its own words what
that commit decided. PR objectstack-ai#20533 is the method, and stages 1 to 10 of this
card (PR objectstack-ai#20624, PR objectstack-ai#20632, PR objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689, PR objectstack-ai#20703,
PR objectstack-ai#20713, PR objectstack-ai#20723, PR objectstack-ai#20735, PR objectstack-ai#20741) are the precedents. The card
stays open for the lane's remaining packages, so this PR says `Part of`.

That is **25 sites on 25 lines in 10 files, covering 9 numbers**,
rewritten to **8 distinct commits**:
- the census's **3 sites**: `src/banner.ts` 2, `src/index.ts` 1 (2
numbers);
- **22 test-file comment sites** in 8 test files (the census defers
`*.test.ts`; stages 1 to 10 took test comments too):
`starter-comments-self-contained.test.ts` 9,
`scaffold-e2e-boot-probe.test.ts` 3, `banner-version.test.ts` 2,
`blank-readme-validate-disclosure.test.ts` 2,
`scaffold-next-steps-pm.test.ts` 2, `template-consistency.test.ts` 2,
`scaffold-skills-single-copy.test.ts` 1, `template-ci-workflow.test.ts`
1.

Only comments changed: **25 lines out, 25 in**, every one of them a site
(no companion line), and every touched file keeps its line count (147 /
67 / 58 / 617 / 910 / 261 / 357 / 328 / 221 / 745), so no line citation
into these files moves. **No citation number is added**: the added lines
carry no tracker number at all, and no PR number stands on an added
line. No ADR or ruling-record file in `docs/adr/` or
`scripts/adr-anchors/` records any of these 9 decisions (a grep for the
9 numbers there reads 0 hits; the control number `objectstack-ai#7329` reads 2 in the
same tree), so every anchor is a commit.

**No changeset; `skip-changeset`.** The rewritten comments do not reach
the published `dist` (measured below), as in stages 5 and 7 (PR objectstack-ai#20689,
PR objectstack-ai#20713).

**Scaffold output is untouched.** No site sits inside a template literal
or in a file the scaffolder copies: `src/templates/**` carries zero
tracker citations in either projection, and all 25 sites are `//` or
JSDoc comment prose outside any string. A real scaffold run at base and
at head emits a byte-identical project (below).

## Census: `packages/create-objectstack`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run under `with-fleet.sh
--read` for the token. The count is its `allocated-but-absent` findings
under `packages/create-objectstack/`. Both runs enumerated the whole
board.

| reading | tree | board | whole-repo `allocated-but-absent` | package
sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `01e78dceef`, run 2026-09-30T01:14:08Z to 01:19:48Z |
enumerated, 186 pages, frontier objectstack-ai#20742, 18,569 numbers | 1,077 | **3** |
3 | 2 | 2 |
| after | `4ed638093d`, run 01:30:22Z to 01:35:31Z | enumerated, 186
pages, frontier objectstack-ai#20745, 18,572 numbers | 1,074 | **0** | 0 | 0 | 0 |

The whole-repo drop of 3 is exactly these sites: a site-by-site diff of
the two JSON outputs has 3 findings gone (`banner.ts:10`,
`banner.ts:17`, `index.ts:441`) and none added. The other three tallies
(`resolves` 33,014, `resolves-as-pull-request` 1,984,
`cross-repo-unjudged` 995) are equal in both runs.
`packages/create-objectstack` is byte-identical at `4ed638093d` and at
the head (the one merge brought no file under it).

**Supplementary scan (test files, strings and files outside `src/`
included).** The gate's exported `extractCitations` and
`classifyCitation` over all 53 tracked files of the package
(`CHANGELOG.md` excluded), comment-prose and whole-file projections,
with the board from the gate's own `probeBoard`: 77 citations and 33
dead before, 52 and 8 after. Under `src/`: comments 3 dead to 0, test
comments 23 to 1, test strings 7 unchanged; `src/templates/**` 0
citations of any kind. Outside `src/`, one citation
(`vitest.config.ts:24`, `objectstack-ai#10374`) answers 200. Its before list of `src/`
comment sites equals the census's. The 8 left are 7 test strings and 1
test comment with no deciding commit (see "The site left" and Acceptance
notes).

## Per-number table

`git blame` at the base ties each line to the commit that wrote it, and
each anchor was read in its message, changeset or diff, not only its
subject.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#10325` | `banner.ts:10`; `banner-version.test.ts:3` | `cec9d239d`:
the startup banner reads the real version from `package.json` through
the new `renderVersionBanner()`, and sizes the box from the version's
plain length, widening and never truncating, instead of the hardcoded
`v6.x`. Both lines blame to it; its message carries the closing trailer
for this number. New anchor. |
| `objectstack-ai#10322` | `banner.ts:17`; `index.ts:441`;
`banner-version.test.ts:17`;
`blank-readme-validate-disclosure.test.ts:3`, `:50`;
`scaffold-next-steps-pm.test.ts:3`, `:7` | `8d21f7a76`: detect the
package manager once, up front, and name it in the install line, the
install-failure remedy and every "Next steps" line (labels padded to the
longer of the two instead of hand-kerned for `npm`), and name `validate`
in the blank README's "Getting started". Its message carries the closing
trailer for this number. `index.ts:441` and the two test headers blame
to it; `banner.ts:17` and `banner-version.test.ts:17` blame to
`cec9d239d`, whose message calls this "the sibling bug fixed one
function away in the same file"; `scaffold-next-steps-pm.test.ts:7`
blames to `c6c7feccd`, a re-wrap that keeps the sentence. New anchor. |
| `objectstack-ai#19424` | `scaffold-e2e-boot-probe.test.ts:397`, `:679`, `:816` |
`c27e16059`: the boot-probe neighbour announces its own listener (or its
bind error), asks the kernel for its port with `listen(0)`, and the
harness names five distinct outcomes instead of one "never came up"; the
controls block pins each. All three lines blame to it; its message
carries the closing trailer for this number. New anchor. |
| `objectstack-ai#16331` | `scaffold-skills-single-copy.test.ts:3` | `fd75728bc`:
install the skills bundle for one agent (`--skill '*' --agent
claude-code -y`) so a scaffolded project's first commit stages it once,
with no symlinks. The line blames to it, and its diff is what added the
number; its message names none. New anchor. |
| `objectstack-ai#10990` | `starter-comments-self-contained.test.ts:41`, `:283` |
`21756b325`: converge the shipped template files on the ruled canonical
docs origin and pin that convergence as assertion 4 over
`shippedFiles()`. Both lines blame to it; its message carries the
closing trailer for this number. New anchor for this number. |
| `objectstack-ai#11022` | `starter-comments-self-contained.test.ts:50`, `:91`,
`:122`, `:221` | `21756b325`: rewrite the blank README's two
monorepo-only references, add the fifth `MONOREPO_ONLY` pattern (the
framework's own name next to a "repo" word), retire the self-retiring
`EXCLUDED` entry and add the README's two RATIONALE facts. All four
lines blame to it. Stage 3 (PR objectstack-ai#20656) gave this number the same anchor.
|
| `objectstack-ai#15150` | `starter-comments-self-contained.test.ts:72`, `:133`,
`:141` | `cc986c913`: the sixth `MONOREPO_ONLY` pattern, for a reference
written as a relative path that climbs out of the project, anchored on
bare `../` rather than on a depth judgement. All three lines blame to
it; its diff is what added the number (8 times, across both scaffolders'
pins), its message names none. New anchor. |
| `objectstack-ai#16330` | `template-ci-workflow.test.ts:3`;
`template-consistency.test.ts:376` | `4998efa71`: ship
`.github/workflows/ci.yml` in the blank template (the template's first
dot-directory) so a scaffolded project has gates from its first push.
Both lines blame to it; its diff added the number, its message names
none. New anchor. |
| `objectstack-ai#10326` | `template-consistency.test.ts:498` | `675ab574e`: declare
the two benign peer skews a clean first install reported as scoped pnpm
`allowedVersions` inside the scaffold. The line blames to it. Stage 3
(PR objectstack-ai#20656) gave this number the same anchor. |

**Anchor checks.** Every cited sha matches exactly one object (`git
rev-parse --disambiguate`, count 1 for each of the 8), is a commit, has
one parent, and is an ancestor of `main` (`merge-base --is-ancestor`
against `01e78dceef`, exit 0 for all 8). The checkout is not shallow.
The control leg `2aca1bc4c0` (the parent of the oldest anchor
`675ab574e`, 2026-08-20) exits 0 against the base, and the negative
control (the base as an ancestor of `675ab574e`) exits 1. Two anchors
reuse the landed stages' (`21756b325`, `675ab574e`); six are new.

**Numbers.** All 9 dropped numbers answer 404 by REST (probed
2026-09-30T01:11:14Z and again at 01:50:21Z). The one number kept on a
line beside the changed ones, `objectstack-ai#9779`
(`scaffold-e2e-boot-probe.test.ts:673`), answers 200. The anchor
commits' own PR numbers are not cited: three of them (objectstack-ai#11030, objectstack-ai#11013,
objectstack-ai#11191) answer 404 as well, which is the reason the ruling cites
commits.

## The site left

**No deciding commit (1 site, a test comment, so not in the census):**
`template-consistency.test.ts:153` (`objectstack-ai#11048`): "admitting them is a
support decision (objectstack-ai#11048), not a value to drift here". The number names
an open support decision (whether to admit pnpm 10.0 to 10.4). The only
commit naming it, `568de194e`, files it unassigned; no later commit
decides it, and the floor is still pnpm 10.15 or later at the base.
Stage 3 (PR objectstack-ai#20656) left the sibling site
`packages/cli/src/commands/init.ts:267` for the same reason.

## Mechanical guard: no code token moves, and nothing emitted moves

**H2 holds on both readings: the parser-token diff is empty, and the
emitted `dist` and the scaffolded project are byte-identical.**

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, `getChildren` walk, JSDoc nodes excluded) of the 10
touched files at base `01e78dceef` and at `4ed638093d`. Controls mutate
the head text in memory only.
- Real run: 16,198 base tokens, 0 files differing, exit 0.
- Comment-insertion control: 0 differing, exit 0.
- Code-insertion control: all 10 files differ, exit 1.
- String control (the first character of the first import specifier
flipped in each file): all 10 files differ, first differing kind
`StringLiteral`, exit 1.

All 50 changed lines (25 out, 25 in) are `//` or `*` comment lines.

**Emitted `dist`.** `pnpm --filter create-objectstack build` at base
(before any edit) and at `4ed638093d`, after the same dependency build.
All 24 `dist` files (`index.js`, `chunk-ZIUW7UEA.js`,
`created-summary.js`, `created-summary.d.ts` and the 20 copied template
files) have equal sha256 at base and head, and `diff -r` is empty. None
of the dead numbers appears in the base `dist` at all: tsup drops these
comments.
- Code-mutation control (`scripts/ablation-replace.mjs`, wrap mode,
anchor `Dependency installation failed.` hit 1 to 0, planted marker 0 to
1, blob `b68538942c96` to `860de8778f10`;
`scripts/ablation-dist-preflight.mjs` found the marker in
`dist/index.js`): `index.js` differs from the head build. The blob was
restored to HEAD `b68538942c96` with `git diff HEAD` empty, `dist` was
rebuilt, the preflight in `--absent` mode reads the marker absent from
all 24 files with a clean tree, and the 24 sha256 values equal the first
head build.
- The whole-workspace builds (below) left `create-objectstack`'s `dist`
equal to the same 24 values.

**Scaffold output.** `node
packages/create-objectstack/bin/create-objectstack.js demo-app
--skip-install --skip-skills`, run in an empty directory from the base
build and again from the head build: both emit the same 21 files with
equal sha256, `diff -r` is empty, and the printed output differs only in
the absolute target directory line.

A raw scan of the 10 changed files for ASCII control bytes finds none (a
positive probe on a scratch file with one such byte reads 1), and
`check:nul-bytes` exits 0.

## Changeset

**None; `skip-changeset`.** The package's `files[]` is `dist`,
`README.md` and `CHANGELOG.md`; the build above emits a byte-identical
`dist` at base and head, and the code-mutation control proves that build
does move when code moves. The two other shipped files are untouched, so
this diff publishes nothing.

## Gates (head `a84b73af13`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its official wording, verbatim (printed by every run; the
command line differs per run and is listed in the verdicts below):

> **Declared narrowing — verification ran UNLOCKED.**
`scripts/pm/os-verify-lock.sh`
> could not take the shared verify lock on this host: no usable `flock`.
The shared
> verify lock is declared Linux-only (`flock` is util-linux, and a stock
macOS does
> not ship it), so the command below was run directly, without the lock
—
> a declared narrowing, not a silent one. No serialization guarantee
held for this
> run, nor for any sibling agent in this container while it ran.

Its verdict line from each run (the closure build and the base build at
`01e78dceef`; the head build, the first whole-workspace build, the
tests, the boot-probe file and the typecheck at `4ed638093d`; the second
whole-workspace build, tests and typecheck at this head after the
merge):

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 22s · declare it in the PR body · pnpm --workspace-concurrency=2 --filter 'create-objectstack^...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter create-objectstack build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 1s · declare it in the PR body · pnpm --filter create-objectstack build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 134s (2m14s) · declare it in the PR body · pnpm exec turbo run build --filter=./packages/* --filter=./packages/*/* --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 8s · declare it in the PR body · pnpm --filter create-objectstack exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter create-objectstack exec vitest run --maxWorkers=2 src/scaffold-e2e-boot-probe.test.ts
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter create-objectstack typecheck
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 35s · declare it in the PR body · pnpm exec turbo run build --filter=./packages/* --filter=./packages/*/* --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 7s · declare it in the PR body · pnpm --filter create-objectstack exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm --filter create-objectstack typecheck
```

- **Build:** `create-objectstack`'s dependency closure
(`@objectstack/spec`, its only workspace dependency), then the package,
then the whole workspace, `turbo run build --filter=./packages/*
--filter=./packages/*/* --concurrency=2`, 71 of 71 tasks, before and
again after the merge. The tree was clean after each.
- **Tests:** `vitest run --maxWorkers=2`: 16 files, 247 tests: 233
passed and 14 skipped, at this head and at `4ed638093d`. The 14 skipped
are the whole of `scaffold-e2e-boot-probe.test.ts` (run alone: 1 file
skipped, 14 tests skipped), which its own `RUNNABLE` gate
(`process.platform === 'linux'`, plus `bash`, `curl`, `openssl`) skips
on this macOS host. **NOT MEASURED locally:
`scaffold-e2e-boot-probe.test.ts`, reason: Linux-only by its own gate;
CI runs it.** Its diff is 3 comment lines with identical parser tokens.
- **Typecheck:** `pnpm --filter create-objectstack typecheck` (`tsc
--noEmit`) exits 0 at this head and at `4ed638093d`. `--listFiles`
reaches 26 `src/` files outside `src/templates/`, including all 16 tests
and all 10 touched files.
- **Spec artifacts:** not run. Neither `origin/main`'s one incoming
commit nor this diff touches `packages/spec`.
- **Lint:** the repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 at this head (2026-09-30T02:00:09Z to 02:00:43Z), and at
`4ed638093d` (01:49:31Z to 01:50:04Z).
- **Citation judging:** after merging `origin/main` (`697845d19f`),
`node scripts/check-issue-citations.mjs --base origin/main` reports "no
issue citations added against 697845d (2 file(s) read)" (exit 0).
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 52 families, the same
list at `4ed638093d` and at this head. All 52 exit 0 at this head in one
pass, and `--ran` with the exit-coded record reads "52 derived, 52 run,
0 NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:
`check:issue-citations`, `check:doc-authoring`, `check:nul-bytes`,
`check:published-files`, `check:cross-package-test-inputs`,
`check:dts-closure`, `check:dual-build-cjs-loads`,
`check:type-check-debt`, `check-changeset-no-major`.
- **Artifact rosters:** 36 of the 39 non-self-test roster rows exit 0 at
this head, among them `check:scaffold-emission-policy` and the three the
derivation marks as keeping their roster under one of this diff's paths
(`check:authz-resolver`, `check:error-code-casing`,
`check:filter-alias-parity`). The other three need a pull request's
context; they are run against this PR once it exists and reported on the
card. The 18 self-test-only rows grade their checkers' fixtures and
cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `01e78dceef` the filtered census answers 3 sites
on 3 lines, 2 numbers, 2 files, as on the seat's `0be898499f`. The
whole-repo count is 1,077.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/create-objectstack`. No census site was left for an open PR
(the file lists of all open PRs were read at 2026-09-30T01:21:44Z and
again at 01:52:53Z, 8 PRs each time: only the Version Packages PR objectstack-ai#20639
touches the package, in `CHANGELOG.md` and `package.json`) or for an
unfound anchor. The one site left for an unfound anchor is a test
comment, outside the census.
- **H2 holds.** The parser leaf-token diff of all 10 touched files is
empty with its controls firing, and, independently, the emitted `dist`
and the scaffolded project are byte-identical at base and head, with a
code-mutation control that changes `dist`.

## Acceptance notes

- **Strings, the form-D stage.** Seven dead numbers remain in string
literals, all test titles in `src/`: `banner-version.test.ts:66` and
`:96` (`objectstack-ai#10325`), `blank-readme-validate-disclosure.test.ts:25`
(`objectstack-ai#10322`), `scaffold-e2e-boot-probe.test.ts:829` (`objectstack-ai#19424`),
`scaffold-next-steps-pm.test.ts:173` and `:197` (`objectstack-ai#10322`),
`template-consistency.test.ts:503` (`objectstack-ai#10326`). They stay on the card for
its form-D stage; no string moved here. None is an assertion text or
scaffold output.
- **Outside `src/**`:** nothing dead. The one citation there,
`vitest.config.ts:24` (`objectstack-ai#10374`), answers 200; `README.md` and `bin/`
carry none.
- **Live but misdirected numbers, a different class.** Two numbers in
this package answer 200, but as unrelated pull requests. `objectstack-ai#4902`
(`index.ts:165`, `:239`; `rewrite-identity.ts:36`;
`runtime-image.ts:140`; `rewrite-identity.test.ts:3`, and the test title
at `:123`) was written by `8d41998b0`, whose own message names `objectstack-ai#4926`
(the remote-template object-name rewrite being silently skipped), and
`f2f09e4e3` repeated it at `runtime-image.ts:140`; `objectstack-ai#4902` itself is an
unrelated `init-service` guard PR. `objectstack-ai#3120` (`template-copy.ts:20`;
`template-consistency.test.ts:259`) was written by `3b6ef8a32` (the
scaffolded `.gitignore`), and `objectstack-ai#3120` is an unrelated approvals-docs PR.
The census reads both as `resolves-as-pull-request`, a reading and not a
finding, and this card is about 404s, so neither moved here. Noted, not
filed.
- **Card-word residue, cited nowhere.** Some rewritten test headers
still say "the card" or "per triage" nearby
(`banner-version.test.ts:13`,
`blank-readme-validate-disclosure.test.ts:3`). They cite no dead number,
so they were left, as the landed stages left theirs.
- **The moving `origin/main`.** The branch merged `origin/main` once
(`a84b73af13`, merging `697845d19f`: PR objectstack-ai#20742, the `service-package`
citation re-anchoring). Nothing under `packages/create-objectstack` or
`packages/spec` changed, so the package's tests, typecheck, every
derived gate, the roster rows and lint were rerun at the merge head and
all read as before.

## Deviations

- **Three derived gates first read NOT MEASURED.**
`check:dual-build-cjs-loads`, `check:lean-entry-closure` and
`check:type-check-debt` exited 3 (PREREQUISITE NOT MET: built output
absent) in the first pass, before the whole-workspace build. Rerun after
it, each exits 0, and all 52 exit 0 in the single pass at this head.
- **The first code-mutation attempt was void.** Its replacement text
contained the anchor, so the anchor count could not fall;
`ablation-replace.mjs` refused it (anchor 1 to 1, exit 1) and restored
the blob to HEAD before anything was built. The second attempt, with a
replacement that does not contain the anchor, is the one reported above.
- **The two builds inside the code-mutation control** (the mutate leg
and the restore leg) ran directly, not through `os-verify-lock.sh`. On
this host that wrapper runs unlocked anyway, so nothing was serialized
either way.
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it. The merge
commit carries git's default message.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…ugins/plugin-dev/src to the commits that decided them (objectstack-ai#20767)

Part of objectstack-ai#20594
Clause-②: no

## What changed

This is stage 12 of the `domain:cli` lane of the dead-citation sweep:
`packages/plugins/plugin-dev/src`. Every comment site there that cited a
tracker number answering 404 now cites, in ruling C+D's form C (comment
5749154545 on objectstack-ai#19123), the commit in this repository's history that
decided what the line describes, and keeps saying in its own words what
that commit decided. PR objectstack-ai#20533 is the method, and stages 1 to 11 of this
card (PR objectstack-ai#20624, PR objectstack-ai#20632, PR objectstack-ai#20656, PR objectstack-ai#20673, PR objectstack-ai#20689, PR objectstack-ai#20703,
PR objectstack-ai#20713, PR objectstack-ai#20723, PR objectstack-ai#20735, PR objectstack-ai#20741, PR objectstack-ai#20748) are the
precedents. The card stays open for the lane's remaining packages, so
this PR says `Part of`.

That is **6 sites on 6 lines in 3 files, covering 2 numbers**, rewritten
to **2 distinct commits**:
- the census's **3 sites**, all in `src/dev-plugin.ts` (`:1063`,
`:1078`, `:1097`);
- **3 test-file comment sites** (the census defers `*.test.ts`; stages 1
to 11 took test comments too): `dev-plugin.test.ts:90` and `:127`,
`dev-plugin-security-enforcement-warning.test.ts:53`.

Only comments changed: **6 lines out, 6 in**, every one of them a site
(no companion line), and every touched file keeps its line count (1159 /
317 / 199), so no line citation into these files moves. **No citation
number is added**: the only tracker number on an added line is `objectstack-ai#3900`
at `dev-plugin.ts:1063`, which the removed line already carried and
which answers 200; no PR number stands on an added line. No ADR or
ruling-record file in `docs/adr/` or `scripts/adr-anchors/` records
either decision (a grep there for the 2 numbers, their PR number objectstack-ai#10092
and the 2 shas reads 0 hits; the control number `7329` reads 1 file in
the same tree), so both anchors are commits. ADR-0115 records the older
decision the warning comes from (an empty security slot gets one loud
boot-log line), not the move these lines describe.

**A `patch` changeset** for `@objectstack/plugin-dev` rides along
(`.changeset/plugin-dev-provenance-anchors.md`, in PR objectstack-ai#20632's form),
because the two rewritten docblock lines reach the published `dist`
(measured below), as stage 6 (PR objectstack-ai#20703) measured for its package.

## Census: `packages/plugins/plugin-dev`, before and after

**Instrument.** The gate's own `node scripts/check-issue-citations.mjs
--census --json`, read-only and unchanged, run under `with-fleet.sh
--read` for the token. The count is its `allocated-but-absent` findings
under `packages/plugins/plugin-dev/`. Both runs enumerated the whole
board.

| reading | tree | board | whole-repo `allocated-but-absent` | package
sites | lines | numbers | files |
|---|---|---|---|---|---|---|---|
| before | base `33e4a5609c`, run 2026-09-30T02:45:30Z to 02:51:51Z |
enumerated, 186 pages, frontier objectstack-ai#20757, 18,584 numbers | 1,061 | **3** |
3 | 2 | 1 |
| after | head `a237b10ee7`, run 03:07:39Z to 03:14:14Z | enumerated,
186 pages, frontier objectstack-ai#20765, 18,592 numbers | 1,058 | **0** | 0 | 0 | 0 |

The whole-repo drop of 3 is exactly these sites: a site-by-site diff of
the two JSON outputs has 3 findings gone (`dev-plugin.ts:1063`, `:1078`,
`:1097`) and none added. The other three tallies (`resolves` 33,038,
`resolves-as-pull-request` 1,984, `cross-repo-unjudged` 995) are equal
in both runs.

**Supplementary scan (test files, strings and files outside `src/`
included).** Every `#N` token (two to six digits) in the package's 19
tracked files, `CHANGELOG.md` excluded, was probed by REST: 39 distinct
numbers at base, of which 2 answer 404 in `src/` (`objectstack-ai#10035`, `objectstack-ai#10036`)
and 1 outside it (`objectstack-ai#13176`, in `tsconfig.test.json`); `objectstack-ai#1020` is
`cloud#1020`, cross-repo. Dead occurrences at base: 6 in `src/` comments
(3 source, 3 test), 1 in a test string, 2 in `tsconfig.test.json`.
After: 0 in comments, the test string and the two `tsconfig.test.json`
lines unchanged (see Acceptance notes). A grep for the two numbers with
no word-boundary operator, beside a control of the same shape (`objectstack-ai#3900`
reads 6 lines of `dev-plugin.ts`), finds only those three lines left.

## Per-number table

`git blame` at the base ties every one of the 6 lines to `7552e0337`,
the commit that wrote them, and each anchor was read in its message and
its diff, not only its subject.

| number | sites (base line) | anchor: what it decided |
|---|---|---|
| `objectstack-ai#10036` | `dev-plugin.ts:1063`, `:1078`; `dev-plugin.test.ts:90`,
`:127`; `dev-plugin-security-enforcement-warning.test.ts:53` |
`7552e0337`: the "RBAC/RLS/masking are NOT enforced" warning stops
probing the three `SecurityPlugin.init()` internals
(`security.permissions`, `security.rls`, `security.fieldMasker`, which
the spec contract names implementation internals) and asks the published
`security` service instead, and asks it from `DevPlugin.start()`, after
the child-start loop and beside the boot banner, since asking from
`init()` would find it absent on every stack; the internal handles keep
one use, telling "never loaded" apart from "loaded, then failed to
start". Both halves of its squash message carry this number. Its own PR
number (objectstack-ai#10092) answers 404 as well. |
| `objectstack-ai#10035` | `dev-plugin.ts:1097` | `c1731d023`: `plugin-hono-server`'s
`/auth/me/permissions` and `/me/apps` delegate permission-set resolution
to the `security` service, and their degraded branches key on the
published `security` service instead of `security.permissions` (its
docblock "What absent now means, precisely"). The site's sentence says
the same presence signal misled that endpoint and was cured "by this
same move"; `objectstack-ai#10035` is that commit's own PR number, carried in its
subject. |

**How the lines read now.** `:1063` keeps `objectstack-ai#3900` and says `commit
7552e03 moved this check here from init()`; the `:1078` heading and
the test-comment brackets name `commit 7552e03` where the number
stood, with the decision spelled out in the surrounding prose they
already carried; `:127` reads `(the two told apart since commit
7552e03)`; `:1097` reads `commit c1731d0 by this same move`.

**Anchor checks.** Both cited shas match exactly one object (`git
rev-parse --disambiguate`, count 1 each), are commits, have one parent,
and are ancestors of `main` (`merge-base --is-ancestor` against
`33e4a5609c`, exit 0 for both). The checkout is not shallow. Control
legs: `44738f7af6` (the parent of `c1731d023`) exits 0 against the base;
the negative control (the base as an ancestor of `7552e0337`) exits 1.

**Numbers.** `objectstack-ai#10035`, `objectstack-ai#10036` and `objectstack-ai#10092` answer 404 by REST (probed
2026-09-30T02:43:04Z and again at 03:14:40Z). `objectstack-ai#3900`, kept on `:1063`,
answers 200.

## Mechanical guard: no code token moves

**H2 holds on the token reading; the emitted `dist` is NOT
byte-identical, and the difference is exactly the two docblock lines.**

**Token guard.** It compares the TypeScript parser's leaf tokens
(TypeScript 6.0.3, `getChildren` walk, JSDoc nodes excluded) of the 3
touched files at base `33e4a5609c` and at `37eaf1647f` (the comment
commit). Controls mutate the head text in memory only.
- Real run: 6,653 base tokens, 0 files differing.
- Comment-insertion control: 0 differing.
- Code-insertion control: all 3 files differ.
- String control (the first character of the first import specifier
flipped in each file): all 3 files differ, first differing kind
`StringLiteral`.
- The script's own verdict: exit 0 (real 0 and every control as
expected).

All 12 changed lines in `src/` (6 out, 6 in) are `//` or `*` comment
lines.

**Emitted `dist`.** `pnpm --filter @objectstack/plugin-dev build` at
base (before any edit, after its dependency closure) and at
`37eaf1647f`. Of the 6 `dist` files, `index.js.map` and `index.mjs.map`
have equal sha256; `index.js`, `index.mjs`, `index.d.ts` and
`index.d.mts` differ, and `diff -r` shows exactly two changed lines in
each: the `:1078` heading and the `:1097` line of the
`warnIfNothingIsEnforcingSecurity` docblock. The `//` comment at `:1063`
does not ship. So the published tarball carried both dead numbers, and
now carries the commits.
- Code-mutation control (`scripts/ablation-replace.mjs`, wrap mode,
anchor `ctx.logger.info(' Discovery: /.well-known/objectstack');` hit 1
to 0, planted marker 0 to 1, blob `708af69f9b2a` to `b0b387f53d6a`;
`scripts/ablation-dist-preflight.mjs` found the marker in
`dist/index.js` and `dist/index.mjs`): `index.js`, `index.mjs` and both
source maps differ from the head build. The blob was restored to HEAD
`708af69f9b2a` with `git diff HEAD` empty, `dist` was rebuilt, the
preflight in `--absent` mode reads the marker absent from all 6 files
with a clean tree, and the 6 sha256 values equal the head build.
- The whole-workspace build (below) left `plugin-dev`'s `dist` equal to
the same 6 values.

A raw scan of the 4 changed files for ASCII control bytes finds none (a
positive probe on a scratch file with one such byte reads 1), and
`check:nul-bytes` exits 0.

## Changeset

**`patch` for `@objectstack/plugin-dev`.** The package publishes
(`files` is `dist`, `README.md`, `CHANGELOG.md`), and the measurement
above shows the rewritten docblock reaching four `dist` files. The
changeset states comments only, with no behaviour change.
`check-empty-changeset`, `check-changeset-no-major`,
`check-adr-0087-registration` (1 non-breaking changeset seen) and
`check-changeset-fixed` all exit 0.

## Gates (head `a237b10ee7`)

This host has no `flock`, so `os-verify-lock.sh` ran in its declared
unlocked mode. Its official wording, verbatim (printed by every run; the
command line differs per run and is listed in the verdicts below):

> **Declared narrowing — verification ran UNLOCKED.**
`scripts/pm/os-verify-lock.sh`
> could not take the shared verify lock on this host: no usable `flock`.
The shared
> verify lock is declared Linux-only (`flock` is util-linux, and a stock
macOS does
> not ship it), so the command below was run directly, without the lock
—
> a declared narrowing, not a silent one. No serialization guarantee
held for this
> run, nor for any sibling agent in this container while it ran.

Its verdict line from each run (the closure build at base `33e4a5609c`;
the head build at `37eaf1647f`; the whole-workspace build, the tests and
the typecheck at this head):

```text
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 65s (1m05s) · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/plugin-dev...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/plugin-dev build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 97s (1m37s) · declare it in the PR body · pnpm exec turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 7s · declare it in the PR body · pnpm --filter @objectstack/plugin-dev exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 6s · declare it in the PR body · pnpm --filter @objectstack/plugin-dev typecheck
```

- **Build:** `plugin-dev` with its dependency closure (36 packages, the
filter spelled with the package included), then the package, then the
whole workspace, `turbo run build --filter=./packages/*
--filter=./packages/*/* --concurrency=2`, 71 of 71 tasks. The tree was
clean after each.
- **Tests:** `vitest run --maxWorkers=2`: 9 files, 86 tests, all passed.
- **Typecheck:** `pnpm --filter @objectstack/plugin-dev typecheck` (`tsc
--noEmit`, then `check:test-typecheck` over `tsconfig.test.json`) exits
0. `--listFiles` under both configs reaches all 12 `src/` files,
including the 9 tests and the 3 touched files.
- **Spec artifacts:** not run. `origin/main` did not move while this
branch was open (still `33e4a5609c`; the merge was a no-op), and this
diff does not touch `packages/spec`.
- **Lint:** the repo-wide `pnpm lint` (`eslint . --no-inline-config`)
exits 0 at this head (2026-09-30T03:07:02Z to 03:07:32Z).
- **Citation judging:** after merging `origin/main` (already up to date
at `33e4a5609c`), `node scripts/check-issue-citations.mjs --base
origin/main` judges 1 added citation (`objectstack-ai#3900`), which resolves (exit 0).
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 62 families from the 4
changed paths. All 62 exit 0 in one pass at this head, and `--ran` with
the exit-coded record reads "62 derived, 62 run, 0 NOT-MEASURED, 0
UNRUN" (a derived zero). Among them: `check:issue-citations`,
`check:doc-authoring`, `check:nul-bytes`, `check:published-files`,
`check:cross-package-test-inputs`, `check:dts-closure`,
`check:dual-build-cjs-loads`, `check:type-check-debt`,
`check-empty-changeset`, `check-adr-0087-registration`.
- **Artifact rosters:** 36 of the 39 non-self-test roster rows exit 0 at
this head, among them `check-changeset-fixed` and the three others the
derivation marks as keeping their roster under one of this diff's paths
(`check:authz-resolver`, `check:error-code-casing`,
`check:filter-alias-parity`). The other three need a pull request's
context; they are run against this PR once it exists and reported on the
card. The 18 self-test-only rows grade their checkers' fixtures and
cannot judge this diff.

## Hypotheses (measured first)

- **H0 holds.** At base `33e4a5609c` the filtered census answers 3 sites
on 3 lines, 2 numbers, 1 file, as on the seat's `0be898499f`. The
whole-repo count is 1,061.
- **H1 holds.** After the rewrite, the filtered census answers 0 for
`packages/plugins/plugin-dev`. No site was left for an open PR (the file
lists of all 8 open PRs were read at 2026-09-30T02:45:10Z: only the
Version Packages PR objectstack-ai#20639 touches the package, in `CHANGELOG.md` and
`package.json`) or for an unfound anchor.
- **H2 holds, by the token reading, not the `dist` reading.** The parser
leaf-token diff of all 3 touched files is empty with its controls
firing. The emitted `dist` is not byte-identical, and it is not meant to
be: its only difference is the two docblock lines, which is why the
changeset ships.

## Acceptance notes

- **Strings, the form-D stage.** One dead number remains in a string
literal: the `describe` title at
`dev-plugin-security-enforcement-warning.test.ts:121` (`objectstack-ai#10036`). It
stays on the card for its form-D stage; no string moved here. It is not
assertion text. The same title is quoted in three recorded CI-log
fixtures under `scripts/fixtures/merge-queue-triage/`; those are
captured logs read by `check-merge-queue-triage-outcome.mjs`, so a later
rename of the title does not need them edited.
- **Outside `src/**`:** `tsconfig.test.json:3` and `:56` cite `objectstack-ai#13176`,
which answers 404. The same number sits in the `tsconfig.test.json` of
13 `packages/plugins/*` packages (17 `tsconfig*.json` files under
`packages/` in all), outside the census's declared surface; stage 10 (PR
objectstack-ai#20741) recorded its own copy for a later stage of this card. Every
other citation in the package outside `src/` answers 200
(`vitest.config.ts`, `README.md`, `tsconfig.json`, `package.json`);
`CHANGELOG.md` is release-owned and was not read as a site.
- **`origin/main` did not move.** It read `33e4a5609c` at worktree
creation and at every later fetch, so every run above is against the
same base and nothing needed rerunning after the merge.

## Deviations

- **The two builds inside the code-mutation control** (the mutate leg
and the restore leg) ran directly, not through `os-verify-lock.sh`. On
this host that wrapper runs unlocked anyway, so nothing was serialized
either way.
- **The dependency-closure build** used the filter
`'@objectstack/plugin-dev...'` (package plus its dependencies) rather
than the closure-only `^...` spelling; it built the same closure and the
package in one run.
- **Commit trailers** are AGENTS.md's model-free pair (`Claude-Session`
plus `Co-authored-by: Claude`), and the pre-push trailer check passed on
every push. The harness's attribution reminder asked for a model-named
trailer and a different PR footer, and AGENTS.md overrides it.

---
_Generated by [Claude
Code](https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289)_

---------

Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/s skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant