docs(mcp): re-anchor the dead tracker citations in packages/mcp/src to the commits that decided them - #20713
Conversation
…o the commits that decided them Stage 7 of the domain:cli lane's dead-citation sweep, in ruling C+D's form C: every comment site in packages/mcp/src that cited a tracker number answering 404 now cites the commit in this repository's history that decided what the line describes. Comments only: 18 lines out, 18 in, every file keeps its line count. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift Check1 anchor(s) derived from 1 changed package(s); no hand-written page names any of them. What this run could not see
Coarse fallback — 12 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 6bd09d745fe859e9995e40db8aba65bb850e97b6 && git checkout 6bd09d745fe859e9995e40db8aba65bb850e97b6
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 57574637129bebb4a6868c465be7e1b80eed1954 7a0f15de6274d74343e27c4b6a70b89c0b35a1cd && git checkout -B drift-repro 57574637129bebb4a6868c465be7e1b80eed1954 && git merge --no-ff 7a0f15de6274d74343e27c4b6a70b89c0b35a1cd
node scripts/docs-audit/affected-docs.mjs --json 57574637129bebb4a6868c465be7e1b80eed1954 |
Part of #20594
Clause-②: no
What changed
This is stage 7 of the
domain:clilane of the dead-citation sweep:packages/mcp/src. Every comment site there that cited a tracker number answering 404 now cites, in ruling C+D's form C (comment 5749154545 on #19123), the commit in this repository's history that decided what the line describes, and keeps saying in its own words what that commit decided. PR #20533 is the method, and stages 1 to 6 of this card (PR #20624, PR #20632, PR #20656, PR #20673, PR #20689, PR #20703) are the precedents. The card stays open for the lane's remaining packages, so this PR saysPart of.That is 17 sites on 17 lines in 9 files, covering 9 numbers, rewritten to 9 distinct commits:
mcp-server-runtime.ts(5),plugin.ts(3) andstdio-data-bridge.ts(2), 7 numbers;*.test.ts; stages 1 to 6 took test comments too).One more line changed:
__tests__/plugin-execution-context.test.ts:7, the second half of the:6sentence ("this face was not in that card's inventory" now reads "not in that commit's inventory", since the card it pointed back to is now named as a commit).Only comments changed: 18 lines out, 18 in, and every touched file keeps its line count, so no line citation into these files moves. No citation number is added: over the 18 line pairs, added-minus-removed numbers is empty, and no PR number stands newly on any line. No ADR or ruling-record file in
docs/adr/orscripts/adr-anchors/records any of these 9 decisions (a grep for the 9 numbers there reads 0 hits, with a control number from the same tree reading 2), so every anchor is a commit.No changeset, and
skip-changeset: none of the rewritten comments reachesdist(measured below: base and head emit six byte-identical files, and a code-mutation control changes four of them). That is stage 5's case (PR #20689), not stage 6's.Census:
packages/mcp, before and afterInstrument. The gate's own
node scripts/check-issue-citations.mjs --census --json, read-only and unchanged, run underwith-fleet.sh --readfor the token. The count is itsallocated-but-absentfindings underpackages/mcp/. Both runs enumerated the whole board.allocated-but-absentpackages/mcpsitese4e5222b7b, run 2026-09-29T19:45:33Z to 19:50:37Z459ff81088, run 19:58:39Z to 20:02:47ZThe whole-repo drop of 10 is exactly these sites: a site-by-site diff of the two JSON outputs has 10 findings gone, all under
packages/mcp/src, and none added. The other three tallies (resolves32,968,resolves-as-pull-request1,984,cross-repo-unjudged994) are equal in both runs.packages/mcp/srcis byte-identical at459ff81088and at the head.Supplementary scan (test files included). The gate's exported
extractCitationsandclassifyCitationover all 43.tsfiles undersrc/, with the board from the gate's ownprobeBoard: 365 citations and 21 dead before (src comments 10, test comments 7, src strings 0, test strings 4), 348 and 4 after (0, 0, 0, 4). Its before list of src comment sites is identical to the census's. The 4 left are test titles, the form-D stage (see Acceptance notes).Per-site table
git blameat the base ties each line to the commit that wrote it, and each anchor was read in its message, changeset or diff, not only its subject. Where the pull request that landed an anchor still answers, its body's first line names the dead number, which is noted.#13318mcp-server-runtime.ts:2723ec8646f1: the bridged tools'readOnlyHint/destructiveHintcome from what the definition declares, and a tool that declares nothing is served neither hint (omit-when-unsourced). The line blames toc39369d12, theopenWorldHintsibling, whose changeset calls this the repair "that preceded it". The PR that landed3ec8646f1answers 404 too.#6724mcp-server-runtime.ts:625;mcp-server-runtime.metadata-outage.test.ts:2894f3d2322e: correctsdiagnoseEmptyRead's falsified claim thatMetadataFacade.getObjectdiffers fromget('object', n), in the TSDoc and in the outage test's restatement of it. Both lines blame to it; PR #6948, which landed it, names #6724.#6745mcp-server-runtime.ts:6367a5ef0008: addsmetadata-service-getobject-equivalence.test.ts, pinninggetObject(n)equal toget('object', n)across all three implementations. The line's "PR #6839 for #6745" named this commit's PR (answers 200), which stays beside the sha as a convenience link. The spec lane gave the number this anchor.#6723mcp-server-runtime.ts:637,:652;mcp-server-runtime.metadata-outage.test.ts:2938ad609c69: declares onIMetadataService.getObjectthat it answers the same asget('object', name).#6723was the pull request that landed as this commit (its subject carries the number);#6505, the issue beside it on:637, answers 200 and stays. The spec lane gave the number this anchor.#17114plugin.ts:8,:67;stdio-tenancy-posture-api-key-matrix.test.ts:5694af758d47: the last two admission doors, this one included, classify the tenancy rejection through the sharedclassifyAdmissionTenancyPosture. All three lines blame to it; PR #17683 names #17114, and stage 1 gave the number this anchor.#6216plugin.ts:126;__tests__/plugin-execution-context.test.ts:6f586f1a89: oneExecutionContextassembler for the dispatcher, REST and share-link sites. Both lines blame to502dc6fe7, which converged this stdio face afterwards and names that convergence as its precedent. Its file list touches nopackages/mcpfile, which is what:7("not in that commit's inventory") says. Stages 1 and 2 and the spec lane gave the number this anchor.#8422stdio-data-bridge.ts:85,:394;stdio-data-bridge.not-found.test.ts:44810dd628: the stdio bridge's by-id write seams throw the sharedrecordNotFoundErrorenvelope instead of a bareError. All three lines blame to it; PR #8507 names #8422.#17568mcp-record-id-key-mistake-refusal.test.ts:49c9e6d08f: pins that a missing-recordIdrefusal also names theidthe caller sent (test-only). The line blames to it; PR #17650 names #17568.#13486mcp-tool-bridge-safety-annotations.test.ts:4236193e576d: pins the bridge's two hand-copied safety name sets in the direction the old pin could not see (the docblock's heading is that commit's subject). The line blames to it; PR #13888 names #13486.Anchor checks. Every cited sha matches exactly one object (
git rev-parse --disambiguate, count 1 for each of the 9), is a commit, has one parent, and is an ancestor ofmain(merge-base --is-ancestoragainst5757463712, exit 0 for all 9). The checkout is not shallow. The control leg979ad9575(2026-08-08, the parent of the oldest anchor8ad609c69of 2026-08-08) exits 0, and the negative control, this branch's own459ff81088, exits 1. Four anchors reuse the landed stages' (f586f1a89,4af758d47,7a5ef0008,8ad609c69), so each number carries one anchor across the tree; five are new (3ec8646f1,4f3d2322e,4810dd628,9c9e6d08f,6193e576d).Numbers. All 9 dropped numbers answer 404 by REST (re-probed 2026-09-29T19:54Z). The numbers kept on changed lines (
#6839, a pull request;#6505,#15348,#16013,#4435,#5138,#7867) answer 200. Four slash-joined groups stand inpackages/mcp/src, whose later halves the citation grammar does not read (#4435/#5138/#7867twice,#5138/#5581,#7728/#7823); every half answers 200, so none is dead.Mechanical guard: no code token moves
H2 holds on both readings: the parser leaf-token diff is empty, and the emitted
distis byte-identical.Token guard. It compares the TypeScript parser's leaf tokens (TypeScript 6.0.3, JSDoc nodes excluded) of the 9 touched files at base
e4e5222b7band at459ff81088. Controls mutate the head text in memory only.'vitest'import specifier inplugin-execution-context.test.tsflipped): exactly 1 differingStringLiteral, at token 15 of that file (exit 1).Emitted
dist.pnpm --filter @objectstack/mcp buildat the head, then at base (the base tree ofpackages/mcp/srcrestored in place under a trap-armed restore; an on-disk probe read#133181 andcommit 3ec8646f10 before that build; afterwards every touched blob equals its HEAD blob andgit diff HEADis empty), with the same dependency builds:index.cjs,index.cjs.map,index.d.cts,index.d.ts,index.js,index.js.map) are byte-identical by sha256. The built files do carry docblocks (14 inindex.js, 78 inindex.d.ts); none of the rewritten ones is on an emitted declaration.scripts/ablation-replace.mjs, anchor: the sync leg's typedctx.getServicecall on'tenancy'inplugin.ts, hit 1 to 0, its argument renamed to a marker; blob restored to HEAD0a1aaa7955,git diff HEADempty):scripts/ablation-dist-preflight.mjsfound the marker inindex.cjsandindex.js, andindex.cjs,index.jsand both.mapfiles differ from the head build.distwas then rebuilt, its six sha256 values equal the first head build, and the preflight in--absentmode reads the marker absent from all 6 files with a clean tree.A raw scan of the 9 changed files for control bytes finds none (a positive probe on a scratch file matched).
Changeset
None, and
skip-changeset.@objectstack/mcp'sfiles[]isdist,README.mdandCHANGELOG.md, and the build above emits byte-identicaldistat base and head, so this diff publishes nothing from any released package. Stage 5 (PR #20689) measured the same and shipped the same; stage 6 (PR #20703) measured the opposite and carried apatch.Gates (head
7a0f15de62)This host has no
flock, soos-verify-lock.shran in its declared unlocked mode. Its disclosure, verbatim, from each run at this head and from the fourdistbuilds (at459ff81088,packages/mcp/srcbyte-identical to this head):@objectstack/mcpwith its closure (9 of 81 workspace projects), then the whole workspace,turbo run build --filter='./packages/*' --filter='./packages/*/*', 71 of 71 tasks, after the merge. The tree was clean after both.vitest run: 32 files, 344 tests passed (every*.test.tsundersrc/), at the head and before the merge.pnpm --filter @objectstack/mcp typecheckexits 0.tsc --listFiles:tsconfig.jsoncompiles the 11 non-testsrcfiles,tsconfig.test.jsonall 43 including the 32 test files.check:test-typecheck: 6 files, 53 errors, 8 pinned signatures, held.pnpm lint(eslint . --no-inline-config) exits 0 at this head (2026-09-29T20:18:54Z to 20:19:23Z), and at459ff81088before the merge.origin/main(9b384f63ae),node scripts/check-issue-citations.mjs --base 9b384f63aejudges 5 citations on the changed lines of 3 files (the kept numbers#15348,#16013,#4435,#6505, and#6839as a pull request) and exits 0: every one resolves. Againstorigin/mainafter it moved to5757463712, the same 5 citations, exit 0.node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commandsderived 53 families. All 53 exit 0, and--ranwith the exit-coded record reads "53 derived, 53 run, 0 NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:check:issue-citations,check:doc-authoring(808 pinned sites, no growth),check:nul-bytes(9,331 files, no raw control bytes),check:published-files,check:type-check-debt.check:authz-resolver,check:error-code-casing,check:filter-alias-parity). The other three need a pull request's context; they are run against this PR once it exists and reported on the card. The 18 self-test-only rows grade their checkers' fixtures and cannot judge this diff.Hypotheses (measured first)
e4e5222b7bthe filtered census answers 10 sites on 10 lines, 7 numbers, in 3 files, as on the seat's0be898499f. The whole-repo count is 1,222.packages/mcp. No site was left for an open PR (the file lists of all 8 open PRs were read at 20:08:05Z: only the Version Packages PR chore: version packages #20639 touchespackages/mcp, inCHANGELOG.mdandpackage.json) or for an unfound anchor.distis byte-identical at base and head with a code control that changes it.Acceptance notes
packages/mcp/src(describetitles, no assertion text):#17568twice inmcp-record-id-key-mistake-refusal.test.ts(:151,:315),#8422instdio-data-bridge.not-found.test.ts:99,#17114instdio-tenancy-posture-api-key-matrix.test.ts:592. They stay on the card for its form-D stage; no string moved here.src/**, a later stage of the card:packages/mcp/vitest.config.ts:18cites#8651(404).packages/mcp/test-typecheck-debt.json:2cites#13470(404) inside its_commentfield, which the file itself says is generated byscripts/check-test-typecheck.mts, so a fix there is at that producer, in thescripts/**lane, not a hand edit. The other citations inpackages/mcpoutsidesrc/**(CHANGELOG.mdexcluded) answer 200.stdio-data-bridge.not-found.test.ts:19,mcp-record-id-key-mistake-refusal.test.ts:19,stdio-tenancy-posture-api-key-matrix.test.ts:580,:584). They cite no number, so they were left, as the landed stages left theirs; only the one same-sentence companion (plugin-execution-context.test.ts:7) was changed.origin/main. The branch mergedorigin/mainonce (7a0f15de62, merging9b384f63ae:service-storage,platform-objectsandplugin-audit, nothing inpackages/mcp). A later fetch advanced the shared ref to5757463712, one commit inplatform-objectstranslations. There was no second merge; CI judges the merge ref.Deviations
plugin-execution-context.test.ts:7) beyond the 17 sites, the second half of the:6sentence.Claude-SessionplusCo-authored-by: Claude), and the pre-push trailer check passed on every push. The harness's attribution reminder asked for a model-named trailer and a different PR footer, and AGENTS.md overrides it. The merge commit carries git's default message.Generated by Claude Code