Skip to content

docs(cloud-connection): re-anchor the dead tracker citations in packages/cloud-connection/src to the commits that decided them - #20735

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-20594-cloud-connection-citations
Sep 29, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-20594-cloud-connection-citations

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Part of #20594
Clause-②: no

What changed

This is stage 9 of the domain:cli lane of the dead-citation sweep: packages/cloud-connection/src. Every comment site there that cited a tracker number answering 404 now cites, in ruling C+D's form C (comment 5749154545 on #19123), the commit in this repository's history that decided what the line describes, and keeps saying in its own words what that commit decided. PR #20533 is the method, and stages 1 to 8 of this card (PR #20624, PR #20632, PR #20656, PR #20673, PR #20689, PR #20703, PR #20713, PR #20723) are the precedents. The card stays open for the lane's remaining packages, so this PR says Part of.

That is 10 sites on 10 lines in 3 files, covering 3 numbers, rewritten to 3 distinct commits:

  • the census's 5 sites, all in src/marketplace-install-local-plugin.ts (3 numbers);
  • 5 test-file comment sites in 2 test files (the census defers *.test.ts; stages 1 to 8 took test comments too).

Only comments changed: 10 lines out, 10 in, and every touched file keeps its line count (1,969 / 377 / 308), so no line citation into these files moves. No citation number is added: over the 10 line pairs, added-minus-removed numbers is empty, and no PR number stands on an added line. No ADR or ruling-record file in docs/adr/ or scripts/adr-anchors/ records any of these 3 decisions (a grep for the 3 numbers there reads 0 hits, with a control number from the same tree, #7329, reading 1), so every anchor is a commit.

A patch changeset for @objectstack/cloud-connection rides along, because the rewritten docblocks reach dist (measured below). That is stage 6's case (PR #20703), not stages 5 and 7's.

Census: packages/cloud-connection, before and after

Instrument. The gate's own node scripts/check-issue-citations.mjs --census --json, read-only and unchanged, run under with-fleet.sh --read for the token. The count is its allocated-but-absent findings under packages/cloud-connection/. Both runs enumerated the whole board.

reading tree board whole-repo allocated-but-absent packages/cloud-connection sites lines numbers files
before base b291fcdae9, run 2026-09-29T22:34:12Z to 22:38:18Z enumerated, 186 pages, frontier #20731, 18,558 numbers 1,153 5 5 3 1
after 4a1f38a4e6, run 22:44:08Z to 22:47:58Z enumerated, 186 pages, frontier #20731, 18,558 numbers 1,148 0 0 0 0

The whole-repo drop of 5 is exactly these sites: a site-by-site diff of the two JSON outputs has 5 findings gone, all in packages/cloud-connection/src/marketplace-install-local-plugin.ts, and none added. The other three tallies (resolves 32,994, resolves-as-pull-request 1,984, cross-repo-unjudged 995) are equal in both runs. packages/cloud-connection/src is byte-identical at 4a1f38a4e6 and at the head.

Supplementary scan (test files included). The gate's exported extractCitations and classifyCitation over all 44 .ts files under src/, with the board from the gate's own probeBoard: 301 citations and 14 dead before (src comments 5, test comments 5, src strings 1, test strings 3), 291 and 4 after (0, 0, 1, 3). Its before list of src comment sites is identical to the census's. The 4 left are strings, the form-D stage (see Acceptance notes).

Per-site table

git blame at the base ties each line to the commit that wrote it, and each anchor was read in its message, changeset or diff, not only its subject.

number sites (base line) anchor: what it decided
#9011 marketplace-install-local-plugin.ts:35, :1001, :1821; marketplace-install-local-capability-enumeration.test.ts:50, :303; marketplace-install-local-list-posture.test.ts:4, :302 01074e551: the install-local listing requires an authenticated principal (anonymous gets 401) and serves installedBy / storageDir only to a manage_metadata holder, the maintainer's 2026-08-16 "Option 3" that :1008 still names; it also extracts the one refuseUnauthenticated 401 envelope that :1821 describes. All seven lines blame to it. The PR that landed it (PR #9256, which answers 200) names #9011 on its first line. list-posture.test.ts:302 now reads "The wire shape before commit 01074e5" for "The pre-(number) wire shape".
#8919 marketplace-install-local-plugin.ts:98; marketplace-install-local-capability-enumeration.test.ts:40 b5378550e: gates the /meta publish and rollback promotion verbs on manage_metadata and adds meta-write-door-capability-enumeration.test.ts, the enumeration pin :40 names as its precedent. Both lines blame to e0695b582, the commit that gated the four mutating install-local doors for #8976 (which answers 200), whose message cites this gate as the precedent. Stages 2 and 5 gave the number this anchor. The PR that landed b5378550e answers 404 too.
#13279 marketplace-install-local-plugin.ts:1813 6a180e42d: a failed permission-store read raises AuthzStoreUnavailableError instead of resolving as an unauthenticated or capability-less principal, and each fail-closed transport catch re-raises it. The line blames to it; PR #13475 names #13279. Stages 1, 2 and 4 gave the number this anchor.

Anchor checks. Every cited sha matches exactly one object (git rev-parse --disambiguate, count 1 for each of the 3), is a commit, has one parent, and is an ancestor of main (merge-base --is-ancestor against 36d043be17, exit 0 for all 3). The checkout is not shallow. The control leg 818fcafda (2026-08-16, the parent of the oldest anchor b5378550e of 2026-08-16) exits 0, and the negative control, this branch's own 16a88d69b2, exits 1. Two anchors reuse the landed stages' (b5378550e, 6a180e42d), so each number carries one anchor across the tree; one is new (01074e551).

Numbers. All 3 dropped numbers answer 404 by REST (probed 2026-09-29T22:40:35Z). The numbers kept near the changed lines (#8976, #15353) answer 200. Three slash-joined groups stand in packages/cloud-connection/src, whose later halves the citation grammar does not read (#6603/#7020, #4127/#4251 twice); every half answers 200, so none is dead.

Mechanical guard: no code token moves

H2 holds on the comment-stripped reading; the emitted dist is NOT byte-identical, because the docblocks ship.

Token guard. It compares the TypeScript parser's leaf tokens (TypeScript 6.0.3, JSDoc nodes excluded) of the 3 touched files at base b291fcdae9 and at 4a1f38a4e6. Controls mutate the head text in memory only.

  • Real run: 12,349 base tokens (8,351 / 2,246 / 1,752), 0 differing (exit 0 for each file).
  • Comment-insertion control: 0 differing (exit 0).
  • Code-insertion control: all 3 files differ (exit 1).
  • String control ('Authentication required.' to 'Authentication requireD.' in refuseUnauthenticated): exactly 1 differing StringLiteral, at token 7,973 of marketplace-install-local-plugin.ts (exit 1).

Emitted dist. pnpm --filter @objectstack/cloud-connection build at the head, then at base (the base tree of packages/cloud-connection/src restored in place under a trap-armed restore; an on-disk probe read [#13279] 1 and commit 6a180e42d 0 before that build; afterwards every touched blob equals its HEAD blob and git diff HEAD is empty), with the same dependency builds:

  • index.cjs, index.js, index.d.ts and index.d.cts differ; index.cjs.map and index.js.map are equal.
  • The same parser comparison over the four differing dist files reads 0 differing tokens (19,465 / 18,741 / 16,868 / 16,868), so the whole dist delta is comment text. Its code control (a code line appended after a newline) reads COUNT DIFFERS in each.
  • The new wording is in dist: "commit 01074e5" appears 2 times in index.js and index.cjs and 3 times in each declaration file, where the base build carries #9011 in the same places.
  • Code-mutation control (scripts/ablation-replace.mjs, anchor 'Authentication required.' hit 1 to 0, planted marker 0 to 1, blob 2ef0f0ae8bac to 77c3cef6324b; scripts/ablation-dist-preflight.mjs found the marker in dist): index.cjs, index.js and both .map files differ from the head build. The blob was restored to HEAD 2ef0f0ae8bac with git diff HEAD empty, dist was rebuilt, its six sha256 values equal the first head build, and the preflight in --absent mode reads the marker absent from all 6 files with a clean tree.

A raw scan of the 4 changed files for control bytes finds none (a positive probe on a scratch file matched).

Changeset

patch for @objectstack/cloud-connection (.changeset/cloud-connection-provenance-anchors.md), in PR #20632's form. @objectstack/cloud-connection's files[] is dist, README.md and CHANGELOG.md, and the build above emits different index.js / index.cjs / index.d.ts / index.d.cts at base and head, so this diff publishes. check-changeset-no-major, check-empty-changeset, check-adr-0087-registration and check-changeset-fixed all exit 0.

Gates (head 16a88d69b2)

This host has no flock, so os-verify-lock.sh ran in its declared unlocked mode. Its disclosure, verbatim, from each run (the closure build at 4a1f38a4e6, whose packages/cloud-connection and dependency closure are byte-identical to this head; the whole-workspace build, the tests and the typecheck at this head; the three dist builds at 4a1f38a4e6, whose packages/cloud-connection/src is byte-identical to this head):

os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 59s · declare it in the PR body · pnpm --workspace-concurrency=2 --filter '@objectstack/cloud-connection...' build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 118s (1m58s) · declare it in the PR body · pnpm turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 11s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection exec vitest run --maxWorkers=2
os-verify-lock: VERDICT command-exit 2 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 2s · declare it in the PR body · pnpm exec tsc --noEmit -p tsconfig.json --listFiles
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection build
os-verify-lock: VERDICT command-exit 0 · UNLOCKED (declared) · no usable `flock` on this host, so the shared verify lock was NEVER taken and NOTHING was serialized · ran 3s · declare it in the PR body · pnpm --filter @objectstack/cloud-connection build
  • Build: @objectstack/cloud-connection with its closure (33 of 81 workspace projects), then the whole workspace, turbo run build --filter='./packages/*' --filter='./packages/*/*', 71 of 71 tasks, after the merge. The tree was clean after both, and the package's six dist files after the whole build equal the first head build by sha256.
  • Tests: vitest run: 30 files, 397 tests passed (every *.test.ts under src/), at this head and before the merge.
  • Typecheck: @objectstack/cloud-connection has no typecheck script; it is a DEBT entry in scripts/check-type-check-coverage.mjs (13 errors: 11 TS2493, 2 config-tier). tsc --noEmit -p tsconfig.json exits 2 with exactly those 13 (11 TS2493, 2 TS2550), all in three test files this PR does not touch (cloud-connection-plugin.test.ts 4, connection-credential-store.test.ts 7, marketplace-install-local-bundle.test.ts 2). --listFiles compiles all three touched files and all 30 test files. check:type-check-debt and check:type-check-coverage exit 0, and the dist build's DTS step, this package's type gate, succeeds.
  • Lint: the repo-wide pnpm lint (eslint . --no-inline-config) exits 0 at this head (2026-09-29T23:01:12Z to 23:01:39Z).
  • Citation judging: after merging origin/main (36d043be17), node scripts/check-issue-citations.mjs --base origin/main reports "no issue citations added against 36d043b (1 file(s) read)" (exit 0); pinned --base 36d043be17 reads the same.
  • Derived gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands derived 61 families. All 61 exit 0, and --ran with the exit-coded record reads "61 derived, 61 run, 0 NOT-MEASURED, 0 UNRUN" (a derived zero). Among them: check:issue-citations, check:doc-authoring, check:nul-bytes, check:published-files, check:type-check-debt, check-adr-0087-registration, check-empty-changeset.
  • Artifact rosters: 36 of the 39 non-self-test roster rows exit 0, including the four the derivation marks as keeping their roster under one of this diff's paths (check-changeset-fixed, check:authz-resolver, check:error-code-casing, check:filter-alias-parity). The other three need a pull request's context; they are run against this PR once it exists and reported on the card. The 18 self-test-only rows grade their checkers' fixtures and cannot judge this diff.

Hypotheses (measured first)

  • H0 holds. At base b291fcdae9 the filtered census answers 5 sites on 5 lines, 3 numbers, all in src/marketplace-install-local-plugin.ts, as on the seat's 0be898499f. The whole-repo count is 1,153.
  • H1 holds. After the rewrite, the filtered census answers 0 for packages/cloud-connection. No site was left for an open PR (the file lists of all 10 open PRs were read at 2026-09-29T22:41:18Z: only the Version Packages PR chore: version packages #20639 touches packages/cloud-connection, in CHANGELOG.md and package.json) or for an unfound anchor.
  • H2 holds on the token reading, not on the dist reading. The parser leaf-token diff of all 3 touched files is empty with its controls firing. The emitted dist differs, and the difference is comment text only (token-identical dist with a code control). That is why the changeset ships.

Acceptance notes

  • Strings, the form-D stage. 4 dead numbers remain in string literals in packages/cloud-connection/src: #9011 in the three describe titles of marketplace-install-local-list-posture.test.ts (:206, :247, :287, no assertion text), and #9011 in the note string of the GET /api/v1/marketplace/install-local row of cloud-connection-route-ledger.ts (:215), a runtime string already recorded in scripts/doc-authoring-prose-id.baseline.json. They stay on the card for its form-D stage; no string moved here.
  • Outside src/**, a later stage of the card: packages/cloud-connection/vitest.config.ts:64 cites #16917 (404). The other citations in packages/cloud-connection outside src/** (CHANGELOG.md excluded) answer 200: README.md:108 (#10805, #12681) and vitest.config.ts (#10374, #11480, #7668/#7778, #7955, #10374/#13522).
  • Card-word residue, cited nowhere. A few docblocks still say "this card's ruling" or "That ruling has since landed" a paragraph away from a rewritten line (marketplace-install-local-capability-enumeration.test.ts:48, marketplace-install-local-list-posture.test.ts:12). They cite no number, so they were left, as the landed stages left theirs.
  • The moving origin/main. The branch merged origin/main once (16a88d69b2, merging 36d043be17: service-automation and two changesets, nothing in packages/cloud-connection or its dependency closure).

Deviations

  • The first token-guard run was void. It looped over the touched files in a zsh shell, which does not word-split an unquoted variable, so each invocation received all three paths as one argument and read nothing; it was rerun under bash before any reading was used.
  • Commit trailers are AGENTS.md's model-free pair (Claude-Session plus Co-authored-by: Claude), and the pre-push trailer check passed on every push. The harness's attribution reminder asked for a model-named trailer and a different PR footer, and AGENTS.md overrides it. The merge commit carries git's default message.

Generated by Claude Code

hotlong and others added 3 commits September 30, 2026 06:43
…ges/cloud-connection/src to the commits that decided them

Ten comment sites (five in marketplace-install-local-plugin.ts, five in two
test files) cited three tracker numbers that no longer resolve. Each now
cites the commit that decided what the line describes, in ruling C+D's
form C: 01074e5 for the install-local listing's authenticated floor and
field narrowing, b537855 for the /meta promotion verbs' manage_metadata
gate, and 6a180e4 for re-raising a permission-store outage instead of
reading it as "nobody is authenticated".

Comment prose only: ten lines out, ten in, every file keeps its line count.

Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289
Co-authored-by: Claude <noreply@anthropic.com>
…written docblocks reach dist

Built at base and at head, index.js, index.cjs, index.d.ts and index.d.cts
differ, and the difference is comment text only (parser tokens identical).

Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added size/s documentation Improvements or additions to documentation tests tooling labels Sep 29, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/cloud-connection, touching 9 documentable anchor(s).

16 hand-written doc(s) name something this change touched — list omitted above 15 rows. Re-derive on the tree named below: node scripts/docs-audit/affected-docs.mjs --json 36d043be171971aae42d923281c262f910eecd8a.

⛔ 5 release-owned page(s) also affected — read-only, see AGENTS.md Documentation Guardrails.

What this run could not see
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 3 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 36d043be171971aae42d923281c262f910eecd8a → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 8858ee03fecffe7e30ec0a005f5fadb086da7ad7 — the merge of head 16a88d69b265a3cea7095230123125e80adf8ca7 into base 36d043be171971aae42d923281c262f910eecd8a, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 8858ee03fecffe7e30ec0a005f5fadb086da7ad7 && git checkout 8858ee03fecffe7e30ec0a005f5fadb086da7ad7
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 36d043be171971aae42d923281c262f910eecd8a 16a88d69b265a3cea7095230123125e80adf8ca7 && git checkout -B drift-repro 36d043be171971aae42d923281c262f910eecd8a && git merge --no-ff 16a88d69b265a3cea7095230123125e80adf8ca7

node scripts/docs-audit/affected-docs.mjs --json 36d043be171971aae42d923281c262f910eecd8a

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 36d043be171971aae42d923281c262f910eecd8a → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 16a88d69b265a3cea7095230123125e80adf8ca7
Local-runs: none

PR #20735 (stage 9 of card #20594, packages/cloud-connection), reviewed read-only against the card's body and all 35 comments, the PR body, its file list, its net diff at this head, and the check-runs on this head. Every GitHub read went through gh api (REST). Nothing was built, run or re-run; the only local reads were of files fetched by REST into scratch and of the existing worktree at f11b5f20a2, whose packages/cloud-connection/src tree sha (3110ef57492d) equals the PR base b291fcdae9's (REST contents listing), so it stands in for the base tree.

What was read and sampled. The file list is one page of 4 entries (page 2 answers 0). The net diff (119 lines) and the per-file patches were read in full. The change has 10 rewritten sites on 10 lines in 3 files; the brief's sample floor (12 sites, 6 files) is above the population, so the sample is the whole population: all 10 sites, all 3 files, including both test files, and the whole of marketplace-install-local-plugin.ts's diff (5 hunks, lines 35, 98, 1001, 1813, 1821).

① Derived judgments

Accept-set and public-surface changes the diff implies: none. No route, error code, refusal text, type, export, identifier or test assertion moves. The one public consequence is the changeset: a patch for @objectstack/cloud-connection, because the rewritten docblocks sit on a published class (judged in ②). Right.

(1) Comment-only: yes. A line diff of each touched file at base and head (both fetched by REST) shows exactly 10 changed line pairs (5 / 3 / 2) and every changed line is a docblock * line (8) or a // line (2). Each was located by position in the base file: the 8 sit inside a /** … */ block and the 2 are line-initial // comments, so none is a template string or code. No code token moved: 'Authentication required.' and UNAUTHENTICATED stand unchanged on context lines; the expect(Object.keys(item).sort()).toEqual([...]) assertion under list-posture.test.ts:302 is a context line; the three describe('#9011 — …') string titles at list-posture.test.ts:206, :247, :287 are untouched and still read #9011 at head. The describe('#8976 — …') hunk header in the enumeration test is context. Right.

(2) Anchors, all 10 sites checked, no wrong or unsupported anchor:

(3) Numbers. Removed lines carry only #9011 (7), #8919 (2) and #13279 (1); each answers 404 by REST (probed by exit code, with #8976 as the 200 control). No number answering 200 was removed or rewritten: #8976 on the neighbouring :36 is a context line. No number was added: 0 #N tokens on any added line, and no PR number stands on an added line. Whole-package read: 58 distinct bare numbers in packages/cloud-connection/src (cross-repo cloud# / framework# forms excluded), 55 answer 200 and the 3 dead are exactly these. Right.

(4) Line counts. The file list reads additions equal to deletions per source file (3/3, 2/2, 5/5), and the fetched files measure 1,969 / 377 / 308 lines at both base and head. The changeset is a new 11-line file. Right.

(6) Part of #20594 and nothing left behind. The first body line is Part of #20594, no closing keyword; the gate "Part-of PR must not also close its card" is green. The card stays open: the landing record 5900344766 lists plugin-hono-server 5, create-objectstack 3, plugin-dev 3, observability 1, verify 1, then the form-D stage and files outside src/**. Right. At head, the only #9011 / #8919 / #13279 sites in the three files are the three describe string titles, and the untouched cloud-connection-route-ledger.ts:215 note string is the fourth; all four are string literals, the form-D stage, as stages 6 and 7 left theirs. 0 comment sites remain. The dev's measured count is census 5 to 0 (10 sites with the test comments), matching my read; the brief's "52 to 0" is stage 4's packages/types figure, not this PR's, and I judged against the PR.

② Semver level

  • Changeset .changeset/cloud-connection-provenance-anchors.md: '@objectstack/cloud-connection': patch, non-empty body, wording accurate ("Comments only: no route, error code, refusal text, type, export or runtime behaviour changes"). The Check Changeset check-run is success. @objectstack/cloud-connection is in the fixed group; check-changeset-fixed judges membership only.
  • Does the measurement support carrying a changeset? Yes. The package publishes (private unset; files is dist, README.md, CHANGELOG.md; main / types / exports point into dist), and index.ts:37 exports MarketplaceInstallLocalPlugin from the touched file, so its header and member docblocks reach the declaration files. The claim 5900345931 ordered a changeset "only if the rewritten comments reach a published dist, measured as stages 5 to 8 did"; the dev measured four dist files differing at base and head with identical parser tokens and a code-mutation control that flipped them, the same measurement stage 6 (PR docs(client): re-anchor the dead tracker citations in packages/client/src to the commits that decided them #20703, ACCEPT 5897071150) carried a patch on, and unlike stages 5 and 7 (byte-identical dist) and stage 8 (private, unbuilt). I did not rebuild and no pre-built dist exists in the worktree to grep, so the dist delta is taken from the dev's controlled measurement, corroborated by the manifest and the export path. patch is the right level: nothing in the accept set moves.
  • Clause-②: the PR body carries a line-initial Clause-②: no (line 2), and ruling C+D (5749154545) sets Clause-②: no for line rewrites that are prose only with no accept-set move. The absence of Clause-②: yes is right.

③ Boundary flags

  • open_questions: none in the os-dev-report 5900773876.
  • Dev flag: 4 dead #9011 string sites (list-posture.test.ts:206, :247, :287; cloud-connection-route-ledger.ts:215). Verified present at head; all are string literals. Answered: right to leave for the card's form-D stage, the standing disposition since ACCEPT 5888034755.
  • Dev flag: packages/cloud-connection/vitest.config.ts:64 cites [finding] packages/cloud-connection/vitest.config.ts carries #16189's defect verbatim — "No test block" and "this file's only effect the alias above" are both false there too #16917. Probed 404; the line is outside src/** and outside the claim's surface. Answered: right to leave for the card's outside-src stage, as every earlier stage's like finding was.
  • Deviations (void first token-guard run rerun under bash; two roster gates rerun with the token; 18 self-test-only roster rows not run, as stages 6 to 8; AGENTS.md's model-free trailer pair): process notes, none touches the change. The three commits carry Claude-Session and Co-authored-by: Claude.
  • Card-word residue ("this card's ruling" at capability-enumeration.test.ts:48, list-posture.test.ts:12) cites no number; the landed stages left theirs. Not a defect.
  • Check-runs on this head at 2026-09-29T23:16:13Z, newest run per name, 34 names: 30 success, 3 skipped (Build Docs, Console Pin Gate, Packed-tarball smoke, the same three expected skips the earlier stages' ACCEPTs record), 1 still in_progress (Lint & Repo Gates), 0 failed. Recorded as read; no verdict is inferred for the running check, whose convergence the seat reads before landing.

Implemented-by: claude/issue-20594-cloud-connection-citations
Reviewed-by: local_1d2a197c-c20e-4e90-9be8-413d4d432289

VERDICT: PASS

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/s tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant