docs(plugin-dev): re-anchor the dead tracker citations in packages/plugins/plugin-dev/src to the commits that decided them - #20767
Conversation
…ugins/plugin-dev/src to the commits that decided them Six comment lines in three files cited two tracker numbers that no longer resolve. Each now cites the commit in this repository's history that decided what the line describes (ruling C+D, form C): - the security-enforcement warning asks the published `security` service, and asks it in start(): commit 7552e03 (dev-plugin.ts x2, and three test-file comments); - plugin-hono-server's current-user endpoints key on the same published service instead of the init()-registered internals: commit c1731d0 (dev-plugin.ts x1). Comments only; every touched file keeps its line count. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude <noreply@anthropic.com>
…rovenance comments The two rewritten docblock lines reach dist (index.js, index.mjs, index.d.ts, index.d.mts), so the package ships different bytes and takes a patch changeset, in the form the earlier stages of this sweep used. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 1 package(s): 1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
What this run could not see
Coarse fallback — 3 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 8452a32c8a492e655d182c9e620969aa637efa1f && git checkout 8452a32c8a492e655d182c9e620969aa637efa1f
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin a51920f5fb1059ae6e8c7b1a96aa785f1da5d248 a237b10ee73b097d836b08da5af92e1bae1872f1 && git checkout -B drift-repro a51920f5fb1059ae6e8c7b1a96aa785f1da5d248 && git merge --no-ff a237b10ee73b097d836b08da5af92e1bae1872f1
node scripts/docs-audit/affected-docs.mjs --json a51920f5fb1059ae6e8c7b1a96aa785f1da5d248
|
Contract reviewServed-tier: Inputs read: card #20594 body and all 49 comments (the dev report Seat correction on adoption: the reviewer wrote that ① Derived judgmentsDiff: 4 files, +17/-6. Three files under Site by site, each judged against the cited commit's own message and diff:
Anchor choice.
Changeset (
Left in the package, and right to leave: Check-runs on the head:
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
Part of #20594
Clause-②: no
What changed
This is stage 12 of the
domain:clilane of the dead-citation sweep:packages/plugins/plugin-dev/src. Every comment site there that cited a tracker number answering 404 now cites, in ruling C+D's form C (comment 5749154545 on #19123), the commit in this repository's history that decided what the line describes, and keeps saying in its own words what that commit decided. PR #20533 is the method, and stages 1 to 11 of this card (PR #20624, PR #20632, PR #20656, PR #20673, PR #20689, PR #20703, PR #20713, PR #20723, PR #20735, PR #20741, PR #20748) are the precedents. The card stays open for the lane's remaining packages, so this PR saysPart of.That is 6 sites on 6 lines in 3 files, covering 2 numbers, rewritten to 2 distinct commits:
src/dev-plugin.ts(:1063,:1078,:1097);*.test.ts; stages 1 to 11 took test comments too):dev-plugin.test.ts:90and:127,dev-plugin-security-enforcement-warning.test.ts:53.Only comments changed: 6 lines out, 6 in, every one of them a site (no companion line), and every touched file keeps its line count (1159 / 317 / 199), so no line citation into these files moves. No citation number is added: the only tracker number on an added line is
#3900atdev-plugin.ts:1063, which the removed line already carried and which answers 200; no PR number stands on an added line. No ADR or ruling-record file indocs/adr/orscripts/adr-anchors/records either decision (a grep there for the 2 numbers, their PR number #10092 and the 2 shas reads 0 hits; the control number7329reads 1 file in the same tree), so both anchors are commits. ADR-0115 records the older decision the warning comes from (an empty security slot gets one loud boot-log line), not the move these lines describe.A
patchchangeset for@objectstack/plugin-devrides along (.changeset/plugin-dev-provenance-anchors.md, in PR #20632's form), because the two rewritten docblock lines reach the publisheddist(measured below), as stage 6 (PR #20703) measured for its package.Census:
packages/plugins/plugin-dev, before and afterInstrument. The gate's own
node scripts/check-issue-citations.mjs --census --json, read-only and unchanged, run underwith-fleet.sh --readfor the token. The count is itsallocated-but-absentfindings underpackages/plugins/plugin-dev/. Both runs enumerated the whole board.allocated-but-absent33e4a5609c, run 2026-09-30T02:45:30Z to 02:51:51Za237b10ee7, run 03:07:39Z to 03:14:14ZThe whole-repo drop of 3 is exactly these sites: a site-by-site diff of the two JSON outputs has 3 findings gone (
dev-plugin.ts:1063,:1078,:1097) and none added. The other three tallies (resolves33,038,resolves-as-pull-request1,984,cross-repo-unjudged995) are equal in both runs.Supplementary scan (test files, strings and files outside
src/included). Every#Ntoken (two to six digits) in the package's 19 tracked files,CHANGELOG.mdexcluded, was probed by REST: 39 distinct numbers at base, of which 2 answer 404 insrc/(#10035,#10036) and 1 outside it (#13176, intsconfig.test.json);#1020iscloud#1020, cross-repo. Dead occurrences at base: 6 insrc/comments (3 source, 3 test), 1 in a test string, 2 intsconfig.test.json. After: 0 in comments, the test string and the twotsconfig.test.jsonlines unchanged (see Acceptance notes). A grep for the two numbers with no word-boundary operator, beside a control of the same shape (#3900reads 6 lines ofdev-plugin.ts), finds only those three lines left.Per-number table
git blameat the base ties every one of the 6 lines to7552e0337, the commit that wrote them, and each anchor was read in its message and its diff, not only its subject.#10036dev-plugin.ts:1063,:1078;dev-plugin.test.ts:90,:127;dev-plugin-security-enforcement-warning.test.ts:537552e0337: the "RBAC/RLS/masking are NOT enforced" warning stops probing the threeSecurityPlugin.init()internals (security.permissions,security.rls,security.fieldMasker, which the spec contract names implementation internals) and asks the publishedsecurityservice instead, and asks it fromDevPlugin.start(), after the child-start loop and beside the boot banner, since asking frominit()would find it absent on every stack; the internal handles keep one use, telling "never loaded" apart from "loaded, then failed to start". Both halves of its squash message carry this number. Its own PR number (#10092) answers 404 as well.#10035dev-plugin.ts:1097c1731d023:plugin-hono-server's/auth/me/permissionsand/me/appsdelegate permission-set resolution to thesecurityservice, and their degraded branches key on the publishedsecurityservice instead ofsecurity.permissions(its docblock "What absent now means, precisely"). The site's sentence says the same presence signal misled that endpoint and was cured "by this same move";#10035is that commit's own PR number, carried in its subject.How the lines read now.
:1063keeps#3900and sayscommit 7552e0337 moved this check here from init(); the:1078heading and the test-comment brackets namecommit 7552e0337where the number stood, with the decision spelled out in the surrounding prose they already carried;:127reads(the two told apart since commit 7552e0337);:1097readscommit c1731d023 by this same move.Anchor checks. Both cited shas match exactly one object (
git rev-parse --disambiguate, count 1 each), are commits, have one parent, and are ancestors ofmain(merge-base --is-ancestoragainst33e4a5609c, exit 0 for both). The checkout is not shallow. Control legs:44738f7af6(the parent ofc1731d023) exits 0 against the base; the negative control (the base as an ancestor of7552e0337) exits 1.Numbers.
#10035,#10036and#10092answer 404 by REST (probed 2026-09-30T02:43:04Z and again at 03:14:40Z).#3900, kept on:1063, answers 200.Mechanical guard: no code token moves
H2 holds on the token reading; the emitted
distis NOT byte-identical, and the difference is exactly the two docblock lines.Token guard. It compares the TypeScript parser's leaf tokens (TypeScript 6.0.3,
getChildrenwalk, JSDoc nodes excluded) of the 3 touched files at base33e4a5609cand at37eaf1647f(the comment commit). Controls mutate the head text in memory only.StringLiteral.All 12 changed lines in
src/(6 out, 6 in) are//or*comment lines.Emitted
dist.pnpm --filter @objectstack/plugin-dev buildat base (before any edit, after its dependency closure) and at37eaf1647f. Of the 6distfiles,index.js.mapandindex.mjs.maphave equal sha256;index.js,index.mjs,index.d.tsandindex.d.mtsdiffer, anddiff -rshows exactly two changed lines in each: the:1078heading and the:1097line of thewarnIfNothingIsEnforcingSecuritydocblock. The//comment at:1063does not ship. So the published tarball carried both dead numbers, and now carries the commits.scripts/ablation-replace.mjs, wrap mode, anchorctx.logger.info(' Discovery: /.well-known/objectstack');hit 1 to 0, planted marker 0 to 1, blob708af69f9b2atob0b387f53d6a;scripts/ablation-dist-preflight.mjsfound the marker indist/index.jsanddist/index.mjs):index.js,index.mjsand both source maps differ from the head build. The blob was restored to HEAD708af69f9b2awithgit diff HEADempty,distwas rebuilt, the preflight in--absentmode reads the marker absent from all 6 files with a clean tree, and the 6 sha256 values equal the head build.plugin-dev'sdistequal to the same 6 values.A raw scan of the 4 changed files for ASCII control bytes finds none (a positive probe on a scratch file with one such byte reads 1), and
check:nul-bytesexits 0.Changeset
patchfor@objectstack/plugin-dev. The package publishes (filesisdist,README.md,CHANGELOG.md), and the measurement above shows the rewritten docblock reaching fourdistfiles. The changeset states comments only, with no behaviour change.check-empty-changeset,check-changeset-no-major,check-adr-0087-registration(1 non-breaking changeset seen) andcheck-changeset-fixedall exit 0.Gates (head
a237b10ee7)This host has no
flock, soos-verify-lock.shran in its declared unlocked mode. Its official wording, verbatim (printed by every run; the command line differs per run and is listed in the verdicts below):Its verdict line from each run (the closure build at base
33e4a5609c; the head build at37eaf1647f; the whole-workspace build, the tests and the typecheck at this head):plugin-devwith its dependency closure (36 packages, the filter spelled with the package included), then the package, then the whole workspace,turbo run build --filter=./packages/* --filter=./packages/*/* --concurrency=2, 71 of 71 tasks. The tree was clean after each.vitest run --maxWorkers=2: 9 files, 86 tests, all passed.pnpm --filter @objectstack/plugin-dev typecheck(tsc --noEmit, thencheck:test-typecheckovertsconfig.test.json) exits 0.--listFilesunder both configs reaches all 12src/files, including the 9 tests and the 3 touched files.origin/maindid not move while this branch was open (still33e4a5609c; the merge was a no-op), and this diff does not touchpackages/spec.pnpm lint(eslint . --no-inline-config) exits 0 at this head (2026-09-30T03:07:02Z to 03:07:32Z).origin/main(already up to date at33e4a5609c),node scripts/check-issue-citations.mjs --base origin/mainjudges 1 added citation (#3900), which resolves (exit 0).node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commandsderived 62 families from the 4 changed paths. All 62 exit 0 in one pass at this head, and--ranwith the exit-coded record reads "62 derived, 62 run, 0 NOT-MEASURED, 0 UNRUN" (a derived zero). Among them:check:issue-citations,check:doc-authoring,check:nul-bytes,check:published-files,check:cross-package-test-inputs,check:dts-closure,check:dual-build-cjs-loads,check:type-check-debt,check-empty-changeset,check-adr-0087-registration.check-changeset-fixedand the three others the derivation marks as keeping their roster under one of this diff's paths (check:authz-resolver,check:error-code-casing,check:filter-alias-parity). The other three need a pull request's context; they are run against this PR once it exists and reported on the card. The 18 self-test-only rows grade their checkers' fixtures and cannot judge this diff.Hypotheses (measured first)
33e4a5609cthe filtered census answers 3 sites on 3 lines, 2 numbers, 1 file, as on the seat's0be898499f. The whole-repo count is 1,061.packages/plugins/plugin-dev. No site was left for an open PR (the file lists of all 8 open PRs were read at 2026-09-30T02:45:10Z: only the Version Packages PR chore: version packages #20639 touches the package, inCHANGELOG.mdandpackage.json) or for an unfound anchor.distreading. The parser leaf-token diff of all 3 touched files is empty with its controls firing. The emitteddistis not byte-identical, and it is not meant to be: its only difference is the two docblock lines, which is why the changeset ships.Acceptance notes
describetitle atdev-plugin-security-enforcement-warning.test.ts:121(#10036). It stays on the card for its form-D stage; no string moved here. It is not assertion text. The same title is quoted in three recorded CI-log fixtures underscripts/fixtures/merge-queue-triage/; those are captured logs read bycheck-merge-queue-triage-outcome.mjs, so a later rename of the title does not need them edited.src/**:tsconfig.test.json:3and:56cite#13176, which answers 404. The same number sits in thetsconfig.test.jsonof 13packages/plugins/*packages (17tsconfig*.jsonfiles underpackages/in all), outside the census's declared surface; stage 10 (PR docs(plugin-hono-server): re-anchor the dead tracker citations in packages/plugins/plugin-hono-server/src to the commits that decided them #20741) recorded its own copy for a later stage of this card. Every other citation in the package outsidesrc/answers 200 (vitest.config.ts,README.md,tsconfig.json,package.json);CHANGELOG.mdis release-owned and was not read as a site.origin/maindid not move. It read33e4a5609cat worktree creation and at every later fetch, so every run above is against the same base and nothing needed rerunning after the merge.Deviations
os-verify-lock.sh. On this host that wrapper runs unlocked anyway, so nothing was serialized either way.'@objectstack/plugin-dev...'(package plus its dependencies) rather than the closure-only^...spelling; it built the same closure and the package in one run.Claude-SessionplusCo-authored-by: Claude), and the pre-push trailer check passed on every push. The harness's attribution reminder asked for a model-named trailer and a different PR footer, and AGENTS.md overrides it.Generated by Claude Code