Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .changeset/20234-liveness-ledger-provenance-anchors-3.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
'@objectstack/spec': patch
---

Notes in twenty-one more liveness ledgers, and one `datasource` evidence string, cite the commit that decided them, or say the decision in words, instead of a tracker number that no longer resolves

Clause-②: no

Notes in the `book`, `doc`, `job`, `validation`, `translation`, `hook`, `seed`, `flow`,
`capability`, `qa`, `dashboard`, `action`, `agent`, `skill`, `tool`, `rest_api`,
`route_generation`, `crud_endpoints`, `metadata_endpoints`, `batch_endpoints` and
`analytics_cube` ledgers cited tracker numbers that no longer resolve on GitHub, so a reader
could not tell why a row carries its verdict. Each such note now either names the commit that
made the decision or, where the number alone carried the meaning, says what was decided. The
`datasource` ledger's `ssl.rejectUnauthorized` evidence string cited one such number in its
prose; it now names the commit that made the fix, and its code anchors are unchanged. The
`liveness/` ledgers ship in this package's tarball, which is why this is a release note at all.
Note text and that one evidence parenthesis only: no row's status, proof or date changes, and
no schema, export or runtime behaviour changes.
10 changes: 5 additions & 5 deletions packages/spec/liveness/action.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion packages/spec/liveness/agent.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"type": "agent",
"_note": "AgentSchema. Seeded from docs/audits/2026-06-agentschema-property-liveness.md. agent-runtime.ts is the PRINCIPAL runtime consumer, not the only one: `routes/agent-routes.ts`, `routes/assistant-routes.ts`, `routes/agent-access.ts` and `eval/eval-runner.ts` each read keys classified here, and `planning` is read in three of those and in agent-runtime.ts NOT AT ALL — the citation this entry carried for it named the wrong file until 2026-09-15 (#13272). AgentPreview is display-only. ⚠ EVIDENCE LIVES IN CLOUD/EE: the `cloud @<sha>: packages/service-ai/...` paths cited below are the closed `@objectstack/service-ai` runtime in the CLOUD repo, NOT git-tracked framework code. 2026-08-30 (#13272): the previous wording of this sentence was false in BOTH halves. (a) It called the framework's own service-ai tree “a stale build artifact with no src/” — there is no tree at all: `packages/services/` holds every sibling service EXCEPT service-ai, and `git ls-files | grep -ic service-ai` returns 0. Absent, not stale. (b) The citations spelled `packages/services/service-ai/...`, a path present in NEITHER repo; cloud's real layout, measured at cloud@15f55df (#13042), is `packages/service-ai/...`. Every citation below now carries the explicit `cloud` realm marker, so it is attributed by the marker `scanEvidence` reads rather than riding the `FOREIGN_PATH_PREFIXES` special case that silently exempted the stale spelling from resolution — which is why 22 dead pointers sat green. ✅ RE-VERIFIED 2026-09-15 (#13272): the re-verification half this entry parked is discharged. Every cloud consumer cited below was re-read in a cloud checkout at cloud @cb8ee7ff60c097cc21a584fe9caf8ef4391cc0e8, and the ten rows the read confirmed now carry `verifiedAt`, `evidenceScope: cross-repo`, and a `#symbol` anchor pinned to the consumer instead of a line number — the two cited line numbers (`agent-runtime.ts:264`, `agent-access.ts:50`) had both drifted onto prose, which is the rot a line citation produces and a symbol does not. The anchors are the load-bearing half, and they are why the DATE matters: `scanEvidence` never collects an anchor while a foreign realm marker is in force, so CI cannot re-derive a single one of the cloud anchors — each rests on that dated reading alone. ⛔ Never re-stamp `verifiedAt` here without re-reading cloud; a bare re-stamp restores exactly the unfalsifiable pointer this entry's history is made of. ⛔ ONE ROW WAS DELIBERATELY NOT STAMPED, AND HAS SINCE BEEN RE-GRADED. `tools` was FALSIFIED by the same read: zero consumers in cloud at that ref, where the only two mentions are comments recording the removal of the branch, while this repo's own AgentSchema already declares the key `retiredKey(...)`. A `verifiedAt` beside `live` would have certified the wrong thing, so #13272 left that row's `status`, `note` and old evidence untouched and handed the liveness re-grade to triage as #18304; triage graded it (b) and the re-grade LANDED 2026-09-18 — `live` -> `dead`, the stale `evidence` pointer deleted, and the cloud reading attributed and dated inside the row's own `note`. Note the shape — that row sat `live` since the 2026-06 audit BECAUSE `FOREIGN_PATH_PREFIXES` exempted its citation from resolution, so the exemption this card was filed about had hidden a dead key, not only a misspelled path. These props are `live` because that cloud runtime consumes them; the OPEN framework edition does not — see content/docs/ai for the open/cloud boundary. 2026-07-30 (#3896 close-out sweep): the dead authoring keys were REMOVED — tombstoned at the schema with prescriptions (retiredKey) and stripped by the protocol-17 close-out conversions; entries deleted per the #3715 precedent. agent.knowledge (and AIKnowledgeSchema) removed; the topics→sources rename was absorbed into the removal pre-release.",
"_note": "AgentSchema. Seeded from docs/audits/2026-06-agentschema-property-liveness.md. agent-runtime.ts is the PRINCIPAL runtime consumer, not the only one: `routes/agent-routes.ts`, `routes/assistant-routes.ts`, `routes/agent-access.ts` and `eval/eval-runner.ts` each read keys classified here, and `planning` is read in three of those and in agent-runtime.ts NOT AT ALL — the citation this entry carried for it named the wrong file until 2026-09-15 (#13272). AgentPreview is display-only. ⚠ EVIDENCE LIVES IN CLOUD/EE: the `cloud @<sha>: packages/service-ai/...` paths cited below are the closed `@objectstack/service-ai` runtime in the CLOUD repo, NOT git-tracked framework code. 2026-08-30 (#13272): the previous wording of this sentence was false in BOTH halves. (a) It called the framework's own service-ai tree “a stale build artifact with no src/” — there is no tree at all: `packages/services/` holds every sibling service EXCEPT service-ai, and `git ls-files | grep -ic service-ai` returns 0. Absent, not stale. (b) The citations spelled `packages/services/service-ai/...`, a path present in NEITHER repo; cloud's real layout, measured at cloud@15f55df (commit c19035e97), is `packages/service-ai/...`. Every citation below now carries the explicit `cloud` realm marker, so it is attributed by the marker `scanEvidence` reads rather than riding the `FOREIGN_PATH_PREFIXES` special case that silently exempted the stale spelling from resolution — which is why 22 dead pointers sat green. ✅ RE-VERIFIED 2026-09-15 (#13272): the re-verification half this entry parked is discharged. Every cloud consumer cited below was re-read in a cloud checkout at cloud @cb8ee7ff60c097cc21a584fe9caf8ef4391cc0e8, and the ten rows the read confirmed now carry `verifiedAt`, `evidenceScope: cross-repo`, and a `#symbol` anchor pinned to the consumer instead of a line number — the two cited line numbers (`agent-runtime.ts:264`, `agent-access.ts:50`) had both drifted onto prose, which is the rot a line citation produces and a symbol does not. The anchors are the load-bearing half, and they are why the DATE matters: `scanEvidence` never collects an anchor while a foreign realm marker is in force, so CI cannot re-derive a single one of the cloud anchors — each rests on that dated reading alone. ⛔ Never re-stamp `verifiedAt` here without re-reading cloud; a bare re-stamp restores exactly the unfalsifiable pointer this entry's history is made of. ⛔ ONE ROW WAS DELIBERATELY NOT STAMPED, AND HAS SINCE BEEN RE-GRADED. `tools` was FALSIFIED by the same read: zero consumers in cloud at that ref, where the only two mentions are comments recording the removal of the branch, while this repo's own AgentSchema already declares the key `retiredKey(...)`. A `verifiedAt` beside `live` would have certified the wrong thing, so #13272 left that row's `status`, `note` and old evidence untouched and handed the liveness re-grade to triage as #18304; triage graded it (b) and the re-grade LANDED 2026-09-18 — `live` -> `dead`, the stale `evidence` pointer deleted, and the cloud reading attributed and dated inside the row's own `note`. Note the shape — that row sat `live` since the 2026-06 audit BECAUSE `FOREIGN_PATH_PREFIXES` exempted its citation from resolution, so the exemption this card was filed about had hidden a dead key, not only a misspelled path. These props are `live` because that cloud runtime consumes them; the OPEN framework edition does not — see content/docs/ai for the open/cloud boundary. 2026-07-30 (#3896 close-out sweep): the dead authoring keys were REMOVED — tombstoned at the schema with prescriptions (retiredKey) and stripped by the protocol-17 close-out conversions; entries deleted per the #3715 precedent. agent.knowledge (and AIKnowledgeSchema) removed; the topics→sources rename was absorbed into the removal pre-release.",
"props": {
"name": {
"status": "live",
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/liveness/analytics_cube.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"type": "analytics_cube",
"_note": "CubeSchema (packages/spec/src/data/analytics.zod.ts). Seeded 2026-09-17 (#18582): the LAST of the three PENDING_GOVERNANCE debts #18133 declared when PR #18581 widened the governance denominator from the registered kinds to `authorableTypes()`; `sharing_rule` was paid first (PR #18587) and `connector` is paid in the same diff as this file, which empties the map. NOT a registered metadata KIND — it is bound in `UNREGISTERED_KIND_SCHEMAS` (#10194) and reaches this walk through `getMetadataTypeSchema`'s unregistered-kind fallback, so the ledger governs it while `listMetadataTypeSchemaTypes()` still does not enumerate it. THE SHAPE FACT THAT DECIDES EVERY ROW BELOW: one Cube shape, THREE producers, one registry. `packages/services/service-analytics/src/cube-registry.ts` names them itself — (1) authored cubes (`defineStack({ analyticsCubes })` / `defineCube()`), threaded by the CLI into `AnalyticsServiceConfig.cubes` and registered by `registerAll`; (2) COMPILED DATASETS (ADR-0021), where `dataset-compiler.ts` MINTS a Cube from a `dataset` document; (3) ad-hoc query inference (`inferCubeFromQuery`). Only (1) is the authoring door this ledger governs, so a key whose only reader sits on path (2) is NOT live here however busy that reader is — that is the #4837 producer rule applied to a shape with three producers, and it is what kept `dimensions.granularities` and `measures.format` dead until 2026-09-29, when the query doors began reading both off whichever cube answers the name (their rows). Every `live` row therefore carries a `producer` naming the CLI threading site: a consumer citation alone would be the `seed.env` shape, where the mechanism was right and nobody supplied the input. #10238 IS NOT PREJUDGED: the PENDING_GOVERNANCE row this file discharges said whether cube authoring is live end-to-end is its own measurement and 'this row does not prejudge it'. This ledger does not answer that question either — it answers the per-key one (who reads this key?), and the answers below are mixed: the query path (`sql`, `measures.sql`/`.type`, `dimensions.sql`/`.type`, `joins.name`) is genuinely consumed, and so is the visibility key `public` (enforced at discovery and at every query door since 2026-09-27 — its row), and so are the measure display `format` and the dimension default bucket `granularities` (read on the query doors since 2026-09-29 — their rows), and so are the three `description` annotations (published on discovery by `getMeta` since 2026-09-29 — their rows), while the retired caching block is not. PREVIEW READ POINTS ENUMERATED (the #7131 mechanical rule, objectui @dda8f3815): `registerBuiltinPreviews()` in packages/app-shell/src/views/metadata-admin/previews/index.ts registers nineteen types and `analytics_cube` is NOT one of them — this type has no registered metadata-admin preview. Recorded rather than skipped, because 'the type has no registered preview' is the sentence a later sweep needs. What objectui DOES consume is the whole SHAPE: `clientValidation.ts` maps `analytics_cube` to `CubeSchema` itself, and unlike `sharing_rule` it is absent from `AUTHOR_SHAPE_ONLY_TYPES`, so both the CREATE and the EDIT door in metadata-admin refuse a cube this schema rejects. ADR-0054: no row here carries a `proof`, and none is owed — the `analytics` high-risk class binds `dataset/dimensions.dateGranularity` (the dataset door), not this type.",
"_note": "CubeSchema (packages/spec/src/data/analytics.zod.ts). Seeded 2026-09-17 (#18582): the LAST of the three PENDING_GOVERNANCE debts #18133 declared when PR #18581 widened the governance denominator from the registered kinds to `authorableTypes()`; `sharing_rule` was paid first (PR #18587) and `connector` is paid in the same diff as this file, which empties the map. NOT a registered metadata KIND — it is bound in `UNREGISTERED_KIND_SCHEMAS` (commit 2306a765c) and reaches this walk through `getMetadataTypeSchema`'s unregistered-kind fallback, so the ledger governs it while `listMetadataTypeSchemaTypes()` still does not enumerate it. THE SHAPE FACT THAT DECIDES EVERY ROW BELOW: one Cube shape, THREE producers, one registry. `packages/services/service-analytics/src/cube-registry.ts` names them itself — (1) authored cubes (`defineStack({ analyticsCubes })` / `defineCube()`), threaded by the CLI into `AnalyticsServiceConfig.cubes` and registered by `registerAll`; (2) COMPILED DATASETS (ADR-0021), where `dataset-compiler.ts` MINTS a Cube from a `dataset` document; (3) ad-hoc query inference (`inferCubeFromQuery`). Only (1) is the authoring door this ledger governs, so a key whose only reader sits on path (2) is NOT live here however busy that reader is — that is the #4837 producer rule applied to a shape with three producers, and it is what kept `dimensions.granularities` and `measures.format` dead until 2026-09-29, when the query doors began reading both off whichever cube answers the name (their rows). Every `live` row therefore carries a `producer` naming the CLI threading site: a consumer citation alone would be the `seed.env` shape, where the mechanism was right and nobody supplied the input. THE END-TO-END MEASUREMENT IS NOT PREJUDGED: the PENDING_GOVERNANCE row this file discharges said whether cube authoring is live end-to-end is its own measurement and 'this row does not prejudge it'. This ledger does not answer that question either — it answers the per-key one (who reads this key?), and the answers below are mixed: the query path (`sql`, `measures.sql`/`.type`, `dimensions.sql`/`.type`, `joins.name`) is genuinely consumed, and so is the visibility key `public` (enforced at discovery and at every query door since 2026-09-27 — its row), and so are the measure display `format` and the dimension default bucket `granularities` (read on the query doors since 2026-09-29 — their rows), and so are the three `description` annotations (published on discovery by `getMeta` since 2026-09-29 — their rows), while the retired caching block is not. PREVIEW READ POINTS ENUMERATED (the #7131 mechanical rule, objectui @dda8f3815): `registerBuiltinPreviews()` in packages/app-shell/src/views/metadata-admin/previews/index.ts registers nineteen types and `analytics_cube` is NOT one of them — this type has no registered metadata-admin preview. Recorded rather than skipped, because 'the type has no registered preview' is the sentence a later sweep needs. What objectui DOES consume is the whole SHAPE: `clientValidation.ts` maps `analytics_cube` to `CubeSchema` itself, and unlike `sharing_rule` it is absent from `AUTHOR_SHAPE_ONLY_TYPES`, so both the CREATE and the EDIT door in metadata-admin refuse a cube this schema rejects. ADR-0054: no row here carries a `proof`, and none is owed — the `analytics` high-risk class binds `dataset/dimensions.dateGranularity` (the dataset door), not this type.",
"props": {
"name": {
"status": "live",
Expand Down
Loading
Loading