docs(observability,verify): re-anchor the dead tracker citations in packages/observability/src and packages/verify/src to the commits that decided them - #20842
Conversation
…he commits that decided them Four comment lines in packages/observability/src and packages/verify/src cited tracker numbers that answer 404. Each now cites the commit in this repository's history that decided what the line describes: - observability semconv.ts: the transport-seam move of http_request_duration_ms -> commit 1e050a5 - verify harness.ts: the host importer's undeclared fallback resolving from the caller -> commit 46d34ab - verify erasure-transaction-authorization.test.ts (two lines): the /admin/remove-user shading that runs gateAdmin before the break-glass guard -> commit 6dd3e69 Comments only; every touched file keeps its line count. Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB Co-authored-by: Claude <noreply@anthropic.com>
…ored comment ships in dist The rewritten SEMCONV comment reaches dist/index.js and dist/index.cjs (one line each; both maps and both .d.ts unchanged). The verify rewrites leave its dist byte-identical, so verify carries no changeset. Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 2 package(s): ⛔ 2 release-owned page(s) name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 5 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 84d05fd1a27cc348671c2099a516054cbb82ae80 && git checkout 84d05fd1a27cc348671c2099a516054cbb82ae80
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8 62e556317c5aaeda8c4dce93d872a178551bf2aa && git checkout -B drift-repro 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8 && git merge --no-ff 62e556317c5aaeda8c4dce93d872a178551bf2aa
node scripts/docs-audit/affected-docs.mjs --json 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8
|
Contract reviewServed-tier: Inputs read: card #20594 body and all 53 comments (the handover Seat correction on adoption: the dev report reads ① Derived judgmentsDiff: 4 files, +15/-4, 2 commits. Three files under Site by site, each judged against the cited commit's own message and diff, with
Anchor choice. Occurrence counts under the two Changeset (
Census (the card's instrument, the dev's runs at Check-runs on the head (converged 2026-09-30T11:45:18Z; the
② Semver level
③ Boundary flagsThe dev report
Both
Nothing needs escalation. Implemented-by: VERDICT: PASS Generated by Claude Code |
Part of #20594
Clause-②: no
What changed
This is stage 13 of the
domain:clilane of the dead-citation sweep:packages/observability/srcandpackages/verify/srcin one PR. The maintainer ruled that in the handover5903477632on the card (「合成一个 PR (Recommended)」). The ruling changes the one-package-per-PR direction for these two packages only, so each package's before and after census counts are listed separately below.Every comment site in these two trees that cited a tracker number answering 404 now cites the commit in this repository's history that made the decision the line describes. The form is ruling C+D's form C (comment
5749154545on #19123), as stages 1 to 12 of this card applied it. The last stage wasplugin-dev, landed asf7c6d65f5. The card stays open for its later stages, so this PR saysPart of.In total, 4 sites on 4 lines in 3 files, covering 3 numbers, now cite 3 distinct commits:
observability: 1 site,src/semconv.ts:49(a census site);verify: 3 sites:src/harness.ts:580(a census site);src/erasure-transaction-authorization.test.ts:163and:167. These are test-file comments, which the census defers. Stages 1 to 12 took test comments too.Only comments changed: 4 lines out, 4 in. Every one of them is a site, with no reflow and no companion line. Every touched file keeps its line count (178 / 955 / 185 at base and head), so no line citation into these files moves.
No citation number is added. The only tracker numbers on added lines are
#9650and#9835atsemconv.ts:49. The removed line already carried both, and both answer 200. No PR number stands on an added line.No ADR or ruling-record file records any of the three decisions. A grep of
docs/adr/andscripts/adr-anchors/for the 3 numbers, the 3 shas,afterResponseandhttp_request_duration_msreads 0 hits; the control number7329reads 1 file in the same tree. So all three anchors are commits.One
patchchangeset, for@objectstack/observabilityonly (.changeset/20594-observability-provenance-anchors.md). Its rewritten//line reaches the publisheddist. Theverifyrewrites leaveverify'sdistbyte-identical, soverifytakes no changeset. Both results are measured below.Census, before and after, one package at a time
Instrument: the gate's own
node scripts/check-issue-citations.mjs --census --json, read-only and unchanged. The count is itsallocated-but-absentfindings under each package's path. Both runs enumerated the whole board (187 pages).22e584c9db)62e556317c)packages/observabilitysrc/semconv.ts:49,#10004)packages/verifysrc/harness.ts:580,#10943)22e584c9db62e556317cThe whole-repo drop of 2 is exactly these two sites. A site-by-site diff of the two JSON outputs has 2 findings gone (
semconv.ts:49,harness.ts:580) and 0 added. The other three tallies are equal in both runs: 33,155 citations that answer 200, 1,985 that answer as pull requests, and 1,018 cross-repo.Supplementary scan (census-invisible spellings, test files and files outside
src/). The scan covers every#Ntoken (two to six digits) in the two packages' 53 tracked files,CHANGELOG.mdexcluded, and probes each by REST (2026-09-30 10:34Z, re-probed 10:58Z).observabilityand 79 inverify, with 1 shared. 86 answer 200 and 4 answer 404:#10004,#10943,#11477and#15145.src/: 1 inobservabilityand 3 inverifyat base, 0 and 0 at head. None of them was in a string literal. At head all 232#Ntokens under the twosrc/trees answer 200.#N-word: 0.#A/#B: 4 sites. Onlysemconv.ts:49held a dead member.option #Norclause #N: 0.word-#N: 1, thepre-#11477at:167, rewritten.issues/N,pull/N): 0. The onlygithub.comstrings are the twopackage.jsonrepository/bugsURLs.verify/tsconfig.test.json:1(see Acceptance notes). A control of the same shape,#9835, reads 2 lines ofsemconv.ts.Per-number table
git blameat the base (on a full, unshallowed history) ties each line to the commit that wrote it. That commit's message and diff were read to decide the anchor.#10004observability/src/semconv.ts:491e050a5b1http_request_duration_msis emitted from theIHttpServer.afterResponsetransport seam, so p95 latency sees every inbound surface. It is the squash of the pull request numbered#10004, and the line cites it beside the two live numbers for the same seam move. The line was written by914c41302(thehttp_request_errors_totalretirement), whose changeset, now the released entry atobservability/CHANGELOG.md:985, cites#10004for this same seam move.#10943verify/src/harness.ts:58046d34ab7c@objectstack/types, andbootStackhands in(s) => import(s). The line blames to this commit. Stages 3 and 4 used the same anchor for the same number incliandtypes.#11477verify/src/erasure-transaction-authorization.test.ts:163,:1676dd3e6968/admin/remove-usergets the raw-mount shading whosegateAdminruns before the break-glass guard (ruled option A, as its message records), so a plain member hearsPERMISSION_DENIED. Both lines blame to this commit. Its squashed message includes thetest(verify)step that rewrote this pin. Theplugin-authstage used the same anchor for the same number.All three shas were checked the same way:
rev-parse --disambiguate.merge-base --is-ancestorof each against base22e584c9dbexits 0, on a history that is not shallow (--is-shallow-repositoryfalse).1e050a5b1^against the base exits 0, and base-as-ancestor-of-1e050a5b1exits 1.Wording per site
semconv.ts:49:(#9650 / #9835 / #10004)becomes(#9650 / #9835 / commit 1e050a5b1). Precedents for a mixed list:cli/src/commands/lint.ts:915,mcp/src/plugin.ts:8.harness.ts:580:#10943:becomesCommit 46d34ab7c:. The neighbouring#4700:,#4719:and#17911:labels answer 200 and stay.erasure-transaction-authorization.test.ts:163:#11477 (maintainer-ruled option A):becomesCommit 6dd3e6968 (maintainer-ruled option A):.erasure-transaction-authorization.test.ts:167:the pre-#11477 routebecomesthe route before that commit, which refers back to:163four lines up.Does the rewrite reach
dist? Measured per packageBoth packages were built at base
22e584c9db(closure plus package,pnpm --workspace-concurrency=2 --filter '@objectstack/verify...' --filter '@objectstack/observability...' build, VERDICT 0) and again at head5a144efc39(VERDICT 0). All 6distfiles of each package were compared byte for byte.observability: reachesdist.index.jsandindex.cjsdiffer in exactly 1 line each: thesemconv.ts:49comment, which esbuild keeps inside theSEMCONVobject literal.index.d.ts,index.d.ctsand both maps are equal.distcarried#10004inindex.jsandindex.cjs.patchchangeset.verify: does not reachdist. All 6 files are byte-equal at base and head, and the basedistcarried none of the three numbers. ⇒ no changeset.verify, which proves that "equal" was a measurement and not a stale build.scripts/ablation-replace.mjsin wrap mode. The anchorconst organizationsPkg = opts.organizationsPackagewent 1 to 0, and the markerABLMARK20594S13went 0 to 1 in the source. The blob moved47a921ad0bto3f54cdebfe.ablation-dist-preflightfound the marker indist/index.jsanddist/index.cjs.index.js,index.cjsand both maps differ from the head build, and both.d.tsfiles are equal.47a921ad0bandgit diff HEADis empty. After a rebuild,preflight --absentreads the marker absent from all 6 files with a clean tree, and all 6 files are byte-equal to the head build.pnpm exec turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2, finished 71/71 (all cache hits). Thedistof both packages is byte-equal to the head build.Token guard
The guard compared TypeScript 6.0.3 parser leaf tokens (
getChildren, JSDoc nodes excluded) of the 3 source files at base22e584c9dband at5a144efc39, over 3,523 base tokens:StringLiteral.The script exited 0, and its controls ran in memory only. A first attempt with a bare scanner was discarded: it misaligns inside template literals and reported a false difference.
Tests, typecheck, lint and gates (head
62e556317c)observabilitytests:pnpm --filter @objectstack/observability exec vitest run --maxWorkers=2→ Test Files 7 passed (7), Tests 85 passed (85).verifytests:pnpm --filter @objectstack/verify exec vitest run --maxWorkers=2→ Test Files 16 passed (16), Tests 120 passed (120). The package has 16 test files,erasure-transaction-authorization.test.tsincluded.verifytypecheck:pnpm --filter @objectstack/verify typecheckpassed, with VERDICT command-exit 0 (tsc --noEmit, thencheck:test-typecheckovertsconfig.test.json: 0 files / 0 errors).tsc --listFilesconfirms thattsconfig.jsonreachesharness.tsandtsconfig.test.jsonreaches both editedverifyfiles.observabilitytypecheck: the package has notypecheckscript; it is a DEBT entry incheck-type-check-coverage.mjsat 11 errors.tsc -p packages/observability/tsconfig.json --noEmitreads 11 errors, all insrc/__tests__/, none insemconv.ts, and the program includessemconv.ts.pnpm check:type-check-coverageandpnpm check:type-check-debtpass (exit 0).pnpm lint: the repo-wideeslint . --no-inline-configexits 0 (2026-09-30 10:54:08 to 10:57:25 UTC, at62e556317c).node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands(run with no path) derived 60 commands, and all 60 were run with their exit codes recorded before any pipe.pnpm check:dual-build-cjs-loadsfirst exited 3 (PREREQUISITE NOT MET: nodistfor 33 packages). After the whole-workspace build it was run again and exited 0.--ranreconciliation: 「60 derived, 60 run, 0 NOT-MEASURED, 0 UNRUN」, exit 0.node scripts/check-issue-citations.mjsjudged the 2 citations this change adds (#9650,#9835); both answer 200, exit 0.pnpm check:nul-bytespassed, and a control-byte scan of the 4 changed files reads 0.origin/mainmoved 8 commits past the base (to1741c5dcb6).git diff --name-onlyover the two packages and the changeset path reads 0 files, so this branch was not merged forward. The merge ref CI builds covers the joint tree.Acceptance notes
src/**, listed and not changed (a later stage of the card):packages/verify/tsconfig.test.json:1cites#15145, which answers 404. The other 14 citations outsidesrc/**in the two packages answer 200:observability/vitest.config.ts:11,verify/tsconfig.json:5and:13,verify/tsconfig.test.json:1,:2,:32,:35,:43and:60, andverify/vitest.config.ts:8,:14,:32,:63and:70.README.mdin either package carries no#N.packages/observability/CHANGELOG.md:985carries#10004(with#9834) in a released entry. This PR does not edit it.CHANGELOG.mdandpackage.json.Generated by Claude Code