Skip to content

docs(observability,verify): re-anchor the dead tracker citations in packages/observability/src and packages/verify/src to the commits that decided them - #20842

Merged
objectstack-fleet[bot] merged 2 commits into
mainfrom
claude/issue-20594-observability-verify-citations
Sep 30, 2026
Merged

objectstack-fleet[bot] merged 2 commits into
mainfrom
claude/issue-20594-observability-verify-citations

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Part of #20594
Clause-②: no

What changed

This is stage 13 of the domain:cli lane of the dead-citation sweep: packages/observability/src and packages/verify/src in one PR. The maintainer ruled that in the handover 5903477632 on the card (「合成一个 PR (Recommended)」). The ruling changes the one-package-per-PR direction for these two packages only, so each package's before and after census counts are listed separately below.

Every comment site in these two trees that cited a tracker number answering 404 now cites the commit in this repository's history that made the decision the line describes. The form is ruling C+D's form C (comment 5749154545 on #19123), as stages 1 to 12 of this card applied it. The last stage was plugin-dev, landed as f7c6d65f5. The card stays open for its later stages, so this PR says Part of.

In total, 4 sites on 4 lines in 3 files, covering 3 numbers, now cite 3 distinct commits:

  • observability: 1 site, src/semconv.ts:49 (a census site);
  • verify: 3 sites:
    • src/harness.ts:580 (a census site);
    • src/erasure-transaction-authorization.test.ts:163 and :167. These are test-file comments, which the census defers. Stages 1 to 12 took test comments too.

Only comments changed: 4 lines out, 4 in. Every one of them is a site, with no reflow and no companion line. Every touched file keeps its line count (178 / 955 / 185 at base and head), so no line citation into these files moves.

No citation number is added. The only tracker numbers on added lines are #9650 and #9835 at semconv.ts:49. The removed line already carried both, and both answer 200. No PR number stands on an added line.

No ADR or ruling-record file records any of the three decisions. A grep of docs/adr/ and scripts/adr-anchors/ for the 3 numbers, the 3 shas, afterResponse and http_request_duration_ms reads 0 hits; the control number 7329 reads 1 file in the same tree. So all three anchors are commits.

One patch changeset, for @objectstack/observability only (.changeset/20594-observability-provenance-anchors.md). Its rewritten // line reaches the published dist. The verify rewrites leave verify's dist byte-identical, so verify takes no changeset. Both results are measured below.

Census, before and after, one package at a time

Instrument: the gate's own node scripts/check-issue-citations.mjs --census --json, read-only and unchanged. The count is its allocated-but-absent findings under each package's path. Both runs enumerated the whole board (187 pages).

package before (base 22e584c9db) after (head 62e556317c)
packages/observability 1 (src/semconv.ts:49, #10004) 0
packages/verify 1 (src/harness.ts:580, #10943) 0
whole repository 752 750
run tree when (UTC) board
before base 22e584c9db 2026-09-30 10:33:12 to 10:37:06 frontier #20838, 18,665 numbers
after head 62e556317c 2026-09-30 10:49:43 to 10:53:16 frontier #20839, 18,666 numbers

The whole-repo drop of 2 is exactly these two sites. A site-by-site diff of the two JSON outputs has 2 findings gone (semconv.ts:49, harness.ts:580) and 0 added. The other three tallies are equal in both runs: 33,155 citations that answer 200, 1,985 that answer as pull requests, and 1,018 cross-repo.

Supplementary scan (census-invisible spellings, test files and files outside src/). The scan covers every #N token (two to six digits) in the two packages' 53 tracked files, CHANGELOG.md excluded, and probes each by REST (2026-09-30 10:34Z, re-probed 10:58Z).

  • It finds 90 distinct numbers: 12 in observability and 79 in verify, with 1 shared. 86 answer 200 and 4 answer 404: #10004, #10943, #11477 and #15145.
  • Dead occurrences in src/: 1 in observability and 3 in verify at base, 0 and 0 at head. None of them was in a string literal. At head all 232 #N tokens under the two src/ trees answer 200.
  • Spellings the census cannot see:
    • #N-word: 0.
    • #A/#B: 4 sites. Only semconv.ts:49 held a dead member.
    • option #N or clause #N: 0.
    • word-#N: 1, the pre-#11477 at :167, rewritten.
    • URL forms (issues/N, pull/N): 0. The only github.com strings are the two package.json repository/bugs URLs.
  • A re-grep of the four numbers with no word-boundary operator finds only verify/tsconfig.test.json:1 (see Acceptance notes). A control of the same shape, #9835, reads 2 lines of semconv.ts.

Per-number table

git blame at the base (on a full, unshallowed history) ties each line to the commit that wrote it. That commit's message and diff were read to decide the anchor.

number sites (file:line) anchor what that commit decided
#10004 observability/src/semconv.ts:49 1e050a5b1 http_request_duration_ms is emitted from the IHttpServer.afterResponse transport seam, so p95 latency sees every inbound surface. It is the squash of the pull request numbered #10004, and the line cites it beside the two live numbers for the same seam move. The line was written by 914c41302 (the http_request_errors_total retirement), whose changeset, now the released entry at observability/CHANGELOG.md:985, cites #10004 for this same seam move.
#10943 verify/src/harness.ts:580 46d34ab7c The host importer's undeclared fallback resolves from the caller's base, not from @objectstack/types, and bootStack hands in (s) => import(s). The line blames to this commit. Stages 3 and 4 used the same anchor for the same number in cli and types.
#11477 verify/src/erasure-transaction-authorization.test.ts:163, :167 6dd3e6968 /admin/remove-user gets the raw-mount shading whose gateAdmin runs before the break-glass guard (ruled option A, as its message records), so a plain member hears PERMISSION_DENIED. Both lines blame to this commit. Its squashed message includes the test(verify) step that rewrote this pin. The plugin-auth stage used the same anchor for the same number.

All three shas were checked the same way:

  • Each has exactly 1 match under rev-parse --disambiguate.
  • Each is a commit with one parent.
  • merge-base --is-ancestor of each against base 22e584c9db exits 0, on a history that is not shallow (--is-shallow-repository false).
  • The control legs: 1e050a5b1^ against the base exits 0, and base-as-ancestor-of-1e050a5b1 exits 1.

Wording per site

  • semconv.ts:49: (#9650 / #9835 / #10004) becomes (#9650 / #9835 / commit 1e050a5b1). Precedents for a mixed list: cli/src/commands/lint.ts:915, mcp/src/plugin.ts:8.
  • harness.ts:580: #10943: becomes Commit 46d34ab7c:. The neighbouring #4700:, #4719: and #17911: labels answer 200 and stay.
  • erasure-transaction-authorization.test.ts:163: #11477 (maintainer-ruled option A): becomes Commit 6dd3e6968 (maintainer-ruled option A):.
  • erasure-transaction-authorization.test.ts:167: the pre-#11477 route becomes the route before that commit, which refers back to :163 four lines up.

Does the rewrite reach dist? Measured per package

Both packages were built at base 22e584c9db (closure plus package, pnpm --workspace-concurrency=2 --filter '@objectstack/verify...' --filter '@objectstack/observability...' build, VERDICT 0) and again at head 5a144efc39 (VERDICT 0). All 6 dist files of each package were compared byte for byte.

  • observability: reaches dist.
    • index.js and index.cjs differ in exactly 1 line each: the semconv.ts:49 comment, which esbuild keeps inside the SEMCONV object literal.
    • index.d.ts, index.d.cts and both maps are equal.
    • The base dist carried #10004 in index.js and index.cjs.
    • ⇒ a patch changeset.
  • verify: does not reach dist. All 6 files are byte-equal at base and head, and the base dist carried none of the three numbers. ⇒ no changeset.
  • Code-mutation control for verify, which proves that "equal" was a measurement and not a stale build.
    • The mutation went through scripts/ablation-replace.mjs in wrap mode. The anchor const organizationsPkg = opts.organizationsPackage went 1 to 0, and the marker ABLMARK20594S13 went 0 to 1 in the source. The blob moved 47a921ad0b to 3f54cdebfe.
    • After a rebuild, ablation-dist-preflight found the marker in dist/index.js and dist/index.cjs. index.js, index.cjs and both maps differ from the head build, and both .d.ts files are equal.
    • The restore leg: the restored blob equals HEAD 47a921ad0b and git diff HEAD is empty. After a rebuild, preflight --absent reads the marker absent from all 6 files with a clean tree, and all 6 files are byte-equal to the head build.
    • The first control attempt used an anchor that was a prefix of its own replacement. The tool refused it (anchor count 1 to 1) and restored the file, so no build ran on it.
  • The whole workspace build, pnpm exec turbo run build --filter='./packages/*' --filter='./packages/*/*' --concurrency=2, finished 71/71 (all cache hits). The dist of both packages is byte-equal to the head build.

Token guard

The guard compared TypeScript 6.0.3 parser leaf tokens (getChildren, JSDoc nodes excluded) of the 3 source files at base 22e584c9db and at 5a144efc39, over 3,523 base tokens:

  • the real diff: 0 files differ;
  • comment-insertion control: 0 differ;
  • code-insertion control: 3 of 3 differ;
  • string control (first character of the first string literal): 3 of 3 differ, first differing kind StringLiteral.

The script exited 0, and its controls ran in memory only. A first attempt with a bare scanner was discarded: it misaligns inside template literals and reported a false difference.

Tests, typecheck, lint and gates (head 62e556317c)

  • observability tests: pnpm --filter @objectstack/observability exec vitest run --maxWorkers=2 → Test Files 7 passed (7), Tests 85 passed (85).
  • verify tests: pnpm --filter @objectstack/verify exec vitest run --maxWorkers=2 → Test Files 16 passed (16), Tests 120 passed (120). The package has 16 test files, erasure-transaction-authorization.test.ts included.
  • verify typecheck: pnpm --filter @objectstack/verify typecheck passed, with VERDICT command-exit 0 (tsc --noEmit, then check:test-typecheck over tsconfig.test.json: 0 files / 0 errors). tsc --listFiles confirms that tsconfig.json reaches harness.ts and tsconfig.test.json reaches both edited verify files.
  • observability typecheck: the package has no typecheck script; it is a DEBT entry in check-type-check-coverage.mjs at 11 errors. tsc -p packages/observability/tsconfig.json --noEmit reads 11 errors, all in src/__tests__/, none in semconv.ts, and the program includes semconv.ts. pnpm check:type-check-coverage and pnpm check:type-check-debt pass (exit 0).
  • pnpm lint: the repo-wide eslint . --no-inline-config exits 0 (2026-09-30 10:54:08 to 10:57:25 UTC, at 62e556317c).
  • Gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands (run with no path) derived 60 commands, and all 60 were run with their exit codes recorded before any pipe.
    • 59 exited 0 on the first pass.
    • pnpm check:dual-build-cjs-loads first exited 3 (PREREQUISITE NOT MET: no dist for 33 packages). After the whole-workspace build it was run again and exited 0.
    • --ran reconciliation: 「60 derived, 60 run, 0 NOT-MEASURED, 0 UNRUN」, exit 0.
    • The diff-scoped node scripts/check-issue-citations.mjs judged the 2 citations this change adds (#9650, #9835); both answer 200, exit 0.
    • pnpm check:nul-bytes passed, and a control-byte scan of the 4 changed files reads 0.
  • Main moved during the work: origin/main moved 8 commits past the base (to 1741c5dcb6). git diff --name-only over the two packages and the changeset path reads 0 files, so this branch was not merged forward. The merge ref CI builds covers the joint tree.

Acceptance notes

  • Left outside src/**, listed and not changed (a later stage of the card): packages/verify/tsconfig.test.json:1 cites #15145, which answers 404. The other 14 citations outside src/** in the two packages answer 200: observability/vitest.config.ts:11, verify/tsconfig.json:5 and :13, verify/tsconfig.test.json:1, :2, :32, :35, :43 and :60, and verify/vitest.config.ts:8, :14, :32, :63 and :70. README.md in either package carries no #N.
  • Release-owned, not a site: packages/observability/CHANGELOG.md:985 carries #10004 (with #9834) in a released entry. This PR does not edit it.
  • Open-PR overlap (read 2026-09-30 10:58Z): 13 open PRs. Only the Version Packages PR chore: version packages #20639 touches either package, and only in CHANGELOG.md and package.json.
  • Not governed: no path is on the governed-surface register. The diff changes 19 lines, far under 5,000.

Generated by Claude Code

…he commits that decided them

Four comment lines in packages/observability/src and packages/verify/src
cited tracker numbers that answer 404. Each now cites the commit in this
repository's history that decided what the line describes:

- observability semconv.ts: the transport-seam move of
  http_request_duration_ms -> commit 1e050a5
- verify harness.ts: the host importer's undeclared fallback resolving
  from the caller -> commit 46d34ab
- verify erasure-transaction-authorization.test.ts (two lines): the
  /admin/remove-user shading that runs gateAdmin before the break-glass
  guard -> commit 6dd3e69

Comments only; every touched file keeps its line count.

Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB
Co-authored-by: Claude <noreply@anthropic.com>
…ored comment ships in dist

The rewritten SEMCONV comment reaches dist/index.js and dist/index.cjs
(one line each; both maps and both .d.ts unchanged). The verify rewrites
leave its dist byte-identical, so verify carries no changeset.

Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added size/s documentation Improvements or additions to documentation tests tooling labels Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 2 package(s): @objectstack/observability, @objectstack/verify, touching 2 documentable anchor(s).

⛔ 2 release-owned page(s) name something this change touched. These are read-only:

  • content/docs/releases/v17/17-0.mdx (via bootStack (symbol, a top-level function))
  • content/docs/releases/v17/17-2.mdx (via SEMCONV (symbol, a top-level const object))

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

What this run could not see
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 5 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 84d05fd1a27cc348671c2099a516054cbb82ae80 — the merge of head 62e556317c5aaeda8c4dce93d872a178551bf2aa into base 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 84d05fd1a27cc348671c2099a516054cbb82ae80 && git checkout 84d05fd1a27cc348671c2099a516054cbb82ae80
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8 62e556317c5aaeda8c4dce93d872a178551bf2aa && git checkout -B drift-repro 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8 && git merge --no-ff 62e556317c5aaeda8c4dce93d872a178551bf2aa

node scripts/docs-audit/affected-docs.mjs --json 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 1741c5dcb62d11bc9b59702dd67080ef6a7ac9e8 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 62e556317c5aaeda8c4dce93d872a178551bf2aa
Local-runs: none

Inputs read: card #20594 body and all 53 comments (the handover 5903477632 with the maintainer's 「合成一个 PR (Recommended)」 ruling, the claim 5909415031, the dev report 5910216119, the stage-12 dev report 5903397162 and the stage-12 release 5904216649 included); the stage-12 record 5903823584 on PR #20767; ruling 5749154545 on #19123 read at its source; PR #20842 body, file list and the net diff git diff 22e584c9db refs/review/pr-20842 (merge-base 22e584c9dbee155c9a2cfabf91059275448093c5, the branch fetched into a ref of my own); the check-runs on the head, polled in the background until every run completed; and the three cited commits 1e050a5b1, 46d34ab7c, 6dd3e6968 read in full with git show on the unshallowed history, plus 914c41302 (the commit that wrote the semconv.ts line). Nothing was built, run or re-run; the tracker numbers were probed by REST at review time.

Seat correction on adoption: the dev report reads origin/main as 8 commits past the base (to 1741c5dcb6). At review time it is 9 (to 30839063b5, a ci(test-core) shard-env change). The intersection of the PR's file list with git diff --name-only 22e584c9db origin/main is 0 files, and 0 under packages/observability, packages/verify and the changeset path. The verdict does not depend on the count.

① Derived judgments

Diff: 4 files, +15/-4, 2 commits. Three files under packages/observability/src/ and packages/verify/src/ with 4 comment lines out and 4 in; every touched file keeps its line count (178 / 955 / 185 at base and head, read by me). One new file, .changeset/20594-observability-provenance-anchors.md. Every hunk replaces a // comment line and nothing else: no code token, string literal, export, type, assertion or message moves, so the accept set of neither package moves. The describe title string #10792 in the erasure test is untouched (a string literal, the card's form-D stage; it answers 200 anyway). Not governed: no path is on the register, Governed Surface Queue Guard is success, 19 changed lines.

Site by site, each judged against the cited commit's own message and diff, with git blame at the base tying each line to its author commit:

  1. observability/src/semconv.ts:49: (#9650 / #9835 / #10004) becomes (#9650 / #9835 / commit 1e050a5b1). Right.
    • The line sits in the RETIRED block that 914c41302 wrote in place of httpRequestErrorsTotal; the sentence says the transport emits http_requests_total through the seam so it covers every inbound surface. 1e050a5b1 is the squash landing of the pull request numbered 10004: its subject is "emit http_request_duration_ms from the transport seam, so p95 latency sees every inbound surface", and its diff rewrites this same file's HTTP block to attribute each family to its emitter. Substituting the dead member of the list with the commit that landed it says truthfully what was decided.
    • #9650 and #9835 are kept, not added; both answer 200 at review time. #10004 answers 404.
    • Mixed-list precedent confirmed on origin/main: cli/src/commands/lint.ts:915 and mcp/src/plugin.ts:8.
  2. verify/src/harness.ts:580: #10943: becomes Commit 46d34ab7c:. Right.
    • The line blames to 46d34ab7c, whose diff on this very file adds both this comment block and the fallbackImport: (specifier) => import(specifier) argument the block explains. Its message is that decision: the host importer's undeclared fallback resolves from the caller, not from @objectstack/types. The neighbouring #4700:, #4719: and #17911: labels answer 200 and stay. #10943 answers 404.
    • Stages 3 and 4 of this card already anchor the same number to the same commit in packages/cli and packages/types (read on origin/main).
  3. verify/src/erasure-transaction-authorization.test.ts:163: #11477 (maintainer-ruled option A): becomes Commit 6dd3e6968 (maintainer-ruled option A):. Right.
  4. verify/src/erasure-transaction-authorization.test.ts:167: the pre-#11477 route becomes the route before that commit, referring to :163 four lines up. Right: before 6dd3e6968 the route was served unshaded, and the vendor literal was reached only after the guard had answered, exactly as the sentence says.

Anchor choice. docs/adr/** and scripts/adr-anchors/** at the base hold 0 hits for the three numbers, the three shas, afterResponse, http_request_duration_ms, createHostImporter, fallbackImport, remove-user and gateAdmin (control 7329: 2 hits). break-glass hits ADR-0090, ADR-0091 and ADR-0134, which govern grant-lifecycle break-glass and the SCIM last-administrator guard, not the /admin/remove-user ordering. So ruling C's order lands on the commit for all three, each cited by sha alone; no PR number stands on an added line.

Occurrence counts under the two src/ trees, base to head, read by me: #10004 1 to 0, #10943 1 to 0, #11477 2 to 0; the three shas 0 to 1 each; controls #9650 2 and 2, #9835 9 and 9, #10792 2 and 2. Test files are a DEFERRED surface of the gate (an exclusion glob, packages/**/*.test.ts), so the two erasure-test sites are census-invisible; rewriting them follows stages 1 to 12, as the stage-12 record judged three test-file sites.

Changeset ('@objectstack/observability': patch):

  • Accurate: the SEMCONV comment beside the retired http_request_errors_total entry is where the line sits (914c41302 removed the key and wrote the block); the cited number answers 404; 1e050a5b1 is the commit that moved http_request_duration_ms to the transport seam; comments only.
  • Carries no tracker number, no PR number and no model identifier in the body (scanned: no #N token, no bare 4-to-6-digit number). The filename carries 20594, the same form as 115 changesets on origin/main (the 20596-*-provenance-anchors series among them); the filename is consumed by changeset version and never ships, so this is a form observation, not a defect.
  • Matches what publishes: @objectstack/observability is public (files: dist, no private), and the dev's measurement is that the base dist already carried #10004 in index.js and index.cjs while the head dist differs in exactly that one line each. @objectstack/verify is public too, but the base dist carried none of #10943 or #11477, so the lines never shipped and their replacements cannot, under an unchanged build config; the dev's byte-equal reading with a code-mutation control (marker reached dist, restore leg byte-equal) is consistent with that. I ran no build; the record rests on the diff, the dev's measurement and that reasoning. No changeset for verify is right, and no skip-changeset is right since one package publishes.

Census (the card's instrument, the dev's runs at 22e584c9db and 62e556317c, whole board enumerated both times): packages/observability 1 to 0, packages/verify 1 to 0, whole repository 752 to 750 with a site-by-site diff of exactly these two sites gone and 0 added. The PR body lists each package's before and after count separately, in its own table row, as the handover ruling requires. The "before" of 1 per package agrees with my blame and REST probes: the only dead census-visible sites in these trees at base were semconv.ts:49 and harness.ts:580.

Check-runs on the head (converged 2026-09-30T11:45:18Z; the Test Core roll-up completed at 11:44:59Z):

  • 34 names, all completed: 31 success and 3 skipped (Build Docs, Console Pin Gate, Packed-tarball smoke (opt-in)). 0 failed.
  • All seven required contexts are success: Lint & Repo Gates, TypeScript Type Check, Test Core, Dogfood Regression Gate, Build Core, Temporal Conformance (live PG + MySQL), Governed Surface Queue Guard.
  • Check Changeset, Part-of PR must not also close its card, The card this PR closes must claim this branch and both single-claim guards are success.

② Semver level

  • patch for @objectstack/observability is right: a released package publishes changed bytes (one comment line in dist/index.js and dist/index.cjs) while no accept set, export, type or behaviour moves.
  • No changeset for @objectstack/verify is right: nothing it publishes changes.
  • Clause-②: no on the claim and on the PR body is right; the changeset is non-breaking, so no ADR-0087 marker is due.
  • PR shape: draft, base main, head repo equals base repo, assignee huangyiirene mirrors the card, first line Part of #20594, no closing keyword anywhere in the body, session-URL footer. Both commits carry the model-free trailer pair.

③ Boundary flags

The dev report 5910216119 has empty open_questions and premise_still_valid true. Each of its ten deviations is answered:

  1. main not merged forward (dev: 8 commits; seat: 9, to 30839063b5): 0 files overlap on the full file list and 0 under the PR's paths; the change is comment prose, so no joint-behaviour question exists; the PR's merge-ref CI is green on the joint tree and the merge queue rebuilds on current main. The skipped pull-main step is declared and costs nothing here. Accepted.
  2. git fetch --unshallow on the shared object store: additive only (objects and history; no ref, index or working tree moved, no stash); no rule in AGENTS.md forbids it, and blame and --is-ancestor needed it. It is also why this review could read the three anchors with git show. Declared, accepted.
  3. Closure build spelled as package-plus-dependencies: local only, no bearing on the diff.
  4. First code-mutation control refused as a no-op: nothing built on it; the second attempt is the measurement.
  5. Bare-scanner token guard discarded for the parser-leaf form: the four hunks are readable by eye as comment-only; no bearing.
  6. Seven gate families beyond the PM's stale lead list ran, exit 0: no bearing; Lint & Repo Gates is success.
  7. Artifact-roster and wide-population families not run locally: the head's check-runs are the verdict, all green.
  8. observability has no typecheck script (DEBT ledger at 11 errors): Type Check · debt ledger and Type Check · workspace are success, and semconv.ts moves no token.
  9. Model-free trailer pair and session-URL footer used over the harness reminder: right per AGENTS.md; verified on both commits.
  10. Worktree cleanup after posting: no bearing on the diff.

Both out_of_scope_findings are noted, not filed, and that is right:

  • packages/verify/tsconfig.test.json:1 cites #15145 (404 at review time): outside the census's declared surface, carried by item 3 of the card's release 5904216649 (each package's files outside src/**).
  • packages/observability/CHANGELOG.md:985 carries #10004 in a released entry: release-owned, a deferred surface of the gate, and the card's direction forbids edits to published release text; the entry was true when published, so it is not a factual error owed a docs-only PR. Listed in the PR's Acceptance notes.

Nothing needs escalation.

Implemented-by: claude/issue-20594-observability-verify-citations
Reviewed-by: session_01VvcEokUG1tvVxkceYfR5XB

VERDICT: PASS


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/s tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants