Skip to content

fix(spec): a stack whose mapping authors connectorSource validates and lints again — the live ledger row carries no author warning (#21127) - #21176

Merged
objectstack-fleet[bot] merged 5 commits into
mainfrom
claude/issue-21127-connector-source-live-row
Oct 1, 2026
Merged

objectstack-fleet[bot] merged 5 commits into
mainfrom
claude/issue-21127-connector-source-live-row

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21127

Clause-②: no

What this changes

os validate --json and os lint --json exited 1 on any stack whose mappings[] entry authors connectorSource. The whole answer was the liveness lint's integrity sentinel: lintLivenessProperties: ledger entry has unrecognised status "live". The ledger row mapping.connectorSource had been re-graded live and kept authorWarn: true. describe() in packages/lint/src/lint-liveness-properties.ts throws on a warned live row by design, and that throw stays as it is.

  • The row (packages/spec/liveness/mapping.json): connectorSource stays live and drops authorWarn / authorHint. Its note records why.
  • The caveat moves to where an author reads it (packages/spec/src/data/mapping.zod.ts). The connectorSource .describe() now reads: "Pulled when a job drives it; nothing schedules it yet, so the binding alone moves no rows — schedule the pull with a job once a job can drive one". The docblock no longer says the ledger keeps authorWarn.
  • The existing integrity check refuses the combination, inside its current gate (check:liveness, packages/spec/scripts/liveness/check-liveness.mts). No new gate or script was added. The graded walk never reads a container row that drills into children, and connectorSource is such a row, so the new rule walks the raw ledger rows at every depth. It fails on status: "live" with authorWarn: true, prints a prescription, and prints a census line on every run: author warnings: 2 ledger row(s) opt into authorWarn, at any depth (planned 2); 0 on a live row.
  • Regenerated: content/docs/references/data/mapping.mdx and integration/connector.mdx (gen:docs), and packages/spec/src/migrations/registry.ts (gen:migration-registry).

Files beyond the claim's listed surface (each one is text this change made false)

The claim lists the ledger row, the connectorSource describe, the existing integrity check, the regenerated artefacts, the pins and one changeset. These files are outside that list. Each one said that authoring the binding warns, and that stopped being true with the row fix:

  • packages/spec/src/integration/connector.zod.ts: the retired connector.syncConfig prescription, which an author sees in the refusal.
  • packages/spec/src/migrations/entries/semantic/18.connector-sync-keys-retired.ts: the upgrade entry's acceptance text. registry.ts is regenerated from it.
  • packages/spec/src/integration/connector-sync-retirement.test.ts: a one-line pin on that prescription text.
  • packages/spec/docs/SYNC_ARCHITECTURE.md: "authoring connectorSource still warns".
  • packages/spec/liveness/README.md: the mapping row's note, plus a third authorWarn rule (a live row carries none).
  • packages/lint/src/authoring-rules.ts: comments only.
  • packages/lint/src/runtime-gate.inert-type-writes.test.ts: a comment, and a pin. A mapping write that authors connectorSource used to get an authoring-rule-threw advisory at the runtime door, and now gets none.
  • packages/cli/test/validate-lint-mapping-connector-source.test.ts: the door pin, a new file.
  • .changeset/20919-spec-connector-source-live.md: see the next section.

⚠️ One deliberate correction of a pending release note (needs confirming)

.changeset/20919-spec-connector-source-live.md belongs to PR #21084. It has not been released yet, and it said "connectorSource rows are live and keep authorWarn". This PR makes that false, so the sentence now reads "rows are live, with no author warning: that nothing schedules a pull yet is said on the key's description".

node scripts/check-empty-changeset.mjs --base origin/main is therefore red by design. It says: "This PR changes a changeset it did not add … DELIBERATE CORRECTION -- … do NOT restore it -- say so on the PR and get it confirmed". This section is that statement, and skip-changeset is not applied.

.changeset/20281-connector-sync-moved-to-mapping.md carried a similar claim. PR #21150 has since rewritten it on main without the warn claim, and this PR does not touch it.

Premise check

  • H1, the crash (measured at the dispatch base 665cab338f, which contains PR feat(lint): a ledger-dead or live-elsewhere key warns without an authorWarn opt-in, and never shows the ledger note (#16094) #21092 b616c0a63d). The card's fixture is one object fx_account with sharingModel: 'private', plus one mapping with sourceFormat: 'json', targetObject: 'fx_account', mode: 'upsert', a fieldMapping and connectorSource: { connector: 'crm_api', action: 'request' }.
    • At base, os validate --json and os lint --json both exited 1, and the only error was the sentinel.
    • After the fix, on the merged head b6d58dd04: validate exits 0 with "valid": true. lint exits 0 with "passed": true and one unrelated warning (protocol/missing-engines-range). Neither output names connectorSource or contains the sentinel.
    • The crash had been hiding a real finding. Without sharingModel, the same object gets security-owd-unset, so the fixture declares it.
  • H2, the integrity check. Yes, inside check:liveness. Run against the unfixed ledger, the gate exits 1 with exactly one ✗ block: "1 live ledger row(s) opt into authorWarn — the author-side lint throws on them: mapping/connectorSource".
  • H3, census (re-run on the merged head). Across all 41 governed ledgers, 924 rows were walked at every depth. Two carry authorWarn: true, both planned (object.externalSharingModel, translation.flows). None is live. Before the fix, mapping.connectorSource was the only live one, so no other row has this defect.
  • H4, describe text. Done as above. Author-facing text cites no tracker number.

Pins

  • packages/spec/src/data/mapping-connector-source.test.ts: every key of the binding is live, and no row of it, at any depth, carries authorWarn / authorHint. The description still says nothing schedules a pull. The old assertion authorWarn === true pinned the defect.
  • packages/spec/scripts/liveness/check-liveness.test.ts runs the real gate via --ledger-root:
    • green on the shipped ledgers, with the census line showing warned planned rows and none on a live row (the control);
    • red when a live container row with children opts in (the regression's shape);
    • red when a drilled live child opts in.
    • The carriers are picked from the shipped ledgers by shape, not by name.
  • packages/lint/src/lint-liveness-properties.test.ts runs against the real ledger. The card's fixture lints without throwing and draws no connectorSource finding. Control: object.externalSharingModel (planned + authorWarn) still warns as liveness-planned-property.
  • packages/lint/src/runtime-gate.inert-type-writes.test.ts: a mapping write that authors connectorSource gets no errors and no advisories at the runtime door.
  • packages/cli/test/validate-lint-mapping-connector-source.test.ts is in the integration tier and spawns the CLI:
    • the card's fixture: os validate --json exits 0 with valid: true, and os lint --json exits 0 with passed: true;
    • control: adding externalSharingModel produces a liveness-planned-property warning, still at exit 0.

Reverse verification (one-time, not a permanent file)

This was run twice on the committed fix, with identical results: once at 7bc7c5c26, and again after the main merge at b6d58dd04. node scripts/ablation-replace.mjs put "authorWarn": true back on the connectorSource row. The anchor count went 1 → 0, and the blob changed 49cc72e394b8 → 65665b90b21d. With the defect back, every leg went red:

  • door: validate exit 1 and lint exit 1, with the sentinel in both;
  • check:liveness exit 1 (1 on a live row — FORBIDDEN);
  • spec pins: 2 failed;
  • lint pins: 3 failed;
  • CLI door pin: 3 failed.

The tool restored the file and proved it: the blob equals HEAD and git diff HEAD is empty. The ledger is read from packages/spec/liveness/ at runtime, not from dist/, so no rebuild was involved.

Verification (all at b6d58dd04, the PR head)

origin/main fde553c50 was merged in with bash scripts/pm/os-regen-merge.sh. The merge was clean. registry.ts auto-merged as text, and check:migration-registry then confirmed it. Main had not touched the two reference pages, so they kept the branch's bytes. No regeneration commit was needed: after a fresh spec build, check:generated reports all 15 generated artefacts up to date. The delta against main is unchanged: 19 files, +538 / −42.

what command result
spec build pnpm --filter @objectstack/spec build exit 0
generated artefacts pnpm --filter @objectstack/spec run check:generated exit 0, "All 15 generated artifacts are up to date"
CLI closure build pnpm exec turbo run build --filter=@objectstack/cli... --concurrency=2 exit 0, 59/59 tasks
the card's fixture os validate --json / os lint --json exit 0 / exit 0, sentinel 0 times, connectorSource 0 times
ledger integrity pnpm --filter @objectstack/spec run check:liveness exit 0, "0 on a live row"
strictness ledger pnpm --filter @objectstack/spec run check:strictness-ledger exit 0
spec tests vitest run scripts/liveness src/data src/integration/connector-sync-retirement.test.ts src/migrations exit 0, 130 files, 4269 passed, 1 todo
spec typecheck pnpm --filter @objectstack/spec typecheck exit 0
lint, whole package pnpm --filter @objectstack/lint exec vitest run + typecheck exit 0, 118 files, 5489 passed; typecheck exit 0
CLI unit tier vitest run --project unit test/lint test/validate src/commands/validate src/commands/lint exit 0, 11 files, 125 passed
CLI door pin vitest run --project integration test/validate-lint-mapping-connector-source.test.ts exit 0, 3/3
eslint, narrowed pnpm exec eslint --no-inline-config --format json on all 19 changed paths exit 0. eslint linted 12 and reported 7 (.md / .mdx / .json) as "no matching configuration"; 0 errors, 0 warnings
derived gates dispatch-gates.mjs --commands (117), each run, then --ran 117 run: 116 exit 0, and 1 exit 1. That one is check-empty-changeset --base origin/main, the deliberate correction above. --ran: "117 run, 0 NOT-MEASURED, 0 UNRUN". check:pm-dispatch-gates was killed by a timeout at 400s and then at 540s. It was then run to completion and exited 0; its battery took 1432s on this box

The eslint narrowing is a measurement, not a skip:

  • The population comes from eslint's own answer for each changed path: 12 linted, and 7 that eslint.config.mjs has no configuration for.
  • The file count comes from the --format json output.
  • The config enables no type-aware linting (no parserOptions.project), so this diff cannot move the verdict on any file it did not touch.

Acceptance notes


Generated by Claude Code

claude added 5 commits October 1, 2026 10:05
…`authorWarn`

The author-side lint's describe() throws on a warned `live` row by design,
which turns `os validate` / `os lint` into exit 1 for every stack that
authors the key. The graded walk never reads a container row that drills
into `children`, so the gate now walks the raw rows at every depth, refuses
the combination, and prints the warned-row census every run.

Red at this commit on purpose: the shipped `mapping.connectorSource` row is
the one offender, re-graded in the next commit.

Claude-Session: https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU
Co-authored-by: Claude <noreply@anthropic.com>
…arning, so `os validate` / `os lint` judge a stack that authors it

The liveness lint has no verdict for a warned `live` row and throws its
ledger-integrity error, which made both commands exit 1 on every stack
whose mapping authors the binding. The row drops `authorWarn` /
`authorHint`; the caveat they carried (nothing schedules a pull until a
job can drive one) moves to the key's description. The retired
`connector.syncConfig` prescription, the `connector-sync-keys-retired`
upgrade entry (registry regenerated), SYNC_ARCHITECTURE.md, the ledger
README, the pending connector-source changeset and two lint comments no
longer say authoring the binding warns.

Pins: the spec ledger pin now asserts no row of the binding warns; the
lint suite and the runtime door judge the card's binding silent, with a
warned `planned` row still warning as the control; a CLI integration test
runs the fixture through `os validate --json` / `os lint --json` (exit 0).

Claude-Session: https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU
Co-authored-by: Claude <noreply@anthropic.com>
… the connectorSource description

Claude-Session: https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 2 package(s): @objectstack/lint, @objectstack/spec, touching 3 documentable anchor(s). ⚠️ 3 changed file(s) yielded no anchor (packages/spec/docs/SYNC_ARCHITECTURE.md, packages/spec/liveness/README.md, packages/spec/liveness/mapping.json), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files.

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/deployment/validating-metadata.mdx (via AUTHORING_RULES (symbol, a top-level const object))
What this run could not see
  • 3 changed file(s) yielded no anchor (packages/spec/docs/SYNC_ARCHITECTURE.md, packages/spec/liveness/README.md, packages/spec/liveness/mapping.json) — pages documenting those are invisible to this run
  • 2 name(s) were too generic to anchor anything (single lowercase words)
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 137 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json d34aa58a2affc87ded426dc6a326edb03534cb62 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from b6ed1851f47fad8414e834a77d9f453750c82426 — the merge of head b6d58dd04427126553d781fc78e05778642bee65 into base d34aa58a2affc87ded426dc6a326edb03534cb62, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin b6ed1851f47fad8414e834a77d9f453750c82426 && git checkout b6ed1851f47fad8414e834a77d9f453750c82426
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin d34aa58a2affc87ded426dc6a326edb03534cb62 b6d58dd04427126553d781fc78e05778642bee65 && git checkout -B drift-repro d34aa58a2affc87ded426dc6a326edb03534cb62 && git merge --no-ff b6d58dd04427126553d781fc78e05778642bee65

node scripts/docs-audit/affected-docs.mjs --json d34aa58a2affc87ded426dc6a326edb03534cb62

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs d34aa58a2affc87ded426dc6a326edb03534cb62 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: b6d58dd04427126553d781fc78e05778642bee65
Local-runs: none

Rendered at 2026-10-01T13:11Z by an isolated reviewer subagent of the domain:spec seat 2 session. Inputs, and nothing else: card #21127 (body and its four comments: triage 5928085861, claim 5928949500, re-dispatch note 5930371536, os-dev-report 5932014253); PR #21176 (body, the 19-file list, and the net diff against the fork point fde553c50: +538 / −42); the check-runs on the head, read at 2026-10-01T13:09Z. Files at the head were read from the fetched branch ref (reading only; nothing built, run or re-run).

① Derived judgments

Accept set and public surface, item by item:

  1. MappingSchema.connectorSource (packages/spec/src/data/mapping.zod.ts): only the .describe() string and the docblock move. Shape, optionality, children and strictness are untouched. No accept-set change. Right.
  2. ConnectorSchema.syncConfig tombstone (packages/spec/src/integration/connector.zod.ts): one clause of the SYNC_CONFIG_RETIRED message. The key stays never and refused. No accept-set change. Right.
  3. Migration entry 18 (18.connector-sync-keys-retired.ts) description, with registry.ts step18 regenerated to the same bytes: upgrade-notice prose; no conversion, key or step moves. Right.
  4. The ledger row packages/spec/liveness/mapping.json (shipped: liveness is in the spec package's files[]): connectorSource loses authorWarn and authorHint, its note is rewritten, and every row of the binding stays live. Read at the head: the container, its five children and the two watermark grandchildren are all live and none carries authorWarn or authorHint. Shipped data the lint reads, not an accept set. Right. This is the fix.
  5. Published prose faces: content/docs/references/data/mapping.mdx carries the new describe byte for byte; both syncConfig rows of content/docs/references/integration/connector.mdx carry the new prescription. No other committed generated artefact holds either old sentence (grepped at the head: api-surface, authorable-surface, authorable-defaults, spec-changes.json, json-schema.manifest, docs/protocol-upgrade-guide.md; packages/spec/json-schema/ is gitignored). Build Docs is green on the head; check:generated runs under the still-running Lint & Repo Gates. Right.
  6. check:liveness (packages/spec/scripts/liveness/check-liveness.mts): two report fields, a raw-row walk at every depth, one more failed || arm, a prescription block and a census line printed on every run. All inside the existing script and its existing CI step (Spec property liveness, green on this head); the diff adds no script, no package.json entry and no workflow step. Triage's "no new gate" holds. Right. One non-blocking note: the lint's own warn map flattens one level of children, so a warned live row at depth three or deeper would be inert noise today rather than an active crash; refusing it anyway is the stricter, correct invariant, and the prescription's sentence that the lint throws on such a row is the only imprecision.
  7. The sentinel packages/lint/src/lint-liveness-properties.ts: zero lines in the net diff; describe() at the head still throws on live. Right.
  8. packages/lint/src/authoring-rules.ts: nine lines in, seven out, every one inside a // comment block. No rule, export or type moves. Right.
  9. Files beyond the claim's listed surface (the seat's question 2), each judged on its own: connector.zod.ts (the prescription said "authoring the binding warns until a job can"), entry 18 plus the regenerated registry (the same sentence), connector-sync-retirement.test.ts (a one-line comment on the pin of that prescription), SYNC_ARCHITECTURE.md ("authoring connectorSource still warns"), liveness/README.md (the mapping row's history plus the rule the gate now enforces), authoring-rules.ts (the comment said mapping.json is "8 / 1" with the key "live with authorWarn"), runtime-gate.inert-type-writes.test.ts (the comment said mapping "has one such row now", plus a pin that the runtime door returns no authoring-rule-threw advisory, which the card body itself names as part of the reach). Each is a sentence the row fix made false, or a pin on the card's measured reach; review-checklist requires a published sentence this round made false to be fixed in the round. The CLI door pin (packages/cli/test/validate-lint-mapping-connector-source.test.ts) is the claim's own listed pin ("the card's fixture validates and lints with exit 0"), not a file beyond it. Inside the card's family throughout; no widening. The seat amends the claim surface at review, as the re-dispatch note foresaw.
  10. Pins: the spec ledger pin walks every depth of the binding for a stray warning; the check:liveness pins run the real gate via --ledger-root (green control with a published census that must read planned at least 1 and 0 on a live row, red on a warned live container, red on a warned drilled child, carriers chosen by shape, exactly one failure block asserted); the lint pin lints the card's fixture against the real ledger with LIVENESS_LEDGER_UNREADABLE excluded as the anti-vacuity control, plus a planned control; the runtime-door pin; the CLI door pin with a planned control at exit 0. The CLI pin spawns the CLI and lands in the derived integration tier; it carries no nightly tier name, so the queue population includes it. Right.

Check-runs on the head, read at 2026-10-01T13:09Z: 33 runs. 20 success, 2 skipped as expected (Console Pin Gate, Packed-tarball smoke (opt-in)), 1 failure (Check Changeset, by design; see ②), 10 in progress at that reading: Lint & Repo Gates, Type Check · workspace, Test Core (1/6) through (6/6), Temporal Conformance (live PG + MySQL), Dogfood Regression Gate (the rollup). Green and bearing on this diff: Spec property liveness (the gate this PR extends, with its new arm, on the fixed ledger), Type Check · source gates, Type Check · consumer gates, Type Check · debt ledger, Build Core, Build Docs, Dogfood Verify CLI, Dogfood Regression Gate (1/3) to (3/3). A run still in progress is not a FAIL; the seat's own landing rule (every check green or an expected skip, the red by design excepted) waits on those ten.

② Semver level

  • .changeset/21127-connector-source-live-row.md: @objectstack/spec: patch. Right: a ledger grade, describe prose, one tombstone message clause and one upgrade-notice sentence; "No key, value or default changed" is true of the diff. Each claim in the note checked against the diff: both commands exit 0 on the fixture (CLI door pin), the runtime door returns no advisory (runtime-gate pin), check:liveness refuses live plus authorWarn at any depth and prints the census (check-liveness.mts), a planned row with authorWarn still warns (three controls). All true.
  • @objectstack/lint: no changeset (the seat's question 3). os-dev.md's fast track names comments among what is not published, beside the files[] rule that defines published as what ships; the fast track is the carve-out that answers "tsup keeps comments, so dist bytes move": by rule, a comment is not a published change. No lint behaviour, export or type moves; the behaviour an upgrader sees change comes from the spec package's shipped ledger and is carried by the spec note. No patch owed. Option A stands.
  • @objectstack/cli: test-only; nothing shipped moves; no changeset owed. The PR adds a changeset, so no skip-changeset question arises, and the label is absent on the PR, as it must be on a PR that edits an existing changeset.
  • The DELIBERATE CORRECTION (the seat's question 1). The note changed: .changeset/20919-spec-connector-source-live.md, PR feat(service-automation,core,types): the connector sync executor pulls a mapping's connectorSource through the import runner, moved beside bulkWrite #21084's pending @objectstack/spec: patch. The Check Changeset failure's annotations name exactly one violation, that file as modified on the merge base, with the two-class remedy; nothing else is red in that job. Sentence by sentence at this head:
    • Rewritten sentence, first clause: "The liveness ledger's connectorSource rows are live, with no author warning". TRUE: all eight rows live, none warned (read at the head, item 4).
    • Rewritten sentence, second clause: "that nothing schedules a pull yet is said on the key's description". TRUE: the describe at the head reads "nothing schedules it yet, so the binding alone moves no rows — schedule the pull with a job once a job can drive one".
    • The next sentence keeps its words but is re-anchored to the new one: "The retired connector.syncConfig prescription and the connector-sync-keys-retired upgrade entry say the same". TRUE: both now read that nothing schedules a pull yet, so the binding alone moves no rows, and neither says authoring warns. "and the entry's acceptance criterion no longer claims the connector is validated at authoring". TRUE and untouched: entry 18's acceptanceCriteria at the head names no authoring-time validation.
    • Restoring the original sentence ("rows are live and keep authorWarn, nothing schedules a pull yet") would publish a sentence false at this head in the same release as the fix, and would make the following "say the same" sentence false with it, since neither the prescription nor the entry says authoring warns any more. Both notes are @objectstack/spec: patch, so one Version Packages carries both, and they now agree.
    • The three carry-the-red conditions: the script at the head self-describes the red ("this gate stays red either way"); pr-automation.yml triggers on pull_request only, with no merge_group; the PR body names the gate and the cause in its own section. All three hold. Per landing-operations, this same-head PASS record is the confirmation of the correction; no maintainer wait is owed.
  • Clause-②: no. Holds. The card relaxes no accept set and widens no public surface: schema shapes, the tombstone refusal, the migration steps and the lint's exports are unchanged; the CLI judging stacks it used to crash on is the defect fix, and the shipped ledger bytes and comment bytes are outside the accept set, which contract-review.md says does not flip the clause.

③ Boundary flags

open_questions:

  1. Confirm the correction of .changeset/20919-spec-connector-source-live.md? Answered: A. Confirmed by this record, with the sentence-by-sentence judgment in ②.
  2. A lint changeset for a comment-only change? Answered: A, no changeset, per os-dev.md's fast track; reasoning in ②.

deviations:

  • Files beyond the claim surface: answered in ① item 9. In-family, no widening; the seat amends the claim.
  • The 20919 note changed, check-empty-changeset red by design, no skip-changeset: answered in ②; the label's absence verified on the PR.
  • No lint changeset: answered in ②.
  • All 117 derived gates run locally, check:pm-dispatch-gates run detached past the foreground cap: not a contract matter; the head's check-runs are the verdicts and are recorded in ①.
  • Readings reused from the dispatch base: pre-fix readings whose inputs the merge did not touch; the CI readings on the head supersede them.
  • PR body footer form: not a contract matter.
  • turbo wrote into AGENTS.md before the merge: AGENTS.md is not among the 19 files; nothing leaked into the diff.
  • Clause-②: no kept: judged right in ②.

out_of_scope_findings: the check:pm-dispatch-gates battery running past the foreground cap against its header's claim is a tooling drift in the skills lane, not this card's contract; left with the seat, no escalation from this review.

The seat's question 4: the check:liveness refusal sits inside the existing gate (no new script, step or workflow), the sentinel is untouched, and Clause-②: no holds. All three confirmed in ①.

Nothing escalated: the diff forks no product semantics and no public contract shape; correcting a pending note is the ruled in-seat path.

Implemented-by: claude/issue-21127-connector-source-live-row
Reviewed-by: session_017VaLJnYwhPsanVCe9dMCJU

VERDICT: PASS


Generated by Claude Code

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Designed red, recorded before enqueue · domain:spec seat 2 (session_017VaLJnYwhPsanVCe9dMCJU) · 2026-10-01T13:13Z


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation protocol:data size/l tests tooling

Projects

None yet

2 participants