docs(objectql): re-anchor the dead tracker citations to the commits and ADRs that decided them (stage 3 of #20595) - #21268
Conversation
…he commits and ADRs that decided them Comment and docblock prose only, in packages/objectql: every site citing a tracker number that answers 404 now cites an object this repository controls (ruling C+D, form C), an ADR where one records the decision, otherwise the commit that made it. Each file keeps its line count; no code token, string literal or live citation moves. Claude-Session: https://claude.ai/code/session_017xfMoEjKUuSh2xYB8sCozp Co-authored-by: Claude <noreply@anthropic.com>
…ublished dist The rewritten docblocks sit on exported members and land in index.d.ts, core.d.ts and the shared type chunk, and esbuild keeps some of the comments in the JavaScript output: a patch, comment text only. Claude-Session: https://claude.ai/code/session_017xfMoEjKUuSh2xYB8sCozp Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 1 package(s): 27 hand-written doc(s) name something this change touched — list omitted above 15 rows. Re-derive on the tree named below: ⛔ 8 release-owned page(s) also affected — read-only, see AGENTS.md Documentation Guardrails. What this run could not see
Coarse fallback — 17 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 8f2e0f9e602208f23f2bddbf44c65c368572fd97 && git checkout 8f2e0f9e602208f23f2bddbf44c65c368572fd97
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 7923c8eca09258b52591039b1b12725e0e67445a 1e0895870dae7b969fe202f7039d2854bc351836 && git checkout -B drift-repro 7923c8eca09258b52591039b1b12725e0e67445a && git merge --no-ff 1e0895870dae7b969fe202f7039d2854bc351836
node scripts/docs-audit/affected-docs.mjs --json 7923c8eca09258b52591039b1b12725e0e67445a
|
Contract reviewServed-tier: Inputs read, and nothing else: card #20595 (body and all thirteen comments: the two lane pointers, the post-landing census ① Derived judgmentsDiff of record. The merge base of the head with Accept set and public surface: nothing moves. Judged RIGHT, on this reading of the diff text: every Sampled hunks, 36 pairs across 25 files, each read as its Anchors. All 67 shas in the per-number table (the 70 numbers less the three ADR-only rows, with The #10629 exception, judged on the commits. The four ADR anchors, read at The two splits. #13178: No new tracker number; live numbers stayed. For every pair, the numbers on the Rewritten sentences stay true. Each sentence that credits a commit with a ruling, a measurement, a reason or a phrase was matched against that commit: Reach into ② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
Part of #20595
Clause-②: no
What changed
Stage 3 of the
domain:enginelane of the dead-citation sweep:packages/objectql/**, comment and docblock prose only, per the claim (5941871762). Stages 1 and 2 (packages/metadata-protocol) landed asa7d9768ecandd150c3039; #20595 stays open for the next stage (driver-sql).Every comment or docblock site in the package that cited a tracker number answering 404 is rewritten in ruling C+D's form C (record
5749154545on #19123): the ADR when one records the decision, otherwise the commit in this repository's history that made it. That is 279 sites on 275 lines in 67 files, covering 70 numbers:src/): the wholeallocated-but-absentpopulation of the gate's own census in this package at the base, the slash-joinedplugin.ts#10629from the post-landing census (5923084795, now at:1543) included;vitest.config.ts(:61,#17853): outside the census glob, inside the claimed surface;Anchors: 66 numbers by commit, 4 by ADR, 0 by words alone. 45 numbers reuse the anchor another lane or stage already measured for them, 23 were measured here, and 2 are split between a reused and a measured commit (see the table). Two depart from another lane's anchor for a stated reason (
#10629,#10243, under Wordings to check).Only comments changed. Every file keeps its line count (275 lines out, 275 in, plus the changeset), so no line citation into any of them moves. No code token moves (the guard below). No citation number is added: on every changed line, the numbers on the new text are a subset of those on the old, and the diff-scoped gate judged the 14 citations left on changed lines: 13 resolve and 1 is a declared cross-repo reference.
A
patchchangeset: 54 of the 137 rewritten non-test lines are in the publisheddist(the.d.tskeeps JSDoc on exported members, and esbuild keeps some comments in the JS), anddistis not byte-identical with the base text (see Changeset).Census:
objectql, before and afterInstrument (A1). The gate's own
node scripts/check-issue-citations.mjs --census --json, read-only and unchanged. The count is itsallocated-but-absentfindings underpackages/objectql/.allocated-but-absent4727fcb22, run 22:38:04Z to 22:41:42Z8d6465457, run 23:19:32Z to 23:22:54ZThe whole-repo drop is 136, and the two finding sets differ by exactly the 136 rows of this package, removed; none was added.
resolves(34,638),resolves-as-pull-request(2,095) andcross-repo-unjudged(1,144) did not move. The card's 135 was taken atf11b5f20a2with the older extractor; the base here reads 136, the difference beingplugin.ts#10629. The same census at the first based150c3039(before a fast-forward to4727fcb22, which touched noobjectqlfile) read the identical 136 rows. The head's only later commit is a merge ofmainthat touches no file underpackages/objectql(git diff 8d6465457 1e0895870d -- packages/objectqlis empty).Supplementary instrument, the whole package. The census reads neither test files nor strings nor files outside
src. A second reading runs the gate's own exportedextractCitations(whole-file and comment-prose projections) andnamesThisRepositoryover every tracked file in the package (430.ts, 6.json, 2.md,LICENSE), and classifies each citation with the gate'sclassifyCitationagainst one board enumerated by the gate'senumerateBoard(191 pages, frontier #21252, 19,073 records, 22:43:50Z). Every one of the 70 numbers in the population was then read on its own over the issues endpoint: all 70 answer 404, and the lit controls#5286and#12624answer 200.4727fcb22src commentincludesvitest.config.ts. The drop of 279 citations is exactly the rewritten sites, and the live counts did not move (non-test comment: 2,971 resolve, 80 as pull requests; test comment: 2,700 and 122). A third, raw reading (every#followed by 2 to 6 digits, whatever surrounds it) counts 9,504 before and 9,225 after: the same drop of 279.Comment ids. Six distinct comment-id citations stand on 11 lines in this package (
5237739551,5434929046,5791803339,5805782503,5865053231,5865693155). Each was read over the issue-comments endpoint and each answers 200 (control5941871762, 200), so none is in the population.Per-number table
srccounts census sites (plusvitest.config.tsfor#17853),testcounts test-comment sites. Every sha below matches exactly one commit (git rev-parse --disambiguate, count 1) and is an ancestor of the base (git merge-base --is-ancestor, exit 0 for all 67 shas; the clone is not shallow, 15,432 commits at the base). The message or the diff of each one names the number it replaces, with one exception,#10629, explained under Wordings to check. Where a sentence credits a ruling, a measurement or a note to the number, the anchor's own message or diff carries it (checked per site; the ones that needed a reworded sentence are listed below).sourcesays whether another lane or stage already used this anchor for this number (reused) or it was measured here (measured).#603718189983d#608353068c130#624183a3b1f2e:typesegment once per handler so the plural spelling cannot skip the §6.7 audience gate#630074155c735#631159b794f71HookContext.apifromz.unknown()to the minimalIScopedContext#6478474f131cfflow'sallowOrgOverrideback tofalseper ADR-0005's original call, the write path refusing loudly#6483ee58392e1allowOrgOverride: trueflags rolled back tofalse(its message records the 2026-08-08 ruling)#6573708431313registerHookrefuses an emptyobjecttarget and a self-cancelling scope#67238ad609c69#67251507ba356#67457a5ef0008#8454427344c26#846001a7337fc)#8648e5eeb499c#8672ff08691e6#8818fd6bdf89f#88234dfa369a9#903027a567dd8#10062fa5d137ab#10091da891e0ef#10165801296050#101942306a765c#10243flowEnabledmap, retiring the env-wide toggle leak's mechanism (it names the number)#102902570ab05c__searchcompanion source#10347530c1df65ttlinstead of archiving bycreated_atage alone#1048535ad101bcthemescarrier key and ThemeSchema —app.brandingis the one colour surface#105275649efbf9#105287d483e1e5#10629199ec4712#106435649efbf9#1072910485009aid#1106520950404c#113111272f0a6b#11427c3c72a4bc#116749a884c6e4+1cba33f16#12194311433f6b#13178f087c376f+e49d98896#1319756c093c4duniqueso a colliding write is refused, not landed#132733a86a65e7findfailure log level from the cause — "the table is not provisioned yet" is not "the read failed"#1364434ce8e7db#13657b003cf2e8#141631dcb995f21dcb995f2landed it, and its changeset names the number#14345e89fa9233#143909d7f7259fupdateanswers a driver unique violation with theDUPLICATE_RECORDenvelope, on every driver#143993c1bbd2a8nameis LAST at every SOURCE registrar#14422dc7c226b9#14423a56baa2bd#1447200ff228fe#14474df657d9df#144843f64fe6c6#145351aba3159areferencekey#14666d0ee598e6namedisagrees with its derived object key#14667dc7c226b9#146803bd9b3498/view-containersubpath keeps objectql's lean ADR-0076 closure free of the manager, chokidar, glob and js-yaml#1468396326040f#1472365846bc46UNIQUE_VIOLATION, the route's one wire spelling#14770d5cbb44f3getMetaItem's overlay read on the metadata registry#1487829db3cd2a#1495726144c204#15041sys_fileid; its execution order puts the driver card at step 2 (it names the number)#15094901773b21#16608a016f08b8checkon the row that will be stored, afterbeforeInsert#167117862fb711#167290f38ab084syncSchemare-registration#16783854639b31findOne,updateanddeletedeclare what they answer, and their hook seams are guarded#167865c8f5af50+6059b29c0ObjectRepositorydeclares thefindOne/updateshapes it already published / declare IScopedObjectRepository.updateById's answer — the record or null, not any#16805a016f08b8checkon the row that will be stored, afterbeforeInsert#17195d2c1d1980#17219706ad0fcc#1785308f5f0e5aWordings to check
Most rewrites swap a tag in place (
[#N]to[commit SHA],(#N)to(commit SHA),#N's Xtocommit SHA's X,PR #Nto its squash commit), the form the landed stages use. These say more than the tag:#10629, three sites (plugin.ts:1543,skip-schema-sync-registers-object-metadata.test.ts:22,:153): 「the same ruling external-datasource-federated-read: federated read returns empty — the external object→remote-table mapping never registers (boot ordering) #7737/[finding] 15 more PASSING@objectstack/runtimetests print the samerefused a read onfeature — 134 lines after #10380 quiets its two, led bynotifications.hono.integration.test.ts(52) #10629 made for federated objects」 became 「the same ruling external-datasource-federated-read: federated read returns empty — the external object→remote-table mapping never registers (boot ordering) #7737 made for federated objects (commit 199ec47)」.199ec4712is external-datasource-federated-read: federated read returns empty — the external object→remote-table mapping never registers (boot ordering) #7737's fix, and its message states the ruling the sites paraphrase:OS_SKIP_SCHEMA_SYNCis a DDL flag while the federated binding is DDL-free, and the binding is reconciled onkernel:ready. Its message and diff name external-datasource-federated-read: federated read returns empty — the external object→remote-table mapping never registers (boot ordering) #7737, not [finding] 15 more PASSING@objectstack/runtimetests print the samerefused a read onfeature — 134 lines after #10380 quiets its two, led bynotifications.hono.integration.test.ts(52) #10629: the only commit that names [finding] 15 more PASSING@objectstack/runtimetests print the samerefused a read onfeature — 134 lines after #10380 quiets its two, led bynotifications.hono.integration.test.ts(52) #10629 as its own (13a6cb4ad, the runtime lane's anchor for it) is an expected-log-noise capture, a different subject, anda037f7cbd, which wrote the 「external-datasource-federated-read: federated read returns empty — the external object→remote-table mapping never registers (boot ordering) #7737/[finding] 15 more PASSING@objectstack/runtimetests print the samerefused a read onfeature — 134 lines after #10380 quiets its two, led bynotifications.hono.integration.test.ts(52) #10629 ruling」 phrase, records nothing [finding] 15 more PASSING@objectstack/runtimetests print the samerefused a read onfeature — 134 lines after #10380 quiets its two, led bynotifications.hono.integration.test.ts(52) #10629 added. So the dead number is dropped and the live external-datasource-federated-read: federated read returns empty — the external object→remote-table mapping never registers (boot ordering) #7737 carries the citation, beside the commit that decided it. The same pair stands indriver-sql(sql-driver.ts), the next stage.#10243, two sites (action-activation.ts:185,action-activation.test.ts:23): 「the Decide whether POST /api/v1/automation/:name/toggle belongs in the manage_metadata write set — it mutates flow enablement with no authoring capability #10243 mechanism ADR-0126 retires」 became 「the env-wide toggle leak's mechanism ADR-0126 §7.2 retires」. ADR-0126 §7.2 names that mechanism (the process-localflowEnabledmap) and the number (「the Decide whether POST /api/v1/automation/:name/toggle belongs in the manage_metadata write set — it mutates flow enablement with no authoring capability #10243 leak's mechanism」), so ruling C's ADR rung applies; the dogfood lane anchored a similar sentence to02b41232d, the measurement commit.#8672, ten sites: Observation: package permission sets are materialized with a tenant-less system context, sosys_permission_setrows land organization-less #8672 was an observation that no commit fixed.ff08691e6is the first in-repo record of its reasoning: its diff quotes 「an org-less row is defensible forsys_permission_set」 and names Observation: package permission sets are materialized with a tenant-less system context, sosys_permission_setrows land organization-less #8672 five times. So 「Observation: package permission sets are materialized with a tenant-less system context, sosys_permission_setrows land organization-less #8672's reasoning」 became 「commit ff08691's (recorded) reasoning」, and 「Observation: package permission sets are materialized with a tenant-less system context, sosys_permission_setrows land organization-less #8672 measured this primitive」 (system-write-organization.test.ts:347) became 「The card commit ff08691 cites measured this primitive」.system-write-organization.test.ts:117quotes what the file used to read, 「platform namespace ⇒ deliberately org-less (Observation: package permission sets are materialized with a tenant-less system context, sosys_permission_setrows land organization-less #8672)」; the quoted number is elided to 「(…)」 rather than re-spelled, so the quote stays true.#13178's census figure (engine.ts:5450,tenancy-by-object-classification.test.ts:26): 「tenant-audit: the "write without tenantId" signal is a throttled log warn gated on multi-tenant posture, so it cannot fire in any environment where code is exercised #13178 census measured … 135 of 175」 became 「census cited in commit e49d988's message measured … 135 of 175」. That message carries the figure; see Acceptance notes for what4ecafc78brecords about it.platform-object-tenancy.ts:144(thesys_upload_sessionupdate writer) takesf087c376f, the service-storage lane's anchor.#15094(find-hook-result-shape.ts:30): 「the ~70 … normalizer limbs the The{ records }-normalizer gate's population is app-showcase page modules, but all three instances found so far are outside it — #14460's stated evidence threshold is now met #15094 census counted」 became 「… limbs a census counted (commit 901773b records its band)」.901773b21wrote the header ofscripts/check-react-page-adapter-contract.mjs, which records that census (104 blocks atca46f8f12) and a re-measure band; it does not restate 「~70」, so the sentence points at the band and claims nothing more.#16805(engine.ts:13014,:13218): 「the contract review of PR fix(plugin-security)!: evaluate the insert-side RLScheckon the row that will be stored, afterbeforeInsert#16805 measured」 became 「the contract review commit a016f08 records measured」.a016f08b8is that pull request's squash, and its message records the review's finding.#16786: theobjectqlhalf (engine.ts:18230,:18264, two tests) takes5c8f5af50, the commit that declaredObjectRepository'sfindOne/updateshapes;engine.ts:18272's 「stays open on [finding] Ruling A on #16231 narrowsIScopedObjectRepository, butctx.api.object(name)resolves through the CLASSObjectRepository— the hook-facing door keepsPromise<any>, andupdateByIdkeeps it too #16786」 became 「(its spec half: commit 6059b29)」, the spec lane's anchor, since that half has landed.#14163(registry-ownership-refusal-envelope.test.ts:11):(ADR-0130 D3, commit 1dcb995f2). The cited thing is the install-time object-name check; ADR-0130 D3 decides it, and1dcb995f2landed it with a changeset naming ADR-0130 D1+D3:installPackage 命名空间闸认同物共同所有者 + 安装期对象名唯一性检查(同 PR 机器不可拆) #14163.#8460(sevenregistry.tssites): ADR-0029 D9.2a, the 2026-08-13 amendment, which names A package extension's scalar overwrites a tenant's Studio rename inside the object fold, so the rename still reaches no read #8460; the dogfood and spec lanes used the same.:2508's 「every shape A package extension's scalar overwrites a tenant's Studio rename inside the object fold, so the rename still reaches no read #8460 measured」 became 「every shape the ADR-0029 D9.2a amendment records」.#15041(engine.ts:7164,:9860, one test): 「the ruling on [finding] FILE_REFERENCE_TYPES disagree about their column:driver-sqlputs file/image/avatar/video/audio inJSON_COLUMN_TYPES,packages/cligenerate.ts gives themVARCHAR(2048)— and neither side is obviously the one that should move #15041 step 2」 became 「sequencing step 2 of ADR-0104's 2026-09-05 addendum」, the cli lane's spelling of the same record.#6241(metadata-service-roundtrip-conformance.test.ts:41): 「the gate's header carries /meta 的每个按类型闸门只在单数拼写下生效 —— 复数(PD #3 的规范拼写)整条绕过,含 book audience、app RBAC、dashboard 能力门 #3984/ADR-0057 D10 的 dashboardrequiresService组件门禁在GET /meta/:type/:name的缓存分支(默认路径)被完全跳过 #5881/GET /meta/books/:name(复数拼写)绕过 ADR-0046 §6.7 audience 门禁 —— 缓存分支的 doc/book 排除写的是字面量比较 #6241」 became 「… carries /meta 的每个按类型闸门只在单数拼写下生效 —— 复数(PD #3 的规范拼写)整条绕过,含 book audience、app RBAC、dashboard 能力门 #3984, ADR-0057 D10 的 dashboardrequiresService组件门禁在GET /meta/:type/:name的缓存分支(默认路径)被完全跳过 #5881 and the third bypass, fixed in commit 83a3b1f」, because that header (scripts/, another lane's surface) still carries the number itself.getMetaItem(SINGULAR) has the same ungated-caller defect asgetMetaItemsand it is sharper — its overlay read is??PRECEDENCE, not a union, so a pre-#6190 phantom SHADOWS the live env-wide row and becomes the served document #14770 removes」 became 「… commit d5cbb44 removed」 (protocol-meta.test.ts:100) and 「the resurrection Where does the allowOrgOverride read gate belong for metadata sweeps that read MORE THAN ONE type per request?getMetaItemsapplies none of its own #14683 closes」 became 「… commit 9632604 closed」 (:169), as stage 1 wrote it.:181's backticked`#14770`became plain 「commit d5cbb44」; its message records the four raw-org callers the line says it measured.loadManywhile the router's isloadby name, andunboundDeclarationsstill reads two sources where the undeclared-handler half now reads three #14423」 became 「the whole subject of the card commit a56baa2 closed」 (action-governance.ts:406); 「the C4 cell [finding] Two residual audit ↔ router asymmetries after #14123: the audit's third source isloadManywhile the router's isloadby name, andunboundDeclarationsstill reads two sources where the undeclared-handler half now reads three #14423's ruling left open」 became 「the C4 cell commit a56baa2 left open」 (plugin-governance-scoped-metadata.test.ts:5; that commit pins C4 as 「a BOUNDARY, not a defect」); 「route 3 of A comment asserts the SEARCH-axis remedy is worded identically to SORT/FILTER, the pin does not cover SEARCH, and the emitted message does not match — declared-≠-enforced on the refusal vocabulary #8648」 became 「route 3 of the card commit e5eeb49 fixed」 (query-expression-conformance.test.ts:1070, a line that commit wrote); 「filed [观察] registerHook 的代码注册面没有 #4281 那道校验:object: '' 静默变全局;allow 与 exclude 完全抵消时静默永不触发 #6573」 / 「[观察] registerHook 的代码注册面没有 #4281 那道校验:object: '' 静默变全局;allow 与 exclude 完全抵消时静默永不触发 #6573's ruling」 became 「filed the card commit 7084313 closed」 / 「The decision commit 7084313 records」 (hook-exclude-objects.test.ts:501,:502); 「(Seed pass-2 deferral is structurally unreachable for a KEYLESS dataset — so a declared pointer pair on an engine-owned object is order-dependent #11674, the card's "Second, NOT measured" question)」 became 「(the "Second, NOT measured" question on the card commit 9a884c6 fixed)」; 「measurement (Declare a first-classctx.referentialFieldClearon HookContextSchema — apps can only tell the engine'sset_nullcleanup write from a user edit by reading the operation-private__referentialFieldClear, or by sniffing write shape #13644)」 became 「measurement (on the card commit 34ce8e7 closed)」.engine.ts:2433; its message gives the reason); 「question at this line (finding(objectql): withretention+ttl+archiveall declared, only the ttl cutoff bounds the hot store #10527), since decided」 became 「question at this line, since decided by that commit」 (lifecycle-service.ts:1294, where:1293now cites5649efbf9); 「[finding]engine.tsreachesderiveViewContainerObjectthrough@objectstack/metadata's ROOT entry, so objectql's lean ADR-0076core.tsclosure now pulls MetadataPlugin, chokidar, glob and js-yaml for a six-line pure function #14680 is what they cost」 became 「the leak commit 3bd9b34 closed is what they cost」 (core-boundary.ratchet.test.ts:52); 「The lifecyclettlaccepts no row filter, so atransientobject with terminal rows in-band cannot spare them — givettlanonlyWhenmirroringretention.onlyWhen#10165 acceptance criterion」 became 「The acceptance criterion behind commit 8012960」.metadata-service-getobject-equivalence.test.ts:51,metadata-service-roundtrip-conformance.test.ts:68,metadata-facade.test.ts:101): the dead numbers became their commits, in the spec lane's 「commits SHA (what), …」 form; the live numbers in those lists stay,PR #7211beside its1507ba356.eslint.config.mjsdeclares no line-length rule, and a reflow would move neighbouring lines and every line citation into the file).Sites left
vitest.config.ts): none.ittitles, assertion arguments):#144224,#132733,#136573,#172193,#116743,#65733,#144232,#101652,#145352,#102902,#86722, and 14 more once each. Every one of the 25 is in this stage's population, so the table above holds an anchor for each. Non-test strings carry none. Strings are outside this stage's surface.src: the release-ownedCHANGELOG.mdnames dead numbers on 66 sites (44 numbers); left.test-typecheck-debt.json,tsconfig.test.jsonandtsconfig.scripts.jsoncite only live numbers.Mechanical guard: no code token moves
The guard (stage 2's) compares, base
4727fcb22against the working tree, over all 67 touched files, with TypeScript 6.0.3:forEachChildwalk. Comments are trivia there, and JSDoc is never visited.getChildrenwalk, JSDoc nodes skipped. String, template and numeric literals are compared in full on both readings.Results:
engine.ts:5): 0 files changed (exit 0).ARCHIVE_BATCH_SIZEtoARCHIVE_BATCH_SIZEX,lifecycle-service.ts): DIFFER on both readings (exit 1).'[value redacted]'to'[value redactedX]',driver-fault-redaction.ts): DIFFER on both readings (exit 1).ARCHIVE_MAX_BATCHES_PER_SWEEP = 20to21): DIFFER on both readings (exit 1).Each mutation went through
scripts/ablation-replace.mjs(wrap mode) under a shell trap that restores by absolute path fromHEAD. Each landed (anchor 1 to 0, blob changed), and each restore was proven equal to itsHEADblob (71f6c9268aeb,34b1dd7989b8,9594cdd593c8), withgit diff HEADempty and a clean tree afterwards.Changeset:
patch(distmeasured)files[]isdist,README.mdandCHANGELOG.md, and the package is not private. The dependency closure was built first (turbo run build --filter='@objectstack/objectql^...', 13 tasks). Then the package's ownbuild(tsup pluscheck-dts-emitted) ran three times in one script under the shared verify lock (VERDICT command-exit 0):9d6a0a8d6: 14distfiles hashed. Of the 137 rewritten non-test lines, 54 appear verbatim indist: 25 fromengine.ts, 7 fromaction-governance.ts, 5 fromplatform-object-tenancy.ts, and 17 from ten other files; inindex.d.ts/index.d.mts, the sharedutil-*.d.tschunk, andindex.js/index.mjs/core.js/core.mjs.coreandindexin.d.ts,.d.mts,.js,.mjs, and theutil-*chunk's two.dfiles).HEADblob,git diff HEADempty): all 14 files are byte-identical to leg 1, so the build is deterministic and the difference is the rewrite.So the rewrite ships, and
.changeset/20595-objectql-provenance-anchors.mddeclares apatchfor@objectstack/objectql, comment text only, with the claim'sClause-②: noline.Gates (head
1e0895870d)node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commandsat1e0895870d(68 paths against merge base8dea55d31; no stale-tree warning) derived 68 commands. All 68 ran, each exit code captured before any pipe: 68 exit 0.--ranreports 「68 derived, 68 run, 0 NOT-MEASURED, 0 UNRUN」 (a derived zero) and exits 0. A fullturbo run buildover./packages/*and./packages/*/*ran first under the verify lock (71 of 71 tasks, VERDICT command-exit 0), so no gate read an unbuilt workspace.node scripts/check-issue-citations.mjsexits 0 (「every citation this change adds resolves (or is a declared cross-repo reference)」, 14 judged across 17 files);pnpm check:issue-citationsexits 0 (self-test);pnpm check:doc-authoringexits 0 (the sibling-package prose-id baseline holds, no growth);pnpm check:nul-bytesexits 0, and a raw scan of the 68 changed files for control bytes finds none.1e0895870d:pnpm --filter @objectstack/objectql test: 360 test files and 7,082 tests pass.pnpm --filter @objectstack/objectql typecheckexits 0; itscheck:test-typecheckstep compiles all 361 tracked test files undertsconfig.test.json(tsc --listFiles), the ledger holding (40 files, 234 errors, 65 pinned signatures)..tsfiles plusdist/index.jsas the control: 68 results, 0 errors and 1 warning, the control's ignore notice; none of the 67 is reported ignored.eslint.config.mjsnever enables type-aware linting (its lines 327-328 say so), so a comment edit cannot move the verdict on an untouched file. The repo-widepnpm lintis CI's run.Acceptance notes
d150c3039, fast-forwarded to4727fcb22before any edit (both census readings of this package agree), and merged withmainonce at8dea55d31before the gates; that merge touched no file underpackages/objectqland neithercheck-issue-citations.mjsnordispatch-gates.mjs. Tests, typecheck and gates ran on the merged head.135 of 175figure.engine.ts:5450andtenancy-by-object-classification.test.ts:26state that census figure as measured.4ecafc78b, which re-derived the tenant-audit census as an in-tree artifact after tenant-audit: the "write without tenantId" signal is a throttled log warn gated on multi-tenant posture, so it cannot fire in any environment where code is exercised #13178 became unreachable, records that 「the 135/77% "silenced by the isSystem guard" figure has no surviving corroboration and is not reproduced」. This stage moves the citation to the commit whose message carries the figure and leaves the claim as written; whether those two sentences should say so is outside a citation sweep.enumerateBoard, between two full ones, returned 91 pages, 9,000 records and frontier [Decision] Pre-auth discovery/bootstrap payloads: inside BaseResponseSchema (coordinated objectui flip) or ruled exempt with reasons — today they are neither #9389, and raised nothing; the runs either side of it read 191 pages and frontier fix(driver-sql): a MySQL NOW() datetime default carries its column's precision #21252. Its only guard is a zero-record check. This stage discarded that reading and re-enumerated; nothing above rests on it. Noted only.Generated by Claude Code