docs(adr): qualify the pre-repo ADR-0081 citations as cloud ADR-0081, letter-checked per site - #15612
docs(adr): qualify the pre-repo ADR-0081 citations as cloud ADR-0081, letter-checked per site#15612claude[bot] wants to merge 2 commits into
Conversation
… letter-checked per site (#9072) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012zGPuVVX3deAx9LdjK8jCk
…-0081-cloud-qualification
📓 Docs Drift CheckThis PR changes 4 package(s): 1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 2 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 134 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 34acf5f0574d1118d0b6dcf237b66eb9501ed677 && git checkout 34acf5f0574d1118d0b6dcf237b66eb9501ed677
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 4444885271c4fec39672a892d5189d6905a65b2c 6e019fa0add1a4b7a8a23e7826d776ac024536fc && git checkout -B drift-repro 4444885271c4fec39672a892d5189d6905a65b2c && git merge --no-ff 6e019fa0add1a4b7a8a23e7826d776ac024536fc
node scripts/docs-audit/affected-docs.mjs --json 4444885271c4fec39672a892d5189d6905a65b2c
|
|
REVIEW (mirror of the record on #9072; governed surface — Reviewed against the three-dot diff
Dev's verification quoted (on Disposition: review recorded here per the standing ADR rule; the PR stays a draft for an authorized human to approve and merge. On merge this seat probes ADR-0093 Generated by Claude Code |
Fixes #9072
What this settles
The cloud-side reading delivered on 2026-08-20 (issue comment
5350230356,objectstack-ai/cloudorigin/main@5f1bf23f) identified the pre-repoADR-0081as cloud ADR-0081 — Organization Management — Open Basics, Enterprise@objectstack/organizations, Accepted 2026-07-09 — with D1 = the default-org bootstrap (ensureDefaultOrganization,slug='default'reuse-or-create, owner binding,kernel:ready, the!resolveMultiOrgEnabled()gate) and D2 = the multi-org machinery closing intocloud/packages/organizations. The 2026-09-04 re-triage ruled: requalify, letter-check every site, do not prefix blind, and record the identification in ADR-0093's Relates to line.This PR does exactly that. It changes citations only — no decision text, no behaviour, no test assertion, no changeset-bearing surface.
Why no gate could have caught this. This repo owns its own
docs/adr/0081-trusted-react-page-tier.md(thekind:'react'page tier), so a bareADR-0081here resolves — to the wrong record.check-adr-anchors.mjsonly fails a number that names no record; a number that names the wrong record is invisible to it. That gate does, however, already recognisecloud ADR-0081structurally (CROSS_REPO_QUALIFIERS), so the repaired spelling is the one the tooling was built for.No site carried D4. D4 is the
SCOPE_RULES.sys_memberchange from{field:'user_id', from:'user'}to{field:'organization_id', from:'org'}.git grep -n "SCOPE_RULES" -- packagesreturns nothing in this repo — the surface left withplugin-org-scopingunder D2 — so there was no D4 site to mislabel. Likewise the kernel service name'org-scoping'is untouched (setup-nav.contributions.tsstill spellsrequiresService: 'org-scoping').Per-site classification
Every one of the 72 non-CHANGELOG
ADR-0081occurrences onorigin/mainwas classified before anything was edited.cloud D1— 18 citations requalified (letter kept, verified)content/docs/permissions/sharing-rules.mdx:179docs/qa/platform-checklist/areas/identity-auth.json:757docs/qa/platform-checklist/areas/identity-auth.json:824(2nd citation on the line)packages/platform-objects/src/apps/setup-nav.contributions.ts:79org-scoping— the OPEN basicspackages/platform-objects/src/identity/sys-user.object.ts:89packages/plugins/plugin-auth/src/auth-plugin.test.ts:1259packages/plugins/plugin-auth/src/ensure-default-organization.test.ts:3packages/plugins/plugin-auth/src/ensure-default-organization.ts:4packages/plugins/plugin-auth/src/ensure-default-organization.ts:12packages/plugins/plugin-auth/src/ensure-default-organization.ts:354packages/spec/src/kernel/public-auth-features.ts:125packages/verify/src/harness.org-context.test.ts:183packages/verify/src/harness.ts:181,:238,:418autoDefaultOrganizationflip and its posture abstentionpackages/verify/src/harness.ts:337,:656scripts/publish-smoke.sh:890cloud D3— 7 citations requalified (nav deep-link; 6 were bare on main)D3 is the nav deep-link, per the reading's own bounds note. Each of these describes the active-org record page reached from
nav_organizationwithrecordId: '{current_org_id}', or that token's resolution.docs/qa/platform-checklist/areas/identity-auth.json:762{current_org_id}recordIddocs/qa/platform-checklist/areas/identity-auth.json:774docs/qa/platform-checklist/areas/identity-auth.json:820docs/qa/platform-checklist/areas/identity-auth.json:824(1st citation on the line)nav_organizationsource pinpackages/platform-objects/src/apps/setup-nav.contributions.ts:74packages/platform-objects/src/identity/invite-entry-toolbar.test.ts:4packages/platform-objects/src/identity/sys-member.object.ts:47wrong letter— 1 site correcteddocs/adr/0093-tenancy-mode-and-membership-lifecycle.md:388(D8 non-goal 2) called thefeatures.organizationvsfeatures.multiOrgEnabledsplit "a deliberate ADR-0081-D1 distinction". Only the open half is D1's ("basic add-a-teammate stays OPEN"); the enterprise half — org management available — is squarely D2's ("multi-org machinery closes into@objectstack/organizations"). Corrected tocloud ADR-0081 D1/D2, with one clause naming which letter draws which half. The decision itself is untouched.cloud D2— 0 live sitesNo live citation in this tree carried a D2 label. ADR-0105's Builds on line at
:5already spelled itcloud ADR-0081 (@objectstack/organizations)— that was the clue the finding was filed on — and its:345citation note quotes"ADR-0081 D2"only as the superseded label it is describing.identification prose — 5 blocks (they name the record rather than carrying a live label)
docs/adr/0093:7(Relates to)docs/adr/0093:69(D9 summary bullet)docs/adr/0093:404(D9 recording preamble)docs/adr/0105:345(Citation note)docs/adr/0131:828-830(census note)react (ours, untouched)— 39 occurrences across 20 filesdocs/adr/0081-trusted-react-page-tier.md,docs/adr/0082:5,:8,docs/adr/0084:5, the two react-tier links inside the ADRs edited above (0093:409,0105:352),content/docs/protocol/objectui/layout-dsl.mdx,content/docs/references/ui/page.mdx,content/docs/ui/pages.mdx,docs/audits/2026-06-react-tier-authoring-dogfood.md(x5),docs/audits/2026-07-unknown-key-strictness-ledger.md:676,docs/qa/platform-checklist/areas/studio-authoring.json:1052,:1088, the threeexamples/app-showcasereact pages,packages/lint(x7),packages/spec/scripts(x3),packages/spec/src/ui/chart.zod.ts(x2),page.zod.ts:685,react-blocks.ts:3,scripts/gen-sdui-manifest.sh:650,scripts/regen-artifacts.mjs:327,skills/objectstack-ui/references/react-blocks.md(x2). None touched — see the control below.left verbatim and reported — 5 occurrences
Not
ambiguous: each is deliberate, and each is why the branch's "unqualified org-meaning" count is 5 rather than 0.docs/adr/0093:68,:403anddocs/adr/0105:344,:348— these quote the superseded label ("ADR-0081 D1"/"ADR-0081 D2") inside the very sentence that identifies it. Requalifying a quotation would erase the thing the prose is about.docs/qa/platform-checklist/areas/identity-auth.json:833— the append-onlyhistoryrow for revision 1, a record of what a past edit did. Itemrevisionwas deliberately not bumped and no history row added: a citation repair changes nothing a runner does, and bumping would invalidate run results pinned to revision 2. The gate'srevision == last history revisioninvariant still holds (both 2).ambiguous → left, reported— 0Every site's letter was determinable from its own surrounding text.
Grep controls
Occurrence counts,
git grep -o, excludingCHANGELOG.mdat every depth.origin/maincloud ADR-0081(qualified)ADR-0081not preceded bycloudReact-tier byte-identity control. The sorted multiset of every
ADR-0081-bearing line was taken on both sides.comm -23(present on main, absent on the branch) is 31 lines, andgrep -cE "react|REACT|kind:'react'|PageSchema|ObjectChart|OS_PAGE_REACT|trusted-react-page-tier"over those 31 rewritten lines returns 0 — no react-tier line was rewritten. The react-marker subset itself is 29 lines on both sides,diffempty,sha256sumidentical on both:D4 control.
git grep -n "SCOPE_RULES" -- packages→ no output, exit 1. There is nosys_memberscope-rule surface in this repo to have mislabelled.Verification
Gate family derived mechanically, not from a hand-written list:
Derived at HEAD
6e019fa0aagainst merge base900334a56— 16 changed paths, 106 commands. The first derivation ran on a stale tree (it warned thatscripts/pm/dispatch-gates.mjsitself had moved onorigin/main);origin/mainwas merged into this branch and the family re-derived clean before anything was run. Exit codes were captured before any pipe, into per-command log files. Every run reported below — the gate union, the builds, the typechecks, the tests and the grep controls — was taken on that same tree:git rev-parse --short HEAD=6e019fa0a, which is the tip this PR pushes.check:adr-anchors,check-adr-links,check-adr-symbol-anchors,check:doc-anchors,check:nul-bytes,check:role-word,check:docs-single-h1,check:org-identifier,check:cross-package-test-inputs,check:type-check-coverageThe 11 that first refused for a missing build — 2 with exit 3, 6 with exit 1 whose text says "Build first, then re-run", 3 with
PREREQUISITE NOT MET:@objectstack/lint check:doc-formula-expressions,@objectstack/lint check:doc-security-posture,@objectstack/spec check:api-surface,check:browser-reachable-entries,check:dual-source-exports,check:entry-nameability,check:exported-any,check:skill-examples,check:dual-build-cjs-loads,check:i18n,check:type-check-debt.Builds and every heavy run went through
scripts/pm/os-verify-lock.shwithOS_VERIFY_LOCK_SLOT=issue-9072. One acquisition returned 99 (never got a turn, slot parked); the interval was spent on lock-free work and the same slot was resumed rather than re-queued.turbo run build --filter='@objectstack/spec...' --filter='@objectstack/formula...' --filter='@objectstack/lint...'VERDICT command-exit 0 · held the lock 165sturbo run build --filter='./packages/*' --filter='./packages/*/*'VERDICT command-exit 0 · held the lock 235s—Tasks: 71 successful, 71 totalpnpm check:type-check-debtcheck-type-check-coverage --re-measure: OK — 13 ledger entr(ies) re-measured in 118.6s, 143 raw tsc error(s) total, none above its recorded number.typecheckfor@objectstack/platform-objects,@objectstack/plugin-auth,@objectstack/spec,@objectstack/verifycheck:test-typecheck: OKfor spec (54 files / 261 errors / 145 pinned signatures held) and plugin-auth (10 / 94 / 23) — both at their recorded numberspnpm check:pm-dispatch-gates— named by the dispatch;scripts/pm/**is untouched by this branch, so it is outside the derived familyVERDICT command-exit 0 · held the lock 418s—dispatch-gates self-test: 1445 cases pass(1445, not the 1415 the dispatch quoted: the tool moved onmain. No case was edited)vitest runon the three edited test filesTest Files 2 passed (2) · Tests 122 passed (122)(plugin-auth) andTest Files 1 passed (1) · Tests 21 passed (21)(platform-objects)check:platform-checklistis not CI-wired (#11730), so it was run by hand, as the ruling requires:Exit 0. Coverage derives inside this same gate — there is no separate
check:platform-checklist-coveragescript in this tree.Declared narrowing — whole-repo
pnpm lint. It is not in the derived family and CI runs it on this PR regardless. Locally, eslint was run over the 10 changed TypeScript files with the same flags CI uses:eslint --no-inline-config --format json, 10 files linted, 0 errors, 0 warnings (counts read from the JSON output, not from the console). The narrowing is safe to state as a measurement rather than a gap because this config is not type-aware — it declares noparserOptions.projectand noprojectService, andeslint.config.mjs:328says so in its own words — so a file's verdict is a function of that file plus the config, and this diff can move no untouched file's result.No test pins any of the edited comment strings.
git grep -n "ADR-0081" -- "*.test.ts"returns 6 hits on main, all of them comments ordescribe()titles; none is an assertion argument. The two runtime strings that changed (ensure-default-organization.ts:354,harness.ts:337/:656) are matched by tests only on other substrings (/orgContext:true does not compose with multiTenant/,/walled posture/), which are unchanged.Scope
skip-changesetis right and is applied: thepackages/**edits are comment and log-string text only, nothing is published or behavioural, and the rest isdocs/adr/**,docs/qa/**,content/docs/**and one shell script comment.ADR-0081label survives in 37 more citations across three unrelated claims — same collision #8474 fixed for the active-org stamp only #8531's remaining claims B and C are out of scope here and are untouched. This PR settles the identification they depend on: the mint-a-new-owning-record route those claims assumed is not needed, because the referent is recoverable and now written so a reader can follow it across repositories.🤖 Generated with Claude Code
https://claude.ai/code/session_012zGPuVVX3deAx9LdjK8jCk
Generated by Claude Code