You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] Three merged ADRs still say "Proposed — awaiting the maintainer's hand-merge, which is itself the acceptance act" — a sentence their own presence on main disproves, and which seats read as a gate #15453
Finding-class, filed by the domain:services execution seat (session 03324ae2-0f5b-5ad2-8a2e-cf4aaff5a909, seat post #6021). ⛔ domain:*, type and priority are triage's — this seat does not produce them. ⛔ docs/adr/** is a governed surface, so this is filed, not fixed.
⛔ Read this first: this is NOT a claim that any pause is over
ADR-0131's execution pause is enforced by #15193, which is open, and by the maintainer's own chat instruction. Neither is affected by this finding. What is wrong is only the marker a seat reads, not the state it reports.
The sentence
Three ADRs on origin/main carry a Status line of this shape:
Status: Proposed (…) — awaiting the maintainer's hand-merge, which is itself the acceptance act for a governed surface (Prime Directive #14).
The sentence names its own acceptance act as pending. But the file is on main — which is to say the hand-merge already happened. A reader who takes the line at its word is waiting for an event whose completion is the only reason they can read the line at all.
Measured, by searching for the predicate rather than recalling which ADRs are open
Scanning every docs/adr/*.md on origin/main for that phrase:
Controls, so this reads as an outlier rather than a house style: 135 ADRs on main; 86 carry Accepted. ADR-0125 shows the resolved spelling — "Status: Accepted (2026-08-20) — accepted by the merge that landed it on main" — which is exactly the act these three describe as still owed. And a negative control on the landing check: git log origin/main --oneline | grep -c '(#14976)' → 1, while the same command for a fabricated PR number → 0, so the merge reading is a reading.
Why ADR-0131's copy is load-bearing right now
Three records already treat ADR-0131 as in force while its own header says it is not:
ADR-0126's Status reads "Amended (2026-09-04) by ADR-0131" — a record cannot be amended by one that has not been accepted.
Meanwhile this seat reads that exact Status line on every check-in as its pause condition — it is written into the seat's standing check-in text as "re-read the Status line, never assume". That instruction is right; the line it reads is not. A pause keyed to a marker that can never change by itself is a pause with no end condition, which is a different thing from the pause the maintainer actually declared (and which #15193 correctly encodes as a card that closes).
⇒ The risk runs in both directions, which is why it is worth a card rather than a shrug: a seat could wait forever on a line that will never flip, or a seat could notice the contradiction and "correct" it themselves — and docs/adr/** is precisely where a seat must not do that.
What is actually owed (advisory — the disposition is the maintainer's)
For each of the three, one of:
Accepted, in ADR-0125's spelling, dated to the landing commit — if the merge was the acceptance act, which is what the sentence itself says it is; or
an explicit Proposed with the hand-merge clause removed, if a record can sit on main un-accepted — in which case the corpus needs one sentence saying so, because 86 Accepted records currently imply the opposite.
⚠️ Whoever takes this should re-run the scan rather than trusting this table — three is the count at 2026-09-04T16:1xZ and the corpus moves.
Refs: #15193 (the gate that actually holds the ADR-0131 line, open) · #14976 / 0ed271574 (ADR-0131's landing) · ADR-0125 (the resolved spelling) · ADR-0126 (already amended by ADR-0131) · Prime Directive #14.
Finding-class, filed by the
domain:servicesexecution seat (session03324ae2-0f5b-5ad2-8a2e-cf4aaff5a909, seat post #6021). ⛔domain:*, type and priority are triage's — this seat does not produce them. ⛔docs/adr/**is a governed surface, so this is filed, not fixed.⛔ Read this first: this is NOT a claim that any pause is over
ADR-0131's execution pause is enforced by #15193, which is open, and by the maintainer's own chat instruction. Neither is affected by this finding. What is wrong is only the marker a seat reads, not the state it reports.
The sentence
Three ADRs on
origin/maincarry a Status line of this shape:The sentence names its own acceptance act as pending. But the file is on
main— which is to say the hand-merge already happened. A reader who takes the line at its word is waiting for an event whose completion is the only reason they can read the line at all.Measured, by searching for the predicate rather than recalling which ADRs are open
Scanning every
docs/adr/*.mdonorigin/mainfor that phrase:0128-producer-discriminated-aad-for-cryptocontext.mdbbf88be850130-release-artifact-as-co-ownership-boundary.md09cc6be43(an anchor migration — its original landing is earlier; not chased here)0131-total-organization-ownership-no-null-organization-id.md0ed271574— "docs(adr): ADR-0131 … (#14976)"Controls, so this reads as an outlier rather than a house style: 135 ADRs on
main; 86 carryAccepted. ADR-0125 shows the resolved spelling — "Status: Accepted (2026-08-20) — accepted by the merge that landed it onmain" — which is exactly the act these three describe as still owed. And a negative control on the landing check:git log origin/main --oneline | grep -c '(#14976)'→ 1, while the same command for a fabricated PR number → 0, so the merge reading is a reading.Why ADR-0131's copy is load-bearing right now
Three records already treat ADR-0131 as in force while its own header says it is not:
mainvia docs(adr): ADR-0131 — organization ownership is total: no NULL organization_id; declared metadata stays in code; rows only when an organization authored them (Refs #13564) #14976, approved by the maintainer 2026-09-04".singleand refused under a wall (ADR-0131 D2/D3/D5/D13) #15204 / refactor(plugin-email): templates resolve the registry; the seed and the provenance stamp retire; organization-level editing is closed (ADR-0131 D6/D10) #15205 / feat(spec,services): deployment-level state has no organization column — settings global rung, plumbing objects, the audit ledger, #12699 made total (ADR-0131 D7) #15207 / feat(objectql,cli): inventory + migration — four fates per object, mirrors deleted only after the id→name rewrite is verified, per-table boot report (ADR-0131 D10) #15211 is cut from its §8.Meanwhile this seat reads that exact Status line on every check-in as its pause condition — it is written into the seat's standing check-in text as "re-read the Status line, never assume". That instruction is right; the line it reads is not. A pause keyed to a marker that can never change by itself is a pause with no end condition, which is a different thing from the pause the maintainer actually declared (and which #15193 correctly encodes as a card that closes).
⇒ The risk runs in both directions, which is why it is worth a card rather than a shrug: a seat could wait forever on a line that will never flip, or a seat could notice the contradiction and "correct" it themselves — and
docs/adr/**is precisely where a seat must not do that.What is actually owed (advisory — the disposition is the maintainer's)
For each of the three, one of:
mainun-accepted — in which case the corpus needs one sentence saying so, because 86 Accepted records currently imply the opposite.Refs: #15193 (the gate that actually holds the ADR-0131 line, open) · #14976 /
0ed271574(ADR-0131's landing) · ADR-0125 (the resolved spelling) · ADR-0126 (already amended by ADR-0131) · Prime Directive #14.