feat(spec)!: retire the incident-response, training and change-management families whole and the ESignatureConfig deadline pair (#15513, #14477, ADR-0049) - #15973
Conversation
…ment families whole and the ESignatureConfig deadline pair (ADR-0049) Nineteen defs and forty-five exported names leave @objectstack/spec/system via RETIRED_DEFS_BY_MAJOR[18] with three D3 semantic entries; the fourteen deadline-key tombstones leave with their defs' source and their registry entries stay as history. ESignatureConfig.expirationDays / reminderDays become retiredKey() tombstones with two RETIRED_KEYS_BY_MAJOR[18] entries and one D3 entry. Generated artifacts follow in the next commit (build + check:generated --fix). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
…mpliance-families-retirement
…e compliance-families retirement authorable-surface/system.json -88 rows and authorable-defaults/system.json -9 (the deliberate hand-deletions gate (a) asks for on a whole-def retirement), data.json +2 [RETIRED] rows and -2 defaults for the ESignatureConfig pair; api-surface -44, declaration-map -38, export-origins -44; the three reference pages removed and the system nav / index regenerated; strictness-ledger counts follow the schema files. All by the repo tooling (build + check:generated --fix). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
…gs in the compliance-families pin Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
…es (36 -> 33, 207 -> 204) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
…mpliance-families-retirement
…r counts on the merged tree The merge script's designed collection point: both artifacts were taken from main's side of the merge and regenerated on the merged tree (gen:docs, gen:strictness-ledger) so the system rows the retirement removed and the automation rows main added compose. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
📓 Docs Drift CheckThis PR changes 1 package(s): 12 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
What this run could not see
Coarse fallback — 129 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 98bba19479d746740ba173835f7a3b8d7e230eb5 && git checkout 98bba19479d746740ba173835f7a3b8d7e230eb5
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin f7db8f4fd268a86a08c62ae4894cf7417720f8c9 f8ccc47539ae4f189fb2be7bf5e56c53e27c0811 && git checkout -B drift-repro f7db8f4fd268a86a08c62ae4894cf7417720f8c9 && git merge --no-ff f8ccc47539ae4f189fb2be7bf5e56c53e27c0811
node scripts/docs-audit/affected-docs.mjs --json f7db8f4fd268a86a08c62ae4894cf7417720f8c9
|
…mpliance-families-retirement
|
CI note from the dispatching seat. Of the two red checks on Generated by Claude Code |
…les and drop the dead PROTOCOL_MAP row The dispatch-gates self-test pins that no cross-package hint reaches a test file outside packages/**; a bare examples/** glob covered the CRM example's smoke test. The pin now scans only JSON / MD / MDX / YAML under examples/ (every example has its own tsc typecheck) and the declaration + turbo.json name those five extension globs with heldBy witnesses. PROTOCOL_MAP.md linked the deleted change-management module; its row is dropped (the map test's own remedy). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
Fixes #15513
Fixes #14477
Two-card fold, one branch, one PR (
domain:spec, mode subagent). The three compliance-shaped families —system/incident-response.zod.ts,system/training.zod.ts,system/change-management.zod.ts— leave@objectstack/spec/systemwhole under ADR-0049 enforce-or-remove viaRETIRED_DEFS_BY_MAJOR[18]with one D3 semantic entry per family (theintegration/ErrorMappingConfig/ PR #15299 precedent), and theESignatureConfigdeadline pair (data/document.zod.tsexpirationDays/reminderDays) becomesretiredKey()tombstones with twoRETIRED_KEYS_BY_MAJOR[18]entries and one D3 entry (the PR #15514 precedent). Clause-②: yes — published exported symbols and two authorable keys leave; the seat hangs and clearsneeds:contract-reviewitself. ⛔content/docs/releases/**untouched.Rulings executed (verbatim)
#15513, director ruling 5548577921 (2026-09-05T01:57Z; maintainer, decision batch #40, verbatim 「同意」 — answering "not roadmapped"):
#14477, director comment 5548578591 (same batch, same verbatim reply), the 2026-09-02 ruling's own conditional:
The def list — nineteen, not fifteen (M2)
The ruling names the families and says "15 defs"; the files and
json-schema.manifest/system.jsoncount 19. Every one of them is retired — the number was the card's reading, the families are the ruling's. All forty-five exported names (19*Schemaconsts, 20z.inputaliases, 6*Parsedaliases) leave with them.incident-response.zod.ts(8)system/Incident,IncidentCategory,IncidentNotificationMatrix,IncidentNotificationRule,IncidentResponsePhase,IncidentResponsePolicy,IncidentSeverity,IncidentStatustraining.zod.ts(5)system/TrainingCategory,TrainingCompletionStatus,TrainingCourse,TrainingPlan,TrainingRecordchange-management.zod.ts(6)system/ChangeImpact,ChangePriority,ChangeRequest,ChangeStatus,ChangeType,RollbackPlanReader census (M1) — three takes, zero readers, every leg with a lit control
Word-bounded grep over all 45 exported names; tests and CHANGELOGs excluded; objectui read at the pinned sha
a472b07(the sibling checkout is exactly at the pin). Taken atb398ad258(branch base),82e5f28ca(first merge of main) and70582583f(final head,origin/main0cf086759merged) — identical each time.ObjectSchema,FieldSchema,defineStack/ViewSchema)packages/**outsidepackages/spec(+packages/drivers/driver-turso/src/spec, re-added after the--exclude-dir=specsweep)apps/**,examples/**,skills/**examples/app-showcase/src/automation/flows/index.ts:1237,title: 'Incident push failed: …'— a notify-message string literal, not a reference to the type)a472b07ESignatureConfig*,eSignature,expirationDays,reminderDays), all three legspackages/spec/src:document.zod.ts,document.test.ts(+ the new kit files)cloudand real customer configurations are UNMEASURED (the changeset says so verbatim).skills/,docs/,.claude/,README.md,ROADMAP.md: zero mentions.What changed
export *lines dropped fromsystem/index.tswith a survivor note per module (themessage-queue.zod/audit.zodhouse shape); 19entries/retired-defs/18.system__*.ts+ 3entries/semantic/18.*-family-retired.ts; the step-18rationaleextended by one sentence;registry.tsregenerated bygen:migration-registry(add-only: +737 lines, the one deleted line is the extended rationale). The 19 manifest keys and the families' 88authorable-surface/ 9authorable-defaultsrows hand-deleted — the deliberate deletion gates (a) and the manifest gate ask for; gen:schema then adjudicated it: "19 schema(s) left the published set since 0cf0867, each declared (json-schema.manifest.json 的「deliberate removal」删行仍是纪律而非门禁 —— #4650 的同类洞,上移一层(整 schema 级) #4725)" and "11 baseline deletion(s) … carry their own proof (authorable-surface 的 tombstone 门禁可被手编基线绕过 —— 删掉基线行就删掉了证据(#4638 / #4643 已两次这样过绿) #4650)".RETIRED_KEYS_BY_MAJOR[18]entries and 3 D3 entries stay as history — gate (b2) ofbuild-schemas.tssays so in its own words ("An entry naming a key the build no longer emits at all is NOT an error"), and the 17→18 upgrade guide still owes those prescriptions.deadline-keys-retirement.test.ts(every pin needed the schemas) is replaced bysystem/compliance-families-retirement.test.ts, which also pins the history.retiredKey()tombstones with the feat(spec): retire the fourteen inert deadline keys of the incident-response, training and change-management schemas (#14477, ADR-0049) #15514 guidance shape (qualified key, version, ADR, why inert, the former default, "Delete the key.", noos migrate metasentence — nothing covers the surface); the docblock example no longer authors the keys;entries/retired-keys/18.data__ESignatureConfig__{expirationDays,reminderDays}.ts+entries/semantic/18.esignature-config-deadline-keys-retired.ts;ESignatureConfigSchemastays live.compliance-families-retirement.test.ts— zero holders of the 45 names on every public entry (export-originstestkit), deletion probe, in-package importer walk, runtime namespace, shard absence under all three row spellings, the ADR-0087 registration (19 defs, 3 D3, no D2), the feat(spec): retire the fourteen inert deadline keys of the incident-response, training and change-management schemas (#14477, ADR-0049) #15514 history kept, and a tree-scoped absence leg whose radius is declared (scripts/cross-package-test-inputs.mjs+turbo.json,heldBywitnesses — the playbook rule docs(skills): make the retirement pin's walk radius a declared radius #15566 added after PR feat(spec): retire the fourteen inert deadline keys of the incident-response, training and change-management schemas (#14477, ADR-0049) #15514; [finding] the spec-property-retirement playbook mandates a tree-scoped absence scan thatcheck:cross-package-test-inputsstructurally cannot declare — every retirement written to the playbook gets a pin turbo does not hash, and an untyped resurrection can replay a cached green #15528 is closed by it).esignature-deadline-keys-retirement.test.ts— refusal at both sites on the base schema and throughDocument.eSignature(issue path,invalid_type, prescription, former default), no-materialize, the tscneverchannel, the ADR-0087 registration.document.test.ts: the two former default pins replaced by refusal witnesses, three fixtures stop authoring the pair.type-alias-convention.pin.test.ts: the 13 isomorphism pins those modules held leave (825 → 812; M122/M133/M151 slots vacant per the file's rule).api-surface−44,declaration-map−38,export-origins−44,authorable-surface/system.json−88,authorable-defaults/system.json−9,authorable-surface/data.json+2[RETIRED],authorable-defaults/data.json−2,json-schema.manifest/system.json−19, three reference pages removed,references/system/index.mdx+meta.json,references/index.mdx,references/data/document.mdx, the strictness-ledger counts.authorable-surface.base.jsonuntouched (its lag line is informational).Change Managementrow leavesgetting-started/quick-reference.mdx(heading17 of 36→16 of 33, both measured);packages/spec/llms.txtinventory counts 207 → 204 andsystem36 → 33 (thecheck:llms-txtfinding)..changeset/compliance-families-retired.md,@objectstack/specminor, BREAKING banner, the 19 defs + the pair, the census, FROM → TO, the kit,adr-0087: registeredfor the four ids (check:adr-0087-registration: "1 declared-breaking changeset(s), each carrying an ADR-0087 disposition").Hot file (M5)
packages/spec/src/migrations/registry.tsis generated fromentries/; my edits there are 25 new entry files plus one appended sentence in the hand-written step-18rationale— add-only, no reordering. Main's own new entry (18.plugin-security-scanner-retired.ts, PR #15930) text-merged clean beside them (check:migration-registry: current, 161 semantic / 105 retired-key / 116 retired-def). The #14478 stack (PRs #15626, #15814) merges main after this lands throughscripts/pm/os-regen-merge.sh.Verification (final head
70582583f,origin/main0cf086759merged viaos-regen-merge.sh, both times)pnpm --filter @objectstack/spec build— VERDICT command-exit 0 (2m24s held).check:generated— "✓ All 15 generated artifacts are up to date."check:migration-registrycurrent;check:adr-0087-registration✓.document.test.ts, the type-alias pin,message-queue-retirement,migrations,strictness-ledger,retired-key-migrate-sentence,alias-integrity,export-list,root-index,category-title,file-description).pnpm --filter @objectstack/spec typecheck— exit 0 (tsc, scripts, test layer: "54 file(s) / 261 error(s) … held", unchanged).pnpm --filter '...@objectstack/spec'= consumers): a probe file underpackages/coreimportingIncidentSchema,TrainingCourseSchema,ChangeRequestSchema, typeIncidentResponsePolicyand authoringexpirationDayson anESignatureConfig→tscexit 2 with TS2305 ×3, TS2724 (ChangeRequestSchema— "Did you meanChangeSetSchema?") and TS2322 (the pair'sneverinput); the survivor control (DataClassificationSchema,ComplianceFrameworkSchema,ESignatureConfigSchema) → exit 0. Probe removed under an EXIT trap;git statusclean.node scripts/pm/dispatch-gates.mjson the final tree and reconciled with--ran: 116 derived, 116 run, 0 UNRUN. 113 green, includingcheck:api-surface,check:authorable-surface,check:liveness,check:docs,check:variant-docs,check:dts-closure,check:doc-anchors,check:quick-reference-counts,check:cross-package-test-inputs("27 package(s) read outside themselves, all declared"), ci-filter parity ("all 162 declared cross-package glob(s) … covered"),check:nul-bytes, the three lint-doc gates (lint closure built). 3 NOT MEASURED, all exit-3/prerequisite refusals needing the whole-repodist(check:dual-build-cjs-loads,check:skill-examples—packages/client-react/distunbuilt,check:type-check-debt --re-measure— 32 unbuilt dependencies; its coverage half passed): CI'sLint & Repo Gatesruns them.pnpm lintis CI's; locally the 32 changed source files + the generatedregistry.tsunder the repo config with--no-inline-config: 0 errors / 0 warnings (--format json); the config is not type-aware (eslint.config.mjs:328), so this diff moves no untouched file's verdict.turbo ls --affectedvs the merge base: 78 of 79 packages (everything downstream of spec) — the farm run is CI's.documentorESignatureConfigis an enrolledpackages/spec/liveness/type, socheck:livenesswalks none of them; green, no rows invented.Not in this PR
.objectui-shabump: zero hits in objectui at the pin.ttlkeys with different units in one block, baretimeoutkeys, unit-less tenant timeouts #14478, feat(spec)!: duration-shaped number keys carry their unit in the key name — no-baseline gate + seven ADR-0087 renames (timeoutMs, ttlSeconds/ttlMs, *TimeoutSeconds) #15626, [#14478 stack 1/6] declare the two exemption classes ON THE SCHEMA — a sharedEpochMsfor the 6 epoch instants and a.meta({ externalVocabulary })marker on the 13 external-standard keys, honoured bycheck:duration-unit-keysand printed by the docs generator #15676,integration/ErrorMappingConfig+ErrorMappingRuleare 11 authorable keys with zero consumers — and one of them is nameduserMessage, colliding with the live #9934 channel #14676, feat(spec): retire the fourteen inert deadline keys of the incident-response, training and change-management schemas (#14477, ADR-0049) #15514, spec-property-retirement playbook still prescribes an issue id inside theretiredKey()guidance string, whichcheck:doc-authoringnow refuses #15388, [finding] the spec-property-retirement playbook mandates a tree-scoped absence scan thatcheck:cross-package-test-inputsstructurally cannot declare — every retirement written to the playbook gets a pin turbo does not hash, and an untyped resurrection can replay a cached green #15528 — each remains as it is.🤖 Generated with Claude Code
https://claude.ai/code/session_01M59rPZZFzqhfMUPFqqZTkf
Generated by Claude Code