test(spec): security, ai, identity, integration, migrations, marketplace, meta-spelling and studio test titles state each cited decision in words instead of a tracker number (stage 14) - #21799
Merged
Conversation
…ace, meta-spelling and studio test titles state each cited decision in words instead of a tracker number (stage 14) The eight small directories under packages/spec/src: 89 test titles and declared test strings that carried 94 tracker ids now state what the cited record decided, in words, or drop a number the title already explains. Text only: no assertion, identifier, test count or code comment changes. The two build-progress assertion needles that pin the source docblock's own carrier names stay. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
Contributor
📓 Docs Drift CheckNothing in this diff resolved to a documentable surface (no symbol, route or SDK anchor derived from 0 changed package(s)), so this run has no opinion about the docs. What this run could not see
Coarse fallback — 0 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #20749
Clause-②: no
Stage 14 of this card, and the fifth area of class (e): the test strings shipped under
packages/spec/src, as ruled in5902360492on #20513. This stage takes the eight small directories together:security/,ai/,identity/,integration/,migrations/,marketplace/,meta-spelling/andstudio/. Their 91 test-title and test-string literals carried 96 tracker ids citing 65 records. 94 ids in 89 literals now either state what their record decided, in words (form D), or are dropped where the title already says it. Two ids stay, for the reason given below. Text only: no assertion, identifier, test count or code comment changes.Census at the base (
e83c9f6154)Instruments:
census10.cjs(md59d08602ab972b4b8643c90d64d40fa41),census.cjs(md56e42a45a926d375013c32d62f16a296e) andcensus-wide.cjs(md5c98410a19529c439adb0afbfb00026a2), byte-identical to the copies stages 10 to 13 used. A literal counts as a test title when its folded message is argument 0 of adescribe/it/testcall,.each/.skip/.onlychains included. Everything else is an "other" string.The worktree was cut from
origin/mainate83c9f6154, one commit past the claim's8256a4b272. That commit touches onlyapi/error-code-ledger.zod.ts, which is not a test file, so the test census is the same at both.Both instruments read 1414 messages / 1500 ids in 315 files, the seat's reading at
8256a4b272. That is one more than stage 13's head reading (1413 / 1499 at72513933ee), and the one id is inui/component-props-unknown-members.pin.test.ts. It moved from 1 / 1 to 2 / 2 when #21764 (4331a6b16c, 2026-10-04T17:33Z) landed between the two readings. That commit removed one id-bearing string and added two: aruling:value at:322that the assertion at:417matches with a regular expression on its number, and adescribetitle at:596. It joins theui/stages.data/ui/api/system/src/)security/(this PR)ai/(this PR)identity/(this PR)integration/(this PR)migrations/(this PR)marketplace/(this PR)meta-spelling/(this PR)studio/(this PR)contracts/The eight directories read 91 messages / 96 ids in 34 files, the seat's figures.
migrations/migrations.test.ts:293. Lit, anexpectmessage:identity/api-key-retirement.test.ts:82. Dark: the comment atsecurity/permission.test.ts:309("The spec: retire theallowRestore/allowPurgepermission props (ruled 2026-08-26; M2 anchor stays open, keys return with M2) #12497 refusal shape was measured as") reads 0. Planted in a scratch copy of the headsecurity/explain.test.ts: an id put back into a title reads 1 / 1, and an id put into a comment reads 0.#plus digits) reads the same totals in seven of the eight directories. Instudio/it reads 5 / 5 at the base, because three literals in two test files are hex colours (#7c3aed,#2563eb,#94a3b8). None matches the gate's pattern.ai/reads 2 / 2 (the two needles below), and the other seven directories read 0 / 0. Nothing outside the eight moved. The wider pattern adds only the three hex colours.How the area was chosen
Stage 10's rule ranks whole first-level directories by ids and takes the busiest within about 10% of the ~100-id bound.
data/(501),ui/(416),api/(201) andsystem/(165) each exceed it alone, and the files directly insrc/(120) are 20% over. The eight small directories read 96 together, within the bound. That is the group the stage-12 and stage-13 ACCEPTs named, so the rule needed no second pass.Named for the next stages (the head census, 1325 / 1406):
data/501 in five stages. It has one subdirectory, so the files directly under it go in name order, in groups near the bound:aggregate-field-type-compatibility.test.tstodefault-value-tokens.test.ts: 22 files, 109 ids;document.test.tstofilter-dotted-head.test.ts: 21 files, 109 ids;filter-empty-operator.test.tstohook-body.test.ts: 21 files, 108 ids;hook.test.tstorecord-surface.test.ts: 16 files, 107 ids;search-fields.test.tstovalidation.test.ts(8 files, 16 ids) withdata/driver/(7 files, 52 ids): 68 ids.ui/416, about four stages.api/201, two.system/165, two.src/, 120, one.ai/build-progress.test.tsand the one incontracts/approval-service.test.ts. Each leaves only together with the source docblock it pins.What each id became
29 literals (33 ids) now state a decision in words. 60 literals (61 ids) drop a number the title already explains. Every cited record was read with its comments through REST: 60 answer 200. #6362, #8715 and #14676 answer 404, and their decisions were read from the landing commits.
cloud#1967andcloud#2172answer 403, because the cloud repository is not attached to this session.cloud#1967's decision was read from what landed, andcloud#2172is one of the two needles that stay.security/explain.test.ts:413security/high-privilege.test.ts:30security/permission.test.ts:545security/rls.test.ts:704security/tenancy-posture.test.ts:21,:50security/tenant-layer0-verdict.test.ts:16plugin-securityrecords the Layer 0 verdict it computed, and the publish site reads it.ai/agent.test.ts:74agent.tools[]was removed, and the docs teach the action-to-skill path.ai/knowledge-source.test.ts:97it.eachrow: "a dialect the protocol does not declare (js, a retired expression dialect, ADR-0058 addendum)".ai/skill-trigger-condition-value-shape.test.ts:47,:175ai/skill.test.ts:195triggerPhrases— phrases never routed a skill; triggerConditions do". See the note below the table.identity/api-key-retirement.test.ts:82expectmessage: "... must have zero holders after the ApiKeySchema retirement". The record answers 404.2c86fe3ea7retired the fictionalApiKeySchema, sosys_api_keyhas one declaration.identity/identity.test.ts:88,identity/organization.test.ts:132OrganizationSchema.logo(landed asb9d5422142).identity/platform-admin-capabilities.test.ts:10identity/platform-admin-capabilities.test.ts:34allowExportleft the admin sets' wildcard entry.integration/connector-provider-errors.test.ts:13integration/connector.test.ts:244integration/connector.test.ts:846b5404f496f.integration/connector.test.ts:1163,:1195expectmessage, "... after the errorMapping retirement", and "the errorMapping retirement is registered under ADR-0087". The record answers 404. The decision is read from13c48c2a55, which retired the elevenconnector.errorMappingkeys.migrations/migrations.test.ts:258visibleclient-side only — the half the server-side item gate did NOT change". The record made the server filter the nav entries insideareas[].migrations/migrations.test.ts:268migrations/migrations.test.ts:293migrations/migrations.test.ts:299migrations/migrations.test.ts:333migrations/migrations.test.ts:455migrations/migrations.test.ts:555Dropped only (61 ids): #123, #3544, #4001 (4), #4641, #4703, #4737, #4911, #5337, #5481, #5515 (4), #5685, #5955, #6628, #6698, #6861, #6919, #7113 (4), #7319 (2), #7990, #8326 (6), #8424, #8715, #9885, #11503, #12497, #12840 (2), #14103, #14676 (2), #14825, #15028, #15680, #15813, #16870, #17425, #17487, #18728 (4), #18978, #20321, #21260 (2),
cloud#1967.skill-trigger-condition-value-shape.test.ts:130, "(ComparisonOperatorSchema 的 $gt/$gte/$lt/$lte 不含 string,与平台自己只产出字符串的日期宏解析器相矛盾 #5685: no stricter than the runtime)" became "— no stricter than the runtime".#123inai/conversation.test.ts:294('Support Chat - Case #123') is a placeholder that cites no record: objectstack#123 is an unrelated broken-links report. The string is a fixture's session name, an input only. No assertion reads it, so dropping the number moves nothing.cloud#1967inai/solution-blueprint.test.ts:674: the record answers 403. Its decision is read from3e3ecb0e8fand its CHANGELOG entry: the strict mirror the design model generates against carries the applier'sSNAKE_CASEconstraints. The title already says "VALUE parity".#3896is the sharing-rule card (POST /data/sharing/rulesbypassingSharingRuleSchema). The skill title cited it as an "audit close-out", the batch that removedtriggerPhrasesalong with other dead clusters. The title now states the decision that landed with the key's tombstone (ai/skill.zod.ts:386) and its conversion entry (conversions/registry.ts:2744): phrases were never matched, and activation istriggerConditionsintersected with the agent'sskills[].it.eachrows atai/knowledge-source.test.ts:97and:98feed a%splaceholder. vitest 4.1.11 formats%swithString(value)and does not truncate it (@vitest/utilsbaseFormat). Only$nameinterpolation goes through the 40-characterobjDisplay. Both rows are short anyway, and the name comparison below confirms both full names.The two ids that stay
ai/build-progress.test.ts:236and:237areexpect(SOURCE).toContain('cloud#2172')andexpect(SOURCE).toContain('objectui#7388 block 2'). They are not titles. They are the expected values of assertions that read theai/build-progress.zod.tsdocblock and pin that its liveness watch names its two carriers (:84-85). Changing them needs a code comment and assertion logic, which this claim excludes. They leave together with that docblock's citations, like thecontracts/approval-service.test.ts:274needle.Readers
-tand--testNamePatternfinds onlypackages/qa/dogfood/README.md:142(-t "owner-scoped"), which is unrelated.__snapshots__directory exists under the eight directories, and no.snapfile is tracked underpackages/spec.packages/spec/vitest.repo-tests.json:ai/tool-confirmation-prescription-tense.pin.test.tsandidentity/position-delegatable-enforcer.pin.test.ts. Both were run in therepoproject at the base and at the head, and the other 32 inlocal.scripts/check-*.mjsself-test reads one. The hits are:unknown keys are rejected, not stripped (#4001)in the four files this PR edits;data/driver-nosql.test.ts:375,data/driver/memory.test.ts:548,data/driver/turso.test.ts:172andui/dashboard.test.ts:717(carries its unit (#15680)),data/object.test.ts:105((#5955)) andui/action.test.ts:1612(#3896 close-out). They are already in thedata/andui/census;ai/agent.test.ts:193, thesecurity/sharing.zod.ts:261docblock, twopackages/spec/CHANGELOG.mdentries andcontent/docs/releases/v17/17-0.mdx:326. None reads a test title, and none is this card's share.docs/protocol-upgrade-guide.md,packages/spec/spec-changes.json,packages/spec/src/migrations/registry.tsand the 842 files undermigrations/entries/, together withspec-changes.ts,chain.ts,index.tsandtypes.ts. Searched for every changed literal whole, at the base and at the head (178 needles), they read 0 hits. The lit controlsresumeAuthority,ui-notification-action-embed-config-retiredandelement-filter-and-form-node-refusedhit 5, 4 and 2 files.migrations.test.tsfinds each entry by itsid, never by a title.Text-only proof
Stage 10's scratch tool (
textonly10.cjs, md5d5e4801dbb4329ab1984da91e92fc47c) compares base and head file by file on three legs:#plus digits after. The declared lines areai/conversation.test.ts:294,ai/knowledge-source.test.ts:97and:98,identity/api-key-retirement.test.ts:82andintegration/connector.test.ts:1163.ai/build-progress.test.tsreads SAME with 0 changed.+and-lines are exactly the 89 planned lines, and every file keeps its line count.expectmessage changed VIOLATION; a title re-split into a+chain DIFF.Test counts: the 34 files were run at the base, in a separate base worktree at
e83c9f6154, and at the head, with--project local --project repo. Both sides read 911 / 911 passed, with the same count and status sequence per file in 34 of 34. 310 full test names change, and each equals the base name with the planned replacements applied (0 mismatches). No full name repeats on either side.Changeset:
skip-changesetMeasured, not assumed:
npm pack --dry-runof@objectstack/speclists 2068 files. 0 of the 34 touched files are in it, and no*.test.tsat all. The controlssrc/security/permission.zod.ts,src/ai/knowledge-source.zod.tsanddist/security/index.jsare in it.dist/, five new phrases and four old literals each read in 0 files. The controlUnrecognized key(s) onreads in 42.So this PR publishes nothing, and no changeset is added.
Verification (at
b364b8179b)pnpm turbo run buildover all packages: 71 / 71.@objectstack/spec:vitest run --project local: 615 files, 18358 passed, 1 todo.typecheckexit 0, includingcheck:test-typecheck(52 files / 246 errors / 135 pinned signatures held). Its program holds all 34 touched files, counted withtsc --listFilesOnly -p tsconfig.test.json.dispatch-gates --commandsderived 79 families, the same set as stage 13, and all 79 exit 0.--ranreconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN.check:meta-url-spelling,check:spec-changes,check:authz-resolver,check:error-code-casingandcheck:filter-alias-parity.--no-inline-configover the 34 files reads 0 errors and 0 warnings. The population comes from ESLint's own config: 34 configured, 0 ignored. No file setsparserOptions.projectorprojectService, so no untouched file's verdict can move.check-governed-merges --test: NOT governed, 178 changed lines.Acceptance notes
build-progressneedles stay with theai/build-progress.zod.tsdocblock they pin. Thecontracts/approval-service.test.ts:274needle is untouched, as the claim required.describe/it/testlines outsidepackages/specfinds 90 lines citing ids this PR handled, in 16 packages:plugin-security28 (14 files),rest20 (7),service-automation11 (7),lint5 (4),plugin-audit4 (3),runtime4 (2),qa/dogfood3 (2),plugin-hono-server3 (1),client2,platform-objects2,plugin-sharing2,cli2,objectql1,connectors1,formula1 andplugin-approvals1.ai/agent.test.ts:193andsecurity/sharing.zod.ts:261. Comments are not this card's share, and none is touched here.origin/mainmoved two commits past the base before this PR opened (fix(cloud-connection): refuse install-local sample data for a session with no active organization (ADR-0123 D2/D4) #21780, docs(pm-dispatch): say how the claim reads the Clause-② public surface #21783). Neither touchespackages/specor any file here, so nothing was merged. The gate reconciliation noted that two baselines changed across them (query-options-erasure,slot-lookup). This diff feeds neither, and the queue re-runs both on the merged generation.Generated by Claude Code