You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Filed by the skills seat executing a maintainer ruling (decision-inbox batch 5, 2026-08-26, session session_01JANH3y7qe3MD8aLaLXci8N, verbatim: 「12452 不处理,其他接受」 accepting #1883's presented recommendation B). Reader: the domain:spec lane queue — this is the implementing card for that ruling.
Scope
Retire the two declared-but-unenforceable object-permission props allowRestore and allowPurge from packages/spec, following the ADR-0049 enforce-or-remove discipline and the ADR-0087 retirement flow (the spec-property-retirement playbook is the route map: removal route choice, liveness-ledger verdict confirmation, registry conversion, generated baselines/forms/docs, pin tests).
⛔ allowTransfer is NOT in scope — it is enforced and stays.
Why (from the ruling)
The operations these props claim to gate (undelete/restore, hard-delete/purge) do not exist in the platform today: no destructive lifecycle verb is in the ObjectQL operation vocabulary (pinned by packages/objectql/src/engine-middleware-operation-vocabulary.test.ts, from PR #8106). The props are therefore advertised switches with nothing behind them — an AI author declares allowPurge and believes a lock exists; the failure is silent. Retirement removes the trap; the keys return with the M2 lifecycle initiative (maintainer 2026-08-03: feature + RBAC in one batch), whose anchor card #1883 stays open on pm:on-hold with a machine-readable restart.
Day-of obligations for the implementing dev
Re-measure before touching anything — the anchor card's assertions are 72+ days old and its fact surface moved once already (allowTransfer got enforced after filing). Establish on that day's origin/main: current spec declaration sites of the two props; the OPERATION_TO_PERMISSION rows (recorded 2026-08-06 as pre-wired at permission-evaluator.ts:14-24 — re-verify); any reader that appeared since. A falsified premise ⇒ stop and report, never push through.
Retirement of published keys follows the playbook end to end (registries, baselines, forms, docs, pin tests) — never a drive-by delete. Clause-② applies at claim time (accepting-set change on a published surface).
Executable acceptance
git grep for allowRestore/allowPurge on origin/main after landing returns only ADR-0087 tombstone/registry rows (and the M2 anchor's prose); the retirement registries and generated surfaces are regenerated by the repo's tooling; the vocabulary pin stays green.
Filed by the skills seat executing a maintainer ruling (decision-inbox batch 5, 2026-08-26, session
session_01JANH3y7qe3MD8aLaLXci8N, verbatim: 「12452 不处理,其他接受」 accepting #1883's presented recommendation B). Reader: thedomain:speclane queue — this is the implementing card for that ruling.Scope
Retire the two declared-but-unenforceable object-permission props
allowRestoreandallowPurgefrompackages/spec, following the ADR-0049 enforce-or-remove discipline and the ADR-0087 retirement flow (thespec-property-retirementplaybook is the route map: removal route choice, liveness-ledger verdict confirmation, registry conversion, generated baselines/forms/docs, pin tests).⛔
allowTransferis NOT in scope — it is enforced and stays.Why (from the ruling)
The operations these props claim to gate (undelete/restore, hard-delete/purge) do not exist in the platform today: no destructive lifecycle verb is in the ObjectQL operation vocabulary (pinned by
packages/objectql/src/engine-middleware-operation-vocabulary.test.ts, from PR #8106). The props are therefore advertised switches with nothing behind them — an AI author declaresallowPurgeand believes a lock exists; the failure is silent. Retirement removes the trap; the keys return with the M2 lifecycle initiative (maintainer 2026-08-03: feature + RBAC in one batch), whose anchor card #1883 stays open onpm:on-holdwith a machine-readable restart.Day-of obligations for the implementing dev
allowTransfergot enforced after filing). Establish on that day'sorigin/main: current spec declaration sites of the two props; theOPERATION_TO_PERMISSIONrows (recorded 2026-08-06 as pre-wired atpermission-evaluator.ts:14-24— re-verify); any reader that appeared since. A falsified premise ⇒ stop and report, never push through.Executable acceptance
git grepforallowRestore/allowPurgeonorigin/mainafter landing returns only ADR-0087 tombstone/registry rows (and the M2 anchor's prose); the retirement registries and generated surfaces are regenerated by the repo's tooling; the vocabulary pin stays green.