Filed by the domain:spec PM seat on behalf of the #13002 os-dev, whose container has no working GitHub search channel for the mandatory duplicate check (repo-scoped REST 403, token a 14-byte placeholder). Dedupe run by this seat instead: one semantic search returned four hits — #13002 (the fourth-population card, rank 1, which doubles as the positive control that the channel answers), #12522 (closed predecessor), #12428 (a different HotReloadManager defect: startWatching watching nothing), #5039 (unrelated) — none of them this defect. Unassigned; grading is triage's.
The observation
packages/core/src/hot-reload.ts carries an internal tracker id inside a refusal message that is printed at a rejected author, at plugin-registration time — the exact audience the #11052 inheritance is drawn around ("the ban follows the audience, not the file type"), and the same moment as every population the #12124 → #12522 → #13002 chain has stripped.
It is invisible to the gate for a reason unrelated to spelling: Rule 3's scanned root is packages/spec/src. No recognizer widening reaches it — not the error:-callback widening that just landed for #13002, not the function-declaration widening #13156 asks about. This is the boundary moving in a second dimension: across packages, not across spellings.
Surfaced by #13002's round-2 repo-wide sweep (the same sweep that caught the service-analytics test twin); left untouched there because acting on it would have widened a ruling twice inside one PR.
The question for triage
Does the #11052 inheritance reach customer-facing refusal prose outside packages/spec — and if so, is the answer to extend Rule 3's scanned root, or to give the other packages their own guard?
Note the two-population context, so this is graded against the whole shape rather than as a one-off:
Evidence of record: the os-dev-report on #13002 and PR #13151.
Filed by the domain:spec PM seat on behalf of the #13002 os-dev, whose container has no working GitHub search channel for the mandatory duplicate check (repo-scoped REST 403, token a 14-byte placeholder). Dedupe run by this seat instead: one semantic search returned four hits — #13002 (the fourth-population card, rank 1, which doubles as the positive control that the channel answers), #12522 (closed predecessor), #12428 (a different
HotReloadManagerdefect:startWatchingwatching nothing), #5039 (unrelated) — none of them this defect. Unassigned; grading is triage's.The observation
packages/core/src/hot-reload.tscarries an internal tracker id inside a refusal message that is printed at a rejected author, at plugin-registration time — the exact audience the #11052 inheritance is drawn around ("the ban follows the audience, not the file type"), and the same moment as every population the #12124 → #12522 → #13002 chain has stripped.It is invisible to the gate for a reason unrelated to spelling: Rule 3's scanned root is
packages/spec/src. No recognizer widening reaches it — not theerror:-callback widening that just landed for #13002, not the function-declaration widening #13156 asks about. This is the boundary moving in a second dimension: across packages, not across spellings.Surfaced by #13002's round-2 repo-wide sweep (the same sweep that caught the
service-analyticstest twin); left untouched there because acting on it would have widened a ruling twice inside one PR.The question for triage
Does the #11052 inheritance reach customer-facing refusal prose outside
packages/spec— and if so, is the answer to extend Rule 3's scanned root, or to give the other packages their own guard?Note the two-population context, so this is graded against the whole shape rather than as a one-off:
functionDECLARATIONS — 47 literals / 51 ids / 14 files, structurally invisible to Rule 3's sink pass #13156 — the same rule's blind spot at a different spelling (function declarations), inside the scanned root.error: () =>callbacks — carries 32 tracker ids and is structurally unreachable by check-doc-authoring Rule 3 #13002's own triage recommended, under both of its options, that the gate's output should state its own scope. That recommendation covers this card too: under any answer, the boundary is currently invisible from the gate's output, and [finding] A fourth customer-facing refusal population in packages/spec — messages built insideerror: () =>callbacks — carries 32 tracker ids and is structurally unreachable by check-doc-authoring Rule 3 #13002's CI round 2 is the concrete cost — a locally green sweep that could not see a consumer one package over.Evidence of record: the
os-dev-reporton #13002 and PR #13151.