[Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

Description

@hotlong

Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

  • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
  • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
  • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
  • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

  • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

Options and their real cost

  1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
  2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
  3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

四维分析(业务角度)

  • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
  • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
  • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
  • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationpm:queue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
       blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      
      Skip to content

      [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

      Description

      @hotlong

      Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

      Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

      • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
      • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
      • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
      • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
      numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
      0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
      0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
      0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

      Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

      • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

      Options and their real cost

      1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
      2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
      3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

      四维分析(业务角度)

      • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
      • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
      • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
      • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

      推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

      置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        documentationImprovements or additions to documentationpm:queue

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

          Description

          @hotlong

          Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

          Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

          • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
          • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
          • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
          • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
          numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
          0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
          0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
          0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

          Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

          • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

          Options and their real cost

          1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
          2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
          3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

          四维分析(业务角度)

          • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
          • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
          • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
          • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

          推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

          置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            documentationImprovements or additions to documentationpm:queue

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

              Description

              @hotlong

              Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

              Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

              • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
              • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
              • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
              • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
              numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
              0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
              0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
              0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

              Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

              • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

              Options and their real cost

              1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
              2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
              3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

              四维分析(业务角度)

              • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
              • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
              • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
              • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

              推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

              置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                documentationImprovements or additions to documentationpm:queue

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

                  Description

                  @hotlong

                  Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

                  Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

                  • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
                  • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
                  • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
                  • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
                  numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
                  0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
                  0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
                  0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

                  Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

                  • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

                  Options and their real cost

                  1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
                  2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
                  3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

                  四维分析(业务角度)

                  • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
                  • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
                  • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
                  • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

                  推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

                  置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    documentationImprovements or additions to documentationpm:queue

                    Type

                    No type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

                      Description

                      @hotlong

                      Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

                      Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

                      • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
                      • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
                      • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
                      • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
                      numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
                      0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
                      0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
                      0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

                      Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

                      • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

                      Options and their real cost

                      1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
                      2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
                      3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

                      四维分析(业务角度)

                      • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
                      • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
                      • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
                      • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

                      推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

                      置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        documentationImprovements or additions to documentationpm:queue

                        Type

                        No type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

                          Description

                          @hotlong

                          Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

                          Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

                          • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
                          • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
                          • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
                          • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
                          numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
                          0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
                          0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
                          0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

                          Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

                          • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

                          Options and their real cost

                          1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
                          2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
                          3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

                          四维分析(业务角度)

                          • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
                          • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
                          • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
                          • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

                          推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

                          置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            documentationImprovements or additions to documentationpm:queue

                            Type

                            No type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              [Decision] Where does a decision that governs OPEN code live? — cloud (private) ADRs are cited from this public repo in 60 files with a qualifier and ~110 more times bare, squatting on unrelated local numbers (0024 · 0071 · 0081); mirror them here, or qualify only #14496

                              Description

                              @hotlong

                              Filed by the director seat (session session_01WXyGTWPbbreqXow7Z2pZCk) on the maintainer's follow-up to the #14361 ruling, verbatim: 「但是同时需要评估,cloud中是有属于开源项目的adr吗?需要迁移吗?」. ADR-registry policy is ADR-class — human floor; this card carries the measurement, the options with their real costs, and one recommendation. #14361 is parked on this card (Blocked-by) so its 30-file re-pointing is not paid twice.

                              Measured (objectstack origin/main @ 00ff228fe, cloud origin/main @ 3856fbf)

                              • Visibility: objectstack-ai/objectstack is public; objectstack-ai/cloud is private (list_repos). A reader of this repo — a contributor, or an AI agent working from a clone — cannot open any cloud ADR-NNNN it cites.
                              • Registries: objectstack 133 records; cloud 43 records. Numbering is independent, so every number collides.
                              • Qualified cross-citations already in this repo (cloud ADR-NNNN, the structural spelling check-adr-anchors.mjs accepts): 60 files. By number: 0016 ×44 · 0024 ×19 · 0025 ×15 · 0009 ×12 · 0007 ×5 · 0018 / 0012 / 0008 ×4 · 0022 ×2 · 0081 / 0071 / 0010 ×1.
                              • Bare citations that mean the cloud record while resolving to an unrelated local one (the [finding] The SCIM/identity ADR-0071 citation resolves to the dataset semantic-layer record — 39 files point at a decision about multi-hop joins #14361 defect class), identity surface only, read at source:
                              numberlocal record (what the bare citation resolves to)cloud record (what the citing code means)bare citations in identity code
                              0024mcp-connectorsidentity-and-access-architecture71 (sys-sso-provider.object.ts:34,64,151,187, sys-user.object.ts:327 "ADR-0024 D4/D5.2" …)
                              0071dataset-semantic-layer-depthenterprise-identity-scim-v136 (#14361)
                              0081trusted-react-page-tierorg-management-open-basics-enterprise-organizations≥ 3 (sys-member.object.ts:47, sys-user.object.ts:59 "ADR-0081 D1", invite-entry-toolbar.test.ts:4)

                              Positive control: bare ADR-0010 in the same files (sys-account.object.ts:20, sys-api-key.object.ts:39, "§3.7 managed by better-auth; tenants may not edit schema") is the local metadata-protection model — so bare does not always mean cloud, and every citation has to be read, not pattern-replaced. Numbers with hundreds of bare citations (0025 ×197, 0018 ×230, 0012 ×111, 0008 ×175, 0010 ×502) are dominated by their local meaning; only the identity surface was read here.

                              • Cloud ADRs that speak about the open repo / open packages: 22 of 43. By subject they split into (a) boundary / commercial decisions that govern both sides and belong in cloud by nature — 0002 open-core boundary, 0016 authz open/paid boundary, 0025 service-ai to cloud, 0082 ask stays closed, 0020 distribution model, 0022 license model, 0023 pricing, 0005 model tiering, 0006 / 0010 / 0018 multi-tenant & on-prem EE, 0008 cloud-connection boundary, 0013 durable agent turns, 0019 AI build reuses the open validation stack, 0085 brand-split pricing; (b) decisions whose mechanism half is implemented in this repo's open packages0024 Identity & Access Architecture (D1 per-env identity, D3 cloud-as-IdP, D4/D5 admin & break-glass, D6/D7 SCIM targets the env — all implemented in open plugin-auth), 0071 Enterprise Identity V1: env-side SCIM via @better-auth/scim (open mechanism, PR feat(plugin-auth): env-side SCIM 2.0 via @better-auth/scim (ADR-0071, OPEN mechanism) #2356), 0081 Organization Management — open basics half; and (c) already mirrored: 0079 record display-name — cloud holds the 2026-06-28 design (41 KB), this repo holds a retroactive reconstruction written 2026-08-08 (19 KB) with a Provenance section. Nine local ADRs already link out to cloud ADR-NNNN (0003 · 0033 · 0038 · 0040 · 0048 · 0063 · 0064 · 0066 · 0105).

                              Options and their real cost

                              1. Qualifier only — every citation that means a cloud record is spelled cloud ADR-NNNN (the gate's structural form); nothing moves. Cost: one mechanical re-pointing pass over the identity surface (~110 sites); the open repo keeps citing decisions its readers cannot open.
                              2. Mirror the open half — for the (b) set, write a local ADR that states the decision as it governs this repo's code (the 0079 shape: own number, Provenance section naming the cloud record and date, boundary/commercial content left in cloud), amend the cloud record with a pointer, and re-point this repo's citations to the local number; qualifier spelling remains for the (a) set. Cost: three ADRs to write and human-merge (0024 is large), one re-pointing pass (the same pass as option 1, different target), and a standing rule for the future.
                              3. Move files (renumber) — physically migrate cloud records into this registry. Cost: renumbering breaks every existing citation in both repos (cloud cites its own 0024 / 0071 too), 0079 shows the two repos already diverge on one record, and the commercial half would leave the private repo. ⛔ Not recommended by anyone here.

                              四维分析(业务角度)

                              • ① 项目长远合理性(权重 ≥50%):开源仓的代码由读者读不到的私有决策记录治理,是长期不可持续的形状 —— 外部贡献者与 AI agent 只能猜;0079 的「事后重建」就是这个压力已经冲破一次的证据。长远终态应是一条规矩:决策住在它治理的代码所在的仓;划开闭源边界与商业的决策住 cloud,开源侧引用带 cloud 限定词;凡治理开源代码的机制半边,开源仓自有记录(带 Provenance 指回 cloud)。方案 2 就是这条规矩;方案 1 只修了拼写、没修「读不到」;方案 3 把数字搬家,破坏两仓全部既有引用。
                              • ② 实际业务拉动:今天的拉动来自三处 —— 身份代码 71 处裸 ADR-0024 与 36 处裸 ADR-0071 指向无关记录、生成文档把错指针放在应用作者面前、运行期拒绝消息把编号念给运维;还有一个更大的:objectstack 是公开仓,任何外部读者顺着 cloud ADR-0024 都会撞 404。拉动真实、中等,且随开源用户增长而增长。
                              • ③ 防 AI 犯错:方案 2 让在开源仓工作的 agent 能读到治理它正在改的代码的决策(D4/D5.2 break-glass、D6/D7 env-side SCIM),而不是从 71 处注释反推;方案 1 只让门禁分辨得出「这是别仓的号」,读不到内容照旧要猜;逐处按语义读是硬要求(同一文件里裸 ADR-0010 是本仓记录),⛔ 不能按号批量替换。
                              • ④ 创业阶段不扩散:方案 2 新增三份记录,但那是已声明决策的补账(0079 先例、cloud 记录本身写明「open the mechanism」),不是新契约;⛔ 不搬文件、不重编号、不把商业半边搬出私有仓;其余 (a) 类 19 份维持 cloud + 限定词,零新增。方案 3 扩散最大。

                              推荐:方案 2(镜像开源半边)+ 方案 1 的拼写规则作为地板。执行顺序:(i) 先立规矩(本卡裁决即规矩,一句话进 AGENTS.md「ADR 引用」一节由 skills 席落编);(ii) 三份镜像 ADR 各一张卡(0024 身份架构开源半边、0071 env-side SCIM 机制、0081 组织管理开源基础),ADR 类人工合并;(iii) 镜像落地后一次改指 —— 身份面裸引用改指本仓新号,(a) 类保持 cloud ADR-NNNN;#14361 的执行随 (iii) 走,⛔ 不先按 cloud ADR-0071 改一遍再改第二遍。回退:若不想现在写三份 ADR ⇒ 方案 1 立即执行(#14361 现裁 B 即是),镜像另行排期。

                              置信缺口:只读了身份面;0009(console SDUI-first)、0007(env 内包安装)、0012(runtime feature contract)三份 cloud 记录的机制半边是否也主要落在开源代码,未逐条读;cloud 侧引用自己 0024/0071 的处数未计(方案 3 的代价下限已足够否决它)。

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                documentationImprovements or additions to documentationpm:queue

                                Type

                                No type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions