Uh oh!
There was an error while loading. Please reload this page.
feat(tooling): a DETERMINED register so the swallow-census worklist means what its heading says - #14433
Conversation
Uh oh!
There was an error while loading. Please reload this page.
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 33602264534 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
Fixes#13886
The
#12981census prints its tier-1 bucket under the heading "[1] DARK members, by file — the repair worklist". On the merge base that bucket holds 5 rows and four of them are settled determinations, not outstanding repairs. Membership is decided on three mechanical conjuncts and a comment is trivia to the AST, so an annotation — the programme's own way of recording a determination — cannot move a site out of the bucket. That is measured, not inferred: writing the batch-8 determination intopackages/verify/src/harness.tsleft the census byte-identical. The heading is a true statement about membership and a false one about work, and two rounds were spent on the gap.This adds the
DETERMINEDregister the card named, in the shape the card named.What it does — and the one thing it must not do
DETERMINEDregister keyedfile::function, the granularity and the reason of the sibling gate'sFAILURE_PROPAGATION_SITESinscripts/check-durability-degradation-log-level.mjs(never a line — line numbers churn; never a whole file — a file-wide key licences every future catch in it). That script is read as precedent and not imported: coupling a non-gate instrument to a merge-blocking one is the mistakeWRITE_SHAPED_CALLEESalready declines by copying the gate vocabulary by value.[1] DARK, stays at tierdark. The register changes exactly one thing: which heading the row prints under. Proven bydiffbelow and asserted arithmetically in the self-test.file::functionstill resolves to a tier-1 DARK member. A row failing any of the three goes STALE: it reddens the self-test in both modes, prints a loud block in the census, and — the part that matters — excuses nothing, so its site goes straight back onto the printed worklist.Two design points worth reviewing:
[#12981]marker. A bare marker in a large file is kept alive by every unrelated repair that mentions the programme, so the cross-check would pass over a determination that had been deleted outright — a green certifying nothing. Matching is whitespace-normalised and comment-prefix-stripped: re-wrapping a comment is safe, rewording it is not, which is the sensitivity wanted (a reworded determination is one a person should re-read).packages/plugins/plugin-auth/src/auth-manager.ts::verifyMcpAccessTokenis one today: batch 6 read it as a census FALSE MEMBER, but that reading lives in a report, not in the file, so there is nothing here to cross-check against. It stays on the printed worklist. The alternative — a row anchored on the file's unrelated[#12981]mentions — is exactly the "new lie carrier" the ruling forbids, and adding an annotation would need an edit outsidescripts/, which this PR does not make.The three registered rows:
packages/plugins/plugin-auth/src/ensure-default-organization.ts::tryInserterror(PR #13685)file(the determination is recorded at the caller, in the same file)packages/runtime/src/domains/keys.ts::handleKeysRequestsitepackages/verify/src/harness.ts::inviteForAudienceGatevoidand the loss is refused one line later (batch 8)siteThe counts are byte-identical — full
diffof the census outputBase is this PR's own merge base
96b627d13; the base reading was taken by runningorigin/main's copy of the script against the same tree. The only differences are the worklist annotation lines. Every count line is byte-identical, including MEMBERS 56/37, DARK 5/5, carries-error 24/19, channelled 27/14, QUIET 99, the AWAITED drop count and the SCOPE-resolver refusal count.That is the whole diff of the two outputs —
diff -ureports nothing else.Self-test — the register family is asserted in BOTH modes
The cross-check is asserted in
--self-test=gated(what CI runs viacheck:swallow-census-controls) as well as--self-test. A STALE leg that only fired in a mode the farm never invokes would be the lie carrier again — that is the finding #13919 already paid for. It also passes that card's own admission test: a successful repair cannot destroy it. A register row names a site the programme ruled OUT of repair, so emptying the worklist does not touch one; a row does go STALE if someone repairs its site anyway, and that red is the sibling gate's stale-entry discipline, demanding a one-line deletion that lands with the repair. Categorically unlikePOSITIVE_CONTROLS, where the cheapest way to green is to weaken the control.Three declared controls were added, run against synthetic registers so no leg needs the working tree mutated:
anchor-goneand excuse nothing;not-a-memberand excuse nothing;excused + outstanding == dark, and every excused key is still inmembers. This is the one that proves the register and the tier-1 DARK positive control cannot fight — the control asserts a file yields a member at tierdark, the register asserts the same site is still such a member before it excuses anything, and membership is computed before the register is consulted.Ablation — the STALE leg fires, and the site is not silently excused
Reworded the in-file determination in
packages/verify/src/harness.ts("silent BY DESIGN" to "silent BY ACCIDENT") under atrap ... EXIT INT TERMrestore. No build/dist leg is owed: the census reads the target file as text off the working tree (parseSourceFileon an absolute path), so nothing resolves through a packageexportsto adist/.Mutation proven on disk by occurrence counts on the anchored text —
pre old-count: 1 new-count: 0topost old-count: 0 new-count: 1— never by the editor's exit code.Restore proven byte-identical rather than by exit code:
git checkout HEAD -- ABSOLUTE_PATH,git diff HEADempty, andgit hash-objectback to the HEAD blob3325fd058232f51af1f8739d3c6c914327e1fb4d. Post-restore occurrence counts back toold 1 / new 0.git status --porcelainon the branch shows only the one intended file.Gates
Derived on the final tree with
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands(no hand-written path list). Change set: 1 path,scripts/measure-durability-swallow-family.mjs, vs merge base96b627d13. Union re-run after the final commit;git rev-parse --short HEADat that run:9c1beba32.Reconciliation via
--ran: 16 derived, 14 run, 1 NOT-MEASURED, 1 UNRUN.check-ci-filter-parity,check-cross-package-test-inputs,check-shard-attestation,pm/bare-root-worklist --self-test,check:agent-test-spelling,check:bash32-floor,check:cli-command-ids,check:cross-package-test-inputs,check:entry-guard,check:parse-guard,check:pnpm-filter-targets,check:ratchet-remedy-authority,check:swallow-census-controls,check:watch-hint-literal. Exit codes captured by redirect-then-read, never across a pipe.node scripts/check-test-completeness.mjs— exit 3,PREREQUISITE NOT MET. It grades a savedturbo run testlog and the family names it with no argument; its own text says to record this as NOT MEASURED, and that it is not a red.pnpm check:pm-dispatch-gates— cap-killed at 520s under the container's foreground ceiling. Recorded as UNRUN, not NOT-MEASURED, exactly as the reconciler's own warning demands (a run the OS killed leaves no verdict). CI runs it inLint & Repo Gates. What it could plausibly touch was checked by hand instead: its pin['scripts/measure-durability-swallow-family.mjs', 'selfTestMode', true]still holds (selfTestModeis unrenamed), and its end-to-end--rancase drives this card by path, not by the file's literals.Beyond the derived family, because this diff edits a gate-class script and adds path literals to it:
pnpm check:nul-bytes(0),pnpm check:declared-population-live(0),node scripts/check-self-test-wired.mjs(0),node scripts/check-self-test-workflow-commands.mjs(0),node scripts/measure-self-test-floor.mjs(0), and the script's own suite in both modes (0 / 0).Changeset
None, and the
skip-changesetlabel is applied. This diff isscripts/**only and publishes nothing from any package. Direct precedent, same file: the #13919 landing (PR #14413) carriedskip-changesetand no changeset, on a strictly wider diff (it also touchedpackage.jsonandlint.yml).Coordination
793065de2) —SELF_TEST_MODESand thecheck:swallow-census-controlswiring are in. The hot-serial the triage named is discharged and this PR is the later lander on that file, as ordered.catch { return null; }seeder family — 15 files outside #12923's five, and neither widening path is cheap #12981 batch 9) is still open and draft at8d79c623fand edits the SAME file in one disjoint block,POSITIVE_CONTROLS. This PR ⛔ does not touchPOSITIVE_CONTROLS. When fix(plugin-sharing): report a refused resolveToken usage stamp once as a durability degradation — #12981 batch 9 #14383 lands it moves the census to 55/36 and DARK to 4/4 and repoints the tier-1 DARK control atpackages/verify/src/harness.ts— that shift is fix(plugin-sharing): report a refused resolveToken usage stamp once as a durability degradation — #12981 batch 9 #14383's, not this one's, and this PR's own before/after stays byte-identical on every count either way.harness.ts::inviteForAudienceGatebeing both a positive control and a register row is compatible by construction and is control (3) above.DURABILITY_CRITICAL_CALLEESand declaringkeys.ts::handleKeysRequest) has not landed — zero hits forhandleKeysRequestunderscripts/on the base. This card lands before it, as the triage ordered. ⛔ Batch 10 must not re-key this register: thekeys.tsrow's own note says so in the file.Draft on purpose — not ready, no auto-merge.
Dev session:
https://claude.ai/code/session_01WLJQhde67SeTccsmnBVarVGenerated by Claude Code
Generated by Claude Code