Uh oh!
There was an error while loading. Please reload this page.
tooling(pm): record 14 unrecorded REFUSE-WIDE gate families - #14800
Merged
Conversation
…the sandbox-filename fix 12 of #14695's 14 unrecorded REFUSE-WIDE members are recorded in a new CENSUS_REFUSE_WIDE table in scripts/pm/bare-root-worklist.mjs, each with its own measured share and the base commit (2aa8456, the base #14325's own census used) it was measured at. A new table rather than new TRIAGE rows: TRIAGE is coupled to sweep(), which can only discover a bare-word population literal assigned to a POPULATION_CONSTANT-shaped name, and none of these families hold that shape (confirmed empirically: adding one to TRIAGE makes --self-test fail STALE immediately). Two of the fourteen ("the two packages/spec-filtered ones") are not recorded -- PR #14692's body, read in full, does not name them, and guessing would fabricate a measurement no one took. Also folds in the small second half: scripts/check-whole-set-label-write.mjs's three self-test sandbox filenames (scripts/w.mjs, scripts/writer.sh, .github/workflows/w.yml) existed in no tracked tree and, spelled as bare literals in a top-level export outside any selfTest()-shaped function, entered the gate's own declared-population hint set as dead leads. Renamed to three real, unrelated, already-tracked paths; no behaviour change to the gate's verdict. Fixes#14695 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WLJQhde67SeTccsmnBVarV
… 14) Follow-up to a36af67, which shipped 12 of 14 and left the two `packages/spec`-filtered members ("check:error-code-provenance", "check:objectui-pin-citations") as an open question -- the issue text's claim that they were named in PR #14692's body with their shares did not hold up against that body's actual text. The filing session's own sitting-1 census artifacts supplied the two names (both in its "root-wide, same class, no ledger row" bucket, members 13 and 14). Re-measured here by this table's own method rather than copied: strace openat tracing against a 2aa8456 worktree, run via `pnpm --filter @objectstack/spec run check:X` (tsx production leg). Both land within 1 file of the filing session's own sitting-1 counts (2070 vs 2069, and an exact 1192 vs 1192) -- corroborating the method a second time, now on a tsx-run gate rather than a plain node one. check:objectui-pin-citations (20.4%) lands below the issue's summarised 32-52% band; recorded as measured rather than forced into it. Fixes#14695 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WLJQhde67SeTccsmnBVarV
baozhoutao
marked this pull request as ready for review
September 3, 2026 04:02
This was referenced Sep 3, 2026
This was referenced Sep 3, 2026
Contributor
This was referenced Sep 3, 2026
Contributor
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes#14695
What landed
All 14 of the 14 unrecorded REFUSE-WIDE members, recorded in a new
CENSUS_REFUSE_WIDEtable inscripts/pm/bare-root-worklist.mjs, each carrying its own measured share and the base commit it was measured at (2aa8456cf, the base #14325's own census used). Shipped in two sittings on this PR — 12 first, then the remaining 2 once the filing session supplied their names (see "Follow-up" below):check:route-envelopecheck:driver-memory-censuscheck:parse-guardcheck:live-db-isolationcheck:org-identifiercheck:startup-registry-verdictcheck:wildcard-fallthroughcheck:init-service-contractcheck:settings-bind-windowcheck:cli-command-idscheck:type-check-coveragecheck:type-check-debtcheck:error-code-provenancecheck:objectui-pin-citationsPlus the folded second half:
scripts/check-whole-set-label-write.mjs's three self-test SANDBOX filenames (scripts/w.mjs,scripts/writer.sh,.github/workflows/w.yml) — dead leads that existed in no tracked tree, spelled as bare literals in a top-levelexport const(not inside aselfTest()-shaped function, somaskSelfTestsnever hid them) — now renamed to three real, unrelated, already-tracked paths (scripts/check-nul-bytes.mjs,scripts/build-console.sh,.github/workflows/ci.yml). No behaviour change:check-whole-set-label-write --self-testand its production leg print byte-identical verdicts before and after;check:declared-population-live's "158 of 202 families … every one reaches this tree's tracked files" line is unchanged, but the family's own declared-hint set no longer contains a dead entry.Follow-up: the last 2 of 14
The first sitting on this PR shipped 12 of 14 and left
check:error-code-provenanceandcheck:objectui-pin-citations(the "twopackages/spec-filtered ones") as an open question — the issue text's claim that they were "named in PR #14692's body with their measured shares" did not hold up against that body's actual text, which states an exact share for onlycheck:route-envelopeand names the other 13 only in an aggregate bucket row.The filing session (which ran the original #14325 census) supplied its own census artifacts directly, confirming both families sit in that census's "root-wide, same class, no ledger row" bucket as members 13 and 14:
pnpm --filter @objectstack/spec run check:error-code-provenance(sitting-1 tracked_reads 2079, undeclared 2077, byRoot.packages 2069) andpnpm --filter @objectstack/spec run check:objectui-pin-citations(tracked_reads 1200, undeclared 1200, byRoot.packages 1192).Both shares below are re-measured here by this table's own method — never copied from the filing session's numbers, to keep the table one-method/one-base — using the same
strace -f -e trace=openattechnique against a2aa8456cfworktree, this time invoked aspnpm --filter @objectstack/spec run check:X(thetsxproduction leg, no--self-test) rather than a plainnode scripts/check-X.mjs. Both land within 1 file of the filing session's own sitting-1 counts — 2070 vs 2069, and an exact 1192 vs 1192 — corroborating the method a second time, now on atsx-run gate rather than a plainnodeone.check:objectui-pin-citations(20.4%) lands below the issue's summarised "32–52%" range for this bucket; recorded as measured rather than forced into the quoted band, matching how the earlier sitting handled the four members that measured above it.Why a NEW table, not new
TRIAGErowsRecording one of the 14 as an ordinary
TRIAGErow was tried first and self-reverts:TRIAGEis coupled tosweep(), which can only ever discover aconst X_ROOTS = ['packages']-shaped bare-word population literal (this file's own narrow recogniser). None of these 14 families hold that shape — most declare no population constant of any kind;check:route-envelope's bare'packages'word is ajoin(ROOT, 'packages')call argument, not an assignment. Confirmed empirically: addingcheck:route-envelope SCAN_ROOTS packagestoTRIAGEmakes--self-testfail immediately withSTALE: check:route-envelope SCAN_ROOTS packages—sweep()never produces the key. These 14 rows were found by #14325's wider fs-trace census (PR #14692, PR #14323), a different and broader instrument than this file's own sweep — so they live in a newCENSUS_REFUSE_WIDEtable with its own self-test battery, explicitly uncoupled fromTRIAGE's stale/fresh/contradicted machinery (which would ask a question this table has no honest answer to).Method — re-measured, not copied, and why
PR #14692's body, read in full before writing this (saved and live copies diff byte-for-byte but for a trailing newline), states an exact share for exactly one of the fourteen —
check:route-envelope(36.6%, "2138 undeclared reads"). The other thirteen are named with no percentage in the issue/PR text; the body's own bucket table states only the aggregate "14 members, 32–52%". Carrying a share that isn't actually recorded anywhere reachable would be the exact "defect wearing fresher digits"bare-root-worklist.mjs's own docblock prices as the costlier error, so every one of the 14 shares is measured fresh, at the base #14695 names (2aa8456cf) — never mixed with this branch's later tree.Method:
strace -f -e trace=openatover each gate's own production CLI leg, run in a dedicated detached worktree checked out at2aa8456cf(pnpm installd there), filtered to successfulopenatcalls landing on a tracked file underpackages/. This traces the syscall, so it counts what the process actually opened regardless of which Node API did the opening. A JS-levelfs.readFileSyncmonkey-patch (--importpreload) was tried first and measured empty — 0 reads — againstcheck:route-envelope's known-nonzero population, because Node's ESM binding for a core module's named export does not reliably re-resolve through a later reassignment of the CJS-compatfsobject property; recorded in the new table's docblock so the same dead end isn't re-walked.check:route-envelopetraced at 2181/5837 (37.4%), within 2% of PR #14692's cited 2138 "undeclared reads" (36.6%) — the gap being that figure's own subtraction of the handful of route paths this gate already spells as literals elsewhere (already visible toextractWatchHints, hence excluded from "undeclared") — corroborating the method against the one figure available without reproducing its bookkeeping term for term.What is NOT in this PR
No subtree was declared for any of the 14 — recording REFUSE-WIDE is the opposite action from declaring, per the card and the 2026-08-26 ruling it cites.
Six of the fourteen measure outside the issue's summarised "32–52%" range: four above it (
check:driver-memory-census91.7%,check:parse-guard90.6%,check:live-db-isolation90.3%,check:type-check-coverage/check:type-check-debt55.8%) and one below it (check:objectui-pin-citations20.4%) — each measured by the identical method as the rest, and the verdict is unaffected either direction: existingTRIAGEREFUSE-WIDE rows already span 39%–99% under the same trade.Verification
node scripts/pm/bare-root-worklist.mjs --self-test— green: 57 live TRIAGE rows unchanged (none stale/fresh/contradicted), plus 14 CENSUS row(s) … well-formed, disjoint from TRIAGE, contribute no hint of their own, and share one base commit.CENSUS_REFUSE_WIDErow'sreadsto an invalid value (9999999 > of, then-5) —--self-testwent RED on exactly the new battery's shape assertion each time (direct exit-code capture, not piped); restored from a saved pre-mutation copy and reverified green both times.node scripts/check-whole-set-label-write.mjs --self-testand its production leg — byte-identical verdict text before/after the fixture rename.node scripts/check-declared-population-live.mjs— unchanged: "158 of 202 famil(ies) declare a path population, and every one of them reaches this tree's tracked files".node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands— 17 commands derived for this changeset (unchanged across both sittings); run underscripts/pm/os-verify-lock.shat heada78607fe0c: 16 of 17 green, the one exceptionnode scripts/check-test-completeness.mjsexiting 3 — NOT MEASURED by its own design (it needs a CI test log and says so), not a red.pnpm check:pm-dispatch-gates(the heaviest — its self-test respawns its own CLI many times) passed at 1240 cases.node scripts/pm/dispatch-gates.mjs --ranreconciliation: 17 derived, 17 run, 0 UNRUN.origin/mainfetched and checked before both pushes; 0 commits behind at the second sitting's push.git diff --stat(cumulative): 2 files changed, both underscripts/—skip-changeset, per this card's explicit dispatch (tooling-only, publishes nothing from any package).🤖 Generated with Claude Code
https://claude.ai/code/session_01WLJQhde67SeTccsmnBVarV