Refiled after data loss. This replaces card #18021, which is unreachable: the account that filed it (os-musk) was suspended, and its issues, pull requests and comments now 404. The original is not recoverable through the API, so this card is rebuilt from a fresh measurement rather than from its text — and the measurement came out larger than the original reported (14 sites, not six).
Filed by the PM seat via the maintainer direct-dispatch channel, session_01NFSv55L8jzmE9yvi9UwZug, 2026-09-13. Maintainer instruction, verbatim: 「#18021 现在重立」. ⚠️ domain:* is the triage seat's field; the label here follows the anchoring rule (the fix lands in packages/spec) and the triage seat may overrule it without giving a reason.
The defect
14 ADR-0049 tombstones name @objectstack/spec 18 as the release that removed a key. @objectstack/spec is at 17.4.0 on main. There is no npm 18, and under the level ruling recorded in docs/adr/0087-metadata-protocol-upgrade-contract.md (Amended 2026-09-13, landed as a0dd872c1b) there will not be one as the carrier for a retirement:
- Pre-GA, a metadata-facing retirement or break ships
minor, carrying the **BREAKING** banner and its ADR-0087 disposition entry. […]
- An npm
major is a planned act — taken when the window closes and the queued conversions activate together — ⛔ never a side effect of one retirement card, however breaking that card is.
⇒ an author who meets one of these tombstones is told to look for a version that does not exist. The removal reaches them in a 17.x release.
⚠️ These tombstones are not wrong about history — they are stale relative to that ruling. They were written when a 18.0.0 cut was the assumed carrier. The ruling changed the carrier, not the removal. That is why this is a prose-accuracy card and ⛔ not a re-adjudication of any retirement.
Measurement — origin/main, 2026-09-13
packages/spec/package.json → "version": "17.4.0".
git grep -n "@objectstack/spec 18" origin/main -- packages/spec/src → 14 sites across 8 files:
| file |
lines |
api/export.zod.ts |
577, 718 |
automation/execution.zod.ts |
525 |
integration/connector.zod.ts |
254 |
kernel/plugin-lifecycle-advanced.zod.ts |
79, 85, 93, 291, 320 |
system/cache.zod.ts |
177, 207 |
system/disaster-recovery.zod.ts |
56, 259 |
ui/view.zod.ts |
2324 |
Lit control, same corpus, same pass — the house form @objectstack/spec 17.<minor>.<patch> is in wide use: ai/tool.zod.ts ×4, automation/flow.zod.ts ×6, data/datasource.zod.ts ×6, data/mapping.zod.ts ×3, plus ai/agent.zod.ts, ai/skill.zod.ts, api/analytics.zod.ts ×2, api/auth.zod.ts, api/batch.zod.ts, api/rest-server.zod.ts, data/driver.zod.ts ×2, data/hook.zod.ts, data/object.zod.ts ×2, integration/connector.zod.ts ×2, kernel/manifest.zod.ts, security/rls.zod.ts and others. ⇒ the 14 above are a deviation from an established convention, not the convention itself.
⚠️ Honest gap: the dark control in this pass was written badly and returned an ambiguous result; it is not relied on here. The lit control above is what makes the 14 a reading.
Precedent — the correct form is already settled in-tree
A sibling session already corrected one tombstone of exactly this shape from 18 to 17.5.0 (commit 89421dc402, on the claude/issue-16929-assignedprofiles-removal branch). ⇒ the target spelling needs no decision; it needs applying to the remaining sites.
Scope guard — load-bearing
⛔ Do NOT rewrite references to the metadata PROTOCOL major 18. That number is real and correct: toMajor: 18 in packages/spec/src/conversions/registry.ts, step18 in packages/spec/src/migrations/registry.ts, and the PROTOCOL_VERSION ladder D2/D3 are built on it. The ADR amendment above says so in terms — "Every 'major' above means a protocol major […] The level a changeset declares is the npm version of the lockstep fixed group, and the two move independently."
The defect is only where the number is attached to the package name (@objectstack/spec 18), which reads as an npm release. A tombstone that says "retired in protocol major 18" is correct and ⛔ must not be touched.
Acceptance
- Each of the 14 sites names the npm release that actually carries its removal — ⛔ determined per site from that key's own changeset/CHANGELOG, not by pasting
17.5.0 across all 14.
- ⛔ Zero occurrences of
@objectstack/spec 18 remain in packages/spec/src, with the lit control above re-run to prove the probe still fires.
- ⛔ No protocol-major reference is altered; state the before/after count for
toMajor: 18 / step18 as the untouched-control.
- Generated artifacts regenerated where tombstone prose renders into them (
content/docs/references/** projects describe() text — that exact coupling is what reddened check:docs on a sibling branch this week).
Clause-②: no expected — this moves no accept set and adds no key. Confirm rather than assume.
The defect
14 ADR-0049 tombstones name
@objectstack/spec 18as the release that removed a key.@objectstack/specis at 17.4.0 onmain. There is no npm 18, and under the level ruling recorded indocs/adr/0087-metadata-protocol-upgrade-contract.md(Amended 2026-09-13, landed asa0dd872c1b) there will not be one as the carrier for a retirement:⇒ an author who meets one of these tombstones is told to look for a version that does not exist. The removal reaches them in a
17.xrelease.18.0.0cut was the assumed carrier. The ruling changed the carrier, not the removal. That is why this is a prose-accuracy card and ⛔ not a re-adjudication of any retirement.Measurement —
origin/main, 2026-09-13packages/spec/package.json→"version": "17.4.0".git grep -n "@objectstack/spec 18" origin/main -- packages/spec/src→ 14 sites across 8 files:api/export.zod.tsautomation/execution.zod.tsintegration/connector.zod.tskernel/plugin-lifecycle-advanced.zod.tssystem/cache.zod.tssystem/disaster-recovery.zod.tsui/view.zod.tsLit control, same corpus, same pass — the house form
@objectstack/spec 17.<minor>.<patch>is in wide use:ai/tool.zod.ts×4,automation/flow.zod.ts×6,data/datasource.zod.ts×6,data/mapping.zod.ts×3, plusai/agent.zod.ts,ai/skill.zod.ts,api/analytics.zod.ts×2,api/auth.zod.ts,api/batch.zod.ts,api/rest-server.zod.ts,data/driver.zod.ts×2,data/hook.zod.ts,data/object.zod.ts×2,integration/connector.zod.ts×2,kernel/manifest.zod.ts,security/rls.zod.tsand others. ⇒ the 14 above are a deviation from an established convention, not the convention itself.Precedent — the correct form is already settled in-tree
A sibling session already corrected one tombstone of exactly this shape from
18to17.5.0(commit89421dc402, on theclaude/issue-16929-assignedprofiles-removalbranch). ⇒ the target spelling needs no decision; it needs applying to the remaining sites.Scope guard — load-bearing
⛔ Do NOT rewrite references to the metadata PROTOCOL major 18. That number is real and correct:
toMajor: 18inpackages/spec/src/conversions/registry.ts,step18inpackages/spec/src/migrations/registry.ts, and thePROTOCOL_VERSIONladder D2/D3 are built on it. The ADR amendment above says so in terms — "Every 'major' above means a protocol major […] The level a changeset declares is the npm version of the lockstepfixedgroup, and the two move independently."The defect is only where the number is attached to the package name (
@objectstack/spec 18), which reads as an npm release. A tombstone that says "retired in protocol major 18" is correct and ⛔ must not be touched.Acceptance
17.5.0across all 14.@objectstack/spec 18remain inpackages/spec/src, with the lit control above re-run to prove the probe still fires.toMajor: 18/step18as the untouched-control.content/docs/references/**projectsdescribe()text — that exact coupling is what reddenedcheck:docson a sibling branch this week).Clause-②: noexpected — this moves no accept set and adds no key. Confirm rather than assume.