Skip to content

fix(drivers): text-operator case folding is the contract's answer, not the dialect's (#6518) - #6706

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-6518-contains-case-folding
Aug 8, 2026
Merged

os-zhuang merged 3 commits into
mainfrom
claude/issue-6518-contains-case-folding

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Fixes #6518

$contains / $notContains / $startsWith / $endsWith are case-SENSITIVE by contract (#4706 Q2 = A), and $icontains folds ASCII only (#4706 Q1 = A). Neither held: case sensitivity was whatever LIKE happened to mean on the dialect underneath. Both directions over-matched — rows the filter excludes came back — which on an ADR-0021 RLS read scope is over-reach, not a loose filter (#3948).

$contains family — case-SENSITIVE $icontains — ASCII-only fold
SQLite / turso / sqlite-wasm ❌ LIKE folds ASCII ✅ lower() is ASCII-only
Postgres ✅ LIKE is case-exact ❌ LOWER() folds all of Unicode
MySQL ❌ follows the collation ❌ LOWER() folds all of Unicode

Read across: each dialect was already right on the half another one got wrong. That is why neither half was findable from one backend, and why the acceptance asked for a live PG/MySQL cell.

Premise re-verified against post-#6549 origin/main

#6549 (82397b6) merged the morning this was dispatched and rewrote applyLike / pushLike (adding the fold axis) and the five DEBT rows. Re-measured on d13f627: the premise still holds. applyLike still emitted one LIKE … ESCAPE ? for every dialect and LOWER() for the fold; the five case rows of FILTER_TEXT_CASES were still unanswered and still the sole reason the five DEBT rows survived. premise_still_valid: true.

What is emitted now

One emitter (textMatchPredicate), construct chosen by dialect, so escaping and folding stay a single code path — an unescaped wildcard is a filter bypass, P0 (#5567):

  • SQLite family → GLOB. PRAGMA case_sensitive_like is connection-global (one query would redefine every other query on the connection), so the fold cannot be switched off per statement. Of the operand-level tricks, CAST(col AS BLOB) LIKE ? was measured to match nothing at all — SQLite's LIKE is false for a BLOB operand — so the operator has to change. GLOB is case-exact and brings its own escaped class: *, ?, [ → [*], [?], [[], because SQLite's grammar gives GLOB no ESCAPE clause. $icontains keeps lower() on both operands.
  • Postgres → LIKE, unchanged (already case-exact). Only the fold moved, from LOWER() to an explicit translate() over the 26 ASCII letters — the mapping is visible in the emitted SQL, so its ASCII-only-ness is structural rather than a property of the server's locale.
  • MySQL → LIKE over CAST(… AS BINARY), byte-wise so no collation decides the case; the fold is 26 REPLACEs over that same binary rendering. Byte-wise ASCII lowering is the ruled fold because UTF-8 is self-synchronising — a byte in 0x41..0x5A can only ever be a real ASCII A..Z. The rejected alternatives are written out on the helper (LOWER() over-folds; LOWER() on a binary string is documented ineffective; CONVERT(… USING ascii) collides café with cafÉ, strictly worse).
  • Any other client keeps the pre-drivers(sql family): 文本算子的大小写折叠是「方言的」而非「契约的」—— $contains 在 SQLite 过折叠、$icontains 在 PG/MySQL 过折叠 #6518 shape — the only form that still runs there — recorded as residue in the ledger rather than left to be discovered.

Per-face verdict table

Every face from the dispatch inventory. "Not mentioned" would read as "missed", so all of them are here.

# face verdict evidence
1 driver-sql applyLike → textMatchPredicate 已改 Per-dialect construct table. All 17 FILTER_TEXT_CASES green on sqlite and on live PG.
2 driver-turso RemoteTransport.pushLike 已改 Independent compiler, moved in the same batch to GLOB + glob escapes. New parity suite pins it to the local face on every case.
— driver-sqlite-wasm 已改 (inherited, executed) Inherits face 1; the whole case-set now runs on sql.js. GLOB is supplied by the SQLite build, not the application, so "it inherits" is not taken on faith.
3 service-analytics read-scope-sql 本就合规 Emits ? that both consumers rewrite to $N, with "double quoted" identifiers — Postgres-shaped, and on Postgres LIKE is the ruled semantics (measured live: %acme% → row 2 only, %ACME% → row 1 only). Assumption now written down in like-pattern.ts and pinned by new cases, so it fails rather than rots.
4 service-analytics filter-normalizer + shared like-pattern.ts (+ native-sql-strategy, objectql-strategy) 本就合规 Same Postgres-shaped evidence; both executing compilers assert $N placeholders and no ILIKE/LOWER(.
5 formula matchesFilterCondition 本就合规 (now pinned) String.prototype.includes / startsWith / endsWith compare exactly. Nothing changed — which is exactly why it is pinned: this is the JS baseline the drivers were brought to, and the next mistake here is a "helpful" toLowerCase() that no assertion would have caught.
half objectql having-filter 本就合规 (now pinned) Same mechanism. Pinned because it is the ONE text face with no conformance-table coverage (check-driver-conformance scopes itself to packages/drivers/*), so a fold added here would go red nowhere.
frozen driver-memory (memory-driver.ts RegExp-'i'; memory-matcher.ts includes; analytics face) 明确不在范围 + #5499 Freeze restated as a ruling in the dispatch. Still folds full Unicode on the query path while its reference matcher is case-exact — one package, two answers. DEBT row kept and re-pointed.
frozen driver-mongodb (mongodb-filter.ts hard-coded $options: 'i') 明确不在范围 + #5499 Same. DEBT row kept and re-pointed.

$icontains on faces 3/4, per the dispatch's (d): verified fail-closed, unchanged. The package has zero $icontains references; filter-normalizer.ts's fieldLeaves throws invalidFilterError and read-scope-sql.ts's compileOperator throws from its default: arm. Both are now asserted, so "unimplemented" cannot quietly become "dropped" — a dropped predicate widens. Adding the operator there stays #6520's programme.

Reverse verification — direction predicted BEFORE each run

Three experiments, each reverting one arm, each predicted to fail a different set of cells. That the sets are disjoint is the claim that this issue really is two independent defects rather than one seen twice.

experiment predicted measured
sqlite arm GLOB → LIKE exactly the 5 case-sensitivity rows red on sqlite, nothing red on postgres ✅ exactly those 5 case rows (+5 blocks naming the construct directly = 10 reds in that file), no other case in the table moved
drop the column-side lower() (sqlite) the fold becomes observable in ROWS — retiring #5702's "unobservable on SQLite" caveat ✅ $icontains: 'acme' and 'ACME' both ['1','2'] → ['2']; $icontains: 'CAFÉ' ['3'] → []
postgres fold translate() → LOWER() exactly the 2 ASCII-only rows red on the live postgres cell, nothing red on sqlite ✅ $icontains: 'café' answered ['3','4'] where the case-set demands ['4']; the 'CAFÉ' mirror answered ['3','4'] where it demands ['3']

The CAST(col AS BLOB) LIKE ? candidate was also measured before being written off, on better-sqlite3 3.53.4 against the nine-row fixture: every shape returned []. GLOB's escape class was measured the same way — unescaped *a*b* returned 6 rows where *a[*]b* returns 1.

Which live cells executed, and which did not

  • sqlite — ran (embedded).
  • live postgres — RAN, on a PostgreSQL 16.13 provisioned in-container, database created with the ICU locale provider — the configuration where LOWER('CAFÉ') genuinely is 'café', so the over-fold was reproduced before the fix and is absent after. All 17 cases + the fixture-control green (OS_TEST_POSTGRES_URL set).
  • live mysql — NOT run. No MySQL server was provisionable here (no mysqld, no working Docker daemon). It is a declared skip by name via the testkit's declareUnprovisionedCell, never a faked green, and OS_EXPECT_LIVE_DIALECT_MATRIX=1 turns that skip into a failure for a runner that believes it provisioned one. CI's Temporal Conformance (live PG + MySQL) job already sets both URLs, so the mysql cell executes there. Its arm rests meanwhile on documented behaviour plus a compiled-SQL pin — knex builds a MySQL statement without a server, so the shape (two CAST(… AS BINARY), 52 REPLACEs under the fold, no LOWER() is asserted in-process.

Pin sweep

Swept the whole repo in one pass; every flipped pin asserts the new substance, none was merely deleted, and every refusal assertion is verbatim.

file what moved
driver-sql/sql-driver-icontains-and-retired-operators.test.ts compiled-SQL pin LOWER(…) LIKE LOWER( → lower(…) GLOB lower(; now imports FILTER_TEXT_CASES; added case-sensitivity, negation, glob-escape blocks
driver-sql/sql-driver-text-case-conformance.test.ts new — the case-set across DIALECT_CELLS (#5589 conventions) + the per-dialect compiled shape
driver-sqlite-wasm/sqlite-wasm-icontains-…test.ts now imports FILTER_TEXT_CASES; added case-sensitivity + glob-escape blocks on sql.js
driver-turso/remote-transport-text-predicates.test.ts "the two operators agree on SQLite today" → they now differ; LIKE … ESCAPE shape → GLOB, plus a new block asserting */?/[ are escaped and % is not
driver-turso/turso-local-remote-text-parity.test.ts new — case-set on BOTH transports, difference asserted first
driver-turso/remote-transport-{comparand,null-comparand,undefined-comparand}-refusal.test.ts incidental pattern pins %…% → *…*, LIKE → GLOB; each keeps the claim it was making
formula/matches-filter.test.ts, objectql/having-filter.test.ts new case-sensitivity pins on faces that were already compliant
service-analytics/__tests__/like-metacharacter-escape.test.ts new block pinning the Postgres-shape + case-exactness assumption, and $icontains fail-closed at both doors
scripts/check-driver-conformance.mjs three rows deleted, two re-graded (below)

Searched for and found no other fixture, REST-layer test or doc example asserting a folded row set.

DEBT re-grade

driver              FILTER_TEXT
driver-memory       DEBT   → re-pointed to #6682 (+ #6520)
driver-mongodb      DEBT   → re-pointed to #6682 (+ #6520)
driver-sql          ok
driver-sqlite-wasm  ok
driver-turso        ok
check-driver-conformance: OK — 28 covered cell(s), 2 in the DEBT ledger, 0 exempt.

The two frozen rows could not point at #6518 (it closes here), and #6520 covers only requirement 1 ($icontains). Requirement 2 for those two packages had no successor, so one was filed unassigned, search-first-deduped: #6682. Both rows now say explicitly that both successors must land before the row can go, because coverage is judged by importing the whole case-set — a half-answered cell must not import it.

Changeset level — graded, with reasoning

minor on the three driver packages. Not a downgrade to dodge the ADR-0087 gate: no declared surface moves. $contains still exists, takes the same comparand, and filter.zod.ts is untouched — the case-sensitivity delivered here was already published as the contract by #5701 one release earlier in this same open v17 major, and the drivers were the half that had not caught up. Prime Directive #12 in the direction it points: declared = enforced. Walking the gate's four dispositions honestly, none applies (registered: nothing registered; unpublished: the packages are published; already-registered: no id; no-migration-prescription: refused, since the body does carry migration guidance) — which is the gate saying this is not an ADR-0087-class change. Same grade its sibling #5702/#6549 took for the same operator family in the same rc cycle. The gate confirms: this PR adds no declared-breaking changeset.

The behaviour change is stated prominently in the changeset body regardless: result sets only ever get narrower, and anyone relying on $contains to ignore case should write $icontains.

Gates — enumerated from .github/workflows/lint.yml, run one by one

pnpm lint                                    OK (exit 0)
turbo run typecheck (packages/*, apps/*)     OK — 120 successful, 120 total
pnpm --filter @objectstack/spec exec tsc     OK
pnpm test (whole repo)                       OK — 135 successful, 135 total
check:driver-conformance                     OK — 28 covered, 2 DEBT, 0 exempt
check:query-options-erasure                  OK — test surface 263 sites (at the ceiling, not under it)
check:type-check-debt                        OK — 34 entries re-measured, none above its number
check:engine-double-contract                 OK — 98 pinned, 133 DEBT, 2 exempt
check:nul-bytes                              OK — 6228 files
check:adr-0087-registration                  OK — no declared-breaking changeset
check:empty-changeset                        OK — 1 declaring changeset added

Also green, each run individually: check:slot-lookup, check:verify-stand-in, check:doc-authoring, check:docs-audit-scope, check:role-word, check:quick-reference-counts, check:adr-anchors, check:org-identifier, check:authz-resolver, check:service-providers, check:route-envelope, check:error-code-casing, check:wildcard-fallthrough, check:meta-type-normalized, check:init-service-contract, check:durability-log-level, check:startup-registry-verdict, check:objectui-changeset, check:release-notes, check:release-body, check:node-version, check:workflow-status-functions, check:shard-attestation, check:published-files, check:resume-authority-declared, check:merge-driver, check:spec-parsed-alias, check:stall-guard, check:type-check-coverage, check:i18n, check:i18n-coverage, check:app-nav-i18n, check:skill-frame-sync, check:skill-compatibility, check:prerelease-pins, and the spec-scoped set (check:generated --reconcile-only, check:skill-docs, check:spec-changes, check:upgrade-guide, check:authorable-surface, check:docs, check:skill-refs, check:react-blocks, check:api-surface, check:exported-any, check:dual-source-exports, check:skill-examples), plus check:doc-formula-expressions, examples typecheck and the downstream-contract typecheck.

One red, and it is not in lint.yml: check:objectui-pin-fresh reports the objectui pin as stale. It lives in release.yml / objectui-pin-freshness.yml (the Version-Packages/release path), is a function of repo state versus objectui's main rather than of this diff, and refreshing it would be exactly the pin-bump rider this change must not carry. Left untouched and reported.

Constraints honoured

  • packages/spec source: zero changes — the case-set already encoded the ruled contract, so no spec-side change turned out to be necessary.
  • content/docs/releases/: untouched.
  • No pin bumps.
  • Zero new as any / as never / @ts-ignore. The one as unknown as added is the sanctioned fix(drivers): 聚合函数拒收带上 ADR-0112 信封,并把两类条件分开措辞 (#5907) #6204 named-member spelling, and it replaces rather than adds erosion: asLibsqlClient() in the turso testkit names the Client target type once, where the pre-existing suites each wrote client: stub as never — a cast to the bottom type, which would keep compiling even if client were re-typed to something the stub cannot model. Existing call sites can migrate to it; nothing forces them to here. The new matrix suite reaches knex through the public getKnex() rather than the (driver as any).knex its sibling matrices use.
  • No new fake engines were introduced, so no assertEngineDeleteDispatch site was needed; every new/rewritten rejection case asserts code and status (ADR-0112), never a bare toThrow.

Successor repricing (必答项)

issue effect why
#6409 — count_distinct in the SQL family unaffected Aggregation projection; shares no code with the text-predicate emitter and no dialect-selection seam with it.
#6543 — unique-violation regex → shared @objectstack/types predicate unaffected Error-message parsing on the write path. Different file, different direction; nothing here touches unique-violation.ts.
#6402 — turso options?: any narrowing very slightly easier remote-transport.ts gains no new any, and the new parity suite exercises both transports through the typed driver surface on 22 cases — narrowing work there now has a row-level regression net it did not have. Not a blocker either way.
#6401 — GroupByNode.alias unaffected Group-by AST; no overlap with the filter emitter.

Open questions (adjudicated here, per the dispatch — not blocking)

  1. translate() vs lower(x COLLATE "C") on Postgres. Both measured ASCII-only on live PG 16 (C.utf8 and ICU databases). Chose translate(): its ASCII-only-ness is structural — the 26-character mapping is visible in the emitted SQL — where COLLATE "C" is a property of a collation definition a reader has to go look up. Long-term-project axis, and it also makes the MySQL arm read as the same idea rather than an unrelated trick.
  2. MySQL's 26 REPLACEs are verbose (~52 per $icontains predicate). Accepted: the alternatives are wrong rather than merely uglier (spelled out on the helper), the predicate was a full scan either way, and correctness that a reviewer can verify by reading beats brevity that needs a live server to trust.
  3. 'unknown' dialect keeps the old shape. GLOB is a syntax error and CAST(… AS BINARY) means something else outside the three modelled clients, so the old form is the only one that runs. Recorded as residue in the ledger and pinned in the matrix rather than left silent.
  4. service-analytics was not given a dialect seam. Measured: the package genuinely has no dialect input, and its compilers emit Postgres-shaped SQL where the ruled semantics already hold, so adding one would have been speculative surface for no behaviour change. The dependency is now the thing written down — like-pattern.ts says in as many words that the file is wrong the day these compilers emit for SQLite or MySQL, and the pin fails if the emitted shape stops being Postgres-shaped.

Out-of-scope findings


Generated by Claude Code

`$contains` 族与 `$icontains` 的大小写答案此前取决于底层数据库的 `LIKE`
语义,两个方向都是**过匹配**——返回了 filter 排除的行,在 ADR-0021 的 RLS
读作用域上是越权而非「宽松过滤」(#3948):

| | `$contains` 族(契约要求大小写敏感,#4706 Q2=A) | `$icontains`(只折叠 ASCII,#4706 Q1=A) |
|:--|:--|:--|
| SQLite / turso / sqlite-wasm | ❌ `LIKE` 自带 ASCII 折叠 | ✅ `lower()` 只折 ASCII |
| Postgres | ✅ `LIKE` 恰好大小写精确 | ❌ `LOWER()` 折全 Unicode |
| MySQL | ❌ 随 collation | ❌ `LOWER()` 折全 Unicode |

横着读:**每个方言恰好在另一个方言犯错的那一半上是对的**——这就是两半都
无法从单一后端上被发现的原因。

下译改为按方言选构造,仍然只有一个发射点(转义与折叠是同一条代码路径,
未转义的通配符是 P0 —— #5567):

- **SQLite 族 → `GLOB`**。`LIKE` 的 ASCII 折叠无法按语句关闭
  (`PRAGMA case_sensitive_like` 是连接级全局开关),实测
  `CAST(col AS BLOB) LIKE ?` 一行都不匹配。`GLOB` 大小写精确,并自带转义类
  (`*` / `?` / `[` 写作自闭合字符类,因为 SQLite 语法不给 `GLOB` 任何
  `ESCAPE` 子句)。
- **Postgres → `LIKE` 不变**,只把折叠从 `LOWER()` 换成显式 `translate()`;
  live PG 16 实测 `LOWER('CAFÉ')` 就是 `'café'`。
- **MySQL → `CAST(… AS BINARY)` 上的 `LIKE`**,比较按字节,collation 不再
  参与;折叠同样按字节做,因 UTF-8 自同步故恰为 ASCII-only。
- 其余 client 保留改动前的 `LIKE`/`LOWER()` 形状,并记为残留而非静默。

turso 的 remote transport 自带一份编译器,同批移动;两个 transport 由新的
`turso-local-remote-text-parity.test.ts` 用共享 `FILTER_TEXT_CASES` 钉在同
一组行上。driver-sql / -sqlite-wasm / -turso 三格的 `FILTER_TEXT_CASES`
DEBT 随之清偿;driver-memory / driver-mongodb 属 #5499 冻结族,如实留 DEBT
并改指新填的后继单 #6682。

Fixes #6518

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AYvVzTaCWDCC32e9Le9zXn
@vercel

vercel Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectstack Ignored Ignored Aug 8, 2026 1:25pm

Request Review

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 3 package(s): @objectstack/driver-sql, @objectstack/driver-turso, @objectstack/service-analytics.

17 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:

  • content/docs/api/data-api.mdx (via @objectstack/service-analytics)
  • content/docs/api/index.mdx (via @objectstack/service-analytics)
  • content/docs/data-modeling/drivers.mdx (via @objectstack/driver-sql, @objectstack/driver-turso)
  • content/docs/deployment/cli.mdx (via @objectstack/driver-turso)
  • content/docs/deployment/environment-variables.mdx (via @objectstack/driver-turso)
  • content/docs/deployment/self-hosting.mdx (via @objectstack/driver-turso)
  • content/docs/getting-started/glossary.mdx (via @objectstack/driver-sql, @objectstack/driver-turso)
  • content/docs/kernel/services-checklist.mdx (via @objectstack/driver-sql, @objectstack/service-analytics)
  • content/docs/permissions/sharing-rules.mdx (via @objectstack/service-analytics)
  • content/docs/plugins/anatomy.mdx (via @objectstack/driver-sql)
  • content/docs/plugins/packages.mdx (via @objectstack/driver-sql, @objectstack/driver-turso, @objectstack/service-analytics)
  • content/docs/protocol/kernel/index.mdx (via @objectstack/driver-sql)
  • content/docs/protocol/kernel/lifecycle.mdx (via @objectstack/driver-sql)
  • content/docs/protocol/objectql/query-syntax.mdx (via @objectstack/driver-sql)
  • content/docs/releases/implementation-status.mdx (via @objectstack/driver-sql, @objectstack/service-analytics)
  • content/docs/releases/v17.mdx (via @objectstack/service-analytics)
  • content/docs/releases/v9.mdx (via @objectstack/service-analytics)

Advisory only. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs origin/main → pass the list as args.docs.

@github-actions github-actions Bot added documentation Improvements or additions to documentation tests tooling labels Aug 8, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review August 8, 2026 13:48
@os-zhuang
os-zhuang added this pull request to the merge queue Aug 8, 2026
Merged via the queue into main with commit 3172831 Aug 8, 2026
25 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-6518-contains-case-folding branch August 8, 2026 14:21
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…rds instead of a tracker number (stage 6) (objectstack-ai#21593)

Part of objectstack-ai#20749
Clause-②: no

Stage 6 of the `domain:spec` lane's share of the runtime-string
burn-down (ruling `5902360492`, form D): class (c), the case notes and
names of the eight shared conformance modules in `packages/spec/src`,
with the two test seams that bind their text. Every rewritten note or
name now states in words what the cited decision was, or drops a
citation its sentence already explained. Text only.

## What changed

- **58 messages / 68 tracker ids / 40 distinct cards** in eight modules:
`contracts/metadata-service-roundtrip-conformance.ts` and, in `data/`,
`aggregation-conformance.ts`, `filter-comparand-type-conformance.ts`,
`filter-logic-conformance.ts`, `filter-text-conformance.ts`,
`filter-text-operator-declared-type.ts`, `temporal-conformance.ts`,
`value-roundtrip-conformance.ts`. Fifty-two are `note` / `why` texts and
six are case names.
- **The selector seam**
(`packages/lint/src/validate-empty-combinators.test.ts:275`): selects
the same four empty-combinator cases by a phrase the rewritten notes
carry instead of `objectstack-ai#5322` (A3 below).
- **The name-pin seam**
(`packages/services/service-analytics/src/__tests__/icontains-dialect-sql.test.ts:369`):
pins the renamed infix `icontains` case verbatim, the same strength (A4
below).
- One `@objectstack/spec` **patch** changeset, `Clause-②: no`: the
conformance tables ship in the package's `dist` (measured: the new note
text is in `dist/data/index.mjs`; the two test files ship nowhere, since
`@objectstack/lint` and `@objectstack/service-analytics` publish `dist`
only and neither dist carries the seam text, with the package's own
symbols as the positive control).
- No generated artifact moves (`check:generated` green; the tables are
values behind annotated types, so the API surface is unchanged).

## Census at the base (A1)

Stage 3's instrument (`census.cjs`, byte-identical copy, md5
`e5fe562290fcd1ac392bd560cb86d861`) at base `cc645f2385`: class (c) is
**58 messages / 68 ids in 8 files, 40 distinct cards**, exactly stage
3's count (the `[c-SELECTOR]` 4 / 7 and `[c-NAMEPIN]` 1 / 1 rows
included). Under the ~60-card bar, so one stage. Lines are the base's.

| file (under `packages/spec/src`) | line:id | messages / ids | field |
consumer |
|:--|:--|--:|:--|:--|
| `contracts/metadata-service-roundtrip-conformance.ts` | 194:objectstack-ai#6725 ·
202:objectstack-ai#6725 · 280:objectstack-ai#7378 · 296:objectstack-ai#7378 · 304:objectstack-ai#7378 | 5 / 5 | `why` | none
prints it: both runners title a row by its `id`; the text is a reader's
note in the shared table |
| `data/aggregation-conformance.ts` | 342:objectstack-ai#6409 · 398:objectstack-ai#11065,objectstack-ai#11151 ·
407:objectstack-ai#11065 · 417:objectstack-ai#11152 419:objectstack-ai#11249 · 535/550/561:objectstack-ai#15546 · 577/596:objectstack-ai#6401
| 9 / 11 | `note` | the assertion message in the driver-memory,
driver-sql, driver-turso, driver-sqlite-wasm, objectql and
mongodb-translation suites |
| `data/filter-comparand-type-conformance.ts` | 153:objectstack-ai#7956 · 160:objectstack-ai#7872 ·
272/282/289:objectstack-ai#19757 (names) · 178:objectstack-ai#5234 · 191:objectstack-ai#6050 (notes) | 7 / 7 | 5
`name`, 2 `note` | names are test titles in five driver suites and in
`filter-save-door-face-parity.test.ts`; notes are assertion messages |
| `data/filter-logic-conformance.ts` | 339/362:objectstack-ai#3774 · 420:objectstack-ai#5322 ·
426:objectstack-ai#5322,objectstack-ai#5134 · 432/438:objectstack-ai#5322,objectstack-ai#5297 · 470:objectstack-ai#5298 · 476:objectstack-ai#5146 ·
503/509:objectstack-ai#5298,objectstack-ai#13356 · 539:objectstack-ai#5299,objectstack-ai#5962 · 561/567/573/579/595:objectstack-ai#20444 | 16
/ 22 | `note` | the assertion message in the eleven filter-logic
harnesses; **the one selector**:
`validate-empty-combinators.test.ts:275` picks the four `objectstack-ai#5322` notes |
| `data/filter-text-conformance.ts` | 300:objectstack-ai#8934 (name) · 309:objectstack-ai#8934 ·
349:objectstack-ai#6518,objectstack-ai#6682 · 428:objectstack-ai#4706 · 436:objectstack-ai#5710,objectstack-ai#6993 · 452:objectstack-ai#5240 | 6 / 8 | 1
`name`, 5 `note` | names are test titles in the text-conformance suites;
**the one name pin**: `icontains-dialect-sql.test.ts:369`; notes are
assertion messages |
| `data/filter-text-operator-declared-type.ts` | 392:objectstack-ai#8296 · 553:objectstack-ai#8371 ·
554:objectstack-ai#8296 | 3 / 3 | `note` | the assertion message in
`engine-text-operator-declared-type-door.test.ts` |
| `data/temporal-conformance.ts` | 211:objectstack-ai#3773 · 215/216:objectstack-ai#3777 ·
220:objectstack-ai#20600 (row `why`) · 270:objectstack-ai#3777 · 393:objectstack-ai#3773 · 448/457:objectstack-ai#1874 ·
549:objectstack-ai#3994 (case `note`) | 9 / 9 | 4 `why`, 5 `note` | a row `why` is
seeded as DATA into each harness's `why` string column (never filtered
on); a case `note` is an assertion message |
| `data/value-roundtrip-conformance.ts` | 213:objectstack-ai#11535 · 225/226:objectstack-ai#11782 |
3 / 3 | `note` | printed in the TEST TITLE `round-trips NAME (NOTE)` in
five driver suites |

No non-test code reads any of these texts (every `.note` / `.why` read
outside a test is another table's: `RETIRED_FILTER_OPERATORS`, the
driver-conformance ledger).

## Delivered (A2): each site, the decision as read, the new words

Each cited card was read with its body and every comment; the decision
column names the record (comment id, or the landing record where the
card carries none). Line = the base line of the edit anchor. "Old → new"
shows only the words that changed.

| file:line | ids | decision as read | old → new |
|:--|:--|:--|:--|
| `contracts/metadata-service-roundtrip-conformance.ts:194` | objectstack-ai#6725 |
objectstack-ai#6725: card answers 404 here; landing record: changesets 1507ba3 /
bbee302 (objectql and spec CHANGELOGs):
MetadataFacade.register('object') wrote into a map none of its own
object reads consulted | objectstack-ai#6725 would have failed → that catches an
object write landing in a store none of the object reads consult — the
hole a shipped implementation once fell through |
| `contracts/metadata-service-roundtrip-conformance.ts:202` | objectstack-ai#6725 |
objectstack-ai#6725: card answers 404 here; landing record: changesets 1507ba3 /
bbee302 (objectql and spec CHANGELOGs):
MetadataFacade.register('object') wrote into a map none of its own
object reads consulted | produced objectstack-ai#6725 → let an object write land in
the generic store while every object read looked elsewhere |
| `contracts/metadata-service-roundtrip-conformance.ts:280` | objectstack-ai#7378 |
objectstack-ai#7378: maintainer ruling 5261734580 (2026-08-12): row 1 refuse a
name/data.name disagreement, row 2 one answer converged with
check:meta-type-normalized, row 3 refuse non-object data | objectstack-ai#7378,
maintainer 2026-08-12, row 1 → maintainer 2026-08-12, row 1 of the
round-trip ruling |
| `contracts/metadata-service-roundtrip-conformance.ts:296` | objectstack-ai#7378 |
objectstack-ai#7378: maintainer ruling 5261734580 (2026-08-12): row 1 refuse a
name/data.name disagreement, row 2 one answer converged with
check:meta-type-normalized, row 3 refuse non-object data | objectstack-ai#7378,
maintainer 2026-08-12, row 2 → maintainer 2026-08-12, row 2 of the
round-trip ruling |
| `contracts/metadata-service-roundtrip-conformance.ts:304` | objectstack-ai#7378 |
objectstack-ai#7378: maintainer ruling 5261734580 (2026-08-12): row 1 refuse a
name/data.name disagreement, row 2 one answer converged with
check:meta-type-normalized, row 3 refuse non-object data | objectstack-ai#7378,
maintainer 2026-08-12, row 3 → maintainer 2026-08-12, row 3 of the
round-trip ruling |
| `data/aggregation-conformance.ts:342` | objectstack-ai#6409 | objectstack-ai#6409: card body,
executing the objectstack-ai#6188 split ruling: count_distinct stays declared and is
enforced as distinct non-null values on the SQL family | objectstack-ai#6409: →
count_distinct was kept and enforced on every face, as distinct non-null
values: |
| `data/aggregation-conformance.ts:398` | objectstack-ai#11065 objectstack-ai#11151 | objectstack-ai#11065: card
answers 404 here; landing record: driver-memory changeset 2095040:
avg/sum over a boolean answer the same numbers as every SQL face (a
boolean is worth 1 or 0) · objectstack-ai#11151: PR objectstack-ai#12819 (triage 5446817173):
driver-mongodb's boolean aggregand answers the ruled values too |
objectstack-ai#11065/objectstack-ai#11151: an arithmetic accumulator that drops booleans answers its
identity 0 here — a plausible number, which → A boolean aggregand is
worth 1 or 0 on every face — driver-memory and then driver-mongodb were
both moved onto that answer: an arithmetic accumulator that drops
booleans answers its identity 0 here — a plausible number, which |
| `data/aggregation-conformance.ts:407` | objectstack-ai#11065 | objectstack-ai#11065: card answers
404 here; landing record: driver-memory changeset 2095040: avg/sum over
a boolean answer the same numbers as every SQL face (a boolean is worth
1 or 0) | objectstack-ai#11065: the rate-over-a-flag-column shape (an SLA-violation
rate, a win rate). → The rate-over-a-flag-column shape (an SLA-violation
rate, a win rate) that driver-memory answered null for until it counted
a boolean as 1 or 0. |
| `data/aggregation-conformance.ts:417` | objectstack-ai#11152 objectstack-ai#11249 | objectstack-ai#11152:
maintainer ruling 2026-08-28, option A (changeset f6fa22c in the driver
CHANGELOGs; decision request 5446817173): booleans aggregate as numbers,
min/max answer 0/1 · objectstack-ai#11249: ruling 5386670755 (false/true for min/max
over a boolean), superseded by objectstack-ai#11152's 2026-08-28 ruling | objectstack-ai#11152
ruling (2026-08-28): booleans aggregate as numbers with no per-aggregate
exception, so the order statistics answer 0/1 in the same domain sum/avg
answer in — not false/true (objectstack-ai#11249, superseded) → Ruled 2026-08-28:
booleans aggregate as numbers with no per-aggregate exception, so the
order statistics answer 0/1 in the same domain sum/avg answer in — not
the false/true an earlier ruling had chosen, which this one superseded |
| `data/aggregation-conformance.ts:535` | objectstack-ai#15546 | objectstack-ai#15546: ruling
5572006116 (option A): a non-empty group whose aggregand is NULL in
every row sums to 0 on every face | objectstack-ai#15546: → Ruled: a non-empty group
whose aggregand is NULL in every row sums to 0. |
| `data/aggregation-conformance.ts:550` | objectstack-ai#15546 | objectstack-ai#15546: ruling
5572006116 (option A): a non-empty group whose aggregand is NULL in
every row sums to 0 on every face | objectstack-ai#15546: the reachability control for
the → The reachability control for the all-NULL-sums-to-0 |
| `data/aggregation-conformance.ts:561` | objectstack-ai#15546 | objectstack-ai#15546: ruling
5572006116 (option A): a non-empty group whose aggregand is NULL in
every row sums to 0 on every face | objectstack-ai#15546: the partial-null control →
The partial-null control for the same ruling |
| `data/aggregation-conformance.ts:577` | objectstack-ai#6401 | objectstack-ai#6401: dev report
5229051388 (PR objectstack-ai#6849): GroupByNode.alias is enforced, not removed; every
SQL face projects the group under alias ?? field | objectstack-ai#6401: t → A
structured group node's `alias` names the projected group column on
every face — the SQL faces that ignored it were made to honour it. T |
| `data/aggregation-conformance.ts:596` | objectstack-ai#6401 | objectstack-ai#6401: dev report
5229051388 (PR objectstack-ai#6849): GroupByNode.alias is enforced, not removed; every
SQL face projects the group under alias ?? field | objectstack-ai#6401: the degenerate
alias. Its twin above → The degenerate alias, under the same every-face
`alias` rule. Its twin above |
| `data/filter-comparand-type-conformance.ts:153` | objectstack-ai#7956 | objectstack-ai#7956:
ACCEPT 5264821447: a measurement only; its control cell ({qty: {$eq:
100}}) returned the row on every driver, so the zeros were real answers
| objectstack-ai#7956 control cell → control cell of the cross-driver comparand-type
measurement |
| `data/filter-comparand-type-conformance.ts:160` | objectstack-ai#7872 | objectstack-ai#7872:
maintainer ruling 5265944890 and ACCEPT 5273103599 (PR objectstack-ai#8234): a shared
comparand-type door; a safe-range bigint narrows to its exact number,
beyond 2^53 is refused | (objectstack-ai#7872) → at the shared comparand door |
| `data/filter-comparand-type-conformance.ts:178` | objectstack-ai#5234 | objectstack-ai#5234:
ACCEPT 5217619370 (PR objectstack-ai#6296): a non-$field object member of $in/$nin and
an object LIKE comparand are refused; each member is judged on its own |
right (objectstack-ai#5234) → right, each judged like a scalar comparand |
| `data/filter-comparand-type-conformance.ts:191` | objectstack-ai#6050 | objectstack-ai#6050:
ruling B 5211349926: an undefined comparand is refused loudly; null
keeps its meaning as the null predicate | (objectstack-ai#6050's untouched half) — → —
the half left untouched when an undefined comparand was ruled a loud
refusal — so |
| `data/filter-comparand-type-conformance.ts:272` | objectstack-ai#19757 | objectstack-ai#19757:
ruling 5793368540 (letter 乙): an array in the implicit-equality slot is
refused at the shared face, for every driver at once | (objectstack-ai#19757) → at the
shared face |
| `data/filter-comparand-type-conformance.ts:282` | objectstack-ai#19757 | objectstack-ai#19757:
ruling 5793368540 (letter 乙): an array in the implicit-equality slot is
refused at the shared face, for every driver at once | (objectstack-ai#19757) → at the
shared face |
| `data/filter-comparand-type-conformance.ts:289` | objectstack-ai#19757 | objectstack-ai#19757:
ruling 5793368540 (letter 乙): an array in the implicit-equality slot is
refused at the shared face, for every driver at once | too (objectstack-ai#19757) →
too, at the shared face |
| `data/filter-logic-conformance.ts:339` | objectstack-ai#3774 | objectstack-ai#3774: defect:
driver-sql OR-ed a $or branch's own keys and operators; rule: everything
inside one filter object ANDs at every depth (card body) | objectstack-ai#3774:
compiled → A $or combines its branches, never the keys inside one: a
driver that OR-ed a branch's own keys compiled this |
| `data/filter-logic-conformance.ts:362` | objectstack-ai#3774 | objectstack-ai#3774: defect:
driver-sql OR-ed a $or branch's own keys and operators; rule: everything
inside one filter object ANDs at every depth (card body) | objectstack-ai#3774: a
single-key branch is miscompilable too — the operator map is looped with
the same → A single-key branch is miscompilable too — that driver looped
the operator map with the same OR |
| `data/filter-logic-conformance.ts:420` | objectstack-ai#5322 | objectstack-ai#5322: maintainer
ruling 5185589944: every face reduces an empty combinator to its boolean
identity ($and:[] all rows, $or:[] none, {} TRUE, $not:{} none), whole
tree | objectstack-ai#5322: a → Ruled: every face reduces an empty combinator to its
boolean identity. A |
| `data/filter-logic-conformance.ts:426` | objectstack-ai#5322 objectstack-ai#5134 | objectstack-ai#5322:
maintainer ruling 5185589944: every face reduces an empty combinator to
its boolean identity ($and:[] all rows, $or:[] none, {} TRUE, $not:{}
none), whole tree · objectstack-ai#5134: defect repaired by PR objectstack-ai#5243 (ACCEPT
5178806144): driver-sql dropped an empty $and/$or group instead of
applying the boolean identity; empty $or and empty $not now compile to
FALSE | objectstack-ai#5322/objectstack-ai#5134: a disjunction of zero conditions matches nothing.
Fail-closed for an RLS scope — a disjunct list that loops to zero items
hides every row instead of exposing the table → Ruled: every face
reduces an empty combinator to its boolean identity. A disjunction of
zero conditions matches nothing. Fail-closed for an RLS scope — a
disjunct list that loops to zero items hides every row instead of
exposing the table, as a SQL lowering that dropped the empty group once
did |
| `data/filter-logic-conformance.ts:432` | objectstack-ai#5322 objectstack-ai#5297 | objectstack-ai#5322:
maintainer ruling 5185589944: every face reduces an empty combinator to
its boolean identity ($and:[] all rows, $or:[] none, {} TRUE, $not:{}
none), whole tree · objectstack-ai#5297: dispatch 5184116664: read-scope-sql's { $not:
{} } compiled to nothing (an RLS scope with no WHERE) and dropped a {}
disjunct; both aligned to the boolean identity | objectstack-ai#5322: collapsing to
the surviving branches instead compiles `a = x` — a silently NARROWED
scope (objectstack-ai#5297) → Ruled: every face reduces an empty combinator to its
boolean identity, so `{}` is a TRUE disjunct. Collapsing to the
surviving branches instead compiles `a = x` — a silently NARROWED scope,
the answer the RLS read-scope compiler gave until it was aligned |
| `data/filter-logic-conformance.ts:438` | objectstack-ai#5322 objectstack-ai#5297 | objectstack-ai#5322:
maintainer ruling 5185589944: every face reduces an empty combinator to
its boolean identity ($and:[] all rows, $or:[] none, {} TRUE, $not:{}
none), whole tree · objectstack-ai#5297: dispatch 5184116664: read-scope-sql's { $not:
{} } compiled to nothing (an RLS scope with no WHERE) and dropped a {}
disjunct; both aligned to the boolean identity | objectstack-ai#5322: emitting nothing
for it runs the query UNSCOPED — on an RLS lowering that is a permission
bypass (objectstack-ai#5297) → Ruled: every face reduces an empty combinator to its
boolean identity, so NOT of `{}` is FALSE. Emitting nothing for it runs
the query UNSCOPED — on an RLS lowering that is a permission bypass,
which the read-scope compiler was until it compiled this to an
always-false clause |
| `data/filter-logic-conformance.ts:470` | objectstack-ai#5298 | objectstack-ai#5298: ruling
5202271174 (option A, confirmed 5204511921 item 4): $ne / $nin /
$notContains are NULL-safe on the non-negated path, a no-value row is
included | objectstack-ai#5298 → Ruled NULL-safe on every face |
| `data/filter-logic-conformance.ts:476` | objectstack-ai#5146 | objectstack-ai#5146: maintainer
ruling 5181102507: $not is NULL-safe on every driver; a row with no
value does not satisfy the negated condition, so the negation returns it
| objectstack-ai#5146: the same ruling reached through the combinator → The same
NULL-safe ruling reached through the combinator, where it was first made
for `$not` itself |
| `data/filter-logic-conformance.ts:503` | objectstack-ai#5298 | objectstack-ai#5298: ruling
5202271174 (option A, confirmed 5204511921 item 4): $ne / $nin /
$notContains are NULL-safe on the non-negated path, a no-value row is
included | objectstack-ai#5298 option A → Ruled NULL-safe |
| `data/filter-logic-conformance.ts:503` | objectstack-ai#13356 | objectstack-ai#13356: PR objectstack-ai#13356:
driver-memory's reference matcher realigned so a no-value row satisfies
$nin / $notContains | PR objectstack-ai#13356 → it was realigned to the ruling |
| `data/filter-logic-conformance.ts:509` | objectstack-ai#5298 | objectstack-ai#5298: ruling
5202271174 (option A, confirmed 5204511921 item 4): $ne / $nin /
$notContains are NULL-safe on the non-negated path, a no-value row is
included | objectstack-ai#5298 option A → Ruled NULL-safe |
| `data/filter-logic-conformance.ts:509` | objectstack-ai#13356 | objectstack-ai#13356: PR objectstack-ai#13356:
driver-memory's reference matcher realigned so a no-value row satisfies
$nin / $notContains | PR objectstack-ai#13356 → it was realigned to the ruling |
| `data/filter-logic-conformance.ts:539` | objectstack-ai#5299 objectstack-ai#5962 | objectstack-ai#5299: ruling
5219858433 item 2, kept by 5238865560: $exists means has a value
(non-null), never key-presence, since SQL cannot tell a missing key from
null · objectstack-ai#5962: PR objectstack-ai#5962 (ACCEPT 5205011148 on objectstack-ai#5298): the NULL-safe
operators and the $exists has-a-value reading shipped | objectstack-ai#5299 cell 2 /
objectstack-ai#5962: `$exists` means HAS A VALUE, never key-presence → Ruled:
`$exists` means HAS A VALUE, never key-presence, because SQL cannot tell
a missing key from a stored null |
| `data/filter-logic-conformance.ts:561` | objectstack-ai#20444 | objectstack-ai#20444: card body
executing ruling A on objectstack-ai#20399 (5865693155): every compile surface answers
$empty by the field's declared type; $empty: false is the exact
complement | objectstack-ai#20444: null is empty on every row of the ruled table →
Every face answers `$empty` by the field's declared type, and null is
empty under every type's arm |
| `data/filter-logic-conformance.ts:567` | objectstack-ai#20444 | objectstack-ai#20444: card body
executing ruling A on objectstack-ai#20399 (5865693155): every compile surface answers
$empty by the field's declared type; $empty: false is the exact
complement | objectstack-ai#20444: the exact complement → `$empty: false` is the exact
complement by ruling |
| `data/filter-logic-conformance.ts:573` | objectstack-ai#20444 | objectstack-ai#20444: card body
executing ruling A on objectstack-ai#20399 (5865693155): every compile surface answers
$empty by the field's declared type; $empty: false is the exact
complement | objectstack-ai#20444: `$empty` spells its NULL case out, so it → The
ruled `$empty` arms spell their NULL case out, so `$empty` |
| `data/filter-logic-conformance.ts:579` | objectstack-ai#20444 | objectstack-ai#20444: card body
executing ruling A on objectstack-ai#20399 (5865693155): every compile surface answers
$empty by the field's declared type; $empty: false is the exact
complement | objectstack-ai#20444: → Under the same declared-type arms, |
| `data/filter-logic-conformance.ts:595` | objectstack-ai#20444 | objectstack-ai#20444: card body
executing ruling A on objectstack-ai#20399 (5865693155): every compile surface answers
$empty by the field's declared type; $empty: false is the exact
complement | objectstack-ai#20444: a face that lowers `$empty` → A face that lowers
`$empty` to the field's declared-type arm |
| `data/filter-text-conformance.ts:300` | objectstack-ai#8934 | objectstack-ai#8934: ruling A
5305708745: icontains joins the view and infix vocabularies;
ilike/$ilike and icontains/$icontains are never aliased onto each other
| objectstack-ai#8934 → ruled never an alias of ilike |
| `data/filter-text-conformance.ts:309` | objectstack-ai#8934 | objectstack-ai#8934: ruling A
5305708745: icontains joins the view and infix vocabularies;
ilike/$ilike and icontains/$icontains are never aliased onto each other
| capability (objectstack-ai#8934) → capability, ruled when `icontains` joined the
view and infix vocabularies |
| `data/filter-text-conformance.ts:349` | objectstack-ai#6518 objectstack-ai#6682 | objectstack-ai#6518: ACCEPT
5226386725 (PR objectstack-ai#6706): the SQL family's $contains family is case-exact
(GLOB on the SQLite dialects), per objectstack-ai#4706 Q2 = A · objectstack-ai#6682: ACCEPT
5251849449 and the memory half: the hardcoded case-folding flag came off
driver-mongodb and driver-memory, the last two folding faces | match.
SQLite's LIKE folds ASCII — the defect objectstack-ai#6518 replaced with GLOB on the
SQLite dialects; a JS backend's equivalent is a RegExp carrying the `i`
flag, which objectstack-ai#6682 took off → match: the `$contains` family is
case-sensitive on every backend, by ruling. SQLite's LIKE folds ASCII —
the defect the SQL family replaced with GLOB on the SQLite dialects; a
JS backend's equivalent is a RegExp carrying the `i` flag, since taken
off driver-memory and driver-mongodb, |
| `data/filter-text-conformance.ts:428` | objectstack-ai#4706 | objectstack-ai#4706: ruling B
5199214776: $regex retired under ADR-0049 with a loud refusal naming the
replacement, $icontains added | objectstack-ai#4706 retired the operator over →
`$regex` was retired over, by ruling, with a loud refusal naming
`$icontains` |
| `data/filter-text-conformance.ts:436` | objectstack-ai#5710 objectstack-ai#6993 | objectstack-ai#5710: ACCEPT
5201171068 (PR objectstack-ai#5812): plugin-auth's adapter stopped emitting bare
$regex for better-auth contains, unblocking the $regex retirement ·
objectstack-ai#6993: ACCEPT 5231388316 (PR objectstack-ai#7054): the expired status claims were
re-measured by executing each face (2026-08) and rewritten | objectstack-ai#5710
flipped that producer before any backend enrolled this case (re-verified
2026-08, objectstack-ai#6993 → That producer was moved off `$regex` before any backend
enrolled this case (re-verified 2026-08 by executing each face |
| `data/filter-text-conformance.ts:452` | objectstack-ai#5240 | objectstack-ai#5240: maintainer
ruling 5181107825: { field: {} } is refused loudly (INVALID_FILTER) on
every backend, not read as TRUE or FALSE | objectstack-ai#5240 refused `{ field: {} }`
over → for which a field with zero operators, `{ field: {} }`, is
refused by ruling |
| `data/filter-text-operator-declared-type.ts:392` | objectstack-ai#8296 | objectstack-ai#8296:
standing ruling recorded in 5277439872: a where on a formula field is
refused (INVALID_FIELD 400) because no driver materialises the column |
objectstack-ai#8296 door refuses EVERY formula filter with INVALID_FIELD 400 whatever
the `returnType` → unmaterializable-field door refuses EVERY formula
filter with INVALID_FIELD 400 whatever the `returnType` (no driver
stores a formula column) |
| `data/filter-text-operator-declared-type.ts:553` | objectstack-ai#8371 | objectstack-ai#8371:
ruling 5300373151 (option 2): a type-directed verdict on the dotted head
segment; the structured/JSON head stays deliberately unjudged | unjudged
there, objectstack-ai#8371 → left unjudged there, by ruling |
| `data/filter-text-operator-declared-type.ts:554` | objectstack-ai#8296 | objectstack-ai#8296:
standing ruling recorded in 5277439872: a where on a formula field is
refused (INVALID_FIELD 400) because no driver materialises the column |
objectstack-ai#8296 → the unmaterializable-field door |
| `data/temporal-conformance.ts:211` | objectstack-ai#3773 | objectstack-ai#3773: defect: SQLite
read an epoch-ms Field.datetime as a Julian day so date buckets were
NULL; repaired by storage-aware bucketing (card body; cross-update
5099832227 on objectstack-ai#3777) | (objectstack-ai#3773) → as SQLite bucketing once did |
| `data/temporal-conformance.ts:215` | objectstack-ai#3777 | objectstack-ai#3777: defect: a bare-day
$lte on a datetime column stopped at midnight and dropped the rest of
the final day; the bound keeps the whole day (card body; 5099832227) |
by the objectstack-ai#3777 bug → when a bare-day upper bound stopped at midnight |
| `data/temporal-conformance.ts:216` | objectstack-ai#3777 | objectstack-ai#3777: defect: a bare-day
$lte on a datetime column stopped at midnight and dropped the rest of
the final day; the bound keeps the whole day (card body; 5099832227) |
by the objectstack-ai#3777 bug → when a bare-day upper bound stopped at midnight |
| `data/temporal-conformance.ts:220` | objectstack-ai#20600 | objectstack-ai#20600: triage direction
5886142901, landed PR objectstack-ai#20643: the whole-day bound past 9999-12-31 is
unbounded above and the drivers compile none | (objectstack-ai#20600) → and none is
compiled |
| `data/temporal-conformance.ts:270` | objectstack-ai#3777 | objectstack-ai#3777: defect: a bare-day
$lte on a datetime column stopped at midnight and dropped the rest of
the final day; the bound keeps the whole day (card body; 5099832227) |
objectstack-ai#3777: the default dashboard window → The default dashboard window,
whose bare-day $lte keeps the whole final day |
| `data/temporal-conformance.ts:393` | objectstack-ai#3773 | objectstack-ai#3773: defect: SQLite
read an epoch-ms Field.datetime as a Julian day so date buckets were
NULL; repaired by storage-aware bucketing (card body; cross-update
5099832227 on objectstack-ai#3777) | objectstack-ai#3773 famil → family of the SQLite bucketing
defect that read an epoch-ms datetime as a Julian da |
| `data/temporal-conformance.ts:448` | objectstack-ai#1874 | objectstack-ai#1874: the templates'
date-equality family that surfaced ADR-0053, whose Phase 1 stores
Field.date as its calendar day (ADR-0053 Surfaced-by line; card body, no
comments) | objectstack-ai#1874: `date == today` silently matched nothing while dates
were stored as instants. E → `date == today` silently matched nothing
while dates were stored as instants; ADR-0053 stores a date as its
calendar day, so e |
| `data/temporal-conformance.ts:457` | objectstack-ai#1874 | objectstack-ai#1874: the templates'
date-equality family that surfaced ADR-0053, whose Phase 1 stores
Field.date as its calendar day (ADR-0053 Surfaced-by line; card body, no
comments) | from the objectstack-ai#1874 family → that surfaced ADR-0053 |
| `data/temporal-conformance.ts:549` | objectstack-ai#3994 | objectstack-ai#3994: Field.time takes
one canonical HH:MM:SS[.fff] text form on write, filter and read
(ADR-0053 addendum D-C1..D-C3; driver-sql changeset 9774b78) | objectstack-ai#3994,
measured → Measured before `Field.time` took one canonical
`HH:MM:SS[.fff]` text form |
| `data/value-roundtrip-conformance.ts:213` | objectstack-ai#11535 | objectstack-ai#11535: defect: a
single-to-multi-value change kept the old text column on Postgres, so
arrays came back as stringified literals; the drift detector now reports
the base-type mismatch (claim 5395496220) | objectstack-ai#11535's exact shape → the
exact shape a single-value column kept for a multi-value field corrupted
|
| `data/value-roundtrip-conformance.ts:225` | objectstack-ai#11782 | objectstack-ai#11782: landing
5406878917 (PR objectstack-ai#12019): a declared boolean answers JSON booleans on
every read door and dialect; MySQL's tinyint 1/0 leaked before | objectstack-ai#11782
read this back as 1 on MySQL → MySQL read this back as 1 until every
read door presented a declared boolean as true/false |
| `data/value-roundtrip-conformance.ts:226` | objectstack-ai#11782 | objectstack-ai#11782: landing
5406878917 (PR objectstack-ai#12019): a declared boolean answers JSON booleans on
every read door and dialect; MySQL's tinyint 1/0 leaked before | objectstack-ai#11782
→ that MySQL read-back |
| `lint: validate-empty-combinators.test.ts:275` | objectstack-ai#5322 | objectstack-ai#5322:
maintainer ruling 5185589944: every face reduces an empty combinator to
its boolean identity ($and:[] all rows, $or:[] none, {} TRUE, $not:{}
none), whole tree | objectstack-ai#5322 → every face reduces an empty combinator to
its boolean identity |
| `analytics: icontains-dialect-sql.test.ts:369` | objectstack-ai#8934 | objectstack-ai#8934: ruling
A 5305708745: icontains joins the view and infix vocabularies;
ilike/$ilike and icontains/$icontains are never aliased onto each other
| objectstack-ai#8934 → ruled never an alias of ilike |

## The selector seam (A3)

The filter over `FILTER_LOGIC_CASES` now tests `(c.note ??
'').includes('every face reduces an empty combinator to its boolean
identity')` where it tested `.includes('objectstack-ai#5322')`. The phrase is the
objectstack-ai#5322 ruling in words, and the four rewritten notes open with it.
Measured with an AST extractor over the table (`name` and `note` of all
36 cases, then the selector applied exactly as the test applies it):

- base `cc645f2385` with `objectstack-ai#5322` → **4 of 36**: `$not of {} is FALSE —
NOT TRUE`, `a {} branch is a TRUE disjunct and absorbs its $or`, `empty
$and is TRUE — the AND identity`, `empty $or is FALSE — the OR
identity`.
- head with the phrase → **the same 4 of 36**, the same names.
- cross: the old selector on the head selects 0 (so the move is
required), the new phrase on the base selects 0.
- control outside the set: the broader word `Ruled` selects 8, the four
plus `$exists true selects exactly the valued rows`, `$ne …`, `$nin …`
and `$notContains returns the rows with no value`; none of those four is
picked by the phrase.
- mutation control on a scratch copy (anchor hit 1, replacement present
1, anchor left 0): dropping the phrase from the empty-`$or` note leaves
3, which the test's own guard (`toEqual` on the four sorted names,
`toBe(4)`) turns red.

The test asserts exactly what it asserted before (the names pin, the
count, and the row-set wording per case); only the selector moved.
`validate-empty-combinators.test.ts` ran green: 21 of 21, the three
identity cases included.

## The name pin (A4)

`'icontains (the infix/view spelling, objectstack-ai#8934) lowers to $icontains — %
stays a LITERAL through that door too'` becomes `'icontains (the
infix/view spelling, ruled never an alias of ilike) lowers to $icontains
— % stays a LITERAL through that door too'` in `FILTER_TEXT_CASES`, and
the `toEqual` pin in `icontains-dialect-sql.test.ts:369` moves to the
new string verbatim. No other consumer keys on that name (searched the
whole tree for the old name and its fragments: the source and the pin
only); the other consumers use it as a test title. The file ran green:
16 of 16. The five renamed `FILTER_COMPARAND_TYPE_CASES` names have no
pin anywhere; they are test titles only.

## Text only (A5)

Stage 3's `skeleton.cjs` (one line changed: the TypeScript load path to
this worktree), TypeScript 6.0.3: leg 1 an AST skeleton with every
string's text masked (a `+` chain's adjacent string operands read as one
string), leg 2 the text of every string group, each changed group
required to carry a tracker id before and none after, every other group
byte-identical. Base copies vs the committed files, **10 of 10 SAME on
both legs, exit 0**:

| file | tokens | string groups | changed |
|:--|--:|--:|--:|
| `metadata-service-roundtrip-conformance.ts` | 1352 | 157 | 5 |
| `aggregation-conformance.ts` | 1268 | 133 | 9 |
| `filter-comparand-type-conformance.ts` | 1309 | 107 | 7 |
| `filter-logic-conformance.ts` | 1682 | 223 | 16 |
| `filter-text-conformance.ts` | 1093 | 137 | 6 |
| `filter-text-operator-declared-type.ts` | 1821 | 114 | 3 |
| `temporal-conformance.ts` | 2041 | 374 | 9 |
| `value-roundtrip-conformance.ts` | 1197 | 175 | 3 |
| `validate-empty-combinators.test.ts` | 2684 | 129 | 1 |
| `icontains-dialect-sql.test.ts` | 4345 | 217 | 1 |

Parse diagnostics 0 / 0 throughout. 58 changed groups in the eight
modules, one per seam. No case's filter, input, expected rows, verdict,
code, operator, dialect, order or count moves. Edits were applied by a
script whose 62 anchors each had to hit exactly once before any write,
and were read back from disk after it (each anchor gone, each
replacement present once). Census after the edit: class (c) **0 / 0**;
non-test 118 → 60 messages, 297 → 229 ids; test strings unchanged (1804
/ 1920).

## Pins, titles and quotes (A6)

- Pins moved: the two seams above, nothing else. Every old note and name
was searched across the tree in 32-character windows: no test asserts a
changed phrase; the remaining hits are code comments and other modules'
own prose that share a phrase with an unchanged part of a note.
- Titles that follow the text: the comparand-type and text-case names
(test titles in the driver suites), and the `VALUE_ROUNDTRIP_CASES`
notes (`round-trips NAME (NOTE)`). No skip list, ledger or snapshot
names any of those titles.
- Quotes: no `content/docs/**` page and no `skills/**` file quotes a
changed note or name.
- `TEMPORAL_ROWS[].why` is seeded into a `string` column (a `varchar` on
Postgres and MySQL), so the four rewritten `why` texts stay short (164
characters at most).

## Gates

Head `1427993cc3` (the merge of `origin/main` `901e7cf13a`; that merge
touched no file under `packages/spec`, `packages/lint` or
`packages/services/service-analytics`, 0 diff lines there).

- `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack
--commands`: 11 paths vs merge base `901e7cf13`, 153 changed lines; **88
derived commands, 88 exit 0** on `1427993cc3`, each exit code written
from `$?` before any pipe; `--ran`: "✓ dispatch-gates --ran: 88 derived
famil(ies) accounted for — 88 run, 0 NOT-MEASURED".
- `pnpm --filter @objectstack/spec build` exit 0 (the dependency closure
is empty: no workspace dependencies); `check:generated`: "✓ All 15
generated artifacts are up to date".
- `pnpm --filter @objectstack/spec test`: "Test Files 606 passed (606) /
Tests 17952 passed | 1 todo (17953)"; `typecheck` exit 0
("check:test-typecheck: OK — … 52 file(s) / 246 error(s) / 135 pinned
signature(s) held").
- `pnpm --filter @objectstack/lint test`: "Test Files 119 passed (119) /
Tests 5620 passed (5620)"; `typecheck` exit 0.
- `pnpm --filter @objectstack/service-analytics test`: "Test Files 175
passed (175) / Tests 4152 passed | 253 skipped (4405)"; `typecheck` exit
0; `icontains-dialect-sql.test.ts` alone 16 of 16.
- `pnpm check:doc-authoring` (self-test, then the run): "✓ doc authoring
guard: 17337 customer-facing string(s) across 1251 spec sources clean"
and "sibling-package prose ids hold the baseline — 0 pinned site(s) … no
growth, no burn-down unrecorded". `pnpm check:nul-bytes`:
"check-nul-bytes: OK (scanned 9947 text file(s) …; no raw ASCII control
bytes)".
- Changeset gates: `check-changeset-no-major.mjs`,
`check-empty-changeset.mjs`, `check-adr-0087-registration.mjs` (each
`--base origin/main`) exit 0; with this body as the `--event` payload,
see the report.
- ESLint, a proven narrowing: `eslint --no-inline-config --format json`
over the 10 changed TS files reads 10 files, 0 errors, 0 warnings; the
population is ESLint's own (`calculateConfigForFile` returns a config
for each, `isPathIgnored` false); invariance: `eslint.config.mjs`
enables no type-aware linting (`parserOptions.project` /
`projectService` null for all 10), so a string-text edit cannot move an
untouched file's verdict. Repo-wide `pnpm lint` is CI's.
- Spec `test:repo` was not run locally: none of its 51 files names a
changed module or table.

## Acceptance notes

- **Two cited cards answer 404** in this repository (objectstack-ai#6725 and objectstack-ai#11065;
the same numbers in objectui are unrelated PRs). Their decisions were
read from the shipped landing records instead: the objectql and spec
CHANGELOG entries `1507ba3` / `bbee302`
(`MetadataFacade.register('object')` wrote into a map none of its own
object reads consulted) and the driver-memory entry `2095040` (a boolean
aggregand counts as 1 or 0, as on every SQL face). Neither decision read
as unclear.
- Two decisions live in shipped records rather than card comments:
objectstack-ai#11152's 2026-08-28 ruling (option A, booleans aggregate as numbers,
superseding objectstack-ai#11249) is recorded in changeset `f6fa22c` and matches the
source comment above those cases; objectstack-ai#3994's in ADR-0053's D-C addendum.
- Left for later stages, untouched here: the seam files' own test titles
(`(objectstack-ai#5322/objectstack-ai#5659)`, `[objectstack-ai#16028]`) and every other test string; code comments
(including the section comments beside these cases); class (f) in
`api/error-code-ledger.zod.ts` and `kernel/public-auth-features.ts`;
`migrations/registry.ts`.
- Not governed: no `.claude/**`, `skills/**`, ADR, NORTH-STAR or
AGENTS.md path.

## Line budget

153 changed lines (+90 / -63) over 11 files vs merge base `901e7cf13`
(dispatch-gates), under the 5000 human-merge threshold: the eight
modules, the two test files (one line each) and the changeset. No
generated file, no governed surface.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01YDt3PzwfrkuFzUBF89WPmM)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/xl tests tooling

Projects

None yet

2 participants