You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] Three more producers still write bracketed openers that restate their own declared code — the #16245 family beyond its two named files #19709
Filing gate: ① defect. Class (b) — the 2026-08-29 maintainer ruling is a declared contract («error is HUMAN LANGUAGE, code is the MACHINE TOKEN, and a prefix is removed because the same fact already rides the code axis»), and these producers violate it exactly as the 38 sites #16245 just retired did.
Filed by the domain:spec execution seat (session_013RDBh5DqXd2xnLwvHLgLFr) from the #16245 dev's out-of-scope findings. It ⛔ correctly did not take them: the dispatch said stop on breach and triage warned against opportunistic expansion on that card.
The carriers, in the order a fixer should take them
① packages/metadata-protocol/src/runtime-authoring-gate.ts — writes [invalid_metadata] in front of its own declared code = 'INVALID_METADATA' / status = 422. ⭐ Same package, third producer, and it reaches dist/index.js, so the bytes publish. The #16245 dev named this the obvious next increment; it meets the bounded in-place-fix bar and is the cheapest of the three.
② packages/rest/src/rest-server.ts — raises its own [invalid_request] opener.
③ packages/runtime/src/domains/packages.ts — raises its own [writable_package_required] opener.
⇒ the idiom is repo-wide well beyond the two files #16245 was scoped to.
What #16245 established that this card inherits, ⛔ so it is not re-derived
Reachability:withoutDeclaredCodePrefix strips a prefix only when the message opens with the declared code followed by a colon. A bracketed lowercase tag matches neither the casing nor the separator, so it is ⛔ never stripped and reaches the caller in error.message.
No consumer parses the tag. The only consumers found anywhere are STRIPPERS — @object-ui/react's extractWriteErrorMessage and two plugin-detail call sites remove a leading bracketed prefix before showing the sentence. They cannot break on its absence: the regex simply matches nothing.
Clause-②: yes applies by the same reasoning — this changes published output bytes.
⚠️ Two hard-won cautions from that round, which this one will meet too
Untouched in #16245 and to be left alone here: the path [zod code] locators inside a validation headline, and the [rule] locators the author-time gate composes. Neither restates a declared code — each names WHICH finding, a fact the envelope carries nowhere else. The [Protocol] / [SysMetadataRepository] logger prefixes are likewise not this family.
Splitting
⚠️ ① is one package and one bounded edit; ② and ③ are different packages and different lanes. Triage may well want this as more than one card — ⛔ this seat does not split or route, it reports the family with its boundaries.
Blocked-by: #16245 — the pin and the precedent land there first.
Filing gate: ① defect. Class (b) — the 2026-08-29 maintainer ruling is a declared contract («
erroris HUMAN LANGUAGE,codeis the MACHINE TOKEN, and a prefix is removed because the same fact already rides thecodeaxis»), and these producers violate it exactly as the 38 sites #16245 just retired did.Filed by the
domain:specexecution seat (session_013RDBh5DqXd2xnLwvHLgLFr) from the #16245 dev's out-of-scope findings. It ⛔ correctly did not take them: the dispatch said stop on breach and triage warned against opportunistic expansion on that card.The carriers, in the order a fixer should take them
①
packages/metadata-protocol/src/runtime-authoring-gate.ts— writes[invalid_metadata]in front of its own declaredcode = 'INVALID_METADATA'/status = 422. ⭐ Same package, third producer, and it reachesdist/index.js, so the bytes publish. The #16245 dev named this the obvious next increment; it meets the bounded in-place-fix bar and is the cheapest of the three.②
packages/rest/src/rest-server.ts— raises its own[invalid_request]opener.③
packages/runtime/src/domains/packages.ts— raises its own[writable_package_required]opener.⇒ the idiom is repo-wide well beyond the two files #16245 was scoped to.
What #16245 established that this card inherits, ⛔ so it is not re-derived
withoutDeclaredCodePrefixstrips a prefix only when the message opens with the declared code followed by a colon. A bracketed lowercase tag matches neither the casing nor the separator, so it is ⛔ never stripped and reaches the caller inerror.message.@object-ui/react'sextractWriteErrorMessageand twoplugin-detailcall sites remove a leading bracketed prefix before showing the sentence. They cannot break on its absence: the regex simply matches nothing.Clause-②: yesapplies by the same reasoning — this changes published output bytes.console.warninterpolating onlyerr.message) lost its only machine-readable token when the opener went, and the fix belonged at the PRODUCER's log site — printing the declared code — ⛔ never re-adding the opener. Check every carrier for this shape before removing anything.objectqlandcliconsumers surfaced on SUCCESSIVE runs because the first shard stopped at the first failure and printed «@objectstack/cliwas scheduled but never reached». ⇒ scan the tree for assertions on the removed bytes rather than following CI.Two vocabularies that are ⛔ NOT this family
Untouched in #16245 and to be left alone here: the
path [zod code]locators inside a validation headline, and the[rule]locators the author-time gate composes. Neither restates a declared code — each names WHICH finding, a fact the envelope carries nowhere else. The[Protocol]/[SysMetadataRepository]logger prefixes are likewise not this family.Splitting
Blocked-by: #16245— the pin and the precedent land there first.Dedupe words:
runtime-authoring-gate bracketed opener invalid_metadata·rest-server packages door bracketed refusal restates code·bracketed opener family repo-wide beyond 16245Generated by Claude Code