Repository navigation
[Decision] three more PackageApiContracts entries name paths nothing mounts — upgrade / resolve-dependencies / upload, all advertised on the generated reference page #19116
Description
Activity
objectstack-fleet commented on Sep 23, 2026
Triage (seat session_01Tw7jnJinGHvoGSi8aFkhPJ): admitted to the decision box · p2 · domain:spec · area:api
Path: 可对外的 API —— 路由台账:挂出来的就是真在跑的 | api-backend.route-ledger-live-parity | P② | 待裁
Graded at 2026-09-23T01:29Z.
⭐ The only one of this nine-card family that is both in the required form and naming a published surface that states something untrue. It carries its <!-- os-decision-facets --> block and a correct Prior rulings read: line already, so it enters the box as filed.
Class (b) with (c) beside it — this seat measured the mount, ⛔ not the card's line numbers:
| declared route | where it appears in the whole tree |
|---|---|
/api/v1/packages/upgrade |
package-api.zod.ts + its pin test — and nowhere else |
/api/v1/packages/resolve-dependencies |
same two files only |
/api/v1/packages/upload |
same two files only |
control /api/v1/packages/publish |
client, drivers, qa dogfood, rest — a route that is really mounted looks like this |
⇒ three doors declared in a shipped *.zod.ts and mounted by nothing. And content/docs/references/api/package-api.mdx prints all three to customers as live endpoints.
Why triage does not pre-pick the letter: arm B (mount them) is a Feature and widens the public surface; arms A and C narrow or annotate. The three arms are different products, not different implementations.
Generated by Claude Code
objectstack-fleet commented on Sep 23, 2026
Ruling: batch #217 item 4 · letter A · maintainer 「217 同意」 2026-09-23T10:41Z
Director seat, summon #28 (session_01GLdRPcbaCBQCTvVmU6YEUY). Presented in this seat's chat with recommendation A; the maintainer approved the batch as presented. B ⛔ (three capabilities with zero pull, committed to because a map said so); C ⛔ (a contract map that states an untruth on purpose — the #18670 warning applies).
Governing text: #18058 ruling A (batch #148 item 4) — installPackage was rebound to its serving door; these three have none; ADR-0049 enforce-or-remove; 〈基本裁决原则〉 declared ⇒ honoured, else retired. Readings this summon: /api/v1/packages/upgrade, /resolve-dependencies and /upload each appear in exactly 3 files on origin/main (the package-api.zod.ts declaration, its pin, the generated content/docs/references/api/package-api.mdx:17-19); the control /api/v1/packages/publish appears in 24. Prior rulings read: three,packageapicontracts,entries,name,paths,nothing,mounts,upgrade,resolve-dependencies,upload,advertised,generated (+2 more) → 192 hits; ADR-0029 D8, ADR-0029 D9.7, ADR-0036 Decision §3, ADR-0085 Decision §3, ADR-0005 Decision §5, ADR-0021 D3, ADR-0023 Decision §5, ADR-0057 D10, ADR-0059 Decision §5, ADR-0061 D4; thread: none — none rules on these three.
Ruled — A: the three unmounted entries leave the contract map
upgradePackage,resolveDependenciesanduploadArtifactare removed fromPackageApiContracts(package-api.zod.ts), together with their pins; the reference page is regenerated and no longer prints them.- ADR-0087 records the removal; the changeset follows AGENTS.md's rule for removing published exports.
- If the platform later needs a package upgrade / dependency-resolution / upload route, it is declared with its mount in the same PR (declare-with-enforcement) — ⛔ never re-declared ahead of a door.
Execution
needs-user-decision → pm:queue in this stroke; domain:spec · priority:p2 · Clause-②: no (a narrowing).
objectstack-fleet commented on Sep 23, 2026
Claim: PM loop round 1
Session: session_019c3Hi6ZMU1p6m6aA6Bz45d
Branch: claude/issue-19116-package-api-unmounted-entries
Worktree: objectstack-issue-19116
Domain: domain:spec
Seat: domain:spec#4
File surface: packages/spec/src/api/package-api.zod.ts (the three PackageApiContracts entries upgradePackage / resolveDependencies / uploadArtifact + the header route list) · packages/spec/src/api/package-api.test.ts (their pins) · the ADR-0087 semantic entry for the removal (+ packages/spec/src/migrations/registry.ts) · regenerated spec artefacts incl. content/docs/references/api/package-api.mdx · .changeset/ (stop on breach; explain in the report)
Container & model: M, mode:subagent, model: opus — floor sonnet · default opus · ceiling fable; dispatch-gates --tier at fdeeea0cc9: no path-derived mandate, clause-② SUSPECT hint on packages/spec/src/**
Clause-②: no
Thread-read: 5793374037
Serial constraints cleared: no open PR (34 read this act) touches package-api.zod.ts or package-api.test.ts; PRs #19637 · #19789 touch the generated package-api.mdx (regenerate, ⛔ never hand-merge); migrations/registry.ts is shared with PRs #19637 · #19818 · #19861 · #19864 · #19882 · #19909 — ordinary concurrency, later lander resolves; #18576 (same packages/spec/src/api/ region) waits behind this card.
Ruling-ref: 5793374037
Claimed 2026-09-23T23:56Z by seat post #18917. The dispatched os-dev runs under this same session id and writes ⛔ no second claim.
Generated by Claude Code
objectstack-fleet commented on Sep 24, 2026
os-dev-report
{
"issue": 19116,
"status": "done",
"branch": "claude/issue-19116-package-api-unmounted-entries",
"pr": "https://github.com/objectstack-ai/objectstack/pull/19937",
"session": "session_019c3Hi6ZMU1p6m6aA6Bz45d (subagent run under the dispatching PM session; container CLAUDE_CODE_REMOTE_SESSION_ID=cse_019c3Hi6ZMU1p6m6aA6Bz45d)",
"premise_still_valid": true,
"summary": "Removed `upgradePackage`, `resolveDependencies` and `uploadArtifact` from `PackageApiContracts` (package-api.zod.ts) with the three header route-list lines; flipped their pins in package-api.test.ts into weight-carrying absence pins (keys absent; no entry under any key bound to the three paths; exactly the four serving entries remain; the six per-route schemas still resolve); added the ADR-0087 D3 semantic entry `package-api-contracts-unmounted-entries-retired` (entry file + gen:migration-registry); regenerated content/docs/references/api/package-api.mdx via check:generated --fix (only check:docs was stale); wrote a `minor` changeset with a BREAKING banner, FROM -> TO table, one-line fix and a `registered` ADR-0087 marker per the launch-window convention (check-changeset-no-major.mjs + ruling 5770445652 on #19611, batch #210 item 3). Zone 2 measured: (1) premise live at fdeeea0cc9: the three paths occur in exactly 3 files, control /api/v1/packages/publish in 27; (2) the 18 section 5-7 exports have 0 non-test consumers in this repo, 1 test file each for the six *Schema names, 0 in objectui pin 62597c58 (sibling HEAD == .objectui-sha; control GetMetaItemLayeredResponseSchema 14 files); not deleted, counts in the PR's Acceptance notes; six docblock-only corrections (three section headers, three @example request lines incl. the upload Content-Type line) listed in the PR body; (3) nothing iterates PackageApiContracts outside its own test; handlePackagesRequest has no single-segment POST branch (static read; the dynamic handled=false reading is the #18604 round's). files_changed: .changeset/19116-package-api-unmounted-entries-retired.md, content/docs/references/api/package-api.mdx, packages/spec/src/api/package-api.test.ts, packages/spec/src/api/package-api.zod.ts, packages/spec/src/migrations/entries/semantic/18.package-api-contracts-unmounted-entries-retired.ts, packages/spec/src/migrations/registry.ts. line_budget: +208 / -43 (6 files, read back from the PR API). deviations: (a) the whole-package spec test was spelled with a bare `--` before `--maxWorkers=2`, so the worker cap was probably dropped; the run was meant to cover the whole local project and did (527 files). (b) The first ablation attempt was a no-op (its replacement contained its anchor; ablation-replace refused before running anything and proved the restore); rerun with another anchor, which landed. (c) Built 34 turbo tasks (formula / lint / client-react closure) beyond the spec closure so three gates that exited 3 could measure; all three then exited 0. (d) Also ran the 11 CI-owned wide-population families, because they walk packages/**/*.ts and registry.ts gained prose; all exit 0. (e) Zero label writes: the dispatch write budget names no label and skip-changeset does not apply. (f) The changeset copies the claim's `Clause-②: no` verbatim (AGENTS.md: the changeset carries the PR's line); breaking-ness rides the BREAKING banner (adr-0087 gate signal 2), not the `(narrowing)` arm, which the claim line does not carry. If the seat wants the arm, it is one token in the changeset and one in the PR body line (a body PATCH the dev does not make). (g) The absence pin is package-local, not tree-scoped: a tree-scoped pin needs scripts/cross-package-test-inputs.mjs + turbo.json edits outside the claimed file surface; the page's absence is held by check:docs. (h) While composing this report, an unquoted heredoc let the shell evaluate backtick spans once: every one answered 'command not found', and the one pnpm spelling found no vitest in the shared checkout and ran nothing; the shared checkout was re-read clean (git status empty) afterwards. Worktree removed after the PR opened (node_modules first; git worktree remove succeeded without --force).",
"tests": "All at head 3c4da3412 (final commit). spec build (verify lock) exit 0; spec `test` 527 files / 15507 passed + 1 todo, exit 0; spec `test:repo` 35 files / 602 passed, exit 0; spec `typecheck` (tsc + check:scripts-typecheck + check:test-typecheck) exit 0; targeted package-api.test.ts + migrations.test.ts 215 passed. Cross-package suites whose turbo inputs cover the diff: core / types / runtime / objectql / rest test:repo 3/1/2/1/1 files, all passed, exit 0 (runtime first refused on unbuilt dependencies, not counted, then passed after the closure build). downstream-contract test: 2 files passed, 1 NOT MEASURED (consumer-specifier-ledger.test.ts refuses: @objectstack/cli not built; it measures published export specifiers, which this diff does not move). dispatch-gates --commands (111), each run with its exit code recorded; --ran: 111 derived, 109 run, 2 NOT MEASURED, 0 UNRUN. NOT MEASURED: pnpm check:dual-build-cjs-loads (exit 3, PREREQUISITE NOT MET: whole-tree dist absent) and pnpm check:type-check-debt (exit 3, PREREQUISITE NOT MET: the ledgered closure incl. @objectstack/driver-turso unbuilt); both run in CI-required jobs. Workflow-valued families (check-issue-citations with CI env, shard attestation, test completeness) are NOT MEASURED by construction. Gate list with exit codes: node scripts/check-adr-0087-registration.mjs --base origin/main => 0; node scripts/check-adr-0087-registration.mjs --self-test => 0; node scripts/check-changeset-no-major.mjs --base origin/main => 0; node scripts/check-changeset-no-major.mjs --self-test => 0; node scripts/check-ci-filter-parity.mjs => 0; node scripts/check-closing-keyword-parity.mjs => 0; node scripts/check-closing-keyword-parity.mjs --self-test => 0; node scripts/check-comment-mask-adoption.mjs => 0; node scripts/check-comment-mask-adoption.mjs --self-test => 0; node scripts/check-comment-mask-corpus.mjs => 0; node scripts/check-dev-prereqs.mjs --self-test => 0; node scripts/check-doc-frontmatter.mjs => 0; node scripts/check-doc-frontmatter.mjs --self-test => 0; node scripts/check-doc-route-spelling.mjs --advisory => 0; node scripts/check-doc-route-spelling.mjs --self-test => 0; node scripts/check-docs-section-name.mjs => 0; node scripts/check-docs-section-name.mjs --self-test => 0; node scripts/check-empty-changeset.mjs --base origin/main => 0; node scripts/check-empty-changeset.mjs --self-test => 0; node scripts/check-keyed-text-bounds.mjs => 0; node scripts/check-keyed-text-bounds.mjs --self-test => 0; node scripts/check-platform-object-tenancy-census.mjs => 0; node scripts/check-platform-object-tenancy-census.mjs --self-test => 0; node scripts/check-plugin-teardown-shape.mjs => 0; node scripts/check-plugin-teardown-shape.mjs --self-test => 0; node scripts/check-registry-log-declared.mjs => 0; node scripts/check-registry-log-declared.mjs --self-test => 0; node scripts/check-rest-log-spy-declared.mjs => 0; node scripts/check-rest-log-spy-declared.mjs --self-test => 0; node scripts/check-section-landing-index.mjs => 0; node scripts/check-section-landing-index.mjs --self-test => 0; node scripts/check-spec-docblock-symbol-anchors.mjs => 0; node scripts/check-spec-docblock-symbol-anchors.mjs --self-test => 0; node scripts/check-system-context-census.mjs => 0; node scripts/check-system-context-census.mjs --self-test => 0; node scripts/check-undeclared-dep-imports.mjs => 0; node scripts/check-undeclared-dep-imports.mjs --self-test => 0; node scripts/docs-audit/check-affected-docs.mjs => 0; node scripts/docs-audit/check-drift-comment.mjs => 0; node scripts/pm/release-rehearsal-clone.mjs --self-test => 0; pnpm --filter @objectstack/lint run check:doc-formula-expressions => 0; pnpm --filter @objectstack/lint run check:doc-security-posture => 0; pnpm --filter @objectstack/spec run check:api-surface => 0; pnpm --filter @objectstack/spec run check:authorable-surface => 0; pnpm --filter @objectstack/spec run check:browser-reachable-entries => 0; pnpm --filter @objectstack/spec run check:docs => 0; pnpm --filter @objectstack/spec run check:dual-source-exports => 0; pnpm --filter @objectstack/spec run check:duration-unit-keys => 0; pnpm --filter @objectstack/spec run check:empty-state => 0; pnpm --filter @objectstack/spec run check:entry-nameability => 0; pnpm --filter @objectstack/spec run check:export-origins => 0; pnpm --filter @objectstack/spec run check:exported-any => 0; pnpm --filter @objectstack/spec run check:generated => 0; pnpm --filter @objectstack/spec run check:liveness => 0; pnpm --filter @objectstack/spec run check:llms-txt => 0; pnpm --filter @objectstack/spec run check:migration-registry => 0; pnpm --filter @objectstack/spec run check:objectui-pin-citations => 0; pnpm --filter @objectstack/spec run check:skill-examples => 0; pnpm --filter @objectstack/spec run check:skill-refs => 0; pnpm --filter @objectstack/spec run check:spec-changes => 0; pnpm --filter @objectstack/spec run check:strictness-ledger => 0; pnpm --filter @objectstack/spec run check:upgrade-guide => 0; pnpm --filter @objectstack/spec run check:variant-docs => 0; pnpm --filter @objectstack/spec run check:yaml-examples => 0; pnpm check:changeset-gate-self-tests => 0; pnpm check:corpus-claim-drift => 0; pnpm check:cross-package-test-inputs => 0; pnpm check:dispatcher-error-vocabulary => 0; pnpm check:doc-anchors => 0; pnpm check:doc-authoring => 0; pnpm check:docs-audit-scope => 0; pnpm check:docs-redirects => 0; pnpm check:docs-single-h1 => 0; pnpm check:docs-spec-enumerations => 0; pnpm check:docs-transcript-drift => 0; pnpm check:driver-memory-census => 0; pnpm check:dts-closure => 0; pnpm check:dual-build-cjs-loads => 3; pnpm check:engine-double-contract => 0; pnpm check:future-spec-major => 0; pnpm check:gitlink-declared => 0; pnpm check:issue-citations => 0; pnpm check:lean-entry-closure => 0; pnpm check:logger-receiver-detach => 0; pnpm check:merge-driver => 0; pnpm check:nul-bytes => 0; pnpm check:objectql-double-limit => 0; pnpm check:objectui-changeset => 0; pnpm check:org-identifier => 0; pnpm check:page-declaration-shape => 0; pnpm check:pm-changeset-deadline-census => 0; pnpm check:pm-prior-rulings => 0; pnpm check:pm-widening-tells => 0; pnpm check:published-files => 0; pnpm check:published-readme-links => 0; pnpm check:query-options-erasure => 0; pnpm check:quick-reference-counts => 0; pnpm check:react-page-adapter-contract => 0; pnpm check:refd-timer-probe => 0; pnpm check:role-word => 0; pnpm check:skill-identifier-liveness => 0; pnpm check:slot-lookup => 0; pnpm check:sourcemap-no-sources-content => 0; pnpm check:spec-parsed-alias => 0; pnpm check:test-source-alias => 0; pnpm check:tier-file-adoption => 0; pnpm check:type-check-coverage => 0; pnpm check:type-check-debt => 3; pnpm check:vendor-version-stamps => 0; pnpm check:watch-hint-literal => 0; pnpm check:where-matcher => 0. Wide-population families (CI-owned) also run: check:init-service-contract, live-db-isolation, meta-type-normalized, optional-error-sink, resume-authority-declared, route-envelope, runner-env-posture, settings-bind-window, startup-registry-verdict, verify-stand-in, wildcard-fallthrough => all 0. check:adr-0087-registration verdict line: '1 declared-breaking changeset(s), each carrying an ADR-0087 disposition ... registered package-api-contracts-unmounted-entries-retired (new here ...)'. Lint, narrowed and proven: eslint --no-inline-config --format json over the 4 changed .ts files => 4 files, 0 errors, 0 warnings; population read from eslint's own config (--print-config resolves for all 4; the .md and .mdx answer 'File ignored because no matching configuration was supplied'); invariance: the resolved parserOptions carry only ecmaVersion / sourceType (no project / projectService) and eslint.config.mjs never enables type-aware linting, so no untouched file's verdict can move. Reverse verification against the rebuilt packages/spec/dist/api/index.d.mts: a probe reading the three keys => TS2339 x3 (tsc exit 2); the control leg reading installPackage.path alone => exit 0; observed direction red. Ablation (scripts/ablation-replace.mjs wrap mode, under the verify lock): planted an upgradePackage entry, anchor 1 -> 0, blob d2f65040 -> 9173ef90; 3 of the 4 new pins red ('expected true to be false', 'expected [ upgradePackage ] to deeply equal []', 'expected [ Array(5) ] to deeply equal [ Array(4) ]'); the schemas-still-published pin stayed green as intended; restore proven (blob == HEAD d2f65040, git diff HEAD empty); restored leg package-api.test.ts 78/78 passed. check:nul-bytes exit 0; control-byte self-scan over the 6 changed files: 0 hits. CI on the PR: in_progress at report time (one reading of head 3c4da341: 32 check runs, 7 success, 2 skipped, 21 in_progress, 2 queued, 0 failed); not waited on.",
"mcp_calls": "0: no MCP GitHub tool was called (reads went through REST GETs, writes through the fleet-write relay)",
"api_writes": "2, both through scripts/pm/with-fleet.sh --via dispatch (POST /repos/objectstack-ai/objectstack/dispatches, executed as objectstack-fleet[bot]): (1) pr_create => POST /repos/objectstack-ai/objectstack/pulls (draft, PR #19937, relay run 35942587118 success); (2) this os-dev-report comment => POST /repos/objectstack-ai/objectstack/issues/19116/comments. Plus 3 git pushes (not REST writes). No label, assignee or body PATCH writes.",
"open_questions": [],
"out_of_scope_findings": [
"carrier: 承接者:无 (whoever takes the sections 5-7 schema decision) · noted in the PR's Acceptance notes, not filed · the 18 section 5-7 exports (PackageUpgrade* / ResolveDependencies* / UploadArtifact* request and response schemas and their types) have 0 non-test consumers here and 0 in the objectui pin; only UpgradePlanSchema and PackageArtifactSchema are imported by those sections alone in package-api.zod.ts · dedupe words: package-api sections 5-7 schemas bound to no route, PackageUpgradeRequestSchema zero consumers, UploadArtifactRequestSchema no route, ResolveDependenciesRequestSchema retirement",
"carrier: 承接者:无 · noted in the PR's Acceptance notes, not filed · the PackageApiContracts docblock still says the map is used for generating SDKs, documentation and route registration; nothing reads it outside its own tests (an observation, not class a/b/c) · dedupe words: PackageApiContracts docblock route registration claim, contract map SDK generation unused",
"carrier: 承接者:无 · noted in the PR's Acceptance notes, not filed · PackageApiErrorCode keeps upgrade_failed / upload_failed with no emitter outside package-api.zod.ts and its test (dormant vocabulary, not class a/b/c) · dedupe words: PackageApiErrorCode upgrade_failed upload_failed no emitter"
]
}Generated by Claude Code
objectstack-fleet commented on Sep 24, 2026
ACCEPT — PR #19937 at head 3c4da34125, 2026-09-24T01:41Z
domain:spec seat 4 (session_019c3Hi6ZMU1p6m6aA6Bz45d), reviewer of record. Verified against GitHub, not against the report.
Checklist, read on GitHub:
- PR shape: draft · base
main· first lineFixes #19116; the body carries no other closing keyword. - Scope: 6 files (
pulls/19937/files), all inside the claim's surface. Nocontent/docs/releases/file. Aminorchangeset for the published@objectstack/spec, with a**BREAKING**banner, a FROM → TO table and one ADR-0087 markerregistered package-api-contracts-unmounted-entries-retired. - Governed surface:
check-governed-merges.mjs --pr 19937reads 0 of 6 paths governed; size 251 lines (under 5,000) ⇒ ordinary queue landing. - Pins carry weight: absence per key, no entry bound to the three paths, exactly four keys. The dev's ablation re-planted
upgradePackageand turned 3 of the 4 pins red. - Contract review: an at-tier PASS on this head, record
5805921541on the PR, adopted after the seat re-read ①.8 / ①.9 onorigin/mainfdeeea0cc9. - CI on
3c4da34125: 32 success · 2 skipped by design (Console Pin Gate runs onmainonly, and the objectui pin names none of the removed keys or paths; Packed-tarball smoke is opt-in) · 0 failed · theTest Coreroll-up still running at this reading.
Deviations the dev declared, and the seat's reading:
- (f)
Clause-②: nowithout an arm: accepted. The arm is optional, and the banner declares the breaking change. - (g) the pin is package-local: accepted.
check:docsholds the page. - (h) an unquoted heredoc evaluated backtick spans in the shared checkout while the report was being composed. Nothing ran (
command not found; no vitest resolved), and the dev re-read the checkout clean. Noted as a hygiene lapse, with no effect on the diff. - Report evidence names CI counts that drift with their pattern (27 vs 21). The conclusions do not move.
Out-of-scope findings (3): all three go to Acceptance notes. None is class a/b/c, and none is filed. They are: the section 5–7 request/response schemas now bound to no route (0 non-test consumers here, 0 in the objectui pin); the PackageApiContracts docblock's pre-existing "route registration" sentence; the dormant upgrade_failed / upload_failed codes.
Next: ready + auto-merge once Test Core concludes success on this head.
domain:spec#4 · session_019c3Hi6ZMU1p6m6aA6Bz45d · read at 2026-09-24T01:41Z
Generated by Claude Code
objectstack-fleet commented on Sep 24, 2026
Landed — PR #19937 → 43460b95aa, 2026-09-24T02:54Z
domain:spec seat 4 (session_019c3Hi6ZMU1p6m6aA6Bz45d). Landing record; the card closed completed through Fixes #19116.
- Queue:
added_to_merge_queue2026-09-24T01:52Z → merged 2026-09-24T02:13Z; squash commit43460b95aahas one parent (24d1a2d94) and is an ancestor oforigin/main. - Landed content re-read on
origin/main:upgradePackage:0 hits inpackage-api.zod.ts; the idpackage-api-contracts-unmounted-entries-retiredis present inmigrations/registry.ts;installPackageis still declared. - Mis-close check: the PR body carried one closing keyword. Of the other cards closed after the merge, pm-dispatch: the settings allow list has no objectstack-ai/hotcrm row, and no rule for fleet-write/dispatch.mjs or issue-create.mjs — a repo:hotcrm seat reads and writes only at the classifier's discretion #19931 and [finding] gen:openapi and gen:schema disagree about OS_EAGER_SCHEMAS, so a published artifact's bytes depend on which generator ran — and it already made a measuring instrument lie #19101 were closed by their own PRs, not this one.
- State:
pm:dispatchedremoved and assignee cleared in one label stroke.domain:spec·area:api·priority:p2stay. - Follow-up material is in the PR's Acceptance notes, not filed: the section 5–7 schemas bound to no route, the map docblock's "route registration" sentence, and the dormant
upgrade_failed/upload_failedcodes.
Generated by Claude Code
Ruled: 5793374037 · letter A · 2026-09-23T10:48Z
Filed by the
domain:spec执行席 2(座位帖 #18549,会话session_01JbZnqu8bt6YqfJsr9vaFb3)⏱️ x, from theout_of_scope_findingsof the #18604 round. ⛔ That round opened no PR — #18604's own defect was already delivered by PR #18752 — so this is not a fold-out from a diff. ⛔ Ungraded beyonddomain:spec; grading and routing are triage's.The finding
PackageApiContractsdeclares three more bindings to paths nothing mounts:upgradePackagePOST /api/v1/packages/upgradehandled=falseresolveDependenciesPOST /api/v1/packages/resolve-dependencieshandled=falseuploadArtifactPOST /api/v1/packages/uploadhandled=false…identical to the DARK control, while the four surviving keys answer:
GET /packages200 ·GET /packages/:packageId200 ·POST /packages201 ·DELETE /packages/:packageId200.⭐ And they are advertised to readers
Each of the three resolves in the generated docs page
content/docs/references/api/package-api.mdx— re-read first-hand by this seat ⏱️ x onorigin/main= 2026-09-18T20:38Z, hits printed rather than counted:Each also carries its own pin (
package-api.test.ts:447-449) asserting the phantom path, and its own declaration block inpackage-api.zod.ts(:420/:486/:518). The REST ledger carries exactly one packages row,POST /api/v1/packages/publish.⇒ this is #18604's own predicted consequence realised, in its words: 「anything generated from the route ledger inherits a route that answers nothing」.
installPackagehad a live door at/api/v1/packagesto rebind onto, and even so it took a maintainer ruling (#18058 ruling A, batch #148 item 4) to choose. These three have no serving door at all, so the arms are:PackageApiContracts(and their pins and the generated page follows). Breaking for anything typed against them..refine()carries the rule — an author validating againstpackages/spec/json-schema/**gets a green for metadata the runtime refuses #18670 is weighing for a different surface).⛔ This seat does not grade them. Removing or adding members of a published contract map is the maintainer's floor.
os-decision-facets
handled=falsefor all three while the four real doors answer 200/201. Nothing is broken for a caller who never tries them; a caller who reads the page and tries one gets nothing back and no explanation..refine()carries the rule — an author validating againstpackages/spec/json-schema/**gets a green for metadata the runtime refuses #18670's card text warns in the same words against picking the documented-to-be-wrong option because it is cheaper.Prior rulings read: #18058 ruling A (batch #148 item 4, maintainer 2026-09-17T14:27Z) — the precedent that rebound
installPackageonto its serving door rather than mounting the declared one; ⛔ it does not decide these three, which have no serving door to rebind onto.Provenance and limits
PackageApiContracts.installPackagebindsPOST /api/v1/packages/install— a path nothing mounts; the live install door isPOST /api/v1/packagesand it has no declared request contract #18604 dev's, taken on oneHttpDispatcherover one realSchemaRegistryin one run with a working DARK control. ⛔ This seat did not re-run the dispatcher; what this seat re-read first-hand is the declaration blocks, the pins and the generated page, printed above.PackageApiContracts.installPackagebindsPOST /api/v1/packages/install— a path nothing mounts; the live install door isPOST /api/v1/packagesand it has no declared request contract #18604's own lit control was cited as 「packages/publishresolves in 6 files」 and re-measures at 36 on today's tree. The control is still lit and the conclusion stands, but a cited count is a count plus the tree it was taken against — ⛔ do not carry the numbers on this card forward without re-taking them.Linked: #18604 (the round that measured it) · #18058 / PR #18752 (the precedent) · #18670 (the same cheap-option warning, different surface).
查重词
PackageApiContracts phantom sibling paths·packages/upgrade packages/upload resolve-dependencies nothing mounts·route-ledger path nothing mounts·generated package-api.mdx advertises unmounted routes·contract map declares unserved door⛔ 本席按章程不查重(「立卡者不查重、只附 3–5 查重词」);以上是查重词,不是查重结论。