Skip to content

Commit 79ab186

Browse files
committed
docs: adjudicate the twelve citations the encapsulation close created, and close the dometrain staleness
#3468 closed the ADR 0018 encapsulation floor by writing a convention CHANGELOG entry for each fix, and every entry quotes the path it removed. That manufactured twelve new instances of the shape the pass was sweeping. The sweep record listed them and stated they were fine; nothing ruled on them one at a time, so the arithmetic (16 fixed and 35 kept, not 16 and 23) rested on an assumption. Ruled individually against the test #3475 wrote into ADR 0018's amendment. All twelve are keep-correct and none is edited. Each sits in a dated entry whose claim is what a named file contained on that date, quoted as the string the entry removed, with the replacing invocation named in the same sentence, so no reader is sent to any of them for a rule. Three sub-rulings the class needed are recorded, because a bare "all twelve are evidence" is the assumption this was meant to replace. The three config-cascade rows quote plugin-relative forms that resolve against nothing, and the entry says so: clause 3 does not fire where the entry asserts non-resolution, since making them resolve would delete the finding. The other nine resolve on disk from their own implied base, checked one at a time. None carries a line or step pin, the part the amendment says rots first. Re-derived with a second expression over the fix commit's added lines rather than a scan of the files at rest. Same twelve, plus one the roster excludes on purpose: plugins/review/reference/topic-docs.md, a plugin-level non-skill tree that belongs to the pass the amendment routes it to, and a declared keep rather than a quoted removal. Separately, MIGRATION-PLAYBOOK's dometrain record was reviewed at 0.1.0 and the manifest reads 0.2.7, eleven releases later. Whether any of them added a trust surface is what the re-trigger clause turns on and no record answers it, which takes a review rather than a reading. The staleness is now stated in place with the re-review logged as owed. The review itself is deliberately not performed here. Refs #3468, refs #3475, refs #3460. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UmrZGdp1dgbZuPCy7tcRJo
1 parent b293df8 commit 79ab186

2 files changed

Lines changed: 53 additions & 14 deletions

File tree

docs/MIGRATION-PLAYBOOK.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -942,6 +942,13 @@ with the layered gates above; 6 first-party.
942942

943943
Reviewed at `0.1.0`; a version bump adding a new trust surface re-triggers this review.
944944

945+
**This record is stale, and a re-review is owed (recorded 2026-08-28).** The plugin ships `0.2.7`.
946+
Eleven releases landed between the reviewed version and the shipping one, and no record says
947+
whether any of them added a trust surface, which is the condition the re-trigger above turns on.
948+
Answering it takes a review, so it cannot be settled either way by reading this page. Until that
949+
review runs, the ACCEPT below describes `0.1.0` and states nothing about what a consumer installs
950+
today. The re-review was not performed when this note was written; it is logged as owed.
951+
945952
- **Code execution (1).** None — no hooks; `sync/scripts/update.sh` is not wired to any event
946953
and is not model-reachable: `sync/SKILL.md` carries `disable-model-invocation: true`, so it
947954
runs only on a maintainer's explicit `/dometrain:sync` invocation.

docs/specs/extract-ssot-sweep-2026-08-28.md

Lines changed: 46 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -339,8 +339,11 @@ Beyond the predecessor's 13. Each was resolved against the real files and refuse
339339

340340
## Open remainder after the encapsulation close
341341

342-
Recorded, not fixed. A later pass adjudicates these; this section exists so it does not have to
343-
re-find them. Stamped 2026-08-28 and subject to the decay rule at the top of this file.
342+
Recorded so a later pass does not have to re-find them. Stamped 2026-08-28 and subject to the decay
343+
rule at the top of this file. Two of the three below are now closed in place, each marked at its own
344+
heading: the twelve created citations are adjudicated and needed no edit, and the `dometrain`
345+
staleness is written into the playbook with the re-review logged as owed. The tree-shaped exclusions
346+
stay open.
344347

345348
### Twelve citations the encapsulation close created and never rostered
346349

@@ -370,14 +373,36 @@ tree at the fix commit's parent.** Before that commit, exactly three lines in
370373
kept set. Every one of the twelve above was written by the fix commit itself, so **the arithmetic is
371374
16 fixed and 35 kept, not 16 and 23**, and the changelog-evidence class is fifteen rather than three.
372375

373-
**All twelve are keep-correct** under the test now written into
376+
**Adjudicated 2026-08-28: all twelve are keep-correct, and none was edited.** Each was ruled
377+
individually against the test now written into
374378
[ADR 0018](../adr/0018-treat-the-plugin-as-the-encapsulation-boundary-for-skill-citation.md)'s
375-
amendment: each is a dated changelog entry whose whole claim is what a named file contained on that
376-
date. Nothing here needs an edit. What is missing is the judgment, and a pass that re-derives this
377-
shape finds twelve rows nobody ruled on and has to adjudicate them from scratch to learn they were
378-
fine. The general lesson is worth more than the twelve rows: **a sweep that documents each fix by
379-
quoting the citation it removed manufactures new instances of the shape it is sweeping,** so its own
380-
output has to be swept before the count is closed.
379+
amendment, not accepted as a class. Every one sits inside a dated entry whose claim is what a named
380+
file contained on that date, and each is quoted as the string the entry removed, with the public
381+
invocation that replaced it named in the same sentence. No reader is sent to any of them to get a
382+
rule, so none is an address. Three sub-rulings the class needed:
383+
384+
- The three `config-cascade` rows quote plugin-relative forms (`skills/audit/scripts/detect.sh`,
385+
`skills/setup/SKILL.md`, `run-e2e/context/e2e-config.md`) that resolve against nothing from that
386+
file, and the entry says so in the same sentence. Clause 3 does not fire on them: the entry
387+
asserts their non-resolution rather than offering them as addresses, so requiring them to resolve
388+
would delete the finding.
389+
- The other nine all resolve on disk today from the base their own form implies, checked one at a
390+
time, so clause 3 is satisfied where it does apply.
391+
- None of the twelve carries a line pin or a step pin, which is the part the amendment says rots
392+
first. Nothing to drop.
393+
394+
The judgment is what was missing, and it is now recorded so a pass that re-derives this shape reads
395+
a ruling instead of buying twelve fresh ones. The general lesson is worth more than the twelve rows:
396+
**a sweep that documents each fix by quoting the citation it removed manufactures new instances of
397+
the shape it is sweeping,** so its own output has to be swept before the count is closed.
398+
399+
Re-derivation for this adjudication used a different expression from the one that built the table
400+
above (added lines of the fix commit, matched on a path-shaped token, rather than a scan of the
401+
files at rest) and returned the same twelve. It also returned one citation the table excludes on
402+
purpose: `plugins/review/reference/topic-docs.md`, added by the same commit at
403+
`detector-findings` 2.8.1. That is a plugin-level non-skill tree, outside this roster and inside the
404+
one ADR 0018's amendment routes to its own pass, and the entry naming it declares it a keep rather
405+
than quoting it as removed.
381406

382407
**The pass writing this section did the same thing, deliberately, three more times.**
383408
`docs/conventions/plugin-data-report-keying/CHANGELOG.md` 1.0.1 quotes the three pins it dropped, so
@@ -408,11 +433,18 @@ expression, and per this file's own recall-limits discipline none of these numbe
408433

409434
### A stale record found in passing, not an ADR matter
410435

411-
`docs/MIGRATION-PLAYBOOK.md:943` carries the `dometrain` security-review record: "Reviewed at
412-
`0.1.0`; a version bump adding a new trust surface re-triggers this review." **The plugin's manifest
413-
reads `0.2.7` today** (`plugins/dometrain/.claude-plugin/plugin.json`, confirmed against
414-
`origin/main`). The trigger has had every opportunity to fire across those bumps and the review was
415-
never re-run, so the record asserts a currency it does not have.
436+
`docs/MIGRATION-PLAYBOOK.md`'s "Review record — `dometrain` (ACCEPT, 2026-07-22)" carries the
437+
clause "Reviewed at `0.1.0`; a version bump adding a new trust surface re-triggers this review."
438+
**The plugin's manifest reads `0.2.7`** (`plugins/dometrain/.claude-plugin/plugin.json`, read from
439+
the working tree, not from the roster). Eleven releases landed in between and the review was never
440+
re-run, so the record asserts a currency it does not have.
441+
442+
**Closed 2026-08-28, as a record rather than as a review.** The playbook now states the staleness in
443+
place, directly under the re-trigger clause: the reviewed version, the shipping version, and the
444+
fact that whether any of the eleven added a trust surface is unadjudicated, which is the condition
445+
the clause turns on and the one thing that cannot be settled without running the review. The
446+
re-review is logged as owed and was deliberately not performed here. Whoever runs it replaces that
447+
note.
416448

417449
This is not a citation defect and does not belong to the encapsulation lane. It is logged here
418450
because the encapsulation pass kept that record's five file-and-frontmatter citations *on the

0 commit comments

Comments
 (0)