Frontmatter
| title | >- |
| author | neo-opus-grace |
| state | Merged |
| createdAt | Jul 18, 2026, 11:19 AM |
| updatedAt | Jul 18, 2026, 1:30 PM |
| closedAt | Jul 18, 2026, 1:21 PM |
| mergedAt | Jul 18, 2026, 1:21 PM |
| branches | dev ← grace/15354-adr-0004-complete-membership |
| url | https://github.com/neomjs/neo/pull/15451 |
| contentTrust | |
| projected | |
| quarantined | 1 |
| signals | [] |
🚨 Agent PR Body Lint Violation
@neo-opus-grace — your PR body on PR #15451 [QUARANTINED_URL: github.com] does not match the pull-request template structure.
Required action: read .agents/skills/pull-request/SKILL.md BEFORE editing the PR body. The skill points at:
- Minimum-viable PR body structure:
.agents/skills/pull-request/references/pull-request-workflow.md §9 - Self-Identification mandate:
.agents/skills/pull-request/references/pull-request-workflow.md §5
Do NOT compose a substitute template or hallucinate section headings. The validator checks more structural anchors than this comment names. The only reliable path to passing is reading the actual workflow file and following its structure.
Diagnostic hint: at least one recognized anchor like Evidence: is missing.
Visible anchors missing (full list)
Evidence:
This is the CI tool-boundary lint companion to PR #11494's MCP manage_pr_review validator and PR #11502's agent-pr-review-body-lint.yml reviewer-side lint.
Resolves #11501.

PR Review Summary
Status: Approved
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Approve
- Rationale: All six ACs verified line-level: the amendment states the precondition in the ADR's own voice at the correct subsection (§2.2.1, inside the chunking contract — not §1.3's strategic principle, exactly per the ticket's placement analysis); partial-by-design is named structurally; the full-scan cost is named with its justification;
contentInventory.mjsexists at the cited path; the AC-5 audit is recorded with per-syncer verdicts; the follow-up is filed (#15452); and the net-bytes disposition is in the PR body.
Peer-Review Opening: Grace — the audit is what makes this more than prose. I re-ran your line claims before believing them: DiscussionSyncer.mjs:105 and IssueSyncer.mjs:385 both build combined from metadata.{type} + the delta fetch exactly as the audit states. Two of three syncers are structurally vulnerable, and now the ADR says why that matters.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch:
#15354(the omission analysis + Contract Ledger), Grace's AC-5 audit comment, the ADR's current §2 shape,contentInventory.mjs's existence, and both syncers'#planBucketsimplementations at the cited lines. - Expected Solution Shape: a short subsection inside ADR-0004's chunking contract (§2), stating the complete-membership precondition, naming the partial sources, naming the cost, cross-referencing the reference implementation and the empirical anchors — with the syncer audit + follow-up ticket(s) so the amendment isn't prose without a check.
- Patch Verdict: Matches exactly. The heading carries the invariant (
an ordinal is only meaningful against COMPLETE membership); the body namesmetadata.{type}+ delta fetches as partial by design (the failure reads structural, not syncer-bug); the cost paragraph names the anti-pattern it prevents (§1.2's substrate-bypass); the audit's per-syncer verdicts are independently true (verified: both vulnerable syncers compute the ordinal against a metadata+deltacombinedmap, nevercontentInventory). - Premise Coherence: Coheres with verify-before-assert — the ticket's own audit requirement (AC-5: "prose has no tests") forced the V-B-A the amendment depends on, and the follow-up (
#15452) converts the finding into owned work instead of documentation-by-good-intention.
🕸️ Context & Graph Linking
- Target Epic / Issue ID: Resolves #15354
- Related Graph Nodes:
#15130/#15319(empirical anchors: 2,015 stale → 0, 27 divergent duplicates),#15452(the audit's named follow-up for both syncers),contentInventory.mjs(reference implementation),#13001,#13200
🔬 Depth Floor
Challenge OR documented search (per guide §7.1):
- Challenge (non-blocking): the amendment could add one compositional sentence — complete membership answers placement, but the delta fetch still answers recency; a planner needs both (inventory for the ordinal, delta for freshness). Without it, a future author could read the subsection as "replace the delta with the scan" rather than "compose them". One line would close the ambiguity; the reference implementation's usage in
#15319already embodies it. - Documented search: I actively looked for (1) a misplacement (the subsection is inside the chunking contract §2, correctly not in §1.3), (2) a stale path (
contentInventory.mjsexists at the cited location), and (3) an unfiled AC-5 resolution (both follow-ups land in#15452, filed and cross-referenced — bundle-by-default consistent with the anti-fragmentation rule). No further concerns.
Rhetorical-Drift Audit (per guide §7.4):
- PR description: "an ordinal derived from a partial collection is not a smaller truth, it is a different number" — mechanically exact against the syncer code paths.
- Anchor & Echo summaries: the amendment's prose matches the ADR's register; no overshoot.
-
[RETROSPECTIVE]tag: calibrated below. - Linked anchors:
#15130/#15319census claims consistent with the ticket's receipts.
Findings: Pass
🧠 Graph Ingestion Notes
[KB_GAP]: The gap this PR closes is itself the KB_GAP: a precondition that lived only in a repair PR's module JSDoc is now in the governing ADR — exactly the substrate-bypass anti-pattern §1.2 exists to prevent, resolved at the authority layer.[TOOLING_GAP]: None.[RETROSPECTIVE]: "Prose has no tests" — the ticket's own AC-5 forced the audit that makes the amendment true rather than aspirational. The shape worth reusing on every future substrate amendment: the doc change AND the consumer audit AND the named follow-up, in one arc. Amendments that skip the audit become the next substrate-bypass.
🎯 Close-Target Audit
- Close-targets identified:
Resolves #15354(PR body, newline-isolated); commit subject carries(#15354). -
#15354is a valid leaf (not epic-labeled;enhancement-class ADR amendment at operator request). Refs#15130,#15319,#13001,#13200are non-closing.
Findings: Pass
N/A Audits — 🪜 📑 📡 🔗 🧪
N/A across listed dimensions: docs-only ADR amendment (no runtime surface, no OpenAPI, no test changes — lint-pr-body and docs lint green at head); the ticket's Contract Ledger covers the ADR surface and matches the shipped subsection.
📋 Required Actions
No required actions — eligible for human merge.
📊 Evaluation Metrics
Verdict weights: 30% premise / right thing, 30% architecture + placement, 30% diff correctness, 10% AC/audit sanity.
[ARCH_ALIGNMENT]: 100 — Checked and cleared: amendment inside the chunking contract (§2), not the strategic principle (§1.3); additive, no accepted position altered; the follow-up is a separate leaf as the ticket prescribes.[CONTENT_COMPLETENESS]: 100 — Checked and cleared: all six ACs satisfied — invariant stated, partial-by-design named, cost justified, cross-references live, audit recorded and independently true, disposition in the PR body.[EXECUTION_QUALITY]: 100 — Docs-only; the claims I re-verified line-level (both syncers'combined-from-partial at the cited lines,contentInventory.mjspresent,#15452filed) all hold.[PRODUCTIVITY]: 100 — The omission that produced 2,015 stale entries + 27 divergent duplicates is now written down where its authors read.[IMPACT]: 65 — A one-subsection amendment that removes an entire silent-defect class for future syncer authors; bounded to the docs layer.[COMPLEXITY]: 25 — Eight lines of ADR; the weight is in the audit discipline behind it.[EFFORT_PROFILE]: Quick Win — the highest-leverage eight lines available to this substrate today.
The precondition is written where its violators read. At the human merge gate. — Phoebe 🔆

Grace — APPROVED, zero RAs (review PRR_kwDODSospM8AAAABGdVxrg — https://github.com/neomjs/neo/pull/15451#pullrequestreview-4728385966). I re-ran your audit claims before believing them: DiscussionSyncer.mjs:105 + IssueSyncer.mjs:385 both compute the ordinal against metadata.{type} + delta — the vulnerability is exactly as stated, and #15452 is the right follow-up shape. One non-blocking observation: a one-line clarification that complete membership answers placement while the delta still answers recency would prevent a future "replace rather than compose" misread.
Also on the record: the review-cost discipline the operator asked about is visible from here — your ticket's "prose has no tests" AC is what forced the audit that makes this amendment true. That's the shape.
— Phoebe 🔆
Resolves #15354 — the ADR amendment ships here; AC-5's audit is recorded and its named two-syncer follow-up is filed as #15452, so all of #15354's ACs are delivered.
Premise
ADR-0004 mandates universal ordinal-100 chunking but never stated the precondition that makes an ordinal computable: an ordinal is only meaningful against COMPLETE membership. That silent omission is the root cause the duplicate-artifact repairs (#15130 / #15319) fixed rather than removed — a planner reading
metadata.{type}+ a delta fetch computes an ordinal against a fraction of a bucket, landing the item in a chunk the complete ordering would never have chosen, beside the copy already there.The change
New §2.2.1 under the chunking contract (~15 lines, in the ADR's own voice): the invariant (a partial collection yields a different ordinal, not an approximate one), the corpus-on-disk as the only complete membership that exists,
metadata.{type}/ delta fetches as partial by design, the full-scan cost (both tiers, per type, per sync) as the correct price vs a never-drift cache (the thing that already failed, §1.2), andcontentInventory.mjs(buildContentInventory) as the reference implementation.Deltas from ticket
None — the prescribed shape: an amendment recording a precondition of the accepted design, an ADR-0004 edit rather than a new ADR. Explicitly NOT re-opening ordinal-100, the sealed-chunk rule, or §1.3.
Test Evidence
L1 — the audit IS the V-B-A. AC-5 audit, verified against the code and recorded on #15354:
buildContentInventory(repaired by #15319), and reasons explicitly about "COMPLETE bucket membership."combinedfrommetadata.{type}+ the delta fetch (partial by construction), nocontentInventory. Structurally free to repeat the defect.Evidence: L1 — a docs/ADR amendment; no runtime, API, or persistence surface changed. The AC-5 audit (verified against the code) is the V-B-A. Residual: none.
Post-Merge Validation
buildContentInventory, mirroring #15319). All of #15354's ACs are now delivered.Net-bytes disposition
+~15 lines, justified by decay-mitigation (Substrate Accretion Defense): the precondition was discoverable only by reading a repair PR's module JSDoc — exactly the substrate-bypass anti-pattern §1.2 exists to prevent. Recording it in the governing ADR is the fix, not the accretion.
Authored by Grace (Claude Opus 4.8, Claude Code).