You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 4d221c0
Browse filesBrowse the repository at this point in the historyBrowse files
fix(lint,spec): packagesOf refuses packages: null too, and lists its stamp under @objectstack/lint's ledger key
Rework round 1. Ruling A on #19926 (5805260775): `null` is malformed,
everywhere. `packages/lint`'s site census (#20206, ruling A on #15293) put
`null` out of scope with a pointer to #19926, but #19926's own claim fenced
`packages/lint` out as this card's surface -- the lint leg had no owner.
`packagesOf` (object-graph.ts) now treats only `undefined` as absent;
`null` falls to the same INVALID_ARTIFACT_PACKAGES refusal as `{}`/`0`/`'x'`/
a keyed object. The message names `null` as itself rather than `typeof`'s
`'object'`, matching the type label PR #20228 uses in
packages/core/src/artifact-packages.ts. Every `null` pin flips from a
silence control to a refusal assertion, at `packagesOf` directly and at
each of the three public functions its four (now five, with
validate-mapping-target-fields.ts) call sites sit behind. `undefined`
(absent) and a well-formed array stay green controls.
CI fix: `check:error-code-provenance` (job "Lint & Repo Gates", step 120)
was red on the prior head -- `packages/lint` stamps the registered code
`INVALID_ARTIFACT_PACKAGES` (object-graph.ts's `err.code = ...`) without
being listed under its own owner key in `ERROR_CODE_LEDGER`. Fixed the way
the gate prescribes: a new `'@objectstack/lint'` row in
packages/spec/src/api/error-code-ledger.zod.ts, with a comment recording
the wire path (door: 'none' -- packages/lint's rules are pure
`(stack) => Finding[]` functions called from `os validate`/`os lint`/
`os build`, never through an HTTP boundary). No code minted or duplicated;
the existing registered code is reused, provenance is merely now recorded
under a second owner (precedent: 3f9e2ea, "list plugin-security's
class-field error codes under its own ledger key").
Two changesets: `@objectstack/lint: minor` (Clause-②: no (narrowing) --
unchanged from round 1) for the behavior change, and a new
`@objectstack/spec: minor` (Clause-②: yes) for the ledger row -- a new
per-package face on a published payload, modelled on the 3f9e2ea
precedent's own spec-only changeset. The PR-level declaration becomes
`Clause-②: yes (narrowing)`, carrying both facts.
Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QcAS3qiYYZNezaxZxaUdMV
`ERROR_CODE_LEDGER['@objectstack/lint']` now lists `INVALID_ARTIFACT_PACKAGES`, the code `packages/lint`'s `packagesOf` reader stamps for a malformed `stack.packages` (#20206) — required by `check:error-code-provenance`, which refuses a registered code stamped by a package whose own owner key does not list it.
6
+
7
+
Clause-②: yes
8
+
9
+
Provenance, not identity: the code was already registered under `@objectstack/core` (`resolveArtifactPackageOrder`, the producer `packagesOf` deliberately mirrors rather than mints a new code for), so the `ErrorCode` union, the wire, and every other package's rows are unchanged. What widens is the per-package face a consumer reads from `ERROR_CODE_LEDGER['@objectstack/lint']`, newly present where it was absent before. Nothing to migrate.
Copy file name to clipboardExpand all lines: .changeset/20206-lint-packages-non-array-refused.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,12 +2,12 @@
2
2
"@objectstack/lint": minor
3
3
---
4
4
5
-
`packages/lint`'s four`stack.packages` readers (plus a fifth added by #20208 after this ruling's own site census) now refuse a PRESENT non-array `packages` — `{}`, `0`, `'x'`, or a keyed object— the same way `@objectstack/core`'s `resolveArtifactPackageOrder` already does, instead of silently reading it as "no packages" (#20206, ruling A on #15293, comment 5634034754).
5
+
`packages/lint`'s five`stack.packages` readers (four named by #20206, plus one added by #20208 after that card's site census) now refuse a PRESENT non-array `packages` — `{}`, `0`, `'x'`, a keyed object, and (as of this round) `null` too — the same way `@objectstack/core`'s `resolveArtifactPackageOrder` already does, instead of silently reading it as "no packages" (#20206, ruling A on #15293 comment 5634034754; the `null` leg is ruling A on #19926, comment 5805260775: `null` is malformed, everywhere).
6
6
7
7
Clause-②: no (narrowing)
8
8
9
9
<!-- adr-0087: not-required (no-migration-prescription) an already-malformed `packages` value is refused rather than converted; no key, export or stored value moves, and nothing in this repo emits the shape today -->
10
10
11
-
-**What changes**: `validateObjectReferences`, `validateTranslationReferences` and `validateMappingTargetFields` (the three public `@objectstack/lint` functions these readers sit behind) now throw an `INVALID_ARTIFACT_PACKAGES` error (ADR-0112, `status: 422`) instead of returning findings, when the stack they are handed carries a `packages` key that is present but not an array. `os validate` / `os lint` / `os build` surface it as a refusal on stderr (and in `error`/`code` under `--json`) instead of reporting the stack as clean.
12
-
-**What does not change**: an absent `packages`, and `packages: null`, are still read as "no packages" — unchanged, and #19926's surface, not this one. A well-formed `packages[]` array is read exactly as before, junk entries dropped exactly as before.
11
+
-**What changes**: `validateObjectReferences`, `validateTranslationReferences` and `validateMappingTargetFields` (the three public `@objectstack/lint` functions these readers sit behind) now throw an `INVALID_ARTIFACT_PACKAGES` error (ADR-0112, `status: 422`) instead of returning findings, when the stack they are handed carries a `packages` key that is present but not an array — `null` included. `os validate` / `os lint` / `os build` surface it as a refusal on stderr (and in `error`/`code` under `--json`) instead of reporting the stack as clean.
12
+
-**What does not change**: an absent `packages` (the key omitted, or explicitly `undefined`) is still read as "no packages" — unchanged. A well-formed `packages[]` array is read exactly as before, junk entries dropped exactly as before.
13
13
-**Fix**: write `packages` as an array of `{ manifest: … }` entries, or omit the key entirely for a single-package stack.
0 commit comments