Repository navigation
[finding] hono UI auto-discovery: the slug-from-name fallback and the staticPath guard are unreachable through kernel.use() once PluginSchema requires both keys (#16334) #16599
Description
Activity
- addeddocumentationImprovements or additions to documentationImprovements or additions to documentationand removed
on Sep 7, 2026 Triage: lands in
domain:services(packages/plugins/plugin-hono-server/src/hono-plugin.ts+ its pin file);Bug,priority:p3,pm:queue. Routed as a child of the open parent #15638 — perSKILL.md, a parent with sub-structure gets the queue label and triage expands the children individually; ⛔ the parent is a coordination node and is never dispatched.Admission basis, stated because the obvious reading would close it: unreachable arms are 死代码, which the rule lists under 其余 ⛔ 不立卡. ⇒ Two things admit it anyway:
- ⭐ A false statement in the tree, which is class (a). The
it.todofor case C "still narrates a boot path that never callsPluginSchema, which stopped being true at feat(core): enforce PluginSchema at kernel.use() (#16049) #16363." ⇒ Same grounds as objectstack#16602, [finding] a pinned NON-rule in packages/spec justifies itself with a record-validator.ts line number that is 319 lines off, and nothing checks prose line anchors #16441 and objectui#8029 today — prose that is measurably wrong, in a file whose comments are load-bearing. - ⭐ The unreachability is proven, not asserted, and it is proven by a change that already landed. The two pins that exercised these branches through the real kernel — "derives the slug from the last path segment of the plugin name when none is declared" and "a
uitype with no staticPath mounts nothing" — had to be inverted into refusal pins on PR fix(spec,core): PluginSchema requires staticPath/slug for type "ui", and Plugin derives its metadata keys from PluginDefinition (#16334) #16598, becausekernel.use()now throwsPLUGIN_CONTRACT_VIOLATION … at 'slug'/at 'staticPath'beforestart()ever runs. ⇒ The tests that used to reach the arms now assert they cannot be reached.
priority:p3: ⛔ no behaviour, no consumer-visible change — the arms cannot execute, so removing them changes nothing observable. This is ledger hygiene under ADR-0049 plus one false comment.Scope, and ⭐ the third arm is the one worth not missing: the same block reads
plugin.default || plugin.isDefault, andisDefaultis not aPluginSchemakey — ⇒ likely a fourth dead alias, and the card is right that it "is worth a look in the same pass." ⛔ Do not retire two arms and leave a third of the same shape two lines away unexamined; that is how this card's parent came to have children.⇒ Deliverable, as the card shapes it: read
plugin.slugandplugin.staticPathas the contract now guarantees them, drop the||fallback and the&& plugin.staticPathconjunct, rewrite the case-C todo against the post-#16363 boot path, and measureisDefault.⚠️ Coordinate with the parent: #15638 owns theui-plugindisjunct of the same guard, which was already unreachable after #16363. ⇒ Whoever lands either should check whether both can go in one PR — three arms of one guard, one verification surface — or state why not. ⛔ Two PRs racing on the sameifis the avoidable outcome.⛔ Correctly left out of #16334: retiring these is a
plugin-hono-serverchange with its own verification surface, and that PR is the spec half.⛔ This seat grades and routes only: not claimed, not dispatched, no code.
Generated by Claude Code
- ⭐ A false statement in the tree, which is class (a). The
- added a commit that references this issue
on Sep 9, 2026 - added a commit that references this issue
on Oct 7, 2026
Observation from #16334 (spec half of #16049), filed unassigned. Sub-issue of #15638 because it is the same block and the same class — an arm of the auto-discovery block in
packages/plugins/plugin-hono-server/src/hono-plugin.ts(around line 508) that no object can reach any more.What is dead, and since when
const slug = plugin.slug || plugin.name.split('/').pop();— the||fallback. With spec:PluginSchemamakesstaticPath/slugreally required fortype: "ui"(superRefine), and core'sPlugininterface derives fromPluginDefinition(spec half of #16049) #16334,PluginSchemarefuses atype: 'ui'plugin withoutslug, andkernel.use()runs the schema ([finding] PluginSchema has zero runtime callers — the boot path validates name, init and semver only, so the declared plugin contract is never enforced #16049, landed as feat(core): enforce PluginSchema at kernel.use() (#16049) #16363), so auiobject with noslugnever reacheskernel.plugins, the only population the block iterates.if ((plugin.type === 'ui' || plugin.type === 'ui-plugin') && plugin.staticPath)— the&& plugin.staticPathconjunct, for the same reason (staticPathis required foruitoo). Theui-plugindisjunct is [finding]plugin-hono-serverstill accepts the legacyui-plugintype thatPluginSchemarefuses — an unreachable arm under ADR-0049 #15638's own subject and was already unreachable after feat(core): enforce PluginSchema at kernel.use() (#16049) #16363.Evidence. The two pins that exercised those branches through the real kernel — "derives the slug from the last path segment of the plugin name when none is declared" and "a
uitype with no staticPath mounts nothing" insrc/ui-plugin-auto-discovery.pin.test.ts— had to be inverted into refusal pins on the #16334 PR (#16598): with the schema tightened,kernel.use()throwsPLUGIN_CONTRACT_VIOLATION … at 'slug'/at 'staticPath'beforestart()ever runs. Theit.todofor case C in that file still narrates a boot path that "never callsPluginSchema", which stopped being true at #16363.Left out of #16334 by scope. Retiring the two arms is a
plugin-hono-serverchange with its own verification surface, and #15638 already owns the third arm of the same guard. Suggested shape, for whoever lands it: readplugin.slugandplugin.staticPathas the contract now guarantees them, drop the fallback and the guard, and rewrite the case-C todo against the post-#16363 boot path. The same block also reads anisDefaultalias besidedefault(plugin.default || plugin.isDefault);isDefaultis not aPluginSchemakey and is worth a look in the same pass.