Skip to content

Epic: 11.0 major release — breaking-change batch + GA readiness #2364

Description

@os-zhuang

Goal: define and ship the next major version (11.0) as a deliberate, batched breaking-change + GA-readiness release.

Why this epic exists

Fixed-group packages are at 10.3.0; the 43 pending changesets are all minor/patch (0 major), so today's release would be 10.4.0. Majors in this project are triggered by breaking changes (e.g. 10.0.0 = ADR-0057 sys_department→sys_business_unit). Nothing currently forces 11.0 — it is a choice to batch the breaking cleanups + close GA gaps. This epic is the cut list. Each breaking item should ship with an additive migration (spec sync / os migrate, per #2186).

Status legend: ☐ todo · ◐ partial · ✅ done (verify & close)


A. Breaking batch — the "definition of 11.0" (core)

Each of these removes or changes an authored/public contract → belongs in a major. Pair each with a migration.

A1. Security "enforce-or-remove" (ADR-0049)

A2. Dead spec-surface removal (liveness ledger — ADR-0049)

  • field: remove aspirational nested configs that are author-facing no-ops — currencyConfig, vectorConfig, encryptionConfig, maskingRule, cached, dataQuality, fileAttachmentConfig (verify each), + naming-drift props (~39 dead of 73).
  • object: remove the dead versioning / partitioning / CDC tier props (~17 dead); decide apiEnabled (unenforced).
  • action / agent / skill / dataset: remove action.disabled (CEL ignored), action.type:'form' / shortcut / bulkEnabled; agent.access/permissions/visibility (chat route hardcodes); skill.triggerPhrases / skill.permissions; dataset.measures.certified.
  • decide experimental: agent.autonomy, tool.inputSchema → implement or mark deprecated-for-removal.

A3. Deprecated alias / API removals (verified still present)

  • flow node aliases http_request / http_call / webhook → canonical http (packages/spec/src/automation/flow.zod.ts:33); align FlowNodeAction enum with the live registry.
  • ADR-0041 — remove old plugin-trigger-record-change / plugin-trigger-schedule (new @objectstack/trigger-* already shipped).
  • client-react legacy query fields select/filters/sort/top/skip → fields/where/orderBy/limit/offset.
  • remove HttpDispatcher class (replaced by createDispatcherPlugin()), UIServiceSchema, IDataEngine (→IDataDriver), legacy env-var aliases.
  • delete the stale plugin-dev stub still annotated "removed in v4.0.0" (we're at v10).

B. GA functional gaps (triaged — mostly objectui/cloud)


C. Unfinished ADRs

  • ADR-0028 — namespace isolation ((namespace,type,name) identity + physical-name derivation): prevents silent table-name collisions across co-installed packages. Identity change is itself breaking → good 11.0 fit.
  • ADR-0029 K3/K4 — kernel object decomposition finish + remove migration-era empty barrels (hygiene).
  • ADR-0017 has-many — RLS still client-enforced (security gap); backend enforcement before GA.
  • High-value, optional: ADR-0025 plugin install/consent loop, ADR-0027 authoring lifecycle orchestrator, ADR-0013 Slack inbound.
  • Backend-done / UI-pending (objectui): ADR-0007 Settings UI, ADR-0032 expression builders, ADR-0044 approval send-back designer.

Deferred by design (not blockers): ADR-0039 Track B, ADR-0010 NL→Flow, ADR-0031 BPMN, ADR-0026 client-UI plugins.


D. Release mechanics & quality (healthy)

  • changeset hygiene: fixed group (73 pkgs) consistent; cut major cleanly; wait for remote CI green, no --auto (per past tag-race).
  • confirm atomic tag push (fix(release): push version tags in one atomic push (avoid commit_refs race) #2195) still in place for the large fixed group.
  • quality baseline good: ~6 source TODOs (none blocking), minimal/intentional test skips, field-zoo xfail are deliberate watchdogs.

Cut checklist (Definition of Done for 11.0)

  1. A1–A3 breaking items landed, each with an additive migration.
  2. B gaps triaged → GA-required subset (likely portal + composer + notify proof) shipped; resolved ones ([P0] field-type: file field has no upload UI; no attachment_list type — attachments end-to-end blocked #1296) closed.
  3. ADR-0028 + 0029 K3/K4 + 0017 backend RLS merged.
  4. objectui/cloud surface PRs aligned & merged.
  5. changesets clean, fixed group consistent, remote CI green → tag 11.0.

Triage source: assessment + two verification passes (functional P0s #1292/#1295/#1296/#1293/#1294; security P0s #1882/#1883/#1886) on 2026-06-27.

Activity

  1. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    Version-cut mechanism in place → #2366. Found that the breaking service-ai removal (#2325, feat!: open edition is MCP-only) was merged but unreleased with no changeset — the pending release would have leaked it as 10.4.0 (minor). #2366 adds the missing major changeset so the next release cuts 11.0.0 (the 73-package fixed group bumps together; all pending changes fold in). Low-key wording, no code change. This is the concrete trigger for 11.0; the A/B/C work items above can land into the same major.

  2. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    A3 started → #2369: removed the deprecated http_request/http_call/webhook flow-node aliases (canonical http only; ADR-0018 M3). spec 154 + service-automation 111 tests green, examples build clean. First mechanical breaking-cleanup landing into 11.0.

  3. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    A3 progress (alias removals, both verified): #2369 flow http aliases ✅, #2372 client-react useQuery aliases ✅.

    Full A-scoping finding: most remaining A items cascade into examples/features → each needs its own PR:

    • A1 PolicySchema ([P0][security] PolicySchema is 100% dead — enforce or remove #1882): NOT dead in practice — app-crm + app-showcase define/pass policies: + stack.policies field; removal ⇒ migrate both examples.
    • A1 role.parent ([P0][security] Role parent dead — manager-rollup unimplemented #1886): removal guts RoleGraphService + role_and_subordinates recipient (ADR-0056 D6) → product decision (remove vs implement walk).
    • A2 dead props: real dead set smaller than listed (currencyConfig/action.disabled/agent.access/skill.* are LIVE). Dead: field{vectorConfig,fileAttachmentConfig,dependencies,caseSensitive}, object{versioning,partitioning,softDelete,recordName,keyPrefix,tags,abstract,isSystem,active,enable.*,search,defaultDetailForm}, action type:'form', agent{tenantId,planning.strategy/allowReplan}, dataset.measures.certified.
    • A3 IUIService: couples to CoreServiceName 'ui' + plugin-dev.
    • A3 HttpDispatcher: 245 refs/7 adapters → staged.
    • A3 IDataEngine + env vars: deprecation says v12 → not for 11.0.
    • ADR-0041 trigger pkgs: already gone.
  4. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    A-class session-2: 3 verified PRs landed — #2369 (flow http aliases), #2372 (client-react useQuery aliases), #2374 (IUIService). Decisions: role.parent→remove feature, IDataEngine+env→remove in 11.0. Remaining queue: PolicySchema #1882, role.parent #1886, A2 dead props, IDataEngine, env vars, HttpDispatcher — each a cascading PR; continuing.

  5. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    A-class remaining queue — one issue each

    Done (PRs): #2369 (flow http aliases), #2372 (client-react useQuery aliases), #2374 (IUIService contract).

    Remaining — tracked issues (execution order: low→high risk):

    Every PR also: gen:api-surface snapshot regen + (if examples touched) example build verify + major changeset.

  6. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    #2379 done → PR #2383 (env aliases). Removed ObjectStack's own renames (OS_MULTI_TENANT, OBJECTSTACK_METADATA_WRITABLE, OS_AUTH_BASE_URL/AUTH_BASE_URL); kept ecosystem standards (DATABASE_URL, AUTH_SECRET, etc.) as silent. Local: cli 436 / objectql 718 / driver-sql 234 / plugin-auth 175 / mcp 53 / hono 40 / types 7 green, api-surface unchanged.

  7. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    Adapter trim landed (#2391, merged): removed 6 non-Hono adapters + plugin-msw → Hono-only open edition; resolves #2380 (HttpDispatcher blast radius collapsed). Verified ../objectui has no real dependency on the removed packages (only a stale comment in one e2e spec). Docs-accuracy pass tracked in #2392 — to run after the remaining A-items. A-batch merged so far: #2369/#2372/#2374/#2379/#2378/#1882/#2391. Remaining: #1886 role.parent, #2377 A2 dead props (deferred), then #2392 docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions