Repository navigation
sdui.manifest.json 的来源未定:声明一致性 ratchet 目前只在手工 pnpm sdui:manifest 时跑,CI 里从来不跑(#4690 的遗留决定) #5960
Description
Activity
发现分诊轮:晋级(摘
finding)—— 但晋级去向是决策箱(needs-user-decision),不是pm:queue;域domain:spec-tooling。- 落点锚定:候选改面全部落在生成器/门禁侧 ——
scripts/gen-sdui-manifest.sh、scripts/build-console.sh、.github/workflows/ci.yml(A 案),或 objectui 的scripts/dump-public-manifest.mjs(B/C 案)。本仓侧属 spec-tooling 座位(协议工具链/门禁/生成器);来源单 check:react-declaration-parity 是唯一没接进任何 workflow 的源码审计门禁,且无 MANIFEST 时静默 skip 退出 0 —— 它现在永远不可能红 #4690 亦在该座位队列,连续性一致。 - 为什么不入队:A / B / C / D 的分歧是成本与归属 —— A 把 objectui 全量构建 + Vite dev server + Playwright chromium 下载压进本仓 CI 并要定触发条件,B 要跨仓协调发布制品,C 的可行性未测,D 是显式承认「按需门禁」。这是排期/胃口问题,
os-dev不该猜,分诊座位也不代裁。 - PM 倾向(供裁决,不构成裁决):B > D > A。B 把浏览器成本留在它本来就存在的那一侧(objectui 已有 Playwright),本仓在 pin 更新时消费一个制品即可;D 是零成本的诚实兜底(把「只在 pin 更新流程里人工跑」写进规程),随时可退守;A 的增量成本会落在每一个命中路径过滤的 PR 上。C 需要先测可行性,不宜先押。
- 过时前提检查:正文的四行实测(无签入副本、
build-console.sh故意不产出、已发布 console tarball 零命中、无 workflow 跑pnpm sdui:manifest)读的是origin/main 72bd873,与本轮 main 同代,未见相关改动。check:react-declaration-parity 是唯一没接进任何 workflow 的源码审计门禁,且无 MANIFEST 时静默 skip 退出 0 —— 它现在永远不可能红 #4690 已把静默 skip 改成报错退出,所以当前没有「假装跑过」的风险,只有「实际零覆盖」——这降低了紧迫度,不改变问题本身。 - 可与主问题脱钩的一条小尾巴(建议单独处理,不占决策箱):ADR-0082 的 Consumers 行与 D4、以及
docs/audits/2026-06-react-blocks-conformance.md都写着 ratchet 跑在scripts/build-console.sh,实际 check-react-blocks-conformance 比的是两份声明,不是声明↔实现——#4413 全程它都是绿的(Prime Directive #10 落在门禁自己身上) #4472 之后搬到了scripts/gen-sdui-manifest.sh—— 纯文档订正,照 ADR 去找的人会翻错文件。裁决时可一并说「文档订正照做」,由 spec-tooling 座位搭任何过路单。 - 查重:三仓全文比对,
sdui.manifest相关仅 objectui#3407(record:highlights的inputs声明,内容无关)。不重复。
本评论来自分诊座位 Routine(#5474 试点),不构成认领。
Generated by Claude Code
- 落点锚定:候选改面全部落在生成器/门禁侧 ——
Ruling (maintainer, 2026-08-07): option D — declare it an on-demand gate and write it into the pin-update procedure.
sdui.manifest.jsononly changes when the objectui pin moves, so the correct trigger has always been the pin-update flow, not every PR. The procedure gains one line: runpnpm sdui:manifestwhen bumping the objectui pin, and the ratchet runs there. #4690 already guarantees this cannot go falsely green — a missing manifest fails loudly — so honest on-demand coverage beats expensive full coverage.Option A (produce the manifest in this repo's CI) is rejected: it would push a full objectui build plus Playwright/chromium onto every matching PR, and this repo just paid a large bill for merge-queue health (#6082). Option B (objectui publishes the manifest as a release artefact, this repo consumes it at pin time) is the structurally right end state — the cost stays on the side that already runs a browser — but there is no pull for it today; leave it for whenever objectui's release pipeline is next opened.
Rider, no ruling needed: ADR-0082's Consumers/D4 note and the audit doc still point at
build-console.shwhen the producer isgen-sdui-manifest.sh— correct that in passing.Operator: PM session
session_01GcjbQLUQKysMU9uXB34iyv; maintainer ruling 2026-08-07 (decision-inbox round 2). Veto window open — comment or reopen to overturn.
Generated by Claude Code
os-project-manager commented
on Aug 7, 2026 CollaboratorMore actionsClaim: PM loop round 1
Session:session_01AZgRyPVwi1jLb1mNNuQ9o(full:session_01AZgRyPVwi1jLb1mNNuUQ9o, seatdomain:spec-tooling, GitHubos-project-manager, seat card #6018)
Branch:claude/issue-5960-sdui-manifest-on-demand
Worktree:objectstack-issue-5960
Domain:domain:spec-tooling
File surface:scripts/bump-objectui.sh(and/or the pin-update procedure text it anchors),docs/adr/0082-react-component-contract-governance.md,docs/audits/2026-06-react-blocks-conformance.md, possiblyscripts/gen-sdui-manifest.shcomments — nopackages/spec/src/**, nocontent/docs/releases/**(stop on breach; explain in the report)
Serial constraints cleared: in-flight #5475 (packages/spec/tsconfig*+packages/spec/scripts/**), #6384 (packages/spec/docs/SYNC_ARCHITECTURE.md), #6229 (packages/spec/scripts/lib/file-description.ts+ references regen) — all file-disjoint from this surface; no other same-file predecessor PRs or claims found
Container classification: S (procedure line + two doc corrections),mode:subagentshared containerBasis: maintainer ruling of 2026-08-07 (option D, comment above) — decision made, veto window has been open 13h with no objection. Stale-premise check done: zero commits on the named files since 2026-08-05 (REST
list_commitsper path).
Generated by Claude Code
os-project-manager commented
on Aug 7, 2026 CollaboratorMore actionsACCEPT — PR #6421 (round 1, spec-tooling seat, session
session_01AZgRyPVwi1jLb1mNNuUQ9o).What shipped, against the maintainer's option-D ruling of 2026-08-07:
- The pin-update procedure gains the
pnpm sdui:manifeststep in all five places an operator meets it:scripts/bump-objectui.shprints a NEXT STEP block on both successful exits (incl.--no-commit, which also moves the pin),scripts/build-console.sh's closing line names the trigger,docs/releases-maintenance.mdgains "After the pin moves" + the pin-freshness fix-when-it-fires step, andAGENTS.md§Frontend records the settled answer instead of an "open provenance question". - The reminder is pinned by a gate, not prose alone:
check:objectui-changeset's self-test now asserts a bump prints the step (reverse-verified red→green in the report). Deliberately a reminder, not a hard bump-blocker — a Playwright-less machine can still move the pin, and per the ruling no CI wiring was added. - Rider done: 6 stale producer pointers (5 in ADR-0082 incl. Consumers row / TL;DR / D4 / chain diagram / Consequences, 1 in the 2026-06 audit doc) corrected to
scripts/gen-sdui-manifest.sh, with a new ADR-0082 Addendum 2 recording the ruling and the rejected/deferred options. No ADR decision reversed.
Review verified against GitHub, not the report: file surface = the claimed surface exactly (7 files, no
packages/spec/**, no releases pages); premise re-measured by the dev againstorigin/main761a0ba (all four issue claims held); ESLint job success 17:32:59Z and TypeScript Type Check success 17:41:15Z (gate-family carriers), all 26 check runs converged with zero failures;skip-changesetapplied by the PM after independent file-surface verification (nothing publishable in the diff — the one Check Changeset red was the known #6260 opened-event race, cleared by rerun). Out-of-scope finding filed as #6425 (--helphardcoded sed range), left for triage grading.Proceeding to land: marking ready and adding to the merge queue. Option B (objectui publishes the manifest as a release artefact) remains deferred per the ruling — no issue filed now; it waits for the next time objectui's release pipeline is opened.
Generated by Claude Code
- The pin-update procedure gains the
- added a commit that references this issue
on Aug 25, 2026 - added a commit that references this issue
on Sep 1, 2026
在 #4690(把
check:react-declaration-parity的静默 skip 改成报错退出)里实测出来的遗留问题,按 PM 裁决 (c) 单独记一笔。本条只记录测量与选项,不含实现主张。事实(#4690 的实测,2026-08-06,origin/main 72bd873)
spec↔registry 声明一致性 ratchet 需要 objectui 的
sdui.manifest.json。它在本仓的可得性:packages/console/只跟踪 4 个文件,dist/在.gitignore里;git ls-files里没有任何sdui.manifest.jsonscripts/build-console.sh(ci.yml 会跑)@objectstack/consolesdui命中 0;dist/manifest.json是 PWA manifest。→ CLIresolveSduiManifest()的 console 兜底路径对任何 npm 安装用户都解析不到pnpm sdui:manifest;除 showcase-smoke(无关)外没有装 Playwright唯一生产者:objectui 的
scripts/dump-public-manifest.mjs—— Playwright chromium 打开构建后 console 的dev/manifest-dump.html,读window.__MANIFEST。包装脚本是scripts/gen-sdui-manifest.sh(pnpm sdui:manifest),它按.objectui-sha构建 objectui、dump manifest、然后跑 ratchet。净结果:ratchet 只在有人手工跑
pnpm sdui:manifest时才跑。 #4690 已经让「没 manifest」从静默退 0 变成报错退 1,所以现在不会再有人误以为它跑过了;但它在自动化里跑到的次数仍然是零,registry 侧的声明漂移在实践中没有被 ratchet 住。待决定(带成本,不宜由开发 agent 猜)
.objectui-sha路径过滤时),所以并非不可能;增量是 objectui 全量 workspace 构建 + Vite dev server + 一次 Playwright chromium 下载,且需要决定触发条件(.objectui-sha变、或packages/spec/src/ui/react-blocks.ts变 —— spec 侧删属性同样会把某个 registry input 变成 registry-only)。关联
#4690(本条来源)、ADR-0082 D4(「manifest 只在 console 构建期存在,不值得每个 PR 跑」—— 该判断成立,但当时没回答「那到底什么时候跑」)、#4804 / #4777(把 #4690 当作「只在 main 上绿的门禁证明不了任何事」的反面教材引用)。
顺带一条同源观察,可一并裁:ADR-0082 的 Consumers 行与 D4 都写着 ratchet 跑在
scripts/build-console.sh里,实际它在 #4472 之后搬到了scripts/gen-sdui-manifest.sh;docs/audits/2026-06-react-blocks-conformance.md有同样的过期指向。照 ADR 去找的人会翻错文件。