Skip to content

sdui.manifest.json 的来源未定:声明一致性 ratchet 目前只在手工 pnpm sdui:manifest 时跑,CI 里从来不跑(#4690 的遗留决定) #5960

Description

@baozhoutao

在 #4690(把 check:react-declaration-parity 的静默 skip 改成报错退出)里实测出来的遗留问题,按 PM 裁决 (c) 单独记一笔。本条只记录测量与选项,不含实现主张。

事实(#4690 的实测,2026-08-06,origin/main 72bd873)

spec↔registry 声明一致性 ratchet 需要 objectui 的 sdui.manifest.json。它在本仓的可得性:

候选来源 实测
签入副本 无。packages/console/ 只跟踪 4 个文件,dist/ 在 .gitignore 里;git ls-files 里没有任何 sdui.manifest.json
scripts/build-console.sh(ci.yml 会跑) 故意不产出。收尾注释:manifest 需要真实浏览器,console 构建不能拖进浏览器依赖
已发布的 @objectstack/console 无。16.1.0 tarball 共 513 个文件,sdui 命中 0;dist/manifest.json 是 PWA manifest。→ CLI resolveSduiManifest() 的 console 兜底路径对任何 npm 安装用户都解析不到
任何 workflow 没有一个跑 pnpm sdui:manifest;除 showcase-smoke(无关)外没有装 Playwright

唯一生产者:objectui 的 scripts/dump-public-manifest.mjs —— Playwright chromium 打开构建后 console 的 dev/manifest-dump.html,读 window.__MANIFEST。包装脚本是 scripts/gen-sdui-manifest.sh(pnpm sdui:manifest),它按 .objectui-sha 构建 objectui、dump manifest、然后跑 ratchet。

净结果:ratchet 只在有人手工跑 pnpm sdui:manifest 时才跑。 #4690 已经让「没 manifest」从静默退 0 变成报错退 1,所以现在不会再有人误以为它跑过了;但它在自动化里跑到的次数仍然是零,registry 侧的声明漂移在实践中没有被 ratchet 住。

待决定(带成本,不宜由开发 agent 猜)

  • A. 在本仓 CI 里生产 manifest。 ci.yml 已有一个 job 会 shallow-clone objectui 并构建 console(命中 .objectui-sha 路径过滤时),所以并非不可能;增量是 objectui 全量 workspace 构建 + Vite dev server + 一次 Playwright chromium 下载,且需要决定触发条件(.objectui-sha 变、或 packages/spec/src/ui/react-blocks.ts 变 —— spec 侧删属性同样会把某个 registry input 变成 registry-only)。
  • B. 让 objectui 把 manifest 作为发布制品带出来(随 console dist 或独立 artifact),本仓在 pin 更新时消费。跨仓协调,但把浏览器成本留在它本来就存在的那一侧。
  • C. 在 objectui 侧做 Node 端 dump(若 public registry 能被切成不拉浏览器依赖的一层),则 manifest 变成一次普通 node 调用。可行性未测,属 objectui 仓。
  • D. 维持现状:显式承认这是「按需门禁」,只在 pin 更新流程里由人跑,并把这一点写进 pin 更新的操作规程。

关联

#4690(本条来源)、ADR-0082 D4(「manifest 只在 console 构建期存在,不值得每个 PR 跑」—— 该判断成立,但当时没回答「那到底什么时候跑」)、#4804 / #4777(把 #4690 当作「只在 main 上绿的门禁证明不了任何事」的反面教材引用)。

顺带一条同源观察,可一并裁:ADR-0082 的 Consumers 行与 D4 都写着 ratchet 跑在 scripts/build-console.sh 里,实际它在 #4472 之后搬到了 scripts/gen-sdui-manifest.sh;docs/audits/2026-06-react-blocks-conformance.md 有同样的过期指向。照 ADR 去找的人会翻错文件。

Activity

  1. claude commented on Aug 6, 2026

    @claude
    Contributor

    发现分诊轮:晋级(摘 finding)—— 但晋级去向是决策箱(needs-user-decision),不是 pm:queue;域 domain:spec-tooling。

    • 落点锚定:候选改面全部落在生成器/门禁侧 —— scripts/gen-sdui-manifest.sh、scripts/build-console.sh、.github/workflows/ci.yml(A 案),或 objectui 的 scripts/dump-public-manifest.mjs(B/C 案)。本仓侧属 spec-tooling 座位(协议工具链/门禁/生成器);来源单 check:react-declaration-parity 是唯一没接进任何 workflow 的源码审计门禁,且无 MANIFEST 时静默 skip 退出 0 —— 它现在永远不可能红 #4690 亦在该座位队列,连续性一致。
    • 为什么不入队:A / B / C / D 的分歧是成本与归属 —— A 把 objectui 全量构建 + Vite dev server + Playwright chromium 下载压进本仓 CI 并要定触发条件,B 要跨仓协调发布制品,C 的可行性未测,D 是显式承认「按需门禁」。这是排期/胃口问题,os-dev 不该猜,分诊座位也不代裁。
    • PM 倾向(供裁决,不构成裁决):B > D > A。B 把浏览器成本留在它本来就存在的那一侧(objectui 已有 Playwright),本仓在 pin 更新时消费一个制品即可;D 是零成本的诚实兜底(把「只在 pin 更新流程里人工跑」写进规程),随时可退守;A 的增量成本会落在每一个命中路径过滤的 PR 上。C 需要先测可行性,不宜先押。
    • 过时前提检查:正文的四行实测(无签入副本、build-console.sh 故意不产出、已发布 console tarball 零命中、无 workflow 跑 pnpm sdui:manifest)读的是 origin/main 72bd873,与本轮 main 同代,未见相关改动。check:react-declaration-parity 是唯一没接进任何 workflow 的源码审计门禁,且无 MANIFEST 时静默 skip 退出 0 —— 它现在永远不可能红 #4690 已把静默 skip 改成报错退出,所以当前没有「假装跑过」的风险,只有「实际零覆盖」——这降低了紧迫度,不改变问题本身。
    • 可与主问题脱钩的一条小尾巴(建议单独处理,不占决策箱):ADR-0082 的 Consumers 行与 D4、以及 docs/audits/2026-06-react-blocks-conformance.md 都写着 ratchet 跑在 scripts/build-console.sh,实际 check-react-blocks-conformance 比的是两份声明,不是声明↔实现——#4413 全程它都是绿的(Prime Directive #10 落在门禁自己身上) #4472 之后搬到了 scripts/gen-sdui-manifest.sh —— 纯文档订正,照 ADR 去找的人会翻错文件。裁决时可一并说「文档订正照做」,由 spec-tooling 座位搭任何过路单。
    • 查重:三仓全文比对,sdui.manifest 相关仅 objectui#3407(record:highlights 的 inputs 声明,内容无关)。不重复。

    本评论来自分诊座位 Routine(#5474 试点),不构成认领。


    Generated by Claude Code

  2. claude commented on Aug 7, 2026

    @claude
    Contributor

    Ruling (maintainer, 2026-08-07): option D — declare it an on-demand gate and write it into the pin-update procedure.

    sdui.manifest.json only changes when the objectui pin moves, so the correct trigger has always been the pin-update flow, not every PR. The procedure gains one line: run pnpm sdui:manifest when bumping the objectui pin, and the ratchet runs there. #4690 already guarantees this cannot go falsely green — a missing manifest fails loudly — so honest on-demand coverage beats expensive full coverage.

    Option A (produce the manifest in this repo's CI) is rejected: it would push a full objectui build plus Playwright/chromium onto every matching PR, and this repo just paid a large bill for merge-queue health (#6082). Option B (objectui publishes the manifest as a release artefact, this repo consumes it at pin time) is the structurally right end state — the cost stays on the side that already runs a browser — but there is no pull for it today; leave it for whenever objectui's release pipeline is next opened.

    Rider, no ruling needed: ADR-0082's Consumers/D4 note and the audit doc still point at build-console.sh when the producer is gen-sdui-manifest.sh — correct that in passing.

    Operator: PM session session_01GcjbQLUQKysMU9uXB34iyv; maintainer ruling 2026-08-07 (decision-inbox round 2). Veto window open — comment or reopen to overturn.


    Generated by Claude Code

  3. os-project-manager commented on Aug 7, 2026

    @os-project-manager
    Collaborator

    Claim: PM loop round 1
    Session: session_01AZgRyPVwi1jLb1mNNuQ9o (full: session_01AZgRyPVwi1jLb1mNNuUQ9o, seat domain:spec-tooling, GitHub os-project-manager, seat card #6018)
    Branch: claude/issue-5960-sdui-manifest-on-demand
    Worktree: objectstack-issue-5960
    Domain: domain:spec-tooling
    File surface: scripts/bump-objectui.sh (and/or the pin-update procedure text it anchors), docs/adr/0082-react-component-contract-governance.md, docs/audits/2026-06-react-blocks-conformance.md, possibly scripts/gen-sdui-manifest.sh comments — no packages/spec/src/**, no content/docs/releases/** (stop on breach; explain in the report)
    Serial constraints cleared: in-flight #5475 (packages/spec/tsconfig* + packages/spec/scripts/**), #6384 (packages/spec/docs/SYNC_ARCHITECTURE.md), #6229 (packages/spec/scripts/lib/file-description.ts + references regen) — all file-disjoint from this surface; no other same-file predecessor PRs or claims found
    Container classification: S (procedure line + two doc corrections), mode:subagent shared container

    Basis: maintainer ruling of 2026-08-07 (option D, comment above) — decision made, veto window has been open 13h with no objection. Stale-premise check done: zero commits on the named files since 2026-08-05 (REST list_commits per path).


    Generated by Claude Code

  4. os-project-manager commented on Aug 7, 2026

    @os-project-manager
    Collaborator

    ACCEPT — PR #6421 (round 1, spec-tooling seat, session session_01AZgRyPVwi1jLb1mNNuUQ9o).

    What shipped, against the maintainer's option-D ruling of 2026-08-07:

    • The pin-update procedure gains the pnpm sdui:manifest step in all five places an operator meets it: scripts/bump-objectui.sh prints a NEXT STEP block on both successful exits (incl. --no-commit, which also moves the pin), scripts/build-console.sh's closing line names the trigger, docs/releases-maintenance.md gains "After the pin moves" + the pin-freshness fix-when-it-fires step, and AGENTS.md §Frontend records the settled answer instead of an "open provenance question".
    • The reminder is pinned by a gate, not prose alone: check:objectui-changeset's self-test now asserts a bump prints the step (reverse-verified red→green in the report). Deliberately a reminder, not a hard bump-blocker — a Playwright-less machine can still move the pin, and per the ruling no CI wiring was added.
    • Rider done: 6 stale producer pointers (5 in ADR-0082 incl. Consumers row / TL;DR / D4 / chain diagram / Consequences, 1 in the 2026-06 audit doc) corrected to scripts/gen-sdui-manifest.sh, with a new ADR-0082 Addendum 2 recording the ruling and the rejected/deferred options. No ADR decision reversed.

    Review verified against GitHub, not the report: file surface = the claimed surface exactly (7 files, no packages/spec/**, no releases pages); premise re-measured by the dev against origin/main 761a0ba (all four issue claims held); ESLint job success 17:32:59Z and TypeScript Type Check success 17:41:15Z (gate-family carriers), all 26 check runs converged with zero failures; skip-changeset applied by the PM after independent file-surface verification (nothing publishable in the diff — the one Check Changeset red was the known #6260 opened-event race, cleared by rerun). Out-of-scope finding filed as #6425 (--help hardcoded sed range), left for triage grading.

    Proceeding to land: marking ready and adding to the merge queue. Option B (objectui publishes the manifest as a release artefact) remains deferred per the ruling — no issue filed now; it waits for the next time objectui's release pipeline is opened.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions