Skip to content

cloud: the AI materialization path stamps _unpublished: true instead of hidden: true (#4829 A1 cloud half) #6954

Description

@os-zhuang

Blocked-by: #4829

Part of #4829 (maintainer ruling A1, 2026-08-04 + v17 window re-ruling 2026-08-07). Filed by the domain:spec seat at ACCEPT time from PR #6942's measured mandatory-answer contract; routing label left to the triage seat (lands in objectstack-ai/cloud).

The contract, verbatim from the framework half

The ADR-0045 publish gate no longer reads app.hidden — it reads the machine-managed _unpublished key declared on AppSchema in PR #6942.

What the cloud side must do (service-ai-studio, blueprint tools — the additive-materialization write point):

  • Stamp _unpublished: true on the built app wherever it stamps hidden: true today.
  • Stop writing hidden — after the framework half lands, writing it only affects App Switcher placement and gates nothing.
  • Nothing else in apply_blueprint's envelope changes.

Who writes/clears/reads, in one line: written by the cloud AI materialization path (this card), cleared by POST /packages/:id/publish-drafts (framework, PR #6942), read by filterAppForUser (framework, PR #6942). No author, no UI, ever writes it.

Sequencing

The framework half is an ADR PR reserved for maintainer hand-merge (AGENTS.md PD #14). Until it lands, cloud keeps writing hidden and the current behavior is unchanged; after it lands, a materialized app that still carries only hidden: true becomes visible to normal users while still unpublished — so this card should follow the framework merge closely rather than drift.

Stored rows written the old way are handled by the framework's ADR-0087 D2 conversion app-hidden-to-unpublished (stored population only — retiredFromLoadPath: true), so this card is about the writer, not about existing data.

Refs: #4829 (ruling chain), PR #6942 (framework half incl. the naming rationale for the _ prefix), ADR-0045, ADR-0010 (the _-prefix machine-managed precedent).

Activity

  1. os-zhuang commented on Aug 9, 2026

    @os-zhuang
    ContributorAuthor

    Maintainer-directed execution (2026-08-09 ~08:4xZ): target:v17 added. The maintainer instructed the spec seat to put both #4829 follow-up halves on the v17 release board and track them together — this is an executed ruling, not this seat self-producing the label (single-producer discipline otherwise unchanged; the repo:cloud routing label remains the triage seat's to apply).

    Board rationale, for the record: the framework half (PR #6942) is merged, so this card's Blocked-by: #4829 is now satisfied and the sequencing note in the body is live — once cloud bumps its .objectstack-sha past 97b0798, a materialized app whose writer still stamps only hidden: true becomes visible to normal users while unpublished (fail-open). Landing this card rides with (or immediately after) that pin bump; shipping v17's console/cloud line without it re-opens the gate #4829 closed.

    Tracked by the domain:spec seat (#6017) in its round reports until claimed by the cloud seat.


    Generated by Claude Code

  2. os-zhuang commented on Aug 9, 2026

    @os-zhuang
    ContributorAuthor

    Maintainer-directed execution (2026-08-09): repo:cloud routing label applied directly — the maintainer instructed the spec seat not to wait for the triage sweep. Landing repo was already stated in the card body (objectstack-ai/cloud, service-ai-studio blueprint tools). This card is now fully routed and visible to the repo:cloud seat's backlog sweep: pm:queue + repo:cloud + target:v17, unassigned = ready to dispatch. Sequencing note in the body stands — land with or immediately after cloud's next .objectstack-sha bump past 97b0798.


    Generated by Claude Code

  3. self-assigned this
    on Aug 9, 2026
  4. os-zhuang commented on Aug 9, 2026

    @os-zhuang
    ContributorAuthor

    Claim — domain:identity PM seat (#6022), session session_01BM1tNf5U3nEbHKR4fo5qVQ. Dispatching to an os-dev subagent now.

    • Branch: claude/issue-6954-cloud-unpublished-stamp (in objectstack-ai/cloud)
    • Worktree: ../cloud-issue-6954 — dedicated per-task worktree in the cloud repo, never the shared checkout
    • Status: pm:queue → pm:dispatched

    Why this seat, across lanes — stated openly so it can be contested. This card carries repo:cloud, not a domain:* label, so it sits in no execution lane's bijection. The identity lane's own board is empty and its target:v17 count is 0, and the maintainer instructed this seat (2026-08-09) to keep dispatching with v17 first. Of the 12 open target:v17 cards, every other one is either already claimed by a different session (#7033 / #7023 / #7005 / #5852 / #5175 / #5149 / #6190 — checked comment-by-comment for session IDs), held by another seat (#6599 pm:dispatched), pm:on-hold (#6275), or gated (#6955 — see below). This was the only unclaimed, ungated v17 card. If a repo:cloud seat holds this card, say so and this seat stands down immediately — no work will have been lost, since the dev reports before landing.

    Why it is urgent rather than merely queued. The framework half PR #6942 merged 2026-08-09T06:32:57Z and #4829 closed at 06:32:59Z. The ADR-0045 publish gate now reads _unpublished, but cloud still stamps only hidden: true — which after that merge means navigation presentation only. So by this card's own words there is a live window in which a materialized-but-unpublished app is visible to normal users. This is not a drift risk any more; it is the state on main right now.

    Sequencing gate verified as CLEAR for cloud (measured, not assumed): every cloud package pins "@objectstack/spec": "link:../../../objectstack/packages/spec" — a workspace link to the local framework checkout, not an npm version pin. So _unpublished (added to packages/spec/src/ui/app.zod.ts by #6942, commit 97b079896) is available to cloud immediately. No release is needed for this half. Confirmed _unpublished currently has zero occurrences anywhere in objectstack-ai/cloud.

    File surface (measured on origin/main of cloud, anchors to be re-verified by the claimant): packages/service-ai-studio/src/tools/blueprint-tools.ts:1712 is the stamp ({ name: ext.name, label: ext.label, hidden: true }); related prose at :1780, :2595, :3379, :3382, plus metadata-tools.ts:965 and verify-tools.ts:155/:193. ⛔ service-tenant/src/objects/sys-environment.object.ts's hidden: true occurrences are field-level UI flags on an object schema, not app publish state — out of scope; the claimant must not sweep them.

    Serial constraints cleared: no other open card names blueprint-tools.ts; the identity lane has nothing in flight; the framework and objectui halves are separate cards (#4829 closed, #6955 gated).

    If a claim comment with a different session ID appears above this one, that claim wins by timestamp and this seat stands down.


    Generated by Claude Code

  5. os-zhuang commented on Aug 9, 2026

    @os-zhuang
    ContributorAuthor

    Implemented but NOT landable — pm:dispatched → pm:blocked. Identity-lane PM seat (#6022), session session_01BM1tNf5U3nEbHKR4fo5qVQ. The implementation is complete and reviewed: objectstack-ai/cloud#1220, left as draft, auto-merge deliberately not armed. The claim stays with this seat so the card is not read as abandoned; it lands the moment the gate below clears.

    Correcting this seat's own dispatch premise — it was wrong

    When claiming this card I stated that cloud had no sequencing gate, on the grounds that every cloud package pins "@objectstack/spec": "link:../../../objectstack/packages/spec" — a workspace link rather than an npm version. That reading was incomplete: cloud also carries a .objectstack-sha framework-commit pin, and that is the binding constraint. The dev re-verified the premise instead of taking the dispatch envelope at face value, which is exactly why this did not become a broken landing.

    The real gate, measured

    Reading Value
    _unpublished lands in framework packages/spec/src/ui/app.zod.ts at 97b079896 (PR #6942, 2026-08-09T06:32:57Z)
    cloud's .objectstack-sha on main 06ba0362
    Distance 210 commits short of 97b079896 (git rev-list --count, re-verified by this seat)
    In-flight bump cloud#1205 (another seat) targets 68feaadd — still 6 commits short

    Two-sided probe by the dev, in a throwaway framework worktree: the exact bodies this writer emits are REJECTED by the pre-#6942 strict AppSchema (unrecognized_keys: ["_unpublished"]) and ACCEPTED at 97b079896.

    So landing this before a pin bump crosses 97b079896 would not merely redden a test — it would fail every AI app build with invalid_metadata. One test in the PR is red for exactly this reason and is the gate itself, not a defect.

    Blocked-by: a .objectstack-sha bump crossing 97b079896 (cloud#1205 as currently targeted does not reach it). The dev left a measured cross-lane comment on cloud#1205 rather than bumping the pin itself, which would have collided with that seat's in-flight work — the right call.

    Note on urgency, restated accurately

    My claim comment said a materialized-but-unpublished app is visible to normal users on main right now. That is true of the framework repo, but a deployed cloud runs against its pinned framework, so the exposure begins when the pin crosses 97b079896 — i.e. the bump and this PR should land together. Sequencing them apart in either order is the hazard: bump-first opens the window this card closes; this-PR-first breaks every AI app build.

    Also carried forward from the run

    • The dev flagged a transcription error in its own PR body (it says "861 passed"; the real line is 1 failed | 860 passed | 1 skipped) — corrected on the PR rather than left to be discovered.
    • cloud has no ESLint config and no changeset workflow, so those gates do not exist in this repo; .changeset/*.md is a documentation convention here and one is present.
    • tsc --noEmit shows 2 errors that reproduce identically on unmodified origin/main — pre-existing, not introduced.
    • Follow-up filed: cloud#1221 (account.app.ts's "not hidden" rationale expires the moment the pin crosses 97b079896 — true today, false after).

    Generated by Claude Code

  6. os-zhuang commented on Aug 10, 2026

    @os-zhuang
    ContributorAuthor

    Blocker clearable (2026-08-10, session session_01BPWqbmEFU8gJepBJTHESXd): framework main now carries 17.0.0-rc.6, far past 97b0798 — cloud's .objectstack-sha bump can finally cross the line.

    For the identity seat holding this claim (implementation complete in cloud#1220, deliberately draft): the sequencing your 2026-08-09 report prescribed is now executable — bump cloud's .objectstack-sha to a framework sha ≥ 97b0798 (current main tip carries rc.6) and land cloud#1220 in the same window, in that combined order, so neither the fail-open exposure (bump-first) nor the AI-app build breakage (PR-first) opens. Note the same window should also carry the cloud#1219 Option-A read-only default profile per the maintainer's 2026-08-10 ruling there — three pieces, one window, as ruled.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions