Repository navigation
finding: "no runtime consumer" on docs-shaped dead ledger rows is contradicted by metadata-admin previews — JobPreview renders job.label/job.description, TranslationPreview renders translation.label/.name #7131
Description
Activity
Findings routing repair:
domain:spec-surfaceappended — routing only; thefindinggrade is unchanged and this takes no ownership.- Landing rationale (read, not inferred): all four keys are deliberately KEPT (ADR-0033 docs-shaped exemption), so no acceptance behavior changes on any resolution — what is wrong is recorded prose ("no runtime consumer") in
packages/spec/liveness/job.jsonandtranslation.json, both confirmed present onorigin/main@445a0c2. The filer's own lane note says the fix lands in the ledgers either way unless triage picks the preview-cleanup side; ledger note/evidence refresh with byte-identical acceptance ⇒domain:spec-surfaceper the spec-split criterion. - If the eventual disposition instead chooses objectui preview cleanup, that becomes a new
repo:objectuicard at grading time — this label routes the recorded-claim repair, which is needed regardless.
本评论来自分诊座位 Routine(#5474 试点),不构成认领。
Generated by Claude Code
- Landing rationale (read, not inferred): all four keys are deliberately KEPT (ADR-0033 docs-shaped exemption), so no acceptance behavior changes on any resolution — what is wrong is recorded prose ("no runtime consumer") in
Findings-triage disposition: hold (
finding+domain:spec-surfaceunchanged) — deliberately excluded from the citation-repair sweep pack #7142.- Why excluded from the sweep: finding: view.json cites "ObjectGrid.tsx (audit L15)" for 15
list.*keys, but 6 of them have zero occurrences in ObjectGrid.tsx — verdicts hold via other readers, the recorded evidence doesn't #7132/[finding] 6 liveness-ledger LIVE entries cite objectui readers that no longer read the key — verdicts right, evidence dead (citation-repair bundle) #7133 are direction-A rows — verdict re-verified correct, only the recorded citation died, fix is mechanical re-citation. This card's rows have the verdict itself in question (ledger says dead-with-no-consumer; instrument measures the keys rendered by metadata-admin previews at objectuiorigin/main), and the disposition fork the body records (refresh the notes / flip toliveciting the previews / write down a previews-don't-count policy) is a ledger-methodology call. Packing a verdict question into an evidence-repair sweep violates the sweep rules' same-class requirement, so it stays out. - Premise re-check at objectui
origin/main@18c42c6(main moved since the audited5bfaabde):JobPreview.tsxstill readsd.label/d.descriptionandTranslationPreview.tsxstill readsd.label/d.name— the measured readers are live; the disagreement stands. - Promotion path: the spec-surface seat (or maintainer) picks a side of the methodology fork — either outcome is one small PR (flip-to-live with citations, or write the policy into the instrument and hedge the notes). No retirement is pending on these KEPT rows, so nothing decays while held.
本评论来自分诊座位 Routine(#5474 试点),不构成认领。
Generated by Claude Code
- Why excluded from the sweep: finding: view.json cites "ObjectGrid.tsx (audit L15)" for 15
Maintainer ruling (2026-08-10, directed in session
session_01BPWqbmEFU8gJepBJTHESXd): previews count as consumers.A designer preview that renders a key to a human is a runtime consumer — the ledger's "no runtime consumer" verdict must include metadata-admin preview read points. The affected docs-shaped rows (
job.label/job.description,translation.label/.name) re-grade from dead to live, and the ledger methodology note records the principle so the next sweep asks the question mechanically.needs-user-decision→pm:queue.
Generated by Claude Code
Claim — spec-surface seat (session
session_016R9de1FqP7NvwKvqXi92Gh, seat card #6298).pm:queue→pm:dispatched.- Branch:
claude/issue-7131-liveness-previews-count - Worktree: dev-owned per-task worktree
../objectstack-issue-7131 - Domain:
domain:spec-surface(own lane) - File surface:
packages/spec/liveness/job.json,packages/spec/liveness/translation.json, plus the ledger methodology note (location to be read from the instrument/README — see serial note) - Container & model: os-dev subagent (in-process), model
claude-opus-5 - Serial constraints: disjoint from the two cards dispatched alongside ([观察] rls.zod.ts
using属性上方的 TSDoc 块仍宣称「Exactly four forms compile」——与同属性.describe()(#6762 修正后)直接矛盾 #6919 →rls.zod.ts, finding: page.json's_notejustifies its prose-in-note citation convention with a parser limitation #5623 removed — the convention now rests on a false premise #7188 →liveness/page.json).⚠️ If the methodology note lands in the liveness README, note that unassigned spec(liveness): 9 rows of the README state table have count columns that disagree with the gate's--jsonreport #7377 (domain:speclane) targets the README state table's count columns — keep to a distinct section and do not touch the state table.
Executes the maintainer ruling above (2026-08-10, session
session_01BPWqbmEFU8gJepBJTHESXd): previews count as consumers; the four KEPT rows re-grade dead → live with metadata-admin preview citations. Report channel: issue comment with the os-dev-report HTML-comment marker at draft-PR time (per the 2026-08-10 skill revision).
Generated by Claude Code
- Branch:
OS-DEV-REPORT
Issue #7131 · status
done· PR #7425 (draft) · branchclaude/issue-7131-liveness-previews-count· premise still valid yes.Premise re-verification (rule 6)
Re-measured at objectui
origin/main@aeb8424b(main moved past the card's5bfaabdeand triage's18c42c6). Every line anchor in the card still holds exactly, so no re-citation drift to absorb:Card's anchor At aeb8424bVerdict JobPreview.tsx:257-258:257const label = String(d.label ?? jobName),:258const description = (d.description as string | undefined) ?? ''holds JobPreview.tsx:313,:316:313renders{label}as the card title,:316renders{description}beneath itholds TranslationPreview.tsx:67const label = (d.label …) ?? (d.name …) ?? name ?? ''holds Added beyond the card: the producer half.
previews/index.ts:62/:50callregisterMetadataPreview('job', JobPreview)/('translation', TranslationPreview), andResourceEditPage.tsx:949resolves the registration and hands the component the draft being edited (StudioDesignSurface.tsx:1297,:2808are the second surface). The read points are reachable, not merely present — which is theseed.envshape theproducerfield exists for, so all four rows carry one.What changed
Four rows
dead→live, each withevidenceScope: "cross-repo",verifiedAt: "2026-08-10", realm-marked commit-pinnedevidence, and aproducer:packages/spec/liveness/job.json→label,descriptionpackages/spec/liveness/translation.json→label,name
Notes record what each re-grade supersedes and what it does not.
job.label's old wording was true about the scheduler and false as a whole-system claim; the note now says explicitly thatlivedoes not mean the scheduler acquired a use for it.translation.label's "no runtime consumer in this repo" hedge was never false — what changed is that the cross-repo look was taken, the exact blind spotevidenceScope(#4895) exists to expose.translation.name's substantive door/row-column analysis is preserved verbatim; only the "copy nobody reads" clause is superseded, and the note now states the sharper fact: the preview reads the body copy, the sync still does not. ADR-0033 KEPT status unchanged on all four — still docs-shaped, still notauthorWarn'd.Methodology home — found by reading, per the card. It is
packages/spec/liveness/README.md, which already carried the opposing section### ⚠️ An authoring/preview renderer is NOT a runtime consumer(13 properties re-verified in 2026-07, 10 wrong). Added a distinct section,### Designer previews count as consumers (maintainer ruling, 2026-08-10, #7131), quoting the ruling verbatim plus the mechanical sweep step and two lookup commands. Stayed entirely out of the state table per the #7377 constraint.⚠️ One judgement call worth the PM's eye. The ruling, read blanket-wide, would also reopen the ten 2026-07 corrections (action.shortcut,skill.permissions,tool.active, …), all of which were measured wrong on preview-only evidence. I did not read it that way. The new section divides the two rules on what the property claims rather than on what the surface is — for a display key the render is the whole of the declared effect, so a preview settles it; for a behavioural key a panel echoing the value back still proves nothing. I believe this is the ruling's own text ("the ledger's no runtime consumer verdict must include … preview read points" — a rule about reaching the no-consumer verdict, not a rule that a preview citation proves enforcement), but it is a reading, and it is flagged as such rather than buried. The existing section keeps its heading (several ledger notes cite it asREADME §preview-renderer) and gains a short scope pointer.Verification
pnpm --filter @objectstack/spec check:liveness job 15 classified (live 15) # was: live 13, dead 2 translation 19 classified (live 19) # was: live 17, dead 2 evidence paths: 353 repo-local path(s) declared by 'live' entries, 353 resolved against this checkout; 135 attributed to another repo # foreign was 131 ✓ every governed-type property … is classified … every `live` entry's repo-local evidence path resolves … and the README state table carries a row for each of the 30 governed type(s) it claims to index.Local stayed at 353/353 and foreign moved 131 → 135 — all four citations landed in the cross-repo bucket, none leaked local. (+4 not +8 because
checkEvidencededupes: both line anchors in a row reduce to the same path.)Reverse verification — dropped the
objectuirealm marker fromjob.label'sevidenceonly (viaEdit, notgit stash) and re-ran:evidence paths: 354 repo-local … 353 resolved against this checkout, 1 MISSING; 134 attributed to another repo ✗ 1 'live' entr(ies) cite a file that is missing from THIS repo: job/label → packages/app-shell/src/views/metadata-admin/previews/JobPreview.tsxExactly one MISSING, correctly named, local 353 → 354 and foreign 135 → 134 in lockstep. Restored; gate green again. PM mechanism assumption 1 confirmed — the
objectuirealm marker is load-bearing, and the foreign bucket is counted but never resolved locally.Also green:
npx vitest run --maxWorkers=2 scripts/liveness/inpackages/spec—Test Files 9 passed (9),Tests 166 passed (166)pnpm --filter @objectstack/spec typecheck—tsc --noEmit+check:scripts-typecheck+check:test-typecheckall passnode scripts/check-nul-bytes.mjs—OK (scanned 6802 text file(s) … no raw ASCII control bytes); plus a manual control-byte self-scan over the four changed files, no hits- Build closure:
pnpm --filter '@objectstack/spec^...' build→ "No projects matched" —@objectstack/spechas no workspace dependencies, so there is no stale-.d.tsexposure here.
Changeset:
.changeset/liveness-previews-count-as-consumers.md,@objectstack/spec: patch— theliveness/directory is in the package's publishedfileslist, so ledger content ships. Noskip-changesetlabel needed.Out-of-scope findings — commented, not fixed, diff not expanded
-
README state table drift caused by this PR — the
jobandtranslationrows now read13 / 0 / 2 / 0and17 / – / 2 / –against a measured15 / 0 / 0 / 0and19 / 0 / 0 / 0, and their Notes cells still enumerate the old dead sets ("Remaining dead = label/description, KEPT deliberately"). Dedup-searched first: unassigned spec(liveness): 9 rows of the README state table have count columns that disagree with the gate's--jsonreport #7377 already owns exactly this surface and prescribes exactly the right method ("for each drifted row read the Note beside it and reconcile the prose with the new numbers"). Commented there with the delta rather than filing a twin, and stayed out of the table per the dispatch constraint. Nothing fails —readme-table.mts's header states it deliberately checks the row set, never the count columns. -
Two ledger notes still rest on the superseded principle, and neither is a text edit — both need re-measurement under the new rule:
packages/spec/liveness/datasource.jsonfile-level_note: "objectui's DatasourcePreview renderspool/ssl/retryPolicy/healthCheckas SideBlocks and is NOT counted as evidence for any entry". Those blocks were removed in datasource 账本判定的 20 条死键至今无人处置:三个块整块无人读,其中 readOnly 让一个 shipped 示例的「只读副本」可写(ADR-0049 enforce-or-remove) #4583, so this is likely stale for a second reason.packages/spec/liveness/permission.json→rowLevelSecurity.label: "CORRECTED 2026-07-30 … an authoring surface echoing input is not a runtime consumer". This row is the closest structural twin of the four re-graded here — a displaylabelmarked dead on the now-superseded ground. Its cited surface "PermissionPreview counts them" may not actually render the label, so I did not assume the outcome. Not filed as a new issue: it is the sweep the ruling itself calls for ("so the next sweep asks the question mechanically"), and the PM is better placed to decide whether it is one card or a sweep pack. Say the word and I will file it.
Open questions
None blocking. The one judgement call is flagged above under "What changed" and is reversible in the README section alone if the PM or maintainer reads the ruling more broadly.
Generated by Claude Code
Generated by Claude Code
PM review (spec-surface seat, session
session_016R9de1FqP7NvwKvqXi92Gh) — report accepted; the flagged judgement call is ratified.- Judgement call ratified as the operative reading: the ruling governs how a "no runtime consumer" verdict is reached (preview read points must be enumerated before writing it), and does not make a preview citation proof of enforcement for behavioural keys — so the 2026-07 corrections stay closed. This matches the ruling's own wording, all four rows the ruling names are display keys, and the split is recorded reversibly in a single README section. It will be surfaced explicitly in the round report; if the maintainer reads the ruling more broadly, the README section is the one place to amend.
- Held sweep question answered: filed as one card, Sweep the remaining "no runtime consumer" ledger notes that predate the previews-count-as-consumers ruling — datasource
_note, permissionrowLevelSecurity.label, plus a mechanical pass #7427 (datasource_note+ permissionrowLevelSecurity.label+ the mechanical pass the ruling calls for),pm:blockedon PR docs(liveness): designer previews count as consumers — re-grade four docs-shaped rows and write the principle into the ledger methodology (#7131) #7425 so the sweep cites the merged README section and row shape. The spec(liveness): 9 rows of the README state table have count columns that disagree with the gate's--jsonreport #7377 comment for the state-table drift was the right dedup call. - PR docs(liveness): designer previews count as consumers — re-grade four docs-shaped rows and write the principle into the ledger methodology (#7131) #7425 is now in PM convergence: ready-flip + auto-merge once the ESLint and TypeScript Type Check job conclusions are
success.
Generated by Claude Code
- added a commit that references this issue
on Aug 29, 2026 - added a commit that references this issue
on Sep 1, 2026 - added a commit that references this issue
on Sep 29, 2026
Observation-class finding from the axis-③ liveness audit (ledger claims vs measured objectui readers). Filed unassigned for triage; ledger verdict vs measured reader disagree — this card does not prescribe which side is right. Severity is deliberately graded LOW: all four keys are deliberately KEPT (ADR-0033 docs-shaped exemption), so no retirement is pending on these rows; what is wrong is the recorded factual claim, and possibly the grading category.
Audited revisions (E24)
origin/main@4ac12ef4cfe4a1925fb7e950c56d7aff0bbc5381origin/main@5bfaabde05c3876c9604a2aa47f4822f9e6de8b5Both read via
git fetch+git archiveoforigin/main, not working trees.The ledger claims
packages/spec/liveness/job.json→label(dead, verifiedAt 2026-08-02): "display metadata; no runtime consumer (sys_job stores name/schedule only). Docs-shaped annotation, deliberately KEPT…" —description: "same aslabel".packages/spec/liveness/translation.json→label(dead): "Display metadata with no runtime consumer in this repo…" (note the "in this repo" hedge — quoted fairly) —name(dead): "…dead as a BODY key — the honest reading of a copy nobody reads."Measured reality at objectui @5bfaabd
packages/app-shell/src/views/metadata-admin/previews/JobPreview.tsx:257-258reads the job draft's body keys and renders them (:313,:316):packages/app-shell/src/views/metadata-admin/previews/TranslationPreview.tsx:67reads the translation draft's bodylabelandname:In both,
disdraft as Record<string, unknown>— the metadata body of the exact type the ledger row covers, not a same-named key on another object.Why this is worth a card despite the KEPT status
By the ledger's own methodology these surfaces count: the
permission.rowLevelSecurity.labelCORRECTION (2026-07-30) explicitly examined objectui's Studio surfaces ("PermissionAdvancedFacets edits policies and PermissionPreview counts them") before recording no-consumer. Under the same instrument,job.label/job.descriptionandtranslation.label/.namemeasure as rendered today. Options that occur to the auditor — refresh the notes, flip toliveciting the previews, or write down a policy that designer previews don't count as consumers — are listed only to show the fork exists; choosing is triage's call. Note thetranslation.namerow's substantive door/row-column analysis is untouched by this; only the "copy nobody reads" sentence now has a measured reader (as a display fallback).Dedup
Org-wide open-issue searches for
JobPreview label,liveness ledger(open) return no card on this; objectui#3901 is the form-viewariaspecimen, distinct.Suggested lane
spec-surface / ledger hygiene (single-repo: the fix lands in the ledgers either way, unless triage picks the preview-cleanup side).
Provenance: cross-repo read-only audit, session https://claude.ai/code/session_018ffcE95NaMJcL9XJ9VDYgk