Skip to content

feat(spec)!: object-gantt markers, object-timeline mapping and both forms' fields take the shape each block reads; five objectui-held contracts reported as forks (#21464, S-objectui-held) - #21699

Merged
objectstack-fleet[bot] merged 6 commits into
mainfrom
claude/issue-21464-s-objectui-held
Oct 4, 2026
Merged

objectstack-fleet[bot] merged 6 commits into
mainfrom
claude/issue-21464-s-objectui-held

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Part of #21464
Clause-②: yes (narrowing)

What this does

The S-objectui-held stage of the ComponentPropsMap z.unknown() close-out, per the claim 5976829576, the stage-5 landing record 5976140848, the seat answers 5963787404 and 5969669440, the stage-5 ACCEPT 5975923386 and domain:devx's pointer 5974144504. The stage took its own value census first (below), then wrote down and typed the contracts that have one viable shape. Under the stop valve, it holds the five contracts (seven ledger lines) that have more than one shape, records them in the enumeration pin, and reports them on the card as forks. Read points are at the .objectui-sha pin ab1879721595. Every cited reader is byte-identical at objectui main 94985a92ba; the two cited @object-ui/types declaration files changed elsewhere, and their cited lines are identical.

member was now read point at ab1879721595
object-gantt markers z.array(z.unknown()) strict { date, label?, color? } entries, date a string (module-private factory objectGanttMarker()), with aliases title / text / name to label and colour / stroke to color ObjectGantt.tsx:2505 hands schema.markers to GanttView, which re-bases date (GanttView.tsx:913-924), drops a marker whose date does not parse or falls outside the range (:2394-2413), and draws label and color (:2407, :4083-4100, SVG :3320-3332). objectui declares the authored marker as exactly this shape (types/src/objectql.ts:3787-3794, zod mirror types/src/zod/objectql.zod.ts:2738-2746)
object-timeline mapping z.unknown() strict { title?, date?, description?, variant? }, each a field name (module-private ObjectTimelineMappingSchema), with aliases from the flat titleField / dateField / startDateField / descriptionField / variantField ObjectTimeline.tsx:551 (title), :576 (date), :578 (description), :579 (variant). objectui declares the same four strings on the component prop (:254-259) and in TimelineMappingSchema (:144-149)
object-form fields z.array(z.unknown()), held at stage 3 field-name strings (formFieldNameList()). A { name } or { field } object entry is refused with what to write instead ObjectForm.tsx:961-981, flatFields.ts:68-79. objectui declares ObjectFormSchema.fields: string[]. The form still draws a STORED { name } entry by its name (:972, flatFields.ts:72) and skips any other object entry with a warning (:978)
object-master-detail-form fields z.array(z.unknown()), held at stage 3 the same list (one schema, pinned) handed to the parent form verbatim, MasterDetailForm.tsx:1693

The fields hold's exit. objectstack-ai/objectui#11550's triage ruling (5969880008 there) retired the { name } entry from objectui's authoring faces, and its closing paragraph says this card "types object-form and master-detail fields as names once its .objectui-sha covers this landing". The pin covers both code landings: objectui 806f327 (the fixtures respelled) and dbd1081 (the registration descriptions and the warning text). merge-base --is-ancestor exits 0 for each. The guide's own respelling (0a53c67) is on objectui main only. Measured at both trees, the only refused values are fixtures probing the read (census below).

No new export. The three new shapes are module-private. No new member carries a default or a transform, so each parsed value is the authored one. The gantt marker is a factory the row calls, as masterDetailDetailEntry() is, and not a lazySchema proxy. A bare proxy used as an array element is never forced by alias-integrity.test.ts's walk, which skips def values that are functions. The first full-suite run caught exactly that: alias integrity — coverage listed ui/component.zod.ts:6611 (this object-gantt marker) as unreached. The factory form is green.

Held as forks (the stop valve)

Each of these has two or more viable spec shapes that no existing ruling or seat answer decides. Each keeps its hold. The enumeration pin's ledger now files each under a new fork stage that names the shapes, and §2 checks that every fork line names at least two different shapes. The emptied objectui-held stage leaves STAGES. Each fork is reported in this stage's os-dev-report open_questions with its census.

  • object-metric drillDown.report: direction A's premise is disproved by measurement, so it is reported as a fork and takes no shape, as the ACCEPT 5975923386 directs. Premise (1) holds: the one drawn report the census finds (objectMetricDrillDownMembers-8071.test.tsx:282, a dataset-bound summary report with name and label) parses through ReportSchema. Premise (2), that isDatasetBoundReport's two arms are exactly what ReportSchema admits, fails in both directions (measured by parse, this branch's source):

    value drawer (isDatasetBoundReport) ReportSchema
    { name, label, type: 'joined', blocks: [{ name }] }, no block binds a dataset lists the records ACCEPT
    { dataset: 'sales' }, no name / label / values draws the report REFUSE
    { name, label, dataset: 'sales' }, no values draws the report REFUSE (custom at dataset)
    { name, label, type: 'joined', dataset, blocks: [...] } draws the report REFUSE (custom at dataset)

    The first row is the silent-fallback class this card closes. It comes from ReportSchema itself: a joined block's dataset is optional, although the schema's own refinement comment says each block is "dataset-bound". objectstack validate passes such a report with exit 0, while a bound block naming an undeclared dataset is refused (chart-dataset-unknown). See Acceptance notes.

  • object-form customFields: objectui's runtime FormField (types/src/form.ts:1770) is open (an index signature beside forty-five members, :1906), and eight of its members are the grid widget's snake_case keys (min_rows, allow_add, …), which this package's camelCase rule for config keys does not admit as written.

  • object-form and object-master-detail-form sections: objectui#11550 KEPT the inline runtime field in a section ("shape 3", sectionFields.ts:369-370, declared ObjectFormSection.fields: (string | FormField)[]), so this waits on customFields's fork for its third entry arm.

  • object-timeline items: a feed entry's content is child schema nodes (a slot position the page walks would judge, or an opaque member), and the arm an entry must match is chosen by the parent's variant (objectui's row-level refinement, or a plain union of the arms).

  • action:group / action:menu members: measured from the reads, the key set is mostly action:button's, keyed by type. It also takes keys the rows leave undecided: outcomeMessages (recorded on action:button as "a contract decision, not a pin re-measure"), a member className, the member's own properties.params bag (static-params.ts:142-160) and endpoint (refused on the rows since finding(spec): action:button / action:icon accept endpoint, the key ActionSchema refuses with the prescription endpoint → target: one concept, two verdicts in one release #21005).

The object-kanban conditionalFormatting hold (held-for-decision) is not in this stage's member list and is untouched. Its carrier, objectstack-ai/objectui#11522, is now in state completed (2026-10-03), so its exit may be readable. That is for the seat.

The census

A writer is a value written on the block: a page-component node (an object literal naming the type, flat or in properties, a literal annotated or asserted with the block's objectui type, a direct parse through the row), the block's React component with the member as a prop or inside schema={{…}}, or the argument of a same-file helper that mounts one (helpers found through a block literal or the block's JSX in their body, including one spread from a const; positional parameters resolved at every call site). Values resolve through same-file constants and spreads. Instrument: a TypeScript-AST walk over .ts .tsx .js .jsx .mjs .cjs .mts .json .yaml .md .mdx (fenced code parsed). For the typed members, a text search for the member key in every file naming the block found what the walk does not reach, and each hit was read by hand. Cross-check: the walk reproduces stage 5's drillDown population exactly (26, 25 static).

corpus markers mapping fields, both forms
objectstack 7d0781482d (examples/, packages/, content/, skills/, apps/, docs/, 9306 files) 0 1 · parses 4, all master-detail · all parse
objectui pin ab1879721595 (whole tree, 10267 files) 9 · 8 parse · 1 refused 9 · all parse 73 · 55 parse · 7 refused · 11 not static
objectui main 94985a92ba (7564 files; the release deleted 2726 changesets) same 9 same 9 73 · 56 parse · 6 refused · 11 not static
hotcrm 4054ec2680, cloud b2d7a7f6f8 0 0 0

objectstack writers: packages/spec/src/ui/component-element-navigation-17987.test.ts (mapping: { title, variant }). For master-detail fields: the showcase's project-workspace.page.ts, content/docs/protocol/objectui/layout-dsl.mdx, and two test copies (packages/lint/src/validate-component-props.test.ts, packages/spec/src/ui/component.test.ts). All are field names.

objectui refused values, under the writer test (5966636964):

refused value where drawn or probe
markers: [{ date: 5 }] types/src/__tests__/gantt-declared-keys.test.ts:168 compile-time refusal probe (@ts-expect-error)
fields: [{ field: 'note' }], [{ field: 'sent_at' }] plugin-form/src/__tests__/objectFormFieldsMembers-8071.test.tsx:140, :199 probes: the form skips the entry with a named warning
fields: [{ name: 'note' }] ×2 objectFormFieldsMembers-8071.test.tsx:177, :182 probes: objectui's own mirror refuses it; a STORED one still draws
master-detail fields: [{ field: 'note' }] topLevelFieldsWarnCoverage-8847.test.tsx:110 probe: the warning fires
master-detail fields: [{ name: 'note' }, 'status'] topLevelFieldsWarnCoverage-8847.test.tsx:258 probe: a STORED entry still draws
fields: [{ name, label, type, required }, …] (pin only) skills/objectui/guides/page-builder.md the retired guide example, respelled to names on objectui main

Not writers: five markers arrays mount GanttView, the runtime chart, directly (GanttView.virtual.test.tsx ×2, GanttView.dateOnlyZone-10866.test.tsx, the plugin README's GanttView example, demo/main.tsx). Fourteen fields matches are object definitions or permission maps whose own fields key the walk read as the block's (ObjectForm.effectiveOps ×3, ObjectForm.managedEdit ×3, ObjectForm.mobileFullscreen ×3, drawerFormSectionDescription-9834, objectFormNumericStep-9574 ×2, LineItemsPanel.fieldWriteGate-10163 ×2). The 11 that are not static are run-time hand-offs (AppContent, useActionModal, RecordFormPage, ViewPreview, StudioDesignSurface, DrawerForm, EmbeddableForm, ModalForm, ObjectForm.tsx:387, MasterDetailForm.tsx:1693, ObjectView). None passes through the component-props gate.

The forks' census, both objectui trees identical. objectstack, hotcrm and cloud author none of these, except one items and three sections (strings) in objectstack.

  • drillDown.report: 3 values. The one drawn report parses through ReportSchema; the two it.each probes ({ note }, the retired objectName form) are not drawn and are refused.
  • customFields: 27 values (24 static, 31 entries), every entry keyed name with label and type. One carries group and one defaultValue, keys outside FormField's forty-five that ride its index signature. No entry writes a snake_case grid key.
  • sections: object-form 165 values (99 static); 192 string entries, 3 { field } entries and 7 shape-3 inline runtime fields (plugin-form/README.md's wizard, submitTargetRefusal.test.tsx ×3). Master-detail: 13 values, strings only.
  • items: 14 values (11 static): 8 feed entries and 5 gantt rows, none with content.
  • action:group / action:menu: 40 / 19 values (12 / 6 static, 15 / 6 members). The keys used are name, label, type, locations, target, bodyExtra, bodyShape, objectName, and one autoTrigger in a host auto-trigger test. None uses an undecided key.

Changes

  • packages/spec/src/ui/component.zod.ts: objectGanttMarker() (with the reason it is a factory), ObjectTimelineMappingSchema, formFieldNameRefusal and formFieldNameList() with their docblocks. The four members are typed. The held members' docblocks now record each fork, re-read at ab1879721595: the drill report with the measured disagreement, customFields, both sections, items and actionMemberList. The gantt and timeline row docblocks no longer say markers / mapping stay open.
  • packages/spec/src/ui/component-objectui-held-typed-members.pin.test.ts (new): §1 15 byte-identical parses of the census writers, plus the absent-member case; §2 17 refusals by code and path, plus the two prescriptions, the no-prescription control and the alias pointers; §3 each shape's exact member set, and the two forms' fields answering identically, messages included; §4 the three D3 ids.
  • packages/spec/src/ui/component-props-unknown-members.pin.test.ts: four lines leave the ledger (markers[], mapping, both fields[]). Seven become fork lines naming their shapes (customFields, both forms' sections, items, both action containers' members, and the drill report, which was objectui-held). The objectui-held stage is replaced by fork, and a §2 case is added.
  • packages/spec/src/ui/component-form-family-typed-members.pin.test.ts: the header records this stage's outcome.
  • packages/spec/src/migrations/entries/semantic/18.ui-object-gantt-markers-typed.ts, 18.ui-object-timeline-mapping-typed.ts, 18.ui-object-form-fields-names-typed.ts (new), and packages/spec/src/migrations/registry.ts: three step-18 rationale fragments at orders 74, 75 and 76 (73 is the last taken on main), inserted where each id sorts. The semantic region is regenerated by gen:migration-registry. No D2 conversion and no RETIRED_KEYS_BY_MAJOR row: page-component properties is not parsed on the save or load path, and the refused values are nested member values.
  • Regenerated by check:generated --fix, which proved only these two stale: content/docs/references/ui/component.mdx and docs/audits/2026-07-unknown-key-strictness-ledger.counts/ui.md (ui/ 196 → 198 sites, +2 strict).
  • .changeset/21464-component-props-objectui-held-typed.md: @objectstack/spec minor, BREAKING banner, the Clause-② line, FROM → TO, the census, and the ADR-0087 marker registering the three ids.

Measurements

Head 723df54741, base 7d0781482d. Heavy runs went through scripts/pm/os-verify-lock.sh, and every exit code was captured before any pipe.

  • Red first, on the published @objectstack/spec@17.6.0 (the npm tarball, ComponentPropsMap[type].safeParse). Each of these is ACCEPTED there: markers: [{ date: 5 }], [{ label: 'Deadline' }], [{ date, title }]; mapping: 'subject', { titleField: 'code' }, { title: 5 }; object-form fields: [{ name, label, required }], [{ field: 'note' }], [5]; master-detail fields: [{ name: 'note' }, 'status']. Each is refused on this branch, pinned in §2.
  • pnpm --filter @objectstack/spec test at 723df54741: exit 0, Test Files 611 passed (611), Tests 18157 passed, 1 todo, nothing skipped. An earlier run at a88b9f3e4a read 610 passed and 1 skipped: root-entry-type-nameability.pin.test.ts skips by design while dist is stale, and it ran here after a rebuild.
  • pnpm --filter @objectstack/spec typecheck at a88b9f3e4a (only a test comment differs at the head): exit 0, check:test-typecheck: OK (52 files / 246 errors / 135 signatures held). tsc -p tsconfig.test.json --listFilesOnly names the three touched pins.
  • Build and generated artifacts: the spec build is green, including the eager gen:schema pass. check:generated proved check:docs and check:strictness-ledger stale, --fix regenerated those two only, and the re-check is green. A later turbo run build --filter=!@objectstack/docs built 72 tasks, all successful.
  • Consumers: pnpm --filter @objectstack/lint test passed 119 files and 5622 tests. The 5 skipped tests read lint's own built dist, which this worktree had not built yet. After the turbo build, lazy-deps, runtime-lazy-deps and validate-component-props passed 61 of 61. pnpm --filter @objectstack/example-showcase validate printed "Validation passed".
  • The public door, both ways (validateComponentProps from lint src over the built spec, one block per page). These report nothing: a marker with date / label / color, a { title, variant } mapping, form and master-detail name lists, and an arbitrary drill report (still held). These are reported: markers.0.date: 5 as component-props-invalid; a marker title as component-props-unknown-key at properties.markers.0.title, its message naming label; mapping: 'subject' as component-props-invalid; mapping.titleField as component-props-unknown-key; a form { name: 'email', … } entry as component-props-invalid at properties.fields.0, with "write 'email', not an object"; and a master-detail { field: 'note' } entry with the section-vocabulary prescription.
  • Ablation, one leg per narrowing, on the committed tree (a88b9f3e4a). Each leg used node scripts/ablation-replace.mjs in wrap mode, inside a driver with its own EXIT INT TERM restore trap on the absolute path, an empty hash read as failure, and HEAD blob 1a6b65102a:
    • markers → z.array(z.unknown()): anchor x1 → x0, blob → 1f6bdbd1a9. Red: 9 failed, 86 passed. The enumeration pin's §1 received exactly [ "object-gantt markers[]" ] and its census-equals-ledger control read 88 against 87. The companion pin failed its five marker refusals, the alias pointer and the §3 member set.
    • mapping → z.unknown(): blob → 2ee8a60e25. Red: 8 failed, 87 passed. §1 received [ "object-timeline mapping" ], 88 against 87, plus the four mapping refusals, the alias pointer and §3.
    • object-form fields → z.array(z.unknown()): blob → 5211b43913. Red: 9 failed, 86 passed. §1 received [ "object-form fields[]" ], 88 against 87, plus the four refusals, both prescriptions and the §3 two-forms identity.
    • Restore after every leg: blob equals HEAD and git diff HEAD is empty. The pins import ./component.zod from source, so no build or dist preflight sits between mutation and run.
  • Derived gates at 723df54741: node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack (no paths) derived 114 commands, all exit 0. --ran printed "114 derived, 114 run, 0 NOT-MEASURED, 0 UNRUN". The first pass reddened only check-spec-docblock-symbol-anchors (and its --self-test) on a line anchor in the new pin's comment; it now cites the file. Every command was re-run on the final head.
  • check-widening-tells over the branch diff: --declaration no exits 4 with seven T1 tells, every one a key inside a former z.unknown() bag (the marker's three, the mapping's four). --declaration yes exits 0.
  • Narrowed lint: eslint --no-inline-config --format json over the 8 changed TypeScript files reports 8 files, 0 errors, 0 warnings. Population comes from eslint's own --print-config: those 8 resolve a config, and the changeset, component.mdx and the counts page resolve undefined. Invariance: eslint.config.mjs never enables type-aware linting (its own text, about line 327), so this diff cannot move a verdict on an untouched file. The full pnpm lint is CI's.
  • NOT MEASURED: the Console Pin Gate, the Dogfood Regression Gate and the full pnpm lint, because they are CI-owned; objectui was read at the pin and at main, not built against this spec. CI on this PR was not waited on.

Acceptance notes

  • ReportSchema admits a joined report with no dataset-bound block. objectstack validate exits 0 on reports: [{ name, label, type: 'joined', blocks: [{ name, label }, { name, label }] }]. The same report with a bound block naming an undeclared dataset is refused by chart-dataset-unknown. objectui's report renderer sends it past isDatasetReport (plugin-report/src/DatasetReportRenderer.tsx:208-214) to the pre-9.0 presentation bridge (ReportRenderer.tsx:108), which issues no query. The schema's own refinement comment says a joined report "carries its data on blocks (each block dataset-bound)". This is reported in the dev report for the seat to file, and it is the cheapest route out of the report fork.
  • mapping.title / mapping.date are second spellings of timeline.titleField / timeline.startDateField, read between those and the flat fallbacks. They are typed here as objectui declares them; whether to retire them is a different question. Noted, not filed.
  • A marker date is any string, as objectui declares it and as the same row's holidays / minDate / maxDate are. An unparseable date is still accepted and draws no line. Noted, not filed.
  • objectui's next @objectstack/spec bump: its block schemas take these rows by reference (propsBag over stripImportedDefaults(...)), but no objectui test parses a refused value through them. The refused values are fixtures that mount the component or parse objectui's own mirror. objectui source reads none of the four members' narrowed types.

Generated by Claude Code

@github-actions github-actions Bot added size/xl documentation Improvements or additions to documentation protocol:ui tests tooling labels Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

11 anchor(s) derived from 1 changed package(s); no hand-written page names any of them, so this run has nothing to list — not a clean bill of health. This check sees only pages that NAME a derived anchor: one that documents this change in prose, or enumerates it in an authoring dialect, names none and stays invisible to it on every run.

What this run could not see
  • 6 name(s) were too generic to anchor anything (single lowercase words)
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 138 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 83e2feeb46be3c22b7139b01114612e93afcf412 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 0b902788dd7ccc2935c5468004c5db734a782c64 — the merge of head 723df5474159ed4b2100cd3742a6874f7e22fd69 into base 83e2feeb46be3c22b7139b01114612e93afcf412, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 0b902788dd7ccc2935c5468004c5db734a782c64 && git checkout 0b902788dd7ccc2935c5468004c5db734a782c64
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 83e2feeb46be3c22b7139b01114612e93afcf412 723df5474159ed4b2100cd3742a6874f7e22fd69 && git checkout -B drift-repro 83e2feeb46be3c22b7139b01114612e93afcf412 && git merge --no-ff 723df5474159ed4b2100cd3742a6874f7e22fd69

node scripts/docs-audit/affected-docs.mjs --json 83e2feeb46be3c22b7139b01114612e93afcf412

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

⛔ merge queue 构建失败 — 先分诊,再决定要不要重排

队列构建 37185775211 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集),
所以失败的测试可能在本 PR 没碰过的包里 —— 那不是重排能修的。每次盲目重排都会让排在后面的所有 PR 重建一轮。

失败的 job(日志抽取,best effort):

  • Console Pin Gate — 失败步骤: Build the Console SPA at the pinned objectui SHA

    ✗ Built console still carries the PUBLISHED @objectstack/spec.
    

↳ 失败原因 是判读的关键:超时(Test timed out in … / Hook timed out in …)多半是负载/时序,不是本 PR 的回归;
断言(AssertionError: …)才指向真实的行为改变。两者的 FAIL 行长得一模一样,只有这一行能区分。

⚠️ 断言这一侧有一类例外,判据是断言在测什么,不是它是不是 AssertionError。 断言的对象是产品行为(一个值、一个形状、一次拒收)⇒ 照上面读:真实的行为改变,去查,⛔ 不要重排掉;
断言的对象是这次实验自身的有效性前提(跑完的耗时、负载下的先后、任何只在时间预算内才成立的条件)⇒ 它跟超时是同一类,同样对负载敏感,重排一次是合法的判别手段。
识别是机械的:断言的消息或它比较的值本身点名了一段时长、一个时间戳、一个耗时计数。实测过的一对 —— AssertionError: SecurityPlugin.init() ran: expected false to be true 测的是产品行为(真回归);
AssertionError: this run took over a second, so second-precision stamps could have differed too: expected 1006 to be less than 1000 测的是实验前提:它守护的那条不变式当时是绿的,同一个 head 原样重排一次即成功。
穿着 AssertionError 外衣的时间测量,仍然是时间测量。(⛔ 这只改「怎么读一次红」,不改「哪些测试可以重排」——后者由别处管。)

跨 PR 相同签名(24h,按失败测试文件聚合):

  • ⚠️ 本次没有可用的聚合签名(日志里没有能解析出测试文件名的 FAIL 行)—— 这不是「没有同签名的其他 PR」,是这一轮没测到。跨 PR 聚合本次不可用,请手工比对其他 PR 的同类评论。
  • ⚠️ 24h 评论账本没读完(超过 5 页仍未读到窗口尽头),所以上面的「不同 PR 数」是下界,不是全量。

历史信号:

  • 本 PR 过去 24h 无队列失败记录(首次)。
  • 过去 24h 队列共有 1 个失败构建(不含本次)。

分诊清单:

  1. 失败测试在本 PR 改动的包里 → 真回归,修 PR。
  2. 失败测试与本 PR 无关 → 看上面的「跨 PR 相同签名」;已有汇总 issue ⇒ flaky/环境问题实锤,去那张 issue 上谈,修好前重排只会再烧一轮全队列。
  3. 两者都不是 → 可能与同组 PR 语义冲突;等前面的 PR 落地或失败出队后再重排一次即可,不要连续重排。

Generated by Claude Code · merge-queue-triage workflow (#4859)

akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…t blocks[i].dataset, naming the block (objectstack-ai#21702) (objectstack-ai#21712)

Fixes objectstack-ai#21702
Clause-②: yes (narrowing)

Triage direction `5977861131` (enforce), claim `5977924610`. The joined
arm of `ReportSchema`'s refinement now refuses each block of a `joined`
report that binds no `dataset`, at `blocks[i].dataset`, naming the
block, with the prescription to bind the block to a dataset. The
refinement comment "each block dataset-bound" and the reports guide's
type-table cell "(each block dataset-bound)" were declarations; they are
now enforced.

## What changes

- **The refusal** (`packages/spec/src/ui/report.zod.ts`). A per-block
arm inside the joined branch of `ReportSchema`'s `superRefine`, right
after the existing "needs `blocks`" check. For each block whose
`dataset` is undefined it adds one `custom` issue at `['blocks', i,
'dataset']`. The message comes from a module-private builder,
`joinedBlockDatasetRequired`, worded like the neighbouring joined
refusals:

  ```text
a `joined` report draws each block from that block's own `dataset`, and
block `NAME` binds none, so nothing queries it and it draws no rows.
Bind the block to a dataset: set its `dataset` to the dataset whose
measures (`values`) and dimensions (`rows`) it shows.
  ```

`NAME` is the block's `name`. A block whose `name` is empty (its own
`too_small` issue, which does not stop the refinement) is named by
position instead, as `blocks[1]`.
- **What stays accepted.** `JoinedReportBlockSchema.dataset` stays
`.optional()`: `blocks` is read on a `joined` report only, so the
requirement lives on the joined arm, and a block on a non-joined report
is not judged (pinned). No type, export or JSON Schema key changes. The
block's `dataset` `.describe()` now reads "Dataset name to bind
(ADR-0021); a joined report refuses a block without one", and
`content/docs/references/ui/report.mdx` is regenerated with `gen:docs`
(two table rows).
- **The ADR-0087 kit**, in objectstack-ai#21687's shape:
- the D3 semantic entry
`entries/semantic/18.ui-report-joined-block-dataset-required.ts`;
- its step-18 rationale fragment in `STEP18_RATIONALE` at **order 77**,
inserted where its id sorts. 77 is the next free order: the highest on
`main` is 76, re-read at `7e0066af7a` just before this PR. objectstack-ai#21699 (74 to
76) and objectstack-ai#21698 landed before this branch's base `16d241a6af`, so no
merge was needed;
  - `registry.ts` regenerated with `gen:migration-registry`;
- one BREAKING `@objectstack/spec` `minor` changeset,
`.changeset/21702-joined-report-block-dataset-required.md`, carrying the
`Clause-②` line, the `adr-0087: registered
ui-report-joined-block-dataset-required` disposition marker and a FROM →
TO table.

The fragment and entry text state each decision in words and carry no
tracker number. No tombstone (no key is removed) and no D2 conversion
(only the author knows which dataset a block was meant to show).
- **`content/docs/ui/reports.mdx`: no edit.** No sentence there became
false; the type-table cell became true. See Acceptance notes.

## Census, at base `16d241a6af`, before any edit

`git grep` for a `type: 'joined'` report across `examples/**`,
`packages/**`, `skills/**`, `content/docs/**`, `docs/**`, `scripts/**`
and `apps/**` gave 33 lines in 15 files: CHANGELOG quotations, the
spec's own comments, and these reports:

| where | joined reports | unbound blocks |
|:--|:--|:--|
| `examples/app-showcase` `TaskOverviewReport` | 1 | 0 |
| `content/docs/ui/reports.mdx` example | 1 | 0 |
| `packages/lint` `validate-chart-bindings.test.ts` (raw stacks, never
parsed) | 4 | 0 |
| `packages/platform-objects` `report-form-echo-decisions.test.ts` | 2 |
0 |
| `packages/spec` tests (`report.test.ts`,
`filter-save-door-face-parity.test.ts`,
`joined-report-block-type.test.ts`) and the
`report-joined-chart-removed` conversion fixture | 10 | 0 |
| `packages/metadata-protocol`
`protocol.invalid-metadata-422-face-inventory.test.ts` | 1 | **1**,
unbound on purpose (below) |
| `skills/**` | 0 | 0 |

- Triage measured hotcrm `4054ec26` (1 joined report, 0 unbound blocks)
and cloud `2205b530` (none). I took those readings as given. I read
hotcrm's `src/sales/reports/churn.report.ts` once, to shape the
preservation fixture. Every block binds a dataset: three bind
`account_metrics` and the fourth, `recently_closed_lost`, binds
`opportunity_metrics`. So triage's line "every block binds
`account_metrics`" is slightly off; its conclusion, zero unbound blocks,
stands.
- **objectui (read only, at `2e818d0b51` and at this repo's pin
`ab18797215`).** Studio's joined-report authoring **can** save a block
with no `dataset`. That producer is this narrowing's reach:
- `ReportDefaultInspector.tsx` renders the blocks through `SchemaForm`
with the spec `reportForm` "Joined blocks" repeater;
- `RepeaterField`'s `add()` seeds a blank row with every column
`undefined`;
- the row's `dataset` column is free text and not required (the block's
derived JSON Schema `required` is `["name"]`, measured);
- the bundled `ReportSchema` (`clientValidation.ts`) and the save door
both accepted the result.

Filed as objectstack-ai/objectui#11601: category ①, no labels, dedupe
query and hit count in its body. After the spec bump, Studio's live
validation and the save door both refuse such a block at
`blocks.N.dataset`.
- The renderers, at the pin: `DatasetReportRenderer`'s joined branch
passes `String(block.dataset ?? '')` to each block's table, and that
table's query hook goes idle on an empty name (`:443`). A report whose
blocks all lack one fails `isDatasetReport` and falls through to the
presentation bridge. `DrillDownDrawer`'s `isDatasetBoundReport` lists
the records instead of drawing it.

## Fixture triage: one test-only file outside the claim's file surface

`protocol.invalid-metadata-422-face-inventory.test.ts` section 5 (the
joined-report `chart` door pins) left its block **unbound on purpose**:
the door's author-time gate refuses an unresolvable dataset with
`chart-dataset-unknown`, and the stub engine had no dataset universe.
The new refusal turned 2 of its 23 tests red (`Tests 2 failed | 21
passed`): the container case got a second issue at `blocks.0.dataset`,
and the CONTROL was refused at `blocks.0.dataset`. That second red is
the metadata save door (`422 INVALID_METADATA`, `writeFace:
'meta-envelope'`) refusing the probe shape.

- **Disposition: add the declaration.** The block binds `task_metrics`,
and the harness gains an optional `makeProtocol({ datasets })`, which
registers that dataset through `registry.listItems('dataset')`. Every
other caller passes nothing, so the registry lists nothing, as before.
Result: `Tests 23 passed (23)`.
- **The registration is load-bearing.** I mutated the CONTROL to call
`makeProtocol()` without datasets (`scripts/ablation-replace.mjs`,
anchor 1 → 0, blob `f718099c2d` → `9dc51bd7b8`). Predicted 1 red / 22
green; observed `Tests 1 failed | 22 passed`. The failure was
`chart-dataset-unknown` at `reports[0].blocks[0].dataset`, "Declared
datasets: (none)". Restore: blob back to `f718099c2d`, which equals
HEAD, and `git diff HEAD` is empty.
- This file is outside the claim's declared file surface. It is reported
in the dev report as a deviation.
- Queue check: objectstack-ai#21706, queued at this writing, appends a section to the
same file at line 570 and later. A local `git merge-tree` of this head
with that queue head exits 0. The file is not `merge=os-regen` routed,
so that local answer is also GitHub's.

## Doors, tested and probed

- **Pins** (`packages/spec/src/ui/report-joined-block-dataset.test.ts`,
16 tests):
- the triage probe shape is refused once per block at `blocks.0.dataset`
and `blocks.1.dataset`, each naming its block; a bound block beside an
unbound one draws one issue, at the unbound index; an empty name is
named by position;
- the new issue joins the other joined-arm refusals rather than
replacing them;
  - taking the advice parses;
- CONTROLS: a block on a non-joined report, and
`JoinedReportBlockSchema` parsed on its own, both still parse;
- doors: `defineReport` throws; the registered `report` type schema
refuses (and accepts the bound report); `ObjectStackDefinitionSchema`,
the stack parse `objectstack validate` runs, refuses at
`reports.1.blocks.{0,1}.dataset`; `defineStack` answers
`STACK_SCHEMA_INVALID` / 422;
- preservation: the showcase `TaskOverviewReport` (mirrored byte for
byte) parses with output equal to its input, and a fixture shaped like
hotcrm's `customer_churn_signals` parses, gaining only the `drilldown`
default;
- ledger: one D3 entry at protocol 18 with no conversion; the step-18
rationale names it; no `JoinedReportBlock:dataset` tombstone, with a
control on a known tombstone.
- **`objectstack validate`, the real CLI** (`packages/cli/bin/run.js`,
built here). Fixtures were temporary, in the session scratchpad, outside
the repo; `@objectstack/spec` resolved to this worktree's build.
- The triage probe stack (two blocks, each only `name` + `label`):
**exit 1**, `"code": "STACK_SCHEMA_INVALID"`, `defineStack validation
failed (2 issues)` at `reports.0.blocks.0.dataset` and
`reports.0.blocks.1.dataset`, each with the message above.
- CONTROL, the same report with both blocks bound to a declared dataset:
**exit 0**, `"valid": true`.
- The showcase app (`examples/app-showcase/objectstack.config.ts`, four
reports including `TaskOverviewReport`): **exit 0**, `"valid": true`.
- **The CLI door's verdict is this arm's, proven through `dist`.** The
CLI reads `@objectstack/spec` through `dist`, so the mutation was
rebuilt:
- mutated leg: the `ctx.addIssue` of the new arm became a `globalThis`
marker assignment (anchor 1 → 0, blob `fadd536165` → `2cbfdb9feb`);
`@objectstack/spec` rebuilt; `ablation-dist-preflight.mjs` found the
marker in `dist` (exit 0); the probe then gave **exit 0**, `"valid":
true`. That reproduces the card's reading at `main`;
- restore leg: blob back to `fadd536165`, which equals HEAD, and `git
diff HEAD` is empty; rebuilt; `--absent` found the marker in none of 228
built files (exit 0); the probe gave **exit 1** `STACK_SCHEMA_INVALID`
again.

## Ablation of the refusal, at the pins (predicted first)

`scripts/ablation-replace.mjs` replaced the arm's `ctx.addIssue(...)`
with a no-op (anchor 1 → 0, blob `fadd536165` → `45f34370c5`). The pins
import `./report.zod` relatively, which resolves to `src`, so no build
was needed. Predicted: 8 red, the 4 refusal pins and the 4 door pins; 8
green, the advice, the 2 controls, the 2 preservation pins and the 3
ledger pins; `report.test.ts` untouched. Observed: `Tests 8 failed | 80
passed (88)` over the pin file and `report.test.ts`. The 8 were exactly
the predicted ones. Restore: blob equals HEAD (`fadd536165`), and `git
diff HEAD` is empty.

## Verification (all at head `c4e3ab9631` unless noted)

- `@objectstack/spec` full suite (`vitest run --project local
--maxWorkers=2`): `Test Files 613 passed (613)`, `Tests 18201 passed | 1
todo`.
- `pnpm --filter @objectstack/spec typecheck` (tsc, scripts, test layer:
`check:test-typecheck: OK`) and `pnpm --filter
@objectstack/metadata-protocol typecheck`: exit 0. `--listFiles` shows
both edited test files in their programs.
- Consumers that parse a joined report: `platform-objects`
`report-form-echo-decisions.test.ts` 35 passed; `lint`
`validate-chart-bindings.test.ts` 47 passed;
`@objectstack/example-showcase` whole suite `32 files, 399 passed`;
`metadata-protocol` face-inventory 23 passed.
- `pnpm --filter @objectstack/spec check:generated`: one artifact stale
before regeneration (`content/docs/references/**`), regenerated with
`gen:docs`; then `check:generated` exit 0.
- Derived gates: `node scripts/pm/dispatch-gates.mjs --commands --repo
objectstack-ai/objectstack` derived 115 commands. Every one was run,
with its exit code recorded before any pipe. `--ran` reconciled **115
derived, 115 run, 0 NOT-MEASURED, 0 UNRUN**.
- Two first exited 3 (prerequisite not met, packages with no `dist`):
`check:skill-examples` and `check:dual-build-cjs-loads`. Both were
re-run green after building those packages. All 115 exited 0.
- Among them: `check:adr-0087-registration`, `check:changeset-no-major`,
`check:migration-registry`, `check:spec-changes`, `check:upgrade-guide`,
`check:authorable-surface`, `check:api-surface`, `check:docs`,
`check:doc-authoring`, `check:issue-citations`, `check:nul-bytes`,
`check:cross-package-test-inputs`.
- eslint, narrowed and proven:
1. population: `eslint.config.mjs`'s `**/*.{ts,…}` block covers all five
changed `.ts` files;
  2. `--format json`: 5 files, 0 errors, 0 warnings;
3. invariance: the config enables no type-aware linting (no
`parserOptions.project`, as its own comment states), so this diff cannot
move a verdict on an untouched file.

  The repo-wide `pnpm lint` is CI's.
- Declared to CI: the path-scheduled jobs (Test Core shards, Dogfood,
Temporal Conformance, Build Core), the whole-workspace type-check lanes
and every downstream consumer suite of `@objectstack/spec` beyond the
four above.

## Acceptance notes (observations, not filed)

- `reports.mdx` says a `joined` report "must declare at least one
block". That is still true, but it no longer names every requirement:
each block must now also bind a `dataset`. Not edited, under the claim's
rule that only a sentence this change makes false is edited. Carrier:
none.
- The block row in the spec's own `reportForm`
(`packages/spec/src/ui/report.form.ts`, "Joined blocks" repeater) offers
`dataset` with no `ref:dataset` widget and no `required`.
objectstack-ai/objectui#11601 names this as a possible spec-side fix for
the Studio producer, to be measured first. Carrier:
objectstack-ai/objectui#11601's acting seat.
- The requirement is a refinement, so the published JSON Schema does not
carry it. `ui/Report` already sits in
`dropped-refinements.baseline.json`, and the new arm adds no site there.
The `.describe()` text is now the JSON-Schema-visible hint.
- The joined arm, this check included, does not run while a block
carries an unknown key or a wrong-typed member: that issue aborts the
refinement. The dataset refusal then arrives after that first issue is
fixed. This is existing behaviour shared by every arm of the refinement.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
… instead of a tracker number (stage 10) (objectstack-ai#21713)

Part of objectstack-ai#20749
Clause-②: no

Stage 10 of this card, and the first area of class (e): the test strings
shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513.
This stage takes the whole `automation/` directory. Its 105 test-title
and test-message literals carried 110 tracker ids citing 55 records.
Each id now either states what its record decided, in words (form D), or
is dropped where the title already says it. Text only: no assertion,
fixture value, test count or code comment changes.

## Census at the base (`7e0066af7a`, the claim's base)

Instrument: stage 9's `census.cjs` (md5
`6e42a45a926d375013c32d62f16a296e`, byte-identical), plus one added
classification pass. A literal counts as a test title when its folded
message is argument 0 of a `describe` / `it` / `test` call, `.each` /
`.skip` / `.only` chains included. Everything else is an "other" string.

Reference: the same instrument reads **1803 messages / 1919 ids in 425
files at `9b8c7f38d7`**, stage 9's reading exactly. Since then, objectstack-ai#21699
added 1 / 1 (`ui/component-props-unknown-members.pin.test.ts:143`) and
objectstack-ai#21700 moved 3 / 3 (the two reader literals it re-anchored), which gives
1801 / 1917 at the base.

| directory | files | titles msg / ids | other msg / ids | total msg /
ids | excluded files |
|:--|--:|--:|--:|--:|:--|
| `data/` | 95 | 445 / 475 | 23 / 26 | 468 / 501 | |
| `ui/` | 81 | 374 / 397 | 18 / 18 | 392 / 415 | `report.test.ts` 3 / 3
|
| `api/` | 40 | 181 / 193 | 8 / 8 | 189 / 201 | |
| `system/` | 34 | 128 / 138 | 26 / 27 | 154 / 165 | `job.test.ts` 4 / 4
|
| (files directly in `src/`) | 30 | 117 / 119 | 1 / 1 | 118 / 120 | |
| **`automation/`** (this PR) | 21 | 101 / 106 | 4 / 4 | **105 / 110** |
|
| `kernel/` | 36 | 92 / 96 | 10 / 10 | 102 / 106 | |
| `shared/` | 21 | 73 / 81 | 12 / 14 | 85 / 95 | |
| `contracts/` | 25 | 59 / 70 | 4 / 4 | 63 / 74 | |
| `conversions/` | 9 | 34 / 34 | 0 | 34 / 34 | |
| `security/` | 8 | 28 / 28 | 0 | 28 / 28 | |
| `ai/` | 9 | 13 / 15 | 5 / 5 | 18 / 20 | |
| `identity/` | 6 | 14 / 14 | 1 / 1 | 15 / 15 | |
| `integration/` | 4 | 13 / 13 | 1 / 1 | 14 / 14 | |
| `migrations/` | 2 | 9 / 12 | 0 | 9 / 12 | |
| `marketplace/`, `meta-spelling/`, `studio/` | 5 | 7 / 7 | 0 | 7 / 7 |
|
| **total** | **426** | **1688 / 1798** | **113 / 119** | **1801 /
1917** | 7 / 7 |

- **Excluded, in flight under this seat:** `system/job.test.ts` carries
objectstack-ai#16292 (`:92`), objectstack-ai#14478 (`:471`), objectstack-ai#4667 (`:836`) and objectstack-ai#19184 (`:881`), and
`ui/report.test.ts` carries objectstack-ai#20161 (`:233`), objectstack-ai#3916 (`:334`) and objectstack-ai#5013
(`:426`). All seven sit in titles. They wait for a later stage, after
objectstack-ai#21703 and objectstack-ai#21702.
- **Controls.** Lit, single line: `automation/approval.test.ts:135`
reads one title with objectstack-ai#3508. Lit, multi-line:
`api/discovery-environment-subset.pin.test.ts:63-66`, a `+` chain, reads
as ONE message with its id on `:65`. Dark: the `// objectstack-ai#3508` comment at
`automation/approval.test.ts:131` reads 0. Planted in a scratch copy of
the head file: an id in a title reads 1 / 1, and an id in a comment
reads 0.
- **A wider pattern** (any `#` plus digits, so two-digit and six-digit
numbers too) reads the same 105 / 110 in `automation/` at the base, and
0 / 0 at the head.
- **At the head:** 1696 messages / 1807 ids in 405 files. `automation/`
reads 0 / 0. Nothing else moved.

## How the area was chosen

The directories are ranked by id count, and a stage takes whole
directories up to about 100 ids. The four busiest each exceed that bound
alone: `data/` (501), `ui/` (415), `api/` (201) and `system/` (165). The
files directly in `src/` (120) are 20% over. `automation/` (110) is the
busiest whole directory within about 10% of the bound, so it is this
stage. The rule picked it before any card was read.

Its 55 records (53 in this repository, 2 in objectui) were all readable
in one pass. 54 answer 200. objectstack-ai#6362 answers 404, and its decision was read
from its landing commit `b5404f496`.

**Named for the next stages** (by directory, from the table): `data/`
(about five stages, by subdirectory or file group; `data/driver/` alone
is 52), `ui/` (about four), `api/` (two), `system/` (two), the files
directly in `src/` (one), `kernel/` (one), `shared/` (one), `contracts/`
with `conversions/` (one, 108), and `security/`, `ai/`, `identity/`,
`integration/`, `migrations/`, `marketplace/`, `meta-spelling/` and
`studio/` together (one, 96). The seven excluded ids join `system/` and
`ui/` once their owners land.

## What each id became

38 literals (40 ids) now state a decision in words. 67 literals (70 ids)
drop a citation the title already explains. Each record was read with
its comments through REST, and where a record has no comments, from what
landed.

| record | ids | result |
|:--|--:|:--|
| objectstack-ai#3508 | 2 | `APPROVER_VALUE_BINDINGS`: "an approver value is picked
from the records the engine resolves". `APPROVER_VALUE_SOURCES` (the
follow-up): "where each picker finds its candidates, published on the
wire". |
| objectui#2955 | 1 | "for the decision dialog to render and enforce":
both decision entry points collect the typed outputs, and `required` is
enforced. |
| objectstack-ai#3810 | 1 | "names the match-everything-write hazard": a filter
emptied by interpolation matches every row, and the node is refused
instead. The test pins the words `match-everything write`. |
| objectstack-ai#4001 | 13 | "strict as of objectstack-ai#4001 批 9" becomes "an unknown key is
refused, not stripped" (5 titles). Also "refused, not stripped", "an
unknown key is refused, per shape" and "the unknown-key gate". Dropped
from 5 titles that already read "unknown keys are rejected, not
stripped". |
| objectui#2670 | 1 | "so the flow designer renders it as a template":
the designer's loop and region rendering reads this marker. |
| objectstack-ai#4396 | 2 | "a function that writes says so; pure is the default", and
"the authoring surface where a function declares its effect" (landed
`eb4204b`). |
| objectstack-ai#4697 | 2 | `defaultValue`: "a declared variable is bound on every
path" (ruling A). Dropped once. |
| objectstack-ai#3896 | 3 | "outputSchema retired: declared, never validated" (the
audit close-out's reason, as `flow.zod.ts`'s tombstone records it).
Dropped twice. |
| objectstack-ai#4247 | 1 | "maxRetries — one default, and no zero-attempt “retry”"
(landed `a648e96`). |
| objectstack-ai#16134, objectstack-ai#15713 | 7 | "a region node reusing a top-level id is refused
— one node-id space now spans every region" (ruling, batch 61). Dropped
from 5 titles that state uniqueness. |
| objectstack-ai#9205 | 5 | "template reference — notify content localized through an
email template" (the ruled emailTemplates route). Three titles say "the
template path" where they said "pre-objectstack-ai#9205". Dropped once. |
| objectstack-ai#7086 | 1 | "severity — the closed info \| warning \| critical
vocabulary" (the enum route). |
| objectstack-ai#4415 | 3 | "FlowNodeSchema parses its own regions" (ruling
2026-08-07, direction 1). Dropped from 2 titles that already say it. |
| objectstack-ai#4347 | 1 | "collectFlowGraphs — every region is walked, not only the
top level" (landed `31e0be9`). |
| objectstack-ai#4401 | 2 | "FLOW_REGION_SLOTS, the one declaration of where regions
live" (landed `4bfd455`). Dropped once. |
| objectstack-ai#4414 | 1 | "`condition` is pointed at the out-edges, NOT given the
one-edit rename" (one working routing model, landed `5293114`). |
| objectstack-ai#15429 | 1 | "taking every true branch must be declared" (ruling item
2: explicit `inclusive`). |
| objectstack-ai#14149 | 3 | "every entry older than the value role" (ruling A: a
value-role CEL slot on `assignment`). Dropped twice. |
| objectstack-ai#19938 | 4 | "the CRUD `fields.*` value slots added exactly two rows".
Dropped three times. |
| objectstack-ai#15572 | 3 | "predicateSlotRefusal — a predicate slot holds bare CEL
text", and "the other two doors refuse it". Dropped once. |
| objectstack-ai#15662 | 1 | "structuralConditionRefusal — a structural condition is
CEL text or an expression". |
| objectstack-ai#15792, objectstack-ai#15807 | 4 | "REFUSES an `ast`-only envelope — admitted at
first, refused once an evaluated slot required a `source`". Dropped from
2 titles that state the rule. |
| objectstack-ai#17493 | 3 | Table row "a blank string — blanks are refused" (ruling
A). Dropped twice. |
| objectstack-ai#14945 | 4 | "EndConfigSchema — the `end` node contract: it may refuse
the run with a message" (ruling 2′). Dropped three times. |
| objectstack-ai#15617 | 4 | "`failed` is the fold INCLUDING what a delegating node
rolled up from its child — it answers what the run caused" (ruling
option 1). Dropped three times. |
| dropped only | 36 | objectstack-ai#3196, objectstack-ai#3266, objectstack-ai#4158, objectstack-ai#4277, objectstack-ai#4343 (2), objectstack-ai#4389,
objectstack-ai#4525, objectstack-ai#4738, objectstack-ai#4964 (2), objectstack-ai#6758, objectstack-ai#7085, objectstack-ai#9106, objectstack-ai#12278, objectstack-ai#14964, objectstack-ai#15430,
objectstack-ai#15646 (3), objectstack-ai#16752, objectstack-ai#17306, objectstack-ai#17852, objectstack-ai#18102, objectstack-ai#18112 (2), objectstack-ai#18847, objectstack-ai#19151,
objectstack-ai#19961 (4), objectstack-ai#20316 (2): each title already states the pinned decision.
For objectstack-ai#4988 and objectstack-ai#6414, the two expect messages already say what was
retired. |
| objectstack-ai#6362 (404) | 1 | Dropped. The title "PRESERVES all seven envelope
keys — measured, not assumed" carries the decision recorded in
`b5404f496` (`webhook` was measured, and all seven keys survive). |

## Readers

- **Test-name filters:** none. A tracked-tree search for `-t` and
`--testNamePattern` finds only `packages/qa/dogfood/README.md:142` (`-t
"owner-scoped"`), which is unrelated.
- **Snapshots:** none. `automation/` has no `__snapshots__` and no
`toMatchSnapshot`.
- **Titles by substring:** every old title, plus a window around each id
(250 needles), was searched across the tracked tree outside its own
file. No gate, doc or script matches one. The hits are other files' own
titles with the same words: `identity/`, `security/` and `automation/`
siblings, a later stage's lot. There are also two code comments in
`flow.zod.ts` and `flow-function.zod.ts`, which belong to the comment
lane.
- **Twin tables, not readers:**
`packages/lint/src/validate-expressions.test.ts:4442/4445` and
`packages/services/service-automation/src/decision-branch-expression-absent.test.ts:61/64`
repeat the `flow-decision-branch-expression-absent` table's row names.
Nothing compares them mechanically: the "same table" parity is prose in
the headers, and it covers assertions, not names. They are outside this
stage's surface (see Acceptance notes).

## Text-only proof

A scratch tool (`textonly10.cjs`) compares base and head file by file on
three legs:
1. **Skeleton:** the full AST, with string pieces masked. It must be
identical.
2. **Comments:** every comment, byte-equal.
3. **Strings:** each string leaf that changed must sit in a test-call
title position, or on one of the 4 declared lines
(`flow-decision-branch-expression-absent.test.ts:63` and `:66`, table
`name` values that feed `$name` titles; `sync-retirement.test.ts:120`
and `:158`, expect messages). It must carry a tracker id before and no
`#` plus digits after.

- **Result:** 21 of 21 files SAME, 105 changed (101 title, 4 declared),
on all three legs.
- **Diff hunks:** exactly the 105 planned lines, with every file keeping
its line count.
- **Controls (10 of 10 as predicted, on scratch copies, each anchor hit
once):** identifier rename DIFF; numeric literal DIFF; comment edit
COMMENT DIFF; a non-title string with an id VIOLATION; a rewritten title
given a new id VIOLATION; a title that was id-free at base edited
VIOLATION; one title reverted to base SAME (104 changed); a declared
string keeping an id VIOLATION; an undeclared expect message changed
VIOLATION; a title re-split into a `+` chain DIFF.

**Test counts:** the 21 files run at the base (in a separate base
worktree) and at the head: 801 / 801 tests on both sides, with the same
count and status sequence per file in 21 of 21. 560 full test names
change, and each equals the base name with the planned replacements
applied.

## Changeset: `skip-changeset`

Measured, not assumed:
- `npm pack --dry-run` of `@objectstack/spec` lists 2068 files, under
`files[]` (`dist`, `src/**/*.zod.ts` and the rest). 0 of the 21 touched
files are in it, and 0 `*.test.ts` at all. The control
`src/automation/flow.zod.ts` is in it.
- In `dist/`, three new phrases and three old ones each read in 0 files.
The control `A predicate slot holds BARE CEL TEXT` reads in 2.

So this PR publishes nothing, and no changeset is added.

## Verification (at `f3dc3fab03`)

- `pnpm turbo run build` over all packages: 71 / 71.
- `@objectstack/spec`: `vitest run --project local`, 612 files and 18185
passed, 1 todo. `typecheck` exit 0, including `check:test-typecheck`,
whose program holds all 21 touched files.
- **Gates:** `dispatch-gates --commands` derived 79 families, and all 79
exit 0. `--ran` reconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN.
- **ESLint, a proven narrowing:** `--no-inline-config` over the 21
files, 0 errors and 0 warnings. The population comes from ESLint's own
config: 21 configured, 0 ignored. No `parserOptions.project` or
`projectService`, so no untouched file's verdict can move.
- `check-governed-merges --test`: NOT governed, 210 changed lines.

## Acceptance notes

- **Twin row names in other packages:** the lint and service-automation
copies of the decision-branch table keep their `the objectstack-ai#19961 shape` and
`the objectstack-ai#17493 control` row names, and their twin `describe` titles keep
their ids. The lint copy is this card's own later share (the
`packages/lint` test strings). The service-automation copy belongs to
that package's lane.
- **Code comments still carry ids** in these 21 files (for example
`approval.test.ts:56`, `:69` and `:131`). They are the comment lane's,
untouched here.
- **`origin/main` moved** three commits past the base before this PR
opened (objectstack-ai#21701, objectstack-ai#21707, objectstack-ai#21706). None touches `packages/spec`, so
nothing was merged.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
… carries as the published spec (objectstack-ai#21709) (objectstack-ai#21717)

Fixes objectstack-ai#21709

Clause-②: no

## What changes

The `Console Pin Gate`'s probes no longer treat text that objectui's own
source carries as evidence of either spec. A console bundle carries text
from objectui's code as well as from the specs. objectui's component
registry writes `inputs` descriptions that copy spec `.describe()` text,
either verbatim or as a prefix it then extends. When the spec rewords
one of those, the old text becomes published-only. objectui's literal
still carries it, so a substring search found "the published spec" in a
bundle built from this tree's spec. That is what has turned every
merge-queue build red since objectstack-ai#21699 (`16d241a6af`): the object-gantt
`markers` describe and objectui's
`packages/plugin-gantt/src/index.tsx:190`.

- `scripts/console-spec-probes.mjs`: `readHostSourceBlob(dir)` reads
objectui's tracked code files at the pin (`git ls-files`; test files
excluded; a quote's backslash normalised). `chooseProbes` now takes that
blob as `hostBlob`, required. It is a TypeError without it.
- **The rule (both legs):** a candidate that is in the bundle **and**
carried by objectui's source is not evidence. It is counted
(`counts.hostCarried`), never decides a verdict, and is never returned
as a probe, so it is never stamped. A candidate **absent** from the
bundle is still evidence, whoever else carries it. The rule excuses
presence, never absence.
- **One new refusal:** if every published-only candidate is in the
bundle and objectui carries every one, the stale leg has no probe left.
That is neither "no skew" nor "absent", so the assert exits **2**
(inconclusive). The old code answered that same state exit 1, with a
false accusation. It never passed.
- `scripts/assert-console-spec-injection.mjs`: a new required
`--objectui` flag (objectui's build tree, the git checkout at the pin).
Its messages report host-carried text separately, so a pass no longer
prints "all N published-only descriptions are absent" when one of them
is in the bundle.
- `scripts/build-console.sh` (**declared, and strictly needed by the
route**): the single assert call site passes `--objectui "$BUILD_ROOT"`,
the tree it just built. The only other way to find that tree is to reach
two levels up from `--vendored`, which couples the assert to a path
layout. A required flag means a forgotten call site fails loudly (exit
2).
- `scripts/check-console-injection.mjs`: the replay logic is unchanged.
It needs no objectui tree, because the build never stamps a host-carried
probe. Its self-test gains battery 14, and batteries 12 and 13 now pass
`--objectui`.
- **Same-class fix on the fresh leg, declared:** the same rule applies
to the injected-only witness. A witness that objectui writes itself is
no proof of the injection. Before this change, a bundle that held
objectui's literal and **no spec at all** passed; now it reads "neither
spec appears" (exit 2). The four bounded-fix conditions all hold: same
defect class, same function, a file nobody else has claimed, and the
same gate family. It is pinned in battery 14.
- The stamp shape is unchanged (`stampVersion` 1). The stamp now records
the **filtered** choice, so a cache-hit replay agrees with the build.

## Reproduction (base `7e0066af7a`, the head of queue run `37187916146`)

- **CI:** queue run `37187916146`, job `111393796807` ("Build the
Console SPA at the pinned objectui SHA"). Its triage comment on objectstack-ai#21700
quotes `✗ Built console still carries the PUBLISHED @objectstack/spec.`
I could not read the raw job log from this container: the log blob host
answered 403. So the per-candidate figure comes from the local build
below, at the same commit.
- **Local, the real door:** `scripts/build-console.sh` at `7e0066af7a`,
run under `os-verify-lock.sh`. It used objectui `ab1879721595`, and the
vendored `@objectstack/spec` resolved to **17.6.0**. Lock held 559s.
Result: exit 1, `(1 of 38 published-only descriptions), the first of
them: "Extra vertical reference lines drawn like the Today marker ({
date, label?, color? })"`.
- **Measured, not assumed:** over that real bundle (33.3 MB of JS), the
published-only candidates present are exactly **1 of 38**, and it is the
`markers` text. objectui's tracked non-test source carries it. The
injected-only candidates present are 26 of 26, and none of those is
host-carried.

## Route: (a), by measurement

- **(b), whole-literal matching, would fix today's collision.** The
`markers` text is not a whole literal in the real bundle.
- **It leaves half the family open.** In the real bundle, **9** spec
describes are whole literals inside objectui's own chunks, for example
"Action IDs available for related records" in the `plugin-grid` chunk.
Rewording any of those 9 would recreate this red under (b).
- **At the pin, over the module's own file filter**, objectui's non-test
code holds 18 literals equal to a spec describe and 18 more that begin
with one.
- **(a) covers both shapes.** It drops only text whose presence could
not have been evidence anyway, and only when that text is in the bundle.
- **Leak detectability (pin 2 on the real bundle):** I added the
published 17.6.0 JS as a chunk to the real assets. The head assert exits
1 on `37 of 38`, detector "Actions to execute during transition".
Replaying the good build's stamp beside those assets also exits 1.
- **Cost:** the host blob is 32.3 MB and reads in about 0.3 s.

## Pins (battery 14, `node scripts/check-console-injection.mjs
--self-test`)

Base: 44 assertions. Head: 67. Every fixture runs the real assert script
and replays its stamp through `evaluate()`. The mirrored texts sort
**first**, so an unfiltered pick would choose them.

1. **Pin 1 passes:** the injected spec plus an objectui literal that
begins with a published-only describe, plus a second literal equal to
one (which exercises the quote-backslash normalisation). The stamp
records `staleDetector` = a text objectui does not write. The replay
passes.
2. **Pin 2 still fails:** a bundle carrying the published spec's own JS
fails with exit 1 and names a detector objectui does not write. No stamp
is written. objectui's **test** file quotes that detector, so this case
also pins that tests are not read as source.
3. **Pin 3, the replay agrees:** the replay matches the assert on both
bundles: 0 on bundle 1, and 1 ("carries the PUBLISHED") on bundle 2 with
the good stamp beside it.

Battery 14 also covers:
- the all-host-carried stale leg (exit 2, "cannot judge");
- host-carried text absent from the bundle, which stays a valid detector
(exit 0, stamped, replay 0);
- the fresh-leg case (exit 2);
- an objectui tree git cannot list (exit 2);
- `chooseProbes` without `hostBlob` (TypeError).

**Ablation.** Predicted first and saved, then run through
`scripts/ablation-replace.mjs` in wrap mode. The mutation was `const
hostCarried = new Set();`. On disk the anchor went 1 to 0 and the marker
0 to 1. The restore was proven: blob `903c3e80cce1` equals HEAD, and
`git diff HEAD` is empty.
- **Self-test:** exit 1, with **13 failures, exactly the predicted
list**, all in battery 14 (pin 1 ×6, pin 2 detector wording ×2, pin 3
bundle-2 wording ×1, all-host-carried ×2, fresh leg ×2). No other
battery failed.
- **Pin 2's exit 1 held with and without the fix.**
- **Synthetic bundles under ablation:** exit 1 `1 of 38` with the
`markers` detector, and exit 1 `38 of 38`.
- **Real bundle under ablation:** exit 1 `1 of 38` with the `markers`
detector, and exit 1 `38 of 38` with the published chunk added.

## The real door on this head

- **End to end:** `scripts/build-console.sh` on `93ea8e7d80` reused the
built objectui tree, rebuilt the console at the pin, and ran the fixed
assert. Exit **0**, with `37 of 38 published-only descriptions are
absent; 1 ... ARE in the bundle, and objectui's own source at the pin
carries each of them too`. Lock held 278s. The next CI steps then ran on
that dist: `pnpm check:console-sha` exited 0, and `pnpm
check:console-injection --require-stamp` exited 0 (self-test 67, replay
passed).
- **That build was before the last commit.** `93ea8e7d80` differs from
the final head `0bcf6a0a95` only in a self-test fixture line in
`check-console-injection.mjs`, and that self-test was re-run on
`0bcf6a0a95`.
- **PR side:** all four changed paths are in `ci.yml`'s `console`
filter, so `Console Pin Gate` runs on this PR. Three of them
(`build-console.sh`, the assert, the probes module) are in the dist
cache key, so the key moves and the cache misses. The PR head therefore
gets a full console build at the pin with this assert, and that is the
CI reading of the real door.
- **Queue:** once this merges, every queue build's `Console Pin Gate`
runs this assert. `release.yml`'s key hashes `build-console.sh`, so its
next run rebuilds through the new call site too.

## Gates (on `0bcf6a0a95`)

- `node scripts/pm/dispatch-gates.mjs --commands --repo
objectstack-ai/objectstack` derived 32 commands. All 32 exited 0.
- `--ran` reconciliation: 32 derived, 32 run, 0 NOT MEASURED, 0 unrun,
every one with a recorded exit code. That includes `pnpm
check:console-injection`, `check:console-sha`, `check:ci-filter-parity`
(+ self-test), `check:nul-bytes`, `check:entry-guard` and
`check:pm-dispatch-gates` (1976 cases, run detached).
- **eslint, narrowed:** `eslint.config.mjs` lints all three changed
`.mjs` files, so none is ignored. `--format json` reported 3 files, 0
errors and 0 warnings. The config has no type-aware linting, so this
diff cannot move any untouched file's verdict. `build-console.sh` is
outside eslint's population. The full `pnpm lint` is left to CI.

## Changeset

`skip-changeset`: nothing published changes. The diff is root `scripts/`
only, and the root package is private and ships no `files`. I built the
console dist (the one published package this build feeds) and grepped
it: `readHostSourceBlob` / `hostCarried` have 0 hits, while the positive
control, the `markers` literal, is found in 3 files.

## Acceptance notes

- **Dead branch, not touched:** the assert's "published spec is gone,
but nothing unique ... was found" branch is unreachable, both before and
after this change. The "neither" branch and the stale exit cover every
way into it. Carrier: none.
- **Parity tests stay evidence:** objectui's
`apps/console/src/__tests__/registry-inputs-spec-parity.test.ts` quotes
2 of the 38 published-only describes. Tests are excluded from the host
source, so in a real leak those two still count as evidence.
- **Same-tree pin:** the reproduction and the real-door runs used the
same tree as the failing queue run, `7e0066af7a` (its `head_sha`).
`origin/main` has since moved by four commits, and none of them touches
this gate's inputs.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation protocol:ui size/xl tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants