Repository navigation
feat(spec)!: object-gantt markers, object-timeline mapping and both forms' fields take the shape each block reads; five objectui-held contracts reported as forks (#21464, S-objectui-held) - #21699
Conversation
…d form fields typed; forks recorded Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
…ness counts Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
… audit reaches its table Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016tKoy8NJa35Yih1FdzrVmn Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift Check11 anchor(s) derived from 1 changed package(s); no hand-written page names any of them, so this run has nothing to list — not a clean bill of health. This check sees only pages that NAME a derived anchor: one that documents this change in prose, or enumerates it in an authoring dialect, names none and stays invisible to it on every run. What this run could not see
Coarse fallback — 138 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 0b902788dd7ccc2935c5468004c5db734a782c64 && git checkout 0b902788dd7ccc2935c5468004c5db734a782c64
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 83e2feeb46be3c22b7139b01114612e93afcf412 723df5474159ed4b2100cd3742a6874f7e22fd69 && git checkout -B drift-repro 83e2feeb46be3c22b7139b01114612e93afcf412 && git merge --no-ff 723df5474159ed4b2100cd3742a6874f7e22fd69
node scripts/docs-audit/affected-docs.mjs --json 83e2feeb46be3c22b7139b01114612e93afcf412 |
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 37185775211 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
…t blocks[i].dataset, naming the block (objectstack-ai#21702) (objectstack-ai#21712) Fixes objectstack-ai#21702 Clause-②: yes (narrowing) Triage direction `5977861131` (enforce), claim `5977924610`. The joined arm of `ReportSchema`'s refinement now refuses each block of a `joined` report that binds no `dataset`, at `blocks[i].dataset`, naming the block, with the prescription to bind the block to a dataset. The refinement comment "each block dataset-bound" and the reports guide's type-table cell "(each block dataset-bound)" were declarations; they are now enforced. ## What changes - **The refusal** (`packages/spec/src/ui/report.zod.ts`). A per-block arm inside the joined branch of `ReportSchema`'s `superRefine`, right after the existing "needs `blocks`" check. For each block whose `dataset` is undefined it adds one `custom` issue at `['blocks', i, 'dataset']`. The message comes from a module-private builder, `joinedBlockDatasetRequired`, worded like the neighbouring joined refusals: ```text a `joined` report draws each block from that block's own `dataset`, and block `NAME` binds none, so nothing queries it and it draws no rows. Bind the block to a dataset: set its `dataset` to the dataset whose measures (`values`) and dimensions (`rows`) it shows. ``` `NAME` is the block's `name`. A block whose `name` is empty (its own `too_small` issue, which does not stop the refinement) is named by position instead, as `blocks[1]`. - **What stays accepted.** `JoinedReportBlockSchema.dataset` stays `.optional()`: `blocks` is read on a `joined` report only, so the requirement lives on the joined arm, and a block on a non-joined report is not judged (pinned). No type, export or JSON Schema key changes. The block's `dataset` `.describe()` now reads "Dataset name to bind (ADR-0021); a joined report refuses a block without one", and `content/docs/references/ui/report.mdx` is regenerated with `gen:docs` (two table rows). - **The ADR-0087 kit**, in objectstack-ai#21687's shape: - the D3 semantic entry `entries/semantic/18.ui-report-joined-block-dataset-required.ts`; - its step-18 rationale fragment in `STEP18_RATIONALE` at **order 77**, inserted where its id sorts. 77 is the next free order: the highest on `main` is 76, re-read at `7e0066af7a` just before this PR. objectstack-ai#21699 (74 to 76) and objectstack-ai#21698 landed before this branch's base `16d241a6af`, so no merge was needed; - `registry.ts` regenerated with `gen:migration-registry`; - one BREAKING `@objectstack/spec` `minor` changeset, `.changeset/21702-joined-report-block-dataset-required.md`, carrying the `Clause-②` line, the `adr-0087: registered ui-report-joined-block-dataset-required` disposition marker and a FROM → TO table. The fragment and entry text state each decision in words and carry no tracker number. No tombstone (no key is removed) and no D2 conversion (only the author knows which dataset a block was meant to show). - **`content/docs/ui/reports.mdx`: no edit.** No sentence there became false; the type-table cell became true. See Acceptance notes. ## Census, at base `16d241a6af`, before any edit `git grep` for a `type: 'joined'` report across `examples/**`, `packages/**`, `skills/**`, `content/docs/**`, `docs/**`, `scripts/**` and `apps/**` gave 33 lines in 15 files: CHANGELOG quotations, the spec's own comments, and these reports: | where | joined reports | unbound blocks | |:--|:--|:--| | `examples/app-showcase` `TaskOverviewReport` | 1 | 0 | | `content/docs/ui/reports.mdx` example | 1 | 0 | | `packages/lint` `validate-chart-bindings.test.ts` (raw stacks, never parsed) | 4 | 0 | | `packages/platform-objects` `report-form-echo-decisions.test.ts` | 2 | 0 | | `packages/spec` tests (`report.test.ts`, `filter-save-door-face-parity.test.ts`, `joined-report-block-type.test.ts`) and the `report-joined-chart-removed` conversion fixture | 10 | 0 | | `packages/metadata-protocol` `protocol.invalid-metadata-422-face-inventory.test.ts` | 1 | **1**, unbound on purpose (below) | | `skills/**` | 0 | 0 | - Triage measured hotcrm `4054ec26` (1 joined report, 0 unbound blocks) and cloud `2205b530` (none). I took those readings as given. I read hotcrm's `src/sales/reports/churn.report.ts` once, to shape the preservation fixture. Every block binds a dataset: three bind `account_metrics` and the fourth, `recently_closed_lost`, binds `opportunity_metrics`. So triage's line "every block binds `account_metrics`" is slightly off; its conclusion, zero unbound blocks, stands. - **objectui (read only, at `2e818d0b51` and at this repo's pin `ab18797215`).** Studio's joined-report authoring **can** save a block with no `dataset`. That producer is this narrowing's reach: - `ReportDefaultInspector.tsx` renders the blocks through `SchemaForm` with the spec `reportForm` "Joined blocks" repeater; - `RepeaterField`'s `add()` seeds a blank row with every column `undefined`; - the row's `dataset` column is free text and not required (the block's derived JSON Schema `required` is `["name"]`, measured); - the bundled `ReportSchema` (`clientValidation.ts`) and the save door both accepted the result. Filed as objectstack-ai/objectui#11601: category ①, no labels, dedupe query and hit count in its body. After the spec bump, Studio's live validation and the save door both refuse such a block at `blocks.N.dataset`. - The renderers, at the pin: `DatasetReportRenderer`'s joined branch passes `String(block.dataset ?? '')` to each block's table, and that table's query hook goes idle on an empty name (`:443`). A report whose blocks all lack one fails `isDatasetReport` and falls through to the presentation bridge. `DrillDownDrawer`'s `isDatasetBoundReport` lists the records instead of drawing it. ## Fixture triage: one test-only file outside the claim's file surface `protocol.invalid-metadata-422-face-inventory.test.ts` section 5 (the joined-report `chart` door pins) left its block **unbound on purpose**: the door's author-time gate refuses an unresolvable dataset with `chart-dataset-unknown`, and the stub engine had no dataset universe. The new refusal turned 2 of its 23 tests red (`Tests 2 failed | 21 passed`): the container case got a second issue at `blocks.0.dataset`, and the CONTROL was refused at `blocks.0.dataset`. That second red is the metadata save door (`422 INVALID_METADATA`, `writeFace: 'meta-envelope'`) refusing the probe shape. - **Disposition: add the declaration.** The block binds `task_metrics`, and the harness gains an optional `makeProtocol({ datasets })`, which registers that dataset through `registry.listItems('dataset')`. Every other caller passes nothing, so the registry lists nothing, as before. Result: `Tests 23 passed (23)`. - **The registration is load-bearing.** I mutated the CONTROL to call `makeProtocol()` without datasets (`scripts/ablation-replace.mjs`, anchor 1 → 0, blob `f718099c2d` → `9dc51bd7b8`). Predicted 1 red / 22 green; observed `Tests 1 failed | 22 passed`. The failure was `chart-dataset-unknown` at `reports[0].blocks[0].dataset`, "Declared datasets: (none)". Restore: blob back to `f718099c2d`, which equals HEAD, and `git diff HEAD` is empty. - This file is outside the claim's declared file surface. It is reported in the dev report as a deviation. - Queue check: objectstack-ai#21706, queued at this writing, appends a section to the same file at line 570 and later. A local `git merge-tree` of this head with that queue head exits 0. The file is not `merge=os-regen` routed, so that local answer is also GitHub's. ## Doors, tested and probed - **Pins** (`packages/spec/src/ui/report-joined-block-dataset.test.ts`, 16 tests): - the triage probe shape is refused once per block at `blocks.0.dataset` and `blocks.1.dataset`, each naming its block; a bound block beside an unbound one draws one issue, at the unbound index; an empty name is named by position; - the new issue joins the other joined-arm refusals rather than replacing them; - taking the advice parses; - CONTROLS: a block on a non-joined report, and `JoinedReportBlockSchema` parsed on its own, both still parse; - doors: `defineReport` throws; the registered `report` type schema refuses (and accepts the bound report); `ObjectStackDefinitionSchema`, the stack parse `objectstack validate` runs, refuses at `reports.1.blocks.{0,1}.dataset`; `defineStack` answers `STACK_SCHEMA_INVALID` / 422; - preservation: the showcase `TaskOverviewReport` (mirrored byte for byte) parses with output equal to its input, and a fixture shaped like hotcrm's `customer_churn_signals` parses, gaining only the `drilldown` default; - ledger: one D3 entry at protocol 18 with no conversion; the step-18 rationale names it; no `JoinedReportBlock:dataset` tombstone, with a control on a known tombstone. - **`objectstack validate`, the real CLI** (`packages/cli/bin/run.js`, built here). Fixtures were temporary, in the session scratchpad, outside the repo; `@objectstack/spec` resolved to this worktree's build. - The triage probe stack (two blocks, each only `name` + `label`): **exit 1**, `"code": "STACK_SCHEMA_INVALID"`, `defineStack validation failed (2 issues)` at `reports.0.blocks.0.dataset` and `reports.0.blocks.1.dataset`, each with the message above. - CONTROL, the same report with both blocks bound to a declared dataset: **exit 0**, `"valid": true`. - The showcase app (`examples/app-showcase/objectstack.config.ts`, four reports including `TaskOverviewReport`): **exit 0**, `"valid": true`. - **The CLI door's verdict is this arm's, proven through `dist`.** The CLI reads `@objectstack/spec` through `dist`, so the mutation was rebuilt: - mutated leg: the `ctx.addIssue` of the new arm became a `globalThis` marker assignment (anchor 1 → 0, blob `fadd536165` → `2cbfdb9feb`); `@objectstack/spec` rebuilt; `ablation-dist-preflight.mjs` found the marker in `dist` (exit 0); the probe then gave **exit 0**, `"valid": true`. That reproduces the card's reading at `main`; - restore leg: blob back to `fadd536165`, which equals HEAD, and `git diff HEAD` is empty; rebuilt; `--absent` found the marker in none of 228 built files (exit 0); the probe gave **exit 1** `STACK_SCHEMA_INVALID` again. ## Ablation of the refusal, at the pins (predicted first) `scripts/ablation-replace.mjs` replaced the arm's `ctx.addIssue(...)` with a no-op (anchor 1 → 0, blob `fadd536165` → `45f34370c5`). The pins import `./report.zod` relatively, which resolves to `src`, so no build was needed. Predicted: 8 red, the 4 refusal pins and the 4 door pins; 8 green, the advice, the 2 controls, the 2 preservation pins and the 3 ledger pins; `report.test.ts` untouched. Observed: `Tests 8 failed | 80 passed (88)` over the pin file and `report.test.ts`. The 8 were exactly the predicted ones. Restore: blob equals HEAD (`fadd536165`), and `git diff HEAD` is empty. ## Verification (all at head `c4e3ab9631` unless noted) - `@objectstack/spec` full suite (`vitest run --project local --maxWorkers=2`): `Test Files 613 passed (613)`, `Tests 18201 passed | 1 todo`. - `pnpm --filter @objectstack/spec typecheck` (tsc, scripts, test layer: `check:test-typecheck: OK`) and `pnpm --filter @objectstack/metadata-protocol typecheck`: exit 0. `--listFiles` shows both edited test files in their programs. - Consumers that parse a joined report: `platform-objects` `report-form-echo-decisions.test.ts` 35 passed; `lint` `validate-chart-bindings.test.ts` 47 passed; `@objectstack/example-showcase` whole suite `32 files, 399 passed`; `metadata-protocol` face-inventory 23 passed. - `pnpm --filter @objectstack/spec check:generated`: one artifact stale before regeneration (`content/docs/references/**`), regenerated with `gen:docs`; then `check:generated` exit 0. - Derived gates: `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` derived 115 commands. Every one was run, with its exit code recorded before any pipe. `--ran` reconciled **115 derived, 115 run, 0 NOT-MEASURED, 0 UNRUN**. - Two first exited 3 (prerequisite not met, packages with no `dist`): `check:skill-examples` and `check:dual-build-cjs-loads`. Both were re-run green after building those packages. All 115 exited 0. - Among them: `check:adr-0087-registration`, `check:changeset-no-major`, `check:migration-registry`, `check:spec-changes`, `check:upgrade-guide`, `check:authorable-surface`, `check:api-surface`, `check:docs`, `check:doc-authoring`, `check:issue-citations`, `check:nul-bytes`, `check:cross-package-test-inputs`. - eslint, narrowed and proven: 1. population: `eslint.config.mjs`'s `**/*.{ts,…}` block covers all five changed `.ts` files; 2. `--format json`: 5 files, 0 errors, 0 warnings; 3. invariance: the config enables no type-aware linting (no `parserOptions.project`, as its own comment states), so this diff cannot move a verdict on an untouched file. The repo-wide `pnpm lint` is CI's. - Declared to CI: the path-scheduled jobs (Test Core shards, Dogfood, Temporal Conformance, Build Core), the whole-workspace type-check lanes and every downstream consumer suite of `@objectstack/spec` beyond the four above. ## Acceptance notes (observations, not filed) - `reports.mdx` says a `joined` report "must declare at least one block". That is still true, but it no longer names every requirement: each block must now also bind a `dataset`. Not edited, under the claim's rule that only a sentence this change makes false is edited. Carrier: none. - The block row in the spec's own `reportForm` (`packages/spec/src/ui/report.form.ts`, "Joined blocks" repeater) offers `dataset` with no `ref:dataset` widget and no `required`. objectstack-ai/objectui#11601 names this as a possible spec-side fix for the Studio producer, to be measured first. Carrier: objectstack-ai/objectui#11601's acting seat. - The requirement is a refinement, so the published JSON Schema does not carry it. `ui/Report` already sits in `dropped-refinements.baseline.json`, and the new arm adds no site there. The `.describe()` text is now the JSON-Schema-visible hint. - The joined arm, this check included, does not run while a block carries an unknown key or a wrong-typed member: that issue aborts the refinement. The dataset refusal then arrives after that first issue is fixed. This is existing behaviour shared by every arm of the refinement. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
… instead of a tracker number (stage 10) (objectstack-ai#21713) Part of objectstack-ai#20749 Clause-②: no Stage 10 of this card, and the first area of class (e): the test strings shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513. This stage takes the whole `automation/` directory. Its 105 test-title and test-message literals carried 110 tracker ids citing 55 records. Each id now either states what its record decided, in words (form D), or is dropped where the title already says it. Text only: no assertion, fixture value, test count or code comment changes. ## Census at the base (`7e0066af7a`, the claim's base) Instrument: stage 9's `census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`, byte-identical), plus one added classification pass. A literal counts as a test title when its folded message is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` / `.only` chains included. Everything else is an "other" string. Reference: the same instrument reads **1803 messages / 1919 ids in 425 files at `9b8c7f38d7`**, stage 9's reading exactly. Since then, objectstack-ai#21699 added 1 / 1 (`ui/component-props-unknown-members.pin.test.ts:143`) and objectstack-ai#21700 moved 3 / 3 (the two reader literals it re-anchored), which gives 1801 / 1917 at the base. | directory | files | titles msg / ids | other msg / ids | total msg / ids | excluded files | |:--|--:|--:|--:|--:|:--| | `data/` | 95 | 445 / 475 | 23 / 26 | 468 / 501 | | | `ui/` | 81 | 374 / 397 | 18 / 18 | 392 / 415 | `report.test.ts` 3 / 3 | | `api/` | 40 | 181 / 193 | 8 / 8 | 189 / 201 | | | `system/` | 34 | 128 / 138 | 26 / 27 | 154 / 165 | `job.test.ts` 4 / 4 | | (files directly in `src/`) | 30 | 117 / 119 | 1 / 1 | 118 / 120 | | | **`automation/`** (this PR) | 21 | 101 / 106 | 4 / 4 | **105 / 110** | | | `kernel/` | 36 | 92 / 96 | 10 / 10 | 102 / 106 | | | `shared/` | 21 | 73 / 81 | 12 / 14 | 85 / 95 | | | `contracts/` | 25 | 59 / 70 | 4 / 4 | 63 / 74 | | | `conversions/` | 9 | 34 / 34 | 0 | 34 / 34 | | | `security/` | 8 | 28 / 28 | 0 | 28 / 28 | | | `ai/` | 9 | 13 / 15 | 5 / 5 | 18 / 20 | | | `identity/` | 6 | 14 / 14 | 1 / 1 | 15 / 15 | | | `integration/` | 4 | 13 / 13 | 1 / 1 | 14 / 14 | | | `migrations/` | 2 | 9 / 12 | 0 | 9 / 12 | | | `marketplace/`, `meta-spelling/`, `studio/` | 5 | 7 / 7 | 0 | 7 / 7 | | | **total** | **426** | **1688 / 1798** | **113 / 119** | **1801 / 1917** | 7 / 7 | - **Excluded, in flight under this seat:** `system/job.test.ts` carries objectstack-ai#16292 (`:92`), objectstack-ai#14478 (`:471`), objectstack-ai#4667 (`:836`) and objectstack-ai#19184 (`:881`), and `ui/report.test.ts` carries objectstack-ai#20161 (`:233`), objectstack-ai#3916 (`:334`) and objectstack-ai#5013 (`:426`). All seven sit in titles. They wait for a later stage, after objectstack-ai#21703 and objectstack-ai#21702. - **Controls.** Lit, single line: `automation/approval.test.ts:135` reads one title with objectstack-ai#3508. Lit, multi-line: `api/discovery-environment-subset.pin.test.ts:63-66`, a `+` chain, reads as ONE message with its id on `:65`. Dark: the `// objectstack-ai#3508` comment at `automation/approval.test.ts:131` reads 0. Planted in a scratch copy of the head file: an id in a title reads 1 / 1, and an id in a comment reads 0. - **A wider pattern** (any `#` plus digits, so two-digit and six-digit numbers too) reads the same 105 / 110 in `automation/` at the base, and 0 / 0 at the head. - **At the head:** 1696 messages / 1807 ids in 405 files. `automation/` reads 0 / 0. Nothing else moved. ## How the area was chosen The directories are ranked by id count, and a stage takes whole directories up to about 100 ids. The four busiest each exceed that bound alone: `data/` (501), `ui/` (415), `api/` (201) and `system/` (165). The files directly in `src/` (120) are 20% over. `automation/` (110) is the busiest whole directory within about 10% of the bound, so it is this stage. The rule picked it before any card was read. Its 55 records (53 in this repository, 2 in objectui) were all readable in one pass. 54 answer 200. objectstack-ai#6362 answers 404, and its decision was read from its landing commit `b5404f496`. **Named for the next stages** (by directory, from the table): `data/` (about five stages, by subdirectory or file group; `data/driver/` alone is 52), `ui/` (about four), `api/` (two), `system/` (two), the files directly in `src/` (one), `kernel/` (one), `shared/` (one), `contracts/` with `conversions/` (one, 108), and `security/`, `ai/`, `identity/`, `integration/`, `migrations/`, `marketplace/`, `meta-spelling/` and `studio/` together (one, 96). The seven excluded ids join `system/` and `ui/` once their owners land. ## What each id became 38 literals (40 ids) now state a decision in words. 67 literals (70 ids) drop a citation the title already explains. Each record was read with its comments through REST, and where a record has no comments, from what landed. | record | ids | result | |:--|--:|:--| | objectstack-ai#3508 | 2 | `APPROVER_VALUE_BINDINGS`: "an approver value is picked from the records the engine resolves". `APPROVER_VALUE_SOURCES` (the follow-up): "where each picker finds its candidates, published on the wire". | | objectui#2955 | 1 | "for the decision dialog to render and enforce": both decision entry points collect the typed outputs, and `required` is enforced. | | objectstack-ai#3810 | 1 | "names the match-everything-write hazard": a filter emptied by interpolation matches every row, and the node is refused instead. The test pins the words `match-everything write`. | | objectstack-ai#4001 | 13 | "strict as of objectstack-ai#4001 批 9" becomes "an unknown key is refused, not stripped" (5 titles). Also "refused, not stripped", "an unknown key is refused, per shape" and "the unknown-key gate". Dropped from 5 titles that already read "unknown keys are rejected, not stripped". | | objectui#2670 | 1 | "so the flow designer renders it as a template": the designer's loop and region rendering reads this marker. | | objectstack-ai#4396 | 2 | "a function that writes says so; pure is the default", and "the authoring surface where a function declares its effect" (landed `eb4204b`). | | objectstack-ai#4697 | 2 | `defaultValue`: "a declared variable is bound on every path" (ruling A). Dropped once. | | objectstack-ai#3896 | 3 | "outputSchema retired: declared, never validated" (the audit close-out's reason, as `flow.zod.ts`'s tombstone records it). Dropped twice. | | objectstack-ai#4247 | 1 | "maxRetries — one default, and no zero-attempt “retry”" (landed `a648e96`). | | objectstack-ai#16134, objectstack-ai#15713 | 7 | "a region node reusing a top-level id is refused — one node-id space now spans every region" (ruling, batch 61). Dropped from 5 titles that state uniqueness. | | objectstack-ai#9205 | 5 | "template reference — notify content localized through an email template" (the ruled emailTemplates route). Three titles say "the template path" where they said "pre-objectstack-ai#9205". Dropped once. | | objectstack-ai#7086 | 1 | "severity — the closed info \| warning \| critical vocabulary" (the enum route). | | objectstack-ai#4415 | 3 | "FlowNodeSchema parses its own regions" (ruling 2026-08-07, direction 1). Dropped from 2 titles that already say it. | | objectstack-ai#4347 | 1 | "collectFlowGraphs — every region is walked, not only the top level" (landed `31e0be9`). | | objectstack-ai#4401 | 2 | "FLOW_REGION_SLOTS, the one declaration of where regions live" (landed `4bfd455`). Dropped once. | | objectstack-ai#4414 | 1 | "`condition` is pointed at the out-edges, NOT given the one-edit rename" (one working routing model, landed `5293114`). | | objectstack-ai#15429 | 1 | "taking every true branch must be declared" (ruling item 2: explicit `inclusive`). | | objectstack-ai#14149 | 3 | "every entry older than the value role" (ruling A: a value-role CEL slot on `assignment`). Dropped twice. | | objectstack-ai#19938 | 4 | "the CRUD `fields.*` value slots added exactly two rows". Dropped three times. | | objectstack-ai#15572 | 3 | "predicateSlotRefusal — a predicate slot holds bare CEL text", and "the other two doors refuse it". Dropped once. | | objectstack-ai#15662 | 1 | "structuralConditionRefusal — a structural condition is CEL text or an expression". | | objectstack-ai#15792, objectstack-ai#15807 | 4 | "REFUSES an `ast`-only envelope — admitted at first, refused once an evaluated slot required a `source`". Dropped from 2 titles that state the rule. | | objectstack-ai#17493 | 3 | Table row "a blank string — blanks are refused" (ruling A). Dropped twice. | | objectstack-ai#14945 | 4 | "EndConfigSchema — the `end` node contract: it may refuse the run with a message" (ruling 2′). Dropped three times. | | objectstack-ai#15617 | 4 | "`failed` is the fold INCLUDING what a delegating node rolled up from its child — it answers what the run caused" (ruling option 1). Dropped three times. | | dropped only | 36 | objectstack-ai#3196, objectstack-ai#3266, objectstack-ai#4158, objectstack-ai#4277, objectstack-ai#4343 (2), objectstack-ai#4389, objectstack-ai#4525, objectstack-ai#4738, objectstack-ai#4964 (2), objectstack-ai#6758, objectstack-ai#7085, objectstack-ai#9106, objectstack-ai#12278, objectstack-ai#14964, objectstack-ai#15430, objectstack-ai#15646 (3), objectstack-ai#16752, objectstack-ai#17306, objectstack-ai#17852, objectstack-ai#18102, objectstack-ai#18112 (2), objectstack-ai#18847, objectstack-ai#19151, objectstack-ai#19961 (4), objectstack-ai#20316 (2): each title already states the pinned decision. For objectstack-ai#4988 and objectstack-ai#6414, the two expect messages already say what was retired. | | objectstack-ai#6362 (404) | 1 | Dropped. The title "PRESERVES all seven envelope keys — measured, not assumed" carries the decision recorded in `b5404f496` (`webhook` was measured, and all seven keys survive). | ## Readers - **Test-name filters:** none. A tracked-tree search for `-t` and `--testNamePattern` finds only `packages/qa/dogfood/README.md:142` (`-t "owner-scoped"`), which is unrelated. - **Snapshots:** none. `automation/` has no `__snapshots__` and no `toMatchSnapshot`. - **Titles by substring:** every old title, plus a window around each id (250 needles), was searched across the tracked tree outside its own file. No gate, doc or script matches one. The hits are other files' own titles with the same words: `identity/`, `security/` and `automation/` siblings, a later stage's lot. There are also two code comments in `flow.zod.ts` and `flow-function.zod.ts`, which belong to the comment lane. - **Twin tables, not readers:** `packages/lint/src/validate-expressions.test.ts:4442/4445` and `packages/services/service-automation/src/decision-branch-expression-absent.test.ts:61/64` repeat the `flow-decision-branch-expression-absent` table's row names. Nothing compares them mechanically: the "same table" parity is prose in the headers, and it covers assertions, not names. They are outside this stage's surface (see Acceptance notes). ## Text-only proof A scratch tool (`textonly10.cjs`) compares base and head file by file on three legs: 1. **Skeleton:** the full AST, with string pieces masked. It must be identical. 2. **Comments:** every comment, byte-equal. 3. **Strings:** each string leaf that changed must sit in a test-call title position, or on one of the 4 declared lines (`flow-decision-branch-expression-absent.test.ts:63` and `:66`, table `name` values that feed `$name` titles; `sync-retirement.test.ts:120` and `:158`, expect messages). It must carry a tracker id before and no `#` plus digits after. - **Result:** 21 of 21 files SAME, 105 changed (101 title, 4 declared), on all three legs. - **Diff hunks:** exactly the 105 planned lines, with every file keeping its line count. - **Controls (10 of 10 as predicted, on scratch copies, each anchor hit once):** identifier rename DIFF; numeric literal DIFF; comment edit COMMENT DIFF; a non-title string with an id VIOLATION; a rewritten title given a new id VIOLATION; a title that was id-free at base edited VIOLATION; one title reverted to base SAME (104 changed); a declared string keeping an id VIOLATION; an undeclared expect message changed VIOLATION; a title re-split into a `+` chain DIFF. **Test counts:** the 21 files run at the base (in a separate base worktree) and at the head: 801 / 801 tests on both sides, with the same count and status sequence per file in 21 of 21. 560 full test names change, and each equals the base name with the planned replacements applied. ## Changeset: `skip-changeset` Measured, not assumed: - `npm pack --dry-run` of `@objectstack/spec` lists 2068 files, under `files[]` (`dist`, `src/**/*.zod.ts` and the rest). 0 of the 21 touched files are in it, and 0 `*.test.ts` at all. The control `src/automation/flow.zod.ts` is in it. - In `dist/`, three new phrases and three old ones each read in 0 files. The control `A predicate slot holds BARE CEL TEXT` reads in 2. So this PR publishes nothing, and no changeset is added. ## Verification (at `f3dc3fab03`) - `pnpm turbo run build` over all packages: 71 / 71. - `@objectstack/spec`: `vitest run --project local`, 612 files and 18185 passed, 1 todo. `typecheck` exit 0, including `check:test-typecheck`, whose program holds all 21 touched files. - **Gates:** `dispatch-gates --commands` derived 79 families, and all 79 exit 0. `--ran` reconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN. - **ESLint, a proven narrowing:** `--no-inline-config` over the 21 files, 0 errors and 0 warnings. The population comes from ESLint's own config: 21 configured, 0 ignored. No `parserOptions.project` or `projectService`, so no untouched file's verdict can move. - `check-governed-merges --test`: NOT governed, 210 changed lines. ## Acceptance notes - **Twin row names in other packages:** the lint and service-automation copies of the decision-branch table keep their `the objectstack-ai#19961 shape` and `the objectstack-ai#17493 control` row names, and their twin `describe` titles keep their ids. The lint copy is this card's own later share (the `packages/lint` test strings). The service-automation copy belongs to that package's lane. - **Code comments still carry ids** in these 21 files (for example `approval.test.ts:56`, `:69` and `:131`). They are the comment lane's, untouched here. - **`origin/main` moved** three commits past the base before this PR opened (objectstack-ai#21701, objectstack-ai#21707, objectstack-ai#21706). None touches `packages/spec`, so nothing was merged. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
… carries as the published spec (objectstack-ai#21709) (objectstack-ai#21717) Fixes objectstack-ai#21709 Clause-②: no ## What changes The `Console Pin Gate`'s probes no longer treat text that objectui's own source carries as evidence of either spec. A console bundle carries text from objectui's code as well as from the specs. objectui's component registry writes `inputs` descriptions that copy spec `.describe()` text, either verbatim or as a prefix it then extends. When the spec rewords one of those, the old text becomes published-only. objectui's literal still carries it, so a substring search found "the published spec" in a bundle built from this tree's spec. That is what has turned every merge-queue build red since objectstack-ai#21699 (`16d241a6af`): the object-gantt `markers` describe and objectui's `packages/plugin-gantt/src/index.tsx:190`. - `scripts/console-spec-probes.mjs`: `readHostSourceBlob(dir)` reads objectui's tracked code files at the pin (`git ls-files`; test files excluded; a quote's backslash normalised). `chooseProbes` now takes that blob as `hostBlob`, required. It is a TypeError without it. - **The rule (both legs):** a candidate that is in the bundle **and** carried by objectui's source is not evidence. It is counted (`counts.hostCarried`), never decides a verdict, and is never returned as a probe, so it is never stamped. A candidate **absent** from the bundle is still evidence, whoever else carries it. The rule excuses presence, never absence. - **One new refusal:** if every published-only candidate is in the bundle and objectui carries every one, the stale leg has no probe left. That is neither "no skew" nor "absent", so the assert exits **2** (inconclusive). The old code answered that same state exit 1, with a false accusation. It never passed. - `scripts/assert-console-spec-injection.mjs`: a new required `--objectui` flag (objectui's build tree, the git checkout at the pin). Its messages report host-carried text separately, so a pass no longer prints "all N published-only descriptions are absent" when one of them is in the bundle. - `scripts/build-console.sh` (**declared, and strictly needed by the route**): the single assert call site passes `--objectui "$BUILD_ROOT"`, the tree it just built. The only other way to find that tree is to reach two levels up from `--vendored`, which couples the assert to a path layout. A required flag means a forgotten call site fails loudly (exit 2). - `scripts/check-console-injection.mjs`: the replay logic is unchanged. It needs no objectui tree, because the build never stamps a host-carried probe. Its self-test gains battery 14, and batteries 12 and 13 now pass `--objectui`. - **Same-class fix on the fresh leg, declared:** the same rule applies to the injected-only witness. A witness that objectui writes itself is no proof of the injection. Before this change, a bundle that held objectui's literal and **no spec at all** passed; now it reads "neither spec appears" (exit 2). The four bounded-fix conditions all hold: same defect class, same function, a file nobody else has claimed, and the same gate family. It is pinned in battery 14. - The stamp shape is unchanged (`stampVersion` 1). The stamp now records the **filtered** choice, so a cache-hit replay agrees with the build. ## Reproduction (base `7e0066af7a`, the head of queue run `37187916146`) - **CI:** queue run `37187916146`, job `111393796807` ("Build the Console SPA at the pinned objectui SHA"). Its triage comment on objectstack-ai#21700 quotes `✗ Built console still carries the PUBLISHED @objectstack/spec.` I could not read the raw job log from this container: the log blob host answered 403. So the per-candidate figure comes from the local build below, at the same commit. - **Local, the real door:** `scripts/build-console.sh` at `7e0066af7a`, run under `os-verify-lock.sh`. It used objectui `ab1879721595`, and the vendored `@objectstack/spec` resolved to **17.6.0**. Lock held 559s. Result: exit 1, `(1 of 38 published-only descriptions), the first of them: "Extra vertical reference lines drawn like the Today marker ({ date, label?, color? })"`. - **Measured, not assumed:** over that real bundle (33.3 MB of JS), the published-only candidates present are exactly **1 of 38**, and it is the `markers` text. objectui's tracked non-test source carries it. The injected-only candidates present are 26 of 26, and none of those is host-carried. ## Route: (a), by measurement - **(b), whole-literal matching, would fix today's collision.** The `markers` text is not a whole literal in the real bundle. - **It leaves half the family open.** In the real bundle, **9** spec describes are whole literals inside objectui's own chunks, for example "Action IDs available for related records" in the `plugin-grid` chunk. Rewording any of those 9 would recreate this red under (b). - **At the pin, over the module's own file filter**, objectui's non-test code holds 18 literals equal to a spec describe and 18 more that begin with one. - **(a) covers both shapes.** It drops only text whose presence could not have been evidence anyway, and only when that text is in the bundle. - **Leak detectability (pin 2 on the real bundle):** I added the published 17.6.0 JS as a chunk to the real assets. The head assert exits 1 on `37 of 38`, detector "Actions to execute during transition". Replaying the good build's stamp beside those assets also exits 1. - **Cost:** the host blob is 32.3 MB and reads in about 0.3 s. ## Pins (battery 14, `node scripts/check-console-injection.mjs --self-test`) Base: 44 assertions. Head: 67. Every fixture runs the real assert script and replays its stamp through `evaluate()`. The mirrored texts sort **first**, so an unfiltered pick would choose them. 1. **Pin 1 passes:** the injected spec plus an objectui literal that begins with a published-only describe, plus a second literal equal to one (which exercises the quote-backslash normalisation). The stamp records `staleDetector` = a text objectui does not write. The replay passes. 2. **Pin 2 still fails:** a bundle carrying the published spec's own JS fails with exit 1 and names a detector objectui does not write. No stamp is written. objectui's **test** file quotes that detector, so this case also pins that tests are not read as source. 3. **Pin 3, the replay agrees:** the replay matches the assert on both bundles: 0 on bundle 1, and 1 ("carries the PUBLISHED") on bundle 2 with the good stamp beside it. Battery 14 also covers: - the all-host-carried stale leg (exit 2, "cannot judge"); - host-carried text absent from the bundle, which stays a valid detector (exit 0, stamped, replay 0); - the fresh-leg case (exit 2); - an objectui tree git cannot list (exit 2); - `chooseProbes` without `hostBlob` (TypeError). **Ablation.** Predicted first and saved, then run through `scripts/ablation-replace.mjs` in wrap mode. The mutation was `const hostCarried = new Set();`. On disk the anchor went 1 to 0 and the marker 0 to 1. The restore was proven: blob `903c3e80cce1` equals HEAD, and `git diff HEAD` is empty. - **Self-test:** exit 1, with **13 failures, exactly the predicted list**, all in battery 14 (pin 1 ×6, pin 2 detector wording ×2, pin 3 bundle-2 wording ×1, all-host-carried ×2, fresh leg ×2). No other battery failed. - **Pin 2's exit 1 held with and without the fix.** - **Synthetic bundles under ablation:** exit 1 `1 of 38` with the `markers` detector, and exit 1 `38 of 38`. - **Real bundle under ablation:** exit 1 `1 of 38` with the `markers` detector, and exit 1 `38 of 38` with the published chunk added. ## The real door on this head - **End to end:** `scripts/build-console.sh` on `93ea8e7d80` reused the built objectui tree, rebuilt the console at the pin, and ran the fixed assert. Exit **0**, with `37 of 38 published-only descriptions are absent; 1 ... ARE in the bundle, and objectui's own source at the pin carries each of them too`. Lock held 278s. The next CI steps then ran on that dist: `pnpm check:console-sha` exited 0, and `pnpm check:console-injection --require-stamp` exited 0 (self-test 67, replay passed). - **That build was before the last commit.** `93ea8e7d80` differs from the final head `0bcf6a0a95` only in a self-test fixture line in `check-console-injection.mjs`, and that self-test was re-run on `0bcf6a0a95`. - **PR side:** all four changed paths are in `ci.yml`'s `console` filter, so `Console Pin Gate` runs on this PR. Three of them (`build-console.sh`, the assert, the probes module) are in the dist cache key, so the key moves and the cache misses. The PR head therefore gets a full console build at the pin with this assert, and that is the CI reading of the real door. - **Queue:** once this merges, every queue build's `Console Pin Gate` runs this assert. `release.yml`'s key hashes `build-console.sh`, so its next run rebuilds through the new call site too. ## Gates (on `0bcf6a0a95`) - `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` derived 32 commands. All 32 exited 0. - `--ran` reconciliation: 32 derived, 32 run, 0 NOT MEASURED, 0 unrun, every one with a recorded exit code. That includes `pnpm check:console-injection`, `check:console-sha`, `check:ci-filter-parity` (+ self-test), `check:nul-bytes`, `check:entry-guard` and `check:pm-dispatch-gates` (1976 cases, run detached). - **eslint, narrowed:** `eslint.config.mjs` lints all three changed `.mjs` files, so none is ignored. `--format json` reported 3 files, 0 errors and 0 warnings. The config has no type-aware linting, so this diff cannot move any untouched file's verdict. `build-console.sh` is outside eslint's population. The full `pnpm lint` is left to CI. ## Changeset `skip-changeset`: nothing published changes. The diff is root `scripts/` only, and the root package is private and ships no `files`. I built the console dist (the one published package this build feeds) and grepped it: `readHostSourceBlob` / `hostCarried` have 0 hits, while the positive control, the `markers` literal, is found in 3 files. ## Acceptance notes - **Dead branch, not touched:** the assert's "published spec is gone, but nothing unique ... was found" branch is unreachable, both before and after this change. The "neither" branch and the stale exit cover every way into it. Carrier: none. - **Parity tests stay evidence:** objectui's `apps/console/src/__tests__/registry-inputs-spec-parity.test.ts` quotes 2 of the 38 published-only describes. Tests are excluded from the host source, so in a real leak those two still count as evidence. - **Same-tree pin:** the reproduction and the real-door runs used the same tree as the failing queue run, `7e0066af7a` (its `head_sha`). `origin/main` has since moved by four commits, and none of them touches this gate's inputs. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Part of #21464
Clause-②: yes (narrowing)
What this does
The S-objectui-held stage of the
ComponentPropsMapz.unknown()close-out, per the claim5976829576, the stage-5 landing record5976140848, the seat answers5963787404and5969669440, the stage-5 ACCEPT5975923386anddomain:devx's pointer5974144504. The stage took its own value census first (below), then wrote down and typed the contracts that have one viable shape. Under the stop valve, it holds the five contracts (seven ledger lines) that have more than one shape, records them in the enumeration pin, and reports them on the card as forks. Read points are at the.objectui-shapinab1879721595. Every cited reader is byte-identical at objectuimain94985a92ba; the two cited@object-ui/typesdeclaration files changed elsewhere, and their cited lines are identical.ab1879721595object-ganttmarkersz.array(z.unknown()){ date, label?, color? }entries,datea string (module-private factoryobjectGanttMarker()), with aliasestitle/text/nametolabelandcolour/stroketocolorObjectGantt.tsx:2505handsschema.markerstoGanttView, which re-basesdate(GanttView.tsx:913-924), drops a marker whose date does not parse or falls outside the range (:2394-2413), and drawslabelandcolor(:2407,:4083-4100, SVG:3320-3332). objectui declares the authored marker as exactly this shape (types/src/objectql.ts:3787-3794, zod mirrortypes/src/zod/objectql.zod.ts:2738-2746)object-timelinemappingz.unknown(){ title?, date?, description?, variant? }, each a field name (module-privateObjectTimelineMappingSchema), with aliases from the flattitleField/dateField/startDateField/descriptionField/variantFieldObjectTimeline.tsx:551(title),:576(date),:578(description),:579(variant). objectui declares the same four strings on the component prop (:254-259) and inTimelineMappingSchema(:144-149)object-formfieldsz.array(z.unknown()), held at stage 3formFieldNameList()). A{ name }or{ field }object entry is refused with what to write insteadObjectForm.tsx:961-981,flatFields.ts:68-79. objectui declaresObjectFormSchema.fields: string[]. The form still draws a STORED{ name }entry by its name (:972,flatFields.ts:72) and skips any other object entry with a warning (:978)object-master-detail-formfieldsz.array(z.unknown()), held at stage 3MasterDetailForm.tsx:1693The
fieldshold's exit. objectstack-ai/objectui#11550's triage ruling (5969880008there) retired the{ name }entry from objectui's authoring faces, and its closing paragraph says this card "types object-form and master-detailfieldsas names once its.objectui-shacovers this landing". The pin covers both code landings: objectui806f327(the fixtures respelled) anddbd1081(the registration descriptions and the warning text).merge-base --is-ancestorexits 0 for each. The guide's own respelling (0a53c67) is on objectuimainonly. Measured at both trees, the only refused values are fixtures probing the read (census below).No new export. The three new shapes are module-private. No new member carries a default or a transform, so each parsed value is the authored one. The gantt marker is a factory the row calls, as
masterDetailDetailEntry()is, and not alazySchemaproxy. A bare proxy used as an array element is never forced byalias-integrity.test.ts's walk, which skips def values that are functions. The first full-suite run caught exactly that:alias integrity — coveragelistedui/component.zod.ts:6611 (this object-gantt marker)as unreached. The factory form is green.Held as forks (the stop valve)
Each of these has two or more viable spec shapes that no existing ruling or seat answer decides. Each keeps its hold. The enumeration pin's ledger now files each under a new
forkstage that names the shapes, and §2 checks that everyforkline names at least two different shapes. The emptiedobjectui-heldstage leavesSTAGES. Each fork is reported in this stage'sos-dev-reportopen_questionswith its census.object-metricdrillDown.report: direction A's premise is disproved by measurement, so it is reported as a fork and takes no shape, as the ACCEPT5975923386directs. Premise (1) holds: the one drawn report the census finds (objectMetricDrillDownMembers-8071.test.tsx:282, a dataset-bound summary report withnameandlabel) parses throughReportSchema. Premise (2), thatisDatasetBoundReport's two arms are exactly whatReportSchemaadmits, fails in both directions (measured by parse, this branch's source):isDatasetBoundReport)ReportSchema{ name, label, type: 'joined', blocks: [{ name }] }, no block binds a dataset{ dataset: 'sales' }, noname/label/values{ name, label, dataset: 'sales' }, novaluescustomatdataset){ name, label, type: 'joined', dataset, blocks: [...] }customatdataset)The first row is the silent-fallback class this card closes. It comes from
ReportSchemaitself: a joined block'sdatasetis optional, although the schema's own refinement comment says each block is "dataset-bound".objectstack validatepasses such a report with exit 0, while a bound block naming an undeclared dataset is refused (chart-dataset-unknown). See Acceptance notes.object-formcustomFields: objectui's runtimeFormField(types/src/form.ts:1770) is open (an index signature beside forty-five members,:1906), and eight of its members are the grid widget's snake_case keys (min_rows,allow_add, …), which this package's camelCase rule for config keys does not admit as written.object-formandobject-master-detail-formsections: objectui#11550 KEPT the inline runtime field in a section ("shape 3",sectionFields.ts:369-370, declaredObjectFormSection.fields: (string | FormField)[]), so this waits oncustomFields's fork for its third entry arm.object-timelineitems: a feed entry'scontentis child schema nodes (a slot position the page walks would judge, or an opaque member), and the arm an entry must match is chosen by the parent'svariant(objectui's row-level refinement, or a plain union of the arms).action:group/action:menumembers: measured from the reads, the key set is mostlyaction:button's, keyed bytype. It also takes keys the rows leave undecided:outcomeMessages(recorded onaction:buttonas "a contract decision, not a pin re-measure"), a memberclassName, the member's ownproperties.paramsbag (static-params.ts:142-160) andendpoint(refused on the rows since finding(spec):action:button/action:iconacceptendpoint, the keyActionSchemarefuses with the prescriptionendpoint→target: one concept, two verdicts in one release #21005).The
object-kanbanconditionalFormattinghold (held-for-decision) is not in this stage's member list and is untouched. Its carrier, objectstack-ai/objectui#11522, is now in statecompleted(2026-10-03), so its exit may be readable. That is for the seat.The census
A writer is a value written on the block: a page-component node (an object literal naming the type, flat or in
properties, a literal annotated or asserted with the block's objectui type, a direct parse through the row), the block's React component with the member as a prop or insideschema={{…}}, or the argument of a same-file helper that mounts one (helpers found through a block literal or the block's JSX in their body, including one spread from a const; positional parameters resolved at every call site). Values resolve through same-file constants and spreads. Instrument: a TypeScript-AST walk over.ts.tsx.js.jsx.mjs.cjs.mts.json.yaml.md.mdx(fenced code parsed). For the typed members, a text search for the member key in every file naming the block found what the walk does not reach, and each hit was read by hand. Cross-check: the walk reproduces stage 5'sdrillDownpopulation exactly (26, 25 static).markersmappingfields, both forms7d0781482d(examples/,packages/,content/,skills/,apps/,docs/, 9306 files)ab1879721595(whole tree, 10267 files)main94985a92ba(7564 files; the release deleted 2726 changesets)4054ec2680, cloudb2d7a7f6f8objectstack writers:
packages/spec/src/ui/component-element-navigation-17987.test.ts(mapping: { title, variant }). For master-detailfields: the showcase'sproject-workspace.page.ts,content/docs/protocol/objectui/layout-dsl.mdx, and two test copies (packages/lint/src/validate-component-props.test.ts,packages/spec/src/ui/component.test.ts). All are field names.objectui refused values, under the writer test (
5966636964):markers: [{ date: 5 }]types/src/__tests__/gantt-declared-keys.test.ts:168@ts-expect-error)fields: [{ field: 'note' }],[{ field: 'sent_at' }]plugin-form/src/__tests__/objectFormFieldsMembers-8071.test.tsx:140,:199fields: [{ name: 'note' }]×2objectFormFieldsMembers-8071.test.tsx:177,:182fields: [{ field: 'note' }]topLevelFieldsWarnCoverage-8847.test.tsx:110fields: [{ name: 'note' }, 'status']topLevelFieldsWarnCoverage-8847.test.tsx:258fields: [{ name, label, type, required }, …](pin only)skills/objectui/guides/page-builder.mdmainNot writers: five
markersarrays mountGanttView, the runtime chart, directly (GanttView.virtual.test.tsx×2,GanttView.dateOnlyZone-10866.test.tsx, the plugin README'sGanttViewexample,demo/main.tsx). Fourteenfieldsmatches are object definitions or permission maps whose ownfieldskey the walk read as the block's (ObjectForm.effectiveOps×3,ObjectForm.managedEdit×3,ObjectForm.mobileFullscreen×3,drawerFormSectionDescription-9834,objectFormNumericStep-9574×2,LineItemsPanel.fieldWriteGate-10163×2). The 11 that are not static are run-time hand-offs (AppContent,useActionModal,RecordFormPage,ViewPreview,StudioDesignSurface,DrawerForm,EmbeddableForm,ModalForm,ObjectForm.tsx:387,MasterDetailForm.tsx:1693,ObjectView). None passes through the component-props gate.The forks' census, both objectui trees identical. objectstack, hotcrm and cloud author none of these, except one
itemsand threesections(strings) in objectstack.drillDown.report: 3 values. The one drawn report parses throughReportSchema; the twoit.eachprobes ({ note }, the retiredobjectNameform) are not drawn and are refused.customFields: 27 values (24 static, 31 entries), every entry keyednamewithlabelandtype. One carriesgroupand onedefaultValue, keys outsideFormField's forty-five that ride its index signature. No entry writes a snake_case grid key.sections: object-form 165 values (99 static); 192 string entries, 3{ field }entries and 7 shape-3 inline runtime fields (plugin-form/README.md's wizard,submitTargetRefusal.test.tsx×3). Master-detail: 13 values, strings only.items: 14 values (11 static): 8 feed entries and 5 gantt rows, none withcontent.action:group/action:menu: 40 / 19 values (12 / 6 static, 15 / 6 members). The keys used arename,label,type,locations,target,bodyExtra,bodyShape,objectName, and oneautoTriggerin a host auto-trigger test. None uses an undecided key.Changes
packages/spec/src/ui/component.zod.ts:objectGanttMarker()(with the reason it is a factory),ObjectTimelineMappingSchema,formFieldNameRefusalandformFieldNameList()with their docblocks. The four members are typed. The held members' docblocks now record each fork, re-read atab1879721595: the drillreportwith the measured disagreement,customFields, bothsections,itemsandactionMemberList. The gantt and timeline row docblocks no longer saymarkers/mappingstay open.packages/spec/src/ui/component-objectui-held-typed-members.pin.test.ts(new): §1 15 byte-identical parses of the census writers, plus the absent-member case; §2 17 refusals bycodeand path, plus the two prescriptions, the no-prescription control and the alias pointers; §3 each shape's exact member set, and the two forms'fieldsanswering identically, messages included; §4 the three D3 ids.packages/spec/src/ui/component-props-unknown-members.pin.test.ts: four lines leave the ledger (markers[],mapping, bothfields[]). Seven becomeforklines naming their shapes (customFields, both forms'sections,items, both action containers' members, and the drillreport, which wasobjectui-held). Theobjectui-heldstage is replaced byfork, and a §2 case is added.packages/spec/src/ui/component-form-family-typed-members.pin.test.ts: the header records this stage's outcome.packages/spec/src/migrations/entries/semantic/18.ui-object-gantt-markers-typed.ts,18.ui-object-timeline-mapping-typed.ts,18.ui-object-form-fields-names-typed.ts(new), andpackages/spec/src/migrations/registry.ts: three step-18 rationale fragments at orders 74, 75 and 76 (73 is the last taken onmain), inserted where each id sorts. The semantic region is regenerated bygen:migration-registry. No D2 conversion and noRETIRED_KEYS_BY_MAJORrow: page-componentpropertiesis not parsed on the save or load path, and the refused values are nested member values.check:generated --fix, which proved only these two stale:content/docs/references/ui/component.mdxanddocs/audits/2026-07-unknown-key-strictness-ledger.counts/ui.md(ui/196 → 198 sites, +2 strict)..changeset/21464-component-props-objectui-held-typed.md:@objectstack/specminor, BREAKING banner, theClause-②line, FROM → TO, the census, and the ADR-0087 marker registering the three ids.Measurements
Head
723df54741, base7d0781482d. Heavy runs went throughscripts/pm/os-verify-lock.sh, and every exit code was captured before any pipe.@objectstack/spec@17.6.0(the npm tarball,ComponentPropsMap[type].safeParse). Each of these is ACCEPTED there:markers: [{ date: 5 }],[{ label: 'Deadline' }],[{ date, title }];mapping: 'subject',{ titleField: 'code' },{ title: 5 }; object-formfields: [{ name, label, required }],[{ field: 'note' }],[5]; master-detailfields: [{ name: 'note' }, 'status']. Each is refused on this branch, pinned in §2.pnpm --filter @objectstack/spec testat723df54741: exit 0, Test Files 611 passed (611), Tests 18157 passed, 1 todo, nothing skipped. An earlier run ata88b9f3e4aread 610 passed and 1 skipped:root-entry-type-nameability.pin.test.tsskips by design whiledistis stale, and it ran here after a rebuild.pnpm --filter @objectstack/spec typecheckata88b9f3e4a(only a test comment differs at the head): exit 0,check:test-typecheck: OK(52 files / 246 errors / 135 signatures held).tsc -p tsconfig.test.json --listFilesOnlynames the three touched pins.gen:schemapass.check:generatedprovedcheck:docsandcheck:strictness-ledgerstale,--fixregenerated those two only, and the re-check is green. A laterturbo run build --filter=!@objectstack/docsbuilt 72 tasks, all successful.pnpm --filter @objectstack/lint testpassed 119 files and 5622 tests. The 5 skipped tests read lint's own builtdist, which this worktree had not built yet. After the turbo build,lazy-deps,runtime-lazy-depsandvalidate-component-propspassed 61 of 61.pnpm --filter @objectstack/example-showcase validateprinted "Validation passed".validateComponentPropsfrom lintsrcover the built spec, one block per page). These report nothing: a marker withdate/label/color, a{ title, variant }mapping, form and master-detail name lists, and an arbitrary drillreport(still held). These are reported:markers.0.date: 5ascomponent-props-invalid; a markertitleascomponent-props-unknown-keyatproperties.markers.0.title, its message naminglabel;mapping: 'subject'ascomponent-props-invalid;mapping.titleFieldascomponent-props-unknown-key; a form{ name: 'email', … }entry ascomponent-props-invalidatproperties.fields.0, with "write'email', not an object"; and a master-detail{ field: 'note' }entry with the section-vocabulary prescription.a88b9f3e4a). Each leg usednode scripts/ablation-replace.mjsin wrap mode, inside a driver with its ownEXIT INT TERMrestore trap on the absolute path, an empty hash read as failure, and HEAD blob1a6b65102a:markers→z.array(z.unknown()): anchor x1 → x0, blob →1f6bdbd1a9. Red: 9 failed, 86 passed. The enumeration pin's §1 received exactly[ "object-gantt markers[]" ]and its census-equals-ledger control read 88 against 87. The companion pin failed its five marker refusals, the alias pointer and the §3 member set.mapping→z.unknown(): blob →2ee8a60e25. Red: 8 failed, 87 passed. §1 received[ "object-timeline mapping" ], 88 against 87, plus the four mapping refusals, the alias pointer and §3.fields→z.array(z.unknown()): blob →5211b43913. Red: 9 failed, 86 passed. §1 received[ "object-form fields[]" ], 88 against 87, plus the four refusals, both prescriptions and the §3 two-forms identity.git diff HEADis empty. The pins import./component.zodfrom source, so no build ordistpreflight sits between mutation and run.723df54741:node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack(no paths) derived 114 commands, all exit 0.--ranprinted "114 derived, 114 run, 0 NOT-MEASURED, 0 UNRUN". The first pass reddened onlycheck-spec-docblock-symbol-anchors(and its--self-test) on a line anchor in the new pin's comment; it now cites the file. Every command was re-run on the final head.check-widening-tellsover the branch diff:--declaration noexits 4 with seven T1 tells, every one a key inside a formerz.unknown()bag (the marker's three, the mapping's four).--declaration yesexits 0.eslint --no-inline-config --format jsonover the 8 changed TypeScript files reports 8 files, 0 errors, 0 warnings. Population comes from eslint's own--print-config: those 8 resolve a config, and the changeset,component.mdxand the counts page resolveundefined. Invariance:eslint.config.mjsnever enables type-aware linting (its own text, about line 327), so this diff cannot move a verdict on an untouched file. The fullpnpm lintis CI's.pnpm lint, because they are CI-owned; objectui was read at the pin and atmain, not built against this spec. CI on this PR was not waited on.Acceptance notes
ReportSchemaadmits a joined report with no dataset-bound block.objectstack validateexits 0 onreports: [{ name, label, type: 'joined', blocks: [{ name, label }, { name, label }] }]. The same report with a bound block naming an undeclared dataset is refused bychart-dataset-unknown. objectui's report renderer sends it pastisDatasetReport(plugin-report/src/DatasetReportRenderer.tsx:208-214) to the pre-9.0 presentation bridge (ReportRenderer.tsx:108), which issues no query. The schema's own refinement comment says a joined report "carries its data onblocks(each block dataset-bound)". This is reported in the dev report for the seat to file, and it is the cheapest route out of thereportfork.mapping.title/mapping.dateare second spellings oftimeline.titleField/timeline.startDateField, read between those and the flat fallbacks. They are typed here as objectui declares them; whether to retire them is a different question. Noted, not filed.dateis any string, as objectui declares it and as the same row'sholidays/minDate/maxDateare. An unparseable date is still accepted and draws no line. Noted, not filed.@objectstack/specbump: its block schemas take these rows by reference (propsBagoverstripImportedDefaults(...)), but no objectui test parses a refused value through them. The refused values are fixtures that mount the component or parse objectui's own mirror. objectui source reads none of the four members' narrowed types.Generated by Claude Code