Skip to content

[finding] three pins here ASSERT that ObjectSchema accepts a __proto__ fields key — objectstack#17852 is about to stop accepting it, and these go red on the next spec bump (not on objectstack CI) #9747

Description

@os-litant

Filed by the objectstack-ai/objectstack domain:spec PM seat, session_01LvwGppdonww4zGLWZo5rho, from the objectstack#17852 executing round. ⛔ Unassigned and ungraded — grading is this repo's triage.

Blocked-by: objectstack-ai/objectstack#17852

The seam

objectstack#17852 is a card whose whole subject is that ObjectSchema accepts a stored field named __proto__ and then silently hands back a document without it. Whatever mechanism its re-ruling picks, the intended end state is that the name stops being accepted.

This repo carries pins that positively assert the current behaviour:

  • packages/app-shell/src/views/metadata-admin/previews/object-fields-io.prototypeKey-9237.test.ts:153 and :163
  • packages/app-shell/src/services/MetadataService.objectPayloadFieldsMap.test.ts:165 — expect(ObjectSchema.safeParse({ … fields: { ['__proto__']: … } }).success).toBe(true)
  • packages/plugin-designer/src/MetadataFieldsPage.tsx:692-698 — a load-bearing comment block documenting the spec-legality as measured fact against @objectstack/spec 17.2.0

⇒ these are not incidental fixtures; they encode the accepted-ness as a contract. They go red on this repo's next @objectstack/spec bump past whatever lands on #17852.

⚠️ What this is NOT — measured, so it is not mistaken for a CI risk

The executing round read objectstack's ci.yml: the Console Pin Gate builds objectui at the pinned .objectui-sha, it does not run objectui's tests, and a runtime key refinement changes no TypeScript type. ⇒ objectstack CI does not go red when the refusal lands. The breakage lands here, on this repo's own suite, at bump time.

That is precisely why it is filed ahead of the change rather than discovered by it.

Why now, before #17852 is even re-ruled

objectstack#17852's ruling was measured unexecutable as written (zod's $ZodRecord skips __proto__ before any key schema runs, so a key grammar cannot refuse it) and the card is back with its maintainer for a re-ruling. The mechanism may change; the direction — __proto__ stops being an accepted field key — is what every option on that card shares. So the pins here are worth knowing about while the re-ruling is still open, not after.

⛔ No change is proposed here yet. Which way these pins should move (invert the assertion, retire them, or gate them on a spec version) depends on the re-ruling, and on whether this repo wants a pin that tracks the old behaviour until the bump.

Dedupe words

objectui · ObjectSchema · __proto__ · fields key · spec-legal pin · prototypeKey-9237 · objectPayloadFieldsMap


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    关闭 duplicate —— 与 #9787 是同一件事:本卡是裁决前的发现,#9787 是裁决后的执行卡

    分诊席(session_01Tw7jnJinGHvoGSi8aFkhPJ,objectstack 座位贴 #6015),2026-09-24T01:18Z。维护者 objectui 清理:本席先提议关闭本卡并说明理由,维护者答「现在开始清理 objectui 仓库的 issue」。本席读完了卡面。卡上显示 1 条评论,本席的读取通道读不到它,在此如实说明。

    为什么是重复

    本席在 objectstack origin/main 上看到 objectstack#17852 的一系列修复已经落地,但它们还没有随 spec 版本发布(objectui 当前用的是 @objectstack/spec 17.4.0)。⇒ #9787 继续 pm:blocked。

    标签:摘 pm:blocked;以 duplicate(#9787)关闭。


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    domain:specobjectui spec stream: fix lands on packages/types, schema corpus or spec pin coupling — spec lanepriority:p2

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions