Skip to content

docs(adr-0056): reconcile Consequences with the P2/P4 pure model - #5970

Merged
os-trump merged 1 commit into
mainfrom
claude/issue-3794-adr0056-consequences
Aug 25, 2026
Merged

os-trump merged 1 commit into
mainfrom
claude/issue-3794-adr0056-consequences

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes #3794

⛔ This PR is docs/adr/** — a governed path. It must be merged by a human and must NOT reach the merge queue. It stays a draft: not marked ready, not enqueued, no auto-merge. Human merge is the review record.

What changed

docs/adr/0056-permission-editing-studio.md, prose only, two bullets in Consequences. Nothing else in the repo.

Both bullets still described the ADR's original Option B (system_permissions editable in Setup as an exception) — the model this ADR's own Status line records as superseded by the pure model. Direction was settled by triage on 2026-08-09: "the later, specific rulings win over the earlier summary sentence". P2/P4 stay as they are.

1. The bullet the card names (the target of #3794)

Capabilities are authored once, in Setup, through the sys_capability picker.

→ Capabilities are designed once, in Studio, through the sys_capability picker (P2); Setup only assigns permission sets to users (P1b) and shows every facet read-only (P1).

Verified still present before editing, with control probes so a zero-hit would have read as real rather than mis-pathed:

probe result
One authoring path per concern (control — known present) hit, line 223
P2 — Studio: System Capabilities editor (control — known present) hit, line 203
authored once, in Setup (target) hit, line 225

2. A second contradiction found by the audit — same defect class, same section

Studio becomes load-bearing for permission ops. An admin who can assign sets but lacks studio.access can no longer design them. … hence P2 keeps that grant in Setup and first-class.

This is Option-B residue twice over, and it is contradicted by four settled statements inside this same file:

  • P2 — "Capabilities are now designed here, not authored in Setup."
  • Decision 3 — "No exception for system_permissions. … The bootstrap concern (granting studio.access shouldn't require Studio) is resolved by the editor's env-scope entry point living inside Setup (/apps/com.objectstack.setup/metadata/permission/:name, setup.access), not by keeping a JSON/authoring field on the record."
  • Decision 1 — "reached from the Studio Access pillar (package scope, studio.access) and from Setup's env-scope metadata route (setup.access) … the same component, two entry points."
  • A2 (revised, ADOPTED) — "so capability design is available to an operator without a separate Studio entry".

The replacement text says only what those four already decide, plus what the code shows. A reviewer who prefers the audit bounded strictly to the one sentence #3794 names can drop this hunk on its own — it is a separate, self-contained hunk.

Evidence — every Consequences bullet audited against P1–P4 and against the code

# Bullet Verdict How it was checked
1 One authoring path per concern FIXED CapabilityMultiSelectField is rendered by Studio's packages/app-shell/src/views/metadata-admin/PermissionMatrixEditor.tsx:980, bound to draft.systemPermissions. Setup stamps permission-facet-link on all six facets including system_permissions — packages/data-objectstack/src/index.ts:3397-3402.
2 Setup/Studio audience split is honored accurate "operators assign" — RecordPermissionAssignmentsRenderer renders AssignedUsersSection on the Setup record page (P1b). "makers design" — Studio Access pillar → PermissionMatrixEditPage. A statement about audience, not about which surface hosts the editor; no tension with Decision 1's two entry points.
3 AI-authoring safety improves — no security concern reachable as a free-text blob accurate All three Setup surfaces short-circuit to the read-only renderer: detail read (DetailSection.tsx:261), inline edit (InlineFieldInput.tsx:248), record form (ObjectForm.tsx:664-669, widget || type). PermissionFacetLink.tsx contains no onChange, input, or textarea. The raw-JSON escape hatch contemplated in open question 5 was never shipped.
4a Rendering changed objectui-side; storage columns untouched accurate applyFieldWidgetOverrides is invoked from getObjectSchema (packages/data-objectstack/src/index.ts:3361) — the ADR names exactly that choke point. It sets only widget, never type; the framework object definition is unchanged.
4b Editors "read RowLevelSecurityPolicySchema / tabPermissions enum / AdminScopeSchema from @objectstack/spec — the editors couple to those shapes" left as-is; measurement reported Measured: those two symbols are imported nowhere in this repo — the only repo-wide occurrence is a comment at packages/app-shell/src/views/metadata-admin/clientValidation.ts:526 explaining that RowLevelSecurityPolicySchema is deliberately not substituted. PermissionAdvancedFacets.tsx declares local mirror interfaces and says the shapes were "checked against the spec schemas rather than sampled from live data (objectstack#7130)". So the bullet's trailing clause — "the editors couple to those shapes" — is exactly right, and it is the sentence's own gloss on "read". Under that reading the bullet is not wrong, so the fix would be a wording preference, not a direction correction. Not touched. If a reviewer wants it sharpened: "mirror RowLevelSecurityPolicySchema, the tabPermissions enum and AdminScopeSchema — checked against the spec schemas rather than importing them."
4c Q7 — env-scope metadata saves don't project onto the queryable data record left as-is; not falsifiable from this fence Self-labelled an open framework follow-up; P1–P4 are all objectui-side and none of them touches the projection, so nothing in this repo can close or contradict it. Not a Consequences↔P1–P4 mismatch.
5 Studio becomes load-bearing for permission ops FIXED See section 2 above. Also measured: PermissionFacetLink.tsx:71-78 builds the deep-link from the current appName (useParams), so from a Setup record page it targets /apps/com.objectstack.setup/metadata/permission/:name and never cross-navigates into Studio — i.e. what shipped is the "Setup-hosted route that reuses the component" branch of open question 1, which is what makes Decision 3's setup.access entry point real.

Audit outcome: 6 Consequences claims (5 bullets, the 4th having three sub-bullets). 2 fixed, 2 accurate, 2 deliberately left with the measurement reported.

Verification

Gate union re-run at the final commit c18be84e8, working tree clean, each verdict quoted from the gate's own output (not from $?):

gate verdict line
node scripts/check-changeset-presence.mjs ✅ No source of a released package changed in this range, so no changeset is owed. (1 file(s) changed, 0 of them under the src/ of a package the release covers)
node scripts/check-control-bytes.mjs ✅ check-control-bytes: OK (scanned 4950 tracked text file(s); skipped 85 binary).
node scripts/check-doc-links.mjs Links are valid across 13 scan roots.
node scripts/check-doc-component-types.mjs ✅ Every documented component type is registered.

No changeset — the presence gate itself says none is owed for this range.

Declared narrowings (CI runs the full farm regardless):

  • check:doc-snippets — outside its scan surface, by the script's own constant: check-doc-snippet-types.mjs:208 sets DOCS_ROOT = 'content/docs'; this diff is under docs/adr/. (It also cannot run in this worktree — ERR_MODULE_NOT_FOUND: typescript, no node_modules installed for a docs-only change.)
  • eslint — the changed file is outside the linted population by eslint's own configuration, not by my judgement: lint:root is eslint . … --ignore-pattern 'docs/**', and lint is turbo run lint (per-package) while docs/adr belongs to no workspace package (no docs/package.json). File count: 1, from the changeset gate's own output. Invariance: the diff is prose inside one Markdown file — no eslint config, tsconfig, or package.json changed, so no untouched file's verdict can move.

Manual on-disk confirmation of the edit, anchored in both directions rather than trusting an editor exit code:

authored once, in Setup:                0   (removed)
P2 keeps that grant in Setup:           0   (removed)
designed once, in Studio:               1   (injected)
structured editor becomes load-bearing: 1   (injected)

Generated by Claude Code


Generated by Claude Code

Two bullets in ADR-0056's Consequences still described the original
Option B (capabilities editable in Setup as an exception), contradicting
P2, P4, and Decision 3/4 of the same file:

- "Capabilities are authored once, in Setup, through the `sys_capability`
  picker" — P2 says capabilities are designed in the structured editor,
  "not authored in Setup", and the code agrees: the picker
  (CapabilityMultiSelectField) is rendered by Studio's
  PermissionMatrixEditor, while Setup stamps the read-only
  `permission-facet-link` widget on all six facets including
  `system_permissions`.
- "hence P2 keeps that grant in Setup and first-class", preceded by "an
  admin who ... lacks `studio.access` can no longer *design* them" —
  Decision 1/3 and A2 (revised) settle the opposite: the same editor has
  two entry points, and Setup's env-scope metadata route runs under
  `setup.access`, which is what dissolves the bootstrap knot.

Prose only; no code, no schema, no other file.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CSoz9uGhaaSgiq3hshtN7L
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Aug 24, 2026
@yinlianghui
yinlianghui requested a review from os-zhuang August 24, 2026 10:12
Merged via the queue into main with commit 090927f Aug 25, 2026
20 checks passed
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 28, 2026
…ts name 23 objectui issues that answer 404, and re-qualify 19 bare objectstack numbers (objectui#10803, batch 6) (objectstack-ai#10914)

Part of objectstack-ai#10803
Clause-②: no

Dispatched implementation of the `domain:ui` seat objectstack-ai#1 claim (comment
`5864334310`) on objectui#10803, batch 6, session
`https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk`. Citations
only: no sentence's claim moves, and every edited pending changeset's
frontmatter is byte-identical. The one runtime string that moves is
`InputSchema.wrapperClass`'s zod `.describe()` text in
`@object-ui/types`, which loses its dead pointer and nothing else
(amendment `5860244997`, Q1 = A; `patch` changeset). No test pins any
changed text: the literal-anchor sweep below finds no specific anchor,
so no test file is edited.

This batch carries the release note `5863776648`'s three lists:
- the last **23 family numbers**;
- the **18 bare objectstack numbers above 10900** from PR
objectui#10892's C0 census, plus **#13086**, a 404 the C0 instrument
cannot see because it shares a token with #13337 (**Premise**);
- the live-but-wrong bare `objectstack-ai#3391` at the two `rowCrudAffordances.ts`
sites beside `objectstack#3720`.

## Why `Part of`, not a closing line

The order says `Part of`. With this PR the family list (all 115 numbers
of amendment `5860244997` Q2) and the C0 above-10900 list both read 0.
Whether the card now closes, or carries the dead `objectstack#N` class
measured in **Acceptance notes** 1, is the seat's call.

## Premise, re-measured on `origin/main` `9f0c84a44` (the branch point)

- **The 23 family numbers.** REST `GET
/repos/objectstack-ai/objectui/issues/N`: 23 of 23 answer 404, and a
second read of each answers 404 again. `GET .../pulls/N` answers 404 for
all 23. Lit controls: objectui#10533 and objectui#7714 answer 200.
- **No new family member.** The distinct `objectui#N` citations in the
two in-scope classes at the branch point, less those at batch 1's head
`6c3ad7c80`, are 24 numbers. Each was read once: 24 of 24 answer 200. So
the family list is still batch 5's 23.
- **#14026 was a sister-repo card written as objectui's.**
objectui#14026 answers 404 as an issue and as a pull. objectstack#14026
answers 301 to objectui#10102, the card it was transferred to. That
card's measurement-round claim (branch
`claude/issue-14026-import-mapping-selector-probe`) is the session of
`ecf14190e`, the commit that added `14026-list-import-mappings-pin.md`,
and six sibling in-scope lines already write `objectstack#14026` for the
same card.
- **C0, the bare-number census** (the instrument of PRs objectui#10875
and objectstack-ai#10892, at the branch point):

```
git grep -hoP '(?:^|(?<=[^\w#&/.\-]))#\d+(?![0-9A-Za-z_])' 9f0c84a -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | sort -u | wc -l
```

- 984 distinct at `9f0c84a44`, against 998 at batch 5's `b2683a2c0`. The
14 that batch 5 re-pointed are gone, and none is new.
- Above 10900 there are 23: the same 5 CSS colours and the same 18
numbers. Each of the 18 answers 404 as an objectui issue and as an
objectui pull on two reads.
- In objectstack, 16 of the 18 answer 200 with the sentence's own
subject (the **C0 mapping** below). #13033 and #13413 answer 404 there
too, as issues and as pulls. Their squash commits exist in objectstack's
history (a full, not shallow, clone): `c459da6bc` "narrow the per-option
`default` key out of the form-view options vocabulary … (#13033)" and
`89448a52b` "remove the inert AUTH_SSO_PROVIDER_SCHEMA export (#13413)".
Both are ancestors of objectstack `main` (`git merge-base
--is-ancestor`, exit 0).
- **The C0 instrument's blind spot.** Its lookbehind refuses a `#`
preceded by `/`, `-`, `.` or `&`. That form (`#A/#B`, `-#N`) carries 109
distinct numbers at the branch point. The 17 that no earlier batch read
were each read once. 16 answer 200. **#13086 answers 404**, as an issue
and as a pull, in objectui and in objectstack. It sits in
`6985-wizard-card-r-alignment.md` as "the #13337/#13086 fence", in the
same token as #13337, so it rides here. objectstack's
`check-yaml-examples.ts` header, at its landing `2ebfe7e9f` (PR
objectstack#13267, which answers 200), reads "Check YAML Examples
(anti-drift for the AUTHORING format, #13086)" and "Ruled 2026-08-29
(#13086)".
- **objectstack-ai#3391.** objectui#3391 answers 200 with an unrelated subject (a
record-header api action placeholder). objectstack#3391 answers 200 as
the apiMethods whitelist contract card ("跟踪:UI 操作按钮与 apiMethods
白名单一致性契约落地"), and objectstack#3720's own title calls itself "objectstack-ai#3391
遗漏的第四个面".
- Every edited changeset is pending: it is present in `.changeset/` on
`main`. The checkout is not shallow.

## Census (the enumeration pin for this batch)

The instrument PR objectui#10854 printed and PRs objectui#10869 / objectstack-ai#10875
/ objectstack-ai#10892 reused, with this batch's 23 numbers substituted (REF = a
commit or tree):

```
git grep -nE '(objectui#|#|issues/)(8072|8127|8137|8204|8229|8248|8307|8408|9231|9241|9244|9365|9373|9375|9542|9553|9585|10117|10119|10120|10129|10132|14026)([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | grep -v 'objectstack#' | wc -l
```

- REF = `9f0c84a44` (branch point): **104** lines.
- One more line is hidden by the `grep -v 'objectstack#'` filter:
`9943-viewtype-totals-page-row-retired.md` names objectui#8127 beside an
`objectstack#` citation.
- So the true population is **105** lines: 28 changeset lines in 26
files, and 77 src lines in 42 files.
- Unfiltered, REF reads 111. The other 6 lines are live
`objectstack#14026` lines.
- REF = `2b3d2061a` (this head): **0**. Unfiltered it reads 7, all live:
the six `objectstack#14026` lines and the re-qualified one.
- This head merged with a fresh `main` (`8522396c0`, `git merge-tree
--write-tree`, clean, tree `f19d17884`): **0**. REF = `8522396c0` alone:
104.
- **C0**, the 19 numbers, bare and not `objectstack#`-qualified: 28
lines in 23 files at the branch point; 0 at this head. At this head C0
reads 966 distinct numbers, and above 10900 only the five CSS colours
are left.
- Lit control, the printed instrument over live objectui#7714 at this
head: 17 lines. Hex-colour false positives (a number followed by a hex
letter) at the branch point: 0.
- **Out of scope, as it stands** (the 23 numbers, filtered, whole tree
at this head):
  - 94 test lines in 36 files;
  - 5 `.github` lines in 1 file (`ci.yml`, objectui#9241);
  - 2 `apps/console` lines in 1 file (`FormPage.tsx`, objectui#8408);
  - 1 line of the root `vitest.config.mts`;
  - 0 scripts, 0 governed, 0 `CHANGELOG.md`.
- For the 19 C0 numbers: 13 test lines in 10 files, and 1 line of
`packages/plugin-tree/README.md`.

## Citation form

- **Landing shas.** The 9-character backticked sha of the commit on
`main` that landed the change the sentence rests on, as in the earlier
batches. All 15 distinct objectui shas below are ancestors of `main`:
`git merge-base --is-ancestor`, exit 0 each. Control legs in the same
checkout: the head of PR objectui#10902 (`496c63c06`) answers exit 1,
and the known ancestor `5f789538d` answers exit 0. `git rev-parse
--short=9` returns the same 9 characters for each.
- **Own-card pointers** in a changeset are dropped, not replaced. The
configured changelog generator (`@changesets/cli/changelog`, per
`.changeset/config.json`) prefixes each released entry with the hash of
the commit that added the file, which is that landing.
- **The claim lived only on the card.** Where the sentence rests on
something that lived only on the dead card, the sha only locates it:
"the card behind SHA".
- **Nothing answers.** The pointer is dropped and the sentence names the
card by role (objectstack-ai#9553 only).
- **Sister-repo numbers.**
- A bare sister-repo number becomes `objectstack#N` after reading it
there.
- "objectstack PR #N" becomes "PR objectstack#N", since the qualifier
now carries the repository. "framework #N", "upstream #N" and "spec #N"
keep their word, as batch 4 kept "framework PR objectstack#6942".
- Where the objectstack pull request itself answers 404, the sentence
cites its commit in that repository as objectstack `SHA`, the spelling
the tree already uses for an objectstack commit ("Measured on
objectstack `9bd4344e4`").
- **Runtime text** carries no sha: see **Special cases** 6.

## Mapping, the 23 family numbers

Lines / files are the branch-point census for that number. "Method" is
how the landing was found; for every source site, `git log -S
'objectui#N' -- FILE` names the commit that wrote the citation, and it
is the landing below unless the row says otherwise.

| dead number | resolution | method | lines / files | why the commit
carries it |
|:--|:--|:--|:--|:--|
| objectstack-ai#8072 | `c974edf14`; own-card pointer dropped; runtime pointer dropped
| changeset's adding commit, subject "(objectui#8072)" | 5 / 3 | it
mirrors `wrapperClass` on `InputSchema`, which is what both comments and
the `7722` changeset say happened |
| objectstack-ai#8127 | `ca3942729`; "the card behind `ca3942729`" twice (**Special
cases** 2) | `git log -S` names `ca3942729` for the first citation in
all 10 source files; `05a49f2ee` (objectui#9880) and `8a7e09fa1` (the
`9943` changeset's landing) wrote three later sentences that cite the
same fix | 17 / 11 | it derives `ViewType` from `@objectstack/spec`
instead of re-declaring it, and its message records the
`page`-degrades-like-a-typo measurement the sentences cite |
| objectstack-ai#8137 | own-card pointer dropped (landing `0fa7a9c83`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's pointer |
| objectstack-ai#8204 | own-card pointer dropped (landing `580b0fdf4`) | changeset's
adding commit | 1 / 1 | the pointer opened a paragraph as its own
sentence |
| objectstack-ai#8229 | "a separate finding" (changeset); "the finding `8b7ea3945`
reconciled" (`flex.tsx`) | `8b7ea3945`'s message: "Reconciles the third
face objectui#8229 found" | 2 / 2 | the finding lived on the dead card;
`8b7ea3945` is the commit that reconciled it, and it is the `7735`
changeset's own landing |
| objectstack-ai#8248 | own-card label dropped from the second list item (landing
`d02942b0e`) | changeset's adding commit; its message covers
objectui#8458 and objectui#8248 | 1 / 1 | the changeset lists the two
cards its one landing closed |
| objectstack-ai#8307 | `5591f03bd`; own-card pointer dropped | changeset's adding
commit | 11 / 4 | it makes a lane header over a windowed fetch say
`77+`, and it wrote every comment that cites the card |
| objectstack-ai#8408 | own-card pointer dropped; "seam 2 of the card behind
`8241a4400`" | changeset's adding commit; `8241a4400`'s message names no
seams | 2 / 2 | the seam list lived on the dead card |
| objectstack-ai#9231 | `383502b23`; own-card pointer dropped | changeset's adding
commit | 3 / 2 | it gives the create dialog's confirm control its own
accessible name, the rule both `i18n.ts` comments state |
| objectstack-ai#9241 | own-card pointer dropped (landing `250429c8f`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's heading |
| objectstack-ai#9244 | `bd0995738` | `git log --grep`: its message names the card; it
wrote all three comments | 3 / 2 | it emits one col-span class per
breakpoint tier, not one for the widest |
| objectstack-ai#9365 | own-card pointer dropped (landing `0970a0e00`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's pointer |
| objectstack-ai#9373 | `c1006ed8e`; own-card pointer dropped | changeset's adding
commit | 2 / 2 | it resolves the inline locale map before the
interpolation options, the `ListView` comment's subject |
| objectstack-ai#9375 | own-card pointer dropped (landing `e427e9c00`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's pointer |
| objectstack-ai#9542 | `43c0d1710`; own-card pointer dropped; "filed as a separate
card" (**Special cases** 3) | changeset's adding commit; `git log -S`
names it for the `action-button` / `action-icon` comments too | 9 / 6 |
it accepts and resolves an inline `I18nLabel` on `resultDialog` and
makes `ResultDialogSpec` derive its label members |
| objectstack-ai#9553 | nothing answers: "a separate card carried that census" | `git
log --grep` finds only `40f34b4ba`, which points at the card; no commit
lands it | 1 / 1 | see **Special cases** 4 |
| objectstack-ai#9585 | "`ee70287e4`'s pin measures it NOT GATED"; in its own
changeset, "a pin in this change measures it" | no commit names it;
`ee70287e4` adds the test "NOT GATED: the renderer paints the very node
the mirror refuses, without parsing it" | 2 / 2 | see **Special cases**
5 |
| objectstack-ai#10117 | `4c6f549ef`; own-card pointer dropped | changeset's adding
commit | 3 / 2 | it resolves a lookup title candidate in `page:header`
and adds the record-key safety net both comments describe |
| objectstack-ai#10119 | `73a3c89af`; own-card pointer dropped | changeset's adding
commit | 4 / 2 | it makes a nav ancestor's gates reach its subtree and
stops a group outliving its children |
| objectstack-ai#10120 | `80c54122e`; own-card pointer dropped | changeset's adding
commit; for each file `git log -S` names it, or a later commit that
cites its gate: `e0f820246` (objectui#10563) or `b809375ac`
(objectui#10163) | 16 / 13 | it makes a form neither submit nor offer a
field the caller may read but not edit, the FLS half every site names |
| objectstack-ai#10129 | `6cc910b6d`; own-card pointer dropped | changeset's adding
commit | 10 / 5 | it routes a field-backed action param to its record
picker and refuses an unreadable one |
| objectstack-ai#10132 | `061f5e829`; own-card pointer dropped | changeset's adding
commit | 8 / 4 | it makes the two declared-translatable dashboard
surfaces resolve, including the axis `title` forward |
| #14026 | re-qualified `objectstack#14026` | see **Premise** | 1 / 1 |
it is the card the pin's measurement answered |

## Mapping, the 19 bare sister-repo numbers

| number | resolution | what objectstack says | lines / files |
|:--|:--|:--|:--|
| objectstack-ai#11289 | `objectstack#11289` ("upstream") | "record:details sections
cannot survive an empty record: `hideEmpty` / `collapsible` /
`showBorder` are honoured by the renderer but undeclared" | 2 / 2 |
| objectstack-ai#11662 | PR `objectstack#11662` | "feat(spec): declare hideEmpty /
collapsible / showBorder on record:details sections" | 1 / 1 |
| #12616 | PR `objectstack#12616` | "feat(spec): declare record:details
section headerColor as a closed six-token enum" | 1 / 1 |
| #12718 | PR `objectstack#12718` | "feat(spec): retire preview mode —
the RuntimeMode 'preview' value and the whole PreviewModeConfig block" |
1 / 1 |
| #13033 | objectstack `c459da6bc` | the pull request answers 404; its
squash commit narrows the per-option `default` key out of the form-view
options vocabulary, the ruling `form-spec.ts` says was executed upstream
| 1 / 1 |
| #13337 | `objectstack#13337` | "docs(objectui): layout-dsl teaches
only shapes the live schemas accept" | 1 / 1 |
| #13086 | `objectstack#13267` | the card answers 404; PR
objectstack#13267 landed its ruled YAML-examples gate (see **Premise**)
| the same line |
| #13413 | objectstack `89448a52b` | the pull request answers 404; its
squash commit removes an inert schema export and leaves a note recording
the absence as a choice, the shape the `base.zod.ts` note cites as
precedent | 1 / 1 |
| #13632 | `objectstack#13632` | "[spec] `FieldSchema` accepts a
`lookup`/`master_detail` with no `reference` target …", the card
17.3.0's refinement answered | 3 / 3 |
| #13733 | PR `objectstack#13733` | "feat(spec): wizard view v1 —
declaration-and-refusal tightening of FormViewSchema type:'wizard' (Card
S)" | 1 / 1 |
| #13855 | `objectstack#13855` | the field-grouping decision card whose
option B is a section `group` reference, landed by `39404f3d9` (#13897)
"a layout section can reference a declared field group" | 1 / 1 |
| #13906 | `objectstack#13906` ("framework") | "two more
`computeExecCtx` seams read "failed" and "not wired" as one value …" | 6
/ 3 |
| #14274 | PR `objectstack#14274` | "fix(sdui-parser): refuse an
authored `type` attribute on the html tier …" | 1 / 1 |
| #14945 | `objectstack#14945` | "A flow cannot REFUSE with per-record
text …", honoured by `cca699149` "the flow `end` node honours `outcome:
'refused'`" | 1 / 1 |
| #15469 | `objectstack#15469` ("spec") | "`GanttConfigSchema` is
`strictObject(...).passthrough()` …", landed as `9c270bba0` "close the
gantt/tree config .passthrough() windows … (#15469)" | 2 / 2 |
| #15948 | `objectstack#15948` | "fix(plugin-auth)!: session payload
`positions[]` is the security axis, not the better-auth role scalar" | 1
/ 1 |
| #17493 | `objectstack#17493` | "three residues of #17322's node-door
refusal …", landed as `2c1011b01` "refuse a blank string in a flow
node's predicate slot" | 1 / 1 |
| #20051 | `objectstack#20051` | "judge a flattened view overlay's
top-level `options.KIND` …", whose door half is `6a4aec71d` | 1 / 1 |
| #20160 | PR `objectstack#20160` | "fix(spec): a joined report refuses
a top-level dataset / rows / columns / values, pointing each onto
blocks[]" | 2 / 2 |

The live-but-wrong number: "(`/me/permissions` `apiOperations`, objectstack-ai#3391)"
becomes "… `apiOperations`, objectstack#3391)" at the two
`rowCrudAffordances.ts` sites.

## Special cases (the judgement calls)

1. **#14026 is re-qualified, not dropped as an own-card pointer.** The
card behind `14026-list-import-mappings-pin.md` was never an objectui
card: it was objectstack#14026, now objectui#10102. Dropping the pointer
would lose which hypothesis the pin refuted. Re-qualifying it matches
the six sibling lines.
2. **objectstack-ai#8127, the card by role twice.**
- `CreateViewDialog.tsx`: "one of the sites the card records as
"drifted, …"" becomes "one of the sites the card behind `ca3942729`
records as …". That record lived on the card.
- `plugin-list` `ViewSwitcher.tsx`: "objectui#8127 was filed against the
two in `@object-ui/types`, and the maps below were described there as
total …" becomes "the card behind `ca3942729` was filed against …".
- `normalize-list-view.ts`: "The bug objectui#8127 records" becomes "The
bug `ca3942729` records". That commit's message carries the measurement:
`page` resolved "to exactly what it resolved a typo to".
3. **objectstack-ai#9542 in `8648-ui-action-four-undeclared-keys.md`.**
- The superseded paragraph keeps its pre-landing voice: "so it is filed
as a separate card and ⛔ not guessed at here".
- The superseding paragraph reads "`43c0d1710` landed the derivation".
- "(Noted here by the objectui#9542 seat, …)" becomes "(Noted here by
the seat that landed `43c0d1710`, …)".
4. **objectstack-ai#9553, nothing answers.** `base.zod.ts` said "No count of authored
`events` keys is stated here — objectui#9553 carries that census." No
commit landed that card. `40f34b4ba` only points at it, and the
`AGENTS.md` fix `7550728a6` names a different card. So the sentence now
reads "— a separate card carried that census". The census is not
restated, per AGENTS.md objectstack-ai#9.
5. **objectstack-ai#9585, the measurement's instrument.** The card measured the render
path NOT GATED, and no commit names it. But the commit that wrote both
citing sentences, `ee70287e4`, adds a pin that re-measures exactly that:
"NOT GATED: the renderer paints the very node the mirror refuses,
without parsing it".
- `disclosure.ts` now reads "(`ee70287e4`'s pin measures it NOT GATED)".
- Its own changeset, `8236-collapsible-open-intercept-retire.md`, whose
landing is `ee70287e4`, reads "(a pin in this change measures it NOT
GATED)".
6. **The runtime string.** Only the listed text moves.

| file | member | before | after |
|:--|:--|:--|:--|
| `types/src/zod/form.zod.ts` | `InputSchema.wrapperClass` `.describe()`
| "Classes on the wrapper div around the input and its label
(objectui#8072)" | "Classes on the wrapper div around the input and its
label" |

No test, doc or changeset quotes it: a whole-tree search for the old
string returns only the source line.
7. **objectstack-ai#8229 in `flex.tsx`.** "(objectui#8229, folded into objectui#7735's
ruling)" becomes "(the finding `8b7ea3945` reconciled, folded into
objectui#7735's ruling)". objectui#7735 answers 200 and stays.
8. **#13413's sentence.** "Precedent of the same shape:
objectstack#12009 / PR #13413." becomes "… objectstack#12009 /
objectstack `89448a52b`." objectstack#12009 answers 404 too, but it is a
qualified sister-repo number outside this batch's lists, so it is left
and listed (**Acceptance notes** 1).
9. **#20160 across a line break.** In
`10746-joined-report-clears-binding.md`, "(objectstack PR" ends one line
and "#20160: …" opens the next. They become "(PR" and
"objectstack#20160: …".

## The literal-anchor sweep (both test-pin classes, ruling `5861900779`)

- **Instrument.** Every string, template, numeric and regex literal in
all 4068 tracked test and script files (119016 distinct literals),
parsed with TypeScript.
- **Candidate filter.** A literal is a candidate only if it matches the
diff's removed lines with two lines of context, raw or
comment-flattened. That leaves 2839.
- **Test applied to each candidate.** Does its occurrence count DROP
between `9f0c84a44` and `2b3d2061a` in any of the 92 files this PR
changes, in raw text or in a comment-flattened form? 229 distinct
literals drop.
- **Every one is a generic token.** Digits and short numbers,
punctuation, single letters, `objectui#`, `objectui#1`, and whole-tree
scanners such as `/#\d+/` and `/objectui#\d+/`. The three `objectui#\d+`
matchers (`ActionRunner.disabledGate`, `registry-inputs-spec-parity`,
`catalog-gallery-render`) assert over their own test data and read no
changed file.
- **No specific anchor.** None is a batch number, a changed phrase, or
the changed `.describe()` string. So no test pins changed runtime text
(class one), and no source-reading test pins a changed comment or
docblock citation (class two).
- Test titles and comments that name these numbers are out of the card's
classes and stay (**Census**, out of scope).

## Held

**By the serial rule: nothing.** Re-mapped before the push, on 9 open
PRs: objectui#10910, objectstack-ai#10908, objectstack-ai#10907, objectstack-ai#10906, objectstack-ai#10901, objectstack-ai#10891, objectstack-ai#10777,
objectstack-ai#10278 and the release PR objectstack-ai#5400 (objectstack-ai#10902 and objectstack-ai#10904 had merged since the
claim).

Two of them share files with this PR. Their hunks were read against
their merge-bases; each file is identical at its merge-base and at
`9f0c84a44`, so the lines map directly.
- **objectui#10907, `types/src/zod/form.zod.ts`.** It inserts a refusal
constant before `InputSchema`, two tombstone members further down
`InputSchema`, and a comment in the `InputShorthandSchema` arm. This
PR's three edited lines (the `wrapperClass` comment and description, and
the arm's "shrank that row" comment) sit outside every one of its hunks
and their 3-line context.
- **objectui#10906, `metadata-admin/i18n.ts` and
`previews/ViewPreview.tsx`.** Its `i18n.ts` insertions are far from the
two `createDraft` comments, and its `ViewPreview.tsx` hunks are far from
the `options` fold docblock.

Trial merges with this head (`git merge-tree --write-tree`):
- clean for objectstack-ai#10910, objectstack-ai#10908, objectstack-ai#10907, objectstack-ai#10906, objectstack-ai#10901, objectstack-ai#10891 and objectstack-ai#10777;
- objectstack-ai#10278 (`eab4c8e52`) conflicts in `ObjectGrid.tsx`,
`plugin-grid/README.md` and `content/docs/plugins/plugin-grid.mdx`, and
conflicts identically against `9f0c84a44` alone;
- objectstack-ai#5400 (Version Packages) regenerates and is not a hold.

objectui#10891 shares no file with this PR.

## Changesets

- `.changeset/10803-dead-citation-sweep-sixth-batch.md`, EMPTY
frontmatter. It covers the comment-only edits in 15 released packages;
no published behaviour changes through them. It points at the second
file for `@object-ui/types`' runtime text.
- `.changeset/10803-sixth-batch-runtime-strings.md`,
`'@object-ui/types': patch`: the `wrapperClass` description loses its
pointer. No key, path, issue code, accept set, refusal or severity
moves.

## Proof of prose-only (C4), against `9f0c84a44`, on this head
`2b3d2061a`

- **Source.** Each of the 53 touched `.ts` / `.tsx` files was parsed at
`9f0c84a44` and at this head with TypeScript 6.0.3's `createSourceFile`,
and re-printed by `createPrinter({ removeComments: true })`.
  - 52 of 53 prints are identical.
- `form.zod.ts` is equal once the one listed substitution (**Special
cases** 6) is applied to the base print, matched once.
  - 0 parse diagnostics.
- Lit controls on the same instrument: editing a string literal moves
the print; re-spacing a comment does not.
- **Changesets.** The frontmatter block of every one of the 37 edited
changesets is byte-identical at `9f0c84a44` and this head (37 of 37, by
md5). The overwrite gate below agrees.
- **Scope of the diff:** 92 files, +175 / −140. That is 37 edited and 2
new changesets, and 53 non-test source files in 15 released packages. No
test file.

## Gates, on this head `2b3d2061a`

Each line is the gate's own verdict and exit code, captured by
redirect-then-`$?`.

- `node scripts/check-changeset-presence.mjs`, exit 0: "53 source
file(s) of 15 released package(s) changed, and this change declares 2
changeset(s): .changeset/10803-dead-citation-sweep-sixth-batch.md,
.changeset/10803-sixth-batch-runtime-strings.md."
- `pnpm changeset:check`, exit 0: "All workspace packages are in the
changeset fixed group." / "No changeset declares a `major` bump."
- `node scripts/check-changeset-overwrite.mjs` (report-only), exit 0: "2
changeset(s) added, 37 modified, 0 deleted". `declared at base` equals
`declares now` for 37 of 37.
- `pnpm check:changeset-claims` (report-only), exit 0:
- "Every one of those 1 address(es) either names the tree it was read
from, or points at a line this change does not move";
- "Every package declared across those 31 body(ies) is either not
negated …";
- the standing notice "75 pending changeset(s) describe a file this
change touches".
- Read against the diff: a pending changeset quoting a replaced pointer
would itself carry the dead number and sit in the census, which reads 0.
No pending changeset quotes the changed description.
- `pnpm check:control-bytes`, exit 0: "check-control-bytes: OK (scanned
9178 tracked text file(s); skipped 85 binary)."
- `pnpm check:new-line-citations`, exit 0: "VERDICT
new-cross-file-line-citations: 0 new citation(s), enforcement
report-only -> exit 0".
- `pnpm check:pending-changeset-literals`, exit 0: "No test source names
a pending changeset."
- Also run over the touched comments:
  - `pnpm check:installed-pin-claims`, exit 0 ("OK");
- `pnpm check:comment-mask-corpus`, exit 0 (1 disagreeing file, within
the ceiling objectui#7882 holds open);
- `pnpm check:handler-key-reads`, exit 0 ("every judged read is a
declared member of it").
- The governed-surface predicate over the 92 paths, exit 0: "NOT
GOVERNED — 92 path(s) checked against 5 governed surface(s); none
matched." Lit control `AGENTS.md`: exit 3.

**Tests**, through the shared verify lock, on `2b3d2061a`. Each is
`VERDICT command-exit 0`.
- `scripts/__tests__/`, the whole directory, whose whole-tree scanners
read the touched files: `Test Files 177 passed | 2 skipped (179)`,
`Tests 5322 passed | 2 skipped (5324)`. The two skipped files are the
network-escape fixtures that run only as a child.
- `packages/types/`, the whole package, whose runtime text moved: `Test
Files 264 passed (264)`, `Tests 5854 passed (5854)`. `pnpm --filter
@object-ui/types type-check`, exit 0.
- **The pins nearest the re-pointed text:**
- in `types`: `input-wrapper-class-mirrored-8072`, `zod-mirror-parity`,
`wrapper-class-declared-7722`, `zod-mirror-authors-no-defaults-7735`,
`collapsible-open-refusal-8236`, `tree-view-config-readers-8253` and
`layout-default-jsdoc-7361`;
- in `components`: `collapsible-open-intercept-8236`,
`registration-defaults-match-renderer-8229` and
`action-undeclared-keys-8648`;
- in `plugin-view`: `ViewSwitcher` and
`ViewSwitcher.viewTypeTotalsBothLegs-9943`;
  - in `plugin-kanban`: `laneCountHonesty-8307`;
  - in `plugin-grid`: `rowCrudAffordances` and `rowCrudEffectiveOps`.
  - Result: `Test Files  15 passed (15)`, `Tests  381 passed (381)`.
- No red leg: the sweep found no anchor to move, so there is no pin
whose old copy should fail.

**Declared narrowing.** NOT MEASURED locally:
- the full suites and type-check of the 14 other touched packages, and
eslint.
- Reason: the comment-stripped syntax tree of 52 of 53 touched source
files is identical to `main`, and the 53rd differs only by the listed
literal.
- CI runs the full farm.

## Acceptance notes

1. **A sister-repo class of the same defect: 30 `objectstack#N`
citations answer 404 in objectstack.**
- **Measurement.** Every distinct `objectstack#N` in the two in-scope
classes at the branch point is 359 numbers. Each was read once: 328
answer 200, 1 answers 301 (objectstack#14026 to objectui#10102), and 30
answer 404, each confirmed by a second read.
- **The 30:** objectstack-ai#5970 objectstack-ai#5976 objectstack-ai#6038 objectstack-ai#6124 objectstack-ai#6281 objectstack-ai#6331 objectstack-ai#6450 objectstack-ai#6483 objectstack-ai#6515
objectstack-ai#9933 objectstack-ai#9934 objectstack-ai#10354 objectstack-ai#10485 objectstack-ai#10695 objectstack-ai#11330 objectstack-ai#11507 objectstack-ai#11513 objectstack-ai#11658 objectstack-ai#11703
objectstack-ai#11753 objectstack-ai#11846 objectstack-ai#12009 #12868 #13117 #13670 #16126 #17147 #17762 #17987
#18012.
- **Sites at this head:** 82 lines in 63 files, 26 of them changeset
lines.
- **Three of them sit in sentences this PR edits, and are left as they
are:**
- objectstack#11846, "(objectstack#11846, landed as PR
objectstack#12718)" in `6748-preview-mode-provenance-ratchet.md`;
     - objectstack#12009, in `base.zod.ts`'s precedent line;
- objectstack#12868, in `form-spec.ts`'s "RULED 2026-08-28
(objectui#6263 / objectstack#12868, …)".
- **Why left.** They were not in this batch's lists, and the class is
the seat's to scope. objectstack's own card for dead tracker citations
in its tree is objectstack#19123, whose landing `66e266c93` counts
#12868 among the dead numbers it measured. Triage item 3 would put a
dead number in these classes on this card. The fix shape measured here
for such a number is the objectstack commit, as with `c459da6bc`.
2. **The rest of the bare `objectstack-ai#3391` population.** Only the two sites the
claim names were re-qualified. 28 more in-scope lines in 10 files write
the apiMethods whitelist card as a bare `objectstack-ai#3391`, which resolves to the
unrelated objectui#3391:
   - `ObjectDataPage.tsx`, `ObjectView.tsx` (app-shell);
   - `managedBy.ts`;
- `MePermissionsProvider.tsx`, `PermissionContext.ts`,
`PermissionProvider.tsx`;
   - `fieldWriteGate.ts`;
   - `ImportWizard.tsx`, `ObjectGrid.tsx`;
   - `ListView.tsx`.

It is live, not a 404, so it is outside the family pin. Two of those
lines pair it with a bare 3546 that means objectstack#3546 ("detail/form
面的 edit/delete 按钮接入服务端 effective 操作集"), while objectui#3546 is an
unrelated i18n card. Carrier: none.
3. **A stale claim beside a re-pointed sentence.** The same
`base.zod.ts` paragraph says "AGENTS.md's abridged protocol sketch shows
`events?: Record…` and its action-system commandment authors one".
`7550728a6` removed both from `AGENTS.md`, so that sentence is now
false. It is not a citation, and this PR does not touch it. Carrier:
none.
4. **The C0 blind spot, for any later census.** The bare-number
instrument's lookbehind hides a number written after `/`, `-`, `.` or
`&` (`#13337/#13086`, `-objectstack-ai#2231`). This batch read the 17 such numbers no
batch had read, and #13086 was the only 404. A later census can narrow
the lookbehind to refuse only a word character, `#` or `&` before the
`#`, and drop URL fragments by hand.
5. **Filenames are not citations.** Pending changeset and test FILENAMES
carry several of these numbers. They stay, as in PRs objectui#10707,
objectstack-ai#10797, objectstack-ai#10854, objectstack-ai#10869, objectstack-ai#10875 and objectstack-ai#10892.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk)_

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Oct 7, 2026
… bare apiMethods-card number (objectui#10803, batch 7) (objectstack-ai#10962)

Part of objectstack-ai#10803
Clause-②: no

Dispatched implementation of the `domain:ui` seat objectstack-ai#1 claim (comment
`5867587761`) on objectui#10803, batch 7, session
`https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk`. Citations
only: no sentence's claim moves, and every edited pending changeset's
frontmatter is byte-identical. The only runtime text that moves is two
console warnings, one in `@object-ui/app-shell` and one in
`@object-ui/plugin-detail`, which lose their dead pointer and nothing
else (amendment `5860244997`, Q1 = A; `patch` changeset). No test pins
any changed text: the literal-anchor sweep below finds no specific
anchor, so no test file is edited.

This batch carries release `5866922219`'s two lists:
- the **30 `objectstack#N` citations that answer 404**, in the card's
two classes (pending changeset prose and non-test `packages/*/src`);
- the **28 bare `objectstack-ai#3391` lines in 10 files** that mean objectstack's
apiMethods whitelist card, which batch 6 fixed at 2 other sites.

## Why `Part of`, not a closing line

Both lists read **0** after this batch (**Census**). The brief's rule
was a closing line if the card's lists all read 0. They do, but reading
the sentences found **10 more lines in the same two classes that cite a
dead objectstack number written bare**, three numbers in all
(**Acceptance notes** 1). Triage item 3 puts a dead number found later
in these classes on this card, so the card is not finished. Whether it
carries them as a batch 8 or closes is the seat's call.

## Premise, re-measured on `origin/main` `3b469c8ea` (the branch point)

- **Every distinct `objectstack#N` in the two in-scope classes.** 372
numbers (the one objectstack issue URL in these classes names 6227,
which is among them). Each was read once with REST `GET
/repos/objectstack-ai/objectstack/issues/N`:
  - 341 answer 200;
- 1 answers 301: objectstack#14026, transferred to objectui#10102, which
batch 6 re-qualified;
  - **30 answer 404**, exactly the 30 batch 6 listed.
- **The 30, read again.** A second `issues/N` read of each answers 404
(30 of 30), and `pulls/N` answers 404 for all 30. Lit controls in the
same run: objectstack#3391, objectstack-ai#3720 and objectstack-ai#3546 answer 200 as issues, and
`pulls/13267` answers 200.
- **objectstack-ai#3391 and objectstack-ai#3546, both repositories.**
- objectui#3391 is the record-header api-action placeholder card,
unrelated.
- objectstack#3391 is the apiMethods whitelist contract card: "UI 操作按钮与
apiMethods 白名单一致性契约落地". Its body names the effective operation set,
`/me/permissions`, the 405 import refusal and export derived from list,
which is what each of the 28 sentences says.
  - objectui#3546 is the missing-i18n-keys card, unrelated.
- objectstack#3546 is "detail/form 面的 edit/delete 按钮接入服务端 effective
操作集", the inline-edit gate the two paired lines describe.
- **objectstack history.** Read from a full, not shallow, treeless clone
of objectstack `main` (`git rev-parse --is-shallow-repository`: false).
- Every objectstack sha this PR cites is an ancestor of objectstack
`main` (`git merge-base --is-ancestor`, exit 0): the 24 this PR adds to
the tree, the 3 its edited sentences already cited (`c459da6bc`,
`89448a52b`, `9bd4344e4`), and the 7 this body names besides.
  - `git rev-parse --short=9` returns the same 9 characters for each.
- Control legs in the same clone: the head of the open PR
objectstack#20421 (`a22b90fc0`) answers exit 1; the known ancestor
`51789064` answers exit 0.
- **The one objectui sha.** `7a197e7c5` is an ancestor of the branch
point, exit 0. Control legs: the head of PR objectui#10945 answers exit
1, and `5f789538d` answers exit 0. This checkout is not shallow.
- **A cross-check, not the method.** objectstack's own sweep of dead
tracker citations in its tree (objectstack#19123's landing `66e266c93`,
its stages `21ab41041`, `5cf58eb16` and `0d7ed5a37`, and `f415bcf18`)
anchored eight of these numbers in its own files. For each of the eight
(objectstack-ai#5970, objectstack-ai#6483, objectstack-ai#9934, objectstack-ai#10485, objectstack-ai#11330, objectstack-ai#11846, #12868 and #17147) it
chose the same commit this PR cites.
- Every edited changeset is pending: it is present in `.changeset/` on
`main`.

## Census (the enumeration pin for this batch)

The 30 numbers (REF = a commit or tree):

```
git grep -nE 'objectstack#(5970|5976|6038|6124|6281|6331|6450|6483|6515|9933|9934|10354|10485|10695|11330|11507|11513|11658|11703|11753|11846|12009|12868|13117|13670|16126|17147|17762|17987|18012)([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | wc -l
```

The bare `objectstack-ai#3391`, with the same pathspec:

```
git grep -nE '(^|[^0-9A-Za-z_#/])objectstack-ai#3391([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | wc -l
```

| REF | the 30 | bare `objectstack-ai#3391` |
|:--|:--|:--|
| `3b469c8ea` (branch point) | **82**: 26 changeset lines in 24 files,
56 src lines in 39 files | **28** in 10 files |
| `c292a6400` (this head) | **0** | **0** |
| this head merged with `main` `5c94589f0` (`git merge-tree
--write-tree`, clean, tree `bba27eece`) | **0** | **0** |
| `5c94589f0` (`main` alone) | 82 | 28 |

- Lit controls on the same instruments at this head: live
objectstack#10856 reads 4 lines (4 at the branch point);
`objectstack#3391` reads 32 lines, against 3 at the branch point (28
re-qualified here, and this PR's sweep changeset names it once).
- **Out of scope, as it stands** (whole tree at this head, unfiltered):
- the 30 numbers: 84 test lines in 47 files, 1 scripts line, 2 lines in
2 `apps/console` files, 2 package READMEs (`auth`, `react`), 11 lines of
published `CHANGELOG.md` history in 8 files; 0 `.github`, 0 governed, 0
`content/docs`;
- bare `objectstack-ai#3391`: 12 test lines in 9 files and 23 `CHANGELOG.md` lines in
8 files.

## Citation form

- **An objectstack commit** is written the way batch 6 wrote its
stand-ins: objectstack and the 9-character backticked sha of the commit
on objectstack `main` that landed the change the sentence rests on.
- **A dead card beside its own dead pull request** collapses to that
pull request's squash commit (objectstack-ai#5970 with PR objectstack-ai#6450, objectstack-ai#10485 with PR
objectstack-ai#10695).
- **A dead number beside the live landing it already names** is dropped:
objectstack-ai#11846 beside PR objectstack#12718, #16126 beside PR objectstack#16920,
#12868 beside objectstack `c459da6bc`, and objectstack-ai#12009 beside objectstack
`89448a52b` (**Special cases** 3).
- **A ruling the dead card carried** is cited by its date, with the
commit that executed or recorded it, as batches 3 to 6 did for objectui
rulings.
- **One sentence cites this repository's commit**, `7a197e7c5`, because
the change it names landed here (objectstack-ai#6331).
- **Runtime text carries no sha.** In the two console warnings the dead
pointer is dropped (**Special cases** 8).
- **The bare `objectstack-ai#3391`** becomes `objectstack#3391`, and on the two lines
that write `objectstack-ai#3391/objectstack-ai#3546`, `objectstack#3391/objectstack#3546`.

## Mapping, the 30 numbers

Lines / files are the branch-point census for that number (a line naming
two of them counts under both).

| dead number | resolution | what that commit carries | lines / files |
|:--|:--|:--|:--|
| objectstack-ai#5970 | objectstack `97e7e3caa` | "unify ActionSchema.visible/disabled
on one condition shape (objectstack-ai#6450)", body "(objectstack-ai#5970)": `visible` gains the
boolean arm | 2 / 1 |
| objectstack-ai#6450 (PR) | the same `97e7e3caa`, its squash | as above; the card /
PR pair collapses | 2 / 1 |
| objectstack-ai#5976 (PR) | objectstack `795b6e1aa`, its squash | "5 值子集改名
`HttpMethodSubset`" | 1 / 1 |
| objectstack-ai#6038 | objectstack `7618ee814` | "key a container's default `list`
`_views` name by the runtime identity": leg 2 of 3 of the
objectstack#5164 ruling, the `packages/lint` half | 1 / 1 |
| objectstack-ai#6124 (PR) | objectstack `b3c1f3cd5`, its squash | "key `_views`
translations by the runtime view identity"; "The extractor now ASKS the
composer for the key" | 1 / 1 |
| objectstack-ai#6281 (PR) | objectstack `85ec26d28`, its squash, 2026-08-07 | "SDUI
props — enforce or remove (objectstack-ai#5775) (objectstack-ai#6281)": the shared
`PageContainerProps`, whose single key is `children`, for `page:section`
/ `page:footer` / `page:sidebar`, which were `EmptyProps` | 1 / 1 |
| objectstack-ai#6331 | objectui `7a197e7c5` | this repository's "SchemaForm reads the
canonical `visibleWhen`, reviving every metadata-form predicate
(objectstack#6331)" | 1 / 1 |
| objectstack-ai#6483 | objectstack `ee58392e1` | "ADR-0005 白名单强制 … (objectstack-ai#6483)"; its diff
carries the sentence the comment quotes, "Runtime-created sets … ride
`allowRuntimeCreate` (still `true`) and keep working" | 1 / 1 |
| objectstack-ai#6515 (PR) | objectstack `2fdb36eb9`, its squash | "SpecifierSchema
gains a closed `valueDomain` enum": "`bcp47_locale` is deliberately not
in the vocabulary", because `localization.locale`'s options ARE the
shipped catalogs | 1 / 1 |
| objectstack-ai#9933 | objectstack `d5552ca13` | "admit columnState as an explicitly
runtime-only view-overlay key" (subject ending "(objectstack-ai#9996)"; "(objectstack-ai#9933)" is
on the message's first body line), on the overlay faces including
`viewItemWireFields` | 3 / 3 |
| objectstack-ai#9934 | objectstack `79c46da90` | "producer-side user-facing marking
for hook refusal messages — userMessage channel (objectstack-ai#9934)":
`ApiErrorSchema.userMessage`, the contract half of the objectui#5210
split | 10 / 9 |
| objectstack-ai#10354 (PR) | objectstack `9e04c3e35`, its squash | "let the publish
door state the package it is promoting"; its changeset and code comment
carry the key-presence / `no_draft` warning `ResourceEditPage.tsx`
points at | 4 / 3 |
| objectstack-ai#10485 | objectstack `35ad101bc` | "retire the `themes` carrier key
and ThemeSchema (objectstack-ai#10485, ADR-0049) (objectstack-ai#10695)": "Ruled B (退役授权面,
2026-08-21)", "delete ui/theme.zod.ts whole" | 15 / 13 |
| objectstack-ai#10695 (PR) | the same `35ad101bc`, its squash | as above; the card /
PR pair collapses | 6 / 6 |
| objectstack-ai#11330 | objectstack `a9ee98992` | "manifest.runtime trust-tier text
states publish-gate-only enforcement truthfully", the trust-tier half
(**Special cases** 2) | 1 / 1 |
| objectstack-ai#11507 | objectstack `88b9d749a` | "declare sys_activity.type as an
open, author-extensible vocabulary": "Maintainer ruling 2026-08-24,
direction 4" | 13 / 9 |
| objectstack-ai#11513 | objectstack `e170b0ae5` | "lock package-declared permission
sets at the save door; clone to customize", quoting the 2026-08-24
ruling 「同意 第一步(创业阶段,Salesforce 式)」 | 3 / 3 |
| objectstack-ai#11658 | objectstack `1a6a19c31` | "open RecordActivityProps.types to
author-contributed activity kinds"; its message names objectstack-ai#11658 as the card
it settles, and it executes the 2026-08-24 ruling | 1 / 1 |
| objectstack-ai#11703 | objectstack `5cb62d88b` | "make clone_permission_set carry
all five copied facets"; its message names objectstack-ai#11703 as the card it
settles: the silent-grant-loss shape | 1 / 1 |
| objectstack-ai#11753 | "the 2026-08-25 ruling whose spec half is objectstack
`0e4e51b0a`" | `ActionParamSchema.carryOver`, whose changeset reads
"(objectstack-ai#11753 ruling, spec half; objectstack-ai#11992)" and "The maintainer's 2026-08-25
ruling on objectstack-ai#11753" | 2 / 2 |
| objectstack-ai#11846 | objectstack `0c2334f6c`; dropped beside PR objectstack#12718
| "retire preview mode — the RuntimeMode 'preview' value and the whole
PreviewModeConfig block (#12718)" | 3 / 3 |
| objectstack-ai#12009 | dropped beside objectstack `89448a52b` | the card of the
`AUTH_SSO_PROVIDER_SCHEMA` removal, whose landing the line already cites
(**Special cases** 3) | 1 / 1 |
| #12868 | dropped beside objectstack `c459da6bc` | the line already
cites the commit that executed the ruling; objectstack's own `f415bcf18`
anchors #12868 to the same `c459da6bc` | 1 / 1 |
| #13117 (PR) | objectstack `225e7690f`, its squash | "Readiness read
for the Phase-2 members … global:search and global:notifications both
have shipped platform data sources, so per the ruling both STAY
declared" | 1 / 1 |
| #13670 | "maintainer ruling 2026-08-31, option 2, recorded in
objectstack `8c6a7fc0b`" | "The #13670 ruling settled the question:
text's intended evaluation channel is `content` alone" | 1 / 1 |
| #16126 | dropped beside PR objectstack#16920 | PR objectstack#16920
(200) names #16126 in its body as the card it settles; merged 2026-09-08
as `859ded3ec` | 2 / 2 |
| #17147 | objectstack `aaacf1d5c` | "the install-time granted
permission set is REGISTERED at load and refuses nothing — say so, and
pin the measurement (#17147)", the measurement on `9bd4344e4` | 2 / 2 |
| #17762 | objectstack `4342c9923` | "guard three data lookups against
Object.prototype fall-through"; its message names #17762 as a card it
settles, `classifyFilterToken` among the three lookups | 1 / 1 |
| #17987 | objectstack `e233db9db` | "declare element-level `navigation`
on object-kanban / object-calendar …"; its message names #17987 as the
card it settles, and its Downstream note: objectui#8652 waits on it,
unlock criterion a released, installable `@objectstack/spec` (**Special
cases** 1) | 2 / 2 |
| #18012 | objectstack `176b03582` | "`$between` requires two non-blank
endpoints (#18012)": "Ruling executed: decision batch objectstack-ai#146 item 5,
**letter A**" | 3 / 3 |

The 28 `objectstack-ai#3391` lines, all now `objectstack#3391`: `ObjectDataPage.tsx`
(3) and `ObjectView.tsx` (2) in app-shell; `managedBy.ts` (5);
`MePermissionsProvider.tsx` (2), `PermissionContext.ts`,
`PermissionProvider.tsx`; `fieldWriteGate.ts`; `ImportWizard.tsx` (6),
`ObjectGrid.tsx` (4); `ListView.tsx` (3). Each was read: every one names
the server's effective API operation set, `/me/permissions`
`apiOperations`, or the 405 import refusal.

## Special cases (the judgement calls)

1. **#17987, two sentences.**
- `ObjectTree.tsx`: "blocked on objectstack#17987, whose unlock
criterion is a released `@objectstack/spec` carrying the declaration
being installable here" becomes "blocked on objectstack `e233db9db`,
whose unlock criterion …". That commit's Downstream note states the same
criterion.
- `ObjectCalendar.tsx`: "that card is `pm:blocked` on objectstack#17987"
becomes "that card waits on objectstack `e233db9db`". The label word is
not kept, because objectui#8652's label reads `pm:on-hold` today
(measured); "waits on" is the phrase `e233db9db`'s own note uses for
that card.
2. **objectstack-ai#11330.** "it is objectstack#11330's half of the same panel"
becomes "it is the trust-tier half of the same panel, which objectstack
`a9ee98992` settled separately". `aaacf1d5c`'s message calls objectstack-ai#11330 "the
sibling half of this very sentence", ruled the same way on 2026-08-30,
and `a9ee98992` (2026-08-30) is that half's landing.
3. **objectstack-ai#12009 collapses into the sha beside it.** objectui#6910's body and
ruling comment `5534414562` name "objectstack#12009 / PR #13413"
together as the one `AUTH_SSO_PROVIDER_SCHEMA` precedent, a card and its
pull request. Batch 6 replaced PR #13413 with its squash `89448a52b`, so
the card goes the way of batch 3's objectstack-ai#5401 / objectstack-ai#5505 pair.
4. **objectstack-ai#11753, two sites.** The card carried the ruling, and `0e4e51b0a`
is its spec half. Both sites keep "ruling" as the antecedent that
`ActionParamDialog.tsx`'s next paragraph ("The ruling's point …") reads.
5. **objectstack-ai#10354 in `ResourceEditPage.tsx`.** "since objectstack#10354
`doPublish` states" gains a comma, "since objectstack `9e04c3e35`,
`doPublish` states", so two adjacent code spans do not read as one.
6. **objectstack-ai#11507 in the 8137 changeset.** "objectstack#11658 executing the
maintainer's 2026-08-24 ruling on objectstack#11507" becomes
"objectstack `1a6a19c31` executing the maintainer's 2026-08-24 ruling":
the executing commit is named, and the ruling is cited by its date.
7. **Line breaks moved** where the stand-in is longer or shorter:
`ActionRunner.ts` (two sites), `ActionParamDialog.tsx`, `theme.ts`,
`theme.zod.ts` (two sites), `index.zod.ts` and the metadata-admin
`i18n.ts` comment, where "ruling on" became "ruling of 2026-08-24,".
8. **The runtime strings.** Only the listed text moves.

| file | member | before | after |
|:--|:--|:--|:--|
| `app-shell/src/layout/activityItemType.ts` | the `console.warn` in
`warnUnmappedActivityType` | "… `sys_activity.type` is author-extensible
(objectstack#11507, ruled 2026-08-24) and is not validated on write …" |
"… `sys_activity.type` is author-extensible (ruled 2026-08-24) and is
not validated on write …" |
| `plugin-detail/src/renderers/recordActivityFeed.ts` | the `warnOnce`
message in `warnUnknownActivityType` | "… `sys_activity.type` is
author-extensible (objectstack#11507, ruled 2026-08-24) and is not
validated on write …" | "… `sys_activity.type` is author-extensible
(ruled 2026-08-24) and is not validated on write …" |

No test, doc or changeset quotes either message with the pointer: the
census reads 0 in `.changeset/`, and the anchor sweep finds no test
literal that drops.
9. **`objectstack-ai#3391/objectstack-ai#3546`.** On the two lines that pair them (`managedBy.ts`,
`ObjectGrid.tsx`), both halves are qualified, as batch 6 qualified both
halves of "#13337/#13086". The other bare `objectstack-ai#3546` lines are not in this
batch's lists and are left (**Acceptance notes** 2).

## The literal-anchor sweep (both test-pin classes, ruling `5861900779`)

- **Instrument.** Every string, template and regex literal in all 4073
tracked test and script files (106544 distinct literals), read with the
TypeScript scanner.
- **Candidate filter.** A literal is a candidate if it matches the
diff's removed lines with two lines of context, raw or
comment-flattened: 1983.
- **Test.** Does its occurrence count DROP between `3b469c8ea` and
`c292a6400` in any of the 74 changed files, raw or comment-flattened?
136 do.
- **Every one is generic:** digits, punctuation, single words ("object",
"blocked", "locked"), character classes, and two regexes that read no
changed file: `/objectui#\d+|objectstack#\d+/` in
`registry-inputs-spec-parity`, which asserts over its own ledger's
reasons, and the older spelling of the three submitRedirect tests'
ruling matcher, quoted in their own doc comments (the live
`CITES_ITS_RULING` asserts over their own refusal text). None is a
changed phrase, a dead number or a changed warning.

## Held

**By the serial rule: nothing.** Open PRs were mapped at branch time (9
open) and again after the push, before this PR opened (11 open). The
second mapping came after the push, not before it; the same three files
were shared both times.

Three open PRs share a file with this PR:
- _Both PRs below have merged since this PR opened (objectui#10945 as
`06a96e948`, objectui#10908 as `b45d463a9`). The trial merge with
today's `main` is clean, and both censuses read 0 on it (contract review
`5870922323`), so nothing is owed. The two rows are kept as the record
at the time._
- **objectui#10945, `RecordDetailView.tsx`.** The blob at its merge-base
equals the branch point's. Its hunks are the imports and one block far
below; this PR's one changed line in that file is far from both.
- **objectui#10908, `types/src/zod/index.zod.ts`.** Its one insertion is
in the export list, far below this PR's two changed comment lines.
- **objectui#10278, `plugin-grid/src/ObjectGrid.tsx`.** The file drifted
between its merge-base and the branch point, so this PR's four changed
lines were mapped onto its merge-base by a line alignment: the nearest
of its hunks is more than 150 lines from any of them.

Trial merges with this head (`git merge-tree --write-tree`):
- clean for objectui#10952, objectstack-ai#10950, objectstack-ai#10949, objectstack-ai#10947, objectstack-ai#10945, objectstack-ai#10944,
objectstack-ai#10930, objectstack-ai#10908 and objectstack-ai#10777;
- objectui#10278 conflicts in `ObjectGrid.tsx`, `plugin-grid/README.md`
and `content/docs/plugins/plugin-grid.mdx`, and conflicts in the same
three files against `main` alone;
- objectui#5400 (Version Packages) regenerates and is not a hold.

`.changeset/9954-read-rate-banner.md` is held by this seat's
objectui#10913 dispatch (PR objectui#10949) and is untouched here. It
carries none of this batch's numbers.

## Changesets

- `.changeset/10803-dead-citation-sweep-seventh-batch.md`, EMPTY
frontmatter. It covers the comment-only edits in 17 released packages;
no published behaviour changes through them. It points at the second
file for the runtime text.
- `.changeset/10803-seventh-batch-runtime-strings.md`,
`'@object-ui/app-shell': patch` and `'@object-ui/plugin-detail': patch`:
the two warnings lose their pointer. What renders, and when and how
often each warning fires, are unchanged.

## Proof of prose-only (C4), against `3b469c8ea`

- **Source.** Each of the 48 touched `.ts` / `.tsx` files was parsed at
`3b469c8ea` and at this head with TypeScript 6.0.3's `createSourceFile`,
and re-printed by `createPrinter({ removeComments: true })`.
  - 46 of 48 prints are identical.
- `activityItemType.ts` and `recordActivityFeed.ts` are equal once the
one listed substitution each (**Special cases** 8) is applied to the
base print, each matched once.
  - 0 parse diagnostics.
- Lit controls on the same instrument: editing a string literal moves
the print; re-spacing a comment does not.
- **Changesets.** The frontmatter block of every one of the 24 edited
changesets is byte-identical at `3b469c8ea` and this head (24 of 24,
md5). The overwrite gate below agrees.
- **Scope of the diff:** 74 files, +157 / −115: 24 edited and 2 new
changesets, and 48 non-test source files in 17 released packages. No
test file.

## Gates, on this head `c292a6400`

Each line is the gate's own verdict and exit code, captured by
redirect-then-`$?`.

- `node scripts/check-changeset-presence.mjs`, exit 0: "48 source
file(s) of 17 released package(s) changed, and this change declares 2
changeset(s): .changeset/10803-dead-citation-sweep-seventh-batch.md,
.changeset/10803-seventh-batch-runtime-strings.md."
- `pnpm changeset:check`, exit 0: "All workspace packages are in the
changeset fixed group." / "No changeset declares a `major` bump."
- `node scripts/check-changeset-overwrite.mjs` (report-only), exit 0: "2
changeset(s) added, 24 modified, 0 deleted". `declared at base` equals
`declares now` for each of the 24.
- `pnpm check:changeset-claims` (report-only), exit 0:
- "Every one of those 1 address(es) either names the tree it was read
from, or points at a line this change does not move";
- "Every package declared across those 22 body(ies) is either not
negated …";
- the standing notice "87 pending changeset(s) describe a file this
change touches". Read against the diff: a pending changeset quoting a
replaced pointer would itself carry a dead number and sit in the census,
which reads 0.
- `pnpm check:control-bytes`, exit 0: "check-control-bytes: OK (scanned
9229 tracked text file(s); skipped 85 binary)." A `grep -P` control-byte
self-scan of the 74 files finds none.
- `pnpm check:new-line-citations`, exit 0: "VERDICT
new-cross-file-line-citations: 0 new citation(s), enforcement
report-only -> exit 0".
- `pnpm check:pending-changeset-literals`, exit 0: "No test source names
a pending changeset."
- Also run over the touched comments:
- `pnpm check:spec-symbols`, exit 0: "spec member citations: 1421
sources + 184 documentation pages; nothing cites a key its spec symbol
does not declare.";
  - `pnpm check:installed-pin-claims`, exit 0 ("OK");
- `pnpm check:comment-mask-corpus`, exit 0 (1 disagreeing file, within
the ceiling objectui#7882 holds open);
- `node scripts/check-hand-rolled-comment-mask.mjs`, exit 0 ("OK every
carrier is a DEBT entry, and every DEBT entry still carries one.");
- `pnpm check:handler-key-reads`, exit 0 ("every judged read is a
declared member of it").
- The governed-surface predicate over the 74 paths, exit 0: "NOT
GOVERNED — 74 path(s) checked against 5 governed surface(s); none
matched." Lit control `AGENTS.md`: exit 3.

**Tests and type-check**, through the shared verify lock, on
`c292a6400`. Each is `VERDICT command-exit 0`.
- `scripts/__tests__/`, the whole directory, whose whole-tree scanners
read the touched files and changesets: `Test Files 177 passed | 2
skipped (179)`, `Tests 5332 passed | 2 skipped (5334)`. The two skipped
files are the network-escape fixtures that run only as a child.
- `packages/types/`, `core/`, `react/`, `i18n/`, `providers/`,
`permissions/` and `data-objectstack/`, whole packages, in one run:
`Test Files 704 passed (704)`, `Tests 13170 passed | 13 skipped
(13183)`.
- The eight touched plugin packages (calendar, designer, detail, form,
grid, kanban, list, tree): `Test Files 787 passed | 1 skipped (788)`,
`Tests 7521 passed | 27 skipped (7548)`.
- `packages/components/`: `Test Files 324 passed | 1 skipped (325)`,
`Tests 3148 passed | 24 skipped (3172)`.
- `packages/app-shell/`: `Test Files 854 passed | 1 skipped (855)`,
`Tests 8789 passed | 9 skipped (8798)`.
- Type-check: `turbo run build` of the 28-package dependency closure
(`Tasks: 28 successful, 28 total`), then `pnpm
--workspace-concurrency=2` with the 17 package filters `run type-check`:
17 script echoes, 17 `Done`. A first attempt before the build exited 2
on an unbuilt dependency (`Cannot find module '@object-ui/types'`) and
measured nothing.
- No red leg: the sweep found no anchor to move, so there is no pin
whose old copy should fail.

CI on `c292a6400`: 43 check-runs, 40 success, 3 skipped, 0 failed; `Spec
Main Shape Gate` success.

## Acceptance notes

1. **Dead objectstack numbers written bare: 10 more lines in the same
two classes.** A bare number resolves to this repository, where each of
these is a live, unrelated card, so no `objectstack#` census sees them.
- **Measurement.** The bare-number instrument of PRs objectui#10875 /
objectstack-ai#10892 / objectstack-ai#10914 reads 965 distinct numbers at this head. The 916 between
100 and 25000 were each read once as objectstack issues: 877 answer 200
and 39 answer 404. Reading the sentences of those 39, three mean an
objectstack card or pull request (below); the other 36 cite objectui
cards or objectui pull requests.
- **objectstack-ai#9934**, 7 lines in 7 files:
`.changeset/7980-agent-key-envelope-read.md`, and in app-shell
`index.ts`, `apiErrorEnvelope.ts` (2), `PackageFormDialog.tsx`,
`StudioDesignSurface.tsx` and `packages-io.ts`. All mean the
`userMessage` channel, objectstack `79c46da90`.
- **"PR objectstack-ai#6281"**, 2 lines in `containers.tsx`, beside objectstack#5775.
The landing is objectstack `85ec26d28`.
- **"objectstack PR objectstack-ai#8452"**, 1 line in `useRecordCrudVerdicts.ts`. The
landing is objectstack `27358d517` ("add batch recordIds to
security/explain (objectstack-ai#8326) (objectstack-ai#8452)").
- None of them sits in a sentence this PR edits, so they are outside
this batch's lists and left. Carrier: this card, triage item 3.
2. **The rest of the bare `objectstack-ai#3546` population.** Five more comment lines
write objectstack#3546 as a bare `objectstack-ai#3546` (`RecordDetailView.tsx` 2,
`RelatedRecordActionsBridge.tsx`, `record-details.tsx`,
`fieldWriteGate.ts`), and one writes it as `objectui#3546`
(`plugin-detail`'s `index.tsx`). Each names the server's effective API
operation set on a detail or form surface. It is live-but-wrong, not a
404, like the `objectstack-ai#3391` class this batch closed. Carrier: none.
3. **A stale label in a comment.** The `ObjectCalendar.tsx` sentence
said objectui#8652 is `pm:blocked`; that card reads `pm:on-hold` today.
**Special cases** 1 says how the repaired sentence avoids the label.
4. **Filenames are not citations.**
`.changeset/17147-plugin-disclosure-not-enforced.md` carries one of the
30 numbers in its name; it stays, as in PRs objectui#10707, objectstack-ai#10797,
objectstack-ai#10854, objectstack-ai#10869, objectstack-ai#10875, objectstack-ai#10892 and objectstack-ai#10914.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk)_

_Tests block completed by the `domain:ui` seat objectstack-ai#1 from the dev report
`5870507620` (the suites that finished after this PR opened), and three
figures corrected after contract review `5870922323` (the objectstack-ai#9933 and
objectstack-ai#6515 quotes, and the Held rows); no code claim moved._

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ADR-0056 的 Consequences 自相矛盾:「Capabilities 在 Setup 里作者化」与 P2/P4「在 Studio 设计、Setup 里没有 facet 可编辑」冲突

2 participants