Skip to content

chore(objectui): bump the console pin to 0df67f237c5a (carries objectui#12089) - #22812

Merged
objectstack-fleet[bot] merged 5 commits into
mainfrom
claude/issue-15204-s5-objectui-pin
Oct 11, 2026
Merged

objectstack-fleet[bot] merged 5 commits into
mainfrom
claude/issue-15204-s5-objectui-pin

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Part of #15204
Clause-②: yes (widening: the html-page save gate and os validate accept an element:repeater bound through dataSource alone)

This moves the bundled Console's objectui pin from 20c6d351ad74 (PR #22592) to 0df67f237c5ab46cbc65252c5f6bd05f2be44c48. That commit is objectui main at dispatch and the merge of objectstack-ai/objectui#12089, C9 part 1 (objectstack-ai/objectui#7611): Setup's positions and permission sets read the registry, and the catalog's active switch writes the activation ledger through stage 2c's door. This is stage 5 of #15204 (stage plan 6094501866, stage-0 order correction 3 in 6095755866, claim amendment 6106816979). Stage 6a (#22793) waits on it. #15204 remains open for its remaining stages.

The bump follows the repo's own procedure, as PR #22592 did: scripts/bump-objectui.sh, then pnpm objectui:build and node scripts/gen-sdui-manifest-node.mjs, then the gates they derive. It adds no step to that procedure.

This is not a release act. The Version Packages PR is untouched, and this diff edits neither packages/console/CHANGELOG.md nor packages/console/package.json. The console's release input is the new .changeset/console-0df67f237c5a.md.

Range

  • REST compare on objectstack-ai/objectui, 20c6d351ad74...0df67f237c5a (read 2026-10-11T07:48:57Z): status: ahead, ahead_by: 21, behind_by: 0, 293 files, merge base 20c6d351ad74. The pin moves forward from main's, and it contains objectui#12089's merge.
  • In the objectui object store, git merge-base --is-ancestor 0df67f237c5a origin/main exits 0. 20c6d351ad74..0df67f237c5a has 21 commits and 0 merges. Its 293 paths are 73 added, 219 modified, 1 renamed and 0 deleted.
  • The pin names exactly 0df67f237c5a, as the dispatch ruled. objectui main has moved since, to 802f0bc41f39 (git ls-remote, 2026-10-11T08:22:44Z). This bump does not chase it.
  • Cloud's .objectui-sha must not pass 0df67f237c5a until cloud is on objectstack v18. That decision is with the maintainer. Nothing in this PR touches cloud.

The range's notable commits (breaking first)

  1. 12ff25631 (objectui#6349 batch 10), annotated breaking. The row type of @object-ui/plugin-designer's VersionHistory timeline is declared as VersionHistoryEntry instead of VersionEntry. In the same batch, ConnectionState gets one declaration, in @object-ui/types, and @object-ui/providers' ThemeProvider props become ThemePreferenceProviderProps. These are objectui TypeScript types. No ObjectStack key moves.
  2. ce991bd70 (objectui#12085, objectui#12093): the one commit that moves an objectstack accept set. element:repeater and element:number publish the node-level dataSource binding as their only query input. The regenerated sdui.manifest.json loses the repeater's object (required), filter, sort and limit inputs, and the number's object and filter. It is the html tier's half of the retirement @objectstack/spec already carries ([Direction · v18] Retire the flat object/filter data-binding family — dataSource as the single data-binding door (re-anchor of the deleted #6590 tracker) #11509, .changeset/11509-element-flat-binding-retired.md). The renderer still reads the flat keys as the binding's fallback. The section below has the measurement.
  3. 0df67f237 (objectui#12089, C9 part 1): Setup's positions and permission sets read the registry, through the metadata-admin pages' environment scope. This is the card's acceptance, measured below.
  4. 5330afd1f (objectui#12086): list views read an absent userActions.editInline as on, the v18 default. This is the consumer half of spec: ListView.userActions.editInline defaults to true in v18 and editInline: false is the opt-out; objectui reads an absent key as on (maintainer ruling 2026-10-10, after objectui#5144) #22605, whose spec half (f53f14bb3, feat(spec)!: ListView.userActions.editInline defaults to true on the v18 line; editInline: false is the opt-out (#22605, spec half) #22629) is already on main. A list view that declares neither key now offers in-place editing to a caller who may update the object.
  5. Write affordances read one affordance-to-grant map:
    • 023f00d46 / 5af42dbbd (objectui#12082): a create form asks the create grant, and eighteen write affordances, then five more that read no grant at all, read one affordance-to-grant map (the grid's row Edit/Delete, bulk Delete and inline edit, and the kanban card move among them);
    • 5f75cfad1 (objectui#12103): in-place and in-cell edit honour the field write grant, and the owner field the transfer grant.
  6. Other console behaviour:
    • 29b994902 (objectui#12105): a promoted bulk action's field-backed param resolves through the shared action-param resolver.
    • b7cd5c891 (objectui#12108): a create form says "Set automatically when saved." under a server-filled field.
    • 16c8810ac (objectui#12081 item 2): a list's calendar view fetches the days it shows, in fetch batches.
    • 029bdaf45 (objectui#12081 item 8): the activity feed asks only a caller who may read sys_activity.
    • 5a65f7d57 (objectui#12109): an object entry is not drawn for a caller who cannot read the object.
    • 206505c34 (objectui#12104): a timeline groups an explicit groupByField by its display value.
    • de302c731 (objectui#12078): the chatter reads and writes reactions as sys_comment_reaction records. That object is on main since Comment reactions (ruling A amended on #22505): a reaction is the reactor's own sys_comment_reaction record, and sys_comment.reactions retires with no aggregate and no data migration #22566, and the column path stays for a framework without it.
    • 417e24567 (objectui#12079): an app that serves no navigation opens on an app-level empty state.
    • 4d0ff2331 (objectui#12080): a long flow screen keeps Submit / Confirm on screen.
    • 3c0f8069e / a21ff9a95 (objectui#12087, objectui#12097): marketplace installs wait until the app is served.
  7. Types only: d758f2f20 and 1b2d0160f (objectui#6349 batches 8 and 9). No changeset: a194b4e37 (objectui#12114, objectui's own scripts).

The digest reads 28 releasing changesets of 29 across 21 non-merge commits, 1 release-nothing, and 1 commit with no changeset. None declares major, and one carries the author's breaking annotation. The highest declared level is minor, so the console changeset is minor. Its adr-0087: TODO placeholder is answered not-required (no-migration-prescription), which names the annotated entry and the manifest move.

Clause-②: what moves, measured

The html-page save gate (metadata-protocol runtime-authoring-gate.ts) and the CLI's JSX gate (os validate / compile / lint) compile a page source against the SDUI manifest the console ships. The gate fails a save only on an error-severity diagnostic (CompileResult.ok). compile() from @objectstack/sdui-parser (this branch's build) was run against the previous manifest (the tracked file at 680a86b4c) and the regenerated one:

page source previous manifest this manifest
an element:repeater with dataSource={{ object: "account" }} and no flat object ok=false, error: missing-required-prop ok=true, no diagnostic
an element:repeater with a flat object ok=true, no diagnostic ok=true, warning: unknown-prop
an element:repeater with flat object, filter, sort, limit ok=true ok=true, four unknown-prop warnings
an element:number with a flat object ok=true ok=true, warning: unknown-prop
an element:number with dataSource={{ object: "account" }} ok=true ok=true

So the html tier now accepts a repeater bound through dataSource alone, which it refused before. Nothing it accepted before is refused now: the retired flat keys draw a non-gating warning. That makes it a widening, and it is declared Clause-②: yes (widening) on line 2 and in the console changeset. A contract-tier review is owed for this PR. The JSON tier does not move here: @objectstack/spec already retired those flat keys (#11509).

Acceptance, measured in the browser

The showcase was booted from this branch (pnpm dev -- --fresh -p 38138, OS_PORT exported), serving the console dist built at the new pin. At boot, check:console-sha printed "Console dist matches the objectui pin (objectui@0df67f237c5a)". The run used Chromium (/opt/pw-browsers/chromium, headless, 1440x900) and signed in through the form as the seeded platform admin. The boot and the run were held under the verify lock, and the server was torn down at the end.

  • system/permissions lands on the registry catalog. /_console/apps/setup/system/permissions redirects to /_console/apps/setup/metadata/permission?scope=environment. The page reads GET /api/v1/meta/permission (200) and GET /api/v1/data/sys_metadata_activation?top=1000 (200), and nothing from sys_permission_set. It lists 17 permission sets, each from an Artifact source, each with a live switch.
  • Switching a set off (showcase_auditor):
    • request: POST /api/v1/security/_activation/permission/showcase_auditor with body {"enabled":false};
    • response: 200 {"success":true,"data":{"type":"permission","name":"showcase_auditor","enabled":false}};
    • the switch reads aria-checked="false".
  • After a reload the switch still reads off (aria-checked="false"). The ledger read answers one row: metadata_type: "permission", name: "showcase_auditor", package_id: "com.example.showcase", active: false.
  • The holder loses it. The demo persona auditor.demo@example.com holds the auditor position, which binds showcase_auditor. That persona signed in and read its own permissions with GET /api/v1/auth/me/permissions at each step:
    • before: ["showcase_auditor","showcase_member_default","member_default"];
    • while off: ["showcase_member_default","member_default"];
    • after the restore: ["showcase_auditor","showcase_member_default","member_default"].
  • Switched back on and restored. Request: the same path with body {"enabled":true}. Response: 200 {"success":true,"data":{"type":"permission","name":"showcase_auditor","enabled":true}}. After a reload the switch reads aria-checked="true".
  • The admin is asked once to set the workspace timezone (objectui#11758). The run answered "Keep the default". The only console errors were a 404 and the signed-out session 401, both on the sign-in page before sign-in.

What changed here (21 files, +519 / -157 = 676 changed lines, generated files included)

file written by gate that required it
.objectui-sha scripts/bump-objectui.sh 0df67f237c5a… --no-commit Console Pin Gate builds what it names
.changeset/console-0df67f237c5a.md the same run (the digest). The later edits are the ADR-0087 answer and the Clause-② line check-adr-0087-registration, check:objectui-changeset
sdui.manifest.json, scripts/sdui-manifest.record.json node scripts/gen-sdui-manifest-node.mjs over .cache/objectui-0df67f237c5a check-sdui-manifest.mjs
packages/sdui-parser/objectui-lockstep.json node scripts/check-sdui-lockstep.mjs --update, OBJECTUI_ROOT at the built tree check:sdui-lockstep
55 asserting citations in 14 files under packages/spec/src, and three quoted anchors of the dated view.zod.ts map record re-measured by hand (below) check:objectui-pin-citations (and --verify-anchors)
.changeset/objectui-pin-citations-0df67f237c5a.md hand-written, @objectstack/spec patch Check Changeset (the shipped describes name the pin)
content/docs/references/ui/view.mdx check:generated --fix (gen:docs) check:docs
  • The manifest keeps 107 components. Its sha256 moves to 9d87162a3ef6…, and only the two element rows above change (32 lines removed). objectui's workspace version stays 17.7.0.
  • The lockstep records 214 grammar lines (blob 0131f27cf86d), 25 diagnostic codes and containment predicate 76c18fb95d1f. All are unchanged; objectui's packages/sdui-parser is untouched by the range, so no port is owed.
  • packages/spec/src/migrations/registry.ts is gitignored on main now and is regenerated, not committed.
  • The bump script read the shared objectui checkout read-only (the range walks there: 21 commits). The console build ran with OBJECTUI_ROOT at a scratch repository with no refs of the sibling's own, using objectui's object store as its alternate. So the build's git worktree add and worktree prune registered nothing in the shared checkout.

How the citations were re-measured

  • Method. Each asserting record's cited objectui files were resolved at 20c6d351ad74 and intersected with the range's changed paths. Every anchor in a changed file was mapped through git diff -U0 20c6d351ad74 0df67f237c5a and its text compared at both pins. A record whose cited files are all byte-identical (git diff --quiet) gains that sentence and no re-pointing.
  • Changed cited files: ObjectGrid.tsx, ListView.tsx, ObjectCalendar.tsx, plugin-calendar/src/index.tsx, ObjectTimeline.tsx, plugin-timeline's renderer.tsx, ObjectKanban.tsx, KanbanBoardCore.tsx, KanbanImpl.tsx, plugin-kanban.mdx, MePermissionsProvider.tsx, PermissionProvider.tsx, record-details.tsx, basic/data-list.tsx, data-objectstack/src/index.ts, form.tsx and plugin-view's ObjectView.tsx. The en / zh / de packs changed too, but not their calendar.configRequired strings. Every cited line moved or held byte-identical.
  • Readings that changed around a cited read, each said in its hop sentence:
    • basic/data-list.tsx (objectui#12085): the element:repeater row's two sentences that named the published flat inputs became false. Those were the required object input at :320-326 and the binding published "beside these keys". Both are rewritten where they stand. The renderer still reads the four as the fallback.
    • ObjectGrid.tsx (objectui#12082): the delete verdict the implicit bulk-delete rides on now comes from the affordance map's rowDelete row. That row still asks the managed-object policy and the effective API operations, and now the delete grant too, so the sys_api_key record in api-methods-batch-conformance.test.ts still holds. Its selection block still hashes c88443302d40…, moved 4868-4895 -> 4897-4924. inlineEditable reads the map's listInlineEdit row, still the authored editable AND the viewer's write verdict.
    • ListView.tsx (objectui#12081): the case 'calendar' arm gained a fetch-window callback. Its date-field reads are byte-identical and still declared-only, with no floor, and the fetch window's own copies (:2495-2498) read the declared bindings only.
  • Two stale anchors corrected on the object-tree flat-config record. Its opening still named the case 'tree' arm at its 47b1f0bb7 span (3913-3932), and its hop cited the labelField line as :3986, which is the fields line under it at 20c6d351a. At this pin the arm is 4120-4144 and labelField is :4140.
  • Counts re-taken by each record's own method.
    • keyboardNavigation: 15 hit lines against 3 for schema.editable.
    • ObjectKanban.tsx's quickAdd / onQuickAdd / onCardClick: 2 / 2 / 11. No kanban-ui registration outside tests.
    • The ElementDataSourceGate occurrences in the five src/index.tsx shells: 0, 3, 3, 3 and 4. plugin-calendar's shell changed in its HOST_CALLBACKS list only.
    • The schema.* read sets: 19 names in ObjectTimeline.tsx and 5 in renderer.tsx, at both pins.
  • Corpus counts. The six migration entries' counts were re-taken with git grep -o -F. That method first reproduced every 20c6d351ad74 number: 8351 files, objectstack 18047, @objectstack/spec 7545, useState 2630, timeout 1694, RuntimeConfig 337, resourceLimits 2, window 4470, period 249, interval 213, metrics 456, Span 517, SpanSchema 57, TTL 184 and tenant 1340.
    • At the new pin they read: 8424 files, objectstack 18248, @objectstack/spec 7582, useState 2645, timeout 1705, RuntimeConfig 347, resourceLimits 2 (the same two packages/app-shell hits), window 4596, period 251, interval 233, metrics 456, Span 517, SpanSchema 57, TTL 184 and tenant 1357.
    • The zero tokens: 100 were checked (the exports of plugin-lifecycle-advanced.zod.ts, tracing.zod.ts and metrics.zod.ts, plus every named key). 98 read 0 at both pins; Span / SpanSchema read 517 / 57 at both.

For the contract review: changed lines in packages/spec/src/** that are neither a comment nor a string fragment

There are none. This was measured mechanically. Each of the 14 changed .ts files was scanned with the TypeScript scanner at 680a86b4c and at the head, comments skipped and every string, template and regular-expression literal replaced by one placeholder token. The token sequences are identical in 12 of the 14 files. The other two are 18.system-metrics-jsdoc-durations-unit-in-key.ts and 18.system-tracing-otel-exporter-durations-unit-in-key.ts. Each gains one + joining one new string fragment (the older count) into its reason string. No identifier, key, value or export moves. The one shipped describe that changes is FormField.span's, and only its sha moves.

Gates and tests

The derived gate union ran at the final head ecd4ed7458, on merge base 680a86b4c. The tests and the builds ran at 7c7c5c8ab, after a full workspace build at that tree (turbo run build --concurrency=2 --filter=!@objectstack/docs, 73 tasks, exit 0). The one commit between the two re-words a sentence inside the console changeset's ADR-0087 comment and touches nothing a build or a test reads. Exit codes were captured before any pipe.

  • The gates this bump touches:
    • Console Pin Gate (local equivalent). The dependency closure was built first: turbo run build --concurrency=2 --filter=@objectstack/client --filter=@objectstack/spec --filter=@objectstack/sdui-parser, 34 tasks, exit 0. Then pnpm objectui:build exited 0 (lock held 5m58s). Its log reads "Bundle canary 'import/jobs' present", "Single-zod canary: exactly one zod version literal {major:4,minor:6,patch:5}", "Console bundle carries THIS tree's @objectstack/spec, and only it" and "@objectstack/console dist ready (64368 KB) from objectui@0df67f237c5a". check:console-sha reads "Console dist matches the objectui pin (objectui@0df67f237c5a)" (exit 0), and check:console-injection reads "the dist carries this tree's copy, and not the published one" (exit 0). The CI job itself is NOT MEASURED here; it is CI's run.
    • check:objectui-bump: "bump-objectui self-test PASSED — 20 assertions across 5 cases" (exit 0).
    • check-sdui-manifest.mjs: "present, intact (sha256 9d87162a3ef6…, 107 components) and recorded at the live objectui pin 0df67f237c5a…" (exit 0).
  • Derived gates. node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack derived 125 commands from 21 changed paths against merge base 680a86b4c. All 125 ran and exited 0. The --ran reconciliation reads "125 derived famil(ies) accounted for — 125 run, 0 NOT-MEASURED (a DERIVED zero — all 125 recorded an exit code and none of them is 3)". Verdict lines:
    • check:objectui-pin-citations: "55 asserting objectui pin citation(s) match .objectui-sha (0df67f237), 145 historical citation(s) recorded and not checked, across 1976 spec source(s)." With --verify-anchors (OBJECTUI_ROOT at the objectui checkout): "13 anchor content assertion(s) verified against objectui at 0df67f237".
    • check:sdui-lockstep: "OK — this copy is byte-identical to objectui@0df67f237c5a (2026-10-11T07:26:10+00:00) over 214 grammar line(s) [blob 0131f27cf86d], agrees on all 25 diagnostic code(s) and on the not-a-container predicate [blob 76c18fb95d1f]".
    • check-adr-0087-registration --base origin/main: "1 declared-breaking changeset(s), each carrying an ADR-0087 disposition". check-changeset-no-major --base origin/main: "This diff introduces no major bump".
    • check:generated: "All 14 generated artifacts are up to date". check:api-surface: "public API surface + factory signatures unchanged". check:docs: "225 generated files in sync". check:nul-bytes: OK, no raw control bytes.
  • Tests.
    • @objectstack/spec (pnpm --filter @objectstack/spec test, --project local): 645 files, 19311 passed, 1 todo. @objectstack/spec typecheck (the scripts and test-layer checks included): exit 0.
    • @objectstack/sdui-parser test and typecheck: 14 files, 225 passed; exit 0.
    • @objectstack/lint validate-jsx-pages.production-witness.test.ts: 5 passed. @objectstack/metadata-protocol protocol.runtime-authoring-gate.test.ts: 133 passed.
    • @objectstack/cli, unit tier (sdui-manifest, console.sha-drift, validate-build-gate-parity, console-resolve): 4 files, 108 passed. The integration tier (jsx-gate-manifest-notice.e2e.test.ts among it) is declared to CI: this diff touches no integration-tier file and no spawn entry.
  • Lint, narrowed and proven. ESLint (--no-inline-config) over the 14 changed TS files under packages/spec/src gives 0 errors and 0 warnings, 14 files by the --format json count. The population is the eslint.config.mjs block that lints every ts file (line 971). The config never enables type-aware linting (line 328), so this diff cannot move the verdict on any file it does not touch. The repo-wide pnpm lint is CI's run.
  • main after the cut. origin/main gained five commits after 680a86b4c (feat(plugin-webhooks): the webhooks service serves the redeliver door from a Request, and the veto no longer waits for realtime (webhooks segment 3 of #22564) #22797, feat(spec): declare ITriggerApiService.handleInboundHook, the optional transport-neutral inbound-hook member #22779, docs(skills): field-types rule states a formula's five returnType members and the currencyConfig a currency formula carries (#22743) #22798, docs(governed): ADR-0087, AGENTS.md and the retirement playbook describe the D4 projections and the migration registry as main builds them #22796, docs(spec): RuntimeAuthoringIssueSchema.path states the name-keying rule for every collection-resident write type #22784, up to 098481744f). None touches a file of this diff, so there is no merge here; CI and the merge queue judge the merge.

Acceptance notes

Seat note, 2026-10-11: this PR's earlier Check Changeset red was the gate's blind spot for the repo-root sdui.manifest.json. #22816 (stage 5-pre) fixed it on main at 5fdc1a890db5, and this body edit re-runs the gate. Nothing above changed.


Generated by Claude Code

…ui#12089)

WIP: pin, console changeset digest, regenerated SDUI manifest and record,
and the re-measured objectui pin citations in packages/spec/src.

Claude-Session: https://claude.ai/code/session_01Rerax7QTjKMPCUZxQUtPFR
Co-authored-by: Claude <noreply@anthropic.com>
…ecord the sdui lockstep, add the citations changeset

Claude-Session: https://claude.ai/code/session_01Rerax7QTjKMPCUZxQUtPFR
Co-authored-by: Claude <noreply@anthropic.com>
…ine's package correctly

Claude-Session: https://claude.ai/code/session_01Rerax7QTjKMPCUZxQUtPFR
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 2 package(s): @objectstack/sdui-parser, @objectstack/spec, touching 14 documentable anchor(s). ⚠️ 2 changed file(s) yielded no anchor (packages/sdui-parser/objectui-lockstep.json, packages/spec/src/kernel/functional-completeness.ts), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files.

2 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/data-modeling/analytics.mdx (via DatasetMeasureSchema (symbol, a top-level const))
  • content/docs/protocol/objectui/layout-dsl.mdx (via ComponentPropsMap (symbol, a top-level const object))

⛔ 6 release-owned page(s) also name something this change touched. These are read-only:

  • content/docs/releases/v15.mdx (via PageTabsProps (symbol, a top-level const object))
  • content/docs/releases/v17/17-1.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-3.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-4.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-5.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-7.mdx (via ComponentPropsMap (symbol, a top-level const object))

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

What this run could not see
  • 2 changed file(s) yielded no anchor (packages/sdui-parser/objectui-lockstep.json, packages/spec/src/kernel/functional-completeness.ts) — pages documenting those are invisible to this run
  • 1 name(s) were too generic to anchor anything (single lowercase words)
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 140 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json b7cd1af9df7ade29e165e838503cbbef05e4299e → packageMentionDocs.

Which tree this was computed on

This run read content/docs from f79ba8c43b05590ea929349da73e2b0bf14e574e — the merge of head 33307259d21dfcbe221e11dd4fd814e90a9df741 into base b7cd1af9df7ade29e165e838503cbbef05e4299e, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin f79ba8c43b05590ea929349da73e2b0bf14e574e && git checkout f79ba8c43b05590ea929349da73e2b0bf14e574e
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin b7cd1af9df7ade29e165e838503cbbef05e4299e 33307259d21dfcbe221e11dd4fd814e90a9df741 && git checkout -B drift-repro b7cd1af9df7ade29e165e838503cbbef05e4299e && git merge --no-ff 33307259d21dfcbe221e11dd4fd814e90a9df741

node scripts/docs-audit/affected-docs.mjs --json b7cd1af9df7ade29e165e838503cbbef05e4299e

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs b7cd1af9df7ade29e165e838503cbbef05e4299e → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: ecd4ed745807c93b8cf5454bd5bb099a2e0a61ff
Local-runs: none

Read: card #15204 (body and all 94 comments, the stage plan 6094501866, stage 0 6095755866, the stage-5 amendment 6106816979, the dev report 6107413519, the 5-pre measurement 6107458914, the 5-pre amendment 6107473261 and ACCEPT 6107654069); objectui#7611's ACCEPT 6106655511 and Landed record 6106811169; the PR body, its 21 files (+519 / −157) and the diff; the 35 check-runs on the head; the gate workflow, scripts/check-changeset-no-major.mjs, scripts/build-console.sh, packages/console/package.json, packages/sdui-parser/src/validate.ts, packages/metadata-protocol/src/runtime-authoring-gate.ts and packages/cli/src/commands/validate.ts at the head; PR #22816 (body, its one file); objectui compare/20c6d351ad74...0df67f237c5a, commits ce991bd70 and 5330afd1f, PR #12089, six objectui changesets and twelve cited objectui source files at 0df67f237c5a (and ObjectGrid.tsx at 20c6d351ad74). The gate's own log, job 114433350057: NOT READ (the proxy refuses the Azure redirect the logs endpoint answers with); its 17 step conclusions and the check-run's 4 annotations were read instead and carry the verdict below.

① Derived judgments

The regenerated sdui.manifest.json and its record — the one accept set that moves — right.

  • The diff removes 32 lines and adds none: the element:repeater row loses object (required: true), filter, sort, limit; the element:number row loses object and filter (both of whose descriptions already read "NOT READ (objectui#11880)"). No other row changes; the record keeps 107 components and moves its sha256 and pin. This matches objectui ce991bd70 (objectui#12085 / docs(skills): teach the flow value-expression function vocabulary in objectstack-automation #12093, PR lanes/spec.md: the landed ledger-append pre-approval states the permission but not the test — the case that grew a closed vocabulary is the one it does not answer #12100) exactly: at 0df67f237c5a the repeater registration (data-list.tsx:317) publishes titleField, fields, emptyText, divided plus the injected binding, and the number registration (elements.tsx) publishes aggregate, field, format, prefix, suffix plus the binding. objectui's own packages/sdui-parser is not in the range's 293 paths.
  • "Nothing that passed before is refused now" is TRUE, read off the code at the head rather than the dev's measurement alone: validate.ts:206 makes missing-required-prop severity: 'error' and :223-224 makes unknown-prop severity: 'warning'; runtime-authoring-gate.ts:750 ("errors refuse, warnings advise") and :1095 refuse on severity === 'error' findings only; os validate (validate.ts:539-568) exits 1 on splitBySeverity(findings).errors only, warnings are advisories. So a repeater bound through dataSource alone goes from refused (error) to accepted, and a flat object / filter / sort / limit on a repeater, or object / filter on a number, goes from clean to a non-gating warning. One direction, a widening. The dev's compile() table in the PR body says the same.
  • The renderer side is also as stated: data-list.tsx:160-162 and :196-200 read dataSource first and the flat four as the fallback. One PR-body looseness, not shipped: the "notable commits" item 2 says "The renderer still reads the flat keys as the binding's fallback" under a sentence covering both elements; for element:number the metric has not read its flat keys since objectui#11880 (objectui's own changeset says so). Every SHIPPED sentence (the console changeset, the spec changeset, component.zod.ts) scopes that fallback to the repeater. Noted, no defect.

The 55 re-measured citations in 14 packages/spec/src files — right; every changed shipped sentence is true at the new pin.

  • Scope of the text: the diff's changed lines in the 14 files are comments and string fragments only (checked by filtering the hunks: no non-comment, non-literal line changes; the two migration entries each gain one + joining a new count fragment). check:api-surface is unchanged per the PR, and nothing in these hunks could move it.
  • Shipped text that changes: (a) FormField.span's describe moves only the pin sha (view.mdx diff shows the two rows changing 20c6d351ad74 → 0df67f237c5a and nothing else); its claims rest on autoLayout.ts and field-type-alias.ts, neither in the range, and on spanLadderFor, which is at form.tsx:274-301 with its one call at :3246 at the new pin, as the hop sentence says. (b) The six migration entries' reason strings: the corpus size 8424 is verified (the git tree at 0df67f237c5a holds 8424 blobs, not truncated); the token counts (objectstack 18248, @objectstack/spec 7582, timeout 1705, useState 2645, window 4596, period 251, interval 233, metrics 456, RuntimeConfig 347, resourceLimits 2, TTL 184, tenant 1357, Span 517, SpanSchema 57) are taken by the record's own git grep -o -F method, which needs a checkout this review did not make; they are mutually consistent across all six entries and each entry's previous-pin numbers are carried forward verbatim. The "0 at both pins" claims for the 98 zero tokens are the load-bearing ones and are plausible on their face (the range adds Setup catalog, affordance-map and element-binding code, none of it in the spec's kernel/system namespaces).
  • Anchors, spot-checked at 0df67f237c5a by reading the cited files: data-list.tsx every read point in the repeater row (:144, :173-174, :181-189, :193-200, :210-211, :219, :235-238, :244-247, :280, :285, :290-295, :317); ObjectGrid.tsx :1786 resolveAffordance('rowDelete', …), :1850 inlineEditable, :5570 keyboardNavigation, :5609, :6587-6588, :6604-6605, and the selection block 4897-4924 hashes to c88443302d40c2db739ddb235470bafa29056e2e, identical to 4868-4895 at 20c6d351ad74; ListView.tsx :95, :209, :695, :2495-2498, :3813, :3902, :3959, :4079, :4120-4144 (case 'tree') and :4140 (labelField), which are the two corrected anchors; ObjectKanban.tsx :10, :100, :626-627, :757-767 with $top at :764, :1370, :1378-1379, :1642, :1658-1671, :1751, :1775, and the counts quickAdd 2 / onQuickAdd 2 / onCardClick 11; KanbanImpl.tsx :688 / :701; KanbanBoardCore.tsx :85, :120-121; ObjectTimeline.tsx :589-591, :617, :854, :867, :883, :921-923, :974, :984-1003, :1055-1056 and its 19 distinct schema.* names; timeline renderer.tsx :1589, :1814-1829, :1889 and its 5; ObjectCalendar.tsx :311, :1055, :1057-1058, :1354, :1361-1362, :1391, :1404-1417, :1471; plugin-view ObjectView.tsx:2479 case 'map':; plugin-calendar index.tsx 3 ElementDataSourceGate lines and onVisibleRangeChange in HOST_CALLBACKS. All hold. The per-file change sizes the hop sentences cite (ObjectGrid.tsx +82/−32, ListView.tsx +229/−57, ObjectCalendar.tsx +75/−19, ObjectKanban.tsx +21/−1, KanbanImpl.tsx +30/−7, KanbanBoardCore.tsx +9/−0, ObjectTimeline.tsx +42/−20, renderer.tsx +28/−8, MePermissionsProvider.tsx +36/−5, PermissionProvider.tsx +6/−1, record-details.tsx +13/−7, data-objectstack/src/index.ts +5/−2, data-list.tsx +17/−26, form.tsx +63/−3, plugin-kanban.mdx +5/−1) equal the compare's. The 17 cited changed files the spec changeset names are these plus plugin-calendar/src/index.tsx; the one renamed path (resolveActionParams.ts) is cited by no record. useBulkExecutor.ts is not in the range, so the "byte-identical" claim holds. Not reproduced: the keyboardNavigation "15 hit lines" count (the record's own method over more than one file; ObjectGrid.tsx alone has 1 such line and 3 schema.editable lines, which matches the control). CI's Type Check · source gates step 40 (check:objectui-pin-citations) is green on this head.

The sdui-parser lockstep re-record — right. Only rev, revDate and recordedAgainstPin move; the grammar region, the diagnostic codes and the containment predicate are unchanged, and the range touches no packages/sdui-parser path in objectui. CI step 29 "sdui-parser stays in lockstep with objectui's copy" is green.

The console changeset's content — right, as it publishes. @objectstack/console: minor. Its 28 entries are one per releasing changeset in the range: the 29 added .changeset/*.md minus the empty-frontmatter 12093-spec-main-compile.md, mapped commit by commit (12ff25631 5, 1b2d0160f 2, d758f2f20 4, 023f00d46 / 5af42dbbd 2, 16c8810ac / 029bdaf45 2, and one each for the rest), 15 minor and 13 patch; the one commit with no changeset (a194b4e37) is listed by subject. The BREAKING entry's text is 6349-batch10-plugin-designer.md verbatim (its "Breaking-change note" is the author's annotation, no major declared anywhere in the range), and the ADR-0087 comment names @object-ui/plugin-designer correctly after the head commit's fix. The Clause-②: yes (widening …) sentence is true as judged above. The ADR-0087 disposition not-required (no-migration-prescription) is right: no ObjectStack-authorable key moves in this diff; CI step 13 (ADR-0087 disposition) and the objectui pin-changeset digest guard (Lint & Repo Gates step 131) are green. The objectui range: trailer and the file form match PR #22592's console-20c6d351ad74.md.

The out-of-scope note on objectui#12086 — right and sufficient. 5330afd1f makes ListView read an absent userActions.editInline as on and the ADR-0047 interface page open its grid editable; the spec half f53f14bb36 (#22629) is an ancestor of objectstack main (compare reads ahead 107, behind 0), so the console is catching up with a default the maintainer already ruled. The console changeset's digest carries the entry, so the release record will say it. Carrier none is acceptable; nothing in this PR can or should gate it.

Range and net diff. objectui compare reads ahead 21, behind 0, 293 files (73 added, 219 modified, 1 renamed, 0 removed), 21 single-parent commits, merge base 20c6d351ad74; 0df67f237c5a is objectui#12089's merge commit (26 files, +1,948 / −136, merged 2026-10-11T07:44:50Z), as the Landed record 6106811169 says. main...head on objectstack lists the same 21 files with the same +519 / −157, and none of the 17 commits main gained since the merge base 680a86b4c touches a file of this diff or adds a line naming 20c6d351, so the net diff against main is this diff and the merged tree keeps the citation gate green. The claim amendment's exclusions hold: no objectui change, no packages/console/CHANGELOG.md or package.json, nothing under content/docs/releases/; Part of #15204 on line 1.

② Semver level

  • @objectstack/console: minor — right. The range's highest declared level is minor (28 releasing changesets, none major, one author-annotated breaking type rename), and a widening of what the shipped manifest's consumers accept takes at least minor (the 2026-09-04 ruling the gate cites). @objectstack/spec: patch — right: comments and describe / reason text only, no key, default, enum member or export moves, and check:api-surface is unchanged. Both packages sit in the one fixed group (70 members), so the version itself moves together either way; the levels are the declarations.
  • Clause-②: yes (widening: the html-page save gate and os validate accept an element:repeater bound through dataSource alone) — right, and the only true declaration: a page source refused with an error-severity diagnostic against the previous manifest passes against this one. objectui's own Clause-②: no on ce991bd70 speaks to objectui's surface (its registration narrows); the objectstack gates widen, and the stage-5 amendment's conditional ("no unless the range's commits move an objectstack accept set") resolves to yes. The dev's open question → A.
  • The Check Changeset red is EXACTLY the level-axis blind spot, and nothing else. Job 114433350057: steps 11 (changeset present), 12 (no empty frontmatter), 13 (ADR-0087 disposition) and 14 (allow-major read) succeeded; only step 15, node scripts/check-changeset-no-major.mjs --base MERGE_BASE, failed, and its annotation reads "Moved and graded patch: @objectstack/spec: patch … None of them is graded minor or above … direction arm: widening". The script at this head counts a package as grown when the diff moves its packages/**/src/** (leg 1) or a bin target its manifest names (leg 2) and no other way. packages/console tracks only package.json, README.md, CHANGELOG.md, .gitignore; it is not private and packs files: ["dist","README.md","CHANGELOG.md"]; scripts/build-console.sh:398-405 copies the repo-root sdui.manifest.json into packages/console/dist/. So the touched set on this diff is {@objectstack/spec} and the existing @objectstack/console: minor is invisible, which is the shape fix(changeset-gate): the level axis sees @objectstack/console when a diff moves the manifest its dist ships #22816 names and repairs: its leg 3 reads that copy out of the build script, its dev ran the fixed gate on chore(objectui): bump the console pin to 0df67f237c5a (carries objectui#12089) #22812's real inputs (head ecd4ed7458, --event from the live body) to exit 0 with the console minor discharging it, and its self-test pins the chore(objectui): bump the console pin to 0df67f237c5a (carries objectui#12089) #22812 shape. The seat ACCEPTed fix(changeset-gate): the level axis sees @objectstack/console when a diff moves the manifest its dist ships #22816 at 87d0ed90cc (6107654069), queued on green. The Check Changeset job checks out the PR merge ref (its actions/checkout step sets fetch-depth: 0 and no ref), so once fix(changeset-gate): the level axis sees @objectstack/console when a diff moves the manifest its dist ships #22816 is on main a re-run of this job on chore(objectui): bump the console pin to 0df67f237c5a (carries objectui#12089) #22812 executes the fixed script with no push to this branch. No real level defect: grading spec minor would be false (it did not grow), and Clause-②: no would be false.
  • The other 33 check-runs on the head are success (Console Pin Gate built the console at the pin and verified the dist stamp and the bundled spec; Lint & Repo Gates 198 steps; six Test Core shards; four type-check jobs; the three dogfood shards; Temporal Conformance); Packed-tarball smoke is opt-in and skipped.

③ Boundary flags

Implemented-by: claude/issue-15204-s5-objectui-pin
Reviewed-by: session_01Rerax7QTjKMPCUZxQUtPFR

VERDICT: PASS


Generated by Claude Code

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 11, 2026 11:27
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 11, 2026 11:27
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 11, 2026
Merged via the queue into main with commit e040b8c Oct 11, 2026
37 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-15204-s5-objectui-pin branch October 11, 2026 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants