Repository navigation
Sync ako/mxcli: describe round-trips, multi-file check, Go 1.27.2, docs gated on check - #1359
Conversation
`dataview … (ShowFooter: true)` warned "not recognized and will be silently dropped on write" although the builder writes it and describe emits it (mendixlabs#1346). navigationtree/menubar `Menu`/`Profile`/ `Orientation` and a scroll-container region's `SizeMode` were in the same state: read by a builder, emitted by describe, absent from staticWidgetKnownProps. The allow-list's drift guard was itself a hand-typed list, so it drifted with it. Add a guard that derives the vocabulary from the source with go/parser — every Get*Prop / lookupPropCI / Properties["…"] read in the page builders and every "Key: " describe emits — so a key added to a builder without the allow-list fails the test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…on (mendixlabs#1343) describe navigation and describe menu wrote a menu caption as '%s', so a caption such as "Customer's orders" produced MDL that does not re-parse ("extraneous input 's' expecting {MENU_KW, '}'}") and a describe -> exec round trip lost the navigation statement. printMenuMDL now writes captions through mdlQuote, and the menu-item notes quote the caption the same way (mdl0Quote, so a line break cannot end the comment). cmd_navigation.go joins the files scanned by TestDescribers_HaveNoHandRolledStringLiterals, which would have flagged every site. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HFYL51zws8i82jHBt5pi9V
describe nanoflow had its own body renderer without the grant block that describe microflow and renderMicroflowMDL each carried, so a describe -> exec round trip silently left a nanoflow with no allowed roles. The grant block is now one helper, flowGrantLines, used by all three renderers. The mock test parses the describe output and asserts a GrantNanoflowAccessStmt with both roles; it failed on the unfixed code with "describe nanoflow emitted no grant execute statement". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012udirbKUVSyk2w4KroxRbZ
…1347) `mxcli describe published rest service M.Api` printed "Unknown type" and auto-detect could not resolve the service from the catalog, although the MDL statement works under -c / exec / the REPL. The subcommand keeps its own type-keyword switch and auto-detect maps, none of which had the type. - move the keyword -> DESCRIBE dispatch into the pure describeMDLCommand() - accept publishedrestservice / published rest service / restservice / rest service - map catalog PUBLISHED_REST_SERVICE and Rest$PublishedRestService for auto-detect - test that every auto-detect keyword dispatches and its MDL parses Refs mendixlabs#1347 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TH9ZBkHgxDUoFjUY9iwd5A
…guage (mendixlabs#1344) `on delete restrict error message '…'` (and the alter / delete_behavior spellings) stored the ChildErrorMessage translation under a hardcoded en_US, so a nl_NL app had no message in its own language when a delete was refused, with mx check reporting nothing. DeleteBehavior now carries ErrorMessageLanguage (write side, set from authoringLanguage by the create and alter handlers) and ErrorMessageTranslations (read side). DESCRIBE and the alter read-back pick the project's default language instead of en_US-first, and the cross-module patch edits one language while keeping the others. Verified on a real 11.12.4 project with nl_NL default: HEAD stores en_US, this build stores nl_NL; mx check 0 errors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016ztHsFnPPVETT2Z3XgvSuD
fix(check): stop false MDL-WIDGET07 on builder-read widget properties
With no .mxcli/catalog.db, `mxcli describe Mod.Name` reported "no
describable document named ... found" for every document type. Its live
fallback calls ListRawUnits on the backend that the root package's Open
returns, and the modelsdk backend left that method to the
errUnimplemented stub; the fallback discarded the error.
The reachability record listed ListRawUnits as an accepted bypass
("describe holds a concrete reader"), which stopped being true when Open
began returning a backend value. scripts/backend-reachability.sh
ListRawUnits now reports LIVE at cmd/mxcli/cmd_describe.go.
- Backend.ListRawUnits delegates to the codec reader
- drop the stale entry from unreachableUnimplemented
- TestListRawUnits (fails on the stub with "not implemented")
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TH9ZBkHgxDUoFjUY9iwd5A
On Windows, `run --local --watch` failed every domain model change with "The process cannot access the file '...\deployment\web' because it is being used by another process", leaving the app on 404 until the run was restarted (mendixlabs#1342). The incremental rollup bundler runs with deployment/web as its working directory (mxbuild's pages plugin resolves paths against cwd, so it has to), and Windows refuses to delete a directory that is any process's cwd. Page and microflow edits only rewrite files inside web/; a domain model change makes mxbuild recreate web/ itself. Killing the bundler by hand did not help because EnsureAlive restarted it right before the next build. bundlerSupervisor.BuildReleasingWebDir wraps the watch loop's serve build: on that sharing violation it stops the bundler, retries the build, and starts a fresh bundler, whose first build is a full bundle of the new web/. Page edits keep the incremental path. Verified end to end on Windows 11 with Mendix 11.13.0: with the retry disabled the report reproduces exactly (build failure, then 404); with it the change applies via restart, twice in a row, and a later page edit still re-bundles incrementally. 11.12.6 and 11.14+ bundle in mxbuild and never start mxcli's bundler, so they are unaffected either way.
govulncheck failed CI on Go standard library advisories GO-2026-6603..6617 (net/http, crypto/tls, net/textproto, os; fixed in go1.26.9) and on golang.org/x/net v0.57.0 (fixed in v0.60.0). main has the same pins, so every PR was red on it. Toolchain go1.27.2 in go.mod and the workflows' setup-go; x/net v0.60.0 (x/crypto, x/sync, x/sys, x/term, x/text follow). The go directive stays 1.26.0. govulncheck: "Your code is affected by 0 vulnerabilities". x/net v0.60 reads the lowercase proxy variables before the uppercase ones, so TestProxyForURL, which set only HTTPS_PROXY, failed wherever an ambient https_proxy is set. It now sets both spellings. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HFYL51zws8i82jHBt5pi9V
gofmt 1.27 indents the composite literals of a multi-value return one level less than gofmt 1.26 does, so the E007 recovery return in parsePrimary failed `make lint-go` on CI after the move to go1.27.2, and no single layout satisfies both versions (the devcontainer still ships 1.26's gofmt). Building the RecoveredExpr into a variable first leaves nothing for the two to disagree on. No behaviour change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HFYL51zws8i82jHBt5pi9V
Fix menu caption apostrophe escaping in navigation describe output
Bumps [handlebars](https://github.com/handlebars-lang/handlebars.js) from 4.7.9 to 4.7.10. - [Release notes](https://github.com/handlebars-lang/handlebars.js/releases) - [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/v4.7.10/release-notes.md) - [Commits](handlebars-lang/handlebars.js@v4.7.9...v4.7.10) --- updated-dependencies: - dependency-name: handlebars dependency-version: 4.7.10 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
PatchReconcileMemberAccesses had no production callers — UPDATE SECURITY
and the marketplace step use the backend's ReconcileMemberAccesses. It
looked like it had a bug: it matched "HasOwner"/"HasChangedBy" where the
stored keys are "HasOwnerAttr"/"HasChangedByAttr". But "fixing" the keys
would have made it preserve and add MemberAccess entries for
System.owner / System.changedBy, which mxbuild rejects:
mxbuild 11.14.0, one entity with AutoOwner + AutoChangedBy, one rule
no audit MemberAccess 0 errors
+ System.owner, System.changedBy entries CE0066
(matches #554, which the live reconciler already implements and
access_rule_audit_member_test.go pins). A file whose only live-looking
defect is what keeps it harmless is a deletion, not a fix.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…bs#1354) check -p passed `create module role NoSuchModule.Reader`; exec then wrote the statements above it and stopped on "module not found: NoSuchModule". validateWithContext resolved the module of every other module-scoped CREATE but had no case for CreateModuleRoleStmt. Control: the pre-fix binary on PedApp creates Administration.Writer, then fails; fixed, the exec pre-flight refuses and nothing is written. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XG6zuHZcX5etjJTbg2hWrv
…l 1 header mendixlabs#1356: "fmt --upgrade adds `mdl 1;` to a .test.mdl, but fmt --help and the test-microflows skill say test files take no header". The behaviour is the intended one: #847 made the runner and check read a test file's header and made fmt --upgrade add it by default (its CHANGELOG entry says so). The fmt --help paragraph and the skill sentence still described the pre-#847 behaviour. Both now say the header is added by default and name --header=false as the way to decline it. cmd_fmt_testfile_header_doc_test.go runs the reporter's file through fmt --upgrade and fails if either text again says a test file takes no header. Control: against the unfixed texts it failed on both, quoting "It takes no language header yet, so --header adds none to it". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc8N9pk2jT4XkUx2bv94tE
…s write (mendixlabs#1355) check -p over several files resolved each one against the project as it stands, so a later file's reference to anything an earlier file creates — the reported combobox datasource, but equally a page parameter, an association or a module — was reported as missing, although exec run on each file in order succeeds. Each file is now resolved against one scratch copy of the project that the files before it have been applied to (scriptdiff.Scratch, the copy and outside-guard `mxcli diff` already runs scripts under). A file that does not pass is left out of the copy, as exec's pre-flight would write nothing, and the output names it. The project itself is not changed. Control: with the copy not used, the new test fails with "parameter $Order of page MyFirstModule.ShopOrderEdit: entity MyFirstModule.ShopOrder does not exist"; wrong file order and a datasource entity no file creates are still reported. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XG6zuHZcX5etjJTbg2hWrv
… failed mendixlabs#1357: three skill examples marked correct failed `mxcli check`: - write-microflows control-flow.md "Robust External Call" created $response twice (MDL063; CE0111 "Duplicate variable name 'response'" from mxbuild 11.12.1). The handler now creates $fallbackResponse and returns it. Measured on 11.12.1 with docker check: 0 errors, and CE0111 with the old form. - write-oql-queries patterns.md and odata-data-sharing walkthroughs.md declared String(400) and unlimited String over `a + ' ' + b`. A derived string column is always String(200) (MDL031; CE6770 at build). check-skill-mdl.sh splits blocks into statements and fails only on syntax, so a whole example that parses but that check rejects was never judged. scripts/check-skill-mdl-semantics.sh runs each whole block through `mxcli check --json` and fails on any error. It skips fragments (MDL-SYNTAX), real SQL, and ❌/check-skip blocks, and ignores MDL-DUPDEF (alternatives shown side by side). It is wired into `make check-skill-mdl` and push-test.yml for the skill pack, the packs and the quick reference. Run against the pre-fix docs, it reports exactly the three blocks above. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TWST8VP811CQVCFSBAGJTv
mendixlabs#1357, the prose half: - check-syntax, resolve-forward-references, overview-pages: `create or replace` was described as deleting the document and minting a new UUID. It is the deprecated spelling of `create or modify` (MDL-DEPR001): a snippet replace reuses the stored ID (cmd_pages_create_v3.go, UpdateSnippet). Only `create or replace view entity` without an `mdl 1;` header drops and recreates. - organize-project: the checklist put a page's folder "inside properties". It is a clause after the name; the `Folder:` property is MDL-DEPR105. - debug-bson, create-page widgets.md: `docker check`/`build` were recommended to clear CE0463. They normalise a temporary copy, so the check passes while the stored project still fails MxBuild. The fix is `mxcli fix widgets`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TWST8VP811CQVCFSBAGJTv
Fix: emit grant execute statement in describe nanoflow output
fix: store a restrict association's delete message in the project language (mendixlabs#1344)
fix: describe auto-detect finds documents without a catalog
docs: clarify that test files get mdl 1; header by default
fix: describe subcommand accepts published REST services (mendixlabs#1347)
…site Follow-up to mendixlabs#1357. 24 complete examples in docs-site/src parsed but `mxcli check` rejected them: - reserved names: `Id`/`Type` attributes (MDL021); `CreatedDate: DateTime` on persistent entities (MDL020), now `AutoCreatedDate` where it means the creation timestamp, `ReleaseDate` in the tutorial - AutoNumber without a seed (MDL023, CE7247), including a DESCRIBE output sample; describe prints `AutoNumber default 1` - attributes outside a data container (MDL-WIDGET34): snippet bodies now sit in a data view over their parameter; the dashboard count in a microflow data view; the parameterless footer uses Content - grant-revoke: user roles without System.User (MDL-SEC20); security: entity access granted to a user role (MDL-GRANT02) - crm-module: overview page before the page it opens (MDL-PAGE01), and its New button opened Customer_NewEdit without the required object - quick-reference OData path with a leading slash (MDL-ODATA05); tutorial/skills.md entity type without a module (MDL008); create-snippet text still describing the deprecated Folder property Building the fixed examples with mxbuild 11.12.1 found three that the linter passes: - the CRM validation microflow never parsed (`NOT contains(...)`); it is now `not(contains(...))`, calls VAL_Customer with its real parameter name, and carries `mdl 1;` like the rest of the page - the CRM demo-user passwords were 10 characters, under a new project's 12-character policy - the published OData service had no KEY (CE6585). Email is now the key, with a note that it must be NOT NULL UNIQUE (CE6624/CE0309) The CRM example and the snippets then build with 0 errors. check-skill-mdl-semantics.sh now covers docs-site/src in `make check-skill-mdl` and push-test.yml. The conformance allowlist is shrunk for crm-module.md (5 syntax findings to 0). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TWST8VP811CQVCFSBAGJTv
Fix script set checking to resolve files against accumulated state
chore(mpr): delete the dead security_patch reconciler
…status `create or modify published odata service` carries each published member's stored CanBeEmpty by entity and member name (#743), because MDL has no spelling for it. A member published without (KEY) is stored with CanBeEmpty true. When the statement added (KEY) to it, the carry wrote that true onto a key member. mxbuild refuses that: CE0309 "Exposed attribute 'Email' of entity 'Customer' that is part of the key cannot be marked as 'Can be empty'." A fresh create of the same statement built clean. The carry now applies only while the member's key status matches the stored one. On a change, the derived value (!IsPartOfKey) is used. TestModifyODataService_CanBeEmptyNotCarriedAcrossKeyChange covers both directions, with a control member whose key status is unchanged and still carries. Before the fix it failed on both the new key and the former key. Measured on mxbuild 11.12.1 with the same script and project: the old binary gives CE0309, the fixed one 0 errors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TWST8VP811CQVCFSBAGJTv
…ution The quick-reference note said the key attribute must be NOT NULL UNIQUE, or mxbuild reports CE6624/CE0309. CE0309 came from the CanBeEmpty carry fixed in the previous commit, not from the entity. Measured on 11.12.1: a key over `Email: String(200) UNIQUE`, nullable, builds with 0 errors. The docs-site finding no longer blames the entity's NOT NULL change either. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TWST8VP811CQVCFSBAGJTv
…skills/packs/mendix-vega-charts/widget/handlebars-4.7.10 build(deps-dev): Bump handlebars from 4.7.9 to 4.7.10 in /.claude/skills/packs/mendix-vega-charts/widget
Fix skill and docs-site examples that fail mxcli check (mendixlabs#1357)
AI Code ReviewCritical IssuesNone found. Moderate IssuesNone found. Minor IssuesNone found. What Looks GoodThe PR is a sync of 18 commits from a fork that addresses multiple discrete issues while maintaining excellent quality:
Automated review via OpenRouter (Nemotron Super 120B) — workflow source |
fix(run-local): apply domain model changes under --watch on Windows
AI Code ReviewCritical IssuesNone found. Moderate IssuesNone found. Minor Issues
What Looks Good
RecommendationApprove the PR. All changes are well-tested, address real bugs, follow project patterns, and improve robustness without introducing regressions. The minor documentation nits don't block merging. Automated review via OpenRouter (Nemotron Super 120B) — workflow source |
Syncs
ako/mxcli:mainintomendixlabs/mxcli:main: 18 commits since #1353, landed in the fork through PRs ako#1062–ako#1073.Describe round-trips
grant executeline (describe nanoflow omits grant execute on nanoflow, so a describe -> exec round trip loses its access rules #1345). A describe → exec round trip left a nanoflow with no allowed roles. All three flow renderers now share one helper.Customer's ordersproduced MDL that did not re-parse.mxcli describe published rest service M.Apiworks as a subcommand, and auto-detect finds the service (mxcli describe rejects published rest service, although the MDL statement works #1347).ListRawUnitsand discarded the error.Check
mxcli diffalready does. The project itself is not changed.create module role NoSuchModule.Readeris refused before exec writes anything (check -p passescreate module rolein a module that does not exist; exec then fails after earlier statements were written #1354).ShowFooterand navigationtreeMenu/Profile(check: false MDL-WIDGET07 for showFooter on a data view #1346). The allow-list is now guarded by a test that derives the vocabulary from the builder and describer source.Model fixes
en_US(Restrict association delete error message is always stored as en_US, missing in a non-English app language #1344). Verified on an 11.12.4 project with nl_NL default.create or modify published odata serviceno longer carries a member's storedCanBeEmptyacross a change of key status (CE0309 when(KEY)was added).Docs and skills (#1356, #1357)
mxcli check. Three skill examples and 24 docs-site examples that failed check or mxbuild are fixed (duplicate variable, derived string length, reserved names, AutoNumber seed, attributes outside a data container, and more).create or replaceis the deprecated spelling ofcreate or modify(it does not delete and re-mint), folder placement is a clause, and CE0463 advice is corrected.fmt --helpand the test-microflows skill say test files take themdl 1;header, whichfmt --upgradeadds by default.Build
golang.org/x/netv0.60.0, which clear govulncheck advisories GO-2026-6603..6617. Thegodirective stays 1.26.0, and a gofmt layout is made stable across 1.26 and 1.27.security_patchreconciler. "Fixing" its keys would have introduced CE0066, as measured on mxbuild 11.14.0.handlebars4.7.10