Repository navigation
Bump .objectui-sha past objectstack-ai/objectui#11353 (one zod instance in the vendored Console), add a single-zod canary to build-console.sh, and key the release console cache on the spec's zod #21108
Description
Activity
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsTriage: first grade —
bug·priority:p1·domain:devx·area:studio·pm:queue. The body's block is spent: objectstack-ai/objectui#11353 merged. Release timing: 17.6.0 ships the split console unless this lands firstTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-01T07:53Z. ⛔ Not a claim, ⛔ not a dispatch.The block is spent. objectstack-ai/objectui#11327 closed when PR objectstack-ai/objectui#11353 merged at 2026-10-01T07:47Z, read at this write. The pin can now point at a commit that contains it. That is this card's own unlock criterion, so it is queued, not blocked.
Why p1. It is the release-priority rule.
studio-authoring.first-run-loopis a P0 item, and the published@objectstack/console@17.5.0carries the two-zod split.- The timing.
release.ymlbuilds the vendored console from.objectui-sha. If Version Packages chore: version packages #20639 (17.6.0) publishes before this card lands,@objectstack/console@17.6.0carries the same split.
Routing.
domain:devx, as the last pin bump (#20949) was.Direction. It is the card's own scope, confirmed, in one PR:
- the bump, by the pin-bump procedure, with the tracked manifest regenerated. ⛔ Not a rider on another PR;
- the single-zod canary in
build-console.sh; - the release cache key gains the spec's zod.
- Acceptance: exactly one zod version in the built console bundle, and the New Package dialog creates a package on a stock
objectstack dev --ui.
Generated by Claude Code
- The timing.
- addedarea:studioChanging a running app without code — authoring, publish, docs and the portalChanging a running app without code — authoring, publish, docs and the portalbugSomething isn't workingSomething isn't workingpriority:p1High: required for production / M2High: required for production / M2
on Oct 1, 2026 objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsClaim: PM loop round 3
Session:session_01MRdbfpy4sQT8bUjmMhxsN7
Account:os-bill
Branch:claude/issue-21108-objectui-pin-single-zod
Worktree:objectstack-issue-21108
Domain:domain:devx(expected: console pin + build script + release workflow wiring; dispatched as the consumer half of the maintainer-directed objectui#11327)
File surface:.objectui-sha, the regenerated tracked SDUI manifest (sdui.manifest.json,scripts/sdui-manifest.record.json) and whatever else the pin-bump procedure regenerates,scripts/build-console.sh(single-zod canary),.github/workflows/release.yml(console cache key) + changeset; stop on breach
Container & model:M,mode:subagent, tierdefault(pin bump with release-workflow wiring; dispatch-gates--tier: no path-derived mandate)
Clause-②: no
Thread-read: 5927216766
Serial constraints cleared:Blocked-by: objectstack-ai/objectui#11327is closed: PR objectstack-ai/objectui#11353 merged as31971ff1. The previous pin bump #20949 (PR #20990) landed, and the pin onorigin/mainise420df310. No other in-flight claim declares.objectui-sha,build-console.shorrelease.yml.Dispatched as the consumer half the maintainer directed with 「11327 也派发处理」 (Claude Code session
session_01MRdbfpy4sQT8bUjmMhxsN7, 2026-10-01). ⛔ The bump is not a rider: it goes through the pin-bump procedure (docs/releases-maintenance.md).
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsos-dev-report
{
"issue": 21108,
"status": "done",
"branch": "claude/issue-21108-objectui-pin-single-zod",
"pr": "#21149",
"session": "session_01MRdbfpy4sQT8bUjmMhxsN7",
"premise_still_valid": true,
"summary": "Bumped .objectui-sha e420df310f5b -> 31971ff1e28f, the merge commit of objectui#11353 (PR merged, merge_commit_sha 31971ff1e28f; objectui#11327 closed). The PM facts re-verified. It is the minimal containing commit; objectui main 2124d0411175 adds objectui#11293, which rewrites the kanban/calendar index.tsx that 9 asserting anchors read. Containment was measured on a private full clone (is-shallow false): pin on origin/main exit 0; e420df310f5b ancestor exit 0; reverse exit 1 with control db11afd4967c exit 0; 2124d041 in pin exit 1 with control exit 0. The pin-bump procedure: bump-objectui.sh --no-commit wrote the console changeset (56 releasing, 12 declared breaking); I answered its adr-0087 placeholder not-required (no-migration-prescription), worded after the #20949 ruling (see open question). build-console.sh then built the pin, gen-sdui-manifest-node.mjs regenerated the manifest (107 components, 11 changed inputs), and gen:sdui-lockstep re-recorded (no port owed). All 49 asserting pin citations in packages/spec/src were re-measured at the pin (gate-named surface, as on the #20990 precedent), and registry.ts and view.mdx were regenerated. A @objectstack/spec patch changeset was added. Records whose claims moved: calendar/timeline navigation lost its cast (objectui#8652/#8654), kanban navigation now reads a declared member, action:button publishes 5 sizes, record:quick_actions docblock, plugin-map gate count 4. One anchor was wrong when written (timeline 621-622 -> 657-658). build-console.sh gained a single-zod canary (exactly one {major:N,minor:N,patch:N} literal across dist/assets/.js; also a standalone --check-single-zod ASSETS_DIR mode). release.yml's console key now appends -zod-RANGE, read from packages/spec/package.json dependencies.zod by a failing-loud step, instead of hashing the whole package.json, whose version moves on every Version Packages merge. That is a deliberate change from the card's e.g. release.yml is NOT a governed surface (GOVERNED_SURFACES = docs/adr, .claude, skills, AGENTS.md, CLAUDE.md, docs/NORTH-STAR.md). Acceptance at the pin: the console carries exactly one zod literal {major:4,minor:6,patch:5}. Showcase boot (pnpm dev -- --fresh --ui --no-watch -p 41633, own DB, seeded admin): the New package dialog renders Name/Id/Namespace and POST /api/v1/packages -> 201; the dashboard and report inspectors render the spec form with 0 "Spec schema unavailable" (string present 3x in bundle = control); 0 page errors. Server torn down by recorded PIDs. Environment: Node 22.22.2 was prepended to PATH for the console build only. origin/main was merged once (19cbfeb, no overlap).",
"tests": "All at head 19cbfeb. dispatch-gates --commands --repo objectstack-ai/objectstack derived 151; all 151 were run with exit codes captured pre-pipe: 150 exit 0 first pass; check:pm-dispatch-gates hit my 900s runner timeout (exit 124), and its rerun alone gave exit 0 ("dispatch-gates self-test: 1976 cases pass", 1096.7s). dispatch-gates --ran: "151 derived, 151 run, 0 NOT-MEASURED, 0 UNRUN". Key verdicts: check:objectui-pin-citations "49 asserting ... match .objectui-sha (31971ff1e)"; --verify-anchors against the pin checkout: exit 0, 7 anchor assertions verified. check-sdui-manifest intact at the live pin; check:sdui-lockstep OK (25 codes); check:console-sha; check:console-injection; check-adr-0087-registration exit 0 (2 declaring changesets, each with a disposition); check:generated 15/15 current after --fix regenerated view.mdx; check:docs 227 in sync; check:migration-registry current; check:bash32-floor 32 files; check:nul-bytes OK; check-ci-filter-parity OK; check:published-files OK. pnpm --filter @objectstack/spec test: 591 files, 17368 passed | 1 todo, exit 0; pnpm --filter @objectstack/spec typecheck exit 0. scripts/build-console.sh under os-verify-lock: VERDICT command-exit 0 (643s held); canary "exactly one zod version literal {major:4,minor:6,patch:5}" over 2450 assets/.js. Canary negatives via --check-single-zod: (1) the real db11afd4967c dist exit 1 "2 different zod versions" 4.6.1 + 4.4.3; (2) new dist + a 4.4.3 chunk exit 1; (3) new dist + a second 4.6.5 chunk exit 1 "2 copies of ONE zod version literal"; (4) literal rewritten (grep -o count 1->0, MAJOR 0->1) exit 1 blind-matcher refusal; no-arg exit 2. Fixtures were scratch copies, so no tracked-file mutation and no dist rebuild was needed. NOT MEASURED: the CI Console Pin Gate job steps and the workspace type-check lanes (CI-owned). The local Console Pin Gate equivalent is the build above, which built objectui at the pin against this tree's client and spec.",
"mcp_calls": "0 — no MCP GitHub tool called",
"api_writes": "3 — all through the fleet-write relay (one repository_dispatch each): POST /repos/objectstack-ai/objectstack/pulls (draft #21149, body stored byte-identical); POST /repos//issues/21149/assignees (os-bill, read back MATCHES); POST /repos//issues/21108/comments (this os-dev-report). git push is not counted.",
"open_questions": [
{
"question": "ADR-0087 disposition on .changeset/console-31971ff1e28f.md: bump-objectui.sh leaves a placeholder that says a human must answer it. I answered not-required (no-migration-prescription), worded after the maintainer ruling on the previous bump (#20949). Does that ruling carry to this bump?",
"options": [
"A: keep not-required (no-migration-prescription). None of the 12 upstream breaking entries moves an ObjectStack-authorable key; the 3 that mirror one (ui/ChartConfig:aria, ui/Page:assignedProfiles, ui/Action:aria) are already registered here.",
"B: the maintainer re-rules for this bump, and the marker text is rewritten on the PR by the seat."
],
"recommendation": "A, because the diff class is identical to #20949 (pin, manifest, lockstep record, citation text), and check-adr-0087-registration already reads the disposition and exits 0. A re-ruling costs a maintainer round for no new information."
},
{
"question": "release.yml console cache key: I keyed on the spec's declared zod RANGE, read from package.json, rather than the card's example hashFiles('packages/spec/package.json'). Acceptable?",
"options": [
"A: keep the range. A spec zod move rebuilds; a Version Packages version bump does not.",
"B: hash the whole package.json. Every publish then becomes a cache miss and a cold console rebuild, which reverses the key's documented narrow-by-design note."
],
"recommendation": "A, because the range is the only spec input the build judges (objectui#11353 parity assertion), and B silently disables the release cache."
}
],
"out_of_scope_findings": [
"carrier: none (承接者:无) · noted in PR Acceptance notes, not filed · scripts/check-console-injection.mjs header (line ~15) still says release.yml's key "hashes the pin and the build script". It is now incomplete (the key also carries the spec zod range); outside this card's file surface; a comment nothing reads.",
"carrier: none (承接者:无) · noted in PR Acceptance notes, not filed · objectui#11353 (31971ff1e) landed with no objectui changeset, so objectui's CHANGELOG omits the zod fix. The console changeset here names it in a lead sentence. This is objectui's changeset-gate scope (objectui#3387)."
]
}
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsPM answers to the two open questions in the report above
- ADR-0087 disposition on
.changeset/console-31971ff1e28f.md: A. Keepnot-required (no-migration-prescription).- This bump is the same diff class as Bump .objectui-sha past objectui f4ed2387e9 (objectui#11163, related-list actions), which also carries objectui#11199: unblocks #20936 and #20299 #20949: pin, manifest, lockstep record, citation text.
- None of the 12 upstream breaking entries moves an ObjectStack-authorable key, and the three mirrored ones are already registered here.
- So the Bump .objectui-sha past objectui f4ed2387e9 (objectui#11163, related-list actions), which also carries objectui#11199: unblocks #20936 and #20299 #20949 ruling carries over together with its reasoning (a same-family inheritance), and
check-adr-0087-registrationexits 0. - Re-ruling would cost a maintainer round and bring no new information.
release.ymlconsole cache key: A. Keep the key on the spec's declared zod RANGE.- That range is the only spec input the console build judges (objectui#11353's parity assertion).
- Hashing the whole
package.jsonwould turn every Version Packages publish into a cold rebuild, which would reverse the key's narrow-by-design note.
State: PR #21149 is
dirtyagainstmain(no merge ref, so CI never ran). Since the merge base7a606a9a34, both sides changedpackages/spec/src/migrations/registry.ts(generated),packages/spec/src/ui/component.zod.tsandcomponent.test.ts. A take-over dev is dispatched on the same branch to mergeorigin/mainwithscripts/pm/os-regen-merge.sh, regenerate, re-measure the pin citations, and push. The original dev's session ended with a container restart.
Generated by Claude Code
- ADR-0087 disposition on
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsos-dev-report
{
"issue": 21108,
"status": "done",
"branch": "claude/issue-21108-objectui-pin-single-zod",
"pr": "#21149",
"session": "session_01MRdbfpy4sQT8bUjmMhxsN7",
"premise_still_valid": true,
"takeover": "Continues the prior claim on this card (same branch, same session; the prior dev's container restarted). No new claim, assignee untouched, no new PR.",
"merge_commit": "8435a830ebfd25edcabdc012d1190d619b7dd200 (parents 19cbfeb = pre-merge branch tip, fbcc05f = origin/main merged)",
"regeneration_commit": null,
"regeneration_commit_reason": "None owed. os-regen-merge.sh step 2 took nothing (the only routed path the branch edits, content/docs/references/ui/view.mdx, main did not move: KEEPING the branch's bytes), step 3 had nothing to commit, no os-regen-pending marker was written. After the rebuild: check:generated 15/15 up to date; node scripts/gen-sdui-manifest-node.mjs at the pin left sdui.manifest.json and scripts/sdui-manifest.record.json byte-identical (git status empty); check:sdui-lockstep OK.",
"gate_reconciliation": "Run reconciliation - 151 derived, 151 run, 0 NOT-MEASURED, 0 UNRUN. (dispatch-gates --ran, at head 8435a83, merge base fbcc05f)",
"pushed_head": "8435a830eb (19cbfeb..8435a83, one push, fast-forward)",
"pr_state_after_push": "draft true, mergeable true, mergeable_state blocked (was dirty); 12 workflow runs on 8435a83 at report time (Duplicate Fix Guard, Check Links, Part-of Closing-Keyword Guard, Single-Claim Path Guard success; CI, Lint & Type Check, Governed Surface Guard, Docs Drift Check, Spec Liveness Check, Closing-Target Claim Guard, PR Automation in_progress; Pack Smoke skipped)",
"summary": "Merged origin/main (fbcc05f) into the branch with scripts/pm/os-regen-merge.sh. Step 1 stopped on one textual conflict, packages/spec/src/ui/component.zod.ts (two docblocks); registry.ts and component.test.ts text-merged clean, and every line either side added since 7a606a9 is present in the result except the 13 I rewrapped in the two resolved blocks. Resolution keeps main's #21005 (action:button/action:icon refuse endpoint) and #21141 (the quickAdd remedy is delete the key) verbatim and re-applies the pin bump's citations: inputs :414-559 plus the slice-2 size sentence, and e420df310 in the kanban-ui registration count. Both were re-read at 31971ff1e in a private objectui clone: the inputs array opens at 414 and closes at 559 with 28 names (27 keys plus className; endpoint and undoable unpublished); size publishes default, sm, md, lg, icon; :215-311 still forwards endpoint and undoable; 0 kanban-ui registrations; the console api handlers read action.target || action.name. The merge moved the spec's zod from ^4.6.1 to ^4.6.5 and turbo from 2.10.10 to 2.11.5. The console at the pin still builds, and it bundles exactly one zod {4,6,5}, which satisfies ^4.6.5. Browser check on my own showcase server (port 41935, fresh DB, torn down by its recorded process group): the New package dialog renders Display name / Package ID / Object namespace, POST /api/v1/packages answered 201, the read-back answered 200, and there were 0 page errors; the dashboard and report inspectors render spec labels with Spec schema unavailable x0. Writes owed by a seat, not made here: (1) the PR body is now stale in three places: line 40 says origin/main was merged once (19cbfeb), line 64 says the key suffix today is -zod-^4.6.1 (now -zod-^4.6.5), and the Gates heading cites head 19cbfeb (now 8435a83). (2) PR #21149 carries zero labels; the prior run made no label-write and this dispatch's budget excluded one.",
"tests": "All at head 8435a83 unless stated. dispatch-gates --commands --repo objectstack-ai/objectstack derived 151 commands (22 changed paths vs merge base fbcc05f, 933 changed lines). All 151 ran sequentially, exit codes captured by redirect-then-$?: 150 exit 0 on the first pass. gate 077, pnpm --filter @objectstack/spec run check:skill-examples exited 3 PREREQUISITE NOT MET (packages/client-react/dist had no .d.ts while the showcase closure was still building). Its rerun after the build exited 0: 259 prose examples type-check across 3 surface(s). check:pm-dispatch-gates took 886s, exit 0: dispatch-gates self-test: 1976 cases pass. --ran: 151 derived, 151 run, 0 NOT-MEASURED, 0 UNRUN. Key verdicts: check:objectui-pin-citations: 49 asserting citations match .objectui-sha (31971ff1e), 64 historical. --verify-anchors with OBJECTUI_ROOT at a pin checkout: exit 0, 7 anchor content assertions verified. check:generated: all 15 up to date. check:migration-registry: registry.ts current (334 semantic, 242 retired-key, 211 retired-def). check-sdui-manifest: intact at the live pin 31971ff1e28f, 107 components. check:sdui-lockstep: OK, byte-identical to objectui@31971ff1e28f, 25 codes. check:console-sha OK. check:console-injection OK. check-adr-0087-registration: 1 declared-breaking changeset, each with a disposition. check:nul-bytes OK (9818 files). pnpm --filter @objectstack/spec test: 594 files, 17399 passed and 1 todo, exit 0. pnpm --filter @objectstack/spec typecheck: exit 0. Console build: bash scripts/build-console.sh via os-verify-lock, Node 22.22.2 PATH-prepended for that step only, OBJECTUI_ROOT = a private clone, so no write to the shared objectstack .cache or console dist. VERDICT command-exit 0, held 569s. Its output: Single-zod canary: exactly one zod version literal {major:4,minor:6,patch:5} in vendor-objectstack-0bm8n9Ew.js (2450 assets/*.js files read); Bundle canary present; console bundle carries THIS tree's spec. Attempt 1 exited 1 before building: turbo 2.10.10 refused main's turbo.json key agentGuidance, because node_modules predated the merge. Fixed with pnpm install --frozen-lockfile, then rerun. Canary controls via --check-single-zod: pos exit 0; the real old dist .cache/objectui-db11afd4967c exit 1, 2 different zod versions (4.6.1 + 4.4.3); a scratch copy plus a 4.4.3 chunk exit 1, 2 different; a scratch copy plus a duplicate 4.6.5 chunk exit 1, 2 copies of ONE literal; the literal rewritten (grep count 1 to 0) exit 1, blind-matcher refusal; no argument exit 2. Fixtures were scratch copies, no tracked file was mutated. Mergeability probe (bare --shared clone, no driver) of 8435a83 against the newer origin/main 454bbb6: merge-tree exit 0, clean. NOT MEASURED: the CI Console Pin Gate and the type-check lanes (CI-owned). Also NOT MEASURED: the 4 commits main gained after fbcc05f (454bbb6, which also touches registry.ts, #21176). dispatch-gates flagged STALE TREE for scripts/doc-authoring-prose-id.baseline.json and scripts/engine-double-contract.pinned.json; CI's merge ref is the reading for those.",
"mcp_calls": "0 - no MCP GitHub tool called",
"api_writes": "1 - POST /repos//issues/21108/comments (this os-dev-report) through scripts/pm/post-stamped.mjs and the fleet-write relay. git push not counted. Reads only via gh api GET.",
"open_questions": [],
"out_of_scope_findings": [
"carrier: none (承接者:无) · noted, not filed · the prior report's two findings stand unchanged (check-console-injection.mjs header sentence on release.yml's key; objectui#11353 landed with no objectui changeset)"
]
}
Generated by Claude Code
objectstack-fleet commented
on Oct 1, 2026 ContributorAuthorMore actionsPM review — PR #21149: ACCEPT; landed by the seat (normal path: no governed path, not a security change, under the human-merge size threshold)
Reviewed-by: PM seat,
session_01MRdbfpy4sQT8bUjmMhxsN7. Implemented-by: os-dev subagent, then a take-over os-dev on the same claim after a container restart.- Pin:
.objectui-shae420df310f5b→31971ff1e28f. That is objectui#11353's merge commit, the minimal commit that contains it. It went through the pin-bump procedure (bump-objectui.sh,build-console.sh,gen-sdui-manifest-node.mjs,gen:sdui-lockstep), and all 49 asserting pin citations were re-measured at the pin. - Single-zod canary in
scripts/build-console.sh, proven both ways:- the new dist exits 0 with exactly one zod
4.6.5; - the old dist at
db11afd4967cexits 1 (4.6.1 + 4.4.3); - synthetic two-version, duplicate-literal and blind-matcher controls each exit 1.
- the new dist exits 0 with exactly one zod
- Release cache key: keyed on the spec's declared zod range (PM answer A on this card).
- Merge with
main: done throughos-regen-merge.sh. One textual conflict, incomponent.zod.tsdocblocks, was resolved with main's finding(spec):action:button/action:iconacceptendpoint, the keyActionSchemarefuses with the prescriptionendpoint→target: one concept, two verdicts in one release #21005 / fix(spec): the object-kanban quickAdd retirement prescribes "delete the key", not the unregistered kanban-ui block #21141 kept verbatim. No regeneration was owed. The spec's zod is now^4.6.5, and the console still bundles exactly one zod4.6.5. - Gates: 151 derived / 151 run / 0 NOT-MEASURED / 0 UNRUN at head
8435a830eb. The spec tests pass (17399), and CI is 39 success / 3 skipped / 0 failed, mergeableclean. - Browser: the Studio New Package dialog renders Name / Id / Namespace and creates a package (201). The dashboard and report inspectors show the spec schema.
- Docs-drift bot note:
content/docs/data-modeling/analytics.mdxandcontent/docs/protocol/objectui/layout-dsl.mdxare named via symbols that main's merged changes touched. This PR changes only citation text in those spec files, so no page owes an edit from this diff. - Seat writes done: the stale PR-body lines were corrected (read back identical), and the PR assignee was set.
Generated by Claude Code
- Pin:
- added a commit that references this issue
on Oct 7, 2026
Blocked-by: objectstack-ai/objectui#11327
Filing gate: ④ the consumer-side child of a cross-repo fix (the producer half is objectstack-ai/objectui#11327 / PR objectstack-ai/objectui#11353, accepted by the PM seat; this card is owed by cross-repo coordination the moment that PR is accepted). Reader: the lane that moves the console pin, once objectui#11353 is merged — the unlock criterion is the pin being able to point at a commit that contains it. Dedupe: semantic searches on two zod instances in the console bundle and on console zod parity in
build-console.sh(open + closed, both repos) → 26 hits, none this follow-up.QA-source: #21056 · studio-authoring.first-run-loop · acceptance[0]
Why it matters for the release
The vendored Console at the current pin
db11afd4967cbundles two zod instances: objectui's 4.4.3 and the framework spec's 4.6.1. As a result, every spec-derived Studio schema form crashes: the New Package dialog cannot create a package, and the dashboard/report inspectors show "Spec schema unavailable". The published@objectstack/console@17.5.0carries the same split (static evidence: run #21056, card objectui#11327). The fix landed on the objectui side; the framework only picks it up when the pin moves.Scope
.objectui-shato an objectui commit that contains PR fix(console): an injected spec shares the console's one zod instance (objectui#11327) objectui#11353, using the pin-bump procedure (docs/releases-maintenance.md, AGENTS.md "Frontend"). Runpnpm objectui:build, thennode scripts/gen-sdui-manifest-node.mjsfor the tracked manifest. ⛔ The bump is not a rider on another PR. Note that with objectui#11353 the console build REFUSES an injected spec whose declared zod range the console's zod does not satisfy. That is by design, and it is why the current pin (zod 4.4.3 vs spec^4.6.1) must move.scripts/build-console.sh, next to the existing bundle canary: count the distinct zod version literals acrosspackages/console/dist/assets/*.jsand fail if there is more than one. This is belt-and-braces, since objectui#11353'sassertSingleZodInstancealready fails the build inside Vite. It also holds if a future pin drops that guard.release.ymlconsole cache key: today it hashes.objectui-shaandscripts/build-console.shonly. Add the spec's zod dependency (e.g.packages/spec/package.json), so that a spec zod move rebuilds the console.Acceptance
scripts/build-console.shat the new pin carries exactly one zod version literal.studio-authoring.first-run-loopacceptance[0] re-runs green.Generated by Claude Code