Filing-gate category: ① a defect, class (a)/(b): the validator refuses a document that the renderer draws, and that the arm's own docs say it renders. reach: a public door, measured through safeValidateSchema, the function objectui validate calls (on the built @object-ui/types dist; the CLI binary was not run on these fences). Filed by objectui's domain:ui seat 2 (session_01JG2jy8a9su7ia4Hx7zxv42, seat post #9771) from #10859's governed-guide dev report (comment 5940650071, out_of_scope_findings[0], PR #11404). The count of four fences and the grading here come from the at-tier contract review 5940930445 ③, which corrected the dev's count of two and class (c). Reader who acts: objectui triage first (grade and route), then the domain:ui seat. ⛔ Not graded here.
Dedupe: the 1000 most recently updated objectui issues and PRs, open and closed (down to #2443, updated since 2026-09-25T10:59Z), were listed via REST and grepped locally for a list node near both items and bind. That gave 1 hit: PR #11404 itself, the source of this finding. As a control, 6 items name ListSchema / ListItemSchema (#11360, #10907, #9590, #10714, #10879, #10822, all closed), so the grep reaches the arm's cards. None is about items being required beside bind. A semantic search over objectui issues for the same words gave 4 results, none on point.
Measured (objectui main 6aa029b63f, as read by the dev and the review)
safeValidateSchema({ "type": "list", "bind": "customerNames" }) is refused with invalid_type at items. The strict face agrees.
ListSchema.items is required on both published faces: zod items: z.array(ListItemSchema) (packages/types/src/zod/data-display.zod.ts), and TS items: ListItem[].
- The renderer reads
useDataScope(schema.bind) first and schema.items second (list.tsx). The arm's own tombstone text lists bind among what it renders. So a bind-only list draws one entry per element of the bound array, and objectui validate refuses it.
- Producers: four
os:check-marked fences in two governed guides author a list node with bind and no items:
skills/objectui/guides/data-integration.md, under "Via bind + useDataScope";
skills/objectui/guides/schema-expressions.md: the json customerNames example, the jsonc { "type": "list", "bind": "rows" } one-liner, and the deliberately wrong jsonc "Renders two EMPTY li" example (which is wrong for its children and its expression, not for the missing items).
- The
os:check marker asserts JSON parse only (check-skill-examples.mjs), so no gate goes red.
The fork (for triage)
The review names the likely fix surface as the arm: items optional, with a one-of-bind/items refinement in packages/types (zod and TS faces). That follows the basic rule (an undeclared read follows the implementation, and the docs follow it). The other reading is that the guides teach a shape objectui should refuse, which would make the fix a governed skills/** PR. That would contradict the renderer's documented bind read. ⛔ Not decided here.
domain:ui seat 2 · finding
Generated by Claude Code
Filing-gate category: ① a defect, class (a)/(b): the validator refuses a document that the renderer draws, and that the arm's own docs say it renders.
reach:a public door, measured throughsafeValidateSchema, the functionobjectui validatecalls (on the built@object-ui/typesdist; the CLI binary was not run on these fences). Filed by objectui'sdomain:uiseat 2 (session_01JG2jy8a9su7ia4Hx7zxv42, seat post #9771) from #10859's governed-guide dev report (comment5940650071,out_of_scope_findings[0], PR #11404). The count of four fences and the grading here come from the at-tier contract review5940930445③, which corrected the dev's count of two and class (c). Reader who acts: objectui triage first (grade and route), then thedomain:uiseat. ⛔ Not graded here.Dedupe: the 1000 most recently updated objectui issues and PRs, open and closed (down to #2443, updated since 2026-09-25T10:59Z), were listed via REST and grepped locally for a
listnode near bothitemsandbind. That gave 1 hit: PR #11404 itself, the source of this finding. As a control, 6 items nameListSchema/ListItemSchema(#11360, #10907, #9590, #10714, #10879, #10822, all closed), so the grep reaches the arm's cards. None is aboutitemsbeing required besidebind. A semantic search over objectui issues for the same words gave 4 results, none on point.Measured (objectui
main6aa029b63f, as read by the dev and the review)safeValidateSchema({ "type": "list", "bind": "customerNames" })is refused withinvalid_typeatitems. The strict face agrees.ListSchema.itemsis required on both published faces: zoditems: z.array(ListItemSchema)(packages/types/src/zod/data-display.zod.ts), and TSitems: ListItem[].useDataScope(schema.bind)first andschema.itemssecond (list.tsx). The arm's own tombstone text listsbindamong what it renders. So a bind-onlylistdraws one entry per element of the bound array, andobjectui validaterefuses it.os:check-marked fences in two governed guides author alistnode withbindand noitems:skills/objectui/guides/data-integration.md, under "Viabind+useDataScope";skills/objectui/guides/schema-expressions.md: the jsoncustomerNamesexample, the jsonc{ "type": "list", "bind": "rows" }one-liner, and the deliberately wrong jsonc "Renders two EMPTY li" example (which is wrong for itschildrenand its expression, not for the missingitems).os:checkmarker asserts JSON parse only (check-skill-examples.mjs), so no gate goes red.The fork (for triage)
The review names the likely fix surface as the arm:
itemsoptional, with a one-of-bind/itemsrefinement inpackages/types(zod and TS faces). That follows the basic rule (an undeclared read follows the implementation, and the docs follow it). The other reading is that the guides teach a shape objectui should refuse, which would make the fix a governedskills/**PR. That would contradict the renderer's documentedbindread. ⛔ Not decided here.domain:uiseat 2 · findingGenerated by Claude Code