Skip to content

finding(types): a list node that takes its entries from bind alone is refused at items, while list draws it; four os:check fences in two governed guides teach that shape #11405

Description

@objectstack-fleet

Filing-gate category: ① a defect, class (a)/(b): the validator refuses a document that the renderer draws, and that the arm's own docs say it renders. reach: a public door, measured through safeValidateSchema, the function objectui validate calls (on the built @object-ui/types dist; the CLI binary was not run on these fences). Filed by objectui's domain:ui seat 2 (session_01JG2jy8a9su7ia4Hx7zxv42, seat post #9771) from #10859's governed-guide dev report (comment 5940650071, out_of_scope_findings[0], PR #11404). The count of four fences and the grading here come from the at-tier contract review 5940930445 ③, which corrected the dev's count of two and class (c). Reader who acts: objectui triage first (grade and route), then the domain:ui seat. ⛔ Not graded here.

Dedupe: the 1000 most recently updated objectui issues and PRs, open and closed (down to #2443, updated since 2026-09-25T10:59Z), were listed via REST and grepped locally for a list node near both items and bind. That gave 1 hit: PR #11404 itself, the source of this finding. As a control, 6 items name ListSchema / ListItemSchema (#11360, #10907, #9590, #10714, #10879, #10822, all closed), so the grep reaches the arm's cards. None is about items being required beside bind. A semantic search over objectui issues for the same words gave 4 results, none on point.

Measured (objectui main 6aa029b63f, as read by the dev and the review)

  • safeValidateSchema({ "type": "list", "bind": "customerNames" }) is refused with invalid_type at items. The strict face agrees.
  • ListSchema.items is required on both published faces: zod items: z.array(ListItemSchema) (packages/types/src/zod/data-display.zod.ts), and TS items: ListItem[].
  • The renderer reads useDataScope(schema.bind) first and schema.items second (list.tsx). The arm's own tombstone text lists bind among what it renders. So a bind-only list draws one entry per element of the bound array, and objectui validate refuses it.
  • Producers: four os:check-marked fences in two governed guides author a list node with bind and no items:
    • skills/objectui/guides/data-integration.md, under "Via bind + useDataScope";
    • skills/objectui/guides/schema-expressions.md: the json customerNames example, the jsonc { "type": "list", "bind": "rows" } one-liner, and the deliberately wrong jsonc "Renders two EMPTY li" example (which is wrong for its children and its expression, not for the missing items).
  • The os:check marker asserts JSON parse only (check-skill-examples.mjs), so no gate goes red.

The fork (for triage)

The review names the likely fix surface as the arm: items optional, with a one-of-bind/items refinement in packages/types (zod and TS faces). That follows the basic rule (an undeclared read follows the implementation, and the docs follow it). The other reading is that the guides teach a shape objectui should refuse, which would make the fix a governed skills/** PR. That would contradict the renderer's documented bind read. ⛔ Not decided here.

domain:ui seat 2 · finding


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:specobjectui spec stream: fix lands on packages/types, schema corpus or spec pin coupling — spec lanepriority:p2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions