Skip to content

chore(objectui): bump the console pin to a58626c88dc8 (carries objectui#11670 and #11669) - #22015

Merged
objectstack-fleet[bot] merged 6 commits into
mainfrom
claude/issue-21996-objectui-pin-bump
Oct 6, 2026
Merged

objectstack-fleet[bot] merged 6 commits into
mainfrom
claude/issue-21996-objectui-pin-bump

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21996
Clause-②: no

This moves the bundled Console's objectui pin from 0abd4f9f8769 (#21807, PR #21827) to a58626c88dc85954bd0af24f16ebb69454c03eee, which was objectui main when this run started. The new pin carries 5ba255538a (objectui#11670): the Studio flow designer saves a screen field's Min / Max as numbers. That is the commit the timing clause of #21898 (PR #21974) waits on. The range also carries c3623eb1 (objectui PR 11669, Studio's shared picklists).

The bump follows the repo's own procedure (scripts/bump-objectui.sh, then pnpm objectui:build and node scripts/gen-sdui-manifest-node.mjs) and the gates it derives. It adds no step to that procedure. Every file below is one the procedure or a gate wrote, and nothing else rides here.

⛔ This is not a release act. Version Packages PR #21988 is untouched. It edits packages/console/CHANGELOG.md and packages/console/package.json, and this diff edits neither. The console's release input is the new .changeset/console-a58626c88dc8.md.

Range

  • objectui git ls-remote origin refs/heads/main read a58626c88dc85954bd0af24f16ebb69454c03eee at 2026-10-06T15:32:48Z, the same sha the dispatch read at 15:08Z.
  • REST compare on objectstack-ai/objectui proves containment (base...head, head = the new pin):
    • 5ba255538a...a58626c88d: status: ahead, ahead_by: 18, behind_by: 0, merge base 5ba255538a1115e2dc2d52fa094ecf491621a5fe. The pin contains objectui#11670.
    • c3623eb1...a58626c88d: ahead, 15 ahead, 0 behind.
    • 0abd4f9f87...a58626c88d: ahead, 36 ahead, 0 behind.
  • 0abd4f9f8769..a58626c88dc8 has 36 commits, 0 merges and 252 changed paths.
  • objectui declared 36 changesets over the range, and all 36 release. There are 0 release-nothing changesets and 0 commits without a changeset. None declares major. Three carry the author's breaking annotation. The highest declared level is minor, so the console changeset is minor. The script takes the highest level objectui itself declared over OLD..NEW. These counts are the bump's own digest output.
  • No commit subject in the range carries !. git log --format='%h %s' 0abd4f9f8..a58626c88 | grep -E '^[0-9a-f]+ [a-z]+(\([^)]*\))?!:' matches nothing (exit 1).
  • Re-read at 16:25:59Z, objectui main reads 834c5594b, four commits past the pin (objectui#11685, objectui PR 11724, objectui#11682 and objectui#11687). This PR does not carry them.

Declared-breaking entries and the ADR-0087 disposition

The script wrote its adr-0087: TODO placeholder into the console changeset. It is answered not-required (no-migration-prescription), in the wording the previous bumps used. check-adr-0087-registration --base origin/main reports "1 declared-breaking changeset(s), each carrying an ADR-0087 disposition". check-changeset-no-major --base origin/main exits 0.

Each entry is objectui's own package surface:

  1. objectui#4425 (eb4552e71): objectui's @object-ui/types faces refuse label on a metric-card in an objectui dashboard node's widgets[] slot.
  2. objectui#11709 (89cc738da): inside a widget's legacy component envelope, a metric-card is judged by the slot's component arm alone.
    • metric-card is not a member of @objectstack/spec's PageComponentType and has no ComponentPropsMap row.
    • The ObjectStack dashboard widget's type vocabulary is the chart types (metric, kpi and the rest).
    • No example or package source here authors a metric-card node, and the regenerated sdui.manifest.json has no metric-card entry.
  3. objectui#11678 (48c82c9d5): @object-ui/app-shell's RecentItem becomes a union, and addRecentItem stops taking a label for an object, dashboard, page or report entry. No code here imports @object-ui/app-shell. The only code here that names the ui.recent preference is the SQL driver's tests, which store the row as an opaque value.

What changed here (22 files, +491 / -161)

file written by gate that required it
.objectui-sha scripts/bump-objectui.sh a58626c88dc85954bd0af24f16ebb69454c03eee --no-commit Console Pin Gate builds what it names
.changeset/console-a58626c88dc8.md the same run (the digest); the only later edit is the ADR-0087 answer above check-adr-0087-registration, check:objectui-changeset
sdui.manifest.json, scripts/sdui-manifest.record.json node scripts/gen-sdui-manifest-node.mjs over .cache/objectui-a58626c88dc8 check-sdui-manifest.mjs
packages/sdui-parser/objectui-lockstep.json pnpm gen:sdui-lockstep against the same tree check:sdui-lockstep
54 asserting citations in 12 files under packages/spec/src; migrations/registry.ts via gen:migration-registry re-measured by hand (below) check:objectui-pin-citations
.changeset/objectui-pin-citations-a58626c88dc8.md hand-written, @objectstack/spec patch check:published-files / Check Changeset (the shipped describes name the pin)
content/docs/references/ui/view.mdx check:generated --fix check:docs
  • The bump script. It ran against the sibling objectui checkout after git fetch origin main there, with the target sha passed explicitly. The range walked completely without a deepen. The checkout was read and fetched only.
  • The manifest. It still has 107 components. The sha256 moves from f95d406a584e… to e0654735a318….
    • One input moved: record:details sections gained a sentence in its description. A section that names a field group now takes the group's visibleWhen as well (objectui#11630).
    • No key, type or required flag moves.
    • The record moves its pin and modulesRoot. objectui's workspace version stays 17.7.0.
  • The lockstep. It records 214 grammar lines (blob 0131f27cf86d), 25 diagnostic codes and containment predicate 76c18fb95d1f. All are unchanged, so no port is owed.
  • The 54 asserting pin citations were re-measured, not restamped.
    • Method. Each record's cited objectui files were resolved against the tree at 0abd4f9f8 and intersected with the range's 252 changed paths. Every anchor in a changed file was mapped through git diff -U0 0abd4f9f8 a58626c88 and its text compared at both pins.
    • Fifteen cited files changed: ObjectKanban.tsx, KanbanImpl.tsx, ObjectTree.tsx, ObjectTimeline.tsx, record-details.tsx, action-group.tsx, action-menu.tsx, static-params.ts, MetricWidget.tsx, MetricCard.tsx, form.tsx, plugin-kanban.mdx and the en / zh / de packs.
    • Result. Every cited line in them is byte-identical at the new pin. 97 anchor citations in the records' current text MOVED and were re-pointed, and each record's new hop sentence says by how much. No read point an asserting record cites changed content or died. Every other cited file is byte-identical across the hop (git diff --quiet).
    • Records. Each of the 41 comment records gains a dated 2026-10-06 hop sentence and keeps its earlier history. The FormField.span describe changes its sha only: WIDE_FIELD_TYPES, the field-type alias table and spanLadderFor are byte-identical.
    • Counts. Each was re-taken by the record's own method and reads as before: the keyboardNavigation hit lines (15, against 3 for schema.editable), ObjectKanban.tsx's quickAdd / onQuickAdd (2 each, against 11 for onCardClick), and the ElementDataSourceGate occurrences in the five src/index.tsx shells (0, 3, 3, 3 and 4).
    • Corpus counts. The six migration entries' counts were re-taken with git grep -o -F. That method first reproduced every 0abd4f9f8 number: 7650 files, objectstack 17390, @objectstack/spec 7209, timeout 1360, RuntimeConfig 293, resourceLimits 2, useState 2478, window 4194, period 238, interval 195, metrics 401, Span 508, SpanSchema 57, TTL 182 and tenant 1318.
    • The new readings are 7754 files, objectstack 17468, @objectstack/spec 7246, timeout 1431, RuntimeConfig 299, resourceLimits 2 (the same two packages/app-shell hits), useState 2491, window 4255, period 247, interval 200, metrics 401, TTL 184 and tenant 1319.
    • All 99 checked tokens still read zero at both pins: the export lists of plugin-lifecycle-advanced.zod.ts, tracing.zod.ts and metrics.zod.ts, plus every named key. The exceptions are Span / SpanSchema, which read 509 / 57. The one new Span hit is a colSpan.

No example, test or gate needed adapting, and no code changed outside generated records, citations and changesets.

Console build (the local Console Pin Gate equivalent)

Both steps ran under the verify lock.

  • Dependency build. turbo run build --filter=@objectstack/client --filter=@objectstack/spec --filter=@objectstack/sdui-parser ran 33 tasks and exited 0 in 2m05s.
  • Console build. pnpm objectui:build exited 0 in 7m03s on the shared box.
    • OBJECTUI_ROOT pointed at a scratch repository holding only the pin commit, so the build's git worktree add registered nothing in the sibling objectui checkout.
    • The log reports "Bundle canary 'import/jobs' present".
    • It reports "Single-zod canary: exactly one zod version literal {major:4,minor:6,patch:5}".
    • It reports "Console bundle carries THIS tree's @objectstack/spec, and only it".
    • It reports "@objectstack/console dist ready (64400 KB) from objectui@a58626c88dc8".
  • check:console-sha and check:console-injection exit 0 against that dist.

Gates and tests (head b86e6f264)

  • Derived gates. node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack derived 127 commands from the 22-path diff. A throwaway merge onto current main (1bc6ca1d3) derives the same 127.
    • All 127 ran at b86e6f264 after a full workspace build (turbo run build --filter=!@objectstack/docs), each exit code written to disk. All 127 exit 0. --ran reports "127 derived, 127 run, 0 NOT-MEASURED, 0 UNRUN", with every exit code recorded.
    • An earlier pass also ran all 127. There, check:skill-examples and check:dual-build-cjs-loads answered PREREQUISITE NOT MET (exit 3). check:dts-closure and check:docs-transcript-drift read a packages/spec/dist that a concurrent build of mine was rewriting. All four are green on the rerun above.
  • Pin citations. check:objectui-pin-citations --verify-anchors reads the sibling checkout at the pin. It reports "54 asserting objectui pin citation(s) match .objectui-sha (a58626c88)" and "7 anchor content assertion(s) verified against objectui at a58626c88".
  • Other pin gates. check:sdui-lockstep reports "this copy is byte-identical to objectui@a58626c88dc8". check-sdui-manifest reports "recorded at the live objectui pin a58626c88dc8… @object-ui 17.7.0 is the version objectui a58626c88dc8… declares".
  • @objectstack/spec. vitest run --project local passed 619 files: 18485 tests, 1 todo. typecheck exits 0.
  • @objectstack/sdui-parser. 14 files and 225 tests pass, and typecheck exits 0.
  • Suites that read the regenerated manifest:
    • @objectstack/lint src/validate-jsx-pages.production-witness.test.ts: 5 passed.
    • @objectstack/metadata-protocol src/protocol.runtime-authoring-gate.test.ts: 70 passed.
    • @objectstack/cli unit tier src/utils/sdui-manifest.test.ts, src/utils/console.sha-drift.test.ts and test/validate-build-gate-parity.test.ts: 3 files, 87 passed.
    • The CLI integration tier (test/jsx-gate-manifest-notice.e2e.test.ts spawns the CLI) is declared to CI.
  • Lint. eslint --no-inline-config --format json over the 15 changed TS files reports 15 files, 0 errors and 0 warnings.
    • The lint population is **/*.{ts,tsx,mts,cts,js,jsx,mjs,cjs} (eslint.config.mjs:971).
    • The config enables no type-aware linting (:328), so this diff cannot move a verdict on an untouched file.
    • Repo-wide pnpm lint is left to CI.
  • Console Pin Gate. It is CI's to run on this head, and its verdict is read on the PR.
  • Browser smoke. NOT MEASURED. The dispatch asked for none, and the range's own landings carry their objectui-side tests.

Acceptance notes

  • objectui#11638 retired a read that a dated record still lists. The two action containers no longer read a member's properties.params.
    • ui/component.zod.ts's action-container member docblock still lists that read under "Read, and refused anyway". The docblock is in the historical spelling, measured at .objectui-sha pin 2e818d0b51ec.
    • The spec refuses the key either way, so the accept set and the save gate do not move, and the renderer and the save gate still agree.
    • The record is a dated measurement that the pin-citation gate does not hold to the current pin, so nothing here re-measures it. Noted, not filed. Carrier: none.
  • The shipped console now reads KanbanConfig.summarizeField (objectui#11629): each kanban column header totals it. The key is declared in ui/view.zod.ts, and the liveness ledger carries no row for it, so nothing here is owed.
  • The console's sign-up gating now reads features.audiencePosture from /api/v1/auth/config (objectui#11691, objectui#11705). This repo's auth plugin serves that key (auth-manager.ts, getPublicConfig) and serves GET /auth/bootstrap-status, so that seam holds.
  • main moved four commits past this branch's base (f0022c46c..1bc6ca1d3). None of them touches a file this diff touches, and git merge-tree --write-tree HEAD origin/main is clean. No merge was made; the merge queue rebuilds on the current main.
  • Writes. One draft PR through the relay, one label write on the PR (assignee os-justin), and the report comment on chore(objectui): bump the console pin past objectui 5ba255538a — it carries objectstack-ai/objectui#11670, which unlocks #21898 (PR #21974, ACCEPTed) #21996.

Generated by Claude Code

claude added 6 commits October 6, 2026 15:36
…onsole changeset)

Written by scripts/bump-objectui.sh a58626c88dc85954bd0af24f16ebb69454c03eee --no-commit.

Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>
…parser lockstep at a58626c88dc8

node scripts/gen-sdui-manifest-node.mjs over .cache/objectui-a58626c88dc8 (pnpm objectui:build),
and pnpm gen:sdui-lockstep against the same tree.

Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>
…for a58626c88dc8

Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>
…ns at a58626c88dc8

54 asserting citations re-read against objectui 0abd4f9f8769..a58626c88dc8: moved anchors
re-pointed with their text byte-identical, counts re-taken by each record's own method, the
six migration entries' corpus counts re-taken with git grep -o -F, and registry.ts
regenerated with gen:migration-registry.

Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>
…m to asserting records

Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>
….span describe's pin

pnpm --filter @objectstack/spec check:generated --fix (check:docs was the one stale artifact).

Claude-Session: https://claude.ai/code/session_01VF48aw8RPG6wzDnMgp6rtw
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 2 package(s): @objectstack/sdui-parser, @objectstack/spec, touching 14 documentable anchor(s). ⚠️ 2 changed file(s) yielded no anchor (packages/sdui-parser/objectui-lockstep.json, packages/spec/src/kernel/functional-completeness.ts), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files.

2 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/data-modeling/analytics.mdx (via DatasetMeasureSchema (symbol, a top-level const))
  • content/docs/protocol/objectui/layout-dsl.mdx (via ComponentPropsMap (symbol, a top-level const object))

⛔ 6 release-owned page(s) also name something this change touched. These are read-only:

  • content/docs/releases/v15.mdx (via PageTabsProps (symbol, a top-level const object))
  • content/docs/releases/v17/17-1.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-3.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-4.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-5.mdx (via ComponentPropsMap (symbol, a top-level const object))
  • content/docs/releases/v17/17-7.mdx (via ComponentPropsMap (symbol, a top-level const object))

content/docs/releases/ is RELEASE-OWNED (AGENTS.md "Documentation Guardrails"): release
notes are written centrally at release time, and a code PR that edits them is the exact PR
that guardrail exists to stop. They are still audited — read-only. If one of them is actually
wrong, file an issue or open a dedicated docs-only PR; do not edit it here.

What this run could not see
  • 2 changed file(s) yielded no anchor (packages/sdui-parser/objectui-lockstep.json, packages/spec/src/kernel/functional-completeness.ts) — pages documenting those are invisible to this run
  • 2 name(s) were too generic to anchor anything (single lowercase words)
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 140 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 1fb274e61cfff12ede54963d779acdfd079be318 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 9ed99b3475b1885f5a4a2592dab6e2773a892825 — the merge of head b86e6f2646d430231aa00cb6b400d836be17bded into base 1fb274e61cfff12ede54963d779acdfd079be318, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 9ed99b3475b1885f5a4a2592dab6e2773a892825 && git checkout 9ed99b3475b1885f5a4a2592dab6e2773a892825
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 1fb274e61cfff12ede54963d779acdfd079be318 b86e6f2646d430231aa00cb6b400d836be17bded && git checkout -B drift-repro 1fb274e61cfff12ede54963d779acdfd079be318 && git merge --no-ff b86e6f2646d430231aa00cb6b400d836be17bded

node scripts/docs-audit/affected-docs.mjs --json 1fb274e61cfff12ede54963d779acdfd079be318

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 1fb274e61cfff12ede54963d779acdfd079be318 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 6, 2026 17:25
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 6, 2026 17:25
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 299a2c6 Oct 6, 2026
37 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-21996-objectui-pin-bump branch October 6, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(objectui): bump the console pin past objectui 5ba255538a — it carries objectstack-ai/objectui#11670, which unlocks #21898 (PR #21974, ACCEPTed)

2 participants