You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Found in #9 and verified independently by the PM. Upstream as objectstack-ai/objectstack#14105; this card is the repo-local stopgap, the same shape as #29's flow-predicate guard.
The gap
Renaming last_update_at to last_update_attt in 7 places across src/datasets/stagnation.dataset.ts — the measure field, the filter keys, the dimension:
pnpm validate EXIT=0
pnpm build EXIT=0
Nothing in the toolchain checks that a dataset's base object, include path, dimension field, measure field or filter key names anything real. #9's dev measured six such mutations, all green; I reproduced one.
The asymmetry is what makes it dangerous: a bad date-macro token on the same node is caught, path-precisely. So the layer looks guarded.
Why p0
#10 binds widgets to these datasets. The widget-to-dataset binding above is guarded (#7529/#8902); the dataset-to-object binding below is not. A mistyped measure field produces an empty chart on a green build — and an empty "not moving" tile reads exactly like a healthy team.
Three datasets carrying roughly forty field references landed in #45. I checked every one by hand before merging and they all resolve, but that check was mine, off the cuff, and it does not run again.
Scope
test/dataset-bindings.test.ts, walking dulyDatasets and resolving against dulyObjects:
base object names a declared object
every dimension field and measure field resolves on that object
joined paths (duty.frequency) resolve through a real lookup field to a real field on the target
platform objects the app references (sys_user, sys_business_unit) resolve too
Label it a stopgap pending objectstack#14105, written to be deleted rather than maintained — same convention as test/flow-predicates.test.ts.
Prove it can fail: mutate a real dataset field path, confirm on disk before measuring, confirm the guard reds while pnpm validate stays green, restore. Commit before ablating.
Note for whoever takes it
src/datasets/governed.ts is a helper, not a *.dataset.ts. Walk the barrel export, not the filenames.
Found in #9 and verified independently by the PM. Upstream as objectstack-ai/objectstack#14105; this card is the repo-local stopgap, the same shape as #29's flow-predicate guard.
The gap
Renaming
last_update_attolast_update_atttin 7 places acrosssrc/datasets/stagnation.dataset.ts— the measure field, the filter keys, the dimension:Nothing in the toolchain checks that a dataset's base object,
includepath, dimension field, measure field or filter key names anything real. #9's dev measured six such mutations, all green; I reproduced one.The asymmetry is what makes it dangerous: a bad date-macro token on the same node is caught, path-precisely. So the layer looks guarded.
Why p0
#10 binds widgets to these datasets. The widget-to-dataset binding above is guarded (#7529/#8902); the dataset-to-object binding below is not. A mistyped measure field produces an empty chart on a green build — and an empty "not moving" tile reads exactly like a healthy team.
Three datasets carrying roughly forty field references landed in #45. I checked every one by hand before merging and they all resolve, but that check was mine, off the cuff, and it does not run again.
Scope
test/dataset-bindings.test.ts, walkingdulyDatasetsand resolving againstdulyObjects:objectnames a declared objectfieldand measurefieldresolves on that objectduty.frequency) resolve through a real lookup field to a real field on the targetsys_user,sys_business_unit) resolve tooLabel it a stopgap pending objectstack#14105, written to be deleted rather than maintained — same convention as
test/flow-predicates.test.ts.Prove it can fail: mutate a real dataset field path, confirm on disk before measuring, confirm the guard reds while
pnpm validatestays green, restore. Commit before ablating.Note for whoever takes it
src/datasets/governed.tsis a helper, not a*.dataset.ts. Walk the barrel export, not the filenames.