Skip to content

Align the docs with framework 17.0 — the pages still describe the 16.x contract #78

Description

@os-zhuang

objectstack 17.0.0 was released on 2026-08-14 (release notes). These docs were aligned to 16.0 in #52 and have not moved since, so several pages now describe a contract the runtime no longer has.

Measured against the release notes and origin/main of both repositories. Grouped by how much a reader loses, not by page.

Live contradictions — a reader who follows these fails

Page Line Says 17.0
quickstart.mdx 18 "Node.js 20 or newer — node --version" engines.node is >=22.0.0 across all 50 manifests. Node 20 reached EOL 2026-04-30
resources/faq.mdx 13 "Node 20+ and the CLI are enough" same
resources/faq.mdx 38-39 "Q: Does ObjectOS support GraphQL? A: REST is the primary surface. GraphQL is on the roadmap" The GraphQL surface was removed in 17.0. The answer promises a roadmap item that was deleted
build/data/index.mdx 220, 226-228 documents enable: { trash: true } as the shipped key, "on by default", and explicitly directs readers to it as the replacement for a 16.0 removal object.enable.trash and mru were removed in 17.0. The page now points at a key that no longer parses

The enable.trash one is the worst of the four: it is not stale prose, it is an instruction that tells a reader to write a key which — under 17.0's closed authorable surface — now fails at parse time with a named error.

Stale framing — nothing fails, but the page describes the wrong product

  • GraphQL, elsewhere. reference/runtime-capabilities.mdx:73 ("GraphQL and OData are framework-level capabilities"), extend-existing-systems.mdx:72 ("REST/GraphQL endpoints"), and the skill blurbs at reference/skills-cli.mdx:53 and build/ai-skills.mdx:45 ("REST/GraphQL endpoints, auth, realtime"). Each needs a different call — some should drop the word, the skill blurbs may be quoting upstream text that itself changed.
  • Media fields. reference/field-types.mdx:136-158 documents file/image/avatar/video/audio with flat accept / maxSize, and carries a 16.0 note about fileAttachmentConfig. In 17.0 a media field stores an opaque sys_file id, the {url, name, size, …} object is the read (expanded) form, and accept / maxSize moved from declarable to declarable and server-enforced. The page never states what is stored, so it is not wrong so much as silent about the thing that changed. configure/storage.mdx:19-21 already says metadata persists in sys_file and should be checked for agreement.
  • Export as a privilege. configure/permissions/index.mdx:83, permission-sets.mdx:19,56 and managing-access.mdx:147 treat export as one system permission among several. In 17.0 allowExport unset means denied rather than "inherit read", and viewAllRecords / modifyAllRecords no longer confer it. Whether these pages actually assert the old inheritance needs reading — the grep found the word, not the claim.
  • Record access fail-closed. configure/permissions/record-access.mdx:14 and resources/glossary.mdx:182 describe sharing rules as "grant access based on declarative criteria". 17.0 made a rule stored without criteria share nothing (it previously matched every record), and an RLS policy with enabled: false actually disabled (it previously still contributed its grant). If either page implies the old behaviour, it is describing a security contract that no longer holds.
  • Approvals. 17.0 adds expression approvers (CEL), a node-level onEmptyApprovers policy, and declared decision outputs resuming as <nodeId>.<key>. build/automation/approvals.mdx was rewritten for 16.0 quorum/会签 in docs: align product docs with framework 15.x→16.0 changes #52 and does not have these.
  • Boot and readiness. 17.0 makes a datasource that objects bind to fail the boot, objectql.init() refuse to start on a dead driver, and /ready answer 503 when one stops answering. deploy/docker.mdx:121, deploy/kubernetes.mdx:38 and operate/backup.mdx:137 already describe /api/v1/ready; they should be checked for whether they now under-promise.
  • resources/changelog.mdx stops at 16. No 17 entry exists.

One item to verify, not to transcribe

configure/mcp.mdx:157 documents ai.requiresConfirmation on an action. 17.0 removed tool.requiresConfirmation. Those may be different keys on different schemas. ⛔ Do not assume they are the same — read packages/spec and decide from the schema, not from the similar name.

How to work this card

The release notes are a lead. packages/spec on objectstack@main is the authority. Every claim above was derived from release prose plus a grep of this repository; none of it was checked against the schema. Where the two disagree, the schema wins and the finding should be corrected in the PR body.

Same constraints as #64: this repository is not the authority for runtime behaviour or measurements. Where 17.0 changed something this repo cannot observe, describe the shape and link to the reference rather than inventing detail.

English only. Locale siblings are generated artifacts; leave them, they will report as stale and the next translation pass picks them up. The output validator landing in #74 blocks only on locale files a PR changes, so an English-only PR is unaffected.

Related: #52 (the 16.0 alignment, same shape), #63, #70 (six pages still teaching the multi-Environment model — adjacent, decide whether to fold in or keep separate).

Activity

  1. self-assigned this
    on Aug 18, 2026
  2. os-zhuang commented on Aug 18, 2026

    @os-zhuang
    ContributorAuthor

    Claim: PM loop round 4
    Session: session_01CJPxtTxoxTUnjNdTbiEaRa
    Branch: claude/issue-78-align-docs-with-17-0
    Worktree: objectos-issue-78
    Domain: n/a — objectos has no lane or seat (objectstack-ai/objectstack#9551). Dispatch authorized by the maintainer, 原话: 「现在允许你派 objectos 的活」.
    File surface: content/docs/**/*.mdx (English only) — quickstart, resources/faq, resources/changelog, build/data/index, build/automation/approvals, reference/field-types, reference/runtime-capabilities, reference/skills-cli, build/ai-skills, extend-existing-systems, configure/permissions/**, configure/mcp, configure/storage, deploy/**, operate/**, resources/glossary
    Container & model: M/L, mode:subagent, model: opus
    Clause-②: no — this repository holds no contract surface; the 17.0 contract changes happen in objectstack, this card only describes them.
    Serial constraints cleared: nothing in flight in this repository. #79 (the Console rename) is filed Blocked-by: this card precisely because its file surface overlaps almost completely — correctness lands first.

    Freshness of the inputs

    objectstack@origin/main was fetched at claim time; 17.0.0 is released (published to latest on 2026-08-14) and content/docs/releases/v17.mdx is the source the card quotes. The local objectstack checkout in this container is 15 commits behind and is shared with other agents — read it via git show origin/main:<path>, never by checking out or switching its HEAD.

    What this claim does not assert

    Every finding on the card came from release prose plus a grep of this repository. None of it was checked against packages/spec. The card says so and the dispatch repeats it: the schema is the authority, and a finding corrected by the schema is a good outcome, not a failed one.


    Generated by Claude Code

  3. os-zhuang commented on Aug 18, 2026

    @os-zhuang
    ContributorAuthor

    ACCEPT — #82.

    Accepted under the direct-acceptance fallback: the dev died to a container restart after pushing, so no report ever arrived. All three conditions hold — draft PR present, CI green, agent confirmed dead by an explicit host signal rather than inferred from silence. Review criteria are not reduced for it; if anything the verification below is wider than usual, because the PR body is the only account of the work and nothing in it can be taken on trust.

    Spec claims sampled against objectstack@origin/main

    Every one of these is a claim the PR makes about the schema. I checked the load-bearing ones rather than all of them, weighted toward the changes that would be hardest to notice if wrong:

    Claim Reading
    engines.node is >=22.0.0 ✓ root package.json
    ActionAiSchema.requiresConfirmation is live ✓ packages/spec/src/ui/action.zod.ts:718
    The removed tool.requiresConfirmation prescribes it ✓ packages/spec/src/ai/tool.zod.ts:68 — "action.ai.requiresConfirmation — that is the flag the HITL approval queue reads"
    allowExport unset = denied, not implied by viewAllRecords / modifyAllRecords ✓ packages/spec/src/security/permission.zod.ts:132, verbatim
    trackHistory default false ✓ object.zod.ts:247
    files default false ✓ object.zod.ts:281
    searchable / clone exist, default true ✓ object.zod.ts:250,303
    enable.trash never had a runtime consumer ✓ object.zod.ts:136 retirement guidance, verbatim including the "false affordance" reasoning

    The card was wrong twice, and the PR caught both

    configure/mcp.mdx — refuted, correctly. I flagged ai.requiresConfirmation against the tool.requiresConfirmation 17.0 removed. They are different keys on different schemas, and the removed one's own guidance prescribes the one that page documents. The page was already correct; editing it would have replaced a true statement with a false one. The card told the dev to read both schemas rather than assume, and that instruction is the only reason this did not become a regression — but the card should not have carried the item as a finding in the first place.

    build/data/index.mdx — the defect was older and larger than the card said. I described it as "documents a key 17.0 removed". The schema says trash never had a runtime consumer at all: every delete has always been hard, and trash: false was authors opting out of something that never ran. So the page was not describing a retired capability, it was describing a capability that never existed. The rewrite says that plainly, which is the correct fix and not the one the card asked for.

    While there, it corrected a pre-existing error the card never flagged: the page documented trackHistory as "default true" when the schema defaults it to false, and showed files: true in a sample whose own comment said "default false".

    Other checks

    Item Reading
    Scope 19 files, all content/docs/**, English only — zero locale siblings, matching the declared surface
    CI build and Ownership & freshness both green on 8fe88ba
    Freshness gate 15 stale per locale (the edited pages), gate passes — the designed shape for an English-only PR
    Output validator passes, 104 pre-existing corpus findings reported, none unsafe, none in files this PR touches
    GraphQL nuance Preserved in both surviving mentions: graphql remains valid as an external datasource protocol, which is a system ObjectOS queries rather than a surface it serves. Dropping that distinction would have been the easy over-correction

    One item flagged for the maintainer rather than settled here

    The Support windows table on resources/changelog.mdx was rewritten from fixed branches and dates ("14.x (current) … at least 12 months after 15.0 ships") to a statement relative to the current major, with dates deferred to the release notes.

    This is the only change in the PR that removes a concrete claim instead of correcting one, and the PR says so. It is defensible — the old table named 14.x as current while the product is on 17.x, so it was already false, and this repository has no authority to publish support dates. But a support window is a commercial commitment, not a technical fact, so the shape of that promise is the maintainer's call and not a PM seat's. Landing it because a false table is worse than a vaguer true one; raising it because it should not pass unnoticed.

    Out-of-scope findings


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions