Repository navigation
Align the docs with framework 17.0 — the pages still describe the 16.x contract #78
Description
Activity
Claim: PM loop round 4
Session:session_01CJPxtTxoxTUnjNdTbiEaRa
Branch:claude/issue-78-align-docs-with-17-0
Worktree:objectos-issue-78
Domain: n/a — objectos has no lane or seat (objectstack-ai/objectstack#9551). Dispatch authorized by the maintainer, 原话: 「现在允许你派 objectos 的活」.
File surface:content/docs/**/*.mdx(English only) —quickstart,resources/faq,resources/changelog,build/data/index,build/automation/approvals,reference/field-types,reference/runtime-capabilities,reference/skills-cli,build/ai-skills,extend-existing-systems,configure/permissions/**,configure/mcp,configure/storage,deploy/**,operate/**,resources/glossary
Container & model: M/L,mode:subagent,model: opus
Clause-②: no — this repository holds no contract surface; the 17.0 contract changes happen inobjectstack, this card only describes them.
Serial constraints cleared: nothing in flight in this repository. #79 (the Console rename) is filedBlocked-by:this card precisely because its file surface overlaps almost completely — correctness lands first.Freshness of the inputs
objectstack@origin/mainwas fetched at claim time; 17.0.0 is released (published tolateston 2026-08-14) andcontent/docs/releases/v17.mdxis the source the card quotes. The localobjectstackcheckout in this container is 15 commits behind and is shared with other agents — read it viagit show origin/main:<path>, never by checking out or switching its HEAD.What this claim does not assert
Every finding on the card came from release prose plus a grep of this repository. None of it was checked against
packages/spec. The card says so and the dispatch repeats it: the schema is the authority, and a finding corrected by the schema is a good outcome, not a failed one.
Generated by Claude Code
ACCEPT — #82.
Accepted under the direct-acceptance fallback: the dev died to a container restart after pushing, so no report ever arrived. All three conditions hold — draft PR present, CI green, agent confirmed dead by an explicit host signal rather than inferred from silence. Review criteria are not reduced for it; if anything the verification below is wider than usual, because the PR body is the only account of the work and nothing in it can be taken on trust.
Spec claims sampled against
objectstack@origin/mainEvery one of these is a claim the PR makes about the schema. I checked the load-bearing ones rather than all of them, weighted toward the changes that would be hardest to notice if wrong:
Claim Reading engines.nodeis>=22.0.0✓ root package.jsonActionAiSchema.requiresConfirmationis live✓ packages/spec/src/ui/action.zod.ts:718The removed tool.requiresConfirmationprescribes it✓ packages/spec/src/ai/tool.zod.ts:68— "action.ai.requiresConfirmation— that is the flag the HITL approval queue reads"allowExportunset = denied, not implied byviewAllRecords/modifyAllRecords✓ packages/spec/src/security/permission.zod.ts:132, verbatimtrackHistorydefaultfalse✓ object.zod.ts:247filesdefaultfalse✓ object.zod.ts:281searchable/cloneexist, defaulttrue✓ object.zod.ts:250,303enable.trashnever had a runtime consumer✓ object.zod.ts:136retirement guidance, verbatim including the "false affordance" reasoningThe card was wrong twice, and the PR caught both
configure/mcp.mdx— refuted, correctly. I flaggedai.requiresConfirmationagainst thetool.requiresConfirmation17.0 removed. They are different keys on different schemas, and the removed one's own guidance prescribes the one that page documents. The page was already correct; editing it would have replaced a true statement with a false one. The card told the dev to read both schemas rather than assume, and that instruction is the only reason this did not become a regression — but the card should not have carried the item as a finding in the first place.build/data/index.mdx— the defect was older and larger than the card said. I described it as "documents a key 17.0 removed". The schema saystrashnever had a runtime consumer at all: every delete has always been hard, andtrash: falsewas authors opting out of something that never ran. So the page was not describing a retired capability, it was describing a capability that never existed. The rewrite says that plainly, which is the correct fix and not the one the card asked for.While there, it corrected a pre-existing error the card never flagged: the page documented
trackHistoryas "default true" when the schema defaults it tofalse, and showedfiles: truein a sample whose own comment said "default false".Other checks
Item Reading Scope 19 files, all content/docs/**, English only — zero locale siblings, matching the declared surfaceCI buildandOwnership & freshnessboth green on8fe88baFreshness gate 15 stale per locale (the edited pages), gate passes — the designed shape for an English-only PR Output validator passes, 104 pre-existing corpus findings reported, none unsafe, none in files this PR touchesGraphQL nuance Preserved in both surviving mentions: graphqlremains valid as an external datasource protocol, which is a system ObjectOS queries rather than a surface it serves. Dropping that distinction would have been the easy over-correctionOne item flagged for the maintainer rather than settled here
The Support windows table on
resources/changelog.mdxwas rewritten from fixed branches and dates ("14.x (current) … at least 12 months after 15.0 ships") to a statement relative to the current major, with dates deferred to the release notes.This is the only change in the PR that removes a concrete claim instead of correcting one, and the PR says so. It is defensible — the old table named 14.x as current while the product is on 17.x, so it was already false, and this repository has no authority to publish support dates. But a support window is a commercial commitment, not a technical fact, so the shape of that promise is the maintainer's call and not a PM seat's. Landing it because a false table is worse than a vaguer true one; raising it because it should not pass unnoticed.
Out-of-scope findings
- glossary "Record Share" names two recipient kinds that no longer exist (
role,group) #80 — glossary "Record Share" namesrole/group, renamed toposition/teamby ADR-0090. Pre-17.0 drift, correctly filed rather than folded in. - turbo
type-check/builddeclare noinputs, so a content-only change replays a cached green locally #81 —turbo.jsondeclares noinputsfortype-check/build, so a content-only change does not move the hash and a cached green from a sibling worktree replays asFULL TURBOin 55ms. This is the third can't-go-red finding in this repository today, after the CItestjob (The CItestjob executes nothing and cannot go red #72) and the swallowed pipefail exit status (fixed in ci(translations): enforce the output checklist as a validator #74). Worth treating as a pattern rather than three coincidences.
Generated by Claude Code
- glossary "Record Share" names two recipient kinds that no longer exist (
objectstack17.0.0 was released on 2026-08-14 (release notes). These docs were aligned to 16.0 in #52 and have not moved since, so several pages now describe a contract the runtime no longer has.Measured against the release notes and
origin/mainof both repositories. Grouped by how much a reader loses, not by page.Live contradictions — a reader who follows these fails
quickstart.mdxnode --version"engines.nodeis>=22.0.0across all 50 manifests. Node 20 reached EOL 2026-04-30resources/faq.mdxresources/faq.mdxbuild/data/index.mdxenable: { trash: true }as the shipped key, "on by default", and explicitly directs readers to it as the replacement for a 16.0 removalobject.enable.trashandmruwere removed in 17.0. The page now points at a key that no longer parsesThe
enable.trashone is the worst of the four: it is not stale prose, it is an instruction that tells a reader to write a key which — under 17.0's closed authorable surface — now fails at parse time with a named error.Stale framing — nothing fails, but the page describes the wrong product
reference/runtime-capabilities.mdx:73("GraphQL and OData are framework-level capabilities"),extend-existing-systems.mdx:72("REST/GraphQL endpoints"), and the skill blurbs atreference/skills-cli.mdx:53andbuild/ai-skills.mdx:45("REST/GraphQL endpoints, auth, realtime"). Each needs a different call — some should drop the word, the skill blurbs may be quoting upstream text that itself changed.reference/field-types.mdx:136-158documentsfile/image/avatar/video/audiowith flataccept/maxSize, and carries a 16.0 note aboutfileAttachmentConfig. In 17.0 a media field stores an opaquesys_fileid, the{url, name, size, …}object is the read (expanded) form, andaccept/maxSizemoved from declarable to declarable and server-enforced. The page never states what is stored, so it is not wrong so much as silent about the thing that changed.configure/storage.mdx:19-21already says metadata persists insys_fileand should be checked for agreement.configure/permissions/index.mdx:83,permission-sets.mdx:19,56andmanaging-access.mdx:147treat export as one system permission among several. In 17.0allowExportunset means denied rather than "inherit read", andviewAllRecords/modifyAllRecordsno longer confer it. Whether these pages actually assert the old inheritance needs reading — the grep found the word, not the claim.configure/permissions/record-access.mdx:14andresources/glossary.mdx:182describe sharing rules as "grant access based on declarative criteria". 17.0 made a rule stored without criteria share nothing (it previously matched every record), and an RLS policy withenabled: falseactually disabled (it previously still contributed its grant). If either page implies the old behaviour, it is describing a security contract that no longer holds.expressionapprovers (CEL), a node-levelonEmptyApproverspolicy, and declared decision outputs resuming as<nodeId>.<key>.build/automation/approvals.mdxwas rewritten for 16.0 quorum/会签 in docs: align product docs with framework 15.x→16.0 changes #52 and does not have these.objectql.init()refuse to start on a dead driver, and/readyanswer 503 when one stops answering.deploy/docker.mdx:121,deploy/kubernetes.mdx:38andoperate/backup.mdx:137already describe/api/v1/ready; they should be checked for whether they now under-promise.resources/changelog.mdxstops at 16. No 17 entry exists.One item to verify, not to transcribe
configure/mcp.mdx:157documentsai.requiresConfirmationon an action. 17.0 removedtool.requiresConfirmation. Those may be different keys on different schemas. ⛔ Do not assume they are the same — readpackages/specand decide from the schema, not from the similar name.How to work this card
The release notes are a lead.
packages/speconobjectstack@mainis the authority. Every claim above was derived from release prose plus a grep of this repository; none of it was checked against the schema. Where the two disagree, the schema wins and the finding should be corrected in the PR body.Same constraints as #64: this repository is not the authority for runtime behaviour or measurements. Where 17.0 changed something this repo cannot observe, describe the shape and link to the reference rather than inventing detail.
English only. Locale siblings are generated artifacts; leave them, they will report as stale and the next translation pass picks them up. The output validator landing in #74 blocks only on locale files a PR changes, so an English-only PR is unaffected.
Related: #52 (the 16.0 alignment, same shape), #63, #70 (six pages still teaching the multi-Environment model — adjacent, decide whether to fold in or keep separate).