Skip to content

Commit c993b7c

Browse files
os-billclaude
andauthored
fix(scripts): relate the recorded @object-ui version to the objectui pin (#18814)
Fixes #18611 Clause-②: no — one repo script, `scripts/check-sdui-manifest.mjs`. No published bytes move (measured below). ## What changed The gate gains **check 4**: the record's `objectuiPackagesVersion` must be the version `packages/core/package.json` **declares at the pinned commit**. Checks 1-3 already reached both fields and related neither — the version was a presence check only, so a record naming pin C and a version C never declared was green. That is not hypothetical: `gen-sdui-manifest-node.mjs` defaults `--objectui-version` to **the version already in the record**, while re-recording `objectuiSha` from the live pin. A regeneration after a pin bump therefore writes the NEW pin under the OLD version string, and every check in this gate stayed green through it. ## Question 1 — how "corresponds" is judged, and the channel readings behind the choice The seat marked this unverified and asked for the channel to be measured first. Measured in this container, worktree at `034f5a3af`: | channel | reading | | --- | --- | | sibling checkout `../objectui` | **present** (`/home/user/objectui`). Shallow (`--is-shallow-repository` = true) and still carries the pin: `git cat-file -e 53ded82b...^{commit}` exit 0; `git show 53ded82b:packages/core/package.json` reads `"version": "17.6.0"` | | in-tree witness of the version | **none**. `grep -c "@object-ui/" pnpm-lock.yaml` = 0; no workspace `package.json` declares an `@object-ui/*` dependency; `packages/sdui-parser/objectui-lockstep.json` records objectui's `rev` but no version. There is no second in-repo fact to relate the version to | | the required lint job | **oracle absent**. `.github/workflows/lint.yml` has one `actions/checkout@v7` (this repo) and no objectui clone; this gate's own header declines a network dependency inside a required lint job | | `ci.yml` console-build job | **oracle present** — it already shallow-clones objectui at the pin to build the Console SPA | | depth-1 fetch of the pin | **works**: `git init` + `git fetch --depth=1 origin 53ded82bf7a494f54e344e19099dbf00854b8694` exit 0, commit resolves. The remedy line the gate prints is true, not a guess | So the predicate cannot be offline: nothing in this repo can relate the two fields. Check 4 reads the pinned commit's `packages/core/package.json` from an objectui checkout — `OBJECTUI_ROOT`, else the `../objectui` sibling, the same two places `bump-objectui.sh` and `objectui-range.mjs` look (deliberately not a second env spelling for one checkout). **Because the oracle is external, absence is reported and never scored.** Three outcomes are kept apart: `resolved` (compare), `unreachable` (no checkout, or one without the commit — NOT converted into a disagreement), `unsupported` (checkout in hand and still unable to answer — that is RED). On an unreachable oracle the success line says which leg did not run, and `--require-objectui` turns that gap into an exit 1 for callers that do hold a checkout. ## Question 2 — the BEFORE reading: do they agree today? **They agree.** Record `objectuiPackagesVersion` = `17.6.0`; `packages/core/package.json` at pin `53ded82b` declares `17.6.0`. Tightening the gate does **not** red main, and no data was touched — `sdui.manifest.json`, `scripts/sdui-manifest.record.json` and `.objectui-sha` are read-only on this card and are unchanged in this diff (1 file, 259 insertions, 24 deletions). ⚠️ This agreement does **not** contradict the card's 12-day skew observation, and check 4 does not claim it does. The card's skew is that the published tarball at `17.6.0` was built from a commit **earlier** than the pin. Check 4 cannot see that and does not pretend to: it asserts only that the record's two fields describe **one** objectui commit. Which mechanism should produce the artefact — so that the published bytes and the pinned tree are the same thing — remains #17735's question and is not ruled here. ## Acceptance controls Both legs are the real CLI, on a tree assembled from the real `sdui.manifest.json` and the real `.objectui-sha`, with the gate copied in as `scripts/check-sdui-manifest.mjs` so `DEFAULT_ROOT` resolves to the fixture. Only the record's version field differs between LIT and DARK; the artefact bytes are untouched, so `sha256` still matches and the hash leg stays green in every run. `OBJECTUI_ROOT=/home/user/objectui`. "before" is the gate taken from the merge base `034f5a3af` by `git show`, not from memory — control: `grep -c readPinnedDeclaredVersion` on that copy is **0**, with a non-zero control on the same file (`grep -c checkTree` = **8**) proving the instrument reached it. ### LIT — the red leg (record says `17.5.0`, pin declares `17.6.0`) | leg | exit | output | | --- | --- | --- | | **before** | **0** (GREEN) | `✓ check-sdui-manifest: ... and fresh at objectui pin 53ded82bf7a4….` | | **after** | **1** (RED) | `✗ check-sdui-manifest: the record's two objectui fields describe different commits: objectuiPackagesVersion is "17.5.0", but objectui 53ded82bf7a4… — the pin the record itself names — declares "17.6.0" in packages/core/package.json` … `Regenerate against the pin: node scripts/gen-sdui-manifest-node.mjs --objectui-version 17.6.0` | Same input, same command. The red leg is the evidence; "it is still green" is not. ### DARK — the real, agreeing record | leg | exit | output | | --- | --- | --- | | **before** | 0 | `✓ ... and fresh at objectui pin 53ded82bf7a4….` | | **after** | 0 | `✓ ... and recorded at the live objectui pin 53ded82bf7a4….` + `@object-ui 17.6.0 is the version objectui 53ded82bf7a4… declares in packages/core/package.json (read from /home/user/objectui)` | Plus, on this worktree at `3ba8c97dd4`: `node scripts/check-sdui-manifest.mjs` exit 0, `--self-test` exit 0 (11 cases), `--require-objectui` exit 0 (the sibling is in hand here). ### The no-oracle shape — what CI will see today | run | exit | reading | | --- | --- | --- | | LIT input, no checkout reachable | **0** | `NOT CHECKED — objectuiPackagesVersion "17.5.0" was not compared with what the pin declares: no objectui checkout at …` — the disagreement is **not** scored as a match | | same, `--require-objectui` | **1** | `--require-objectui was passed and check 4 could not run: …` | This is the honest cost of an external oracle, stated rather than hidden: **in the required lint job check 4 will report NOT CHECKED, not green**. Wiring `--require-objectui` where a checkout already exists (the `ci.yml` console-build job) is a workflow edit outside this card's declared file surface — named in the report for the seat, not smuggled in here. ### Self-test The red leg is pinned, not just demonstrated. Five rows added (roster and floor 6 → 11), each against a throwaway objectui git repository — a real one, because check 4 resolves the pin through `git cat-file` / `git show` and a stubbed resolver would leave exactly that resolution unexercised: - `pin-declared version agreeing with the record passes` - `pin-declared version disagreeing with the record is RED` - `an unreachable objectui checkout is not a version verdict` (same disagreeing tree, oracle removed → GREEN) - `--require-objectui turns an unreachable checkout RED` - `a pinned commit with no packages/core/package.json is RED` Every row now passes its oracle explicitly, so `OBJECTUI_ROOT` in the ambient environment can neither green nor red this self-test. Each new row was probed for the reason it reds: the four RED rows carry four different problems, and the unreachable row carries none. ## Gates 30 derived families, 30 run, all exit 0, reconciled with the deriver itself: ``` node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.txt ✓ dispatch-gates --ran: 30 derived famil(ies) accounted for — 30 run, 0 NOT-MEASURED (a DERIVED zero — all 30 recorded an exit code and none of them is 3). ``` Re-derived after a fresh `git fetch origin main`: the family list is unchanged. `pnpm check:nul-bytes` exit 0 (8855 files), plus a direct control-byte scan of the changed file (no matches, with a non-zero control on the same predicate). **Lint, narrowed and the narrowing proven** — measured at `3ba8c97dd4`, clean tree: - population: **6837** files, read from eslint's own config (the extension set parsed from its `files` globs) filtered by eslint's own `isPathIgnored`, with both controls firing (the changed file reads in-population; a built artefact reads ignored); - this PR lints **1** of them: `npx eslint --no-inline-config --format json scripts/check-sdui-manifest.mjs` → 1 file, 0 errors, 0 warnings, exit 0 (file count read from the JSON output, not from prose); - invariance: type-aware linting is **not** enabled (`eslint.config.mjs` states no `parserOptions.project` and no typed rules; the only `parserOptions` are `ecmaVersion` / `sourceType`), so this diff cannot move the verdict on any file it does not touch. The repo-wide `pnpm lint` run is CI's. ## Changeset: none owed, measured Not inferred from the path. The root package is `private`. All **70** publishable packages declare package-relative `files[]` (`dist`, `README.md`, `CHANGELOG.md`; `packages/spec` adds seven more, all inside itself), and npm packs only from the package directory, so a repo-root `scripts/` file is outside every tarball. Measured on the package with the widest surface: `npm pack --dry-run --json` in `packages/spec` lists **275** entries — **0** matching `check-sdui-manifest`, **0** under `scripts/`, with the positive control firing (**202** shipped `src/**/*.zod.ts` entries), so the zero is a reading and not a dead instrument. `skip-changeset` applied. ## Acceptance notes (out of scope, noted and not folded in) - The lint step's NAME still reads "fresh at the objectui pin"; the success line it prints now separates what was verified from the correspondence leg. A workflow-prose nit, outside this file surface. - A pin hand-edited to a malformed value in **both** `.objectui-sha` and the record is silent here (check 3 compares equals, check 4 reports unreachable-by-shape). `cut-rc.yml` shape-checks the pin on the release lane, which is where that is caught. - `gen-sdui-manifest-node.mjs`'s `--objectui-version` default is the mechanism that makes a stale-version record reachable at all. It is producer behaviour and #17735 is the open decision card on the producer mechanism — reported back with dedupe words rather than filed from here, and ⛔ not fixed here. --- _Generated by [Claude Code](https://claude.ai/code/session_01JbZnqu8bt6YqfJsr9vaFb3)_ Co-authored-by: Claude <noreply@anthropic.com>
1 parent 9bd631f commit c993b7c

1 file changed

Lines changed: 259 additions & 24 deletions

File tree

0 commit comments

Comments
 (0)